copy
Source: http://gizmodo.com/5877000/what-is-sopa
If you hadn’t heard of SOPA before, you probably have by now: Some of the internet’s most influential sites—Reddit and Wikipedia among them—are going dark to protest the much-maligned anti-piracy bill. But other than being a very bad thing, what is SOPA? And what will it mean for you if it passes?
SOPA is an anti-piracy bill working its way through Congress…
House Judiciary Committee Chair and Texas Republican Lamar Smith, along with 12 co-sponsors, introduced the Stop Online Piracy Act on October 26th of last year. Debate on H.R. 3261, as it’s formally known, has consisted of one hearing on November 16th and a “mark-up period” on December 15th, which was designed to make the bill more agreeable to both parties. Its counterpart in the Senate is the Protect IP Act (S. 968). Also known by it’s cuter-but-still-deadly name: PIPA. There will likely be a vote on PIPA next Wednesday; SOPA discussions had been placed on hold but will resume in February of this year.
…that would grant content creators extraordinary power over the internet…
The beating heart of SOPA is the ability of intellectual property owners (read: movie studios and record labels) to effectively pull the plug on foreign sites against whom they have a copyright claim. If Warner Bros., for example, says that a site in Italy is torrenting a copy of The Dark Knight, the studio could demand that Google remove that site from its search results, that PayPal no longer accept payments to or from that site, that ad services pull all ads and finances from it, and—most dangerously—that the site’s ISP prevent people from even going there.
…which would go almost comedically unchecked…
Perhaps the most galling thing about SOPA in its original construction is that it let IP owners take these actions without a single court appearance or judicial sign-off. All it required was a single letter claiming a “good faith belief” that the target site has infringed on its content. Once Google or PayPal or whoever received the quarantine notice, they would have five days to either abide or to challenge the claim in court. Rights holders still have the power to request that kind of blockade, but in the most recent version of the bill the five day window has softened, and companies now would need the court’s permission.
The language in SOPA implies that it’s aimed squarely at foreign offenders; that’s why it focuses on cutting off sources of funding and traffic (generally US-based) rather than directly attacking a targeted site (which is outside of US legal jurisdiction) directly. But that’s just part of it.
…to the point of potentially creating an “Internet Blacklist”…
Here’s the other thing: Payment processors or content providers like Visa or YouTube don’t even need a letter shut off a site’s resources. The bill’s “vigilante” provision gives broad immunity to any provider who proactively shutters sites it considers to be infringers. Which means the MPAA just needs to publicize one list of infringing sites to get those sites blacklisted from the internet.
Potential for abuse is rampant. As Public Knowledge points out, Google could easily take it upon itself to delist every viral video site on the internet with a “good faith belief” that they’re hosting copyrighted material. Leaving YouTube as the only major video portal. Comcast (an ISP) owns NBC (a content provider). Think they might have an interest in shuttering some rival domains? Under SOPA, they can do it without even asking for permission.
…while exacting a huge cost from nearly every site you use daily…
SOPA also includes an “anti-circumvention” clause, which holds that telling people how to work around SOPA is nearly as bad as violating its main provisions. In other words: if your status update links to The Pirate Bay, Facebook would be legally obligated to remove it. Ditto tweets, YouTube videos, Tumblr or WordPress posts, or sites indexed by Google. And if Google, Twitter, WordPress, Facebook, etc. let it stand? They face a government “enjoinment.” They could and would be shut down.
The resources it would take to self-police are monumental for established companies, and unattainable for start-ups. SOPA would censor every online social outlet you have, and prevent new ones from emerging.
…and potentially disappearing your entire digital life…
The party line on SOPA is that it only affects seedy off-shore torrent sites. That’s false. As the big legal brains at Bricoleur point out, the potential collateral damage is huge. And it’s you. Because while Facebook and Twitter have the financial wherewithal to stave off anti-circumvention shut down notices, the smaller sites you use to store your photos, your videos, and your thoughts may not. If the government decides any part of that site infringes on copyright and proves it in court? Poof. Your digital life is gone, and you can’t get it back.
…while still managing to be both unnecessary and ineffective…
What’s saddest about SOPA is that it’s pointless on two fronts. In the US, the MPAA, and RIAA already have the Digital Millennium Copyright Act (DMCA) to request that infringing material be taken down. We’ve all seen enough “video removed” messages to know that it works just fine.
As for the foreign operators, you might as well be throwing darts at a tse-tse fly. The poster child of overseas torrenting, Pirate Bay, has made it perfectly clear that they’re not frightened in the least. And why should they be? Its proprietors have successfully evaded any technological attempt to shut them down so far. Its advertising partners aren’t US-based, so they can’t be choked out. But more important than Pirate Bay itself is the idea of Pirate Bay, and the hundreds or thousands of sites like it, as populous and resilient as mushrooms in a marsh. Forget the question of should SOPA succeed. It’s incredibly unlikely that it could. At least at its stated goals.
…but stands a shockingly good chance of passing…
SOPA is, objectively, an unfeasible trainwreck of a bill, one that willfully misunderstands the nature of the internet and portends huge financial and cultural losses. The White House has come out strongly against it. As have hundreds of venture capitalists and dozens of the men and women who helped build the internet in the first place. In spite of all this, it remains popular in the House of Representatives.
That mark-up period on December 15th, the one that was supposed to transform the bill into something more manageable? Useless. Twenty sanity-fueled amendments were flat-out rejected. And while the bill’s most controversial provision—mandatory DNS filtering—was thankfully taken off the table recently, in practice internet providers would almost certainly still use DNS as a tool to shut an accused site down.
…unless we do something about it.
The momentum behind the anti-SOPA movement has been slow to build, but we’re finally at a saturation point. Wikipedia, BoingBoing, WordPress, TwitPic: they’ll all be dark on January 18th. An anti-SOPA rally has been planned for tomorrow afternoon in New York. The list of companies supporting SOPA is long but shrinking, thanks in no small part to the emails and phone calls they’ve received in the last few months.
So keep calling. Keep emailing. Most of all, keep making it known that the internet was built on the same principles of freedom that this country was. It should be afforded to the same rights.
—
drag2share – drag and drop RSS news items on your email contacts to share (click SEE DEMO)
Tags: ability, abuse, act, appearance, beating heart, Blacklist, Bricoleur, Bros, co sponsors, Comcast, committee chair, Congress, construction, content, content creators, copy, copyright, Court, court appearance, Dark, dark knight, delist, Facebook, faith, faith belief, February, good faith, google, government, heart, hold, house judiciary committee, intellectual property owners, interest, kind, Knight, lamar smith, language, life, line, MPAA, notice, October, online, original construction, party, payment, Piracy, plug, record, record labels, Reddit, search, Senate, single court, site, SOPA, stop, target, texas republican, traffic, US-based, version, video, vigilante, vote, warner bros, wikipedia, year, YouTube
Source: http://gizmodo.com/5855547/gamechanger-turns-your-ipad-into-a-closets-worth-of-board-games/gallery/1
You can tweak the rules to keep it interesting, but that copy of Monopoly sitting in your closet is always going to be Monopoly. The GameChanger, however, incorporates swappable skins and an iPad running accompanying apps so every game night it can be something completely different.
Instead of just using the iPad as a source for quiz questions or flashy animations, the GameChanger board actually serves as an iPad dock, allowing it to interact with the four included game pieces as they make their way around the board. Out of the box it includes two skins, The Magic School Bus and AnimalMania, with free downloadable apps that provide instructions, trivia, a virtual wheel and even automatic score keeping. But replay value isn’t its only advantage. The use of the iPad also eliminates the need for stacks of cards, dice, hotels, tiles and other accessories that can get bumped or even go missing, rendering a traditional board game unplayable. GameChanger’s available now for $80, while additional skins are promised to be released sometime in November. [GameChanger via Engadget]
![GameChanger Turns Your iPad into a Closet's Worth of Board Games medium gamechanger 1 GameChanger Turns Your iPad into a Closets Worth of Board Games [Video]](http://cache.gawkerassets.com/assets/images/4/2011/11/medium_gamechanger_1.jpg)
![GameChanger Turns Your iPad into a Closet's Worth of Board Games medium gamechanger 2 GameChanger Turns Your iPad into a Closets Worth of Board Games [Video]](http://cache.gawkerassets.com/assets/images/4/2011/11/medium_gamechanger_2.jpg)
—
drag2share – drag and drop RSS news items on your email contacts to share (click SEE DEMO)
Tags: advantage, AnimalMania, automatic score, board, board games, box, Bus, Closet, closets, copy, demo, dock, drag and drop, email, email contacts, Engadget, gallery 1, game, game night, game pieces, GameChanger, games gallery, interact, iPad, magic, magic school bus, Monopoly, need, news, news items, night, November, quiz, quiz questions, replay, school, score, share, something, Stacks, tiles, traditional board game, tweak, two skins, use, value, video, video source, way, wheel, worth
Source: http://gizmodo.com/5855547/gamechanger-turns-your-ipad-into-a-closets-worth-of-board-games/gallery/1
You can tweak the rules to keep it interesting, but that copy of Monopoly sitting in your closet is always going to be Monopoly. The GameChanger, however, incorporates swappable skins and an iPad running accompanying apps so every game night it can be something completely different.
Instead of just using the iPad as a source for quiz questions or flashy animations, the GameChanger board actually serves as an iPad dock, allowing it to interact with the four included game pieces as they make their way around the board. Out of the box it includes two skins, The Magic School Bus and AnimalMania, with free downloadable apps that provide instructions, trivia, a virtual wheel and even automatic score keeping. But replay value isn’t its only advantage. The use of the iPad also eliminates the need for stacks of cards, dice, hotels, tiles and other accessories that can get bumped or even go missing, rendering a traditional board game unplayable. GameChanger’s available now for $80, while additional skins are promised to be released sometime in November. [GameChanger via Engadget]
![GameChanger Turns Your iPad into a Closet's Worth of Board Games medium gamechanger 1 GameChanger Turns Your iPad into a Closets Worth of Board Games [Video]](http://cache.gawkerassets.com/assets/images/4/2011/11/medium_gamechanger_1.jpg)
![GameChanger Turns Your iPad into a Closet's Worth of Board Games medium gamechanger 2 GameChanger Turns Your iPad into a Closets Worth of Board Games [Video]](http://cache.gawkerassets.com/assets/images/4/2011/11/medium_gamechanger_2.jpg)
—
drag2share – drag and drop RSS news items on your email contacts to share (click SEE DEMO)
Tags: advantage, AnimalMania, automatic score, board, board games, box, Bus, Closet, closets, copy, demo, dock, drag and drop, email, email contacts, Engadget, gallery 1, game, game night, game pieces, GameChanger, games gallery, interact, iPad, magic, magic school bus, Monopoly, need, news, news items, night, November, quiz, quiz questions, replay, school, score, share, something, Stacks, tiles, traditional board game, tweak, two skins, use, value, video, video source, way, wheel, worth
Type the following User Agent String according to the screen shots for Chrome and Safari
Mozilla/5.0(iPad; U; CPU iPhone OS 3_2 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B314 Safari/531.21.10
For Safari (see screenshots below)
Go to Prefrences -> Advanced Tab
– make sure “Show Develop menu in menu bar” is checked
Go to Develop -> User Agent -> Other
- in the popup window, copy and paste the User Agent string from above and click OK
Log into Gmail — voila
For Chrome
Go to Windows Start Menu -> Run -> Type “cmd” and click enter to get to a command line window
- from your current directory you need to cd (change directory) into the directory where your chrome installation resides; for example C:\Documents and Settings\[YOUR NAME]\Local Settings\Application Data\Google\Chrome\Application>
- once in this directory, you type chrome.exe -user-agent=”Mozilla/5.0(iPad; U; CPU iPhone OS 3_2 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B314 Safari/531.21.10″
- once the application launches, log into Gmail — voila



Tags: #Safari site:twitter.com, access gmail ipad through chrome, access ipad gmail with safari, Advanced, Agent, AppleWebKit, application, application data, bar, c documents, Change, change chrome agent mac, change directory, change user agent chrome for gmail ONLY, change user agent chrome ipad, change user agent chrome to iphone, change user agent in chrome mac, changing user agent in chrome mac os x, Chrome, chrome change user agent string os X, chrome for ipad, chrome gmail ipad, CHROME IPAD, chrome ipad agent, chrome ipad gmail, chrome ipad user agent, chrome ipad user string, chrome mobile gmail, chrome os x gmail ipad, chrome user agent ipad, cmd, command, copy, copy and paste, CPU, data, directory, documents and settings, example, exe, Faux iPad experience on your netbook, Gecko, get the ipad version of gmail in safari, Gmail, gmail for ipad, gmail for ipad chrome, gmail for ipad for pc, gmail for ipad in chrome, gmail for ipad on chrome, gmail for safari mac ipad, gmail ipad access, gmail ipad chrome, gmail ipad chrome mac, gmail ipad howto, gmail ipad in chrome, gmail ipad on chrome, gmail ipad on pc, gmail ipad on safari, gmail ipad on safari mac, gmail ipad pc, gmail ipad safari, gmail ipad safari mac, gmail ipad settings, gmail ipad string, gmail ipad user agent chrome, gmail ipad version on chrome, gmail ipad version on computer chrome, gmail ipad version on mac, gmail ipad view, gmail ipad view chrome, gmail ipad view for safari, gmail ipadchrome, gmail like ipad on chrome, gmail on ipad, gmail on safari ipad, gmail safari ipad, gmail safari ipad user agent, gmail user agent in chrome, gmail view ipad, google, google chrome ipad user agent, how do i view iPad version of gmail, How Does your Website Look on an iPad?, how to access gmail for ipad using chrome, How to use gmail ipad view from google chro..., How to use Gmail with tablet interface using Chrome browser, How to Use Gmail's iPad Interface in Your Desktop, how to use ipad gmail in chrome, how to view gmail mobile site on chrome, how to view gmail on computer like on iphon..., how to view gmail on ipad safari, how to view ipad gmail in chrome, how to view ipad version of gmail, How-To Surf The Web iPad Style From Your PC and Chrome, How-To Surf The Web iPad Style From Your PC and Firefox, How-To Surf The Web iPad Style From Your PC and Safari, install user agent chrome ipad, installation, iPad, ipad agent for chrome, iPad and chrome, ipad chrome gmail, ipad chrome useragent, ipad gecko site:go-digital.net, ipad gmail chrome, ipad gmail for chrome, ipad gmail for mac chrome, ipad gmail for pc, ipad gmail in chrome, ipad gmail in mozilla, ipad gmail in safari, ipad gmail on chrome, ipad gmail on pc, ipad gmail on pc chrome, ipad gmail on regular computer, ipad gmail on safari, ipad gmail on windows chrome, ipad gmail safari, ipad gmail safari mac, ipad gmail view, ipad gmail view pc, ipad gmail view safari, ipad gmail with safari, ipad safari gmail, iPad safari menu bar, ipad safari user agent, ipad user agent chrome, ipad user agent for chrome, iPad User Agent Safari OS X, ipad useragent chrome, ipad useragent safari, ipad version of gmail in chrome os x, ipad version of gmail on pc, ipad view, ipad view chrome, ipad view menus, iPad; U; CPU iPhone OS 3_2 like Mac OS X; c..., iPad; U; CPU iPhone OS 3_2 like Mac OS X; chr..., iPhone, KHTML, line, Local, local settings, Log, mac chrome gmail ipad, mac chrome ipad, Mac OS, mac os x, make chrome run like ipad, menu, menu bar, Mobile, Mozilla, name, os x, osx chrome ipad gmail, paste, popup, popup window, Prefrences, run, run ipad gmail on pc, Safari, safari gmail ipad, safari ipad gmail, safari ipad user agent gmail, safari ipad user agent string, safari ipad view, safari user agent ipad, screen, screen shots, see gmail for ipad now, see gmail in ipad view, Settings, settings for gmail on ipad, setup chrome browser to get ipad gmail view, show, Start, start menu, string, Tab, Test your Website Design on an Apple iPad Without Having One, type, user, user agent ipad chrome, user agent ipad safari, User agent settings in Chrome, user agent string, user agent string for chrome mac, using the ipad gmail view in pc, version, view gmail ipad, view gmail ipad safari, view gmail ipad version on a pc, view gmail like ipad, view gmail mobile on computer, view gmail on computer in iPad view, view ipad gmail in chrome, view ipad gmail on mac, view ipad gmail on pc, view ipad version gmail on macboo, viewing gmail ipad, visit gmail ipad site on chrome, voila, window, Windows
Source: http://gizmodo.com/5501346/law-enforcement-appliance-subverts-ssl
That little lock on your browser window indicating you are communicating securely with your bank or e-mail account may not always mean what you think its means.
Normally when a user visits a secure website, such as Bank of America, Gmail, PayPal or eBay, the browser examines the website’s certificate to verify its authenticity.
At a recent wiretapping convention however, security researcher Chris Soghoian discovered that a small company was marketing internet spying boxes to the feds designed to intercept those communications, without breaking the encryption, by using forged security certificates, instead of the real ones that websites use to verify secure connections. To use the appliance, the government would need to acquire a forged certificate from any one of more than 100 trusted Certificate Authorities.
The attack is a classic man-in-the-middle attack, where Alice thinks she is talking directly to Bob, but instead Mallory found a way to get in the middle and pass the messages back and forth without Alice or Bob knowing she was there.
The existence of a marketed product indicates the vulnerability is likely being exploited by more than just information-hungry governments, according to leading encryption expert Matt Blaze, a computer science professor at University of Pennsylvania.
“If company is selling this to law enforcement and the intelligence community, it is not that large a leap to conclude that other, more malicious people have worked out the details of how to exploit this,” Blaze said.
The company in question is known as Packet Forensics, which advertised its new Man-In-The-Middle capabilities in a brochure handed out at the Intelligent Support Systems (ISS) conference, a Washington DC wiretapping convention that typically bans the press. Soghoian attended the convention, notoriously capturing a Sprint manager bragging about the huge volumes of surveillance requests it processes for the government.
According to the flyer: “Users have the ability to import a copy of any legitimate key they obtain (potentially by court order) or they can generate ‘look-alike’ keys designed to give the subject a false sense of confidence in its authenticity.” The product is recommended to government investigators, saying “IP communication dictates the need to examine encrypted traffic at will” and “Your investigative staff will collect its best evidence while users are lulled into a false sense of security afforded by web, e-mail or VOIP encryption.”
Packet Forensics doesn’t advertise the product on its website, and when contacted by Wired.com, asked how we found out about it. Company spokesman Ray Saulino initially denied the product performed as advertised, or that anyone used it. But in a follow-up call the next day, Saulino changed his stance.
“The technology we are using in our products has been generally discussed in internet forums and there is nothing special or unique about it,” Saulino said. “Our target community is the law enforcement community.”
Blaze described the vulnerability as an exploitation of the architecture of how SSL is used to encrypt web traffic, rather than an attack on the encryption itself. SSL, which is known to many as HTTPS://, enables browsers to talk to servers using high-grade encryption, so that no one between the browser and a company’s server can eavesdrop on the data. Normal HTTP traffic can be read by anyone in between – your ISP, a wiretap at your ISP, or in the case of an unencrypted WiFi connection, by anyone using a simple packet sniffing tool.
In addition to encrypting the traffic, SSL authenticates that your browser is talking to the website you think it is. To that end, browser makers trust a large number of Certificate Authorities – companies that promise to check a website operator’s credentials and ownership before issuing a certificate. A basic certificate costs less than $50 today, and it sits on a website’s server, guaranteeing that the BankofAmerica.com website is actually owned by Bank of America. Browser makers have accredited more than one hundred Certificate Authorities from around the world, so any certificate issued by any one of those companies is accepted as valid.
To use the Packet Forensics box, a law enforcement or intelligence agency would have to install it inside an ISP, and persuade one of the Certificate Authorities – using money, blackmail or legal process – to issue a fake certificate for the targeted website. Then they could capture your username and password, and be able to see whatever transactions you make online.
Technologists at the Electronic Frontier Foundation, who are working on a proposal to fix this whole problem, say hackers can use similar techniques to steal your money or your passwords. In that case, attackers are more likely to trick a Certificate Authority into issuing a certificate, a point driven home last year when two security researchers demonstrated how they could get certificates for any domain on the internet simply by using a special character in a domain name.
“It is not hard to do these attacks,” said Seth Schoen, an EFF staff technologist. “There is software that is being published for free among security enthusiasts and underground that automate this.”
China, which is known for spying on dissidents and Tibetan activists, could use such an attack to go after users of supposedly secure services, including some Virtual Private Networks, which are commonly used to tunnel past China’s firewall censorship. All they’d need to do is convince a Certificate Authority to issue a fake certificate. When Mozilla added a Chinese company, China Internet Network Information Center, as a trusted Certificate Authority in Firefox this year, it set off a firestorm of debate, sparked by concerns that the Chinese government could convince the company to issue fake certificates to aid government surveillance.
In all, Mozilla’s Firefox has its own list of 144 root authorities. Other browsers rely on a list supplied by the operating system manufacturers, which comes to 264 for Microsoft and 166 for Apple. Those root authorities can also certify secondary authorities, who can certify still more – all of which are equally trusted by the browser.
The list of trusted root authorities includes the United Arab Emirates-based Etilisat, a company which was caught last summer secretly uploading spyware onto 100,000 customers’ Blackberrys.
Soghoian says fake certificates would be a perfect mechanism for countries hoping to steal intellectual property from visiting business travelers. The researcher published a paper (.pdf) on the risks Wednesday, and promises he will soon release a Firefox add-on to notify users when a site’s certificate is issued from an authority in a different country than the last certificate the user’s browser accepted from the site.
EFF’s Schoen, along with fellow staff technologist Peter Eckersley and security expert Chris Palmer, want to take the solution further, using information from around the net so that browsers can eventually tell a user with certainty when they are being attacked by someone using a fake certificate. Currently browsers warn users when they encounter a certificate that doesn’t belong to a site, but many people simply click through the multiple warnings.
“The basic point is that in the status quo there is no double check and no accountability,” Schoen said. “So if Certificate Authorities are doing things that they shouldn’t, no one would know, no one would observe it. We think at the very least there needs to be a double check.”
EFF suggests a regime that relies on a second level of independent notaries to certify each certificate, or an automated mechanism to use anonymous Tor exit nodes to make sure the same certificate is being served from various locations on the internet – in case a user’s local ISP has been compromised, either by a criminal, or a government agency using something like Packet Forensics’ appliance.
One of the most interesting questions raised by Packet Forensics product is how often do governments use such technology and do Certificate Authorities comply. Christine Jones, the general counsel for GoDaddy – one of the net’s largest issuers of SSL certificates – says her company has never gotten such a request from a government in her 8 years at the company. ”I’ve read studies and heard speeches in academic circles that theorize that concept, but we never would issue a ‘fake’ SSL certificate,” Jones said, arguing that would violate the SSL auditing standards and put them at risk of losing their certification. “Theoretically it would work, but the thing is we get requests from law enforcement every day, and in entire time we have been doing this, we have never had a single instance where law enforcement asked us to do something inappropriate.”
VeriSign, the largest Certificate Authority, declined to comment.
Matt Blaze notes that domestic law enforcement can get many records, such as a person’s Amazon purchases, with a simple subpoena, while getting a fake SSL certificate would certainly involve a much higher burden of proof and technical hassles for the same data.
Intelligence agencies would find fake certificates more useful, he adds. If the NSA got a fake certificate for Gmail – which now uses SSL as the default for e-mail sessions in their entirety (not just their logins) – they could install one of Packet Forensics’ boxes surreptitiously at an ISP in, for example, Afghanistan, in order to read all the customer’s Gmail messages. Such an attack, though, could be detected with a little digging, and the NSA would never know if they’d been found out.
Despite the vulnerabilities, experts are pushing more sites to join Gmail in wrapping their entire sessions in SSL.
“I still lock my doors even though I know how to pick the lock,” Blaze said.
Wired.com has been expanding the hive mind with technology, science and geek culture news since 1995.
Tags: acco, account, Agency, Alice, America, Anyone, appliance, attack, authenticity, authority, bank, bank of america, being, Bob, browser, case, certificate, certificate authorities, check, China, Chris Palmer, Chris Soghoian, com, communication, community, company, computer, computer science professor, confidence, convention, copy, Court, domain, e mail account, eBay, eff, encryption, enforcement, existence, expert, feds, Firefox, forensics, Gmail, government, ility, information, Intelligence, intelligence community, intercept, Internet, ISP, law, leap, list, lock, Mallory, man in the middle attack, Matt Blaze, mechanism, money, Mozilla, need, new man, order, Packet, PayPal, Pennsylvania, Peter Eckersley, point, Private Networks, Product, professor, Ray Saulino, researcher, root, Science, secure website, security, security certificates, sense, server, Seth Schoen, site, SSL, staff, technologist, Tor, traffic, United Arab Emirates, University, university of pennsylvania, user, vulnerability, Washington, way, Web, website, window, year