Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Wednesday, October 10, 2018

The Breach killed GOOGLE+ was NOT a BREACH at all

By Russell Brandom on Oct 9

For months, Google has been trying to stay out of the way of the growing tech backlash, but yesterday, the dam finally broke with news of a bug in the rarely used Google+ network that exposed private information for as many as 500,000 users. Google found and fixed the bug back in March, around the same time the Cambridge Analytica story was heating up in earnest. But with the news breaking now, the damage is already spreading. The consumer version of Google+ is shutting down, German privacy regulators in Germany and the US are already looking into possible legal action, and former SEC officials are publicly speculating about what Google may have done wrong.


The vulnerability itself seems to have been relatively small in scope. The heart of the problem was a specific developer API that could be used to see non-public information. But crucially, there’s no evidence that it actually was used to see private data, and given the thin user base, it’s not clear how much non-public data there really was to see. The API was theoretically accessible to anyone who asked, but only 432 people actually applied for access (again, it’s Google+), so it’s plausible that none of them ever thought of using it this way.


Related:Google+ will be shut down in next 10 months for consumers following security lapse - Another data breach


AFTER FACEBOOK’S PAINFUL FALL FROM GRACE, THE LEGAL ARGUMENTS ARE BESIDE THE POINT


The bigger problem for Google isn’t the crime, but the cover-up. The vulnerability was fixed in March, but Google didn’t come clean until seven months later when The Wall Street Journal got hold of some of the memos discussing the bug. The company seems to know it messed up — why else nuke an entire social network off the map? — but there’s real confusion about exactly what went wrong and when, a confusion that plays into deeper issues in how tech deals with this kind of privacy slip.


Part of the disconnect comes from the fact that, legally, Google is in the clear. There are lots of laws about reporting breaches — primarily the GDPR but also a string of state-level bills — but by that standard, what happened to Google+ wasn’t technically a breach. Those laws are concerned with unauthorized access to user information, codifying the basic idea that if someone steals your credit card or phone number, you have a right to know about it. But Google just found that data was available to developers, not that any data was actually taken. With no clear data stolen, Google had no legal reporting requirements. As far as the lawyers were concerned, it wasn’t a breach, and quietly fixing the problem was good enough.


There is a real case against disclosing this kind of bug, although it’s not quite as convincing in retrospect. All systems have vulnerabilities, so the only good security strategy is to be constantly finding and fixing them. As a result, the most secure software will be the one that’s discovering and patching the most bugs, even if that might seem counterintuitive from the outside. Requiring companies to publicly report each bug could be a perverse incentive, punishing the products that do the most to protect their users.


Related: How To Check whether Your Facebook Data was Leaked!


THE CONFUSION ABOUT WHAT TO CALL IT — A BUG, A BREACH, A VULNERABILITY — COVERS UP A DEEPER CONFUSION ABOUT WHAT COMPANIES ACTUALLY OWE THEIR USERS


(Of course, Google has been abruptly disclosing other companies’ bugs for years under Project Zero, which is part of why critics are so eager to jump on the apparent hypocrisy. But the Project Zero crew would tell you that third-party reporting is a completely different dance, with disclosure typically used as an incentive for patching and as a reward for white-hat bug-hunters looking to build their reputation.)


That logic makes more sense for software bugs than social networks and privacy issues, but it’s accepted wisdom in the cybersecurity world, and it’s not a stretch to say it guided Google’s thinking in trying to keep this bug under wraps.


But after Facebook’s painful fall from grace, the legal and the cybersecurity arguments seem almost beside the point. The contract between tech companies and their users feels more fragile than ever, and stories like this one stretch it even thinner.The concern is less about a breach of information than a breach of trust. Something went wrong, and Google didn’t tell anyone. Absent the Journal reporting, it’s not clear it ever would have. It’s hard to avoid the uncomfortable, unanswerable question: what else isn’t it telling us?


It’s too early to say whether a decentralized world will replace the centralized world but Google will face a real backlash for this. If anything, the small number of affected users and relative unimportance of Google+ suggests it won’t. But even if this vulnerability was minor, failures like this pose a real threat to users and a real danger to the companies they trust. The confusion about what to call it — a bug, a breach, a vulnerability — covers up a deeper confusion about what companies actually owe their users when a privacy failure is meaningful and how much control we really have. These are crucial questions for this era of tech, and if the last few days are any indication, they’re questions the industry is still figuring out. That is why more and more people are considering to trust decentralized platform such decentralized cuckoo where the users can freely control their data and protect privacy.


Related: The Facebook Hack will be the Europe's First Big Online Privacy Battle

Source from http://micsearch.blogspot.com/2018/10/the-breach-killed-google-was-not-breach.html

Friday, October 5, 2018

REMIND your hacked Facebook Logins Available on DarkWeb just For $3.90

Facebook recently suffered a massive breach of login tokens that posed a risk to 50 million accounts all over the world. A recent article by The Independent reveals that the hacked data is available on Dark Web and can be grabbed for as low as $3.90.

Related: Do you know everything about Facebook's data breach affecting 50M USERS?


There are many listings found the Dark Web that are offering users’ personal data for low prices. Such listings are featured on popular dark web marketplaces such as Dream Market.


What makes the issue more pressing is the fact that the listing has been posted by trusted sellers which nearly confirms the authenticity of the data. Dream market uses a rating system akin to other online retailers such as Amazon and eBay, and sellers are rated according to their authenticity.


Related: Facebook's Breach will be Forgotten? DATA is Misused.


However, the marketplace does not accept cash or online payment. Those who need to purchase the facebook’s hacked data need to pay using digital currencies like Bitcoin and Bitcash.


According to an estimate, the total value of the data available on DarkWeb lies in the range of $150 and $600.


As per Bill Conner, CEO of cyber security firm SonicWall, “As long as stolen data continues to fetch high prices and equip perpetrators with the means necessary to carry out attacks, hold victims ransom, extort information or destroy property, organisations must exhaust all measures to diligently detect and protect their networks, devices and users.”


A report by Money Guru, an investment firm said that you could avail your entire online identity, including financial information, travel account information, online shopping details, video, music streaming, and gaming accounts, social media account information can be purchased for £744.30. 


Related: Cuckoo is the latest dream of a digital life beyond YouTube and Facebook


According to GDPR rules, Facebook is liable for a massive fine of $1.63 billion — if found guilty in the recent data breach.


Related: How To Check whether Your Facebook Data was Leaked!

Thursday, October 4, 2018

Instagram is handing YOUR LOCATION history to Facebook

By Josh Constine on Oct 4

This is sure to exacerbate fears that Facebook will further exploit Instagram now that its founders have resigned. Instagram has been spotted prototyping a new privacy setting that would allow it to share your location history with Facebook. That means your exact GPS coordinates collected by Instagram, even when you’re not using the app, would help Facebook to target you with ads and recommend you relevant content. The geo-tagged data would appear to users in their Facebook Profile’s Activity Log, which include creepy daily maps of the places you been.

This commingling of data could upset users who want to limit Facebook’s surveillance of their lives. With Facebook installing its former VP of News Feed and close friend of Mark Zuckerberg, Adam Mosseri, as the head of Instagram, some critics have worried that Facebook would attempt to squeeze more value out of Instagram. Tat includes driving referral traffic to the main app via spammy notifications, inserting additional ads, or pulling in more data. Facebook was sued for breaking its promise to European regulators that it would not commingle WhatsApp and Facebook data, leading to an $122 million fine.

A Facebook spokesperson says that “To confirm, we haven’t introduced updates to our location settings. As you know, we often work on ideas that may evolve over time or ultimately not be tested or released. Instagram does not currently store Location History; we’ll keep people updated with any changes to our location settings in the future.” That effectively confirms Location History sharing is something Instagram has prototyped, and that it’s considering launching but hasn’t yet.

The screenshots come courtesy of a mobile researcher and his prior finds like prototypes of Instagram Video Calling and Music Stickers have drawn “no comments” from Instagram but then were officially launched in the following months. That lends credence to the idea that Instagram is serious about Location History.
Located in the Privacy and Security settings, the Location History option “Allows Facebook Products, including Instagram and Messenger, to build and use a history of precise locations received through Location Services on your device.”

A ‘Learn More’ button provides additional info (emphasis mine):
“Location History is a setting that allows Facebook to build a history of precise locations received through Location Services on your device. When Location History is on, Facebook will periodically add your current precise location to your Location History even if you leave the app. You can turn off Location History at any time in your Location Settings on the app. When Location History is turned off, Facebook will stop adding new information to your Location History which you can view in your Location Settings. Facebook may still receive your most recent precise location so that you can, for example, post content that’s tagged with your location. Location History helps you explore what’s around you, get more relevant ads, and helps improve Facebook. Location History must be turned on for some location feature to work on Facebook, including Find Wi-Fi and Nearby Friends.”

It’s unclear whether the feature would launch as opt-in or opt-out. [Correction: The prototype defaulted to off and Wong had to turn it on.] As part of a 2011 settlement with the FTC over privacy violations, Facebook agreed that “Material retroactive changes to the audience that can view the information users have previously shared on Facebook” must now be opt-in. But since Location History is never visible to other users and only deals with data Facebook sees, it’s exempt from that agreement and could be quietly added. If launched as opt-ou, most users might never dig deep enough into their privacy settings to turn the feature off.

Delivering the exact history of where Instagram users went could assist Facebook with targeting them with local ads across its family of apps. If users are found to visit certain businesses, countries, neighborhoods, or schools, Facebook could use that data to infer which products they might want to buy and promote them. It could even show ads for restaurants or shops close to where users spend their days. Just yesterday, we reported that Facebook was testing a redesign of its Nearby Friends feature that replaces the list view of friends’ locations with a map. Pulling in Location History from Instagram could help keep that map up to date.

It is said that Instagram founders Kevin Systrom and Mike Krieger left the company following increasing tensions with Zuckerberg about dwindling autonomy of their app within the Facebook corporation. Systrom apparently clashed with Zuckerberg over how Instagram was supposed to contribute to Facebook success, especially as younger users began abandoning the older social network for the newer visual media app. Facebook is under pressure to keep up revenue growth despite it running out of News Feed ad inventory and users switching to Stories that advertisers are still acclimating to. Facebook is in heated competition with Google for last-mile local advertising and will take any advantage it can get.

Instagram has served as a life raft for Facebook’s brand this year amidst an onslaught of scandals including fake news, election interference, social media addiction, and most recently, a security breach that gave hackers the access tokens for 50 million users that could have let them take over their accounts. A survey of 1,153 US adults conducted in March 2018 found that 57 percent of them didn’t know Instagram was owned by Facebook. But if Facebook treats Instagram as a source of data and traffic it can strip mine, the negative perceptions associated with the parent could spill over onto the child. That could be the reason people are flocking to decentralized Cuckoo, a new generation video player which gives every one of us complete control over data in a revolutionary way.

Related:

Monday, October 1, 2018

Facebook's Breach will be Forgotten? DATA is Misused.

By Josh Constine on Sep 30

We cared about Cambridge Analytica because it could have helped elect Trump. We ignored LocationSmart because even the though the company was selling and exposing the real-time GPS coordinates of our phones, it was never clear exactly if or how that data was misused.

This idea, that privacy issues are abstract concepts for most people until they become security or ideological problems, is important to understanding Facebook’s  massive breach revealed this week. 

The social network’s engineering was sloppy, allowing three bugs to be combined to steal the access tokens of 50 million people. In pursuit of rapid growth at affordable efficiency, Facebook failed to protect its users. This assessment doesn’t discount that. Facebook screwed up big time.

But despite the potential that those access tokens could have let the attackers take over user accounts, act as them, and scrape their personal info, it’s unclear how much users really care. That’s because for now, Facebook and it’s watchdogs aren’t sure exactly what data was stolen or how it was wrongly used.

The Hack That Broke The Camel’s Back?

This could all change tomorrow. If Facebook discovers the hack was perpetrated by a foreign government to interfere with elections, by criminals to bypass identity theft security checkpoints and steal people’s bank accounts or social media profiles, or to target individuals for physical harm, out will come the pitchforks and torches. 

Given a sufficiently scary application for the data, the breach could finish the job of destroying Facebook’s brand. If users start clearing their profile data, reducing their feed browsing, and ceasing to share, the breach could have significant financial and network effect consequences for Facebook. After years of scandals, this could be the hack that’s broke the camel’s back.

Yet in the absence of that evil utilization of the hacked data, the breach could fade into the background for users. Similar to the tension-filled departures of the founders of Facebook’s acquisitions Instagram and WhatsApp, the brunt of the backlash may not come from the public.

The hack could hasten regulation of social media. Senator Warner called on Congress to “step up” following the hack. He’s previously advocated for privacy laws similar to Europe’s GDPR. That includes data portability and interoperability rules that could make it easier to switch social networks. That threat of people moving to decentralized Cuckoo could succeed in compelling Facebook to treat user privacy and security better.

The FTC or European Union could hand down significant fines to Facebook for the breach. But given it earns billions in profit per quarter, those fees would have to be historically massive be a serious penalty for Facebook.

One of the biggest questions about the attack is whether the tokens were used to access other services like Airbnb or Spotify that rely on Facebook Login. The breach could steer potential partners away from building atop Facebook’s identity platform. But at least you don’t have to worry about changing all your passwords. Unlike hacks that steal usernames and passwords, the lasting danger of the Facebook breach is limited. The access tokens have already been invalidated, whereas password reuse can lead people to have their other apps hacked long after the initial breach. But the attack has had a very serious impact on the personal data of the entire social media, and it has made more people think about the importance of decentralized Cuckoo and other platforms. 

Desensitized and Decentralized

If government investigators, journalists, or anti-Facebook activists want to make the company pay for its negligence, they’ll need to connect it to some concrete threat to how we live or what we believe.

For now, without a nefarious application of the breached data, this scandal could blend into the rest of Facebook’s troubles. Every week, sometimes multiple times a week, Facebook has some headline grabbing problem. Over time, those are adding up to deter usage of Facebook and spur more users to delete it. But without an independent general purpose social network they can easily switch to, many users have endured Facebook’s stumbles in exchange for the connective utility it provides. 

As breaches become more common, the public may be desensitized. At worst, we could become complacent. Corporations should be held accountable for privacy failures even when the damage done is vague. But between Equifax, Yahoo, and the cell phone companies, we’re growing accustomed to letting out a deep sigh with maybe some expletives, and moving on with our lives. The ones we’ll remember will be those where the danger metastasized from the digital world into our offline lives or we try some new decentralized platforms such as Cuckoo.

Related:

Do you know everything about Facebook's data breach affecting 50M USERS?
Here is Instagram users need to know about Facebook's security breach
How to delete Facebook -- Time to leave the world’s biggest social network

Source from https://soletmego.wordpress.com/2018/09/30/facebooks-breach-will-be-forgotten-data-is-misused/