Tor Network Removes Risky Relays Associated With Cryptocurrency Scheme

The Tor Project announced on Monday that it has removed many relays due to the high risk they posed to the network’s integrity and users.

A blog post published by the anonymity network’s maintainers reveals that directory authorities have voted in favor of removing the relays associated with a for-profit scheme that involves the payment of cryptocurrency tokens.  

“We consider these relays to be harmful to the Tor network for a number of reasons, including that certain of the relays do not meet our requirements, and that such financial schemes present a significant threat to the network’s integrity and the reputation of our project as they can attract individuals with malicious intent, put users at risk, or disrupt the volunteer-driven spirit that sustains the Tor Community,” the Tor Project explained

It added, “As part of our assessment and due diligence into the matter, we engaged with relay operators and were often presented with scenarios in which relay operators associated with this scheme were putting themselves at risk by lacking the awareness of what project they were actually contributing to or operating relays in unsafe or high-risk regions. It has become clear to us that this scheme is not beneficial to the Tor network or the Tor Project.”

While the cryptocurrency project in question has not been named, it seems to be ATOR, which claims its goal is to enhance the Tor network through rewards paid in the ATOR cryptocurrency to relay operators.  

The value of ATOR plummeted on Monday after the Tor Project made its announcement, dropping to below $1 after reaching an all-time high of $2 just days before the relays were removed. Over 1,000 nodes have been reportedly shut down.

Following the Tor Project’s decision, ATOR maintainers said they plan to develop their own decentralized peer-to-peer routing network. 

The Tor Project last week published a financial report for the period between July 1, 2021, and June 30, 2022, revealing that it had a total of nearly $7 million in revenue and support.

Advertisement. Scroll to continue reading.

The US government continues to account for the largest chunk of revenue, contributing with more than 50% of the total ($3.2 million), followed by individual donations ($1.7 million), and governments other than the US ($450,000).  

Related: Amazon Rolls Out Independent Cloud for Europe to Address Stricter Privacy Standards

Related: US Officials Make Case for Renewing FISA Surveillance Powers

Related: Apple, Civil Liberty Groups Condemn UK Online Safety Bill

https://www.securityweek.com/tor-network-removes-risky-relays-associated-with-cryptocurrency-scheme/




Key GOP Lawmaker Calls for Renewal of Surveillance Tool as He Proposes Changes to Protect Privacy

The Republican chairman of the House Intelligence Committee called Thursday for the renewal of a key US government surveillance tool as he proposed a series of changes aimed at safeguarding privacy.

The proposals by Rep. Mike Turner are part of a late scramble inside Congress and the White House to guarantee the reauthorization of Section 702 of the Foreign Intelligence Surveillance Act, which allows spy agencies to collect emails and other communications. They emerged from a congressional working group and are expected to form the basis of a legislative package that Turner hopes can be passed before Section 702 expires at the end of the year.

“We believe that before the end of the year, we will have a significant package of reforms that will be unprecedented, and at the same time, we will have the renewal of 702,” Turner told reporters.

The section of law at issue permits U.S. officials to collect without a warrant the communications of targeted foreigners who are outside the country and suspected of posing a national security threat. The government also captures the communications of American citizens and others in the U.S. when they’re in contact with those targeted foreigners.

The program has come under scrutiny in the last year following revelations that FBI analysts improperly searched the database of intelligence, including for information about people tied to the Jan. 6, 2021, riot at the U.S. Capitol and the racial justice protests of 2020.

The changes described by Turner are meant to heighten the penalties for such abuses, including by allowing Congress to trigger a mandatory inspector general review into alleged violations, and to tighten restrictions on queries, especially ones that are politically sensitive. He also called for allowing only a limited group of FBI supervisors and attorneys to authorize queries of people inside the U.S.

Much of the debate so far has centered on whether U.S. officials should be required to obtain a warrant before accessing intelligence on people inside the U.S.

A bill introduced last week by Democratic Sen. Ron Wyden and other lawmakers included a warrant requirement. The White House, however, has said such a proposal would cross a “red line,” and FBI Director Christopher Wray told lawmakers at a hearing Wednesday that a mandate for a court order would be legally unnecessary and would snarl vital investigations at a time of rising terrorism threats.

Advertisement. Scroll to continue reading.

“At a time when the FBI director is claiming that we have the largest threat to national security … it would be incredibly dangerous and detrimental for us to either allow 702 to expire or to saddle it in a way that it’s unusable,” Turner said.

Turner said his proposal would require a warrant only when the database query seeks evidence of a specific crime — but not for searches related to national security.

Additional legislative proposals are expected. Asked Thursday about the status of negotiations with Rep. Jim Jordan, the Republican chairman of the House Judiciary Committee, Turner said Jordan had indicated that he planned to submit a different proposal.

Related: US Officials Make Case for Renewing FISA Surveillance Powers

Related: UK Introduces Mass Surveillance With Online Safety Bill

https://www.securityweek.com/key-gop-lawmaker-calls-for-renewal-of-surveillance-tool-as-he-proposes-changes-to-protect-privacy/




Steam might let you hide those embarrassing games in your profile soon

Gamer with headphones playing a PC game in a dark room
Enlarge / I’m just so good at this game, it would be disheartening for you to see my progress in your feed. Yep, that’s it.
Getty Images

Steam has long sought to strike the right balance between convenience, community, and private refuge. Until recently, sharing your gaming history was either public, exclusive to your friends, or turned off entirely. A screenshot from a noted Steam watcher suggests that a “Mark as Private” option could be coming for individual games that you’re not keen on anyone, including friends, knowing you’ve put some time into.

Posting on X (formerly Twitter), Pavel Djundik, creator of the Steam insight tool SteamDB, shows options on the three-dot menu to the right of a game, with the last being “Mark as Private.” A tooltip on the option reads, “Mark this game as private and hide it from my friends.” Djundik’s example is Counter-Strike 2, which, perhaps in some circles, is a game worth hiding.

Tweet (Xeet?) from the SteamDB founder, pointing to a not-yet-public feature in Steam for hiding certain games from public or friends' profiles.
Tweet (Xeet?) from the SteamDB founder, pointing to a not-yet-public feature in Steam for hiding certain games from public or friends’ profiles.

Some folks may be concerned to show the massive hour counts they’ve put into certain games. Others might be concerned about certain obsessive or ignoble achievements in games standing out in their timeline. More likely, of course, are the kinds of adult and fetish games with which Steam has a highly confusing relationship. The replies to Djundik’s tweet suggest that people get this, though they also have some suggestions about other refinements, like finer-grained friend management tools.

At the moment, the “Privacy Settings” for Steam profiles let you choose between three levels that affect all the games you play: Public, Friends Only, and Private. You can set your profile, game details, friends list, “inventory” (those strange playing cards), comments, and screenshots to each of these settings. But soon, it seems, you can share most of your gaming life with friends, or the whole web, while certain games are just for you. It would be beneficial if you could set the privacy in place straight from the purchase page, as adding a game to your inventory is another thing Steam often broadcasts.

“Private” settings on Steam have previously had some problems, as Ars reported in 2013. Over time, Valve shifted to a “private by default” stance, incidentally eliminating sales and playtime data tools like Steam Spy. It’s unclear whether a private setting for games will affect statistics-keeping tools like SteamDB or sales of adult-minded games, generally.

https://arstechnica.com/?p=1982241




Motori di ricerca, ecco i migliori in termini di risultati e di protezione della privacy

Motori di ricerca, IA e privacy

La scelta del motore di ricerca non è solo legata alla velocità e la pertinenza dei risultati, ma anche alla privacy. Dal 1990 ad oggi, anno in cui è andato online il primo search engine Archie, sono stati lanciati più di 20 motori di ricerca.

Google è certamente il più noto ed utilizzato al mondo, ma non certo l’unico. Negli ultimi tempi si parla tanto di intelligenza artificiale (IA) e di assistenti virtuali, ma sono anni che si impiegano queste tecnologie per affinare le attività di ricerca online.

Il fattore privacy ha reso ancora più particolare la scelta di questi motori e ogni browser offre numerose opzioni extra per integrare diverse soluzioni.

Fondamentale, prima di impostare un motore di ricerca come predefinito, è fare molta attenzione al modo in cui le ricerche vengono effettuate, alla sicurezza informatica e al trattamento dei dati personali.

Google

Google è sicuramente il più usato dagli utenti di internet, con una quota dell’83% delle ricerche effettuate in tutto il mnondo, ma anche il più potente, visto che alimenta siti come YouTube ed integra diverse funzionalità, tra cui Google Workspace.

Quest’anno la Big Tech di Mountain View ha introdotto Bard, un assistente di ricerca basato su IA.

I motori di ricerca utilizzano da anni algoritmi di intelligenza artificiale per identificare modelli, personalizzare risultati di ricerca e annunci per singoli utenti, ma le cose stanno cambiando molto rapidamente.

L’IA generativa ci ha catapultati in una nuova era e non passerà molto tempo prima che anche Google possa disporre di assistenti virtuali sia per attività di ricerca, sia per la generazione di contenuti.

Il problema, al momento, è che questo motore di ricerca raccoglie anche un gran volume di dati utente e sfrutta le nostre informazioni per la personalizzazione dei risultati, creando qualche problema in termini di privacy.

Bing

Il principale competitor di Google è certamente Bing. Il motore di ricerca di Microsoft è il secondo più utilizzato al mondo, con ottimi risultati in termini di integrazione di soluzioni IA.

Il bot di ricerca Bing Chat è direttamente alimentato da ChatGPT, una delle IA generative più note al mondo. Questa soluzione avanzata aiuta a perfezionare le ricerche, selezionare e valutare le fonti e a convalidare i risultati, anche se non sempre in maniera soddisfacente.

Le ricerche di immagini, video e mappe su Bing sono considerate tra le migliori al mondo. I suoi detrattori hanno notato che le pagine con i risultati possono sembrare molto simili a quelle di Google, in alcuni casi addirittura non è semplice distinguerle.

Il motore di Microsoft, inoltre, offre anche un programma a premi. Ogni volta che si effettuano ricerche e magari si fanno anche degli acquisti l’utente guadagna dei punti, che poi possono essere riscattati sotto forma di buoni regalo o donazioni. Per ogni ricerca si guadagno 5 punti in media.

Anche in questo caso, però, il motore di ricerca raccoglie molti dati personali per rendere i risultati cercati il più possibile “su misura” utente, con diversi problemi in termini di privacy.

DuckDuckGo

Meno popolare e performante dei due precedenti, DuckDuckGo è al momento uno dei migliori motori di ricerca in termini di tutela dei dati personali.

Non li memorizza, non traccia la nostra navigazione, ne raccoglie coockie, con il risultato che si vedono comunque gli annunci ma non personalizzati in relazione alle nostre attività online.

DuckDuckGo sfrutta crawler di proprietà e incorpora anche altri motori di ricerca, ma non Google, cercando di diversificare così l’offerta dei risultati e offrire un’esperienza utente alternativa.

Come specificato, il punto forte di questa tecnologia è l’attenzione alla privacy, ma anche la semplificazione delle operazioni di ricerca, con una pagina di risultati più elementare e allo stesso tempo più facile da navigare (se cerchi il miglior router o il Pc che costa meno, non ti servono centinaia di migliaia di risultati).

Starpage

Sullo stesso livello del precedente, c’è Startpage. Un motore di ricerca che valorizza la privacy e anche la sicurezza. Evita di tracciare gli utenti e di registrare cronologie di navigazione, impedendo anche ad occhi indiscreti di spiare le nostre attività o di raccogliere dati a nostra insaputa.

La nota dolente è che questa attenzione all’utente rende le ricerche online più lente delle soluzioni alternative.

Tra le funzionalità di base la visualizzazione anonima delle pagine, senza condivisione dei dati personali, grazie alla rimozione del proprio indirizzo IP prima di inviare la query, e il servizio di posta elettronica StartMail.

Yahoo

È sicuramente uno dei vecchi motori di ricerca presenti in rete. Yahoo esiste infatti dal 1994 e oggi integra Bing per la creazione delle pagine dei risultati (il che ha come conseguenza una certa similarità nell’output finale dei due motori).

Tante le funzionalità base offerte, da quelle più comuni (meteo, news, sport e tendenze), al popolare servizio di posta elettronica Yahoo Mail, fino alla pagina dedicata ai mercati finanziari.

Molto apprezzato il servizio open source Yahoo Maps.

The post Motori di ricerca, ecco i migliori in termini di risultati e di protezione della privacy appeared first on Key4biz.

https://www.key4biz.it/motori-di-ricerca-ecco-i-migliori-in-termini-di-risultati-e-di-protezione-della-privacy/465934/




Canada Bans WeChat and Kaspersky on Government Phones

Canada on Monday banned popular Chinese messaging app WeChat and Russian platform Kaspersky from government smartphones and other mobile devices, citing privacy and security risks.

The suite of applications would be immediately removed from government-issued devices and users will be blocked from downloading them in the future, said a statement.

Treasury Board President Anita Anand, who overseas Canada’s federal public service, said the nation’s chief information officer determined the apps “present an unacceptable level of risk to privacy and security.”

No breaches have been detected but the platforms’ data collection methods on mobile devices, she added, “provide considerable access to the device’s contents.”

“The decision to remove and block the WeChat and the Kaspersky applications was made to ensure that government of Canada networks and data remain secure and protected and are in line with the approach of our international partners,” Anand concluded.

The move comes after Ottawa in February also banned TikTok — a platform owned by ByteDance in China — on government devices.

Oracle last year was tapped to store all TikTok data from US users after President Joe Biden revoked his predecessor Donald Trump’s executive orders seeking to ban TikTok and WeChat from US markets on national security concerns.

Advertisement. Scroll to continue reading.

Relations between Ottawa and Beijing — already strained over tit-for-tat detentions of a Huawei senior executive and two Canadian nationals in December 2018 — hit a new low earlier this year.

Ottawa accused Beijing of meddling in Canadian elections and the attempted intimidation of MPs that led to the expulsion of a Chinese diplomat in May. Last week, the Canadian government warned of a “Spamouflage” disinformation campaign linked to China that used waves of online posts and deepfake videos manipulated to try to disparage and discredit Canadian lawmakers, including Prime Minister Justin Trudeau.

A public inquiry into foreign interference accusations — which China has rejected — kicked off in September.

https://www.securityweek.com/canada-bans-wechat-and-kaspersky-on-government-phones/




Apple Improves iMessage Security With Contact Key Verification

Apple on Friday introduced contact key verification, a new capability meant to improve the security of its iMessage service.

To ensure the privacy of conversations, iMessage offers end-to-end encryption, so that only the sender and receiver can read a message, and relies on sets of encryption keys, where public keys are stored on a key directory service, while private keys rest on the device and never leave it.

Key directory services, like Apple’s identity directory service, represent a single point of failure, where a powerful adversary may be able to compromise the service to intercept or monitor encrypted messages.

To address the shortcoming, iMessage contact key verification, Apple explains, relies on key transparency, a mechanism that uses a verifiable log-backed map data structure to deliver cryptographic proofs of inclusion, ensuring user privacy and allowing audits.

“iMessage contact key verification advances the state of the art of key transparency deployments by having user devices themselves verify consistency proofs and ensure consistency of the KT system across all user devices for an account,” Apple says.

This mechanism, the tech giant notes, is meant to protect against both key directory and transparency service compromises, allowing changes to the log-backed map while making device keys immediately verifiable.

iMessage contact key verification, Apple explains, uses an account-level elliptic curve digital signature algorithm (ECDSA) signing key that is generated on the device, stored in iCloud keychain, and available to the user on their trusted devices only.

Advertisement. Scroll to continue reading.

“Each device uses the synchronized account key to sign its iMessage public keys. The account keys and signatures are included in the IDS service database along with the existing data,” Apple notes.

When the user enables iMessage contact key verification, their devices verify that the key transparency map includes the data presented by the identity directory service, and notifies the user if a validation error occurs.

Users’ devices will periodically query the service for account information, verify the response against the key transparency mechanism, and flag inconsistencies.

“[The user’s] devices will additionally compare the KT data for identifiers, device records, and opt-in state against records stored in an end-to-end encrypted CloudKit container. This database is maintained by [the user’s] devices and is not readable or modifiable by Apple,” the tech giant explains.

Additionally, iMessage contact key verification allows users to perform manual contact verification code comparisons using the Vaudenay SAS protocol. Upon successful verification, the hash of the peer’s account key is saved to an end-to-end encrypted CloudKit container and linked to the peer’s card.

“Because the contact card is linked, all conversations with the peer’s identifiers — phone number and email address — are marked as verified. Group chats with peers that have been independently verified one-to-one are also automatically marked as verified,” Apple explains.

iMessage contact key verification is now available in the developer previews of iOS 17.2, macOS 14.2, and watchOS 10.2.

Related: Stealth Techniques Used in ‘Operation Triangulation’ iOS Attack Dissected

Related: Apple Patches Actively Exploited iOS, macOS Zero-Days

Related: NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab

https://www.securityweek.com/apple-improves-imessage-security-with-contact-key-verification/




The UK’s problematic Online Safety Act is now law

The UK’s problematic Online Safety Act is now law
panorios/Getty Images

Jeremy Wright was the first of five UK ministers charged with pushing through the British government’s landmark legislation on regulating the Internet, the Online Safety Bill. The current UK government likes to brand its initiatives as “world-beating,” but for a brief period in 2019 that might have been right. Back then, three prime ministers ago, the bill—or at least the white paper that would form its basis—outlined an approach that recognized that social media platforms were already de facto arbiters of what was acceptable speech on large parts of the Internet, but that this was a responsibility they didn’t necessarily want and weren’t always capable of discharging. Tech companies were pilloried for things that they missed, but also, by free speech advocates, for those they took down. “There was a sort of emerging realization that self-regulation wasn’t going to be viable for very much longer,” Wright says. “And therefore, governments needed to be involved.”

The bill set out to define a way to handle “legal but harmful” content—material that wasn’t explicitly against the law but which, individually or in aggregate, posed a risk, such as health care disinformation, posts encouraging suicide or eating disorders, or political disinformation with the potential to undermine democracy or create panic. The bill had its critics—notably, those who worried it gave Big Tech too much power. But it was widely praised as a thoughtful attempt to deal with a problem that was growing and evolving faster than politics and society were able to adapt. Of his 17 years in parliament, Wright says, “I’m not sure I’ve seen anything by way of potential legislation that’s had as broadly based a political consensus behind it.”

Having passed, eventually, through the UK’s two houses of Parliament, the bill received royal assent this week. It is no longer world-beating—the European Union’s competing Digital Services Act came into force in August. And the Online Safety Act enters into law as a broader, more controversial piece of legislation than the one that Wright championed. The act’s more than 200 clauses cover a wide spectrum of illegal content that platforms will be required to address and give platforms a “duty of care” over what their users—particularly children—see online. Some of the more nuanced principles around the harms caused by legal but harmful content have been watered down, and added in is a highly divisive requirement for messaging platforms to scan users’ messages for illegal material, such as child sexual abuse material, which tech companies and privacy campaigners say is an unwarranted attack on encryption.

Companies, from Big Tech down to smaller platforms and messaging apps, will need to comply with a long list of new requirements, starting with age verification for their users. (Wikipedia, the eighth-most-visited website in the UK, has said it won’t be able to comply with the rule because it violates the Wikimedia Foundation’s principles on collecting data about its users.) Platforms will have to prevent younger users from seeing age-inappropriate content, such as pornography, cyberbullying, and harassment; release risk assessments on potential dangers to children on their services; and give parents easy pathways to report concerns. Sending threats of violence, including rape, online will now be illegal, as will assisting or encouraging self-harm online or transmitting deepfake pornography, and companies will need to quickly act to remove them from their platforms, along with scam adverts.

In a statement, UK Technology Secretary Michelle Donelan said: “The Bill protects free speech, empowers adults and will ensure that platforms remove illegal content. At the heart of this Bill, however, is the protection of children. I would like to thank the campaigners, parliamentarians, survivors of abuse and charities that have worked tirelessly, not only to get this Act over the finishing line, but to ensure that it will make the UK the safest place to be online in the world.”

Enforcement of the act will be left to the UK’s telecommunications regulator, Ofcom, which said in June that it would begin consultations with industry after royal assent was granted. It’s unlikely that enforcement will begin immediately, but the law will apply to any platform with a significant number of users in the UK. Companies that fail to comply with the new rules face fines of up to £18 million ($21.9 million) or 10 percent of their annual revenue, whichever is larger.

Some of the controversy around the act is less about what is in it and more about what isn’t. The long passage of the legislation means that its development straddled the Covid-19 pandemic, giving legislators a live view of the social impact of mis- and disinformation. The spread of anti-vaccination and anti-lockdown messages became an impediment to public health initiatives. After the worst of the pandemic was over, those same falsehoods fed into other conspiracy theories that continue to disrupt society. The original white paper that was the bill’s foundation included proposals for compelling platforms to tackle this kind of content—which individually might not be illegal but which en masse creates dangers. That’s not in the final legislation, although the act does create a new offense of “false communications,” criminalizing deliberately causing harm by communicating something the sender knows to be untrue.

https://arstechnica.com/?p=1979426




iPhones have been exposing your unique MAC despite Apple’s promises otherwise

Private Wi-Fi address setting on an iPhone.
Enlarge / Private Wi-Fi address setting on an iPhone.

Three years ago, Apple introduced a privacy-enhancing feature that hid the Wi-Fi address of iPhones and iPads when they joined a network. On Wednesday, the world learned that the feature has never worked as advertised. Despite promises that this never-changing address would be hidden and replaced with a private one that was unique to each SSID, Apple devices have continued to display the real one, which in turn got broadcast to every other connected device on the network.

The problem is that a Wi-Fi media access control address—typically called a media access control address or simply a MAC—can be used to track individuals from network to network, in much the way a license plate number can be used to track a vehicle as it moves around a city. Case in point: In 2013, a researcher unveiled a proof-of-concept device that logged the MAC of all devices it came into contact with. The idea was to distribute lots of them throughout a neighborhood or city and build a profile of iPhone users, including the social media sites they visited and the many locations they visited each day.

In the decade since, HTTPS-encrypted communications have become standard, so the ability of people on the same network to monitor other people’s traffic is generally not feasible. Still, a permanent MAC provides plenty of trackability, even now.

As I wrote at the time:

Enter CreepyDOL, a low-cost, distributed network of Wi-Fi sensors that stalks people as they move about neighborhoods or even entire cities. At 4.5 inches by 3.5 inches by 1.25 inches, each node is small enough to be slipped into a wall socket at the nearby gym, cafe, or break room. And with the ability for each one to share the Internet traffic it collects with every other node, the system can assemble a detailed dossier of personal data, including the schedules, e-mail addresses, personal photos, and current or past whereabouts of the person or people it monitors.

In 2020, Apple released iOS 14 with a feature that, by default, hid Wi-Fi MACs when devices connected to a network. Instead, the device displayed what Apple called a “private Wi-Fi address” that was different for each SSID. Over time, Apple has enhanced the feature, for instance, by allowing users to assign a new private Wi-Fi address for a given SSID.

On Wednesday, Apple released iOS 17.1. Among the various fixes was a patch for a vulnerability, tracked as CVE-2023-42846, which prevented the privacy feature from working. Tommy Mysk, one of the two security researchers Apple credited with discovering and reporting the vulnerability (Talal Haj Bakry was the other), told Ars that he tested all recent iOS releases and found the flaw dates back to version 14, released in September 2020.

“From the get-go, this feature was useless because of this bug,” he said. “We couldn’t stop the devices from sending these discovery requests, even with a VPN. Even in the Lockdown Mode.”

When an iPhone or any other device joins a network, it triggers a multicast message that is sent to all other devices on the network. By necessity, this message must include a MAC. Beginning with iOS 14, this value was, by default, different for each SSID.

To the casual observer, the feature appeared to work as advertised. The “source” listed in the request was the private Wi-Fi address. Digging in a little further, however, it became clear that the real, permanent MAC was still broadcast to all other connected devices, just in a different field of the request.

Mysk published a short video showing a Mac using the Wireshark packet sniffer to monitor traffic on the local network the Mac is connected to. When an iPhone running iOS prior to version 17.1 joins, it shares its real Wi-Fi MAC on port 5353/UDP.

[embedded content]
Upgrade to iOS 17.1 to prevent your iPhone from being tracked across Wi-Fi networks.

In fairness to Apple, the feature wasn’t useless, because it did prevent passive sniffing by devices such as the above-referended CreepyDOL. But the failure to remove the real MAC from the port 5353/UDP still meant that anyone connected to a network could pull the unique identifier with no trouble.

The fallout for most iPhone and iPad users is likely to be minimal, if at all. But for people with strict privacy threat models, the failure of these devices to hide real MACs for three years could be a real problem, particularly given Apple’s express promise that using the feature “helps reduce tracking of your iPhone across different Wi-Fi networks.”

Apple hasn’t explained how a failure as basic as this one escaped notice for so long. The advisory the company issued Wednesday said only that the fix worked by “removing the vulnerable code.”

This post has been updated to add paragraphs 3 and 11 to provide additional context.

https://arstechnica.com/?p=1979099




Signal Pours Cold Water on Zero-Day Exploit Rumors

Privacy-focused messaging firm Signal is pouring cold water on widespread rumors of a zero-day exploit in its popular encrypted chat app.

“We have seen the vague viral reports alleging a Signal 0-day vulnerability. After responsible investigation *we have no evidence that suggests this vulnerability is real* nor has any additional info been shared via our official reporting channels,” Signal said late Sunday night.

Rumors of a Signal zero-day started circulating over the weekend with what appears to be a copy-pasted warning the “generate link preview” feature could be exploited to take full control of devices.

“To close the vulnerability, have everyone go to settings under your profile in signal> chats> deselect “generate link preview”. Also make sure your signal app is up to date,” according to the cryptic note.

The original source for the zero-day warning is unknown but Signal said it checked with its contacts across the US Government, since the copy-paste report claimed USG as a source.  “Those we spoke to have no info suggesting this is a valid claim,” the company said on X, the social media site previously known as Twitter.

The “generate link preview” feature is known to have privacy and security risks and has led to critical-severity vulnerability problems on Meta’s WhatsApp platform. 

The feature, on by default on some Signal installations, displays a short summary and preview image of a URL being sent but experts have long warned that it provides attack surface to leak IP addresses, expose links sent in end-to-end encrypted chats, and unnecessarily downloading gigabytes of data quietly in the background.

Advertisement. Scroll to continue reading.

Interestingly, Apple’s optional LockDown Mode disables the iMessage link preview feature in response to malicious targeting by surveillance spyware vendors.

Related: Link Previews in Chat Apps Pose Privacy, Security Issues

Related: Signal Discloses Impact From Twilio Hack

Related: Vulnerability in WhatsApp Desktop Exposed User Files

Related: Can ‘Lockdown Mode’ Solve Apple’s Mercenary Spyware Problem?

https://www.securityweek.com/signal-pours-cold-water-on-zero-day-exploit-rumors/




23andMe says private user data is up for sale after being scraped

The 23andMe logo displayed on a smartphone screen.
Enlarge / The 23andMe logo displayed on a smartphone screen.

Genetic profiling service 23andMe has commenced an investigation after private user data was been scraped off its website

Friday’s confirmation comes five days after an unknown entity took to an online crime forum to advertise the sale of private information for millions of 23andMe users. The forum posts claimed that the stolen data included origin estimation, phenotype, health information, photos, and identification data. The posts claimed that 23andMe’s CEO was aware the company had been “hacked” two months earlier and never revealed the incident. In a statement emailed after this post went live, a 23andMe representative said “nothing they have posted publicly indicates they actually have any ‘health information.’ These are all unsubstantiated claims at this point.”

23andMe officials on Friday confirmed that private data for some of its users is, in fact, up for sale. The cause of the leak, the officials said, is data scraping, a technique that essentially reassembles large amounts of data by systematically extracting smaller amounts of information available to individual users of a service. Attackers gained unauthorized access to the individual 23andMe accounts, all of which had been configured by the user to opt in to a DNA relative feature that allows them to find potential relatives.

In a statement, the officials wrote:

We do not have any indication at this time that there has been a data security incident within our systems. Rather, the preliminary results of this investigation suggest that the login credentials used in these access attempts may have been gathered by a threat actor from data leaked during incidents involving other online platforms where users have recycled login credentials.

We believe that the threat actor may have then, in violation of our terms of service, accessed 23andme.com accounts without authorization and obtained information from those accounts. We are taking this issue seriously and will continue our investigation to confirm these preliminary results.

The DNA relative feature allows users who opt in to view basic profile information of others who also allow their profiles to be visible to DNA Relative participants, a spokesperson said. If the DNA of one opting-in user matches another, each gets to access the other’s ancestry information.

The crime forum post claimed the attackers obtained “13M pieces of data.” 23andMe officials have provided no details about the leaked information available online, the number of users it belongs to, or where it’s being made available. On Friday, The Record and Bleeping Computer reported that one leaked database contained information for 1 million users of Ashkenazi heritage, all of whom had opted in to the DNA relative service. The Record said a second database included 300,000 users of Chinese heritage who also had opted in.

The data included profile and account ID numbers, display names, gender, birth year, maternal and paternal haplogroups, ancestral heritage results, and data on whether or not each user has opted into 23andme’s health data. Some of this data is included only when users choose to share it.

The Record also reported that 23andMe website allows people who know the profile ID of a user to view that user’s profile photo, name, birth year, and location. The 23andMe representative said that “anyone who a 23andMe account who has opted into DNA Relatives can view basic profile information of any other account who has also explicitly optend into making their profile visible to other DNA Relative participants.”

By now, it has become clear that storing genetic information online carries risks. In 2018, MyHeritage revealed that email addresses and hashed passwords for more than 92 million users had been stolen through a breach of its network that occurred seven months earlier.
That same year, law enforcement officials in California said they used a different genealogy site to track down a long-sought suspect in a string of grisly murders that occurred 40 years earlier. Investigators matched DNA left at a crime scene with the suspect’s DNA. The suspect had never submitted a sample to the service, which is known as GEDMatch. Instead, the match was made with a GEDMatch user related to the suspect.

While there are benefits to storing genetic information online so people can trace their heritage and track down relatives, there are clear privacy threats. Even if a user chooses a strong password and uses two-factor authentication as 23andMe has long urged, their data can still be swept up in scraping incidents like the one recently confirmed. The only sure way to protect it from online theft is to not store it there in the first place.

This post has been updated to include details 23andMe provided.

https://arstechnica.com/?p=1974265