Privacy, indirizzi IP utenti accessibili agli inquirenti in caso di reati online

I reati online e l’identificazione degli autori, il caso francese

I reati online si moltiplicano e le Istituzioni corrono ai ripari. Si pone quindi il problema di come raccogliere, elaborare, gestire e conservare i dati relativi ai singoli utenti che hanno violato la legge. Sull’argomento c’è una nuova sentenza della Corte di Giustizia dell’Unione europea, nella causa “C-470/21 – La Quadrature du Net e a. (Dati personali e lotta contro la contraffazione)”, in cui si precisano i requisiti relativi alle modalità di conservazione di tali dati e di accesso agli stessi.

Si tratta di una sentenza in risposta ad un ricorso di diverse associazioni per la tutela dei diritti e delle libertà su internet, diretto all’annullamento di un decreto del Governo francese che ha introdotto due diversi trattamenti dei dati personali.

Il primo consiste nella raccolta, da parte di organismi che rappresentano gli autori, di indirizzi IP che appaiono essere stati utilizzati su siti tra pari (peer-to-peer) per la commissione di tali reati, nonché nella loro messa a disposizione dell’Alta autorità francese per la diffusione delle opere e la tutela dei diritti su Internet (la legge Hadopi). Il secondo comprende, in particolare, la messa in relazione, da parte dei fornitori di accesso a internet, che agiscono su richiesta della Hadopi, dell’indirizzo IP e dei dati relativi all’identità civile del suo titolare.

In entrambi i casi, l’Autorità può avviare procedimenti anche repressivi nei confronti dei soggetti identificati dalle forze dell’ordine.

La sentenza della Corte di Giustizia UE

Su questo, la Corte si è pronunciata in questo modo: “Gli Stati membri possono imporre ai fornitori di accesso a Internet un obbligo di conservazione generalizzata e indifferenziata degli indirizzi IP per lottare contro i reati in generale, purché tale conservazione non consenta di trarre conclusioni precise sulla vita privata dell’interessato”.

A determinate condizioni, è specificato nella sentenza, “gli Stati membri possono inoltre, autorizzare l’autorità nazionale competente ad accedere ai dati relativi all’identità civile riferentisi a indirizzi IP, purché sia assicurata una conservazione tale che garantisca una separazione stagna delle diverse categorie di dati”.

Onde evitare una raccolta scriteriata di informazioni sensibili sulla vita privata dell’interessato, “l’accesso deve essere assoggettato a un previo controllo da parte di un giudice o di un ente amministrativo indipendente”.

Tale trattamento dei dati consente all’Autorità di “avviare, nei confronti delle persone identificate, un procedimento che combina misure pedagogiche e repressive, che può dar luogo a un deferimento alla procura nei casi più gravi”.

La separazione stagna delle diverse categorie di dati personali

La Corte, pronunciandosi in seduta plenaria, ha inoltre sottolineato che “la conservazione generalizzata e indifferenziata di indirizzi IP non costituisce necessariamente una grave ingerenza nei diritti fondamentali”, basta che la normativa nazionale imponga modalità di conservazione “che garantiscano una separazione effettivamente stagna delle diverse categorie di dati personali, escludendo così che possano essere tratte conclusioni precise sulla vita privata dell’interessato”.

Inoltre, la sentenza della Corte specifica che “il diritto dell’Unione non osta a una normativa nazionale che autorizza l’autorità pubblica competente, al solo scopo di identificare la persona sospettata di aver commesso un reato, ad accedere ai dati relativi all’identità civile corrispondenti a un indirizzo IP, conservati separatamente e in maniera effettivamente stagna dai fornitori di accesso a Internet”.

Fondamentale è “garantire che tale accesso non consenta di trarre conclusioni precise sulla vita privata dei titolari degli indirizzi IP di cui trattasi” e che si eviti di effettuare un tracciamento del percorso di navigazione a partire dagli indirizzi IP.

Una sentenza che potrebbe risultare di grande aiuto nella lotta alla criminalità online, soprattutto in casi di contraffazione e quindi di violazione della proprietà intellettuale, nonché nella più generale violazione del diritto d’autore, che affligge l’industria audiovisiva e dei contenuti online.
Ciò che deve essere salvaguardata è la vita privata dell’individuo e i dati relativi a questa sfera individuale sono tutelati dalla legge (che ne definisce anche le eventuali deroghe). Le informazioni in possesso degli inquirenti dovranno quindi servire ‘esclusivamente’ all’individuazione del soggetto che ha commesso reato. Qui risiede l’indicazione chiave di mantenere sempre una “separazione effettivamente stagna delle diverse categorie di dati personali, escludendo così che possano essere tratte conclusioni precise sulla vita privata dell’interessato”.

https://www.key4biz.it/privacy-indirizzi-ip-utenti-accessibili-agli-inquirenti-in-caso-di-reati-online/488652/




Message-scraping, user-tracking service Spy Pet shut down by Discord

Image of various message topics locked away in a wireframe box, with a Discord logo and lock icon nearby.

Spy Pet, a service that sold access to a rich database of allegedly more than 3 billion Discord messages and details on more than 600 million users, has seemingly been shut down.

404 Media, which broke the story of Spy Pet’s offerings, reports that Spy Pet seems mostly shut down. Spy Pet’s website was unavailable as of this writing. A Discord spokesperson told Ars that the company’s safety team had been “diligently investigating” Spy Pet and that it had banned accounts affiliated with it.

“Scraping our services and self-botting are violations of our Terms of Service and Community Guidelines,” the spokesperson wrote. “In addition to banning the affiliated accounts, we are considering appropriate legal action.” The spokesperson noted that Discord server administrators can adjust server permissions to prevent future such monitoring on otherwise public servers.

Kiwi Farms ties, GDPR violations

The number of servers monitored by Spy Pet had been fluctuating in recent days. The site’s administrator told 404 Media’s Joseph Cox that they were rewriting part of the service while admitting that Discord had banned a number of bots. The administrator had also told 404 Media that he did not “intend for my tool to be used for harassment,” despite a likely related user offering Spy Pet data on Kiwi Farms, a notorious hub for doxxing and online harassment campaigns that frequently targets trans and non-binary people, members of the LGBTQ community, and women.

Even if Spy Pet can somehow work past Discord’s bans or survive legal action, the site’s very nature runs against a number of other Internet regulations across the globe. It’s almost certainly in violation of the European Union’s General Data Protection Regulation (GDPR). As pointed out by StackDiary, Spy Pet and services like it seem to violate at least three articles of the GDPR, including the “right to be forgotten” in Article 17.

In Article 8 of the GDPR and likely in the eyes of the FTC, gathering data from what could be children’s accounts and profiting from them is almost certainly to draw scrutiny, if not legal action.

Ars was unsuccessful in reaching the administrator of Spy Pet by email and Telegram message. Their last message on Telegram stated that their domain had been suspended and a backup domain was being set up. “TL;DR: Never trust the Germans,” they wrote.

https://arstechnica.com/?p=2020247




L’IA generativa complica la gestione sicura delle applicazioni SaaS


La corsa all’IA generativa ha spinto i produttori di applicazioni SaaS (Software-as-a-Service) ad aggiornare i propri strumenti integrando nuove funzionalità intelligenti per aumentare la produttività.

La GenAI si sta confermando come un assistente indispensabile per facilitare lo sviluppo di software, velocizzare la scrittura di documenti ed email e supportare la creazione di contenuti di valore.

The Hacker News sottolinea che i grandi nomi del panorama tecnologico, tra cui Microsoft, Google, GitHub e Salesforce, hanno già integrato funzionalità di IA generativa nella propria offerta di applicazioni in cloud, e a breve queste feature diventeranno lo standard dei servizi SaaS.

A fronte degli indubbi vantaggi che porta, l’IA generativa nelle applicazioni cloud comporta anche una serie di nuovi rischi di sicurezza che non andrebbero sottovalutati. La diffusione dei nuovi tool ha complicato il panorama delle minacce informatiche, preoccupando le organizzazioni.

La risposta delle aziende ai rischi dell’IA generativa

I modelli usati per alimentare i chatbot di IA generativa utilizzano i dati inseriti dagli utenti per migliorare il proprio addestramento e la qualità delle risposte, rendendoli potenzialmente accessibili agli sviluppatori che lavorano ai modelli; ciò amplia notevolmente la superficie di attacco delle organizzazioni. Anche se gli strumenti avvertono gli utenti di non condividere dati sensibili o informazioni relative alla propria azienda nella maggior parte dei casi questo avvertimento viene ignorato.

Tra i rischi principali ci sono la perdita di IP, dati riservati dei clienti e PII, oltre al fatto che i cybercriminali possono sfruttare le informazioni condivise dagli utenti per eseguire attacchi di phishing e furti di identità.

Le organizzazioni sono preoccupate dai rischi dell’IA generativa, tanto che alcune di esse, soprattutto quelle in industrie e settori che trattano dati riservati, hanno già vietato l’uso di questi tool. The Hacker News riporta che il settore bancario è stato il primo a vietare l’IA generativa, nonostante i manager del settore si dicano fiduciosi sui vantaggi dell’uso dell’IA per migliorare l’efficienza operativa.

Anche il Governo degli Stati Uniti sta seguendo una linea molto severa nei confronti della GenAI: dopo aver bloccato ChatGPT su tutti i PC in dotazione al governo, il mese scorso il Congresso ha vietato l’utilizzo di Copilot di Microsoft.

I divieti imposti dalle organizzazioni rivelano un’incapacità di base nel monitorare l’uso delle applicazioni SaaS basate su IA generativa a causa di un’importante carenza di competenze, sia nella forza lavoro che tra i leader.

I blocchi non impediscono però ai dipendenti di usare comunque i tool di GenAI, spesso appoggiandosi ai dispositivi personali: uno studio di Salesforce ha rivelato che più della metà degli utenti di IA generativa usa strumenti non approvati dal proprio datore di lavoro. I mancati controlli su questi comportamenti e l’assenza di policy chiare per l’uso dell’IA sta mettendo a serio rischio i business.

Pixabay

È ora di riprendere il controllo delle proprie applicazioni

La rapida evoluzione della tecnologia e la diffusione del lavoro ibrido e remoto ha complicato il lavoro degli esperti di cybersecurity. Sempre più organizzazioni si affidano a soluzioni SaaS che spesso soffrono di configurazioni errate e di meccanismi di controllo dell’identità e degli accessi inadeguati.

I cybercriminali stanno sfruttando queste debolezze per distribuire malware ed eseguire attacchi di vario tipo, e l’uso non autorizzato e incontrollato di strumenti di intelligenza artificiale generativa complica un quadro già difficile.

Impedire la diffusione della GenAI è impossibile e contro produttivo; le aziende dovrebbero quindi rivalutare la propria postura di sicurezza e dotarsi di strumenti capaci di gestire la nuova generazione di minacce.

Per ottenere il controllo e la visibilità sulle applicazioni SaaS di IA generativa è necessario mettere in campo soluzioni di sicurezza avanzate basate sul principio di zero-trust che consentono di abilitare l’uso dell’IA riducendone i rischi. Solo con una visione completa delle applicazioni in uso è possibile prevenire, rilevare e rispondere alle minacce, proteggendo al contempo i dati e i processi centrali per il business.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2024/04/18/ia-generativa-complica-gestione-sicura-applicazioni-saas/?utm_source=rss&utm_medium=rss&utm_campaign=ia-generativa-complica-gestione-sicura-applicazioni-saas




Billions of public Discord messages may be sold through a scraping service

Discord logo, warped by vertical perspective over a phone displaying the app
Getty Images

It’s easy to get the impression that Discord chat messages are ephemeral, especially across different public servers, where lines fly upward at a near-unreadable pace. But someone claims to be catching and compiling that data and is offering packages that can track more than 600 million users across more than 14,000 servers.

Joseph Cox at 404 Media confirmed that Spy Pet, a service that sells access to a database of purportedly 3 billion Discord messages, offers data “credits” to customers who pay in bitcoin, ethereum, or other cryptocurrency. Searching individual users will reveal the servers that Spy Pet can track them across, a raw and exportable table of their messages, and connected accounts, such as GitHub. Ominously, Spy Pet lists more than 86,000 other servers in which it has “no bots,” but “we know it exists.”

As Cox notes, Discord doesn’t make messages inside server channels, like blog posts or unlocked social media feeds, easy to publicly access and search. But many Discord users many not expect their messages, server memberships, bans, or other data to be grabbed by a bot, compiled, and sold to anybody wishing to pin them all on a particular user. 404 Media confirmed the service’s function with multiple user examples. Private messages are not mentioned by Spy Pet and are presumably still secure.

Spy Pet openly asks those training AI models, or “federal agents looking for a new source of intel,” to contact them for deals. As noted by 404 Media and confirmed by Ars, clicking on the “Request Removal” link plays a clip of J. Jonah Jameson from Spider-Man (the Tobey Maguire/Sam Raimi version) laughing at the idea of advance payment before an abrupt “You’re serious?” Users of Spy Pet, however, are assured of “secure and confidential” searches, with random usernames.

This author found nearly every public Discord he had ever dropped into for research or reporting in Spy Pet’s server list. Those who haven’t paid for message access can only see fairly benign public-facing elements, like stickers, emojis, and charted member totals over time. But as an indication of the reach of Spy Pet’s scraping, it’s an effective warning, or enticement, depending on your goals.

Ars has reached out to Spy Pet for comment and will update this post if we receive a response. A Discord spokesperson told Ars that the company is investigating whether Spy Pet violated its terms of service and community guidelines. It will take “appropriate steps to enforce our policies,” the company said, and could not provide further comment.

https://arstechnica.com/?p=2017957




Facebook let Netflix see user DMs, quit streaming to keep Netflix happy: Lawsuit

A promotional image for Sorry for Your Loss, with Elizabeth Olsen
Enlarge / A promotional image for Sorry for Your Loss, which was a Facebook Watch original scripted series.

Last April, Meta revealed that it would no longer support original shows, like Jada Pinkett Smith’s Red Table Talk talk show, on Facebook Watch. Meta’s streaming business that was once viewed as competition for the likes of YouTube and Netflix is effectively dead now; Facebook doesn’t produce original series, and Facebook Watch is no longer available as a video-streaming app.

The streaming business’ demise has seemed related to cost cuts at Meta that have also included layoffs. However, recently unsealed court documents in an antitrust suit against Meta [PDF] claim that Meta has squashed its streaming dreams in order to appease one of its biggest ad customers: Netflix.

Facebook allegedly gave Netflix creepy privileges

As spotted via Gizmodo, a letter was filed on April 14 in relation to a class-action antitrust suit that was filed by Meta customers, accusing Meta of anti-competitive practices that harm social media competition and consumers. The letter, made public Saturday, asks a court to have Reed Hastings, Netflix’s founder and former CEO, respond to a subpoena for documents that plaintiffs claim are relevant to the case. The original complaint filed in December 2020 [PDF] doesn’t mention Netflix beyond stating that Facebook “secretly signed Whitelist and Data sharing agreements” with Netflix, along with “dozens” of other third-party app developers. The case is still ongoing.

The letter alleges that Netflix’s relationship with Facebook was remarkably strong due to the former’s ad spend with the latter and that Hastings directed “negotiations to end competition in streaming video” from Facebook.

One of the first questions that may come to mind is why a company like Facebook would allow Netflix to influence such a major business decision. The litigation claims the companies formed a lucrative business relationship that included Facebook allegedly giving Netflix access to Facebook users’ private messages:

By 2013, Netflix had begun entering into a series of “Facebook Extended API” agreements, including a so-called “Inbox API” agreement that allowed Netflix programmatic access to Facebook’s users’ private message inboxes, in exchange for which Netflix would “provide to FB a written report every two weeks that shows daily counts of recommendation sends and recipient clicks by interface, initiation surface, and/or implementation variant (e.g., Facebook vs. non-Facebook recommendation recipients). … In August 2013, Facebook provided Netflix with access to its so-called “Titan API,” a private API that allowed a whitelisted partner to access, among other things, Facebook users’ “messaging app and non-app friends.”

Meta said it rolled out end-to-end encryption “for all personal chats and calls on Messenger and Facebook” in December. And in 2018, Facebook told Vox that it doesn’t use private messages for ad targeting. But a few months later, The New York Times, citing “hundreds of pages of Facebook documents,” reported that Facebook “gave Netflix and Spotify the ability to read Facebook users’ private messages.”

Meta didn’t respond to Ars Technica’s request for comment. The company told Gizmodo that it has standard agreements with Netflix currently but didn’t answer the publication’s specific questions.

https://arstechnica.com/?p=2013174




GM stops sharing driver data with brokers amid backlash

Scissors cut off a stream of data from a toy car to a cloud
Aurich Lawson | Getty Images

After public outcry, General Motors has decided to stop sharing driving data from its connected cars with data brokers. Last week, news broke that customers enrolled in GM’s OnStar Smart Driver app have had their data shared with LexisNexis and Verisk.

Those data brokers in turn shared the information with insurance companies, resulting in some drivers finding it much harder or more expensive to obtain insurance. To make matters much worse, customers allege they never signed up for OnStar Smart Driver in the first place, claiming the choice was made for them by salespeople during the car-buying process.

Now, in what feels like an all-too-rare win for privacy in the 21st century, that data-sharing deal is no more.

“As of March 20th, OnStar Smart Driver customer data is no longer being shared with LexisNexis or Verisk. Customer trust is a priority for us, and we are actively evaluating our privacy processes and policies,” GM told us in a statement.

https://arstechnica.com/?p=2012276




Airbnb bans creepy surveillance cameras inside rentals starting April 30

camera hidden in flower pot indoors

Airbnb, like hotels and rival vacation rental site Vrbo, will no longer allow hosts to record guests while they’re inside the property. Airbnb previously allowed hosts to have disclosed cameras outside the property and in “common areas” inside, but Airbnb’s enforcement of the policy and the rules’ lack of specificity made camera use troubling for renters.

Airbnb announced today that as of April 30, it’s “banning the use of indoor security cameras in listings globally as part of efforts to simplify our policy on security cameras and other devices” and to prioritize privacy.

Cameras that are turned off but inside the property will also be banned, as are indoor recording devices. Airbnb’s updated policy defines cameras and recording devices as “any device that records or transmits video, images, or audio, such as a baby monitor, doorbell camera, or other camera.”

Also starting April 30, Airbnb will require hosts to disclose the presence of noise decibel monitors. Airbnb said it will only allow noise-monitoring devices that “do not record or transmit sounds or conversations” and that these are also “only allowed in common spaces of listings.”

Room for interpretation

Airbnb’s old policy allowed hosts to have cameras inside the property as long as the cameras weren’t hidden. The policy stated that Airbnb allowed: “Devices that allow for viewing or monitoring of only a public space (ex: a front door or a driveway) or a common space that are clearly identified and disclosed ahead of a reservation,” per an archived version of the policy. The policy added that “common spaces do not include sleeping areas or bathrooms” and listed “bedrooms, bathrooms, or common areas that are being used as sleeping areas, like a living room with a sofa bed)” as examples of private spaces.

This policy dramatically differed from the rules of other hospitality businesses. Hotels typically don’t surveil guests after they’re in their room, for example.

Also alarming was the vagueness of Airbnb’s policy. What about rooms with a futon or a couch that isn’t literally listed as a “sofa bed” but is roomy enough for slumber? Could a policy-abiding camera be placed in that room? Airbnb’s updated policy for noise decibel monitors, which allows them inside but only “in a common space,” still doesn’t address the potential for broad interpretations of the phrase.

Renters can see if a listing has cameras or noise-monitoring devices under the “Home safety” section of a listing’s amenities section, but that could include dozens of so-called amenities.

Airbnb’s old policy didn’t force hosts to state cameras’ locations. A rental I currently have booked under the old policy, for example, merely states that it has “security cameras to ensure the safety of guests and property.” That doesn’t clearly specify where the cameras are and if they’re indoors or only outdoors.

Another example of gaps in Airbnb’s policy for unspecified surveillance comes from Jeffrey Bigham. In 2019, he detailed his experience when Airbnb originally told him that a photo in an Airbnb listing with a camera subtly sitting in the walls’ corner counted as disclosure of indoor camera usage (after the blog went viral, the user reported receiving a refund). Bigham noted that even though the camera was technically in a common area (the living room), it was “very likely that my 2-year-old ran in front of this camera naked (the field of view of the camera was close to the exit of the bathroom).”

Airbnb’s announcement today said those who break the new policies will be subject to investigation and disciplinary action, which may include the removal of a listing or account.

However, Airbnb has a spotted history of responding to renter surveillance complaints. For example, in 2019, Ars Technica reported on a family finding a hidden camera inside their Airbnb that was disguised as a smoke or carbon monoxide detector. Airbnb initially “exonerated” the host of wrongdoing but eventually refunded the family and banned the host. Other Airbnb hosts have also previously claimed to see lax response from Airbnb after upsetting renters with surveillance cameras.

Airbnb hosts have long relied on technology to help spot problems like unwarranted guests, messes, parties, and robberies. But even outdoor surveillance can perturb renters, as the use of outdoor cameras can be overbearing and uncomfortable.

Airbnb previously claimed that hidden cameras are an exception. The company said today that the majority of its listings “do not report having a security camera” but didn’t share specific numbers.

https://arstechnica.com/?p=2009366




Meta accusata di pratiche illegali che violano il GDPR (di nuovo)


Qualche mese fa su Facebook e Instagram è comparso un avviso che chiedeva ai suoi utenti di scegliere se pagare per non avere più pubblicità sui social o continuare a usare il servizio in modo gratuito, acconsentendo alla raccolta e all’analisi dei propri dati. Questa scelta non è piaciuta a otto associazioni dei consumatori dell’UE che hanno presentato denunce contro Meta, accusandola di violare il GDPR.

Dietro la mossa della compagnia c’era l’intenzione di rispettare le leggi UE offrendo una scelta ai consumatori; scelta che, però, è stata giudicata “finta” dalle organizzazioni a protezione dei consumatori e non in linea col regolamento europeo.

Come riporta The Register, l’organizzazione no-profit austriaca NOYB (Non Of Your Business) ha sottolineato che le leggi europee sulla privacy impongono che la scelta sulla condivisione dei dati deve essere libera, e non, come in questo caso, un’alternativa quasi obbligata a una tassa.

Pexels

Le associazioni dei consumatori affermano che il nuovo modello proposto da Meta per l’uso dei social viola i principi di data protection espressi nel GDPR, come il principio della limitazione delle finalità, dell’offuscamento dei dati, dell’elaborazione etica e trasparente delle informazioni. La scelta di inserire un abbonamento per usare i social senza annunci non offre una vera scelta agli utenti, ed è visto come un modo per costringere i consumatori a condividere i propri dati e continuare a proporre pubblicità.

Contattata da The Register, Meta ha affermato che è pronta a contrastare le accuse, sottolineando che “i nostri obblighi normativi sono estremamente seri e siamo fiduciosi che il nostro approccio sia conforme al GDPR”. La compagnia ha aggiunto che il nuovo modello introdotto per l’uso dei suoi social sia in linea con il regolamento dell’UE.

Le battaglie legali per Meta sembrano non finire mai: l’anno scorso la compagnia ha dovuto pagare una multa da più di un miliardo di euro per aver inviato i dati dei cittadini europei negli Stati Uniti, violando la legislazione UE.

Le organizzazioni dei consumatori hanno presentato le loro denunce lo scorso giovedì, e ora Meta è in attesa di sapere se dovrà imbarcarsi ancora una volta in una dura battaglia legale.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2024/03/04/meta-accusata-di-pratiche-illegali-che-violano-il-gdpr-di-nuovo/?utm_source=rss&utm_medium=rss&utm_campaign=meta-accusata-di-pratiche-illegali-che-violano-il-gdpr-di-nuovo




How your sensitive data can be sold after a data broker goes bankrupt

Blue tone city scape and network connection concept , Map pin business district

In 2021, a company specializing in collecting and selling location data called Near bragged that it was “The World’s Largest Dataset of People’s Behavior in the Real-World,” with data representing “1.6B people across 44 countries.” Last year the company went public with a valuation of $1 billion (via a SPAC). Seven months later it filed for bankruptcy and has agreed to sell the company.

But for the “1.6B people” that Near said its data represents, the important question is: What happens to Near’s mountain of location data? Any company could gain access to it through purchasing the company’s assets.

The prospect of this data, including Near’s collection of location data from sensitive locations such as abortion clinics, being sold off in bankruptcy has raised alarms in Congress. Last week, Sen. Ron Wyden (D-Ore.) wrote the Federal Trade Commission (FTC) urging the agency to “protect consumers and investors from the outrageous conduct” of Near, citing his office’s investigation into the India-based company.

Wyden’s letter also urged the FTC “to intervene in Near’s bankruptcy proceedings to ensure that all location and device data held by Near about Americans is promptly destroyed and is not sold off, including to another data broker.” The FTC took such an action in 2010 to block the use of 11 years worth of subscriber personal data during the bankruptcy proceedings of the XY Magazine, which was oriented to young gay men. The agency requested that the data be destroyed to prevent its misuse.

Wyden’s investigation was spurred by a May 2023 Wall Street Journal report that Near had licensed location data to the anti-abortion group Veritas Society so it could target ads to visitors of Planned Parenthood clinics and attempt to dissuade women from seeking abortions. Wyden’s investigation revealed that the group’s geofencing campaign focused on 600 Planned Parenthood clinics in 48 states. The Journal also revealed that Near had been selling its location data to the Department of Defense and intelligence agencies.

As of publication, Near has not responded to requests for comment.

According to Near’s privacy policy, all of the data they have collected can be transferred to the new owners. Under the heading of “Who do you share my personal data with?” It lists “Prospective buyers of our business.”

This type of clause is common in privacy policies, and is a regular part of businesses being bought and sold. Where it gets complicated is when the company being sold owns data containing sensitive information.

This week, a new bankruptcy court filing showed that Wyden’s requests were granted. The order placed restrictions on the use, sale, licensing, or transfer of location data collected from sensitive locations in the US and requires any company that purchases the data to establish a “sensitive location data program” with detailed policies for such data and ensure ongoing monitoring and compliance, including the creation of a list of sensitive locations such as reproductive health care facilities, doctor’s offices, houses of worship, mental health care providers, corrections facilities and shelters among others. The order demands that unless consumers have explicitly provided consent, the company must cease any collection, use, or transfer of location data.

In a statement emailed to The Markup, Wyden wrote, “I commend the FTC for stepping in—at my request—to ensure that this data broker’s stockpile of Americans’ sensitive location data isn’t abused, again.”

Wyden called for protecting sensitive location data from data brokers, citing the new legal threats to women since the Supreme Court’s June 2022 decision to overturn the abortion-rights ruling Roe v. Wade. Wyden wrote, “The threat posed by the sale of location data is clear, particularly to women who are seeking reproductive care.”

The bankruptcy order also provided a rare glimpse into how data brokers license data to one another. Near’s list of contracts included agreements with several location brokers, ad platforms, universities, retailers, and city governments.

It is not clear from the filing if the agreements covered Near data being licensed, Near licensing the data from the companies, or both.

This article was originally published on The Markup and was republished under the Creative Commons Attribution-NonCommercial-NoDerivatives license.

https://arstechnica.com/?p=2005720




Avast ordered to stop selling browsing data from its browsing privacy apps

Avast logo on a phone in front of the words
Getty Images

Avast, a name known for its security research and antivirus apps, has long offered Chrome extensions, mobile apps, and other tools aimed at increasing privacy.

Avast’s apps would “block annoying tracking cookies that collect data on your browsing activities,” and prevent web services from “tracking your online activity.” Deep in its privacy policy, Avast said information that it collected would be “anonymous and aggregate.” In its fiercest rhetoric, Avast’s desktop software claimed it would stop “hackers making money off your searches.”

All of that language was offered up while Avast was collecting users’ browser information from 2014 to 2020, then selling it to more than 100 other companies through a since-shuttered entity known as Jumpshot, according to the Federal Trade Commission. Under a proposed recent FTC order (PDF), Avast must pay $16.5 million, which is “expected to be used to provide redress to consumers,” according to the FTC. Avast will also be prohibited from selling future browsing data, must obtain express consent on future data gathering, notify customers about prior data sales, and implement a “comprehensive privacy program” to address prior conduct.

Reached for comment, Avast provided a statement that noted the company’s closure of Jumpshot in early 2020. “We are committed to our mission of protecting and empowering people’s digital lives. While we disagree with the FTC’s allegations and characterization of the facts, we are pleased to resolve this matter and look forward to continuing to serve our millions of customers around the world,” the statement reads.

Data was far from anonymous

The FTC’s complaint (PDF) notes that after Avast acquired then-antivirus competitor Jumpshot in early 2014, it rebranded the company as an analytics seller. Jumpshot advertised that it offered “unique insights” into the habits of “[m]ore than 100 million online consumers worldwide.” That included the ability to “[s]ee where your audience is going before and after they visit your site or your competitors’ sites, and even track those who visit a specific URL.”

While Avast and Jumpshot claimed that the data had identifying information removed, the FTC argues this was “not sufficient.” Jumpshot offerings included a unique device identifier for each browser, included in data like an “All Clicks Feed,” “Search Plus Click Feed,” “Transaction Feed,” and more. The FTC’s complaint detailed how various companies would purchase these feeds, often with the express purpose of pairing them with a company’s own data, down to an individual user basis. Some Jumpshot contracts attempted to prohibit re-identifying Avast users, but “those prohibitions were limited,” the complaint notes.

The connection between Avast and Jumpshot became broadly known in January 2020, after reporting by Vice and PC Magazine revealed that clients, including Home Depot, Google, Microsoft, Pepsi, and McKinsey, were buying data from Jumpshot, as seen in confidential contracts. Data obtained by the publications showed that buyers could purchase data including Google Maps look-ups, individual LinkedIn and YouTube pages, porn sites, and more. “It’s very granular, and it’s great data for these companies, because it’s down to the device level with a timestamp,” one source told Vice.

The FTC’s complaint provides more detail on how Avast, on its own web forums, sought to downplay its Jumpshot presence. Avast suggested both that only non-aggregated data was provided to Jumpshot and that users were informed during product installation about collecting data to “better understand new and interesting trends.” Neither of these claims proved true, the FTC suggests. And the data collected was far from harmless, given its re-identifiable nature:

For example, a sample of just 100 entries out of trillions retained by Respondents
showed visits by consumers to the following pages: an academic paper on a study of symptoms
of breast cancer; Sen. Elizabeth Warren’s presidential candidacy announcement; a CLE course
on tax exemptions; government jobs in Fort Meade, Maryland with a salary greater than
$100,000; a link (then broken) to the mid-point of a FAFSA (financial aid) application;
directions on Google Maps from one location to another; a Spanish-language children’s
YouTube video; a link to a French dating website, including a unique member ID; and cosplay
erotica.

In a blog post accompanying its announcement, FTC Senior Attorney Lesley Fair writes that, in addition to the dual nature of Avast’s privacy products and Jumpshot’s extensive tracking, the FTC is increasingly viewing browsing data as “highly sensitive information that demands the utmost care.” “Data about the websites a person visits isn’t just another corporate asset open to unfettered commercial exploitation,” Fair writes.

FTC commissioners voted 3-0 to issue the complaint and accept the proposed consent agreement. Chair Lina Khan, along with commissioners Rebecca Slaughter and Alvaro Bedoya, issued a statement on their vote.

Since the time of the FTC’s complaint and its Jumpshot business, Avast has been acquired by Gen Digital, a firm that contains Norton, Avast, LifeLock, Avira, AVG, CCLeaner, and ReputationDefender, among other security businesses.

Disclosure: Condé Nast, Ars Technica’s parent company, received data from Jumpshot before its closure.

https://arstechnica.com/?p=2005605