Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

How Protecting Your Privacy Could Make You the Bad Guy

http://www.wired.com/opinion/2013/07/the-catch-22-of-internet-commerce-and-privacy-could-mean-youre-the-bad-guy/
Protecting your privacy
There’s a funny catch-22 when it comes to privacy best practices. The very techniques that experts recommend to protect your privacy from government and commercial tracking could be at odds with the antiquated, vague Computer Fraud and Abuse Act (CFAA).

A number of researchers (including me) recently joined an amicus brief (filed by Stanford’s Center for Internet and Society in the “Weev” case), arguing how security and privacy researchers are put at risk by this law.

However, I’d also like to make the case here that the CFAA is bad privacy policy for consumers, too. It’s not just something that affects hackers and academics.

The crux of a CFAA violation hinges on whether or not an action allows a user to gain “access without authorization” or “exceed authorized access” to a computer. The scary part, therefore, is when these actions involve everyday behaviors like clearing cookies, changing browser reporting, using VPNs, and even protecting one’s mobile phone from being identified.

Dan Misener: Merit badges for online privacy? Mozilla soon might give you one

http://www.cbc.ca/news/technology/story/2013/07/22/f-vp-misener-mozilla-online-privacy.html
Online Privacy
Growing up, I was never a Scout.

I never earned merit badges for canoeing, or pioneering, or fire safety.

But soon, I may be able to earn badges for "web mechanics" or "online privacy." Not from Scouts Canada, but through a series of projects by Mozilla, makers of the open-source Firefox web browser.

This Friday, the Mozilla Foundation plans to unveil a beta version of its Web Literacy Standard.

Basically, it's a list of skills and competencies they believe are important for anyone who wants to read, write and interact with others on the web.

We often talk about "digital literacy" or "web literacy" -- especially in the context of children and formal education -- but it's not always clear exactly what those terms mean. Mozilla wants to clarify.

According to project lead Doug Belshaw, there's great work going on in the field of web literacy. He points to online tools, programs in libraries and schools, and informal education through non-profit groups.

"There's so many fantastic groups doing some awesome work," he says, "but it's all in silos and it's not joined up."

Dan Misener: Merit badges for online privacy? Mozilla soon might give you one | CBC News

SIM cards vulnerable to hacking, says researcher

Millions of mobile phones may be vulnerable to spying due to the use of outdated, 1970s-era cryptography, according to new research due to be presented at the Black Hat security conference.

http://www.networkworld.com/news/2013/072213-sim-cards-vulnerable-to-hacking-272040.html?source=nww_rss
SIM cards vulnerable to hacking
Karsten Nohl, an expert cryptographer with Security Research Labs, has found a way to trick mobile phones into granting access to the device's location, SMS functions and allow changes to a person's voicemail number.

Nohl's research looked at a mobile phones' SIM (Subscriber Identification Module), the small card inserted into a device that ties it to a phone number and authenticates software updates and commands sent over-the-air from an operator.

More than 7 billion SIM cards are in use worldwide. To ensure privacy and security, SIM cards use encryption when communicating with an operator, but the encryption standards use vary widely.
A mobile communication trade group, the GSM Association, said in a statement that only a "minority" of SIM cards that use older encryption standards would appear to be vulnerable.

"There is no evidence to suggest that today's more secure SIMs, which are used to support a range of advanced services, will be affected," GSMA said.


AT&T Will Start Anonymously Selling Your Location Data To Marketers

AT&T updated its privacy policy last week with a notice that it plans to start selling anonymous location data about its customers to marketers.
http://www.businessinsider.com/att-to-sell-location-data-2013-7
AT&T will start to sell yout location data
Although the policy was updated on June 28, news sites like Fierce Wireless just picked up on it this week. 

Here's the kind of information AT&T will be selling: your location based on WiFi networks you connect to, Web browsing data, and apps you use.

Facebook security bug exposed 6 million users personal information

Facebook Security bug
Facebook Security
Facebook recently received a report to their White Hat program regarding a bug that may have allowed some of a person’s contact information (email or phone number) to be accessed by people who either had some contact information about that person or some connection to them.

Security team has concluded that approximately 6 million Facebook users had email addresses or telephone numbers shared. There were other email addresses or telephone numbers included in the downloads, but they were not connected to any Facebook users or even names of individuals. For almost all of the email addresses or telephone numbers impacted, each individual email address or telephone number was only included in a download once or twice. This means, in almost all cases, an email address or telephone number was only exposed to one person. Additionally, no other types of personal or financial information were included and only people on Facebook – not developers or advertisers – have access to the DYI tool.

Important Message from Facebook's White Hat Program | Facebook Security

Firefox Web browser to move ahead with ‘Do Not Track’ option

The maker of the popular Firefox browser is moving ahead with plans to block the most common forms of Internet tracking, allowing hundreds of millions of users to eventually limit who watches their movements across the Web, company officials said Wednesday.

Mozilla Firefox Do Not Track
Mozilla Firefox - Do Not Track

Firefox made the decision despite intense resistance from advertising groups, which have argued that tracking is essential to delivering well-targeted, lucrative ads that pay for many popular Internet services. When Firefox’s maker, Mozilla, first suggested in February that it might limit blocking, one advertising executive called it “a nuclear first strike” against the industry.

Source | The Washington Post

Need some privacy? Open WhisperSystems

Open WhisperSystems
Open WhisperSystems, a company that is working on security and privacy in the mobile environment, provides a way to secure your communication with their mobile applications: RedPhone & TextSecure.

RedPhone

RedPhone provides end-to-end encryption for your calls, securing your conversations so that nobody can listen in.

Features:

  • Use the default system dialer and contacts apps to make calls as you normally would. 
  • RedPhone will give you the opportunity to upgrade to encrypted calls whenever possible. 
  • RedPhone calls are encrypted end-to-end, but function just like you're used to. 
  • RedPhone uses your normal phone number to make and receive calls, so you don't need yet another identifier.

TextSecure

TextSecure encrypts your text messages over the air and on your phone. It's almost identical to the normal text messaging application, and is just as easy to use.

Features:

  • A full replacment for the default text messaging application. 
  • All messages are encrypted locally, so if your phone is lost, your messages will be safe. 
  • Messages to other TextSecure users are encrypted over the air, protecting your communication in transit.

The source for both projects is open, so that anyone can easily verify they work as advertised. They are licensed GPLv3 and will always be free.

The Value of a Hacked Email Account

This post aims to raise awareness about the street value of a hacked email account, as well as all of the people, personal data, and resources that are put at risk when users neglect to properly safeguard their inboxes.

Sign up with any service online, and it will almost certainly require you to supply an email address. In nearly all cases, the person who is in control of that address can reset the password of any associated services or accounts –merely by requesting a password reset email.

A Taxonomy of PRISM Possibilities

NSA
A lot of people are trying to synthesize reasonable technical explanations for how the NSA could implement the program described in the leaked PowerPoint deck and keep it secret for so long. In an effort to improve the quality of the public discussion, I have decided to create a taxonomy of the theories that I have seen floated and supply my own commentary in italics.

Everything listed below is based upon data contained in the news articles I have seen. I also recognize that many of these theories sound far-fetched, although I have to admit that my personal Overton Window for crazy conspiracy theories has shifted in the last 24 hours.

Original Source

U.S. surveillance revelations deepen European fears

U.S. surveillance revelations deepen European fears
Europeans reacted angrily on Friday to revelations that U.S. authorities had tapped the servers of internet companies for personal data, saying they confirmed their worst fears about American Web giants and showed tighter regulations were needed.

The Washington Post and the Guardian aroused outrage with reports that the National Security Agency (NSA) and FBI had accessed central servers of Google, Facebook and others and gathered millions of phone users' data.

Europe, which lacks internet giants of its own, has long yearned to contain the power of the U.S. titans that dominate the Web, and privacy-focused Germany was quick to condemn their co-operation with the U.S. security services.

How to Detect Apps Leaking Your Data

Mobilescope
A new service called Mobilescope hopes to change that by letting a smartphone user examine all the data that apps transfer, and alerting him when sensitive information, such as his name or e-mail address, is transferred.