NSA uses Google cookies to pinpoint targets for hacking
151–160 of 178 posts
Re: NSA uses Google cookies to pinpoint targets for hacking
#152A perfect reason to NOT let Google own all layers of the stack between you and the internet (or indeed the real world). Search - Check (goog.com) Mail - Check (Gmail) Browser - Check (chrome) Devices - Check (Android/Chrome books) Websites - Check (Double click/AdMob, Unknown number of other companies) Google Analytics - Check Your DNA - Check (23&Me) Cars - Check (self-driving cars) I am probably missing large chunk…
This is all assuming you consider your adversary to be the NSA. If it's google, well, choose other vendors. If it's both, you'll have to consider both your destination and wire-protocol axes.
FWIW, if your traffic is split evenly between 3-4 main vendors (e.g., google, amazon, bing, etc), and all HTTPS, it's hard to tell what you're doing.
Re: NSA uses Google cookies to pinpoint targets for hacking
#153Earlier quoted context omitted.
It's only hostile to sites that try and steal bandwidth resources by hotlinking/leeching images or direct linking downloads. It's not about milking visitors. It's about preventing unethical behavior by other sites. I've spent 10s of thousands of dollars hosting free and open source software for millions of people over the years and I make sure to prevent bandwidth theft from other sites that cut into my ability to pr…
So it sounds like there's already a solution to your problem that doesn't require leaking privacy all over the internet, since presumably the one-time links are on request from a page on your website, and tells you nothing but someone on your website wanted something from your website. How is this a bad thing? How would removing referrals harm you in any way?
For images, the whole point of a CDN is to keep them in one place with a long expiry (a week or more) possibly downloaded from a nice geographically close edge node so that visitors load the images very quickly once and then cache them for the next pages and later visits of the site. The only current way CDNs implement of keeping folks from leeching/hotlinking images is to check referrals. The unique download link bit would negate the whole benefit of the CDN (you'd lose caching and the back and forth to generate the unique URL would slow it down), so that's out. Basically, lots of folks would ditch CDNs and host internally, possibly using server log checking to see if said IP recently hit a page. Otherwise they have to deal with lots of bandwidth leeches. The end result would be slowing down visitors' experience.
So, for both images and downloads, users wind up losing if referrals go away. It's far better to just leave it as is. Enable referrals by default. Let the privacy conscious disable them (sending blank ones). And build systems to take into account both userbases. Again, as a software developer, publisher, and host, I don't really care about referrals in terms of violating privacy, so I don't care if you disable them and send blank ones. I purposely set up my redirects and CDNs to allow for that. I care about them in terms of continuing to deliver services effectively to my users without competitors stealing my resources.
Re: NSA uses Google cookies to pinpoint targets for hacking
#154Earlier quoted context omitted.
So it sounds like there's already a solution to your problem that doesn't require leaking privacy all over the internet, since presumably the one-time links are on request from a page on your website, and tells you nothing but someone on your website wanted something from your website. How is this a bad thing? How would removing referrals harm you in any way?
What if the page containing a one-time link was cached, but the resource itself was not? The "secure link" solution doesn't seem to work in all cases.
Re: NSA uses Google cookies to pinpoint targets for hacking
#155Earlier quoted context omitted.
For lots of us using basic CDN services, we enable referrer checks to ensure that folks aren't hotlinking images or direct linking downloads from other sites. These CDNs allow basic blocking based on referrers. You usually set it to only permit when there is a referrer from your own domain as well as blank referrers (if the CDN supports it) since most privacy conscious folks will disable referrer rather than fake it.…
There is a trivial solution to this. Introduce a new HTTP response header 6 months before phasing out the Referer header. This header would be optionally delivered with content and would specify which third party domains are allowed to access the content. Perhaps Content-Security-Policy could be extended for this purpose.
Of course, even if this was released today and referrers were phased out in June 2014. We'd still be able to use them for at least 5 years until you could safely assume that they were gone. Likely longer.
Re: NSA uses Google cookies to pinpoint targets for hacking
#156There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…
It does everything I want it to do (so far), but I'm not an analytics power user by any means.
[1] - http://piwik.org/
Re: NSA uses Google cookies to pinpoint targets for hacking
#157Earlier quoted context omitted.
[Replying to aroch, who's too nested.] > And how exactly is it trickery if users have to opt-in to the program and they're told what the program does? Ghostery seems to rely on vague messaging (last I looked, they don't actually say anywhere in their extension that they sell the data you share to ad co's and data brokers) and UX "optimization" (what quesera dubbed the "reconfigure-on-update dance", for example) to ge…
In the second paragraph (though really, its just a statement...) on the preferences page -- no need to navigate to another page, and they tell it to you in plain english. Once again, you have to opt-in, so if you opt-in without knowing what it does it's your own fault and you're being a dumb user: When you enable GhostRank, Ghostery collects anonymous data about the trackers you've encountered and the sites on which…
I'd argue that Ghostery should come with a default configuration of ALL trackers and cookies blocked. I'd argue even more strenuously that after the user configures Ghostery manually to do so, ALL should continue to mean ALL even after updates. Ghostery currently has 700 3P cookies in their database, and almost 1700 trackers. There is no valid argument, imho, that a user who configures to block ALL really means "block ALL right now, but if you see any new ones, I would really like to try them out first!"
However, I mostly agree that Evidon has been up front and straightforward about what they do and how they do it. I want to like Ghostery. I do like Ghostery. This little bit of sneakiness though, honestly, taints the whole operation. You can call it an oversight, and I will agree that it can't possibly have much marginal value to Evidon...but it's somewhere between tone-deafness and carelessness, two qualities that call for heightened vigilance.
Re: NSA uses Google cookies to pinpoint targets for hacking
#158Earlier quoted context omitted.
I didn't downvote him, but I can understand why others might. His comment seems willfully ignorant of the problem, which is that Ghostery calls itself a tracker-blocker, but squirrels that obviously-desirable config option away under "advanced" settings. If Ghostery was on our side, really and truly, that would be the default. Indeed, it probably wouldn't even be an option. Of course when the tracker list is updated,…
Quesera, this is a good point I didn't cover. Ghostery does not call itself a tracker-blocker, our users do. This is an obvious oversight for most users, and its somethign that we will address, but at this time, Ghostery is designed to reveal the invisible web and give user the control over it, not make decisions for the users... As far as the feature, at the implementation time, we've queried a set of users that agr…
Sorry, I cannot accept that answer.
From your home page, in big letters, right now:
> Knowledge + Control = Privacy
>
> See which companies are tracking you
> Block over 1 6 0 0 trackers
> Learn how they track
> Ghostery is FREE
What do you call yourself then?Please be honest with us. How do you view your operation internally? What services do you provide, and to whom?
Thank you.
Re: NSA uses Google cookies to pinpoint targets for hacking
#159Earlier quoted context omitted.
folks please don't downvote people when they're giving useful info. there is a button in the advanced section that makes blocking work by default on new data. that's useful to know - i've just enabled it, and you should too. just because you don't like someone (likely based on one comment on a web site...) doesn't mean that they should be downvoted...
I didn't downvote him, but I can understand why others might. His comment seems willfully ignorant of the problem, which is that Ghostery calls itself a tracker-blocker, but squirrels that obviously-desirable config option away under "advanced" settings. If Ghostery was on our side, really and truly, that would be the default. Indeed, it probably wouldn't even be an option. Of course when the tracker list is updated,…
Re: NSA uses Google cookies to pinpoint targets for hacking
#160Earlier quoted context omitted.
In the second paragraph (though really, its just a statement...) on the preferences page -- no need to navigate to another page, and they tell it to you in plain english. Once again, you have to opt-in, so if you opt-in without knowing what it does it's your own fault and you're being a dumb user: When you enable GhostRank, Ghostery collects anonymous data about the trackers you've encountered and the sites on which…
Actually, I'd completely forgotten about GhostRank, the opt-in data collection service. The sneaky part I was referring to was just the default setting to add new trackers but not block them. I don't think any users have the expectation that updates will work that way. I'd argue that Ghostery should come with a default configuration of ALL trackers and cookies blocked. I'd argue even more strenuously that after the u…
If you feel strongly that your opinion is important and should be prioritized, please create relevant topic here: https://getsatisfaction.com/ghostery/ and gather support to change it so we address it quicker.