Live data from Hacker News

NSA uses Google cookies to pinpoint targets for hacking

washingtonpost.com

161–170 of 178 posts

Re: NSA uses Google cookies to pinpoint targets for hacking

#161

Earlier quoted context omitted.

Quesera, this is a good point I didn't cover. Ghostery does not call itself a tracker-blocker, our users do. This is an obvious oversight for most users, and its somethign that we will address, but at this time, Ghostery is designed to reveal the invisible web and give user the control over it, not make decisions for the users... As far as the feature, at the implementation time, we've queried a set of users that agr…

> Ghostery does not call itself a tracker-blocker, our users do. Sorry, I cannot accept that answer. From your home page, in big letters, right now: https://www.ghostery.com/ > Knowledge + Control = Privacy > > See which companies are tracking you > Block over 1 6 0 0 trackers > Learn how they track > Ghostery is FREE What do you call yourself then? Please be honest with us. How do you view your operation internally?…

As I said, we are adjusting to fit what our users think rather than what we preached. The site is 2 month old, and it reflects the new updated stance, and as I said earlier, the extensions will also be updated with pre-configured settings.

I'm not sure what you mean by that question? Ghostery is a separate team inside Evidon with full control over what we do. I'm one of the people managing the product and my customers are users of Ghostery. As such, my primary goal isn't improved blocking, its education - to let users know that they are being tracked, to provide relevant info on who are the trackers and where to find out more about them, and finally, provide control in the form of blocking.

Re: NSA uses Google cookies to pinpoint targets for hacking

#163

Earlier quoted context omitted.

> Ghostery does not call itself a tracker-blocker, our users do. Sorry, I cannot accept that answer. From your home page, in big letters, right now: https://www.ghostery.com/ > Knowledge + Control = Privacy > > See which companies are tracking you > Block over 1 6 0 0 trackers > Learn how they track > Ghostery is FREE What do you call yourself then? Please be honest with us. How do you view your operation internally?…

As I said, we are adjusting to fit what our users think rather than what we preached. The site is 2 month old, and it reflects the new updated stance, and as I said earlier, the extensions will also be updated with pre-configured settings. I'm not sure what you mean by that question? Ghostery is a separate team inside Evidon with full control over what we do. I'm one of the people managing the product and my customer…

I appreciate you taking the time to reply in these threads.

I won't needle you with follow-up questions, but for the record, I think there's more than a little cognitive dissonance here regarding customers and conflicting goals.

This is why people who spend time thinking seriously about the issue are concerned about Ghostery, but I accept that "trust" doesn't pay the bills.

Re: NSA uses Google cookies to pinpoint targets for hacking

#164
post #107
post #93

Earlier quoted context omitted.

I didn't downvote him, but I can understand why others might. His comment seems willfully ignorant of the problem, which is that Ghostery calls itself a tracker-blocker, but squirrels that obviously-desirable config option away under "advanced" settings. If Ghostery was on our side, really and truly, that would be the default. Indeed, it probably wouldn't even be an option. Of course when the tracker list is updated,…

> His comment seems willfully ignorant of the problem, which is that Ghostery calls itself a tracker-blocker, but squirrels that obviously-desirable config option away under "advanced" settings. Err, the option under Advanced just lets you set it to auto-block new elements as they're added. When you first install Ghostery, the walk through lets you pick that option as well without having to be "advanced" (oo, scare q…

"advanced" here is a string literal, not an adjective, so it belongs in quotes.

Re: NSA uses Google cookies to pinpoint targets for hacking

#165

Earlier quoted context omitted.

There is a trivial solution to this. Introduce a new HTTP response header 6 months before phasing out the Referer header. This header would be optionally delivered with content and would specify which third party domains are allowed to access the content. Perhaps Content-Security-Policy could be extended for this purpose.

Sure. And have it on by default with a correct content security policy. If it were off by default, it wouldn't be used by most folks and the bandwidth thieves would be content hotlinking images and direct linking binaries, just ignoring the small percentage of users who turned it on. Of course, even if this was released today and referrers were phased out in June 2014. We'd still be able to use them for at least 5 ye…

If they released support for this header with Firefox and Chrome, almost immediately, people wouldn't bother hotlinking to sites which utilise it because a good proportion of their users wouldn't be able to see the content at all.

Re: NSA uses Google cookies to pinpoint targets for hacking

#166

Earlier quoted context omitted.

As I said, we are adjusting to fit what our users think rather than what we preached. The site is 2 month old, and it reflects the new updated stance, and as I said earlier, the extensions will also be updated with pre-configured settings. I'm not sure what you mean by that question? Ghostery is a separate team inside Evidon with full control over what we do. I'm one of the people managing the product and my customer…

I appreciate you taking the time to reply in these threads. I won't needle you with follow-up questions, but for the record, I think there's more than a little cognitive dissonance here regarding customers and conflicting goals. This is why people who spend time thinking seriously about the issue are concerned about Ghostery, but I accept that "trust" doesn't pay the bills.

Thanks for asking relevant questions and I agree about the dissonance. Our teams job is to make sure they are minimized and we're working on fixing those things. Something to keep in mind tho is that our team is very small (4 people), so it takes time to get stuff done.

Re: NSA uses Google cookies to pinpoint targets for hacking

#167
post #70
post #51

Earlier quoted context omitted.

So this is awesome, Ghostery has been a unsettling compromise for years now. I'm very happy to learn that you guys are doing it right. Thank you! I've never been able to detect any nefarious network traffic caused by Ghostery (and I've looked), but I don't like the games they play, so I'll be pleased to ditch them without ceremony.

Ghostery's game seems to be tricking users into sending their data to Evidon. Going off the company's own numbers, something like 45% of Ghostery users send Evidon data (by comparison, only 2% of Firefox users share data through Telemetry).

Ghostery's default setting is to disable submitting data. You have to explicity opt-in. How is that tricking?

I was interested in your project but your smearing of 'competitors' with FUD is seriously disconcerting.

Re: NSA uses Google cookies to pinpoint targets for hacking

#168
post #70

Earlier quoted context omitted.

Ghostery's game seems to be tricking users into sending their data to Evidon. Going off the company's own numbers, something like 45% of Ghostery users send Evidon data (by comparison, only 2% of Firefox users share data through Telemetry).

Ghostery's default setting is to disable submitting data. You have to explicity opt-in. How is that tricking? I was interested in your project but your smearing of 'competitors' with FUD is seriously disconcerting.

Congrats on your first post! [1]

1. http://www.catb.org/jargon/html/A/astroturfing.html

Re: NSA uses Google cookies to pinpoint targets for hacking

#169

A perfect reason to NOT let Google own all layers of the stack between you and the internet (or indeed the real world). Search - Check (goog.com) Mail - Check (Gmail) Browser - Check (chrome) Devices - Check (Android/Chrome books) Websites - Check (Double click/AdMob, Unknown number of other companies) Google Analytics - Check Your DNA - Check (23&Me) Cars - Check (self-driving cars) I am probably missing large chunk…

I am probably missing large chunks of tracking even with this list.

Enormous amounts of things have some connection into Google. Other connections into Google's equipment potentially include Voice, Talk, Hangouts, embedded Google Plus +1 buttons, embedded YouTube, Blogspot sites, embedded Picasa images.

Google runs ReCAPTCHA. ( http://www.google.com/recaptcha/ )

If you email someone with a GMail account your email address is in Google's servers with the email header containing your IP address.

Google's SafeBrowsing URL check built into FireFox which normally works by hashed URLs but could still track that you are using it, but has a simple version of the API so applications could send plain text URLs to it without you knowing ( https://developers.google.com/safe-browsing/ ).

Sites hosted on Google AppEngine ( https://developers.google.com/appengine/ ).

If you have IOS, Safari defaults to Google suggestions - i.e. sending everything you type in the address/search bar to Google.

Google Maps, built into other websites and services. Google Geolocation API built into other software ( https://developers.google.com/maps/documentation/business/ge... ).

Google DNS (last time I read the privacy policy, it said queries are not combined with other data Google collects).

Sites loading popular JavaScript from Google's hosted libraries ( https://developers.google.com/speed/libraries/devguide ).

Sites embedding Google Sparklines ( https://developers.google.com/chart/interactive/docs/gallery... )

Links going via Google's URL shortening service Goo.gl

Not counting things you choose to use (Chromecast, music, docs, drive, Now, voice search, News, Groups, Finance, Toolbar, Android sat nav, Chrome's open tab sync between your devices via Google Cloud, etc.).

That's not to say they are good or bad, or they are or are not tracked. Just that it's way to late to "avoid Google" just by switching away from GMail and blocking Google Analytics.

http://en.wikipedia.org/wiki/List_of_Google_products

Re: NSA uses Google cookies to pinpoint targets for hacking

#170

Earlier quoted context omitted.

Why do we still have referrers? They don't allow us to do anything that we wouldn't be able to do without them. If Mozilla and Google made a statement today saying, "We'll be removing referrers from cross site requests in 6 months time for Chrome and Firefox.", the tiny tiny proportion of sites that are using them for real functionality will have plenty of time to update. Of course, as a web developer, it's useful to…

For lots of us using basic CDN services, we enable referrer checks to ensure that folks aren't hotlinking images or direct linking downloads from other sites. These CDNs allow basic blocking based on referrers. You usually set it to only permit when there is a referrer from your own domain as well as blank referrers (if the CDN supports it) since most privacy conscious folks will disable referrer rather than fake it.…

> For lots of us using basic CDN services, we enable referrer checks to ensure that folks aren't hotlinking images or direct linking downloads from other sites.

This is actually an interesting problem, because it's already solved but most people aren't using the solution: If you have a large file do distribute to a large number of people without authentication, use BitTorrent. As far as I can see there are two primary impediments to this:

A) Most browsers can't by default download large files P2P. You can actually write a BitTorrent client in javascript using Web Sockets if you really want to, but that's just horrible. What would be really nice is to be able to just e.g. embed a video into a webpage using a magnet link. There is no technical reason why this couldn't be implemented and rightly should be for large files.

B) Images are exactly the wrong size. They're big enough that you can't just ignore hotlinking but not big enough that you want to pay the overhead of connecting to 50 different peers instead of one to get a good transfer rate. But that just requires some adjustments to the protocol; if you're looking for realtime retrieval for display in a webpage you would probably want to use UDP and then use erasure coding to deal with slow/broken peers and packet loss. If you have a 60KB image, you can send a ~50 byte packet to each of a dozen peers and have ten of them each send 6KB (approximately four packets) to the target with 6KB worth of erasure bits from each of the others (which also allows the image to be constructed once 60KB of data is received in total from any collection of peers), and now the image is costing you ~600 bytes instead of 60KB. And if the image hasn't been received in 150ms, add more peers.

Post reply on HN