Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Monday, March 24, 2014

Microsoft will break into your Outlook, Hotmail, and instant messenger accounts if it deems necessary.

The company's ability (and willingness) to take such an approach became apparent this week. Microsoft admitted in federal court documents that it forced its way into a blogger's Hotmail account to track down and stop a potentially catastrophic leak of sensitive software. The company says its decision is justified.

From the company's point of view, desperate times call for desperate measures.

"In this case, we took extraordinary actions based on the specific circumstances," said John Frank, one of the company's top lawyers, in a blog post Thursday night.

According to an FBI complaint, Microsoft in 2012 discovered that an ex-employee had leaked proprietary software to an anonymous blogger. Fearing that could empower hackers, Microsoft's lawyers approved emergency "content pulls" of the blogger's accounts to track it down. Company investigators entered the blogger's Hotmail account, then pored over emails and instant messages on Windows Live. The internal investigation led to the arrest on Wednesday of Alex Kibkalo, a former Microsoft employee based in Lebanon.

Although the move could be perceived as a breach of trust, Microsoft says it's allowed to make such unilateral decisions. It pointed to its terms of service: When you use Microsoft communication products, (Outlook, Hotmail, Windows Live) you agree to "this type of review ... in the most exceptional circumstances," Frank wrote.

Microsoft's legal team thought there was enough evidence suggesting the blogger would try selling the illegally obtained intellectual property. In such instances, law enforcement agents would typically seek a warrant, but Microsoft said it didn't need one. The servers storing the information are on its own property.

Ginger McCall, a director at the Electronic Privacy Information Center, said those actions are deeply troubling, because they show "Microsoft clearly believes that the users' personal data belongs to Microsoft, not the users themselves."

"This is part of the broader problem with privacy policies," she said. "There are hidden terms that the users don't actually know are there. If the terms were out in the open, people would be horrified by them."

Microsoft recognizes that it's a sensitive topic, especially as the nation grapples with revelations about the extent of warrantless surveillance on Americans by their own government -- spying that Microsoft and other major tech companies have loudly criticized.

That's why Microsoft is instituting a new policy: In the future, it'll loop in an outside lawyer who's a former federal judge and seek his or her approval.

In a move that might be deemed ironic, Microsoft will now add its own internal searches to its biannual transparency reports on government surveillance.

Source: CNN

Friday, January 10, 2014

Gmail and Google+ implement an "email anyone" policy.

A new feature from Google will let you e-mail just about anyone with a Google+ account, and, in turn, give them the ability to e-mail you.



The feature, announced on the official Gmail blog, won't give your actual e-mail address to strangers. But when a Gmail user begins typing in the address box, it will provide suggestions including people in their Google+ network.


The idea, Google says, is to make it easier to contact friends and other contacts when you've forgotten, or never had, their e-mail address. But some early reactions suggested the new change may make it too easy.


In our opinion, it's just another reason to hate Google+. They have officially turned it into a stalking tool.


Google, clearly anticipating the privacy concerns, notes that users may limit the feature, or opt out of it entirely.


While the default G+ setting will allow anyone on Google+ to contact you, users may limit that access to people in their Circles on the network, or to nobody at all.


There are other limits, too. A user may only e-mail you using the system once if you don't reply (addressing the stalking concerns, perhaps). And messages from people who are not in your G+ Circles will go into the "Social" folder, along with other posts from sites like G+, Facebook and Twitter, instead of the user's primary inbox.


Google said the feature will be rolling out to Gmail and Google+ users over the next couple of days, when they will receive a message with a link to the feature.

Source: Gmail Email Blast

Thursday, June 27, 2013

Yahoo raising security concerns for 'recycling" old e-mail addresses.

Yahoo has announced a plan to "recycle" old e-mail addresses, a move meant to free up accounts for folks who want them but that has sparked privacy concerns.

In a blog post, senior vice president Jay Rossiter announced that Yahoo e-mail accounts that have been dormant for more than a year will be reset so that active users can have access to them.
"If you're like me, you want a Yahoo! ID that's short, sweet, and memorable like albert@yahoo.com instead of albert9330399@yahoo.com," he wrote.
 
The one-year period will officially begin July 15, when users can "claim" a dormant account name. They'll find out in mid-August if they got the account they wanted.
 
It's clearly an effort by Yahoo, which has been working to redefine and rejuvenate itself under new CEO Marissa Mayer, to re-engage older users and reward active ones. But it has security experts nervous.
 
Security analyst Graham Cluley doesn't mince words.
 
"In short: as an idea it sucks, and it shows Yahoo's lack of respect to customers who created accounts with them in years gone by," Cluley wrote Wednesday.
 
Cluley lists several scenarios where the plan could backfire. They include situations in which a user has another primary e-mail account, but has given their Yahoo address as a backup in case of security situations, lost passwords and the like.
 
He said the move appears to be "an underhanded way to get people to re-engage with the site" and that people who may not actively use their Yahoo mail, but use it to store old messages and other documents, could lose them without ever realizing it.
 
Mat Honan of CNN content partner Wired, himself the recent victim of a high-profile hack, called the move "a spectacularly bad idea."
 
In the wake of such complaints, Yahoo released a followup statement saying it's sure the transition can be made without compromising security.
 
"We're committed and confident in our ability to do this in a way that's safe, secure and protects our users' data," the company said.
 
The vast majority of inactive Yahoo IDs don't have a mailbox associated with them, the company said, and any personal data associated with the accounts will be deleted.
 
During a 30-day deactivation period, bounce-back e-mails will alert senders that the deactivated account no longer exists and Yahoo will unsubscribe those accounts from newsletters, commercial e-mail alerts and the like.
 
Businesses, financial institutions, social networks and other e-mail providers will be sent notifications about e-mail addresses that have been deactivated.
 
Source: CNN