Live data from Hacker News

NSA uses Google cookies to pinpoint targets for hacking

washingtonpost.com

41–50 of 178 posts

Re: NSA uses Google cookies to pinpoint targets for hacking

#41
post #24
post #7

There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…

Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…

Greetings. I nearly have the same policy, regarding surfing and my addons.

I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers.

And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl...

I would recommend the FF-addon Diconnect: https://addons.mozilla.org/en-US/firefox/addon/disconnect/

Does anybody have an idea, how I could make my own sites secure in a relatively cheap way? Just a personal site with not that much traffic, so spending much money seems a bit off to me.

Ideas?

Re: NSA uses Google cookies to pinpoint targets for hacking

#42

A perfect reason to NOT let Google own all layers of the stack between you and the internet (or indeed the real world). Search - Check (goog.com) Mail - Check (Gmail) Browser - Check (chrome) Devices - Check (Android/Chrome books) Websites - Check (Double click/AdMob, Unknown number of other companies) Google Analytics - Check Your DNA - Check (23&Me) Cars - Check (self-driving cars) I am probably missing large chunk…

Search was easy to replace. Bing and DuckDuckGo are both good. Firefox was an easy switch now that Chrome seems to be much more of a resource hog (and the extensions are better). I don't have an Android phone. For e-mail I've switched to Fastmail but Outlook is also a good alternative if you want something free. I don't use anything else. I'd say e-mail was the hardest friction point of them all, but overall it was pretty easy to leave Google.

Re: NSA uses Google cookies to pinpoint targets for hacking

#43
post #42

A perfect reason to NOT let Google own all layers of the stack between you and the internet (or indeed the real world). Search - Check (goog.com) Mail - Check (Gmail) Browser - Check (chrome) Devices - Check (Android/Chrome books) Websites - Check (Double click/AdMob, Unknown number of other companies) Google Analytics - Check Your DNA - Check (23&Me) Cars - Check (self-driving cars) I am probably missing large chunk…

Search was easy to replace. Bing and DuckDuckGo are both good. Firefox was an easy switch now that Chrome seems to be much more of a resource hog (and the extensions are better). I don't have an Android phone. For e-mail I've switched to Fastmail but Outlook is also a good alternative if you want something free. I don't use anything else. I'd say e-mail was the hardest friction point of them all, but overall it was p…

Switching to Microsoft from Google is not an ethical accomplishment.

Re: NSA uses Google cookies to pinpoint targets for hacking

#44
post #24

Earlier quoted context omitted.

Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…

Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…

Yes, Ghostery's origin story and reconfigure-on-update dance is bothersome. Thanks for the pointer to Disconnect, I will check it out.

Regarding your sites' security, what sort of advice are you looking for? OS-level hardening? Service config?

Re: NSA uses Google cookies to pinpoint targets for hacking

#45
post #24
post #7

There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…

Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…

I would replace Ghostery in your list with Disconnect. I would also add the 'Self-destructing Cookies' browser plugin. In its settings, whitelist a very limited set of sites you want to allow persistent (or session) cookies.

Re: NSA uses Google cookies to pinpoint targets for hacking

#46
post #27
post #23

Earlier quoted context omitted.

Here's my ideal security policy: - Cross-site requests not allowed without whitelisting. This means some setup will be required at first (for example, for separate image domains used by Amazon, Google, Yahoo, etc.), but after a bit it shouldn't be a problem. This also serves as a "better adblock" in some ways, as it blocks ad networks without relying on a database that needs to be updated. - All cookies blocked by de…

Safari is effectively ungovernable, and Chrome is part of the problem. Firefox is the answer. No other option makes any sense, if you're serious about this stuff. I understand that some people like the UI or process model of other browsers better, and that's where the evaluation of priorities comes in. The good news is that the days of Chrome's technical superiority are truly over.. Speed, memory consumption, renderi…

>but be sure not to dismiss Firefox based on historical issues.

It's incredible how much inertia there is with that. The majority of the people I know that switched to chrome did it back when firefox was blatantly slower and that's the image that's stuck in their head. It's incredibly hard to remove and to get someone to try it long enough to change their mind again.

Firefox has a tough issue with marketing right now. They need to start a nice "firefox is faster" campaign.

Re: NSA uses Google cookies to pinpoint targets for hacking

#47
post #24

Earlier quoted context omitted.

Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…

Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…

This.

I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine:

* Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team

* They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block

Re: NSA uses Google cookies to pinpoint targets for hacking

#49
post #45
post #24

Earlier quoted context omitted.

Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…

I would replace Ghostery in your list with Disconnect. I would also add the 'Self-destructing Cookies' browser plugin. In its settings, whitelist a very limited set of sites you want to allow persistent (or session) cookies.

[deleted]

Re: NSA uses Google cookies to pinpoint targets for hacking

#50
post #45
post #24

Earlier quoted context omitted.

Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…

I would replace Ghostery in your list with Disconnect. I would also add the 'Self-destructing Cookies' browser plugin. In its settings, whitelist a very limited set of sites you want to allow persistent (or session) cookies.

I don't know about either...

https://github.com/gorhill/httpswitchboard/wiki/How-does-HTT...

Post reply on HN