Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
BrianKrebs
BrianKrebs
@briankrebs@infosec.exchange  ·  activity timestamp 4 days ago

Was just browsing the Internet in a VM with script-blockers turned off for a bit, and half the sites were like "IT PUTS THE DATA IN THE BASKET OR IT GETS THE HOSE AGAIN!" with multiple videos, dozens of ads and and 99 pieces of third-party Javascript loading in the background. The amount of advertiser profiling and data sharing that goes on when you visit these noisy sites with a mobile device is even higher and more invasive, which might explain why I do most of my web browsing inside a VM (but with script blockers turned on).

  • Copy link
  • Flag this post
  • Block
Emory
Emory
@emory@soc.kvet.ch  ·  activity timestamp 3 days ago

i occasionally use a script blocker on my mobile devices but not enough and it makes me feel ashamed.

on desktop workstations my default "i clicked a link" handler is "Opener.app" (got it via #setapp) which presents a menu of browsers and flags, and first choice is a browser with no javascript enabled so i can make an informed decision about witnessing it in all its glory. in safari you can use profiles and extensions like 1blocker, etc.

  • Copy link
  • Flag this comment
  • Block
Janet mary
Janet mary
@JanetMary@mastodon.social  ·  activity timestamp 3 days ago

@briankrebs Hey there handsome how are you, I have something for you. I will like to introduce to you if you are interested in booking a massage appointment and I will do my best to accommodate your schedule.
Telegram is.. @JoyMary426
Hi, add my Zangi private number for confidential correspondence and calls.
1060848107
https://services.zangi.com/dl/conversation/1060848107

Zangi Messenger

Use Zangi Private Messenger - it is free, highly secure and available everywhere. You can also create your own Messenger Solution to take full control over your business and data.
  • Copy link
  • Flag this comment
  • Block
8941dc91-867e-4412-afd5-4698d32477be:t_blink:
8941dc91-867e-4412-afd5-4698d32477be:t_blink:
@someone_else@infosec.exchange  ·  activity timestamp 4 days ago

@briankrebs
That’s why I can not use the internet anymore without my #Firefox + #uBlock Origin + #uMatrix ( + Containers)
Not for everyone but I guess you are not everyone 😁

  • Copy link
  • Flag this comment
  • Block
protobuf
protobuf
@protobuf@social.silicon.moe  ·  activity timestamp 4 days ago

@briankrebs another braindead normie post by kreb. it's the age of mass surveillance (since 2000s), you are just finding this out?

  • Copy link
  • Flag this comment
  • Block
Dima Pasechnik 🇺🇦 🇳🇱
Dima Pasechnik 🇺🇦 🇳🇱
@dimpase@mathstodon.xyz  ·  activity timestamp 4 days ago

@briankrebs
that's off-topic, sorry - is it correct that DHS is running Russian software? After all these bans on Kaspersky, still?

https://xcancel.com/pepel_klaasa/status/2024985497194442976#m

  • Copy link
  • Flag this comment
  • Block
Lorenzo "Palinuro" Faletra
Lorenzo "Palinuro" Faletra
@palinuro@mastodon.social  ·  activity timestamp 4 days ago

@briankrebs that's why we ship parrot with ublock origin pre-installed and enabled by default. couldn't live without

  • Copy link
  • Flag this comment
  • Block
Ben Ramsey
Ben Ramsey
@ramsey@phpc.social  ·  activity timestamp 4 days ago

@briankrebs Without an ad blocker, there are many news sites that cause my iPhone to heat up and mobile Safari to crash, just so I can read a text article. Do they not realize they are losing revenue by crashing browsers? Or do folks have a higher tolerance for this stuff than me, and they’re willing to put up with it to get to the content?

  • Copy link
  • Flag this comment
  • Block
Sindarina, Edge Case Detective
Sindarina, Edge Case Detective
@sindarina@ngmx.com  ·  activity timestamp 4 days ago

@ramsey @briankrebs I am regularly surprised by how few people outside of tech circles are aware of how big of a difference even a simple ad blocker makes.

  • Copy link
  • Flag this comment
  • Block
Ben Ramsey
Ben Ramsey
@ramsey@phpc.social  ·  activity timestamp 4 days ago

@sindarina @briankrebs I didn’t even use one until the last year because I thought it was wrong to block the thing those sites use to make money, but after trying one and having a much much better browsing experience, I decided it was more ethically wrong for them to disrupt/harm my browsing experience than it was for me to deny them fractions of a cent for viewing their content.

  • Copy link
  • Flag this comment
  • Block
Sindarina, Edge Case Detective
Sindarina, Edge Case Detective
@sindarina@ngmx.com  ·  activity timestamp 4 days ago

@ramsey @briankrebs Ad blockers are best practice for security and performance, and everyone should be using them.

If their business model does not provide alternatives that do not depend on ads, that is their problem, not yours.

  • Copy link
  • Flag this comment
  • Block
𝕤𝕝𝕒𝕜𝕖  :vivaldi_gray:
𝕤𝕝𝕒𝕜𝕖 :vivaldi_gray:
@slake@social.vivaldi.net  ·  activity timestamp 4 days ago

@briankrebs Some of the public secure dns servers can block most trackers and adds. That will work on all OS's. Mullvad and Adblock for example.

  • Copy link
  • Flag this comment
  • Block
Greg Glockner
Greg Glockner
@gglockner@social.seattle.wa.us  ·  activity timestamp 4 days ago

@briankrebs I use NextDNS with site filtering on all my routers and on my mobile devices. Some sites are now breaking with messages to “disable your adblockers” and others get stuck in a reload loop. And that makes me realize I don’t really need those sites after all.

  • Copy link
  • Flag this comment
  • Block
FoxyLad :tinoflag:
FoxyLad :tinoflag:
@foxylad@mastodon.nz  ·  activity timestamp 4 days ago

@briankrebs Home Network is pi-holed. Browsing on other networks is now so horrendous I usually avoid it.

  • Copy link
  • Flag this comment
  • Block
RossMadness
RossMadness
@rossmadness@infosec.exchange  ·  activity timestamp 4 days ago

@briankrebs Over the holidays we went to visit family and I watched one of them open a recipe website on their iPad to start cooking and the amount of junk and ads almost completely blocked out the view of the recipe. I pointed their iPad at NextDNS and refreshed the page. They actually gasped when all the ads went away and they could read the recipe.

  • Copy link
  • Flag this comment
  • Block
cratermoon
cratermoon
@cratermoon@zirk.us  ·  activity timestamp 4 days ago

@briankrebs I don't know how anyone can go without at least an ad blocker. Most websites seem borderline user hostile without one.

  • Copy link
  • Flag this comment
  • Block
ohir
ohir
@ohir@social.vivaldi.net  ·  activity timestamp 4 days ago

@briankrebs The other side of browsing from VM is a clear signal "a PIO (person of interest) is browsing". Like in early days of TOR. Configuring browser to hide it is on VM is not that easy. For the concerned about having somewhere a joint profiles I'd advise to have a separate device. And if VM, browse in "private" windows always. Just my ¢2.

  • Copy link
  • Flag this comment
  • Block
Natalie Esmerelda
Natalie Esmerelda
@LearnToLivePrivate@privacysafe.social  ·  activity timestamp 4 days ago

@briankrebs I block javascript by default and use nextdns in combo witha vpn and i not only have a denylist but also about 12 active heavy blocklists like hagezi multi ultimate. Recently whenever possible i try to keep offline resources that I use constantly whenever possible. These sites are insane

  • Copy link
  • Flag this comment
  • Block
Mad Engineering
Mad Engineering
@madengineering@mastodon.cloud  ·  activity timestamp 4 days ago

@briankrebs No wonder half the software developers I know have wuit the industry and become woodworkers. blobsweats

  • Copy link
  • Flag this comment
  • Block
Allan
Allan
@MithrilMechanisms@mastodon.social  ·  activity timestamp 4 days ago

@briankrebs
Sadly, your experience is why I found a use case for copilot at work.
Work blocks browser extensions and it's bad enough out there that I use copilot, with all it's flaws, just to avoid having to go to websites at all.

  • Copy link
  • Flag this comment
  • Block
pL
pL
@pl@cosocial.ca  ·  activity timestamp 4 days ago

@briankrebs whenever I heard marketing/advertising people yearn for the web of yesteryear I want to punch them in the throat.

  • Copy link
  • Flag this comment
  • Block
Ed
Ed
@EdBruce@infosec.exchange  ·  activity timestamp 4 days ago

@briankrebs For my mobile devices I used apps that run as a VPN to block sites. I've been testing Rethink DNS on a GrapheneOS phone. Pretty good at blocking known advertisers, etc. On my Android phone run DuckDuckGo App Tracking Protection. Helps with blocking what few apps I use.

p.s. both run as a VPN but just so they can monitor all network traffic and block sites collecting data.

  • Copy link
  • Flag this comment
  • Block
BrianKrebs
BrianKrebs
@briankrebs@infosec.exchange  ·  activity timestamp 4 days ago

Sorry. VM=Virtual Machine, like Parallels, VMWare or VirtualBox, which let you load another operating system as a guest OS and run it on top of your host OS. The nice thing about a VM is that you can configure it how you like, save a snapshot, and then revert to that snapshot when you're ready to shut down.

  • Copy link
  • Flag this comment
  • Block
Emory
Emory
@emory@soc.kvet.ch  ·  activity timestamp 3 days ago

@briankrebs if you have not seen @howardnoakley's impressive collection of free software you may not know that he offers several excellent options for #virtualization on #appleSilicon.

we're talking elegant, powerful software that hooks into core frameworks most people ignore entirely (containers, xhyve/bhyve that sort of thing). you gotta check these out imo. i use them for handling malicious code and for agents to use contained desktop environments. #infosec #bestof

https://eclecticlight.co/virtualisation-on-apple-silicon/

The Eclectic Light Company

Virtualisation on Apple silicon

Viable – create and run macOS virtual machines on Apple silicon Macs Takes an IPSW image, available from Apple or downloaded in the app, and creates a virtual machine from it. Runs those virt…
  • Copy link
  • Flag this comment
  • Block
ṫẎℭỚ◎ᾔ ṫ◎ℳ
ṫẎℭỚ◎ᾔ ṫ◎ℳ
@TycoonTom@infosec.exchange  ·  activity timestamp 3 days ago

@briankrebs 👌🏼 Thanks 👍🏼

  • Copy link
  • Flag this comment
  • Block
Okuna
Okuna
@Okuna@social.tchncs.de  ·  activity timestamp 4 days ago

@briankrebs I seriously love VMs and I always have one or two open.
And instead of clicking a link I copy it into an empty VM which is completely disconnected from the host and then see. in worst case I just throw away the VM and in 30 seconds I have a new one. I usually create one master VM and just clone it.

  • Copy link
  • Flag this comment
  • Block
David Penfold :verified:
David Penfold :verified:
@davep@infosec.exchange  ·  activity timestamp 4 days ago

@briankrebs I'm too lazy to browse from a PC most of the time, so tend to rely on:

Browser: FF with ublock origin and privacy badger

Apps: DDG App Tracking Protection

Belt and Braces: Pi-Hole server.

  • Copy link
  • Flag this comment
  • Block
kwayk42
kwayk42
@kwayk42@sechtor.social  ·  activity timestamp 4 days ago

@briankrebs "What does THIS malware do?" #Sandbox

Your browser does not support the video tag.
GIF
GIF
Open
a little girl is playing in the sand with a pink bucket and shovel
GIF
  • Copy link
  • Flag this comment
  • Block
Zach DeLong
Zach DeLong
@zachery_delong@mastodon.social  ·  activity timestamp 4 days ago

@briankrebs I have been using less and less add blocker and it’s honestly making me just not browse much. Almost every news website I have checked has been borderline unusable. 😵‍💫

  • Copy link
  • Flag this comment
  • Block
mike805
mike805
@mike805@noc.social  ·  activity timestamp 4 days ago

@zachery_delong @briankrebs I use uBlock Origin. Firefox on Linux and Windows. Supermium on my Win7 machines. Kiwi on Android (rarely - mobile sucks.) I wrote my first adblocker in 1998. Have learned a few techniques to defeat news sites. Here's one.

If the article appears and is then blocked by something, reload, CTRL-A CTRL-C, open a word processor, and paste.

That usually works and requires no special tools.

A lot of sites I have stopped using because of paywalls or login required to read.

  • Copy link
  • Flag this comment
  • Block
Dr Susi Arnott
Dr Susi Arnott
@SusiArnott@mastodon.green  ·  activity timestamp 4 days ago

@briankrebs Wot's a VM?

  • Copy link
  • Flag this comment
  • Block
:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉
:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉
@nemo@mas.to  ·  activity timestamp 4 days ago

@briankrebs same here brave, mullvad & browser for the win in the VM tho this concerns me tbh

https://cyberinsider.com/vpn-anonymity-undermined-by-new-adbleed-fingerprinting-technique/

And disabling adblock is no option either to much predator software around 🤷

CyberInsider

VPN anonymity undermined by new AdBleed fingerprinting technique

A new browser fingerprinting technique dubbed AdBleed uses country-specific adblock filter lists, to partially de-anonymize VPN users.
  • Copy link
  • Flag this comment
  • Block
AA
AA
@AAKL@infosec.exchange  ·  activity timestamp 4 days ago

@briankrebs Not just on mobile.

  • Copy link
  • Flag this comment
  • Block

BT Free Social

BT Free is a non-profit organization founded by @ozoned@btfree.social . It's goal is for digital privacy rights, advocacy and consulting. This goal will be attained by hosting open platforms to allow others to seamlessly join the Fediverse on moderated instances or by helping others join the Fediverse.

BT Free Social: About · Code of conduct · Privacy ·
Bonfire social · 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Code of Conduct