Tracking your Internet usage for PM chat

Discussion in 'Markets & Economies' started by boneyard, Sep 28, 2012.

  1. capt.sparrow

    capt.sparrow New Member

    Joined:
    Jun 3, 2011
    Messages:
    379
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    U ASS
    and that would make it alright??
     
  2. capt.sparrow

    capt.sparrow New Member

    Joined:
    Jun 3, 2011
    Messages:
    379
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    U ASS
    Our privacy laws are an absolute farce. The article proves that
     
  3. goldpelican

    goldpelican Administrator Staff Member

    Joined:
    Jun 29, 2009
    Messages:
    17,648
    Likes Received:
    581
    Trophy Points:
    113
    Warrantless data access is for surfing history etc from the ISP - the data in the database for Silver Stackers is essentially private property of the business operating the forum - I would need to check the legalities but if the hosting company where the website is hosted was to simply hand a copy over on request without a warrant they would be in breach of the Privacy Act - assuming the host does more than $3m/pa in turnover.

    Forum is moving shortly to one that definitely does anyway.
     
  4. GoldenEgg

    GoldenEgg Member

    Joined:
    Mar 10, 2012
    Messages:
    230
    Likes Received:
    22
    Trophy Points:
    18
    Is there any international obligations? Would hosting the website on an overseas hosting co/server make any difference in regard to handing over information to the feds?
     
  5. goldpelican

    goldpelican Administrator Staff Member

    Joined:
    Jun 29, 2009
    Messages:
    17,648
    Likes Received:
    581
    Trophy Points:
    113
    Would make the website slower for the 80% of Australian users...
     
  6. petey

    petey Active Member Silver Stacker

    Joined:
    May 19, 2010
    Messages:
    1,043
    Likes Received:
    7
    Trophy Points:
    38
    Location:
    Luxembourg
    I clearly said that I wasn't on board with it. I just suspect that of the 3,400 Australians that have been spied on, 2,000 of those are new employees of government departments, being fully aware that they are being "spied upon".
     
  7. capt.sparrow

    capt.sparrow New Member

    Joined:
    Jun 3, 2011
    Messages:
    379
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    U ASS
    I believe your suspicions are misplaced - along with your trust.
     
  8. metalzzz

    metalzzz Well-Known Member

    Joined:
    Sep 3, 2011
    Messages:
    1,977
    Likes Received:
    86
    Trophy Points:
    48
    Location:
    Australia
    [​IMG]





    Going to have to move office again, we are under attack!
     
  9. Richie

    Richie New Member

    Joined:
    Jun 21, 2010
    Messages:
    158
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Sydney, Australia
    I'm surprised no-one has mentioned SSL encryption to protect the traffic between your computer and the SS server as well as verifying you are actually talking to the SS server ;).

    For ~$20 a year it's a nice little security/privacy boost as long as the servers can stand up to the extra load.
     
  10. fishball

    fishball New Member Silver Stacker

    Joined:
    Apr 11, 2011
    Messages:
    6,509
    Likes Received:
    1
    Trophy Points:
    0
    Location:
    Shin Sekai Yori
    SSL is still prone to MITM attacks.

    With enough resources somebody could spoof a certificate and most people would be none the wiser.

    Back in my olden days on IRC we used a customized encryption system based on twofish and encrypted all of our chats.

    I think something like that is way overkill though for what we're doing (which is totally legal anyway).

    If you really have to do something questionable, perhaps don't do it on a public forum? :)
     
  11. hawkeye

    hawkeye New Member Silver Stacker

    Joined:
    Nov 10, 2010
    Messages:
    2,929
    Likes Received:
    4
    Trophy Points:
    0
    Location:
    Perth, Australia
  12. Richie

    Richie New Member

    Joined:
    Jun 21, 2010
    Messages:
    158
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Sydney, Australia
    Yes it is, but it will also throw a certificate error up and (hopefully) an educated user would not continue. Granted this is the biggest failing of the SSL/TLS standards.


    I love to see some literature or a POC on this because I don't believe this is possible. You can self-sign a cert when doing a MitM or steal the real cert and use it to inspect the flowing traffic but i've not seen anything that can spoof a cert without generating the aforementioned error message.


    If the site is passing any sort of sensitive information (such as passwords) then it really should go across SSL/TLS anyway.
     
  13. Echtes-Geld

    Echtes-Geld New Member

    Joined:
    May 31, 2011
    Messages:
    16
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Germany
    You talk a lot of detail about side issues but looks like most of you missed the main message.

    I think this is normal for apathetic people who live in the moment and cannot see what lies before them.

    Once you reach the stage where countries like Italy and Greece are now - and you will - and the state starts to make greater use of these abusive powers it has taken from under your noses to take whatever "taxes" it thinks appropriate and force on you all other forms of rules like stopping you moving your money out of currency then I believe more people will awaken from their slumber?

    Unfortunately by then it will be too late.
     
  14. fishball

    fishball New Member Silver Stacker

    Joined:
    Apr 11, 2011
    Messages:
    6,509
    Likes Received:
    1
    Trophy Points:
    0
    Location:
    Shin Sekai Yori
    There have been plenty of examples over the years.

    http://it.slashdot.org/story/08/12/23/0046258/perfect-mitm-attacks-with-no-check-ssl-certs

    First one I google'd up.

    Basically you can hijack a legit cert distributor and make your own "legit" certs.

    No error messages and no nothing.

    Have you checked what certs your browser allows without question?

    Here's mines:
    [​IMG]

    Do you vet each and every company on that list to determine they are legit?

    I know I don't.

    I most certainly know that your average computer user does not.
     
  15. Richie

    Richie New Member

    Joined:
    Jun 21, 2010
    Messages:
    158
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Sydney, Australia
  16. Yippe-Ki-Ya

    Yippe-Ki-Ya New Member

    Joined:
    Feb 23, 2011
    Messages:
    5,465
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    The Land of Guilty by Default
    -1
     
  17. Yippe-Ki-Ya

    Yippe-Ki-Ya New Member

    Joined:
    Feb 23, 2011
    Messages:
    5,465
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    The Land of Guilty by Default

Share This Page