Malwarebytes Privacy World

Taken from https://blog.malwarebytes.com/category/security-world/privacy-security-world/feed/

27th April 2018

Please don’t buy this: smart toys

Smart toys attempt to offer what a lot of us imagined as kids—a toy that we can not only play with, but one that plays back. Many models offer voice recognition, facial expressions, hundreds of words and phrases, reaction to touch and impact, and even the ability to learn and retain new information. These features provide an obvious thrill for many children, whose imaginary friend just became a lot more real. At the low end, smart toys can be as simple as a motion-activated rattle designed with features intended to help with developmental milestones. Higher-end toys can be as engaging as a real-life R2-D2 that will watch Star Wars with you and offer commentary. But much like other Internet of Things products, smart toys don’t have a great track record of protecting personal information, designing software according to industry best practices, and updating in a timely manner. And we’re in fairly new territory when it comes to young children and the Internet. Suddenly, we have to worry..
5th April 2018

Maybe you shouldn’t use LinkedIn

UPDATE: 4/6/2018 LinkedIn reached out for comment on the article, and we’d like to clarify our position based on their concerns. They wrote: Members control their connections, who can see them (including keeping them private if they wish) and only first degree connections can get access to your contact info on LinkedIn. This is correct. LinkedIn visibility controls are clear and easily accessible to the non-technical user. What we were concerned about, however, is the categorization of the connections themselves. Any direct relationship the user instigates is a first degree connection. First degree connections have a predefined level of access that is symmetric, and for the most part, not user editable. LinkedIn has added a lockdown option that allows you to restrict your viewable connections and email address to not be viewable by anyone. What it lacks are granular permissions on specific data elements assignable to each level of connection. LinkedIn also informed us that they do..
15th March 2018

GrayKey iPhone unlocker poses serious security concerns

Ever since the case of the San Bernadino shooter pitted Apple against the FBI over the unlocking of an iPhone, opinions have been split on providing backdoor access to the iPhone for law enforcement. Some felt that Apple was aiding and abetting a felony by refusing to create a special version of iOS with a backdoor for accessing the phone’s data. Others believed that it’s impossible to give backdoor access to law enforcement without threatening the security of law-abiding citizens. In an interesting twist, the battle ended with the FBI dropping the case after finding a third party who could help. At the time, it was theorized that the third party was Cellebrite. Since then it has become known that Cellebrite— an Israeli company—does provide iPhone unlocking services to law enforcement agencies. Cellebrite, through means currently unknown, provides these services at $5,000 per device, and for the most part this involves sending the phones to a Cellebrite facility. (Recently, Cellebrit..
6th February 2018

Safer Internet Day 2018: ad blockers and anti-trackers

The path to a safer Internet can be a bit of a quandary. What programs should you buy? How long should your passwords be? Is it okay to write them down? What makes a website secure? All of these questions can merit their own lengthy essays, so today, on Safer Internet Day, we’re going to look at some of the simplest solutions for security. What is the easiest, fastest, completely free thing you can do to have a safer Internet experience? The answer: ad blockers and anti-tracking browser extensions. Let’s take a look at how. Ad blockers Some people feel that ad blockers are unethical, as they deprive others in the content chain of income. While this can be debated, it’s indisputable that cybercriminals love using ads as a malware delivery mechanism. Traditionally, bad ads have delivered exploit kits, forced redirects, fake plugin updates, and more. Recently, malicious ads have been caught running cryptominers, monopolizing your CPU to make the owners a few pennies. Given that you ca..
26th October 2017

Please don’t buy this: smart locks

We all like buying the latest and greatest tech toy. It’s fun to get new and novel features on a product that used to be boring and predictable; a draw of the original BeBox (amongst many) was a layer of “das blinkenlights” across the front. But sometimes, the latest feature is not always the greatest feature. And sometimes, some things should not be on the Internet at all. For readers concerned with privacy, or who simply do not want to introduce additional hassle into their tech maintenance routine, we introduce the first entry in our series called “Please don’t buy this.” Today’s feature: smart locks. The cool new thing Recently, Amazon announced a new service combining a selection of smart locks, a web-connected security camera, and a network of home service providers that work in concert to allow remote access to your home. Ignoring the question of allowing third-party contractors vetted by an unpublished standard unsupervised access, lets take a look at why smart locks might not..