13 ms·
It is easy to expose users' secret web habits, say researchers
- timwaagh 9y agoinstead of making this (even more) illegal, which would solve very little as its still apparantly trivial to do, they should instead work on making that address book. that way when everything is transparant, paedophiles can be caught and we might choose not to vote for somebody with a cocaine addiction.
- drngdds 9y agoSeems like a bad idea. This would also, for example, out tons of LGBT people.
- Freak_NL 9y agoHow does that not fall foul of the "I have nothing to hide" fallacy¹², and its various dangerous consequences³? 1: http://falkvinge.net/2012/07/19/debunking-the-dangerous-nothing-to-hide-nothing-to-fear/ http://falkvinge.net/2012/07/19/debunking-the-dangerous-noth... 2: https://steemit.com/privacy/@tomkirkham/i-have-nothing-to-hide-privacy-argument-is-a-fallacy https://steemit.com/privacy/@tomkirkham/i-have-nothing-to-hi... 3: https://jacquesmattheij.com/if-you-have-nothing-to-hide https://jacquesmattheij.com/if-you-have-nothing-to-hide
- DarkKomunalec 9y agoThose articles either miss, or fail to emphasize enough, the best counterargument: what if you do have something to hide? What if you're organizing a protest, a new political party, a business to compete with entrenched corporations, are a whistleblower (corporate or government), an investigative journalist (still needed in a surveillance society - those in power know better than to turn surveillance on themselves), or a union organizer? Those are all activities (most) people would consider good, or at least necessary, and all require some degree of secrecy.
- emodendroket 9y agoThe kind of people who would make this argument generally have authoritarian tendencies and wouldn't approve so wholeheartedly of your examples.
- timwaagh 9y agoim not saying that because i am a hypocrite who says what he says because its in his best interest. its not. my interests are best served by secrecy. so i might suffer myself. but there are many good people. im saying that because i think its in the interest of soceity that we know how naughty everybody is being. because people are being naughty.
- timwaagh 9y agoof course there is a tradeoff. that example from ww2 is unsettling. For sure that is not my intention, but i doubt that is what would happen. ww2 is a long time ago. hate crime is down a lot. people should not be so pessimistic about modern soceity. but some of our leaders are not people you'd introduce to your mother. and we need that kind of stuff to be out there.
- mnw21cam 9y agoAnd apparently the BBC thinks it needs to explain what the word "trivial" means.
- fredley 9y agoBut not mention which extensions were doing the harvesting...
- megous 9y agoI tried to find if someone is compiling the list of these extensions, but I couldn't find anything.
- wfunction 9y agoI'm guessing it was because "trivial" suggests it is so for everyone, whereas "easy" suggests it is so for someone with the expertise.
- emodendroket 9y agoThat seems quite unlikely.
- thackerhacker 9y agoI've been caught out a couple of times by describing something as trivial (or non-trivial) to people not versed in software-speak. They can either think you are dismissing the whole discussion in some way or just have no idea what you're talking about whatsoever.
- rpns 9y agoI don't think you'll find 'easy' as a definition of trivial in a mainstream dictionary (rather things like 'of little value or importance'). It probably is just computing jargon, though I recall it being used when studying mathematics and meaning 'self-evident' (e.g. a trivial solution).
- deleted 9y ago
- Swizec 9y ago> Two German researchers say they have exposed the porn-browsing habits of a judge, a cyber-crime investigation and the drug preferences of a politician. So how long before we as a society stop making a big deal of things like that? Everyone watches porn, most people enjoy drugs[1]. Why does anyone still care? Why do we make such a hullabaloo if a judge watches porn? Why is it a big deal if a politician smokes some pot to relax? Who cares if a detective drinks a case of beer on the weekend to blow off some steam? I'm all for privacy and there are things I wouldn't care to expose on the internet (like my home address and exact apartment number)[2], but I promise you future generations will not give a shit about each other's "super secret internet browsing habits". My fav porn site is RedTube, my drug of choice is caffeine, and I hate that ThePirateBay has become hard to find in recent months. There's a lot of memes out there about deleting your browser history before you die. But honestly who cares? And if you're doing illegal shit, use a burner laptop. They're $100 on Amazon [3]. Don't be dumb. [1] drugs as in psychoactive substances. Legal drugs like caffeine and alcohol count, as do prescription drugs. [2] you can probably triangulate those from my YouTube videos if you really want to [3] https://www.amazon.com/Performance-RCA-Touchscreen-Quad-Core-Processor/dp/B01MQD63WX/ref=sr_1_2?ie=UTF8&qid=1501500366&sr=8-2&keywords=cheap+laptop https://www.amazon.com/Performance-RCA-Touchscreen-Quad-Core...
- skummetmaelk 9y agoBecause even though it might be accepted in the future, these things have real consequences now and for the foreseeable future.
- Swizec 9y agoThat's kind of circular isn't it? I understand we care because it has real consequences. But why does it have real consequences? That's what I'm wondering and have been for a while. Where does the outrage come from? We all know we all watch porn. But if it comes out that so and so important figure watches porn, suddenly it's the end of the world? Why? Who decides which instance breeds outrage and which doesn't?
- 9y ago
- zeristor 9y agoThis looks to be the presentation: https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEFCON-25-Svea-Eckert-Andreas-Dewes-Dark-Data.pdf https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20pre... From: https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/ https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20pre...
- amelius 9y agoI get this: ERR_SPDY_INADEQUATE_TRANSPORT_SECURITY
- ChristianBundy 9y agoAre you on Chrome Canary? I'm on the stable branch and I'm not having any issues.
- amelius 9y agoI'm using Chromium: Version 48.0.2564.82 Ubuntu 14.04 (64-bit)
- nessup 9y agoI'm also not able to access the link: the connection was unexpectedly terminated.
- DarkKomunalec 9y agoI'm confused.. the article claims the extensions doing the clickstream gathering are illegal... but that the collected data is 'supposed to' be anonymized? Supposed to by what standard? If they're already breaking the law by gathering the data, why would they bother to anonymize it?
- gcp 9y agoBreaking the law in Europe != breaking the law in the country where the click-stream gathering company sits.
- sleepychu 9y agoNot all data collection is illegal, legal data collection requires anonymisation for sale.
- tmnvix 9y agoIllegal in Europe. Maybe by 'anonymising' the data they are satisfying the legal requirements of some other jurisdiction(s).
- deleted 9y ago[deleted]
- gcp 9y agoThe pair found that 95% of the data they obtained came from 10 popular browser extensions. So uhm, which ones are these and how did the researchers obtain the data? (Bought it?) Edit: The answer to the second question is: social engineering.
- FT_intern 9y agoI hope companies uninterested in the data go undercover as potential buyers and expose these extensions. Maybe we can crowdsource a purchase to expose them.
- craigmi 9y agoi had to dns sinkhole requests to pixel.intenta.io that a browser extension was creating, every site site I visited was sent along in an ajax request to this domain. Couldn't isolate what extension it was.
- anc84 9y ago> Couldn't isolate what extension it was. How not? Disabling them in a bisecting way should be a couple of minutes.
- tyingq 9y agoSomeone else noticed the "page refresh" chrome extension making requests to that domain: https://frenchcoding.com/2015/11/12/faites-attention-aux-extensions-google-chrome-que-vous-installez/ https://frenchcoding.com/2015/11/12/faites-attention-aux-ext...
- ThePhysicist 9y agoWe were only able to name one extension (the one named in the presentation), as we did not have conclusive proof that data from other extensions which we found to be suspicious ended up in the data set (as the access to incremental data was limited to a short time period): We developed a sandboxing framework to test whether Chrome extensions send URL data to a third party using a MITM proxy, the code is available on Github: https://github.com/adewes/chrome-extension-behavior-analysis https://github.com/adewes/chrome-extension-behavior-analysis There's also a large study on this that uses a very similar technique: https://arxiv.org/pdf/1612.00766.pdf https://arxiv.org/pdf/1612.00766.pdf In general, you should be careful about any extension that regularly sends data to a third party. You can check this in Chrome by opening the extensions list (chrome://extensions/), checking "Developer Mode" on the top right corner and clicking on "Inspect views: background page" of the extension. You can then open the "Network" tab and see all requests the extension makes while you surf the web.
- usgroup 9y agoI think it makes a lot of sense to start a register of data providers. I.e. so that if you want to sell user data you have to register as a provider and specify where the data comes from and what it contains. That'd make it so much easier to critique the possibilities and to further legislate. It'll also allow for independent control of how anonymous data is and independent attempts and de-anonymising the data. I think it's still not well understood by most people just how much can be known about you and it's potential for misuse. I think an initiative like this would go a long way to bridging that gap and to better legislating for it.
- gcp 9y agoIt's worth looking at the actual presentation. It looks like they didn't buy the data, but used social engineering attacks.
- usgroup 9y agoNo they bought the click-through data and then used social engineering attacks and other sources (YouTube, Google, etc) to connect it to other identities.
- ThePhysicist 9y agoResearcher here, `gcp` is correct in that the NDR acquired the clickstream data from a data provider as part of an investigative story (the data was provided as a free sample), the deanonymization was demonstrated by linking individual URLs with publicly available information from various sources (Twitter, Youtube, Google+, ...), though this often wasn't necessary as many users had URLs that contained direct identifiers (e.g. their full name) as part of the URL and that we could use for efficient de-anonymization.
- PeterisP 9y agoThat's nothing new, the EU does it this way.
- 9y ago
- jlebrech 9y agodon't become a person of interest and they won't go looking for dirt in your browsing history.
- honestoHeminway 9y agoA person of interest is when you patch the kernel and linus says okay- and the NSA wants to talk about gay porn in the mormon cafe down the street
- jlebrech 9y agothey would rather find a bit of dirt on law abiding citizens than the 3000 terrorists they already have a list of.
- awkwarddaturtle 9y agoDid you just reply to your own comment?
- jlebrech 9y agoyes, rather than edit the original
- 24gttghh 9y agoI reject your rehashing of "I've done nothing wrong, so I have nothing to hide." This thread is full of examples of things which many may find innocuous now, but some may also disagree with, and may use as grounds to persecute in the future.
- scrrr 9y agoPrivate browsing mode is your friend. (You can set it as your default, at least on iPhone.) Caveat: You will have to keep confirming cookie usage popups (EU only I guess).
- pricechild 9y agoThere are adblock lists for those notices which is pretty cool. uBlock at least has some in the 3rd party filters options.
- Freak_NL 9y agoPrivate browsing does not conceal what you visit from your ISP, and it only partially prevents trackers and beacons from tracking you (browser fingerprinting is an issue the private browsing won't solve). It also won't safe you from nefarious extensions installed in good faith (as mentioned in the presentation). Using private browsing keeps your local history clean, and prevents existing cookies from being used to track you. That's it. It is there mainly to prevent the letter 'p' typed in the address bar from auto-completing to the more colourful websites just when you want to show your mother-in-law a nice quilt you saw on Pinterest. To prevent the level of tracking mentioned in the presentation, you should at a minimum use a VPN, private browsing, and trusted anti-tracking extensions such as uBlock Origin and Privacy Badger (which as far as I can tell seem to be in the clear and above board at the moment). If your threat level warrants it (e.g., a judge in a morally conservative society) you would use Tor or a VPN with multiple exit points chosen at random for each session.
- qznc 9y agoIt might protect you in the sense that the evil browser extensions are disabled, but then why install them at all? The fact that I visit `https://news.ycombinator.com/user?id=qznc` https://news.ycombinator.com/user?id=qznc` more often than other user pages reveals something about my identity. That is one attack the researchers used. Browsing mode is not designed to protect you from URL snooping. Embedded ads can track those URLs as well and they can in private browsing mode.
- imron 9y agoPrivate browsing mode protects the client, it's so people with access to your browser can't see what you've been up to. It doesn't do much in protecting you from servers that are tracking you - especially over time when there is a large number of individual pieces of information that might not reveal anything in isolation but when put together can be quite revealing.
- ust 9y agoI find this reasoning by prof. Orin Kerr pretty interesting, in respect to whether always collecting the full URLs of users (by IPS) is actually legal. His argument is that it might not be legally OK to do so, and that there already are restrictions, even with rescinding the privacy rules by the FCC: https://www.washingtonpost.com/news/volokh-conspiracy/wp/2017/04/06/the-fccs-broadband-privacy-regulations-are-gone-but-dont-forget-about-the-wiretap-act/?utm_term=.cb7dea7302e8 https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
- jondubois 9y agoThis is great. I look forward to everyone's information being made public in the future. It might be embarrassing initially but if everyone else also has embarrassing stuff released about them then it won't be so bad; it will make people more open and encourage us to be honest. Only criminal and highly unethical activity will be negatively affected. We need to re-calibrate our ideas about people and society to something more realistic. It will probably lower our overall opinion of humanity but at least people will know the truth and behave accordingly. Right now people are idealising certain things and behaving based on false information. In any case, I think it's unavoidable that all information will be public at some point in the future. It's been heading slowly in that direction since the dawn of civilization. Several hundred years ago, even a figure as powerful and well known as the pope could behave unethically and nobody would find out until hundreds of years later. Today it's much harder to keep things secret. I think big, embarrassing revelations like the Anthony Wiener scandal should become increasingly common.
- watty 9y agoWhy would you want everyone's information made public? Do you see any value in anonymous (or semi-anonymous) discussions?
- Semaphor 9y agoIt's possible they were led by utopian thinking. For example, I'd love a society where everyone knows everything about everyone but just doesn't care what weird ideas and preferences they have. But I also expect that no society that hasn't been telepathic since it's dawn would be work as well as the idea goes ;)
- acdha 9y ago> Only criminal and highly unethical activity will be negatively affected. Because nobody has ever suffered for being outed as LGBT, minority religion or political party, etc.? Losing a job, being beaten or killed go way beyond embarrassment and those outcomes are a given for millions of people. Many people like their various bigotries – whole religions feed on the social dynamics of saying everyone outside is sinful and trying to corrupt you – and while it'd be nice if revealing secrets lead to greater tolerance I'd bet a lot that the more likely outcome would be rage that they'd been infiltrated and purging anyone who had been keeping secrets.
- Jonnax 9y agoThe article mentions that the data comes from 10 browser extensions. Didn't mention which though.
- Pxtl 9y agoThis business of using full HTTP requests with full cookies to domains that are secondary to the site I'm visiting needs to end. When I go to Foo.com, the browser does not need to send all my cookies and info to bar.com, even if we're fetching resources to display on Foo.com. Bar.com in this case is acting as a dumb file server, it doesn't need cookies. Yes, this would make single-sign-on harder, but it would make it explicit and be worth the trouble so that when the user is talking to A, they're not being tracked by A's friends B, C, and D. Of course, the big problem: the best browser is owned by the advertiser who stands to lose under such an arrangement. So at best you'd need Safari or IE to spearhead such a change. You can ape it with browser extensions, but without a big browser maker pushing for this kind of shift some sites would just break under such a model (particularly single-sign-on services like Gmail and Facebook).
- catamorphismic 9y agoWhy do you mention Safari and IE but but Firefox?
- catamorphismic 9y ago*but not Can't edit from my mobile HN client.
- kuschku 9y agoBecause Firefox already has implemented this.
- gcp 9y agoCustom settings for history -> Accept third party cookies (Always/Never/From visited). in case anyone is wondering.
- dannysu 9y agohttps://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences#w_how-do-i-change-cookie-settings https://support.mozilla.org/en-US/kb/enable-and-disable-cook... Link with pictures if anyone can't find it.
- amelius 9y agoThat's why I inject noise into the web on a regular basis. Just do some random searches, click some random links.
- mbillie1 9y agoFrom the presentation: > Can I hide in my data by generating noise? (e.g. via random page visits) > Usually not
- deleted 9y ago[deleted]
- amelius 9y agoBut in any case it gives plausible deniability.
- xj9 9y agowhat about adnauseum ? my browser appears to click every as I am exposed to, but I don't see them. better or worse?
- lightbyte 9y agoI'd imagine that is much worse. It's not random at all, you're basically giving them huge amounts of extra data points. That extension was supposed to used to mess up click rates for ads, not stop you from being tracked.
- xj9 9y agothe problem is that humans are really bad at generating random noise. you'd need an automated solution that makes sure you are generating unformly random data.
- pps43 9y agoLet's say there are 10,000 subjects and you are interested in 10. You click 100 links for the subjects you are interested in, and also 1,000 links picked at random. Now random subjects get somewhere between 0 and 2 clicks, way less than your real interests.
- crystaln 9y agoThere have been exposés on this in there part, resulting in fast action from Google. Sadly the behaviour alerts to have crept up on us again. It seems like a list of violating extensions maintained by an outside organisation would help, or perhaps privately reporting to google.
- dalbasal 9y ago”What these companies are doing is illegal in Europe but they do not care," said Ms Eckert, adding that the research had kicked off a debate in Germany about how to curb the data gathering habits of the firms. I think it’s important to be skeptical towards legislation as a solution to these things. The EU/UK cookie law is a cautionary tale, for example. After all that talk we ended up with a law that (effectively) mandates a boilerplate nag screens and no change in behaviour. Even if it had clearer language to distinguish allowable-illegal cookie use, it would still be very difficult to enforce. I don’t mean to say legislation has no part to play. Just saying that the politician outrage to legislation sausage factory has produced some duds in this area. I wouldn’t count on a solution coming from this direction. Speaking of enforcement… Most countries have an advertising standards authority. They create the rules and such. If an ad is (for example) a blatant lie, they can call up the Press/TV/Radio station and get the ad removed. Online, it’s not obvious what authority they have, or how they would enforce that authority at all. Where advertising standards are still not broken is regulated industries. If a locally regulated bank advertises “one weird trick to double your savings,” the advertising standards people can go to the regulator. They have a number to call, genuine threats to make. ..enough to promote self policing. Online, even reputable newspapers allow shockingly crappy ads. Sleazy data collection, snake oils, fake products, click farms, scams even fake news (ironically). Real shyster stuff. This is on the visible end of the online advertising stick, the ad content itself. We already have legislation and a custom of rules. Still, enforcement is nonexistent. Dealing with the unseen data collection end of this stick is even harder.
- DiThi 9y ago> and no change in behaviour In some cases, even the opposite. I used to use self-destructing cookies but stopped after so many websites required using cookies to stop showing that message. I know there are extensions for removing those, but the point is that they made more difficult to avoid what they wanted to avoid in the first place.
- dalbasal 9y agoYep. I forgot to mention that. The irony of remembering users' cookie consent in a cookie.
- rdiddly 9y agoTellingly, the examples cited all involve the use of some form of social media. (There they go thinking Facebook is the internet again.)
- f4rker 9y ago"However, said Mr Dewes, it was "trivial" - meaning easy - " BBC has really gone downhill.