Earlier quoted context omitted.
This. I work on Disconnect. I don't understand why any hacker would still put Ghostery on their machine: * Ghostery is run by former ad execs (7/9ths of their executive team): http://www.evidon.com/our-team * They make their money (I've heard tens of millions of dollars per year) selling user data to ad co's and data brokers: http://www.evidon.com/#block-views-from_our_partners-block
Why is the Disconnect trackers list ( https://services.disconnect.me/disconnect.json , referenced in https://github.com/disconnectme/disconnect/blob/master/firef... ) an encrypted blob? That seems to go against the OS nature of the project.
NSA uses Google cookies to pinpoint targets for hacking
121–130 of 178 posts
Re: NSA uses Google cookies to pinpoint targets for hacking
#122Earlier quoted context omitted.
You have to opt-in to 'Ghostrank' which is the data that they sell. I don't really see what's sneaky about this. Hell,if you click the ' see more... ' toggle on the prefs page it tells you what Ghostrank does. >Online marketing companies need better visibility into real-world applications of their technologies and those owned by their competitors. GhostRank data is sold as reports to businesses to help them market to…
quesera described what's sneaky about Ghostery - their users think they're protected but aren't and don't know they're sending data to Evidon that the company sells but are: > So you offer a very useful product, for free, and make money off of the people who fail to configure it so that it performs the only service they would ever purposely download it for. I gave some numbers above that show, in practice, just how m…
> And how exactly is it trickery if users have to opt-in to the program and they're told what the program does?
Ghostery seems to rely on vague messaging (last I looked, they don't actually say anywhere in their extension that they sell the data you share to ad co's and data brokers) and UX "optimization" (what quesera dubbed the "reconfigure-on-update dance", for example) to get less attentive users to leave blocking off and to send data - as the numbers show.
Re: NSA uses Google cookies to pinpoint targets for hacking
#123There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…
Why do we still have referrers? They don't allow us to do anything that we wouldn't be able to do without them. If Mozilla and Google made a statement today saying, "We'll be removing referrers from cross site requests in 6 months time for Chrome and Firefox.", the tiny tiny proportion of sites that are using them for real functionality will have plenty of time to update. Of course, as a web developer, it's useful to…
I just thought I'm already using NoScript, AdBlock, RequestPolicy, BetterPrivacy, Cookie Monster, Blender, and HTTPS-Everywhere; might as well go all-in.
Re: NSA uses Google cookies to pinpoint targets for hacking
#124Earlier quoted context omitted.
folks please don't downvote people when they're giving useful info. there is a button in the advanced section that makes blocking work by default on new data. that's useful to know - i've just enabled it, and you should too. just because you don't like someone (likely based on one comment on a web site...) doesn't mean that they should be downvoted...
I didn't downvote him, but I can understand why others might. His comment seems willfully ignorant of the problem, which is that Ghostery calls itself a tracker-blocker, but squirrels that obviously-desirable config option away under "advanced" settings. If Ghostery was on our side, really and truly, that would be the default. Indeed, it probably wouldn't even be an option. Of course when the tracker list is updated,…
Ghostery does not call itself a tracker-blocker, our users do. This is an obvious oversight for most users, and its somethign that we will address, but at this time, Ghostery is designed to reveal the invisible web and give user the control over it, not make decisions for the users...
As far as the feature, at the implementation time, we've queried a set of users that agreed that when new trackers are added, there is no need to let the user know until s/he encounters it for the first time and reviews it. Obviously, this is another setting we will be moving away from advanced and into wizard so the users may review and select this option at install time.
Re: NSA uses Google cookies to pinpoint targets for hacking
#125There are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far…
Please do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostile…
There's this add-on called Blender that is supposed to make your browser send headers like the average browser, you might be interested in that.
Re: NSA uses Google cookies to pinpoint targets for hacking
#126Earlier quoted context omitted.
I would replace Ghostery in your list with Disconnect. I would also add the 'Self-destructing Cookies' browser plugin. In its settings, whitelist a very limited set of sites you want to allow persistent (or session) cookies.
I don't know about either... https://github.com/gorhill/httpswitchboard/wiki/How-does-HTT...
Ghostery database is not static either and we update it very often, if you feel we are missing something, please let us know.
Re: NSA uses Google cookies to pinpoint targets for hacking
#127Earlier quoted context omitted.
Heh, Ghostery is not paid to whitelist anyone, I would know since I run the database for Ghostery. As to your question: NoScript does a different thing -- it concentrates on limiting known security issues by disabling Javscript. Tracking is accomplished in a variety of ways, and only some of them are Javascript based. Ghostery looks for all of these and lets users know who is tracking them on any given web page.
Why would you know how or why Ghostery is paid just because you run their database? Unless you are something more than Ghostery's DBA.
Re: NSA uses Google cookies to pinpoint targets for hacking
#128Is there a way for mobile browsers to block analytics cookies JS , a la ghostery and adblock?
Re: NSA uses Google cookies to pinpoint targets for hacking
#129Earlier quoted context omitted.
I'd pay for an intermediate level of GA in a heartbeat. Right now, once you hit 10M pageviews a month you either have to sample or pay $150k/year for Premium. I don't need support, an account manager, four-hour turnaround on data, an SLA, etc. I just need more pageviews sometimes.
Set up 2 GA accounts, then in your embed give even IP addresses version 1, and odd ones version 2, then you can track 20M pageviews. Admittedly it's a little rubbish. Guess you could use the API to combine them again for your own backend use.
I've heard that running a $10/month AdWords campaign gets you higher caps, but it may be an internet old wives tale.