Going dark: online privacy and anonymity for normal people
troyhunt.com
troyhunt.com
Yes, this article is targeted at people who don't understand the problem of using their .gov email address to sign up for dodgy sites, but think about whether you'd rather have your bank statement made public or a large, visualizable data set representing most of your browsing history.
I would love to see more work done on privacy through noise/obfuscation, such as that started by Adnauseum[2] and TrackMeNot[3] - not necessarily publishing your credit card details online as suggest in another comment here, but in making random search queries and clicking on random ads when your device is idle. Most of us have sufficient processing power and bandwidth for the overhead not to be a problem. It's sad that it looks like both add-ons have failed to make a splash, and seem to have fallen out of active development (end of 2015 marks the last commits for both projects, which is too soon to pronounce them dead, but they definitely don't seem to be hives of activity).
[0] http://motherboard.vice.com/read/looking-up-symptoms-online-...
[1] http://www.allaboutcookies.org/cookies/cookie-profiling.html
If someone got access to my banking details, they could do far more damage than just make my bank statements public.
Now I've dealt with identity theft and credit card fraud, and I work in digital marketing, so I know which one I'd choose: Nobody is going to visualise my individual browsing history, and even if they did (for what reason I can't imagine), I can't imagine what they'd do with it! I can imagine someone might try to build a demographic profile about me to sell me stuff that I'd like, but that's good because it would be stuff that I would like.
Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simply because it blacklists the unknown sites you don't know about, the ones that e-mail links open or pop-ups force your browser to load through various tricks.
Edit: While I'm musing on this, I wonder if NoScript could use a UI overhaul. A little icon that says "Something broken? Try activating these domains" with some heuristics e.g. first try allowing the current domain, then stuff on common CDNs, then maybe digging into DNS records or SSL certs for common ownership...
Not only to have pre-built lists but also to share your own list between devices.
It's possible to whitelist (and blacklist) specific targets, including local site, and a set of specified third-party targets.
That said, overall, it's a bit of a complexity bunghole, and may not be for the general public. But then, computers in general aren't, in many ways, either.
Strong consumer protections exist in many developed nations which limit your liability, it is the banks who stand to lose. No doubt it can be a hassle if your credit card number is stolen, But that card is the bank's property. You just report any fraudulent transactions and get a new card if necessary. The more important thing to protect is your private data, you can't get that privacy back.
Also, NoScript is awesome and I highly recommend people try it. It can be fiddly to get working at first but a surprisingly high percentage of websites work better without having to white-list anything. It also helps with privacy by blocking trackers like Google Analytics, especialy on sites like Troy's which lack a privacy policy and do not provide any warning at all about third-party trackers to site visitors. Pretty new site redesign, same lack of transparency as before.
* By 'regular users' I mean when I say "Try an ad-blocking extension with your browser, add it from the menu" and they say "What is the menu?" and we build their knowledge up from there... . It can be frustrating for all but I highly recommend it as it keeps you grounded and provides balance for the HN bubble I sometimes find myself in.
You almost have to be an experienced webdev to recognize which domains are necessary and which aren't.
But this is also why I emphasize that you can freely use the global whitelisting option and still be much safer than without noscript. Simply because the sites that will get you are often the sites that open unexpectedly. Unknown domains that you did not request.
But people who come to these lectures or cryptoparties usually have a desire to do something about their personal IT-security so hopefully they can find the motivation.
When I try explaining this to other people, even other engineers, they usually tangent into a discussion about how paranoia and an inability to trust are unhealthy. And they stand their ground in the face of mounting evidence, insisting the designer is a humble, well-meaning person like themselves, and would have no reason for doing such evil things.
I also cover basics like using better passwords, not reusing them and ways to keep them safe (keepass, last pass, a password memo book, etc.). And I emphasize over and over again to keep your software up to date. Let companies that have experts on staff do the work for you. Update Windows, your web browser and all Internet connect applications regularly (also applicable to iOS, the App Store and the Play Store).
Finally, I cover basic anonymity tools like ad-blockers and Disconnect.
The final paragraph loses a lot of my clientele, so NoScript is a non-starter for them.
Is that your choice or user demand?
Confidentiality is one of the pillars of security, and beyond a doubt the most common attack on user security is on confidentiaility by commercial and government organizations.
First: Freedome by F-Secure is closed source and there is no OpenVPN alternative. Always choose a VPN that has OpenVPN so that users can configure the connection to their needs. No need for this bloated mess.
Second: Whilst disposable Google accounts might seem like a good idea, there are any number of ways for Google to cross-correlate a disposable identity with your actual identity using fingerprinting captchas or even your screen resolution. Google does this to spot serial re-registrations and to stop people gaming Google Plus voting rings and spammers in general.
Third: Be careful of online websites offering fake-name services. Most of this data is generated server-side and logged for the purposes of cross-correlation with your IP address and useragent string. Quite possibly the vast majority of fake-identity sites are run by LEA
- I like to write some quick and dirty ruby gems to generate fake identities because then it can't be correlated. (The names are pulled in from disparate sources and I always ensure true-randomness).
- In terms of email, use things like Riseup which use TLS at every hop so that passive dragnets cant sniff the password. 99% of all IMAP and SMTP services can be passively sniffed because they use weak STARTTLS.
- Use 'honeywords' in an email to correlate different emails with different activities. For example:
john.doe+shopping@riseup.net
john.doe+gaming@riseup.net
john.doe+correspondant@riseup.net
This way you can whitelist those addresses for the purposes of filtering out spam and phishing attempts.Optionally, retain craigds@host.tld for personal and professional communication/correspondence, and move everything else to craigds1+{something}@host.tld (or a different host).
http://www.theregister.co.uk/2015/07/31/incident_managers_pa...
It's also nice to be able to kill specific email addresses once a breach has been disclosed and the spam becomes plentiful.
In all fairness, the author does mention multiple times that a fake Google account is not meant to protect you from Google, but from the site you're signing up on.
The only real omission I noticed is the lack of mention of advanced browser fingerprinting techniques that can be used against browsers, even if caches are emptied, 'porn modes' activated, VPNs opnened. As demonstrated here by the EFF's Panopticlick initiative. https://panopticlick.eff.org/
One of the most important points about the anonymity provied by the Tor project to remember is that the Tor Browser is painstakingly hand crafted to avoid many of these problems. In other discussions about TOR it is worryingly common to see other ways to route browser traffic through TOR, without mentions of the implications.
For those interested, here's a recent look into the Tor Browser system by one of the developers.
The article is wrong about Tor being an alternative option to a VPN. If anonymity is your concern, you should use TOR to connect to a VPN (paid with Bitcoins).
Using a VPN after Tor might defeat a bad exit node sniffing or changing content. But a VPN absolutely hurts anonymity. Plus there's no way to be sure the VPN op isn't keeping logs.
If I were at the NSA and concerned about any of this, I'd start a few VPN companies. And run Bitcoin exchangers/vendors.
Operational security and Tor is such an interesting and frankly, quite scary subject. I've mainly used and instructed people on Tor for read-only uses of the web.
For my own needs, masking the origin of an actively participating persona is out of scope. I generally warn people about doing anything that requires sign-on/nicknames etc without very careful research.
I recognize that my lack of a need for serious anonymity for basic political activism etc is a huge privilege. So I try to give back by running a bunch of Tor middle relay myself.
For serious anonymity, I'd really be strict about using a forensically clean Tails USB boot environment, on varying public Wi-FI hotspots with a dedicated laptop that never has touched my regular network. The laptop must not ever be powered on near my house. Lots of systems, like Cisco Meraki business Wi-Fi APs take note of all nearby Wi-Fi and Bluetooth devices for 'location analytics'.
Javascript and stuff must be disabled of course. Carrying any cell phone, burner or otherwise is out of the question.
The reasons are many, but for starters, you don't want to be identifiable as the only person at your location making Tor connections, if you're doing something important.
Here are some good points on the subject. https://www.youtube.com/watch?v=eQ2OZKitRwc
My approach for promoting Tor to regular people around me is through describing it as a way to do random googling on subjects people don't necessarily want linked back to them, through analytics and ad companies.
I'm personally pretty convinced that insurance companies around the globe are looking pretty seriously at how far they could push their use of intelligence from data brokers. For purposes like identifying people with potential inherited diseases, recreational drug use habits, mental health problems etc.
So, I think Tor is important for all of us.
I can understand it wouldn't be a crime to create a random email address but creating a fake house address and using this for payments sounds a little tricky.
It may make it easier for people to commit fraud, though I suspect anyone considering that career choice is probably slightly ahead of the content of this article.
As to identity theft - I can't see how this article would help or hinder anyone in that pursuit. I guess if you follow one of the practices described - unique ID attributes at your various throwaway / anonymity-desired sites you visit - you may make it slightly harder for someone to pinch your identity.
*Granted, it is an easily unravelled ball of lottery hotlines & public spaces addresses that could easily be traced back to the real "me", but I'm not really hiding, just preserving my right to be left alone from prying marketeers and... ahem.... data scientists.
The difference between a cash transaction and, say, a bitcoin transaction is one of scale. To make a cash transaction requires us to be in the same place and to have at least a basic understanding of identity. A fraudster can obviously profit in this situation, but their targets are limited to who they can physically meet.
The Internet is an order of magnitude larger scale. Fraudsters can work in bulk and hide their transactions easily. It's wholesale and not retail, so to speak. That is a problem worth at least considering.
I'm thinking about going in the opposite direction, and broadcasting all of my personally identifying information (credit card, SSN, etc). Obviously I would have to set aside a large amount of time to deal with issuing fraud reports, and make sure that I wasn't risking anything that I can't afford to lose--but it does seem simpler in some ways.
After all, if you don't have anything to hide, you're bulletproof, right?
In France in particular there is the example of https://en.wikipedia.org/wiki/Ren%C3%A9_Carmille René Carmille, who was in charge of census and actively sabotaged the collection and use of data.
See also http://theinstitute.ieee.org/technology-focus/technology-his... which calls Carmille one of the first hackers:
"After the invasion, the pro-Nazi Vichy government ordered a nationwide census. Carmille requested the assignment of compiling data from the census forms onto tabulator cards for analysis. His group transferred the data, including information from Column 11—where citizens were asked to indicate their religion—onto tabulator cards. They were instructed by the Nazis to sort the cards and print a list of all Jews living in France so that they could be located and sent to concentration camps.
Over the course of two years, Carmille and his group purposely delayed the process by mishandling the punch cards. He also hacked his own machines, reprogramming them so that they’d never punch information from Column 11 onto any census card. Instead, Carmille’s groups spent most of their time using the information on the cards to find and recruit former French soldiers for the French Resistance."
If that's not hacking and data protection, then I don't know what is.
http://www.scientificamerican.com/article/confirmed-the-us-c...
Might be worth noting that children that were in these camps are still alive today.
You don't need to weigh things against extermination explicitly, just any bad consequence, including political ones.
To all individuals equally? weighed against individual risk?
- generic wealth level - generic education level - living in a particular area of the country - disabilities - having small children
You could probably find more examples like those if you browse the history of humanity. The point is, you can be targeted over anything, and you can't predict what it will be in advance. The Nazis exterminated members of religious minorities and different sexual orientation, which was somewhat unusual in history. The Soviets killed people with high educational credentials and with lots of wealth. Who knows what the next evil empire will pick as an excuse to murder people?
You can't run a society on the assumption it's doomed and everyone will get massacred. That some particular demographical data will be used to select and murder people is a low-probability hypothetical. That it is useful for managing a country right now is a fact. I get one not wanting to be oversharing about oneself, but I don't think that a remote possibility that a piece of demographic data will be used for evil purposes is grounds for ditching censuses altogether. This is not something we should be paranoid about.
Finding yourself questioned, monitored, surveilled, on any kind of "list" (no-fly, hollywood-black) or at any kind of increased risk or action by any actor, state or otherwise, is a risk to be weighed against whatever gain you might make from accurate stats.
> Who knows what the next evil empire will pick as an excuse to murder people?
An argument for giving up less discriminating information in general.
> You can't run a society on the assumption it's doomed and everyone will get massacred.
Much of the US constitution seems centered on protecting the people from an overly powerful government, and restricting said power. Make this sentence less hyperbolic, and you can run a society based on certain assumptions of corruption and abuse.
e.g. A gay Russian who opens a LiveJournal account in 2004. Before LJ is bought by a russian company and russia becomes more homophobic.
http://jacquesmattheij.com/if-you-have-nothing-to-hide
It's cropped up on HN before.
Your browser history or credit card statements for porn sites may not be illegal, but might hamper your political career or personal life.
You may be the CEO of a non-profit aiming to combat fossil fuels in which case your youth spent tractor pulling or drag racing may prove "annoying" once a adversary succeeds in spinning the history right.
There are lots of examples where nothing to hide has absolutely nothing to do with the law. And the big deal here is that YOU decide for yourself what your conscience can commit to - not public debate.
And that better sentence busts open the assumption :)
Shouldn't a service like this exist?
Maybe it would go into comment threads, Google the title, and post a blurb paragraph from a top result? Use karma and elastic search to machine learn which sites and topics to post?
It might even respond to questions with the specific random data for that site from when it signed up, to keep it consistent.
The VPN hides your IP. Incognito mode prevents your cookies from giving away your identity. And the fake info helps with things like sites being hacked and the data being dumped online.
Caveat: normal people don't care about such things.
How many people become victims to identity theft per year? How many people end up in a bad breakup where their ex uses private information in some action of revenge? How many people get falsely accused each year by the police?
Ask them if they care about privacy and anonymity, or as it is more commonly phrased, personal security.
Also, the whole "once it happens to someone, they care" applies to pretty much anything. Find someone who invests a lot of their time speaking in public for any cause you can imagine. Someone who talks to audiences about the perils of alcohol, drugs, any cancer or disease - basically anything that is harmful/dangerous/deadly. How many of them do you think ever gave a second thought to their cause, before it affected their lives personally (themselves, a family member, or close friend)? Practically none of them. People generally don't care about the consequences of anything until they've been slapped in the face by it.
People care, they just don't know.
P.S: Dark is cool ;-)
Computer Court 9: "Guilty. Take her down."
Convicted Blank: "I know my rights. I won't be judged by a machine!"
Dragul: "You don't have any rights. You're a Blank."
Convicted Blank: "Blank is beautiful!
Blank is beautiful!
Blank is beautiful!"
Max Headroom, Episode ABC.1.6 "Blanks"That page recommends going to Social Security Number Registry. Again, an unencrypted totally scammy looking page. If you enter a random name and select a random state, it will 'verify' that your identity has been stolen. Then, if you click on 'Validate', you can enter your SSN (unencrypted, of course).
I don't even know how to code, and this is a news site for hackers? This tripe makes it to the top of the front page?
Also, as explained by the creator[2], the SSN registry site is worthless and apparently a joke (although I'm not going to poke around on the site to verify).
[1] https://www.fakenamegenerator.com/premium.php
[2] http://www.forbes.com/sites/adamtanner/2014/02/03/the-mormon...
Apparently, HN is a joke.
(Note that the only way to view the Forbes article you linked is through the cached version.)
Only recently did I stop worrying about privacy/security, and frankly my online experience is much better. I can now participate in any services/apps that catch my eye, I now save CC data at some sites, don't have a VPN/Tor slowing traffic and giving me cloudflare walls/"im not a bot" verification, don't have noscript/ublock/privacy badger breaking most sites, can sync across devices and backup online.
Having both secure & private online behavior is a massive inconvenience. You basically can't participate in the online world as it exists. (There are definitely opportunities to create secure/private versions of existing tools)
Is there a site that sells phone numbers for viop and sms for bitcoin without requiring identity?
I go and ask the staff, and they said their POS is full of some weird software.
a good VPN provider is worth it, but finding one that will not keep logs on you is another story.
I will note, however, that you display some naiveté about grandmothers ;)
> Well, tunneling your web traffic to some random "VPN" provider and having all traffic flow out in the open to the internet is just defending against your last mile ISP basically.
People use VPN services because they can't trust their ISPs. ISPs log traffic, shape traffic, share data with adversaries, etc, etc. People instead choose to trust VPN providers. Typically, there are few ISPs to choose from. But there are numerous VPN services.
> A real encrypted overlay would be a fully connected mesh between all the nodes of the network.
Well, there are https://peervpn.net/ and https://www.onioncat.org/ (which connects through Tor). From years ago, I recall one from some Russian with a friend in Antarctica. But not even the name :(
Pro tip: don't comment if you've just "skimmed the article".