Weather.com Has Become the Pawn of a Data Theft Scheme
hackernoon.com
hackernoon.com
Battery condition and orientation are useful for fingerprinting devices, alongside the more commonly-known canvas attacks.
Your battery status may be used to track you online, 98 comments (2016) https://news.ycombinator.com/item?id=12208880
You're assuming that they must, in the future, again identify you: that is not at all necessary for e.g. spear phishing, blackmail, or other attacks.
"So anyone who has visited weather.com from a mobile device in the past few months is now vulnerable to future malicious activity down the road."
Also: curl wttr.in (I guess hackernews night nock that over heh, it seems like it’s been struggling lately.)
Commercial online weather sites have really gone downhill since wunderground classic. I have yet to see a comparable info-dense site since.
Or at least the page for my market is. https://www.spaghettimodels.com/cities/orlando.htm
weather.com uses an ad provider who gives them a malicious ad .1% of the time.
Install adblockers to universally block advertising networks--even on sites you would otherwise trust and like to support--and encourage all your friends and loved ones to do the same, especially if they're less technically literate.
"Only 0.1% of our profit comes from pureeing children into profit!" isn't a defense.
Edit: Ohh and one more: Jeff Masters and his crew at Weather Underground (wunderground.com). For example another nice meteorogram: https://www.wunderground.com/forecast/us/co/boulder/KCOBOULD...
"if a user stumbles upon a webpage that has a compromised third-party library, the malware runs checks. These checks consist of who the user agent is, the type of device they are operating on, the level of battery it has, and the device’s motion and orientation. After these checks are verified, the malware will connect the infected device to a remoter peer prior to transferring the device’s IP address"
This statement is written to make it seem like like something bad is happening. But read the statement -- it's total BS.
Is this some feature of Wireshark I've never come across, or does the author not know what they're talking about?
It's almost like the author was given some short hand notes and wrote them up wrong.
We use Wireshark day in, day out at my work place and many of us picked up on that statement.
Also, practical advice: use an ad/content blocker.
[1] - https://www.weather.gov/
This is US-specific, but what I use now is the National Weather Service's website. It's actually really excellent. https://www.weather.gov/
But there is.
For example, an entity could have sold the malware to a rube. They would do this by using the same "bullet proof" logic: why would they be selling a tool that can hit 100 million users unless some fish will bite?