The company's ability (and willingness) to take such an approach became apparent this week. Microsoft admitted in federal court documents that it forced its way into a
blogger's Hotmail account to track down and stop a potentially
catastrophic leak of sensitive software. The company says its decision
is justified.
From the company's point of view, desperate times call for desperate measures.
"In this case, we took extraordinary actions based on the specific
circumstances," said John Frank, one of the company's top lawyers, in a blog post Thursday night.
According to an FBI complaint,
Microsoft in 2012 discovered that an ex-employee had leaked proprietary
software to an anonymous blogger. Fearing that could empower hackers,
Microsoft's lawyers approved emergency "content pulls" of the blogger's
accounts to track it down. Company investigators entered the blogger's
Hotmail account, then pored over emails and instant messages on Windows
Live. The internal investigation led to the arrest on Wednesday of Alex
Kibkalo, a former Microsoft employee based in Lebanon.
Although the move could be perceived as a breach of trust, Microsoft
says it's allowed to make such unilateral decisions. It pointed to its
terms of service: When you use Microsoft communication products, (Outlook, Hotmail, Windows Live) you agree to "this type of review ...
in the most exceptional circumstances," Frank wrote.
Microsoft's legal team thought there was enough evidence suggesting the
blogger would try selling the illegally obtained intellectual property.
In such instances, law enforcement agents would typically seek a
warrant, but Microsoft said it didn't need one. The servers storing the
information are on its own property.
Ginger McCall, a director at the Electronic Privacy Information Center,
said those actions are deeply troubling, because they show "Microsoft
clearly believes that the users' personal data belongs to Microsoft, not
the users themselves."
"This is part of the broader problem
with privacy policies," she said. "There are hidden terms that the users
don't actually know are there. If the terms were out in the open,
people would be horrified by them."
Microsoft recognizes that it's a sensitive topic, especially as the
nation grapples with revelations about the extent of warrantless
surveillance on Americans by their own government -- spying that
Microsoft and other major tech companies have loudly criticized.
That's why Microsoft is instituting a new policy: In the future, it'll
loop in an outside lawyer who's a former federal judge and seek his or
her approval.
In a move that might be deemed ironic, Microsoft
will now add its own internal searches to its biannual transparency
reports on government surveillance.
Source: CNN
Based in the historic downtown area of Plymouth, MA, IES is a web design / hosting, computer / IT support, and marketing consulting firm for small to large business, including government & nonprofits. We also sell & service POS equipment, smart systems, CCTV systems, and custom wifi service. IES operates globally via the latest technology.
Showing posts with label Internet privacy. Show all posts
Showing posts with label Internet privacy. Show all posts
Monday, March 24, 2014
Microsoft will break into your Outlook, Hotmail, and instant messenger accounts if it deems necessary.
Labels:
email,
email breach,
email hack,
email privacy,
Hotmail hack,
Internet privacy,
Microsoft,
Microsoft email hack,
Microsoft hack,
online privacy,
Outlook hack,
privacy breach,
security
Monday, August 19, 2013
How's this for irony? Mark Zuckerberg's wall got hacked....warning him of a security problem.
A Palestinian IT expert who claimed to have discovered a Facebook vulnerability said he took his bug report to Mark Zuckerberg's Facebook page after being ignored by the social network's security team.
The vulnerability allows anyone to post anything to anyone else's page, regardless of whether they are a Facebook friend of that person, Khalil Shreateh wrote in a blog post Saturday. Shreateh initially reported the vulnerability through Facebook's "white hat" security disclosure service, which offers a minimum bounty of $500 for legitimate bugs.
However, despite including a demonstration of the bug executed on the Facebook page of Zuckerberg pal Sarah Goodwin, Shreateh was told by a Facebook security engineer in a terse note that "sorry this is not a bug."
Undaunted, Shreateh decided to share his experience with Zuckerberg by posting a note to the Facebook founder's page that apologized for the post but said he had "no other choice."
"[A] couple of days ago I discovered a serious Facebook exploit that allows users to post to other Facebook users timeline while they are not in friend list," Shreateh wrote in his post to Zuckerberg's timeline. "I appreciate your time reading this and getting some one from your company team to contact me."
Within minutes, Shreateh was contacted by a Facebook security seeking details of the exploit, Shreateh said, adding that his own Facebook account was quickly disabled. A security engineer told Shreateh his account had been disabled as a "precaution."
"When we discovered your activity we did not fully know what was happening," an engineer who identified himself as "Joshua" told Shreateh. "Unfortunately your report to our Whitehat system did not have enough technical information for us to take action on it. We cannot respond to reports which do not contain enough detail to allow us to reproduce an issue."
Joshua also informed Shreateh that he would not be receiving a bug reward for reporting the exploit because he violated the site's terms of service. "We do hope, however, that you continue to work with us to find vulnerabilities in the site," he wrote.
A Facebook security engineer responded Saturday in a Hacker News post that the vulnerability was fixed Thursday and conceded that Shreateh should have been asked for more details on the issue after his initial report. Along with offering inadequate information about the bug, Shreateh's post to Zuckerberg's timeline violated the social network's responsible disclosure policy, the security engineer wrote.
"Exploiting bugs to impact real users is not acceptable behavior for a white hat," the engineer wrote, adding that researchers are allowed to create test accounts to aid their research.
The vulnerability allows anyone to post anything to anyone else's page, regardless of whether they are a Facebook friend of that person, Khalil Shreateh wrote in a blog post Saturday. Shreateh initially reported the vulnerability through Facebook's "white hat" security disclosure service, which offers a minimum bounty of $500 for legitimate bugs.
However, despite including a demonstration of the bug executed on the Facebook page of Zuckerberg pal Sarah Goodwin, Shreateh was told by a Facebook security engineer in a terse note that "sorry this is not a bug."
Undaunted, Shreateh decided to share his experience with Zuckerberg by posting a note to the Facebook founder's page that apologized for the post but said he had "no other choice."
"[A] couple of days ago I discovered a serious Facebook exploit that allows users to post to other Facebook users timeline while they are not in friend list," Shreateh wrote in his post to Zuckerberg's timeline. "I appreciate your time reading this and getting some one from your company team to contact me."
Within minutes, Shreateh was contacted by a Facebook security seeking details of the exploit, Shreateh said, adding that his own Facebook account was quickly disabled. A security engineer told Shreateh his account had been disabled as a "precaution."
"When we discovered your activity we did not fully know what was happening," an engineer who identified himself as "Joshua" told Shreateh. "Unfortunately your report to our Whitehat system did not have enough technical information for us to take action on it. We cannot respond to reports which do not contain enough detail to allow us to reproduce an issue."
Joshua also informed Shreateh that he would not be receiving a bug reward for reporting the exploit because he violated the site's terms of service. "We do hope, however, that you continue to work with us to find vulnerabilities in the site," he wrote.
A Facebook security engineer responded Saturday in a Hacker News post that the vulnerability was fixed Thursday and conceded that Shreateh should have been asked for more details on the issue after his initial report. Along with offering inadequate information about the bug, Shreateh's post to Zuckerberg's timeline violated the social network's responsible disclosure policy, the security engineer wrote.
"Exploiting bugs to impact real users is not acceptable behavior for a white hat," the engineer wrote, adding that researchers are allowed to create test accounts to aid their research.
Labels:
Facebook,
Facebook security,
Internet privacy,
Mark Zuckerberg,
Mark Zuckerberg hacked,
White Hat,
Zuckerberg
Thursday, August 1, 2013
So your teenager wants to open a Facebook account...here's how to handle it.
There are plenty of reasons Facebook, Instagram, and other social networks have a minimum age limit. Here's just one: Children aren't born with internal privacy settings.
Moms and Dads can't assume teens know what they should and shouldn't share online. And just because children meet the minimum age requirement (for Facebook, it's age 13), that doesn't mean they should rush to create an account. Colby Zintl of Common Sense Media, a nonprofit family and children's advocacy group, said kids are probably better equipped to deal with the not-always-kid-friendly content and situations found on social networks when they're 14 or 15.
Once everyone's in agreement about when to get online, parents should show kids how to go about it. Walk them through the privacy settings. Show them how to unfriend people and delete posts. Make sure that only their friends can view their profile.
Zintl suggested that parents activate the setting that allows kids to approve all posts before they're added to their timeline. "Talk to your child about the importance of that," Zintl said. "It relates to the concept of a digital footprint -- everything is permanent. If a child is going to post on your child's wall, there should be some barrier to entry there."
The current generation of kids are growing up as digital natives, so they're often comfortable with social media, but they still need to be careful. And thanks to proud parents and grandparents, their lives are probably well-documented. Said Zintl: "Parents posting pictures of their babies starts a kid's digital footprint for their entire life. They're creating a lifetime of photos and history online."
Common Sense Media urges parents to emphasize to kids that the Internet is written with a permanent Sharpie, not pencil. "Once a photo, or a comment, is out in cyberspace, there is no getting it back. Even if you take it down from Facebook, another kid could have forwarded it," Zintl said. "There is no such thing as a real eraser button in social media, and that is an important reminder to share with kids over and over again."
Source: CNET
Moms and Dads can't assume teens know what they should and shouldn't share online. And just because children meet the minimum age requirement (for Facebook, it's age 13), that doesn't mean they should rush to create an account. Colby Zintl of Common Sense Media, a nonprofit family and children's advocacy group, said kids are probably better equipped to deal with the not-always-kid-friendly content and situations found on social networks when they're 14 or 15.
Once everyone's in agreement about when to get online, parents should show kids how to go about it. Walk them through the privacy settings. Show them how to unfriend people and delete posts. Make sure that only their friends can view their profile.
Zintl suggested that parents activate the setting that allows kids to approve all posts before they're added to their timeline. "Talk to your child about the importance of that," Zintl said. "It relates to the concept of a digital footprint -- everything is permanent. If a child is going to post on your child's wall, there should be some barrier to entry there."
The current generation of kids are growing up as digital natives, so they're often comfortable with social media, but they still need to be careful. And thanks to proud parents and grandparents, their lives are probably well-documented. Said Zintl: "Parents posting pictures of their babies starts a kid's digital footprint for their entire life. They're creating a lifetime of photos and history online."
Common Sense Media urges parents to emphasize to kids that the Internet is written with a permanent Sharpie, not pencil. "Once a photo, or a comment, is out in cyberspace, there is no getting it back. Even if you take it down from Facebook, another kid could have forwarded it," Zintl said. "There is no such thing as a real eraser button in social media, and that is an important reminder to share with kids over and over again."
Source: CNET
Labels:
Facebook,
Facebook privacy,
Internet privacy,
kids on Facebook,
teenagers,
teenagers on Facebook
Tuesday, July 30, 2013
5 simple methods to improve your privacy online.
It wasn't long after the Internet came into widespread use that online privacy became a growing concern. After all, anytime people are connected through their computers and sharing resources online, there's the potential for prying and abuse.
1). Browser Settings
There are some easy things that can be done to configure a browser for better security and privacy. Among the basics, go into your Web browser's preference settings and set the browser not to accept cookies from sites you haven't visited, also known as third-party cookies. Generally, you'll want to accept cookies from the sites you visit.
Apple's Safari blocks third-party cookies by default; Mozilla intends to make this the default setting soon in Firefox, but for now you'll need to opt for the setting. You have to choose these settings in Microsoft's Internet Explorer and Google's Chrome.
Also, the newest versions of Internet Explorer, Mozilla Firefox, Google Chrome and several others offer settings for "Do Not Track," a proposed header field that requests that a Web application disable its site and/or cross-site tracking of user activity.
Consider setting your browser preferences to automatically clear cookies when you close the browser.
2). Cloud Storage
Storage of anything private and personal in the cloud should use the strongest form of encryption possible. Strengths of encryption come in various standards. RSA 2048-bit key encryption provides the best possible strength when used with public key infrastructure. The chance of cracking an RSA 2048-bit private key is not nil, but it would take so long that attempting it is not practicable using today's raw computing power.
A strong cipher is the most important consideration. Close behind, however, are the questions of where you should use encryption and with what method.
If you have any data stored on the Internet that you would like to ensure never gets seen by anyone other than yourself, then this is a good candidate for encryption.
The strongest and safest method today for encryption of cloud data is Zero Knowledge. Zero knowledge means that your cloud ISP will have no knowledge of what is being stored on their site. The private key to unlock your data will be created by you on your local drive. Thus only you will have the ability to unlock the data -- not even the cloud ISP will be able to do so.
SpiderOak and Wuala are two examples of ISP Software as a Service sites that offer ZK data encryption.
There are now quite a few SaaS encryption vendors from which to choose, but those that support Zero Knowledge are the safest bet for those with privacy in mind.
3). Two-Factor Authentication
The use of hack-prone password-based access is being gradually replaced by technologies like fingerprint scan, keyfob-generated keys and two-factor authentication methods.
If your ISP uses password-based access, make sure you maintain strong passwords. A password's strength is measured by its ability to avoid being guessed. Many ISPs and portals will test the strength of your password as you create it. Pay attention and be sure that the test returns "strong."
Do not use the same password for multiple accounts. Instead, use strong passwords that are unique to each account - and that's particularly important for your most sensitive online accounts, such as for banking, email, and social networks.
Two-factor authentication is another method that's growing in popularity. Google Gmail now offers a free two-step authentication service. The goal is to avoid having your login stream (which includes your password) from being intercepted by a "man-in-the-middle" attack. Criminals equipped with programs called packet analyzers (also known as "sniffers") can see your streaming data and steal your password.
With two-factor authentication, in addition to entering a password, the system will send to your phone a unique ID number that must be input for authentication as well. Using such a method means the "man-in-the-middle" cannot and will not know what is on your personal phone and so cannot intercept such information.
If your ISP offers two-step authentication, you'd be wise to use it.
4) Encryption for Chat and Email
With Google Talk and Google Hangouts, one can set the chat session to "off the record" to ensure that the chat session is never permanently stored on Google's chat servers.
Also, installing Pidgin for both Windows and Linux - it's a popular multiprotocol messaging software application - along with its "off the record" plugin will ensure that your chat session will remain encrypted and private. This ensures that an additional encryption layer is added to the stream using OTR, regardless of what the underlying protocol provides.
The same encrypted vs. nonencrypted concept applies to email. If you don't want your email read, then it is imperative that you encrypt it. The good news is that encrypting email is technically feasible using GnuPG, PGP or S/MIME standards, for example. The bad news is that few software applications are in circulation that make preparing and sending encrypted email "drop-dead" simple and foolproof in terms of usability by the general public.
5) Surf the Internet Anonymously
Finally, if you really feel strongly about keeping your Internet surfing habits anonymous, you may consider using a proxy for your Internet surfing - though even that won't guarantee complete anonymity.
A more difficult-to-trace method for surfing the Web is called Tor. Essentially, when you install Tor software, you log onto a peer-to-peer (P2P) network representing millions of people, much in the way BitTorrent works. It is encrypted and fully decentralized, meaning not only that it is self-sustainable but also that there is no central server which, if shut down, will stop its Internet activities.
What happens in the Tor scenario is that your IP travels in a random path along the Tor encrypted tunnel and reaches a random endpoint, where your traffic then jumps on the Internet using one of the P2P computing devices as its proxy. That endpoint proxy could be a node anywhere in the world.
If you do try Tor, just go to Google and note which country shows. It will vary from minute to minute - an indication of Tor's anonymity at work.
1). Browser Settings
There are some easy things that can be done to configure a browser for better security and privacy. Among the basics, go into your Web browser's preference settings and set the browser not to accept cookies from sites you haven't visited, also known as third-party cookies. Generally, you'll want to accept cookies from the sites you visit.
Apple's Safari blocks third-party cookies by default; Mozilla intends to make this the default setting soon in Firefox, but for now you'll need to opt for the setting. You have to choose these settings in Microsoft's Internet Explorer and Google's Chrome.
Also, the newest versions of Internet Explorer, Mozilla Firefox, Google Chrome and several others offer settings for "Do Not Track," a proposed header field that requests that a Web application disable its site and/or cross-site tracking of user activity.
Consider setting your browser preferences to automatically clear cookies when you close the browser.
2). Cloud Storage
Storage of anything private and personal in the cloud should use the strongest form of encryption possible. Strengths of encryption come in various standards. RSA 2048-bit key encryption provides the best possible strength when used with public key infrastructure. The chance of cracking an RSA 2048-bit private key is not nil, but it would take so long that attempting it is not practicable using today's raw computing power.
A strong cipher is the most important consideration. Close behind, however, are the questions of where you should use encryption and with what method.
If you have any data stored on the Internet that you would like to ensure never gets seen by anyone other than yourself, then this is a good candidate for encryption.
The strongest and safest method today for encryption of cloud data is Zero Knowledge. Zero knowledge means that your cloud ISP will have no knowledge of what is being stored on their site. The private key to unlock your data will be created by you on your local drive. Thus only you will have the ability to unlock the data -- not even the cloud ISP will be able to do so.
SpiderOak and Wuala are two examples of ISP Software as a Service sites that offer ZK data encryption.
There are now quite a few SaaS encryption vendors from which to choose, but those that support Zero Knowledge are the safest bet for those with privacy in mind.
3). Two-Factor Authentication
The use of hack-prone password-based access is being gradually replaced by technologies like fingerprint scan, keyfob-generated keys and two-factor authentication methods.
If your ISP uses password-based access, make sure you maintain strong passwords. A password's strength is measured by its ability to avoid being guessed. Many ISPs and portals will test the strength of your password as you create it. Pay attention and be sure that the test returns "strong."
Do not use the same password for multiple accounts. Instead, use strong passwords that are unique to each account - and that's particularly important for your most sensitive online accounts, such as for banking, email, and social networks.
Two-factor authentication is another method that's growing in popularity. Google Gmail now offers a free two-step authentication service. The goal is to avoid having your login stream (which includes your password) from being intercepted by a "man-in-the-middle" attack. Criminals equipped with programs called packet analyzers (also known as "sniffers") can see your streaming data and steal your password.
With two-factor authentication, in addition to entering a password, the system will send to your phone a unique ID number that must be input for authentication as well. Using such a method means the "man-in-the-middle" cannot and will not know what is on your personal phone and so cannot intercept such information.
If your ISP offers two-step authentication, you'd be wise to use it.
4) Encryption for Chat and Email
With Google Talk and Google Hangouts, one can set the chat session to "off the record" to ensure that the chat session is never permanently stored on Google's chat servers.
Also, installing Pidgin for both Windows and Linux - it's a popular multiprotocol messaging software application - along with its "off the record" plugin will ensure that your chat session will remain encrypted and private. This ensures that an additional encryption layer is added to the stream using OTR, regardless of what the underlying protocol provides.
The same encrypted vs. nonencrypted concept applies to email. If you don't want your email read, then it is imperative that you encrypt it. The good news is that encrypting email is technically feasible using GnuPG, PGP or S/MIME standards, for example. The bad news is that few software applications are in circulation that make preparing and sending encrypted email "drop-dead" simple and foolproof in terms of usability by the general public.
5) Surf the Internet Anonymously
Finally, if you really feel strongly about keeping your Internet surfing habits anonymous, you may consider using a proxy for your Internet surfing - though even that won't guarantee complete anonymity.
A more difficult-to-trace method for surfing the Web is called Tor. Essentially, when you install Tor software, you log onto a peer-to-peer (P2P) network representing millions of people, much in the way BitTorrent works. It is encrypted and fully decentralized, meaning not only that it is self-sustainable but also that there is no central server which, if shut down, will stop its Internet activities.
What happens in the Tor scenario is that your IP travels in a random path along the Tor encrypted tunnel and reaches a random endpoint, where your traffic then jumps on the Internet using one of the P2P computing devices as its proxy. That endpoint proxy could be a node anywhere in the world.
If you do try Tor, just go to Google and note which country shows. It will vary from minute to minute - an indication of Tor's anonymity at work.
Labels:
anonymous Web surfing,
cloud privacy,
cookies,
do not track,
encryption,
Facebook privacy,
Internet,
Internet privacy,
online privacy,
P2P,
privacy,
proxy,
social media privacy,
Tor,
two-factor authentication
Thursday, March 28, 2013
New Web tool warns people if their tweet will get them fired.
Researchers from Hannover, Germany, have come up the FireMe! Web tool as a way of warning Twitter users if their tweets will get them fired.
A team from the University of Hannover in Germany has created a Web tool that warns people about their reckless tweets.
FireMe!'s goal is to raise awareness about the dangers and consequences of people being reckless online.
Kawase said he thought of the idea after attending a talk at his university about how the Web is influencing the work environment.
"After the talk I immediately started working on FireMe!," Kawase said, adding that he thought it would be a fun topic for research.
According to New Scientist, the team found that in a single week last June, nearly 22,000 people had tweeted about their boss or work in a negative way.
In order to illustrate just how extreme some tweets can get, FireMe! provides examples of actual tweets that got people fired.
Gilbert Gottfried was fired by Aflac for joking about the tsunami that hit Japan. New York University law fellow Nir Rosen resigned from his fellowship after his remarks about Lara Logan's sexual assault.
So how does FireMe! work?
According to Kawase, the system crawls Twitter with a set of predefined sentences that mention something negative about bosses or the workplace.
"Before it was an alert system — once we identified the user who had said something bad, a tweet was sent to warn them about the dangers of sharing such comments," Kawase said.
The alert system received a mixed response, Kawase said.
"Most people didn't care about getting fired," he said. "Still, 6 percent of users who got the alert actually deleted the tweets."
Twitter recently requested Kawaze to stop this alert system because it was violating the company's policy.
Today, Kawase's team has a website where people can see "bad tweets" via a live stream and check their own FireMe! score on the FireMeter.
Kawaze adds that the FireMeter is non-scientific. "It's goal is to improve engagement with the website," he said. "It's a mixed calculation considering the number of mentions to the boss, work and profanity in the users' timeline."
Source: MSN, New Scientist
Labels:
bad tweets,
fired,
FireMe,
Germany,
Internet privacy,
online privacy,
share,
social media,
tweet,
tweet alert,
Twitter
Friday, March 8, 2013
Despite increased privacy concerns, Facebook users are sharing more personal information.
Carnegie Mellon University conducted a study following more than 5,000 Facebook
users over six years, from 2005 and 2011, and found that changes in the
social network's privacy policies caused users to share more -- not
less -- personal data. Lest you think this means that users suddenly
trusted the site more, Carnegie Mellon says that Facebookers became more
and more protective of their personal details as the social network
grew in membership -- and that the uptick in shared information is a
result of increasingly granular privacy settings. If you recall,
Facebook introduced new in-depth privacy controls
in 2010, and the study found that the release of these new settings
corresponded to users sharing more personal data, both within their
network of friends and with strangers and third-party applications.
It's been quite some time since the new privacy policy was introduced, but the university says the sample group didn't reduce the amount of info shared with non-friends on the network, even as of 2011. The takeaway? Well, it's safe to say that more privacy controls doesn't equal more vigilance in protecting personal data, and it's certainly not a stretch to call Facebook's settings confusing. The researchers' comparison of the struggle for privacy to the eternal plight of Sisyphus? That might be a touch more dramatic.
It's been quite some time since the new privacy policy was introduced, but the university says the sample group didn't reduce the amount of info shared with non-friends on the network, even as of 2011. The takeaway? Well, it's safe to say that more privacy controls doesn't equal more vigilance in protecting personal data, and it's certainly not a stretch to call Facebook's settings confusing. The researchers' comparison of the struggle for privacy to the eternal plight of Sisyphus? That might be a touch more dramatic.
Labels:
Facebook,
Facebook privacy,
Facebook privacy policy,
Internet privacy,
online privacy,
privacy
Subscribe to:
Posts (Atom)
