Earlier quoted context omitted.
Sadly, Disconnect detects less trackers than Ghostery (e.g. 5 vs 7 on washingtonpost.com). I also like how Ghostery provides URLs for each tracker source (actual payload) that you can easily view on their site. There's also a database with short description, affiliations and privacy terms for each tracker (e.g. https://www.ghostery.com/apps/google_analytics ). I really appreciate an ethical alternative to tainted Gho…
Not true, Disconnect detects 13 trackers on http://www.washingtonpost.com/ . If you're running multiple filtering extensions all at the same time, install order matters as far as which extension sees which HTTP requests.
NSA uses Google cookies to pinpoint targets for hacking
111–120 of 178 posts
Re: NSA uses Google cookies to pinpoint targets for hacking
#112Earlier quoted context omitted.
I work on Disconnect and don't quite understand what your page is getting at (you probably ought to be disclosing that this is your page and project, btw). If you consider the Guardian page, for instance, all the domains you've listed as third parties except Google and Twitter actually look to be first parties serving content for the page. In other words: If you go to the Guardian, you're going to be tracked by the G…
To answer your reply to my reply: > Given the results, I am quite surprise you would say "look to be first parties serving content for the page". I believe every single domain name you listed (except the Google and Twitter domains, like I said) is a domain owned by or a CDN used by the Guardian or hosts an app run by the Guardian - prove me wrong: > facebook-web-clients.appspot.com > guardian-notifications.appspot.co…
Despite "Adobe tag" marked as blocked by Disconnect, these requests were not blocked:
http://p.typekit.net/p.gif?a=219379&f=175.10294.10295.10296....
http://www.adobetag.com/d1/condenast/live/Wired.js
This is the part that bothers me: fooling people into thinking they are shielded against this kind of thing. That is not ok. I accept bugs can happen, but so far your position has been to rationalize why these 3rd-party domains are not blocked.
Oh and in this particular case, Ghostery blocked everything it said it blocked.
Re: NSA uses Google cookies to pinpoint targets for hacking
#113Earlier quoted context omitted.
I get that you two are rivals, but he does have a point that you haven't addressed. Ghostery seems to be in the business of selling the data that I forget to tell them they may not collect. This is intrinsically a sneaky thing to do. Yes I know about and use the "default to blocking" setting, but I don't think there is much argument that Ghostery users download your software with the expectation that the default woul…
You have to opt-in to 'Ghostrank' which is the data that they sell. I don't really see what's sneaky about this. Hell,if you click the ' see more... ' toggle on the prefs page it tells you what Ghostrank does. >Online marketing companies need better visibility into real-world applications of their technologies and those owned by their competitors. GhostRank data is sold as reports to businesses to help them market to…
> So you offer a very useful product, for free, and make money off of the people who fail to configure it so that it performs the only service they would ever purposely download it for.
I gave some numbers above that show, in practice, just how many users are in one of these unexpected configurations:
> Ghostery's game seems to be tricking users into sending their data to Evidon. Going off the company's own numbers, something like 45% of Ghostery users send Evidon data (by comparison, only 2% of Firefox users share data through Telemetry).
Re: NSA uses Google cookies to pinpoint targets for hacking
#114Can someone answer this question: From a business perspective why is Google and Facebook getting involved in this and calling for the government to not track users. Won't that just bring more attention to their two business models of... wait for it... tracking users and selling their information?
Previously, when the customers didn't care, they did nothing to involve themselves with this, and almost certainly aided the government.
It's purely business. Google and Facebook don't have morals, they have a bottom line. You can understand their actions by following the money.
Re: NSA uses Google cookies to pinpoint targets for hacking
#115Earlier quoted context omitted.
Google is already killing referrer on search results (by redirecting), to force people to pay for Analytics
I'd pay for an intermediate level of GA in a heartbeat. Right now, once you hit 10M pageviews a month you either have to sample or pay $150k/year for Premium. I don't need support, an account manager, four-hour turnaround on data, an SLA, etc. I just need more pageviews sometimes.
Re: NSA uses Google cookies to pinpoint targets for hacking
#116Earlier quoted context omitted.
Why do we still have referrers? They don't allow us to do anything that we wouldn't be able to do without them. If Mozilla and Google made a statement today saying, "We'll be removing referrers from cross site requests in 6 months time for Chrome and Firefox.", the tiny tiny proportion of sites that are using them for real functionality will have plenty of time to update. Of course, as a web developer, it's useful to…
For lots of us using basic CDN services, we enable referrer checks to ensure that folks aren't hotlinking images or direct linking downloads from other sites. These CDNs allow basic blocking based on referrers. You usually set it to only permit when there is a referrer from your own domain as well as blank referrers (if the CDN supports it) since most privacy conscious folks will disable referrer rather than fake it.…
The problem is, all of these "features" allowed by referrers are user-hostile actions.
If referrers went away tomorrow, users wouldn't notice the difference or care. Publishers would get angry and think "we can't milk our content/visitors for as much money anymore!" But that doesn't really change the relationship with the customers who value your product or business so I personally can't believe it will make a sizable difference in the end.
Re: NSA uses Google cookies to pinpoint targets for hacking
#117Earlier quoted context omitted.
Not true, Disconnect detects 13 trackers on http://www.washingtonpost.com/ . If you're running multiple filtering extensions all at the same time, install order matters as far as which extension sees which HTTP requests.
oh, interesting - can you explain the details? is it simple or random? if i install disconnect and then ghostery wil ghostery help with anything disconnect misses or is it more complicated than that? thanks!
* Chrome, Safari, and Opera give precedence to the newest extension - if that extension blocks a request, older extensions don't see the request.
* Firefox gives precedence to the oldest add-on.
Re: NSA uses Google cookies to pinpoint targets for hacking
#118Earlier quoted context omitted.
Not true, Disconnect detects 13 trackers on http://www.washingtonpost.com/ . If you're running multiple filtering extensions all at the same time, install order matters as far as which extension sees which HTTP requests.
ABP has several privacy lists that is managed publicly so I don't see the need for these untrusted and unproven extensions.
* Disconnect has more than a million active users and Ghostery has more than two million.
* Disconnect is also as public as ABP: https://github.com/disconnectme/disconnect.
Re: NSA uses Google cookies to pinpoint targets for hacking
#119Earlier quoted context omitted.
You have to opt-in to 'Ghostrank' which is the data that they sell. I don't really see what's sneaky about this. Hell,if you click the ' see more... ' toggle on the prefs page it tells you what Ghostrank does. >Online marketing companies need better visibility into real-world applications of their technologies and those owned by their competitors. GhostRank data is sold as reports to businesses to help them market to…
quesera described what's sneaky about Ghostery - their users think they're protected but aren't and don't know they're sending data to Evidon that the company sells but are: > So you offer a very useful product, for free, and make money off of the people who fail to configure it so that it performs the only service they would ever purposely download it for. I gave some numbers above that show, in practice, just how m…
Re: NSA uses Google cookies to pinpoint targets for hacking
#120Earlier quoted context omitted.
Oh, hai Brian! Aren't you a former doubleclick-turn-righteous? And don't you also employ an ex-NSA dude? And no, we do not sell user data, just tracker data. Cheers!
I get that you two are rivals, but he does have a point that you haven't addressed. Ghostery seems to be in the business of selling the data that I forget to tell them they may not collect. This is intrinsically a sneaky thing to do. Yes I know about and use the "default to blocking" setting, but I don't think there is much argument that Ghostery users download your software with the expectation that the default woul…
This is somewhat wrong: Ghostery, ever since version 1, had Ghostrank feature in it. It has always been an opt-in deal, the users who trust us may turn it on so provide us with data. For the first 4 years the data sat without any use until recently where Evidon figured out how to turn it into money. Even so, the data Evidon sells has nothing about any user, merely tracker data. Here are some samples of whats actually delivered to clients: http://www.knowyourelements.com/ and http://www.evidon.com/evidon-trackermap/tagchains-static.htm....
As I said, we do not trick the users into anything, and are as transparent about where the data goes as possible, if you have suggestions how to increase this then please let us know. We currently cover this question in every listing Ghostery has, all options pages, web site, FAQ, and many posts on our blog.
As far as defaults: originally, Ghostery was a detection software designed to "reveal the invisible web", but has added blocking since. Our official stance is that we do not make decisions for the user, but we do run every user through an install wizard that explains whats up. Disconnects stance here is a different, they do offer default blocking, tho they also have their own "whiteliest" built into it without telling the users about it. We are going to add some easy configuration in the near future that will pre-block stuff, but this is still in the works.
Finally, Ghostery source is available for review for "sneakiness" since every extension is pure javascript. We host it here if you're interested: https://www.ghostery.com/ghosteries/chrome/ and you can just unzip any other extension to extract source.