Showing posts with label Internet security. Show all posts
Showing posts with label Internet security. Show all posts

Saturday, May 24, 2014

Facebook Privacy Check-up

The New York Times reported the other day that Facebook is offering a "privacy check-up" to subscribers. Apparently the growth of privacy-friendly services such as SnapChat and WhatsApp has caught the attention of Mr. Zuckerberg. Facebook is acquiring WhatsApp this year, according to the Times article. But Snapchat has a strong privacy policy, where they delete "snaps" from their servers and from users' devices once viewed. Snapchat allows users to more easily control what information the service collects and to control with whom they share information on the site (read the privacy policy).

WhatsApp, a "cross-platform mobile messaging app which allows you to exchange messages without having to pay for SMS," does not fund its service through advertisements that depend on user information. (Read "Why we don't sell ads"). It appears to be free for the first year (at least on the versions I checked), and then 99 cents a year thereafter. WhatsApp's privacy policy is contained in their "legal" or Terms of Service. It appears at the bottom of the page. They make the information clear, easy to understand, and easy to control. They also take some pretty good steps to secure the information users do send them against hacking. The policy includes a warning "in the event of merger, sale or bankruptcy" that the policy may change.

However, the Times article makes it sound as though Zuckerberg is seeing some financial benefit in making it easier for users to control the ways his company/companies collect and use their personal information. Both because European laws regulate this much more closely than the U.S. and because consumer pressure is building for more consumer control in this area, the article makes it sound as though Facebook and Zuckerberg are becoming privacy converts. Time will tell if they stay converted!

The image decorating this blog post is the WhatsApp logo from their home page.

Thursday, April 10, 2014

Internet Security Alert: Heartbleed

OOTJ readers may already have read about Heartbleed, the newest Internet security problem. But just in case you have not heard about this, here is your heads up. The Boston Globe today offered an article by Hiawatha Bray, their wonderful tech columnist, who concludes that "The Heartbleed scare is as bad as it sounds."

Heartbleed is a security glitch at the heart of the security of the Internet, that came about through sloppy coding, in an update of the OSSL software that provides the encryption for about two thirds of Internet sites worldwide. Encryption means the software that scrambles your data as it leaves your computer so it travels safely over the Internet. Only the target network should be able to decrypt the data you sent. So, if you are buying something from an Internet vendor, you send your name, address, credit card number over the web, feeling secure with that https:// in front of the URL. That is what the additional "s" is telling you - that the information is being decrypted between your computer and theirs, for secure transactions.

But a little bit of bad code (OSSL is Open Source, collaboratively coded), in 2012 (!) introduced a serious security lapse in how OSSL has been working. The "secure" data stored at the OSSL-secured servers can be searched and retrieved by hackers. Somebody at Google and at a Finnish security company discovered the problem and announced it this past Monday. A security researcher, for instance, was able to retrieve a name and password from Yahoo mail. Hiawatha Bray did a little checking:
Yahoo says it has fixed the problem on its servers. Meanwhile, other major Internet companies are also offering reassurances. I pinged Amazon.com, Facebook, tax preparation company Intuit Inc., and the Internal Revenue Service. All replied that their computers are not vulnerable to the Heartbleed problem.
He then points out that nobody has reported that their bank accounts have been emptied over the past two years while Heartbleed was laying out there waiting to be exploited. On the other hand, Bray also notes that spy agencies like the NSA or China's Ministry of State Security could have been using Heartbleed as a backdoor for some time and nobody would know. Unlike other hacking access points, Heartbleed leaves no marks!

So, the recommendations of security experts? For at least a few days until the Heartbleed code problem is repaired and replaced at all relevant websites,

1. Do not do any shopping or enter personal information on websites.
2. Wait a few days for Heartbleed to be repaired, then change all your passwords, at least for websites that collect personal information, and
3. Remove all the cookies from your computer, at least the ones for websites that collect personal information.

Image of the bleeding heart flowers is from the Wikimedia Commons, a photo by Pharaoh Hound, who posted it under the the Creative Commons Attribution-ShareAlike 3.0 License. The photo is of the flowers of a pink Bleeding Heart (Dicentra spectabilis)- I couldn't bear to put up the more anatomical bleeding hearts I found out there! Thank you, Pharaoh Hound!

Monday, February 10, 2014

Just say NO to continued government surveillance!

Call/email Congress. Ask legislators to oppose the FISA Improvements Act. Look here at the ACLU comments, here at the EFF comments on "fake fix bill", another EFF note on 54 civil liberties and public interest organizations opposing this bill and here for an analysis in the British paper The Guardian (Permanent loophole for "backdoor search provision," and the Cato Institute, which called it the NSA Fig Leaf.

Ask your congresspeople to support the USA Freedom Act, and enact protections for non-Americans. Read the ACLU comments supporting this alternative bill. The EFF also supports this bill, which was co-sponsored by Representative Sensenbrenner (R, Wis) and Senator Leahy (D, Ver).

There are limits to what the USA Freedom Act accomplishes, according to the EFF website:

The bill only addresses a small portion of the problems created by NSA spying and overreaching government secrecy. It does not touch problems like NSA programs to sabotage encryption standards, it does not effectively tackle the issue of collecting information on people outside of the United States, and it doesn't address the authority that the government is supposedly using to tap the data links between service provider data centers, such as those owned by Google and Yahoo.

The bill also does not address a key issue that the government uses to inhibit lawsuits contesting the spying: excessive secrecy. For instance, it won't deal with the major over-classification issues or the state secrets privilege, the latter of which is used aggressively to prevent litigation from getting to a court decision on whether the spying is unconstitutional. The bill also leaves out a clause appearing in Sen. Ron Wyden's bill [113 S. 1551 Intelligence Oversight and Surveillance Reform Act] and, which provides guidelines to obtain standing in legal cases against the spying.

Lastly, it does not hold public officials accountable for their role in allowing this spying to take place and hiding it from public and Congressional oversight, and it does not create a Congressional committee that could independently investigate the surveillance programs and give the country a full accounting. Remember we are still just learning the full depth of the programs on a piecemeal basis.

So while we are happy to support the USA FREEDOM Act, we also acknowledge that there is still much to do to dial back the NSA. This can happen through ongoing improvements to the USA FREEDOM Act as well as through additional bills.
The EFF does list 7 steps the USA Freedom Act uses to improve privacy rights:
1. It would likely stop the NSA's call records program;
2. The bill modifies Section 702 of the FISA Amendments Act (EFF thinks one effect of the amendment is good - it requires the NSA to get a more narrowly tailored order from the FISA court before searching its enormous databases of call data for information on U.S. citizens. However, EFF is concerned that the amendment codifies the practices and existence of the collection and databases rather than abolishing them.
3. The bill creates a special advocate before the FISA court.
4. "Significant decisions" by the FISA court must be disclosed by the Attorney General. This is hugely important, though the FISA court itself has increased the publication of some of its decisions in recent days, there is neither any confidence that it might continue nor anything to show the public that we have had publication of either the most significant decisions or any proportion of significant decisions.
5. It increases protections designed to limit the potential harm from the use of National Security Letters (NSLs, the secret orders from the FBI that include a gag order preventing recipients from ever announcing they got one). Nevertheless, the law fails to address the central problem with NSLs: NSLs would still be unconstitutional.
6. Increases (a tiny bit) the ability of the companies that are ordered to cooperate with government agencies to be more transparent to users about their cooperation. There would still be gag orders limiting the amount of information that could be shared, but reports could be somewhat more detailed.
7. It grants subpoena powers for the Privacy and Civil Liberties Oversight Board (PCLOB). PCLOB is supposed to provide oversight and recommendations to the executive branch when it comes to our civil liberties, but currently has no subpoena powers.


Fight for the Future coordinates an Internet Fight against NSA Surveillance


Who here has gotten the e-mail from Fight for the Future? FFtF is a not for profit that
is dedicated to protecting and expanding the Internet's transformative power in our lives by creating civic campaigns that are engaging for millions of people. Alongside internet users everywhere we beat back attempts to limit our basic rights and freedoms, and empower people to demand technology (and policy) that serves their interests.
Well, they don't have any problem with self esteem, anyway. Their issues, from their About Us page, listed as posing "major threats to freedom of expression online":

Copyright and patent laws are outdated and overzealous. They hurt artists and innovation, shifting control of our art, media, and ideas to large corporations.
Slow speed and limited access: Lack of competition in the U.S. broadband market has resulted in an Internet system that is among the slowest, most expensive and least available among developed nations.
Tracking and Spying: People can’t express themselves freely online when they feel like they are being watched. In an extreme form, government and corporate surveillance can lead to political repression.
On Feb. 11, they are urging websites to add a banner to their sites
urging people to call/email Congress. We'll ask legislators to oppose the FISA Improvements Act, support the USA Freedom Act, and enact protections for non-Americans.

If you're not in the US: Visitors will be asked to urge appropriate targets to institute privacy protections.
Visit their website to see.

I have mixed feelings about the breadth of their issues. But I do know what I think about the NSA and FISA courts.

Thursday, October 22, 2009

Password Security


Newsweek has published an insightful discussion of passwords, which it calls "the weak link in computer security." The author, Nick Summers, reveals that he created a password a number of years ago and kept using it "as the requirements for passwords evolved ... [he] added extra nines, cobbled on a question mark, and blended it with [his] alternate password." The result of all this tweaking was a password that would access Mr. Summers's laptop, email, bank accounts, blog, work PC, health insurance, Facebook, Skype, Snapfish, Hulu, tax returns, "and at least 39 other sites across the Internet." After making this confession, Mr. Summer is quick to note that he is changing his password.

The point of Mr. Summer's confession is to highlight how vulnerable passwords are and to showcase the CyLab, Carnegie Mellon University's cybersecurity-research department. CyLab doesn't just study the "mathematical theory behind passwords but the way humans actually use them." The CyLab researchers are exploring a number of different approaches to computer security, including biometrics, cryptography, "strong" passwords, security questions, one-time passwords generated by special devices, and image-based passwords. The author feels that for the short term, passwords, flawed though they are, are the most feasiable option for computer security. Unless there is a major security breach, corporations and other institutions are unlikely to invest in innovations that would likely be very expensive.