Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter?

There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter?

Scheduled Pinned Locked Moved Uncategorized
18 Posts 16 Posters 53 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • secureowl@infosec.exchangeS secureowl@infosec.exchange

    There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter? The intention is you talk all about resolving DNS of the host, TCP things and HTTP etc.

    A more truthful answer would include:

    - Your email address is sent to launch darkly to get applicable feature flags.
    - A gigabyte of data is logged to DataDog
    - Details about the way you moved your mouse are sent to segment.io
    - A bunch of telemetry is sent to Sentry.
    - Ads are injected from Facebook.
    - Metrics are recorded to Hubspot.
    - Page renders in browser.

    alesandroortiz@infosec.exchangeA This user is from outside of this forum
    alesandroortiz@infosec.exchangeA This user is from outside of this forum
    alesandroortiz@infosec.exchange
    wrote last edited by
    #8

    @SecureOwl Followed by:
    - Malicious ad fingerprints your browser and runs a zero day exploit.
    - Your AWS, GitHub, and npm credentials are exfiltrated within seconds.
    - Within 5 hours you are triaging a widespread supply chain attack that started with you typing in a domain name and pressing enter.

    1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    • secureowl@infosec.exchangeS secureowl@infosec.exchange

      There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter? The intention is you talk all about resolving DNS of the host, TCP things and HTTP etc.

      A more truthful answer would include:

      - Your email address is sent to launch darkly to get applicable feature flags.
      - A gigabyte of data is logged to DataDog
      - Details about the way you moved your mouse are sent to segment.io
      - A bunch of telemetry is sent to Sentry.
      - Ads are injected from Facebook.
      - Metrics are recorded to Hubspot.
      - Page renders in browser.

      ann_effes@berlin.socialA This user is from outside of this forum
      ann_effes@berlin.socialA This user is from outside of this forum
      ann_effes@berlin.social
      wrote last edited by
      #9

      @SecureOwl

      Well ... I don't know if that is "more truthful"

      Yes, that's true for many websites - though in some cases only after the page has been rendered, not before - but it certainly doesn't apply to every domain name or website. Not by a long shot.

      I'm in favor of raising awareness among internet users, but I'm against going overboard and painting a bleak picture. That's more likely to lead to resignation than to a change in behavior in my opinion.

      1 Reply Last reply
      0
      • secureowl@infosec.exchangeS secureowl@infosec.exchange

        There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter? The intention is you talk all about resolving DNS of the host, TCP things and HTTP etc.

        A more truthful answer would include:

        - Your email address is sent to launch darkly to get applicable feature flags.
        - A gigabyte of data is logged to DataDog
        - Details about the way you moved your mouse are sent to segment.io
        - A bunch of telemetry is sent to Sentry.
        - Ads are injected from Facebook.
        - Metrics are recorded to Hubspot.
        - Page renders in browser.

        secureowl@infosec.exchangeS This user is from outside of this forum
        secureowl@infosec.exchangeS This user is from outside of this forum
        secureowl@infosec.exchange
        wrote last edited by
        #10

        I forgot to add that none of this can happen until Cloudflare gets to decide you are a worthy human for some reason

        _ad@hachyderm.io_ 1 Reply Last reply
        0
        • secureowl@infosec.exchangeS secureowl@infosec.exchange

          I forgot to add that none of this can happen until Cloudflare gets to decide you are a worthy human for some reason

          _ad@hachyderm.io_ This user is from outside of this forum
          _ad@hachyderm.io_ This user is from outside of this forum
          _ad@hachyderm.io
          wrote last edited by
          #11

          @SecureOwl that's after the TPM decides your hardware is still blessed and the HDMI equipment grants you permission to observe pixels displayed on the screen.

          1 Reply Last reply
          0
          • secureowl@infosec.exchangeS secureowl@infosec.exchange

            There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter? The intention is you talk all about resolving DNS of the host, TCP things and HTTP etc.

            A more truthful answer would include:

            - Your email address is sent to launch darkly to get applicable feature flags.
            - A gigabyte of data is logged to DataDog
            - Details about the way you moved your mouse are sent to segment.io
            - A bunch of telemetry is sent to Sentry.
            - Ads are injected from Facebook.
            - Metrics are recorded to Hubspot.
            - Page renders in browser.

            mjturner@indieweb.socialM This user is from outside of this forum
            mjturner@indieweb.socialM This user is from outside of this forum
            mjturner@indieweb.social
            wrote last edited by
            #12

            @SecureOwl You forgot "Cloudflare delays everything by a further 30s to make sure you're not a bot" (so that the site doesn't waste time tracking and pushing ads to non-humans!)

            1 Reply Last reply
            0
            • R relay@relay.mycrowd.ca shared this topic
            • ams@infosec.exchangeA ams@infosec.exchange

              @SecureOwl Don't forget the full google search on each partial domain, character-by-character as you type, with all the ad and promoted link bids that entails.

              jandi@mastodon.socialJ This user is from outside of this forum
              jandi@mastodon.socialJ This user is from outside of this forum
              jandi@mastodon.social
              wrote last edited by
              #13

              @AMS @SecureOwl Plus the predicted keypresses, and comparison with previous "keypress sessions"!

              1 Reply Last reply
              0
              • secureowl@infosec.exchangeS secureowl@infosec.exchange

                There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter? The intention is you talk all about resolving DNS of the host, TCP things and HTTP etc.

                A more truthful answer would include:

                - Your email address is sent to launch darkly to get applicable feature flags.
                - A gigabyte of data is logged to DataDog
                - Details about the way you moved your mouse are sent to segment.io
                - A bunch of telemetry is sent to Sentry.
                - Ads are injected from Facebook.
                - Metrics are recorded to Hubspot.
                - Page renders in browser.

                casar@mastodon.socialC This user is from outside of this forum
                casar@mastodon.socialC This user is from outside of this forum
                casar@mastodon.social
                wrote last edited by
                #14

                @SecureOwl Type in a domain name and press enter *into what*?

                1 Reply Last reply
                0
                • secureowl@infosec.exchangeS secureowl@infosec.exchange

                  There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter? The intention is you talk all about resolving DNS of the host, TCP things and HTTP etc.

                  A more truthful answer would include:

                  - Your email address is sent to launch darkly to get applicable feature flags.
                  - A gigabyte of data is logged to DataDog
                  - Details about the way you moved your mouse are sent to segment.io
                  - A bunch of telemetry is sent to Sentry.
                  - Ads are injected from Facebook.
                  - Metrics are recorded to Hubspot.
                  - Page renders in browser.

                  generalx@freeradical.zoneG This user is from outside of this forum
                  generalx@freeradical.zoneG This user is from outside of this forum
                  generalx@freeradical.zone
                  wrote last edited by
                  #15

                  @SecureOwl

                  "Yes, interviewer, when I press enter, uBlock Origin intercepts the request and gets to work filtering ad and tracking sites like google-analytics.com."

                  Interviewer: "Do you realize this is a Google interview?"

                  C 1 Reply Last reply
                  0
                  • secureowl@infosec.exchangeS secureowl@infosec.exchange

                    There is that famous technical interview question that goes: what happens behind the scenes when you type in a domain name and press enter? The intention is you talk all about resolving DNS of the host, TCP things and HTTP etc.

                    A more truthful answer would include:

                    - Your email address is sent to launch darkly to get applicable feature flags.
                    - A gigabyte of data is logged to DataDog
                    - Details about the way you moved your mouse are sent to segment.io
                    - A bunch of telemetry is sent to Sentry.
                    - Ads are injected from Facebook.
                    - Metrics are recorded to Hubspot.
                    - Page renders in browser.

                    dirk@gts.0x7be.netD This user is from outside of this forum
                    dirk@gts.0x7be.netD This user is from outside of this forum
                    dirk@gts.0x7be.net
                    wrote last edited by
                    #16

                    @SecureOwl Haha …

                    Page renders in browser.

                    As if! First a metric shit-ton of external JS libraries are pulled, then the needed CSS styles are compiled on-the-fly locally in the client, causing the client to stall all connections, then the page gives an “application error” because your client by default denies local storage and cookies.

                    1 Reply Last reply
                    0
                    • generalx@freeradical.zoneG generalx@freeradical.zone

                      @SecureOwl

                      "Yes, interviewer, when I press enter, uBlock Origin intercepts the request and gets to work filtering ad and tracking sites like google-analytics.com."

                      Interviewer: "Do you realize this is a Google interview?"

                      C This user is from outside of this forum
                      C This user is from outside of this forum
                      clickymcticker@hachyderm.io
                      wrote last edited by
                      #17

                      @generalx @SecureOwl Probably fine. They want you to drink their corporate kool aid, not the consumer kool aid they distribute widely.

                      generalx@freeradical.zoneG 1 Reply Last reply
                      0
                      • C clickymcticker@hachyderm.io

                        @generalx @SecureOwl Probably fine. They want you to drink their corporate kool aid, not the consumer kool aid they distribute widely.

                        generalx@freeradical.zoneG This user is from outside of this forum
                        generalx@freeradical.zoneG This user is from outside of this forum
                        generalx@freeradical.zone
                        wrote last edited by
                        #18

                        @ClickyMcTicker @SecureOwl

                        Wouldn't the corporate koolaid be the justification of Google Analytics and how my salary depends on it? To ignore the internet hype around tracking and privacy? To become an analytics evangelist and see tracking as a powerful utility unlocking shareholder value?

                        1 Reply Last reply
                        0
                        • pixelate@tweesecake.socialP pixelate@tweesecake.social shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups