23 ms·
A good step forward. Does the NY Times itself track what its users read? Does it provide that information to others? If so, this change amounts to not protecti
by hackuser 10y ago
A good step forward. Does the NY Times itself track what its users read? Does it provide that information to others?
If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy.
- eugeniub 10y agoI don't see how anyone can monetize user privacy without NYT's permission, with or without HTTPS. All of the monetization methods, ad trackers on NYT pages, browser fingerprinting, malware on your computer, etc works with or without HTTPS.
- hackuser 10y agoWithout HTTPS, whoever owns the LAN you use, its ISP, and various intermediary networks can easily track everything that appears in your web browser by reading the same traffic your browser reads.
- acdha 10y agoThis is more than a hypothetical concern, too: back in 2011 a number of ISPs came under fire for hijaacking certain search keywords[1], Comcast has injected ads into hotspot traffic[2], and Andreas Gal has alleged that smaller search engines were buying aggregate Google search result data from ISPs trying to improve their result quality[3]. All of that is impossible with HTTPS. 1. https://www.eff.org/deeplinks/2011/07/widespread-search-hijacking-in-the-us https://www.eff.org/deeplinks/2011/07/widespread-search-hija... 2. http://arstechnica.com/tech-policy/2014/09/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality/ http://arstechnica.com/tech-policy/2014/09/why-comcasts-java... 3. https://andreasgal.com/2015/03/30/data-is-at-the-heart-of-search-but-who-has-access-to-it/ https://andreasgal.com/2015/03/30/data-is-at-the-heart-of-se...
- hackuser 10y agoThanks. And even those issues underplay the magnitude of the problem. Look up Deep Packet Inspection, for example. It doesn't take much to read and record the content, and nothing stops them from doing it in the U.S. (AFAIK).
- chebucto 10y agoYour mention of how it was 'impossible with HTTPS' to inject ads into web traffic made me recall how, two years ago, Lenovo shipped laptops with software ('Superfish') that injected ads into encrypted webpages: http://www.theregister.co.uk/2015/02/19/superfish_lenovo_spyware/ http://www.theregister.co.uk/2015/02/19/superfish_lenovo_spy... Lenovo got approximately $250,000 for installing the malware: http://www.forbes.com/sites/thomasbrewster/2015/02/27/lenovo-got-very-little-from-superfish-deal/#c645206f5ce4 http://www.forbes.com/sites/thomasbrewster/2015/02/27/lenovo...
- wang_li 10y agoVerizon and AT&T (or maybe t-mobile) inject unique headers into http requests over their mobile networks.
- TurningCanadian 10y agoRandom coffee shop / hotel / etc wifi owners and other users on the network will only know that you're reading nytimes.com, and not which particular section/article.
- TurningCanadian 10y agoAnd your session cookie..
- semiquaver 10y agoSession cookies are transmitted as headers which are protected by HTTPS.
- TurningCanadian 10y agoSorry, I meant that as an additional reply to "If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy." The cookie is now hidden from the MITM. Before, not only could they see what pages you see, but they could login as you.
- hackuser 10y agoYes, that's assumed in what I meant. Vendors that track their users, such as Google and maybe the NYT, by implementing HTTPS are basically saying: We don't want to share that data with anyone else (e.g., 'random coffee shop / hotel / etc wifi owners'); we want to keep the monetization of our users' privacy to ourselves.
- nathan_f77 10y agoIt's actually very easy to figure out which article you're reading. I just did a little experiment for fun: https://github.com/ndbroadbent/nyt_privacy https://github.com/ndbroadbent/nyt_privacy The wifi owners can see that you're reading nytimes.com, but they can also see how much data was transmitted. All they need to do is look up the length of each article, and compare that with how much data the server returned. Of course, I'm not too worried about hotel owners. I can imagine this technique is already being used by a lot of governments around the world.