[00:00.820 --> 00:02.460] My name is Micha Lee. [00:02.840 --> 00:09.960] I am a web developer for the Electronic Frontier Foundation and I really like HOPE. [00:10.200 --> 00:11.460] This is my second time to HOPE. [00:12.700 --> 00:15.380] I went to the last HOPE but I didn't make the next HOPE. [00:17.100 --> 00:32.060] And I was so excited about HOPE this year that I was looking at the schedule the other day and I called up Google and was like, hey, I've been looking at the HOPE schedule and Google was like, oh yeah, we know And then I called up Twitter and said the same thing and they're like, [00:32.240 --> 00:39.220] oh yeah, yeah, yeah, we know, we saw you looking at the HOPE schedule on Hope9.net and how do you like Ubuntu, by the way? [00:42.480 --> 01:05.660] So the reason that HOPE, that Google and Twitter know that I was looking at the HOPE schedule is because Hope9.net includes JavaScript files from Google Analytics and also Google web fonts and they have Twitter buttons on their website that include scripts from when you first load the website. [01:06.280 --> 01:14.600] And so here is just, you know, a random sampling of some kind of activist oriented websites that also give visitor data to third parties. [01:14.880 --> 01:16.960] And here's a list of what the third parties are. [01:17.820 --> 01:24.160] And chances are a lot of these people who operate these websites don't even realize that that's going on. [01:27.070 --> 01:29.710] So what data are they giving? [01:30.010 --> 01:39.430] So if you're looking to, like what data, what of your data goes to Google and Twitter when you visit Hope9.net, you make an HTTP request. [01:39.830 --> 01:48.290] And there's a lot of information in this HTTP request and it depends on whether or not you have a cookie set in your browser for their services or not. [01:48.570 --> 01:57.470] But some of this information is your web browser, your operating system, language settings, the refer string is where you came from. [01:57.510 --> 02:05.270] So if you look at Twitter's logs, you you could see a list of everyone who's been visiting HOPE's website. [02:06.670 --> 02:10.070] And obviously your IP address, what time you went there. [02:10.690 --> 02:18.210] And if it's JavaScript, JavaScript is able to get more information about you in the browser, like what plugins you have installed. [02:18.890 --> 02:28.450] And so every time you load a website or any resource on a website or any Ajax request, all this information gets sent to the server. [02:30.410 --> 02:34.990] And so here's some examples of things that include third-party resources. [02:36.630 --> 02:38.190] And it's more than just this. [02:38.350 --> 02:41.270] It's like any time you embed any widget pretty much. [02:41.350 --> 02:45.950] Unless it's specifically designed to be privacy friendly, it's privacy unfriendly. [02:47.590 --> 02:54.390] And so I'm going to talk about ways to get around this and not give visitor data to third parties. [02:56.310 --> 03:04.190] So here are some websites that are specifically, like try to be specifically privacy friendly that don't include any third-party scripts. [03:05.350 --> 03:11.890] And they do this on purpose so that when you visit RiseUp.net, nobody else knows that you're visiting RiseUp.net. [03:11.990 --> 03:15.310] Like your visit to RiseUp.net doesn't appear in anyone else's logs. [03:15.970 --> 03:19.230] And UFF is launching a new privacy policy soon. [03:19.390 --> 03:20.410] And this is from it. [03:20.970 --> 03:27.830] We're going to promise to not include any third-party resources when you initially load the page without giving the user a chance to opt-in. [03:29.830 --> 03:35.210] And I'm going to show how you can give users a chance to opt-in to third-party stuff. [03:37.450 --> 03:45.810] So why does it really matter if there's giant databases of everyone's user agents and things? [03:47.370 --> 03:56.330] So it's really surprising how few, like how little amount of information you need to uniquely identify anyone in the world. [03:57.730 --> 03:59.790] How many people live in Manhattan? [04:00.550 --> 04:01.390] 11 million. [04:01.470 --> 04:02.730] 11 million people in Manhattan. [04:03.010 --> 04:06.830] So let's say that there are investigators trying to figure out who one of these people is. [04:07.950 --> 04:09.610] And they have a web server log. [04:09.970 --> 04:15.070] And they can tell from the user agent that this person uses Fedora Linux. [04:15.650 --> 04:19.390] So like out of 11 million people, how many people use Fedora? [04:19.690 --> 04:20.010] Two. [04:21.090 --> 04:21.650] Two? [04:22.130 --> 04:23.030] There you go. [04:24.650 --> 04:25.730] Let's pretend 200. [04:26.370 --> 04:28.870] And now let's say that their language is French. [04:29.270 --> 04:35.130] Like how many people speak French or have their language on their operating system set to French and use Fedora Linux? [04:35.130 --> 04:36.410] Like maybe one or two. [04:37.790 --> 04:38.750] In Manhattan. [04:39.050 --> 04:44.230] And so it only takes a little bit of information to build a browser fingerprint. [04:44.550 --> 04:50.830] And there's a lot more information than just like the user agent string and the language settings and stuff. [04:51.010 --> 04:55.730] Like if you're using, you know, a netbook, you have like a specific resolution. [04:56.030 --> 05:00.190] You have, you know, maybe you're running an ARM processor. [05:00.190 --> 05:06.070] And you might have various plugins in your browser that JavaScript can detect and stuff. [05:06.570 --> 05:18.750] And so even if you can't trust an IP address to uniquely identify somebody, like let's say the IP address is from a coffee shop somewhere, you can build a unique fingerprint of them from their web browser. [05:20.370 --> 05:27.290] And so the big thing is that third parties can do with this data is log it and use it to track you. [05:29.970 --> 05:33.050] And most people log everything for a long time. [05:33.410 --> 05:38.050] And that means that, you know, these logs could get subpoenaed. [05:38.050 --> 05:41.730] And last night I went to the WikiLeaks talk, the ACLU lawyers. [05:41.970 --> 05:47.930] And they were talking about with the WikiLeaks investigation, this is exactly what law enforcement is doing. [05:48.110 --> 05:53.890] They're like subpoenaing all of these services for information about visitors. [05:54.190 --> 06:08.270] And, you know, Twitter could totally give law enforcement a list of all of their logs with refers from hope9.net and try and build a, you know, a pretty good idea of who is coming to this conference, just from that. [06:11.090 --> 06:14.210] So, my first trick is about Google Web Fonts. [06:15.170 --> 06:21.110] So, it's pretty awesome that CSS finally works well enough so that you can have any font you want. [06:21.870 --> 06:24.990] And now websites are finally stopped, like, pretty. [06:25.290 --> 06:27.210] No more, like, Times New Roman and Verdana. [06:28.870 --> 06:30.970] And Google has this awesome service. [06:30.970 --> 06:39.910] It's a web font repository, and all the fonts are open-source, and you could go put in your text and look through fonts, find the ones you want, and then embed it in your website. [06:40.890 --> 06:43.850] And so, it says, just add this code to your website. [06:44.270 --> 06:51.910] And so, what happens if you add that code to your website is, when someone loads your website, they'll make a request to fonts.googleapis.com. [06:52.950 --> 06:58.190] And so, that's already, Google is getting data about someone that visited your website. [06:58.910 --> 07:07.690] And then also, inside of the CSS file, it makes another request to the actual font file. [07:08.190 --> 07:12.610] But it's really easy to use these web fonts without actually sending requests to Google. [07:12.890 --> 07:20.690] All you have to do is download this WAF file, and then just copy this, put it in your own CSS file, and just link to your own WAF file. [07:20.690 --> 07:23.890] And then when people load your website, it just goes to your own server. [07:28.310 --> 07:34.790] Yeah, well, so, at least the fonts that I looked at, I'm not sure if they have different licenses, but it looks like they're all, like, open licenses. [07:35.030 --> 07:37.030] Which means, you know, you could redistribute them, whatever. [07:42.180 --> 07:42.980] I'm not sure. [07:44.580 --> 07:47.280] I mean, I don't think it's much bigger than, like, in most images. [07:47.560 --> 07:55.280] It's, I mean, obviously, if you're going to not include resources from third parties, you're going to use more bandwidth, because you're going to have to host stuff yourself. [07:55.600 --> 07:56.740] But it's a trade-off for privacy. [07:58.240 --> 08:00.240] And then in some cases, you will use less bandwidth. [08:00.450 --> 08:09.420] Like, social media share links, where, you know, you go and you're like, I want to create a button so I can share this page on Facebook. [08:10.100 --> 08:12.860] You go to Facebook's website, and they say, oh, here's how you do it. [08:12.920 --> 08:16.620] Include this little block of JavaScript, or, like, fill out this form. [08:16.710 --> 08:17.360] We'll make it for you. [08:17.580 --> 08:18.650] Put this in your website. [08:18.650 --> 08:23.680] And then there's, like, a share on Facebook widget. [08:24.100 --> 08:27.540] And it makes, like, lots of requests to Facebook's servers. [08:28.390 --> 08:34.800] And, you know, if the user is currently logged into Facebook, Facebook, like, knows who they are exactly, not just their browser fingerprint. [08:35.760 --> 08:43.660] And so instead of doing that, there's just plain HTML links that you can make that do very similar things. [08:43.660 --> 08:47.120] Like, for the Twitter buttons, it's... [08:47.120 --> 08:49.640] You have to, like, open this in a new tab or whatever. [08:50.120 --> 08:54.080] The Twitter buttons that Twitter provides you opens it in a little pop-up window. [08:54.580 --> 08:57.120] But it's much... [08:58.140 --> 09:05.860] This basically is a way to still use social media sharing without including third-party resources on your website. [09:08.240 --> 09:09.880] And so let's say you want a Twitter button. [09:10.830 --> 09:14.120] I went to Twitter's website, and I said, I want a Twitter button for my Twitter account. [09:14.120 --> 09:17.620] And they said, okay, embed this in your site. [09:17.820 --> 09:20.020] So I embedded this, and I took a look. [09:20.120 --> 09:26.800] It makes requests to platform.twitter.com, p.twitter.com, r.twimage.com, cdn.api.twitter.com. [09:28.900 --> 09:32.380] And, you know, if someone goes to this and they're logged into Twitter... [09:32.380 --> 09:37.180] Actually, Twitter now respects do not track the DNT header, which is cool. [09:37.340 --> 09:44.580] But, you know, if you don't have the DNT header, then it'll, you know, log that, like, this Twitter user went to this website. [09:45.480 --> 09:53.560] But all this is is just a button, you know, that would be really easy to make this without making all of these requests. [09:54.600 --> 10:00.560] And so this is kind of a lot of code because the Twitter widget has a lot of CSS. [10:00.780 --> 10:04.900] But I just used Firebug, looked at the CSS, and made this myself. [10:05.100 --> 10:11.520] And so all it is is just a straight HTML link to my Twitter account, and then just a bunch of styling. [10:11.820 --> 10:15.060] And most of this is this giant big block of Base64 encoded stuff. [10:15.200 --> 10:16.060] It's a data URI. [10:16.060 --> 10:22.220] It's, like, it's an image without having to actually load an image from a server. [10:24.000 --> 10:32.140] But, yeah, so to have things like that, there's no reason to actually use the built-in widgets because those aren't privacy-friendly. [10:32.300 --> 10:34.160] And you could just make it yourself. [10:37.140 --> 10:41.020] So another thing that a lot of people want to do is have their Twitter feed on their website. [10:42.900 --> 10:45.160] And Twitter... most people use the Twitter badge. [10:45.160 --> 10:50.160] And it's this, like, live updating thing of, like, a feed or a search or something. [10:52.190 --> 10:59.920] But here's an example of an EFF website, Global Choke Points, where we have a Twitter feed that isn't using the Twitter badge. [11:01.460 --> 11:04.260] And all we're doing is loading it from the server. [11:04.340 --> 11:08.120] So when people load our website, it builds the Twitter feed from the server. [11:09.060 --> 11:10.620] And there's a couple ways of doing this. [11:11.280 --> 11:13.540] You can do a lot of stuff with the Twitter API. [11:14.920 --> 11:16.740] But it's really a simple way. [11:16.940 --> 11:18.740] Every Twitter account has a JSON URL. [11:19.360 --> 11:21.380] And you just change the username. [11:21.840 --> 11:23.440] And you can get a feed. [11:25.220 --> 11:32.620] And here's, like, a couple-line PHP script that shows how to display a Twitter feed on your website from the server. [11:32.620 --> 11:35.160] And you're not actually sending any traffic to Twitter. [11:35.500 --> 11:39.220] The only requests that go to Twitter is your web server is making this request. [11:41.140 --> 11:47.100] So Twitter only knows, you know, your web server's information and not all of your visitors. [11:49.240 --> 11:55.040] So sometimes you want to use widgets that are a bit more complicated and that, like, update live with Ajax. [11:55.780 --> 11:59.000] And so do you all know what the Humble Indie Bundle is? [12:00.440 --> 12:00.880] Yay! [12:02.000 --> 12:02.940] They're pretty awesome. [12:03.100 --> 12:04.100] DRM-free games. [12:04.100 --> 12:04.840] Pay what you want. [12:05.160 --> 12:06.840] And part of the money goes to charity. [12:07.040 --> 12:09.140] And so EFF is one of those charities. [12:09.520 --> 12:11.980] And so we were embedding this widget on our website. [12:11.980 --> 12:13.840] And they gave us this embed code. [12:14.060 --> 12:15.400] And we looked at it. [12:15.520 --> 12:22.200] And it does, like, Ajax requests, like, as quickly as it can to try and update the time remaining the bundle sold. [12:23.720 --> 12:33.260] And we can't do that because then that means everyone that visits our website will be sending data to actually, like, not to the third party that Humble Indie Bundle is using to manage their data. [12:33.540 --> 12:41.820] And so what we did is just change the JavaScript around a bit and made it so that it sends the data to our own server. [12:41.820 --> 12:48.060] And then our own server goes out and fetches the request from the third party and returns it. [12:48.260 --> 12:56.240] And so here is, like, a two-line, one-line proxy server PHP script thing that can proxy Ajax requests. [12:57.040 --> 12:59.560] And this one is kind of overly simplified. [13:01.220 --> 13:09.380] It's a lot more complicated than this because if you have, like, a thousand people with your website open, then they're making a thousand Ajax requests every second. [13:09.660 --> 13:14.620] And you don't want to be making a thousand get requests to the service every second. [13:14.740 --> 13:18.000] You want to make, like, one get request and return it to the thousand people. [13:18.180 --> 13:25.140] And so you have to do, you know, caching and you might have to mess with HTTP headers to get everything working right. [13:25.140 --> 13:40.600] But this is the general idea and you can pretty much take any sort of Ajax-y widget that makes Ajax requests to third parties and host it yourself and not have third parties get any of your visitors' data. [13:42.700 --> 13:47.720] Okay, so letting users opt-in before including third-party scripts. [13:48.700 --> 13:55.480] Here is a website I made for... it was a Twitter campaign site against CISPA. [13:55.760 --> 14:03.480] And you put in your zip code and it looks up your representatives and specifically their Twitter handles and lets you tweet at them. [14:05.080 --> 14:08.780] And this thing on the right, show me the tweets, is the opt-in thing. [14:08.780 --> 14:12.980] If you click on it, then it actually loads the Twitter badge. [14:16.200 --> 14:17.820] And here's another example. [14:17.980 --> 14:19.800] This is just a page on our website. [14:22.140 --> 14:31.840] Threatened Voices made this interactive Google Maps thing that maps out journalists that have been threatened or murdered around the world. [14:32.740 --> 14:40.260] But, you know, obviously Threatened Voices made it so it will load content from their server and then it's based on Google Maps so it loads a lot of Google content. [14:41.200 --> 14:45.160] So we just made this and then when you click on it, it actually loads the widget. [14:47.260 --> 14:54.700] So when people are just browsing through our website and they come to here, they're not actually sending any data to, you know, Threatened Voices or Google. [14:57.240 --> 14:58.900] And so doing this is really easy. [14:59.220 --> 15:01.680] And here's a quick example of how it works. [15:02.100 --> 15:06.740] The HTML at the top has a widget div and then a widget opt-in div. [15:07.600 --> 15:09.580] Click here to opt-in to the widget. [15:09.900 --> 15:10.920] And then... [15:10.920 --> 15:14.120] So let's say that you want to embed a YouTube video on your site. [15:14.300 --> 15:21.780] What you can do is inside of the widget opt-in, put an image of like a screen from your YouTube video. [15:22.040 --> 15:25.140] And then embed code, just put your YouTube embed code in here. [15:25.400 --> 15:32.240] And then when you click on the opt-in, it just overwrites everything inside of the widget div with your YouTube video. [15:32.680 --> 15:36.860] So that way you could, you know, use YouTube videos. [15:37.180 --> 15:42.180] But like, if you have a hundred people loading your website, maybe five of them will watch the video. [15:42.340 --> 15:45.920] This way you're only sending data of five users to YouTube instead of all hundred users. [15:49.080 --> 15:52.000] Okay, so when you... [15:54.040 --> 15:59.580] When you're setting up your web server and you're logging, you should try not to log more than you need. [15:59.600 --> 16:02.400] Because those logs can fall into the wrong hands. [16:02.840 --> 16:06.040] And there's various ways of limiting your logging. [16:07.180 --> 16:09.420] And one way is disabling IP addresses. [16:10.120 --> 16:15.560] So my examples are all for Apache, but you can do this in most any server software. [16:16.960 --> 16:22.040] With Apache, you have these custom log strings. [16:23.200 --> 16:26.080] And like when you're setting up an Apache virtual host, you... [16:28.580 --> 16:30.080] You do custom log. [16:30.240 --> 16:34.040] You have the path, the file name of where you want your log to be. [16:34.220 --> 16:35.880] And then you say what log format you want. [16:35.880 --> 16:41.800] And so, at least in Ubuntu, this is where the log format... [16:41.800 --> 16:43.620] This is like the common is the default log format. [16:44.200 --> 16:45.060] And this is where it's defined. [16:45.860 --> 16:48.260] Each one of these things is a different piece of the request. [16:48.620 --> 16:51.140] I forget what they all are, but %H is the IP address. [16:51.460 --> 16:56.800] And so you could just copy this, make your own custom log string, and just get rid of the %H and call it no IP. [16:57.180 --> 17:02.080] And then when you set up your logging like this, these logs won't include IP addresses. [17:05.040 --> 17:12.510] But sometimes you might want to know, like, if a thousand requests are coming from the same IP address over and over and over again. [17:12.510 --> 17:19.140] And so here's another trick using the software that I'm working on. [17:19.230 --> 17:22.140] It's not completely done yet, but it's good enough to use. [17:22.400 --> 17:23.600] Called CryptoLog. [17:24.250 --> 17:35.540] Where basically it takes the IP address portion of the log and hashes it with a random salt and uses that instead. [17:35.750 --> 17:38.880] And then this random salt changes overnight at midnight every night. [17:38.880 --> 17:47.120] So you can tell the difference between, like, one IP address making lots of requests or just lots of IP addresses making one request. [17:48.340 --> 17:51.710] And it changes your log strings from looking like this to looking like this. [17:51.950 --> 17:59.560] But, you know, if 192.168.1.118 made a bunch of requests, this IP address will appear on your logs always. [18:01.820 --> 18:03.190] And here's how you use it. [18:04.820 --> 18:06.230] There's a Git repository for it. [18:06.230 --> 18:12.010] And it's not, there isn't actually, like, a website for it or a bug tracker or a mailing list or anything. [18:12.230 --> 18:13.510] Those are coming someday. [18:17.210 --> 18:33.690] But, so here's, okay, so custom log strings let you use filters also in Apache, which means that you can, when it writes your logs, instead of just saving your logs to a file, it pipes your logs into a program running on the server. [18:34.320 --> 18:37.170] And CryptoLog, CryptoLog is a filter. [18:37.800 --> 18:42.250] And so you can tell it to use CryptoLog and then where to write the logs. [18:42.800 --> 18:45.210] And CryptoLog also lets you, like, chain filters. [18:45.230 --> 19:02.800] So if you want to use CryptoLog with CronoLog, which is an Apache filter, or a filter that lets you save your log files into multiple files, like, if you want to have a different file for each day, and with different file names, this is how you would do it. [19:04.040 --> 19:04.400] Yeah. [19:04.880 --> 19:11.970] And then also, ModLog IPHash is, it's an Apache module that does similar stuff. [19:13.060 --> 19:14.120] If you want to check that out. [19:23.650 --> 19:28.250] I mean, the main thing that you get is being able to tell the difference between unique hits and page views. [19:29.870 --> 19:32.530] Yeah, for, like, attacks or for being... [19:32.530 --> 19:43.210] I mean, you know, if you're just grabbing your logs to figure out how much traffic you got to one page on one day or something, you can tell how many requests you got, but that's not how many different people went to your website, you know? [19:54.720 --> 19:56.240] Yeah, you want to be able to do that with hash. [19:56.620 --> 19:56.980] I don't know. [19:57.040 --> 19:59.640] It seems like you want to know the IP address. [20:00.060 --> 20:03.540] I think more of the problem is that people are keeping this information forever. [20:03.540 --> 20:06.500] past, like, a week, you don't really need that information. [20:07.000 --> 20:12.390] Maybe you have a wrong job that once a week goes through your logs and... [20:12.390 --> 20:17.890] Yeah, and actually, with CryptoLog, you can use the CryptoLog... [20:17.890 --> 20:22.190] It's a Python script, but you could use it as a, like, a UNIX tool. [20:22.310 --> 20:24.930] You can pipe data into it and get data piped out. [20:25.030 --> 20:28.990] So you can retroactively CryptoLog old log files with it, too. [20:29.150 --> 20:37.730] So if you wanted to keep your IP addresses so you can, like, block abusive IP addresses, you can still do that and CryptoLog your old ones. [20:41.630 --> 20:48.150] So a lot of content management systems do lots of extra logging that you might not even know about. [20:48.390 --> 20:50.330] And especially a lot of plugins do it. [20:50.430 --> 21:01.590] Like, we found out that UberCart, which is a Drupal module shopping cart software, like, puts IP addresses in the database for every purchase. [21:01.790 --> 21:05.830] And we were thinking it might even do it for every time people add stuff to the store or to their shopping cart. [21:08.730 --> 21:10.690] And we don't want to log IP addresses. [21:10.970 --> 21:24.070] And so here is a way to basically trick your CMS and the plugins in your CMS into not knowing what your visitor's data actually is. [21:25.150 --> 21:36.650] As long as you put these lines of code in your website somewhere before your plugins start running, then when your plugins do start running, they... [21:36.650 --> 21:41.490] When they're trying to access the IP address, they'll just access this instead of what the actual IP address is. [21:41.530 --> 21:42.550] You're just overwriting these values. [21:42.750 --> 21:43.770] And it totally works. [21:46.870 --> 21:51.730] So this is more of a security thing than a privacy thing. [21:52.670 --> 21:59.030] But basic authentication, HTTP basic authentication is pretty awesome and underused. [22:00.270 --> 22:16.710] If you have, like, an internal web application that just people in your organization use and you want to prevent it from getting hacked, if you wanted to, you could use some sort of web app that has users and everyone has to log in. [22:17.210 --> 22:20.190] But, you know, you might not update it. [22:20.230 --> 22:23.510] People might have zero days for that web app and they might be able to hack into it. [22:23.810 --> 22:36.130] But if you put basic authentication in front of the entire thing, then even if people have zero days for what software you're using, they won't be able to exploit them and they won't even be able to know what software you're using. [22:36.870 --> 22:38.210] And it's pretty easy to do. [22:38.530 --> 22:46.730] And I'll show later also that you could lock down just pieces of your website with basic authentication, which is really nice. [22:46.990 --> 22:53.450] But you have to put this stuff inside of your Apache config file or .htaccess file. [22:54.950 --> 23:00.430] And the auth user file path to .htpasswd is a path... [23:00.430 --> 23:04.990] You have to create a password file and manage your usernames and passwords in this file. [23:05.210 --> 23:09.490] And there's a UNIX program called .htpasswd that lets you do this. [23:10.350 --> 23:13.550] And there's, I think, online tools that you generate these too. [23:13.710 --> 23:16.630] But you could just search for it to figure out how to actually manage the files. [23:19.250 --> 23:22.470] Okay, and I'm gonna go into the basic auth soon too. [23:23.010 --> 23:27.550] But, okay, so I was talking about Google Analytics and how everyone uses it. [23:27.630 --> 23:29.930] And it's not very privacy friendly. [23:31.410 --> 23:37.730] Pwic is an open-source PHP MySQL application that is pretty awesome. [23:37.990 --> 23:39.030] And it's a great alternative. [23:40.270 --> 23:44.510] And it's, instead of using third-party analytics, you could use first-party analytics. [23:44.510 --> 23:57.010] And so, you know, if HOPE used it, then there could be, like, pwic.hope.net, and then hope9.org.net. [23:57.710 --> 24:03.490] Hope9.net could include resources from pwic.hope.net. [24:03.710 --> 24:08.490] And that will be fine because they're not giving data to any third parties. [24:09.790 --> 24:12.430] And they can use it for, like, multiple websites. [24:12.430 --> 24:16.370] So they can use the same Pwic server for lots of different...for each conference. [24:18.250 --> 24:19.370] It's very customizable. [24:19.790 --> 24:21.610] There's a lot of privacy settings. [24:22.030 --> 24:23.470] You can, like, delete old logs. [24:23.570 --> 24:26.110] You can anonymize logs as they're getting created. [24:27.910 --> 24:31.570] And you could write plugins for it if it doesn't do what you need. [24:31.730 --> 24:32.930] And it has cool mobile apps too. [24:34.910 --> 24:39.770] But, you know, like any other analytics software, it tracks your visitors. [24:40.130 --> 24:49.810] And so, one thing that it does...so, by default, it tells you to include this block of JavaScript at the bottom of your page, sort of like Google Analytics. [24:50.570 --> 24:57.650] But when the JavaScript runs, it does stuff like detect what plugins you have in your browser and detect screen resolutions and save this in your database. [24:57.870 --> 25:00.970] And maybe you don't actually want this stuff in your Pwic database. [25:01.950 --> 25:17.690] But they also have this thing, which is just an image tracker that basically just this HTTP request, they get all that data from the HTTP request, but they just don't get extra data that JavaScript has access to. [25:17.690 --> 25:22.310] So, you can actually not use the JavaScript stuff at all and only use the image tracker stuff. [25:22.510 --> 25:23.930] And you can pass in more data. [25:24.310 --> 25:33.030] There's a couple of extra get parameters you could use if you want to pass in the refer so that you can, like, see where traffic is coming from to your website and stuff. [25:35.090 --> 25:36.950] And so, yeah. [25:37.090 --> 25:38.590] So, this is a good way. [25:38.770 --> 25:50.110] If you're, like, really paranoid, you don't want to store a lot of user data, or your visitor data in your Pwic database, then use this one instead because it will store a lot less data. [25:52.670 --> 26:01.690] So, here are some screenshots that I took from Pwic of, you know, browser operating system usage and, like, traffic statistics. [26:03.830 --> 26:10.970] And it's good to keep in mind that, like, any of these third parties can build these exact same graphs about your website. [26:11.150 --> 26:20.250] So, if you include a Google web font, Google could build these graphs from your, like, about the traffic and the browsers and operating systems from your website. [26:21.210 --> 26:25.930] And then, also, they have all the IP addresses and, you know, times of day and everything. [26:26.190 --> 26:36.190] So, you're basically giving people a lot of information about you or about all of your visitors just by including a script to their server or an image or a CSS file or anything. [26:38.830 --> 26:39.390] Okay. [26:39.570 --> 26:44.130] So, here is another basic authentication trick to harden Pwic. [26:45.770 --> 26:50.550] So, Pwic uses Peic.js and Pwic.php publicly. [26:50.810 --> 26:51.410] Like, you... [26:52.230 --> 26:59.550] If you want to use the JavaScript one, you include this file on your website and the image is an image to this file. [27:02.990 --> 27:21.710] So, let's say that, you know, you install Pwic and you don't want to upgrade it for a couple of years even though that's a bad idea or you forget to or you don't know how secure it is, you can, in your Apache config file, set up a password to all of Pwic and, [27:21.770 --> 27:28.810] you know, you have to have the htpassword file too and then make exceptions for slash Pwic.php slash Pwic.js. [27:29.190 --> 27:33.690] So, this way, your Pwic server could have... [27:34.870 --> 27:38.070] Could be completely locked out of everything except for those two URLs. [27:38.250 --> 27:42.130] So, you can still collect data from people who are visiting your website. [27:42.390 --> 27:45.490] But, if anyone tries to go there, they won't be able to get any information. [27:45.950 --> 27:52.270] And this is also useful for not just Pwic for, like, locking down any parts of your website. [27:52.270 --> 27:57.910] Like, if you're running WordPress and you don't have users from the public logging into your site. [27:58.010 --> 27:59.530] It's only, like, the people who run the site. [28:00.350 --> 28:06.070] You could lock down wplogin.php and all of wp-admin. [28:06.490 --> 28:16.370] And that will mean that if anyone tries to make any requests to any of that stuff, it will pop up a password box and they won't be able to get through. [28:18.170 --> 28:25.450] Which means that even if someone has, like, a zero day for your version of WordPress or for some plugins that you're using, they probably won't be able to exploit them. [28:28.230 --> 28:28.710] Okay. [28:28.990 --> 28:33.430] So, HTTPS is popular these days. [28:37.090 --> 28:43.790] And I'm sure there's, like, lots of information out there about how HTTPS is important to use. [28:43.790 --> 28:45.850] But it's also really important to use it correctly. [28:47.410 --> 28:52.170] And I'll go into more detail about these various steps of using HTTPS correctly. [28:52.510 --> 28:58.290] But this is a good resource that explains some of this stuff. [28:58.290 --> 29:08.610] And this is Jake Applebaum's Git repository of hardened configuration files for lots of different servers. [29:08.770 --> 29:09.430] Which is really awesome. [29:09.590 --> 29:11.110] Because I'm just going over Apache. [29:11.710 --> 29:16.630] But if you're using Nginx or if you're using Varnish or Pound or anything else to do your... [29:16.630 --> 29:18.150] I guess Varnish can't do it. [29:18.150 --> 29:21.070] But anything to do your SSL termination. [29:23.610 --> 29:27.690] This shows, like, what Cypher Suites to use and has example config files. [29:27.830 --> 29:28.330] And it's really useful. [29:30.730 --> 29:39.090] So, it's good to have HTTPS work on your website and force people to use HTTPS for every request. [29:39.510 --> 29:41.690] And it's really simple to do this. [29:41.950 --> 29:46.130] Here, you can put this in your Apache config file or an htaccess file. [29:47.490 --> 29:49.210] It requires mod rewrite. [29:49.470 --> 29:51.130] But basically, if you're using HTTPS... [29:51.650 --> 29:57.530] Or if HTTPS is off, if you're not using HTTPS, then it rewrites the request to use HTTPS. [29:57.730 --> 29:58.910] And you get a redirect. [29:59.870 --> 30:05.090] So, anyone that tries to do anything on HTTP gets redirected to HTTPS instead. [30:09.530 --> 30:15.570] HSTS, HTTP Strict Transport Security, is something that's kind of little known, I think. [30:15.570 --> 30:19.570] But it's an important part of using HTTPS correctly. [30:20.290 --> 30:24.970] And Firefox, Chrome, maybe the new Internet Explorers. [30:25.110 --> 30:25.490] I'm not sure. [30:25.810 --> 30:27.930] But, like, modern browsers support it now. [30:31.050 --> 30:46.930] And, basically, what it says is if you go to a website over HTTPS and it sets this Strict Transport Security header, it tells your browser never to go to this website over HTTP until the max age expires. [30:46.930 --> 30:54.370] And so, this is important because you can force people to go to HTTPS here. [30:55.010 --> 30:56.570] But, you know, someone might... [30:56.570 --> 30:58.130] They might click on an HTTP link. [30:58.270 --> 31:00.630] Or they might just type in the URL. [31:01.030 --> 31:06.590] Or they might be getting hacked and someone could, like, trick them into loading an HTTP resource. [31:06.590 --> 31:09.350] And if they have an HSTS... [31:09.350 --> 31:15.610] If they have it set in their browser for this domain, then they will never... [31:15.610 --> 31:17.670] Their browser won't make the HTTP requests. [31:17.970 --> 31:20.270] And here's how you set that up in PHP. [31:20.570 --> 31:22.030] And here's how you can set it up in Apache. [31:25.790 --> 31:32.150] And so, the reason why it's important to try and get people not to even make HTTP requests instead of just relying on the redirect... [31:32.150 --> 31:34.710] Well, one of the reasons is cookies. [31:35.590 --> 31:39.250] And this is a different way to guard against cookies getting stolen. [31:39.490 --> 31:40.030] But when... [31:40.910 --> 31:42.810] So, cookies are used for sessions. [31:43.090 --> 31:46.390] You need cookies to maintain a session on the web. [31:46.530 --> 31:49.110] So, if you want to log into a website, the website has to set a cookie. [31:49.110 --> 31:49.810] And the way that... [31:49.810 --> 31:56.010] They know that you're logged into the website is because every time you load the website, you send your cookie session ID back to the server. [31:56.210 --> 31:59.790] And so, secure cookies are... [32:00.450 --> 32:03.030] The cookie header has a secure flag. [32:03.270 --> 32:06.970] And if a cookie is secure, then that means it will never get sent over HTTP. [32:07.670 --> 32:08.670] Which means that, like... [32:08.670 --> 32:10.390] And people don't do this very often. [32:10.490 --> 32:22.290] It means that, like, even if you are forcing HTTPS on your whole website, and then you get tricked into loading an HTTP resource, your session cookie will go in the clear, and a hacker could hijack your session and take over your account. [32:22.950 --> 32:24.570] But if you set the secure... [32:25.170 --> 32:30.290] The secure flag, then that won't be possible, because your cookie won't get sent in the clear, ever. [32:30.550 --> 32:35.330] And if you get tricked into going to an HTTP link, you'll make that request, but you won't send the cookie. [32:36.370 --> 32:37.970] And HTTP only is... [32:40.010 --> 32:46.450] It's confusingly named, because it's talking about the HTTP protocol, not, like, HTTP versus HTTPS. [32:46.630 --> 32:59.930] But basically, it means that JavaScript doesn't have access to read this cookie, which is important, because cross-site scripting bugs, where, you know, an attacker could put JavaScript code running in the context of your browser, won't be able to steal your session. [33:00.150 --> 33:04.070] So if there's a cross-site scripting bug on your website, your accounts can't get stolen. [33:05.590 --> 33:06.470] But here's... [33:06.470 --> 33:10.710] All you have to do is just, you know, set these to true when you are setting the cookie. [33:11.070 --> 33:13.350] But most of the time, you're using a CMS. [33:13.550 --> 33:16.330] You're not actually setting session cookies yourself. [33:16.530 --> 33:28.030] And so in PHP, there's this function session set cookie params, where you actually can choose what the parameters for your session cookies are going to be. [33:28.210 --> 33:37.410] And as long as you run this before the session gets started, then when it sets the cookie in the browser, it will set it as secure and HTTP only. [33:38.270 --> 33:43.810] And also, this first parameter, zero, is how long it takes before the cookie expires. [33:44.110 --> 33:47.750] And if you set it to zero, it's a session cookie, which means it expires when you close the browser. [33:48.230 --> 33:54.930] But you could set this to, like, seven days and seconds or something, and then it'll expire after seven days. [33:56.010 --> 34:06.850] But in WordPress and Drupal, you could just put this in wp-config.php or site's default settings.php, and that code gets executed before the session gets started. [34:07.550 --> 34:11.130] And you'll have secure, HTTP-only cookies. [34:15.850 --> 34:22.170] So when you're administering your web server, use public key authentication if you can. [34:22.330 --> 34:23.390] It's better than password authentication. [34:23.510 --> 34:35.330] It means that someone, like, in most practical situations, needs to actually, like, hack the developer's laptops or something in order to connect to the server instead of just getting the password. [34:36.450 --> 34:39.970] And then use SSH and SFTP to transfer files. [34:40.170 --> 34:41.030] Don't use FTP. [34:41.390 --> 34:42.750] It's, like, really trivial. [34:42.950 --> 34:49.350] Like, if you FTP to a server when you're in a coffee shop or something, everyone else in the coffee shop could just pick up the username and password. [34:49.510 --> 34:49.990] So don't do that. [34:53.450 --> 35:02.410] Okay, and so here are just some things you can do to help people who are trying to be proactive about their privacy. [35:04.770 --> 35:07.050] Try not to require JavaScript for stuff. [35:07.310 --> 35:10.290] Some things you kind of have to require JavaScript for these days. [35:10.510 --> 35:16.610] But if you can, make your website work without JavaScript and just have, like, work better with JavaScript. [35:17.430 --> 35:18.590] Don't use Flash. [35:19.110 --> 35:20.350] That should just be over now. [35:26.210 --> 35:28.950] Don't block the IP addresses of proxy servers. [35:29.790 --> 35:30.290] Because... [35:31.270 --> 35:32.810] And this includes Tor access. [35:33.130 --> 35:36.390] Because people might use it for spam and people might use it for abuse. [35:36.970 --> 35:41.590] But people also will be using these servers just because they're censored and they need to use these servers. [35:43.350 --> 35:45.930] And make sure you use HTTPS correctly. [35:45.930 --> 35:47.530] And always use HTTPS. [35:49.170 --> 35:51.650] And test your site with the Tor browser bundle. [35:51.930 --> 35:54.710] Because Tor is really important. [35:54.910 --> 35:56.910] And I feel like it's getting more and more important all the time. [35:57.090 --> 36:01.490] Especially with, like, all of the revolutions going on. [36:02.210 --> 36:03.710] People are depending on Tor. [36:04.030 --> 36:09.130] And that's, like, the most common way that people who are being censored are getting access to stuff. [36:09.850 --> 36:12.390] And then don't use privacy-invasive third-party services. [36:12.550 --> 36:15.230] But really just don't use third-party services unless you can avoid it. [36:15.370 --> 36:17.090] Or unless you at least let people opt in. [36:17.750 --> 36:18.570] So at least you... [36:18.570 --> 36:26.630] If you're gonna use third-party services, make sure that you don't use it by default. [36:26.970 --> 36:28.490] That you don't send everyone's data. [36:28.490 --> 36:32.530] You only send the data that you need to to get the functionality you need. [36:32.770 --> 36:37.630] So, like, only, you know, send Vimeo data if people try to play the video. [36:37.790 --> 36:38.830] Don't actually do it before that. [36:39.050 --> 36:42.030] And, like, if you have a PayPal button or a Google checkout button or something. [36:42.090 --> 36:42.750] Do the same thing. [36:42.890 --> 36:45.390] Don't actually load scripts from their services. [36:45.390 --> 36:48.370] Because then you're giving PayPal and Google all of this information. [36:52.850 --> 36:53.290] So... [36:53.730 --> 36:56.790] Everyone uses content management systems these days. [36:58.070 --> 36:58.510] But... [36:58.510 --> 37:00.390] And it makes it really convenient. [37:01.190 --> 37:02.530] It makes it way easier to update. [37:02.710 --> 37:03.390] It makes it... [37:04.150 --> 37:07.030] So that, you know, you have multiple people managing content and stuff. [37:07.210 --> 37:10.830] But if you have some sort of high-security thing, just don't use a CMS. [37:11.090 --> 37:14.470] Or use a CMS and then just, like, make a static version of it. [37:14.470 --> 37:15.230] And have... [37:15.230 --> 37:16.070] Host that instead. [37:17.310 --> 37:17.730] Um... [37:18.290 --> 37:18.710] Because... [37:18.710 --> 37:20.830] Content management systems can get hacked. [37:21.090 --> 37:23.250] Because, you know, there's a database on the back-end. [37:23.390 --> 37:24.450] So there could be SQL injection. [37:24.710 --> 37:28.750] There's, you know, some sort of language that's running the code. [37:28.930 --> 37:30.890] Like PHP or Ruby or Python or something. [37:31.150 --> 37:32.510] And there could be bugs in that code. [37:33.810 --> 37:34.230] Um... [37:34.230 --> 37:37.610] And that's what, like, 99% of web hacking is. [37:37.750 --> 37:38.710] Is hacking content... [37:38.710 --> 37:39.870] Or hacking, uh... [37:39.870 --> 37:40.430] Web applications. [37:40.730 --> 37:42.010] If you don't have a web application. [37:42.070 --> 37:43.530] If you're just serving static files. [37:43.530 --> 37:48.330] Then the only way to hack into the website is through the server. [37:48.550 --> 37:51.890] So you need to find, like, a vulnerability in Apache or Nginx. [37:51.990 --> 37:53.530] Or whatever your server software is. [37:53.690 --> 37:55.030] And that's a lot harder. [37:55.310 --> 37:57.670] So if you have, like... [37:57.670 --> 37:59.390] Like, a really high-security thing. [37:59.570 --> 38:02.290] And you want to just serve some information. [38:03.050 --> 38:03.530] Um... [38:03.530 --> 38:04.270] And... [38:04.270 --> 38:06.850] And it would really suck if your server got hacked. [38:07.070 --> 38:08.410] Then, uh... [38:08.410 --> 38:09.530] Then just try and make it static. [38:11.270 --> 38:11.670] Um... [38:11.670 --> 38:12.110] And... [38:12.110 --> 38:15.130] Obviously, if it's static, then you can't have interactive stuff like people commenting. [38:15.870 --> 38:16.670] But, um... [38:16.670 --> 38:18.330] If you don't need that stuff, then make it static. [38:20.310 --> 38:22.030] And that is it. [38:22.270 --> 38:23.170] Are there any questions? [38:27.570 --> 38:28.510] Anonymizing IP addresses. [38:28.990 --> 38:30.670] How bad would it be if you just keep [38:34.460 --> 38:34.650] not... [38:35.380 --> 38:35.570] Yeah. [38:35.760 --> 38:37.590] Can you check with the first three... [38:37.590 --> 38:39.620] Actually, with Pwic, um... [38:41.150 --> 38:41.550] Uh... [38:41.550 --> 38:41.750] That... [38:42.940 --> 38:47.140] The anonymizing IP addresses part lets you choose how many bytes of the IP address you want. [38:47.280 --> 38:50.460] And so you can, like, choose the first three bytes if you want. [38:50.550 --> 38:51.460] Or the first two bytes or whatever. [38:51.460 --> 38:53.420] Does that provide adequate anonymity? [38:54.550 --> 38:55.000] Um... [38:55.000 --> 38:56.300] I think it depends. [38:56.460 --> 38:59.860] I mean, I think the first two bytes probably provides adequate anonymity. [38:59.960 --> 39:01.720] But also, uh... [39:01.720 --> 39:04.070] What we do is we have a local geolocation database. [39:04.480 --> 39:07.500] And just do lookups on the IP address and store the country. [39:07.840 --> 39:09.520] And then anonymize the IP address. [39:09.720 --> 39:13.640] So we know what region people are coming from, even though we don't know their IP addresses. [39:15.160 --> 39:18.920] I serve a stack website using THTBD. [39:19.560 --> 39:20.120] Um... [39:20.120 --> 39:22.940] I was wondering if I want to add, um... [39:22.940 --> 39:24.680] HTTPS to my site. [39:25.140 --> 39:26.040] Would Stunnel... [39:26.040 --> 39:26.780] Am I using... [39:30.260 --> 39:30.820] Um... [39:30.820 --> 39:32.600] Using Stunnel to... [39:32.600 --> 39:34.340] To do the HTTPS? [39:34.500 --> 39:36.160] Because THTBD only does HTTP? [39:36.420 --> 39:37.600] What is it the old-school server? [39:38.800 --> 39:39.360] Um... [39:39.360 --> 39:39.940] Probably. [39:40.460 --> 39:41.040] But it's... [39:41.640 --> 39:43.240] It's kind of hard to keep tunnels open. [39:44.220 --> 39:44.780] But... [39:44.780 --> 39:45.880] But I mean, it probably is. [39:45.880 --> 39:47.000] As long as it's... [39:47.000 --> 39:47.580] It's set up correctly. [39:47.740 --> 39:49.220] And you have, like... [39:49.220 --> 39:50.680] You know, a certificate that's good. [39:50.880 --> 39:51.580] And signed. [39:52.300 --> 39:52.700] And... [40:07.600 --> 40:08.360] Um... [40:08.360 --> 40:08.860] Like... [40:08.860 --> 40:11.400] It will move you to use, like, their private services. [40:11.620 --> 40:13.300] So if you have a static blog, for example, [40:16.790 --> 40:17.010] . [40:17.010 --> 40:17.650] Yeah. [40:17.770 --> 40:20.250] So that kind of... [40:20.250 --> 40:20.910] Yeah. [40:21.150 --> 40:23.570] I mean, you could have a static website and still use Pwic. [40:24.810 --> 40:25.210] Um... [40:25.210 --> 40:25.490] But yeah. [40:25.650 --> 40:27.670] I mean, I think that that's just for... [40:28.210 --> 40:28.610] Like... [40:29.110 --> 40:29.330] Like... [40:29.330 --> 40:29.590] If you... [40:29.590 --> 40:29.970] If... [40:29.970 --> 40:32.490] If it makes sense for you, then you should do it that way. [40:33.130 --> 40:33.490] Like... [40:33.490 --> 40:34.490] TorProject.org. [40:35.270 --> 40:35.630] Um... [40:35.630 --> 40:35.990] It's static. [40:36.150 --> 40:36.490] I think they... [40:36.490 --> 40:42.490] They, like, use a sort of CMS thing, but then they compile it into a bunch of static code and that's what gets hosted. [40:42.950 --> 40:45.110] And so you can't hack TorProject.org through their web app. [40:46.370 --> 40:46.810] Uh... [40:46.810 --> 40:47.330] But you can also... [40:47.650 --> 40:48.010] But you can also segregate [41:06.410 --> 41:06.770] your... [41:06.770 --> 41:07.350] That, uh... [41:07.350 --> 41:13.070] You shouldn't really ever use FTP because it said the information over planned text and someone in the company shop can get it for you. [41:13.410 --> 41:17.620] But the same as Charles... [41:17.620 --> 41:19.720] Well, not if you're doing it over HTTPS. [41:20.160 --> 41:20.600] Um... [41:20.600 --> 41:26.290] And also, over the press blog, most people aren't doing that over HTTPS. [41:27.130 --> 41:36.970] And I think also a lot of those examples, if you're saying you just want to limit the login page to you personally, you could just set that to deny based on the IP address. [41:37.010 --> 41:37.070] Yeah. [41:37.470 --> 41:39.330] Well, also, I mean, even if... [41:39.330 --> 41:39.870] Um... [41:39.870 --> 41:52.250] Even if you don't have HTTPS, if you use the basic authentication, it'll go over plain text, but chances are an attacker is just someone sitting there on the Internet hitting your web server, not in a position to capture your traffic as you're logging in. [41:52.510 --> 41:53.710] So chances are... [41:53.710 --> 41:54.790] So it still protects you a lot. [42:04.690 --> 42:05.690] I don't know. [42:05.890 --> 42:06.410] I think so. [42:08.410 --> 42:08.730] Yeah. [42:22.010 --> 42:23.550] I mean, nothing's wrong with that. [42:23.710 --> 42:24.730] It's just, um... [42:24.730 --> 42:25.930] Could you please repeat the question? [42:26.110 --> 42:27.010] Oh, uh... [42:27.010 --> 42:30.650] What will be wrong with using JavaScript files hosted on his own website? [42:31.770 --> 42:32.090] Um... [42:33.050 --> 42:33.830] Nothing's wrong with it. [42:33.970 --> 42:35.450] And, I mean, a lot of times you have to do it. [42:35.450 --> 42:36.450] It's just, uh... [42:37.050 --> 42:37.470] Uh... [42:37.470 --> 42:38.630] A lot of people use NoScript. [42:39.030 --> 42:39.890] I mean, not a lot of people. [42:40.030 --> 42:40.990] A few people use NoScript. [42:41.590 --> 42:42.030] Um... [42:42.790 --> 42:43.230] NoScript! [42:45.710 --> 42:46.150] Um... [42:46.150 --> 42:48.010] And, uh... [42:48.010 --> 42:58.250] People that are trying to be, like, especially security and privacy conscious, you tend to use it, and it's good to make your website not rely on it so that it still works. [42:58.250 --> 42:58.390] It's... [42:58.390 --> 42:59.190] I mean, a lot... [42:59.190 --> 42:59.930] There's a lot of things you... [42:59.930 --> 43:01.530] You can't do without JavaScript. [43:02.510 --> 43:02.910] So... [43:04.230 --> 43:04.790] Yeah. [43:05.030 --> 43:11.070] You mentioned that, um... [43:11.070 --> 43:16.390] A lot of the plugins, for instance, for WordPress, or for Drupal, will collect information scoring. [43:17.010 --> 43:17.570] Uh... [43:17.570 --> 43:22.290] One of the things you can do is set up a varnish server, and, uh... [43:22.290 --> 43:38.910] If you set up a reverse proxy, for instance, then, uh, your application server, or your application itself, won't know about the IP unless you specifically tell the varnish server, for instance, to pass along the IP on the, uh, caching request. [43:38.910 --> 43:40.910] Yeah, so, what he said is that, um... [43:42.290 --> 43:42.670] Uh... [43:42.670 --> 43:42.810] Uh... [43:42.810 --> 43:57.090] I was saying that a lot of plugins for CMS's, uh, record IP address data, and if you use a reverse caching proxy, like varnish, or squid, or something, uh, it won't actually know what the user's IP address is unless you specifically tell it to know what the user's IP address is. [44:01.690 --> 44:12.850] Oh, I was, I was curious if you knew how, I was wondering how servers detect traffic from proxy networks and stuff like that. [44:13.110 --> 44:14.130] Do you know how that works? [44:14.430 --> 44:15.290] Uh, there's... [44:15.290 --> 44:16.830] I know that, like, um... [44:16.830 --> 44:19.470] Are you talking about proxies like Tor, or...? [44:19.470 --> 44:19.670] Yeah. [44:22.020 --> 44:23.180] Like traffic from... [44:23.180 --> 44:24.600] Well, so, Google block... [44:24.600 --> 44:30.480] Like, if you've ever used Tor, and you do a Google search, and it makes you enter a CAPTCHA, and it's really annoying, and it's slow. [44:31.540 --> 44:32.020] Um... [44:32.020 --> 44:32.360] Uh... [44:32.360 --> 44:32.600] The... [44:32.600 --> 44:37.580] I think that the main reason why Google does that is because people, um, abuse the Tor network. [44:37.960 --> 44:38.860] And so, people... [44:38.860 --> 44:40.080] Such as IP log, there was... [44:40.080 --> 44:43.880] I think that they do that with any IP address that they detect is abusing their... [44:43.880 --> 44:44.860] their server. [44:45.140 --> 44:47.280] And so, uh, that's... [44:47.280 --> 44:51.200] But because people abuse Tor exit nodes, that's why they got blocked. [44:51.280 --> 44:52.840] But also, um... [44:52.840 --> 44:54.360] Uh, it's publicly look... [44:54.360 --> 44:57.740] You can publicly look up IP address to see if they're Tor exits. [44:57.740 --> 45:00.800] So, it's easy to detect Tor exits. [45:01.080 --> 45:02.440] It's not so easy to detect other proxies. [45:08.870 --> 45:13.050] You can actually do aggregation when you get the log and not the system. [45:13.670 --> 45:19.510] And not only do you not have data, but it's also faster. [45:19.950 --> 45:20.430] Yeah. [45:21.450 --> 45:24.790] And it's actually, it's built into Pwic. [45:24.930 --> 45:28.070] You can set up a crown job to delete logs. [45:28.070 --> 45:39.110] So, like, you log individual rows that connect your IP address, your user agent, and what page you hit in a database. [45:39.130 --> 45:41.950] And so, if you get a lot of hits, then the tables fill up really fast. [45:42.110 --> 45:44.970] And you can tell it to aggregate all this data. [45:45.230 --> 45:53.330] So, in aggregate form, you can just see, like, what web browsers people are using and, like, what countries people are coming from. [45:53.370 --> 45:57.530] But you can't actually connect that, like, someone from this country was using this web browser. [45:57.530 --> 45:59.610] And then just delete the individual logs. [46:01.330 --> 46:04.030] You said a lot of people are using Tor exit nodes. [46:04.190 --> 46:05.350] Now, what kind of abuse are you doing? [46:05.750 --> 46:07.370] I mean, I'm not, I'm not really sure. [46:07.650 --> 46:08.690] But, um, I think... [46:11.810 --> 46:20.750] Corporate networks sometimes, if they just get too much traffic from one small number of IP addresses, they will, they will start setting up CAPTCHAs because they think it's in their own bots. [46:20.990 --> 46:26.670] And so, if you're in a corporate building with, like, a couple thousand people, sometimes they start getting CAPTCHA to call them off. [46:26.850 --> 46:27.470] So, it's probably the same. [46:27.930 --> 46:29.590] I mean, you see bots or something. [46:29.770 --> 46:32.850] Well, I mean, people also, like, hack through Tor. [46:33.050 --> 46:37.730] I don't know about, I don't know what Google does to figure this out, but... [46:37.730 --> 46:39.170] Two questions. [46:41.070 --> 46:42.710] You said no flash. [46:42.870 --> 46:46.550] Is there a problem using flash just for sockets? [46:47.530 --> 46:50.030] Um, so, flash... [46:51.390 --> 46:52.830] For web sockets. [46:55.530 --> 46:58.130] There's also HTML5 sockets. [46:58.330 --> 47:01.110] There's also fallback pulling, but flash sockets... [47:01.110 --> 47:06.190] So, the problem with flash is that, um, it doesn't work over... [47:06.190 --> 47:10.730] I mean, you can use flash when you're using Tor, but flash is a vulnerability. [47:10.990 --> 47:13.550] Flash can be used to, uh, de-anonymize you. [47:13.850 --> 47:17.810] And so, if someone is using Tor and also trying to use... [47:17.810 --> 47:25.870] And also using flash, which the Tor browser bundle doesn't let you do, um, by default, uh, uh, then it won't... [47:25.870 --> 47:26.750] Like, it won't work. [47:27.110 --> 47:30.370] And also, flash is just really, uh, ugh. [47:32.610 --> 47:33.090] Uh... [47:33.090 --> 47:33.550] Uh... [47:33.550 --> 47:34.170] Uh... [47:37.770 --> 47:38.050] Uh... [47:38.050 --> 47:46.930] Which is, uh, because I run a pack, we're legally required to collect people's name after some location, or, um, in certain circumstances. [47:47.510 --> 47:55.970] Given that we have to collect them, we don't have to collect them for everybody, but how would you suggest, at least, obeying the law, but also... [47:58.190 --> 48:01.590] Well, you don't get that stuff for visitors to your website. [48:01.970 --> 48:04.290] Not all, like, only people that, like, fill out a form on your website, right? [48:04.690 --> 48:12.430] So just, so just, you know, collect what you need to collect, try and keep it safe, but don't, um, don't track everyone on your website as much. [48:15.110 --> 48:23.550] Um, what, uh, related to Tor hidden services and relevant to this, has anybody actually written specifications about doing that? [48:23.790 --> 48:28.330] Because a lot of what you're talking about is obviously relevant to running a hidden service, you know, dark net, Tor stuff. [48:29.110 --> 48:37.130] Uh, number two, the other thing is, like, this whole thing is, like, is there server-sized ways to deal with blocking your referral for the client, and stuff like that? [48:37.330 --> 48:39.050] Has anybody done anything like that, or not? [48:40.490 --> 48:40.890] Um... [48:44.980 --> 48:58.260] Specifications for running, uh, Tor hidden services, teaching these services, which obviously means lots of other questions, like blocking refer server-side for the users, and so on and so forth. [48:58.340 --> 49:00.260] Has anybody done any specifications on that? [49:00.720 --> 49:08.140] So has anybody done any stuff on, um, uh, blocking refer server-side and Tor hidden services and stuff? [49:08.580 --> 49:10.200] Um, I don't, I don't know. [49:10.200 --> 49:16.350] You can't really do something like, do you refer me? [49:16.690 --> 49:18.410] And that will get rid of the site. [49:18.970 --> 49:19.190] Yeah. [49:19.630 --> 49:21.850] But it's all done client-side. [49:22.190 --> 49:22.750] Yeah. [49:25.670 --> 49:32.790] I have, I have, I have sort of a comment, uh, for people who are asking about, can I use Flash, or can I use JavaScript, or whatever I need to use CMS? [49:33.250 --> 49:37.290] And, correct me if my mom, I think what they're saying is, don't not use any of these tools ever. [49:37.510 --> 49:43.150] Just know that each one you use increases the attack service, and increases the potential for leaking. [49:43.470 --> 49:45.490] So obviously if you need JavaScript, use it. [49:45.490 --> 49:48.450] But they'll just throw it around if you don't really need it. [49:48.650 --> 49:49.910] Just, is that correct? [49:50.490 --> 49:51.110] Yeah, yeah. [49:51.190 --> 49:51.730] You could... [49:51.730 --> 49:53.490] Can you ask, like, can I ever use a CMS? [49:53.610 --> 50:02.290] Yeah, you could definitely use JavaScript, and CMSs are great, and stuff, but, you know, there's ways to harden it, and there's ways to make it so that you aren't leaking private data of your visitors. [50:03.030 --> 50:04.690] Yeah, I just want to add one thing. [50:04.930 --> 50:12.350] I mean, in addition to using, like, third-party JavaScript, or something, what you're seeing more and more of, is iframe embed, that you go to a site, [50:21.850 --> 50:26.070] any time you see an iframe embed code from the site, you're really f*cking careful. [50:26.310 --> 50:26.650] Yeah. [50:27.070 --> 50:30.230] I mean, you could also do the, like, opt-in thing. [50:30.410 --> 50:33.310] Like, don't actually include the iframe until people click something. [50:33.470 --> 50:35.430] And that's an example of using JavaScript. [50:35.610 --> 50:41.110] Like, if you want people to be able to, like, look at this Vimeo video, you have to use JavaScript to do that. [50:59.260 --> 51:02.340] Like, if your server gets hacked and they get your password list? [51:02.540 --> 51:04.360] I mean, that kind of sucks when that happens anyway. [51:08.180 --> 51:09.240] Yeah, I don't know. [51:09.360 --> 51:12.820] I actually haven't looked at, like, what hashing HT password files use. [51:13.340 --> 51:15.020] I just use the... [51:16.080 --> 51:16.480] Okay. [51:16.840 --> 51:17.720] Which isn't good. [51:20.020 --> 51:20.760] Yeah, I don't know. [51:20.760 --> 51:22.860] I'm not sure if there's ways to make that better or not. [51:26.160 --> 51:27.600] Yeah, I just think that's correct. [51:28.300 --> 51:29.020] Anyone else? [51:34.920 --> 51:38.720] It's kind of like, all right, so these are all great recommendations. [51:38.720 --> 51:41.240] I've actually been smart to be here a little bit later. [51:41.460 --> 51:42.740] But one of the pro... [51:42.740 --> 51:44.620] I think one of the main problems is... [51:44.620 --> 51:46.540] I'm just gonna ask you is... [51:46.540 --> 51:47.360] Is the technical problem [51:55.530 --> 51:56.550] any of this shit? [51:56.930 --> 51:59.330] So what is a good way that you think... [51:59.330 --> 52:04.170] Do you say this to people who, like, their biggest accomplishment was installing WordPress? [52:04.430 --> 52:04.810] Yeah. [52:07.750 --> 52:08.190] Um... [52:08.190 --> 52:09.090] I don't... [52:09.090 --> 52:09.590] I mean, I don't know. [52:09.590 --> 52:11.450] Because it's not easy to do this stuff. [52:11.650 --> 52:12.150] It's like... [52:12.530 --> 52:21.710] Like, if you want to include a widget and proxy the ADRAX request and stuff, you have to, like, kind of have a pretty deep understanding of all the moving parts to do that. [52:21.830 --> 52:23.090] And so... [52:23.930 --> 52:24.290] Um... [52:24.290 --> 52:24.830] I don't know. [52:24.970 --> 52:25.870] Like, I wish it were easier. [52:26.010 --> 52:29.470] Like, I think us making more privacy-friendly stuff that's easy. [52:29.470 --> 52:30.910] Like, if... [52:32.190 --> 52:32.630] Uh... [52:32.630 --> 52:32.850] Uh... [52:32.850 --> 52:33.250] If... [52:33.250 --> 52:34.130] If... [52:34.130 --> 52:40.530] You know, when you make embed code for people to embed stuff on their websites, like, include the opt-in thing yourself. [52:40.650 --> 52:42.570] So that everyone will have this opt-in. [52:42.690 --> 52:43.550] And things like that. [52:44.990 --> 52:45.430] Um... [52:45.430 --> 52:48.690] But yeah, I mean, I know there's a lot of people who, like, are, like, an activist. [52:48.750 --> 52:51.390] And they make a bunch of websites for all of these groups. [52:51.530 --> 52:55.730] Like, I've made websites for, like, 20 different groups in the past several years. [52:55.730 --> 52:57.770] And, uh... [52:57.770 --> 52:59.070] If I had... [52:59.070 --> 53:01.090] And, like, this was, like, eight years ago and stuff. [53:01.190 --> 53:05.410] If I had known all this stuff back then, all the websites they would have made would have been much more private. [53:05.630 --> 53:13.730] And so I think that, like, the nerds who are in activist groups, who are, like, the people making the websites, if they learn this stuff, like... [53:14.470 --> 53:14.850] Um... [53:14.850 --> 53:17.430] Then I think that that is a good way of doing it. [53:18.550 --> 53:24.890] Being that you work with EFF, can't EFF push guidelines to encourage WordPress and other type... [53:24.890 --> 53:27.670] And even Google Analytics and even things like that. [53:27.870 --> 53:28.770] Can't they... [53:29.590 --> 53:33.310] Can't EFF publish guidelines so that... [53:33.310 --> 53:35.230] You know, it kind of... [53:35.230 --> 53:40.270] You know, hold these other aggregators to, like, why are you doing this? [53:40.570 --> 53:46.990] You know, like, make a list of, you know, Drupal sucks button or something, you know, until they fix it, you know. [53:47.350 --> 53:48.950] And let people know which... [53:48.950 --> 53:49.310] Yeah. [53:49.310 --> 53:49.470] Uh... [53:50.430 --> 53:51.630] Well, all the... [53:51.630 --> 53:56.510] I mean, it's not like if you install Drupal or WordPress, it will be un-privacy-friendly by default. [53:56.750 --> 54:00.090] It's just that, um, people on top of that add Twitter buttons and stuff. [54:00.450 --> 54:00.810] And it's... [54:00.810 --> 54:01.830] I think that it... [54:01.830 --> 54:03.430] That there's no way of using... [54:03.430 --> 54:05.870] It's impossible to use Google Analytics in a privacy-friendly way. [54:06.170 --> 54:06.990] You just can't. [54:07.090 --> 54:11.810] And so there's nothing that we could tell Google to make it more privacy-friendly, because we're sending them all data. [54:11.910 --> 54:15.490] It's just the nature of how third-party services that you hook into your site work. [54:16.230 --> 54:16.590] Um... [54:16.590 --> 54:19.010] Which sucks, because there's a lot of stuff that's really cool. [54:19.690 --> 54:23.630] It's like the modern web is like a platform, and you stick everything together, and... [54:24.430 --> 54:25.150] Like Padmapper. [54:25.350 --> 54:25.890] It's like... [54:25.890 --> 54:35.490] It scrapes Craigslist for, you know, apartments, and then puts them on a map for you, and it's awesome, but it's impossible to make Padmapper without, like, sending all of your visitors' data to Google. [54:35.990 --> 54:41.490] Unless you, like, you know, use OpenStreetMaps and host the whole mapping database yourself or something, and then that's, like, a lot more expensive. [54:41.490 --> 54:57.210] And so, uh, I mean, I think that some of this stuff is just hard to do, and, um, uh, for people who are especially higher risk, like activists, it's important to just take those trade-offs. [55:14.780 --> 55:15.180] Right. [55:15.700 --> 55:21.000] So how much of these problems is laziness on developers' side, and how much of it is, uh, like, uh... [55:21.000 --> 55:21.920] Just the world we live in. [55:22.140 --> 55:23.120] Just the world we live in? [55:23.260 --> 55:26.460] I mean, I think that developers don't know about this. [55:26.640 --> 55:38.040] I think that, like, there's tons of people who are making websites for, like, you know, different Occupies in, like, Texas and wherever else who have no idea that they shouldn't be including Google web fonts from Google servers. [55:38.320 --> 55:42.140] And they, you know, like, if they knew about it, maybe they would do it, but they just don't know about it. [55:42.200 --> 55:43.980] So that's why I'm giving this talk. [55:46.180 --> 55:47.960] Uh, okay, I think my time is up now. [55:48.260 --> 55:48.820] Thank you.