Live data from Hacker News

Ars tests Internet surveillance by spying on an NPR reporter

arstechnica.com

41–50 of 67 posts

Re: Ars tests Internet surveillance by spying on an NPR reporter

#41
post #25
post #10

I really appreciated this story. It's so hard to make people care about "small" data leaks when they have no idea what many "small" data leaks can lead to. The bug the journalists discovered that revealed Skype's contact list is the perfect example -- the programmer just did something completely "reasonable" (grabbing avatars) that ended up leaking a vital set of information. Imagine if surveillance was your full tim…

> I'll again state that this is why I feel so strongly that Google Analytics should be updated to be HTTPS by default That's an incredible waste of bandwidth for no improvement in privacy whatsoever. If HTTPS pages were including GA over HTTP, then yes, this would be an issue, but you're already requesting the page over HTTP, if you're getting GA over HTTP. There's simply no advantage whatsoever -- for privacy, secur…

There is a major improvement to privacy in the larger scale: the Google Analytics servers are a funnel for a substantial percentage of all web traffic. Read the write-up I linked to, specifically "How does that help the NSA?".

Usage of unencrypted Google Analytics + Google cookies[1] means that you don't need to eavesdrop on individual connections, just one small set: the endpoints to the Google Analytics servers.

Hence, the NSA or other large entities have an economical way to tap a large portion of web traffic.

[1]: http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10...

Re: Ars tests Internet surveillance by spying on an NPR reporter

#42
post #2

None of this is shocking except for maybe how unavoidable sharing all this information online actually is. The default settings on most devices are not designed with privacy in mind. In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the…

> This type of technology is so intertwined in our daily lives that avoiding it isn't a realistic option. That seems like somewhat of an apathetic attitude to have. Try living without internet for a week, or even a day. It isn't so bad.

Sounds great for a vacation. But considering I make a living talking to people who don't wear tinfoil hats, it's really not realistic to live the rest of my life disconnected from the net. I imagine the same goes for 99% of people on this site.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#43
post #37

Earlier quoted context omitted.

The VPN secures my data up to the VPN, but it's unencrypted from the VPN to the host. That might help with the casual Wi-Fi snoop in the coffeeshop, but it's still hoovered up once it leaves the VPN.

Yes, that's true. That's what the situation in the article was, a hostile WiFi access point. I'd say that running a modern platform countermeasures are only useful up to the point that you trust your OS maker and telco. So if you can get your data encrypted until it reaches a major telco's network, then you are almost as safe as if it were all encrypted.

> That's what the situation in the article was, a hostile WiFi access point.

The point of the article was not the hostile AP, but to simulate a pervasive threat:

  we would create a pint-sized version of the Internet
  surveillance infrastructure used by the National
  Security Agency... Porcello would become our one-man
  equivalent of the NSA’s Special Source Operations
  department

Re: Ars tests Internet surveillance by spying on an NPR reporter

#44
post #22
post #10

I really appreciated this story. It's so hard to make people care about "small" data leaks when they have no idea what many "small" data leaks can lead to. The bug the journalists discovered that revealed Skype's contact list is the perfect example -- the programmer just did something completely "reasonable" (grabbing avatars) that ended up leaking a vital set of information. Imagine if surveillance was your full tim…

This was a wake-up call for me. On my desktop browser, I can use SSL, NoScript, etc. to control what's exposed. But on my phone I'm powerless. How do I know what each app is capturing and transmitting in the clear? If even Google searches don't use SSL, what hope is there for other apps?

If you have root then install https://play.google.com/store/apps/details?id=com.googlecode... - at least that way only apps you allow can communicate online.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#45
post #3

Looks like the "Pwnie Express PwnPlug R2"[1] is just a Mirabox[2] with an extra wireless card in the Mini PCIe slot and an external antenna. The PwnPlug R2 sells for $1095; the Mirabox sells for $150. [1]: https://www.pwnieexpress.com/penetration-testing-vulnerabili... [2]: https://www.globalscaletechnologies.com/p-58-mirabox-develop...

Where wireless is a cellular component.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#46
post #3

Looks like the "Pwnie Express PwnPlug R2"[1] is just a Mirabox[2] with an extra wireless card in the Mini PCIe slot and an external antenna. The PwnPlug R2 sells for $1095; the Mirabox sells for $150. [1]: https://www.pwnieexpress.com/penetration-testing-vulnerabili... [2]: https://www.globalscaletechnologies.com/p-58-mirabox-develop...

The original Pwn Plug was just a SheevaPlug:

https://www.pwnieexpress.com/penetration-testing-vulnerabili...

https://www.globalscaletechnologies.com/p-46-sheevaplug-dev-...

I don't begrudge them, they assembled it and created a simple to use interface for administration, created docs and bundled it for one price. It's worth the money for some people.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#47
post #22
post #10

I really appreciated this story. It's so hard to make people care about "small" data leaks when they have no idea what many "small" data leaks can lead to. The bug the journalists discovered that revealed Skype's contact list is the perfect example -- the programmer just did something completely "reasonable" (grabbing avatars) that ended up leaking a vital set of information. Imagine if surveillance was your full tim…

This was a wake-up call for me. On my desktop browser, I can use SSL, NoScript, etc. to control what's exposed. But on my phone I'm powerless. How do I know what each app is capturing and transmitting in the clear? If even Google searches don't use SSL, what hope is there for other apps?

If only it were even just the apps. Check out this blog post by the Tor project and look at what it takes simply securing the OS:

https://blog.torproject.org/blog/mission-impossible-hardenin...

Of particular interest to me was how the captive portal detection reports back to Google everywhere you connect even if everything else is disabled.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#48
post #6

Earlier quoted context omitted.

> In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the ordinary that it would make you stick out like a sore thumb. Have you considered trying this, or some implementation of it? I, for one, would like to see websites that didn't instal…

Google metrics aren't always used for spying on people -- news sites in particular drool over every possible metric to measure popularity, referrals, etc. to better tailor their online marketing (and sometimes story selection). It sounds weird, but I'm not sure a website without tracking would be as good.

Website owners can still get most of their metrics without google the same way we did it before google existed: they can analyze their Apache/Nginx logfiles.

Stats is hard? Find some software that does if for you. Better yet, figure out how to do some of it yourself (it's not paritc8ularly hard). Or hire some statisticians. This way, you free your business from being dependent on a 3rd party.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#49
post #27

How far would an always on VPN go to solving parts of these problems? At least it'd be encrypted to the VPN data centre. I suppose from there it'd be in the clear, but at least it'd stop snooping at an ISP level. Or am I missing something, and would it be useless?

VPN is a tunnel. Your computer is on one end and there will be another computer on another end. The ISP or cloud provider on the other end will be able to spy on you even if you use VPN. And of course the website you are visiting has all the information in any case.

Yeah. What happens is that you are giving one more party - the VPN provider - access to your data.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#50
post #42

Earlier quoted context omitted.

> This type of technology is so intertwined in our daily lives that avoiding it isn't a realistic option. That seems like somewhat of an apathetic attitude to have. Try living without internet for a week, or even a day. It isn't so bad.

Sounds great for a vacation. But considering I make a living talking to people who don't wear tinfoil hats, it's really not realistic to live the rest of my life disconnected from the net. I imagine the same goes for 99% of people on this site.

That's a fair point, but I'm still willing to bet you could at the very least drastically reduce the amount of time you spend on the net if you wanted to.
Post reply on HN