Earlier quoted context omitted.
Little Snitch is amazing. Any windows comparable?
I’ve had good luck with Portmaster [0] - [0] https://safing.io/
Brute-forcing a macOS user’s real name from a browser using mDNS
151–160 of 168 posts
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#152> Both errors will be mapped into the same Failed to fetch JavaScript error, so we can’t rely on the error type, but we can perform a timing attack. Local networks are fast, so the valid mDNS hostname registered in the network will be resolved in a reasonable time frame, which is significantly faster than the default connection timeout. In the example above, the difference is four milliseconds for a valid address ver…
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#153Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#154Earlier quoted context omitted.
False dichotomy. Not only am I pretty sure Sonic isn't selling my DNS queries, I've already opted out of DNS over HTTPS. Refusing to respect the choices I've made is worse than not. Besides, unencrypted SNI means that if my ISP wanted to get the hosts I was looking at, they could.
Can you elaborate on why you'd want to opt-out of DNS over HTTPS? I was under the impression that it was useful and good for privacy, but I may be misinformed.
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#155Earlier quoted context omitted.
False dichotomy. Not only am I pretty sure Sonic isn't selling my DNS queries, I've already opted out of DNS over HTTPS. Refusing to respect the choices I've made is worse than not. Besides, unencrypted SNI means that if my ISP wanted to get the hosts I was looking at, they could.
Unencrypted SNI is fairly rare now.
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#156Earlier quoted context omitted.
So it gets me on MacOS with safari, lynx, and firefox with strict anti-tracking on. Tor works for blocking it. All in all they have created a creepy wee tool.
On MacOS, on Firefox, resistFingerprint=1 and clearing out recent history, or going in incognito mode, (cookies, cache, etc.) defeats the fingerprint. A little disappointed that Privacy Badger didn't seem to make any difference. Was active the whole time.
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#157Is there a way to prevent websites from the broader Internet from making network requests to my local network? I can't imagine why this should be allowed by default. (Not to suggest bringing back IE's Local Intranet Zone permission...)
They generally can't, because of CORS. The only reason this "hack" works is because the timing of the rejection is different between non-resolving domain request and resolving-but-rejected request. But if you run something on https://192.168.2.1 it can't be accessed from a web app running on https://my-own-domain.com unless the service running at 192.168.2.1 allows the "Origin" my-own-domain.com.
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#158Earlier quoted context omitted.
I’ve had good luck with Portmaster [0] - [0] https://safing.io/
I checked that out once but the safing/SPN thing spooked me. It doesn't really explain what it is and why it is needed for a software firewall. As far as I can tell is it a peer-to-peer VPN network? I don't want that. If you have a good answer I'd love to learn it.
Portmaster is actually a privacy suite consisting of many features and modules. It is often described as an "application firewall" to give people a quick, but incomplete idea of what it is.
The SPN is one of these features. It is a blend of VPN and Tor - oversimplified - and is fully optional. In fact, it is a paid feature and won't activate without logging in with an eligible account.
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#159Earlier quoted context omitted.
I checked that out once but the safing/SPN thing spooked me. It doesn't really explain what it is and why it is needed for a software firewall. As far as I can tell is it a peer-to-peer VPN network? I don't want that. If you have a good answer I'd love to learn it.
CTO of Safing here. I hope I can bring some clarity into this. Portmaster is actually a privacy suite consisting of many features and modules. It is often described as an "application firewall" to give people a quick, but incomplete idea of what it is. The SPN is one of these features. It is a blend of VPN and Tor - oversimplified - and is fully optional. In fact, it is a paid feature and won't activate without loggi…
Re: Brute-forcing a macOS user’s real name from a browser using mDNS
#160On my macOS box, I run Little Snitch, a nice UI that can be set to ask local user for explicit permission before allowing a network request. https://www.obdev.at/products/littlesnitch/index.html I’ve occasionally stumbled on it during remote logins, usually when an SSH session wants to download something new, like NPM requesting NodeJS bits. The text terminal SSH download will block; if I figure out it’s the Little S…
Little Snitch is amazing. Any windows comparable?
Also saw this on the main page today and had to share here: