Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

25 Jul 2014

26 Questions EU Regulators Want Google to Answer




By Sam Schechner at WSJ:

PARIS—European Union privacy watchdogs grilled Google Inc. and other search engines for two hours on Thursday on how they are implementing the bloc’s new “right to be forgotten” online–and then gave them homework to do by next week, too.

The main body that joins together the EU’s national data-protection regulators called the Brussels meeting with Google, Microsoft Corp and Yahoo Inc. amid rising discontent from some regulators over elements of Google’s application of the surprise May court decision that gives Europeans the right to ask for the removal of links from search results for their names in some cases.

Regulators  touched on some hot-button issues in six oral questions and another 26 written ones, with answers due by next Thursday. They asked Google to describe the “legal basis” of its decision to notify publishers when it approves right-to-be-forgotten requests, something that has led to requesters’ being publicly identified in some cases. They also asked search engines to explain where they take down the results, after complaints from some regulators that Google does not filter results on google.com. That means that anyone in Europe can switch from, say, google.co.uk to Google.com to see any removed links.

In response to another question, Google told regulators Thursday that it has been removing just over 50% of the items that people have asked to be unlinked from searches for their names, while rejecting just over 30% of requests, and asking for more information on 15%.

But for the most part, data protection officials avoided a more in-depth, controversial discussion during Thursday’s meeting, saving the tough decisions and orders for a set of guidelines the regulators aim to publish in late September or early October, attendees said.

“We didn’t tell the search engines to do anything. We were gathering information,” said Isabelle Falque-Pierrotin, head of France’s data-protection authority, and chairman of the pan-European group of authorities.  “The goal was to help inform our decision on the guidelines.”

Read the full list of questions here, as provided by France’s data-protection authority:


Questions asked during the meeting

1. What information do you request from a data subject prior to considering a delisting request e.g. URLs, justification? Do you ask further motivation from the data subjects to substantiate their request?
2. Do you filter out some requests based on the location, nationality, or place of residence of the data subject? If so, what is the legal basis for excluding such requests?
3. Do you delist results displayed following a search:
a. Only on EU / EEA domains?
b. On all domains pages accessible from the EU / EEA or by EU/EEA residents?
c. On all domains on a global basis?
4. What criteria do you use to balance your economic interest and/or the interest of the general public in having access to that information versus the right of the data subject to have search results delisted?
5. What explanations / grounds do you provide to data subjects to justify a refusal to delist certain URLs?
6. Do you notify website publishers of delisting? In that case, which legal basis do you have to notify website publishers?


Additional questions to be answered in writing by July 31

7. Do you provide proper information about the delisting process on an easily accessible webpage? Have you developed a help center explaining how to submit a delisting claim?
8. Can data subjects request delisting only using the electronic form that you provide, or can other means be used?
9. Can data subjects request delisting in their own language?
10. If you filter out some requests based on the location, nationality, or place of residence, what kind of information must be provided by the data subject in order to prove his nationality and / or place of residence?
11. Do you ask for a proof of identify or some other form of authentication and if yes, what kind? For what reason? What safeguards do you put in place to protect any personal data that you process for the purpose of processing delisting requests?
12. Do you accept general claims for delisting (e.g. delist all search results linking to a news report)?
13. When you decide to accept a delisting request, what information do you actually delist? Do you ever permanently delist hyperlinks in response to a removal request, as opposed to delisting?
14. Do you delist search results based only on the name of the data subject or also in combination of the name with another search term (i.e. Costeja and La Vanguardia)
15. How do you treat removal requests with regard to hyperlinks to pages that do not (no longer) contain the name of the data subject? [Examples: hyperlink to anonymised ruling, hyperlink to page where name of data subject was removed]. Do you immediately recrawl the sites after a removal request?
16. Does your company refuse requests when the data subject was the author of the information he/she posted himself/herself on the web? If so, what is the basis for refusing such requests?
17. Do you have any automated process defining if a request is accepted or refused?
18. What technical solution do you use to ensure that links to material to which a removal agreement applies are not shown in the search results?
19. Which of your services do you consider delisting requests to be relevant to?
20. Do you notify users through the search results’ page information that some results have been removed according to EU law? In that case, which is the legal basis for this? What is the exact policy? In particular, it appears that this notice is sometimes displayed even in the absence of removal requests by data subjects. Can you confirm or exclude that this is actually the case and, if so, could you elaborate on the applicable criteria?
21. Have you considered sharing delisted search results with other search engines providers?
22. What is the average time to process the requests?
23. What statistics can you share at this stage (percentage of requests accepted / partially accepted / refused)? How many have you answered in total? How many per day?
24. Will you create a database of all removal requests or removal agreements?
25. What particular problems have you faced when implementing the Court’s ruling? Are there particular categories of requests that pose specific problems?
26. Could you please provide us with contact details in case we need to exchange on a specific case?

Lisa Fleischer contributed to this article. 

21 May 2014

eBay Suffers Cyberattack, Requests That All Users Change Passwords



By Ben Woods at The Next Web


Ebay will begin the process of asking its entire user base to change their passwords due to hackers gaining access to a database containing encrypted passwords and other non-financial data.

The company detailed the decision in an announcement today, adding that while there was “no evidence of the compromise resulting in unauthorized activity for eBay users”, it’s “best practice” to request that all users change their passwords.

eBay confirmed that credit card information is stored separately in encrypted formats, and as such wasn’t revealed during the intrusion.

“Information security and customer data protection are of paramount importance to eBay Inc., and eBay regrets any inconvenience or concern that this password reset may cause our customers,” the company said.

As it turns out, the breach occurred between late February and early March, and left customers’ names, encrypted passwords, email addresses, their physical address, phone number and date of birth exposed.

The attackers managed to gain access to the server holding the information by compromising “a small number” of employee log-ins, which then allowed access to eBay’s corporate network.

eBay reassured that it has seen “no evidence of unauthorized access or compromises to personal or financial information for PayPal users” either.

Starting today, it’ll start telling customers to reset their passwords via email, on-site messages and other channels, but there’s really no time like the present.

16 Apr 2014

Because of Heartbleed You Need To Change All These Passwords




By Zach Epstein at BGR:  


By now, we all know what a huge deal Heartbleed is. The massive vulnerability in OpenSSL protocol impacted 66% of all sites on the Internet at the time of its discovery, and now companies are scrambling to fix the issue. Most big companies seem to have done a pretty good job of acting quickly, but this bug is several years old so users have been at risk for quite some time regardless of how quickly a site might have patched the flaw. As such, the cybersecurity experts at LWG Consulting have compiled a great list of all the huge sites that were impacted by Heartbleed.

Do you have accounts on any of the sites listed below? Change your password immediately — and be sure to change your passwords on any other sites if you use the same password there.






24 Mar 2014

Apple, Google And Yahoo Also Can Read Your Emails



By Zach Epstein at BGR:


People concerned with online privacy had a field day last week when it was discovered that Microsoft accessed a French blogger’s Hotmail account and read his emails in order to assess his involvement with an alleged theft of Windows trade secrets. As numerous reports pointed out, Microsoft’s Hotmail and Outlook.com terms give the company the right to access and read users’ emails, and bloggers lashed out at Microsoft as a result. As it turns out, however, Microsoft isn’t the only tech giant that reserves the right to read your private correspondence.

Alex Hern at The Guardian took the time to actually read the terms we all agree to when we sign up for the various email services offered by big tech companies. Not surprisingly, he found that Apple, Google and Yahoo each include items in their terms of service that give them the right to access and read users’ emails.

As Hern noted, Google’s terms for Gmail require users to ”acknowledge and agree that Google may access… your account information and any Content associated with that account… in a good faith belief that such access… is reasonably necessary to… protect against imminent harm to the… property… of Google.”

Similarly, regarding iCloud email Apple’s terms say that it ”may, without liability to you, access… your Account information and Content… if we have a good faith belief that such access… is reasonably necessary to… protect the… property… of Apple,” Hern noted, adding that Yahoo mail can also be accessed by Yahoo according to the service’s terms.



Read the full story >>



Obama Meets Facebook & Google Bosses to Discuss NSA



By Malarie Gokey at TechTimes:

President Barack Obama met with leading tech industry executives once again on Friday to discuss reforming the government's system of Internet surveillance. Facebook CEO Mark Zuckerberg took the lead, demanding that the NSA be stopped, one way or the other.

Google Executive Chairman Eric Schmidt, Facebook Chief Executive Mark Zuckerberg, Netflix Chief Executive Reed Hastings, Box Chief Executive Aaron Levie and Palantir Technologies Inc. Chief Executive Alexander Karp all attended the meeting.

Obama sought to reassure the country's leading tech executives that the federal government is taking their recommendations seriously and plans to explore ways to improve the program. In January, Obama passed a few reforms, which limited NSA spying on diplomats and other foreign dignitaries, but kept most of the program intact.

The most controversial and intrusive form of surveillance, the collection and storage of metadata from millions of Americans, still exists. Next week, this mass collection of metadata is up for re-authorization. Internet rights activists like Edward Snowden, who exposed the program last year, as well as the majority of tech executives, demand that this part of the program be terminated.

Tech leaders remain doubtful that meaningful reform to NSA surveillance will be passed any time soon. For its part, the White House declared that it will ensure that the program is thoroughly reviewed and reformed.

"The president reiterated his administration's commitment to taking steps that can give people greater confidence that their rights are being protected while preserving important tools that keep us safe," the White House said after the meeting.




Read the full story >>
http://www.techtimes.com/articles/4659/20140323/obama-meets-facebook-and-google-ceos-to-discuss-nsa-zuckerberg-presses-for-answers.htm



23 Mar 2014

Documents Show the NSA Spied on China's Huawei



By Jon Russel at The Next Web:

The New York Times and German newspaper Spiegel Online have reported the existence of a document that purports to show the US government spying on Chinese tech company Huawei, the world’s second largest supplier of networking products, since at least 2009.

The revelation is laced with irony because Huawei has long been labelled a national security risk by US politicians. Alongside fellow Chinese firm ZTE, Huawei has been the subject of multiple reports over alleged relationships with China’s army, and questions of whether its networking products could leave US organizations open to hacking from China if they were deployed on US soil.

The answer seems to be yes, according to the reports, which claim that the NSA — working in tandem with the FBI and White House — got its hands on the Chinese company’s source code, aka “the holy grail of computer companies,” as Spiegel Online puts it. That, it is said, allowed US officials to spy on emails sent across the Huawei network from January 2009 onward: targets included China-based organizations and Huawei customers in countries like Iran, Afghanistan and Pakistan.




Read the full story >>



22 Mar 2014

Microsoft Just Exposed Email's Ugliest Secret



By Russell Brandom at The Verge

If you're hiding something from Microsoft, you'd better not put it on Hotmail.

It came out yesterday that the company had read through a user's inbox as part of an internal leak investigation. Microsoft has spent today in damage-control mode, changing its internal policies and rushing to point out that they could have gotten a warrant if they’d needed one. By all indications, the fallout is just beginning.

But while Microsoft is certainly having a bad week, the problem is much bigger than any single company. For the vast majority of people, our email system is based on third-party access, whether it's Microsoft, Google, Apple or whoever else you decide to trust. Our data is held on their servers, routed by their protocols, and they hold the keys to any encryption that protects it. The deal works because they're providing important services, paying our server bills, and for the most part, we trust them. But this week's Microsoft news has chipped away at that trust, and for many, it's made us realize just how frightening the system is without it.



Read the full story >>



20 Mar 2014

Hacked Invoices Show How Much Microsoft Charges the FBI



By Valentina Palladino at The Verge:

The Syrian Electronic Army recently revealed documents that show how much Microsoft charges a secret FBI division to legally collect and view customer information. The SEA, which is known for hacking Western companies and their social media accounts, allowed The Daily Dot to analyze the emails and invoices documenting months of transactions between Microsoft's Global Criminal Compliance team and the FBI's Digital Intercept Technology Unit (DITU) before the group went public with them.

Each time the DITU requested customer information, Microsoft charged anywhere from $50 to $200 for the transaction. Monthly totals reached in the hundreds of thousands of dollars, with the most recent invoice for November 2013 totaling $281,000. Neither Microsoft or the DITU would confirm the validity of the documents, but a specialist told The Daily Dot that he saw no indication that the documents were fake.

It's no secret that Microsoft and companies like it can legally charge for information requests from the government, and the company told The Verge that this is standard procedure. "Regarding law enforcement requests, there’s nothing unusual here," a Microsoft spokesperson said in an email. "Under US law, companies can seek reimbursement for costs associated with complying with valid legal orders for customer data. We attempt to recover some of the costs associated with any such orders."

These documents show how frequently the government calls on tech companies for information, and how nonchalantly they do business. The DITU allegedly requested information from Microsoft hundreds of times a month, and it appears that the government can buy customer information by simply shooting the right person an email.



Read the full story >>
http://www.theverge.com/2014/3/20/5530630/hacked-invoices-show-how-much-microsoft-charges-the-fbi-for-customer-information


17 Mar 2014

NATO Websites Hit In Cyber Attack



By Adrian Croft at Business Insider:

(Reuters) - Hackers brought down several public NATO websites, the alliance said on Sunday, in what appeared to be the latest escalation in cyberspace over growing tensions over Crimea.

The Western military alliance's spokeswoman, Oana Lungescu, said on social networking site Twitter that cyber attacks, which began on Saturday evening, continued on Sunday, although most services had now been restored.

"It doesn't impede our ability to command and control our forces. At no time was there any risk to our classified networks," another NATO official said.

NATO's main public website (www.nato.int), which carried a statement by Secretary-General Anders Fogh Rasmussen saying that Sunday's referendum on Crimea's status would violate international law and lack legitimacy, worked intermittently.

The so-called "distributed denial of service" (DDoS) attack, in which hackers bombard websites with requests causing them to slow down or crash, also hit the site of a NATO-affiliated cyber security center in Estonia. NATO's unclassified e-mail network was also affected.

A group calling itself "cyber berkut" said the attack had been carried out by patriotic Ukrainians angry over what they saw as NATO interference in their country.

The claim, made at www.cyber-berkut.org, could not be independently verified. "Berkut" is a reference to the feared and since disbanded riot squads used by the government of ousted pro-Russian Ukrainian President Viktor Yanukovich.

Cyber warfare expert Jeffrey Carr, in a blog on the attacks, described cyber berkut as staunch supporters of Yanukovich and a "pro-Russia hacktivist group working against Ukrainian independence".

Lungescu noted the statement by "a group of hacktivists" but said that, due to the complexities involved in attributing the attacks, NATO would not speculate about who was responsible or their motives.



Read the full story >>
http://www.businessinsider.com/r-nato-websites-hit-in-cyber-attack-linked-to-crimea-tension-2014-16


22 Feb 2014

iPhone Owners: Download The Patch Before Your Emails Get Hacked



A major flaw in Apple Inc software for mobile devices could allow hackers to intercept email and other communications that are meant to be encrypted, the company said on Friday, and experts said Mac computers were even more exposed.

If attackers have access to a mobile user's network, such as by sharing the same unsecured wireless service offered by a restaurant, they could see or alter exchanges between the user and protected sites such as Gmail and Facebook. Governments with access to telecom carrier data could do the same.

"It's as bad as you could imagine, that's all I can say," said Johns Hopkins University cryptography professor Matthew Green.

Apple did not say when or how it learned about the flaw in the way iOS handles sessions in what are known as secure sockets layer or transport layer security, nor did it say whether the flaw was being exploited.

Apple released software patches and an update for the current version of iOS for iPhone 4 and later, 5th-generation iPod touches, and iPad 2 and later.

Without the fix, a hacker could impersonate a protected site and sit in the middle as email or financial data goes between the user and the real site, Green said.

After analyzing the patch, several security researchers said the same flaw existed in current versions of Mac OSX, running Apple laptop and desktop computers. No patch is available yet for that operating system, though one is expected soon.



Read the full story >>
http://www.huffingtonpost.com/2014/02/21/apple-security-flaw_n_4835870.html?utm_hp_ref=technology



16 Dec 2013

3 Things You Need to Know About Facebook Privacy



By Maggie McGary at Social Media Today

If you’ve read this blog for a while, you know I used to be kind of obsessed with Facebook’s privacy fails. I frequently wrote posts detailing every one of Facebook’s “oops” pretend privacy slips (sorry for all the links--I’ll digress but I’m not exaggerating when I say I was obsessed). Then, just as Facebook wanted for everyone in the world, I just got over it. I stopped caring. Or, rather, I gave up any illusion that anything I or anyone else posts or does on Facebook is private and continued using it anyway because it’s convenient.

And I’m still using it. But three things I’ve read lately have reminded me that benign trust in Facebook can be dangerous. If you use Facebook, you really need to read these three posts to know just what you’re giving up in terms of privacy.

Danny Brown’s post about how, just by installing the Android version of the Facebook Messenger app, you are granting the app permission to automatically call numbers in your phone book, as well as to send SMS messages, record audio and pictures with your camera, all without your knowledge.

This Slate article about how Facebook actually saves and keeps even the status updates you don’t post. You know, like when you start typing something then decide it’s too personal or too offensive or too something, then think the better of it and don’t post it after all? Yeah, those posts. Facebook saves them and analyzes them to learn about what makes people self-censor. And, knowing Facebook, they’ll figure out a way to monetize that data at some point.

This Salon article about how Facebook can--and does--take private messages between users and make them public. It happened to the author recently--a private message from 2006 appeared on her public timeline recently. As the article points out, this isn’t the first time Facebook has had this particular “oops”--the same thing happened last year.

I need to take my own advice and take these things to heart because, while I don’t share stuff on Facebook that I wouldn’t share publicly, I do occasionally start typing something then think the better of it and not post on occasion--I need to stop doing this-- and I do participate in private Facebook groups--again, something I need to reconsider. And if you or your kids are thinking that Instagram’s new direct message feature is just the thing for your private messaging needs, just remember--Facebook owns Instagram. Just what the world needs: a bunch of Snapchat-like personal photos and videos becoming publicly accessible. But I’d be willing to bet a million dollars that’s exactly what will happen eventually, probably sooner rather than later.



Read the full story >>


5 Sept 2013

Why No One Is Surprised By Facebook, Twitter And Google Spying



The news that the top social networks have been spying on their users is . . . well, it’s not really news, is it?
Out of the fifty social networks tested in a recent experiment by High-Tech Bridge, six were found to be trawling links sent in private messages and emails.
Two of those caught were link-shortening services, so I guess we can let them off — that’s how they operate.
But for Facebook, Twitter, Google and Formspring, there really is no excuse. And there’s really no reason to be surprised. We all know they’ve been doing it.
There have been tailored ads showing up in Gmail’s margins since forever, and Facebook has got more dirt on you than your best friend. And Twitter — well, if everybody else is doing it, why shouldn’t they?
It’s possible that there’s an unspoken safety-in-numbers thing going on here. People won’t stop using Facebook, Twitter and Google unless something better comes along, and without a privacy-respecting alternative around, the networks can more-or-less do as they please.
It’s not like anyone reads the privacy policies anyway — to most people, they’re unreadable. Take Google’s, for example:
We provide personal information to our affiliates or other trusted businesses or persons to process it for us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures.
What do they even mean by “process”? And what information are they talking about? Who are these affiliates, anyway?
And Google aren’t the only ones with a privacy policy that’s intentionally vague.
Twitter tells you how it uses your data for tailored ads, and explains how to opt out of said ads— but it doesn’t say it’ll stop reading your data. 
Facebook is no better, and is probably the creepiest of the three:
Your trust is important to us, which is why we don’t share information we receive about you with others unless we have [...] given you notice, such as by telling you about it in this policy
Because seriously, you can guarantee that most people will not have read it. Each network’s privacy policy would take at least half an hour to read — and because none of them are particularly clear anyway, you’d probably be no better off if you did.
Oh, and for anybody wondering, LinkedIn wasn’t found to be spying — but then, LinkedIn is the Goody Two-Shoes of social media anyway, so that’s no surprise, either.
I guess the only thing truly surprising here is that people are surprised!

1 Sept 2013

Malware Hijacks Facebook, Twitter, and Google+ Accounts via Chrome and Firefox Plugins


A new piece of malware that takes the form of fake extensions for Google Chrome and Mozilla Firefox which in turn hijack Facebook, Twitter, and Google+ accounts has been discovered. Users of these browsers and social networks are lured into downloading what they think is a video player update. To make matters worse, the threat is digitally-signed.
The malware, which was first discovered by security firm Trend Micro, is detected as TROJ_FEBUSER.AA. It installs a browser extension for Chrome and an add-on for Firefox, but doesn’t adapt itself to Internet Explorer, Safari, nor Opera.



2 Jun 2013

#Hootsuite Offers Twitter Security Alerts To Help Protect Your Accounts

Do you live in fear of the Syrian Electronic Army hacking your Twitter account? Or do you have a CEO with less than stellar social media skills? Or maybe you belong on our Twit List as someone who outsources “social” to interns and kinda deserve whatever public embarrassment you get.
But regardless of the scenario, a little Twitter security couldn’t hurt. For at the end of the day, even the most savvy social-ites are at risk.
And guess what? Hootsuite’s got yo’ back:
HootSuite now offers Security Services. It’s designed to head off your next social media crisis by preventing “account hackings and high-profile mis-tweets” and ensuring your “social assets are secure.”
It’s all about preventative measures these days, isn’t it?
Providing centralized control, alerts and crisis training, HootSuite Security Services are insurance for valuable social assets against both internal and external threats. Key components of the program include social media education, training, best practices and simulations along with innovative social media security tools and the highest level of support and account management available. 
And here’s more info on the Twitter Security Alerts:
Think this would help your business divert disaster? The preventative stuff is great, of course, but the real value is probably found in the simulated crisis trainings. Learn more about them here!
Do you have a social media crisis plan?

6 May 2013

#INFOGRAPHIC: How Facebook Graph Search Affects Your #Privacy

Facebook Graph Search is being rolled out to the masses and it’s important to be aware of the searchable content you post. Public information will come up in search queries and may prove problematic if you have content on Facebook that you don’t want the world to see. Our previous post detailed what Graph Search is and what it means for your business. The infographic below illustrates how Graph Search might affect you personally and how to customize your privacy settings to better control who sees the content you post. It only takes a few clicks and a bit of knowledge to ensure all your content is only shared with and searchable by the people you allow. The power is in your hands, so make good use of it. http://blog.marketo.com/blog/2013/05/how-facebook-graph-search-affects-your-privacy.html


23 Sept 2012

INFOGRAPHIC: Twitter, Facebook And Your Online Security

By Lauren Dugan at Media Bistro:
How safe are you when tweeting or posting a message to Facebook? You might think you’re protecting your privacy by logging out after every session, but, as this infographic shows, there are multiple aspects to keeping yourself safe and secure online.

For starters, you should never access Twitter or Facebook (or any other site that stores personal information) using an insecure connection – your URL should always start with “HTTPS://”. If you’re unsure of how to set up secure browsing on Twitter or Facebook, check out the links in the infographic.
And a big part of how safe you are online is your password. The author of this infographic recommends using a 12-character, random password – that is, don’t use dictionary words, names, or birthdates. It might be harder to remember, but it will keep you safer from hackers.
It’s also a good idea to double check which apps you’ve given permission to. Third-party apps on both Facebook and Twitter can access things like your full name, pictures, GPS location and more.

Secure and Hack your Facebook and Twitte (English)
Learn about infographics software.