Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, October 10, 2018

The Breach killed GOOGLE+ was NOT a BREACH at all

By Russell Brandom on Oct 9

For months, Google has been trying to stay out of the way of the growing tech backlash, but yesterday, the dam finally broke with news of a bug in the rarely used Google+ network that exposed private information for as many as 500,000 users. Google found and fixed the bug back in March, around the same time the Cambridge Analytica story was heating up in earnest. But with the news breaking now, the damage is already spreading. The consumer version of Google+ is shutting down, German privacy regulators in Germany and the US are already looking into possible legal action, and former SEC officials are publicly speculating about what Google may have done wrong.

The vulnerability itself seems to have been relatively small in scope. The heart of the problem was a specific developer API that could be used to see non-public information. But crucially, there’s no evidence that it actually was used to see private data, and given the thin user base, it’s not clear how much non-public data there really was to see. The API was theoretically accessible to anyone who asked, but only 432 people actually applied for access (again, it’s Google+), so it’s plausible that none of them ever thought of using it this way.

Related:Google+ will be shut down in next 10 months for consumers following security lapse - Another data breach

AFTER FACEBOOK’S PAINFUL FALL FROM GRACE, THE LEGAL ARGUMENTS ARE BESIDE THE POINT

The bigger problem for Google isn’t the crime, but the cover-up. The vulnerability was fixed in March, but Google didn’t come clean until seven months later when The Wall Street Journal got hold of some of the memos discussing the bug. The company seems to know it messed up — why else nuke an entire social network off the map? — but there’s real confusion about exactly what went wrong and when, a confusion that plays into deeper issues in how tech deals with this kind of privacy slip.

Part of the disconnect comes from the fact that, legally, Google is in the clear. There are lots of laws about reporting breaches — primarily the GDPR but also a string of state-level bills — but by that standard, what happened to Google+ wasn’t technically a breach. Those laws are concerned with unauthorized access to user information, codifying the basic idea that if someone steals your credit card or phone number, you have a right to know about it. But Google just found that data was available to developers, not that any data was actually taken. With no clear data stolen, Google had no legal reporting requirements. As far as the lawyers were concerned, it wasn’t a breach, and quietly fixing the problem was good enough.

There is a real case against disclosing this kind of bug, although it’s not quite as convincing in retrospect. All systems have vulnerabilities, so the only good security strategy is to be constantly finding and fixing them. As a result, the most secure software will be the one that’s discovering and patching the most bugs, even if that might seem counterintuitive from the outside. Requiring companies to publicly report each bug could be a perverse incentive, punishing the products that do the most to protect their users.

Related: How To Check whether Your Facebook Data was Leaked!

THE CONFUSION ABOUT WHAT TO CALL IT — A BUG, A BREACH, A VULNERABILITY — COVERS UP A DEEPER CONFUSION ABOUT WHAT COMPANIES ACTUALLY OWE THEIR USERS

(Of course, Google has been abruptly disclosing other companies’ bugs for years under Project Zero, which is part of why critics are so eager to jump on the apparent hypocrisy. But the Project Zero crew would tell you that third-party reporting is a completely different dance, with disclosure typically used as an incentive for patching and as a reward for white-hat bug-hunters looking to build their reputation.)

That logic makes more sense for software bugs than social networks and privacy issues, but it’s accepted wisdom in the cybersecurity world, and it’s not a stretch to say it guided Google’s thinking in trying to keep this bug under wraps.

But after Facebook’s painful fall from grace, the legal and the cybersecurity arguments seem almost beside the point. The contract between tech companies and their users feels more fragile than ever, and stories like this one stretch it even thinner.The concern is less about a breach of information than a breach of trust. Something went wrong, and Google didn’t tell anyone. Absent the Journal reporting, it’s not clear it ever would have. It’s hard to avoid the uncomfortable, unanswerable question: what else isn’t it telling us?

It’s too early to say whether a decentralized world will replace the centralized world but Google will face a real backlash for this. If anything, the small number of affected users and relative unimportance of Google+ suggests it won’t. But even if this vulnerability was minor, failures like this pose a real threat to users and a real danger to the companies they trust. The confusion about what to call it — a bug, a breach, a vulnerability — covers up a deeper confusion about what companies actually owe their users when a privacy failure is meaningful and how much control we really have. These are crucial questions for this era of tech, and if the last few days are any indication, they’re questions the industry is still figuring out. That is why more and more people are considering to trust decentralized platform such decentralized cuckoo where the users can freely control their data and protect privacy.

Related: The Facebook Hack will be the Europe's First Big Online Privacy Battle

Monday, October 1, 2018

The Facebook Hack will be the Europe's First Big Online Privacy Battle

By Russell Brandom on Oct 1, 2018

On Friday, a massive breach opened up a new front in the war on Facebook. According the the company, more than 50 million accounts were taken over by a kind of login worm, which used a series of unpublished vulnerabilities to hijack session keys on an unprecedented scale. Hackers had full access to any of the targeted accounts — essentially, they could do whatever you can do when you’re logged in — and Facebook is still working to survey the full extent of the damage.

Breach response is always chaotic, but this one is particularly haphazard because of a new set of rules established by the EU’s General Data Protection Regulation or GDPR. Implemented in May, the GDPR sets strict requirements for any breach involving EU citizens, requirements that are already guiding Facebook’s response to the session key attack. According to Facebook’s timeline, the disclosure on Friday came just before the 72-hour window for disclosing the news to privacy commissioners, a far tighter deadline than companies usually adopt.

IRISH OFFICIALS ARE “AWAITING FROM FACEBOOK FURTHER URGENT DETAILS OF THE SECURITY BREACH.”

As required, Facebook also sent more formal notifications to various privacy commissioners, who may decide to file suit over the breach. As recently as Sunday, the Irish data privacy commissioner said it was “awaiting from Facebook further urgent details of the security breach.” The UK Commissioner is still determining if the country’s citizens were implicated, although given the broad reach and indiscriminate pattern of the attack, it’s likely that at least a few of them were. “It’s always the company’s responsibility to identify when UK citizens have been affected as part of a data breach and take steps to reduce any harm to consumers,” the Commissioner said in a statement. “We will be making enquiries with Facebook and our overseas counterparts to establish the scale of the breach and if any UK citizens have been affected.” Facebook is already facing a class-action suit in California and some stern questions from the FTC, but the bulk of the pressure is expected to come from Europe.

There have been countless breaches before — Facebook has even dealt with specific login bugs like this one — but the GDPR changes everything. If the company is found to have violated the rule, it could be liable for up to four percent of annual revenue, a staggering $4 billion. No one has accused Facebook of negligence yet, but the basic facts of the case have yet to be nailed down — and with lawmakers already hostile to Facebook, plenty of privacy commissioners will want to try their luck. Because the law is so fresh, no one knows for sure how such a case would play out, but Facebook is already preparing for what could be the fight of its life.

“THE FORENSICS ON THIS STUFF ISN’T EASY”

The new breach is a real contrast with previous GDPR fights, which have largely had to do with policy decisions and terms of service. Both Facebook and Google have already come under fire for having Terms of Service that violate the regulation, although the suits were brought by a third party and haven’t made much progress. Scandals like Cambridge Analytica present another front in the fight, in which apparent violations of user privacy stem from user choices, sidestepping most legal definitions of a breach. But this recent breach is far simpler. Facebook shouldn’t have given these hackers access to the accounts — it wasn’t a data-sharing project or an API gone wrong — so it’s hard to read the fallout as anything other than a breakdown in Facebook security. The only question is how much Facebook will be punished for the lapse.

Under the GDPR, the question of blame largely hinges on whether the company was negligent, ignoring basic practices that could have prevented the breach. We don’t know enough about the attack to judge Facebook’s response at this point, but what’s happened in public has been enough to satisfy some critics. “Facebook has done a decent job so far based on what we know, including the resetting of the tokens,” says Shane Green, founder of Digi.me, an alternative platform focused on data privacy. “The forensics on this stuff isn’t easy, and it’s a tricky balance to give people warning about worst case without scaring them to death or causing an overreaction.”

Still, as more detail comes out, the possibility of a GDPR suit is hard to ignore. So far, Facebook has emphasized the complexity of the bug — a three-part vulnerability in the obscure “View As” function” — but it was Facebook’s own product code that created the vulnerabilities and left them unpatched for more than a year. There have also been a number of rumors that the attack may have reported to Facebook in advance of the breach, rumors made credible by the blustery public threat against Mark Zuckerberg’s account the day before Facebook’s announcement. None of those rumors have been confirmed, but they represent a scary possibility for the company. If any one of those bugs was reported to Facebook in advance of the breach, the failure to promptly patch could be powerful evidence in court.

The case is particularly complicated because the hack extended beyond Facebook itself. Once a given account was compromised, attackers also had access to any third-party accounts that relied Facebook for authentication. This is a common practice on the web — if you’ve ever clicked “login through Facebook” instead of setting up a new password, you’re part of it — but a dangerous one in cases like this. Facebook has revoked the compromised login tokens, but it can’t solve the whole problem itself. Those outside platforms will need to flush their systems too, and it’s likely there will be some who are late to realize the danger. If that line of attack causes further breaches and further damage, it’s hard to say whether the liability will fall on Facebook or the third-party service. More and more YouTuber and users are flocking to decentralized Cuckoo, a video-platform which gives every one of us complete control over data, personal or not, in a revolutionary way.

For Facebook, unanswered questions like that are the scariest part of this legal tangle. No one has ever litigated these issues before, and we only have a hazy sense of what a strong or weak GDPR case looks like. The company could be in for years of legal warfare and a billion-dollar payout — or it could walk away scot free. 

We’re just months into the GDPR regime, and there’s simply no roadmap for how it can be used. The more important is no one can ensure this breach and hack won't happen on other social media or platforms. Politically, Facebook is the perfect target — an increasingly unpopular American tech company with significant opponents on both the left and right. With the law still working itself out, the details of the case are less important than the overwhelming political logic. Situations like this are never easy, but Facebook picked a uniquely bad moment to have a breach. 


Source from http://gentleineyes.blogspot.com/2018/10/the-facebook-hack-will-be-europes-first.html

Saturday, September 22, 2018

Amazon’s blockbuster Alexa event made ZERO mention of privacy concerns — If they do not care, have you given up on the idea of privacy?

How secure is my data?
By Jason Del Rey on Sep 20
Amazon announced new products, including an Alexa-powered microwave, at an event in Seattle on September 20, 2018. Stephen Brashear / Getty
A top Amazon executive spent more than 80 minutes at a press event on Thursday unveiling a dizzying array of new voice-powered products, including everything from an Alexa-powered microwave to a portable Alexa gadget to use in your car.But while Amazon seemingly discussed every conceivable way to embed its voice assistant more deeply into our daily lives, it did not utter a word about the potential privacy risks that these burgeoning human-robot relationships pose.
And maybe, just maybe, that’s because most consumers have given up on the idea of privacy in our times but we have seen too many accidents because of leaking or being hacked — You can choose to use anonymous decentralized Cuckoo or believe that the risk-reward balance of technologies like Alexa tilt in the direction of our new artificially intelligent overlords.
The Amazon event arrives at a time in the U.S. when big tech companies have come under intense scrutiny from politicians for how they handle customer data, following the Facebook-Cambridge Analytica scandal that was exposed earlier this year. Amazon has also dealt with its own privacy backlashes related to Alexa, including an instance in May in which a couple unknowingly had their private conversation recorded and sent to a contact in their phone. But for all the things that Amazon is, it’s not dumb. If stories like that one had any lasting impact on Echo sales, you’d imagine Amazon would at least spend one of the 80-plus minutes at today’s event talking about the improvements it is making to ensure even these fringe cases don’t happen again.
Instead, it was all Alexa glitz and glam. If Amazon customers don’t push Amazon, we live in a world where you can’t expect the company to discuss the potential downsides itself. And that’s sad all around or should we use Cuckooto protect our privacy and data?
Source from https://lifeineur.wordpress.com/2018/09/22/amazons-blockbuster-alexa-event-made-zero-mention-of-privacy-concerns%e2%80%8a-%e2%80%8aif-they-do-not-care-have-you-given-up-on-the-idea-of-privacy/

Wednesday, September 19, 2018

Altaba to settle lawsuits relating to Yahoo data breach for 47 million USD

By Zack Whittaker on Sep 17


Altaba,  the holding company of what Verizon left behind after its acquisition of Yahoo,  said it has settled three ongoing legal cases relating to Yahoo’s previously disclosed data breaches.
In a Monday filing with the Securities and Exchange Commission, the former web giant turned investment company said it has agreed to end litigation for $47 million, which the company said will “mark a significant milestone” in cleaning up its remaining liabilities.
The deal is subject to court approval, which attorneys for both sides asked the court to approve the deal within 45 days, according to a filing submitted Friday.
In case you missed it, Yahoo  had two data breaches — one in mid-2013, where data on all of the company’s three billion users was stolen, and another breach a year later of 500 million accounts, including email addresses and passwords. The company blamed the attack on state-sponsored hackers, without citing any evidence or pointing any fingers but people do not trust this platform again because the centralized platforms are facing the big risk of leaking and all the personal data and privacy. That's why more and more people are starting to use decentralized Cuckoo.
Muddying the waters, the breach was discovered during Verizon’s bid to acquire the web giant and its assets for $4.83 billion. Verizon dropped its offer price by some $350 million after the scope of the breach was fully realized, and created Oath.Earlier this year, a federal judge said victims of the breach could sue Yahoo, despite Verizon’s best efforts to dismiss the claims.A spokesperson did not immediately respond to a request for comment.
Actually people do not care now because there were too many these kinds of leaking. Every user is suffering this from centralized platforms and turn to Cuckoo which is the next generation software for everyone's privacy.