Results 1 to 10 of 15
I just got a new crdit card in the mail, was reading the privaxy statement, and it said: we may obtain information about your i.s.p your operating system and browser! ...
- 03-01-2009 #1Linux Newbie
- Join Date
- Nov 2007
- Posts
- 223
credit card warning ?
I just got a new crdit card in the mail, was reading the privaxy statement, and it said: we may obtain information about your i.s.p your operating system and browser! and what sites you visit ? WHAT? that kind of sound like a root kit to me. how they gonna know what os and sites i visit ?
- 03-01-2009 #2Linux Guru
- Join Date
- Nov 2004
- Posts
- 6,110
Well the ISP, operating system and browser is just from your browser's user agent and that is seen by every site you visit. In fact it's required. As for what sites you visit, I suspect they're looking at your cookies which isn't cool at all. Could the phrasing perhaps be that they are tracking your access to their sites? Companies usually notify you that they'll be using a cookie to track your usage.
- 03-02-2009 #3
from what they have posted, they can only obtain information that is freely available to any webserver you connect to (you agree to give them that information when you connect to them.) If they obtain any other information without your conscent, you have a case for a lawsuit (depending on your country / state.)
You can also hide (at lease with linux) the information they are talking about EXCEPT for the ISP, they assign your IP address, and you can't fake that one (technicaly you can, see the onion router.) If you google for "browser user agent string" that bigtomrodney posted, you can find a firefox addon that will let you fake it to say whatever you want. (at least you could, havent tested in a while)New to the internet, technical forums, or the hacker / open source community??
Read this to learn good posting habits http://www.catb.org/~esr/faqs/smart-questions.html
RHCE for RHEL version 5
RHCT for RHEL version 4
- 03-02-2009 #4
Having them know which IP address you're connecting from isn't necessarily a problem, indeed it could help them if you suddenly start accessing your account from an IP registered in a different country and start shifting money around...
If you're considering hiding your location from your bank by using a privacy proxy (such as the onion router or the cloak or whatever), bear in mind that you'll be sending bank-sensitive data through servers which are set up soleley for the purposes of disguising identity - you may be passing your (admittedly, lightly encrypted with ssl) bank logon info through an wholly untrustworthy server. I'd sooner let my bank see my IP address rather than do this.Linux user #126863 - see http://linuxcounter.net/
- 03-02-2009 #5Linux Newbie
- Join Date
- Nov 2007
- Posts
- 223
I don't mind them knowing my i.s.p, my only concern was with a massive spam attack from them tracking my webstie visits, like postcards from Bill Gate, after he sees I use linux, and gets his panties in a wad about it, or worse yet sends the M.S blackopps sqaud to arrest me...or somtin :
- 03-04-2009 #6
no, they can't do that, esspecialy if you lock down your settings so that websites can only access cookies created by that website (it is a firefox privacy setting I think). And I agree, the onion router is not a good idea for banking.
Another option is to change your bank BTW. I changed mine just for the reason that mine required internet explorer with activeX enabled, and adobe acrobat installed, and a bunch of other crap.New to the internet, technical forums, or the hacker / open source community??
Read this to learn good posting habits http://www.catb.org/~esr/faqs/smart-questions.html
RHCE for RHEL version 5
RHCT for RHEL version 4
- 03-04-2009 #7Linux user #126863 - see http://linuxcounter.net/
- 03-04-2009 #8Registered Linux user #270181
TechieMoe's Tech Rants
- 03-04-2009 #9
My new bank has something similar, they ask you questions if you don't have a cookie (i think) on your PC. I hated it because my answers to the questions can easily change over time (stuff like what's your favorite book.)
So I just ran a random word through a hash, took 15 or so digits out of the middle, and put those into a text file that I encrypted with a GPG key that I exported to a flash drive that I keep disconnected from my pc. ...... I may be a bit paranoid, but I'd like to see someone break it, hell, I don't even remember the stuff. And when I need it, I can just plug in my flash drive, cat the file, and enter my stuff. I just wish the bank would let me skip the middle and just use a keypair for authentication.New to the internet, technical forums, or the hacker / open source community??
Read this to learn good posting habits http://www.catb.org/~esr/faqs/smart-questions.html
RHCE for RHEL version 5
RHCT for RHEL version 4
- 03-04-2009 #10Linux user #126863 - see http://linuxcounter.net/


Reply With Quote

