The Value of Activity Recording

The Value of Activity Recording

Jun 27, 2023

Online tricks and deceptions can be anywhere, even on the most trusted websites and from the most trusted service providers. Successful cases filed by the U.S. Consumer Financial Protection Bureau (CFPB), a branch of the Federal Trade Commission, establish this clearly. In one case, PayPal was found by the CFPB to be misleading customers by not disclosing the extent to which it monitored and reviewed transactions as well as regarding the authority it assumed to cancel transactions and even restrict the user’s access to funds in the user’s account. To correct this, the CFPB’s 2018 order requires that PayPal:

… when making any representation through any Payment and Social Networking Service, expressly or by implication, about the availability of funds to be transferred or withdrawn to a bank account (1) must disclose, clearly and conspicuously, and in close proximity to such representation (a) that the transaction is subject to review and (b) the fact, if true, that funds could be frozen or removed as a result of transaction reviews performed during the bank transfer or withdrawal process, and (2) the representation must not be otherwise misleading.

The order also required PayPal to:

… conspicuously disclose to each User, through the Payment and Social Networking Service, and separate and apart from any “privacy policy,” “terms of use,” “blog,” “helpful information” page, or similar document: (1) how the User’s transaction information will be shared with other Users; and (2) how the User can use privacy settings to limit or restrict the visibility or sharing of the User’s transaction information on the Payment and Social Networking Service. For Users that have already created an account when this disclosure is first issued, this disclosure must occur at or immediately prior to the time that the User next engages in a transaction through the Payment and Social Networking Service. For Users that have not created an account when this disclosure is first issued, this disclosure must occur at the time the User opens an account.

The lack of disclosures from PayPal during the user’s activities on PayPal’s internet service and on it’s mobile application makes it difficult for the user to prove that anything unusual or not in compliance with their user agreement(s) happened. This CFPB order in fact states that inclusion of the subject notice in the published user agreement(s) is not sufficient when the user’s access to their funds can be interfered with by the financial services provider, or when the user’s transaction information can be shared with other users.

How do you prove something did not happen during your interaction with a web service or application on the Internet? The means by which user’s generally find out about such concealed activities or service provider powers is when their consequences respecting use of the Internet service become apparent by other means, such as an email notifying them of cancellations, charges, or restrictions that they were not aware of, or when the application’s usual features become unavailable. When their transaction information is shared with other users, there is no notice generally, so the user never finds out about the violation.

To show that something relevant or essential did not happen, a recording of the entire interaction is required. Evidence necessary to show what a user does and what the application does in response requires a print out, download, or screen-shot of every page or screen or dialog in which the user interacts with the application. In addition, an activity log which is secure and stored on the user’s computer or cell phone and to which secure application software provides access for user review would be a good idea. This logging feature of course requires features to export selected entries to reports in the form of PDF documents and searchable databases. Modern web browsers do not provide these capabilities. Generally, Internet application user activity logging is currently only done at the service provider’s end.


Another case in which the value of recording by the user of their interaction with an Internet application is obvious is the Federal lawsuit by the CFPB against ACTIVE Network, LLC, which like PayPal is a payment processor. According to CFPB:

ACTIVE provides enrollment and payment processing services to organizers of charity races, youth camps, and other events. The Bureau alleges that ACTIVE engaged in deceptive and abusive acts and practices in violation of the Consumer Financial Protection Act of 2010 (CFPA) by enrolling consumers in and charging them for discount club memberships without their knowledge, consent, or a full understanding of the material terms of the transaction. ACTIVE does this by inserting a webpage into the online event registration and payment process that provides an offer for a free trial enrollment in a discount club membership called “Active Advantage.” Many consumers click on the highlighted call to action button—which is typically labeled “Accept”—because they believe that by doing so, they are accepting charges to participate in an event. Instead, consumers are enrolling in a trial membership in Active Advantage, which automatically converts to a paid subscription with an annual fee, unless consumers opt out by canceling their membership within 30 days.

It would be easy to prove the deceptive design of the Internet application if the user merely had screenshots of all of the pages that they interacted with the application on where they entered any information, clicked any button, or otherwise used any interactive control that the application provided. To catch ANY deceptive design requires recording ALL interaction with the application. Just having HTML to PDF page print outs stored of each page in the sequence constituting the subject interaction would reinforce the “power point presentation” that the screen shot sequence provides. Add to this a secure, activity logging database at the user end and you have detailed irrefutable proof, lacking hacking either by the user or some “outside” party.

For another example, in 2015, CFPB took action against PayPal for covertly signing users up for credit and then using that credit for purchases that the user had chosen another form of payment for. According to CFPB’s online press release, “... PayPal deceptively advertised promotional benefits that it failed to honor, signed consumers up for credit without their permission, made them use PayPal Credit instead of their preferred payment method, and then mishandled billing disputes.” (https://www.consumerfinance.gov/about-us/newsroom/cfpb-takes-action-against-paypal-for-illegally-signing-up-consumers-for-unwanted-online-credit/) PayPal also ignored disputes when customers complained about this activity. The credit service, first offered in 2008, was known as PayPal credit and as Bill Me Later and was offered at eBay, the online retail giant and owner of PayPal since 2003. (https://www.salehoo.com/blog/ebay-breaks-it-off-with-paypal)


Clear evidence that the deception was a deliberate design by PayPal’s is that, according to CFPB:

… PayPal offered consumers limited-time, deferred-interest promotions, and that PayPal purported to let consumers pick how payments would be applied to these promotional balances. But consumers who attempted to contact the company to get more information or request to apply their payments to promotional balances often could not get through to the company’s customer service line or were given inaccurate information. Many such consumers were hit with deferred-interest fees that, due to the company’s conduct, they could not avoid.


Customers found out about PayPal’s action enrolling them for its credit service only later, for instance when they received the welcome email, or if they missed these, debt collection calls for amounts past due.

Again, It would be easy to prove the deceptive design of PayPal’s Internet application if the user had screenshots and PDF prints of all of the pages that they interacted with when they were unknowingly signed up for the PayPal “Bill Me Later” credit. According to the CFPB complaint, no notice was provided when the customer was enrolled, so it would be necessary to record, using browser file save features and separate screen-shot applications, all purchases the user made using PayPal. This would be tedious if one had to do it by hand. I know because I have done it. Therefore, web browser features which did this type of recording automatically at the user end would be a valuable addition to web browser technology. I do not know of any web browsers that have any automatic activity recording feature that is made available to the user, although based on their required opt-out messages, they do by default record and transmit user activities to the web browser provider for, according to them, product improvement.

Evidence Locker Product Design

One solution to this would be to launch a thread from a separate application that is capable of monitoring a web browser application’s activities, identifying ones of interest to the user, and then taking screen-shots and performing logging when particular browser activity events or event types are detected. By then configuring a common browser screen-shot save folder, particular types of events could be configured to trigger automatic recording of the user’s activity in the form of a chronologically sorted set of screen shots and local database table logged browser events. Controlling the browser’s page save and print to PDF file features would require not just activity monitoring, but the ability to issue commands to the browser form the separate activity recording application.

To provide this feature to users by implementing a background thread that monitors their browser's activities and performs one or more of the record functions, along with logging to a database table, would require the browser developers to provide some standard interface to a 'socket' or plug-in to a callback or messaging feature that delivers identifiable browser state changes and events which occur in or take the user to pages that need to be recorded. Since recording via screen-shots of particular activity at particular locations on web pages requires the browser to deliver content identifying information and GUI component and event identifiers, this would be a serious compromise of the security of existing browsers, so this type of feature would need to be seriously crippled if it were implemented in any form at all.

Implementing a secure recording feature in a custom browser provided with a package of security tools is a much simpler matter, and one which preserves the security strategy and privacy of implementation details of the standard web browser. The Qt GUI framework includes a component called QWebEngine which includes the needed browser view independently with the standard browser capabilities. The application programming interface of QWebEngine and its components provides the access to the browser’s internal operation needed to add customization features needed to implement activity logging of any kind, including screen-shots, HTML page saves and PDF prints. The features one can implement using it will make the configurable security features automatic, and the user will be able to review, search, filter, and export the log or logs produced to HTML and / or PDF reports. The automatic logging will be configurable to record on various events, such as all page loads or all actions of the user of particular kinds. Logs can be coordinated with screenshots and page saves, meaning the same monitoring configuration can be used to trigger any or all activity recording, and different configurations can be used to trigger different recording behaviors.

For interactive control of activity recording, a screenshot button can be present when the user activates a recording dashboard pop-up dialog which also includes page save buttons, with the file naming and storage location(s) configured by installation default or by the user while using the pop-up itself. The best current screen shot programs and page saver and exporter features of browsers require you to expressly save the file and to select a storage location each time the tool is used, although some provide the convenience feature of automatically going to the same folder as on the previous save / print. This can not be improved while maintaining the current security capabilities of modern web browsers, so a separate custom browser is needed in the Evidence Locker tool sets, and one is currently in the works.

Building the time-line presenting the evidence requires another tool, which I am also currently writing. Here are links to my YouTube videos showing some of the capabilities I have developed so far:

https://youtu.be/zpXjmchFgQo

and

https://youtu.be/--ydwEbtFc8

The next video shows use of the Linux locate command configuration dialog to run the locate command and use its output for creating a time-line, or evidence file collection by selecting files which were found by locate. When the locate output is viewed, it is show as a folder tree without files that you can select a branch of to display in a tabbed view. The files in the tabbed view are in chronological order according to the last-modified time-stamp of the file. This video then shows how to create a time-line collection using the tabbed view and add a file to it.

https://youtu.be/A0Y6fWXG5mw

This application is not only useful for searching and organizing files into collections centering around particular areas of interest, but also provides a way of saving collections into index pages and documents which contain the information entered for each individual file along with a link to view the file. This video demonstrates how to do this with the application and shows the product, a file index with links in both HTML and PDF formats.

https://youtu.be/rfu0IgIuUa4

Ti piace questo post?

Offri un caffè a Keith Watson

Altro da Keith Watson