From a business perspective why is Google and Facebook getting involved in this and calling for the government to not track users. Won't that just bring more attention to their two business models of... wait for it... tracking users and selling their information?
NSA uses Google cookies to pinpoint targets for hacking
71–80 of 178 posts
Re: NSA uses Google cookies to pinpoint targets for hacking
#72Browser string, viewed content, frequency and magnitude of access, user authentication cookies, and ad-tracking cookies all would be tremendously helpful for this purpose.
Also, I'm betting they can easily tell when specific computers on a network are powered on or not based on fixed-interval network traffic from anything that polls regularly, such as anti-virus, news readers, mail clients and background updater services.
All of the above could aid in painting a more complete per-user picture behind the NAT, without actually having to compromise the local network or individual computers in question.
Re: NSA uses Google cookies to pinpoint targets for hacking
#73There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…
Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…
Re: NSA uses Google cookies to pinpoint targets for hacking
#74This news makes me happy to see there's a point to me having Google Analytics blocked the last two years. I've noticed a new thing, Google tag manager, lately. Any point in whitelisting this? Anyone know what it does?
Re: NSA uses Google cookies to pinpoint targets for hacking
#75Earlier quoted context omitted.
Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…
Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…
Ghostery does what the user tells it to do. If you are seeing unblocked trackers, most likely, its because we've added new trackers and you didn't select "block" by default for the new trackers when the list gets updated. You can change this preference by going into Ghostery options, Advanced, and review the "auto-update" section.
And heres a full explanation as to what Evidon gets and what it does with it: http://purplebox.ghostery.com/?p=1016023438
Re: NSA uses Google cookies to pinpoint targets for hacking
#76Earlier quoted context omitted.
Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…
This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block
Aren't you a former doubleclick-turn-righteous? And don't you also employ an ex-NSA dude?
And no, we do not sell user data, just tracker data.
Cheers!
Re: NSA uses Google cookies to pinpoint targets for hacking
#77I see a lot of you are using Ghostery, which I've never even downloaded because they get paid to whitelist and are run by ad executives. Is there a reason why I would want Ghostery in addition to Noscript, or is all of the (privacy-protecting) functionality redundant? This news makes me happy to see there's a point to me having Google Analytics blocked the last two years. I've noticed a new thing, Google tag manager,…
As to your question: NoScript does a different thing -- it concentrates on limiting known security issues by disabling Javscript. Tracking is accomplished in a variety of ways, and only some of them are Javascript based. Ghostery looks for all of these and lets users know who is tracking them on any given web page.
Re: NSA uses Google cookies to pinpoint targets for hacking
#78There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…
Can't we simply block all requests to Google Analytics so that the GA javascript is never loaded?
Re: NSA uses Google cookies to pinpoint targets for hacking
#79Earlier quoted context omitted.
Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…
This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block
* I can't seem to see a list of all Google trackers. Some sites have multiple Google trackers, but if I click on the icon to see them it just turns off blocking for them. I'm assuming sites don't have 6 GA trackers, what are the others?
* I can't seem to turn off Content trackers for all sites. Configuring this site-by-site seems clumsy, to say the least.
Re: NSA uses Google cookies to pinpoint targets for hacking
#80Earlier quoted context omitted.
Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…
This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block
That seems to go against the OS nature of the project.