Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Friday, January 16, 2015

Jimmy Kimmel shows just how easy it is to steal someone's password.

Did you know that "password123" is the most common password used in the US?
 
Even though we all know better, human beings will forever insist on using insecure, awful passwords. Awful passwords that, apparently, we are more than happy to broadcast on national television.
 
Jimmy Kimmel's producers went around the streets of LA under the guise of assessing people's password security, which they were able to do by getting them to reveal their super secret passwords directly into the microphone. We don't know their email address or anything, so it's not the worst thing in the world. But perhaps they should go home and at least turn two-factor authentication on?
 

Source: YouTube

Monday, January 5, 2015

A false copyright message is rapidly spreading across Facebook. Don't waste your time copy & pasting.

"In response to the new Facebook guidelines, I hereby declare that my copyright is attached to all of my personal details, illustrations, comics, paintings, professional photos and videos, etc. (as a result of the Berner Convention). For commercial use of the above my written consent is needed at all times!"

You may have seen that very message pop up -- perhaps time and time again -- in your Facebook feed. The message has been making the rounds on the social network. It encourages people to copy and paste the text and post it on their own walls if they want to be placed "under protection of copyright laws."

It's a frightful message and those worried that Facebook will own their photos or other media are posting it -- unaware that it is a hoax. Here's the truth: Facebook doesn't own your media and there is no such thing as the Berner Convention.

"We have noticed some statements that suggest otherwise and we wanted to take a moment to remind you of the facts -- when you post things like photos to Facebook, we do not own them," Facebook spokesman Andrew Noyes said in a statement. "Under our terms (https://www.facebook.com/legal/terms), you grant Facebook permission to use, distribute, and share the things you post, subject to the terms and applicable privacy settings." 

Brad Shear, a Washington-area attorney and blogger who is an expert on social media, said the message was "misleading and not true." He said that when you agree to Facebook's terms of use you provide Facebook a "non-exclusive, transferable, royalty-free, worldwide license to use any content you post. You do not need to make any declarations about copyright issues since the law already protects you.  The privacy declaration [in this message] is worthless and does not mean anything."
 
Facebook users cannot retroactively negate any of the privacy or copyright terms they agreed to when they signed up for their Facebook accounts nor can they unilaterally alter or contradict terms instituted by Facebook simply by posting a contrary legal notice on their Facebook walls.

This isn't the first time a message like this has popped up on Facebook. A similar message made the rounds in June and a few years ago as well. 

Bottom line? Don't bother copying, pasting, and posting. It was a hoax before and is still a hoax now.

Friday, January 10, 2014

Gmail and Google+ implement an "email anyone" policy.

A new feature from Google will let you e-mail just about anyone with a Google+ account, and, in turn, give them the ability to e-mail you.



The feature, announced on the official Gmail blog, won't give your actual e-mail address to strangers. But when a Gmail user begins typing in the address box, it will provide suggestions including people in their Google+ network.


The idea, Google says, is to make it easier to contact friends and other contacts when you've forgotten, or never had, their e-mail address. But some early reactions suggested the new change may make it too easy.


In our opinion, it's just another reason to hate Google+. They have officially turned it into a stalking tool.


Google, clearly anticipating the privacy concerns, notes that users may limit the feature, or opt out of it entirely.


While the default G+ setting will allow anyone on Google+ to contact you, users may limit that access to people in their Circles on the network, or to nobody at all.


There are other limits, too. A user may only e-mail you using the system once if you don't reply (addressing the stalking concerns, perhaps). And messages from people who are not in your G+ Circles will go into the "Social" folder, along with other posts from sites like G+, Facebook and Twitter, instead of the user's primary inbox.


Google said the feature will be rolling out to Gmail and Google+ users over the next couple of days, when they will receive a message with a link to the feature.

Source: Gmail Email Blast

Friday, November 22, 2013

Jack Vale perfectly demonstrates how nothing is really private with his social media experiment...

Jack Vale is a California comedian that has been on TV shows such as "Lopez Tonight" (TBS), "Most Outrageous Moments" (NBC), "The View" (ABC), "Pranked" (MTV), "World's Dumbest" (TruTV), and many more. In his most recent YouTube video, he shows how easy it is to find out someone's most personal details using social media.

Source: YouTube

Thursday, October 17, 2013

Do you have a Google / Google Plus account? You may be featured in inappropriate advertising. Here's how to opt out:

You may have seen a warning at the top of your Gmail or Chrome browser explaining that Google is changing its privacy policy. What Google is actually doing is starting a program where it takes things you’ve “liked” (or +1′ed, or rated) around the web, then use your name and face in advertisements that show up in other people’s Google search queries.

Remember when Facebook introduced a similar program, one unlucky guy became a spokesman for a giant barrel of lube (story link)? For the vast majority of people, this use of data is unacceptable.

The good news is that Google is giving you a one-click way to opt out of this sort of invasive use of your likeness.

Here's how to do it:

  1. Follow this link: https://plus.google.com/settings/endorsements.
  2. Now uncheck the box. Congratulations, you’re now opted-out of Google’s endorsement program.

Tuesday, July 30, 2013

5 simple methods to improve your privacy online.

It wasn't long after the Internet came into widespread use that online privacy became a growing concern. After all, anytime people are connected through their computers and sharing resources online, there's the potential for prying and abuse.

1). Browser Settings
There are some easy things that can be done to configure a browser for better security and privacy. Among the basics, go into your Web browser's preference settings and set the browser not to accept cookies from sites you haven't visited, also known as third-party cookies. Generally, you'll want to accept cookies from the sites you visit.

Apple's Safari blocks third-party cookies by default; Mozilla intends to make this the default setting soon in Firefox, but for now you'll need to opt for the setting. You have to choose these settings in Microsoft's Internet Explorer and Google's Chrome.

Also, the newest versions of Internet Explorer, Mozilla Firefox, Google Chrome and several others offer settings for "Do Not Track," a proposed header field that requests that a Web application disable its site and/or cross-site tracking of user activity.

Consider setting your browser preferences to automatically clear cookies when you close the browser.

2). Cloud Storage
Storage of anything private and personal in the cloud should use the strongest form of encryption possible. Strengths of encryption come in various standards. RSA 2048-bit key encryption provides the best possible strength when used with public key infrastructure. The chance of cracking an RSA 2048-bit private key is not nil, but it would take so long that attempting it is not practicable using today's raw computing power.

A strong cipher is the most important consideration. Close behind, however, are the questions of where you should use encryption and with what method.

If you have any data stored on the Internet that you would like to ensure never gets seen by anyone other than yourself, then this is a good candidate for encryption.

The strongest and safest method today for encryption of cloud data is Zero Knowledge. Zero knowledge means that your cloud ISP will have no knowledge of what is being stored on their site. The private key to unlock your data will be created by you on your local drive. Thus only you will have the ability to unlock the data -- not even the cloud ISP will be able to do so.

SpiderOak and Wuala are two examples of ISP Software as a Service sites that offer ZK data encryption.

There are now quite a few SaaS encryption vendors from which to choose, but those that support Zero Knowledge are the safest bet for those with privacy in mind.

3). Two-Factor Authentication
The use of hack-prone password-based access is being gradually replaced by technologies like fingerprint scan, keyfob-generated keys and two-factor authentication methods.

If your ISP uses password-based access, make sure you maintain strong passwords. A password's strength is measured by its ability to avoid being guessed. Many ISPs and portals will test the strength of your password as you create it. Pay attention and be sure that the test returns "strong."

Do not use the same password for multiple accounts. Instead, use strong passwords that are unique to each account - and that's particularly important for your most sensitive online accounts, such as for banking, email, and social networks.

Two-factor authentication is another method that's growing in popularity. Google Gmail now offers a free two-step authentication service. The goal is to avoid having your login stream (which includes your password) from being intercepted by a "man-in-the-middle" attack. Criminals equipped with programs called packet analyzers (also known as "sniffers") can see your streaming data and steal your password.

With two-factor authentication, in addition to entering a password, the system will send to your phone a unique ID number that must be input for authentication as well. Using such a method means the "man-in-the-middle" cannot and will not know what is on your personal phone and so cannot intercept such information.

If your ISP offers two-step authentication, you'd be wise to use it.

4) Encryption for Chat and Email
With Google Talk and Google Hangouts, one can set the chat session to "off the record" to ensure that the chat session is never permanently stored on Google's chat servers.

Also, installing Pidgin for both Windows and Linux - it's a popular multiprotocol messaging software application - along with its "off the record" plugin will ensure that your chat session will remain encrypted and private. This ensures that an additional encryption layer is added to the stream using OTR, regardless of what the underlying protocol provides.

The same encrypted vs. nonencrypted concept applies to email. If you don't want your email read, then it is imperative that you encrypt it. The good news is that encrypting email is technically feasible using GnuPG, PGP or S/MIME standards, for example. The bad news is that few software applications are in circulation that make preparing and sending encrypted email "drop-dead" simple and foolproof in terms of usability by the general public.

5) Surf the Internet Anonymously
Finally, if you really feel strongly about keeping your Internet surfing habits anonymous, you may consider using a proxy for your Internet surfing - though even that won't guarantee complete anonymity.

A more difficult-to-trace method for surfing the Web is called Tor. Essentially, when you install Tor software, you log onto a peer-to-peer (P2P) network representing millions of people, much in the way BitTorrent works. It is encrypted and fully decentralized, meaning not only that it is self-sustainable but also that there is no central server which, if shut down, will stop its Internet activities.

What happens in the Tor scenario is that your IP travels in a random path along the Tor encrypted tunnel and reaches a random endpoint, where your traffic then jumps on the Internet using one of the P2P computing devices as its proxy. That endpoint proxy could be a node anywhere in the world.
If you do try Tor, just go to Google and note which country shows. It will vary from minute to minute - an indication of Tor's anonymity at work.

Friday, July 26, 2013

The new school ID: iris scans.

By the fall, several schools -- ranging from elementary schools to colleges -- will be rolling out various iris scanning security methods.

Winthrop University in South Carolina is testing out iris scanning technology during freshman orientation this summer. Students had their eyes scanned as they received their ID cards in June.

"Iris scanning has a very high level of accuracy, and you don't have to touch anything, said James Hammond, head of Winthrop University's Information Technology department. "It can be hands free security."

The college will be deploying scanning technology from New Jersey-based security company Iris ID.

South Dakota-based Blinkspot manufactures iris scanners specifically for use on school buses. When elementary school students come aboard, they look into a scanner (it looks like a pair of binoculars). The reader will beep if they're on the right bus and honk if they're on the wrong one.

The Blinkspot scanner syncs with a mobile app that parents can use to see where their child is. Every time a child boards or exits the bus, his parent gets an email or text with the child's photograph, a Google map where they boarded or exited the bus, as well as the time and date.

Iris-scanning is part of a growing trend called "biometrics," a type of security that recognizes physical characteristics to identify people. As the technology becomes faster and cheaper to build, several security equipment manufacturers are looking at biometric methods like iris scanning as the ID badge of the future.

In the next year, industry insiders say the technology will be available all over-- from banks to airports. That means instead of entering your pin number, you can gain access to an ATM in a blink. Used in an airport, the system will analyze your iris as you pass through security, identifying and welcoming you by name.

One company developing that technology is Eyelock. The company's scanners are already in use in foreign airports and at high-security offices, including Bank of America's North Carolina headquarters.

Eyelock's technology records video of your eyeball and uses an algorithm to find the best image of each eye. Eyelock is also entering the school market, piloting their devices in elementary school districts and nursery schools around the country.

"Imagine a world where you're no longer reliant on user names and passwords," Eyelock CMO Anthony Antolino told CNNMoney. "If we're going through a turnstile and you have authorization to go beyond that, it'll open the turnstile for you, if you embed it into a tablet or PC, it will unlock your phone or your tablet or it will log you into your email account."

Eyelock's airport security technology can process up to fifty people per minute.
"You walk through without stopping, you look at the camera, it recognizes you in less than one second," Antolino said. "In the case of customs, by the time you approach the customs agent your profile would pull up and present your documents for authorization."

Though some privacy advocates worry that convenience could be coming at the expense of security.

The iris scanning companies note that the data their scanners collect is encrypted -- an outsider would only see 1s and 0s if they went in search of your iris scans. And the companies themselves don't collect any of the data -- the schools, airports and businesses that use them own the data.

"It's sort of like a brave new world; the new technology is sort of scary," said Page Bowden, a parent of a student at Winthrop University's on-campus nursery school. "But when you stop to actually think about it, and think about the level of security that [it] affords you as a parent and your children, it's worth it."

Source: CNN Money

Thursday, June 27, 2013

Yahoo raising security concerns for 'recycling" old e-mail addresses.

Yahoo has announced a plan to "recycle" old e-mail addresses, a move meant to free up accounts for folks who want them but that has sparked privacy concerns.

In a blog post, senior vice president Jay Rossiter announced that Yahoo e-mail accounts that have been dormant for more than a year will be reset so that active users can have access to them.
"If you're like me, you want a Yahoo! ID that's short, sweet, and memorable like albert@yahoo.com instead of albert9330399@yahoo.com," he wrote.
 
The one-year period will officially begin July 15, when users can "claim" a dormant account name. They'll find out in mid-August if they got the account they wanted.
 
It's clearly an effort by Yahoo, which has been working to redefine and rejuvenate itself under new CEO Marissa Mayer, to re-engage older users and reward active ones. But it has security experts nervous.
 
Security analyst Graham Cluley doesn't mince words.
 
"In short: as an idea it sucks, and it shows Yahoo's lack of respect to customers who created accounts with them in years gone by," Cluley wrote Wednesday.
 
Cluley lists several scenarios where the plan could backfire. They include situations in which a user has another primary e-mail account, but has given their Yahoo address as a backup in case of security situations, lost passwords and the like.
 
He said the move appears to be "an underhanded way to get people to re-engage with the site" and that people who may not actively use their Yahoo mail, but use it to store old messages and other documents, could lose them without ever realizing it.
 
Mat Honan of CNN content partner Wired, himself the recent victim of a high-profile hack, called the move "a spectacularly bad idea."
 
In the wake of such complaints, Yahoo released a followup statement saying it's sure the transition can be made without compromising security.
 
"We're committed and confident in our ability to do this in a way that's safe, secure and protects our users' data," the company said.
 
The vast majority of inactive Yahoo IDs don't have a mailbox associated with them, the company said, and any personal data associated with the accounts will be deleted.
 
During a 30-day deactivation period, bounce-back e-mails will alert senders that the deactivated account no longer exists and Yahoo will unsubscribe those accounts from newsletters, commercial e-mail alerts and the like.
 
Businesses, financial institutions, social networks and other e-mail providers will be sent notifications about e-mail addresses that have been deactivated.
 
Source: CNN

Saturday, June 22, 2013

New Facebook bug exposes some contact information.

A newly discovered Facebook bug may have inadvertently compromised the contact information of 6 million users, the company says.

The bug, which has since been repaired, was part of the Download Your Information tool, which lets Facebook users export all the data from profiles, such as posts to their timeline and conversations with friends. People using the tool may have downloaded inadvertently the contact information for people they were somehow connected to.
 
Some people upload their contact lists or address books to Facebook, which the company then uses to suggest new friends they can connect with who are already using the service.
 
Though the number of people impacted is sizable, the actual spread of their contact information appears to be limited. The phone numbers and e-mail addresses were not exposed to developers or posted publicly. It is only shown to people they had at least a tentative connection with, and who may have already had their contact information. Even in that pool, it was only exposed to people who had used the data-exporting tool.

"For almost all of the email addresses or telephone numbers impacted, each individual email address or telephone number was only included in a download once or twice. This means, in almost all cases, an email address or telephone number was only exposed to one person," Facebook's security team said in a post.
 
The company says it has no evidence that the bug was "exploited maliciously" and that there have been no complaints so far.
 
The social media company announced the bug on Friday afternoon. The issue was discovered by a third-party security researcher who submitted it through Facebook's White Hat program.
 
Facebook's White Hat program is set up so that people such as security researchers can report any vulnerabilities they find on the social network and get a reward for $500 and up in return. These types of programs are common at Internet companies.
 
"Your trust is the most important asset we have, and we are committed to improving our safety procedures and keeping your information safe and secure," read the post.
People who were affected by the bug will receive an e-mail from Facebook.
 
Source: CNN

Thursday, April 18, 2013

Watch out everyone...CISPA has passed in the House. Let's all hope it gets stuck in the Senate!

CISPA, the controversial bill intended to let Internet companies share information about users more freely with the government, has been passed by the House of Representatives. The bill has been touched up since its first appearance last year, but many remain suspicious after what they view as years of misguided tech legislation. Both outside critics and the White House have said CISPA is fundamentally unsound.

The Cyber Intelligence Sharing and Protection Act (CISPA) is meant to let Internet companies share information with the government for cybersecurity purposes. A company like Facebook or Twitter, for instance, may have info the government wants, like when a user logged in or where they were at a certain time.

The bill would facilitate sharing that data, but many believe it throws privacy protections out the window in the process. Critics say it amounts to the government deputizing private companies to do their surveillance for them.

Source: NBC

Tuesday, March 19, 2013

Talk about a phishing expedition by law enforcement...

A newly proposed law states that AT&T, Verizon Wireless, Sprint, and other wireless providers would be required to capture and store Americans' confidential text messages.

The law enforcement proposal would require wireless providers to record and store customers' SMS messages -- a controversial idea similar to requiring them to record audio of their customers' phone calls -- in case police decide to obtain them at some point in the future.

"Billions of texts are sent every day, and some surely contain key evidence about criminal activity," Richard Littlehale from the Tennessee Bureau of Investigation will tell Congress, according to a copy of his prepared remarks. "In some cases, this means that critical evidence is lost. Text messaging often plays a big role in investigations related to domestic violence, stalking, menacing, drug trafficking, and weapons trafficking."

So, for all of you that talk about private matters through text message, I'd suggest you stop doing that. Face to face is the only way that can even be considered private anymore.

Source: CNET

Friday, March 8, 2013

Despite increased privacy concerns, Facebook users are sharing more personal information.

Carnegie Mellon University conducted a study following more than 5,000 Facebook users over six years, from 2005 and 2011, and found that changes in the social network's privacy policies caused users to share more -- not less -- personal data. Lest you think this means that users suddenly trusted the site more, Carnegie Mellon says that Facebookers became more and more protective of their personal details as the social network grew in membership -- and that the uptick in shared information is a result of increasingly granular privacy settings. If you recall, Facebook introduced new in-depth privacy controls in 2010, and the study found that the release of these new settings corresponded to users sharing more personal data, both within their network of friends and with strangers and third-party applications.

It's been quite some time since the new privacy policy was introduced, but the university says the sample group didn't reduce the amount of info shared with non-friends on the network, even as of 2011. The takeaway? Well, it's safe to say that more privacy controls doesn't equal more vigilance in protecting personal data, and it's certainly not a stretch to call Facebook's settings confusing. The researchers' comparison of the struggle for privacy to the eternal plight of Sisyphus? That might be a touch more dramatic.

Source: Engadget

Wednesday, February 27, 2013

Your Internet provider is spying on you!

The five major Internet service providers (AT&T, Cablevision, Verizon, Time Warner, and Comcast) have signed onto help copyright holders "educate" consumers downloading copyrighted movies, games, music, and more. How? By spying on their customers.

The Copyright Alert System, aka "six strikes," kicked off today with the cooperation of five major Internet service providers. The goal of the new campaign is to curb copyright infringement by going after consumers rather than pirates.

While the CAS seems like something that would raise the hackles of privacy and civil liberty groups, the plan isn't to arrest, sue, or fine people downloading illegal movies, games, or music. Instead, the group managing the program -- the Center for Copyright Information -- says its objective is to "educate" such downloaders that they are infringing on protected intellectual copyrights

Under graduated response, or six strikes, entertainment companies will notify a participating Internet service providers that a customer has allegedly been pirating movies or TV shows illegally. The bandwidth provider will then send a notice intended to educate the customer about the consequences of downloading unauthorized content.

The Internet service provider is then supposed to gradually ratcheting up the pressure on customers who ignore the warnings. Eventually, after six warnings, they can choose to suspend service. Graduated response, however, does not include the termination of service. Customers wrongly accused can appeal to their company and take their case to an arbitration group for review. The plan doesn't protect Internet consumers from being sued by copyright owners, however.

Some ways that pirated material is shared on the Internet, such as cyberlockers, e-mail attachments, and Dropbox folders, are not included under six strikes.


Source: CNET

Wednesday, February 20, 2013

Have you been Scroogled by Google? (Yes, scroogle is a real word).

In a new ad sweeping the nation, Microsoft is bringing it to your attention that you may be one of the many getting "scroogled" by Google. Of course, they're pushing their own product, Outlook.com, who doesn't go through your email to sell ads. Applause to Microsoft...you finally came up with a catchy, must see commercial!

"Think Google respects your privacy? Think again.

Google goes through every Gmail that's sent or received, looking for keywords so they can target Gmail users with paid ads. And there's no way to opt out of this invasion of your privacy. Outlook.com is different—we don't go through your email to sell ads."