Privacy, Schmivacy

Matt Drudge has an interesting story about Condi Rice out at a big gathering of Republican Establishment types, probably making her pitch to be the Romney’s VP nominee, but this isn’t about that.

Because of the chronic problem I have with poorly maintained (or abandoned) web sites attempting to infect visitors, I do most of my browsing now with Firefox and an addin called NoScript

http://noscript.net/

It looks very deep into what web sites are doing and blocks attempts to do sneaky things – the most common being what are called “Cross Site Scripting” attacks.   They come in lots of flavors, but the general idea is that you visit  acme123.com’s web site, and either because they were hacked or fooled, or perhaps on purpose, a script on  weRHackerz.com.ru tries to run, possibly because you have acme123.com in your “trusted” zone.

So I clicked on the link, which is nothing but a link to news.yahoo.com (what follows is not Matt Drudge’s “fault”…   I hear the “Alert” sound NoScript has blocked something  -which usually gives me a detailed description of what was blocked and why – but the screen immediately switches to the news story so I couldn’t see the warning being reported and act on it.

After maybe a half dozen retries, I was able to get a screen capture:

What it is telling me – clicking on that link, fired off 34 different scripts, most are companies I recognize as being in the tracking business for advertisers.   NoScript allows 29 of 34 scripts to run, and blocked the remaining 5 as suspicious.

This entry was posted in Technology. Bookmark the permalink.

5 Responses to Privacy, Schmivacy

  1. Art Stone says:

    A few days ago, a manual scan I started using Microsoft Security Essentials detected a very recent exploit that allows someone to “escape” from the Java Virtual Machine “Sandbox” and do pretty much anything they wanted (like install Stuxnet)

    http://blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-case-of-jre-sandbox-breach-cve-2012-0507.aspx

    has a very detailed description. This is very evil stuff and not likely being done by a 13 year old in Bulgaria. I don’t think it actually did anything to my computer, but it’s pretty hard to know for sure. A “rootkit” is a thing it could have installed that hides all evidence that your computer is infected – creating an unknown that you can’t know. There are rootkit detectors available, but they generally work by looking for indirect signs. Booting from external media and then checking the disk for rootkits is more reliable – but that relies on your trust in the people who wrote the rootkit detector and that the rootkit detector itself hasn’t been infected by something.

  2. popsmayhem says:

    Well now ain’t that sneaky!!

    I am going to get the no script add-on, might save a few headaches in the long run.

    • Art Stone says:

      The default (which I turned off) is to not run any JavaScript unless you give explicit permission for a domain to be trusted… But once you do that, you are essentially giving permission to allow 3rd party scripts to run and do things like share tracking cookies. Few websites will work fully without JavaScript.

  3. Parrott says:

    awesome recommendation Art, Thanks !!

    • Art Stone says:

      Be aware that if you go with the recommended settings that disallow all javascript unless you specifically allow it – many streams will break. You might also click something (like opening preferences here) and getting no response, or incomplete actions. If you right click on the page, there is an option to talk to noscript and it will show you things it recently blocked, with an option to allow the script to execute (temporarily or always)… so you’ll find things like Google Analytics on almost every web page, and quantserve on many of them. It becomes trial and error to see which javascript piece has to run.

      Being the paranoid person that I am, I worry about jquery.com. It’s an opensource javascript library widely used on MANY, many web sites. You really can’t block it – but if some day some hacker added in malicious code, overnight almost every internet connected computer in the world would be infected.

Leave a Reply