Tool beeps every time data is sent to Google
twitter.com
twitter.com
"Audible feedback on just how much your browsing feeds into Google" (290 points | 5 days ago | 205 comments)
That's a pretty big caveat at the bottom of the GitHub readme
> we need to define an ip(6)tables ipset. This will first exclude Google Cloud, and then include all the other Google IP addresses.
This graph [2] isn't mine but it looks similar to my results.
[1]: https://nextdns.io [2]: https://twitter.com/NextDNS/status/1159804929680257024
I am running my custom made proxy (dns blocking like pihole is a joke, you can circumvent it as simply as https://2899908462 ) with interesting features like ASN ( https://en.wikipedia.org/wiki/Autonomous_system_(Internet) ) blocking and for fun I have blocked all google ASNs.
Half of the internet stopped working.
Then I have expanded this to google, microsoft, amazon, facebook ASNs.
The whole internet stopped working. From all search engines I am aware of, only yandex.ru was still operational.
What you are seeing with beeping is just a tip of iceberg. The google is getting far more data from its cloud.
I don't believe that most of advanced users are aware of, how deep the rabbit hole of internet centralization has gone.
And until people figure out how important self hosting actually is, it is only going for worse (yeah, I understand how convenient, blah, blah... the cloud is).
The rabbit hole goes as far as locking yourself out of many government services. If you’re a Canadian, it means not being able to travel without submitting to corporate privacy policies and ToS (ArriveCan apps/website).
Then I have expanded this to google, microsoft, amazon, facebook ASNs.
The whole internet stopped working.
Neither am I delighted to have my machine talk to Cloudflare or Akamai (per https://news.ycombinator.com/item?id=32618098). Add to that a few font, framework services and ad delivery networks and why bother having any independent servers at all?For decent people there is no privacy, but, for malicious people, it is more than enough privacy to avoid accountability. That's no surprise today, but who would have looked forward to a net like this back in the 1990's?
Just scrap everything and start again. What we have now is a failed experiment.
what's your concern around CDNs? Its not like its viable for every company to put in 1000s of edge nodes to ensure every area of every country has a good website/app experience.
Its not like its viable [...]
I agree. That's why I ended by writing "Just scrap everything and start again. What we have now is a failed experiment"Nextdns (lazy man's pihole) does a decent job of adblock and seems to stop stuff like Braze tracking from working.
[Edit: apparently this is more encrypted than I was thinking, so the next bit is probably wrong.] They could potentially look inside the VM to look at the specific data on the other side of TLS.
Which is quite similar to meta data that's collected on phone calls, such data is regularly the basis for governments killing people [0]
[0] https://www.justsecurity.org/10311/michael-hayden-kill-peopl...
Some apps will do one DNS query and cache the IP they get, so maybe what you're seeing is them using IPs they cached before you rigged up this custom network situation.
You're saying this like it's not the point. Six or seven companies control the internet and have root and logs of all incoming traffic on ~all servers.
No it wouldn't.
At this point it could be revealed tomorrow by mountain of incontrovertible evidence and most people would shrug, move on and ask "what next?".
Snowden. Shrug. Cisco backdoors. Shrug. Pegasus. Shrug. Solar winds. Shrug...
The past decade can be described by the pattern "It would be a terrible scandal if X happened", and then precisely X happens. Then we normalise to it.
> Have I missed that scandal?
You may say it semi-sarcastically, but of course the irony is that actually you very well could have misse it. You only need to take a vacation for one week, a major shitstorm hits the front pages and fades from the news cycle. Now it's the "new normal".
The important point is, you might never know. Without homomorphic encryption you simply have to trust entities that have the means, the motive, the opportunity and the track record for screwing you over.
This is Blotto front exhaustion and fatigue in action. It's in the counter-terrorism literature. When you're under attack on many fronts, and adversaries regularly create new ones, and attacks are frequent but random, eventually some get through.
And I very much consider "big tech" to be adversaries in the civic cyber-security game, because they can and will do whatever would make them money, bending and breaking laws, covering up wrongdoing, silencing critics and smearing whistleblowers. They've done so reliably for years.
Perhaps at issue is what we think a "scandal" is.
Scandals used to be mainstream news events that caused widespread public discontent, led to lengthy investigations. government reports, companies being fined, shut down, careers being ruined, even suicides and jail time....
Today the word has lost its currency. Data leaks were once scandalous but we long passed the point when weekly and then daily major breaches lost the interest of the media. By definition, news has to be something new. Otherwise it's "Oh-Dearism". Again, company X installing malware and spying on you is hardly raising eyebrows. People are coming to expect it.
I'm not making a point of moral outrage, or even passing much by way of judgement here. It's just what's happening. But the essential "criminality" of big-tech (if only in spirit not letter) does have profound implications for the future of digital technology, and we should not ignore it. The possibility that the main players have been silently compromising rented VMs for reasons other than mandated law-enforcement should not be lightly dismissed.
I'm curious to know what you think the mechanism/psychology is at play in the "people not caring", other than the fatigue factor I mentioned.
And theyre now still painted as the bad guy for "censoring".
The censoring makes the western internet quite hard to use without vpns (or last time I was there, Google Fi seemed to not have to go through the firewall and routed the traffic through Europe somehow?)
Windows laptops from OEMs frequently come with backdoored https implementations and nobody cared after the first one.
Dell business laptops come with malware that sends videos and photos to ukraine and israel and nobody cares.
It won't even be a blip when they are caught doing it.
Cloud providers made themselves the best solution for a lot of services.
I've also done AS blocking (preventing certain IPs from getting a free compute trial without human intervention; this was back in the crypto days), and indeed, blocking the networks that you did is great for getting rid of bots and harms 0 legitimate users. (I think the big culprit is "free for open source" CI systems; they tend to be hosted on the major cloud providers and I found those doing a lot of command-and-control. I'm surprised those are viable to keep around for free, though.)
Self hosting is a huge undertaking and one really has to justify the value proposition, especially for people who want a presence on the internet but don't want their full-time job to be internet administration.
What are the major differences from a layperson view? Is spinning VMs on your hardware that much harder than doing it on other people's computers? It's an honest question because I haven't done both
I worked at a small company where we planned for 24/7 uptime before clouds were ubiquitous. We planned out which of the three engineers in the team would hold the pager and the cost of gas reimbursements for them to drive one state over to deal with the machine in the secured rack facility if it physically went down. We didn't have nearly enough bandwidth capacity to our building itself to support the traffic we anticipated for our service.
Smaller projects that don't require 24/7 uptime can be self-hosted, but you still want to be aware of fabric-layer security... If you're hosting on a machine in your building and somebody roots it, what will physical access to your intranet let them get away with? Can they see source code from there? Financials? Employee database? All of this is less a concern if you're using AWS with separated instances that are no more connected to each other than Netflix is to Disney+, even if they're in the same building.
Cloud hosting lets you focus on the software and credentials and pay someone else to focus on hardware and application of credentials.
Low hanging fruits like cloud storage, web hosting, VPN are fairly easy to setup and self maintain.
> The whole internet stopped working.
Not that surprising, considering these companies already had direct influence over 70%+ of internet traffic back in 2014 [0]
By now that number is probably in the 80-90% range as it's a problem the vast majority of people are either completely unaware of, or sometimes deny it to be even a problem in the first place.
[0] https://staltz.com/the-web-began-dying-in-2014-heres-how.htm...
172<<24 + 217<<16 + 23<<8 + 110 = 2899908462
Saves 4 whole keystrokes if you quickly want to ping something to test connectivity.
So if you own some 31.x block, you could have a phone number which matches your IP.
I think I'm wrong, it was about the 10-digit Dutch numbers.
[0] https://en.wikipedia.org/wiki/Universal_Personal_Telecommuni...
The US phone system had such a service for a few years (area code 500 iirc). It had so little uptake that it was shut down.
#!/bin/ksh
Die() {
echo Bad IP
exit 1
}
[ $# = 1 ] || Die
[ ${1%%?*.?*.?*.?*} ] && Die
I=$1
until [ ${#I} = 0 ]
do
J=${I#[0-9.]}
[ ${#I} = ${#J} ] && Die
I=$J
done
I=$1.
typeset -ui N=0
while [ $I ]
do
J=${I%%.*}
I=${I#$J.}
[ $((J>>8)) = 0 ] || Die
N=$(( (N<<8) + J ))
done
echo $N
# End man inet_aton
[…] int inet_aton(const char *cp, struct in_addr *inp)
[…]
The address supplied in cp can have one of the following forms:
[…]
a The value a is interpreted as a 32-bit value that is stored
directly into the binary address without any byte rearrangement.
https://manpages.debian.org/stable/manpages-dev/inet_aton.3....And it is a regular ip address, just written differently :)
https://www.lookip.net/ip/172.217.23.110
Funny I wasn't aware of this despite 25 years of being an Internet user
You're not alone… I been using the Internet longer'n that and I didn't ever think of converting an IP address to a decimal number either. It makes perfect sense now that it's been pointed out, but for some reason it just never crossed my mind to even try it.
The "special" case is supporting network addresses to be written as 10.2932832 ("convenient" for class A's), 172.16.61031 (ditto for B's), or just one big address like 39282329, when we're used to 4 octets separated by dots.
Not every bit of host software supports these cases anymore, as basically their sole remaining use case is as a curiosity or to circumvent bad security controls.
Maybe having Russia not being part of the same monopoly is actually a good thing for the internet.
except no company actually does this
This is not a jab at linux, I wouldn't know how to do that with MacOS either; the default Cmd+Shift+5 video capture tool doesn't allow recording internal sound.
I'm surprised that in 2022 this task can still be so problematic.
>If you would like to screen record on your Mac with audio, you can use the QuickTime Player provided by Apple. Select it from your applications folder and then go to File > New Screen Recording from the top menu bar.
https://www.geeky-gadgets.com/screen-record-on-mac-with-soun...
BlackHole adds a loopback audio device which can be used with the default video capture tool (select the loopback device in the options menu after pressing shift-command-5).
To be able to play audio from the speakers while you're recording, you need to add a multi-output audio device in the macOS "Audio MIDI Setup" app. Switch to the multi-output device by option-clicking the audio icon in the top menu bar. Now both the speakers as well as the BlackHole audio device will receive audio.
You can also use ffmpeg to create a "screencast" with sound and it's just a couple of extra command-line options. E.G. the options
-f pulse -ac 2 -i default
work well for me.Of course, if you don't know this or your machine's setup well, and you happen to have another device lying around, you're prone to pick it up and make the video that way instead.
Which may be harder because then you have to get the video off the other device somehow. Lol, epistemology is an interesting field.
A simple one is to monitor any access to files inside a directory:
inotifywait -r -m . | ./teller
You could also beep on important events in your own log files, beep for each request that hits your socket, or set up the runtime to tell you when the garbage is collected.(over 200 comments)