13 ms·
NSA uses Google cookies to pinpoint targets for hacking
- sehugg 13y agoInteresting choice of cookie: http://blogs.wsj.com/digits/2012/02/28/the-google-cookie-that-seems-to-come-out-of-nowhere/ http://blogs.wsj.com/digits/2012/02/28/the-google-cookie-tha... https://bugzilla.mozilla.org/show_bug.cgi?id=368255 https://bugzilla.mozilla.org/show_bug.cgi?id=368255
- PavlovsCat 13y agoGotta love the arrogance of "This is intend behavior of the feature. WONTFIX for me.", without the ability to explain why this cookie would be required for the feature to function.
- simfoo 13y agoAlso "...I am not worried that google is misusing this data...". This clearly isn't acceptable in a post-Snowden world.
- driverdan 13y ago> On Firefox, the cookie shows up automatically as part of Safe Browsing, unless a user disables “third party” cookies. Disable 3rd party cookies. It solves a lot of these types of tracking issues.
- chroem 13y agoHah, the joke is on them: I browse with cookies disabled. Of course, I'm sure they have some other way to pwn me, but it's nice to know that I was doing something right.
- misiti3780 13y agoif you browse with cookies disabled, that means you cannot successful browse arounds sites logged in - correct ? you basically do a ctrl+shift+N in chrome every time you open a new window ?
- chroem 13y agoI have a select few sites whitelisted, but they're disabled by default. Also, I'm on Iceweasel/ Firefox instead of Chrome. It's probably nothing to worry about, but you can never be too careful these days.
- kzrdude 13y agoIt's interesting but also annoying how my browsing is now diverged from the web as others see it. I mean, with increased amounts of blocking addons, the difference between an adblocked, ghostery'd, etc browsing experience to the vanilla experience is growing bigger.
- gress 13y agoSo all that paranoia about being tracked by Google... wasn't paranoid at all. Yes, I know Google likely didn't cooperate in this, but they built a giant tracking engine, so it's not surprising to see it repurposed.
- psbp 13y ago"I know Google likely didn't cooperate in this" I'm sure they have plausible deniability.
- eli 13y agoIt is indeed quite plausible.
- 001sky 13y agoThere was a quote here from oppenhimer the other day, about when it comes to cool technical solutions, you shoot (solve) first and deal with the morality (ask questions) later. Pity that everyon seems to be "hacking" the hell out of pandora's box, though.
- PavlovsCat 13y agoIf you build it, they will come.
- Smerity 13y agoThere are two primary issues here: the prevalence of Google Analytics and the unencrypted nature of the majority of websites. Google Analytics is on a substantial proportion of the Internet. 65% of the top 10k sites, 63.9% of the top 100k, and 50.5% of the top million[1]. My own partial results from a research project I'm doing using Common Crawl estimates approximately 39.7% of the 535 million pages processed so far have GA on them[2]. That means that you're basically either on a site that has Google Analytics or you've likely just left one that did. If the page you're on has Google Analytics and isn't encrypted, the Javascript request and response is in the clear. That JS request to GA also has your referrer in it, in the clear. The aim of my research project is to end with understanding what proportion of links either start or end in a page with Google Analytics. If it starts with Google Analytics, your present "location" is known. If the link ends with Google Analytics, but doesn't start with it, then when you reach that end page, the referrer sent to GA in the clear will state where you came from. All of this is then tied to your identity. If people are interested when I get the results of my research, ping me. I'll also write it up and submit it to HN as it would seem to be of interest. [1]: http://trends.builtwith.com/analytics/Google-Analytics http://trends.builtwith.com/analytics/Google-Analytics [2]: http://www.youtube.com/watch?v=pkoIUmP5ma8 http://www.youtube.com/watch?v=pkoIUmP5ma8 (GA specific results at 1:20)
- quesera 13y agoPlease do post your research when it's cooked. It sounds like useful stuff. Firefox, ABE, NoScript, Request Policy, Ghostery, HTTPS-everywhere, hygiene. The irony of my militant approach toward privacy is that I probably make myself more interesting to would-be eavesdroppers by my carefulness than I would if they could see it all -- I'm just not that interesting. On the plus side, the LCD of legitimate-threat hostiles is greatly increased. I'm fairly boring even to neighbors and law enforcement and copyright holders and scam artists and advertisers. I imagine I'm pretty stultifying to nation-state actors. :) Still, I'd like everyone else to join me so that I can get lost in the crowd. The untracked, encrypted, well-rested crowd. Come on in, the water's fine.
- dunham 13y agoI use Ghostery/Adblock, but I have found that it breaks some web sites (whose javascript expects the tracking code to be loaded). BTW, if you're using Chrome, you might also want to look into the "Users" section of preferences. You can create multiple user profiles with separate history, cookies, cache, etc. You can have a different user profile per window at the same time. (After you create a second user, there will be an icon in the top right corner of the window to open a window as another user.) I like to use this to protect against CSRF. (I do financial stuff as another profile and facebook as another profile.) It's also useful for QA if you need to be logged in as multiple people at the same time.
- cromwellian 13y agoDon't even need cookies if you have JS enabled (https://www.eff.org/deeplinks/2010/05/every-browser-unique-results-fom-panopticlick https://www.eff.org/deeplinks/2010/05/every-browser-unique-r...) Without JS and with HTTP headers alone, you might be able to reduce entropy by using Geo-IP.
- bottled_poe 13y agoIn my opinion, browsers should block all third party website content by default. Yeah, I know, the interwebs will break if they actually did this. Well perhaps someone should come up with some kind of website quality rating which indicates that a site can be viewed withing worrying about the prying eyes of FaceBook, Google, Twitter, LinkedIn, etc.
- pavanred 13y agoFirefox + Third party cookies blocked + Ghostery + NoScript Can be a little inconvenient at times but seems justified now.
- greenyoda 13y agoIf you're using Firefox, you might like a little add-on called "Cookie Monster", which lets you easily control which sites can set cookies (permanently or temporarily) and indicates whether the site you're on has attempted to set them. https://addons.mozilla.org/en-US/firefox/addon/cookie-monster https://addons.mozilla.org/en-US/firefox/addon/cookie-monste...
- LoganCale 13y agoIn Chrome, you can use Vanilla. It may not have as many options, but it works fairly well.
- Anonymous823 13y agoI made a post the other day, but it got pushed off 'new' in a few seconds. Anyway, I thought someone should setup a simple one or two page site that summarizes the importance of not tracking visitors. Then, it has a few 'this site respects your privacy' images in a variety of sizes that you can copy and paste into your own site, if you agree to respect those rules. It would need to be a recognizable image and symbol. The image would link to the site above, that informs users how you respect their privacy and do not track them. Personally, I'd add it to my sites, because with all the recent concern about privacy, I think my users would appreciate this change, and it would provide some advantage over competing sites. I'd like to visit a site, see that image in the footer, and feel more confident using their service. I think it would be a good way to encourage change from developers. Very few are going to pull Google Analytics on their own. However, if they get pressure from their users to follow a certain privacy standard, and by doing so they can drop an image on their site to illustrate the change and potentially increase trust and improve their reputation, we might see some improvements.
- gorhill 13y agoWhat a coincidence... I was just a few seconds ago, before taking a break to read HackerNews, investigating an issue with a Chromium blocker (https://github.com/gorhill/httpswitchboard/issues/79# https://github.com/gorhill/httpswitchboard/issues/79#), and was puzzled finding that the `pref` cookie of `.google.ca` changed every single time the tab of the page lost focus. Even went to Google privacy page to understand what this cookie did, with nothing in their statement that could explain this. Now this?
- gorhill 13y agoThat part (value of `S`) changes everytime the tab loses focus: pref=[...]:S=J3ITrb9DNMWLQBzc What kind of "preferences" changes in that way each time the user browse away the page and how does it help "user experience"?
- samstave 13y agoSo, are you saying that through this - NSA can see exactly which tab you are viewing at which time?
- gorhill 13y agoNo. I prefer the scientific approach. At this point, I just reported what I observed. Maybe somebody will come up with a sensible hypothesis as to why a value changes so often. Google could just come forward and tell us the exact meaning of each field in its cookie. That would be a start.
- grey-area 13y agoGoogle analytics tracks your time on page, and is probably storing values to do with that when you lose focus on the page - this is used in analytics for showing site owners engagement etc. Re the pref cookie, it could well be to track your interaction with searches, as they do for site analytics, if it changes when you leave a page, that's the most likely explanation.
- gress 13y agoAlso, it's worth pointing out that the tracking isn't for search. It's for more profitable advertising.
- suprgeek 13y agoA perfect reason to NOT let Google own all layers of the stack between you and the internet (or indeed the real world). Search - Check (goog.com) Mail - Check (Gmail) Browser - Check (chrome) Devices - Check (Android/Chrome books) Websites - Check (Double click/AdMob, Unknown number of other companies) Google Analytics - Check Your DNA - Check (23&Me) Cars - Check (self-driving cars) I am probably missing large chunks of tracking even with this list. Where do you draw the line so that organizations like Google do not handover (willingly or inadvertently) our life to NSA, GCHQ, ASIO, CSIS & whatever New Zealand's Intelligence spooks go by, on a platter? Heterogeneity - Make the buggers at least have to work a little bit to invade your privacy.
- eli 13y agoYour larger point might be true, but has nothing to do with the current revelation. If every site switched from Google Analytics to, say, Mixpanel... nothing would change. The NSA would just target the equivalent mixpanel cookie. So long as their are popular third-party cookies, this will be a problem.
- jdubs 13y agoIt also seems like does the risk of being eased dropped upon outway the benefit of having data to drive business needs?
- IBM 13y agoSearch was easy to replace. Bing and DuckDuckGo are both good. Firefox was an easy switch now that Chrome seems to be much more of a resource hog (and the extensions are better). I don't have an Android phone. For e-mail I've switched to Fastmail but Outlook is also a good alternative if you want something free. I don't use anything else. I'd say e-mail was the hardest friction point of them all, but overall it was pretty easy to leave Google.
- psbp 13y agoSwitching to Microsoft from Google is not an ethical accomplishment.
- deleted 13y ago[deleted]
- judk 13y agoIs there a way for mobile browsers to block analytics cookies JS , a la ghostery and adblock?
- maxerickson 13y agoAdblock Plus is available for Firefox on Android.
- fixanoid 13y agoGhostery is available as a stand alone app for iOS, and has extensions for mobile Firefox and Opera.
- timbro 13y ago> it lets NSA home in on someone already under suspicion Like OWS protesters, for example.
- drawkbox 13y agoSo not only are businesses like cloud services, video games and messaging/devices affected by anti-business NSA trust breaches. But now we have the advertising industry that is going to be affected by the anti-privacy and anti-business practices of over the top spying on individuals. If any private company was doing this there would be legal issues.
- timbro 13y agoNo website has to have Google track their users. If you do it, you choose to do it (you're disrespecting your users). You can get your open-source and locally running web analytics here: https://prism-break.org/ https://prism-break.org/
- jimworm 13y agoLet's be charitable to the NSA for a minute, and imagine that they are following the plot of the God Emperor of Dune[1], where in seeing the danger posed to the Internet by the formation of cloud service giants, they became the fearsome yet benevolent tyrant, strategically planning an engineered leak, so that on their death the Internet would react by distributing its services among many providers in The Scattering, thus ensuring the safety and continued survival of the Internet. [1] https://en.wikipedia.org/wiki/God_Emperor_of_Dune https://en.wikipedia.org/wiki/God_Emperor_of_Dune
- salient 13y agoRelevant: http://betanews.com/2013/12/09/tech-giants-surveillance-reform-rally-is-disingenuous-and-self-serving/ http://betanews.com/2013/12/09/tech-giants-surveillance-refo... As long as these companies build the best tracking engines the world has ever seen, that can identify anyone and everything they're doing, it's just a matter of time before governments get their hands on that data, legally or illegally. It's just too tempting to pass. If I were Google I'd start thinking long and hard about how to solve this problem, and try to make money by actually being on the user's side when it comes to privacy, not against them. Google will ultimately fail if their goals aren't aligned with those of the users anymore.
- bosch 13y agoCan someone answer this question: From a business perspective why is Google and Facebook getting involved in this and calling for the government to not track users. Won't that just bring more attention to their two business models of... wait for it... tracking users and selling their information?
- arbitrage 13y agoBecause their customers are pissed off, and if they don't do something to mollify them, they'll lose money. Previously, when the customers didn't care, they did nothing to involve themselves with this, and almost certainly aided the government. It's purely business. Google and Facebook don't have morals, they have a bottom line. You can understand their actions by following the money.
- rl3 13y agoTo speculate: For connections that utilize NAT devices, NSA probably has analysis tools designed to attempt segregation of network traffic on a per-user basis. Browser string, viewed content, frequency and magnitude of access, user authentication cookies, and ad-tracking cookies all would be tremendously helpful for this purpose. Also, I'm betting they can easily tell when specific computers on a network are powered on or not based on fixed-interval network traffic from anything that polls regularly, such as anti-virus, news readers, mail clients and background updater services. All of the above could aid in painting a more complete per-user picture behind the NAT, without actually having to compromise the local network or individual computers in question.
- kissickas 13y agoI see a lot of you are using Ghostery, which I've never even downloaded because they get paid to whitelist and are run by ad executives. Is there a reason why I would want Ghostery in addition to Noscript, or is all of the (privacy-protecting) functionality redundant? This news makes me happy to see there's a point to me having Google Analytics blocked the last two years. I've noticed a new thing, Google tag manager, lately. Any point in whitelisting this? Anyone know what it does?
- fixanoid 13y agoHeh, Ghostery is not paid to whitelist anyone, I would know since I run the database for Ghostery. As to your question: NoScript does a different thing -- it concentrates on limiting known security issues by disabling Javscript. Tracking is accomplished in a variety of ways, and only some of them are Javascript based. Ghostery looks for all of these and lets users know who is tracking them on any given web page.
- usrnam 13y agoLast weak i create extension for Firefox: Disable Google tracking, log off user FROM Google search engine: * keep login into Gmail * also remove ads * remove Cookie,Sess~/localstorage __ First run, need refresh Google page to log off ~~ -- Also remove Google anal-itics Cookie :) https://addons.mozilla.org/pl/firefox/addon/googleantyspam/?src=userprofile https://addons.mozilla.org/pl/firefox/addon/googleantyspam/?...
- chanux 13y agoFor anyone who would find this useful: Self destructing cookies add-on for Firefox https://addons.mozilla.org/en-US/firefox/addon/self-destructing-cookies/ https://addons.mozilla.org/en-US/firefox/addon/self-destruct...
- reginaldjcooper 13y agoThis is a polished and wonderful add-on.
- goldvine 13y agoThis is beyond ridiculous at this point. Wondering what else is still to come...
- dangayle 13y agoAs someone who works closely with several web marketing folks, this hits close to home. Each time they open a Snowden file, things get weirder and weirder.
- elwell 13y agoThe problem with this is that most of the general public will read it as "Google helped NSA intentionally ..."
- tejaswiy 13y agoI mean, disgust aside, technically NSA is doing some seriously cool shit. I wonder what you could do if you had access to a de-identified data dump from the NSA.