Live data from Hacker News

NSA uses Google cookies to pinpoint targets for hacking

washingtonpost.com

51–60 of 178 posts

Re: NSA uses Google cookies to pinpoint targets for hacking

#51
post #47

Earlier quoted context omitted.

Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…

This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block

So this is awesome, Ghostery has been a unsettling compromise for years now. I'm very happy to learn that you guys are doing it right. Thank you!

I've never been able to detect any nefarious network traffic caused by Ghostery (and I've looked), but I don't like the games they play, so I'll be pleased to ditch them without ceremony.

Re: NSA uses Google cookies to pinpoint targets for hacking

#52
post #43
post #42

Earlier quoted context omitted.

Search was easy to replace. Bing and DuckDuckGo are both good. Firefox was an easy switch now that Chrome seems to be much more of a resource hog (and the extensions are better). I don't have an Android phone. For e-mail I've switched to Fastmail but Outlook is also a good alternative if you want something free. I don't use anything else. I'd say e-mail was the hardest friction point of them all, but overall it was p…

Switching to Microsoft from Google is not an ethical accomplishment.

Despite the fact that I'm not the kind of person who "hates" Microsoft, you've got a point there: they were implicated in the NSA docs as much as Google was. In fact it sounded like they cooperated more than Google. Stick to smaller independent companies that have a good privacy track record.

Re: NSA uses Google cookies to pinpoint targets for hacking

#53
post #50
post #45

Earlier quoted context omitted.

I would replace Ghostery in your list with Disconnect. I would also add the 'Self-destructing Cookies' browser plugin. In its settings, whitelist a very limited set of sites you want to allow persistent (or session) cookies.

I don't know about either... https://github.com/gorhill/httpswitchboard/wiki/How-does-HTT...

I work on Disconnect and don't quite understand what your page is getting at (you probably ought to be disclosing that this is your page and project, btw). If you consider the Guardian page, for instance, all the domains you've listed as third parties except Google and Twitter actually look to be first parties serving content for the page. In other words: If you go to the Guardian, you're going to be tracked by the Guardian. If you'd like, you can also prevent their pages from working properly by blocking some secondary domains they use.

Re: NSA uses Google cookies to pinpoint targets for hacking

#54
post #2

Interesting choice of cookie: http://blogs.wsj.com/digits/2012/02/28/the-google-cookie-tha... https://bugzilla.mozilla.org/show_bug.cgi?id=368255

Gotta love the arrogance of "This is intend behavior of the feature. WONTFIX for me.", without the ability to explain why this cookie would be required for the feature to function.

Re: NSA uses Google cookies to pinpoint targets for hacking

#55
post #53
post #50

Earlier quoted context omitted.

I don't know about either... https://github.com/gorhill/httpswitchboard/wiki/How-does-HTT...

I work on Disconnect and don't quite understand what your page is getting at (you probably ought to be disclosing that this is your page and project, btw). If you consider the Guardian page, for instance, all the domains you've listed as third parties except Google and Twitter actually look to be first parties serving content for the page. In other words: If you go to the Guardian, you're going to be tracked by the G…

> "look to be first parties serving content for the page"

"look to be"? How would javascript code know that?

I measured something, and that is the result of my measurement. People can make an informed decision with proper information. I found that the page served well without all the extra requests that Ghostery and Disconnect allowed.

Given the results, I am quite surprise you would say "look to be first parties serving content for the page".

> "If you go to the Guardian, you're going to be tracked by the Guardian"

* facebook-web-clients.appspot.com * guardian-notifications.appspot.com * related-info-hrd.appspot.com * static-serve.appspot.com * cdnjs.cloudflare.com * ajax.googleapis.com * discussion.guardianapis.com * s.ophan.co.uk

Aside `discussion.guardianapis.com`, others are clearly 3rd-parties.

It's seems my definition of "3rd party" aligns more with that of the EFF: https://www.eff.org/deeplinks/2013/06/third-party-resources-...

Now you focused on the Guardian, how about the two other cases I measured?

I'm sure you don't like the result, but this is what came out when I decided to audit. Your response: You don't think it is a problem. That is settled.

Re: NSA uses Google cookies to pinpoint targets for hacking

#56
post #11

What a coincidence... I was just a few seconds ago, before taking a break to read HackerNews, investigating an issue with a Chromium blocker ( https://github.com/gorhill/httpswitchboard/issues/79# ), and was puzzled finding that the `pref` cookie of `.google.ca` changed every single time the tab of the page lost focus. Even went to Google privacy page to understand what this cookie did, with nothing in their statemen…

Google analytics tracks your time on page, and is probably storing values to do with that when you lose focus on the page - this is used in analytics for showing site owners engagement etc. Re the pref cookie, it could well be to track your interaction with searches, as they do for site analytics, if it changes when you leave a page, that's the most likely explanation.

Re: NSA uses Google cookies to pinpoint targets for hacking

#57
post #7

There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…

Can't we simply block all requests to Google Analytics so that the GA javascript is never loaded?

Sure, just black hole www.google-analytics.com and ssl.google-analytics.com in your hosts file.

Re: NSA uses Google cookies to pinpoint targets for hacking

#58
post #2

Interesting choice of cookie: http://blogs.wsj.com/digits/2012/02/28/the-google-cookie-tha... https://bugzilla.mozilla.org/show_bug.cgi?id=368255

Gotta love the arrogance of "This is intend behavior of the feature. WONTFIX for me.", without the ability to explain why this cookie would be required for the feature to function.

Also "...I am not worried that google is misusing this data...". This clearly isn't acceptable in a post-Snowden world.

Re: NSA uses Google cookies to pinpoint targets for hacking

#59
post #47

Earlier quoted context omitted.

Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…

This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block

Sadly, Disconnect detects less trackers than Ghostery (e.g. 5 vs 7 on washingtonpost.com).

I also like how Ghostery provides URLs for each tracker source (actual payload) that you can easily view on their site.

There's also a database with short description, affiliations and privacy terms for each tracker (e.g. https://www.ghostery.com/apps/google_analytics).

I really appreciate an ethical alternative to tainted Ghostery and hope you guys will catch up soon.

Re: NSA uses Google cookies to pinpoint targets for hacking

#60
post #24
post #7

There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…

Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…

I also recommend installing them and running the extra mile by changing your default search engine to DuckDuckGo (HTML SSL) without javascript (use NoScript). They temporarily track you and HTML one gives you direct links as opposed to redirects.

You can even modify you Firefox by changing values in about:config

geo.enabled ---> false

keyword.URL ---> Your Search engine query url

browser.urlbar.trimURLs ---> false

noscript.ABE.wanipCheckURL ---> 0

network.http.sendReferheader ---> 0 network.http.sendSecureXSiteReferrer ---> false ^these ones break some site functionality that rely on it. It's rare at least.

Post reply on HN