6 ms·
Forum post from Dan Kaminsky, co-founder of WhiteOps[1][2]: "Dan Kaminsky here, my apologies for kicking up a ruckus. This is part of a bot detection framework
by dzlobin 11y ago
Forum post from Dan Kaminsky, co-founder of WhiteOps[1][2]:
"Dan Kaminsky here, my apologies for kicking up a ruckus. This is part of a bot detection framework I've built at White Ops; we basically are able to detect browser automation using resources exposed in JavaScript. Nothing dangerous to users -- or we'd go file bugs on it, which we do from time to time -- but it does provide useful data regarding post-exploitation behavior. Happy to jump on a call with anyone concerned or worried; I'm over at dan@whiteops.com."
[1] http://www.whiteops.com/company http://www.whiteops.com/company
[2] https://isc.sans.edu/forums/STUN+traffic/745/2 https://isc.sans.edu/forums/STUN+traffic/745/2
- bri3d 11y agoAdditionally, the STUN attempts are supposedly gone since yesterday: https://github.com/EFForg/privacybadgerchrome/issues/431#issuecomment-121360707 https://github.com/EFForg/privacybadgerchrome/issues/431#iss...
- joosters 11y agoWow, so if I'm reading that right, they wrote a tracker that generates a new request every 5 seconds? These scumbags are ruining the web. And they wonder why people use ad blockers...
- droopybuns 11y agoIt is scenarios like this that make me unhappy with net neutrality principles that suggest all packets are equal. We are still very early in the age of the Internet. People are sending all sorts of trashy traffic. There is ample opportunity to optimize but net neutrality means we have to treat it all the same. It's nuts.
- MichaelGG 11y agoNo. Net neutrality means the ISPs cannot "optimize" this stuff. Everyone else is welcome to do so. That's the entire point.
- bri3d 11y agoIt sounds like the requests were a bug: https://github.com/EFForg/privacybadgerchrome/issues/431#issuecomment-120668943 https://github.com/EFForg/privacybadgerchrome/issues/431#iss... This looks like it's trying to exercise every dark corner of the user's browser in order to ensure that the browser is a real, eyeball-facing browser and not just a URL fetcher, PhantomJS/SlimerJS, or a clickjacking plugin being used to fraudulently click ads. I think it's easy to see both sides here: tools like this are a powerful way to detect and combat botnets and click fraud, but if/when weaponized they're also a form of browser fingerprinting which is a nasty way to ruin anonymity across the web. IMO there are a lot of bigger targets on the Taxonomy of Bad Internet Things: malware-serving bottom-tier ad networks, "wrapped download" sites, clickjacking, and especially cross-site correlative "analytics" companies come to mind as being more sinister to privacy than Dan Kaminsky going botnet hunting.
- joosters 11y agoTheir motives might be good, but if their actions are indistinguishable from the bad guys, then there's still a problem.
- meowface 11y agoI'd argue that collecting unique information from your browser does not necessarily make you "the bad guys". Lots of legitimate anti-fraud products used on bank/investment websites collect that information and detect/prevent account takeovers before fraudsters can steal money and identities, for example. What can make it bad is: 1. What you do with that information. 2. Who or what you share it with. 3. How far your reach extends. An ad network which can place that code on multiple websites can put itself in a position of power and track devices, and thus browsing habits, of individuals. However, if you have fingerprinting code only on your own website, and don't share that information with any other people/companies/websites, and use it solely to detect malicious bots, users, and behaviors, then I don't really think it's bad. It's like the difference between a gas station owner pointing a closed circuit camera at the door and someone flying a surveillance drone over a whole state. Both are surveillance, but one kind is much less ethical.
- IanCal 11y agoHonest question, why? What problems are caused by browser automation? Slightly more on point, what issues might the NYT be seeing that detecting browser automation is the sensible solution?
- WalterGR 11y agoWhat problems are caused by browser automation? Automated registrations. Automated registration confirmations. Fake comments. Fake votes. Referrer spam. Bad analytics data. Ad clicks.
- dougbarrett 11y agoI deal with this all day every day working with advertisements. A lot of money is spent trying to detect "bad users" and/or "bots" (usually the same thing). I'm talking hundreds of thousands of dollars, if not millions a year in some cases. I'm actually working on developing a system to track browser analytics and usage to detect if it's a person on the other end or a bot. The quick solution of course would be to have a captcha when viewing ads on sites so the advertiser could confirm it's actually a legitimate user, but there are users that are doing everything they can to not be tracked/or view ads, so what incentive do they have to confirm they are a human just so they can be targeted for advertisements? That's why there are companies trying to work behind the scenes to see if the browser is a legitimate session, or a bot session. Companies looking to buy advertisement space are really honing in now on bots, because it's become such an issue where server farms are set up that will automate views on pages to inflate profits, or like in the case of the company that runs this script on NYtimes, to see if the user is viewing the page through a legitimate viewing session, or if the user is running software in the background of their computer pushing page views automatically. I could probably talk all day long with this, but advertising is a huge HUGE market. There is little to no day-to-day talk of the users that are running ad block on their computer, it's a low percentage of the actual users we are running into. The large talk is the people that have created botnets of hundreds of computers to push thousands of fake impressions and how to handle that.