Live data from Hacker News

Show HN: Your Social Media Fingerprint (maybe NSFW)

robinlinus.github.io

221–230 of 258 posts

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#221
post #123

FYI, it's very NSFW in the back-end. Your browser is sending requests to obvious porn servers when you hit this link so it can test if you're logged in to them.

Yeah, that would've been nice to know ahead of time. Why not, for example, trigger the test when someone clicks a button, rather than taking someone's page visit as permission to try lighting up their organization's content filter?

What a surprising problem. If the boss mistakenly accuses you of watching porn - why not explain why they're wrong and show them the site? If they won't accept that, then it means you're in danger with any web surfing you do at work and should already not be clicking random links. It's not the site's fault, it's your company's fault and your own for not protecting yourself against breaking their rules.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#223

In Chrome: Settings > Privacy > Content Settings > Tick 'Block third-party cookies and site data' Also set 'Send a "Do Not Track" request with your browsing traffic' And install uBlock Origin, ofc.

I suppose the "block third-party cookies and site data" must be why this is mostly broken at home (doesn't show logins to 5-6 sites that I'm logged in to), but works properly at work (didn't bother to set that option there). Never toyed with exactly what the "site data" part means, though.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#224
post #221

Earlier quoted context omitted.

Yeah, that would've been nice to know ahead of time. Why not, for example, trigger the test when someone clicks a button, rather than taking someone's page visit as permission to try lighting up their organization's content filter?

What a surprising problem. If the boss mistakenly accuses you of watching porn - why not explain why they're wrong and show them the site? If they won't accept that, then it means you're in danger with any web surfing you do at work and should already not be clicking random links. It's not the site's fault, it's your company's fault and your own for not protecting yourself against breaking their rules.

Personally, the idea that there's a network my traffic flows over, where that traffic is sniffed such that its content could potentially result in things like me losing my job, is just debilitating to me.

If I worked for such a company, all my traffic would be flowing over a VPN, full-stop.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#225
post #190

Earlier quoted context omitted.

What about virtualization? It seems to me that something like Qubes might not at present protect against this (I don't know what information is available to guest/isolated domains on that system), but could be made to? One can easily lie to a browser about battery status and fonts from the OS too, for example. I guess my point is that it depends on what you view as pathological? I surmise that this is the kind of thi…

It's very difficult to prevent side channel thumbprints—something as simple as traceroutes, wifi hotspots, caches (DNS, routing) can be uniquely identifiable. Add on top of this biometrics like how you type, how you move your mouse, etc, and it becomes very difficult to avoid concerted tracking efforts. Of course, if you're not pissing off state actors, you're probably fine with qubes/tails.

Presuming you are being pursued by a state actor, isn't using a computer at a library or Internet cafe enough to thwart most of that? Especially if you're using asynchronous store-and-forward protocols like NNTP or Freenet, where you can be long-gone from wherever the computer you used was, before anyone else ever sees "your" activity.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#226
post #190

Earlier quoted context omitted.

It's very difficult to prevent side channel thumbprints—something as simple as traceroutes, wifi hotspots, caches (DNS, routing) can be uniquely identifiable. Add on top of this biometrics like how you type, how you move your mouse, etc, and it becomes very difficult to avoid concerted tracking efforts. Of course, if you're not pissing off state actors, you're probably fine with qubes/tails.

if you're not pissing off state actors, you're probably fine Thank you, this seems to be a point that is often ignored. Most of us don't need to hide our trail from a full wing of CIA analysts, just drive-by snooping and the like. (It of course doesn't help the Snowdens of the world)

I usually prefer to think of the middle case: someone with a grudge against me, who would love to blackmail me if they could get the dirt, and who has money to hire some blackhats and buy some zero-days and set up spear-phishing—but who doesn't actually have any access to the things that states get by default by sending fancy letters with Important Signatures.

It's interesting to work through the case of an absurdly rich private actor, because it works out differently for diferent companies; for some, they can just get a "man on the inside" to leak out your data easily enough, while for others (e.g. Gmail) the employees themselves aren't trusted to access user data, and have been firewalled/ACLed away from it to prevent just such intrusions. State actors get pretty much the same "help" from every service (save for the rare Lavabits of the world) but corporate actors get a rather unpredictable response landscape.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#230
post #224
post #221

Earlier quoted context omitted.

What a surprising problem. If the boss mistakenly accuses you of watching porn - why not explain why they're wrong and show them the site? If they won't accept that, then it means you're in danger with any web surfing you do at work and should already not be clicking random links. It's not the site's fault, it's your company's fault and your own for not protecting yourself against breaking their rules.

Personally, the idea that there's a network my traffic flows over, where that traffic is sniffed such that its content could potentially result in things like me losing my job, is just debilitating to me. If I worked for such a company, all my traffic would be flowing over a VPN, full-stop.

> If I worked for such a company, all my traffic would be flowing over a VPN, full-stop.

When you work for such a company, all VPNs are blocked and prohibited, full-stop.

Source: worked for such a company

Post reply on HN