Google Search

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, December 25, 2014

Google and Facebook under fire from Dutch government over citizens' privacy

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Image of Dutch citizen thumbs up courtesy of ShutterstockThe Dutch government is clamping down on the way in which large organisations use its citizen's personal data.

The Dutch Data Protection Authority (DPA) threatened Google with a fine of €15m (£11.9m, $18.7m) on Monday, saying the search giant had breached various provisions of the Dutch data protection act via a privacy policy it introduced in 2012.

The company has been given until the end of February 2015 to change how it handles personal data, especially in regard to the tailoring of adverts based on keyword search queries, video viewing habits, location data and the content of email messages.

Jacob Kohnstamm, chairman of the Dutch DPA, said:

Google catches us in an invisible web of our personal data without telling us and without asking us for our consent. This has been ongoing since 2012 and we hope our patience will no longer be tested.

Kohnstamm explained how, under Dutch law, Google should have informed users that it was gathering data across a number of platforms - such as YouTube and Gmail - and obtained permission before combining or analysing that data.

The regulator has now demanded that Google obtains "unambiguous" consent from users before combining their data, "via a separate consent screen", rather than through its more generalised privacy policy.

It also ordered the company to add clarification to the policy so that users are better informed as to how each of the company's services is using their data.

Furthermore, Google is required to make it clear that YouTube is part of its setup, though the DPA did note that this already appeared to be underway.

Five other regulators - in France, Germany, Italy, Spain and the UK - have recently received a letter from Google detailing how it intends to comply with European privacy laws but the Dutch DPA says it has yet to establish whether the proposals will suffice within its own jurisdiction.

While the DPA's gripe with Google awaits resolution, it has now moved onto fellow data gatherer Facebook.

In another statement (in Dutch - view Google translate version) released on Tuesday it announced it would investigate Facebook's new privacy policy.

The social network announced last month that it intends to make changes to its policy, effective from 1 January 2015.

As Facebook has a physical presence in the Netherlands, the DPA says it is authorised "to act as supervisor", as per a European Court of Justice ruling on Google vs. Spain on 13 May 2014 (the 'right to be forgotten' case).

As such, it has asked Facebook to hold fire on its new privacy policy until it has had the chance to investigate how the changes may impact Dutch users, including how Facebook obtains permission for the use of their personal data.

The latest iteration of the policy states that Facebook can use:

your name, profile picture, content, and information in connection with commercial, sponsored, or related content (such as a brand you like) served or enhanced by us. This means, for example, that you permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you. If you have selected a specific audience for your content or information, we will respect your choice when we use it.

Given how the key points of the policy have not changed since it was last revised in November 2013, it seems unlikely Facebook will comply with the DPA's wishes.

According to The Telegraph, the company responded by highlighting how it is "a company with international headquarters in Dublin", which routinely reviews its policies and procedures with its own regulator, the Irish Data Protection Commissioner.

Facebook said it is confident that its new privacy policy is compliant with all relevant laws.

Follow @Security_FAQs

Follow @NakedSecurity

Image of Dutch citizen courtesy of Shutterstock.


View the original article here

Sunday, December 21, 2014

Microsoft deluged with support in its email privacy battle against US government

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Image of data center privacy courtesy of ShutterstockMicrosoft would prefer if the US Department of Justice (DOJ) refrained from reaching over the ocean and past international law to ransack its Irish servers.

It's been fighting the issue in court since August, when it refused to comply with a warrant for a user's email that was stored in a Dublin data center.

On Monday, much of the tech industry, along with civil rights advocates, backed Microsoft in its legal battle, with more than 75 civil liberties groups, technology companies, trade associations and computer scientists filing legal briefs in support of the software company.

At issue: the DOJ's insistence that it may search Microsoft's overseas servers with a valid US warrant, sidestepping national and international laws that protect such content.

The scope of support for Microsoft's position is unprecedented, its counsel says.

Verizon has said that if the US prevails in this case, it would produce "dramatic conflict with foreign data protection laws."

Apple and Cisco have also come out against the government, saying that the tech sector runs the risk of being sanctioned by foreign governments and that the US should instead seek cooperation with foreign nations via treaties: a position the US has deemed impractical.

The deluge of support that added to these previously filed briefs point to what a precedent-setting case this will be if the company loses - one that would affect the technology world on a global basis, Microsoft Executive Vice President and General Counsel Brad Smith wrote in a blog posting about the outpouring of support:

Seldom has a case below the Supreme Court attracted the breadth and depth of legal involvement we're seeing today. ... This case involves not a narrow legal question, but a broad policy issue that is fundamental to the future of global technology.

Microsoft published the list of backers that filed amicus briefs, including large media outlets such as National Public Radio, The Washington Post, The Guardian, and Forbes; leading technology companies such as Verizon, Apple, Amazon, Cisco, Salesforce, HP, eBay, Infor, AT&T, and Rackspace; professors of computer science; civil rights and free speech advocates such as Digital Rights Ireland, the Electronic Frontier Foundation, and the Center for Democracy and Technology; trade groups such as the National Association of Manufacturers and the Reporters Committee for Freedom of the Press; and even the US Chamber of Commerce.

The groups and companies are all raising issues similar to those already brought up by Apple, AT&T, Cisco and Verizon, Smith said:

These groups raise a range of concerns about the significant impact this case could have both on the willingness of foreign customers to trust American technology and on the privacy rights of their customers, including US customers if other governments adopt the approach to US datacenters that the US Government is advocating here.

Verizon said in its policy blog that the US government is overreaching:

The law does not allow the US government to use a search warrant to obtain customer data stored overseas. The US Supreme Court has reiterated many times that US statutes are presumed not to have extraterritorial application unless Congress "clearly expressed" its "affirmative intention" to the contrary.

There's good reason why Congress hasn't said that domestic US warrants should apply to data stored offshore, Verizon's Randal Milch wrote. For one thing, the content of private email belongs to a customer, not to a provider.

The DOJ has resisted this argument, claiming that email stored in the cloud ceases to belong exclusively to us, becoming instead the business records of a cloud provider.

Because business records have a lower level of legal protection than personal records, the government claims that it can use its broader authority to reach emails stored anywhere in the world.

But if Microsoft were to give in to the government's demands, it would actually be breaking Irish law, Verizon points out:

Ireland's Minister for Data Protection has made clear that "when governments seek to obtain customer information in other countries they need to comply with the local laws in those countries."

In fact, there are treaties in place that would have dictated whether or not the emails could be dug out of Microsoft's offshore servers. Specifically, the DOJ could have followed procedures under the Mutual Legal Assistance Treaty between the US and Ireland to request the information it needed from the government of Ireland "in a manner consistent with Ireland's laws", Verizon points out.

Why didn't the DOJ go that route? Many suggest that the reason is because it knew full well that it wanted something that was inconsistent with Ireland's laws.

In its latest appeal, Microsoft argued that going outside of well-established treaties and partnerships to get at data wherever it's stored sets a precedent for other countries to do the same and thus threaten the privacy of Americans.

There's good reason why Microsoft and other tech companies store customers' data close to them, Smith said:

As we've said since this case began, tech companies such as Microsoft for good reason store private communications such as email, photos, and documents in datacenters that are located close to our customers. This is so consumers and companies can retrieve their personal information more quickly and securely. For example, we store email in our Irish datacenter for customers who live in Europe.

And even if the treaties need an overhaul, that's no reason to ignore them completely, he suggested:

The US has well-established treaties with countries around the world that allow them to seek the information they need while ensuring that citizens of other countries retain the privacy protections offered by their own laws and Courts. And there's ample opportunity for work to modernize these agreements further.

Follow @LisaVaas

Follow @NakedSecurity

Image of data center privacy courtesy of Shutterstock.


View the original article here

Sunday, June 8, 2014

Privacy compliance for big data systems automated: Search engine code is moving target that eludes manual audits

Web services companies, such as Facebook, Google and Microsoft, all make promises about how they will use personal information they gather. But ensuring that millions of lines of code in their systems operate in ways consistent with privacy promises is labor-intensive and difficult. A team from Carnegie Mellon University and Microsoft Research, however, has shown these compliance checks can be automated.

The researchers developed a prototype automated system that is now running on the data analytics pipeline of Bing, Microsoft's search engine. According to Saikat Guha, researcher at Microsoft, it's the first time automated privacy compliance analysis has been applied to the production code of an Internet-scale system and is a reflection of Microsoft's commitment to creating the technology necessary to further safeguard the privacy of customers.

Employing a new, lawyer-friendly language to specify privacy policies and using a data inventory to annotate existing programs, the researchers showed that a team of just five people could manage a daily compliance check on millions of lines of code written by several thousand developers.

They presented their research findings at the 35th IEEE Symposium on Security & Privacy, May 18-21, in San Jose, Calif.

"Companies in the United States have a legal obligation to declare how they use personal information they gather and it's also good business to establish a bond of trust with customers," said Anupam Datta, associate professor of computer science and electrical and computer engineering. "But these systems are constantly evolving and their scale can be daunting. The manual methods typically used for checking compliance are labor intensive, yet too often fail to catch all violations of policy."

"Tens of millions of lines of code are already in the pipeline," noted Shayak Sen, a Ph.D. student in computer science who interned at Microsoft Research India and the lead student author on the study. "And during our implementation on Bing, we found that more than 20 percent of the code was changing on a daily basis." At these large scales, automated methods offer the best hope of verifying compliance.

"One reason that gaps exist between policies set by a company's privacy team and the code written by software developers is that the two groups don't speak the same language," Datta said. Lawyers and privacy champions typically have little experience in programming and developers attempting to translate policies into code can get tripped up by ambiguities in the language of the privacy policies.

So the researchers developed a language -- Legalease -- that could be easily learned and used by privacy advocates. It employs allow-deny rules with exceptions, a structure that is found in many privacy policies and laws, such as the Health Insurance Portability and Accountability Act (HIPAA), and is expressive enough to capture the real policies of an industrial-scale system such as Bing.

In preliminary usability testing, a dozen Microsoft employees were given a one-page document explaining Legalease and spent an average of under 5 minutes studying it. They then took an average of less than 15 minutes to encode nine Bing policy clauses regarding how user information can be used. "They were able to perform this task with a high degree of accuracy, which is encouraging," Sen said.

But encoding privacy policies correctly means little if it cannot be applied to large codebases written by large teams of programmers. To solve this dilemma, the researchers leveraged Grok -- a data inventory that annotates existing programs written in languages typically employed by MapReduce-like systems, such as those used by Bing and Google -- for their backend data analytics over user data.

Grok performs this automated annotation by combining information from different sources with varying levels of confidence. For instance, automated pattern-matching to column names can be performed across an entire database, but with low confidence, while annotations by developers have high confidence, but low coverage.

Grok had been developed by Microsoft Research and deployed by Bing for the express purpose of automating privacy compliance checking the previous year, but writing policies for Grok was cumbersome.

"Legalease was the final piece of the automated privacy compliance jigsaw puzzle," Guha said. "Developed over Sen's internship and subsequent collaboration with CMU, Legalease bridged privacy teams with Grok, and through Grok, with the developers."

Datta said automating the process of compliance checks could push the industry to adopt stronger privacy protection policies.

"Sometimes, companies want to make their policies stronger, but hesitate because they are not sure they can ensure compliance in these large systems," he explained, noting that online privacy policy compliance is enforced in the United States by the Federal Trade Commission.

The research team included Sriram K. Rajamani of Microsoft Research in Bangalore, India; Janice Tsai of Microsoft Research, Redmond, and Jeannette Wing, corporate vice president of Microsoft Research and former head of CMU's Computer Science Department.

This research was supported, in part, by the Air Force Office of Scientific Research and the National Science Foundation.


View the original article here

Saturday, June 7, 2014

Security and privacy? Now they can go hand in hand

Online identification and authentication keeps transactions secure on the Internet, however this has also implications for your privacy. Disclosing more personal information than needed online when, say, you log in to your bank website may simplify the bank's security at the cost of your privacy. Now, thanks to research by the EU-funded project Attribute-based Credentials for TrustABC4Trust , there is a new approach that keeps systems secure and protects your identity.

The ABC4Trust research team is piloting this technology with young people, often thought to be the less careful about their online security. But 'that's not the case', says Prof. Dr. Kai Rannenberg , Coordinator of the ABC4Trust project, 'The participants were very interested in learning which personal data they reveal and how they can control this. The university students especially feel that Attribute-based Credentials (ABCs) can help them manage their e-identities and enable them use Internet services in a privacy preserving way.'

For example, at Norrtullskolan secondary school in S?derhamn, Sweden, pupils can access counselling services online. However, until recently the pupils couldn't access these services using a pseudonym -- they had to identify themselves by name so the school could check whether they were allowed to use them.

But in the ABC4Trust pilot scheme, each child is issued with a 'deck' of digital certificates that validate information like their enrollment status, their date of birth and so on. This allows the school pupils to enjoy both privacy and security. Instead of having to reveal their whole identity when using the counselling service they can simply use one of the certificates in their deck that pseudonymously verifies they are enrolled at the school.

Another pilot developed at the Computer Technology Institute and Press "Diophantus" and trialled at the University of Patras , Greece, allows students to give anonymous feedback on their courses and lecturers, while ensuring that only registered students can take part in the polls.

Prof. Rannenberg says, 'Our user studies showed, that the school children, parents and the university students are happy that they are giving less of their private information when they access the services and leave feedback. Also the respective authorities are happy with the pilots and the feedback; in the not too distant future we expect more European public services and other organisations switch to Privacy-ABCs.'

Users want Privacy, Organisations want Security

According to recent research by market research organisation, Ovum, 68 % of us in the EU would like to opt out of having our personal data tracked. In a speech in May , Commissioner Neelie Kroes stressed that it is essential for EU business 'To show the citizen that going online is not just convenient, but trustworthy… With resilient and secure networks and systems I think we can build that trust.'

ABC4Trust is a 13.05 Million Euro project, with 8.85 Million Euro funded by the European Union's Seventh Framework Programme (FP7) . The international and multidisciplinary ABC4Trust consortium is led by Johann Wolfgang Goethe-Universit?tFrankfurt am Main, Germany and it is composed of 11 partners from 7 countries. ABC4Trust started in November 2010 and will run for 4 ? years.


View the original article here

Friday, June 6, 2014

Privacy and vulnerability issues: Could decentralized networks help save democracy?

Democratic movements can flourish online, but just as easily get censored. A group of researchers is developing solutions to the vulnerabilities and privacy problems with using big social media platforms like Facebook and Twitter.

Turkish President Recep Tayyip Erdogan disrupted communications between his opponents when he shut down Twitter during the run-up to the country's recent election. But in doing so, he provided yet more proof of how flawed social web activism can be. Whether the lessons in Turkey are heeded could have serious consequences for democracy.

Social networks such as Twitter and Facebook have enabled unprecedented levels of communication and have even received credit for at least one major democratic revolution. There's just one problem: because of their monolithic nature, these centralized networks expose users to snooping and interference of the kind Erdogan caused, says Sonja Buchegger, Associate Professor of Computer Science at KTH Royal Institute of Technology.

A single, large-scale platform provides an easier target for anyone who wants to interfere with online political activity, says Buchegger. "But, if Twitter were decentralized, and you had users cooperating and communicating directly, that wouldn't have been possible to disrupt.

"Decentralization allows for greater freedom of expression.

The good news is that there could be a computer science answer to the problem. Buchegger is leading a group of scientists at KTH who are creating building blocks that developers could use to launch decentralized, distributed networks, which would not only be difficult to interfere with, but would also protect people from government snooping.

"The internet itself is not centralized -- it would be hard to shut down," Buchegger says. "It was built as a robust, decentralized tool to communicate; and we can do the same for other services that are now centralized, like social networks."

Whether the demand for such networks would go mainstream any time soon is hard to tell. Buchegger notes that it is difficult for most people to wrap their head around the notion that their personal information is exposed on web-based email and social platforms.

"The whole privacy issue online is very young, and the population is not used to thinking in this way," she says. "Offline, we know how to protect our privacy; we know who can overhear us; we see who is in the room with us and we know whether we can trust those people; but online we haven't really grasped who the audience is and how that changes over time."

Buchegger's research is focused on the privacy issues of distributed peer-to-peer (P2P) networks, that is, the underlying infrastructure for a decentralized system in which people could store their data beyond the reach of data miners or government surveillance.

"We are developing these little building blocks: this is how you do passwords in a distributed environment; this is how you do search in a privacy-preserving decentralized environment; this is how you make news feeds; this is how you control access," she says. "Then you can put the building blocks together and build a new communications system -- that's the idea."

For example, encryption tools are being tested that could provide users with "fine grain" control over their privacy. One could use encryption keys to decide specifically who can access or view a given piece of content. "You wouldn't have to worry about all the people you don't want to access it because the default is that access is denied," she says.

The research into privacy tools cuts right to one of the major weaknesses of centralized networks -they rely on centralized data centers for storage, thus exposing millions of people's personal information to prying eyes.

Buchegger says that as far as promoting democracy goes, distributed networks could outshine so-called "Facebook revolutions," encouraging more widespread activism, particularly for those whose only connection to the web is with a phone.

"This is a way of developing the idea of a commons, in which more people get together and organize and share resources," she says. "A decentralized network would also be a sort of commons because you could imagine how people with large servers could store encrypted data for others. It could enable access to resources for those who cannot store so much on their phone."

While distributed networks offer potential for greater communication and more effective organizing, Buchegger is quick to point out that technology is not a quick fix for promoting democracy. Ultimately political action depends on people assembling in the non-virtual world. "There is a danger that you think that just because you repost something on Facebook or Twitter that you are doing activism, but it's not actually doing something.

"Networks can reach more people and be used to organize physical activism, but they're not a substitute for activism."

Cite This Page:

KTH The Royal Institute of Technology. "Privacy and vulnerability issues: Could decentralized networks help save democracy?." ScienceDaily. ScienceDaily, 12 May 2014. .KTH The Royal Institute of Technology. (2014, May 12). Privacy and vulnerability issues: Could decentralized networks help save democracy?. ScienceDaily. Retrieved May 30, 2014 from www.sciencedaily.com/releases/2014/05/140512101634.htmKTH The Royal Institute of Technology. "Privacy and vulnerability issues: Could decentralized networks help save democracy?." ScienceDaily. www.sciencedaily.com/releases/2014/05/140512101634.htm (accessed May 30, 2014).

View the original article here

Wednesday, May 14, 2014

Flaw in 'secure' cloud storage could put privacy at risk

Johns Hopkins computer scientists have found a flaw in the way that secure cloud storage companies protect their customers' data. The scientists say this weakness jeopardizes the privacy protection these digital warehouses claim to offer. Whenever customers share their confidential files with a trusted friend or colleague, the researchers say, the storage provider could exploit the security flaw to secretly view this private data.

The lead author of the new article is Duane C. Wilson, a doctoral student in the Department of Computer Science in the university's Whiting School of Engineering. The senior author is his faculty adviser, Giuseppe Ateniese, an associate professor in the department. Both are affiliated with the Johns Hopkins University Information Security Institute.

Their research focused on the secure cloud storage providers that are increasingly being used by businesses and others to house or back up sensitive information about intellectual property, finances, employees and customers. These storage providers claim to offer "zero-knowledge environments," meaning that their employees cannot see or access the clients' data. These storage businesses typically assert that this confidentiality is guaranteed because the information is encrypted before it is uploaded for cloud storage.

But the Johns Hopkins team found that complete privacy could not be guaranteed by these vendors. "Our research shows that as long as the data is not shared with others, its confidentiality will be preserved, as the providers claim," Wilson said. "However, whenever data is shared with another recipient through the cloud storage service, the providers are able to access their customers' files and other data."

The problem, Wilson said, is that privacy during file-sharing is normally preserved by the use of a trusted third party, a technological "middle-man" who verifies the identify of the users who wish to share files. When this authentication process is finished, this third party issues "keys" that can unscramble and later re-encode the data to restore its confidentiality.

"In the secure cloud storage providers we examined," Wilson said, "the storage businesses were each operating as their own 'trusted third party,' meaning they could easily issue fake identity credentials to people using the service. The storage businesses could use a phony 'key' to decrypt and view the private information, then re-encrypt it before sending it on to its intended recipient."

Wilson added, "As a result, whenever data is shared with another user or group of users, the storage service could perform a man-in-the-middle attack by pretending to be another user or group member. This would all happen without alerting the customers, who incorrectly believe that the cloud storage provider cannot see or access their data."

These storage services generally do not share the details of how their technology works, so Wilson and Ateniese substantiated the security flaw by using a combination of reverse engineering and network traffic analysis to study the type of communication that occurs between a secure cloud storage provider and its customers.

The researchers pointed out that their study focused only on three storage providers that claimed their customers' data would remain completely confidential. Other file-sharing services, such as Dropbox and Google Drive, make no pledge of privacy. Instead, they say that after a user's data is uploaded, it is encrypted with keys that are owned by the file-sharing service.

To solve the security flaw, the researchers recommend that the arrangements between customers and secure storage providers be revised so that an independent third party serves as the file-sharing "middle-man," instead of the storage company itself.

"Although we have no evidence that any secure cloud storage provider is accessing their customers' private information, we wanted to get the word out that this could easily occur," said Ateniese, who supervised the research. "It's like discovering that your neighbors left their door unlocked. Maybe no one has stolen anything from the house yet, but don't you think they'd like to know that it would be simple for thieves to get inside?"


View the original article here

Friday, May 9, 2014

Collecting digital user data without invading privacy

The statistical evaluation of digital user data is of vital importance for analyzing trends. But it can also undermine the privacy. Computer scientists from Saarbr?cken have now developed a novel cryptographic method that makes it possible to collect data and protect the privacy of the user at the same time. They present their approach for the first time at the computer expo Cebit in Hannover at the Saarland University research booth.

"Many website providers are able to collect data, but only a few manage to do so without invading users' privacy," explains Aniket Kate, who leads the research group "Cryptographic Systems" at the Cluster of Excellence "Multimodal Computing and Interaction" (MMCI) in Saarbr?cken. Two aspects threaten privacy during data aggregation: On the one hand, where and how is the data aggregated? For example, website owners are interested in the age and gender of their visitors. Therefore, they store data files (cookies) on their computers that observe which other websites they visit. "But this wealth of sensitive information allows them also to reconstruct detailed profiles of each individual," says Kate. On the other hand, it is important to publish aggregated data in a privacy-preserving way. "Researchers have already demonstrated that precise information about the habits of citizens can be reconstructed from the electricity consumption information collected by so-called smart meters," explains Kate.

In cooperation with his colleagues Fabienne Eigner and Matteo Maffei from the Center for IT-Security, Privacy and Accountability (CISPA) and Francesca Pampaloni from the Italian IMT Institute for Advanced Studies Lucca, Kate developed a software system called "Privada." It is not only able to resolve the dilemma between the desire for information and the protection of data, but it can also be easily applied in different domains. "For example, with Privada website owners are still able to observe that their websites are mainly visited by middle-aged women, but nothing more," Kate explains.

To achieve this, users split up the requested information and send parts of it to previously defined servers performing multi-party computation: Each server evaluates its data without being aware of the data of other parties. So together they compute a secret, but are not able to decode it on their own. Moreover, each party adds on a value corresponding to a probability distribution to make the data a little bit imprecise. The perturbated partial results are assembled into the actual analysis. The perturbation ensures that the identity of the individual person is protected, while trends are still significant in the aggregated statistic about user data.

The privacy is even guaranteed if all but one of the servers collaborate. Hence, according to the researchers, it is even conceivable that companies could provide such servers. If only servers, and not users, perturb the data with a certain amount of noise, that has two advantages: Firstly, not much computational power is necessary on the user's side. Hence, even a mobile phone could send the partial result to a particular server. Also, in total, there is only a minimal amount of noise attached to the aggregated data. Hence, the resulting statistic about user data is as accurate as possible.

The computer scientists from Saarbr?cken have already implemented their concept. "The computation is fast; the servers just need a few seconds," says Fabienne Eigner, part of the research group "Secure and Privacy-preserving Systems" at Saarland University. She also worked on the software system. The architecture is constructed in such a way that it would not make any difference if someone were to analyze the data of a thousand or a million people," explains Eigner.


View the original article here

Monday, April 28, 2014

SSCC 144 – iOS malware, fingerprint security, WhatsApp privacy, hacking the taxman [PODCAST]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Apple, Data loss, Featured, iOS, Law & order, Malware, Podcast, Privacy, Security threats, Social networks, Vulnerability

News, opinion, advice and research!

Here's our latest security podcast, featuring Sophos experts and Naked Security writers Chester Wisniewski and Paul Ducklin.

(Audio player above not working for you? Download to listen offline, or listen on Soundcloud.)

Follow @NakedSecurity

Follow @duckblog

Tags: "Canada Revenue", "Galaxy 5S", baby panda, chester wisniewski, chet chat, cra, data breach, data leakage, Galaxy, heartbleed, ios, krebs, LaCie, Malware, Paul Ducklin, Samsung, sophos security chet chat, sscc, unflod, WhatsApp


View the original article here

Friday, November 29, 2013

Jay-Z’s ‘Magna Carta’ mobile app is too snoopy, privacy advocates complain

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Jay-Z. Image courtesy of Shutterstock.Why does Jay-Z want to know who we're talking to?

Because that's the type of information demanded by an app he released earlier this month to promote and distribute his latest album over Samsung devices.

In fact, the galaxy of permissions required by this busybody little app "verges on parody," the Electronic Privacy Information Center (EPIC) said in a complaint it filed this week with the Federal Trade Commission (FTC).

The Magna Carta App, used to promote the album, "Jay-Z Magna Carta Holy Grail", was launched 4 July on Samsung Galaxy Nexus devices in advance of the record release.

EPIC wants the FTC to stop Samsung from distributing the app until its privacy concerns are addressed and the app falls in line with the Consumer Privacy Bill of Rights [PDF].

The app requires these permissions:

To modify or delete contents of phone USB storage.To prevent phone from sleeping and view all running apps.To access your precise (GPS) and approximate (network-based) location.To read your phone status and identity (i.e. who you're talking to on voice calls).To run at startup.To test access to protected storage. To receive data from internet, view Wi-Fi connections, and view network connections.To control your phone's vibration. To find accounts on the device - in other words, to gather email addresses and social media usernames connected to the phone.

The app not only wants to know who you call, it also demands your Twitter or Facebook login so it can post on your behalf, presumably so it can create "social buzz," EPIC says.

Beyond that, people who downloaded the Magna Carta app have been forced to post a canned Facebook or Twitter message to hype the album for each song's lyrics they wanted to check out - a process that "encouraged users to flood their friends with unwanted advertising" and forced users to act as "mandatory marketing tools" to access the lyrics, EPIC says.

Users were suitably appalled. One actually paused for an entire 6 seconds.

And then, well, he or she went ahead and downloaded it.

Others are in mourning for the loss of lifespan the app sucked up.

One user's comment:

"I downloaded it, opened it, noticed the obscene amount of personal data they wanted, closed it again and uninstalled. I'd like that minute and a half of my life back please."

Observers are, naturally, assuming that Jay-Z has undertaken advanced surveillance as a hobby.

From Jon Pareles, writing for the New York Times:

"If Jay-Z wants to know about my phone calls and e-mail accounts, why doesn't he join the National Security Agency?"

Pareles is particularly irked, given lyrics from at least one Jay-Z song - "Somewhere in America" - that seem, confusingly enough, to be anti-NSA:

"Feds still lurking"

"They see I'm still putting work in..."

As Pareles points out, now Jay-Z is lurking, in our phones.

Jay-Z, if you're listening, which it seems like you are, then please, call off your Samsung colleagues.

We've got enough eavesdropping going on without you adding to the snooping.

Follow @LisaVaas

Follow @NakedSecurity

Image of Jay-Z courtesy of Shutterstock.


View the original article here

Friday, October 25, 2013

#Facebook gets #hashtags, which does #WTF to your #privacy?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

facebook logoFor those Facebook users who are allergic to any notion of privacy whatsoever and would prefer that the entire world be privy to contents of their #dinner or antics of their adorable #children, Wednesday was a high and holy day indeed, for that was the day that Facebook embraced the hashtag.

The company announced that starting on Wednesday, users would be able to add clickable hashtags to posts, similar to Twitter (for whom user Chris Messina invented the hashtag back in 2007), Instagram, Tumblr, or Pinterest.

Clicking on a hashtag will lead you to a feed that shows what other people and pages are saying about the hashtagged subject.

Facebook hashtag example

As Messina said about his hashtag rationale, he wasn't interested in other people's talk about creating official groups on Twitter.

Rather, he was more interested in enabling eavesdropping:

I’m more interested in simply having a better eavesdropping experience on Twitter.

To that end, I focused my thinking on contextualization, content filtering and exploratory serendipity within the Twittosphere.

With hashtags, Facebook is also interested in eavesdropping, aka encouraging users to open up conversations to strangers. Likely, as pointed out by The Register's Kelly Fiveash, the aim is to "juice up more ad revenue."

As it is, Facebook is happy to point out, "roughly a Super Bowl-sized audience" engages with the social network every night, during "primetime television alone."

Take Game of Thrones, for example, for which the recent, remarkably gory episode "Red Wedding" got over 1.5 million mentions on Facebook. That's not too shabby, given that 5.2 million people watched it.

How will this impact your privacy? It shouldn't, if you avoid using hashtags to get Facebook Nation to follow your conversations.

#privacyCurrently, users control the audience for their posts, including those with hashtags.

Unfortunately, there have been far too many users who don't control who sees their posts, even in the pre-hashtag world.

As Consumer Reports reported a year ago, 13 million US Facebook users weren't using, or were oblivious to, privacy controls.

At the time, Consumer Reports found that in the prior 12 months, Facebook users "liked", updated their profiles, and posted status updates to produce these data points at these rates:

39.3 million identified a family member in a profile20.4 million included their birth date and year in their profile7.7 million "liked" a Facebook page pertaining to a religious affiliation4.6 million discussed their love life on their wall2.6 million discussed their recreational use of alcohol on their wall2.3 million "liked" a page regarding sexual orientation

If you want to ensure that hashtags don't get the privacy-oblivious into even hotter water, do them a favor and educate them on how to work Facebook privacy controls.

There's a great video from Consumer Reports here on how to do just that.

Oh, and if you want to hear the security latest news about Facebook, give the Naked Security Facebook page a 'like'.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Wednesday, September 11, 2013

Congress asks Google if and how it's protecting privacy with Glass

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Image from Stop the CyborgsThe US Congress on Thursday sent Google a letter [PDF] listing eight specific privacy areas concerning Glass that legislators would like to know quite a bit more about.

Congress members aren't the only ones.

Since the emergence of Glass - Google's uber-geeky, internet-enabled head gear that's worn like discrete, photo-snapping/video-grabbing eyeglasses - the technology has:

Congress - specifically, eight members of the privacy caucus - has thus risen from the swirl of speculation around Glass and asked Google to answer a specific list of questions.

Letter from Congress to Larry Page Google

Here they are, reiterated and unfolded (Congress packed multiple questions into one question in a few spots):

How will Glass not be like WiSpy? As in, how is Google going to prevent Glass from unintentionally collecting data about users or non-users without consent? As it is, Congress pointed out, the company was fined $7 million for its StreetView cars having sucked up information via unsecured wireless networks. How will Google avoid a similar mess with Glass? How will Google proactively protect non-users who get ogled? Is Google building in product lifecycle guidelines? One such framework is Privacy by Design, which covers the embedding of privacy and data protection throughout a technology's lifecycle, from the early design stage to its deployment, use and ultimate disposal. Specifically, Congress wants to know what happens when a customer resells or otherwise disposes of Glass and whether Google has baked in capabilities to keep the original owner's personal information secure. Will Glass use facial recognition? If so, how do users get that information? How do non-users opt out of this personal data collection? If they can't opt out, why is that?Under what circumstances does Google refuse requests from Glass that invade the privacy of others? Congress here references Google's Privacy Policy, which states that it may reject requests that are:

"... unreasonably repetitive, require disproportionate technical effort, ... risk the privacy of others, or would be extremely impractical..."

Is Google tweaking its privacy policy to reflect the sensory and processing capabilities of Google Glass? If not, why not? What device-specific information is Google collecting from Glass? Here, Congress is referencing Google Privacy Policy as it pertains to collecting hardware models, operating system versions, unique device identifiers, and mobile network information, including phone numbers. Is Google collecting data about the user without the user's knowledge? To what extent was privacy considered when approving the first app for Google Glass, rolled out by the New York Times? How is Google ensuring that privacy's a priority for the other app developers who've since followed suit? Is Glass storing data on the device itself? If so, will it be protected, and if so, via what type of user authentication or other means?

Congress is looking for answers by Friday, June 14.

These are great questions, and Congress is to be lauded for asking them.

Some Congress members - well, one, at any rate - actually think highly enough of Google's past respect for privacy to take hope in Glass being rolled out with all due care.

Here's how Sen. Al Franken a Democrat from Minnesota, put it to Ars Technica:

"In the past, Google has taken a principled position in making facial recognition an opt-in service for its social network, Google+... This gives me hope that this same kind of thoughtfulness will be applied to its roll-out of Glass. I’m looking forward to talking to Google more about its deployment of Glass and what it means for privacy."

Senator, let us hope that *your* hope is not misplaced.

Mine tends to be shredded whenever I contemplate Google's voluminous Privacy Rap Sheet.

Follow @LisaVaas
Follow @NakedSecurity

Image of "No Google Glass" courtesy of Stop the Cyborgs.


View the original article here

Saturday, July 20, 2013

Facebook Home - Great if you think privacy is dead

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

FacebookHome170Is Facebook Home the long rumored Facebook phone? Nope.

Rumors of a Facebook phone are nearly as common as OS X users who don't think they need anti-virus, but that doesn't make either one of them true.

Facebook is avoiding the hassles of designing and manufacturing its own hardware, but nevertheless making a land grab for control of the user experience.

The concept is simple: replace the lockscreen and application launcher on popular Android devices with a streamlined, Facebook-focused experience.

It is only available on a few devices at this time, including the Samsung Galaxy S3, Samsung Galaxy Note II, HTC First, HTC One X, and HTC One X+.

So I thought I would take a quick look at it from a security and privacy standpoint.

Modifying things like lockscreens can easily go sideways, as we've seen in the past with iOS.

In fact, without even considering how the app is designed to work, there are already reports of Home disabling the built-in Android pattern/passphrase lock on the new HTC First.

That isn't supposed to happen, of course, so I would think twice about enabling it until Facebook is able to release a fix.

CoverFeed170What Facebook Home is supposed to do is replace your plain vanilla lockscreen with a continuously-updated feed from your Friends, a feature they call Cover Feed.

You will see their photos, wall posts, comments, Likes, and more, all the time, in real time.

All of this information is visible without unlocking your phone and provides the opportunity to double-tap to Like the content you are viewing.

This is an interesting new take on the "lock" in "lockscreen," and while the always-logged-in "privacy is dead" angle won't be a surprise to Facebook fans, it raises worrying opportunities for abuse.

Just imagine what some of your friends might post to their walls simply to have it show up on your phone during a business meeting!

Even if you are not a Facebook Home user, you'll still be impacted.

When you post a photo or comment, you won't know when or where it will show up on your Friends' phones, or who might be around to see it.

And if you travel a lot, you may end up stuck with some heavy-duty roaming fees from downloading all of those photos, all of the time.

The Facebook Home Launcher component is largely uncontroversial.

It's uncomplicated, and while it steers you towards Facebook functionality and apps rather than Android ones, it seems perfectly functional.

ChatHeads170The feature people seem to like the best is called Chat Heads.

I have to admit, if I were a frequent Facebook chatter I would love this -- in fact I wish Google Talk worked more like Chat Heads.

The idea is your Friends' photos appear as little circles at the edge of your screen, popping out and displaying any chat messages, no matter what application you are using on your phone at the time.

My verdict?

If you are a heavy Facebook user and don't mind the privacy risks, I think you'll really like Facebook Home. (I'd wait until Facebook works out the lockscreen bypass problems, but otherwise it isn't inherently broken.)

But if you are a corporate user and enlisted in a BYOD program, I'd steer clear.

In fact if I were administering a BYOD program, I would disallow Facebook Home, as I feel there is too much room for information leakage for it to be a safe choice in a business environment.

My advice?

Take the time to think through the privacy implications before you install it.Be understanding if your employer doesn't let you use it on BYOD devices. Consider living without the Cover Feed option, even if you love the idea.Follow @chetwisniewski

View the original article here

Wednesday, June 5, 2013

Facebook plugs Timeline privacy hole

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Europe vs FacebookEurope v. Facebook, an Austrian student organization that keeps tabs on Facebook's privacy transgressions, recently discovered that Facebook's latest timeline redesign allowed friends of friends to see the total number of Events a user has attended, even if that person's privacy settings were set to only allow friends to see such events.

This screw-up allowed for unintended sharing of sensitive information, such as political beliefs and sexual orientation, the group said in a release.

europe-v-facebook.org - Facebook March

From the release:

"Users were able to look through often times thousands of past events users were invited to, including demonstrations or gay parties."

Facebook's timeline changes allowed unintended displays of information to friends of friends. Facebook’s View as function displayed such information as public, displaying it in batches of event activity under a heading called Events.

Facebook thankfully plugged the hole within hours of the group informing the company about the problem.

The problematic section, Events, disappeared from affected users' profiles, after which the group could no longer access the data in question, Europe v. Facebook said.

Europe-v-facebook.org - Facebook fixed leak in new timeline

When Facebook announced the redesign on March 13, the company said it be would rolled out over a few weeks.

Many users, not having been upgraded yet, were oblivious to the privacy hole, Europe v. Facebook said.

This is the latest of a string of challenges the group has put to Facebook over what it deems privacy violations in Europe.

The group has filed a total of 22 complaints with the Irish Data Protection Authority against Facebook’s European subsidiary in Ireland.

Max SchremsThose complaints were built on the work of meticulous document requester and researcher Max Schrems, who in 2011 extracted a pile of 1,200 pages that comprised his then-current personal-data Facebook dossier.

In fact, Schrems, the organizer of Europe v. Facebook, has been awarded the 2013 International Privacy Champion Award by the Electronic Privacy Information Center (EPIC) for his work, which has "inspired more than 40,000 users around the world to make similar access requests, helping to ensure greater transparency of internet companies".

As reported by IDG News Service's Jeremy Kirk, Facebook committed to changing how it retains data and altered some privacy controls following a critical audit by the regulator released in December 2011.

Unsatisfied, Europe v. Facebook has continued to keep the Irish Data Protection Commissioner's feet to the fire.

This recent privacy hole is just the latest result of the group's praise-worthy efforts.

The group is to be applauded for its vigilance. That vigilance is pricey, so if you care about privacy and want to support their efforts, you might want to consider contributing to their work at https://www.crowd4privacy.org/.

If you're on Facebook and want to keep informed about privacy issues, scams and internet attacks, join the Naked Security page, where over 211,000 people regularly share information on threats and discuss the latest security news.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Sunday, February 3, 2013

Facebook privacy control overhaul will remove ability to limit who can find us

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

FacebookAre you suffering from CFF - Chronic Facebook Fatigue? The mental and bodily malaise that comes from constant tweaking of privacy options in the Land of the Face?

Fear not, for the most recent round of changes, announced today, carry some good privacy tidings, including privacy shortcuts from the main page drop-down menu, plus a new Request Removal tool for managing multiple photos in which you have been tagged.

The changes will begin rolling out at the end of the year.

Facebook is also adding in-context educational notices throughout its platform to help make it easier to understand how to control your sharing.

For example, a reminder may inform users how items hidden on their timelines can still appear in news feeds, in searches, and in other places.

Hidden Education

But lest we get all giddy, note that the new privacy changes are part good, part bad.

On the plus side is the privacy short-cut.

You'll be able to click on a lock icon, next to the Home button on the upper right of the drop-down menu, to quickly access settings for "Who can see my stuff?" "Who can contact me?" and "How do I stop someone from bothering me?"

privacy-shortcuts

You'll also be able to access Help Center content from the short-cut drop-down menu.

As Facebook product manager Sam Lessin notes in his writeup of the changes, this quick access replaces what used to be a bit of a maze.

Up until now, tweaking privacy and timeline controls required you to stop what you were doing and navigate through a separate set of pages.

In the best of all possible worlds, the ease of access to Facebook privacy controls would increase their use.

That's good. It's hard to imagine their use getting worse, at any rate.

As Consumer Reports reported in April, 13 million US Facebook users aren't using, or are oblivious to, privacy controls.

Facebook is arguing that another positive step is the upcoming ability to remove your name from multiple photos that you are tagged in.

We'll be able to go to the "Photos of You" tab, select multiple photos, and ask friends to take down the shots we don’t want to be tagged in. We'll also be able to append a message about why this is important.

The tool will enable you to take off your name from multiple photos. But bear in mind that while untagged photos don’t appear on your timeline, the photos can still appear in other places on Facebook, such as search, news feed, or your friends’ timelines.

request-removal-tool

It's sounds like it will be a convenient way to bemoan rampant tagging to the slap-happy taggers in your network, but it doesn't go far enough.

As Sophos's Graham Cluley noted when he wrote up the last big privacy setting revamp in August 2011, Facebook-using Naked Security readers list photo-tagging as one of the least popular elements of the site.

Rather than having to slog through a continual process of requesting that people untag them in photos, and that they please leave off the habit entirely in the future, and rather than simply blocking tagged photos from appearing on their timelines, many Facebook users want to simply block anyone from tagging them without having received express prior permission to do so.

Unfortunately, Facebook has failed to give us this blanket tag-blocking ability in these recent privacy changes.

Facebook magnifying glassAnother negative change is the removal of the ability to hide yourself from people searching for you by name.

Facebook is axing the setting called "Who can look up my timeline by name," which controlled whether someone could be found by typing their name into the Facebook search bar.

That setting was "very limited in scope," Lessin wrote, and didn't keep people from being found in "many other ways across the site."

He wrote:

"Because of the limited nature of the setting, we removed it for people who weren’t using it, and have built new, contextual tools, along with education about how to use them. In the coming weeks, we’ll be retiring this setting for the small percentage of people who still have it."

Again, it's the wrong direction. If the original setting was limited in scope and failed to do what it purported - e.g., choose who can find you - why not rework it so as to actually protect people's privacy and give them the right to not be found?

Why not patch those privacy leakage holes, those "many other ways across the site" that allow people to find those who don't want to be found?

Facebook deserves kudos for putting privacy controls in a quick short-cut where more people might access and use them, and the contextual education sounds like a win, but it all would be more comforting if the company weren't, at the same time, trashing the important privacy control of who can find us.

If you are on Facebook and want to keep yourself informed about the latest news from the world of internet security and privacy, join the Sophos Facebook page where more than 200,000 people regularly discuss these issues and best practice.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Saturday, December 15, 2012

Just how well do Android privacy apps hide your sexy photos and secret texts?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Android appsDo you have photographs on your smartphone that you don't want others to see? If an app publisher tells you that they will keep your secrets safe would you trust them?

The best advice when it comes to privacy and photos is "don't take a photo that you don't want your teacher/boss/mum/dad to see".

But as this advice is not always heeded, the next best thing is to keep them safe from prying eyes should anyone borrow, steal or find your phone.

Encouraged by a recent article on the shortcomings of the Snapchat safe sexting app, I tried a few apps that promise to protect your privacy, but often fail to do anything of the kind. These examples are all based on tests I conducted on an Android smartphone, but many of the apps are also available for iPhone.

Secret Pictures

First I tested Secret Pictures which describes itself thus:

"Prevent your pictures from letting others know! ... Pictures vanish from Gallery and are locked behind easy-to-use PIN pad. Protect your private pictures ... Secret Pictures locks your private pictures with your PIN. Only you can see the pictures in Secret Pictures."

It sounds very much like your pictures are protected, hidden from view, secured, etc.

But all it really does is move photos to a poorly hidden directory from where the photos can be viewed and shared. All it takes is a file browser and your privacy is ruined!

Photo Safe

Next is Photo Safe which markets itself with the slogan

"Protect Your Privacy! ... No one touches your private data without permission!"

Again, the app gives a definite impression that your hidden photos are safe from prying eyes, and again the app moves your photos out of the gallery - but this time the directory is not even hidden.

Instead the PhotoSafe app renames the file you want to hide in a weak attempt to disguise it, putting some extra characters after the file extension.

This photo is not hidden, protected or secured

You can either rename the file or instruct the phone that the file is an image, and once again it is viewable and shareable just like any normal photo.

KeepSafe Vault

Next in my list was KeepSafe Vault. This app describes itself as the

"Best hide pictures & video app on Android ... Selected pictures vanish from your photo gallery, and stay locked behind an easy-to-use PIN pad. With KeepSafe, only you can see your hidden pictures. Privacy made easy!"

I started to see a recurring theme in the promises that these apps make.

This one has similar failings as the first two apps, using a weakly hidden directory and renaming the images, again easily overcome with nothing more than a file browser.

Hide Pictures and Text messages

It's not all doom and gloom though. There are some apps for hiding the pictures and text messages on your Android which live up to their promises although they all seem to come with some trade-off. You really don't get something for nothing when it comes to apps.

Take, for instance, Hide Pictures & Text Messages:

" lets you hide or encrypt almost anything on your phone including photos, videos, contacts, text messages, and other apps."

For once, when they say they encrypt the content they actually mean it. You can still browse to the directory where files are stored but any feasible attempt to open them outside of the app results in a "Load failed!" error message.

The app lets you hide its own icon too so people won't even know that you have an app for hiding stuff.

All this functionality does come at a price though.

After an initial number of free uses you have to pay in order to be able to encrypt or hide further files.

Due to the extra functionality you will also need to hand over a lot of access permissions to your phone and given that you're looking for extra security and privacy, this may be something that you have reservations about.

Private Gallery

Another promising looking app is Private Gallery which also seems to encrypt your photos meaning they can not easily be viewed outside of the app.

This app is free but it's supported by adverts from an ad network that compromises on security by transmitting the location and identification data from your phone in the clear.

The app also requires some permissions which seem unnecessary given its purpose (for instance, the ability to dial numbers and view/edit your browser history).

Again, if you're in the market for added security and privacy then these concessions may concern you.

Vaulty

The last app I tried was Vaulty which also seems to live up to its promises.

Vaulty looks a little more considerate in that it asks for a more acceptable list of permissions. It also offers a decent balance of functionality in the free version with optional extras in paid-for plugins. If I had a need for a photo/text message privacy app I'd probably go for this one as it seems to ask for the least in return for the most.

Looking into the history of Vaulty highlighted a different problem though.

An automatic update from the developer borked the app for many users, rendering their encrypted files inaccessible. The fault was corrected in a rushed patch but it still demonstrates that should this happen again your protected photos and files might not always be recoverable.

Of course, this risk applies equally to any app which encrypts your data.

In summary, not all apps are created equal and two apps that appear to offer the same service might in fact give very different levels of functionality.

Android tabletSooner or later I expect we'll see an app developer being held accountable for leaked secrets. After all, they promised the unsuspecting user that they would protect those secrets.

It would be better if the descriptions of these Android apps properly reflected what each app does and does not do. At least then users can make an informed choice about how much they wish to trust the app, and whether it is sufficient for the intended purpose.

And, of course, my advice echos those who have gone before me - there is really no situation where you absolutely have to store on your phone naked photographs of yourself.

If you have a photograph or sensitive information that you don't want others to see then try to avoid putting it on a device that others are likely to use.

If you're still determined to go ahead then avoid having anything identifiable in the frame, both of yourself and in the background of the picture.

That way you can at least pretend that it's not you in the photograph when it falls into the wrong hands.

Follow @thegaryhawkins
Follow @NakedSecurity


View the original article here

Monday, November 19, 2012

US court says reading other people's online email is OK, privacy be damned

(B) any storage of such communication by an electronic communication service for the purposes of backup protection of such communication.

Justices Kaye G. Hearn and John W. Kittredge wrote that because the man, respondent Lee Jennings, had no other copies of his Yahoo email, they couldn't possibly constitute a backup as outlined in clause B.

The two judges wrote:

"We decline to hold that retaining an opened e-mail constitutes storing it for backup protection under the Act."

"The ordinary meaning of the word 'backup' is 'one that serves as a substitute or support.' Thus, Congress's use of 'backup' necessarily presupposes the existence of another copy to which this e-mail would serve as a substitute or support. We see no reason to deviate from the plain, everyday meaning of the word 'backup,' and conclude that as the single copy of the communication, Jennings' e-mails could not have been stored for backup protection."

For her part, Chief Justice Jean Hoefer Toal, with Justice Donald Beatty concurring, said that Jennings' email stopped being a 'backup' after its recipient opened them:

"In my view, electronic storage refers only to temporary storage, made in the course of transmission, by an ECS provider, and to backups of such intermediate communications. Under this interpretation, if an e-mail has been received by a recipient's service provider but has not yet been opened by the recipient, it is in electronic storage."

The case came about after Jennings' wife, Gail, found a card for flowers for Jennings' paramour in his car. When Gail confronted him, he confessed he had fallen in love with another woman.

Jennings refused to identify his lover but admitted they had been corresponding via email for some time.

Gail confided in her daughter-in-law, Holly Broome, who had previously worked for Jennings and knew he had a personal Yahoo account.

Broome hacked into his account by correctly guessing answers to his security questions. She read the emails between the two lovers, printed out copies and handed them over to Gail's lawyer and to a private investigator Gail had hired.

Woman at desk, courtesy of Shutterstock

Earlier court rulings found that the emails at issue were in "electronic storage", thus protected under the SCA. Wednesday's ruling reversed that decision, agreeing with Broome's earlier contention that the court had misunderstood the definition of "electronic storage" under the Act and incorrectly concluded the e-mails had been stored for the purpose of backup protection.

The case, as well as our expectations that email won't be hoovered up like so many dust bunnies, turns on an acrobatically convoluted definition of the term "backup".

Previous court decisions have held that opened email that's kept in your online inbox, be it in Yahoo, Gmail or whatever other web service you use, is kept there for backup.

But in this case, Jennings v. Jennings, the judges dived into Merriam-Webster's dictionary for a definition of the word.

Regardless of what that dictionary says, it seems darn clear to me that if people aren't deleting their email, they obviously want to store it for possible future reference.

Woodrow Hartzog, a professor at the Cumberland School of Law at Samford University, holds the same opinion, as he told Ars Technica:

"All of the discussions regarding backups, temporary copies, and the read/unread distinction seem to have very little to do with the way that most people perceive their use of e-mail."

Hartzog said that a "politically palatable" update to the SCA hasn't yet been achieved.

Shocked woman, courtesy of ShutterstockAt any rate, there's still hope for Jennings, he told Ars, given that Broome could still be found liable under the Computer Fraud and Abuse Act.

Turning to a dictionary for a definition of a word such as "backup" is a time-honored way to supposedly win an argument, as the court did in this case.

But this pedantic tactic of treating a dictionary as sacred gospel ignores the fact that dictionaries morph, sag and lag behind current usage. After all, if they were in fact sacred documents, there would be no need for more than one dictionary.

I refer you here to David Foster Wallace's brilliant 2001 review of Oxford University Press's then-recent release of Bryan A. Garner's A Dictionary of Modern American Usage, in which Foster Wallace illustrates the point:

Did you know that probing the seamy underbelly of U.S. lexicography reveals ideological strife and controversy and intrigue and nastiness and fervor on a nearly hanging-chad scale? For instance, did you know that some modern dictionaries are notoriously liberal and others notoriously conservative, and that certain conservative dictionaries were actually conceived and designed as corrective responses to the "corruption" and "permissiveness" of certain liberal dictionaries? That the oligarchic device of having a special "Distinguished Usage Panel ... of outstanding professional speakers and writers" is an attempted compromise between the forces of egalitarianism and traditionalism in English, but that most linguistic liberals dismiss the Usage Panel as mere sham-populism? Did you know that U.S. lexicography even had a seamy underbelly?

If the court wants to determine the meaning of the word "backup" as it pertains to actual usage, by real, live, breathing, email-using humans, as opposed to deriving meaning from an arbitrary dictionary definition, I'd suggest that judges survey real, live, breathing humans, many of whom, I predict, would deliver the unsurprising news that they don't delete their cloud messages because they're storing them for backup purposes - backup meaning, in this case, "I don't want to delete this yet."

Email screen, courtesy of ShutterstockNot that we should trust the cloud to protect our precious documents, mind you.

One incident that made this clear was when US feds told Megaupload users to choose between paying for the forensic expertise to dig out their seized files, or suing Megaupload or its server farm to get them.

No, we shouldn't trust the cloud. But in default of doing anything to further protect our content - namely, backing it up - we do.

And lo, I come across this piece on Lifehacker about Dashlane Courier's new service for sending private, encrypted notes that self-destruct after being read.

Could that be a solution? Are such emails truly deleted forever, beyond the reach of the courts?

If you're familiar with this type of service, please share your thoughts below.

Until and unless the courts apply the Computer Fraud and Abuse Act or other privacy-protecting measures in cases such as this one, it would be nice to have an alternative email solution, for when we really, really don't want email to be read by lawyers and judges.

Follow @LisaVaas
Follow @NakedSecurity

Lisa Vaas has written about technology - specifically, security, databases, technology careers, resume writing and the applicant tracking systems that eat and/or spit out resumes - since 1995. Her stories have appeared in venues including the print and/or online versions of eWEEK, PC Magazine, Computerworld, CIO, IT Expert Voice, HP's Input/Output, and TheLadders. Read more from Lisa on her website at www.lisavaas.com.
var OBCTm='1328889400668'; jQuery(document).ready(function($){ Gravatar.profile_cb = function( h, d ) { WPGroHo.syncProfileData( h, d );}; Gravatar.my_hash = WPGroHo.my_hash; Gravatar.init( 'body', '#wp-admin-bar-my-account' ); });

View the original article here

Tuesday, October 2, 2012

Apache Foundation creates firestorm over user privacy choices [POLL]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Privacy

Creative Commons photo of tracks in the snow courtesy of PöllöThe Apache Foundation, which oversees httpd, the world's most popular web server, has decided to ignore an important privacy setting for users of Microsoft's upcoming Internet Explorer 10 browser.

This feature, known as Do Not Track (DNT), allows users to express their preference to not be tracked by online advertising networks through the use of a header the browser sends every time you visit a website.

Implementing something as politically charged as DNT was going to be an uphill battle to begin with. The advertising industry is fighting a very delicate battle to find a way to avoid government regulation, yet still be able to track most users to support their existing revenue models.

In fact the senior privacy counsel for the largest online advertising company, Google, was quoted as saying:

"I don’t know what a do-not-track header is, I don’t know what it means."

I suppose that it is no surprise, then, that the only major browser without explicit support for DNT is Google's Chrome. Chrome users can install an extension if they wish to take advantage of the feature, though.

So back in May, Microsoft's announcement that it would enable the Do Not Track (DNT) header by default in Internet Explorer 10, which ships with Windows 8, placed the entire standard at risk before it was even agreed upon as a standard.

The controversy centers around this key point: The concept behind DNT, according to the Tracking Protection Working Group (TPWG), of which Microsoft is a member, is to represent a user's preference:

"Key to that notion of expression is that it MUST reflect the user's preference, not the choice of some vendor, institution, or network-imposed mechanism outside the user's control. The basic principle is that a tracking preference expression is only transmitted when it reflects a deliberate choice by the user. In the absence of user choice, there is no tracking preference expressed."

It goes on to clarify exactly how it should be implemented:

"A user agent MUST offer users a minimum of two alternative choices for a Do Not Track preference: unset or DNT:1. A user agent MAY offer a third alternative choice: DNT:0.

If the user's choice is DNT:1 or DNT:0, the tracking preference is enabled; otherwise, the tracking preference is not enabled."

Arguably this means a browser cannot force a user to make a choice, rather it must default to "unset." If the user later explicitly chooses whether or not to be tracked, this preference will then be transmitted to websites the user visits.

From the messages below, does it appear Microsoft is letting the user choose, or are they noncompliant with the TPWG proposed standards?

Windows 8 Express Settings for DNT

And if you choose Customize:

Windows 8 Customize privacy settings

Adding fuel to the fire, Adobe's Roy Fielding, a co-founder of the Apache HTTP Server Project, submitted a patch for httpd titled "Apache does not tolerate deliberate abuse of open standards," which instructs the Apache web server to ignore tracking preferences for users browsing with IE 10.

While this appears to be a stab at Microsoft for what Roy believes is a subversion of the intent of the agreed-upon standard, what it really does is put users at risk.

If I were using IE 10 and I explicitly chose the Do Not Track option, I would be extremely concerned if I discovered my preference was being ignored because of a political dispute.

Many social media users were pinning this decision on Adobe, so I contacted Wiebke Lips, Sr. Manager, Corporate Communications at Adobe. Lips responded in part:

"For your background, releasing this patch was a decision made by Apache, not Adobe. Roy Fielding wears multiple hats. His involvement on this patch relates to his work wearing his Apache hat."

She continued:

"In terms of the Tracking Protection Working Group and the DNT standard, Adobe believes that DNT should reflect a privacy choice by the consumer. Microsoft’s current settings eliminate that choice."

So it appears that Roy, Adobe, Apache and even Mozilla fault Microsoft in this dispute. Where do you stand on the issue?

And don't just make your vote - tell us why you made your choice by leaving a comment below.

Thanks for sharing your point of view!

Follow @chetwisniewski

Creative Commons photo of tracks in the snow courtesy of Pöllö.


View the original article here

Thursday, September 6, 2012

Google staffs up 'Red Team' to protect the world from its privacy lapses

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Privacy. Image from ShutterstockAfter agreeing earlier in the month to cough up a record $22.5 million in a settlement with the Federal Trade Commission for sneaking tracking cookies past Safari browsers' no-tracking controls, Google is creating a privacy "Red Team" to police its products' own privacy bugs and dangers.

The settlement is over Google's override of the cookie controls in Apple's Safari browser.

As the FTC explained, Google snuck around those controls by creating an invisible HTML form and then using JavaScript to pretend a user had submitted it.

Google thereby bypassed the browser's blocking of third-party cookies - i.e., those set by sites other than the ones a user originally visits.

The form was invisible and lacked either content or a Submit button, meaning the user could never have actually submitted it.

But Safari, duped into thinking the user had submitted a form, then allowed Google to place a DoubleClick cookie on the user's computer.

The FTC cried foul, charging Google with misrepresenting its use of tracking cookies and of breaking its privacy promises.

Now, Google's hiring a ninja - pardon me, make that a "back-end ninja" - to slap itself into privacy shape.

Specifically, a recently posted job listing advertises for a Data Privacy Engineer to join its team of privacy "back-end ninjas".

Google job advert

The task of the Google back-end ninja:

As a Data Privacy Engineer at Google you will help ensure that our products are designed to the highest standards and are operated in a manner that protects the privacy of our users. Specifically, you will work as member of our Privacy Red Team to independently identify, research, and help resolve potential privacy risks across all of our products, services, and business processes in place today.

Red teams are nothing new: the term refers to an independent group that serves to challenge an organization to keep it on its toes.

Penetration-testing is on Google's wish list, so the search empire is obviously planning to kick its own privacy tires.

The responsibilities are to:

Analyze software and services from a privacy perspective, ensuring they are in line with Google's stated privacy policies, practices, and the expectations of our users.

That sounds, actually, like whoever assumes the role will function as something of an ombudsman, watching out for the constituent interests of the user base.

Google to date hasn't done much to earn users' trust that even a large-ish fine will stop it from pulling egregious privacy shenanigans.

When Sophos's Paul Ducklin polled users, over 90% said that no, financial penalties are certainly not enough to make the online behemoths play ball on privacy.

Well, hiring a privacy red team certainly sounds like Google's on the road to improving a situation that led to its slipping ghost forms, cookies and ads past the blocks on users' browsers.

This time, let's hope Google's privacy promises aren't as empty as that Safari-bamboozling, empty HTML form.

Follow @LisaVaas

Privacy image from Shutterstock.

Tags: browsers, Data Privacy Engineer, DoubleClick, Federal Trade Commission, fine, ftc, Google, job listing, Red Team, Safari, settlement


View the original article here

Friday, August 17, 2012

Creepy Quora erodes users' privacy, reveals what you have read

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

QuoraThe Quora website launched two years ago, collating questions-and-answers on a variety of topics and receiving favourable write-ups in the media.

It's possible that you were one of the early sign-ups to the service, investigating whether you would find it useful, and don't visit the site much very often. Or you could be one of the die-hard Quora lovers who still gets value out of the site's community.

Question on Quora

But there's something that all Quora users should know.

Earlier this month, Quora made a decision which changes your privacy on the site. And they did it without asking your permission first.

They decided to introduce "Views" - functionality which creepily reveals to others the articles you have been reading.

Views on a Quora article

In a trick presumably learnt from a chorus of other uncaring social networking sites, Quora has left it up to the user to turn off the "Views" feature (opt-out) rather than the much more privacy-friendly alternative of asking users to opt-in if they really want others to see what articles they have read.

As we've said many times before - if a feature really is a huge benefit to the user, why do websites have so little confidence that they can encourage users to opt-in rather than thinking it's alright to reduce privacy without asking first?

Now, you may think - why would I care if people can see what questions I have read on Quora?

Well, here's a few examples of the kind of things you could have read:



Still comfortable?

Sandra Liu Huang, a product manager at Quora, tried to justify why the site enabled the "Views" feature by default in a CNET interview:

"It will help writers get feedback to improve the content they write. If it were an opt-in product it wouldn't be as useful to writers because not enough people may go turn it on. It will improve the content and help readers discover useful and interesting content more quickly."

If you don't like the idea of other people seeing what you are reading you have two options:

1) You can change your Quora account settings, by visiting Profile/Settings/Views and choosing "No". (This is the option that Quora enabled without asking your permission)

Quora settings

2) Another option, of course, is to delete your account. Quora helpfully provides a Q&A about how to delete your Quora account.

At the time of writing, over 1800 people have read the deletion article.

1800+ users have viewed how to delete their Quora account

What do you think about this new feature of Quora?

Was there a better way for Quora to introduce the technology?

Should people be concerned that it was turned on by default, or are we living in the dark ages by being worried about this kind of thing?

Leave a comment below and let us know your thoughts.

Follow @gcluley

View the original article here

Thursday, August 16, 2012

Vote in our poll: is Google's fine of $22.5 million enough to buy privacy?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

An apparently unrepentant Google has agreed to cough up $22.5 million to the US Federal Trade Commission (FTC) to dispose of charges that it "misrepresented privacy assurances to users of Apple's Safari browser."

As with my previous story about Google and its WiFi trawling, we need a timeline summary to keep track (no pun intended) of what's been going on here:

* In February 2010, Google launched Buzz, a social networking application for Gmail.

The launch drew the ire of of those concerned about privacy, and a class action lawsuit arose alleging that Google "automatically enrolled Gmail users in Buzz, and that Buzz publicly exposed data, including users' most frequent Gmail contacts, without enough user consent."

* In November 2010, Google paid $8.5 million to settle the class action.

As we reported back then, Google didn't pay out nickels-and-dimes to each offended individual in the class action, but agreed to put the lump sum "into an independent fund to "support organisations promoting privacy education and policy on the web."

* In March 2011, Google apologised to Buzz users and settled with the FTC.

The settlement included an agreement by Google to implement a comprehensive privacy program that includes privacy and data protection audits by an independent third party every two years for the next 20 years. Google's apology certainly sounded pretty straight-from-the-hip, telling you that:

User trust really matters to Google. That's why we try to be clear about what data we collect and how we use it — and to give people real control over the information they share with us.

* In December 2011, the FTC busted Google using sneaky web coding to bypass Safari's cookie policy.

Briefly explained in a neat technical posting from the FTC itself, Google overrode Safari's cookie controls to bypass the browser's regular behaviour of blocking so-called third party cookies. (That's a cookie which is set by a site other than the original one you visited.)

Google achieved this by creating an invisible HTML form and then using JavaScript to pretend that the user had submitted it. This caused Safari to process the third-party page, and, by extension, its cookies, at the same trust level as the first-party page. The FTC understandably considered this dubious, not least because the HTML form had neither content nor a Submit button.

So much for giving people "real control over the information they share with us."

* In August 2012, Google agreed to pay $22.5 million to the FTC.

The FTC's argument against Google was simple: the company hadn't lived up to the privacy promises it made to its consumers.

And there you have it. What more to say?

Google will cough up $22.5 million for putting sneaky code into its web pages, even after agreeing that it would get comprehensive about privacy.

Nevertheless, according to reports, Google's public response seems unrepentant - or at least unapologetic - and comes close to dismissing the issue as old, tired and unimportant. The BBC, for example, quotes a Google spokesman as saying: "The FTC is focused on a 2009 help centre page published more than two years before our consent decree, and a year before Apple changed its cookie-handling policy."

Optimistically, the BBC goes on to report the comments of Nick Pickles, director of privacy campaign group Big Brother Watch:

The size of the fine in this case should deter any company from seeking to exploit underhand means of tracking consumers. It is essential that anyone who seeks to over-ride consumer choices about sharing their data is held to account.

To be sure, $22.5 million is a lot of money.

But Google already forked out $500 million in August 2011 for helping illegal vendors of pharmaceuticals to place ads on its servers. Not just for taking the scammers' money, you understand, but for helping these "customers" to bypass the controls Google had already put in place to prevent the abuse.

So...is the money enough? Or is Google just treating the penalty as part of its cost of doing business?

Have your say in our poll.


-
Follow @duckblog
-

View the original article here