Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, October 12, 2018

Apple Pens Seven-Page Letter to Fight Against ‘Dangerously Ambiguous’ Anti-Encryption Bill in Australia

Right now in Australia, a potential bill would require tech companies to provide “critical assistance” to various agencies that are investigating crimes.


The bill in its current state leaves a lot to be desired in the eyes of companies like Apple, who considers it “dangerously ambiguous” and rallies against the very idea of encryption. Apple, of course, relies on encryption and personal device security as a major tentpole feature for its products, especially iOS devices. The Australian government, however, says encryption methods “are increasingly being used by terrorist groups and organized criminals to avoid detection and disruption”, and, as a result, wants to temper the implementation moving forward.


TechCrunch reports that Apple has made it very clear it opposes the current bill, penning a seven page letter to the Australian parliament to present its opposition:


“We appreciate the government’s outreach to Apple and other companies during the drafting of this bill,” the letter read. “While we are pleased that some of the suggestions incorporated improve the legislation, the unfortunate fact is that the draft legislation remains dangerously ambiguous with respect to encryption and security.”


“This is no time to weaken encryption,” it read. “Rather than serving the interests of Australian law enforcement, it will just weaken the security and privacy of regular customers while pushing criminals further off the grid.””


Apple has six specific points it touches on in the letter, which is source linked at the bottom of this article. Apple’s arguments include the bill’s potential violation of international agreements, that the bill may harm “user trust”, and that it could potentially weaken cybersecurity in general. Apple also echoes that security experts have made it clear that a “backdoor” in software, even built specifically for law enforcement, would not be immune to hackers looking to exploit the opening.


“For instance, the bill could allow the government to order the makers of smart home speakers to install persistent eavesdropping capabilities into a person’s home, require a provider to monitor the health data of its customers for indications of drug use, or require the development of a tool that can unlock a particular user’s device regardless of whether such tool could be used to unlock every other user’s device as well,” the letter said.”


Apple is a staunch supporter of encryption, and has even gone up against the Federal Bureau of Investigation over it. In that case, Apple also argued that any changes it could make to facilitate the FBI’s needs for software access would also make it possible for hackers to reach the same end result.


This is a battle that Apple is not going to give up on, even internationally. Whether or not it will have any affect on the Australian government’s future decision remains to be seen, though.


[via TechCrunch; Apple; AGDHA]

Like this post? Share it!

Facebook Says 30 Million Accounts Were Affected in Recent ‘Security Issue’

Facebook's stock security banner

Before the end of September this year, Facebook confirmed that a major security breach impacted the social network and upwards of 50 million accounts.


Now, weeks later, Facebook has published another update on the matter, trimming the number of accounts that were apparently affected by the security breach, and saying at length that they not only patched the initial threat, but continue to investigate what happened to avoid any future issues. To start, Facebook now says that only “30 million accounts actually had their tokens stolen”.


The public post breaks down what happened, which starts with the attackers already having control of a set number of accounts, and then accessing the friends list of people, moving from one account to the next. This automated technique allowed the attackers to move from and secure upwards of 400,000 separate accounts. That technique also allowed the attackers to see a person’s profile page as they’d see it, including their News Feed, Messenger conversations, friends lists, and more:


“In the process, however, this technique automatically loaded those accounts’ Facebook profiles, mirroring what these 400,000 people would have seen when looking at their own profiles. That includes posts on their timelines, their lists of friends, Groups they are members of, and the names of recent Messenger conversations. Message content was not available to the attackers, with one exception. If a person in this group was a Page admin whose Page had received a message from someone on Facebook, the content of that message was available to the attackers.”


Facebook says the access to 400,000 accounts then led to the ability to steal the tokens for up to 30 million accounts on the social network. That number is still remarkably high, but it’s down from the initial 50 million that Facebook originally stated back in September. Here’s the most important bit, though:


“For 15 million people, attackers accessed two sets of information – name and contact details (phone number, email, or both, depending on what people had on their profiles). For 14 million people, the attackers accessed the same two sets of information, as well as other details people had on their profiles. This included username, gender, locale/language, relationship status, religion, hometown, self-reported current city, birthdate, device types used to access Facebook, education, work, the last 10 places they checked into or were tagged in, website, people or Pages they follow, and the 15 most recent searches. For 1 million people, the attackers did not access any information.”


Facebook states that if you want to see if your account was vandalized by the attackers, you can visit the social network’s Help Center, through this link. The platform is also going to send personalized messages to individuals who had their tokens stolen, and explain what information from their accounts might have been breached and accessed.


Finally, Facebook says it is not ruling out “small-scale attacks” at this point, and they are investigating:


“This attack did not include Messenger, Messenger Kids, Instagram, WhatsApp, Oculus, Workplace, Pages, payments, third-party apps, or advertising or developer accounts. As we look for other ways the people behind this attack used Facebook, as well as the possibility of smaller-scale attacks, we’ll continue to cooperate with the FBI, the US Federal Trade Commission, Irish Data Protection Commission, and other authorities.”


Our Take


So, that’s a pretty lengthy update, but should be par for the course at this point as this situation develops. It’s great that Facebook is still working out the details and explaining what they discover to those interested in keeping up with what’s going on, at least.


[via Facebook Newsroom]

Like this post? Share it!

Friday, September 28, 2018

Facebook Uses Your 2FA Phone Number for Targeted Advertising

Facebook dislike thumb down button

Being stalked from one website to another by persistent advertising is a real issue, but some companies, like Apple, have made strides to try and reduce its impact.


But targeted advertising isn’t going anywhere anytime soon, especially if Facebook has any say in the matter. The company has recently confirmed that it does indeed go to some pretty great lengths to provide information to advertisers, with this latest effort definitely one of the social networking giant’s worst.


A couple of days ago, Gizmodo ran a piece that outlined how Facebook uses the phone number some users added to take advantage of two factor authentication as a way to target those same individuals with ads. This is an extension of how Facebook already handles phone numbers saved to the platform’s profiles.


How it works normally is if you add your phone number to your Facebook profile, and then add your phone number to some online retailer’s online presence, those two sources can match and be used to target advertisements as you peruse the web. Facebook has said in the past that it doesn’t use security details in this way, but that is definitely not true, as the company has changed its tune in a statement to TechCrunch:


“We use the information people provide to offer a better, more personalized experience on Facebook, including ads. We are clear about how we use the information we collect, including the contact information that people upload or add to their own accounts. You can manage and delete the contact information you’ve uploaded at any time.”


A spokesman also told us that users can opt out of this ad-based repurposing of their security digits by not using phone number based 2FA. (Albeit, the company only added the ability to do non-mobile phone based 2FA back in May, so anyone before then was all outta luck.)”


Our Take


So, Facebook uses your security details in an effort to lock down even more advertising efforts. Crazy to think that’s a thing, because it’s hard to imagine that even Facebook would do something like this. But here we are in 2018 and this is our reality now. The fact that Facebook says if users don’t want to get targeted advertising they need to remove their phone number from 2FA security efforts is bananas.


[via Gizmodo; TechCrunch]

Like this post? Share it!

Facebook Reveals ‘Almost 50 Million’ Accounts Affected by Security Issue

Facebook's stock security banner

This week, Facebook suffered a major breach, which left millions of accounts vulnerable to an outside, malicious attack.


On Friday, Facebook officially announced that hackers accessed the Facebook network on Tuesday. According to the post “nearly 50 million” accounts are affected by the illegal intrusion. The company also revealed that the hackers were able to gain access via the platform’s “View As” code. That particular feature allows Facebook users to see how their Facebook profile appears to folks who look at it.


The hackers gained Facebook’s access tokens, which are individual codes that allow Facebook users to remain logged in.


“On the afternoon of Tuesday, September 25, our engineering team discovered a security issue affecting almost 50 million accounts. We’re taking this incredibly seriously and wanted to let everyone know what’s happened and the immediate action we’ve taken to protect people’s security.


Our investigation is still in its early stages. But it’s clear that attackers exploited a vulnerability in Facebook’s code that impacted “View As”, a feature that lets people see what their own profile looks like to someone else. This allowed them to steal Facebook access tokens which they could then use to take over people’s accounts. Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app.”


At this point, Facebook says that it has informed law enforcement of the situation and has already patched the vulnerability. Facebook does not make it clear if the accounts in question have had any personal information stolen or otherwise obtained, or how those accounts might be misused in the future.


The social network has reset the access tokens to the nearly 50 million accounts that were affected by the breach. The company also confirmed it took precautions with an additional 40 million accounts that were accessed with the View As feature within the last year.


Finally, Facebook says that no one needs to change their passwords.


[via Facebook]

Like this post? Share it!