Live data from Hacker News

NSA uses Google cookies to pinpoint targets for hacking

washingtonpost.com

171–178 of 178 posts

Re: NSA uses Google cookies to pinpoint targets for hacking

#172

Earlier quoted context omitted.

For lots of us using basic CDN services, we enable referrer checks to ensure that folks aren't hotlinking images or direct linking downloads from other sites. These CDNs allow basic blocking based on referrers. You usually set it to only permit when there is a referrer from your own domain as well as blank referrers (if the CDN supports it) since most privacy conscious folks will disable referrer rather than fake it.…

> For lots of us using basic CDN services, we enable referrer checks to ensure that folks aren't hotlinking images or direct linking downloads from other sites. This is actually an interesting problem, because it's already solved but most people aren't using the solution: If you have a large file do distribute to a large number of people without authentication, use BitTorrent. As far as I can see there are two primar…

Our software is used from portable devices (usually usb) as users move between computers (PortableApps.com). As such, using bittorrent would be a technical option within our platform's app store/updater. It would, however, get our platform banned/blocked at many companies and universities that have policies forbidding bittorrent use. (And we can say all day long that it's a legit protocol with lots of legit uses like downloading linux ISOs, it doesn't change the facts and policies on the ground.) Additionally, most users will be behind NATs that they can't poke a hole through to be able to properly share.

As for images, the bittorrent protocol would just be way too slow even with some changes when compared to HTTP with SPDY and all the internal tweaks done at the geographically close CDN edge nodes to make them as fast as possible. 150ms before adding a new peer is an eternity in an age when 47% of people expect a web page to load in 2 seconds or less and the abandon rate increases with each second that passes with 40% abandoning at a little after the 3 second mark.

Re: NSA uses Google cookies to pinpoint targets for hacking

#173

Earlier quoted context omitted.

> For lots of us using basic CDN services, we enable referrer checks to ensure that folks aren't hotlinking images or direct linking downloads from other sites. This is actually an interesting problem, because it's already solved but most people aren't using the solution: If you have a large file do distribute to a large number of people without authentication, use BitTorrent. As far as I can see there are two primar…

Our software is used from portable devices (usually usb) as users move between computers (PortableApps.com). As such, using bittorrent would be a technical option within our platform's app store/updater. It would, however, get our platform banned/blocked at many companies and universities that have policies forbidding bittorrent use. (And we can say all day long that it's a legit protocol with lots of legit uses like…

Couldn't you use an inexpensive CDN like Cloudflare? Your origin would see transfer to Cloudflare, but they'd be able to offload the majority of your download traffic. You also wouldn't be charged per GB as happens with Cloudfront.

Re: NSA uses Google cookies to pinpoint targets for hacking

#174

Earlier quoted context omitted.

I'd pay for an intermediate level of GA in a heartbeat. Right now, once you hit 10M pageviews a month you either have to sample or pay $150k/year for Premium. I don't need support, an account manager, four-hour turnaround on data, an SLA, etc. I just need more pageviews sometimes.

Hate to burst your bubble, but even the premium GA uses samples. They don't give you a firehose of real data.

Some of the reports, yes, but not overall pageviews. Per their capabilities page:

> 1 billion hits per month

> Up to 3 million rows of data in unsampled reports

If you're doing conversion tracking etc. you're going to start getting sampled data at some point, but it's the pageviews our folks care for.

Re: NSA uses Google cookies to pinpoint targets for hacking

#175

Earlier quoted context omitted.

Our software is used from portable devices (usually usb) as users move between computers (PortableApps.com). As such, using bittorrent would be a technical option within our platform's app store/updater. It would, however, get our platform banned/blocked at many companies and universities that have policies forbidding bittorrent use. (And we can say all day long that it's a legit protocol with lots of legit uses like…

Couldn't you use an inexpensive CDN like Cloudflare? Your origin would see transfer to Cloudflare, but they'd be able to offload the majority of your download traffic. You also wouldn't be charged per GB as happens with Cloudfront.

I'm not that familiar with Cloudflare and unsure how well it would work with a Drupal-based site. They do appear to have a module ( https://drupal.org/project/cloudflare ) but it seems like it is a beta and hasn't been developed in a few months. It does seem like it would be more expensive for the level with an SLA ($200 for business plan) than the CDN we use now (which is $79 a month for our images and includes 1TB of bandwidth, about what we need. excluding binary downloads, of course). Do you have any direct experience with CloudFlare?

Re: NSA uses Google cookies to pinpoint targets for hacking

#176

Earlier quoted context omitted.

Couldn't you use an inexpensive CDN like Cloudflare? Your origin would see transfer to Cloudflare, but they'd be able to offload the majority of your download traffic. You also wouldn't be charged per GB as happens with Cloudfront.

I'm not that familiar with Cloudflare and unsure how well it would work with a Drupal-based site. They do appear to have a module ( https://drupal.org/project/cloudflare ) but it seems like it is a beta and hasn't been developed in a few months. It does seem like it would be more expensive for the level with an SLA ($200 for business plan) than the CDN we use now (which is $79 a month for our images and includes 1TB…

I haven't used it with Drupal before; we're using it to cache a read-only JSON service in the event of failure, heavy load, etc. We've been pretty happy with them. You could always try their free or $20/month plan on a separate subdomain.

Re: NSA uses Google cookies to pinpoint targets for hacking

#177

Earlier quoted context omitted.

Ghostery's default setting is to disable submitting data. You have to explicity opt-in. How is that tricking? I was interested in your project but your smearing of 'competitors' with FUD is seriously disconcerting.

Congrats on your first post! [1] 1. http://www.catb.org/jargon/html/A/astroturfing.html

Congrats on the non-answer.

Re: NSA uses Google cookies to pinpoint targets for hacking

#178

Earlier quoted context omitted.

Greetings. I nearly have the same policy, regarding surfing and my addons. I would only advise against Ghostery, as they whitelist some trackers, if being paid. With every update I had to reselect these trackers. And Evidon (Ghostery's mothership) selling usageinformation really bugs me: http://venturebeat.com/2012/07/31/ghostery-a-web-tracking-bl... I would recommend the FF-addon Diconnect: https://addons.mozilla.or…

Hi sboering, how are you? Ghostery does what the user tells it to do. If you are seeing unblocked trackers, most likely, its because we've added new trackers and you didn't select "block" by default for the new trackers when the list gets updated. You can change this preference by going into Ghostery options, Advanced, and review the "auto-update" section. And heres a full explanation as to what Evidon gets and what…

Nice: First I would really prefere it, if my name was spelled right. That much of respect should have been the least to do.

But back on topic: Why should I (as fairly technically adapt person) have to search deeply inside the configuration, to maybe find a feature, that I expect to be active by default?

So sorry - Ghostery is so far off my radar nowadays, as I felt tricked and victim of a dark pattern [1]. And as I nowadays have a strict "zero tolerance" policy regarding sites/services/tools that act this way. Ghostery was, is and will be on my list of tools, that I would never ever recommend to anybody.

Btw.: I do not mind downvoting - as it shows me, I must have done something right:

"Methinks thou dost protest too much." (English proverb)

[1]: http://darkpatterns.org/

Post reply on HN