Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #270469 > unrolled thread

how2 format a flash drive

Started byLee <ler762@gmail.com>
First post2024-06-25 16:00 +0200
Last post2024-07-06 17:50 +0200
Articles 20 on this page of 48 — 18 participants

Back to article view | Back to linux.debian.user


Contents

  how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 16:00 +0200
    Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 16:30 +0200
      Re: how2 format a flash drive David Wright <deblis@lionunicorn.co.uk> - 2024-06-25 16:50 +0200
        Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 18:30 +0200
          Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 18:50 +0200
        Re: how2 format a flash drive eben@gmx.us - 2024-06-25 19:20 +0200
          Re: how2 format a flash drive David Wright <deblis@lionunicorn.co.uk> - 2024-06-26 01:00 +0200
      Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 21:40 +0200
    Re: how2 format a flash drive Joe <joe@jretrading.com> - 2024-06-25 17:50 +0200
      Re: how2 format a flash drive Hans <hans.ullrich@loop.de> - 2024-06-25 18:50 +0200
        Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-26 01:30 +0200
      Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 21:50 +0200
        Re: how2 format a flash drive eben@gmx.us - 2024-06-25 22:20 +0200
        Re: how2 format a flash drive George at Clug <Clug@goproject.info> - 2024-06-26 01:30 +0200
          Re: how2 format a flash drive sd@swampdog.co.uk - 2024-06-27 15:30 +0200
          Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-29 18:50 +0200
            Re: how2 format a flash drive Dan Ritter <dsr@randomstring.org> - 2024-06-29 19:40 +0200
              Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-01 04:40 +0200
                Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-01 07:50 +0200
                  Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-01 15:10 +0200
                    Re: how2 format a flash drive <tomas@tuxteam.de> - 2024-07-01 15:50 +0200
                    Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-01 21:30 +0200
                      Re: how2 format a flash drive Stefan Monnier <monnier@iro.umontreal.ca> - 2024-07-02 05:50 +0200
                        Re: how2 format a flash drive gene heskett <gheskett@shentel.net> - 2024-07-02 06:10 +0200
                        Re: how2 format a flash drive <tomas@tuxteam.de> - 2024-07-02 06:40 +0200
                        Re: how2 format a flash drive George at Clug <Clug@goproject.info> - 2024-07-02 06:50 +0200
                          Re: how2 format a flash drive Jeffrey Walton <noloader@gmail.com> - 2024-07-02 10:20 +0200
                            Telemetry, data hoarding [was: how2 format a flash drive] <tomas@tuxteam.de> - 2024-07-02 10:30 +0200
                          Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-02 11:20 +0200
                          Re: how2 format a flash drive John Hasler <john@sugarbit.com> - 2024-07-02 17:20 +0200
                      Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-02 10:30 +0200
                        Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-02 11:30 +0200
                          Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-02 22:40 +0200
            Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-06-29 22:50 +0200
              Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-06-30 03:40 +0200
                Re: Browser traffic interception/inspection Jeffrey Walton <noloader@gmail.com> - 2024-06-30 08:00 +0200
                  Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-06-30 17:40 +0200
                    Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-01 09:00 +0200
                      Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-07-01 17:10 +0200
                        Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-07 23:50 +0200
                          Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-07-08 04:40 +0200
                            Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-08 16:30 +0200
              Re: Browser traffic interception/inspection (was: how2 format a flash drive) Lee <ler762@gmail.com> - 2024-07-01 03:40 +0200
                Re: Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-07-01 03:50 +0200
                  Re: Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-07-01 07:50 +0200
            Re: how2 format a flash drive Keith Bainbridge <keithrbau@gmail.com> - 2024-06-30 08:20 +0200
            Re: how2 format a flash drive Jeffrey Walton <noloader@gmail.com> - 2024-07-01 08:00 +0200
    Re: how2 format a flash drive Marc SCHAEFER <schaefer@alphanet.ch> - 2024-07-06 17:50 +0200

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#270705

From<tomas@tuxteam.de>
Date2024-07-01 15:50 +0200
Message-ID<IVpzP-6WvG-3@gated-at.bofh.it>
In reply to#270704

[Multipart message — attachments visible in raw view] — view raw

On Mon, Jul 01, 2024 at 09:05:51AM -0400, Lee wrote:
> On Mon, Jul 1, 2024 at 4:53 AM jeremy ardley <jeremy.ardley@gmail.com> wrote:

[...]

> > https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer
> 
> Thanks, but no thanks.  That seems to include the Microsoft spyware
> licensing:  https://code.visualstudio.com/license
>   Data Collection. The software may collect information about you and
> your use of the software, and send that to Microsoft.

Desperate for Data :-)

But yes, that's what they currently do.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#270717

Fromjeremy ardley <jeremy.ardley@gmail.com>
Date2024-07-01 21:30 +0200
Message-ID<IVuSR-6ZOf-1@gated-at.bofh.it>
In reply to#270704
On 1/7/24 21:05, Lee wrote:
>> Visual Studio Code allows you to edit HTML and preview it using Live
>> Server plugin
>>
>> https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer
> Thanks, but no thanks.  That seems to include the Microsoft spyware
> licensing:  https://code.visualstudio.com/license
>    Data Collection. The software may collect information about you and
> your use of the software, and send that to Microsoft.
>
VS Code Telemetry is easily turned off.

https://code.visualstudio.com/docs/getstarted/telemetry#_disable-telemetry-reporting

In the more general case, telemetry is not in itself considered 'evil'. 
For example Debian comes with telemetry that you can enable or disable. 
https://popcon.debian.org/

Firefox, and just about any other web browser you use also has 
telemetry. e.g. https://support.mozilla.org/en-US/kb/telemetry-clientid

To be certain your activity is private you will have to disconnect 
completely from the internet as any software that uses any internet 
resource will automatically leak information about you.

.

[toc] | [prev] | [next] | [standalone]


#270720

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2024-07-02 05:50 +0200
Message-ID<IVCGJ-74AX-1@gated-at.bofh.it>
In reply to#270717
> In the more general case, telemetry is not in itself
> considered 'evil'.

I consider it evil if it's opt-out rather than opt-in.


        Stefan

[toc] | [prev] | [next] | [standalone]


#270721

Fromgene heskett <gheskett@shentel.net>
Date2024-07-02 06:10 +0200
Message-ID<IVD05-74X3-5@gated-at.bofh.it>
In reply to#270720
On 7/1/24 23:41, Stefan Monnier wrote:
>> In the more general case, telemetry is not in itself
>> considered 'evil'.
> 
> I consider it evil if it's opt-out rather than opt-in.
> 
> 
>          Stefan
> 
I think that highly depends on what that telemetry is sending. Crash 
reports, yes, contents of a list of phone numbers it found, not no, but 
hell no! Ditto for passwords and such.

Cheers, Gene Heskett, CET.
-- 
"There are four boxes to be used in defense of liberty:
  soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
  - Louis D. Brandeis

[toc] | [prev] | [next] | [standalone]


#270722

From<tomas@tuxteam.de>
Date2024-07-02 06:40 +0200
Message-ID<IVDt7-75bZ-7@gated-at.bofh.it>
In reply to#270720

[Multipart message — attachments visible in raw view] — view raw

On Mon, Jul 01, 2024 at 11:40:56PM -0400, Stefan Monnier wrote:
> > In the more general case, telemetry is not in itself
> > considered 'evil'.
> 
> I consider it evil if it's opt-out rather than opt-in.

Absolutely.

Plus (a) I don't trust most vendors to be telling the truth
whenever their bottom line is at stake and (b) I've seen
enough dark patterns to nudge users to not opt out to be more
than disgusted.

Just... no.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#270723

FromGeorge at Clug <Clug@goproject.info>
Date2024-07-02 06:50 +0200
Message-ID<IVDCN-75fc-1@gated-at.bofh.it>
In reply to#270720

[Multipart message — attachments visible in raw view] — view raw

Is telemetry evil?  Are guns evil?  Philosophical questions?



I find it objectionable when people gather "telemetry" about "me" and
not just the causes of the "blue screens of death".


I find it objectionable when people gather personal "telemetry" and
then on sell that information to others for whatever purposes, whether
it is to target me with ads, or political analysts like Cambridge
Analytica, or to alter my "Social Credit Score", or to be used to
cancel my Credit Cards, or for whatever other purpose.



While collecting information about individuals and selling their data
is common practice these days, I object. I cannot stop it, but I can
at least use systems that gather such data as minimally as possible.
Hopefully by using Linux for 99% of my computing experience, I am
giving Google and Windows less data.


Of course, by the mere fact of visiting a web site (for example, that
has Google Analytics installed), and by writing emails like this that
well be scanned, and then this data will be added to my profile by any
companies collecting data to gain some view of me, which they will
then sell to political groups, marketers, etc.


Scott McNally’s quip that ‘you have no privacy, get over it’ is
sadly true, but I don't think he meant that we have to resign
ourselves to this fast, we can but do what we can to reduce the data
collected, even while realising our efforts are mostly in vain. 



https://lockstep.com.au/library/quotes/


Privacy is an interesting topic.



What has privacy to do with a Debian User email list?  Well I am
hoping by using Debian less of my data ends up in large tech company
hands. At least let me dream that it does.


I encourage others to use Debian, if by doing so will let them sleep
better at night, even if it is in ignorance.



George.






On Tuesday, 02-07-2024 at 13:40 Stefan Monnier wrote:


> In the more general case, telemetry is not in itself
> considered 'evil'.

I consider it evil if it's opt-out rather than opt-in.


        Stefan

[toc] | [prev] | [next] | [standalone]


#270724

FromJeffrey Walton <noloader@gmail.com>
Date2024-07-02 10:20 +0200
Message-ID<IVGU1-77kM-3@gated-at.bofh.it>
In reply to#270723
On Tue, Jul 2, 2024 at 3:53 AM George at Clug <Clug@goproject.info> wrote:
>
> Is telemetry evil?  Are guns evil?  Philosophical questions?
>
> I find it objectionable when people gather "telemetry" about "me" and not just the causes of the "blue screens of death".
>
> I find it objectionable when people gather personal "telemetry" and then on sell that information to others for whatever purposes, whether it is to target me with ads, or political analysts like Cambridge Analytica, or to alter my "Social Credit Score", or to be used to cancel my Credit Cards, or for whatever other purpose.

For those interested in reading more, pick up a copy of Shoshana
Zuboff's book The Age of Surveillance Capitalism: The Fight for a
Human Future at the New Frontier of Power
(<https://www.amazon.com//dp/1610395697> and
<https://en.wikipedia.org/wiki/Surveillance_capitalism>).

Jeff

[toc] | [prev] | [next] | [standalone]


#270726 — Telemetry, data hoarding [was: how2 format a flash drive]

From<tomas@tuxteam.de>
Date2024-07-02 10:30 +0200
SubjectTelemetry, data hoarding [was: how2 format a flash drive]
Message-ID<IVH3I-77nR-7@gated-at.bofh.it>
In reply to#270724

[Multipart message — attachments visible in raw view] — view raw

On Tue, Jul 02, 2024 at 04:09:39AM -0400, Jeffrey Walton wrote:
> On Tue, Jul 2, 2024 at 3:53 AM George at Clug <Clug@goproject.info> wrote:
> >
> > Is telemetry evil?  Are guns evil?  Philosophical questions?
> >
> > I find it objectionable when people gather "telemetry" about "me" and not just the causes of the "blue screens of death".
> >
> > I find it objectionable when people gather personal "telemetry" and then on sell that information to others for whatever purposes, whether it is to target me with ads, or political analysts like Cambridge Analytica, or to alter my "Social Credit Score", or to be used to cancel my Credit Cards, or for whatever other purpose.
> 
> For those interested in reading more, pick up a copy of Shoshana
> Zuboff's book The Age of Surveillance Capitalism: The Fight for a
> Human Future at the New Frontier of Power
> (<https://www.amazon.com//dp/1610395697> and
> <https://en.wikipedia.org/wiki/Surveillance_capitalism>).

Thanks for that ref. One of the most important books for our
trade, indeed.

If possible, don't buy it at Amazon :-)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#270729

Fromjeremy ardley <jeremy.ardley@gmail.com>
Date2024-07-02 11:20 +0200
Message-ID<IVHQ5-77U9-3@gated-at.bofh.it>
In reply to#270723
On 2/7/24 12:47, George at Clug wrote:
>
> Scott McNally’s quip that ‘you have no privacy, get over it’ is sadly 
> true, but I don't think he meant that we have to resign ourselves to 
> this fast, we can but do what we can to reduce the data collected, 
> even while realising our efforts are mostly in vain.


Linedkin is worse than any organisation I know of. I signed up very 
reluctantly with a fake profile and a throw-awy email address and the 
first thing it suggested was to link to immediate family and people it 
had no way of knowing I was related to.

I can only guess they have profiled my browser signature and worked off 
that.

If you are or ever have been a user of Linkedin your privacy is worse 
than zero. You are a product that can be bought and sold and almost 
everything you see and hear will be managed by them or their customers.

I class that entirely differently to application telemetry with an 
option to opt out.

Back on my original post I use Visual Studio Code because it is a very 
useful tool and has a broad community of people in the open source 
community. I rate VS Code significantly less intrusive than github 
which, with no option to opt out, scans  all your private repositories 
to gain information about you that it can package and resell  
'anonymously'. Even if you aren't a user of github, your access to 
download is recorded and included in the data it resells.

[toc] | [prev] | [next] | [standalone]


#270739

FromJohn Hasler <john@sugarbit.com>
Date2024-07-02 17:20 +0200
Message-ID<IVNst-7bwL-3@gated-at.bofh.it>
In reply to#270723
George at Clug writes:
> While collecting information about individuals and selling their data
> is common practice these days

It's common practice because people won't pay for services but will
tolerate advertising.

> Of course, by the mere fact of visiting a web site (for example, that
> has Google Analytics installed)

I've never visited a site that cares that I block Google Analytics.

The best way to protect your "personal information" is to not have
accounts with any of the popular "social media" services, especially
Google, Facebook, and Twitter (and never use Windows, of course).
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#270727

FromLee <ler762@gmail.com>
Date2024-07-02 10:30 +0200
Message-ID<IVH3I-77nR-9@gated-at.bofh.it>
In reply to#270717
On Mon, Jul 1, 2024 at 6:13 PM jeremy ardley wrote:
>
>
> On 1/7/24 21:05, Lee wrote:
> >> Visual Studio Code allows you to edit HTML and preview it using Live
> >> Server plugin
> >>
> >> https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer
> > Thanks, but no thanks.  That seems to include the Microsoft spyware
> > licensing:  https://code.visualstudio.com/license
> >    Data Collection. The software may collect information about you and
> > your use of the software, and send that to Microsoft.
> >
> VS Code Telemetry is easily turned off.
>
> https://code.visualstudio.com/docs/getstarted/telemetry#_disable-telemetry-reporting

Except the license says
You may opt-out of many of these scenarios, but not all, as described
in the product documentation located at
https://code.visualstudio.com/docs/supporting/faq#_how-to-disable-telemetry-reporting.

So
1. you can't opt-out of _all_ telemetry.  .. at least according to the license.
2. opt-out is evil.  Any group that uses opt-out is evil.  They only
do opt-out because they _know_ almost no one would opt-in.

> In the more general case, telemetry is not in itself considered 'evil'.

Anything opt-out I consider 'evil'.

> For example Debian comes with telemetry that you can enable or disable.
> https://popcon.debian.org/

That's opt-in, so a completely different case.

> Firefox, and just about any other web browser you use also has
> telemetry. e.g. https://support.mozilla.org/en-US/kb/telemetry-clientid

I know & I don't like it.  But it's like apple vs. google -- which one
is less evil?
I have an iPhone so that should tell you what I think.

> To be certain your activity is private you will have to disconnect
> completely from the internet as any software that uses any internet
> resource will automatically leak information about you.

If I use Internet resources I know that I can be tracked .. but **only
when using the Internet**.  Microsoft spyware is always-on tracking
that can't be turned completely off.

And if I don't want to leave Internet footprints - or if I just want
to give the finger to whoever is watching, I'll use the tor browser.
So I have options when I get on the Internet.  I don't see any options
when the OS or my tools are spying on me other than don't use that OS
or those tools.

Regards,
Lee

[toc] | [prev] | [next] | [standalone]


#270730

Fromjeremy ardley <jeremy.ardley@gmail.com>
Date2024-07-02 11:30 +0200
Message-ID<IVHZL-77Xj-1@gated-at.bofh.it>
In reply to#270727

[Multipart message — attachments visible in raw view] — view raw

On 2/7/24 16:24, Lee wrote:
> And if I don't want to leave Internet footprints - or if I just want
> to give the finger to whoever is watching, I'll use the tor browser.


That is probably the worst thing you can do. On my last check *most* Tor 
exit points are operated by intelligence or police agencies.

Going about your business just using a regular ISP makes it unlikely 
anyone will pay attention to you unless you frequent disreputable sites.

Using Tor will automatically put you on a watch list. Your identity can 
easily be found because your ip address at the exit point will be 
recorded and matched with ISP records.

[toc] | [prev] | [next] | [standalone]


#270749

FromLee <ler762@gmail.com>
Date2024-07-02 22:40 +0200
Message-ID<IVSs9-7eGR-3@gated-at.bofh.it>
In reply to#270730
On Tue, Jul 2, 2024 at 5:27 AM jeremy ardley wrote:
>
>
> On 2/7/24 16:24, Lee wrote:
>
> And if I don't want to leave Internet footprints - or if I just want
> to give the finger to whoever is watching, I'll use the tor browser.
>
>
> That is probably the worst thing you can do. On my last check *most* Tor exit points are operated by intelligence or police agencies.

OK.. I'll bite.  How do you know most Tor exit points are operated by
intelligence or police agencies?

I mean, it sounds reasonable, but how do you *know*?

> Going about your business just using a regular ISP makes it unlikely anyone will pay attention to you unless you frequent disreputable sites.
>
> Using Tor will automatically put you on a watch list.

Yeah.  I've heard that too.  But using tor - or any encryption, is
still legal, so what I'm doing doesn't even rise to the level of civil
disobedience.
So if they're going to put me on a list, they're going to put me on a
list.  I've been using tor since however long ago when it came bundled
with privoxy, so I doubt that me not using tor now is going to make a
difference.

> Your identity can easily be found because your ip address at the exit point will be recorded and matched with ISP records.

Indeed.  The TOR documentation used to be up-front about tor not being
proof against a global adversary, so I doubt the NSA needs to bother
my ISP asking for records.
I was just poking around on torproject.org (which has been rumored to
be enough to get one on a watch list) and I don't see any strong
warnings about using tor :(  Or even much of anything that would
discourage one from using TOR.
Oh well.. I guess they need lots of cannon fodder to provide covering
traffic for .. who?

Regards,
Lee

[toc] | [prev] | [next] | [standalone]


#270616 — Browser traffic interception/inspection (was: how2 format a flash drive)

FromJeffrey Walton <noloader@gmail.com>
Date2024-06-29 22:50 +0200
SubjectBrowser traffic interception/inspection (was: how2 format a flash drive)
Message-ID<IUNbc-6wz8-17@gated-at.bofh.it>
In reply to#270603
On Sat, Jun 29, 2024 at 4:13 PM Lee <ler762@gmail.com> wrote:
>
> [...] Debian firefox does NOT allow one to do
> TLS intercept - ie. this does not work:
> C:\UTIL>cat firefox-tlsdecode.bat
> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
> start C:\"Program Files\Firefox\Firefox.exe"
>
> @rem wireshark:
> @rem   edit / preferences
> @rem   protocols / tls  (v2.6: protocols / ssl)
> @rem     paste SSLKEYLOGFILE filename into (Pre)-Master-Secret log
> filename (was SSL debug file entry)

I'm not sure who your complaint is against -- Debian, Firefox or
Linux. I'm also not sure that it is a valid complaint.

Firefox uses its own certificate store. If you want to proxy your
traffic, then the proxy's root cert needs to be in Mozilla's
certificate store. See
<https://support.mozilla.org/en-US/kb/setting-certificate-authorities-firefox>.

Chrome is different. Chrome uses the Windows store by default, but
also has its own certificate store. For Chrome, your Windows admin can
make a change with a Group Policy, and Chrome will pick it up through
the Windows certificate store. Or you can manually install the proxy's
root cert. See <https://chromium.googlesource.com/chromium/src/+/main/net/data/ssl/chrome_root_store/faq.md>.

Debian is not concerned about TLS interception in this case. But for
completeness, Debian has its own store at /etc/ssl/certs. You get the
certificates by installing the ca-certificates package. You can
install certificates into the store by dropping the root cert on the
filesystem at /usr/local/share/ca-certificates, and then running
update-ca-certificates. See
<https://wiki.debian.org/Firefox/PrivateCertificateAuthority> and
<https://manpages.debian.org/buster/ca-certificates/update-ca-certificates.8.en.html>.

When you are intercepting/inspecting traffic, you typically setup your
proxy, and then proxy Firefox and Chrome traffic through your proxy.
The proxy can run on your local machine, like 127.0.0.1. Your proxy's
root certificate should be in the browser's store (as described
above).

Jeff

[toc] | [prev] | [next] | [standalone]


#270623 — Re: Browser traffic interception/inspection

FromMax Nikulin <manikulin@gmail.com>
Date2024-06-30 03:40 +0200
SubjectRe: Browser traffic interception/inspection
Message-ID<IURHP-6zr6-1@gated-at.bofh.it>
In reply to#270616
On 30/06/2024 03:45, Jeffrey Walton wrote:
> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote:
>>
>> [...] Debian firefox does NOT allow one to do
>> TLS intercept - ie. this does not work:
>> C:\UTIL>cat firefox-tlsdecode.bat
>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
>> start C:\"Program Files\Firefox\Firefox.exe"
[...]
> I'm not sure who your complaint is against -- Debian, Firefox or
> Linux. I'm also not sure that it is a valid complaint.

I do not mind to see a link stating that the appropriate logger is 
really disabled. Certainly dumping of TLS session keys may be disabled 
through a compile time flag similar to enforcing signatures for add-ons. 
It may be default Firefox configuration for release builds or some line 
in Debian build rules. It still might be some mistake during attempts to 
enable the logger. I have read about this approach but I have never 
tried it in action.

> Firefox uses its own certificate store.

It is relevant to active traffic interception you described (a proxy). 
Lee prefers passive traffic sniffing and it requires cooperation from a 
peer to get session keys. Each case has its own advantages.

P.S.

At first it was not clear to me that having TLS private key (copied from 
the server) is not enough for passive traffic decryption. Diffie-Hellman 
key exchange scheme allows to generate secret keys even over public 
channel. The main purpose of TLS certificates (public keys in the 
browser or system store) is to confirm that there is no attacker in 
between that blocks packets from the client and establishes its own 
connection to the server. Encryption of email messages using a public 
key is a different case. Session keys are required to debug TLS 
applications.

[toc] | [prev] | [next] | [standalone]


#270635 — Re: Browser traffic interception/inspection

FromJeffrey Walton <noloader@gmail.com>
Date2024-06-30 08:00 +0200
SubjectRe: Browser traffic interception/inspection
Message-ID<IUVLr-6Cpg-1@gated-at.bofh.it>
In reply to#270623
On Sat, Jun 29, 2024 at 9:37 PM Max Nikulin <manikulin@gmail.com> wrote:
>
> On 30/06/2024 03:45, Jeffrey Walton wrote:
> > On Sat, Jun 29, 2024 at 4:13 PM Lee wrote:
> >>
> >> [...] Debian firefox does NOT allow one to do
> >> TLS intercept - ie. this does not work:
> >> C:\UTIL>cat firefox-tlsdecode.bat
> >> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
> >> start C:\"Program Files\Firefox\Firefox.exe"
> [...]
> > I'm not sure who your complaint is against -- Debian, Firefox or
> > Linux. I'm also not sure that it is a valid complaint.
>
> I do not mind to see a link stating that the appropriate logger is
> really disabled. Certainly dumping of TLS session keys may be disabled
> through a compile time flag similar to enforcing signatures for add-ons.
> It may be default Firefox configuration for release builds or some line
> in Debian build rules. It still might be some mistake during attempts to
> enable the logger. I have read about this approach but I have never
> tried it in action.
>
> > Firefox uses its own certificate store.
>
> It is relevant to active traffic interception you described (a proxy).
> Lee prefers passive traffic sniffing and it requires cooperation from a
> peer to get session keys. Each case has its own advantages.

As far as I know, the browsers support active interception. That is,
"interception is a valid use case" for the browsers to support
Dataloss Prevention (DLP) programs. The browsers do that through the
use of interception proxies and root CA's used in the DLP program.

Browsers do not support the passive capture/replay that OP wants. That
is, they don't support exporting the premaster secret or the derived
master secret.

The browsers use tortured logic to arrive at "interception is a valid
use case". They hang it off of the W3C's Design Principles and
Priorities of Constituencies. The browser's argument goes as such: if
a user did not want to be intercepted, then the CA certificate used
for interception would not be present in the certificate store. Since
the proxy's interception certificate is present in the store, the user
wants to be intercepted. (You can't make this shit up).

A corollary to "interception is a valid use case" is, webapps can
never be sure they have a secure channel. Therefore, webapps can only
handle low value data. Higher value data should be handled by hybrid
and native apps.

> At first it was not clear to me that having TLS private key (copied from
> the server) is not enough for passive traffic decryption. Diffie-Hellman
> key exchange scheme allows to generate secret keys even over public
> channel...

Correct. You also need ClientHello.random and ServerHello.random since
the master secret is computed from
(https://datatracker.ietf.org/doc/html/rfc5246#section-8.1):

      master_secret = PRF(pre_master_secret, "master secret",
                          ClientHello.random + ServerHello.random)
                          [0..47];

Something some folks don't realize is, ClientHello.random and
ServerHello.random are also used for key transport schemes like RSA,
when the client encrypts the premaster secret and sends it to the
server. The ClientHello.random and ServerHello.random are present to
ensure both sides contribute to the master secret. Otherwise, only the
client would contribute to the master secret in a key transport
scheme.

> The main purpose of TLS certificates (public keys in the
> browser or system store) is to confirm that there is no attacker in
> between that blocks packets from the client and establishes its own
> connection to the server.

No, not quite. Interception is a valid use case under the browser's
security model.

You can achieve what you are getting at, but you need to use hybrid
and native apps that practice host public key pinning. You need hybrid
and native apps because they can usually obtain the host's public key.
But the browsers don't expose the host public key to the webapp. So
webapps have no way to perform pinning. You can't even get the public
key from a WebSocket.

> Encryption of email messages using a public
> key is a different case. Session keys are required to debug TLS
> applications.

Email transport security is an absolute mess due to opportunistic
encryption and smart hosts. About the best you can do is, encrypt and
sign the message, and send it over an insecure channel.

Jeff

[toc] | [prev] | [next] | [standalone]


#270662 — Re: Browser traffic interception/inspection

FromMax Nikulin <manikulin@gmail.com>
Date2024-06-30 17:40 +0200
SubjectRe: Browser traffic interception/inspection
Message-ID<IV4OJ-6Ige-13@gated-at.bofh.it>
In reply to#270635
On 30/06/2024 12:56, Jeffrey Walton wrote:
>>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote:
>>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
>>>> start C:\"Program Files\Firefox\Firefox.exe"
[...]
> Browsers do not support the passive capture/replay that OP wants.

Lee, may you, please, specify Firefox version and release channel you 
are using on Windows where this feature is working?

[toc] | [prev] | [next] | [standalone]


#270692 — Re: Browser traffic interception/inspection

FromLee <ler762@gmail.com>
Date2024-07-01 09:00 +0200
SubjectRe: Browser traffic interception/inspection
Message-ID<IVjb3-6Sef-5@gated-at.bofh.it>
In reply to#270662
On Sun, Jun 30, 2024 at 11:30 AM Max Nikulin wrote:
>
> On 30/06/2024 12:56, Jeffrey Walton wrote:
> >>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote:
> >>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
> >>>> start C:\"Program Files\Firefox\Firefox.exe"
> [...]
> > Browsers do not support the passive capture/replay that OP wants.

It works for me in Windows.

This looks like the Debian bug report
  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292

> Lee, may you, please, specify Firefox version and release channel you
> are using on Windows where this feature is working?

Firefox 115.12.0esr -- which is the current extended service release software
I'm not sure what you mean by release channel .. ESR?  If I go to
https://www.mozilla.org/en-US/firefox/115.12.0/releasenotes/
under "Download Firefox" there's links to
Windows 64-bit and Windows 64-bit MSI

wow!  I've been letting firefox update itself for awhile now.  What I
installed was Firefox Setup 68.3.0esr.msi

Lee

[toc] | [prev] | [next] | [standalone]


#270707 — Re: Browser traffic interception/inspection

FromMax Nikulin <manikulin@gmail.com>
Date2024-07-01 17:10 +0200
SubjectRe: Browser traffic interception/inspection
Message-ID<IVqPg-6XpD-17@gated-at.bofh.it>
In reply to#270692
On 01/07/2024 13:57, Lee wrote:
> On Sun, Jun 30, 2024 at 11:30 AM Max Nikulin wrote:
>>>>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote:
>>>>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
>>>>>> start C:\"Program Files\Firefox\Firefox.exe"
> 
> This looks like the Debian bug report
>    https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292
> 
>> Lee, may you, please, specify Firefox version and release channel you
>> are using on Windows where this feature is working?
> 
> Firefox 115.12.0esr -- which is the current extended service release software
> I'm not sure what you mean by release channel .. ESR?

Thanks. I expected that you may use either developer release, beta, or 
even nightly.

Is libnss built with logging support ABI compatible with the variant in 
Debian repositories? (Or can it be patched to achieve ABI 
compatibility?) Instead of asking for changing compile flags for all 
users, from my point of view, it is better to suggest alternative 
packages with and without logging enabled.

Browsers are rather sensitive applications, so I find it reasonable that 
dumping of encryption keys are not available by default. However 
debugging should be possible and should require special configuration.

I have not tried .deb packages provided by Mozilla. Since their Windows 
builds allows logging, it might work on Linux as well.
<https://support.mozilla.org/en-US/kb/install-firefox-linux#w_install-firefox-deb-package-for-debian-based-distributions>

[toc] | [prev] | [next] | [standalone]


#270907 — Re: Browser traffic interception/inspection

FromLee <ler762@gmail.com>
Date2024-07-07 23:50 +0200
SubjectRe: Browser traffic interception/inspection
Message-ID<IXHVD-xLQ-5@gated-at.bofh.it>
In reply to#270707
Hi,

On Mon, Jul 1, 2024 at 11:02 AM Max Nikulin wrote:
>
> On 01/07/2024 13:57, Lee wrote:
> > On Sun, Jun 30, 2024 at 11:30 AM Max Nikulin wrote:
> >>>>> On Sat, Jun 29, 2024 at 4:13 PM Lee wrote:
> >>>>>> set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt
> >>>>>> start C:\"Program Files\Firefox\Firefox.exe"
> >
> > This looks like the Debian bug report
> >    https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292
> >
> >> Lee, may you, please, specify Firefox version and release channel you
> >> are using on Windows where this feature is working?
> >
> > Firefox 115.12.0esr -- which is the current extended service release software
> > I'm not sure what you mean by release channel .. ESR?
>
> Thanks. I expected that you may use either developer release, beta, or
> even nightly.

Nope - just regular firefox-esr

> Is libnss built with logging support ABI compatible with the variant in
> Debian repositories? (Or can it be patched to achieve ABI
> compatibility?) Instead of asking for changing compile flags for all
> users, from my point of view, it is better to suggest alternative
> packages with and without logging enabled.
>
> Browsers are rather sensitive applications, so I find it reasonable that
> dumping of encryption keys are not available by default.

Maybe I don't know enough to know what's "reasonable" or not.. but I
don't see a problem with me being able to inspect the traffic between
me and some website.
Anyone else wants to intercept my traffic and they'll have to set an
environment variable - which root can do, but who else?

> However
> debugging should be possible and should require special configuration.
>
> I have not tried .deb packages provided by Mozilla. Since their Windows
> builds allows logging, it might work on Linux as well.
> <https://support.mozilla.org/en-US/kb/install-firefox-linux#w_install-firefox-deb-package-for-debian-based-distributions>

Thanks for the pointer to downloading firefox from mozilla.  But wow!!
plenty too many instructions for to be able to
  Install Firefox .deb package for Debian-based distributions

I suppose it's funny that I have no qualms with
SSLKEYLOGFILE=<whatever> but balk at following those instructions to
modify apt-get actions, but I don't know how to evaluate the security
implications of modifying apt-get files.  So I just downloaded the
binary from mozilla and went from there:

get the 64 bit linux version of firefox esr from
   https://www.mozilla.org/en-US/firefox/all/#product-desktop-esr

tar -xvf firefox-115.12.0esr.tar.bz2
sudo mv firefox /opt/firefox-115.12.0esr/
sudo ln -s /opt/firefox-115.12.0esr/firefox /usr/local/bin/firefox

lee@laptop:~$ cat ~/bin/firefox-tlsdecode.sh
#!/bin/bash
# set things up so that wireshark can decrypt firefox tls traffic
umask 077
SSLKEYLOGFILE=/tmp/FF-SSLkeys.txt
export SSLKEYLOGFILE
/usr/local/bin/firefox "$@" &

# then in wireshark:
#   edit / preferences
#   protocols / tls  (v2.6: protocols / ssl)
#     paste SSLKEYLOGFILE filename into (Pre)-Master-Secret log filename

lee@laptop:~$


So now I've got the debian /usr/bin/firefox that doesn't allow export
tls keys and a /usr/local/bin/firefox that does.

Thanks
Lee

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web