Live data from Hacker News

NSA uses Google cookies to pinpoint targets for hacking

washingtonpost.com

61–70 of 178 posts

Re: NSA uses Google cookies to pinpoint targets for hacking

#61
post #59
post #47

Earlier quoted context omitted.

This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block

Sadly, Disconnect detects less trackers than Ghostery (e.g. 5 vs 7 on washingtonpost.com). I also like how Ghostery provides URLs for each tracker source (actual payload) that you can easily view on their site. There's also a database with short description, affiliations and privacy terms for each tracker (e.g. https://www.ghostery.com/apps/google_analytics ). I really appreciate an ethical alternative to tainted Gho…

Not true, Disconnect detects 13 trackers on http://www.washingtonpost.com/. If you're running multiple filtering extensions all at the same time, install order matters as far as which extension sees which HTTP requests.

Re: NSA uses Google cookies to pinpoint targets for hacking

#62

In my opinion, browsers should block all third party website content by default. Yeah, I know, the interwebs will break if they actually did this. Well perhaps someone should come up with some kind of website quality rating which indicates that a site can be viewed withing worrying about the prying eyes of FaceBook, Google, Twitter, LinkedIn, etc.

this would just lead to sites using subdomains pointed to the ip addresses of those.

Re: NSA uses Google cookies to pinpoint targets for hacking

#63
post #53
post #50

Earlier quoted context omitted.

I don't know about either... https://github.com/gorhill/httpswitchboard/wiki/How-does-HTT...

I work on Disconnect and don't quite understand what your page is getting at (you probably ought to be disclosing that this is your page and project, btw). If you consider the Guardian page, for instance, all the domains you've listed as third parties except Google and Twitter actually look to be first parties serving content for the page. In other words: If you go to the Guardian, you're going to be tracked by the G…

To answer your reply to my reply:

> Given the results, I am quite surprise you would say "look to be first parties serving content for the page".

I believe every single domain name you listed (except the Google and Twitter domains, like I said) is a domain owned by or a CDN used by the Guardian or hosts an app run by the Guardian - prove me wrong:

> facebook-web-clients.appspot.com

> guardian-notifications.appspot.com

> related-info-hrd.appspot.com

> static-serve.appspot.com

> cdnjs.cloudflare.com

> discussion.guardianapis.com

> s.ophan.co.uk

Re: NSA uses Google cookies to pinpoint targets for hacking

#65
So not only are businesses like cloud services, video games and messaging/devices affected by anti-business NSA trust breaches. But now we have the advertising industry that is going to be affected by the anti-privacy and anti-business practices of over the top spying on individuals. If any private company was doing this there would be legal issues.

Re: NSA uses Google cookies to pinpoint targets for hacking

#67

Earlier quoted context omitted.

Can't we simply block all requests to Google Analytics so that the GA javascript is never loaded?

Sure, just black hole www.google-analytics.com and ssl.google-analytics.com in your hosts file.

I've done this for a year or so now.. it works fine.

Add this line to your hosts file:

  0.0.0.0 google-analytics.com ssl.google-analytics.com www.google-analytics.com

Re: NSA uses Google cookies to pinpoint targets for hacking

#68
Let's be charitable to the NSA for a minute, and imagine that they are following the plot of the God Emperor of Dune[1], where in seeing the danger posed to the Internet by the formation of cloud service giants, they became the fearsome yet benevolent tyrant, strategically planning an engineered leak, so that on their death the Internet would react by distributing its services among many providers in The Scattering, thus ensuring the safety and continued survival of the Internet.

[1] https://en.wikipedia.org/wiki/God_Emperor_of_Dune

Re: NSA uses Google cookies to pinpoint targets for hacking

#69
Relevant:

http://betanews.com/2013/12/09/tech-giants-surveillance-refo...

As long as these companies build the best tracking engines the world has ever seen, that can identify anyone and everything they're doing, it's just a matter of time before governments get their hands on that data, legally or illegally. It's just too tempting to pass.

If I were Google I'd start thinking long and hard about how to solve this problem, and try to make money by actually being on the user's side when it comes to privacy, not against them. Google will ultimately fail if their goals aren't aligned with those of the users anymore.

Re: NSA uses Google cookies to pinpoint targets for hacking

#70
post #51
post #47

Earlier quoted context omitted.

This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block

So this is awesome, Ghostery has been a unsettling compromise for years now. I'm very happy to learn that you guys are doing it right. Thank you! I've never been able to detect any nefarious network traffic caused by Ghostery (and I've looked), but I don't like the games they play, so I'll be pleased to ditch them without ceremony.

Ghostery's game seems to be tricking users into sending their data to Evidon. Going off the company's own numbers, something like 45% of Ghostery users send Evidon data (by comparison, only 2% of Firefox users share data through Telemetry).
Post reply on HN