Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts

Saturday, December 15, 2018

Facebook says sorry for bug that exposed private photos of some 6.8 million users


MANILA, Philippines — Social media giant Facebook has apologized for a bug that has exposed private photos of its 6.8 million users.

Tomer Bar, engineering director of Facebook, said in a blog post on Friday night that the company discovered a bug that allowed third-party app developers to access photos of its 6.8 million users.


“Our internal team discovered a photo API bug that may have affected people who used Facebook Login and granted permission to third-party apps to access their photos,” Bar said.

“We’re sorry this happened. Early next week we will be rolling out tools for app developers that will allow them to determine which people using their app might be impacted by this bug,” he added.

According to Bar, the bug may have affected up to 6.8 million users and up to 1,500 apps built by 876 developers.

“We have fixed the issue but, because of this bug, some third-party apps may have had access to a broader set of photos than usual for 12 days between September 13 to September 25, 2018,” he said.

Photos that users have uploaded to their respective social media accounts but did not finish posting could have been accessed by the third party apps, Bar said.

“We will be working with those developers to delete the photos from impacted users,” he added.

Bar said Facebook would notify affected users of the bug via an alert in their accounts.

The notification will direct them to a Help Center where users could see if they have used any third-party apps affected by the bug. /muf

source: technology.inquirer.net

Thursday, June 7, 2018

Australian leader backs Zuckerberg’s grilling in Parliament


CANBERRA, Australia  — Australia’s prime minister said on Thursday he would welcome Facebook founder and chief executive Mark Zuckerberg testifying to an Australian parliamentary committee on the social media giant’s sharing of data with Chinese phone maker Huawei.

Leaders of Australia’s Parliamentary Joint Committee on Intelligence and Security have raised the prospect of the 34-year-old multi-billionaire being invited to explain Facebook’s relationships with Huawei. Prime Minister Malcolm Turnbull supported the call for Zuckerberg to fly more than 12,000 kilometers (7,500 miles) from Menlo Park in California to face lawmakers in Canberra.

“I would welcome Facebook coming and testifying before our parliamentary committees, yes,” Turnbull told reporters. “Of course, we’d love to see the boss.”


Huawei said Wednesday it has never collected or stored Facebook user data, after Facebook acknowledged it shared such data with Huawei and other manufacturers.

Huawei, a company flagged by US intelligence officials as a national security threat and barred on security grounds from involvement in Australia’s National Broadband Network, was the latest device maker at the center of a fresh wave of allegations over Facebook’s handling of private data.

Chinese firms Huawei, Lenovo, Oppo and TCL were among numerous handset makers that were given access to Facebook data in a “controlled” way approved by Facebook, according to a statement Tuesday from Francisco Varela,
Facebook’s vice president of mobile partnerships.

Facebook said it would end its data partnership with Huawei by the end of this week.

It’s the latest privacy gaffe for Facebook since allegations emerged in March that a Trump-affiliated political consultancy firm, Cambridge Analytica, had improperly harvested data of Facebook users in an effort to influence elections.

The Australian committee, like a court, can summons witnesses to give evidence, although it is questionable whether a witness outside Australia could be compelled to attend. In practice, committees always invite rather than compel witnesses to attend hearings.

Facebook was asked by The Associated Press whether Zuckerberg would accept such an invitation.

Facebook replied with a statement on Thursday: “We will be providing the Australian government with more information about the device-integrated APIs,” referring to Application Programming Interfaces that enable servers to communicate directly.

The committee’s chairman Andrew Hastie and deputy chairman Anthony Byrne say Facebook owed answers to its 15 million Australian users.

“It is completely unacceptable that information from Facebook users has been slyly handed over to Huawei by Facebook,” Byrne told The Australian newspaper. “I want to know why Mr. Zuckerberg allowed this to happen. If need be, he will be invited to appear” before the committee, Byrne added.

Byrne was not immediately available for comment on Thursday, but his office confirmed that he had been accurately quoted.

Zuckerberg has been called to give evidence to US congressional committees and the European Parliament in recent months over user privacy breaches. /ee

source: technology.inquirer.net

Wednesday, March 30, 2016

Apple remains in dark on how FBI hacked iPhone without help


WASHINGTON, United States — The FBI’s announcement that it mysteriously hacked into an iPhone is a public setback for Apple Inc., as consumers suddenly discover they can’t keep their most personal information safe. Meanwhile, Apple remains in the dark about how to restore the security of its flagship product.

The government said it was able to break into an iPhone used by a gunman in a mass shooting in California, but it didn’t say how. That puzzled Apple software engineers — and outside experts — about how the FBI broke the digital locks on the phone without Apple’s help. It also complicated Apple’s job repairing flaws that jeopardize its software.

The Justice Department’s announcement that it was dropping a legal fight to compel Apple to help it access the phone also took away any obvious legal avenues Apple might have used to learn how the FBI did it.

Magistrate Judge Sheri Pym vacated her Feb. 16 order, which compelled Apple to help the FBI hack their phone, on Tuesday.

The Justice Department declined through a spokeswoman to comment Tuesday.

A few clues have emerged. A senior law enforcement official told The Associated Press that the FBI managed to defeat an Apple security feature that threatened to delete the phone’s contents if the FBI failed to enter the correct passcode combination after 10 tries. That allowed the government to repeatedly and continuously test passcodes in what’s known as a brute-force attack until the right code is entered and the phone is unlocked.

It wasn’t clear how the FBI dealt with a related Apple security feature that introduces increasing time delays between guesses. The official spoke on condition of anonymity because this person was not authorized to discuss the technique publicly.

FBI Director James Comey has said with those features removed, the FBI could break into the phone in 26 minutes.

The FBI hacked into the iPhone used by gunman Syed Farook, who died with his wife in a gun battle with police after they killed 14 people in December in San Bernardino. The iPhone, issued to Farook by his employer, the county health department, was found in a vehicle the day after the shooting.

The FBI is reviewing information from the iPhone, and it is unclear whether anything useful can be found.

Apple said in a statement Monday that the legal case to force its cooperation “should never have been brought,” and it promised to increase the security of its products. CEO Tim Cook has said the Cupertino-based company is constantly trying to improve security for its users.

The FBI’s announcement — even without revealing precise details — that it had hacked the iPhone was at odds with the government’s firm recommendations for nearly two decades that security researchers always work cooperatively and confidentially with software manufacturers before revealing that a product might be susceptible to hackers.

The aim is to ensure that American consumers stay as safe online as possible and prevent premature disclosures that might damage a U.S. company or the economy.

As far back as 2002, the Homeland Security Department ran a working group that included leading industry technology industry executives to advise the president on how to keep confidential discoveries by independent researchers that a company’s software could be hacked until it was already fixed. Even now, the Commerce Department has been trying to fine-tune those rules. The next meeting of a conference on the subject is April 8 in Chicago and it’s unclear how the FBI’s behavior in the current case might influence the government’s fragile relationship with technology companies or researchers.

The industry’s rules are not legally binding, but the government’s top intelligence agency said in 2014 that such vulnerabilities should be reported to companies.

“When federal agencies discover a new vulnerability in commercial and open source software — a so-called ‘zero day’ vulnerability because the developers of the vulnerable software have had zero days to fix it — it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose,” the Office of the Director of National Intelligence said in a statement in April 2014.

The statement recommended generally divulging such flaws to manufacturers “unless there is a clear national security or law enforcement need.”

Last week a team from Johns Hopkins University said they had found a security bug in Apple’s iMessage service that would allow hackers under certain circumstances to decrypt some text messages. The team reported its findings to Apple in November and published an academic paper after Apple fixed it.

“That’s the way the research community handles the situation. And that’s appropriate,” said Susan Landau, professor of cybersecurity policy at Worcester Polytechnic Institute. She said it was acceptable for the government to find a way to unlock the phone but said it should reveal its method to Apple.

Mobile phones are frequently used to improve cybersecurity, for example, as a place to send a backup code to access a website or authenticate a user.

The chief technologist at the Center for Democracy and Technology, Joseph Lorenzo Hall, said keeping details secret about a flaw affecting millions of iPhone users “is exactly opposite the disclosure practices of the security research community. The FBI and Apple have a common goal here: to keep people safe and secure. This is the FBI prioritizing an investigation over the interests of hundreds of millions of people worldwide.”

source: technology.inquirer.net

Saturday, October 18, 2014

Top 8 enterprise network infrastructure, security trends for 2015


MANILA, Philippines – The networking and security industries are evolving rapidly. Listed below are considered some of the most important developments and technologies to look out for in 2015.



    Security breaches are harder to stop

Security breaches and data leakage will continue to trouble companies of all sizes. The threat timeline over the last 10-15 years has shown that a new threat tends to be quickly answered by a new defence system. The threat then evolves, and a new defence system is needed. This has led to a myriad of disparate security appliances, software agents and management systems that in many cases are unable to talk to one other. When the bad guys tweak the Threat Life Cycle, for example via the creation of Advanced Persistent Threats or APTs, it becomes very difficult to stay ahead of the curve. Next-generation security architectures will integrate discrete security systems into a platform, which can correlate threat life elements and break the infection chain in different places.

2. Cloud technologies are finally taking root

All forms of cloud are starting to make inroads as a viable part of the enterprise infrastructure. Software as a Service (SaaS) has reached a tipping point as most organizations trust a provider’s security capabilities. Infrastructure as a service (IaaS) is still focused on web applications for elasticity and redundancy. Cloud bursting, hybrid clouds and personal clouds will mean more sharing of distributed services, management and security.

3. Diversity in mobile apps and management

Unlike the PC market, the mobile device market (handsets and tablets) will not be dominated by Microsoft. There will be at least two to three platforms across the globe. This mobile diversity will mean management systems will need to be more flexible and open. Improved JavaScript performance will begin to push HTML5 and the browser as a mainstream enterprise application development environment. This will lead to richer applications and more focus on their usability, rather than larger and cumbersome applications.

4. Software defined modular infrastructure becomes the norm

The control layer is being detached and centralized for many different parts of the infrastructure. Most of the initial focus is on the data center with virtualization, Software Defined Networking (SDN), Software Defined Storage (SDS) and standalone switch fabrics. The effect is that API’s are being consumed at a much higher rate. In a world where the infrastructure is being dissected and segmented, API’s themselves are very important but is also a potential security hole to the network element.

5. Internet of Things and Industrial Control Systems (ICS) collide


The Internet of Things (IoT) is already estimated by Gartner to be made up of some 26 billion devices by 2020. Industrial control systems are rolling out IP all the way to the control and measurement points. These networks are separate today and individual in nature. However, both need to deal with cyber threats, which can cause huge damage across industrial complexes, public operational networks (i.e. power grids) or consumers.

6. Wireless continues to replace wired access

Wireless access is ubiquitous across most organizations. New enterprise buildings are less and less wired. Wireless systems are becoming the primary network access control mechanism, meaning that tight integration with authentication systems is essential. Wireless technology itself continues to improve with ac Wave 1 now rolling out rapidly and Wave 2 on the horizon in 2015.

7.  Networking bandwidth continues to double every 10 months

Networking bandwidth requirements continue to expand at a rapid pace. The transition from 1G data centers to 10G data centers took about 10 years. The transition from 10G to 100G will be much faster. All parts of the infrastructure need to perform within the high-speed infrastructure. Traditionally CPU-based firewalls have fallen way behind the performance curve. More recently ASIC-based firewall appliances have taken a quantum leap in performance, allowing 100G interfaces and throughput in the hundreds of Gbps, saving space and power. Now high-speed networks can design security into the architecture without creating bottlenecks.

    Analytics for everything that’s attached to the network

Big Data and analytics can be applied for different reasons. The biggest need is business intelligence but it’s also very important for security.  The amount of data being gathered is staggering but segmenting the data can lead to more actionable results. For example, collecting WiFi presence of consumers in retail stores can lead to understanding their buying behavior. Monitoring where and when clients connect to the network can help determine security posture. Forecasting shipments based on real time data can lead to more efficient operations. Jeff Castillo, Country Manager, Fortinet PH

(Jeffrey Castillo joined Fortinet in the Philippines in October 2009. He has extensive industry knowledge and selling experience in providing end-to-end hardware and software solutions to key verticals. Castillo also has a solid foundation in technology implementations, having been a technical engineer at the start of his career.)

source: technology.inquirer.net

Thursday, September 11, 2014

5M Gmail accounts, passwords leaked online


MANILA, Philippines–Nearly five million Gmail accounts and passwords obtained from multiple breaches on websites have been leaked in an online forum, an executive of a computer data security firm said Wednesday.

The addresses and passwords have been posted on a Russian website btsec.com by a certain “tvskit” which claimed that 60 percent of the leaked data were valid.

Peter Kruse, the chief technology officer of CSIS Security Group, said that “a great amount of the leaked data is legitimate” even as it said the leaked data was old.

Kruse added that the compromised data was not sourced from Google.

The security group  added that the compromised passwords do not correspond to Gmail accounts but are passwords used in other websites with Gmail addresses as the user name.

According to an article from technology website PC World, a Google representative said that the Internet giant has “no evidence that our systems have been compromised.”

Users can input their Gmail account and password at isleaked.com to see if their account has been compromised, according to PC World.

source: technology.inquirer.net