Certbot: Pushing HTTPS Past the Tipping Point

▶ Watch (4:21)

Alexis Hancock described a web where HTTPS once cost money and required manual virtual host configuration. Around 2010 only about 10 sites supported it. Now over 80% of global web traffic uses HTTPS automatically. Certbot, a primary client for Let’s Encrypt, automates TLS certificate issuance. That shift makes it harder for attackers on public Wi-Fi to intercept payment data or form submissions. The project turned a once-ridiculous vision into the default state of the web.

Surveillance Self-Defense: Security Planning for Everyone

▶ Watch (7:13)

Thorin Klosowski runs Surveillance Self-Defense, a 16-year-old repository of security guides. The project replaced military-coded “threat modeling” with “security planning” to bring in non-technical users. The guides teach risk assessment for protests, travel, and daily life. SSD draws directly from EFF’s investigations and training sessions with at-risk communities. It does not recommend specific password managers or VPNs. It teaches people how to choose what fits their situation.

Privacy Badger and the Data Broker Pipeline

▶ Watch (16:06)

Cooper Quintin explained that Privacy Badger started 11 years ago as an ad-blocking browser extension. It detects and stops web trackers. The project became more critical as law enforcement found ways to bypass warrants. Companies like Locate X sell location data from phones. Fog Data Science sells data profiles. Shadow Dragon maps social media presence through exclusive API deals. Police buy all of it. Privacy Badger blocks the tracking that feeds those data brokers.

Threat Lab: From Daycare Apps to Botnet Tablets

▶ Watch (24:15)

Alexis Hancock investigated Brightwheel, a daycare app she was forced to use during the pandemic. It had no two-factor authentication, open cloud buckets of children’s photos, and no security page. COPPA did not apply because parents use the app, not children. After her investigation hit Wired, Brightwheel added 2FA and segmented account types. A separate investigation into her daughter’s Dragon Touch tablet revealed BadBox, a botnet pre-installed on low-budget Android devices. Google estimates 10 million devices are impacted.

Ray Hunter: Finding IMSI Catchers on a Budget

▶ Watch (36:15)

Cooper Quintin built Ray Hunter to detect fake cell towers, known as IMSI catchers or Stingrays. The software runs on a $20 mobile hotspot. It analyzes network traffic between the cellular modem and towers for signs of simulation. Deployed at protests throughout the summer, the devices found no signs of police using IMSI catchers at those events. The data updated SSD guidance to flag other surveillance tools like license plate readers and phone extraction devices instead.

Q&A

How can individuals fight for a better future when contacting representatives feels futile? The panelists recommended building local community resilience, focusing on hyperlocal activism against surveillance tools like Flock cameras, and not giving up on traditional methods as coalitions are fragile and can reach critical mass. ▶ Watch (42:45)

Notable Quotes

the fact that over the 10 plus years we’ve made the web more encrypted is a really big win for us at eff Alexis Hancock · ▶ Watch (6:24)

it is illegal for the government to spy on you in a lot of ways. it is completely legal for private companies to spy on you and then for the government to buy that data. Cliff · ▶ Watch (15:44)

you don’t need a warrant to spy on somebody if you can just buy that data from a company Cooper Quintin · ▶ Watch (17:02)

he confirmed like yes it is as bad as i think it is and actually was a little worse Alexis Hancock · ▶ Watch (27:00)

we’ve found no signs of police using MC catchers at protests Cooper Quintin · ▶ Watch (39:53)

Key Takeaways

  • Certbot helped push HTTPS adoption past 80% globally from near zero in 2010.
  • Privacy Badger blocks trackers that feed data broker pipelines to law enforcement.
  • Surveillance Self-Defense replaced threat modeling with security planning for wider accessibility.
  • Brightwheel added 2FA and account segmentation after EFF’s investigations.
  • Ray Hunter found no IMSI catchers at protests, redirecting activist concerns to other threats.

About the Speaker(s)

Alexis Hancock is an expert technologist and researcher on the security vulnerabilities which plague consumer electronics, and can speak to the disparate impact they have on communities.

Cooper Quintin is a senior public interest technologist with the EFF Threat Lab. He has given talks about security research at prestigious security conferences including Black Hat, DEFCON, Shmoocon, and ReCon about issues ranging from IMSI Catcher detection to Femtech privacy issues to newly discovered APTs. He has two children and is very tired. Cooper has many years of security research experience on tools of surveillance used by government agencies.

Lisa Femia focuses on surveillance, privacy, free speech, and the impact of technology on civil rights and civil liberties.

Thorin Klosowski is the Security and Privacy Activist at EFF, where he focuses on providing practical advice to protecting online security, including handling much of Surveillance Self-Defense.