Malwarebytes Privacy World

Taken from https://blog.malwarebytes.com/category/security-world/privacy-security-world/feed/

25th July 2017

FBI: Smart toys could harm children’s privacy and physical safety

The Federal Bureau of Investigation has recently issued a Public Service Announcement (PSA), encouraging consumers—parents, in particular—to think twice before purchasing internet-connected toys. Smart toys and entertainment devices for kids are part of the Internet of Things, and as such, they have built-in Wi-Fi capabilities. This enables them to communicate with the cloud and with each other. Other than that, these are also equipped with sensors, cameras, microphones, and other bits that allow them to not just respond to their child owners but also store data and tag a child’s location for parents/guardians to keep track of them in real time. CloudPets, Hello Barbie, My Friend Cayla, i-Que Robot, and hereO are just some of the smart toys and devices that security researchers have scrutinized for their lack of security and privacy measures. The FBI has highlighted in the PSA what type of information these toys may be able to gather. As most of these are normally “always on”, they c..
25th July 2017

Going dark: encryption and law enforcement

We’re hearing it a lot lately: encryption is an insurmountable roadblock between law enforcement and keeping us safe. They can’t gather intelligence on terrorists because they use encryption. They can’t convict criminals because they won’t hand over encryption keys. They can’t stop bad things from happening because bad guys won’t unlock their phones. Therefore—strictly to keep us safe—the tech industry must provide them with means to weaken, circumvent, or otherwise subvert encryption, all for the public good. No “backdoors”, mind you; they simply want a way for encryption to work for good people, but not bad. This is dangerous nonsense, for a lot of reasons. 1. It’s technically incorrect Encryption sustains its value by providing an end to end protection of data, as well as what we call “data at rest.” Governments have asked for both means of observing data in transit, as well as retrieving data at rest on devices of interest. They also insist that they have no interest in weakening..
6th June 2017

HTTPS… Everywhere!

We recently updated our redirections rule in HTTPS-Everywhere, a browser extension that automatically redirects you to the HTTPS version of the website you are trying to visit. Now is a good time for us to give a short overview of how important HTTPS is. We’ll also talk about a few major HTTPS-related events that happened lately. When we browse the web, several third-parties are able to snoop on the connection between the user and the website, including the user’s ISP, law enforcement, the website’s ISP, and other people in between. Who can snoop on your connection without HTTPS, and what can they see? (by The TorProject) These intermediaries are able to obtain and modify on the fly most of the information sent through the connection: the website reached, the web page name and content, the potential username and password, the user’s IP address, and more. It obviously poses a lot of problems, which is why HTTPS is now mandatory for more and more websites (public sector, banks, etc.)...
4th April 2017

Your ISP, browsing history, and what to do about it

In late March, Congress approved a bill lifting restrictions imposed on ISPs last year concerning what they could do with information such as customer browsing habits, app usage history, location data, and Social Security numbers. They additionally absolved ISPs of the need to strengthen their existing customer data holdings against hackers and thieves. For more on the particulars of the bill, you can see reports on the Washington Post and Ars Technica. Given that the repealed restrictions hadn’t yet come into effect, the immediate impact of the new bill is somewhat unclear. But given what typically happens with massive stores of aggregated, location-specific customer data, the prognosis is not good. So what’s the worst that can happen? Let’s run through a few probable outcomes: Ad retargeting We all might be familiar with this; when we buy a product online and then see ads for it relentlessly for a couple weeks thereafter. But with increased granularity of metadata, ad retargeting ..
29th September 2016

Snapchat rebrands, introduces new ad platform and hardware

When Google Glass was first released in 2013, the Internet giant also pushed out a guideline for Glass Explorers, telling them “don’t be creepy”. It appears that it was this advice that Snapchat CEO Evan Spiegel took to heart and acted upon, openly disassociating his company from Google and Facebook during last year’s pitch of Snapchat’s new 3V advertising platform at Cannes Lions, one of the world’s biggest marketing and advertising events. In a short video explaining what this ad platform is about, Spiegel reinforced their standpoint that it’s important for them to respect their community and their privacy. Recently, however, Snapchat has made moves that may make one wonder if the CEO suddenly had a change of heart about being “creepy”. According to the Wall Street Journal, Snapchat has begun allowing advertisers to target their consumers by offering three distinct products to choose from: Snap Audience Match allows marketers to make use of Snapchat’s own pool of users’ data and ..