web brother is watching you

50
Dr. Sabin Buragawww.purl.org/net/busaco Web brother is watching you!?

Upload: sabin-buraga

Post on 09-May-2015

2.195 views

Category:

Technology


1 download

DESCRIPTION

Several aspects regarding the user privacy in the context of actual Web applications: treats and possible solutions.

TRANSCRIPT

Page 1: Web brother is watching you

Dr. Sabin Buragawww.purl.org/net/busaco

Web brotheris watching you!?

Page 2: Web brother is watching you

have you heard the news ?

Page 3: Web brother is watching you

Mark Zuckerberg (Facebook)www.guardian.co.uk/technology/2010/jan/11/facebook-privacy

the age of privacy is over

Page 4: Web brother is watching you

Eric Schmidt (Google)http://gawker.com/5419271/google-ceo-secrets-are-for-filthy-people

if you have something that you don’t want anyone to know, maybe you shouldn’t be

doing it in the first place

Page 5: Web brother is watching you

what is privacy?

Page 6: Web brother is watching you

privacy is about secrecy

Page 7: Web brother is watching you

privacy is about secrecy

Page 8: Web brother is watching you

privacy: a person’s right to control accessto his/her personal information

Page 9: Web brother is watching you

privacy: a person’s right to control accessto his/her personal information

Page 10: Web brother is watching you

privacy is an inherent human right

Page 11: Web brother is watching you

privacy is an inherent human right

a requirement for maintainingthe human condition with dignity and respect

Bruce Schneier, 2006

Page 12: Web brother is watching you

basic kinds of privacy rights

Page 13: Web brother is watching you

basic kinds of privacy rights

unreasonable intrusion

Page 14: Web brother is watching you

basic kinds of privacy rights

unreasonable intrusion

e.g., physical/virtual invasion of the private space, searching wallet or USB disks, repeated & persistent

phone calls, obtaining data without person’s consent,…

Page 15: Web brother is watching you

basic kinds of privacy rights

appropriation of a person’s name or likeness

Page 16: Web brother is watching you

basic kinds of privacy rights

appropriation of a person’s name or likeness

the use of a person’s name on a product label orin advertising a product or service

injury to personal feelings

Page 17: Web brother is watching you

basic kinds of privacy rights

publication of private facts

Page 18: Web brother is watching you

basic kinds of privacy rights

publication of private facts

examples: personal letters, medical treatment,photographs of person in his/her home,ordered goodies, Web browser history…

Page 19: Web brother is watching you

basic kinds of privacy rights

publication that places a person in a false light

Page 20: Web brother is watching you

basic kinds of privacy rights

publication that places a person in a false light

defamation acts

Page 21: Web brother is watching you

liberty

versus

control

Page 22: Web brother is watching you

if there is the privacy of garbage

Page 23: Web brother is watching you

if there is the privacy of garbage

…then why not the privacy of virtual life?

Page 24: Web brother is watching you

“Making Sense of Privacy and Publicity”

danah boyd, SXSW 2010

www.danah.org/papers/talks/2010/SXSW2010.html

Page 25: Web brother is watching you

main offenders

Page 26: Web brother is watching you

marketers

Page 27: Web brother is watching you

marketers

spying on Web users

Page 28: Web brother is watching you

marketers

companies are collecting information(via cookies, entered text, Flash cookies,…)

on Web pages you visit

Page 29: Web brother is watching you

http://blogs.wsj.com/wtk/

Page 30: Web brother is watching you
Page 31: Web brother is watching you

solution: Ghostery

Page 32: Web brother is watching you

password crackers

Page 33: Web brother is watching you

password crackers

using high speed GPU (video card) processorsor SSD drives to crack passwords

https://cyberarms.wordpress.com/

Page 34: Web brother is watching you

password crackers

http://tinyurl.com/ybhrhbv

“using SSD drives could crack passwords at a rateof 300 billion passwords a second, and could

decode complex password in under 5.3 seconds”

Page 35: Web brother is watching you

users having access to(public wireless) networks

Page 36: Web brother is watching you

users having access to(public wireless) networks

capturing HTTP messages: client ↔ server

Page 37: Web brother is watching you

users having access to(public wireless) networks

capturing HTTP messages: client ↔ server

impersonating the victims on a variety of Web sites

Page 38: Web brother is watching you

users having access to(public wireless) networks

available tools:WireShark, Firebug (Lite), HTTPwatch, Fiddler,…

Page 39: Web brother is watching you

users having access to(public wireless) networks

available tools:WireShark, Firebug (Lite), HTTPwatch, Fiddler,…

Page 40: Web brother is watching you

users having access to(public wireless) networks

available tools:Firesheep – a “benevolent” HTTP session hijacker

(October 2010)

Page 41: Web brother is watching you

users having access to(public wireless) networks

available tools:Firesheep – a “benevolent” HTTP session hijacker

Page 42: Web brother is watching you
Page 43: Web brother is watching you

resolving this issue:“How to Deploy HTTPS Correctly”

Chris Palmer (November 2010)

www.eff.org/pages/how-deploy-https-correctly

Page 44: Web brother is watching you

HTTPS Everywhere extensionwww.eff.org/https-everywhere

Page 45: Web brother is watching you

…but real-time encryptionis computationally expansive!

Page 46: Web brother is watching you

NOT any more!

www.imperialviolet.org/2010/06/25/overclocking-ssl.html

“SSL/TLS accounts for less than 1% of the CPU load,less than 10KB of memory per connection

and less than 2% of network overhead”

Page 47: Web brother is watching you

a long term solution?

Page 48: Web brother is watching you

WebID (FOAF+TLS)

a secure authentication protocol for the social Web to enable the building of distributed,

open and secure social networks

Henry Story, 2010

Page 49: Web brother is watching you

WebID (FOAF+TLS)

using semantic Web standards +security protocols built into current Web browsers

web of trust

Page 50: Web brother is watching you

Web brotheris still watching you

?