Ars tests Internet surveillance by spying on an NPR reporter
arstechnica.com
arstechnica.com
I was also quite surprised by Google's HTTP Maps flaw in HTTPS search. I'd have previously imagined this would be a standard security pentest that Google products would need to go through. Given how pervasive and important Google is to the digital ecosystem, even small flaws can have a profound impact.
I'll again state that this is why I feel so strongly that Google Analytics should be updated to be HTTPS by default[1]. If you hit a non-HTTP site, you're leaking all the information you would send to Google Analytics to anyone that's listening -- it goes across the wire unencrypted. Considering Google Analytics is on 60+% of the top 100,000 domains, this is a lot of information leakage. Referrers, time on page, browser details, operating system details, everything that Google shows a webmaster in Google Analytics also ends up in the hands of the passive observer.
[1]: http://smerity.com/articles/2013/google_analytics_and_nsa.ht...
I fully agree with you but one small little issue here, wouldn't that violate the 'everything over https or nothing over https' rule for what's displayed on a page? In other words, wouldn't your browser balk at this if it were implemented?
Mixed http/https is frowned upon, and rightly so!
You can actually force Google Analytics to use HTTPS on a HTTP page[1] with _gaq.push(['_gat._forceSSL']) but it's not the default. If it's not the default, it's not going to be used heavily across the hundreds of thousands of pages using Google Analytics. Privacy death by a thousand cuts.
[1]: https://developers.google.com/analytics/devguides/collection...
Maybe something for the likes of ghostery or adblock to implement?
I don't see any issue with loading an HTTP site and then making an HTTPS request to Google Analytics. It's better to secure part of an insecure page than to leak part of a secure one.
This is why I'm a fan of RequestPolicy.
But on my phone I'm powerless. How do I know what each app is capturing and transmitting in the clear? If even Google searches don't use SSL, what hope is there for other apps?
That might help with the casual Wi-Fi snoop in the coffeeshop, but it's still hoovered up once it leaves the VPN.
The point of the article was not the hostile AP, but to simulate a pervasive threat:
we would create a pint-sized version of the Internet
surveillance infrastructure used by the National
Security Agency... Porcello would become our one-man
equivalent of the NSA’s Special Source Operations
departmentThe broad surveillance of any practical intelligence apparatus only bothers to do that to target actual subjects of interest, and don't have infinite leeway to not produce results while doing it - i.e. if the NSA produces no useful intelligence on Al Qaeda for a few months, they're looking at budget cuts.
Or to put it another way: how many man hours did they expend on this effort, and how many people do they actually think work for the NSA? It's certainly not "millions".
These guys were manually viewing wireshark dumps. Obviously they're going to spend a lot more time to get the same info when working at such a low level, with no access to any of the automation tools the NSA uses.
https://blog.torproject.org/blog/mission-impossible-hardenin...
Of particular interest to me was how the captive portal detection reports back to Google everywhere you connect even if everything else is disabled.
That's an incredible waste of bandwidth for no improvement in privacy whatsoever. If HTTPS pages were including GA over HTTP, then yes, this would be an issue, but you're already requesting the page over HTTP, if you're getting GA over HTTP. There's simply no advantage whatsoever -- for privacy, security, or anything else -- to using HTTPS for this script. It doesn't make any attack harder in any way, shape, or form -- it just makes pages slower and more expensive to load.
Of course, you may still be right in that it adds no privacy, but I wouldn't call it an "incredible waste" (particularly not of bandwidth), since the cost is really quite low.
Given that there really is no privacy benefit, I can't imagine why you would take on that overhead; Google clearly agrees, or they would've turned on HTTPS by default.
Usage of unencrypted Google Analytics + Google cookies[1] means that you don't need to eavesdrop on individual connections, just one small set: the endpoints to the Google Analytics servers.
Hence, the NSA or other large entities have an economical way to tap a large portion of web traffic.
[1]: http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10...
Admittedly, it is a smaller number of endpoints than monitoring every site in the world (that much is obvious), but it's not one or two -- they're all over the place.
But even ignoring that, it really comes down to one thing: Google Analytics can't possibly make an HTTP site any less secure or less private -- you're sending a postcard with your personal details on it a million times a second! It may in some situations make it slightly (very slightly) easier for someone to snoop on a tiny bit of info about your traffic, but the fix for this isn't to make that harder, it's to make it harder to snoop on your traffic entirely. We already have a solution for this: ubiquitous TLS.
IMO, this is slapping a band-aid where your arm used to be; trying to increase the privacy of HTTP sites is a fool's errand and a complete and utter waste of time.
[1]: https://www.pwnieexpress.com/penetration-testing-vulnerabili...
[2]: https://www.globalscaletechnologies.com/p-58-mirabox-develop...
I think for the particular purposes of this investigation, the Pineapple would have made a fine substitute for the PwnPlug R2.
Depending on your wifi card and drivers, it would also be possible to run something like Jasager or Karma on a laptop instead of a specialized wifi base station (although then you have to dedicate your laptop to the surveillance function instead of using it for your own regular laptoppy purposes).
I mostly pointed it out because I've used the Mirabox for a bunch of projects and recognized it in the picture. Its a great little ARM box with 2 gigabit ethernet ports (hard to find a on dev board)and 2 USB 3.0 ports.
The Mirabox comes with the Marvell fork of uBoot which is unfortunately quite old. It doesn't have support for device-tree, for example. I'm not aware of a newer working version from either Marvell or Globalscale. There was some initial work to get Barebox working on the Mirabox, but it is very feature limited.
On the plus side, you don't need a JTAG console to reflash the bootloader. Lots of Marvell SoCs support booting over a UART connection using an Xmodem protocol[1][2]. So you can reflash/unbrick your Mirabox using just the USB serial port. (I think that the Dreamplug also supports this protocol, but I have never tried to use it on one.)
[1]: http://git.pengutronix.de/?p=barebox.git;a=commit;h=0535713b...
[2]: http://git.pengutronix.de/?p=barebox.git;a=commit;h=6bb3a08c...
This was the situation with the Dreamplug before it got mainline uBoot support. Is there any hope for the Mirabox?
https://www.pwnieexpress.com/penetration-testing-vulnerabili...
https://www.globalscaletechnologies.com/p-46-sheevaplug-dev-...
I don't begrudge them, they assembled it and created a simple to use interface for administration, created docs and bundled it for one price. It's worth the money for some people.
That is awesome! Hopefully it also nudges Google to audit their properties for similar leakages to plug....and everyone else for that matter.
In the decade between this type of data collection becoming possible and the mass populace becoming concerned about it, I fear we've passed a threshold we can't un-cross. This type of technology is so intertwined in our daily lives that avoiding it isn't a realistic option.
Things like Apple using random MAC addresses to scan for Wi-Fi APs are a start; but too many devices (Android included) use default settings that are far from secure. But it's up to the companies that make usable, mass-market devices to ratchet up the security, and I fear that they have little incentive to do so when their own ambitions include the same type of data collection.
Have you considered trying this, or some implementation of it?
I, for one, would like to see websites that didn't install any tracking software. Specifically, I mean no Google metrics. If there was a news website that didn't install any tracking software, but instead just offered pages with cryptocurrency addresses, I would switch to that as my default news source in a second.
Stats is hard? Find some software that does if for you. Better yet, figure out how to do some of it yourself (it's not paritc8ularly hard). Or hire some statisticians. This way, you free your business from being dependent on a 3rd party.
But, as a corrolary, what if Google Analytics alters the content in a way that makes it less useful? The obvious example here is clickbait articles (See, Clickhole), but I think there's other more subtle problems here. Isn't the job of a reporter to report what _they_ think is news, rather than what people want to read?
Beyond that, I am troubled by the spying on people. It occurs to me that even if I remove Google Analytics from my website, anyone coming to or going from my website will be subject to monitoring by Google. It's not exactly opt out.
Microtransactions are hard, though, that problem still hasn't been solved.
No you wouldn't. You might be hard-minded enough to try and commit to it, but instead you'd almost certainly just stop reading any news...then go back to aggregators/blogs whatever.
It's a well studied problem that as soon as something becomes not free, people change their behaviour dramatically.
Of course, if you really don't care about the news (and broadly normals news websites are pretty useless to me), then you can cheaply skip a step...
Yes I would. I do soft boycotts of all music that isn't Creative Commons, and movies by major media companies. I've listened to almost exclusively free music for years. (Libre music for close to 6 mo.) I still go to movies sometimes, but who cares? The point of a boycott isn't necessarily to hurt a company's revenue, it's also to drive change in consumption habits.
I'm not trying to quit the normal web altogether, I'm just saying that if there were ONE news website that didn't have tracking software installed, I would switch to it as my default news source. I can't say for sure if I would donate to articles via a bitcoin link, but I would imagine it would be optional.
HN is nice, but it's just an aggregator. Even though it doesn't have tracking software, everything that it links to does.
EDIT: Oh, and I meant to say, I have indeed switched to a dumbphone, and I use a VPN. I still use bank related services, but I try to use bitcoin when I can. I have no illusions about its anonymity, I just try to vote with my feet and my dollars. Just because there are a lot of consumers who don't change their consumption habits doesn't mean that some won't.
The point I was making was that the act of knowing that every click through was costing you some small but real amount of money, would change your behavior dramatically.
So that's the challenge: you need no tracking, but no obvious fees either.
Even if you did this it doesn't guarantee that your data doesn't travel through data centers you would rather it not travel through, right?
That seems like somewhat of an apathetic attitude to have. Try living without internet for a week, or even a day. It isn't so bad.
I think in the same way that we who live in an exceptionally wealthy society often get little practice in giving things up, but that this practice might be beneficial. It's not a very original observation to notice how having so many resources and opportunities and conveniences available to us makes us feel more and more dependent and averse to every sort of inconvenience.
As a vegan, I always find it remarkable how emphatically people feel that it would be impossibly difficult for them to go without eating animal products, or that they can't imagine how someone could possibly manage without them. Maybe that's literally true in the Aleutian Islands or the Australian Outback or something, but not so much in New York City or Portland, where one could eat in a different restaurant every day for a year without running out of vegan entrées to order directly off the menu.
But there are plenty of resources and technologies that I have that my parents and aunts and uncles grew up and lived and worked without for decades and that even today most of the world's population doesn't use—but that it's hard for me to imagine life without. (When I visit friends in Brazil, they don't have a machine to dry their laundry, but use a clothesline, the way almost everybody in history has done it, and to my amazement the clothesline still works OK. It's not even much more labor, just more latency in the clothes-washing process.)
The habits we form from being well-off and having so much access to everything we want, worry some people because they consider how something could go wrong and there are skills we might need that we haven't developed. (We might also feel more acute suffering from losing what we're used to; psychologists have documented that losing what you had is consistently perceived as a much greater cost than failing to gain what you didn't have.) War or social unrest or natural disasters or ecological disruption could strike middle-class city dwellers pretty hard because we mostly don't know how to grow food, how to fix things, and so on.
But another consequence of our abundance of resources and choices, one that I think is more core to what the parent commenter is getting at, is that when we become dependent on technologies and products and resources, our demand curve for them shifts. The people who supply these things to us have more power over us in terms of extracting money or concessions, because we and then understand that we're unlikely to actually give up our habits. That has consequences in terms of the difficulty in resisting changes that harm us (a classic example is if an Internet service changes its privacy policy in a way that reduces existing users' protections; service operators know that very few people will stop using the service even if most users dislike the change). It also means that the prospect of boycotts over ethical issues that affect others is dimmer. Manufacturers think that there's not that much chance many people would actually stop buying something because of disagreements with how it was made.
I think it would be amazing to have a culture where people commonly had the experience of successfully giving up a habit or a product that they liked quite a bit, without being forced to, just as a result of a conscious choice. My Catholic friends often do this once a year during Lent (the religious tradition in many communities used to be to give up specific foods, but many people today interpret it more broadly and personally pick something to give up temporarily—normally, something that they enjoy and that it will be an effort for them to give up). From what I hear, many people find it satisfying and empowering when they succeed. And following Scott's idea, it might be good practice for when you decide that you do have an important reason to give something up.
The darker later parts of the documentary make me think that we have a lot of practice celebrating people's power of choice and freedom from constraint (which I fully agree with). We have a lot of recent experience saying yes when there's no reason not to. What we perhaps haven't been practicing as much is saying no at those times when there is a reason to.
The better question to ask is "will being off the grid actually solve the problem?"
Because plenty of people aren't on the net in Syria, Iraq, Afgahnistan...still doesn't really work out.
I'm shocked.
I suppose from there it'd be in the clear, but at least it'd stop snooping at an ISP level. Or am I missing something, and would it be useless?
So the other folks in Starbucks won't know what Reddit comments I'm leaving :p