Live data from Hacker News

Ars tests Internet surveillance by spying on an NPR reporter

arstechnica.com

1–10 of 67 posts

Re: Ars tests Internet surveillance by spying on an NPR reporter

#2
None of this is shocking except for maybe how unavoidable sharing all this information online actually is. The default settings on most devices are not designed with privacy in mind. In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the ordinary that it would make you stick out like a sore thumb.

In the decade between this type of data collection becoming possible and the mass populace becoming concerned about it, I fear we've passed a threshold we can't un-cross. This type of technology is so intertwined in our daily lives that avoiding it isn't a realistic option.

Things like Apple using random MAC addresses to scan for Wi-Fi APs are a start; but too many devices (Android included) use default settings that are far from secure. But it's up to the companies that make usable, mass-market devices to ratchet up the security, and I fear that they have little incentive to do so when their own ambitions include the same type of data collection.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#3
Looks like the "Pwnie Express PwnPlug R2"[1] is just a Mirabox[2] with an extra wireless card in the Mini PCIe slot and an external antenna. The PwnPlug R2 sells for $1095; the Mirabox sells for $150.

[1]: https://www.pwnieexpress.com/penetration-testing-vulnerabili...

[2]: https://www.globalscaletechnologies.com/p-58-mirabox-develop...

Re: Ars tests Internet surveillance by spying on an NPR reporter

#6
post #2

None of this is shocking except for maybe how unavoidable sharing all this information online actually is. The default settings on most devices are not designed with privacy in mind. In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the…

> In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the ordinary that it would make you stick out like a sore thumb.

Have you considered trying this, or some implementation of it?

I, for one, would like to see websites that didn't install any tracking software. Specifically, I mean no Google metrics. If there was a news website that didn't install any tracking software, but instead just offered pages with cryptocurrency addresses, I would switch to that as my default news source in a second.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#7
post #3

Looks like the "Pwnie Express PwnPlug R2"[1] is just a Mirabox[2] with an extra wireless card in the Mini PCIe slot and an external antenna. The PwnPlug R2 sells for $1095; the Mirabox sells for $150. [1]: https://www.pwnieexpress.com/penetration-testing-vulnerabili... [2]: https://www.globalscaletechnologies.com/p-58-mirabox-develop...

You can get pretty good wifi pentesting functionality out of a Pineapple, currently retailing at $100.

https://wifipineapple.com/

I think for the particular purposes of this investigation, the Pineapple would have made a fine substitute for the PwnPlug R2.

Depending on your wifi card and drivers, it would also be possible to run something like Jasager or Karma on a laptop instead of a specialized wifi base station (although then you have to dedicate your laptop to the surveillance function instead of using it for your own regular laptoppy purposes).

Re: Ars tests Internet surveillance by spying on an NPR reporter

#8

Scary that Google Maps wasn't encrypting significant amounts of its traffic (at least for the reporter in this article, since I know Maps has HTTPS support). Location data can be the most revealing of all.

One of the nicest things about this article is seeing that the Ars reporter (Sean Gallagher) reported at least three information leakage bugs upstream, and the responsible parties have addressed them. How many news organizations can claim to have gotten security flaws fixed so directly?

Re: Ars tests Internet surveillance by spying on an NPR reporter

#9
post #8

Scary that Google Maps wasn't encrypting significant amounts of its traffic (at least for the reporter in this article, since I know Maps has HTTPS support). Location data can be the most revealing of all.

One of the nicest things about this article is seeing that the Ars reporter (Sean Gallagher) reported at least three information leakage bugs upstream, and the responsible parties have addressed them. How many news organizations can claim to have gotten security flaws fixed so directly?

Ah, I was interrupted as I read the article and that info was a couple paragraphs later.

That is awesome! Hopefully it also nudges Google to audit their properties for similar leakages to plug....and everyone else for that matter.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#10
I really appreciated this story. It's so hard to make people care about "small" data leaks when they have no idea what many "small" data leaks can lead to. The bug the journalists discovered that revealed Skype's contact list is the perfect example -- the programmer just did something completely "reasonable" (grabbing avatars) that ended up leaking a vital set of information. Imagine if surveillance was your full time job and you did more than just grab the low hanging fruit.

I was also quite surprised by Google's HTTP Maps flaw in HTTPS search. I'd have previously imagined this would be a standard security pentest that Google products would need to go through. Given how pervasive and important Google is to the digital ecosystem, even small flaws can have a profound impact.

I'll again state that this is why I feel so strongly that Google Analytics should be updated to be HTTPS by default[1]. If you hit a non-HTTP site, you're leaking all the information you would send to Google Analytics to anyone that's listening -- it goes across the wire unencrypted. Considering Google Analytics is on 60+% of the top 100,000 domains, this is a lot of information leakage. Referrers, time on page, browser details, operating system details, everything that Google shows a webmaster in Google Analytics also ends up in the hands of the passive observer.

[1]: http://smerity.com/articles/2013/google_analytics_and_nsa.ht...

Post reply on HN