Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, January 16, 2020

Worlds first keylogger?

No comments:
How the KGB Bugged American Typewriters During the Cold War
By Kyle Mizokami,

  • In the 1970s, U.S. intelligence believed the embassy in Moscow was leaking information.
  • Repeated searches for a secret transmitter in the embassy turned up nothing.
  • Finally, engineers discovered a typewriter with a transmitter hacked into it.

Fascinating story about how the Soviets modified an IBM Selectric typewriter to covertly transmit every keystroke to a KGB monitoring station. Electronically, this hack is a work of art.

h/t the Michael Tsai Blog

Thursday, November 14, 2019

Naked Security: Warrantless searches of devices at US borders ruled unconstitutional

No comments:
Warrantless searches of devices at US borders ruled unconstitutional
by Lisa Vaas,

A federal court in Boston on Tuesday ruled that suspicion-free, warrantless searches of travelers’ electronic devices at US border entry points are unconstitutional.

Great news. While most people would agree that Customs has the right to search baggage in order to make sure no prohibited items are being brought into the country, there is no law (as far as I know) prohibiting the importation of data of any kind, which pretty much clobbers any alleged "right" they may have for searching the content of electronic devices.

Of course, if some other law enforcement agency presents them with a warrant, that's a different story.

Yes, I know you can't import child pornography. But that's a law enforcement issue in general, not a Customs issue. Just like police and FBI can't search your computer without a warrant, neither should Customs be allowed to. And that's just what the court ruled.

Thursday, November 07, 2019

Naked Security: Warrant let police search online DNA database

No comments:
Warrant let police search online DNA database
By Lisa Vaas,

Detective Michael Fields of the Orlando Police Department in Florida ... successfully used GEDmatch to identify a suspect in the 2001 murder of a 25-year-old woman that he’d spent six years trying to solve. So, because Fields didn’t want to stop using DNA records – he was searching for suspects in the case of a serial rapist who attacked a number of women decades ago – he took his disappointment to the court.

As Fields reportedly announced at a police convention last week, he won what he was after: a warrant to search GEDmatch’s full database. As the Times reports, he’s now working with the forensic consulting firm Parabon to try to find a DNA match that will lead him to that rapist.

Legal experts told the Times that overriding a site’s policies in this way is a “huge game changer” for genetic privacy. The newspaper quoted Erin Murphy, a law professor at New York University:

The company made a decision to keep law enforcement out, and that’s been overridden by a court. It’s a signal that no genetic information can be safe.

I've been telling friends and relatives for years that submitting DNA samples to geneology databases is risky, and now we're seeing why. Courts are now deciding that law enforcement should have complete access to the databases. This sets a precedent that will, in short order, be used to justify use and abuse of this data by every law enforcement employee, government agency and elected official that asks for it.

Tuesday, October 29, 2019

Naked Security: Stalker found pop star by searching eyes’ reflections on Google Maps

1 comment:
Stalker found pop star by searching eyes’ reflections on Google Maps
By Lisa Vaas,

A predator has confessed to stalking and attacking a young Japanese pop star by zooming in on the reflections in her eyes from photos she posted on social media.
...
A 26-year-old man by the name of Sato was arrested and confessed to police that he’d used the star’s selfies to figure out where she lived. Each of her pupils reflected the nearby streetscape, which he plugged into the street map function of Google Map to find out matching bus stops and scenery.

Holy cow! This is the kind of analysis I used to think only existed in science fiction.

Saturday, November 11, 2017

Facebook knows all and sees all

No comments:
Well, maybe not all, but it sometimes seems pretty darn close. I haven't been a fan of Facebook for a long time, mostly because I don't like how their policies capriciously do things to aggravate users without warning or explanation. But the more I read the more I congratulate myself for suspending my account back in 2010. The thing that really annoys me these days is their censorship of content it finds objectionable, which includes content that is pro-Christian, pro-Israel, or otherwise politically conservative.

But, although very relevant news these days, that is not what I'm writing about today. Today's article is just to share a few links describing how far Facebook's data mining goes in order to build profiles on people for the purpose of targeting ads.

It is known that they maintain a "shadow profile" (a term they don't use and don't like to hear) on all their users. They track not only the contacts you've uploaded and the content you post/view/like, but they also tie it to the profile (contacts, content, etc.) of all your friends. And also people they think might be your friends - any other user who uploaded a contacts list with you in it is fair game here as well. Then they tie it to "web beacons" on sites all over the Internet to track what sites you visit, what you're searching/shopping for and what you purchase, including the browsing/shopping habits of everybody associated with you (including your friends and people they think might want to be friends). And then they tie it in with GPS location monitoring if you have granted access to the FB app/web site in order to discover where you shop, when you're traveling, and what events you are attending. And of course, the content of any text, photos and video you (or your contacts, friends or possible-friends) share via Facebook Messenger, What's App or Instagram also contributes to this profile.

There have even been accusations of them going so far as to listen in via your phone's microphone in order to target ads based on things you say, but Facebook explicitly denies this charge (everything above has pretty much been confirmed - Facebook doesn't deny any of it, they just don't like to talk about it a lot).

None of it should come as much of a surprise, but it looks pretty shocking when it's all piled together in one paragraph.

Sources:

h/t to the Michael Tsai blog for the link that caught my attention this morning.

Wednesday, August 24, 2016

MacRumors: Facebook Now Testing Autoplay Videos With Sound in iOS App

No comments:
Facebook Now Testing Autoplay Videos With Sound in iOS App
Tuesday August 23, 2016 6:18 AM PDT by Joe Rossignol

Starting today, Facebook will begin testing autoplay videos -- including ads -- with sound in its iOS and Android apps. Facebook told Mashable the test will be limited to Australian users and rolled out in two different ways to gauge how users react. In both versions of the test, sound will only play if the iPhone's volume is turned up, and sound can also be turned to "always off" in Facebook settings.

I've been ticked off at Facebook for quite some time now. I suspended my account briefly in 2010 and then for real in 2013. Mostly because of policies that make the site less and less interesting to users and more and more ruled by advertisers.

At this point, I really wonder why it exists or should be used by anyone. You are forced to work in a straightjacket. There's almost no opportunity for personalization anymore (aside from a banner image), they censor what you're allowed to read and write, and now they're going to be forcing auto-play videos with sound on you, despite the fact that users have overwhelmingly said they don't want this.

Wednesday, March 11, 2015

The Intercept: iSpy: The CIA Campaign to Steal Apple’s Secrets

No comments:
iSpy: The CIA Campaign to Steal Apple’s Secrets

Researchers working with the Central Intelligence Agency have conducted a multi-year, sustained effort to break the security of Apple’s iPhones and iPads, according to top-secret documents obtained by The Intercept.

The security researchers presented their latest tactics and achievements at a secret annual gathering, called the "Jamboree," where attendees discussed strategies for exploiting security flaws in household and commercial electronics. The conferences have spanned nearly a decade, with the first CIA-sponsored meeting taking place a year before the first iPhone was released.

None of this should come as a surprise to anyone, but it is interesting to read what our government is doing in their attempt to spy on everybody all the time. I'm also happy to see that Apple is (at least for now) on the side of their customers.

Wednesday, October 08, 2014

The Digital Reader: Adobe is Spying on Users, Collecting Data on Their eBook Libraries

No comments:
In the "Gee, I was looking for another reason to continue hating Adobe" department...

Adobe is Spying on Users, Collecting Data on Their eBook Libraries

Adobe is gathering data on the ebooks that have been opened, which pages were read, and in what order. All of this data, including the title, publisher, and other metadata for the book is being sent to Adobe's server in clear text.

I am not joking; Adobe is not only logging what users are doing, they’re also sending those logs to their servers in such a way that anyone running one of the servers in between can listen in and know everything,

But wait, there’s more.

Adobe isn’t just tracking what users are doing in DE4; this app was also scanning my computer, gathering the metadata from all of the ebooks sitting on my hard disk, and uploading that data to Adobe’s servers.

In. Plain. Text.

And just to be clear, this includes not just ebooks I opened in DE4, but also ebooks I store in calibre and every Epub ebook I happen to have sitting on my hard disk.

Wow!

I have never installed Digital Editions, but you can be certain I won't ever install it in the future.

Please click through to the article. There are some followup posts. Adobe claims you agreed to all this when you clicked on the license agreement that everybody knows you didn't read. They also claim they are only phoning home about documents opened in Digital Editions, even though it's been demonstrated that such a claim is a lie.

Friday, November 22, 2013

In Soviet Russia (and on LG televisions), TV watches you!

2 comments:
You THINK you're watching your LG smart TV - but IT's WATCHING YOU, baby • The Register

According to Yorkshire, UK–based hacker "DoctorBeet," the internet-enabled sets try to phone home to LG every time a viewer changes the channel, giving the chaebol the ability to track exactly which channels are being watched, minute by minute.

Using network packet-sniffing tools, DoctorBeet discovered that his set was also transmitting the names of media files he played off USB storage, which he observes could potentially be embarrassing for those in the habit of watching less savory downloaded fare.
...
Disturbingly, however, there doesn't seem to be any way to opt out of the data collection. DoctorBeet observed that while his TV did have an option called "Collection of watching info" in its settings menu, the data was still transmitted whether the option was set to on or off.

This coupled with the fact that when DoctorBeet complained to LG, he got a brush off (you clicked "I accept" so we can do anything we want) tells me that LG is not a company that should be trusted at all. Time to scratch them off of the list of companies I'm willing to do business with.

I'm more than a little bit worried now about how many other smart TVs are doing the same thing. LG was merely the first to get caught. It may be time to buy a firewall device to insert on my LAN between the router and the modem so I can start blackholing the servers that appliances phone-home to.

Monday, September 16, 2013

EZ-Pass is watching you all over New York

No comments:
Forbes writes, in E-ZPasses Get Read All Over New York (Not Just At Toll Booths) that New York City has EZ-Pass readers all over the city. They track the devices, allegedly for the purpose of detecting congestion and directing traffic:

It's part of Midtown in Motion, an initiative to feed information from lots of sensors into New York's traffic management center. A spokesperson for the New York Department of Transportation, Scott Gastel, says the E-Z Pass readers are on highways across the city, and on streets in Manhattan, Brooklyn and Staten Island, and have been in use for years. The city uses the data from the readers to provide real-time traffic information, as for this tool.

Maybe so, but, as the article cites, the EZ-Pass terms and conditions do not state that this is a permitted use of the device. And if one agency is using it for one purpose, you can be sure that in the future, more agencies in more jurisdictions will use it for more purposes, and some may be a lot more intrusive than dynamically adjusting on-line traffic maps.

I never got EZ-Pass, because I don't travel through toll booths that often, and I don't like the idea of paying a monthly service fee to have the device. With this piece of news, now I think I've got a much stronger reason than "I don't want to pay for it."

Wednesday, August 21, 2013

TechDirt: Feds Threaten To Arrest Lavabit Founder For Shutting Down His Service

No comments:
Here's the link to the TechDirt article, and the link to the NBC News article it references.

In case you haven't been following this case, Lavabit is (or was) a secure e-mail service. All mail is encrypted so no unwanted third parties (not even Lavabit) can snoop the content. The US government didn't like the idea of an e-mail service they couldn't spy on so they sent him threatening letters demanding access. According to the above linked articles, they wanted a full tap into the content of all messages from all users. Rather than comply with this blatantly unconstitutional abuse of power, the owner shut down the service.

And now the Feds are threatening to prosecute him for doing that!

I'm sure my left-wing friends will see no problem with this, but for the rest of us, this is just another example of the abusive totalitarian nature of the US government today.