republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Post a:
Post a:
AuthorAll Replies


swhx7
Premium
join:2006-07-23
Elbonia

reply to fAcEtIOUs

Re: Past BBR stories established Nebuad only monitoring

said by fAcEtIOUs:

following reasonable browser security settings can make the Nebuad monitoring moot.

By "make moot" I understand you to mean that avoiding the injected cookies and Javascript interferes with client-tracking efforts. That much is true, but it does not avoid having all one's packets going thru the data-mining machine. Theoretically (if the spybox company diverges from what they publicly say they'll do) it could still assemble a per-individual browsing history.

Also it seems to me (though I've only briefly glanced at the materials) that the user can avoid the Nebuad cookies only by manually evaluating each cookie, because the fraudulent ones are inserted in headers via forged packets. The browser can't tell that they're not from the site the user intends to accept cookies from.

And in the case of the Javascript, even with Noscript, I'm not sure there is any way to run JS from the real site without running the injected JS.


fAcEtIOUs
Premium
join:2002-03-03
kudos:4

said by swhx7:

Also it seems to me (though I've only briefly glanced at the materials) that the user can avoid the Nebuad cookies only by manually evaluating each cookie, because the fraudulent ones are inserted in headers via forged packets. The browser can't tell that they're not from the site the user intends to accept cookies from.

And in the case of the Javascript, even with Noscript, I'm not sure there is any way to run JS from the real site without running the injected JS.
From my reading of the tests done as laid out in the linked PDF report, blocking the cookies is possible because the cookies involved are clearly identified as coming from faireagle.com. Also the javascript is an addon at the end that also is marked as executing from the faireagle.com domain. So the javascript can be avoided.

Could Nebuad chg that? Maybe. But the way it is setup now, blocking is easily achieved.
--
My BLOG .. .. Internet News .. .. My Web Page


funchords
Hello
Premium,MVM
join:2001-03-11
Yarmouth Port, MA
kudos:5

said by fAcEtIOUs:

From my reading of the tests done as laid out in the linked PDF report, blocking the cookies is possible because the cookies involved are clearly identified as coming from faireagle.com. Also the javascript is an addon at the end that also is marked as executing from the faireagle.com domain. So the javascript can be avoided.

Could Nebuad chg that? Maybe. But the way it is setup now, blocking is easily achieved.
Sure. They can change the faireagle domain to something else, to thwart your blocking. Domains are very cheap and you can't block the dictionary. Hell, they could inject 10 different javascripts into each page, until one eventually gets followed.

They can forge HTTP redirects to drive you to the nefarious code, instead of using javascript to do it. I think this is similar to what Phorm is reportedly going to do now.

They could also make deals with web portals so that the nefarious script doesn't have to be forged at all. They buy ad space or even a 1x1 pixel, that ad server realizes you're from an IP address with a NebuAd deal, the ad server loads you up with their profile-identification cookies, and no forgery ever takes place. Fortunately, this won't be allowed to happen by the best services. Most Yahoo's and Google's of the world actually are fans of the Internet and ultimately side with the user, despite our cookie-erasing habits. They don't want 24/7/365 eavesdropping on the internet, either.
--
Robb Topolski -= funchords.com =- Hillsboro, Oregon
HTTP is the new Bandwidth Hog...


deitarion

@teksavvy.com

And NoScript is based on Javascript whitelisting, so they'd have to embed the JS into the page and hope that the user is viewing a site they've granted JS execute permission to.



funchords
Hello
Premium,MVM
join:2001-03-11
Yarmouth Port, MA
kudos:5

I actually have it on this computer... disabled. There's a less agressive plug-in that I'm used to using, but it hasn't been updated for FF3. :-(


Wednesday, 30-May 14:02:10 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics