Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kkm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
181.
▲
Dark Patterns: How UX design tricks you into giving away your privacy
(cliqz.com)
1 points
by
kkm
8y ago
|
0 comments
182.
▲
by
kkm
8y ago
afaik, extensions will not provide you with 100% protection in this case. It could be for multiple reasons: 1. The 3rd party domain is not on the list: a. Could be because the presence is not huge. b. The domain is too new, and not av
183.
▲
by
kkm
8y ago
More details on what kind of issues it tries to detect: https://threatpost.com/def-con-2018-telltale-urls-leak-pii-t...
184.
▲
by
kkm
8y ago
Thanks for the suggestion, updated the title.
185.
▲
Show HN: Local Sheriff – Browser extension to show PII leaks to third-parties
(github.com)
79 points
by
kkm
8y ago
|
11 comments
186.
▲
Show HN: How websites leak PII to third-parties
(github.com)
2 points
by
kkm
8y ago
|
0 comments
187.
▲
DEF CON 2018: Telltale URLs Leak PII to Dozens of Third Parties
(threatpost.com)
2 points
by
kkm
8y ago
|
0 comments
188.
▲
Non Functional Metrics Evaluation of Android Apps
(medium.com)
1 points
by
kkm
8y ago
|
0 comments
189.
▲
Breaking bad to make good: Firefox CVE-2017–7843
(medium.com)
7 points
by
kkm
8y ago
|
0 comments
190.
▲
We need a reset:strong user rights & strong privacy for a much better internet.
(medium.com)
4 points
by
kkm
8y ago
|
0 comments
191.
▲
by
kkm
9y ago
As long as you don't look at the network, it is not at all scary.
192.
▲
by
kkm
9y ago
Thanks, Yes, That's the first post highlighting the issues. This follow-up post is after Emirates responded via theregister.co.uk. There were so many inaccurate things in their comment that I decided to do a complete post.
193.
▲
by
kkm
9y ago
I wish the Emirates tech team understands the gravity of this problem. None of the services they are using to optimize the websites, needs this sensitive information. It's a side-effect of their implementation. But just a small correct
194.
▲
by
kkm
9y ago
Hopefully, they do. It's pretty weird how they themselves advice not to share the booking reference with other people and are leaking the same to the third-parties.
195.
▲
Airline websites don’t care about privacy follow-up: Emirates in full-on denial
(medium.freecodecamp.org)
36 points
by
kkm
9y ago
|
12 comments
196.
▲
by
kkm
9y ago
Updates: - March 6th, 2018: Emirates responded with a standard statement. Excerpt: “The depiction in Mr Modi’s article as to what data is being shared, or customer choice in ‘opting out’ is inaccurate.” Here is my response: https:/&#x
197.
▲
Airline websites don’t care about your privacy - II: Emirates in Denial
(medium.com)
5 points
by
kkm
9y ago
|
0 comments
198.
▲
by
kkm
9y ago
That was the first question I asked on Twitter support, to which they replied, I can report the issues here. https://cdn-images-1.medium.com/max/1600/1*VvnWUPs8xnWRtH92M... Again, I am more than happy to report it
199.
▲
by
kkm
9y ago
Even though they are not based out of EU and only operate in EU?
200.
▲
by
kkm
9y ago
Strange, I always encounter `NET::ERR_CERT_COMMON_NAME_INVALID` even on Gmail with Chrome. What's your test setup?
201.
▲
by
kkm
9y ago
I think you are referring to an attack similar to this: https://media.ccc.de/v/33c3-7964-where_in_the_world_is_carme... , I just linked this video in the article and not the complete attack vector.
202.
▲
by
kkm
9y ago
For measuring presence of trackers on popular websites, I recommend: https://whotracks.me/ Disclaimer: This is a project from the company I work for. (Cliqz)
203.
▲
by
kkm
9y ago
Certificate pinning and integrity checking will only come into play if the services move to HTTPS :). Sadly, Emirates is sending HTTP links to help user's manage booking.
204.
▲
by
kkm
9y ago
Exactly, the fact that the url does not have any expiry (apart from the end of booking), the email providers in this case Mailchimp would also have access to the same. For the case why browser did not redirect the broken cert, that is becau
205.
▲
by
kkm
9y ago
Lot of the e-commerce sites are bound to similar leaks. I remember reporting similar issues to MakeMytrip.com, Expedia last year, MakeMyTrip.com was prompt enough to fix these issues. Sadly, never go any response from Expedia so not sure if
206.
▲
by
kkm
9y ago
Inspect element is a good place to start. I would suggest the following approach: 1. Open a new tab. 2. Right click inspect element and check the option to preserve logs. 3. Copy and paste the link which you want to check, 4. Preserve log w
207.
▲
by
kkm
9y ago
This comment is spot on. Do you mind if I use it as a caption on the artice aswell(with due credits)
208.
▲
by
kkm
9y ago
Interesting thought, would be really curious to see the outcome for that. AFAIK, the link that Emirates is sharing allowed me to add my own miles number. What I am not sure is, if there is a check at the backend (Emirates side) which compar
209.
▲
by
kkm
9y ago
Failure to accept and acknowledge these issues needs to be sorted out.Unless these issues are treated as a technical priority, organisations will have a huge impact on service delivery issues sooner or later.
210.
▲
by
kkm
9y ago
I hear you, the problem is deeply rooted, in the implementation design. Even reporting these problems is such a tedious task, that you kind of feel like giving up after a certain point. Unfortunately, not just Emirates, but a huge number of
More ›