Tool in the spotlight: Youtube-dl

Tool in the Spotlight: youtube-dl, a command-line program to download videos from your favorite video site(s). It works on Linux, Windows and macOS.

This tool enables you to download (almost) any video from your favorite video site so you can watch it later or just keep a copy of it around. It has support for over 800 sites and that list is always growing. It has an extensive set of options you can give it, including proxy settings and, what’s very interesting for this kind of thing, geo-verification proxy settings that enables you to do location “correction” or spoofing.

You can get the source for the tool and instructions on how to install it or build it yourself on github here.

NOTE: we are entirely unaffiliated with whoever produces this tool, we receive no compensation whatsoever from them.

Tool in the spotlight: Decentraleyes

Tool in the Spotlight: Decentraleyes, a Firefox extension which performs local emulation of Content Delivery Networks (CDN): Websites have increasingly begun to rely much more on large third-parties for content delivery. Canceling requests for ads or trackers is usually without issue, however blocking actual content, not unexpectedly, breaks pages. The aim of this add-on is to cut-out the middleman by providing lightning speed delivery of local (bundled) files to improve online privacy.

Check out the tool here.

NOTE: we are entirely unaffiliated with whoever produces this tool, we receive no compensation whatsoever from them.

Surveillance is creepy!

A person in an unmarked car following your every move and watching you 24/7 is considered creepy or requires a warrant, but replace this with an ever-expanding army of all-seeing machines who pry into everything you do on-line and everyone thinks that this is just dandy.

These all-seeing machines are obviously the tracking pixels, scripts, the browser-fingerprinting, the telemetry-collection, the displayed adverts, and whichever other mechanism or euphemisms used for surveillance, on pretty much every website you use.

We, at Fundamental Software, vehemently reject the idea that this type of surveillance is acceptable and we share insights, tools and conduct research and development to fight back!

IvyDNS is an online service that respects your privacy. It makes it significantly harder for these third parties to track users on-line.

Tool in the spotlight: HTTPS Everywhere

Tool in the Spotlight: HTTPS Everywhere, a Firefox extension by the good folks at the Electronic Frontier Foundation (EFF) that encrypts your communications with many major websites, making your browsing more secure. It checks whether websites you visit offer encrypted browsing and if they do, automatically switches you to the encrypted version of the website.

Check out the tool’s website for download instructions.

NOTE: we are entirely unaffiliated with whoever produces this tool, we receive no compensation whatsoever from them.

Windows 10 telemetry blatantly disregards user choice and privacy

With Windows 10, Microsoft blatantly disregards user choice & privacy. That’s not (just) us saying this, these are the good folks over at the Electronic Frontier Foundation.

Head over to the EFF’s page for the full article, which is most definitely a worthwhile read.

The amount of data that Windows 10 ‘telemetry’ sends back to Microsoft has, without exaggeration, never been greater: which apps you use, how long you use them, when you use which one, which sites you go to, how long you spend on them, even including your text input (yes, that’s what you type), etc… The list of data points that is collected on you and sent back to Microsoft goes on and on and on…

And sadly, one of the main purposes of this all is to profile you and be able to present you with advertising. You can turn if off now if you want, but unfortunately that’s not a guarantee that your devices will obey you nor does it mean that it will stay off when new ‘critical updates’ are pushed onto your devices.

Fortunately, even if you installed Windows 10 (be it willingly or unwillingly), IvyDNS monitors the domains in use by this ‘telemetry collection’ and prevents devices from connecting to them! In fact, IvyDNS keeps a special eye on these telemetry domains… because if your devices can’t reach these domains, they also can’t send the data back to them!

Online advertising is theft of your security

Advertising networks like Google AdSense, DoubleClick, Bing Ads and many others have a huge reach and that makes them very interesting to anyone trying to spread malware. Many mainstream sites give these networks real estate on their pages. When you visit your favorite site, which serves ads from such a network, in effect this network touches you and your device directly.

Advertising is not the only thing that advertising networks serve to passers-by. Increasingly frequently, those with less-than-honorable intentions are and have been using them to distribute drive-by download malware. All you have to do is visit a website where this ‘advert’ is served and if you have no other protection, you get infected without ever having to do a thing: it downloads automatically, infects you automatically, and you would never have known, all you did was visit a site. It could be a virus, spyware or in a worst case scenario, ransomware.

Once again, Google AdSense is being abused to distribute Android spyware. This isn’t the first time that this is happening and it won’t be the last. It’s just too easy for these networks with their huge reach to be exploited this way. The way this works is that someone buys advertising space through the network and submits something that looks and behaves entirely genuine as an ad. Once approved, the benign ad is switched out for the malware which now is served to a very specific set of people, namely those that the advertiser specified as being the target audience. Surprisingly, one can be remarkably specific in who you want to display your adverts to, as specific as saying “here’s a list of e-mail addresses of the people I want to show this specific ad to”. Google calls this particular form of targeting “Google CustomerMatch”.

This is just another reason why it is unwise to just allow any unvetted code coming from the internet to run on your devices. Especially not if it comes from a source that is known to be used as a distribution vector for malware.

IvyDNS protects from these types of attacks. It not only blocks devices from pulling down anything from advertising networks, it also blocks other known malware-related domains, be they exploits, phishing, hijacked domains, scams or other forms of undesirables. IvyDNS specifically hunts these domains down and makes sure you don’t get in contact with them.

More than a traditional ad-blocker

IvyDNS does ad-blocking and while this is not the only thing it does, it is the one that stands out most. With claims, or should we say ‘hopes’, by the IAB (Internet Advertising Board) that usage of ad-blockers is plateauing, they are still trying to get you to absorb as many ads as possible, fortunately IvyDNS is right besides you to protecting against the theft that is on-line advertising.

One of the newest trends that we are observing, and surely you’ve seen this as well, is that certain websites will be passive-aggressive and in most cases just plain aggressive in telling you that you can’t access the site unless you turn off your ad-blocker. How do they even know that you are running an ad-blocker? Well, these websites look for ad-blockers installed as extensions in your browser either by behavior or just by enumerating your extensions and when one is detected, trip the logic that complains to you.

But IvyDNS does not have a detectable footprint on your machine and it is not detectable in the same way ad-blockers are detected. This means that with IvyDNS, you keep flying under the radar, never to be seen by anything that is trying to steal away your attention or your bandwidth.

Traditional ad-blockers run inside your browser and only deal with HTTP/web traffic. Anything outside of that limited space is not something where they are even capable of protecting you. IvyDNS is different from your run-of-the-mill blocker, it works on a much deeper and more comprehensive level than traditional ad-blockers which protects you and your device from ever getting in contact with known advertising networks or domains associated with other undesirable content.

IvyDNS is much more effective in protecting against this undesirable content than regular ad-blockers: it prevents ahead of time instead of dealing with it afterwards!

Why privacy matters

Over the last 16 months, as I’ve debated this issue around the world, every single time somebody has said to me, “I don’t really worry about invasions of privacy because I don’t have anything to hide.” I always say the same thing to them. I get out a pen, I write down my email address. I say, “Here’s my email address. What I want you to do when you get home is email me the passwords to all of your email accounts, not just the nice, respectable work one in your name, but all of them, because I want to be able to just troll through what it is you’re doing online, read what I want to read and publish whatever I find interesting. After all, if you’re not a bad person, if you’re doing nothing wrong, you should have nothing to hide.” Not a single person has taken me up on that offer.

Glenn Greenwald in Why privacy matters – TED Talk

We do not use google analytics

Have you noticed that we don’t run Google Analytics on this site? If you’ve ever used it, you’ll be very well aware of the level of detailed in the information it gathers. When used and activated, it knows who you are, tracks you as you browse from page to page, knows how far down a page you scroll and much, much more, it even follows you from one site to another, because everyone else is using it. All of this information is used to build up a detailed profile of you based on your behavior and habits, all for a single purpose: to sell you on as a ‘known quantity’ to advertisers.

At Fundamental Software, we take privacy very seriously and we think that Google Analytics is a huge invasion of privacy. We therefore do not use it (Take a look at the requests sent by your device when you pull up this website, you’ll notice that those requests only go to our servers and not some set of unknown third parties that hitch a ride to display advertising or collect metrics.).

IvyDNS protects by default from Google Analytics’ (and other’s) prying eyes, even on sites that do use it or other metric-collection (e.g. New Relic). With IvyDNS, you literally stay under the radar of most of the prying eyes on-line.

This is just one of the ways that we walk the walk and don’t just talk the talk!