Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #270469 > unrolled thread
| Started by | Lee <ler762@gmail.com> |
|---|---|
| First post | 2024-06-25 16:00 +0200 |
| Last post | 2024-07-06 17:50 +0200 |
| Articles | 20 on this page of 48 — 18 participants |
Back to article view | Back to linux.debian.user
how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 16:00 +0200
Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 16:30 +0200
Re: how2 format a flash drive David Wright <deblis@lionunicorn.co.uk> - 2024-06-25 16:50 +0200
Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 18:30 +0200
Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 18:50 +0200
Re: how2 format a flash drive eben@gmx.us - 2024-06-25 19:20 +0200
Re: how2 format a flash drive David Wright <deblis@lionunicorn.co.uk> - 2024-06-26 01:00 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 21:40 +0200
Re: how2 format a flash drive Joe <joe@jretrading.com> - 2024-06-25 17:50 +0200
Re: how2 format a flash drive Hans <hans.ullrich@loop.de> - 2024-06-25 18:50 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-26 01:30 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 21:50 +0200
Re: how2 format a flash drive eben@gmx.us - 2024-06-25 22:20 +0200
Re: how2 format a flash drive George at Clug <Clug@goproject.info> - 2024-06-26 01:30 +0200
Re: how2 format a flash drive sd@swampdog.co.uk - 2024-06-27 15:30 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-29 18:50 +0200
Re: how2 format a flash drive Dan Ritter <dsr@randomstring.org> - 2024-06-29 19:40 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-01 04:40 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-01 07:50 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-01 15:10 +0200
Re: how2 format a flash drive <tomas@tuxteam.de> - 2024-07-01 15:50 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-01 21:30 +0200
Re: how2 format a flash drive Stefan Monnier <monnier@iro.umontreal.ca> - 2024-07-02 05:50 +0200
Re: how2 format a flash drive gene heskett <gheskett@shentel.net> - 2024-07-02 06:10 +0200
Re: how2 format a flash drive <tomas@tuxteam.de> - 2024-07-02 06:40 +0200
Re: how2 format a flash drive George at Clug <Clug@goproject.info> - 2024-07-02 06:50 +0200
Re: how2 format a flash drive Jeffrey Walton <noloader@gmail.com> - 2024-07-02 10:20 +0200
Telemetry, data hoarding [was: how2 format a flash drive] <tomas@tuxteam.de> - 2024-07-02 10:30 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-02 11:20 +0200
Re: how2 format a flash drive John Hasler <john@sugarbit.com> - 2024-07-02 17:20 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-02 10:30 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-02 11:30 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-02 22:40 +0200
Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-06-29 22:50 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-06-30 03:40 +0200
Re: Browser traffic interception/inspection Jeffrey Walton <noloader@gmail.com> - 2024-06-30 08:00 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-06-30 17:40 +0200
Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-01 09:00 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-07-01 17:10 +0200
Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-07 23:50 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-07-08 04:40 +0200
Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-08 16:30 +0200
Re: Browser traffic interception/inspection (was: how2 format a flash drive) Lee <ler762@gmail.com> - 2024-07-01 03:40 +0200
Re: Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-07-01 03:50 +0200
Re: Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-07-01 07:50 +0200
Re: how2 format a flash drive Keith Bainbridge <keithrbau@gmail.com> - 2024-06-30 08:20 +0200
Re: how2 format a flash drive Jeffrey Walton <noloader@gmail.com> - 2024-07-01 08:00 +0200
Re: how2 format a flash drive Marc SCHAEFER <schaefer@alphanet.ch> - 2024-07-06 17:50 +0200
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-07-01 15:50 +0200 |
| Message-ID | <IVpzP-6WvG-3@gated-at.bofh.it> |
| In reply to | #270704 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Jul 01, 2024 at 09:05:51AM -0400, Lee wrote: > On Mon, Jul 1, 2024 at 4:53 AM jeremy ardley <jeremy.ardley@gmail.com> wrote: [...] > > https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer > > Thanks, but no thanks. That seems to include the Microsoft spyware > licensing: https://code.visualstudio.com/license > Data Collection. The software may collect information about you and > your use of the software, and send that to Microsoft. Desperate for Data :-) But yes, that's what they currently do. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | jeremy ardley <jeremy.ardley@gmail.com> |
|---|---|
| Date | 2024-07-01 21:30 +0200 |
| Message-ID | <IVuSR-6ZOf-1@gated-at.bofh.it> |
| In reply to | #270704 |
On 1/7/24 21:05, Lee wrote: >> Visual Studio Code allows you to edit HTML and preview it using Live >> Server plugin >> >> https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer > Thanks, but no thanks. That seems to include the Microsoft spyware > licensing: https://code.visualstudio.com/license > Data Collection. The software may collect information about you and > your use of the software, and send that to Microsoft. > VS Code Telemetry is easily turned off. https://code.visualstudio.com/docs/getstarted/telemetry#_disable-telemetry-reporting In the more general case, telemetry is not in itself considered 'evil'. For example Debian comes with telemetry that you can enable or disable. https://popcon.debian.org/ Firefox, and just about any other web browser you use also has telemetry. e.g. https://support.mozilla.org/en-US/kb/telemetry-clientid To be certain your activity is private you will have to disconnect completely from the internet as any software that uses any internet resource will automatically leak information about you. .
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2024-07-02 05:50 +0200 |
| Message-ID | <IVCGJ-74AX-1@gated-at.bofh.it> |
| In reply to | #270717 |
> In the more general case, telemetry is not in itself
> considered 'evil'.
I consider it evil if it's opt-out rather than opt-in.
Stefan
[toc] | [prev] | [next] | [standalone]
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2024-07-02 06:10 +0200 |
| Message-ID | <IVD05-74X3-5@gated-at.bofh.it> |
| In reply to | #270720 |
On 7/1/24 23:41, Stefan Monnier wrote: >> In the more general case, telemetry is not in itself >> considered 'evil'. > > I consider it evil if it's opt-out rather than opt-in. > > > Stefan > I think that highly depends on what that telemetry is sending. Crash reports, yes, contents of a list of phone numbers it found, not no, but hell no! Ditto for passwords and such. Cheers, Gene Heskett, CET. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-07-02 06:40 +0200 |
| Message-ID | <IVDt7-75bZ-7@gated-at.bofh.it> |
| In reply to | #270720 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Jul 01, 2024 at 11:40:56PM -0400, Stefan Monnier wrote: > > In the more general case, telemetry is not in itself > > considered 'evil'. > > I consider it evil if it's opt-out rather than opt-in. Absolutely. Plus (a) I don't trust most vendors to be telling the truth whenever their bottom line is at stake and (b) I've seen enough dark patterns to nudge users to not opt out to be more than disgusted. Just... no. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | George at Clug <Clug@goproject.info> |
|---|---|
| Date | 2024-07-02 06:50 +0200 |
| Message-ID | <IVDCN-75fc-1@gated-at.bofh.it> |
| In reply to | #270720 |
[Multipart message — attachments visible in raw view] — view raw
Is telemetry evil? Are guns evil? Philosophical questions? I find it objectionable when people gather "telemetry" about "me" and not just the causes of the "blue screens of death". I find it objectionable when people gather personal "telemetry" and then on sell that information to others for whatever purposes, whether it is to target me with ads, or political analysts like Cambridge Analytica, or to alter my "Social Credit Score", or to be used to cancel my Credit Cards, or for whatever other purpose. While collecting information about individuals and selling their data is common practice these days, I object. I cannot stop it, but I can at least use systems that gather such data as minimally as possible. Hopefully by using Linux for 99% of my computing experience, I am giving Google and Windows less data. Of course, by the mere fact of visiting a web site (for example, that has Google Analytics installed), and by writing emails like this that well be scanned, and then this data will be added to my profile by any companies collecting data to gain some view of me, which they will then sell to political groups, marketers, etc. Scott McNally’s quip that ‘you have no privacy, get over it’ is sadly true, but I don't think he meant that we have to resign ourselves to this fast, we can but do what we can to reduce the data collected, even while realising our efforts are mostly in vain. https://lockstep.com.au/library/quotes/ Privacy is an interesting topic. What has privacy to do with a Debian User email list? Well I am hoping by using Debian less of my data ends up in large tech company hands. At least let me dream that it does. I encourage others to use Debian, if by doing so will let them sleep better at night, even if it is in ignorance. George. On Tuesday, 02-07-2024 at 13:40 Stefan Monnier wrote: > In the more general case, telemetry is not in itself > considered 'evil'. I consider it evil if it's opt-out rather than opt-in. Stefan
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-07-02 10:20 +0200 |
| Message-ID | <IVGU1-77kM-3@gated-at.bofh.it> |
| In reply to | #270723 |
On Tue, Jul 2, 2024 at 3:53 AM George at Clug <Clug@goproject.info> wrote: > > Is telemetry evil? Are guns evil? Philosophical questions? > > I find it objectionable when people gather "telemetry" about "me" and not just the causes of the "blue screens of death". > > I find it objectionable when people gather personal "telemetry" and then on sell that information to others for whatever purposes, whether it is to target me with ads, or political analysts like Cambridge Analytica, or to alter my "Social Credit Score", or to be used to cancel my Credit Cards, or for whatever other purpose. For those interested in reading more, pick up a copy of Shoshana Zuboff's book The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power (<https://www.amazon.com//dp/1610395697> and <https://en.wikipedia.org/wiki/Surveillance_capitalism>). Jeff
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-07-02 10:30 +0200 |
| Subject | Telemetry, data hoarding [was: how2 format a flash drive] |
| Message-ID | <IVH3I-77nR-7@gated-at.bofh.it> |
| In reply to | #270724 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Jul 02, 2024 at 04:09:39AM -0400, Jeffrey Walton wrote: > On Tue, Jul 2, 2024 at 3:53 AM George at Clug <Clug@goproject.info> wrote: > > > > Is telemetry evil? Are guns evil? Philosophical questions? > > > > I find it objectionable when people gather "telemetry" about "me" and not just the causes of the "blue screens of death". > > > > I find it objectionable when people gather personal "telemetry" and then on sell that information to others for whatever purposes, whether it is to target me with ads, or political analysts like Cambridge Analytica, or to alter my "Social Credit Score", or to be used to cancel my Credit Cards, or for whatever other purpose. > > For those interested in reading more, pick up a copy of Shoshana > Zuboff's book The Age of Surveillance Capitalism: The Fight for a > Human Future at the New Frontier of Power > (<https://www.amazon.com//dp/1610395697> and > <https://en.wikipedia.org/wiki/Surveillance_capitalism>). Thanks for that ref. One of the most important books for our trade, indeed. If possible, don't buy it at Amazon :-) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | jeremy ardley <jeremy.ardley@gmail.com> |
|---|---|
| Date | 2024-07-02 11:20 +0200 |
| Message-ID | <IVHQ5-77U9-3@gated-at.bofh.it> |
| In reply to | #270723 |
On 2/7/24 12:47, George at Clug wrote: > > Scott McNally’s quip that ‘you have no privacy, get over it’ is sadly > true, but I don't think he meant that we have to resign ourselves to > this fast, we can but do what we can to reduce the data collected, > even while realising our efforts are mostly in vain. Linedkin is worse than any organisation I know of. I signed up very reluctantly with a fake profile and a throw-awy email address and the first thing it suggested was to link to immediate family and people it had no way of knowing I was related to. I can only guess they have profiled my browser signature and worked off that. If you are or ever have been a user of Linkedin your privacy is worse than zero. You are a product that can be bought and sold and almost everything you see and hear will be managed by them or their customers. I class that entirely differently to application telemetry with an option to opt out. Back on my original post I use Visual Studio Code because it is a very useful tool and has a broad community of people in the open source community. I rate VS Code significantly less intrusive than github which, with no option to opt out, scans all your private repositories to gain information about you that it can package and resell 'anonymously'. Even if you aren't a user of github, your access to download is recorded and included in the data it resells.
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2024-07-02 17:20 +0200 |
| Message-ID | <IVNst-7bwL-3@gated-at.bofh.it> |
| In reply to | #270723 |
George at Clug writes: > While collecting information about individuals and selling their data > is common practice these days It's common practice because people won't pay for services but will tolerate advertising. > Of course, by the mere fact of visiting a web site (for example, that > has Google Analytics installed) I've never visited a site that cares that I block Google Analytics. The best way to protect your "personal information" is to not have accounts with any of the popular "social media" services, especially Google, Facebook, and Twitter (and never use Windows, of course). -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-02 10:30 +0200 |
| Message-ID | <IVH3I-77nR-9@gated-at.bofh.it> |
| In reply to | #270717 |
On Mon, Jul 1, 2024 at 6:13 PM jeremy ardley wrote: > > > On 1/7/24 21:05, Lee wrote: > >> Visual Studio Code allows you to edit HTML and preview it using Live > >> Server plugin > >> > >> https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer > > Thanks, but no thanks. That seems to include the Microsoft spyware > > licensing: https://code.visualstudio.com/license > > Data Collection. The software may collect information about you and > > your use of the software, and send that to Microsoft. > > > VS Code Telemetry is easily turned off. > > https://code.visualstudio.com/docs/getstarted/telemetry#_disable-telemetry-reporting Except the license says You may opt-out of many of these scenarios, but not all, as described in the product documentation located at https://code.visualstudio.com/docs/supporting/faq#_how-to-disable-telemetry-reporting. So 1. you can't opt-out of _all_ telemetry. .. at least according to the license. 2. opt-out is evil. Any group that uses opt-out is evil. They only do opt-out because they _know_ almost no one would opt-in. > In the more general case, telemetry is not in itself considered 'evil'. Anything opt-out I consider 'evil'. > For example Debian comes with telemetry that you can enable or disable. > https://popcon.debian.org/ That's opt-in, so a completely different case. > Firefox, and just about any other web browser you use also has > telemetry. e.g. https://support.mozilla.org/en-US/kb/telemetry-clientid I know & I don't like it. But it's like apple vs. google -- which one is less evil? I have an iPhone so that should tell you what I think. > To be certain your activity is private you will have to disconnect > completely from the internet as any software that uses any internet > resource will automatically leak information about you. If I use Internet resources I know that I can be tracked .. but **only when using the Internet**. Microsoft spyware is always-on tracking that can't be turned completely off. And if I don't want to leave Internet footprints - or if I just want to give the finger to whoever is watching, I'll use the tor browser. So I have options when I get on the Internet. I don't see any options when the OS or my tools are spying on me other than don't use that OS or those tools. Regards, Lee
[toc] | [prev] | [next] | [standalone]
| From | jeremy ardley <jeremy.ardley@gmail.com> |
|---|---|
| Date | 2024-07-02 11:30 +0200 |
| Message-ID | <IVHZL-77Xj-1@gated-at.bofh.it> |
| In reply to | #270727 |
[Multipart message — attachments visible in raw view] — view raw
On 2/7/24 16:24, Lee wrote: > And if I don't want to leave Internet footprints - or if I just want > to give the finger to whoever is watching, I'll use the tor browser. That is probably the worst thing you can do. On my last check *most* Tor exit points are operated by intelligence or police agencies. Going about your business just using a regular ISP makes it unlikely anyone will pay attention to you unless you frequent disreputable sites. Using Tor will automatically put you on a watch list. Your identity can easily be found because your ip address at the exit point will be recorded and matched with ISP records.
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-02 22:40 +0200 |
| Message-ID | <IVSs9-7eGR-3@gated-at.bofh.it> |
| In reply to | #270730 |
On Tue, Jul 2, 2024 at 5:27 AM jeremy ardley wrote: > > > On 2/7/24 16:24, Lee wrote: > > And if I don't want to leave Internet footprints - or if I just want > to give the finger to whoever is watching, I'll use the tor browser. > > > That is probably the worst thing you can do. On my last check *most* Tor exit points are operated by intelligence or police agencies. OK.. I'll bite. How do you know most Tor exit points are operated by intelligence or police agencies? I mean, it sounds reasonable, but how do you *know*? > Going about your business just using a regular ISP makes it unlikely anyone will pay attention to you unless you frequent disreputable sites. > > Using Tor will automatically put you on a watch list. Yeah. I've heard that too. But using tor - or any encryption, is still legal, so what I'm doing doesn't even rise to the level of civil disobedience. So if they're going to put me on a list, they're going to put me on a list. I've been using tor since however long ago when it came bundled with privoxy, so I doubt that me not using tor now is going to make a difference. > Your identity can easily be found because your ip address at the exit point will be recorded and matched with ISP records. Indeed. The TOR documentation used to be up-front about tor not being proof against a global adversary, so I doubt the NSA needs to bother my ISP asking for records. I was just poking around on torproject.org (which has been rumored to be enough to get one on a watch list) and I don't see any strong warnings about using tor :( Or even much of anything that would discourage one from using TOR. Oh well.. I guess they need lots of cannon fodder to provide covering traffic for .. who? Regards, Lee
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-06-29 22:50 +0200 |
| Subject | Browser traffic interception/inspection (was: how2 format a flash drive) |
| Message-ID | <IUNbc-6wz8-17@gated-at.bofh.it> |
| In reply to | #270603 |
On Sat, Jun 29, 2024 at 4:13 PM Lee <ler762@gmail.com> wrote: > > [...] Debian firefox does NOT allow one to do > TLS intercept - ie. this does not work: > C:\UTIL>cat firefox-tlsdecode.bat > set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt > start C:\"Program Files\Firefox\Firefox.exe" > > @rem wireshark: > @rem edit / preferences > @rem protocols / tls (v2.6: protocols / ssl) > @rem paste SSLKEYLOGFILE filename into (Pre)-Master-Secret log > filename (was SSL debug file entry) I'm not sure who your complaint is against -- Debian, Firefox or Linux. I'm also not sure that it is a valid complaint. Firefox uses its own certificate store. If you want to proxy your traffic, then the proxy's root cert needs to be in Mozilla's certificate store. See <https://support.mozilla.org/en-US/kb/setting-certificate-authorities-firefox>. Chrome is different. Chrome uses the Windows store by default, but also has its own certificate store. For Chrome, your Windows admin can make a change with a Group Policy, and Chrome will pick it up through the Windows certificate store. Or you can manually install the proxy's root cert. See <https://chromium.googlesource.com/chromium/src/+/main/net/data/ssl/chrome_root_store/faq.md>. Debian is not concerned about TLS interception in this case. But for completeness, Debian has its own store at /etc/ssl/certs. You get the certificates by installing the ca-certificates package. You can install certificates into the store by dropping the root cert on the filesystem at /usr/local/share/ca-certificates, and then running update-ca-certificates. See <https://wiki.debian.org/Firefox/PrivateCertificateAuthority> and <https://manpages.debian.org/buster/ca-certificates/update-ca-certificates.8.en.html>. When you are intercepting/inspecting traffic, you typically setup your proxy, and then proxy Firefox and Chrome traffic through your proxy. The proxy can run on your local machine, like 127.0.0.1. Your proxy's root certificate should be in the browser's store (as described above). Jeff
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2024-06-30 03:40 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IURHP-6zr6-1@gated-at.bofh.it> |
| In reply to | #270616 |
On 30/06/2024 03:45, Jeffrey Walton wrote: > On Sat, Jun 29, 2024 at 4:13 PM Lee wrote: >> >> [...] Debian firefox does NOT allow one to do >> TLS intercept - ie. this does not work: >> C:\UTIL>cat firefox-tlsdecode.bat >> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt >> start C:\"Program Files\Firefox\Firefox.exe" [...] > I'm not sure who your complaint is against -- Debian, Firefox or > Linux. I'm also not sure that it is a valid complaint. I do not mind to see a link stating that the appropriate logger is really disabled. Certainly dumping of TLS session keys may be disabled through a compile time flag similar to enforcing signatures for add-ons. It may be default Firefox configuration for release builds or some line in Debian build rules. It still might be some mistake during attempts to enable the logger. I have read about this approach but I have never tried it in action. > Firefox uses its own certificate store. It is relevant to active traffic interception you described (a proxy). Lee prefers passive traffic sniffing and it requires cooperation from a peer to get session keys. Each case has its own advantages. P.S. At first it was not clear to me that having TLS private key (copied from the server) is not enough for passive traffic decryption. Diffie-Hellman key exchange scheme allows to generate secret keys even over public channel. The main purpose of TLS certificates (public keys in the browser or system store) is to confirm that there is no attacker in between that blocks packets from the client and establishes its own connection to the server. Encryption of email messages using a public key is a different case. Session keys are required to debug TLS applications.
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-06-30 08:00 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IUVLr-6Cpg-1@gated-at.bofh.it> |
| In reply to | #270623 |
On Sat, Jun 29, 2024 at 9:37 PM Max Nikulin <manikulin@gmail.com> wrote:
>
> On 30/06/2024 03:45, Jeffrey Walton wrote:
> > On Sat, Jun 29, 2024 at 4:13 PM Lee wrote:
> >>
> >> [...] Debian firefox does NOT allow one to do
> >> TLS intercept - ie. this does not work:
> >> C:\UTIL>cat firefox-tlsdecode.bat
> >> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
> >> start C:\"Program Files\Firefox\Firefox.exe"
> [...]
> > I'm not sure who your complaint is against -- Debian, Firefox or
> > Linux. I'm also not sure that it is a valid complaint.
>
> I do not mind to see a link stating that the appropriate logger is
> really disabled. Certainly dumping of TLS session keys may be disabled
> through a compile time flag similar to enforcing signatures for add-ons.
> It may be default Firefox configuration for release builds or some line
> in Debian build rules. It still might be some mistake during attempts to
> enable the logger. I have read about this approach but I have never
> tried it in action.
>
> > Firefox uses its own certificate store.
>
> It is relevant to active traffic interception you described (a proxy).
> Lee prefers passive traffic sniffing and it requires cooperation from a
> peer to get session keys. Each case has its own advantages.
As far as I know, the browsers support active interception. That is,
"interception is a valid use case" for the browsers to support
Dataloss Prevention (DLP) programs. The browsers do that through the
use of interception proxies and root CA's used in the DLP program.
Browsers do not support the passive capture/replay that OP wants. That
is, they don't support exporting the premaster secret or the derived
master secret.
The browsers use tortured logic to arrive at "interception is a valid
use case". They hang it off of the W3C's Design Principles and
Priorities of Constituencies. The browser's argument goes as such: if
a user did not want to be intercepted, then the CA certificate used
for interception would not be present in the certificate store. Since
the proxy's interception certificate is present in the store, the user
wants to be intercepted. (You can't make this shit up).
A corollary to "interception is a valid use case" is, webapps can
never be sure they have a secure channel. Therefore, webapps can only
handle low value data. Higher value data should be handled by hybrid
and native apps.
> At first it was not clear to me that having TLS private key (copied from
> the server) is not enough for passive traffic decryption. Diffie-Hellman
> key exchange scheme allows to generate secret keys even over public
> channel...
Correct. You also need ClientHello.random and ServerHello.random since
the master secret is computed from
(https://datatracker.ietf.org/doc/html/rfc5246#section-8.1):
master_secret = PRF(pre_master_secret, "master secret",
ClientHello.random + ServerHello.random)
[0..47];
Something some folks don't realize is, ClientHello.random and
ServerHello.random are also used for key transport schemes like RSA,
when the client encrypts the premaster secret and sends it to the
server. The ClientHello.random and ServerHello.random are present to
ensure both sides contribute to the master secret. Otherwise, only the
client would contribute to the master secret in a key transport
scheme.
> The main purpose of TLS certificates (public keys in the
> browser or system store) is to confirm that there is no attacker in
> between that blocks packets from the client and establishes its own
> connection to the server.
No, not quite. Interception is a valid use case under the browser's
security model.
You can achieve what you are getting at, but you need to use hybrid
and native apps that practice host public key pinning. You need hybrid
and native apps because they can usually obtain the host's public key.
But the browsers don't expose the host public key to the webapp. So
webapps have no way to perform pinning. You can't even get the public
key from a WebSocket.
> Encryption of email messages using a public
> key is a different case. Session keys are required to debug TLS
> applications.
Email transport security is an absolute mess due to opportunistic
encryption and smart hosts. About the best you can do is, encrypt and
sign the message, and send it over an insecure channel.
Jeff
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2024-06-30 17:40 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IV4OJ-6Ige-13@gated-at.bofh.it> |
| In reply to | #270635 |
On 30/06/2024 12:56, Jeffrey Walton wrote: >>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote: >>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt >>>> start C:\"Program Files\Firefox\Firefox.exe" [...] > Browsers do not support the passive capture/replay that OP wants. Lee, may you, please, specify Firefox version and release channel you are using on Windows where this feature is working?
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-01 09:00 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IVjb3-6Sef-5@gated-at.bofh.it> |
| In reply to | #270662 |
On Sun, Jun 30, 2024 at 11:30 AM Max Nikulin wrote: > > On 30/06/2024 12:56, Jeffrey Walton wrote: > >>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote: > >>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt > >>>> start C:\"Program Files\Firefox\Firefox.exe" > [...] > > Browsers do not support the passive capture/replay that OP wants. It works for me in Windows. This looks like the Debian bug report https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292 > Lee, may you, please, specify Firefox version and release channel you > are using on Windows where this feature is working? Firefox 115.12.0esr -- which is the current extended service release software I'm not sure what you mean by release channel .. ESR? If I go to https://www.mozilla.org/en-US/firefox/115.12.0/releasenotes/ under "Download Firefox" there's links to Windows 64-bit and Windows 64-bit MSI wow! I've been letting firefox update itself for awhile now. What I installed was Firefox Setup 68.3.0esr.msi Lee
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2024-07-01 17:10 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IVqPg-6XpD-17@gated-at.bofh.it> |
| In reply to | #270692 |
On 01/07/2024 13:57, Lee wrote: > On Sun, Jun 30, 2024 at 11:30 AM Max Nikulin wrote: >>>>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote: >>>>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt >>>>>> start C:\"Program Files\Firefox\Firefox.exe" > > This looks like the Debian bug report > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292 > >> Lee, may you, please, specify Firefox version and release channel you >> are using on Windows where this feature is working? > > Firefox 115.12.0esr -- which is the current extended service release software > I'm not sure what you mean by release channel .. ESR? Thanks. I expected that you may use either developer release, beta, or even nightly. Is libnss built with logging support ABI compatible with the variant in Debian repositories? (Or can it be patched to achieve ABI compatibility?) Instead of asking for changing compile flags for all users, from my point of view, it is better to suggest alternative packages with and without logging enabled. Browsers are rather sensitive applications, so I find it reasonable that dumping of encryption keys are not available by default. However debugging should be possible and should require special configuration. I have not tried .deb packages provided by Mozilla. Since their Windows builds allows logging, it might work on Linux as well. <https://support.mozilla.org/en-US/kb/install-firefox-linux#w_install-firefox-deb-package-for-debian-based-distributions>
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-07 23:50 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IXHVD-xLQ-5@gated-at.bofh.it> |
| In reply to | #270707 |
Hi, On Mon, Jul 1, 2024 at 11:02 AM Max Nikulin wrote: > > On 01/07/2024 13:57, Lee wrote: > > On Sun, Jun 30, 2024 at 11:30 AM Max Nikulin wrote: > >>>>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote: > >>>>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt > >>>>>> start C:\"Program Files\Firefox\Firefox.exe" > > > > This looks like the Debian bug report > > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292 > > > >> Lee, may you, please, specify Firefox version and release channel you > >> are using on Windows where this feature is working? > > > > Firefox 115.12.0esr -- which is the current extended service release software > > I'm not sure what you mean by release channel .. ESR? > > Thanks. I expected that you may use either developer release, beta, or > even nightly. Nope - just regular firefox-esr > Is libnss built with logging support ABI compatible with the variant in > Debian repositories? (Or can it be patched to achieve ABI > compatibility?) Instead of asking for changing compile flags for all > users, from my point of view, it is better to suggest alternative > packages with and without logging enabled. > > Browsers are rather sensitive applications, so I find it reasonable that > dumping of encryption keys are not available by default. Maybe I don't know enough to know what's "reasonable" or not.. but I don't see a problem with me being able to inspect the traffic between me and some website. Anyone else wants to intercept my traffic and they'll have to set an environment variable - which root can do, but who else? > However > debugging should be possible and should require special configuration. > > I have not tried .deb packages provided by Mozilla. Since their Windows > builds allows logging, it might work on Linux as well. > <https://support.mozilla.org/en-US/kb/install-firefox-linux#w_install-firefox-deb-package-for-debian-based-distributions> Thanks for the pointer to downloading firefox from mozilla. But wow!! plenty too many instructions for to be able to Install Firefox .deb package for Debian-based distributions I suppose it's funny that I have no qualms with SSLKEYLOGFILE=<whatever> but balk at following those instructions to modify apt-get actions, but I don't know how to evaluate the security implications of modifying apt-get files. So I just downloaded the binary from mozilla and went from there: get the 64 bit linux version of firefox esr from https://www.mozilla.org/en-US/firefox/all/#product-desktop-esr tar -xvf firefox-115.12.0esr.tar.bz2 sudo mv firefox /opt/firefox-115.12.0esr/ sudo ln -s /opt/firefox-115.12.0esr/firefox /usr/local/bin/firefox lee@laptop:~$ cat ~/bin/firefox-tlsdecode.sh #!/bin/bash # set things up so that wireshark can decrypt firefox tls traffic umask 077 SSLKEYLOGFILE=/tmp/FF-SSLkeys.txt export SSLKEYLOGFILE /usr/local/bin/firefox "$@" & # then in wireshark: # edit / preferences # protocols / tls (v2.6: protocols / ssl) # paste SSLKEYLOGFILE filename into (Pre)-Master-Secret log filename lee@laptop:~$ So now I've got the debian /usr/bin/firefox that doesn't allow export tls keys and a /usr/local/bin/firefox that does. Thanks Lee
[toc] | [prev] | [next] | [standalone]
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web