Showing posts with label Data Breach. Show all posts
Showing posts with label Data Breach. Show all posts

Sunday, April 4, 2021

Data from 500 million Facebook accounts posted online: reports

WASHINGTON - Data affecting more than 500 million Facebook users that was originally leaked in 2019, including email addresses and phone numbers, has been posted on an online hackers forum, according to media reports and a cybercrime expert.

"All 533,000,000 Facebook records were just leaked for free," Alon Gal, chief technology officer at the Hudson Rock cybercrime intelligence firm, said Saturday on Twitter.

He denounced what he called the "absolute negligence" of Facebook.

Some of the data appeared to be current, according to a report in Business Insider which AFP was unable to confirm independently. It said some of the leaked phone numbers still belong to the owners of Facebook accounts.

"This means that if you have a Facebook account, it is extremely likely the phone number used for the account was leaked," Gal said. 

But Facebook said the reports were old news.

"This is old data that was previously reported on in 2019," a company spokesperson told AFP. "We found and fixed this issue in August 2019."

Close to 32 million American accounts and 20 million French accounts were among those affected, Gal tweeted in January, when the person holding the data was trying to sell it. 

The data include phone numbers, complete names, birthdates and, for some accounts, email addresses and relationship status.

"Bad actors will certainly use the information for social engineering, scamming, hacking and marketing," Gal said on Twitter.

This is not the first time leaks or use of data from the world's largest social network -- with nearly two billion users -- has embroiled Facebook in controversy.

In 2016, a scandal around Cambridge Analytica, a British consulting firm that used the personal data of millions of Facebook users to target political ads, cast a shadow over the social network and its handling of private information.

Agence France-Presse

Wednesday, December 9, 2020

US-based hacker fighter FireEye says breached by elite attackers

SAN FRANCISCO - Hacker fighting firm FireEye on Tuesday said its own defenses were breached by sophisticated attackers who stole "Red Team" tools used to test customers' computer systems.

While the hackers had yet to be identified, their tactics and targets led FireEye to believe it was a state-sponsored attack "by a nation with top-tier offensive capabilities."

"The hack of a premier cybersecurity firm demonstrates that even the most sophisticated companies are vulnerable to cyber-attacks," said US Senator Mark Warner, a Democrat who is vice chairman of the

 senate Select Committee on Intelligence.

"We have come to expect and demand that companies take real steps to secure their systems, but this case also shows the difficulty of stopping determined nation-state hackers."

It did not appear any customer data was stolen from FireEye, or that the taken tools have been used in other attacks, according to the Silicon Valley-based firm.

"The attackers tailored their world-class capabilities specifically to target and attack FireEye," FireEye chief executive Kevin Mandia said in a blog post revealing the breach.

"They used a novel combination of techniques not witnessed by us or our partners in the past."

FireEye shares were down more than 7 percent in after-market trades that followed released of news about the hack.

RELENTLESS ATTACKS

FireEye said it is investigating the attack with help from the FBI and industry partners, including technology colossus Microsoft.

"Their initial analysis supports our conclusion that this was the work of a highly sophisticated state-sponsored attacker utilizing novel techniques," Mandia said.

The hackers primarily sought information related to government customers which is consistent with nation-state cyberespionage, according to FireEye.

Also targeted in the attack were "Red Team" tools that help diagnose the security of customers' networks by mimicking the behavior of hackers, Mandia said.

FireEye was making available countermeasures to defend against someone using the tools.

The US Department of Homeland Security said it was aware of the attack but that it had no information indicating the stolen cyber tools were being "maliciously used" so far.

US spy agencies have been asked to brief the House Permanent Select Committee on Intelligence about the cyber attack in the coming days, according to chairman Adam Schiff, a Democrat from California.

"Foreign actors have not stopped attacking our country and its critical and cybersecurity infrastructure since 2016," Schiff said.

Schiff found it troubling that the hackers stole from FireEye tools that could be used in future attacks.

OIL-BANKS-POLITICS

The FireEye hack came less than two months after the US Treasury announced sanctions against a Russian research institute which it said was tied to the powerful malware Triton, used to damage a Saudi petrochemical plant in 2017.

FireEye tied Triton to the Moscow-based research institute and a specific, unnamed person with close ties to the institute.

It was not determined whether Russia was linked to the FireEye hack.

"The Russian government continues to engage in dangerous cyber activities aimed at the United States and our allies," Treasury Secretary Steven Mnuchin said in a statement at the time.

FireEye's track record includes identifying an Iran-based social media campaign to sway public opinion by impersonating reporters, politicians and others, as well as identifying North Korean hackers implicated in of a wave of cyberattacks on global banks that netted "hundreds of millions" of dollars.

Agence France-Presse

Friday, September 27, 2019

Facebook wins dismissal of investor lawsuit over privacy breach


NEW YORK, United States - Facebook Inc and its chief executive Mark Zuckerberg on Thursday won dismissal of an investor lawsuit accusing them of deceiving investors about the likely impact of a privacy breach on its stock price, though the investors will be have a chance to refile their case.

US District Judge Edward Davila in San Jose, California said the investors had failed to allege that Facebook or its executives knowingly made false statements that led to investor losses.

Facebook and lawyers for the investors could not immediately be reached for comment.

The class action lawsuit, which was consolidated from several investor complaints filed since last year, also targeted Facebook chief organization officer Sheryl Sandberg and chief financial officer David Wehner.

The investors focus on a privacy breach, first reported in December 2015, that allowed Cambridge Analytica, a British political consulting firm, to access data for an estimated 87 million Facebook users.

In March 2018, multiple media outlets reported that Facebook was still allowing third parties to access user data, and that data from the Cambridge Analytica breach had been used in connection with US President Donald Trump's campaign. The reports caused the company's stock price to drop more than 18 percent in two weeks.

In July 2018, Facebook's stock price dropped sharply again, by nearly 19 percent, immediately after the company revealed in its quarterly earnings report that growth in the number of active users was slowing and total revenues was declining.

The investors claimed in their lawsuit that Facebook and its executives made dozens of statements downplaying the effect that the Cambridge Analytica leak and related user privacy issues would have on its stock price.

Davila, however, said Thursday that they had failed to identify specific instances of the company or its executives knowingly making false statements. He noted that some were forward-looking predictions and others were general expressions of optimism, which generally cannot be the basis for securities fraud lawsuits.

The judge gave the investors until Oct. 26 to file a new version of their complaint, saying it was "possible plaintiffs can cure their allegations by alleging, among other things, more particular facts as to why statements by the individual defendants were false when made."

Facebook is separately facing a nationwide lawsuit from users seeking to hold the company liable under various state and federal laws for allowing third parties, including Cambrdige Analytica, to access their data.

source: news.abs-cbn.com

Sunday, September 30, 2018

Privacy watchdog probes Facebook security breach


MANILA - The National Privacy Commission said Sunday it has begun probing the security breach reported by Facebook, which logged out millions of users last Friday. 

Facebook had already posted a "security update" statement, explaining how a "security issue" affected around 50 million Facebook accounts. 

But lawyer Kiko Acero from the commission's Complaints and Investigation Division said they still need a clearer explanation on what really happened. 

"Kung ginamit siya ng isang taong may malicious intent, hinahanap namin sino yung naging pabaya sa problemang 'to… Lahat 'yan tinitignan namin," he said. 

(If it was used by a person with malicious intent, we want to know who is liable for this problem. We are looking into all of this.)

In a statement, Facebook said they took immediate measures upon learning the security issue, which caused around 90 million Facebook users worldwide to be logged out of their accounts. 

"Our investigation is still in its early stages. But it’s clear that attackers exploited a vulnerability in Facebook’s code that impacted 'View As' a feature," Facebook said. 

"This allowed them to steal Facebook access tokens which they could then use to take over people’s accounts. Access tokens are the equivalent of digital keys that keep people logged in," it added.

Manila Bulletin technology news editor Art Samaniego said the Facebook users who were logged out of their accounts could be potential targets of hackers.

Samaniego said this may put all other social media sites and service applications connected to an account at risk because "token sessions" are involved. 

"Ito yung digital signature natin na pag nag-log in sa Facebook, malalaman ng apps and services na ikaw 'yun. Pag nag-log in ka via Facebook makukuha 'yung mga details mo," he said. 

(This is our digital signature when we log into Facebook, which lets apps and services know that it is you. When you log in via Facebook, your details will be known.)

"Ibig-sabihin pag nanakaw to (token sessions) ng mga hacker. Puwede niya ma-log in 'yun sa mga services na ginagamit mo halimbawa Instagram, WhatsApp, Tindr," he added.

(This means that if these tokens are stolen by hackers, they can log into the services you use like Instagram, WhatsApp, Tindr.)

Samaniego urged users to use two-factor authentication for their accounts. He also discouraged netizens from using the same passwords for different accounts.

source: news.abs-cbn.com

British ministers' phone numbers leaked in app flaw


LONDON - Phone numbers and other personal details of senior ministers from Britain's Conservative party were made public by an app security flaw on Saturday, including those of top Brexiteers Michael Gove and Boris Johnson.

Several top MPs reportedly received nuisance calls after their profiles were accessed on the official mobile application for the annual party conference, which kicks off this weekend.

The security breach saw members of the public able to enter the profiles using just the politicians' email addresses -- easily available online -- to view and edit the data stored within.

Former foreign secretary Johnson had his profile picture briefly swapped for pornography and his job title changed to an profane insult, according to several Twitter users.

Meanwhile Environment Secretary Gove's picture was changed to one of media tycoon Rupert Murdoch, his former employer when he was a journalist.

Among the first to report the flaw was Dawn Foster, a columnist for daily The Guardian.

"The Tory conference app allows you to log in as other people and view their contact details just with their email address, no emailed security links, and post comments as them," she wrote on Twitter, using a colloquial name for the party.

"They've essentially made every journalist, politician and attendee's mobile number public. Fantastic."

A Conservative party spokesperson apologized for the breach, saying the technical issue had "been resolved and the app is now functioning securely".

Britain's data watchdog, the Information Commissioner's Office (ICO), said it was investigating the data breach related to the app, which was developed by an Australian firm called Crown Comms.

The opposition Labor Party said the blunder showed the ruling party could not be trusted in matters of security.

"They can't even build a conference app that keeps the data of their members, MPs and others attending safe and secure," said shadow cabinet office minister Jon Trickett.

The breach is the latest embarrassment for Prime Minister Theresa May's embattled party, whose yearly gathering begins on Sunday in the city of Birmingham in central England.

Last year's conference was peppered with mishaps, with May's attempt to move past Brexit splits marred by a protest, a collapsing set and a coughing fit.

During the 2017 event, a prankster interrupted the leader's address by handing her a P45 -- a form given to those leaving a job.

No sooner had she resumed, May began coughing uncontrollably and continued to struggle on and off throughout the rest of the speech, as 2 letters fell off the slogan on the wall behind her.

source: news.abs-cbn.com

Thursday, July 26, 2018

Facebook hammered as user growth cools


SAN FRANCISCO, United States - Facebook shares took a hit Wednesday after the world's biggest social network reported weaker-than-expected user growth in the first full quarter since being rocked by a series of scandals on data privacy.

The company said profit was up 31 percent in the second quarter at $5.1 billion as revenues rose 42 percent to $13.2 billion.

But shares slumped 7 percent in after-hours exchanges after hitting record levels in official trading, with the quarterly report largely weaker than had been expected.

"Our community and business continue to grow quickly. We are committed to investing to keep people safe and secure, and to keep building meaningful new ways to help people connect," chief executive Mark Zuckerberg said.

Zuckerberg has said he did not expect a meaningful impact from the uproar over data hijacked by political consulting firm Cambridge Analytica, but the last quarter's figures suggested some cooling.

The key metric of monthly active users rose 11 percent to 2.23 billion, below most estimates of 2.25 billion, while daily active users grew a weaker-than-expected 11 percent to 1.47 billion.

Almost all of Facebook's revenue -- $13 billion of the total $13.2 billion -- came from online advertising, a sector dominated by the California social network along with Silicon Valley rival Google.

Although Facebook shares were in a slump after the Cambridge Analytica scandal broke earlier this year, the stock had risen sharply and hit record levels this month.

According to the research firm eMarketer, Facebook is expected to hold an 18 percent share of the $273.29 billion worldwide digital ad market, behind Google's 31 percent.

According to the research firm, Facebook-owned Instagram is making up for some of the slowdown in growth at social network and will generate $8.06 billion in worldwide ad revenue this year.

source: news.abs-cbn.com

Wednesday, April 11, 2018

#ZuckerBowl without a clear winner as Facebook hearings end


WASHINGTON - Facebook founder Mark Zuckerberg emerged largely unscathed Wednesday from 2 days of high-stakes hearings that saw US lawmakers grill the billionaire over how the online giant feeds users' data to advertisers and chide him over privacy rights.

The marathon 10 hours of questioning was one of the biggest spectacles in Congress in recent memory, followed blow by blow on social media under the hashtags #ZuckerBowl and #ZuckUnderOath.

Channeling public anger over data privacy lapses -- including most spectacularly the leak of personal information from 87 million Facebook users to a political consultant -- lawmakers in both House and Senate raised the specter of regulations to bring online firms to heel.

The 33-year-old CEO conceded that some regulation of social media companies is "inevitable," while offering a laundry list of reform pledges at Facebook and vowing to improve privacy and security.

But he stiffly defended Facebook's business model -- specifically the way it uses data and postings from the 2.2 billion users of its free platform -- calling it necessary to attract ad revenue the $480 billion company depends on.

In the wake of the massive leak of user information to Cambridge Analytica, which worked for Donald Trump's 2016 campaign, Zuckerberg reiterated that the company had shut down the pipeline that allowed data -- including his own -- to slip without consent into the hands of third parties.

A day earlier Zuckerberg took personal responsibility for the data breach.

Yet in his testimony to the House Energy and Commerce Committee, he was also steadfast in arguing that Facebook's users themselves are choosing to make their data available, and that the company's "opt-in" provisions offered them sufficient control.

"Every time that a person chooses to share something on Facebook, they're proactively going to the service and choosing that they want to share a photo, write a message to someone."

"Every time there is a control right there," Zuckerberg said.

'REAL TRUST GAP' 

Zuckerberg faced tougher questions from House lawmakers over Facebook's stance than during Tuesday's 5-hour session in the Senate, where his defense of data sharing was weakly challenged.

"It strikes me that there's a real trust gap here. Why should we trust you?" asked Democratic Representative Mike Doyle.

"The only way we're going to close this trust gap is through legislation that creates and empowers a sufficiently resourced expert oversight agency, with rule-making authority to protect the digital privacy and ensure that companies protect our users' data."

A PATH FORWARD 

Some analysts said Zuckerberg's appearance suggests a new path forward for social media under closer scrutiny.

"Zuckerberg's testimony demonstrated that the company has matured over the last decade, in particular in his acknowledgement that Facebook is responsible for the content shared on its platform," said University of Delaware communications professor Dannagal Young. 

"Acknowledging responsibility for the content shared on the platform changes how Facebook ought to engage in gate-keeping and fact-checking, and how the government might go about regulating the industry."

Syracuse University professor Jennifer Grygiel called the hearings "an important milestone."

"This is a first step in the process of writing much needed regulation," she said.

"It is clear from congressional testimony that self-regulation alone is not working and that regulatory oversight is needed in the United States in order to ensure safe social media."

'GLARING GAPS' IN UNDERSTANDING 

Noting that a European data protection standard due to come into effect on May 25 was more stringent than what was currently in place at Facebook, Zuckerberg suggested it could serve as a rough model for US rules in the future.

Facebook is implementing the General Data Protection Regulation (GDPR) standard for European users next month, and some of its rules will be extended to US and other users later, he confirmed.

"The GDPR requires us to do a few more things and we are going to extend that to the world," he said.

By one measure, Zuckerberg succeeded in his Washington appearance. Facebook shares rose five percent on Tuesday and added another 0.78 percent Wednesday in what was seen as a sign of confidence in the company after steep losses in recent weeks.

"To me, he came across as very conciliatory, especially when he took full responsibility for the mistakes of his company," said Jessica Vitak, head of the University of Maryland's Privacy and Education Research Lab.

"This seems to be a relatively new approach for the company and I believe at least in part responding to critique of Facebook's slow and somewhat tone-deaf response to prior breaches that have led to user outrage."

Others noted however that lawmakers had demonstrated little knowledge of how Facebook works -- potentially complicating any regulatory effort.

"Perhaps the most important revelation of Zuckerberg's testimony are the glaring gaps in our lawmakers' understanding of the internal logic and business model of Facebook," Young said.

"No one is going to be able to sufficiently regulate' Facebook until lawmakers are adequately educated about how it works."

source: news.abs-cbn.com

Facebook CEO says his own data was shared with Cambridge Analytica


WASHINGTON/SAN FRANCISCO - Facebook Inc Chief Executive Mark Zuckerberg on Wednesday told lawmakers that his own personal data was included in that of 87 million or so Facebook users that were improperly shared with political consultancy Cambridge Analytica.

But he pushed back on congress members' suggestions that users do not have enough control of their data on Facebook in the wake of the privacy scandal at the world's largest social media network.

"Every time that someone chooses to share something on Facebook ... there is a control. Right there. Not buried in the settings somewhere but right there," the 33-year-old internet magnate told the U.S. House of Representatives Energy and Commerce Committee.

Once again wearing a dark suit instead of his usual gray T-shirt, the hearing was Zuckerberg's second in two days. On Tuesday, he took questions for nearly five hours in a U.S. Senate hearing without making any further promises to support new legislation or change how the social network does business, foiling attempts by senators to pin him down.

Investors were impressed with his initial performance. Shares in Facebook posted their biggest daily gain in nearly two years on Tuesday, closing up 4.5 percent. They were down 0.7 percent in early trading on Wednesday.

Facebook has been consumed by turmoil for nearly a month, since it came to light that millions of users' personal information were wrongly harvested from the website by Cambridge Analytica, a political consultancy that has counted U.S. President Donald Trump's election campaign among its clients.

Zuckerberg faced broad concerns from members of Congress about how Facebook shares user data.

"How can consumers have control over their data when Facebook does not have control over the data?" asked Representative Frank Pallone of New Jersey, the ranking Democrat on the Energy and Commerce committee.

The latest estimate of affected users is up to 87 million.

Patience with the social network had already worn thin among users, advertisers and investors after the company said last year that Russia used Facebook for years to try to sway U.S. politics, an allegation Moscow denies.

Lawmakers have sought assurances that Facebook can effectively police itself, and few came away from Tuesday's hearing expressing confidence in the social network.

"I don't want to vote to have to regulate Facebook, but by God, I will," Republican Senator John Kennedy told Zuckerberg on Tuesday. "A lot of that depends on you."

Zuckerberg deflected requests to support specific legislation. Pressed repeatedly by Democratic Senator Ed Markey to endorse a proposed law that would require companies to get people's permission before sharing personal information, Zuckerberg agreed to further talks.

"In principle, I think that makes sense, and the details matter, and I look forward to having our team work with you on fleshing that out," Zuckerberg said.

(Reporting by Dustin Volz and David Shepardson in Washington and David Ingram in San Francisco Editing by Bill Rigby and Susan Thomas)

source: news.abs-cbn.com

'My mistake': Key Zuckerberg quotes in Senate Facebook grilling


WASHINGTON - Facebook chief Mark Zuckerberg appeared before US lawmakers Tuesday to apologize for how his company has handled the growing furor over online privacy, to promise change, and explain the social media giant's policies.

The wide-ranging questions -- including about Cambridge Analytica, which used data scraped from 87 million Facebook users to target political ads ahead of the 2016 US election -- put the 33-year-old billionaire under a microscope for several hours at a joint Senate committee hearing.

Here are top quotes from Zuckerberg, and some of the dozens of senators who grilled him. 

SETTING THINGS STRAIGHT 

"We didn't take a broad enough view of our responsibility, and that was a big mistake. And it was my mistake, and I'm sorry. I started Facebook, I run it, and I'm responsible for what happens here."

"When we heard back from Cambridge Analytica that they had told us that they weren't using the data and deleted it, we considered it a closed case. In retrospect, that was clearly a mistake. We shouldn't have taken their word for it. We've updated our policy to make sure we don't make that mistake again."

"It will take some time to work through all the changes we need to make across the company. I'm committed to getting this right. This includes the basic responsibility of protecting people's information, which we failed to do with Cambridge Analytica."

"We're investigating every single app that had access to a large amount of information in the past. And if we find that someone improperly used data, we're going to ban them from Facebook and tell everyone affected.

RUSSIAN ALARM 

"One of my greatest regrets in running the company is that we were slow in identifying the Russian information operations in 2016."

"There are people in Russia whose job it is to try to exploit our systems and other internet systems.... So this is an arms race. They're going to keep getting better and we need to invest in getting better at this too."

TRUMP AND SPECIAL COUNSEL 

Asked if Facebook executives have been interviewed by special counsel Robert Mueller, who is investigating Russian interference in the US election: "Our work with the special counsel is confidential.... I actually am not aware of a subpoena. I believe there may be, but I know we're working with them."

"I know we did help out the Trump campaign overall in sales support in the same way we do with other campaigns."

CHALLENGES AHEAD 

"There will always be a version of Facebook that is free."

"We need to take a more active view in policing the ecosystem and watching and looking out and making sure that all the members in our community are using these tools in a way that's going to be good and healthy."

Asked if he believes the social media giant, with over two billion users worldwide, amounts to a monopoly: "It certainly doesn't feel like that to me."

RIGHT TO PRIVACY

Senator Dick Durbin: "Would you be comfortable sharing with us the name of the hotel you stayed in last night? If you messaged anybody this week, would you share with us the names of the people you've messaged?"

Zuckerberg: "Senator, no I would probably not choose to do that publicly here."

Durbin: "I think that may be what this is all about: your right to privacy, the limits of your right to privacy, and how much you give away in modern America in the name of connecting people around the world."

PRESSURE IS ON

Senator John Thune: "This should be a wake-up call for the tech community.... We're listening, America is listening, and quite possibly the world is listening too."

Senator Bill Nelson: "Let me just cut to the chase. If you and other social media companies do not get your act in order, none of us are going to have any privacy anymore."

source: news.abs-cbn.com

Zuckerberg apologizes to Congress over massive Facebook breach


WASHINGTON, United States - Facebook chief Mark Zuckerberg apologized to US lawmakers Tuesday for the leak of personal data on tens of millions of users as he faced a day of reckoning before a Congress mulling regulation of the global social media giant.

In his first-ever US congressional appearance, the Facebook founder and chief executive sought to quell the storm over privacy and security lapses at the social network that have angered lawmakers and Facebook's two billion users.

Swapping his customary tee-shirt for a business suit and tie, Zuckerberg faced tough questions over how a US-British political research firm, Cambridge Analytica, plundered detailed personal data on 87 million users to be used in the 2016 US presidential election.

Facebook also became the platform of choice for a stunning Russian campaign of online misinformation that US intelligence says was designed to tilt the 2016 vote toward Donald Trump.

"It was my mistake, and I'm sorry," Zuckerberg said in prepared testimony. "I started Facebook, I run it, and I'm responsible for what happens here."

"It's clear now that we didn't do enough to prevent these tools from being used for harm," he said. "That goes for fake news, foreign interference in elections, and hate speech, as well as developers and data privacy." 

Lawmakers questioned whether the election meddling and poor controls on personal data requires the government to step in to regulate Facebook and other social media companies which generate revenue from user data.

"The tech industry has an obligation to respond to widespread and growing concerns over data privacy and security and to restore the public trust. The status quo no longer works," said Senator Chuck Grassley, chair of one of the committees holding the hearing.

"Congress must determine if and how we need to strengthen privacy standards to ensure transparency and understanding for the billions of consumers who utilize these products."

"You have a real opportunity this afternoon to lead the industry and demonstrate a meaningful commitment to protecting individual privacy," Democratic Senator Diane Feinstein told Zuckerberg at the rare joint committee hearing, to be followed by a similar hearing in the House of Representatives on Wednesday.

'#DELETEFACEBOOK' PROTESTS

Dozens of protestors gathered outside Congress before the hearing wearing Zuckerberg masks and #DeleteFacebook T-shirts.

Inside the jammed hearing room, activists from the Code Pink group wore oversized glasses with the words "STOP SPYING" written on the lenses, and waved signs that read "Stop corporate lying."

Testifying was a new step forward for the 33-year-old Zuckerberg, who started Facebook as a Harvard dropout in 2004, and built it into the world's largest social media company worth $470 billion.

In the past he has left it to top lieutenants to answer questions from legislators. 

But after the largest scandal yet for Facebook, Zuckerberg has seen it as imperative to speak out himself and try to prevent the company from bogging down in questions about its core business model, which is to share user data with advertisers.

The lawmakers delivered plenty of warnings that Zuckerberg needs to take action -- though they were thin on concrete proposals.

"If you and other social media companies do not get your act in order, none of us are going to have any privacy anymore," said Senator Bill Nelson.

Zuckerberg called Facebook "an idealistic and optimistic company" and said: "We focused on all the good that connecting people can bring."

But he acknowledged that "it's clear now that we didn't do enough to prevent these tools from being used for harm as well. That goes for fake news, foreign interference in elections, and hate speech, as well as developers and data privacy."

Zuckerberg added: "I want to be clear about what our priority is: protecting our community is more important than maximizing our profit."

'INVESTIGATING EVERY APP'

The Facebook CEO recounted a list of steps aimed at averting improper use of data by third parties like Cambridge Analytica, and noted that other applications were being investigated to determine if they did anything wrong.

On Friday, Facebook sought to allay concerns over political manipulation of its platform by announcing support for the "Honest Ads Act" that requires election ad buyers to be identified, and to go further by verifying who sponsors ads on key public policy issues.

Zuckerberg vowed to "hire thousands of more people" to get the new system in place ahead of US midterm elections in November, starting the process in the United States and taking it global in the coming months.

source: news.abs-cbn.com

Monday, April 2, 2018

Saks Fifth Avenue data breached: parent firm


WASHINGTON - A hack at Saks and Lord & Taylor stores in North America has compromised customer payment data, their parent company announced on Sunday.

Canadian-based Hudson's Bay Company did not say how many credit and debit cards were affected by the breach at upscale retailer Saks Fifth Avenue, Saks OFF Fifth, and Lord & Taylor department stores.

News reports put it at 5 million and said hackers had put these numbers up for sale on the "dark web," where criminals operate.

"HBC has identified the issue, and has taken steps to contain it," the parent firm said of the intrusion, the latest affecting companies with large user bases.

It said there are no signs the breach has affected its e-commerce or other digital platforms, Hudson's Bay stores, Home Outfitters, or HBC Europe.

Customers will not be liable for any fraudulent charges made with their card data, the company said.

On Thursday, sports gear maker Under Armour said a hack of its fitness application affected about 150 million user accounts.

Yahoo, retailer Target and credit bureau Equifax are among those also having reported data breaches in recent years.

source: news.abs-cbn.com

Thursday, March 29, 2018

Facebook overhauls privacy settings amid data breach outcry


WASHINGTON - Facebook on Wednesday launched a fresh effort to quell the firestorm over the hijacking of personal data, unveiling new privacy tools and settings to give users more control over how their information is shared.

The new features follow fierce criticism of the social network giant after it was revealed that the personal data of tens of millions of users was harvested by a British firm linked to Donald Trump's 2016 presidential campaign.

The company acknowledged that it needed to "do more to keep people informed," but said the changes have been "in the works for some time."

"We've heard loud and clear that privacy settings and other important tools are too hard to find," chief privacy officer Erin Egan and deputy general counsel Ashlie Beringer said in a blog post.

"We're taking additional steps in the coming weeks to put people more in control of their privacy."

The updates include easier access to Facebook's user settings and tools to easily search for, download and delete personal data stored on the site used by two billion people.

Facebook said a new privacy shortcuts menu will allow users to quickly increase account security, manage who can see their information and activity on the site, and control advertisements they see.

Facebook's terms of service and data policy are being updated to improve transparency about how the site collects and uses information, according to Beringer and Egan.

The social network said it is also shutting down 'Partner Categories,' a feature which enables more precise targeting of ads by combining information from Facebook with data aggregated by outside companies such as Experian and Acxiom.

"This product enables third-party data providers to offer their targeting directly on Facebook," product marketing director Graham Mudd said in a statement posted online.

"While this is common industry practice, we believe this step, winding down over the next six months, will help improve people's privacy on Facebook."

Earlier this month, whistleblower Christopher Wylie revealed political consulting company Cambridge Analytica had obtained profiles on 50 million Facebook users via an academic researcher's personality prediction app.

The app was downloaded by 270,000 people, but also scooped up their friends' data without consent -- as was possible under Facebook's rules at the time.

LUKEWARM PRAISE

Yet some analysts said Facebook and its chief Mark Zuckerberg have made similar promises in the past.

"Zuck promised easier, better privacy controls 'in the coming weeks' eight years ago," Zeynep Tufekci, a University of North Carolina professor who studies social media, said on Twitter.

"The solution isn't shifting the burden to the user because the problem is the negative externalities of the business model."

Jennifer Grygiel, a Syracuse University professor of communications, said the new privacy settings and tools "are so obviously important to users that one has to wonder why this wasn't already done."

She said Facebook has "some of the best talent in the industry" and that "their old interface was not a mistake, it was by design."

Dylan Gilbert of the consumer group Public Knowledge said Facebook's moves "are welcome steps forward" but "do little to remedy a larger systemic problem."

"Online platforms currently lack meaningful legal incentives to protect users before their privacy is violated," Gilbert said in a statement. 

"Facebook similarly lacks business incentives to engage in responsible data collection because disgruntled advertisers don't have anywhere comparable to go."

DEEPENING TECH CRISIS

Facebook's move comes as authorities around the globe investigate how the social network handles and shares private data, and after its shares have tumbled more than 15 percent, wiping out tens of billions in market value.

The crisis also threatens the Silicon Valley tech industry whose business model revolves around data collected on internet users.


The US Federal Trade Commission this week said it had launched a probe into whether Facebook violated consumer protection laws or a 2011 court-approved agreement on protecting private user data.

US lawmakers are trying to haul Zuckerberg to Washington to testify on the matter.

Authorities in Britain have meanwhile seized data from Cambridge Analytica in their investigation, and EU officials have warned of consequences for Facebook.

Facebook has apologized and vowed to fix the problem.

On Wednesday, six consumer and privacy organizations called upon Facebook to cease all campaign contributions and election activity until they ensure the integrity of all apps on the platform.

"A company whose platform is self-admittedly powerful enough to influence elections, must stay out of them," said a letter from the groups including Consumer Watchdog, Electronic Privacy Information Center and the Center for Digital Democracy.

rl-gc/wd

source: news.abs-cbn.com

Thursday, March 22, 2018

As Facebook scandal mushrooms, Zuckerberg vows to 'step up'


SAN FRANCISCO - Facebook chief Mark Zuckerberg vowed Wednesday to "step up" to fix problems at the social media giant, as it fights a snowballing scandal over the hijacking of personal data from millions of its users.

"We have a responsibility to protect your data, and if we can't then we don't deserve to serve you," Zuckerberg said, in his first public comments on the harvesting of Facebook user data by a British firm linked to Donald Trump's 2016 campaign.

Writing on his Facebook page, Zuckerberg announced new steps to rein in the leakage of data to outside developers and third-party apps, while giving users more control over their information through a special toolbar.

Zuckerberg said measures had been in place since 2014 to prevent precisely the sort of abuse revealed at the weekend.

"But we also made mistakes, there's more to do, and we need to step up and do it," he said.

The scandal erupted when a whistleblower revealed that British data consultant Cambridge Analytica (CA) had created psychological profiles on 50 million Facebook users via a personality prediction app, created by a researcher named Aleksandr Kogan.

The app was downloaded by 270,000 people, but also scooped up their friends' data without consent -- as was possible under Facebook's rules at the time.

Facebook says it discovered last week that CA may not have deleted the data as it certified.

"This was a breach of trust between Kogan, Cambridge Analytica and Facebook," Zuckerberg wrote. "But it was also a breach of trust between Facebook and the people who share their data with us and expect us to protect it."

"We need to fix that."

PROBE BY SPECIAL COUNSEL 

Zuckerberg's admission follows another day of damaging accusations against the world's biggest social network as calls mounted for investigations on both sides of the Atlantic.

Max Schrems, a Vienna-Based activist who has brought online data protection cases before European courts, told AFP he complained to the Irish Data Protection Authority in 2011 about the controversial data harvesting methods.

Schrems also recounted a seven-hour meeting with Facebook representatives the following year to discuss concerns around apps operating in this fashion, but said they said they saw no problems with their policies.

"They explicitly said that in their view, by using the platform you consent to a situation where other people can install an app and gather your data," Schrems said.

ABC News reported meanwhile special counsel Robert Mueller, who is investigating Russian interference in the 2016 campaign, was looking at Cambridge Analytica's role in the Trump effort.

Citing anonymous sources, ABC said several digital experts who worked on Trump's campaign have held closed-door interviews with Mueller's team. 

The British firm has maintained it did not use Facebook data in the Trump campaign, but its now-suspended CEO boasted in secret recordings that his company was deeply involved in the race.

#DELETEFACEBOOK 

The data scandal has ratcheted up the pressure on Facebook -- already under fire for allowing fake news to proliferate on its platform during the US presidential election.

'We can't be arbiter of truth': Why Facebook won't shut down fake news
A movement to quit the social network gathered momentum, while a handful of lawsuits emerged which could turn into class actions -- in a costly distraction for the company.

One of those calling it quits was a high-profile co-founder of the WhatsApp messaging service acquired by Facebook in 2014.

"It is time. #deletefacebook," Brian Acton said in a tweet protesting the social media giant's handling of the crisis.

Both Facebook and CA have denied wrongdoing, as attention focused increasingly on Kogan, the inventor of the controversial app -- personality survey dubbed This Is Your Digital Life.

But Kogan said in an interview he was "stunned" by the allegations against him, claiming CA had assured him his activities were above board.

"I'm being basically used as a scapegoat by both Facebook and Cambridge Analytica," he told the BBC. "We thought we were acting perfectly appropriately. "

The University of Cambridge psychologist said CA had approached him to do the work, and that he did not know how the firm would use the data collected with his app.

European Union officials have called for an urgent investigation while British, US and EU lawmakers have asked Zuckerberg to give evidence.

Responding to Zuckerberg's comments Wednesday, US Senator Ed Markey of Massachusetts was the latest lawmaker to call on Zuckerberg to appear.

"You need to come to Congress and testify to this under oath," Markey tweeted.

British Prime Minister Theresa May has urged Facebook and CA to cooperate with the national information commissioner's probe.

"The allegations are clearly very concerning," she told MPs.

"People need to have confidence in how their personal data is being used."

Facebook shares steadied Wednesday, gaining 0.74 percent after steep declines this week that wiped out some $50 billion in market value.

But questions abounded on the future of Facebook, which has grown from a startup in a Harvard dorm room to become one of the world's most powerful companies.

Analyst Brian Wieser at Pivotal Research said Facebook "is exhibiting signs of systemic mismanagement," possibly from growing too fast.

"Investors now have to consider whether or not the company will conclude that it has grown in a manner that has proven to be untenable," Wieser said in a research note.

source: news.abs-cbn.com

Wednesday, November 22, 2017

Uber's messy data breach collides with launch of SoftBank deal


TORONTO/SAN FRANCISCO - A newspaper advertisement for an Uber Technologies Inc stock sale was juxtaposed on Wednesday with a report that the ride-service provider had covered up a data hack - something of a metaphor for Uber, a company with boundless investor interest, but whose penchant for rule-breaking has led to a series of scandals.

The stock sale advertised in the New York Times will enable Uber investors to sell their shares to Japanese investor SoftBank, a critical deal for the company whose problems included building software to spy on competitors and to evade regulators and being investigated in Asia for paying bribes.

Uber on Tuesday said that it had paid hackers $100,000 to destroy data on more than 57 million customers and drivers that was stolen from the company - and decided under the previous CEO Travis Kalanick not to report the matter to victims or authorities. Uber was first hacked in October 2016 and discovered the data breach the following month.

Chief Executive Dara Khosrowshahi, who took the helm in August with the mission of turning around the company and overhauling its culture, acknowledged in a blog that Uber had erred in its handling of the breach.

The timing of the disclosure could hardly have been worse.

The company is trying to complete a deal with SoftBank Group Corp in which the Japanese firm would invest as much as $10 billion for at least 14 percent of the company, mostly by buying out existing shareholders. SoftBank is advertising to find shareholders who want to sell.

Uber last month announced a preliminary deal for the SoftBank investment.

One question is whether SoftBank will now try to alter the price of the deal. One source familiar with the matter said SoftBank is planning to stick to its agreement to invest in Uber but may seek better terms. SoftBank has not yet made a final decision on whether to renegotiate, the source said.

Another question is the future of Kalanick, the co-founder who led Uber to becoming a global powerhouse but did so with aggressive and controversial tactics. He was forced out by investors in June who feared his leadership style would damage the company, although he stayed on the board and remains a significant shareholder.

A bitter battle among investors over how to resolve Uber's problems led to a lawsuit by early investor Benchmark, which sought to oust Kalanick from any role. But a settlement was reached earlier this month to pave the way for the SoftBank deal, with Kalanick retaining his board seat and other rights.

Kalanick was made aware of the hack last November and was aware of the $100,000 payment, according to a person close to the matter. Kalanick has declined to comment. Uber did not respond to questions from Reuters on Wednesday.

MULTIPLE INVESTIGATIONS, LAWSUITS

The scope of the repercussions Uber will face for the October 2016 data breach began to take shape Wednesday with governments around the world opening investigations.

Authorities in Britain, Australia and the Philippines said they would investigate Uber's response to the data breach. London's transport regulator, which has been in discussions with Uber after stripping it of its license to operate, said it was pressing Uber for details.

Canada's privacy watchdog said that it had asked Uber for details on the breach, though it had not launched a formal investigation.

Attorneys general offices in at least six U.S. states along with the Federal Trade Commission (FTC) have announced they are looking into the matter. Some states are likely to go after Uber for breaking laws on data breach notification within a reasonable period of time.

At least 2 class action lawsuits have been filed against the company in the United States for failing to disclose the data breaches and causing potential harm to consumers.

Uber said that it has been in touch with the FTC and several states to discuss a hack and pledged to cooperate.

Legal experts said the company is likely to face limited financial fallout from data-breach lawsuits. Uber might succeed in squelching them outright because its agreements with both customers and drivers call for mandatory arbitration of disputes.

Uber fired its chief security officer, Joe Sullivan, and a deputy, Craig Clark, over their role in handling the hack.

The board of directors had commissioned an investigation into Sullivan and his team, which is how the breach was discovered. The board committee concluded that neither Kalanick nor Salle Yoo, who was general counsel at the time, had been consulted in the company's response to the breach, according to a second person familiar with the matter.

It is unclear what the board of directors knew, if anything.

Multiple board members did not respond to requests for comment.

"The scope of this breach is something the Uber board should have been briefed about and consulted on at the very least," said Cynthia Clark, an associate professor of management at Bentley University. "It's a monitoring issue and one of strategy and reputation."

Clark said that these sorts of risks could affect Uber's IPO, which the board has agreed will take place in 2019.

The company has begun overhauling its security practices with help from Matt Olsen, former general counsel of the U.S. National Security Agency and director of the National Counterterrorism Center, CEO Khosrwoshahi said.

Uber in August settled with the FTC after the regulator found the company failed to protect the personal information of passengers and drivers, an agreement that requires 20 years of regular auditing of Uber's data.

After this week's disclosures, Uber can expect "more audits and more people inside of the company" from regulators, said cyber security attorney Steven Rubin.


source: news.abs-cbn.com

Thursday, December 15, 2016

Ashley Madison dating site to pay $1.6-M over breach


WASHINGTON - The operators of the Ashley Madison affair-minded dating website agreed Wednesday to pay a $1.6 million penalty over a data breach exposing data from 36 million users, US officials announced.

Ashley Madison's Canadian parent company Ruby agreed to the penalty to settle charges with the US Federal Trade Commission and state regulators for failing to protect confidential user information.

The settlement comes after a hacker group last year released what was said to be personal data on millions of members of Ashley Madison, who were based in 46 countries. The fallout led to reports of blackmail and even suicides.

The financial penalty, split between the federal government and US states suing the company, would increase to $8.75 million to the FTC plus $8.75 million to states if Ashley Madison fails to abide by new information security practices and refrain from misleading consumers.

"This case represents one of the largest data breaches that the FTC has investigated to date, implicating 36 million individuals worldwide," said FTC chairwoman Edith Ramirez.

"The global settlement requires AshleyMadison.com to implement a range of more robust data security practices that will better protect its users' personal information from criminal hackers going forward."

NO COMPENSATION
Ramirez said the penalty being paid is too small to allow for "redress" or compensation to affected consumers, noting that compensation is rarely obtained in data security cases.

"We want them (the company) to feel the pain, we don't want them to profit from unlawful conduct," Ramirez told reporters in a conference call.

But she added that "it would not serve the public interest to put them out of business."

Earlier this year, the dating website -- whose motto had been "life is short, have an affair" rebooted, calling itself an "open-minded dating" service.

The company said at the time it will no longer use female "bots" or automated programs that respond to members pretending to be women on the hunt for men.

According to the FTC complaint, until August 2014, operators of the site lured customers, including 19 million Americans, with fake profiles of women designed to convert them into paid members.

The company failed to adequately protect users' personal information such as date of birth, relationship status and sexual preferences, according to the complaint.

The company confirmed the settlement, saying it would help it move past the hacking episode.

"Today is a pivotal day for our members and for Ashley Madison," said a statement from Ruby chief executive Rob Segal.

"Today's settlement closes an important chapter on the company's past and reinforces our commitment to operating with integrity and to building a new future for our members, our team and our company."

The settlement followed an investigation in cooperation with consumer protection authorities in Canada and Australia. Thirteen US states plus the federal District of Columbia joined the lawsuit.

source: news.abs-cbn.com