Showing posts with label user data. Show all posts
Showing posts with label user data. Show all posts

Friday, October 5, 2018

Instagram is handing YOUR LOCATION history to Facebook

By Josh Constine on Oct 4
This is sure to exacerbate fears that Facebook will further exploit Instagram now that its founders have resigned. Instagram has been spotted prototyping a new privacy setting that would allow it to share your location history with Facebook. That means your exact GPS coordinates collected by Instagram, even when you’re not using the app, would help Facebook to target you with ads and recommend you relevant content. The geo-tagged data would appear to users in their Facebook Profile’s Activity Log, which include creepy daily maps of the places you been.
This commingling of data could upset users who want to limit Facebook’s surveillance of their lives. With Facebook installing its former VP of News Feed and close friend of Mark Zuckerberg, Adam Mosseri, as the head of Instagram, some critics have worried that Facebook would attempt to squeeze more value out of Instagram. Tat includes driving referral traffic to the main app via spammy notifications, inserting additional ads, or pulling in more data. Facebook was sued for breaking its promise to European regulators that it would not commingle WhatsApp and Facebook data, leading to an $122 million fine.
A Facebook spokesperson says that “To confirm, we haven’t introduced updates to our location settings. As you know, we often work on ideas that may evolve over time or ultimately not be tested or released. Instagram does not currently store Location History; we’ll keep people updated with any changes to our location settings in the future.” That effectively confirms Location History sharing is something Instagram has prototyped, and that it’s considering launching but hasn’t yet.
The screenshots come courtesy of a mobile researcher and his prior finds like prototypes of Instagram Video Calling and Music Stickers have drawn “no comments” from Instagram but then were officially launched in the following months. That lends credence to the idea that Instagram is serious about Location History.
Located in the Privacy and Security settings, the Location History option “Allows Facebook Products, including Instagram and Messenger, to build and use a history of precise locations received through Location Services on your device.”
A ‘Learn More’ button provides additional info (emphasis mine):
“Location History is a setting that allows Facebook to build a history of precise locations received through Location Services on your device. When Location History is on, Facebook will periodically add your current precise location to your Location History even if you leave the app. You can turn off Location History at any time in your Location Settings on the app. When Location History is turned off, Facebook will stop adding new information to your Location History which you can view in your Location Settings. Facebook may still receive your most recent precise location so that you can, for example, post content that’s tagged with your location. Location History helps you explore what’s around you, get more relevant ads, and helps improve Facebook. Location History must be turned on for some location feature to work on Facebook, including Find Wi-Fi and Nearby Friends.”
It’s unclear whether the feature would launch as opt-in or opt-out. [Correction: The prototype defaulted to off and Wong had to turn it on.] As part of a 2011 settlement with the FTC over privacy violations, Facebook agreed that “Material retroactive changes to the audience that can view the information users have previously shared on Facebook” must now be opt-in. But since Location History is never visible to other users and only deals with data Facebook sees, it’s exempt from that agreement and could be quietly added. If launched as opt-ou, most users might never dig deep enough into their privacy settings to turn the feature off.
Delivering the exact history of where Instagram users went could assist Facebook with targeting them with local ads across its family of apps. If users are found to visit certain businesses, countries, neighborhoods, or schools, Facebook could use that data to infer which products they might want to buy and promote them. It could even show ads for restaurants or shops close to where users spend their days. Just yesterday, we reported that Facebook was testing a redesign of its Nearby Friends feature that replaces the list view of friends’ locations with a map. Pulling in Location History from Instagram could help keep that map up to date.
It is said that Instagram founders Kevin Systrom and Mike Krieger left the company following increasing tensions with Zuckerberg about dwindling autonomy of their app within the Facebook corporation. Systrom apparently clashed with Zuckerberg over how Instagram was supposed to contribute to Facebook success, especially as younger users began abandoning the older social network for the newer visual media app. Facebook is under pressure to keep up revenue growth despite it running out of News Feed ad inventory and users switching to Stories that advertisers are still acclimating to. Facebook is in heated competition with Google for last-mile local advertising and will take any advantage it can get.
Instagram has served as a life raft for Facebook’s brand this year amidst an onslaught of scandals including fake news, election interference, social media addiction, and most recently, a security breach that gave hackers the access tokens for 50 million users that could have let them take over their accounts. A survey of 1,153 US adults conducted in March 2018 found that 57 percent of them didn’t know Instagram was owned by Facebook. But if Facebook treats Instagram as a source of data and traffic it can strip mine, the negative perceptions associated with the parent could spill over onto the child. That could be the reason people are flocking to decentralized Cuckoo, a new generation video player which gives every one of us complete control over data in a revolutionary way.
Related:

Saturday, September 29, 2018

Do you know everything about Facebook's data breach affecting 50M USERS?

By Sarah Perez & Zack Whittaker on Sep 28
Facebook is cleaning up after a major security incident exposed the account data of millions of users. What’s already been a rocky year after the Cambridge Analytica scandal, the company is scrambling to regain its users trust after another security incident exposed user data.
Here’s everything you need to know so far.
What happened?
Facebook says at least 50 million users’ data were confirmed at risk after attackers exploited a vulnerability that allowed them access to personal data. The company also preventively secure 40 million additional accounts out of an abundance of caution.
What data were the hackers after?
Facebook CEO Mark Zuckerberg said that the company has not seen any accounts compromised and improperly accessed — although it’s early days and that may change. But Zuckerberg said that the attackers were using Facebook developer APIs to obtain some information, like “name, gender, and hometowns” that’s linked to a user’s profile page.
What data wasn’t taken?
Facebook said that it looks unlikely that private messages were accessed. No credit card information was taken in the breach, Facebook said. Again, that may change as the company’s investigation continues.
What’s an access token? Do I need to change my password?
When you enter your username and password on most sites and apps, including Facebook, your browser or device is set an access tokens. This keeps you logged in, without you having to enter your credentials every time you log in. But the token doesn’t store your password — so there’s no need to change your password.
Is this why Facebook logged me out of my account?
Yes, Facebook says it reset the access tokens of all users affected. That means some 90 million users will have been logged out of their account — either on their phone or computer — in the past day. This also includes users on Facebook Messenger.
When did this attack happen?
The vulnerability was introduced on the site in July 2017, but Facebook didn’t know about it until this month, on September 16, 2018, when it spotted a spike in unusual activity. That means the hackers could have had access to user data for a long time, as Facebook is not sure right now when the attack began.
Who would do this?
Facebook doesn’t know who attacked the site, but the FBI is investigating, it says.
However, Facebook has in the past found evidence of Russia’s attempts to meddle in American democracy and influence our elections — but it’s not to say that Russia is behind this new attack. Attribution is incredibly difficult and takes a lot of time and effort. It recently took the FBI more than two years to confirm that North Korea was behind the Sony hack in 2016 — so we might be in for a long wait.
How did the attackers get in? 
Not one, but three bugs led to the data exposure.
In July 2017, Facebook inadvertently introduced three vulnerabilities in its video uploader, said Guy Rosen, Facebook’s vice president of product management, in a call with reporters. When using the “View As” feature to view your profile as someone else, the video uploader would occasionally appear when it shouldn’t display at all. When it appeared, it generated an access token using the person who the profile page was being viewed as. If that token was obtained, an attacker could log into the account of the other person.
Is the problem fixed? 
Facebook says it fixed the vulnerability on September 27, and then began resetting the access tokens of people to protect the security of their accounts.
Did this affect WhatsApp and Instagram accounts?
Facebook said that it’s not yet sure if Instagram accounts are affected, but were automatically secured once Facebook access tokens were revoked. Affected Instagram users will have to unlink and relink their Facebook accounts in Instagram in order to cross post to Facebook.
On a call with reporters, Facebook said there is no impact on WhatsApp users at all.
Are sites that use Facebook Login also affected?
If an attacker obtained your Facebook access token, it not only gives them access to your Facebook account as if they were you, but any other site that you’ve used Facebook to login with, like dating apps, games, or streaming services.
Will Facebook be fined or punished?
If Facebook is found to have breached European data protection rules — the newly implemented General Data Protection Regulation (GDPR) — the company can face fines of up to four percent of its global revenue.
However, that fine can’t be levied until Facebook knows more about the nature of the breach and the risk to users.
Another data breach of this scale – especially coming in the wake of the Cambridge Analytica scandal and other data leaks – has some in Congress calling for the social network to be regulated. Sen. Mark Warner (D-VA) issued a stern reprimand to Facebook over today’s news, and again pushed his proposal for regulating companies holding large data sets as ““information fiduciaries” with additional consequences for improper security.
FTC Commissioner Rohit Chopra also tweeted that “I want answers” regarding the Facebook hack. It’s reasonable to assume that there could be investigators in both the U.S. and Europe to figure out what happened.
Can I check to see if my account was improperly accessed?
You can. Once you log back into your Facebook account, you can go to your account’s security and login page, which lets you see where you’ve logged in. If you had your access tokens revoked and had to log in again, you should see only the devices that you logged back in with.
How can I protect my data while those platforms are hacked or data are leaking?
You can try some decentralized platforms such as Cuckoo can well store your video based on P2P connection, there won't be any hacking or leaking because all the data will be stored as fragments.
Should I delete my Facebook account?
That’s up to you! But you may want to take some precautions like changing your password and turning on two-factor authentication, if you haven’t done so already. If you’re weren’t impacted by this, you may want to take the time to delete some of the personal information you’ve shared to Facebook to reduce your risk of exposure in future attacks, if they were to occur.