Saturday, October 13, 2018

Broadband Industry Getting Nervous That The FCC Might Actually Protect User Privacy | Techdirt

Broadband Industry Getting Nervous That The FCC Might Actually Protect User Privacy | Techdirt




Broadband Industry Getting Nervous That The FCC Might Actually Protect User Privacy

Back in 2008, Verizon proclaimed that broadband services didn't need additional consumer privacy protections because "public shame" would keep the broadband industry honest. But in late 2014, Verizon found itself at the center of a privacy scandal after security researchers discovered the company was embedding stealth tracking technology in every packet sent by the company's wireless users. These "stealth cookies" were being used by Verizon for two years before they were even discovered, and it took another six months of public and press outrage for Verizon to let users opt out.

In other words, public shame didn't work, because even security researchers weren't able to detect what Verizon was doing. Verizon's behavior specifically prompted the FCC to use its new Title II authority to begin crafting marginally-tougher consumer privacy protections. Under Title II, ISPs are now subject to Title II's Section 222 privacy protections regarding "customer proprietary network information" (CPNI). But since those rules were crafted for older phone companies, the FCC's looking to modernize them for the smartphone and "Internet of Things" age.

This has, as you might expect, been met with renewed annoyance by the broadband industry. Most of the broadband industry's major lobbying organizations have fired off a letter to the FCC (pdf) that basically urges the FCC to pass rules that aren't all that clear or tough, since tough rules might just hurt the industry's incredible love of innovation and competition:
If the courts determine that the FCC has authority to regulate broadband privacy, we encourage you to develop a framework that offers consumers robust privacy protection, while at the same time allowing broadband providers to continue to innovate and compete...Our member companies recognize that ensuring robust privacy protection is important and have devoted substantial capital, resources and personnel to develop, maintain, and enhance meaningful data privacy and security programs. Indeed, our companies have strong incentives to earn and maintain their customers' loyalty by protecting their data.
Except that hasn't really proven to be the case.

Verizon's incentive certainly wasn't consumer loyalty when it designed a super cookie that ignored all consumer privacy preferences and browser settings. And that kind of thinking has been more the norm than aberrant behavior, given that ISPs have been selling user clickstream data for more than a decade (and lying about it). Similarly, the kind of "innovations" consumers have grown used to have included being forced to pay a premium for privacy, such as how AT&T forces U-Verse broadband customers to pay $44 to $64 more per month if they want to opt out of AT&T's deep packet inspection snoopvertising.

And that's just fixed-line broadband. Privacy essentially doesn't exist when it comes to wireless, where both usage and location data is shared with absolutely anybody ready to write the major wireless carriers a check. And as the major broadband players push into smart home, security, automation, connected vehicle and other fields, you can be absolutely sure that their total lack of privacy principles will be coming along for the ride. That's why more than fifty privacy-focused groups including the EFF sent their own letter (pdf) to the FCC last month urging it to become a "brawnier cop on the beat" on broadband privacy.

And while the broadband industry's myriad of mouthpieces are sure to whine incessantly about "over regulation" here, the industry had absolutely every opportunity over the last decade to self-regulate and avoid "tougher" (read: any) privacy protections. Instead, as Verizon's super cookies perfectly exemplify, the industry thought that lifting a giant middle finger to consumers was the smarter option.


Elyssa D. Durant 
Research & Policy Analyst
Columbia University, New York

T-Mobile CEO Tells Congress That Reducing Competition Will Increase Competition - Motherboard

T-Mobile CEO Tells Congress That Reducing Competition Will Increase Competition - Motherboard

T-Mobile CEO Tells Congress That Reducing Competition Will Increase Competition

T-Mobile and Sprint are trying to merge, which would make three major cell phone providers instead of four. By Karl Bode | Jun 29 2018, 8:56am

Sprint and T-Mobile are attempting to merge as part of a $23 billion deal that will reduce the number of overall major players in the U.S. wireless market from four to three.

On Wednesday, executives from both companies told a Senate Judiciary subcommittee investigating the deal that reducing the overall number of competitors in the space will somehow result in more competition, better service, and lower prices, something telecom merger history—and basic mathematics—fail to support.

"This consolidation will lead to lower prices," T-Mobile CEO John Legere told hearing attendees.
"This is actually moving from two to three," Legere claimed, insisting that joining forces with Sprint will make a more "viable competitor" for AT&T and Verizon.

But that's not how competition, especially in the already competitively-challenged telecom sector, actually works. Historically, as a market gets more concentrated, there's proportionally less incentive for the remaining companies to seriously compete on price. And since pleasing shareholders is a corporation's primary responsibility, they're quick to oblige.

That's why regulators have repeatedly blocked this merger and others like it. Regulators blocked a previous tie up between Sprint and T-Mobile in 2014—as well as an attempt by AT&T to acquire T-Mobile in 2011—because they felt that reducing the overall number of players in the space would dramatically harm competition.

"For the second time in a decade the DOJ and FCC are asked to bless a transaction that would reduce the number of national wireless carriers from four to three," said Public Knowledge President Gene Kimmelman. "Based on what we know, they should come to the same conclusion this time as they did with the AT&T/T-Mobile deal, and find that this deal also would harm consumers and should be stopped."

History has repeatedly-shown such worries to be well justified. Canadian consumers, for example, pay some of the highest prices in the world for mobile data, thanks to consolidation that left the wireless industry with just three major wireless carriers. Even with four carriers, U.S. mobile customers don't fare much better in comparison with their European counterparts.

Still, T-Mobile has had a profoundly-positive impact on the U.S. wireless sector, highlighting how the DOJ's decision to block AT&T's planned merger was the right decision.

Added competition from T-Mobile and Sprint forced their larger counterparts at AT&T and Verizon to ditch metered data and bring back unlimited data plans several years ago. T-Mobile's policies have also forced a notable reduction in the cost of overseas roaming, as well as the elimination of long term contracts, and early termination fees.

But T-Mobile's consumer-friendly branding does have its limits.

For example, T-Mobile supported the Trump administration's attack on net neutrality, a move that's likely to drive up rates further for consumers. The company has also been routinely criticized for heavy-handed tactics in terms of hamstringing employee unionization efforts, and more recently came under fire for hiring Trump ally Corey Lewandowski as a merger advisor.

Regardless of T-Mobile's promises, some lawmakers remained skeptical that T-Mobile would remain as focused on disrupting AT&T and Verizon post merger.

"Will a combined T-Mobile-Sprint need to compete as hard?" Senator Amy Klobuchar asked the companies at this week's hearing. "Will that competitive energy remain when the lowest-cost provider is gone and the merged company is similar in scale to Verizon and AT&T?"

Historically, the answer to that question has been a resounding no. Meanwhile, others were quick to question the companies' claims that the merger will somehow be a boon for American job creation.

The Communications Workers of America, for example, issued a study in the wake of this week's testimony claiming the deal could result in the loss of up to 30,000 jobs as redundant positions are inevitably eliminated. More objective Wall Street analysts have agreed, estimating that retail store closures are likely to eliminate between 10,000 and 30,000 redundant positions.

That's in stark contrast to what company executives told Congress.

"In his sworn testimony, Mr. Legere pledged that the merger would result in opening 600 new retail stores and would create 11,000 incremental new jobs by 2024, and yet the CWA projects the merger will result in 5,000 store closures and the elimination of 30,000 jobs," argues Peter Adderton, the founder of Boost Mobile, a Sprint-owned prepaid wireless vendor.

Again, the idea that megamergers, especially in telecom, result in higher prices and significant job losses isn't really debatable. You only need to look at the historical landscape of similar deals, from Charter's recent acquisition of Time Warner Cable, to years' worth of similar blockbuster deals by the likes of AT&T and Comcast.

Each and every time, we're promised an amazing universe of synergies that are only made possible via sector consolidation and the erosion of smaller competitors. And time and time again, like Charlie Brown and his football, we're eager to repeat our mistakes, having learned nothing.



Elyssa D. Durant 
Research & Policy Analyst
Columbia University, New York

Medtronic disables pacemaker programmer updates over hack concern - Tech News | The Star Online

Medtronic disables pacemaker programmer updates over hack concern - Tech News | The Star Online
The next big thing is overriding opioid pain pumps at the hospital. 

How do o know? Because that's how my hackers "paid" the junkie to get my info. 

Pueblo the junkie was involved with taking down emergency network communications and is being investigated by the FBI for taking down the emergency cell towers in Colorado. 


Medtronic disables pacemaker programmer updates over hack concern

A researcher holding one of the Medtronic heart defibrillators he successfully hacked, at MIT in Cambridge, Massachusetts. Medtronic has disabled Internet updates for some 34,000 CareLink programming devices. — Reuters
A researcher holding one of the Medtronic heart defibrillators he successfully hacked, at MIT in Cambridge, Massachusetts. Medtronic has disabled Internet updates for some 34,000 CareLink programming devices. — Reuters

NEW YORK: Medical device maker Medtronic Plc has disabled Internet updates for some 34,000 CareLink programming devices that healthcare providers around the world use to access implanted pacemakers, saying the system was vulnerable to cyberattacks.

The company, in a letter sent to physicians this week, said it knows of no cases where the vulnerability was exploited by hackers. The letter was labelled "urgent medical device correction".

ADVERTISEMENT

The vulnerability "could result in harm to a patient depending on the extent and intent of a malicious cyberattack and the patient's underlying condition", according to the letter, which was seen by Reuters on Oct 11.

Pacemakers and implantable defibrillators are small devices placed in the chest that use electronic pulses to control abnormal heart rhythms in patients with arrhythmias.

The US Food and Drug Administration issued a safety notice describing the vulnerability, saying it reviewed the matter and approved of Medtronic's decision to disable the Internet updates.

The agency urged healthcare providers to continue to use the CareLink programs, but advised them not to attempt to update the software over the internet. It said that patients do not need to take any action to mitigate the vulnerability.

Medical device makers have bolstered efforts to mitigate product security vulnerabilities in recent years following a flurry of warnings from security researchers who have identified bugs in devices like the Medtronic implant programmers.

There have been no documented reports of attacks on medical devices, though researchers warn the industry is far behind the computer industry in protecting devices from hackers.

Medtronic in August issued an alert on the issue with its CareLink programmers after researchers discussed the vulnerability at the Black Hat hacking conference. Medical device security experts said they had uncovered a bug that could enable hackers to update malicious software onto the programmers, then attack implanted pacemakers.

Pacemakers and implantable defibrillators are small devices placed in the chest that use electronic pulses to control abnormal heart rhythms in patients with arrhythmias.

Medtronic kept the network updates running until recently, saying it had increased security controls and boosted monitoring for potential malicious activity.

The vulnerability affects the internet-based platform for updating some 34,000 CareLink 2090 and CareLink Encore 29901 programmers that healthcare providers around the globe use to program implanted pacemakers, according to Medtronic.

The company said in the letter that it was is working to develop security updates "that will further address these vulnerabilities and will be implemented pending regulatory agency approvals".

In the meantime, the programmers can still be manually updated using a USB connection, it said. – Reuters



Elyssa Durant

Friday, October 12, 2018

How to Hack WebSockets and Socket.io - Black Hills Information Security

How to Hack WebSockets and Socket.io - Black Hills Information Security

How to Hack WebSockets and Socket.io

Ethan Robish //

WebSockets Overview

WebSockets is a technology to allow browsers and servers to establish a single TCP connection and then asynchronously communicate in either direction. This is great for web apps as it allows real time updates without the browser needing to send hundreds of new HTTP polling requests in the background. It's bad for pentesters as the tool support for WebSockets is not nearly as prevalent or sophisticated as for HTTP.  

In addition to Burp Suite, a few other tools exist for dealing with WebSockets. I attempted to use each of these but none of them worked the way I wanted.

  • Zed Attack Proxy (ZAP)
  • Pappy Proxy
  • Man-in-the-Middle Proxy (mitmproxy)
  • WebSocket/Socket.io (WSSiP)

If you're interested in using WebSockets on the offensive side to evade detection check out this post.

https://www.blackhillsinfosec.com/command-and-control-with-websockets-wsc2/ 

In this post I'm going to mainly focus on socket.io, a popular WebSockets library for JavaScript. However, some of the ideas here could be applied to other libraries or generically to the WebSockets protocol as well.

How popular is socket.io? It has over 41 thousand stars on Github.

It also occupies the slots for 2nd and 3rd most popular WebSockets package on NPM.

It turns out that the excellent OWASP Juice-Shop Project uses the socket.io library so I will be using it for demonstration.

https://github.com/bkimminich/juice-shop/search?utf8=%E2%9C%93&q=socket.io&type=

This post assumes you are already somewhat familiar with testing web applications using Burp Suite, and everything covered can be accomplished in the Community Edition. Without further ado, let's jump in.

If we go to Juice-Shop in the browser, we can quickly see the WebSocket traffic in the background. You can find this in Burp by going to Proxy->WebSockets history.

Unlike HTTP where you always have request/response pairs due to the stateless nature of the protocol, WebSockets is a stateful protocol. This means that you can have any number of outgoing "requests" and any number of incoming "responses" from the server. Since the underlying connection is TCP that is held open both the client and the server can send messages at any time without waiting for the other. This explains the differences in the WebSockets history view from the HTTP history you may be used to looking at.

In this view you'll mostly see single-byte messages sent and received. But when the application does something interesting you'll see messages with larger payloads.

Burp has some capability for testing with WebSockets. You can intercept and modify them real time but there is no Repeater, Scanner, or Intruder functionality for WebSockets. WebSocket interception is enabled by default in Burp and all you need to do is turn on the master interception.

You'll get intercepted WebSocket messages the same way you do for HTTP. You can also edit them in the interception window.

And view the edited messages in the WebSockets history tab.

Downgrading WebSockets to HTTP

Method 1: Abusing Socket.io's HTTP Fallback Mechanism

One oddity I quickly noticed was that sometimes I would see similar messages in the HTTP history as I had seen in the WebSockets history. If you recall from above, the interesting WebSockets message I pointed out had to do with solving the scoreboard challenge. Below shows the same response from the server except this time in HTTP history. So I knew that socket.io was capable of sending messages both over WebSockets or HTTP.

I guessed that HTTP was available in order to fall back on in case WebSockets was not supported or somehow blocked in the application. The transport parameter drew my attention with its values of "websockets" and "polling" in the requests I observed.

This section in socket.io's documentation talks about how "polling" and "websockets" are the two default transport options. It also shows how you can disable polling by specifying WebSockets as the sole transport. I figured the reverse would be true as well and that I could specify polling as the sole transport mechanism.

https://socket.io/docs/client-api/#with-WebSocket-transport-only 

By searching through socket.io.js source code I came across the following, which certainly looked promising.

this.transports=n.transports||["polling","WebSocket"]

That line of code is setting an internal variable called "transports" to some value passed in OR defaulting to ["polling","websocket"] if the passed in value is false/empty. That would definitely fit our understanding so far of the default transports being polling and WebSockets. Let's see what happens if we set up a match and replace rule under Proxy->Options in Burp to change these defaults.

Success! After the rule was added, refresh the page (I also had to enable Burp's built-in rule to "Require non-cached response" or perform a forced refresh), and no more communication was sent via WebSockets.

That's great, but what if the application you are using already provides transport options which would take precedence over our new defaults? In this case we can just modify our match and replace rule. The following rule should work for different versions of the socket.io library, and disregard any transports specified by the application developers.

For ease of copy-paste here are the strings to use:

this\.transports=.*?\.transports\|\|\["polling","websocket"]    this.transports=["polling"]

Be sure to set this as a regex match.


Method 2: Interrupting the WebSockets Upgrade

Method 1 is specific to socket.io and could possibly be extended to other client libraries. But the following method should be a little more universal as it targets the WebSockets protocol itself.

After some investigation, I found that WebSockets first communicates over HTTP in order to negotiate with the server and "upgrade" a connection to a WebSocket. The important parts of this are:

1) The client sends requests an upgrade request with some WebSocket specific headers.

2) The server responds with a status code of 101 Switching Protocols, also with some WebSocket specific headers.

3) The communication transitions to WebSockets and we don't see any more HTTP requests for this particular conversation.

The WebSockets RFC section 4.1 gives all sorts of clues on how we can interrupt this workflow.

Below is an excerpt from https://tools.ietf.org/html/rfc6455#section-4.1 with my own added emphasis.

  1.  If the status code received from the server is not 101, the
client handles the response per HTTP [
RFC2616] procedures. In
particular, the client might perform authentication if it
receives a 401 status code; the server might redirect the client
using a 3xx status code (but clients are not required to follow
them), etc. Otherwise, proceed as follows.

2.  If the response lacks an |Upgrade| header field or the |Upgrade|
header field contains a value that is not an ASCII case-
insensitive match for the value "WebSocket", the client MUST
_Fail the WebSocket Connection_.

3.  If the response lacks a |Connection| header field or the
|Connection| header field doesn't contain a token that is an
ASCII case-insensitive match for the value "Upgrade", the client
MUST _Fail the WebSocket Connection_.

4.  If the response lacks a |Sec-WebSocket-Accept| header field or
the |Sec-WebSocket-Accept| contains a value other than the
base64-encoded SHA-1 of the concatenation of the |Sec-WebSocket-
Key| (as a string, not base64-decoded) with the string "258EAFA5-
E914-47DA-95CA-C5AB0DC85B11" but ignoring any leading and
trailing whitespace, the client MUST _Fail the WebSocket
Connection_.

5.  If the response includes a |Sec-WebSocket-Extensions| header
field and this header field indicates the use of an extension
that was not present in the client's handshake (the server has
indicated an extension not requested by the client), the client
MUST _Fail the WebSocket Connection_. (The parsing of this
header field to determine which extensions are requested is
discussed in
 Section 9.1.)

With those "MUST Fail" conditions in mind, I came up with the follow set of replacement rules which should fail on all five.

Once those rules were in, all WebSocket upgrade requests failed. Since socket.io will silently fail to HTTP by default this has the desired effect. Specific implementations or other libraries may behave differently and cause errors in the application you are testing. But our jobs are to make software do things it wasn't meant to!

The original response looked like this and would have resulted in the client and server transitioning to WebSockets for communication.

Instead, the client received this modified response from the server and by the RFC should fail the WebSockets attempt.

One thing I encountered during a test was that after putting these match and replace rules in, the client was extraordinarily persistent in retrying WebSockets connections and caused a lot of unwanted traffic in my HTTP history. If you are dealing with the socket.io library, it is probably easiest to use Method 1 above. If you have a different library or situation you may have to add more rules to convince the client that the server does not support WebSockets or even cripple the WebSockets functionality in the client library.

Using Burp Repeater as a Socket.io Client

Since we've forced communication to go over HTTP instead of WebSockets you can now add in custom match and replace rules that will apply to the traffic that would have gone over WebSockets!

Next, we can go one step further and pave the way for using tools like Repeater, Intruder, and Scanner. These changes will be specific to the socket.io library.

There are a couple of problems that prevent us from repeating the HTTP requests that socket.io uses.

  1. Each request has a session number and any invalid requests will cause the server to terminate that session.
  2. The body of each request has a calculated field for the length of the message.  If this is incorrect, the server treats it as an invalid request and terminates the session.

Here are a couple of example URLs used in the application.

/socket.io/?EIO=3&transport=polling&t=MJJR2dr

/socket.io/?EIO=3&transport=polling&t=MJJZbUa&sid=iUTykeQQumxFJgEJAABL

The "sid" parameter in the URL represented a single connection stream to the server. If an invalid message was sent (as is common when trying to break things) then the server would close the entire session and I had to start over with a new session.

The body of a given request contained a field with the byte count of the payload. This is similar to the "Content-Length" HTTP header except it was specific to the socket.io payload. For instance, if the payload you wanted to send was "hello" then the body would be "5:hello" and the Content-Length header would be 7. That's 5 for the letters in "hello" and 7 accounts for both the letters in "hello" as well as the "5:" which socket.io adds to the body. As always, Burp will update the Content-Length header for us so we don't need to worry about that. But I could not find a good way to automatically calculate and include the length of the payload. To complicate matters more, I witnessed socket.io sending multiple messages within the same HTTP request. Since each was an encapsulated WebSockets payload, each had its own length and ended up looking something like this: "5:hello,4:john,3:doe" (the actual syntax may have been different but you get the idea). Any error in calculating the length and the server would reject it as an invalid message and bring us back to problem #1.

This is an example of a message body. This is from a response in the Juice-Shop app but the requests were formatted the same. Note that "215" here represents the length of the payload following the ":".

215:42["challenge solved",{"key":"zeroStarsChallenge","name":"Zero Stars","challenge":"Zero Stars (Give a devastating zero-star feedback to the store.)","flag":"e958569c4a12e3b97f38bd05cac3f0e5a1b17142″,"hidden":false}]

Macro

I was able to solve the first problem using a Burp Macro. Basically, each time Burp matched on a server rejection of a message, the macro would automatically establish a new session and update the original request with the valid "sid". Create a new macro by going to Project options->Sessions->Macros->Add

The URL to establish a new session was simply crafted by leaving off the "sid" parameter.  For instance:

/socket.io/?EIO=3&transport=polling&t=MJJJ4Ku

I found that the value of "t" didn't really matter so I left it untouched.

The server response included a brand new "sid" value for us to use.

Next, click the "Configure item" button and fill in the parameter name as "sid".  Use the "Extract from regex group" option and the following regex.

"sid"\:"(.*?)"

Your configuration window should look something like this:

Session Handling Rule

Now that we have a macro, we need a way for it to be triggered. This is where Burp Session Handling Rules come in. Create a new rule by going to Project options->Sessions->Session Handling Rules->Add

Create a new Rule Action for "Check session is valid"

Configure the new rule action as follows:

Finally, after finishing your new rule action, modify the scope of the rule. Here is where you can decide where you want this rule to apply. I'd recommend using it for Repeater at least so you can manually repeat requests.

The following is how I configured the scope rules. You can get more specific with your scope but the options below should work for most.

Here is a request made without the session handling rule in place.

And here is the same request made with the rule in place. Notice that the session handling rule transparently updates the cookies and the value for "sid" in the request for you.

Final Thoughts

Ultimately, I was prevented from using Burp Scanner and Intruder by problem #2 discussed above. I modified an existing Burp plugin and that appeared to do the job, but the server didn't like it for some reason. If anyone is interested in furthering this research feel free to reach out to me.

Related

Pentesting ASP.NET Cookieless Sessions with Burp

Carrie Roberts & Brian King // We were recently testing a web application that used ASP.NET cookieless sessions. This meant that the session token was part of the URL as shown in the example below. http://www.blackhillsinfosec.com/(S(hd73kdjf780sndyfn23elomzqd5ghwa))/login.html In this case, the session token is of the form (S(LongRandomToken), where LongRandomToken is…

January 4, 2016

In "Red Team"



Elyssa D. Durant 
Research & Policy Analyst
Columbia University, New York

Wednesday, October 3, 2018

10/3/2018

M2018-10-03 17:05:02:382 Unable to register Device for Push Notifications: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:01:868 WPAnalytics session started
2018-10-03 19:44:01:884 ===========================================================================
2018-10-03 19:44:01:884 Launching WordPress for iOS 10.9 (10.9.0.1)...
2018-10-03 19:44:01:884 Crash count: 25
2018-10-03 19:44:01:884 Debug mode: Production
2018-10-03 19:44:01:884 Extra debug: YES
2018-10-03 19:44:01:886 Device model: iPhone9,1 (iPhone9,1)
2018-10-03 19:44:01:886 OS: iOS, 11.4.1
2018-10-03 19:44:01:886 Language: en-US
2018-10-03 19:44:01:886 UDID: 97AF4A9C-5056-4367-BBFC-5C598FA6E5D5
2018-10-03 19:44:01:888 APN token: 4d5649ecd7a9acff32855f0fb6c70f7ec426b4e0efc84069d471291921dd93bf
2018-10-03 19:44:01:888 Launch options: [:]
2018-10-03 19:44:01:890 wp.com account: powersthatbeat (ID: 18647202) (verified)
2018-10-03 19:44:01:891 All blogs on device:
2018-10-03 19:44:01:896 <Blog Name: Comcast Must Die URL: https://comcastmustdie.wordpress.com XML-RPC: https://comcastmustdie.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 148364682 plan: Free (1)>
2018-10-03 19:44:01:896 <Blog Name: Just me, e... URL: https://elyssadblog.wordpress.com XML-RPC: https://elyssadblog.wordpress.com/xmlrpc.php wp.com account: ch1llyw1lly blogId: 108242590 plan: (null) ((null))>
2018-10-03 19:44:01:897 <Blog Name: PALM BITCH URL: https://palmbitchresist.wordpress.com XML-RPC: https://palmbitchresist.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 126298627 plan: Free (1)>
2018-10-03 19:44:01:897 <Blog Name: Powers That Beat ©️ 2018 URL: https://powersthatbeat.wordpress.com XML-RPC: https://powersthatbeat.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 18033618 plan: Free (1)>
2018-10-03 19:44:01:897 <Blog Name: TOS Terms of Silence URL: https://tosthegoodthebadtheugly.wordpress.com XML-RPC: https://tosthegoodthebadtheugly.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 126146545 plan: Free (1)>
2018-10-03 19:44:01:897 ===========================================================================
2018-10-03 19:44:01:936 Zendesk - read profile from User Defaults: ["name": Chillieh Penguin, "email": powersthatbeat@gmail.com]
2018-10-03 19:44:01:938 Zendesk Enabled: true
2018-10-03 19:44:01:940 User-Agent set to: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15G77 wp-iphone/10.9
2018-10-03 19:44:02:188 Loading Stats for the following blog: https://powersthatbeat.wordpress.com
2018-10-03 19:44:02:233 Loading Stats for the following blog: https://powersthatbeat.wordpress.com
2018-10-03 19:44:02:653 🔵 Tracked: notifications_notification_details_opened, properties: {
"notification_type" = comment;
}
2018-10-03 19:44:02:845 🔵 Tracked: my_site_tab_accessed
2018-10-03 19:44:03:458 🔵 Tracked: notifications_accessed
2018-10-03 19:44:03:570 didFinishLaunchingWithOptions state: 2
2018-10-03 19:44:03:867 Could not sync sites: Optional(Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.})
2018-10-03 19:44:03:868 Error syncing menu: Optional(Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.})
2018-10-03 19:44:03:869 Error refreshing settings (unrecoverable): Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:890 Failed syncing site details for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:890 Failed syncing post formats for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:891 Failed syncing categories for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:891 Failed syncing settings for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:891 Failed checking muti-author status for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:891 Failed syncing publicize connections for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:894 Error while Updating Last Seen Timestamp: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 19:44:03:901 Device Token received in didRegisterForRemoteNotificationsWithDeviceToken: 4d5649ecd7a9acff32855f0fb6c70f7ec426b4e0efc84069d471291921dd93bf
2018-10-03 19:51:56:199 Unable to register Device for Push Notifications: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:37:683 WPAnalytics session started
2018-10-03 20:58:37:696 ===========================================================================
2018-10-03 20:58:37:696 Launching WordPress for iOS 10.9 (10.9.0.1)...
2018-10-03 20:58:37:697 Crash count: 25
2018-10-03 20:58:37:697 Debug mode: Production
2018-10-03 20:58:37:697 Extra debug: YES
2018-10-03 20:58:37:698 Device model: iPhone9,1 (iPhone9,1)
2018-10-03 20:58:37:698 OS: iOS, 11.4.1
2018-10-03 20:58:37:698 Language: en-US
2018-10-03 20:58:37:698 UDID: 97AF4A9C-5056-4367-BBFC-5C598FA6E5D5
2018-10-03 20:58:37:699 APN token: 4d5649ecd7a9acff32855f0fb6c70f7ec426b4e0efc84069d471291921dd93bf
2018-10-03 20:58:37:700 Launch options: [:]
2018-10-03 20:58:37:701 wp.com account: powersthatbeat (ID: 18647202) (verified)
2018-10-03 20:58:37:702 All blogs on device:
2018-10-03 20:58:37:706 <Blog Name: Comcast Must Die URL: https://comcastmustdie.wordpress.com XML-RPC: https://comcastmustdie.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 148364682 plan: Free (1)>
2018-10-03 20:58:37:706 <Blog Name: Just me, e... URL: https://elyssadblog.wordpress.com XML-RPC: https://elyssadblog.wordpress.com/xmlrpc.php wp.com account: ch1llyw1lly blogId: 108242590 plan: (null) ((null))>
2018-10-03 20:58:37:706 <Blog Name: PALM BITCH URL: https://palmbitchresist.wordpress.com XML-RPC: https://palmbitchresist.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 126298627 plan: Free (1)>
2018-10-03 20:58:37:706 <Blog Name: Powers That Beat ©️ 2018 URL: https://powersthatbeat.wordpress.com XML-RPC: https://powersthatbeat.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 18033618 plan: Free (1)>
2018-10-03 20:58:37:707 <Blog Name: TOS Terms of Silence URL: https://tosthegoodthebadtheugly.wordpress.com XML-RPC: https://tosthegoodthebadtheugly.wordpress.com/xmlrpc.php wp.com account: powersthatbeat blogId: 126146545 plan: Free (1)>
2018-10-03 20:58:37:707 ===========================================================================
2018-10-03 20:58:37:765 Zendesk - read profile from User Defaults: ["name": Chillieh Penguin, "email": powersthatbeat@gmail.com]
2018-10-03 20:58:37:768 Zendesk Enabled: true
2018-10-03 20:58:37:771 User-Agent set to: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15G77 wp-iphone/10.9
2018-10-03 20:58:37:995 Loading Stats for the following blog: https://powersthatbeat.wordpress.com
2018-10-03 20:58:38:025 Loading Stats for the following blog: https://powersthatbeat.wordpress.com
2018-10-03 20:58:38:342 🔵 Tracked: notifications_notification_details_opened, properties: {
"notification_type" = comment;
}
2018-10-03 20:58:38:651 🔵 Tracked: my_site_tab_accessed
2018-10-03 20:58:39:186 🔵 Tracked: notifications_accessed
2018-10-03 20:58:39:353 didFinishLaunchingWithOptions state: 1
2018-10-03 20:58:39:375 PingHub connecting
2018-10-03 20:58:39:696 Error syncing menu: Optional(Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.})
2018-10-03 20:58:39:697 Could not sync sites: Optional(Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.})
2018-10-03 20:58:39:697 Error refreshing settings (unrecoverable): Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:742 Failed syncing post formats for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:743 Failed syncing settings for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:749 Failed syncing site details for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:750 Failed syncing categories for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:751 Failed syncing publicize connections for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:752 Failed checking muti-author status for blog https://powersthatbeat.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:757 Error while Updating Last Seen Timestamp: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:39:769 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 20:58:39:780 Device Token received in didRegisterForRemoteNotificationsWithDeviceToken: 4d5649ecd7a9acff32855f0fb6c70f7ec426b4e0efc84069d471291921dd93bf
2018-10-03 20:58:39:884 <WordPressAppDelegate: 0x1c00d92f0> applicationDidBecomeActive:
2018-10-03 20:58:39:890 🔵 Tracked: application_opened
2018-10-03 20:58:39:953 Unable to register Device for Push Notifications: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:40:027 Error while Updating Last Seen Timestamp: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:58:40:829 PingHub connecting
2018-10-03 20:58:41:005 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 20:58:43:144 PingHub connecting
2018-10-03 20:58:43:309 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 20:58:48:734 PingHub connecting
2018-10-03 20:58:48:910 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 20:58:55:161 TracksService sendQueuedEvents completed. Sent 11 events.
2018-10-03 20:59:04:699 Pushing Notification Details for: [3499409028]
2018-10-03 20:59:04:699 🔵 Tracked: notifications_notification_details_opened, properties: {
"notification_type" = like;
}
2018-10-03 20:59:05:364 PingHub connecting
2018-10-03 20:59:05:545 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 20:59:07:987 🔵 Tracked: my_site_tab_accessed
2018-10-03 20:59:08:798 <BlogService: 0x1c4203610> syncBlogsForAccount:success:failure:
2018-10-03 20:59:09:010 Error syncing blogs: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:59:10:728 TracksService sendQueuedEvents completed. Sent 2 events.
2018-10-03 20:59:11:116 Failed syncing settings for blog https://palmbitchresist.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:59:11:117 Failed syncing publicize connections for blog https://palmbitchresist.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:59:11:117 Failed syncing site details for blog https://palmbitchresist.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:59:11:117 Failed syncing categories for blog https://palmbitchresist.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:59:11:118 Failed syncing post formats for blog https://palmbitchresist.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:59:11:118 Failed checking muti-author status for blog https://palmbitchresist.wordpress.com: Error Domain=WordPressKit.WordPressComRestApiError Code=1 "The OAuth2 token is invalid." UserInfo={WordPressComRestApiErrorCodeKey=invalid_token, WordPressComRestApiErrorMessageKey=The OAuth2 token is invalid., NSLocalizedDescription=The OAuth2 token is invalid.}
2018-10-03 20:59:26:397 🔵 Tracked: site_menu_opened, properties: {
"blog_id" = 126298627;
"menu_item" = plans;
}
2018-10-03 20:59:30:069 🔵 Tracked: support_opened
2018-10-03 20:59:30:082 Zendesk - read profile from User Defaults: ["name": Chillieh Penguin, "email": powersthatbeat@gmail.com]
2018-10-03 20:59:30:097 Zendesk - read profile from User Defaults: ["name": Chillieh Penguin, "email": powersthatbeat@gmail.com]
2018-10-03 20:59:38:338 PingHub connecting
2018-10-03 20:59:38:511 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 20:59:40:864 TracksService sendQueuedEvents completed. Sent 2 events.
2018-10-03 20:59:57:320 [Rest API] ! The specified path was not found. Please visit https://developer.wordpress.com/docs/ for valid paths.
2018-10-03 21:00:08:746 PingHub connecting
2018-10-03 21:00:08:932 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:00:39:794 PingHub connecting
2018-10-03 21:00:39:995 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:01:11:709 PingHub connecting
2018-10-03 21:01:11:894 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:01:44:725 PingHub connecting
2018-10-03 21:01:44:943 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:02:17:705 PingHub connecting
2018-10-03 21:02:17:888 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:02:50:681 PingHub connecting
2018-10-03 21:02:50:852 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:03:23:753 PingHub connecting
2018-10-03 21:03:23:954 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:03:54:213 PingHub connecting
2018-10-03 21:03:54:397 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:04:27:392 PingHub connecting
2018-10-03 21:04:27:590 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:05:00:501 PingHub connecting
2018-10-03 21:05:00:694 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:05:33:671 PingHub connecting
2018-10-03 21:05:33:854 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:06:06:837 PingHub connecting
2018-10-03 21:06:07:001 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:06:37:107 PingHub connecting
2018-10-03 21:06:37:405 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:07:10:343 PingHub connecting
2018-10-03 21:07:10:557 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:07:43:489 PingHub connecting
2018-10-03 21:07:43:669 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:08:16:669 PingHub connecting
2018-10-03 21:08:16:855 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:08:48:792 PingHub connecting
2018-10-03 21:08:48:959 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:09:20:870 PingHub connecting
2018-10-03 21:09:21:056 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:09:53:791 PingHub connecting
2018-10-03 21:09:53:974 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:10:25:808 PingHub connecting
2018-10-03 21:10:25:979 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:10:36:171 <WordPressAppDelegate: 0x1c00d92f0> applicationWillResignActive:
2018-10-03 21:10:37:055 <WordPressAppDelegate: 0x1c00d92f0> applicationDidEnterBackground:
2018-10-03 21:10:37:073 🔵 Tracked: application_closed, properties: {
"last_visible_screen" = "Blog List";
"time_in_app" = 717;
}
2018-10-03 21:10:46:077 <WordPressAppDelegate: 0x1c00d92f0> applicationWillEnterForeground:
2018-10-03 21:10:46:081 PingHub connecting
2018-10-03 21:10:46:279 PingHub disconnected: WSError(type: Starscream.ErrorType.upgradeError, message: "Invalid HTTP upgrade", code: 403)
2018-10-03 21:10:46:772 <WordPressAppDelegate: 0x1c00d92f0> applicationDidBecomeActive:
2018-10-03 21:10:46:821 🔵 Tracked: application_opened


Elyssa D. Durant
Research & Policy Analyst
Columbia University, New York