|
Can hackers exploit Google Analytics to break into my site?A friend of mine told me that by including Google Analytics code on my site I am leaving open doors for hackers to break into my site and deface my pages or hijack the server entirely. Now I'm kinda freaked out. Is this true? This isn't true, and I don't know why people think it's a risk. Google has a ton of smart engineers: do you think they'd have a popular product like Google Analytics (which I run on this site) be something that could be exploited by hackers? I sure don't. But to clarify, I asked my friend Bennett Haselton to share his thoughts on this matter. Bennett writes for the programmer/geek site Slashdot, among others, and has a good handle on how people who break into sites exploit weaknesses. Here's what he said: Your friend, or his web team, is in the twilight zone or something. It's not even theoretically possible for Google Analytics to provide a "doorway" to hackers. When you add Google Analytics code to your website, your webserver just sees that as normal "content" -- just a sequence of bytes, like an image or a video file or a text file -- and when the user requests it, the webserver sends it to them, just as the webserver sends other content like images and videos. Thus it's not possible for adding Google Analytics to enable anyone to "hack" your site, because from the point of view of the webserver, it's just normal content that it sends to the user. What follows is how I would summarize it for a non-techie audience, although only a non-techie can tell if the explanation is any good :) What happens when someone goes to your website, if you have a Google Analytics tag on your page:
The only time installing third-party programs onto your website could expose your website to security attacks, would be in the case of programs like WordPress, because WordPress consists of code (instructions) that is actually run *by the webserver*. If the authors of WordPress have programmed it carefully, the code won't do anything harmful, but sometimes attackers will find ways to exploit it and cause it to do harmful things. In that case you always have to make sure you have the latest WordPress fixes installed. The distinction between *code* and *content* can help simplify things without having to spend years learning about computer security. It's what makes it intuitive to see why installing Google Analytics (or an image or a video file) cannot enable anyone to "break into" your website, but installing WordPress could (sometimes) enable a break-in.
Categorized:
CGI Scripts and Web Site Programming
(Article 9408,
Written by Dave Taylor)
Tagged: google analytics, hackers, hacking, site security Previous: Can I write blog entries in Movable Type on my iPad? Next: How do I pair my Apple wireless bluetooth keyboard with my iPad? Subscribe!
i also want to learn hacking Posted by: sandeep at May 8, 2010 10:44 AMGoogle analytics is a very useful, powerful and popular tool and I don't think hackers can leak into this system. So, I agree with Dave Taylor :) Posted by: Adam at May 9, 2010 10:00 AMHow about the free proxy? Thanks, I personally think Google Analytics is a joke. I use Statcounter instead to get a better picture of my Website statistics. Google uses their algorithms to parse visits and massively truncates the data. If you want up to the second data that is actually usable, go to Statcounter.com Ps. I love Dave Taylor and would love to meet up for some Starbucks sometime. Posted by: Kelly at May 10, 2010 1:01 PMI have something to say, now that you mention it, but ...
I do have a comment, now that you mention it!
|
Recommended
Recent Entries
Search
I Need Help!
Apple iPad Help
Articles and Reviews Auctions and Online Shopping Blogs and RSS Feeds Building Web Site Traffic Business and Management CGI Scripts and Web Site Programming Computer and Internet Basics d) None of the Above Facebook Help Google Plus Help HTML and CSS Industry News and Trade Shows iPhone and Cell Phone Help iPod, Sony PSP and MP3 Player Help Mac OS X Help Pay Per Click (PPC) Advertising Search Engine Optimization (SEO) Shell Script Programming Tech Support Video Help The Writing Business Twitter, LinkedIn and Social Network Help Unix and Linux Help Video Game Tips and Help Windows PC Help WordPress Help |