Skip to main content

Home/ Future of the Web/ Group items tagged exposing

Rss Feed Group items tagged

Gonzalo San Gil, PhD.

Researcher Receives Copyright Threat After Exposing Security Hole - TorrentFreak - 1 views

    • Gonzalo San Gil, PhD.
       
      # ! Notices to prevent people's protection # ! Oh, The 'Copyright Enforcement'...
  •  
    [ Andy on July 15, 2015 C: 69 News A researcher who exposed security flaws in tools used to monitor the Internet usage of UK students has been hit with a copyright complaint. 'Slipstream' discovered flaws in Impero Education Pro which could reveal the personal details of thousands of pupils but in response Impero has sent in its legal team. ...]
  •  
    [ Andy on July 15, 2015 C: 69 News A researcher who exposed security flaws in tools used to monitor the Internet usage of UK students has been hit with a copyright complaint. 'Slipstream' discovered flaws in Impero Education Pro which could reveal the personal details of thousands of pupils but in response Impero has sent in its legal team. ...]
Gonzalo San Gil, PhD.

BTindex Exposes IP-Addresses of BitTorrent Users | TorrentFreak - 0 views

  •  
    " Ernesto on August 7, 2014 C: 10 News The newly launched torrent search engine BTindex crawls BitTorrent's DHT network for new files. It's a handy service, but one that comes with a controversial twist. In addition to listing hundreds of thousands of magnet links, it also exposes the IP-addresses of BitTorrent users to the rest of the world."
  •  
    " Ernesto on August 7, 2014 C: 10 News The newly launched torrent search engine BTindex crawls BitTorrent's DHT network for new files. It's a handy service, but one that comes with a controversial twist. In addition to listing hundreds of thousands of magnet links, it also exposes the IP-addresses of BitTorrent users to the rest of the world."
Gonzalo San Gil, PhD.

Who knew? MPAA concerned online pirates are exposed to malware | Ars Technica - 0 views

  •  
    "The Motion Picture Association of America (MPAA) said Monday it's concerned that intellectual property pirates are being exposed to malware and other dangers" [ #! This is Really Funny # ! ... coming from one of the main #Malware #distributors... # ! :D [# Just one Reference: http://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal] ]
  •  
    "The Motion Picture Association of America (MPAA) said Monday it's concerned that intellectual property pirates are being exposed to malware and other dangers"
Paul Merrell

Nearly Everyone In The U.S. And Canada Just Had Their Private Cell Phone Location Data ... - 0 views

  • A company by the name of LocationSmart isn't having a particularly good month. The company recently received all the wrong kind of attention when it was caught up in a privacy scandal involving the nation's wireless carriers and our biggest prison phone monopoly. Like countless other companies and governments, LocationSmart buys your wireless location data from cell carriers. It then sells access to that data via a portal that can provide real-time access to a user's location via a tailored graphical interface using just the target's phone number.
  • Theoretically, this functionality is sold under the pretense that the tool can be used to track things like drug offenders who have skipped out of rehab. And ideally, all the companies involved were supposed to ensure that data lookup requests were accompanied by something vaguely resembling official documentation. But a recent deep dive by the New York Times noted how the system was open to routine abuse by law enforcement, after a Missouri Sherrif used the system to routinely spy on Judges and fellow law enforcement officers without much legitimate justification (or pesky warrants): "The service can find the whereabouts of almost any cellphone in the country within seconds. It does this by going through a system typically used by marketers and other companies to get location data from major cellphone carriers, including AT&T, Sprint, T-Mobile and Verizon, documents show. Between 2014 and 2017, the sheriff, Cory Hutcheson, used the service at least 11 times, prosecutors said. His alleged targets included a judge and members of the State Highway Patrol. Mr. Hutcheson, who was dismissed last year in an unrelated matter, has pleaded not guilty in the surveillance cases." It was yet another example of the way nonexistent to lax consumer privacy laws in the States (especially for wireless carriers) routinely come back to bite us. But then things got worse.
  • Driven by curiousity in the wake of the Times report, a PhD student at Carnegie Mellon University by the name of Robert Xiao discovered that the "try before you buy" system used by LocationSmart to advertise the cell location tracking system contained a bug, A bug so bad that it exposed the data of roughly 200 million wireless subscribers across the United States and Canada (read: nearly everybody). As we see all too often, the researcher highlighted how the security standards in place to safeguard this data were virtually nonexistent: "Due to a very elementary bug in the website, you can just skip that consent part and go straight to the location," said Robert Xiao, a PhD student at the Human-Computer Interaction Institute at Carnegie Mellon University, in a phone call. "The implication of this is that LocationSmart never required consent in the first place," he said. "There seems to be no security oversight here."
  • ...1 more annotation...
  • Meanwhile, none of the four major wireless carriers have been willing to confirm any business relationship with LocationSmart, but all claim to be investigating the problem after the week of bad press. That this actually results in substantive changes to the nation's cavalier treatment of private user data is a wager few would be likely to make.
Gonzalo San Gil, PhD.

LinkedIn Breach Exposed 117 Million User Accounts - eSecurity Planet [# :/ Note... to k... - 0 views

  •  
    "The stolen database holds 167 million records, of which 117 million include email addresses and passwords. By Jeff Goldman | Posted May 20, 201"
Gonzalo San Gil, PhD.

ISP Vows to Protect Users From a Piracy Witch Hunt - TorrentFreak - 0 views

  •  
    " By Ernesto on April 22, 2016 C: 14 Breaking Swedish Internet service provider Bahnhof says it will do everything in its power to prevent copyright holders from threatening its subscribers. The provider is responding to a recent case in which a competing ISP was ordered to expose alleged BitTorrent pirates, reportedly without any thorough evidence."
  •  
    " By Ernesto on April 22, 2016 C: 14 Breaking Swedish Internet service provider Bahnhof says it will do everything in its power to prevent copyright holders from threatening its subscribers. The provider is responding to a recent case in which a competing ISP was ordered to expose alleged BitTorrent pirates, reportedly without any thorough evidence."
Gonzalo San Gil, PhD.

Patched Android Lockscreen Still a Threat | Mobile | LinuxInsider [MS Note...] - 0 views

    • Gonzalo San Gil, PhD.
       
      [With the announcement that Microsoft would partner with the truly open-source, Android-based Cyanogen OS to provide a bundled suite of apps, both companies made one thing very clear: Android's not just for Google anymore. http://www.wired.com/2015/04/microsoft-google-cyanogen/]
  •  
    Although Google issued a patch for its Nexus line, hackers can have a field day exploiting a recently discovered lockscreen vulnerability on other Android products. "Even when users feel confident about locking their phone with a strong password, if their device is exposed to this exploit, it does not really matter how strong the password is," noted Armando Leon, director of mobile at LaunchKey.
  •  
    Although Google issued a patch for its Nexus line, hackers can have a field day exploiting a recently discovered lockscreen vulnerability on other Android products. "Even when users feel confident about locking their phone with a strong password, if their device is exposed to this exploit, it does not really matter how strong the password is," noted Armando Leon, director of mobile at LaunchKey.
Gonzalo San Gil, PhD.

MPAA Emails Expose Dirty Media Attack Against Google - TorrentFreak - 0 views

  •  
    "New emails have revealed how the MPAA and Mississippi Attorney General Jim Hood orchestrated a PR smear campaign against Google in order to push through their anti-piracy measures. "
  •  
    "New emails have revealed how the MPAA and Mississippi Attorney General Jim Hood orchestrated a PR smear campaign against Google in order to push through their anti-piracy measures. "
Gonzalo San Gil, PhD.

Exposed: NSA program for hacking any cell phone network, no matter where it is | Ars Te... - 1 views

  •  
    "The National Security Agency has spied on hundreds of companies and groups around the world, including in countries allied with the US government, as part of an effort designed to allow agents to hack into any cellular network, no matter where it's located, according to a report published Thursday."
  •  
    "The National Security Agency has spied on hundreds of companies and groups around the world, including in countries allied with the US government, as part of an effort designed to allow agents to hack into any cellular network, no matter where it's located, according to a report published Thursday."
Gonzalo San Gil, PhD.

Leak Exposes Hollywood's Global Anti-Piracy Strategy | TorrentFreak [# ! Via...] - 1 views

    • Gonzalo San Gil, PhD.
       
      [# ! Via, TY, Francisco Manuel HS' FB...]
  •  
    # ! ...there are no 'Leaks' but Public Relations strategy. # ! Hollywood are #educating '#pirates' to #circumvent its measures, # ! as '#They' know that #sharers are its #best #customers...
  •  
    # ! ...there are no 'Leaks' but Public Relations strategy. # ! Hollywood are #educating '#pirates' to #circumvent its measures, # ! as '#They' know that #sharers are its #best #customers...
Gonzalo San Gil, PhD.

Meet the Dogged Researchers Who Try to Unmask Haters Online | MIT Technology Review - 0 views

  •  
    "A group of journalists and researchers wade into ugly corners of the Internet to expose racists, creeps, and hypocrites. Have they gone too far? By Adrian Chen on December 18, 2014 "
  •  
    "A group of journalists and researchers wade into ugly corners of the Internet to expose racists, creeps, and hypocrites. Have they gone too far? By Adrian Chen on December 18, 2014 "
Gonzalo San Gil, PhD.

On net neutrality, Internet providers are betrayed by one of their own | Ars Technica - 2 views

  •  
    "They're not happy anymore, especially not after Wheeler yesterday all but confirmed at the Consumer Electronics Show (CES) that he will propose reclassifying Internet providers as common carriers in order to impose net neutrality rules. This would expose broadband to some of the FCC's strongest powers contained in Title II of the Communications Act, usually reserved for wireline phone service." [# ! The saddest... # ! ... of this story is that , one more time, is clearly shown that, # ! in the #Internet issues, #citizens are the least #important.... (# ! and it's yet to be seen if that, finally, Internet providers are reclassified as "common carriers in order to impose net neutrality rules". )]
  •  
    "They're not happy anymore, especially not after Wheeler yesterday all but confirmed at the Consumer Electronics Show (CES) that he will propose reclassifying Internet providers as common carriers in order to impose net neutrality rules. This would expose broadband to some of the FCC's strongest powers contained in Title II of the Communications Act, usually reserved for wireline phone service."
Gonzalo San Gil, PhD.

ISP Doesn't Have to Expose Pirating Subscribers, Judge Rules | TorrentFreak - 0 views

  •  
    " Ernesto on February 4, 2015 C: 0 Breaking A federal court in Georgia has quashed a broad DMCA subpoena which required local Internet provider CBeyond to reveal the identities of alleged BitTorrent pirates. The magistrate judge ruled that ISPs don't have to hand over personal information as they are not storing any infringing material themselves."
  •  
    " Ernesto on February 4, 2015 C: 0 Breaking A federal court in Georgia has quashed a broad DMCA subpoena which required local Internet provider CBeyond to reveal the identities of alleged BitTorrent pirates. The magistrate judge ruled that ISPs don't have to hand over personal information as they are not storing any infringing material themselves."
Gonzalo San Gil, PhD.

UK "Porn Filter" Triggers Widespread Internet Censorship | TorrentFreak - 2 views

  •  
    " Ernesto on July 2, 2014 C: 38 Breaking A new tool released by the Open Rights Group today reveals that 20% of the 100,000 most-visited websites on the Internet are blocked by the parental filters of UK ISPs. With the newly launched website the group makes it easier to expose false positives and show that the blocking efforts ban many legitimate sites, TorrentFreak included. "
  •  
    " Ernesto on July 2, 2014 C: 38 Breaking A new tool released by the Open Rights Group today reveals that 20% of the 100,000 most-visited websites on the Internet are blocked by the parental filters of UK ISPs. With the newly launched website the group makes it easier to expose false positives and show that the blocking efforts ban many legitimate sites, TorrentFreak included. "
Paul Merrell

Google Concealed Data Breach Over Fear Of Repercussions; Shuts Down Google+ Service | Z... - 0 views

  • Google opted in the Spring not to disclose that the data of hundreds of thousands of Google+ users had been exposed because the company says they found no evidence of misuse, reports the Wall Street Journal. The Silicon Valley giant feared both regulatory scrutiny and regulatory damage, according to documents reviewed by the Journal and people briefed on the incident.  In response to being busted, Google parent Alphabet is set to announce broad privacy measures which include permanently shutting down all consumer functionality of Google+, a move which "effectively puts the final nail in the coffin of a product that was launched in 2011 to challenge Facebook, and is widely seen as one of Google's biggest failures."  Shares in Alphabet fell as much as 2.1% following the Journal's report: 
  • The software glitch gave outside developers access to private Google+ profile data between 2015 and March 2018, after Google internal investigators found the problem and fixed it. According to a memo prepared by Google's legal and policy staff and reviewed by the Journal, senior executives worried that disclosing the incident would probably trigger "immediate regulatory interest," while inviting comparisons to Facebook's massive data harvesting scandal. 
Paul Merrell

Facebook Quietly Notifies Public That Millions Of Instagram Users Had Passwords Exposed... - 0 views

  • While everyone was focused on the release of the Mueller report Thursday, Facebook quietly notified the public that the passwords of "millions of Instagram users" were stored in an unencrypted format on an internal server, and searchable by any employee.
  • In March, security expert Brian Krebs of KrebsonSecurity noted:  The Facebook source said the investigation so far indicates between 200 million and 600 million Facebook users may have had their account passwords stored in plain text and searchable by more than 20,000 Facebook employees. The source said Facebook is still trying to determine how many passwords were exposed and for how long, but so far the inquiry has uncovered archives with plain text user passwords dating back to 2012. My Facebook insider said access logs showed some 2,000 engineers or developers made approximately nine million internal queries for data elements that contained plain text user passwords. -KrebsonSecurity In short, if you believe Facebook that the passwords were not improperly accessed, rest well. If you don't believe them, and you use your Instagram password for other things, perhaps it's time to think of a new one.  
Gonzalo San Gil, PhD.

European Copyright Leak Exposes Plans to Force the Internet to Subsidize Publishers | E... - 1 views

  •  
    "A just-leaked draft impact assessment on the modernization of European copyright rules could spell the end for many online services in Europe as we know them. "
Gonzalo San Gil, PhD.

Company Uses DMCA to Censor and Expose Critical Blogger - TorrentFreak - 0 views

  •  
    " By Ernesto on June 17, 2016 C: 25 News Marketing and sales company Smart Circle is using the DMCA to uncover the identity of a critical blogger. The company obtained a subpoena directed at WordPress, stating that the blogger in question violates their copyrights by publishing modified images of its key employees."
Paul Merrell

Notes from the Fight Against Surveillance and Censorship: 2014 in Review | Electronic F... - 1 views

  • 2014 in Review Series Net Neutrality Takes a Wild Ride 8 Stellar Surveillance Scoops Web Encryption Gets Stronger and More Widespread Big Patent Reform Wins in Court, Defeat (For Now) in Congress International Copyright Law More Time in the Spotlight for NSLs The State of Free Expression Online What We Learned About NSA Spying in 2014—And What We're Fighting to Expose in 2015 "Fair Use Is Working!" Email Encryption Grew Tremendously, but Still Needs Work Spies Vs. Spied, Worldwide The Fight in Congress to End the NSA's Mass Spying Open Access Movement Broadens, Moves Forward Stingrays Go Mainstream Three Vulnerabilities That Rocked the Online Security World Mobile Privacy and Security Takes Two Steps Forward, One Step Back It Was a Pivotal Year in TPP Activism but the Biggest Fight Is Still to Come The Government Spent a Lot of Time in Court Defending NSA Spying Last Year Let's Encrypt (the Entire Web)
  •  
    The Electronic Freedom Foundation just dropped an incredible bunch of articles on the world in the form of their "2014 Year In Review" series. These are major contributions that place an awful lot of information in context. I thought I had been keeping a close eye on the same subject matter, but I'm only part way through the articles and am learning time after time that I had missed really important news having to do with digital freedom. I can't recommend these articles enough. So far, they are all must-read.  
Paul Merrell

XKeyscore Exposé Reaffirms the Need to Rid the Web of Tracking Cookies | Elec... - 0 views

  • The Intercept published an expose on the NSA's XKeyscore program. Along with information on the breadth and scale of the NSA's metadata collection, The Intercept revealed how the NSA relies on unencrypted cookie data to identify users. As The Intercept says: "The NSA’s ability to piggyback off of private companies’ tracking of their own users is a vital instrument that allows the agency to trace the data it collects to individual users. It makes no difference if visitors switch to public Wi-Fi networks or connect to VPNs to change their IP addresses: the tracking cookie will follow them around as long as they are using the same web browser and fail to clear their cookies." The NSA slides released by The Intercept give detailed guides to understanding the data transmitted by these cookies, as well as how to find unique machine identifiers that analysts can use to differentiate between multiple machines using the same IP address. We've written before about how spy agencies piggyback on social media account data to find Internet users' names or other identifying info, and these slides drive home the point that HTTP cookies leave users vulnerable to government surveillance, since any intermediary (or spy agency) can read the sensitive data they contain.
  • Worse yet, most of the time these identifying cookies come from third-party sources on webpages, and users have no meaningful way to opt out of receiving them (short of blocking all third party cookies) since advertisers (the main server of these types of cookies) refuse to honor the Do Not Track header.  Browser makers could help address this sort of non-consensual tracking by both advertisers and the NSA with some simple technical changes—changes that have been shown to reduce the number of third party cookies received by 67%. So far, though, they've been unwilling to build privacy protecting features in by default. Until they do, the best way for users to protect themselves is by installing a privacy protecting app like Privacy Badger, which is designed to block these types of uniquely identifying tracking cookies, or HTTPS Everywhere to block the transmission of HTTP cookies.
1 - 20 of 70 Next › Last »
Showing 20 items per page