Live data from Hacker News

Ars tests Internet surveillance by spying on an NPR reporter

arstechnica.com

51–60 of 67 posts

Re: Ars tests Internet surveillance by spying on an NPR reporter

#51
post #43

Earlier quoted context omitted.

Yes, that's true. That's what the situation in the article was, a hostile WiFi access point. I'd say that running a modern platform countermeasures are only useful up to the point that you trust your OS maker and telco. So if you can get your data encrypted until it reaches a major telco's network, then you are almost as safe as if it were all encrypted.

> That's what the situation in the article was, a hostile WiFi access point. The point of the article was not the hostile AP, but to simulate a pervasive threat: we would create a pint-sized version of the Internet surveillance infrastructure used by the National Security Agency... Porcello would become our one-man equivalent of the NSA’s Special Source Operations department

Which misses the point of NSA surveillance. Ars knew who they were looking at, and could have multiple people look at that one person's history for whatever they wanted.

The broad surveillance of any practical intelligence apparatus only bothers to do that to target actual subjects of interest, and don't have infinite leeway to not produce results while doing it - i.e. if the NSA produces no useful intelligence on Al Qaeda for a few months, they're looking at budget cuts.

Or to put it another way: how many man hours did they expend on this effort, and how many people do they actually think work for the NSA? It's certainly not "millions".

Re: Ars tests Internet surveillance by spying on an NPR reporter

#52
post #6
post #2

None of this is shocking except for maybe how unavoidable sharing all this information online actually is. The default settings on most devices are not designed with privacy in mind. In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the…

> In order to avoid this type of data collection, you'd have to walk around with a dumbphone, avoid using any bank-connected services and basically only log on to the Internet via a VPN. Ironically, this usage pattern is so far out of the ordinary that it would make you stick out like a sore thumb. Have you considered trying this, or some implementation of it? I, for one, would like to see websites that didn't instal…

"If there was a news website that didn't install any tracking software, but instead just offered pages with cryptocurrency addresses, I would switch to that as my default news source in a second."

No you wouldn't. You might be hard-minded enough to try and commit to it, but instead you'd almost certainly just stop reading any news...then go back to aggregators/blogs whatever.

It's a well studied problem that as soon as something becomes not free, people change their behaviour dramatically.

Of course, if you really don't care about the news (and broadly normals news websites are pretty useless to me), then you can cheaply skip a step...

Re: Ars tests Internet surveillance by spying on an NPR reporter

#53
post #42

Earlier quoted context omitted.

Sounds great for a vacation. But considering I make a living talking to people who don't wear tinfoil hats, it's really not realistic to live the rest of my life disconnected from the net. I imagine the same goes for 99% of people on this site.

That's a fair point, but I'm still willing to bet you could at the very least drastically reduce the amount of time you spend on the net if you wanted to.

I could dramatically reduce any number of things if I really wanted to. That doesn't make it practical though, since I don't want to, or I want to still partake in a modern civilization.

The better question to ask is "will being off the grid actually solve the problem?"

Because plenty of people aren't on the net in Syria, Iraq, Afgahnistan...still doesn't really work out.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#54
post #23
post #18

Earlier quoted context omitted.

I only skimmed the description of it, presumably the cost is more about being pre-loaded with a good software package for pen testing as opposed to having to set it all up yourself. Could be a pretty decent expense, even for a bigger pentest shop that has the resources to make a standard process for building and setting up stuff like that.

Right, you are paying an extra $945 for them to install a wifi card/antenna and preload a bunch of open source software on it. I'm sure that for some people it is totally worth it, and others would rather do it themselves. I mostly pointed it out because I've used the Mirabox for a bunch of projects and recognized it in the picture. Its a great little ARM box with 2 gigabit ethernet ports (hard to find a on dev board…

Have you ever used the Dreamplug? I'm still hanging onto mine but it sounds like the Mirabox might be a suitable upgrade. How's the kernel support? How's uBoot? (On the Dreamplug, you have to upgrade uBoot via JTAG once you get past a certain kernel version)

Re: Ars tests Internet surveillance by spying on an NPR reporter

#55
post #22
post #10

I really appreciated this story. It's so hard to make people care about "small" data leaks when they have no idea what many "small" data leaks can lead to. The bug the journalists discovered that revealed Skype's contact list is the perfect example -- the programmer just did something completely "reasonable" (grabbing avatars) that ended up leaking a vital set of information. Imagine if surveillance was your full tim…

This was a wake-up call for me. On my desktop browser, I can use SSL, NoScript, etc. to control what's exposed. But on my phone I'm powerless. How do I know what each app is capturing and transmitting in the clear? If even Google searches don't use SSL, what hope is there for other apps?

On Android, iptables packet filter can be used to control what network connections apps are allowed to make. It is, however, an increased maintenance burden. Recent versions of CyanogenMod also have Privacy Guard pre-installed, which can be used to set granular permissions for apps, such as restricting access to geolocation data.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#56
post #22

Earlier quoted context omitted.

This was a wake-up call for me. On my desktop browser, I can use SSL, NoScript, etc. to control what's exposed. But on my phone I'm powerless. How do I know what each app is capturing and transmitting in the clear? If even Google searches don't use SSL, what hope is there for other apps?

In your mobile browser at least Firefox Nightly supports extensions - I have adblock, ghostery, etc. Aside from the privacy benefits it also makes a significant performance difference on my kindle. https://nightly.mozilla.org/

You can use the stable version too, at least ABP, Ghostery and Self Destructing Cookies works fine on it.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#57
I wonder how much sensitive data from governments and companies leaks this way. It doesn't sound unrealistic for an attacker (a spy, a competitor, an inside trader) to pick a coffee shop frequented by low-level government officials and set up a fake Wi-Fi access point. I doubt people doing mundane administrative tasks are security-conscious enough not to leak important data this way.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#59
post #51
post #43

Earlier quoted context omitted.

> That's what the situation in the article was, a hostile WiFi access point. The point of the article was not the hostile AP, but to simulate a pervasive threat: we would create a pint-sized version of the Internet surveillance infrastructure used by the National Security Agency... Porcello would become our one-man equivalent of the NSA’s Special Source Operations department

Which misses the point of NSA surveillance. Ars knew who they were looking at, and could have multiple people look at that one person's history for whatever they wanted. The broad surveillance of any practical intelligence apparatus only bothers to do that to target actual subjects of interest, and don't have infinite leeway to not produce results while doing it - i.e. if the NSA produces no useful intelligence on Al…

The NSA does this full-time, with a large staff. They have very elaborate systems designed to automatically pull all this information and organise it into databases for easy lookup.

These guys were manually viewing wireshark dumps. Obviously they're going to spend a lot more time to get the same info when working at such a low level, with no access to any of the automation tools the NSA uses.

Re: Ars tests Internet surveillance by spying on an NPR reporter

#60
post #23

Earlier quoted context omitted.

Right, you are paying an extra $945 for them to install a wifi card/antenna and preload a bunch of open source software on it. I'm sure that for some people it is totally worth it, and others would rather do it themselves. I mostly pointed it out because I've used the Mirabox for a bunch of projects and recognized it in the picture. Its a great little ARM box with 2 gigabit ethernet ports (hard to find a on dev board…

Have you ever used the Dreamplug? I'm still hanging onto mine but it sounds like the Mirabox might be a suitable upgrade. How's the kernel support? How's uBoot? (On the Dreamplug, you have to upgrade uBoot via JTAG once you get past a certain kernel version)

Yes I have used the Dreamplug, the Mirabox is a logical upgrade from that. The Mirabox uses a Marvell Armada 370 SOC. When I first got my Mirabox the kernel support wasn't great. But Marvell has been contracting with an embedded Linux contracting firm, Free Electrons, to get everything into the mainline. Free Electrons has done a great job and now you can run a stock kernel fairly easily.

The Mirabox comes with the Marvell fork of uBoot which is unfortunately quite old. It doesn't have support for device-tree, for example. I'm not aware of a newer working version from either Marvell or Globalscale. There was some initial work to get Barebox working on the Mirabox, but it is very feature limited.

On the plus side, you don't need a JTAG console to reflash the bootloader. Lots of Marvell SoCs support booting over a UART connection using an Xmodem protocol[1][2]. So you can reflash/unbrick your Mirabox using just the USB serial port. (I think that the Dreamplug also supports this protocol, but I have never tried to use it on one.)

[1]: http://git.pengutronix.de/?p=barebox.git;a=commit;h=0535713b...

[2]: http://git.pengutronix.de/?p=barebox.git;a=commit;h=6bb3a08c...

Post reply on HN