| Author |
Message |
2byte
Joined: 09 Oct 2006 Posts: 356
|
Posted: Tue 03 Aug 2010, 10:17 Post_subject:
Web attack knows where you live Sub_title: Privacy is dead people. I'm sorry. |
|
Heads up folks.
First demonstration of the true purpose of Google's data gathering?
http://www.bbc.co.uk/news/technology-10850875
| Quote: |
'Creepy' attack
Many people go online via a router and typically only the computer directly connected to the device can interrogate it for ID information.
However, Mr Kamkar found a way to booby-trap a webpage via a browser so the request for the ID information looks like it is coming from the PC on which that page is being viewed.
He then coupled the ID information, known as a Mac address, with a geo-location feature of the Firefox web browser. This interrogates a Google database created when its cars were carrying out surveys for its Street View service
This database links Mac addresses of routers with GPS co-ordinates to help locate them. During the demonstration, Mr Kamkar showed how straightforward it was to use the attack to identify someone's location to within a few metres. |
_________________
|
|
Back to top
|
|
 |
PaulBx1
Joined: 16 Jun 2006 Posts: 2308 Location: Wyoming, USA
|
Posted: Tue 03 Aug 2010, 13:22 Post_subject:
|
|
Now the question is, which routers are vulnerable? Is there a way to check our router? etc...
|
|
Back to top
|
|
 |
jpeps
Joined: 31 May 2008 Posts: 2449
|
Posted: Tue 03 Aug 2010, 16:39 Post_subject:
|
|
I just installed Ghostery plugin, which offers some help regarding trackers.
|
|
Back to top
|
|
 |
Lobster
Official Crustacean

Joined: 04 May 2005 Posts: 15109 Location: Paradox Realm
|
Posted: Wed 04 Aug 2010, 06:35 Post_subject:
|
|
| jpeps wrote: | | I just installed Ghostery plugin, which offers some help regarding trackers. |
Perhaps . . .
| Quote: | Ghostery FAQS
What is Better Advertising?
Better Advertising is a new type of company that brings trust to online advertising. We are an intermediary between consumers, advertisers, industry self-regulatory programs and government. We help consumers protect their privacy and keep quality content ad-supported and free. |
http://www.ghostery.com/faq
Perhaps not . . .
_________________ Puppy WIKI
|
|
Back to top
|
|
 |
jpeps
Joined: 31 May 2008 Posts: 2449
|
Posted: Thu 05 Aug 2010, 00:12 Post_subject:
|
|
| Lobster wrote: | | jpeps wrote: | | I just installed Ghostery plugin, which offers some help regarding trackers. |
Perhaps . . .
| Quote: | Ghostery FAQS
What is Better Advertising?
Better Advertising is a new type of company that brings trust to online advertising. We are an intermediary between consumers, advertisers, industry self-regulatory programs and government. We help consumers protect their privacy and keep quality content ad-supported and free. |
http://www.ghostery.com/faq
Perhaps not . . . |
Paragraph 2:
"Better Advertising is not involved in the collection or sale of any information for advertising purposes. We are not an advertising network or data collection service. We do not collect any data (behavioral or otherwise) for ad targeting, either by ourselves or by third parties."
So far, the ad-on has been helpful blocking lots of trackers. It also gives you information about each site it finds.
|
|
Back to top
|
|
 |
Pizzasgood

Joined: 04 May 2005 Posts: 6270 Location: Knoxville, TN, USA
|
Posted: Fri 06 Aug 2010, 19:33 Post_subject:
|
|
Change your router's default password, and that will solve the bulk of the problem from what I can tell. But I wouldn't be surprised if the router's MAC can be obtained in other ways.
Another thing you can do is simply change your router's MAC address. Many routers have that as an option in their web-based configuration. That would make any data Google has about it obsolete. And from what I understand, this data was obtained by the streetview crew, so if you live in a region that has not ben street-viewed (such as out in the boondocks where I grew up) you have no issue. Also, if you don't have a wireless router, or have changed it since they mapped you, you also have no issue. Your MAC address is useless to them, as they don't know it.
Here is the URL to his webpage about that attack vector, which apparently contains a demo for people using a Verizon FiOS router. I have encrypted the URL with ROT13 as a safety precaution, because this guy has been convicted of hacking in the past and I don't want some nooblet whining to me if anything happens while they're over there.
uggc://fnzl.cy/znckff/
_________________ Between depriving a man of one hour from his life and depriving him of his life there exists only a difference of degree. --Muad'Dib

|
|
Back to top
|
|
 |
John Lewis
Joined: 03 Dec 2007 Posts: 148 Location: Albany West Australia
|
Posted: Sun 08 Aug 2010, 09:14 Post_subject:
|
|
Grabbed this from Mepis forum. I gave it a try and the coods for me were pretty close.
John
Does Google know where you are? Try this terminal command and find out.
Edit: make sure curl is installed.
Working wifi device is required, too.
Link: http://foss-boss.blogspot.com/2010/08/bash-oneliner-get-gps-location-street.html
Basically it sends an iwlist scan of nearby wifi signals to Google, and then Google compares that with its known database.
|
|
Back to top
|
|
 |
tubby
Joined: 24 Jan 2009 Posts: 317
|
Posted: Sun 08 Aug 2010, 09:42 Post_subject:
|
|
| Quote: | | Basically it sends an iwlist scan of nearby wifi signals to Google, and then Google compares that with its known database. |
And if you weren't on it you could be now, nice one
|
|
Back to top
|
|
 |
John Lewis
Joined: 03 Dec 2007 Posts: 148 Location: Albany West Australia
|
Posted: Sun 15 Aug 2010, 09:29 Post_subject:
|
|
| tubby wrote: | | Quote: | | Basically it sends an iwlist scan of nearby wifi signals to Google, and then Google compares that with its known database. |
And if you weren't on it you could be now, nice one  |
Yes, Guess it might now have the list of nearby wifi but they won't be keyed to the GPS location as it would have been if it was working when they did your street.
I did notice that the street address they gave me was quite a way off.
John
|
|
Back to top
|
|
 |
|