Earlier quoted context omitted.
Your clicks being logged by Twitter.
It’s not like the original URL is somehow encoded in the short URL, so this bot still has to request from t.co (and everywhere in between) to get the target.
Intercepting t.co links using DNS rewrites
31–40 of 60 posts
Re: Intercepting t.co links using DNS rewrites
#32Earlier quoted context omitted.
There are different models here: for every person like you who's trying to reasonably proxy their local traffic, there's a nation state, overbearing educational software provider, &c. who's trying to get access to sensitive and potentially life-affecting communications. When it comes to things like finances, private chats, &c. I think there's a reasonable argument to be made that it's in the website's (and my!) inter…
The problem is that in practice, at least in the US, the most realistic threats are from websites you visit delivering drive-by malware (e.g. spyware and adware), which they actually do constantly. It's such a common practice that it's not even usually phrased that way, but just imagine if you exploited eBay's web servers to port scan their internal network, which is exactly what they did to customers. The responsibl…
Re: Intercepting t.co links using DNS rewrites
#33Re: Intercepting t.co links using DNS rewrites
#34Earlier quoted context omitted.
There are different models here: for every person like you who's trying to reasonably proxy their local traffic, there's a nation state, overbearing educational software provider, &c. who's trying to get access to sensitive and potentially life-affecting communications. When it comes to things like finances, private chats, &c. I think there's a reasonable argument to be made that it's in the website's (and my!) inter…
The problem is that in practice, at least in the US, the most realistic threats are from websites you visit delivering drive-by malware (e.g. spyware and adware), which they actually do constantly. It's such a common practice that it's not even usually phrased that way, but just imagine if you exploited eBay's web servers to port scan their internal network, which is exactly what they did to customers. The responsibl…
When I say "audit," I mean in the sense that existing ecosystems like CT already provide automatic auditability of certificate issuance. We're not talking about a private company sleuthing through your computer; we're talking about a way to enforce the stated security model that most users expect when a connection is described as "encrypted."
Re: Intercepting t.co links using DNS rewrites
#35Earlier quoted context omitted.
It’s not like the original URL is somehow encoded in the short URL, so this bot still has to request from t.co (and everywhere in between) to get the target.
The proxy is resolving all links, therefore denying twitter the information on which links you actually click (see also ad nauseum).
It only resolves the links navigated to, right? It shows you the interstitial page, but only when you try to navigate to the link.
It does enable you to get the clean link and share that.
Re: Intercepting t.co links using DNS rewrites
#36Re: Intercepting t.co links using DNS rewrites
#37Re: Intercepting t.co links using DNS rewrites
#38Just quit twitter and it's all good huh? Why is everyone not leaving Twitter?
Re: Intercepting t.co links using DNS rewrites
#39Re: Intercepting t.co links using DNS rewrites
#40Will this show up in Certificate Transparency logs?
There's no need to track certificates from private CAs. In order for your browser to trust the certificates you need to manually trust the CA (or your system admin will configure it). Everyone else will see it as invalid.