Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Saturday, September 4, 2010

Apple's Ping Service for iTunes Hijacked by Scammers and Spammers

The good news is that iPhone 10 fixes a number of security vulnerabilities. The bad news is that Apple failed to pay enough attention to the security of its new Ping service, designed as a social network of iPhone users. Anti-malware developer Sophos is reporting that the service has been hit with a barrage of scams and spam messages in the days since the launch.

Sunday, July 25, 2010

Digital Forensics Association Research Report: Five Years of Data Breaches

A new report from the Digital Forensics Association confirms the need for organizations to pay careful attention to all aspects of information security.The report "The Leaking Vault - Five Years of Data Breaches" analyzes over 2,800 data loss incidents from publicly accessible sources, with a known disclosure of 271.9 million records.  This study—the largest of its kind to date—provides analysis on which breach vectors carry the most risk, and should help provide organizations with more accurate information when combating this problem.


Key findings include:

  • Business, government, educational and medical organizations have been responsible for losing on average over 395,000 people's data per day every day for five years.  
  • Hacking was responsible for 45% of all exposed records with an average loss of 716,000 records
  • Stolen laptops were responsible for 49% of breaches but only 6% of lost records per incident.
  • The fastest growing attack vector is social engineering
  • Social Security Numbers (SSNs) are the most frequent data element reported.
  • The Business sector accounted for 70% of breach incidents

Wednesday, June 16, 2010

California Court Knowingly Exposes Confidential Data for 10 Days

The ABA Journal reports that a court in California's Sacramento County made 443 confidential documents available on a public kiosk. The problem wasn't fixed until June 4 even though a probate lawyer had brought the problem to the attention of the court on May 24. According to Presiding Judge Steve White, court technology employees didn’t act immediately because of another apparently more pressing computer problem.

Read the story here.

Monday, June 14, 2010

Free WiFi at Starbucks — Reminder of Cybersecurity Risk

The New York Times reports that Starbuck's will begin offering free WiFi on July 1. This makes it a good time to remind everyone about the need to be cautious when using public Wi-Fi. While the most common risk is eavesdropping, one cannot overlook the risk of computer compromise. Here are five basic rules anytime you're on a WiFi network whose security cannot be verified:
  1. No online banking or other eCommerce
  2. No email containing sensitive information except via an approved encrypted link from PC to  Mail Server
  3. Keep anti-virus or host intrusion prevention software (better) up-to-date
  4. Make sure software patches are up-to-date
  5. Use VPN for access to office

    Thursday, April 29, 2010

    Facebook's Social Web: Protecting Your Privacy

    Facebook's introduction of Open Graph represents a new challenge for consumers. By default, you're now opted in to the company's new social sharing services which stretch way beyond the confines of Facebook.com.If this concerns you -- and it should -- here are some links with advice on setting your privacy settings.

    Watch a CNET Tech Minute: Take back your privacy from Facebook ...

    Read PC World's advice on protecting your privacy on Facebook ... 

    Read the NY Times guide on opting out of Facebook's instant personalization ...

    Congressman Asks FTC to Investigate Privacy Risks of Copy Machines

    You may not know it but copy machines have computer memories, which means they may store tons of private or otherwise sensitive information. That's why Massachusetts Congressman Edward Markey has asked the Federal Trade Commission to investigate the risk to consumers posed by businesses that don't take steps to erase the memory of their copy machines. Expect a new set of regulations requiring businesses disposing of a copy machine to securely erase its hard drive, just like they are supposed to do for their PCs.

    Read the story at the Washington Post ...

    Watch the CBS News Report that broke the story: Copy Machines, a Security Risk?

    Wednesday, March 31, 2010

    Separating April Fools’ From Fraud on the Web

    NewYorkTimes: On the Internet, every day is April Fools’ Day. ... Thinking about how people get fooled on April 1 is a good way to prepare for the year-round attempts by swindlers to bamboozle the naïve, the witless and those who just aren’t paying close attention. In other words, all of us. ... The same themes run through the e-mail solicitations of Nigerian princes waiting to share their riches, messages by banks to type in your PIN or frantic pleas from Facebook friends trapped overseas without any money. ... How do you tell the real from the surreal today?

    Read more at the New York Times ...

    Tuesday, March 30, 2010

    Technology Coalition Seeks Stronger Privacy Laws

    NewYorkTimes: A broad coalition of technology companies, including AT&T, Google and Microsoft, and advocacy groups from across the political spectrum said Tuesday that it would push Congress to strengthen online privacy laws to protect private digital information from government access. ... The group, calling itself the Digital Due Process coalition, said it wanted to ensure that as millions of people moved private documents from their filing cabinets and personal computers to the Web, those documents remained protected from easy access by law enforcement and other government authorities.

    Read more at the New York Times ...

    E-Mails of Activists, Academics and Journalists Hacked in China

    NewYorkTimes: In what appears to be a coordinated assault, the e-mail accounts of more than a dozen rights activists, academics and journalists who cover China have been compromised by unknown intruders. A Chinese human rights organization also said that hackers disabled its Web site for a fifth straight day. ... The infiltrations, which involved Yahoo e-mail accounts, appeared to be aimed at people who write about China and Taiwan, rendering their accounts inaccessible, according to those who were affected. In the case of this reporter, hackers altered e-mail settings so that all correspondence was surreptitiously forwarded to another e-mail address.

    Read more at the New York Times ...

    Monday, March 29, 2010

    Facebook Proposes Changes in Privacy Policy to Share User Data with Other Sites

    WashingtonPost: On Friday afternoon, Facebook announced a set of proposed changes to its privacy policy that could allow the popular social network to share more of its users' data with other sites without first getting their approval. ... The move builds on the Palo Alto, Calif., company's December revision of its privacy rules that made far more user information -- including individual status updates -- public by default. Under the new proposal, Facebook could then provide that data to "pre-approved third party websites and applications" unless a user opted out of that feature.

    Read more at the Washington Post ...

    Saturday, March 20, 2010

    How Privacy Vanishes Online

    NewYorkTimes: If a stranger came up to you on the street, would you give him your name, Social Security number and e-mail address?... Probably not. ... Yet people often dole out all kinds of personal information on the Internet that allows such identifying data to be deduced. Services like Facebook, Twitter and Flickr are oceans of personal minutiae — birthday greetings sent and received, school and work gossip, photos of family vacations, and movies watched. ... Computer scientists and policy experts say that such seemingly innocuous bits of self-revelation can increasingly be collected and reassembled by computers to help create a picture of a person’s identity, sometimes down to the Social Security number.

    Read more ...

    In Bid to Sway Sales, Cameras Track Shoppers

    New York Times: The curvy mannequin piqued the interest of a couple of lanky teenage boys. Little did they know that as they groped its tight maroon shirt in the clothing store that day, video cameras were rolling. ... At a mall, a father emerged from a store dragging his unruly young son by the scruff of the neck, as if he were the family cat. The man had no idea his parenting skills were being immortalized. ... At an office supply store, a mother decided to get an item from a high shelf by balancing her small child on her shoulders, unaware that she, too, was being recorded.... These scenes may seem like random shopping bloopers, but they are meaningful to stores that are striving to engineer a better experience for the consumer, and ultimately, higher sales for themselves. Such clips, retailers say, can help them find solutions to problems in their stores — by installing seating and activity areas to mollify children, for instance, or by lowering shelves so merchandise is within easy reach. ... Privacy advocates, though, are troubled by the array of video cameras, motion detectors and other sensors monitoring the nation’s shopping aisles.

    Read more ...

    Wednesday, March 17, 2010

    FCC Broadband Plan Calls For Enhanced Cyber Defenses

    ChannelWeb: The National Broadband Plan, presented to Congress by the Federal Communications Commission this week, contains stipulations that could equip U.S. communications networks with stronger defenses against cyber threats and protect users' privacy online. ... Among other things, the plan gives a boost for the development of cyber security infrastructure, proposing the implementation of online privacy measures and calling for continued cooperation between the FCC and the Department of Homeland Security on public safety issues and initiatives.

    Read more ...


    Tuesday, March 16, 2010

    The Snitch in Your Pocket

    Newsweek: Law enforcement is tracking Americans' cell phones in real time—without the benefit of a warrant. ... How many of the owners of the country's 277 million cell phones even know that companies like AT&T, Verizon, and Sprint can track their devices in real time?

    Read more ...

    Thanks to Richard Greenberg for this.

    Tuesday, March 9, 2010

    LifeLock Will Pay $12 Million to Settle Charges by the FTC and 35 States That Identity Theft Prevention and Data Security Claims Were False

    FTC: LifeLock, Inc. has agreed to pay $11 million to the Federal Trade Commission and $1 million to a group of 35 state attorneys general to settle charges that the company used false claims to promote its identity theft protection services, which it widely advertised by displaying the CEO’s Social Security number on the side of a truck. ... “While LifeLock promised consumers complete protection against all types of identity theft, in truth, the protection it actually provided left enough holes that you could drive a truck through it,” said FTC Chairman Jon Leibowitz.

    Read more ...

    Tuesday, March 2, 2010

    Information on U.S. website for medical data thefts is bare-bones

    Los Angeles Times: The medical records of more than 18,000 patients of at least five Torrance doctors were potentially accessed by cyber-thieves on a single day in September, but this is probably the first you're hearing of it. ... Although a new federal law requiring greater disclosure of medical-data security breaches was passed a year ago, it wasn't until recently that the Department of Health and Human Services began posting specific incidents online.

    Read more ...

    Tuesday, February 2, 2010

    Twitter Asks Users To Reset Passwords After Possible Phishing Attack

    Washington Post: Twitter is locking many users out of the system this morning, and sending them notices that they need to change their passwords in order to regain access to the service, due to concerns over a possible phishing attack.

    Read more ...

    Thursday, January 21, 2010

    FTC Says Mortgage Broker Broke Data Security Laws: Dumpster Wrong Place for Consumers’ Personal Information

    FTC: The Federal Trade Commission has charged a mortgage broker with discarding consumers’ tax returns, credit reports, and other sensitive personal and financial information in an unsecured dumpster, in violation of federal law.

    Read more ...

    Wednesday, January 20, 2010

    NY Times: The 3 Facebook Settings Every User Should Check Now

    In December, Facebook made a series of bold and controversial changes regarding the nature of its users' privacy on the social networking site. The company once known for protecting privacy to the point of exclusivity (it began its days as a network for college kids only - no one else even had access), now seemingly wants to compete with more open social networks like the microblogging media darling Twitter.

    Read more ...

    Sunday, December 13, 2009

    Viruses That Leave Victims Red in the Facebook

    What's happening: Malware is spreading through Web sites like Facebook and Twitter. After stealing a Member's screen name and password, these malicious programs are coded to automatically send spam messages to the Member's friends and followers. Unsuspecting friends have been asked for money, have been directed to web-sites where malware is installed on their computers, and have had their user-names and passwords to online bank accounts stolen.

    What it means: Social networks continue to be the wild wild west of the internet.

    What to do: Stay vigilant. Be suspicious. Report suspected problems. And use a strong hard-to-break password.

    **********************************
    Viruses That Leave Victims Red in the Facebook