Showing posts with label anonymization. Show all posts
Showing posts with label anonymization. Show all posts

Sunday, October 2, 2011

There's little privacy in a digital world

From the LA Times,

During his two-hour morning bike ride, Eric Hartman doesn't pay much attention to his iPhone.

But the iPhone is paying attention to him.

As he traverses the 30-mile circuit around Seal Beach, Hartman's iPhone knows precisely where he is at every moment, and keeps a record of his whereabouts. That data is beamed to Apple Inc. multiple times each day, whether Hartman is using his phone to take pictures, search for gas stations or check the weather.

And it's not just the iPhone that's keeping track.


Continue reading here

Facebook Targeted in Group Privacy Suit Over Internet Tracking

From BusinessWeek,

Facebook Inc., the world’s most popular social-networking service, was accused by users of the site in a class-action lawsuit of secretly tracking their Web activity after they log off.

The company assures users that “cookie” files installed on their computers to identify them and track their interactions with Facebook applications and websites while they are logged on are removed when they log off, according to a complaint in federal court in San Jose, California. Facebook admitted on Sept. 26 that the cookies track users’ Internet activity after they log off, according to yesterday’s complaint.


Continue reading here

Thursday, October 28, 2010

When You Think You Surf Anonymously But You Don’t

From Roman Huessy at Abuse.ch ...

Many companies, military- and governmental-networks have banned social networking sites like Facebook, Twitter, MySpace &Co from their networks. For instance in August 2009 the U.S. Marine corps just banned Social Networking Sites (SNS) from their classified network.


Roman continues,

Often there are (legal and comprehensible) reasons to ban SNS from coperate- an governmental networks. But the problem is that often the responsible persons and/or administrators who decided to ban SNS don’t know the consequences that such a ban can trigger. Let me ask you: Do you really think that users will accept a ban of their *most-favorite-websites*? Of course most of the user won’t, so they will start trying digging holes in your coperate firewall and webproxies/gateways. The point I would like to outline in this post are the consequences you will trigger when banning social networks as well as the risks/threats which result out of this.

As said before, most user won’t accept a ban of SNS (and please belive me: that’s fact ). The first thing they will do after your ban becomes active is googling about by-passing your security infrastructure. The first thing your users will come accross are PHP-based web proxy scripts. One of the most popular PHP-based proxy script is called Glype: It’s a tiny, powerful and fast web proxy which is based on PHP. You just have to download the ZIP file, upload the “upload” folder to a webspace and start using your brand new webproxy. But WOW – hey, you even don’t have to install your own web proxy, you just can use sites like proxy[dot]org and get a fresh list of 5’000+ working web proxies!

What sounds like honey being poured down their back to your users is purly pain for the administrators and security folks of companies and governmental organizations: Within a few minutes users will be able to bypass security gateways easily. But let’t talk about the security risks of such Anonymous web proxies.

*** The bad things you don’t know about such proxies ***
Unfortunately the other site of the coin looks much worse:

You don’t know who run these proxies
You don’t know if these proxies are secure and clean from any malware and drive-bys
You don’t know the intentions of the persons who runs these proxies (maybe they have mean ill?)

But you have must be aware of one fact: Those proxies aren’t anonymous! Web Proxy scripts like Glype&Co have a free configurable option wheter the administrator of the (glype-) proxy wants to log the requests which are passing his proxy or not. And you can be sure that the most Glype administrators will do.

Let’s take a deeper look at the origin IP addresses which are using such Glype proxies. A huge part of the Glype users are users from:

Educational networks like schools and univiersities (trying to break the blockade of Facebook&Co on Edu-Networks)
Home users from DSL- and dialup accounts (trying to bypass the internet censoreship of their ISPs/country)
Beside those (mostly) legitimate traffic (generaly I don’t support internet censorship in any country – so in my opinion this is some kind of legitimate traffic), there is a lot of noise coming from governmental and military networks around the world. I wont name any countries, but you can be sure that dozens of countries are affected. Some of the affected departments and ministries are listed below (I have translated the most of them from other languages, so don’t assume all of them belongs to the US – they don’t):

Ministry of Foreign Affairs
Ministry of Finance
Ministry of Economy
Ministry of Statistics
Ministry of Administration and Interior
Ministry of Industry
Ministry of Interior and Justice
Ministry of Labour and Social Policy
Ministry of Social Development
Department of Defense
Department of Atomic Energy
Department of Health
Department of Science and Technology
Department of Home Affairs
Department of Water Affairs and Forestry
Department of Environment and Conservation
National Labratory
National Police Service
Residence of the President
Atomic Energy Comission
Centre for Atomic Research
State police
National Telecommunications Commission
Supervision and Administration Commission
State-owned news agency
Various Military Test- and Command Centres around the globe
Various networks which are just named as “Government of xxxx”


And Roman hammers his point home,

As I already pointed out I don’t see a problem in users bypassing internet censorship per se. They just have to know that they don’t really surf anonymously when they use such script based proxies (like Glype) and that those logfiles are propably accessible by anyone from anywhere.

But such proxies are becoming a problem as soon as they are used by employees of governmental and military organistaions (like shown above): These proxies could be a great resource for terroristic organization and foreign intelligence services! Many of the governmental traces I’ve seen are on facebook – so I was able to catch the names of employees of various governmental and military organizations. To show you the threat of such ‘information’ I will make real example which I saw in those logfiles.

You might have noticed that I mentioned Ministry of Foreign Affairs before (of a country which I won’t name here). While checking the logs I just came across a user who surfed on Facebook. The Logfiles provides a link to a profile of a employee of the Ministry of Foreign Affairs. When I checked the profile, I just noticed that this user is obviously a employee of the Security Service at the Ministry of Foreign Affairs. In fact, this person is now a high value target for terroristic organization and foreign intelligence services who are now able to get personal information about this person easily. This allows them to apply pressure and blackmail the person in order to gain access to classified information and documents.

*** Conclusion ***
My research on these Glype proxies allow me to make the following conclusions:


  • Glype- (and other script based proxies) aren’t really anonymous
  • You don’t know who runs these proxies
  • Most users for those proxies just want to bypass internet censoreship of their country or schools/universities
  • But there are many users from governmental and military organizations using those proxies too
  • In those cases you may be able to hide your web traffic from your administrator but you will leave traces in other places which are probably a threat of your whole company!
  • Administrators and security folks have to know about these risks and have to adopt compensating measures and/or providing awareness to its users
  • If you run such a Glype proxy you have to know that you will propably be responsible for any illegal activites which are passing your proxy. Are you sure that your Glype proxy is not being abuse to access ilegal content like Childporn?

Wednesday, February 17, 2010

Please Rob Me

Jennifer Van Grove from Mashable.com checks-in with a report about an interesting new website that highlights the potential dangers of social media networks with location sharing services like Loopt, Foursquare and Google Buzz.

The creators of the PleaseRobMe.com offer this description of their website:
The danger is publicly telling people where you are. This is because it leaves one place you're definitely not... home. So here we are; on one end we're leaving lights on when we're going on a holiday, and on the other we're telling everybody on the internet we're not home. It gets even worse if you have "friends" who want to colonize your house. That means they have to enter your address, to tell everyone where they are. Your address.. on the internet.. Now you know what to do when people reach for their phone as soon as they enter your home. That's right, slap them across the face.
As Van Grove points out, there is evidence that criminals are using information gleaned from these social networking services to do more than commit cyber fraud. In some cases, criminals are using this information to aid in burglary. In a separate report for Mashable.com, Van Grove wrote
Unfortunately, over-sharing of this variety has been known to cause adverse side effects. Most recently, Israel Hyman (@izzyvideo), a video podcaster, took a trip to the midwest with his family and twittered about the excursion. He came home to find that his house had been burglarized.


This site is just another example of how many in their rush to adopt the latest social media tool inadvertently share too much of their personal information.

Sunday, September 13, 2009

The Database of Intentions

On the surface our search histories do not appear to be particularly sensitive information and they are unlikely to reveal our identity. However, recent history demonstrates the flaws in this logic and show that our search histories can easily reveal our identity. In August 2006 AOL released 20 million "anonymized" search queries from approximately 650,000 users to the research community.

AOL anonymized these search histories by obfuscating or removing 'personally identifiable information' such as usernames and IP addresses. AOL replaced usernames with randomized unique identifiers.

Reporters from the New York Times analyzed these search histories and were able to identify user #4417749. The reporters noted that user #4417749 searched for
  • landscapers in Lilburn, Ga
  • 60 single men
  • homes sold in shadow lake subdivision gwinnett county georgia
  • several people with the last name Arnold
A quick reference of other outside sources lead the Times reporters to Thelma Arnold, a now 65-year widow living in Lilburn, Georgia.

This example reveals the false promise of anonymization. In particular, it is difficult for a database administrator to anonymize one data source when the administrator does not know what other data sources an investigator is able to access. In this case, the Times reporters were able to use the phone book or perhaps property records from Lilburn, Georgia. The combination of these data sources allowed the reporters to identify Thelma Arnold.