U
U
Uncle Seryozha2017-06-14 17:42:16
Information Security
Uncle Seryozha, 2017-06-14 17:42:16

What are the risks of implementing Yandex Metrica on the company's internal website?

And do not ask how such an idea could come)
The first thing that comes to mind

  1. Yandex will be able to see the software used and other browser settings
  2. Yandex will be able to see internal domains, pages, IP, MAC
  3. There were vulnerabilities in Yandex Metrica
  4. Opening an https port for an internal site

Answer the question

In order to leave comments, you need to log in

3 answer(s)
C
cssman, 2017-06-14
@Protos

Yandex will be able to access the data entered on the internal site. What? Yes, almost everyone.
As a rule, parameters and sets are selected that will go into the metric. Discussed when implementing the metric. More details after-before implementation can be found in the scripts that will be loaded on the page. But there is always a chance that they will update and drag something else. For example, a full log of keystrokes in a personal account or in a form with a secret, etc.
There are always risks, the question is, does Yandex need you?
And the second question, why the hell is Yandex metric if there are free standalone solutions? For example piwik

S
sim3x, 2017-06-14
@sim3x

The main problem is that in a situation where the intranet is working and the Internet is disabled, your resource will load for 5 minutes due to the fact that the metric will not be available
From a security point of view, you are building a "trojan" into the very pulp, your dmz

S
Sergey Ryzhkin, 2017-06-14
@Franciz

Doesn't the site have to be visible from the outside in order to install Yametrica? Then it will no longer be an internal site if you open access to it from an external site for Yandex. And therefore all the same risks as for ordinary sites.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question