Google Search

Sunday, November 20, 2011

Facebook will no longer tell you everything it knows about you

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Facebook CDIn the face of an ocean of users demanding their personal data as required by European Union law, Facebook has sharply constricted the amount of data it's handing over.

Instead of sending CDs, Facebook is now directing users to a page where they can download a personal archive, but that archive is now covering only 22 categories — less than half of the 57 categories received by early requesters in the Europe vs. Facebook campaign, according to a report from ITworld.

The new stinginess comes in the midst of an audit by Ireland's Data Protection Commissioner. The audit is the result of 22 privacy-based complaints (to view the list of complaints, go to Kim Cameron's Identity Weblog) lodged by Europe vs. Facebook.

That campaign is led by Max Schrems, a 24-year-old law student from Vienna who secured 1,200 pages of personal data on a CD months ago by using a European requirement that entities with data about individuals make it available to those individuals if they request it.

The Irish agency is auditing Facebook for compliance with the country's Data Protection Acts of 1988 and 2003, which transpose the E.U.'s Data Protection Directive, known as 95/46/EC.

Europe vs. Facebook contends that Facebook is withholding personal data in violation of these laws, which require companies to disclose data to users on request.

Lisa McGann, a senior investigations officer, on Tuesday told IDG News Service that the agency has received an additional 150 complaints about Facebook’s inadequate response to data requests and 10 complaints over data protection, according to ITworld.

Stack of emailMr. Schrems told ITworld that he’s exchanged e-mails with Richard Allan, Facebook's director of European public policy, who’s indicated that Facebook is contemplating a system modification that would allow a more in-depth batch of information if the agency finds fault in the company's current strategy.

In the meantime, Facebook is throttling back the data volume it releases. While Facebook is defending its actions, claiming that it is "fully compliant with E.U. data protection laws," the categories of data it’s releasing has nosedived.

Mr. Schrems told ITworld that the CDs Facebook initially sent out when he and others first requested their personal Facebook dossiers contained 57 categories of data. Now, Mr. Schrems said, Facebook is excerpting between 19 and 24 categories of data.

In addition to cutting back on the data it releases, Facebook has turned to a do-it-yourself model. Facebook recently created an email address, datarequests@fb.com, for people to request data. An autoreply from that account directs users to an archive download tool.

Facebook Download Archive site

The autoreply also curtly snips off further conversation, stating that “We will not enter into further correspondence about your specific data through this email address.”

The latest move by Facebook is just "a way of getting rid of people," Mr. Schrems told ITworld, since more transparency would "freak people out," he said.

Facebook, if what Mr. Schrems believes is correct, I’d like to propose that you’re wrong. More transparency would have the opposite effect to freaking us out.

As it is, we’re already freaked out. Hundreds of legal complaints are a visible symptom of freak-out.
What’s going to continue to freak us out is if you keep tightening your sphincter.

The more tight-fisted you are with our personal data, the more you will cause your users to suspect that you plan to do things with it that we would rather you didn't.

If you're on Facebook and want to keep informed about privacy issues, scams and internet attacks, join the Sophos page on Facebook, where over 150,000 people regularly share information on threats and discuss the latest security news.

Follow @lisavaas

View the original article here

US SCADA infrastructure woefully unprotected

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Creative Commons photo of water tower courtesy of christinejwarner's Flickr photostreamIt has been reported that a SCADA systems failure at a municipal water processing plant may have been caused by hackers infiltrating their network.

The attackers were repeatedly turning a pump on and off until it caused the pump to fail, raising an alert to the operators.

Upon investigation they determined that attackers may have infiltrated the system starting in September 2011, although the attack wasn't discovered until November 8th, 2011.

The notice about the attack noted that it was similar to an attack against the Massachusetts Institute of Technology earlier this year which exploited bugs in the open source software phpMyAdmin.

Reading about this my spidey-sense was tingling... What? They have SCADA control systems hooked up to the public internet? And they are running phpMyAdmin!?!?

I run a reasonably low profile, small website for myself and some friends and at one point had installed phpMyAdmin to assist them with daily SQL management chores.

I removed it four years ago after a never ending stream of severe vulnerabilities made it too risky for my *play* site.

According the the National Vulnerability Database phpMyAdmin has at least 105 reported security vulnerabilities.

It would appear it is common practice these days to connect these sensitive critical infrastructure systems to the public internet and use COTS (Common Off The Shelf) software to manage them.

Convenience and price are always desirable to those responsible for managing these systems, but this is bordering on criminally negligent when you are responsible for our water, power, gas and other sensitive utilities.

The Department of Homeland Security needs to do a top-down audit of these systems and mandate that these insecure practices come to an end.

Within hours of the news breaking on this story a hacker known as pr0f posted images of internal SCADA control systems from the City of South Houston, Nevada.

City of South Houston SCADA system

He insists he hasn't interfered with their operations and is just releasing the information to draw attention to the problem.

Of course that doesn't change the fact that accessing these systems is still a criminal act under the Computer Fraud and Abuse Act.

We may already be at a crisis point with regards to our infrastructure security, but perhaps these stories will be a wake up call for those managing similar systems around the world.

Creative Commons photo of a water tower courtesy of christinejwarner's Flickr photostream.

http://twitter.com/chetwisniewski

View the original article here

UK police foiled attack on royal wedding website

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Creative Commons photo of Will and Kate courtesy of anonlinegreenworld's Flickr photostreamPolice detained a 16-year-old on Oct. 10 in relation to "a suspected attempt to encourage others to commit a distributed denial-of-service attack," according to a spokesman from the cybercrime unit who was quoted in a report from the Associated Press. The spokesman also said that the teenager is out on bail and has not yet been charged.

The unit’s chief, Det. Supt. Charlie McMurdie, mentioned the coup in an address to attendees of the Royal United Services Institute, a defense think tank.

A DDoS would have kicked Britain in the knees. Some providers at the time have said the April 29 wedding may have been the most heavily live-streamed event ever, though the death of Osama bin Laden is said to have since surpassed it.

The official royal wedding website said that, at its peak, it was handling more than 2,000 requests per second.

The popularity of the event did, in fact, crash the BBC’s site, which went down for 17 minutes of prime nuptial time. The Guardian at the time noted that Twitter feeds from users complained of being unable to watch live streaming from Westminster Abbey.

ABC put the record-breaking Internet burden into perspective with these statistics, all as of the date of the wedding:

In the seven days preceding, 2.1 million tweets concerning the event were sent.In the United States alone, more than 1.75 million Facebook comments mentioning the term “royal wedding” were made over the preceding month.More than 800,000 people watched "Royal Wedding Invitation," an official wedding video, as of April 29.The name of Kate’s hair piece—“fascinator”—saw a 70 percent increase in Google searches worldwide over the preceding month.The search term "What Is Prince Williams Last Name" saw a 1,199 percent increase in Yahoo searches in the preceding week.YouTube users uploaded 5,000 videos tagged "royal wedding" over the preceding week.

McMurdie told the conference attendees that action was taken to safeguard the royal wedding’s official site, which received 15 million hits on the wedding date. When the the AP asked for more details, she said her unit had "been called in" to deal with an attack.

LOICIt’s not hard to find a teenager who knows how to launch a DDoS nowadays. As Sophos’s Graham Cluley has written, many Internet users have been urged to voluntarily join a botnet by downloading a DDoS attack tool called LOIC (Low Orbit Ion Cannon, described in this detailed analysis by Sophos's Vanja Svajcer).

But just because it’s easy doesn’t mean it won’t send you to jail if you get caught. Messing around with DDoS has sent multiple U.S. citizens to the klink, for example.

One such, Mitchell L. Frost, was given a 30-month prison sentence at the tender age of 23 for a series of DDoS attacks he launched against the websites of Bill O'Reilly, Ann Coulter and Rudy Giuliani.

Will this 16-year-old get just a slap on the wrist because of his even more tender age?

Maybe. But it’s sure not worth the risk. Teenagers with cyber skills would be far better off spending their early years doing something constructive with their talent.

Creative Commons photo of Will and Kate courtesy of anonlinegreenworld's Flickr photostream.

Follow @LISAVAAS Be the first to like this post.

View the original article here

Will Do Not Track make a difference to web privacy?

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Filed Under: Featured, Privacy

Private signEarlier this week the World Wide Web Consortium (W3C) released the first drafts of two new privacy standards aimed at simplifying and standardising how websites read and comply with web users’ privacy settings.

The Tracking Preference Expression and Tracking Compliance and Scope standards define a ‘Do Not Track’ (DNT) mechanism that will allow users to opt out of the sort of tracking increasingly used for web analytics and behavioural advertising.

The W3C working group who produced the draft included representatives from some of the web’s biggest companies including Apple, Google and Facebook.

It's not unusual for these organisations to take part in drafting W3C standards but I wonder if some of them are feeling a slight conflict of interest. Agreeing to a Do Not Track standard could obviously have a negative impact on organisations like Google and Facebook who rely on targeted advertising.

Perhaps they feel it's better to be inside the tent or perhaps, as the draft suggests, DNT is in the interests of advertisers because annoying their users is counter-productive.

Or perhaps, as some cynics suggests, an answer can be found in the timing of the release of the finished version of the DNT standard.

European CommissionBack in June the European Commission told the technology industry in no uncertain terms that if it didn’t agree a Do Not Track standard by the midde of 2012, it would be forced to act.

Coincidentally the final recommendation of the DNT standard is scheduled for 2012.

A slew of controversies across Europe and the US may also have convinced the industry that it is better off regulating itself than being policed or dictated to by law makers.

So will the advent of DNT-enabled browsers usher in an age of web browsing without being tracked and targeted?

The new standard says that if a browser is incapable of issuing Do No Track instructions then it should be handled as if it has opted-out of Do Not Track rather than opted-in. So users will need to upgrade to a new generation of DNT compliant browsers to get the ball rolling.

Of course just because a browser can do something it doesn't mean it will. I don't know yet if the browser vendors are intending to switch DNT on by default but Firefox, which already implements its own version of DNT, currently has it off by default.

Firefox do not track option - off by default

And then finally, once we have a generation of DNT browsers in-the-wild we'll need a generation of DNT compliant websites and applications to go with them. Perhaps once there is final recommendation in place the law makers will do us all a favour and rattle their sabres again.

You can probably tell that I'm not holding my breath on this one.

When DNT does become commonplace there will surely be a lot of money to be made in successfully working around it.

We've already seen some very inventive tactics from advertising and analytics companies looking to work around users who who delete their cookies.

CookiesSince tracking tends to rely on cookies you might think that deleting them would be enough to prevent it. Sadly it's not. Researchers have shown that advertisers can work around users who delete their cookies by using Flash cookies or HTML 5 storage for the same purpose. Most creepily they can even resurrect delete cookies zombie-like using ETags.

However rocky the road to adoption is though the W3C and the organisations in the working group deserve praise for delivering a simple standard.

At its heart DNT is a simple on/off toggle. Hopefully this will make it easy for privacy concious web-users to define the information they want to share with advertisers and online business. As Lisa Vaas explained earlier this month current privacy tools fail users not because they don't work, but because they are incredibly difficult to use.

Follow @MarkStockley

View the original article here

Saturday, November 19, 2011

Don't fall for the Recovering American Soldier hoax

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

US stampI've seen a post flying around Facebook (and so have others, thanks to those Naked Security readers who send us tips!) that for all intents and purposes, has its heart in the right place:

When filling out your Christmas cards this year, take ONE CARD and SEND it to this address: A Recovering American Soldier, c/o Walter Reed Army Medical Center, 6900 Georgia Avenue, NW Washington, DC 20307-5001. If we pass this on and everyone sends one card, think of how many cards these soldiers could get to bring up their spirits! Feel free to repost. This is a wonderful thing to do !!

This sounds so wonderful, doesn't it? The small problem here is sadly this is a hoax.

The US Postal Service will not accept any mail addressed to "Any Soldier", "Any Wounded Soldier" etc.

According to Snopes, the Walter Reed Army Medical Center agrees. So while people are well-meaning by reposting this story, the cards would either be returned to the sender or sent to the Dead Letter Office.

This hoax has been around for some time and is well documented, but it seems to come back around every year and clutter the inboxes and feeds of folks.

Now before I'm accused of being a Scrooge, there *is* a legitimate program for those who wish to partake. It's called "Holiday Mail for Heroes" and is sponsored through the Red Cross and Pitney Bowes.

Don't forget you should join the Sophos Facebook page, where we not only debunk hoaxes and chain letters, but we also keep you up-to-date on the latest rogue applications, scams and malware attacks threatening Facebook users.

Follow @SophosLabs

View the original article here

FBI investigates Santa Clara University hack which changed exam grades

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

A plus gradeThe FBI is investigating a hack against Santa Clara University's computer system, after someone broke into the network and changed the grades of some undergraduate students.

Officials at the University say that they have reviewed tens of thousands of records dating back to 2000, and have identified a number of unauthorised changes in grades belonging to a small number of current students and about 60 former undergraduates.

Some grades are said to have been changed from an "F" to an "A".

25-year-old electrical engineering student Mark Loiseau tweeted that three FBI agents arrived to question him in his off-campus apartment, brandishining hundreds of pages of his Verizon cellphone records.

Tweets from Mark Loiseau

According to the San Jose Mercury News, Loiseau has denied any involvement in the hack.

The security breach is believed to have taken place between June 2010 and July of this year, according to University President Michael Engh. Fortunately, he claims that no evidence has been found that the personal information of students or staff was accessed.

Dennis Jacobs, Santa Clara University's provost and vice president for academic affairs says that that the institution is taking the security breach seriously and that the university is "reviewing and enhancing all security measures to reduce the likelihood of any intrusion in the future."

No arrests have yet been made by the authorities, but the natural suspicion must be that a current or former student may be responsible for the hack. It's essential that all young people learn that breaking without permission into computer systems is not a prank, and that the integrity of other people's data needs to be treated with respect.

Of course, it's far from the first time that schools have found themselves in the firing line of hackers - I'm reminded, for instance, of the case of the American teenager who was accused of installing spyware onto school computers or the Indian Minister who blamed a virus for incorrect exam results.

No doubt this won't be the last time we hear about educational establishments find themselves dealing with cybercrime on their doorstep.

Follow @gcluley

View the original article here

NASA hacker arrested, perhaps it is time for some defense?

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Creative Commons photo courtesy of Keith Allison's Flickr photostreamRomanian police arrested Robert Butyka of Cluj Napoca for hacking into NASA servers beginning in December of 2010.

Butyka, who goes by the handle Iceman, is accused of unauthorized access to NASA systems, possession of hacking tools and causing the deletion, modification and restricting access to data.

The charges allege that the damages caused by his attack cost approximately $500,000.

Butyka is being held for 24 hours pending further review of the case and the computers seized from his residence.

This isn't the first time NASA has been hacked, as many of our readers will recall this is what originally got British hacker Gary McKinnon in touch with the long arm of the law.

If NASA is repeatedly being hacked to the tune of half a million dollars plus each time, shouldn't we be asking serious questions about the security of their systems?

While I agree that unauthorized access to a system is a punishable offense, isn't there an even bigger problem lurking behind the firewalls at Cape Canaveral?

By my calculations $500,000 buys you a few top notch security experts with a fair bit of money left over for tools/software.

NASA logoOf course this has happened multiple times, so perhaps we have a million or two to play with.

Wasting FBI and international law enforcement resources to continually track down attackers is a massive waste of money.

If Butyka is guilty he should be punished, but we should be asking some serious questions of the administrators at NASA.

I'm afraid the old expression "An ounce of prevention is worth a pound of cure" is something that should be discussed a little more often at NASA IT security.

Creative Commons photo of handcuffed suspect courtesy of Keith Allison's Flickr photostream.

Follow @chetwisniewski

View the original article here