Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Monday, July 5, 2021

FBI warns of large 'scale' in US ransomware attack

NEW YORK - The FBI said Sunday the "scale" of a major ransomware attack against a US IT company could mean investigators won't be able to work with every victim individually. 

Hackers hit Kaseya, a firm that provides IT services to other companies, with a ransomware attack that could have targeted as many as 1,000 other businesses on Friday, just before the long holiday July 4 weekend in the United States. 

The FBI said it had opened an investigation along with the Cybersecurity and Infrastructure Security Agency and other US federal agencies "to understand the scope of the threat."

"If you believe your systems have been compromised, we encourage you to employ all recommended mitigations, follow Kaseya's guidance to shut down your VSA servers immediately and report to the FBI," the bureau said in a statement Sunday, referencing the signature networking software that was attacked. 

"Although the scale of this incident may make it so that we are unable to respond to each victim individually, all information we receive will be useful in countering this threat," the FBI statement said.

President Joe Biden said Saturday that he had ordered an investigation, in particular to find out whether the assault had come from Russia. 

"We're not sure yet," he said Saturday.

Russian-based hackers have been blamed for a string of ransomware attacks, and Biden recently raised the threat in talks with Russian counterpart Vladimir Putin.

Ransomware attacks typically involve locking away data in systems using encryption, making companies pay to regain access.

Kaseya describes itself as a leading provider of IT and security management services to small and medium-sized businesses. VSA is designed to let companies manage networks of computers and printers from a single point.

The company said in a new statement Sunday that they were working "around the clock in all geographies" to get their systems working again.

They said they hoped to get a restricted version of their platform running again within days. 

The disruption forced Swedish supermarket chain Coop Sweden to close on Saturday because their cash register system had been taken down in the attack.

Multiple US companies, including the computer group SolarWinds and the Colonial oil pipeline, have also recently been targeted by ransomware attacks.

Agence France-Presse

Friday, January 17, 2020

2 arrested for 12 billion password sale attempt in Netherlands, Northern Ireland


THE HAGUE - Police arrested two men in the Netherlands and Northern Ireland suspected of trying to sell some 12 billion stolen user names and passwords via an online website, Dutch police said Friday.

A 22-year-old man was arrested in the eastern Dutch city of Arnhem when police raided his house on a tip-off by a Dutch cyber crime unit working with Britain's National Crime Agency, the FBI and the German police.

A second suspect, also aged 22, was arrested in Northern Ireland, Dutch police said in a statement.

During the raid in Arnhem police found professional equipment which made it possible to sell the suspects' offered services via the 'We leak info' website," police said.

The Dutch suspect "is involved in the possession and offering hacked user names and passwords and played a facilitating role in regards to cyber crime," law agents added.

When searched by AFP Friday the website displayed a disclaimer saying: "This domain has been seized" by the FBI in conjunction with the other European law enforcement agencies.

Dutch police declined to give further information, saying the investigation was ongoing.

WeLeakInfo.com allegedly offered unlimited access to all information on its site for two dollars a day or 25 dollars a month, the NOS public broadcaster said.

The information was a collection of leaks and stolen passwords from popular websites and apps such as LinkedIn and MyFitnessPal.

"In theory, you could search hundreds or even thousands of leaked passwords to try and gain access to people's emails, their social media and other accounts," the NOS said.

Dutch and British police in 2018 led an operation in which they shut down a website linked to more than four million cyber attacks around the world.

source: news.abs-cbn.com

Wednesday, January 15, 2020

Microsoft issues critical Windows security fix after tipoff from US NSA


WASHINGTON - Microsoft Corp on Tuesday rolled out an important security fix after the US National Security Agency tipped off the company to a serious flaw in its widely used Windows operating system, officials said.

Microsoft said the flaw could allow a hacker to forge digital certificates used by some versions of Windows to authenticate and secure data. Exploiting the flaw could have potentially serious consequences for Windows systems and users.

The NSA and Microsoft said they had not seen any evidence that the flaw had previously been abused, but both urged Windows users to deploy the update as soon as possible. NSA official Anne Neuberger noted that operators of classified networks had already been prodded to install the update and everyone else should now "expedite the implementation of the patch."

The Microsoft patch marks the first time the NSA has publicly claimed credit for prompting a software security update, although the agency said it has alerted companies in the past to flaws in their products. Neuberger said the agency was striving for more transparency with the information security research community.

"Part of building trust is showing the data," she told reporters in a call just minutes before the patch went live.

Experts said the move was unprecedented.

"I have never seen this before," said Tenable Chief Executive Amit Yoran, who previously served as founding director of the U.S. Computer Emergency Readiness Team.

"I cannot think of a single instance where government shared a zero-day with a vendor and took credit for it," he said in an email.

The NSA faces a balancing act when it comes across such vulnerabilities. The agency had been criticized after its cyberspies took advantage of vulnerabilities in Microsoft products to deploy hacking tools against adversaries and kept the Redmond, Washington-based company in the dark about it for years.

When one such tool was dramatically leaked to the internet in 2016, it was deployed against targets around the globe by hackers of all stripes.

In the most dramatic case, a group used the tool to unleash a massive malware outbreak dubbed WannaCry in 2017. The data-wiping worm wrought global havoc, affecting what Europol estimated was some 200,000 computers in more than 150 countries.

Neuberger did not directly address that controversy in her call but said that the NSA hoped to be "a good cybersecurity partner."

"We're working to evolve our mission," she said.

source: news.abs-cbn.com

Tuesday, January 14, 2020

Grindr, Tinder spread personal details, study says


Popular dating services like Grindr, OkCupid and Tinder are spreading user information like dating choices and precise location to advertising and marketing companies in ways that may violate privacy laws, according to a new report that examined some of the world’s most downloaded Android apps.

Grindr, the world’s most popular gay dating app, transmitted user-tracking codes and the app’s name to more than a dozen companies, essentially tagging individuals with their sexual orientation, according to the report, which was released Tuesday by the Norwegian Consumer Council, a government-funded nonprofit organization in Oslo.

Grindr also sent a user’s location to multiple companies, which may then share that data with many other businesses, the report said. When The New York Times tested Grindr’s Android app, it shared precise latitude and longitude information with 5 companies.

The researchers also reported that the OkCupid app sent a user’s ethnicity and answers to personal profile questions — like “Have you used psychedelic drugs?" — to a firm that helps companies tailor marketing messages to users. The Times found that the OkCupid site had recently posted a list of more than 300 advertising and analytics “partners” with which it may share users’ information.

“Any consumer with an average number of apps on their phone — anywhere between 40 and 80 apps — will have their data shared with hundreds or perhaps thousands of actors online,” said Finn Myrstad, the digital policy director for the Norwegian Consumer Council, who oversaw the report.

The report, “Out of Control: How Consumers Are Exploited by the Online Advertising Industry,” adds to a growing body of research exposing a vast ecosystem of companies that freely track hundreds of millions of people and peddle their personal information. This surveillance system enables scores of businesses, whose names are unknown to many consumers, to quietly profile individuals, target them with ads and try to sway their behavior.

The report appears just two weeks after California put into effect a broad new consumer privacy law. Among other things, the law requires many companies that trade consumers’ personal details for money or other compensation to allow people to easily stop the spread of their information.

In addition, regulators in the European Union are stepping up enforcement of their own data protection law, which prohibits companies from collecting personal information on religion, ethnicity, sexual orientation, sex life and other sensitive subjects without a person’s explicit consent.

The Norwegian group said it planned to file complaints Tuesday asking regulators in Oslo to investigate Grindr and 5 ad tech companies for possible violations of the European data protection law. A coalition of consumer groups in the US said it was also sending letters to American regulators, including the attorney general of California, urging them to investigate whether the companies’ practices violated federal and state laws.

In a statement, the Match Group, which owns OkCupid and Tinder, said it worked with outside companies to assist with providing services and shared only specific user data deemed necessary for those services. Match added that it complied with privacy laws and had strict contracts with vendors to ensure the security of users’ personal data.

In a statement, Grindr said it had not received a copy of the report and could not comment specifically on the content. Grindr added that it valued users’ privacy, had put safeguards in place to protect their personal information and described its data practices — and users’ privacy options — in its privacy policy

The report examines how developers embed software from ad tech companies into their apps to track users’ app use and real-life locations, a common practice. To help developers place ads in their apps, ad tech companies may spread users’ information to advertisers, personalized marketing services, location data brokers and ad platforms.

The personal data that ad software extracts from apps is typically tied to a user-tracking code that is unique for each mobile device. Companies use the tracking codes to build rich profiles of people over time across multiple apps and sites. But even without their real names, individuals in such data sets may be identified and located in real life.

For the report, the Norwegian Consumer Council hired Mnemonic, a cybersecurity firm in Oslo, to examine how ad tech software extracted user data from 10 popular Android apps. The findings suggest that some companies treat intimate information, like sexual orientation or drug habits, no differently from more innocuous information, like favorite foods.

Among other things, the researchers found that Tinder sent a user’s gender and the gender the user was looking to date to two marketing firms.

The researchers did not test iPhone apps. Settings on both Android phones and iPhones enable users to limit ad tracking.

The group’s findings illustrate how challenging it would be for even the most intrepid consumers to track and hinder the spread of their personal information.

Grindr’s app, for instance, includes software from MoPub, Twitter’s ad service, which can collect the app’s name and a user’s precise device location, the report said. MoPub in turn says it may share user data with more than 180 partner companies. One of those partners is an ad tech company owned by AT&T, which may share data with more than 1,000 “third-party providers.”

In a statement, Twitter said: “We are currently investigating this issue to understand the sufficiency of Grindr’s consent mechanism. In the meantime, we have disabled Grindr’s MoPub account.”

AT&T did not immediately respond to a request for comment.

The spread of users’ location and other sensitive information could present particular risks to people who use Grindr in countries, like Qatar and Pakistan, where consensual same-sex sexual acts are illegal.

This is not the first time that Grindr has faced criticism for spreading its users’ information. In 2018, another Norwegian nonprofit group found that the app had been broadcasting users’ HIV status to 2 mobile app service companies. Grindr subsequently announced that it had stopped the practice.

The report’s findings also raise questions about the extent to which businesses are complying with the new California privacy law. The law requires many companies that benefit from trading consumers’ personal details to prominently post a “Do Not Sell My Data” option, allowing people to stop the spread of their information.

But Grindr’s stance challenges that idea. By agreeing to its policy, its site says, users “are directing us to disclose” their personal information “and, therefore, Grindr does not sell your personal data.”

Myrstad said many consumers were comfortable sharing their data with apps they trusted. “But this study clearly shows that many apps abuse that trust,” he said. “Authorities need to enforce the rules we have, and if they are not good enough, we have to make better rules.”


2020 The New York Times Company

source: news.abs-cbn.com

Pompeo warns Silicon Valley on China ahead of trade pact


WASHINGTON -- US Secretary of State Mike Pompeo on Monday warned Silicon Valley not to bolster China's "Orwellian" state, two days before the world's two largest economies sign a partial trade deal.

Speaking to a tech-heavy crowd in San Francisco, Pompeo trumpeted the "phase one" deal to tame a two-year trade war but told businesses that they needed to do more.

"We need to make sure American technology doesn't power a truly Orwellian surveillance state. We need to make sure American principles aren't sacrificed for prosperity," Pompeo said at the Commonwealth Club.


He said he was not discouraging firms from heading to China, insisting that the Trump administration wants "American companies to get rich doing business there."

"At the same time, we need to make sure that our companies don't do deals that strengthen our competitor's military or tighten their regime's grip of repression in parts of that country," he said.

Rights advocates have voiced growing concern about China's use of technology to develop intrusive electronic surveillance.

In the tightly controlled western region of Xinjiang, where experts say more than one million mostly Muslim people are incarcerated, China is said to be fine-tuning technology that will allow security forces to quickly identify anyone and give details about their movements and background.

"Ask yourselves just a few questions -- who am I dealing with? What's the true risk/return calculus to doing business in China?" Pompeo said.

Trump is set to sign the partial deal on Wednesday after prolonged feuding, dropping new tariffs that were set to take effect on Chinese electronic products and cutting in half those imposed on September 1 on $120 billion worth of products.

The White House has said the agreement includes improvements on Beijing's requirements that foreign companies transfer technology -- which the United States say is a pretext for rampant intellectual theft.

The Trump administration says that the accord will also give US companies better access to the Chinese market for financial services and require China to buy more US products.

"We will do our part in the government. We will keep ramping up our enforcement," Pompeo said.

"But defending freedom and national security isn't just the government's job. It's one for each and every citizen," he told the tech companies.

Agence France-Presse

Tuesday, June 18, 2019

Advertisers, agencies and social media combine to tackle online threat


LONDON -- Sixteen of the world's biggest advertisers have joined together to push platforms such as Facebook, Twitter and Google's YouTube to do more to tackle dangerous and fake content online.

The Global Alliance for Responsible Media will also include media buying agencies from the major ad groups - WPP, IPG, Publicis, Omnicom and Dentsu - as well as the platform owners, the group said on Tuesday at the ad industry's annual gathering in Cannes, France.

Luis Di Como, executive vice president of global media at Unilever, said it was the first time that all sides of the industry had come together to tackle a problem that had far reaching consequences for society.

"When industry challenges spill into society, creating division and putting our children at risk, it's on all of us to act," he said. "Founding this alliance is a great step towards rebuilding trust in our industry and society."

He said the group would initially focus on content that was a danger to society, such as terrorism.

Platform owners had taken steps to address the problems, he said, but their focus had been more reactive - tackling content after it appeared - than proactive.

The alliance will work together to develop processes and protocols to protect people and brands, he said.

Other brand owners in the alliance include Adidas , Danone, Diageo, Mondelez International, Nestle and Procter & Gamble. 

source: news.abs-cbn.com

Tuesday, May 14, 2019

WhatsApp urges users to upgrade app after report of spyware attack


JERUSALEM - Facebook's WhatsApp on Tuesday urged users to upgrade to the latest version of its popular messaging app following a report that users could be vulnerable to having malicious spyware installed on phones without their knowledge.

"WhatsApp encourages people to upgrade to the latest version of our app, as well as keep their mobile operating system up to date, to protect against potential targeted exploits designed to compromise information stored on mobile devices," a spokesman said.

"We are constantly working alongside industry partners to provide the latest security enhancements to help protect our users."

The Financial Times reported that a vulnerability in WhatsApp allowed attackers to inject spyware on phones by ringing up targets using the app's phone call function. It said the spyware was developed by Israeli cyber surveillance company NSO Group.

Asked about the report, NSO said its technology is licensed to authorized government agencies "for the sole purpose of fighting crime and terror," and that it does not operate the system itself.

"We investigate any credible allegations of misuse and if necessary, we take action, including shutting down the system. Under no circumstances would NSO be involved in the operating or identifying of targets of its technology, which is solely operated by intelligence and law enforcement agencies," the company said.

"NSO would not or could not use its technology in its own right to target any person or organization, including this individual."

source: news.abs-cbn.com

Huawei is not controlled by China, executive says


LONDON - Huawei is a private company that is not controlled by the Chinese government and would refuse to hand over information to Beijing although no such request has been made, the firm's Vice President of Western Europe said on Tuesday.

The United States has told allies not to use Huawei's technology to build new 5G telecommunications networks because of concerns it could be a vehicle for Chinese spying, an accusation the firm has denied.

"There is no obligation on Huwaei's part to cooperate with the government in the way in which the Americans are indicating," Tim Watkins told BBC radio.

"There is no mandate in (China's national intelligence) law that we have to had over customer data or intelligence that we do not wish to hand over or we think should be sensitive."

Watkins added that the code used in their products was safe and secure.

source: news.abs-cbn.com

Thursday, April 18, 2019

Facebook says it uploaded email contacts of up to 1.5 million users


Facebook Inc. said on Wednesday it may have "unintentionally uploaded" email contacts of 1.5 million new users since May 2016, in what seems to be the latest privacy-related issue faced by the social media company.

In March, Facebook had stopped offering email password verification as an option for people who signed up for the first time, the company said. There were cases in which email contacts of people were uploaded to Facebook when they created their account, the company said.

"We estimate that up to 1.5 million people's email contacts may have been uploaded. These contacts were not shared with anyone and we are deleting them," Facebook told Reuters, adding that users whose contacts were imported will be notified.

The underlying glitch has been fixed, according to the company statement.

Business Insider had earlier reported that the social media company harvested email contacts of the users without their knowledge or consent when they opened their accounts.

When an email password was entered, a message popped up saying it was "importing" contacts without asking for permission first, the report said.

Facebook has been hit by a number of privacy-related issues recently, including a glitch that exposed passwords of millions of users stored in readable format within its internal systems to its employees.

Last year, the company came under fire following revelations that Cambridge Analytica, a British political consulting firm, obtained personal data of millions of people's Facebook profiles without their consent.

The company has also been facing criticism from lawmakers across the world for what has been seen by some as tricking people into giving personal data to Facebook and for the presence of hate speech and data portability on the platform.

Separately, Facebook was asked to ensure its social media platform is not abused for political purposes or to spread misinformation during elections.

source: news.abs-cbn.com

Thursday, March 28, 2019

Told US security at risk, Chinese firm seeks to sell Grindr dating app


Chinese gaming company Beijing Kunlun Tech Co Ltd is seeking to sell Grindr LLC, the popular gay dating app it has owned since 2016, after a US government national security panel raised concerns about its ownership, according to people familiar with the matter.

The Committee on Foreign Investment in the United States (CFIUS) has informed Kunlun that its ownership of West Hollywood, California-based Grindr constitutes a national security risk, the two sources said.

CFIUS' specific concerns and whether any attempt was made to mitigate them could not be learned. The United States has been increasingly scrutinizing app developers over the safety of personal data they handle, especially if some of it involves US military or intelligence personnel.

Kunlun had said last August it was preparing for an initial public offering (IPO) of Grindr. As a result of CFIUS' intervention, Kunlun has now shifted its focus to an auction process to sell Grindr outright, given that the IPO would have kept Grindr under Kunlun's control for a longer period of time, the sources said.

Grindr has hired investment bank Cowen Inc to handle the sale process, and is soliciting acquisition interest from US investment firms, as well as Grindr's competitors, according to the sources.

The development represents a rare, high-profile example of CFIUS undoing an acquisition that has already been completed. Kunlun took over Grindr through two separate deals between 2016 and 2018 without submitting the acquisition for CFIUS review, according to the sources, making it vulnerable to such an intervention.

The sources asked not to be identified because the matter is confidential.

Kunlun representatives did not respond to requests for comment. Grindr and Cowen declined to comment. A spokesman for the US Department of the Treasury, which chairs CFIUS, said the panel does not comment publicly on individual cases.

Grindr, which describes itself as the world's largest social networking app for gay, bisexual, transgender and queer people, had 27 million users as of 2017. The company collects personal information submitted by its users, including a person's location, messages, and in some cases even someone's HIV status, according to its privacy policy.

CFIUS' intervention in the Grindr deal underscores its focus on the safety of personal data, after it blocked the acquisitions of US money transfer company MoneyGram International Inc and mobile marketing firm AppLovin by Chinese bidders in the last two years.

CFIUS does not always reveal the reasons it chooses to block a deal to the companies involved, as doing so could potentially reveal classified conclusions by US agencies, said Jason Waite, a partner at law firm Alston & Bird LLP focusing on the regulatory aspects of international trade and investment.

"Personal data has emerged as a mainstream concern of CFIUS," Waite said.

The unraveling of the Grindr deal also highlights the pitfalls facing Chinese acquirers of US companies seeking to bypass the CFIUS review system, which is based mostly on voluntary deal submissions.

Previous examples of the US ordering the divestment of a company after the acquirer did not file for CFIUS review include China National Aero-Technology Import and Export Corporation's acquisition of Seattle-based aircraft component maker Mamco in 1990, Ralls Corporation's divestment of four wind farms in Oregon in 2012, and Ironshore Inc's sale of Wright & Co, a provider of professional liability coverage to US government employees such as law enforcement personnel and national security officials, to Starr Companies in 2016.

PRIVACY CONCERNS

Kunlun acquired a majority stake in Grindr in 2016 for $93 million. It bought out the remainder of the company in 2018.

Grindr's founder and chief executive officer, Joel Simkhai, stepped down in 2018 after Kunlun bought the remaining stake in the company.

Kunlun's control of Grindr has fueled concerns among privacy advocates in the United States. US senators Edward Markey and Richard Blumenthal sent a letter to Grindr last year demanding answers with regards to how the app would protect users' privacy under its Chinese owner.

"CFIUS made the right decision in unwinding Grindr’s acquisition. It should continue to draw a line in the sand for future foreign acquisition of sensitive personal data," Markey and Blumenthal said in a statement on Wednesday.

Kunlun is one of China's largest mobile gaming companies. It was part of a buyout consortium that acquired Norwegian internet browser business Opera Ltd for $600 million in 2016.

Founded in 2008 by Tsinghua University graduate Zhou Yahui, Kunlun also owns Qudian Inc, a Chinese consumer credit provider, and Xianlai Huyu, a Chinese mobile gaming company.

source: news.abs-cbn.com

Tuesday, January 29, 2019

Hacks and facts: 10 things you didn't know about data privacy


LONDON - From hackers exposing private information online to the handling of users' data by internet giants, online privacy has become a matter of growing concern for countries, companies and people alike.

On Monday, countries around the world marked Data Privacy Day, also known as Data Protection Day - an initiative to raise awareness of internet safety issues.

Here are 10 facts about online privacy:

* Less than 60 percent of countries have laws to secure the protection of data and privacy.

* Europe's data protection regulators have received more than 95,000 complaints about possible data breaches since the adoption of a landmark EU privacy law in May.

* More than one in two respondents to a 2018 global survey by pollster CIGI-Ipsos said they had grown more concerned about their online privacy compared to the previous year.

* Almost 40 percent of respondents to another survey by cyber-security firm Kaspersky Lab said they did not know how to protect themselves from cybercrime.

* A survey of tech professionals by security key maker Yubico suggested experts might not live up to safety standards. It found almost 70 percent of respondents shared passwords with colleagues.

* More than half reused an average of five passwords across their work and personal accounts.

* About 4 percent of people targeted by an email phishing campaign would click on it.

* In 2017, almost 17 million U.S. consumers experienced identity fraud - the unauthorised use of personal information, such as credit card data, for financial gain.

* Data breaches carried out by hackers are expected to go up 22 percent annually, exposing some 146 billion records, including personal information such as name, address and credit card numbers by 2023.

* Data breaches cost companies worldwide almost $4 million on average for every incident. 

source: news.abs-cbn.com

Thursday, December 20, 2018

Facebook shares drop as data privacy fallout spreads


WASHINGTON - Facebook Inc shares sank on Wednesday as concerns about its ability to safeguard user data sparked a government lawsuit, criticism in the US Congress and a New York Times report on how it had shared data with other companies.

The stock of the world's largest social media company fell 7.25 percent, its biggest intraday drop since July, taking losses for the year to about 24 percent. Investors are concerned about snowballing legal and regulatory efforts over data use polices that have upset many customers and could carry significant penalties and costs.

In particular, the Silicon Valley firm has drawn global scrutiny since disclosing earlier this year that a third-party personality quiz distributed on Facebook gathered profile information on 87 million users worldwide and sold the data to British political consulting firm Cambridge Analytica.

Washington, D.C., Attorney General Karl Racine said the US capital city was suing Facebook, accusing it of misleading users because it had known about the incident for 2 years before disclosing it.

It further alleges Facebook misled users by allowing several app makers it called partners "to override Facebook consumers' privacy settings and access their information without their knowledge or consent."

Facebook said in a statement, "We're reviewing the complaint and look forward to continuing our discussions with attorneys general in D.C. and elsewhere."

The New York Times reported new details on Tuesday about the user data that remained available to such partners years after they had shut down features that required them. Facebook acknowledged the lapse in a blog post but said it had not found evidence of wrongdoing by those partners.

In response, both Democrat and Republican lawmakers criticized the company and queried whether Chief Executive Officer Mark Zuckerberg had lied to Congress in hearings earlier this year.

The incoming chair of the House Judiciary Committee's antitrust subcommittee, Representative David Cicilline, tweeted: "Zuckerberg told Congress that Facebook users had 'complete control' over their data. Sure looks like he lied."

Incoming Republican senator Josh Hawley made similar comments about Zuckerberg's testimony.

The stock slide was the worst since the owner of Facebook, WhatsApp and Instagram warned in July that profit margins would erode in coming years because of consumer and government pressure to better guard data and suppress objectionable content.

"Facebook could have prevented third parties from misusing its consumers' data had it implemented and maintained reasonable oversight of third-party applications," according to the lawsuit filed in the Superior Court of Washington, D.C., on Wednesday.

The court could award unspecified damages and impose a civil penalty of up to $5,000 per violation of the district's consumer protection law, or potentially close to $1.7 billion, if penalized for each consumer affected. The lawsuit alleges the quiz software had data on 340,000 D.C. residents, though just 852 users had directly engaged with it.

'CONFUSING SETTINGS'

Facebook offered separate privacy settings around 2013 to control what friends on the network could see and what data could be accessed by apps, enabling the quiz and other services to collect details about users' Facebook friends without many of them realizing it, according to the lawsuit.

Racine told reporters that Facebook had tried to settle the case before he filed suit, as is common during investigations of large companies, but that a lawsuit was necessary "to expedite change" at the Silicon Valley company.

Britain's data protection authority in July fined Facebook 500,000 pounds ($631,000) for breaches of data in the Cambridge Analytica incident.

Since then, Facebook has disclosed a pair of security breaches involving profile data and posts of up to 29 million users and 6.8 million users, respectively.

At least 6 US states have ongoing investigations into Facebook, according to state officials.

In March, a bipartisan coalition of 37 state attorneys wrote to the company, demanding to know more about the Cambridge Analytica data and its possible links to US President Donald Trump's election campaign.

At the same time, the Federal Trade Commission took the unusual step of announcing an investigation into whether Facebook had violated a 2011 consent decree, exposing the company to a multi-billion dollar fine.

State attorneys general have found some success taking on technology companies over data privacy. Uber Technologies Inc in September agreed to pay $148 million as part of a data breach settlement with 50 US states and Washington, D.C..

Agnieszka McPeak, a professor at Duquesne University School of Law, said states will likely make claims similar to those of D.C., pressuring Facebook into a settlement that involves both a monetary fine and modified business practices. "If a company faces 51 separate actions around the country for deceptive practices, that can have a real impact," McPeak said. 

source: news.abs-cbn.com

Friday, December 14, 2018

Police probe hoax bitcoin bomb threats across US, Canada


US law enforcement officials on Friday were investigating a wave of hoax emailed bomb threats demanding bitcoin payment that caused worry but no damage in the United States, Canada, Australia and New Zealand.

On Thursday in North America, hundreds of businesses, government offices and schools received awkwardly-worded letters threatening to set off explosives if payments of $20,000 in cryptocurrency were not received.

The threats led to scattered evacuations of schools and transit stations before the Federal Bureau of Investigation and other agencies dismissed them as lacking credibility.

Hoax threats were received in cities including Washington, New York, Detroit, San Francisco, Los Angeles, Phoenix, Oklahoma City, Grand Rapids, Iowa, Denver, Ottawa and Calgary, Alberta.

Investigators do not yet know who was responsible, 2 federal officials said on Friday. There is no evidence to suggest that any of the recipients made ransom payments, one of the officials said.

Cisco Systems Inc's Talos cyber security unit said it believes the threats came from a group of fraudsters previously responsible for sending "sextortion" emails that claim to have videos showing the recipients having sex.

The fraudsters threaten to release compromising videos they claim to have obtained with software that recorded people through webcams on their computers.

Some of this week's bomb threats came from the same internet addresses used in those sextortion campaigns, Talos researcher Jaeson Schultz said in a blog post.

"The criminals conducting these extortion email attacks have demonstrated that they are willing to concoct any threat and story imaginable that they believe would fool the recipient," the blog said.

"We expect these sorts of attacks to continue as long as there are victims who will believe these threats to be credible, and be scared enough to send money to the attackers," it said.

A similar series of hoax bomb threats occurred in December 2015, prompting officials in Los Angeles to close the city's public school system, which national law enforcement officials later criticized as an over-reaction.

Two weeks previously, a married couple inspired by Islamic State had killed 14 people at a California county office building in a shooting rampage.

A teenager with dual Israeli-US citizenship was arrested in Israel in March 2017 for making bomb threats to more than 100 Jewish organizations and Jewish community centers in dozens of US states over several months.

source: news.abs-cbn.com

Friday, December 1, 2017

UK cyber agency targets Kaspersky in warning on Russian software


Britain's main cyber security agency on Friday warned British government agencies to avoid using anti-virus software from Russian companies, the latest in a series of moves targeting Moscow-based security software maker Kaspersky Lab.

In a letter to departmental permanent secretaries, the director of the UK National Cyber Security Centre, Ciaran Martin, said Russian-made anti-virus software should not be used in systems containing information that would harm national security if it was accessed by the Russian government.

He said his agency is in talks with Kaspersky Lab to develop a system for reviewing its products for use in Britain.

Kaspersky's anti-virus software was banned from U.S. government networks earlier this year on concerns the company has close ties to intelligence agencies in Moscow and that its software could be used to enable Russian spying.

"We are in discussions with Kaspersky Lab ... about whether we can develop a framework that we and others can independently verify,” Martin said in the letter, which was publicly released.

Kaspersky Lab said in a statement that it looked forward to working with the NCSC on the issue.

Kaspersky has strongly denied allegations about the safety of its products or ties to the Russian government, saying it has become a scapegoat in the midst of rising tensions between Washington and Moscow.

source: news.abs-cbn.com

Friday, November 10, 2017

App errors expose data on 180 million phones: security firm


A simple coding error in at least 685 apps put millions of smartphone users at risk of having some of their calls and text messages intercepted by hackers, cyber-security firm Appthority warned on Thursday.

Developers mistakenly coded credentials for accessing text messaging, calling and other services provided by Twilio Inc , said Appthority's director of security research, Seth Hardy. Hackers could access those credentials by reviewing the code in the apps, then gain access to data sent over those services, he said.

Affected apps include the AT&T Navigator app pre-installed on many Android phones and more than a dozen GPS navigation apps published by Telenav Inc. Such apps have been installed as many as 180 million times on Android phones and an unknown number of times on Apple's iOS-based devices.

Shares of Twilio slid nearly 7 percent after the Appthority report. Hackers covet Twilio credentials because they are used in a variety of apps that send text messages, process phone calls and handle other services. Hackers could access related data if they log into a developer's Twilio account, Hardy said.

Appthority, cautious not to tip off potential hackers, did not list all the apps that could be vulnerable. Twillio's website says its users include Uber Technologies Inc and Netflix Inc. However, large companies like those typically have security reviews that catch common coding errors like the one Appthority described.

There was no indication that Uber or Netflix were affected by the problem.

The findings highlight new threats posed by the increasing use of third-party services such as Twilio, which says on its website that it powers communications for more than 40,000 businesses worldwide. Developers can inadvertently introduce security vulnerabilities if they do not properly code or configure such services.

“This isn't just limited to Twilio. It's a common problem across third-party services," Hardy said. "We often notice that if they make a mistake with one service, they will do so with other services as well.”

Appthority said it also warned Amazon.com Inc that it had found credentials for at least 902 developer accounts with cloud-service provider Amazon Web Services in a scan of 20,098 different apps.

Those credentials could be used to access app user data stored on Amazon, Hardy said.

A representative with Amazon declined comment.

One problem with third-party services is that developers often use the same account across multiple apps, similar to how consumers might use one email address for a variety of financial services and can have fraud problems at all of them if hackers compromise that single email account.

Appthority found Twilio credentials exposed in a now-defunct version of the AT&T Navigator mapping and GPS app. The AT&T app was a re-branded version of an app originally built by Telenav.

Appthority found that newer versions of the AT&T app appeared to be safe, but data sent over them could still be at risk if the developer of a related app is still using the same Twilio account. It said the same Twilio credentials were found coded in more than a dozen other Telenav apps.

AT&T and Telenav could not immediately be reached for comment.

The mistakes were caused by developers, not Twilio, Hardy said. Twilio's website warns developers that leaving credentials in apps could expose their accounts to hackers.

Twilio spokesman Trak Lord said the company has no evidence that hackers used credentials coded into apps to access customer data but was working with developers to change credentials on affected accounts.

The Twilio vulnerability only affects calls and texts made inside of apps that use its messaging services, including some business apps for recording phone calls such as Wrappup and RingDNA, according to Appthority's report. Wrappup an RingDNA could not immediately be reached for comment.

In a survey of 1,100 apps, Appthority found 685 problem apps that were linked to 85 affected Twilio accounts. That suggests the theft of credentials for one app's Twilio account could pose a security threat to all users of as many as eight other apps.

Twilio's shares closed down 6.8 percent at $25.93. Shares had rallied in pre-market trading after Twilio beat revenue expectations and raised its revenue forecast during an earnings report after the markets closed on Wednesday.

source: news.abs-cbn.com

Monday, October 30, 2017

iPhone X brings face recognition (and fears) to the masses


WASHINGTON - Apple will let you unlock the iPhone X with your face -- a move likely to bring facial recognition to the masses, along with concerns over how the technology may be used for nefarious purposes.

Apple's newest device, set to go on sale November 3, is designed to be unlocked with a facial scan with a number of privacy safeguards -- as the data will only be stored on the phone and not in any databases.

Unlocking one's phone with a face scan may offer added convenience and security for iPhone users, according to Apple, which claims its "neural engine" for FaceID cannot be tricked by a photo or hacker.

While other devices have offered facial recognition, Apple is the first to pack the technology allowing for a three-dimensional scan into a handheld phone.

But despite Apple's safeguards, privacy activists fear the widespread use of facial recognition would "normalize" the technology and open the door to broader use by law enforcement, marketers or others of a largely unregulated tool.

"Apple has done a number of things well for privacy but it's not always going to be about the iPhone X," said Jay Stanley, a policy analyst with the American Civil Liberties Union.

"There are real reasons to worry that facial recognition will work its way into our culture and become a surveillance technology that is abused."

A study last year by Georgetown University researchers found nearly half of all Americans in a law enforcement database that includes facial recognition, without their consent.

Civil liberties groups have sued over the FBI's use of its "next generation" biometric database, which includes facial profiles, claiming it has a high error rate and the potential for tracking innocent people.

"We don't want police officers having a watch list embedded in their body cameras scanning faces on the sidewalk," said Stanley.

Clare Garvie -- the Georgetown University Law School associate who led the 2016 study on facial recognition databases -- agreed that Apple is taking a responsible approach but others might not.

"My concern is that the public is going to become inured or complacent about this," Garvie said.

ADVERTISERS, POLICE, PORN STARS

Widespread use of facial recognition "could make our lives more trackable by advertisers, by law enforcement and maybe someday by private individuals," she said.

Garvie said her research found significant errors in law enforcement facial recognition databases, opening up the possibility someone could be wrongly identified as a criminal suspect.

Another worry, she said, is that police could track individuals who have committed no crime simply for participating in demonstrations.

Shanghai and other Chinese cities have recently started deploying facial recognition to catch those who flout the rules of the road, including jaywalkers.

Facial recognition and related technologies can also be used by retail stores to identify potential shoplifters, and by casinos to pinpoint undesirable gamblers.

It can even be used to deliver personalized marketing messages -- and could have some other potentially unnerving applications.

Last year, a Russian photographer figured out how to match the faces of porn stars with their social media profiles to "doxx" them, or reveal their true identities.

This type of use "can create huge problems," said Garvie. "We have to consider the worst possible uses of the technology."

Apple's system uses 30,000 infrared dots to create a digital image which is stored in a "secure enclave," according to a white paper issued by the company on its security. It said the chances of a "random" person being able to unlock the device are one in a million, compared with one in 50,000 for its TouchID.

LEGAL BATTLE BREWING

Apple's FaceID is likely to touch off fresh legal battles about whether police can require someone to unlock a device.

FaceID "brings the company deeper into a legal debate" that stemmed from the introduction of fingerprint identification on smartphones, according to ACLU staff attorney Brett Max Kaufman.

Kaufman says in a blog post that courts will be grappling with the constitutional guarantees against unreasonable searches and self-incrimination if a suspect is forced to unlock a device.

US courts have generally ruled that it would violate a user's rights to give up a passcode because it is "testimonial" -- but that situation becomes murkier when biometrics are applied.

Apple appears to have anticipated this situation by allowing a user to press 2 buttons for 2 seconds to require a passcode, but Garvie said court battles over compelling the use of FaceID are likely.

Regardless of these concerns, Apple's introduction is likely to bring about widespread use of facial recognition technology.

"What Apple is doing here will popularize and get people more comfortable with the technology," said Patrick Moorhead, principal analyst at Moor Insights & Strategy, who follows the sector.

"If I look at Apple's track record of making things easy for consumers, I'm optimistic users are going to like this."

Garvie added it is important to have conversations about facial recognition because there is little regulation governing the use of the technology.

"The technology may well be inevitable," she said.

"It is going to become part of everyone's lives if it isn't already."

source: news.abs-cbn.com

Thursday, September 14, 2017

Trump administration orders purge of Kaspersky products


WASHINGTON - The Trump administration on Wednesday told U.S. government agencies to remove Kaspersky Lab products from their information systems, saying it was concerned the Moscow-based cyber security firm was vulnerable to Kremlin influence.

The decision represents a sharp response to what U.S. intelligence agencies have described as a national security threat posed by Russia in cyberspace, following an election year marred by allegations that Moscow weaponized the internet in an attempt to influence its outcome.

In a statement, Kaspersky Lab rejected the allegations, as it has done repeatedly in recent months, and said its critics were misinterpreting Russian data-sharing laws that only applied to communications services.

“No credible evidence has been presented publicly by anyone or any organization as the accusations are based on false allegations and inaccurate assumptions,” the company said.

The Department of Homeland Security issued a directive to federal agencies ordering them to identify Kaspersky products on their information systems within 30 days and begin to discontinue their use within 90 days.

“The Department is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks,” the agency said in a statement.

The department said it would provide Kaspersky with the opportunity to submit a written response to address the allegations. The agency said other entities claiming commercial interests affected by the directive could also submit information

Kaspersky Lab has repeatedly denied that it has ties to any government and said it would not help a government with cyber espionage.

However, the company has not been able to shake off the allegations. Last week, Best Buy Co (BBY.N), the No.1 U.S. electronics retailer, said it was pulling Kaspersky Lab’s cyber security products from its shelves and website.

Rob Joyce, the White House cyber security coordinator, said Wednesday at the Billington CyberSecurity Summit that the Trump administration made a “risk-based decision” to order Kaspersky Lab’s products removed from federal agencies.

Asked by Reuters whether there was a smoking gun showing Kaspersky Lab had provided intelligence to the Russian government, Joyce replied: ”As we evaluated the technology, we decided it was a risk we couldn’t accept.”

Some cyber security experts have warned that blacklisting Kaspersky Lab could prompt a retaliation from Russian President Vladimir Putin. Joyce said those concerns were a factor but that a “tough decision” ultimately had to be made to protect government systems.

The direct financial impact of the decision will likely be minimal for Kaspersky Lab, one of the world’s leading antivirus software companies, which was founded in 1997 and now counts over 400 million global customers.

Federal contracting databases reviewed by Reuters show only a few hundred thousand dollars in purchases from Kaspersky, and an employee told Reuters in July the company’s federal government revenue was “miniscule.”

But Kaspersky also sells to federal contractors and third-party software companies that incorporate its technology in their products, so its technology may be more widely used in government than it appears from the contracting databases, U.S. officials say.

The decision by the Trump administration came as the U.S. Senate was planning to vote as soon as this week on a defense policy spending bill that includes language that would ban Kaspersky Lab products from being used by U.S. government agencies.

Democratic Senator Jeanne Shaheen, who had led efforts in Congress to crack down on Kaspersky Lab, applauded the Trump administration’s announcement.

“The strong ties between Kaspersky Lab and the Kremlin are alarming and well-documented,” Shaheen said, adding that she expected Congress to act soon to reinforce the decision by passing legislation.

Eugene Kaspersky, the company’s co-founder and chief executive, attended a KGB school, and the company has acknowledged doing work for the Russian intelligence agency known as the FSB. But he has adamantly denied charges his company conducts espionage on behalf of the Russian government.

source: news.abs-cbn.com

Wednesday, August 9, 2017

How safe is free public Wi-Fi?


President Rodrigo Duterte recently enacted a law providing free internet access in public places nationwide.

The law, which requires a mandated minimum internet speed per user of two megabits per second (2 Mbps) is expected to get more Filipinos online. However, logging in to a free Wi-Fi access may carry security risks.

Cyber security firm Kaspersky Lab has identified free Wi-Fi as one of the biggest security risks for computer and mobile internet users.

A 2016 survey of the firm revealed that 71 percent of respondents said they use unsecured public Wi-Fi in bars and fastfood restaurants.

Meanwhile, 15 percent use free public Wi-Fi for bank transactions and online payments.

Department of Information Communication Technology (DICT) Asst. Sec. Allan Cabanlong admitted that although there are risks in using free public Wi-Fi services, the government ensured that its project is safe for public use.

"We made sure that the free Wi-Fi of the DICT is only 100 mbps... For the hacker to use it, it may be questionable because 100 mbps is not enough to hack someone," he said.

Cabanlong advised the public to be wary of the public Wi-Fi providers by checking the names and spellings.


-ANC Future Perfect, August 09, 2017

source: news.abs-cbn.com

Thursday, July 13, 2017

Apple unveils iCloud center in China as cyber laws tightened


SHANGHAI - Apple has unveiled plans to build a data center in China to store its local iCloud customers' personal details, marking the first such move by a foreign technology firm following the imposition of strict new cyber-security laws in the country.

The US titan said it was partnering with an internet service provider in southwestern Guizhou province on the project, which will "improve the speed and reliability of our products and services while also complying with newly passed regulations."

It appeared to be referring to the June 1 implementation of a new law that, among other things, requires tech companies to store user data inside the country.

Some foreign firms have said the law is worryingly vague on key provisions and expressed concern over the potential impact on their business in the world's second-largest economy.

The law also further tightens Chinese curbs on web content, banning the publishing of anything that "disturbs economic or social order" or is aimed at overthrowing the government.

But Apple issued a statement seeking to allay fears that data-security could somehow be monitored or compromised by China's government or other parties.

"Apple has strong data privacy and security protections in place and no backdoors will be created into any of our systems," it said in the statement released Wednesday.

The firm did not give any financial details of the project, but China's state-run Xinhua news agency said it was part of a $1 billion investment.

China has hundreds of millions of smartphone users and is a vital market for Apple, whose iPhones are wildly popular in the country.

Fu Liang, a Beijing-based independent telecom analyst, said more foreign data centers were expected under the cyber-security legislation.

"The new rule requires this key information to be put in China. The boundary is very clear," Fu said.

He said the ramifications for Apple and other companies could be higher costs and potentially more restrictions under Chinese law.

"For (Apple) users, the good thing is their user experience like download speed will improve but the downside is that their access to overseas services and resources will be reduced," Fu added.

"It will be harder for them to access services that aren’t allowed in China now."

Computer and data security has become a top international concern following recent cyber attacks including the global ransomware contagion in May that affected government, industrial, academic and other computing systems in more than 150 countries.

The six-month-old administration of US President Donald Trump has been dogged by allegations that his candidacy benefitted from Russian hacking aimed at discrediting his campaign opponent Hillary Clinton.

The finger also has been pointed at Moscow for interference in the recent French elections, and Germany's domestic security watchdog warned last week that the country would likely face Russian cyber attacks heading into September's general election.

source: news.abs-cbn.com

Monday, July 10, 2017

Trump says discussed forming cyber security unit with Putin


US President Donald Trump said on Twitter on Sunday that he discussed forming a cyber security unit to guard against election hacking with Russian President Vladimir Putin.

Tweeting after his first meeting with Putin on Friday, Trump said now was the time to work constructively with Moscow, pointing to a ceasefire deal in southwest Syria that came into effect on Sunday.

"Putin & I discussed forming an impenetrable Cyber Security unit so that election hacking, & many other negative things, will be guarded and safe," he said following their talks at the G20 summit in Hamburg, Germany.

Trump said he had raised allegations of Russian interference in the 2016 US presidential election with Putin.

"I strongly pressed President Putin twice about Russian meddling in our election. He vehemently denied it. I've already given my opinion....."

He added: "We negotiated a ceasefire in parts of Syria which will save lives. Now it is time to move forward in working constructively with Russia!"

Republican Senator Marco Rubio of Florida immediately criticized the move on Twitter, saying Putin was not a trusted partner.

Partnering with Putin on a "Cyber Security Unit" is akin to partnering with (Syrian President Bashar al) Assad on a "Chemical Weapons Unit," he wrote.

Investigations by a special counsel, Robert Mueller, and several US congressional committees are looking into whether Russia interfered in the election and colluded with Trump's campaign. Those probes are focused almost exclusively on Moscow’s actions, lawmakers and intelligence officials say, and no evidence has surfaced publicly implicating other countries.

Moscow has denied any interference, and Trump says his campaign did not collude with Russia.

(This version of the story corrects the day of meeting in second paragraph to Friday)

(Reporting by David Stamp, Valerie Volcovici and Yasmeen Abutaleb; Editing by Janet Lawrence)

source: news.abs-cbn.com