MasterSearch

AddThis

Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

March 28, 2020

#Zoom's iOS App is sending your #PrivateData nonconsensually to Facebook — even if you don’t have a Facebook account.

Zoom's iOS app is sending your data to Facebook, because privacy is a myth
Zoom iOS App
Zoom's iOS app is sending your data to Facebook, because privacy is a myth

Zoom's video conferencing app has grown more popular than ever lately, while people are staying home to flatten the curve. But you should know that there's a major privacy concern with the service.

Last night, Vice reported that Zoom's iOS app is nonconsensually sending data to Facebook — even if you don't have a Facebook account.

What's more shocking is that the company's privacy policy makes no mention of it. Plus, the app doesn't make it clear anywhere that it's sending your data to the social network.

Joseph Cox noted in his report for Vice that every time you open the app, it sends your data to Facebook including your device's model, network provider, time zone, city, and a unique device identifier that advertisers can use to send you targeted ads.

Facebook's policy about using its SDK (Software Development Kit) and tracking Pixels is quite clear: A website or app using it has to explicitly mention that your data is being shared with third-parties, including Facebook. Plus, it has to provide an option to opt-out of tracking. Zoom doesn't address these points at all.

Last week, digital rights non-profit Electronic Frontier Foundation (EFF) pointed out some of the privacy risks in using Zoom's products. The report said IT admins of your company can access a bunch of information about you during a meeting including your device information, IP address, and operating system. Plus, the app has an attention tracking feature, which is off by default, that allows hosts to check if a participant's Zoom app window is active or not on their desktops.

Continue Reading the whole story here: https://thenextweb.com/security/2020/03/27/zooms-ios-app-is-sending-your-data-to-facebook-because-privacy-is-a-myth/?utm_campaign=Feed%3A%2BTheNextWeb%2B%28The%2BNext%2BWeb%2BAll%2BStories%29&utm_medium=feed&utm_source=feedburner


May 13, 2011

Another day, Another Security Leak: Facebook this time

Today it's Facebook.  
" ... Over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties,"
  Symantec had to get them to come out and tell you...


And yet it amazes people continue to put things online that they wouldn't want the whole world to see...

Story from Reuters below:

Facebook may have leaked your personal information: Symantec
Photo
12:46am EDT
(Reuters) - Facebook users' personal information could have been accidentally leaked to third parties, in particular advertisers, over the past few years, Symantec Corp said in its official blog.
Third-parties would have had access to personal information such as profiles, photographs and chat, and could have had the ability to post messages, the security software maker said.
"We estimate that as of April 2011, close to 100,000 applications were enabling this leakage," the blog post said.
" ... Over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties," posing a security threat, the blog post said.
The third-parties may not have realized their ability to access the information, it said.
Facebook, the world's largest social networking website, was notified of this issue and confirmed the leakage, the blog post said.
It said Facebook has taken steps to resolve the issue.
"Unfortunately, their (Symantec's) resulting report has a few inaccuracies. Specifically, we have conducted a thorough investigation which revealed no evidence of this issue resulting in a user's private information being shared with unauthorized third parties," Facebook spokeswoman Malorie Lucich said in a statement.
Lucich said the report also ignores the contractual obligations of advertisers and developers which prohibit them from obtaining or sharing user information in a way that "violates our policies."
She also confirmed that the company removed the outdated API (Application Programing Interface) referred to in Symantec's report.
Facebook has more than 500 million users and is challenging Google Inc and Yahoo Inc for users' time online and for advertising dollars.
(Reporting by Thyagaraju Adinarayan and Sakthi Prasad in Bangalore; Editing by Bernard Orrand Anshuman Daga)
© Thomson Reuters 2011. All rights reserved.
Facebook may have leaked your personal information: Symantec | Reuters

Share
-- The MasterFeeds

February 20, 2011

New Hacking Tools Pose Bigger Threats to Wi-Fi Users - NYTimes.com

New Hacking Tools Pose Bigger Threats to Wi-Fi Users

 

February 16, 2011
You may think the only people capable of snooping on your Internet activity are government intelligence agents or possibly a talented teenage hacker holed up in his parents’ basement. But some simple software lets just about anyone sitting next to you at your local coffee shop watch you browse the Web and even assume your identity online.
“Like it or not, we are now living in a cyberpunk novel,” said Darren Kitchen, a systems administrator for an aerospace company in Richmond, Calif., and the host of Hak5, a video podcast about computer hacking and security. “When people find out how trivial and easy it is to see and even modify what you do online, they are shocked.”
Until recently, only determined and knowledgeable hackers with fancy tools and lots of time on their hands could spy while you used your laptop or smartphone at Wi-Fi hot spots. But a free program called Firesheep, released in October, has made it simple to see what other users of an unsecured Wi-Fi network are doing and then log on as them at the sites they visited.
Without issuing any warnings of the possible threat, Web site administrators have since been scrambling to provide added protections.
“I released Firesheep to show that a core and widespread issue in Web site security is being ignored,” said Eric Butler, a freelance software developer in Seattle who created the program. “It points out the lack of end-to-end encryption.”
What he means is that while the password you initially enter on Web sites like Facebook, Twitter, Flickr, Amazon, eBay and The New York Times is encrypted, the Web browser’s cookie, a bit of code that that identifies your computer, your settings on the site or other private information, is often not encrypted. Firesheep grabs that cookie, allowing nosy or malicious users to, in essence, be you on the site and have full access to your account.
More than a million people have downloaded the program in the last three months (including this reporter, who is not exactly a computer genius). And it is easy to use.
The only sites that are safe from snoopers are those that employ the cryptographic protocol transport layer security or its predecessor, secure sockets layer, throughout your session. PayPal and many banks do this, but a startling number of sites that people trust to safeguard their privacy do not. You know you are shielded from prying eyes if a little lock appears in the corner of your browser or the Web address starts with “https” rather than “http.”
“The usual reason Web sites give for not encrypting all communication is that it will slow down the site and would be a huge engineering expense,” said Chris Palmer, technology director at the Electronic Frontier Foundation, an electronic rights advocacy group based in San Francisco. “Yes, there are operational hurdles, but they are solvable.”
Indeed, Gmail made end-to-end encryption its default mode in January 2010. Facebook began to offer the same protection as an opt-in security feature last month, though it is so far available only to a small percentage of users and has limitations. For example, it doesn’t work with many third-party applications.
“It’s worth noting that Facebook took this step, but it’s too early to congratulate them,” said Mr. Butler, who is frustrated that “https” is not the site’s default setting. “Most people aren’t going to know about it or won’t think it’s important or won’t want to use it when they find out that it disables major applications.”
Joe Sullivan, chief security officer at Facebook, said the company was engaged in a “deliberative rollout process,” to access and address any unforeseen difficulties. “We hope to have it available for all users in the next several weeks,” he said, adding that the company was also working to address problems with third-party applications and to make “https” the default setting.
Many Web sites offer some support for encryption via “https,” but they make it difficult to use. To address these problems, the Electronic Frontier Foundation in collaboration with the Tor Project, another group concerned with Internet privacy, released in June an add-on to the browser Firefox, called Https Everywhere. The extension, which can be downloaded at eff.org/https-everywhere, makes “https” the stubbornly unchangeable default on all sites that support it.
Since not all Web sites have “https” capability, Bill Pennington, chief strategy officer with the Web site risk management firm WhiteHat Security in Santa Clara, Calif., said: “I tell people that if you’re doing things with sensitive data, don’t do it at a Wi-Fi hot spot. Do it at home.”
But home wireless networks may not be all that safe either, because of free and widely available Wi-Fi cracking programs like Gerix WiFi Cracker, Aircrack-ng and Wifite. The programs work by faking legitimate user activity to collect a series of so-called weak keys or clues to the password. The process is wholly automated, said Mr. Kitchen at Hak5, allowing even techno-ignoramuses to recover a wireless router’s password in a matter of seconds. “I’ve yet to find a WEP-protected network not susceptible to this kind of attack,” Mr. Kitchen said.
A WEP-encrypted password (for wired equivalent privacy) is not as strong as a WPA (or Wi-Fi protected access) password, so it’s best to use a WPA password instead. Even so, hackers can use the same free software programs to get on WPA password-protected networks as well. It just takes much longer (think weeks) and more computer expertise.
Using such programs along with high-powered Wi-Fi antennas that cost less than $90, hackers can pull in signals from home networks two to three miles away. There are also some computerized cracking devices with built-in antennas on the market, like WifiRobin ($156). But experts said they were not as fast or effective as the latest free cracking programs, because the devices worked only on WEP-protected networks.
To protect yourself, changing the Service Set Identifier or SSID of your wireless network from the default name of your router (like Linksys or Netgear) to something less predictable helps, as does choosing a lengthy and complicated alphanumeric password.
Setting up a virtual private network, or V.P.N., which encrypts all communications you transmit wirelessly whether on your home network or at a hot spot, is even more secure. The data looks like gibberish to a snooper as it travels from your computer to a secure server before it is blasted onto the Internet.
Popular V.P.N. providers include VyperVPN, HotSpotVPN and LogMeIn Hamachi. Some are free; others are as much as $18 a month, depending on how much data is encrypted. Free versions tend to encrypt only Web activity and not e-mail exchanges.
However, Mr. Palmer at the Electronic Frontier Foundation blames poorly designed Web sites, not vulnerable Wi-Fi connections, for security lapses. “Many popular sites were not designed for security from the beginning, and now we are suffering the consequences,” he said. “People need to demand ‘https’ so Web sites will do the painful integration work that needs to be done.”

New Hacking Tools Pose Bigger Threats to Wi-Fi Users - NYTimes.com: "

iStockphoto
By KATE MURPHY
Published: February 16, 2011

- Sent using Google Toolbar"

Share this|
________________________

August 31, 2010

Research in Motion Continues Its Inevitable Downward Descent In Both Equity Value and Market Share | zero hedge

RIM = RIP ?

Sounds like TAPS in the background....

Between the pressure on the corporate side of the business from governments who want access to all the data passing through the blackberries in their countries, and the real risk of migration by consumers to the iPhone and Android OS, the future doesn't look too bright RIM...

see the article below from zerohedge.com


As Research in Motion Continues Its Inevitable Downward Descent In Both Equity Value and Market Share, Investors Should Tweak Their Assumptions Accordingly


Following up on my Research in Motion commentary in , I’d like to comment on potential future paths for the company. From what I see from their public announcements, I remain as unimpressed now as I was just before (After Getting a Glimpse of the New Windows Phone 7 Functionality, RIMM is Looking More Like a Short Play) and after (RIM Smart Phone Market Share, RIP?) the OS6/Torch launch. The tricky part is that RIMM is now starting to look rather inexpensive relative to consensus earnings and historically projected growth rates. This is where a little strategic foresight comes into play. I have made available for download (for all paying subscribers) the Mobile Operating System Market Share Model which illustrates, on a very granular level, the market share movements (gains and losses) of the major mobile OS providers.
Research in Motions recent equity share decline stems not only from market share loss, but from the apparent lack of a clear cut and believable plan to stem that market share loss.
Thus the downloadable OS model design is to congeal data garnered from Gartner, Bloomberg, Neilsen, Canalys and other sources in order to realistically track movement in the mobile OS space. Since this model actually deserves a post of its own, I will simply pull out some pertinent charts that pertain to RIMM.
Research in Motion, is still currently the market leader in terms of share, but is losing both demonstrably and rapidly in new users. As a matter of fact, if the recent historical trends persist, this is the last quarter that RIM will be able to claim the top of the market title as Android looks well situated to claim that crown.
As can be seen from this chart, Android is just about there. Apple will probably show better numbers in Q3 with additional evidence of iPhone 4 adoption as well.
We, at BoomBustBlog actually believe that RIM is poised to lose market share (particularly the consumer market where it enterprise stickiness can’t come into play) quite quickly and radically due to dissatisfaction among its user base combined with technically far superior handsets in the iPhone and Android camps.
So, although RIM is looking quite cheap now, it is quite possible for it to look much cheaper. The question is how does this market share loss factor into its equity valuation. That is why I have supplied our Professional and Institutional subscribers with the plug and play File Icon RIMM Multivariate Valuation Model. By plugging
Additional writings on Research in Motion:


_______________________________________
Check it out on The MasterTech Blog

August 14, 2010

India eyes Google and Skype in security crackdown - Yahoo! News

India eyes Google and Skype in security crackdown
MUMBAI, India – India may ask Google and Skype for greater access to encrypted information once it resolves security concerns with BlackBerrys, which are now under threat of a ban, according to a government document and two people familiar with the discussions.
The 2008 terror attacks in Mumbai, which were coordinated with satellite and cell phones, helped prompt a sweeping security review of telecommunications ahead of the Commonwealth Games — a major sporting event to be held in New Delhi in October.
Some analysts say more anonymous technologies — like the basic Nokia phones used by 10 gunmen who rampaged through Mumbai in November 2008, leaving 166 dead — and Gmail are more likely to be used to plan terror attacks than BlackBerry devices, which require reliable identity proof and contact information.
On July 12, officials from India's Department of Telecommunications met with representatives of three telecom service provider groups to discuss interception and monitoring of encrypted communications by security agencies.
"There was consensus that there are more than one type of service for which solutions are to be explored," according to a copy of the minutes of the meeting obtained by The Associated Press. "Some of them are BlackBerry, Skype, Google etc. It was decided first to undertake the issue of BlackBerry and then the other services."
"They have clearly instructed us that after BlackBerry, they are going to take to task Google, Skype and similar services that bypass the monitoring department of India," said Rajesh Chharia, president of the Internet Service Providers Association of India, who attended the meeting. "According to the law, they have to allow monitoring."
The officials' immediate concern was the BlackBerry, but they also plan to look at Google and other companies that use encryption for e-mail and messaging services, said Rajan Mathews, director general of the Cellular Operators Association of India, who was briefed on the meeting.
Google and Skype said Friday they haven't received any notices from the government.
The Home Ministry said present talks involve only BlackBerry maker, Canada-based Research In Motion.
"We are talking only to BlackBerry," ministry spokesman D.R.S. Chaudhary said Friday. "Not to Google or others."
On Thursday, India threatened to ban BlackBerry services unless the device's manufacturer makes them accessible to its security agencies by Aug. 31.
On Friday, Research In Motion Vice President Robert E. Crowe met with Home Ministry officials in New Delhi to try to avoid the ban.
"I am optimistic," Crowe told reporters after the meeting.
Saudi Arabia and the United Arab Emirates have also threatened to cut off popular BlackBerry services unless they get greater access. Like India, they've cited security concerns in pushing to access encrypted information sent by the cell phones that gets routed through servers overseas.
Rights groups fear such access could be abused.
Research In Motion said in a Thursday statement that it maintains a consistent global standard for legal access to encrypted information which precludes making specific deals for specific countries.
All such access must be governed by a country's laws and must be applied equally to all vendors and all technologies, RIM said.
It also reiterated that it cannot "unlock" secure corporate e-mails. "Contrary to any rumors, the security architecture is the same around the world and RIM truly has no ability to provide its customers' encryption keys," it said.
The U.S. has technology to crack encrypted BlackBerry messages, which it can legally use when national security is at stake, diplomats say.
India is keen to get the U.S. to transfer technologies, like de-encryption, as part of high-level bilateral discussions on technology transfer likely to come up at Obama's state visit to India in November, diplomats say.
For now, more humble devices may present a greater security threat than the BlackBerrys used by India's business elite.
Mohammed Ajmal Kasab, the lone surviving gunman in the 2008 Mumbai attack, told an Indian court that he and his comrades all had Nokia mobile phones.
Photographs of court evidence show that the gunmen carried the most basic Nokia handsets.
"We did not find any Blackberrys," Special Prosecutor Ujjwal Nikam, who led the case against Kasab, said in an interview.
The relative anonymity and disposability of prepaid mobile phones and Web mail make them attractive to criminals, said Prasanto K. Roy, chief editor at CyberMedia Publications, a trade magazine group.
He said terrorists would likely opt to use disposable handsets and keep changing the SIM cards. Another hard-to-trace method would be to use Internet-based e-mail, like Gmail, updating and saving messages as drafts to avoid interception, he said.
RIM has fast expanded its presence in India from 114,000 users in early 2008 to an estimated 700,000 today — four-fifths of whom are corporate clients, who would be hit by a ban, Roy said.
RIM won't break out the number of users in India.
India has suffered deadly attacks, by both home grown and foreign militants, with some regularity for years. Many BlackBerry users here say national security trumps personal convenience.
"If BlackBerry cannot provide a solution for the security threat to the nation, we're happy to let go of the services," said Sharad Dhariwal, a 26-year-old investment banker.
That could be good news for Nokia — RIM's chief competitor here — and Apple, which recently brought the iPhone to India.
Associated Press writers Nirmala George and Ashok Sharma in New Delhi and Da Yan in Mumbai contributed to this report.


Copyright © 2010 Yahoo! Inc. All rights reserved.

  • Questions or Comments

  • Privacy Policy

  • About Our Ads

  • Terms of Service

  • Copyright/IP Policy

  • India eyes Google and Skype in security crackdown - Yahoo! News

    August 10, 2010

    Saudi Arabia: Blackberry Service To Continue

    Saudi Arabia: Blackberry Service To Continue
    August 10, 2010

    Saudi Arabia will allow the continued usage of Blackberry messenger services and will work with Blackberry service providers to fulfill regulations set by the Saudi Arabian Communication and Information Technology Commission (CITC) on Aug. 3, state-owned SPA reported Aug. 10. The CITC will continue to evaluate the usage and service provided by telecommunications companies for the device.

    --
    The MasterTech Blog
    http://themastertechblog.blogspot.com


    Subscribe to The MasterTech's Feeds

    Add This