Hacker News new | ask | show | jobs
by pdkl95 4236 days ago
While these active MitM attacks are important (the methods seem to be similar to ARP-poisioning), we shouldn't leave out the passive capabilities. These may not even be listed as a feature, if it is a different tool that parses the already-captured traffic as a deferred job.

As we see mentioned here on HN all the time, there is a massive amount interesting data that can be pulled out of large datasets. The original WP publication[1] about COTRAVELER gives a very nice example of the power in just knowing very-inaccurate (cell-sized) location data. You probably don't even need any particular cell-network identifying number, given how easy it is to correlate this kind of data to other identifiers.

[1] http://apps.washingtonpost.com/g/page/world/how-the-nsa-is-t...