4 ms·
In spirit of findings new paths, just an idea (and I'm not sure at all that this is a practical solution): fail2ban---a tool commonly used in servers to automa
by thsealienbstrds 9y ago
In spirit of findings new paths, just an idea (and I'm not sure at all that this is a practical solution):
fail2ban---a tool commonly used in servers to automatically block remote attackers such as spammers---can be configured to automatically send an attack report to some e-mail address when it detects an attack.
A browser extension, such as PrivacyBadger, could do a similar thing when it detects a tracker. Let the report be sent to a law enforcement agency that is setup to deal with this kind of problem. If this agency collects enough data, then it can do some data mining to find, for example, the most violent trackers. If that works, maybe such a tool can be used to give law enforcement some actual power to punish these companies.
- Bartweiss 9y agoHmm... interesting. I'm not sure how practical the "to law enforcement" stop is here, for two reasons. First, lots of these trackers are based in places where their data collection-and-sales are legal - the EU makes decent efforts to pursue foreign actors, but it's a serious limitation nonetheless. Second, it's not clear how often illegal action can be demonstrated. The authors of the DefCon presentation here only identified one of the ten extensions they suspected because the rest couldn't be identified beyond reasonable doubt; with data being gathered by so many actors identifying one is hard. Even so, producing a bank of highly-suspicious extensions could be truly valuable. Law enforcement (sometimes) has the resources to pursue these things beyond a DefCon presentation - honeypotting might make it possible to advance suspicion to proof by providing fake data to specific trackers. And publicizing high-likelihood suspicions might produce publicity against bad actors and moves to transparency and guarantees by better actors. At any rate I'm interested by the idea.