Ars tests Internet surveillance by spying on an NPR reporter
arstechnica.com
Ars tests Internet surveillance by spying on an NPR reporter
1–10 of 67 posts
Re: Ars tests Internet surveillance by spying on an NPR reporter
#2In the decade between this type of data collection becoming possible and the mass populace becoming concerned about it, I fear we've passed a threshold we can't un-cross. This type of technology is so intertwined in our daily lives that avoiding it isn't a realistic option.
Things like Apple using random MAC addresses to scan for Wi-Fi APs are a start; but too many devices (Android included) use default settings that are far from secure. But it's up to the companies that make usable, mass-market devices to ratchet up the security, and I fear that they have little incentive to do so when their own ambitions include the same type of data collection.
Re: Ars tests Internet surveillance by spying on an NPR reporter
#3[1]: https://www.pwnieexpress.com/penetration-testing-vulnerabili...
[2]: https://www.globalscaletechnologies.com/p-58-mirabox-develop...
Re: Ars tests Internet surveillance by spying on an NPR reporter
#4Re: Ars tests Internet surveillance by spying on an NPR reporter
#5Re: Ars tests Internet surveillance by spying on an NPR reporter
#6None of this is shocking except for maybe how unavoidable sharing all this information online actually is. The default settings on most devices are not designed with privacy in mind. In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the…
Have you considered trying this, or some implementation of it?
I, for one, would like to see websites that didn't install any tracking software. Specifically, I mean no Google metrics. If there was a news website that didn't install any tracking software, but instead just offered pages with cryptocurrency addresses, I would switch to that as my default news source in a second.
Re: Ars tests Internet surveillance by spying on an NPR reporter
#7Looks like the "Pwnie Express PwnPlug R2"[1] is just a Mirabox[2] with an extra wireless card in the Mini PCIe slot and an external antenna. The PwnPlug R2 sells for $1095; the Mirabox sells for $150. [1]: https://www.pwnieexpress.com/penetration-testing-vulnerabili... [2]: https://www.globalscaletechnologies.com/p-58-mirabox-develop...
I think for the particular purposes of this investigation, the Pineapple would have made a fine substitute for the PwnPlug R2.
Depending on your wifi card and drivers, it would also be possible to run something like Jasager or Karma on a laptop instead of a specialized wifi base station (although then you have to dedicate your laptop to the surveillance function instead of using it for your own regular laptoppy purposes).
Re: Ars tests Internet surveillance by spying on an NPR reporter
#8Scary that Google Maps wasn't encrypting significant amounts of its traffic (at least for the reporter in this article, since I know Maps has HTTPS support). Location data can be the most revealing of all.
Re: Ars tests Internet surveillance by spying on an NPR reporter
#9Scary that Google Maps wasn't encrypting significant amounts of its traffic (at least for the reporter in this article, since I know Maps has HTTPS support). Location data can be the most revealing of all.
One of the nicest things about this article is seeing that the Ars reporter (Sean Gallagher) reported at least three information leakage bugs upstream, and the responsible parties have addressed them. How many news organizations can claim to have gotten security flaws fixed so directly?
That is awesome! Hopefully it also nudges Google to audit their properties for similar leakages to plug....and everyone else for that matter.
Re: Ars tests Internet surveillance by spying on an NPR reporter
#10I was also quite surprised by Google's HTTP Maps flaw in HTTPS search. I'd have previously imagined this would be a standard security pentest that Google products would need to go through. Given how pervasive and important Google is to the digital ecosystem, even small flaws can have a profound impact.
I'll again state that this is why I feel so strongly that Google Analytics should be updated to be HTTPS by default[1]. If you hit a non-HTTP site, you're leaking all the information you would send to Google Analytics to anyone that's listening -- it goes across the wire unencrypted. Considering Google Analytics is on 60+% of the top 100,000 domains, this is a lot of information leakage. Referrers, time on page, browser details, operating system details, everything that Google shows a webmaster in Google Analytics also ends up in the hands of the passive observer.
[1]: http://smerity.com/articles/2013/google_analytics_and_nsa.ht...