Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, April 12, 2017

European Union regulator will complete the Yahoo email hack investigation in ‘next couple of weeks’

European Union regulator will complete the Yahoo email hack investigation in ‘next couple of weeks’

Image Credit: Yahoo
Yahoo’s European regulator said it is preparing to give the U.S. Internet company the results of an investigation into the 2014 theft of data from 500 million users, including any remedial action to avoid a repeat of the breach. Yahoo said in September last year that hackers had stolen the data in 2014, prompting criticism from U.S. politicians into the delay in notifying customers.
Ireland’s Data Protection Commissioner, the lead European regulator on privacy issues for Yahoo because the company’s European headquarters are in Dublin, told Reuters she would issue the report “in the next couple of weeks”. “We are preparing to serve the final report on Yahoo EMEA Ltd and require of them any remedial actions we have identified,” Helen Dixon said in an interview. It will be up to Yahoo whether to make the report public, she said.
A new EU-wide data protection law coming into force in May 2018 allows fines of up to 4 percent of global turnover. Until then, however, the office of the Data Protection Commissioner said it has no administrative capability to fine a company. A spokesman for Yahoo said it has been cooperating with the commissioner’s office on the investigation and will review the findings carefully when they are available.
Reuters
Publish date: April 12, 2017 12:17 pm| Modified date: April 12, 2017 12:17 pm

Monday, April 10, 2017

Microsoft Finally Reveals What Data Windows 10 Collects From Your PC


Wednesday, April 05, 2017 Mohit Kumar



Since the launch of Windows 10, there has been widespread concern about its data collection practices, mostly because Microsoft has been very secretive about the telemetry data it collects.

Now, this is going to be changed, as Microsoft wants to be more transparent on its diagnostics data collection practices.

Till now there are three options (Basic, Enhanced, Full) for Windows 10 users to select from under its diagnostics data collection section, with no option for users to opt out of sending their data to Microsoft.

Also, the company has never said precisely what data it collects behind these options, which raised huge privacy concerns among privacy-conscious users.



But now for the first time, Microsoft has revealed what data Windows 10 is collecting from your computer with the release of the Windows 10 Creators Update, bringing an end to nearly two years of its mysterious data collection practices.

The Windows 10 Creators Update, which will be available from April 11 for users to download for free, comes with a revamped Privacy settings section.

During the process of upgrading to the Creators Update, you will be displayed a new Privacy Settings screen that will ask you to toggle the following features:


Location – Allow Windows and apps to request your location and share that data with Microsoft.
Speech Recognition – Allow Cortana and Windows Store apps to recognize your voice and send that data to Microsoft to improve speech recognition.
Tailored experiences with diagnostic data – Allow Microsoft to use diagnostic data from your computer to offer tips and recommendations.
Relevant ads – Allow apps to use advertising IDs to show ads more interesting to you based on your app usage.
What's more? On Wednesday, Microsoft published a massive list of diagnostics data – both the Basic and Full levels of diagnostics – on its TechNet site, showing what data gets collected.




Basic – The Basic level collects a limited set of data that is critical for understanding the device and its configuration. This data includes basic device information, quality-related information, app compatibility, and Windows Store.
Full – The Full level collects data for the following nine categories: common data; software setup and inventory data; product and service usage data; browsing, search and query data; content consumption data; linking, typing, and speech utterance data; and licensing and purchase data.
Windows chief Terry Myerson said in a blog post published Wednesday that Microsoft hoped the transparency would allow users to make "more informed choices" as the company starts rolling out its new Creators update to the operating system.

This more transparency in gathering diagnostic data after two years of the Windows 10 release is likely Microsoft's response to European Union regulators that's publicly pressuring the company about its privacy practices for the past year.

In February, European Union regulators said they're still unsatisfied with the privacy changes announced by Microsoft and seeking further clarification from the company.

Marisa Rogers, the privacy officer of the Microsoft's Windows and Devices Group, said that the company is planning to "share more information about how [it] will ensure Windows 10 is compliant with the European Union's General Data Protection Regulation."

Tuesday, April 4, 2017

Apps on your smartphone could be talking to teach other and breaching your privacy: Study

Apps on your smartphone could be talking to teach other and breaching your privacy: Study

Do you use smartphone apps to organise lunch dates, make convenient online purchases or communicate the most intimate details of your existence? Beware, these apps may be secretly talking to each other and potentially breaching your security, researchers warn.
A study showed that applications on the android phones are able to talk to one another and trade information. The biggest security risks were some of the least utilitarian — apps that pertained to personalisation of ringtones, widgets, and emojis, the researchers said. “Researchers were aware that apps may talk to one another in some way, shape, or form,” said Gang Wang, assistant professor at Virginia Polytechnic Institute and State University, US.
But “this study shows undeniably with real-world evidence over and over again is that app behaviour, whether it is intentional or not, can pose a security breach depending on the kinds of apps you have on your phone”, Wang added. The types of threats fall into two major categories, either a malware app that is specifically designed to launch a cyber-attack or apps that simply allow for collusion and privilege escalation.
In the latter category, it is not possible to quantify the intention of the developer, so collusion, while still a security breach, can in many cases be unintentional, the researchers said. The findings were presented at the Association for Computing Machinery Asia Computer and Communications Security Conference in Dubai.
The team examined a whopping 110,150 apps over three years including 100,206 of Google Play’s most popular apps and 9,994 malware apps from Virus Share a private collection of malware app samples. “Of the apps we studied, we found thousands of pairs of apps that could potentially leak sensitive phone or personal information and allow unauthorised apps to gain access to privileged data,” commented Daphne Yao, associate professor at Virginia Tech.
“We hope this study will be a source for the industry to consider re-examining their software development practices and incorporate safeguards on the front end,” Wang added.
Publish date: April 4, 2017 10:47 am| Modified date: April 4, 2017 10:47 am

Wednesday, November 16, 2016

WhatsApp temporarily pauses user data sharing with Facebook in Europe

WhatsApp temporarily pauses user data sharing with Facebook in Europe

Representational image: Reuters
WhatsApp has temporarily suspended giving parent company Facebook information about users in Europe for ad targeting, responding to concerns there over privacy, a source close to the matter said Tuesday. Conversations with officials in Europe over the past few months resulted in the social network deciding to only tapping into WhatsApp user data there for purposes such as fighting spam, according to the source.
The break was described as an effort to give regulators time to share privacy concerns and for Facebook to consider ways to address them. German data protection authorities in September cited privacy concerns when they blocked Facebook from collecting subscriber data from WhatsApp there.
“It has to be (the users’) decision whether they want to connect their account with Facebook,” Hamburg’s Commissioner for Data Protection and Freedom of Information Johannes Caspar said at the time. “Facebook has to ask for their permission in advance.”
WhatsApp announced in August that it would begin sharing data with Facebook, in a bid to allow better targeted advertising and to combat spam on the platform. Users of the instant messenger were given the ability to opt out of sending information to Facebook through settings in WhatsApp’s applications on smartphones.
European data protection group G29 formally expressed its concerns at the end of October. The G29 sent letters asking Facebook and WhatsApp to stop sharing data until appropriate legal safeguards were in place. The sharing of WhatsApp user information with Facebook went beyond what subscribers consented to in the original terms of service, the G29 reasoned.
Facebook bought WhatsApp about two years ago in a deal valued about $19 billion. In mid-September, the European Commission recommended tighter privacy and security requirements for services including WhatsApp and Microsoft-owned video calling service Skype, saying they should be regulated more like traditional telecoms.
Under the proposal, the commission would require companies like WhatsApp or Skype to offer emergency-calling services when customers dial traditional phone numbers as well as obey stricter privacy rules.
AFP

Thursday, November 10, 2016

Russian court upholds decision to ban LinkedIn over data policy

Russian court upholds decision to ban LinkedIn over data policy

Representational image
A Russian court on Thursday upheld a decision to block the website of social networking company LinkedIn Corp., Interfax news agency reported, setting a precedent for the way foreign internet firms operate in the country.
Russia’s Roskomnadzor communications watchdog has said LinkedIn, which has more than 6 million registered users in Russia, was violating a law requiring websites which store the personal data of Russian citizens to do so on Russian servers.
Moscow has said the law, introduced in 2014 but never previously enforced, is aimed at protecting Russians’ personal data. Critics see it as an attack on social networks in a country which has increasingly tightened control over the Internet in recent years.
Moscow’s Tagansky District Court ruled in August that LinkedIn’s site should be blocked, but the decision had not yet come into force pending a company appeal. “The decision of the Tagansky District Court has been upheld, the appeal by LinkedIn Corporation is unsatisfactory,” Interfax quoted a court decision as saying. Russia will take action to block LinkedIn’s website within the next week, RIA news agency cited a Roskomnadzor spokesman as saying.
“LinkedIn’s vision is to create economic opportunity for the entire global workforce. The Russian court’s decision has the potential to deny access to LinkedIn for the millions of members we have in Russia and the companies that use LinkedIn to grow their businesses,” a LinkedIn’s spokesman told Reuters. “We remain interested in a meeting with Roskomnadzor to discuss their data localization request.”
Roskomnadzor did not immediately reply to a request for comment. While some companies such as online reservations site Booking.com have said they will transfer the necessary data to Russian servers, it is unclear whether others, including Facebook and Alphabet unit Google, will comply with the law.
Reuters

Thursday, November 3, 2016

EU-US Privacy Shield data transfer agreement under scrutiny by privacy advocacy groups

EU-US Privacy Shield data transfer agreement under scrutiny by privacy advocacy groups

(Image credit: Getty Images)
A new EU-U.S. pact governing the transfer of personal data faces a second legal challenge, putting the details of the deal which underpins billions of dollars of transatlantic trade in digital services under further scrutiny. French privacy advocacy group La Quadrature du Net, non-profit Internet service provider French Data Network and its Federation FDN industry association have now challenged the adoption of the Privacy Shield pact by the European Commission at the Luxembourg-based General Court, following in the steps of Irish group Digital Rights Ireland.
The Privacy Shield agreement was reached earlier this year after the European Union’s highest court struck down the previous Safe Harbor Principles used by companies to enable them to transfer Europeans’ personal data to the United States, due to concerns about intrusive U.S. surveillance of online data. The new agreement gives businesses storing Europeans’ data on U.S. servers – from human resources information to people’s browsing histories and hotel bookings – an easy way to do so without falling foul of tough EU private data transfer rules.
More than 500 companies have signed up to Privacy Shield so far, including Google, Facebook and Microsoft, while over 1,000 are being processed by the U.S. Department of Commerce. The agreement seeks to strengthen privacy protections for EU citizens by giving them a means of seeking redress in the case of disputes, including through a new privacy ombudsman within the State Department who will deal with complaints from Europeans about U.S. spying.
But the objectors say that restrictions on U.S. surveillance activities – in particular the bulk collection of data and the purposes for which the data can be used – are inadequate and therefore the Privacy Shield agreement should be annulled. Under EU law companies or individuals may challenge EU acts before the EU courts if they are directly concerned within two months of the act coming into force, otherwise they have to go through national courts, a process which takes longer.
However both challenges face a strong risk of being declared inadmissible if the court finds that the associations are not directly concerned. In their challenge the French groups say that the U.S. ombudsman is not an effective mechanism for dealing with complaints. “The fact that it relies on so-called ‘independent’ instruments is in no way sufficient to consider it an independent judicial entity,” they said.
A spokesman for the European Commission, which negotiated the Privacy Shield with Washington, said it was aware of the new complaint. “We don’t comment on ongoing court cases. As we have said from the beginning, the Commission is convinced that the Privacy Shield lives up to the requirements set out by the European Court of Justice, which have been the basis for the negotiations,” Christian Wigand said.
The U.S. Department of Commerce did not respond to questions about the second challenge.
Reuters

Saturday, October 29, 2016

Silicon Valley could gain key data privacy ally in next month’s Senate election

Silicon Valley could gain key data privacy ally in next month’s Senate election

Next month’s Senate election in Wisconsin could gain Silicon Valley a key ally in Washington in the high-tech industry’s battle against the U.S. government’s growing appetite for more access to private data. Democrat Russ Feingold, 63, the only lawmaker to vote against the USA Patriot Act in 2001, leads incumbent Republican Senator Ron Johnson in the state in opinion polls ahead of the Nov. 8 election.
Johnson, 61, rode a wave of support from conservative Tea Party activists to victory six years ago, sweeping Feingold out of office. But polls this year have consistently shown Feingold ahead, although recent surveys show a tighter race.
Privacy advocates and former Feingold staffers said they expected Feingold, if returned to office, to be sympathetic to the privacy concerns of technology companies and civil liberties groups on issues such as encryption and domestic spying, at a time when many lawmakers are being pressured to confront security threats from Islamic State and other militant groups.
The Feingold campaign did not respond to requests for comment. Apple Inc, Microsoft Corp and other tech giants have tussled in recent years with government agencies over how much user data the companies should be forced to retain and share with investigators hunting for criminal suspects or national security threats.
Those tensions grew after former National Security Agency contractor Edward Snowden leaked secrets about U.S. surveillance practices in 2013. They reached a crescendo earlier this year when the FBI tried to force Apple to unlock an iPhone tied to one of the shooters in a San Bernardino, California, attack that killed 14 people.
Chief among the goals of many companies and privacy advocates is reforming a foreign intelligence authority used to justify once-secret broad internet surveillance programs exposed by Snowden that will expire in December 2017 unless Congress reauthorizes them.
Should Feingold return to Capitol Hill, former staffers said he would probably seek a seat on the Senate Intelligence Committee, where he would have privileged access to classified information about government spying.
Feingold’s campaign has received far more contributions than Johnson’s from donors employed by tech companies including Alphabet Inc’s Google and

Monday, October 24, 2016

Comedian Leslie Jones lashes back at hackers in “Saturday Night Live” over recent celeb hacks

Comedian Leslie Jones lashes back at hackers in “Saturday Night Live” over recent celeb hacks

A day after hackers unleashed an attack on some of the world’s best-known websites, comedian Leslie Jones weighed in on cyber-security in a commentary on “Saturday Night Live,” saying cyber criminals could put their talents to far better use than hacking celebrities. Jones, whose own website was hacked in August resulting in nude photos and personal information including her passport and driver’s license being posted, offered her perspective during her recurring gig as an impassioned contributor to the weekly comedy show’s “Weekend Update” news segment.
“I am very comfortable with who I am. I am an open book,” Jones declared, noting “I keep my porn in a folder labeled porn.” “If you wanna see Leslie Jones naked, just ask,” the comedian added, in what one Twitter user, an entertainment website editor, said may have been Jones’ “finest SNL moment.” After starring in the “Ghostbusters” film this summer, Jones briefly quit Twitter because she was bombarded by racist and abusive comments.
“If I was good at computers, I wouldn’t waste it trolling on people,” Jones said. Instead, “I would do something useful, like renew my driver’s license from home. I would hack into Tinder and delete all those other girls’ profiles, so no matter where you swipe, you get me.”
Adopting a seemingly more serious tenor, Jones scolded hackers by saying “If you want to hurt anybody these days, you’re going to have to do way more than leak their news or call them names. You can’t embarrass me more than I have embarrassed myself.”
“At a certain point you got to stop being embarrassed and just start being you, and I have been me for 49 years. Because the only person who can hack me is me,” she vowed, adding: “My firewall is a crazy-ass bitch with a shovel.”
Reuters

Monday, October 17, 2016

Facebook is not making all your posts public, so everybody relax

Facebook is not making all your posts public, so everybody relax

Image Credit: Reuters
By 
A copy paste campaign on Facebook has people posting a legal notice to prevent Facebook from making all their data publicly available. This is a hoax, and Facebook has reassured users that their data is private, owned by them, and they have control over who can access it. Even if Facebook were to make your data public, posting a legal notice in your timeline is not an effective counter measure against Facebook using your data in any such way. Snopes, a fact checking site that monitors rumours has an extensive page with details on this long lived hoax.
fb-hoax
Facebook has put up a post in the FBfacts section of its site that clearly informs users thatusers are in control of the content they post on Facebook. Facebook has requested users not to believe the information in the copy and paste legal notice. Users can download and check all the information that Facebook holds about them, on their own. Users can track the information and connections being monitored by Facebook in the Activity Log, which is a list of all your posts and activity.
This round of rumours are circulating close on the heels of Facebook agreeing to sign a controversial treaty that allows Facebook to store information obtained from EU citizens on servers elsewhere. Some rumours and hoaxes keep circulating in waves and refuse to die. This particular hoax has been around for over four years.

Facebook signs controversial EU Privacy Shield treaty after Google and Microsoft

Facebook signs controversial EU Privacy Shield treaty after Google and Microsoft

Social networking giant Facebook has agreed to adopt a new European Union (EU) data accord that allows personal information to be transferred to the US, potentially sparking yet another privacy row, the media reported. Facebook has quietly signed the Privacy Shield — a controversial treaty that allows US technology companies to transfer EU citizens’ details abroad. It will apply to certain advertising data and its new Workplace service for businesses, the Telegraph UK reported on Saturday.
Privacy Shield, a replacement deal that was designed to provide extra safeguards for Europeans, came into force in July. Google and Microsoft have already adopted the treaty. Facebook signed up at the end of September, although only two aspects of the social network use it. The first is Workplace, a special version of Facebook that allows company employees to communicate, which was launched last week. The other is its “Ads and Measurement” technology that uses customer data supplied by other companies to target adverts.
Other user data is not covered by the treaty, although it can be transferred to the US under secondary legal measures, the report said. “We have signed up two important parts of our business to the EU-US Privacy Shield Framework – Facebook at Work and our relevant Ads and Measurement services,” a Facebook spokesman confirmed the report.
Facebook’s adoption of the treaty is significant because the prior US-EU agreement, Safe Harbour which was abolished by the European Court of Justice as a direct result of legal action against the social network by privacy campaigners. However, it is likely to lead to further scrutiny of the Privacy Shield deal from Facebook’s critics, the report stated.
IANS

Related Posts Plugin for WordPress, Blogger...