Showing posts with label security breach. Show all posts
Showing posts with label security breach. Show all posts

Tuesday, October 2, 2018

Can you believe Facebook or other platforms keep you safe?

By Devin Coldewey on Oct 1, 2018
Another day, another announcement from Facebook that it has failed to protect your personal information. Were you one of the 50 million (and likely far more, given the company’s graduated disclosure style) users whose accounts were completely exposed by a coding error in play for more than a year? If not, don’t worry — you’ll get your turn being failed by Facebook . It’s incapable of keeping its users safe.
Facebook has proven over and over again that it prioritizes its own product agenda over the safety and privacy of its users. And even if it didn’t, the nature and scale of its operations make it nearly impossible to avoid major data breaches that expose highly personal data.
For one thing, the network has grown so large that its surface area is impossible to secure completely. That was certainly demonstrated Friday when it turned out that a feature rollout had let hackers essentially log in as millions of users and do who knows what. For more than a year.
This breach wasn’t a worst case scenario exactly, but it was close. To Facebook it would not have appeared that an account was behaving oddly — the hacker’s activity would have looked exactly like normal user activity. You wouldn’t have been notified via two-factor authentication, since it would be piggybacking on an existing login. Install some apps? Change some security settings? Export your personal data? All things a hacker could have done, and may very well have.
This happened because Facebook is so big and complicated that even the best software engineers in the world, many of whom do in fact work there, could not reasonably design and code well enough to avoid unforeseen consequences like the bugs in question.
I realize that sounds a bit hand-wavy, and I don’t mean simply that “tech is hard.” I mean that realistically speaking, Facebook has too many moving parts for the mere humans that run it to do so infallibly. It’s testament to their expertise that so few breaches have occurred; the big ones like Cambridge Analytica were failures of judgment, not code.
A failure is not just inevitable but highly incentivized in the hacking community. Facebook is by far the largest and most valuable collection of personal data in history. That makes it a natural target, and while it is far from an easy mark, these aren’t script kiddies trying to find sloppy scripts in their free time.
Facebook itself said that the bugs discovered Friday weren’t simple; it was a coordinated, sophisticated process to piece them together and produce the vulnerability. The people who did this were experts, and it seems likely that they have reaped enormous rewards for their work.
The consequences of failure are also huge. All your eggs are in the same basket. A single problem like this one could expose all the data you put on the platform, and potentially everything your friends make visible to you as well. Not only that, but even a tiny error, a highly specific combination of minor flaws in the code, will affect astronomical numbers of people.
Of course, a bit of social engineering or a badly configured website elsewhere could get someone your login and password as well. This wouldn’t be Facebook’s error, exactly, but it is a simple fact that because of the way Facebook has been designed — a centralized repository of all the personal data it can coax out of its users — a minor error could result in a total loss of privacy.
I’m not saying other social platforms could do much better. I’m saying this is just another situation in which Facebook has no way to keep you safe.
And if your data doesn’t get taken, Facebook will find a way to give it away. Because it’s the only thing of value that they have; the only thing anyone will pay for.
The Cambridge Analytica scandal, while it was the most visible, was only one of probably hundreds of operations that leveraged lax access controls into enormous data sets scraped with Facebook’s implicit permission. It was their job to keep that data safe, and they gave it to anyone who asked.
It’s worth noting here that not only does it only take one failure along the line to expose all your data, but failures beyond the first are in a way redundant. All that personal information you’ve put online can’t be magically sucked back in. In a situation where, for example, your credit card has been skimmed and duplicated, the risk of abuse is real, but it ends as soon as you get a new card. For personal data, once it’s out there, that’s it. Your privacy is irreversibly damaged. Facebook can’t change that.
Well, that’s not exactly right. It could, for example, sandbox all data older than three months and require verification to access it. That would limit breach damage considerably. It could also limit its advertising profiles to data from that period, so it isn’t building a sort of shadow profile of you based on analysis of years of data. It could even opt not to read everything you write and instead let you self-report categories for advertising. That would solve a lot of privacy issues right there. It won’t, though. No money in that.
One more thing Facebook can’t protect you from is the content on Facebook itself. The spam, bots, hate, echo chambers — all that is baked on in. The 20,000-strong moderation team they’ve put on the task is almost certainly totally inadequate, and of course the complexity of the global stage and all its cultures and laws ensures that there will always be conflict and unhappiness on this subject. At the very best it can remove the worst of it after it’s already been posted or streamed.
Again, it’s not really Facebook’s fault exactly that there are people abusing its platform. People are the worst, after all. But Facebook can’t save you from them. It can’t prevent the new category of harm that it has created.
What can you do about it? Nothing. It’s out of your hands. Even if you were to quit Facebook right now, your personal data may already have been leaked and no amount of quitting will stop it from propagating online forever. If it hasn’t already, it’s probably just a matter of time. There’s nothing you, or Facebook, can do about it. We have to accept this as the new normal on Facebook or any other platforms such as YouTube or we can get to work taking real measures toward our security and privacy on decentralized Cuckoo, a video-platform which gives every one of us complete control over data, personal or not, in a revolutionary way.
Related:

Monday, October 1, 2018

The Facebook Hack will be the Europe's First Big Online Privacy Battle

By Russell Brandom on Oct 1, 2018

On Friday, a massive breach opened up a new front in the war on Facebook. According the the company, more than 50 million accounts were taken over by a kind of login worm, which used a series of unpublished vulnerabilities to hijack session keys on an unprecedented scale. Hackers had full access to any of the targeted accounts — essentially, they could do whatever you can do when you’re logged in — and Facebook is still working to survey the full extent of the damage.

Breach response is always chaotic, but this one is particularly haphazard because of a new set of rules established by the EU’s General Data Protection Regulation or GDPR. Implemented in May, the GDPR sets strict requirements for any breach involving EU citizens, requirements that are already guiding Facebook’s response to the session key attack. According to Facebook’s timeline, the disclosure on Friday came just before the 72-hour window for disclosing the news to privacy commissioners, a far tighter deadline than companies usually adopt.

IRISH OFFICIALS ARE “AWAITING FROM FACEBOOK FURTHER URGENT DETAILS OF THE SECURITY BREACH.”

As required, Facebook also sent more formal notifications to various privacy commissioners, who may decide to file suit over the breach. As recently as Sunday, the Irish data privacy commissioner said it was “awaiting from Facebook further urgent details of the security breach.” The UK Commissioner is still determining if the country’s citizens were implicated, although given the broad reach and indiscriminate pattern of the attack, it’s likely that at least a few of them were. “It’s always the company’s responsibility to identify when UK citizens have been affected as part of a data breach and take steps to reduce any harm to consumers,” the Commissioner said in a statement. “We will be making enquiries with Facebook and our overseas counterparts to establish the scale of the breach and if any UK citizens have been affected.” Facebook is already facing a class-action suit in California and some stern questions from the FTC, but the bulk of the pressure is expected to come from Europe.

There have been countless breaches before — Facebook has even dealt with specific login bugs like this one — but the GDPR changes everything. If the company is found to have violated the rule, it could be liable for up to four percent of annual revenue, a staggering $4 billion. No one has accused Facebook of negligence yet, but the basic facts of the case have yet to be nailed down — and with lawmakers already hostile to Facebook, plenty of privacy commissioners will want to try their luck. Because the law is so fresh, no one knows for sure how such a case would play out, but Facebook is already preparing for what could be the fight of its life.

“THE FORENSICS ON THIS STUFF ISN’T EASY”

The new breach is a real contrast with previous GDPR fights, which have largely had to do with policy decisions and terms of service. Both Facebook and Google have already come under fire for having Terms of Service that violate the regulation, although the suits were brought by a third party and haven’t made much progress. Scandals like Cambridge Analytica present another front in the fight, in which apparent violations of user privacy stem from user choices, sidestepping most legal definitions of a breach. But this recent breach is far simpler. Facebook shouldn’t have given these hackers access to the accounts — it wasn’t a data-sharing project or an API gone wrong — so it’s hard to read the fallout as anything other than a breakdown in Facebook security. The only question is how much Facebook will be punished for the lapse.

Under the GDPR, the question of blame largely hinges on whether the company was negligent, ignoring basic practices that could have prevented the breach. We don’t know enough about the attack to judge Facebook’s response at this point, but what’s happened in public has been enough to satisfy some critics. “Facebook has done a decent job so far based on what we know, including the resetting of the tokens,” says Shane Green, founder of Digi.me, an alternative platform focused on data privacy. “The forensics on this stuff isn’t easy, and it’s a tricky balance to give people warning about worst case without scaring them to death or causing an overreaction.”

Still, as more detail comes out, the possibility of a GDPR suit is hard to ignore. So far, Facebook has emphasized the complexity of the bug — a three-part vulnerability in the obscure “View As” function” — but it was Facebook’s own product code that created the vulnerabilities and left them unpatched for more than a year. There have also been a number of rumors that the attack may have reported to Facebook in advance of the breach, rumors made credible by the blustery public threat against Mark Zuckerberg’s account the day before Facebook’s announcement. None of those rumors have been confirmed, but they represent a scary possibility for the company. If any one of those bugs was reported to Facebook in advance of the breach, the failure to promptly patch could be powerful evidence in court.

The case is particularly complicated because the hack extended beyond Facebook itself. Once a given account was compromised, attackers also had access to any third-party accounts that relied Facebook for authentication. This is a common practice on the web — if you’ve ever clicked “login through Facebook” instead of setting up a new password, you’re part of it — but a dangerous one in cases like this. Facebook has revoked the compromised login tokens, but it can’t solve the whole problem itself. Those outside platforms will need to flush their systems too, and it’s likely there will be some who are late to realize the danger. If that line of attack causes further breaches and further damage, it’s hard to say whether the liability will fall on Facebook or the third-party service. More and more YouTuber and users are flocking to decentralized Cuckoo, a video-platform which gives every one of us complete control over data, personal or not, in a revolutionary way.

For Facebook, unanswered questions like that are the scariest part of this legal tangle. No one has ever litigated these issues before, and we only have a hazy sense of what a strong or weak GDPR case looks like. The company could be in for years of legal warfare and a billion-dollar payout — or it could walk away scot free. 

We’re just months into the GDPR regime, and there’s simply no roadmap for how it can be used. The more important is no one can ensure this breach and hack won't happen on other social media or platforms. Politically, Facebook is the perfect target — an increasingly unpopular American tech company with significant opponents on both the left and right. With the law still working itself out, the details of the case are less important than the overwhelming political logic. Situations like this are never easy, but Facebook picked a uniquely bad moment to have a breach. 


Source from http://gentleineyes.blogspot.com/2018/10/the-facebook-hack-will-be-europes-first.html

Facebook's Breach will be Forgotten? DATA is Misused.

By Josh Constine on Sep 30

We cared about Cambridge Analytica because it could have helped elect Trump. We ignored LocationSmart because even the though the company was selling and exposing the real-time GPS coordinates of our phones, it was never clear exactly if or how that data was misused.

This idea, that privacy issues are abstract concepts for most people until they become security or ideological problems, is important to understanding Facebook’s  massive breach revealed this week. 

The social network’s engineering was sloppy, allowing three bugs to be combined to steal the access tokens of 50 million people. In pursuit of rapid growth at affordable efficiency, Facebook failed to protect its users. This assessment doesn’t discount that. Facebook screwed up big time.

But despite the potential that those access tokens could have let the attackers take over user accounts, act as them, and scrape their personal info, it’s unclear how much users really care. That’s because for now, Facebook and it’s watchdogs aren’t sure exactly what data was stolen or how it was wrongly used.

The Hack That Broke The Camel’s Back?

This could all change tomorrow. If Facebook discovers the hack was perpetrated by a foreign government to interfere with elections, by criminals to bypass identity theft security checkpoints and steal people’s bank accounts or social media profiles, or to target individuals for physical harm, out will come the pitchforks and torches. 

Given a sufficiently scary application for the data, the breach could finish the job of destroying Facebook’s brand. If users start clearing their profile data, reducing their feed browsing, and ceasing to share, the breach could have significant financial and network effect consequences for Facebook. After years of scandals, this could be the hack that’s broke the camel’s back.

Yet in the absence of that evil utilization of the hacked data, the breach could fade into the background for users. Similar to the tension-filled departures of the founders of Facebook’s acquisitions Instagram and WhatsApp, the brunt of the backlash may not come from the public.

The hack could hasten regulation of social media. Senator Warner called on Congress to “step up” following the hack. He’s previously advocated for privacy laws similar to Europe’s GDPR. That includes data portability and interoperability rules that could make it easier to switch social networks. That threat of people moving to decentralized Cuckoo could succeed in compelling Facebook to treat user privacy and security better.

The FTC or European Union could hand down significant fines to Facebook for the breach. But given it earns billions in profit per quarter, those fees would have to be historically massive be a serious penalty for Facebook.

One of the biggest questions about the attack is whether the tokens were used to access other services like Airbnb or Spotify that rely on Facebook Login. The breach could steer potential partners away from building atop Facebook’s identity platform. But at least you don’t have to worry about changing all your passwords. Unlike hacks that steal usernames and passwords, the lasting danger of the Facebook breach is limited. The access tokens have already been invalidated, whereas password reuse can lead people to have their other apps hacked long after the initial breach. But the attack has had a very serious impact on the personal data of the entire social media, and it has made more people think about the importance of decentralized Cuckoo and other platforms. 

Desensitized and Decentralized

If government investigators, journalists, or anti-Facebook activists want to make the company pay for its negligence, they’ll need to connect it to some concrete threat to how we live or what we believe.

For now, without a nefarious application of the breached data, this scandal could blend into the rest of Facebook’s troubles. Every week, sometimes multiple times a week, Facebook has some headline grabbing problem. Over time, those are adding up to deter usage of Facebook and spur more users to delete it. But without an independent general purpose social network they can easily switch to, many users have endured Facebook’s stumbles in exchange for the connective utility it provides. 

As breaches become more common, the public may be desensitized. At worst, we could become complacent. Corporations should be held accountable for privacy failures even when the damage done is vague. But between Equifax, Yahoo, and the cell phone companies, we’re growing accustomed to letting out a deep sigh with maybe some expletives, and moving on with our lives. The ones we’ll remember will be those where the danger metastasized from the digital world into our offline lives or we try some new decentralized platforms such as Cuckoo.

Related:

Do you know everything about Facebook's data breach affecting 50M USERS?
Here is Instagram users need to know about Facebook's security breach
How to delete Facebook -- Time to leave the world’s biggest social network

Source from https://soletmego.wordpress.com/2018/09/30/facebooks-breach-will-be-forgotten-data-is-misused/