Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts

Tuesday, August 10, 2021

New child safety features for Google, YouTube

Google on Tuesday unveiled a series of online safety measures for children, including a private setting for videos uploaded by teens and safeguard for ads shown to users under 18.

The new features, which come amid heightened concerns about online child exploitation and safety at a time of growing internet usage during the global pandemic, affect Google's YouTube video platform as well its online services such as search and Google Assistant.

"As kids and teens spend more time online, parents, educators, child safety and privacy experts, and policy makers are rightly concerned about how to keep them safe," said Google product and user experience director Mindy Brooks.

"We engage with these groups regularly, and share these concerns."

Google's "safe search" -- which excludes sensitive or mature content -- will be the default setting for users under 18, which up to now had been the case only for under-13 users. 

On the massively popular YouTube platform, content from 13- to 17-year-olds will be private by default, the tech giant said.

"With private uploads, content can only be seen by the user and whomever they choose," said a blog post by James Beser, head of product management for YouTube Kids and Family.

"We want to help younger users make informed decisions about their online footprint and digital privacy... If the user would like to make their content public, they can change the default upload visibility setting and we'll provide reminders indicating who can see their video."

Google will also make it easier for families to request removal of a child's photos from image search requests.

"Of course, removing an image from search doesn't remove it from the web, but we believe this change will help give young people more control of their images online," Brooks said.

In another safety move, Google will turn off location history for all users under 18 globally, without an option to turn it back on. This is already in place for those under 13. 

Google will also make changes in how it shows ads to minors, blocking any "age-sensitive" categories and banning targeting based on the age, gender or interests of people under 18.

Agence France-Presse

Thursday, March 31, 2016

FBI's secret method of unlocking iPhone may never reach Apple


WASHINGTON - The FBI may be allowed to withhold information about how it broke into an iPhone belonging to a gunman in the December San Bernardino shootings, despite a U.S. government policy of disclosing technology security flaws discovered by federal agencies.

Under the U.S. vulnerabilities equities process, the government is supposed to err in favor of disclosing security issues so companies can devise fixes to protect data. The policy has exceptions for law enforcement, and there are no hard rules about when and how it must be applied.

Apple Inc has said it would like the government to share how it cracked the iPhone security protections. But the Federal Bureau of Investigation, which has been frustrated by its inability to access data on encrypted phones belonging to criminal suspects, might prefer to keep secret the technique it used to gain access to gunman Syed Farook's phone.

The referee is likely to be a White House group formed during the Obama administration to review computer security flaws discovered by federal agencies and decide whether they should be disclosed.

Experts said government policy on such reviews was not clear-cut, so it was hard to predict whether a review would be required. "There are no hard and fast rules," said White House cybersecurity coordinator Michael Daniel, in a 2014 blog post about the process.

If a review is conducted, many security researchers expect that the White House group will not require the FBI to disclose the vulnerability it exploited.

Some experts said the FBI might be able to avoid a review entirely if, for instance, it got past the phone's encryption using a contractor's proprietary technology.

Explaining the policy in 2014, the Office of the Director of National Security said the government should disclose vulnerabilities “unless there is a clear national security or law enforcement need."

The interagency review process also considers whether others are likely to find the vulnerability. It tends to focus on flaws in major networks and software, rather than individual devices.

During a press call, a senior Justice Department official declined to disclose whether the method used on Farook's phone would work on other phones or would be shared with state and local law enforcement.

Apple declined to comment beyond saying it would like the government to provide information about the technique used.

PROTECTING "CRUCIAL INTELLIGENCE"

The government reorganized the review process roughly two years ago and has not disclosed which agencies regularly participate other than the Department of Homeland Security and at least one intelligence agency. A National Security Council spokesman did not respond to a request for comment about agency participation.

In his April 2014 blog post, White House cybersecurity coordinator Daniel, who chairs the review group, said secrecy was sometimes justified.

“Disclosing a vulnerability can mean that we forego an opportunity to collect crucial intelligence that could thwart a terrorist attack stop the theft of our nation’s intellectual property,” Daniel wrote.

On Tuesday, a senior administration official said the vulnerability review process generally applies to flaws detected by any federal agency.

Paul Rosenzweig, a former deputy assistant secretary at the Department of Homeland Security, said he would be “shocked” if the Apple vulnerability is not considered by the group.

“I can’t imagine that on one of this significance that the FBI, even if it tried to, would succeed in avoiding the review process,” said Rosenzweig, founder of Red Branch Consulting, a homeland security consulting firm.

He predicted the FBI would not be forced to disclose the vulnerability because it appears to require physical possession of a targeted phone and therefore poses minimal threat to Internet security more broadly.

Many security researchers have suggested that the phone's content was probably retrieved after mirroring the device's storage chip to allow data duplication onto other chips, effectively bypassing limitations on the number of passcode guesses.

Kevin Bankston, director of the think tank Open Technology Institute, said there is no public documentation of how the review process has worked in recent years. He said Congress should consider legislation to codify and clarify the rules.

Stewart Baker, former general counsel of the NSA and now a lawyer with Steptoe & Johnson, said the review process could be complicated if the cracking method is considered proprietary by the third party that assisted the FBI.

Several security researchers have pointed to the Israel-based mobile forensics firm Cellebrite as the likely third party that helped the FBI. That company has repeatedly declined comment.

If the FBI is not required to disclose information about the vulnerability, Apple might still have a way to pursue details about the iPhone hack.

The Justice Department has asked a New York court to force Apple to unlock an iPhone related to a drug investigation. If the government continues to pursue that case, the technology company could potentially use legal discovery to force the FBI to reveal what technique it used, a source familiar with the situation told Reuters.

At least one expert thinks a government review could require disclosure. Peter Swire, a professor of law at the Georgia Institute of Technology who served on the presidential intelligence review group that recommended the administration disclose most flaws, said there is “a strong case” for informing Apple about the vulnerability under the announced guidelines.

“The process emphasizes the importance of defense for widely used, commercial software,” he said.

source: www.abs-cbnnews.com

Thursday, February 26, 2015

Lenovo website hacked; Lizard Squad claims responsibility


China's Lenovo Group Ltd website was hacked, the company said on Wednesday, days after the U.S. government advised Lenovo customers to remove a pre-installed virus-like software, "Superfish", on laptops that makes the devices more vulnerable to attacks.

Hacking group Lizard Squad claimed to be behind the attacks, according to its Twitter page.

Lizard Squad has taken credit for several high-profile outages, including attacks that took down Sony Corp's PlayStation Network and Microsoft Corp's Xbox Live network last month. Members of the group have not been identified.

"The domain name service server hosting Lenovo's website was hacked. We do not have any further information at this time to share. We'll update as soon as possible," Lenovo said in a statement to Reuters.

San Francisco-based security firm CloudFlare said hackers transferred the domain to CloudFlare in order to point it to a defacement site.

"As soon as we at CloudFlare noticed, we seized the account and worked with Lenovo to restore service while they worked to recover their domain," Marc Rogers, Principal Security Researcher at CloudFlare, said in an email to Reuters.

Starting 4 p.m. ET (2100 GMT) on Wednesday, visitors to the Lenovo website saw a slideshow of young people looking into webcams and the song "Breaking Free" playing in the background, according to The Verge, which first reported the breach.

"We're breaking free! Soarin', flyin', there's not a star in heaven that we can't reach!," Lizard Squad posted on its Twitter page, quoting the song from the movie "High School Musical".





The hackers also posted a couple of screenshots of an email between Lenovo employees regarding the "Superfish" software.



The Department of Homeland Security said in an alert on Friday that the "Superfish" program makes users vulnerable to a type of cyberattack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.

Rogers also said CloudFlare was able to restore service before Lenovo recovered the domain, suggesting that the outage was probably "quite small".

However, Lenovo's website was inaccessible at 7:54 p.m. ET (0054 GMT). A message said the site was unavailable due to system maintenance.

source: www.abs-cbnnews.com

Thursday, July 10, 2014

Beware of fake World Cup streaming sites


MANILA – A security software firm has warned fans of the World Cup against websites offering free streaming of the games, saying that some of them may be fake.

In a statement, Kaspersky Lab said a number of websites that claim to stream World Cup games may be harmful, with others aimed at stealing a user’s personal information.

It said websites that ask users to download their program or provide credit card details – which are huge red flags – should be avoided.

“When you search on Internet for the live World Cup broadcast, you will sometimes find purchased advertisements that lead to fraudulent or malicious content,” said Kaspersky Lab researcher Dmitry Bestuzhev.

“When you go to the website, it asks you to download a special plugin available for all browsers. This is supposed to be the player needed to watch the online broadcast of the games. In reality, it is an adware program, which may not show you anything but will drain your computer’s resources,” he added.

Kaspersky Lab encouraged users to be on the safe side and watch the World Cup by logging through an authenticated cable service provider.

source: www.abs-cbnnews.com