Details
-
Type:
Bug
-
Status: Resolved
-
Priority:
Major
-
Resolution: Fixed
-
Affects Version/s: 3.9.0, 3.10.0, 3.11.0
-
Fix Version/s: 3.12.0
-
Component/s: core.users, tools
-
Labels:None
Description
Google Analytics tracking should be turned off by default in open source distribution of Hue.
Currently, even if collect_usage is commented out in the hue.ini (as shipped), the default for collect_usage is set to true. A user/administrator who may not be aware of this default, or who doesn't even have this config var in their hue.ini, may be sending analytics data to Google without knowing it.
While only anonymous tracking data may be collected from the Hue source, the referrer URL is collected by Google and this can represent a significant security hole for some organizations. The referrer URL, especially in the case of the File Browser, can contain the HDFS path, which may contain proprietary information. Users or administrators of Hue may not be aware that Google is receiving the referrer URL, and as such may not be aware that tracking from the File Browser in particular is sending HDFS paths to Google.