Google knows where you are.... creepy.

Thread Tools
 
Search this Thread
 
Old Apr 25, 2011 | 06:57 PM
  #16  
VRT MBasile's Avatar
Thread Starter
VIP Member
iTrader: (17)
 
Joined: May 2005
Posts: 22,776
From: Sunnyvale, CA
Car Info: '13 BRZ Limited / '02 WRX
Originally Posted by kyle16
I think I remember reading an article about this not too long ago. I think this holds some credence.
That would explain why it works better when you're already zoomed in on your region, rather than while viewing the whole globe.
Old Apr 25, 2011 | 07:01 PM
  #17  
pete's Avatar
Registered User
iTrader: (1)
 
Joined: Jan 2008
Posts: 143
From: Santa Cruz, Ca
Car Info: 07 STi, 02 F150-FX4, 04 ZX-636, 07 990 SuperDuke
Originally Posted by VRT MBasile
And no, this isn't in a phone, this is through your interweb browser on your computer.



I'm more just curious how this works, rather than paranoid about it. Does it just look at your IP address and match that with ISP databases?
This is most likely done by cross mapping an internet ip address database (zip code entry form on most sites), along with what google knows about you with your account information. There's no direct mapping of IP address to direct GPS coordinates out there, just general areas for ranges down to the zip code.
Old Apr 25, 2011 | 07:49 PM
  #18  
Irrational X's Avatar
plays well with others
iTrader: (1)
 
Joined: Aug 2006
Posts: 9,923
From: Sac
Car Info: your mother crazy
Originally Posted by pete
This is most likely done by cross mapping an internet ip address database (zip code entry form on most sites), along with what google knows about you with your account information. There's no direct mapping of IP address to direct GPS coordinates out there, just general areas for ranges down to the zip code.
bull****. watch the video i posted above. streetview cars triangulate SSID and router MAC and record the longitude/latitude of the router.

its accurate to about 10 feet.
Old Apr 25, 2011 | 07:52 PM
  #19  
soggynoodles's Avatar
Token Toyota Mod
iTrader: (50)
 
Joined: Jun 2004
Posts: 52,306
From: Palo Alto, CA
Car Info: Something german
Originally Posted by stg2lgcy00
Maybe you already know but you can use Little Snitch on your mac to accept or deny connections to anything.. you can set rules for all apps or rules for 1 specific app.

http://www.obdev.at/products/littlesnitch/index.html
Little snitch rocks!
Old Apr 25, 2011 | 07:56 PM
  #20  
soggynoodles's Avatar
Token Toyota Mod
iTrader: (50)
 
Joined: Jun 2004
Posts: 52,306
From: Palo Alto, CA
Car Info: Something german
Originally Posted by cracker1252
answer to all...

kill yourself.




or move to some remote location and live like a 19th century cattle farmer.
you can try to live off the grid
might want to stock up on these
Name:  NWLPH.jpg
Views: 11
Size:  458.4 KB

or you can accept that privacy is dead.
Old Apr 25, 2011 | 07:59 PM
  #21  
soggynoodles's Avatar
Token Toyota Mod
iTrader: (50)
 
Joined: Jun 2004
Posts: 52,306
From: Palo Alto, CA
Car Info: Something german
also stop using google
Old Apr 25, 2011 | 08:00 PM
  #22  
brucelee's Avatar
Friendly Neighborhood Ogre
iTrader: (6)
 
Joined: Mar 2000
Posts: 19,930
From: www.gunatics.com
Car Info: GUNATICS.COM
^^^ Just waiting for your excuse to use that huh?


Also, what false advertising! $2.99 for a pack of RAMEN!? Are they f'ing HIGH?!
http://www.perpetualkid.com/wasted-a...n-noodles.aspx
Old Apr 25, 2011 | 08:22 PM
  #23  
cracker1252's Avatar
Registered User
 
Joined: Jun 2009
Posts: 837
From: up in them guts.
Car Info: 2008 Forester XT Sports
Originally Posted by VRT MBasile
Thanks for contributing to the community
Despite my abstract humor that does not have any value to the topic at hand, I am forced to ask you why you did not ask the question of 'why they do it' before 'how they do it'.

Granted you already answered your own question along with other folks here, using the tactics of IP logging and locational caching; I would argue that the 'why' derived from your avatar of a google QR code explains the purpose behind it and your website address and 'web spiders' that run through it to obtain all the geotagging of the pictures you have taken give you the how.
Old Apr 25, 2011 | 08:37 PM
  #24  
VRT MBasile's Avatar
Thread Starter
VIP Member
iTrader: (17)
 
Joined: May 2005
Posts: 22,776
From: Sunnyvale, CA
Car Info: '13 BRZ Limited / '02 WRX
Originally Posted by cracker1252
Despite my abstract humor that does not have any value to the topic at hand, I am forced to ask you why you did not ask the question of 'why they do it' before 'how they do it'.

Granted you already answered your own question along with other folks here, using the tactics of IP logging and locational caching; I would argue that the 'why' derived from your avatar of a google QR code explains the purpose behind it and your website address and 'web spiders' that run through it to obtain all the geotagging of the pictures you have taken give you the how.
It is a "show current location" feature, so there is no "why do they do it" and it isn't even anything google is doing without the user asking them to do it.
Old Apr 25, 2011 | 08:47 PM
  #25  
AWDfreak's Avatar
Registered User
 
Joined: Sep 2010
Posts: 997
From: SF Bay Area, CA (USA)
Car Info: 2014 Subaru XV (Crosstrek)
13:52 How does one enable this "NoScript" thing?

http://www.youtube.com/watch?v=2ctRfWnisSk&NR=1


And jeez, internet security (or lack of it) stuff makes me paranoid.
Old Apr 25, 2011 | 08:50 PM
  #26  
stupidchicken03's Avatar
Churro Aficionado
iTrader: (38)
 
Joined: Feb 2008
Posts: 54,661
From: IG - @thomas.teammoist
Car Info: IG - @TEAMMOISTOFFICIAL
Originally Posted by irrational x
hes like a more flamboyant version of you... with skillz.
I wish i had skillz
Old Apr 25, 2011 | 08:52 PM
  #27  
soggynoodles's Avatar
Token Toyota Mod
iTrader: (50)
 
Joined: Jun 2004
Posts: 52,306
From: Palo Alto, CA
Car Info: Something german
Originally Posted by AWDfreak
13:52 How does one enable this "NoScript" thing?

http://www.youtube.com/watch?v=2ctRfWnisSk&NR=1


And jeez, internet security (or lack of it) stuff makes me paranoid.

http://noscript.net/
I think they have one for chrome too.
Old Apr 25, 2011 | 09:12 PM
  #28  
AWDfreak's Avatar
Registered User
 
Joined: Sep 2010
Posts: 997
From: SF Bay Area, CA (USA)
Car Info: 2014 Subaru XV (Crosstrek)
Originally Posted by soggynoodles
http://noscript.net/
I think they have one for chrome too.
Thanks a lot!

I feel a bit safer now.
Old Apr 26, 2011 | 11:33 PM
  #29  
pete's Avatar
Registered User
iTrader: (1)
 
Joined: Jan 2008
Posts: 143
From: Santa Cruz, Ca
Car Info: 07 STi, 02 F150-FX4, 04 ZX-636, 07 990 SuperDuke
Originally Posted by irrational x
bull****. watch the video i posted above. streetview cars triangulate SSID and router MAC and record the longitude/latitude of the router.

its accurate to about 10 feet.
I must be missing the link to the video, where's it at? Are you talking about the Defcon video's?

As for SSID and router MAC, how is google going to know what SSID you're on? I'm not terribly experienced with JAVA or AJAX, but that's typically run in a JVM.

From a "war driving standpoint", sure.. you'll know the location of the SSID, and the MAC address of the wireless radio for that SSID; but unless you do an invasive look (attack) into the AP, you won't know the public address, nor will you know the MAC addresses of the AP's external link ("internet"), or the internal link ("lan") of the AP (Unless the AP's incrementing their MAC's and you guess them). Your typical AP's will actually have at least 3 MAC's: Wireless, WAN, and LAN.
Old Apr 27, 2011 | 09:07 AM
  #30  
Irrational X's Avatar
plays well with others
iTrader: (1)
 
Joined: Aug 2006
Posts: 9,923
From: Sac
Car Info: your mother crazy
Originally Posted by pete
I must be missing the link to the video, where's it at? Are you talking about the Defcon video's?

As for SSID and router MAC, how is google going to know what SSID you're on? I'm not terribly experienced with JAVA or AJAX, but that's typically run in a JVM.

From a "war driving standpoint", sure.. you'll know the location of the SSID, and the MAC address of the wireless radio for that SSID; but unless you do an invasive look (attack) into the AP, you won't know the public address, nor will you know the MAC addresses of the AP's external link ("internet"), or the internal link ("lan") of the AP (Unless the AP's incrementing their MAC's and you guess them). Your typical AP's will actually have at least 3 MAC's: Wireless, WAN, and LAN.
the dude uses XSS and a known port overflow vulnerability to gain access to somone's home routor remotely... google said they erased the SSID data but they never erased the MAC information...

so he grabs the routors MAC and uses a phoney user agent string to query google maps. Gmaps gives him lon/lat for the MAC's known location and he Gets Directions from the street address where the routor is located to the lon/lat.

it nails down the routor location inside the house and says "walk 30 ft" or something like that gmaps. thats how accurate their triangulation is. of course, this only works if the routor is the same as when the streetview car came by.

of course, all of this is after he reduces 160 bits of entropy down to 12bits so he can brute force someones facebook account by spoofing their cookie data and using that port overflow exploit and DCC (old IRC file transfer) to load the XSS on the target system.

dudes pretty serious biz, and very hilarious. I highly recommend watching the video its posted above or you can google "how i met your girlfriend"
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
hey1
SoCal
10
Aug 26, 2005 08:13 AM
itwrx
Bay Area
2
Sep 3, 2004 03:16 PM
Kuonji
Bay Area
25
Jul 16, 2004 12:25 PM




All times are GMT -7. The time now is 12:47 PM.