Live data from Hacker News

Going dark: online privacy and anonymity for normal people

troyhunt.com

51–60 of 125 posts

Re: Going dark: online privacy and anonymity for normal people

#52

I'm surprised he doesn't mention NoScript, Privacy Badger, etc. "Normal people" should be more concerned about about the highly detailed profiles that companies are building based on browsing habits. "Normal people" read about data breaches and embarrassing leaks that force politicians to resign. "Normal people" know nothing about the behind the scenes tracking that goes on when you google medical symptoms[0] or visi…

[deleted]

Re: Going dark: online privacy and anonymity for normal people

#53

I'm surprised he doesn't mention NoScript, Privacy Badger, etc. "Normal people" should be more concerned about about the highly detailed profiles that companies are building based on browsing habits. "Normal people" read about data breaches and embarrassing leaks that force politicians to resign. "Normal people" know nothing about the behind the scenes tracking that goes on when you google medical symptoms[0] or visi…

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

I wonder if there's any demand for a pre-built whitelist for NoScript that includes stuff like Amazon, Google, Apple, banks, and most other popular sites. The admin would err on the side of allowing scripts to run, while the default-block rule would still block unknown and ad/tracker domains. It would obviously be less secure than an intelligent user making all their own decisions, but it would make the barrier to using NoScript much lower.

Edit: While I'm musing on this, I wonder if NoScript could use a UI overhaul. A little icon that says "Something broken? Try activating these domains" with some heuristics e.g. first try allowing the current domain, then stuff on common CDNs, then maybe digging into DNS records or SSL certs for common ownership...

Re: Going dark: online privacy and anonymity for normal people

#55

I'm surprised he doesn't mention NoScript, Privacy Badger, etc. "Normal people" should be more concerned about about the highly detailed profiles that companies are building based on browsing habits. "Normal people" read about data breaches and embarrassing leaks that force politicians to resign. "Normal people" know nothing about the behind the scenes tracking that goes on when you google medical symptoms[0] or visi…

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

I do similar talks for regular users* and I try to explain how to prioritize risks, and why they might not be focused on what's really important. Purchasing an anti-virus suite and identity theft protection and worrying about online banking are way overrated.

Strong consumer protections exist in many developed nations which limit your liability, it is the banks who stand to lose. No doubt it can be a hassle if your credit card number is stolen, But that card is the bank's property. You just report any fraudulent transactions and get a new card if necessary. The more important thing to protect is your private data, you can't get that privacy back.

Also, NoScript is awesome and I highly recommend people try it. It can be fiddly to get working at first but a surprisingly high percentage of websites work better without having to white-list anything. It also helps with privacy by blocking trackers like Google Analytics, especialy on sites like Troy's which lack a privacy policy and do not provide any warning at all about third-party trackers to site visitors. Pretty new site redesign, same lack of transparency as before.

* By 'regular users' I mean when I say "Try an ad-blocking extension with your browser, add it from the menu" and they say "What is the menu?" and we build their knowledge up from there... . It can be frustrating for all but I highly recommend it as it keeps you grounded and provides balance for the HN bubble I sometimes find myself in.

Re: Going dark: online privacy and anonymity for normal people

#56

I'm surprised he doesn't mention NoScript, Privacy Badger, etc. "Normal people" should be more concerned about about the highly detailed profiles that companies are building based on browsing habits. "Normal people" read about data breaches and embarrassing leaks that force politicians to resign. "Normal people" know nothing about the behind the scenes tracking that goes on when you google medical symptoms[0] or visi…

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

Until my aging mother can use NoScript and still understand why many websites just don't seem to work, it isn't covering the majority use cases.

Re: Going dark: online privacy and anonymity for normal people

#58

Earlier quoted context omitted.

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

I do similar talks for regular users* and I try to explain how to prioritize risks, and why they might not be focused on what's really important. Purchasing an anti-virus suite and identity theft protection and worrying about online banking are way overrated. Strong consumer protections exist in many developed nations which limit your liability, it is the banks who stand to lose. No doubt it can be a hassle if your c…

I've been installing NoScript, and instructing how to use it, on "regular" users' browsers for years. The sad inevitability is I end up instructing most of them on how to enable "Allow scripts globally(Dangerous)" option to help quell the flood of phone calls concerning their "broken internets". Many just can't be bothered &/or don't care enough to learn. Free will can be such a bitch, sometimes.

Re: Going dark: online privacy and anonymity for normal people

#59
post #12
post #11

Earlier quoted context omitted.

What you call "fraud" I call "privacy". Anonymous transactions happen all the time with cash, and any new payment method needs an equivalent. In the modern era where it is no longer possible to gain privacy by being unobservable, a new definition of privacy is required. Dan Geer has a very good replacement definition; privacy is "the effective capacity to misrepresent yourself"[1]. If cash isn't possible, misrepresen…

What you call privacy might be called fraud in some countries. That's what my question is about.

I concur & I tread lightly in my guerilla tactics. My bank, my insurance company my Dept Of Motor Vehicles & the other "legit" govs that require my info get it(and I use offline services as exclusively as/while I am still able). For every other "reg required" service, discount card "brick & mortar" or any other entity that requires a unique account, they get all the mis-info I can feed them. In the end, they get their unique identity to track and disseminate, it's just a falsey.

*Granted, it is an easily unravelled ball of lottery hotlines & public spaces addresses that could easily be traced back to the real "me", but I'm not really hiding, just preserving my right to be left alone from prying marketeers and... ahem.... data scientists.

Re: Going dark: online privacy and anonymity for normal people

#60
post #56

Earlier quoted context omitted.

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

Until my aging mother can use NoScript and still understand why many websites just don't seem to work, it isn't covering the majority use cases.

True and this is also what I always mention, Noscript is really an advanced topic and everytime I've tried to make friends use it they've eventually given up.

But people who come to these lectures or cryptoparties usually have a desire to do something about their personal IT-security so hopefully they can find the motivation.

Post reply on HN