Privacy

FTC is considering “do not track” mechanism for web users

Published: December 6, 2010 Reading time: 2 min

The U.S. Federal Trade Commission (FTC) has accepted a preliminary staff report that lays out a framework for Internet privacy and suggests a “do not track” mechanism – possibly a persistent cookie installed on browsers. The agency was careful to point out that the commissioners see privacy measures as a balancing act. The news release quotes FTC chairman Jon Leibowitz: “Technological and business ingenuity have spawned a whole new online culture and vocabulary – email, IMs, apps and blogs – that consumers have come to expect and enjoy. The FTC wants to help ensure that the growing, changing, thriving information marketplace is built on a framework that promotes privacy, transparency, business innovation and consumer choice. We believe that’s what most Americans want as well.” ...

Continue Reading

Proxy services take novel approach to privacy

Published: December 6, 2010 Reading time: 1 min

You’ve locked down your computer. Nothing is going to bypass your privacy shielding programs. AdBlock is fully loaded, NoScript is ready to roll and RefControl is sending “Party on, Wayne” as your custom referrer to all and sundry. However, you really want to hide your IP address too and decide to load up one of the many web-based proxy services available. Something humorous I’ve noticed across many web-based proxies recently is that they’re jumping on a marketing strategy that might be slightly at odds with their attempts at privacy for the end-user. In order to keep your private details private, you have to _fill in a survey and hand over a bunch of information to third party marketers. _ Type in a URL, hit the “Go” button on the proxy and you’ll see one of these: ...

Continue Reading

Facebook adds “new profiles”

Published: December 6, 2010 Reading time: 1 min

Avira TechBlog: Facebook offers a “new profile” feature that many users adopt very fast. It is possible to mark the best friends and family and show them more prominently with their pictures. Also, it accumulates information like the uers’ work places, where they are living and so on. Even projects and co-workers can be shown now. This may be a useful addition for many users. But it should be used with care; in the end, this feature gives Facebook a deeper insight and more valuable data. Before marking family members, friends and colleagues more prominently in the own profile, users should ask for permission. ...

Continue Reading

Stuxnet and WikiLeaks – What do they have in common?

Published: December 4, 2010 Reading time: 2 min

At first glance, two recent security stories, the Stuxnet attack on Iran’s nuclear industry and the WikiLeaks breach of US State Department communications, don’t seem to have much in common, but they do. They are united by a vector, a method of transmission and that vector is removable media. I am sure that the Iranians felt pretty secure with air-gapped systems, but like a spark from the burning house next door that finds its way into your shingles, the right USB found its way into the right PC and then suddenly all those uranium enrichment centrifuges running at 807-1210 hz started to act funny and fail in unexpected and reportedly fairly energetic ways (you can see some pics of failed centrifuges here http://web.mit.edu/charliew/www/centrifuge.html and here http://www.chem.purdue.edu/chemsafety/NewsAndStories/CentrifugeDamages.htm). ...

Continue Reading

Hotmail Always-On Encryption Breaks Microsoft’s Own Apps

Published: November 10, 2010 Reading time: 3 min

Oh look, Microsoft is late to the party again? They are finally launching full-session SSL encryption to Hotmail a mere 2 years after Google did the same thing for Gmail. It looks like the release of FireSheep really has had an impact on web-application vendors due to the amount of mainstream media coverage it got and the sheer number of downloads. At least they are doing something and I hope more vendors follow and give users an option to force full-session HTTPS connections for all web properties. ...

Continue Reading

Firesheep author takes backhanded pot-shot at free speech

Published: November 7, 2010 Reading time: 3 min

Sophos Labs: Two weeks ago, an automatic session-hijacking plugin was released for Firefox. It was named Firesheep, and it’s been downloaded over 600,000 times so far. The decision to release Firesheep publicly is a controversial one. On the good side, it’s reminded people that some of their common web surfing habits are dangerously insecure. Many websites use HTTPS (secure HTTP) for login, which protects your password. But they revert to insecure HTTP for the rest of the session. After you have logged in, security relies on the browser sending a session cookie – a secret authentication token – in every request. ...

Continue Reading

Google bars data from Facebook as rivalry heats up

Published: November 7, 2010 Reading time: 4 min

Reuters: Google Inc will begin blocking Facebook and other Web services from accessing its users’ information, highlighting an intensifying rivalry between the two Internet giants. Google will no longer let other services automatically import its users’ email contact data for their own purposes, unless the information flows both ways. It accused Facebook in particular of siphoning up Google contact data, without allowing for the automatic import and export of Facebook users’ information. ...

Continue Reading

Important Information about Google Buzz Class Action Settlement

Published: November 2, 2010 Reading time: 2 min

Let’s take a look in the Email I got from Google right now: Google rarely contacts Gmail users via email, but we are making an exception to let you know that we’ve reached a settlement in a lawsuit regarding Google Buzz (http://buzz.google.com), a service we launched within Gmail in February of this year. Shortly after its launch, we heard from a number of people who were concerned about privacy. In addition, we were sued by a group of Buzz users and recently reached a settlement in this case. ...

Continue Reading

Firesheep: who is eating my cookies?

Published: October 26, 2010 Reading time: 3 min

Internet is great, and everyday millions of people spend their day surfing it, using Google, Gmail, Youtube, Twitter, Facebook, etc. Some people buy at ebay, or Amazon. Even some people use it to work, though these cases maybe not that common😉 As a reader of this blog, you are concerned about security and therefore you already know that connecting through public WiFi is a risky sport. But it is also really convenient, how many of you have done it in McDonalds,Starbucks, etc.? Yeah, me too😮 ...

Continue Reading

MySpace moves against apps who share user data

Published: October 24, 2010 Reading time: 2 min

New York (CNN) — Social networking site MySpace, while acknowledging it shares profile information with advertisers, said Saturday that it is taking action against app developers who may have violated the website’s terms of use by sharing user data. A spokesman for MySpace who refused to be named told CNN that it shares information with advertisers, but that it does not identify a user. Although MySpace users are not required to provide an actual name when registering, their user IDs link the public information displayed on their profile, which can sometimes reveal names, addresses and other critical information. ...

Continue Reading