3 ms·
I still don't understand the attack-vector how buying targeted advertisements can be used to unmask particular individuals (the example in mudge's testimony: de
by rrix2 4y ago
I still don't understand the attack-vector how buying targeted advertisements can be used to unmask particular individuals (the example in mudge's testimony: democracy-desiring Chinese citizens posting on twitter illegally).
can someone explain this to me?
if the users are accessing twitter + any ad clicks through a GFW-bypassing VPN, and china can target an advertisement to a single user, then they can figure out that that user uses a VPN if they click on the advertisement? how do they unmask the VPN IP address? my understanding is that VPN providers (should! i hope!) internally transit the traffic so that the exit node isn't the same as the IP address the GFW would see users connect to, so i'm not sure how they could correlate that traffic to a "real" IP/identity.
- netsharc 4y agoA possible scenario is: Chinese govt creates a honeypot site talking about e.g. Xinjiang, put Twitter ads pointing to it. Honeypot site has a tracking pixel from something like nothing-to-see-here.cn that sets a cookie on the user's browser (something like "visited=honeypot-site-about-xinjiang"). User disconnects from VPN, browses "normal" Chinese sites from their home IP, another Chinese site has another tracking pixel from nothing-to-see-here.cn, the user's browser connects to that site and sends the above cookie and gives away the user's home IP. Yeah it's poor opsec, but quite possible. The cookie can even store what pages and how long the user spent on the honeypot site. Or the cookie can just be an identifier, and the honeypot site can send which pages were visited (and at what time) to the nothing-to-see-here.cn, which builds a visitor's profile for the reeducation police.
- rrix2 4y agoThanks, I had dis-counted 3rd party cookies for some reason. Luckily the tide here is changing with firefox ETP, Safari cookie isolation, etc, but you're right that a lot of the world still has cross-domain cookies to contend with. Yikes!