25 Major Car Brands Get Failing Marks From Mozilla for Security and Privacy 

Mozilla has analyzed 25 major car brands and gave all of them failing marks for privacy and security. They collect significant amounts of personal data and they can share it with others, often without the customer’s explicit permission.

As part of its ‘Privacy Not Included’ project, Mozilla has analyzed privacy policies and apps provided by car manufacturers. Targeted brands include BMW, Renault, Subaru, Fiat, Jeep, Chrysler, Volkswagen, Toyota, Lexus, Ford, Audi, Mercedes-Benz, Honda, Lincoln, Acura, Kia, GMC, Chevrolet, Hyundai, Nissan, and Tesla.

The research showed that privacy policy documents provided by these companies inform customers about a wide range of data being collected, including health and genetic information, race, immigration status, weight, facial expressions, location, driving speed, multimedia content, and even sexual activity.

The data is collected through mobile apps, dealerships, company websites, vehicle telematics, sensors, cameras, microphones, and phones connected to the vehicle.

Mozilla has ranked companies based on data use, data control, track record, and security. The best are Renault and its subsidiary Dacia, which are European companies required to comply with the EU’s General Data Protection Regulation (GDPR).

At the other end of the chart are Nissan and Tesla. The former stands out for harvesting ‘creepy’ data about the user’s sexual activity, while the latter is the worst because — in addition to failing every privacy and security check — it uses what Mozilla describes as ‘untrustworthy AI’. 

Major car manufacturers often disclose data breaches impacting their customers’ personal data. In addition, privacy policies for more than half of the brands reveal that they can share collected information with law enforcement and other government agencies. Furthermore, 84% say they can share personal data with service providers, data brokers and others, while 76% state that they can sell the harvested personal data.  

Advertisement. Scroll to continue reading.

In the case of many products with a cyber component, the consumer needs to specifically accept a privacy policy before using that product. In the case of cars, however, consent is often presumed simply by being a passenger. 

“For example, Subaru states that by being a passenger, you are considered a user — and by being a user, you have consented to their privacy policy. Several car brands also note that it is a driver’s responsibility to tell passengers about the vehicle’s privacy policies,” Mozilla said.

The organization also noted, “While consumers can choose to not use a car app or try not to use connected services, that might mean their car doesn’t work properly — or at all. Consumers have almost zero control and options in regard to privacy, other than simply buying an older model. Regulators and policy makers are behind on this front.”

Mozilla researchers attempted to reach out to each of the analyzed brands for clarifications on their privacy policies, but only Mercedes responded with a vague statement. 

Mozilla concluded that of all the types of products covered by its Privacy Not Included project, cars are the worst. 

“We’re worried about the amount and the sensitivity of the information car companies collect about you. Based on their track records alone, we don’t trust them to keep it safe. And we don’t think a lot of the ways that your information is being shared or sold benefits drivers or anyone besides the businesses who exist to make money off of your data,” Mozilla said.

“We’re also worried that this is just the beginning. We’re worried that new sensor technology could help car companies create, collect, combine, and sell even more information about you,” it added.

Related: Tesla Discloses Data Breach Related to Whistleblower Leak

Related: Toyota Discloses New Data Breach Involving Vehicle, Customer Information

Related: Ferrari Says Ransomware Attack Exposed Customer Data

https://www.securityweek.com/25-major-car-brands-get-failing-marks-from-mozilla-for-security-and-privacy/




Google’s $30-per-month “Duet” AI will craft awkward emails, images for you

A robot with many hands using digital devices at workplace

On Tuesday, Google announced the launch of its Duet AI assistant across its Workspace apps, including Docs, Gmail, Drive, Slides, and more. First announced in May at Google I/O, Duet has been in testing for some time, but it is now available to paid Google Workspace business users (what Google calls its suite of cloud productivity apps) for $30 a month in addition to regular Workspace fees.

Duet is not just one thing—instead, it’s a blanket brand name for a multitude of different AI capabilities and probably should have been called “Google Kitchen Sink.” It likely represents several distinct AI systems behind the scenes. For example, in Gmail, Duet can summarize a conversation thread across emails, use the content of an email to write a brief or draft an email based on a topic. In Docs, it can write content such as a customer proposal or a story. In Slides, it can generate custom visuals using an image synthesis model. In Sheets, it can help format existing spreadsheets or create a custom spreadsheet structure suited to a particular task, such as a project tracker.

An example of Google Duet in action (one of many), provided by Google.
An example of Google Duet in action (one of many), provided by Google.

Some of Duet’s applications feel like confusion in branding. In Google Meet, Google says that Duet AI can “ensure you look and sound your best with studio look, studio lighting, and studio sound,” including “dynamic tiles” and “face detection”—functions that feel far removed from typical generative AI capabilities—as well as automatically translated captions. It can also reportedly capture notes and video, sending a summary to attendees in the meeting. In fact, using Duet’s “attend for me” feature, Google says that “Duet AI will be able to join the meeting on your behalf” and send you a recap later.

In Google Chat, Duet reads everything that’s going on in your conversations so that you can “ask questions about your content, get a summary of documents shared in a space, and catch up on missed conversations.”

An example of Google Duet in action (one of many), provided by Google.
An example of Google Duet in action (one of many), provided by Google.

Those are the marketing promises. So far, as spotted on social media, Duet in practice seems fairly mundane, like a mix of what we’ve seen with Google Bard and more complex versions of Google’s existing autocomplete features. An author named Charlie Guo ran through Duet features in a helpful X thread, noting the AI model’s awkward email compositions. “The writing is almost painfully formal,” he says.

In Slides, a Google-sponsored teacher named Alice Keeler asked Google Duet to make a robot teacher in front of a chalkboard and posted it on X. The results are awkward and arguably unusable, full of telltale glitches found in image synthesis artwork from 2022. Sure, it’s neat as a tech demo, but this is what a trillion-dollar company says is a production-ready tool today.

Teacher Alice Keeler asked Google Slides to create "a robot teacher in front of the chalkboard." These are the results.
Teacher Alice Keeler asked Google Slides to create “a robot teacher in front of the chalkboard.” These are the results.

Of course, these capabilities can (and will) change over time as Google refines its offerings. Eventually, Duet may be absorbed into daily usage as if it weren’t even there, much like Google’s myriad other machine-learning features in its products.

https://arstechnica.com/?p=1964020




Europe is Cracking Down on Big Tech. This Is What Will Change When You Sign On

Starting Friday, Europeans will see their online life change.

People in the 27-nation European Union can alter some of what shows up when they search, scroll and share on the biggest social media platforms like TikTok, Instagram and Facebook and other tech giants like Google and Amazon.

That’s because Big Tech companies, most headquartered in the U.S., are now subject to a pioneering new set of EU digital regulations. The Digital Services Act aims to protect European users when it comes to privacy, transparency and removal of harmful or illegal content.

Here are five things that will change when you sign on:

You can Turn off AI-Recommended Videos

Automated recommendation systems decide, based on people’s profiles, what they see in their feeds. Those can be switched off.

Meta, owner of Facebook and Instagram, said users can opt out of its artificial intelligence ranking and recommendation systems that determine which Instagram Reels, Facebook Stories and search results to show. Instead, people can choose to view content only from people they follow, starting with the newest posts.

Advertisement. Scroll to continue reading.

Search results will be based only on the words they type, not personalized based on a user’s previous activity and interests, Meta President of Global Affairs Nick Clegg said in a blog post.

On TikTok, instead of being shown videos based on what users previously viewed, the “For You” feed will serve up popular videos from their area and around the world.

Turning off recommender systems also means the video-sharing platform’s “Following” and “Friends” feeds will show posts from accounts users follow in chronological order.

Those on Snapchat “can opt out of a personalized content experience.”

Meta, owner of Facebook and Instagram, said users can opt out of its artificial intelligence ranking and recommendation systems that determine which Instagram Reels, Facebook Stories and search results to show. Instead, people can choose to view content only from people they follow, starting with the newest posts.

Search results will be based only on the words they type, not personalized based on a user’s previous activity and interests, Meta President of Global Affairs Nick Clegg said in a blog post.

On TikTok, instead of being shown videos based on what users previously viewed, the “For You” feed will serve up popular videos from their area and around the world.

Turning off recommender systems also means the video-sharing platform’s “Following” and “Friends” feeds will show posts from accounts users follow in chronological order.

Those on Snapchat “can opt out of a personalised content experience.”

The app by Chinese parent company ByteDance has added a new team of moderators and legal specialists to review videos flagged by users, alongside automated systems and existing moderation teams that already work to identify such material.

Facebook and Instagram’s existing tools for reporting content are “easier for people to access,” said Meta’s Clegg, without providing more details.

You’ll Know Why Your Post Was Taken Down

The EU wants platforms to be more transparent about how they operate.

So, TikTok says European users will get more information “about a broader range of content moderation decisions.”

“For example, if we decide a video is ineligible for recommendation because it contains unverified claims about an election that is still unfolding, we will let users know,” TikTok said. “We will also share more detail about these decisions, including whether the action was taken by automated technology, and we will explain how both content creators and those who file a report can appeal a decision.”

Google said it’s “expanding the scope” of its transparency reports by giving more information about how it handles content moderation for more of its services, including Search, Maps, Shopping and Play Store, without providing more details.

You Can Report Fake Products

The DSA is not just about policing content. It’s also aimed at stopping the flow of counterfeit Gucci handbags, pirated Nike sneakers and other dodgy goods.

Amazon says it has set up a new channel for reporting suspected illegal products and content and also is providing more publicly available information about third-party merchants.

The online retail giant said it invests “significantly in protecting our store from bad actors, illegal content and in creating a trustworthy shopping experience. We have built on this strong foundation for DSA compliance.”

Online fashion marketplace Zalando is setting up flagging systems, though it downplays the threat posed by its highly curated collection of designer clothes, bags and shoes.

“Customers only see content produced or screened by Zalando,” the German company said. “As a result, we have close to zero risk of illegal content and are therefore in a better position than many other companies when it comes to implementing the DSA changes.”

Your Kids Won’t be Targeted With Digital Ads

Brussels wants to crack down on digital ads aimed at children over concerns about privacy and manipulation. Some platforms already started tightening up ahead of Friday’s deadline, even beyond Europe.

TikTok said in July that it was restricting the types of data used to show ads to teens. Users who are 13 to 17 in the EU, plus Britain, Switzerland, Iceland, Norway and Liechtenstein no longer see ads “based on their activities on or off TikTok.”

It’s doing the same in the U.S. for 13- to 15-year-olds.

Snapchat is restricting personalized and targeted advertising to users under 18.

Meta in February stopped showing Facebook and Instagram users who are 13 to 17 ads based on their activity, such as following certain Instagram posts or Facebook pages. Now, age and location are the only data points advertisers can use to show ads to teens.

https://www.securityweek.com/europe-is-cracking-down-on-big-tech-this-is-what-will-change-when-you-sign-on/




India Passes Data Protection Legislation in Parliament. Critics Fear Privacy Violation

Indian lawmakers Wednesday approved a data protection legislation that “seeks to better regulate big tech firms and penalize companies for data breaches” as several groups expressed concern over citizens’ privacy rights.

The legislation will limit cross-border transfer of data and provide a framework for setting up a data protection authority to ensure compliance from tech companies, Information Technology and Telecom Minister Ashwini Vaishnaw said.

Several opposition lawmakers and digital experts say the legislation would allow the government and its agencies to access user data from companies and personal data of individuals without their consent as well as collect private data in a country where digital freedoms have been shrinking since Prime Minister Narendra Modi took office in 2014.

Digital experts also fear that the legislation will weaken the landmark Right To Information law — passed in 2005 — that allows citizens to seek data from public officers, such as salaries of state employees.

“It jeopardizes privacy, grants excessive exemptions to the government, and fails to establish an independent regulator,” digital rights group Access Now said in a statement, adding it will enhance the government’s control over personal data and increase censorship.

The upper house of Parliament passed the Digital Personal Data Protection bill which would later be signed by the country’s ceremonial president, a formality, before becoming law. It was passed by the lower house of the Parliament on Monday.

The legislation is the government’s third attempt to pass such legislation and comes nearly six years after India’s top court ruled that privacy is a fundamental right of every citizen — a landmark judgment that was widely hailed as a win for individual freedom.

Advertisement. Scroll to continue reading.

Earlier drafts of the legislation had raised similar concerns.

Proponents of the legislation have long been saying a data protection law is necessary for a country like India where financial fraud and data leaks are rampant, adding that it could act as a crucial step to protect people’s information from commercial and political exploits.

In 2021, India introduced sweeping regulatory laws that have put social media companies and digital platforms under direct government oversight. Modi’s government said it was needed to quell misinformation and hate speech and to give users more power to flag objectionable content. Critics of the law, however, said the law would lead to online censorship in India, particularly on social media platforms like X, previously known as Twitter.

Related: India Claims It Foiled Chinese Cyberattack on Disputed Border

Related: Indian Cyberspies Expose Their Operation After Infecting Themselves With RAT

Related: India-Linked Threat Actor Involved in Spying, Planting Evidence

https://www.securityweek.com/india-passes-data-protection-legislation-in-parliament-critics-fear-privacy-violation/




Apple will require app devs to explain exactly why they use certain APIs

A blue smartphone with two cameras.
Enlarge / The back of the iPhone 13.
Samuel Axon

Apple has announced an additional hoop developers must jump through to get their apps approved on its App Store. Soon, developers of apps that use certain APIs will have to clarify their reasons for using them when submitting those apps.

Apple is trying to close some fingerprinting loopholes here. The term “fingerprinting” in this context refers to various techniques for learning information about a device or its user and tracking them across multiple unrelated apps or websites.

It’s something that Apple has been saying is not allowed in iPhone apps for a while, and the company introduced the controversial App Tracking Transparency initiative in 2021 to give users a choice in whether things like mobile ad networks (for example) could track them in this way.

That said, some more creative and stealthy forms for fingerprinting have been prohibited since then, even if users do opt in to be tracked—and those include misuse of the APIs in question here.

Clever developers can find ways to use the features, information, or tools they offer to track users in exactly the sorts of ways Apple has been trying to stop—even if that wasn’t the main purpose of the API. The APIs that developers will have to justify do things like see file timestamps or look at system boot times, among others. In Apple’s words, these apps can be “misused to access device signals to try to identify the device or user, also known as device fingerprinting.”

Of course, developers can still technically lie and say they’re using an API for one thing when they’re actually using it for something else. Apple addresses that with the somewhat vague policy that “declared reasons must be consistent with your app’s functionality as presented to users.”

It won’t be a perfect system, but it’s likely it will allow Apple to at least decrease the practice of fingerprinting.

Apple previously stated that this change was coming during WWDC 2023, but the company revealed more details and a specific timeline this week.

The rollout will be slow, giving developers plenty of time to respond—at least those who are in a position to actively maintain their apps. Starting this fall, developers who upload an app or an app update that uses one of these APIs will receive a notice that they will need to specify a reason soon.

In spring of 2024, apps that haven’t done this will be rejected. It will be as easy as picking a pre-approved list from a dropdown menu upon app submission for some developers. Still, others may have to do more substantial work—in particular, those who have been taking advantage of this loophole will need to do some development work to change their applications to make them stop doing that if they can’t make a case that one of the approved reasons applies. Those who feel the pre-approved reasons fail to include their own legitimate, non-fingerprinting reason for using an API can contact Apple via a form to request a new reason be approved.

https://arstechnica.com/?p=1957446




ChatGPT: le aziende italiane non sanno come usarlo. Privacy a rischio


Per Kaspersky le aziende italiane non sono ancora pronte a usare ChatGPT: secondo l’ultima ricerca della firma di sicurezza, “ChatGPT, alleato o nemico in ambito lavorativo?”, più del 40% dei dipendenti italiani non sa come funziona l’elaborazione delle informazioni.

L’indagine ha coinvolto 1.000 dipendenti italiani di età compresa tra i 18 e i 55 anni. Più della metà degli intervistati (53%) ha affermato di aver considerato l’idea di usare gli strumenti di IA come ChatGPT in ambito lavorativo, ma solo il 10% li sta già usando.

Il tool viene usato per lo più per la creazione, revisione e traduzione di testi (48%), oppure per annotazioni, appunti e riassunti di riunioni (46%). Solo il 9% degli utenti lo usa per la scrittura di codice.

ChatGPT

Pixabay

La maggior parte degli utenti però non sembra dare la giusta importanza alle questioni relative alla privacy dei dati e alla veridicità delle risposte, tanto che il 50% degli intervistati ha dichiarato di condividere dati personali e documenti sensibili con il chatbot; il 49% di essi, inoltre, non controlla la correttezza delle informazioni.

Il dato è molto preoccupante, soprattutto se si considera che il 57% dei dirigenti e responsabili non è a conoscenza dell’uso del tool in azienda e non è quindi in grado di monitorare il fenomeno.

L’adozione di tecnologie di IA generativa in Italia sta andando a rilento e, dove queste vengono usate, manca una conoscenza adeguata del loro funzionamento e dei rischi. Secondo Kaspersky, più del 60% delle imprese del Paese non ha definito linee guida e regole per l’uso responsabile degli strumenti di IA, esponendosi a rischi di sicurezza elevati.

La situazione è tutt’altro che rosea: gli strumenti di IA generativa vengono usati con troppa leggerezza, spiega Cesare D’Angelo, General Manager Italy & Mediterranean di Kaspersky, e i responsabili non hanno la visibilità giusta per limitare i rischi.

Se le aziende non riusciranno a contrastare il fenomeno e imporre delle linee guida chiare per l’uso delle tecnologie generative, diventeranno esposte a gravi rischi legali e di privacy.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/07/25/chatgpt-le-aziende-italiane-non-sanno-come-usarlo-privacy-a-rischio/?utm_source=rss&utm_medium=rss&utm_campaign=chatgpt-le-aziende-italiane-non-sanno-come-usarlo-privacy-a-rischio




OneTrust Raises $150 Million at $4.5 Billion Valuation

Data privacy and governance provider OneTrust today announced that it has raised $150 million in new funding, bringing the total raised by the company to over $1 billion.

Founded in 2016, the Atlanta-based firm offers a trust intelligence platform to help organizations visualize the data entering their environment, manage it, meet compliance requirements, and ensure transparency.

According to OneTrust, its privacy and security compliance tools are suited for small to large organizations, delivering a holistic approach to trust.

The company says it has over 14,000 active customers, more than double compared to 2020, when it closed a $300 million Series C funding round, at a $5.1 billion valuation.

OneTrust’s current valuation is of $4.5 billion, but the drop is not surprising. Last year, the company let go of 950 employees. Currently, it employs more than 2,000 people.

OneTrust says the new investment round will support its growth and help it meet customer demand for its trust intelligence software.

The new funding round was led by Generation Investment Management, with participation from previous investor Sands Capital.

Advertisement. Scroll to continue reading.

“Our solutions have never been more mission critical. In the face of changing regulations and new business initiatives like AI, organizations need the technology to drive trust to the center of their operations and manage the complex web of privacy, security, ethics, and ESG requirements,” OneTrust founder, CEO, and chairman Kabir Barday said.

Related: Zluri Raises $20 Million for SaaS Management Platform

Related: Secure Code Warrior Raises $50 Million to Help Developers Write Secure Code

Related: SaaS Application Security Firm Savvy Exits Stealth Mode With $30 Million in Funding

Related: IP Fabric Raises $25 Million in Series B Funding

https://www.securityweek.com/onetrust-raises-150-million-at-4-5-billion-valuation/




Norway Threatens $100,000 Daily Fine on Meta Over Data

Norway’s data protection agency said Monday it would ban Facebook and Instagram owner Meta from using the personal information of users for targeted advertising, threatening a $100,000 daily fine if the company continues.

The business practices of big U.S. tech firms are under close scrutiny across Europe over concerns about privacy, with huge fines handed out in recent years.

The Norwegian watchdog, Datatilsynet, said Meta uses information such as the location of users, the content they like and their posts for marketing purposes.

“The Norwegian Data Protection Authority considers that the practice of Meta is illegal and is therefore imposing a temporary ban of behavioural advertising on Facebook and Instagram,” it said in a statement.

The ban will begin on August 4 and last three months to give Meta time to take corrective measures. The company will be fined one million kroner ($100,000) per day if it fails to comply.

“We will analyze the decision … but there is no immediate effect on our services,” Meta told AFP in a statement.

The Norwegian regulator added that its ruling was neither a ban on Facebook and Instagram operating in the country nor a blanket ban on behavioral advertising.

Advertisement. Scroll to continue reading.

The Austrian digital privacy campaign group noyb, which has lodged a number of complaints against Meta’s activities, said it “welcomes this decision as a first important step” and hopes data regulators in other countries will follow suit.

Meta suffered a major setback earlier this year when European regulators dismissed the legal basis Meta had used to justify gathering users’ personal data for use in targeted advertising.

Meta suffered another major setback earlier this month when the European Court of Justice (ECJ) rejected its various workarounds and empowered antitrust regulators to take data privacy issues into account when conducting investigations.

Related: 3 Tax Prep Firms Shared ‘Extraordinarily Sensitive’ Data About Taxpayers With Meta, Lawmakers Say

Related: Meta Fined Record $1.3 Billion and Ordered to Stop Sending European User Data to US

Related: EU Court Deals Blow to Meta in German Data Case

https://www.securityweek.com/norway-threatens-100000-daily-fine-on-meta-over-data/




IA, quale impatto su pace e sicurezza globali? Domani il Consiglio di sicurezza dell’ONU

Il Consiglio di sicurezza dell’ONU alla prova dell’IA

Domani il Consiglio di sicurezza delle Nazioni Unite aprirà ufficialmente un confronto formale tra tutti i suoi membri sul tema delicatissimo dell’intelligenza artificiale (IA) e del suo impatto su pace, conflitti e sicurezza a livello globale.

Un dibattito interno alle Nazioni Unite, fortemente voluto dalla Gran Bretagna per favorire un dialogo internazionale tutto incentrato sui vantaggi che l’IA può garantire ai singoli Paesi e le loro economie, ma soprattutto sui pericoli e le minacce, ancora nascoste, insiti nel suo utilizzo senza regole e standard.

Ci vuole poco, oggi, per turbare i rapporti tra Paesi e gruppi di Paesi a livello mondiale. Le tensioni geopolitiche sempre molto forti, il conflitto in Ucraina e le sue conseguenze sullo scacchiere planetario, le difficoltà dell’economia mondiale, rendono i mercati sempre più instabili e sensibili a qualsiasi perturbazione interna ed esterna.

La Gran Bretagna cerca un ruolo guida nella regolamentazione dell’IA

La Gran Bretagna, che detiene per il mese di luglio la presidenza di turno del Consiglio di sicurezza delle Nazioni Unite, sta cercando di ricavarsi un ruolo di guida a livello internazionale per quel che riguarda il difficile e necessario percorso di regolamentazione dell’IA.

Domani mattina la riunione sarà aperta e presieduta dal ministro degli Esteri britannico, James Cleverly. Diversi i temi chiave in agenda, tra cui l’intelligenza artificiale.

Il mese scorso, lo stesso segretario generale delle Nazioni Unite, Antonio Guterres, ha lanciato una prima proposta di regolamentazione stringente dell’Intelligenza artificiale, a partire dall’istituzione di un organismo sovranazionale di controllo e regolamentazione dell’IA, sul modello dell’Agenzia internazionale per l’energia atomica (AIEA).

Multilateralismo per affrontare le grandi sfide storiche del nostro tempo

L’idea di un confronto in seno alle Nazioni Unite su questo ed altri temi chiave era già stato annunciato dallo stesso Cleverly a giugno, in occasione della Chatham House London Conference.

“Fondamentale riformare il Consiglio di sicurezza dell’ONU in termini di un maggiore multilateralismo, unica via per affrontare in maniera efficace e condivisa sfide epocali come le migrazioni, la sicurezza, la crescita, il debito, il protezionismo, il cambiamento climatico, le pandemie, i conflitti e le crisi umanitarie”, ha spiegato in quell’occasione il ministro britannico.

Un multilateralismo allargato e reso possibile con la proposta di allargare il Consiglio di sicurezza ONU a India, Germania, Brasile e Giappone.

Tra gli obiettivi chiave che saranno via via discussi dal Consiglio ci sono la riforma delle istituzioni finanziarie internazionali, le nuove regole per l’Organizzazione mondiale per il commercio, considerate necessarie per il rilancio ed il rafforzamento dell’economia digitale globale, in cui inevitabilmente ricade il confronto su come gestire tutti assieme il proliferare sempre più rapido delle applicazioni dell’intelligenza artificiale.

https://www.key4biz.it/ia-quale-impatto-su-pace-e-sicurezza-globali-domani-il-consiglio-di-sicurezza-dellonu/453813/




3 Tax Prep Firms Shared ‘Extraordinarily Sensitive’ Data About Taxpayers With Meta, Lawmakers Say

Three large tax preparation firms sent “extraordinarily sensitive” information on tens of millions of taxpayers to Facebook parent company Meta over the course of at least two years, a group of congressional Democrats reported on Wednesday.

They say some of that data was then used by Meta to create targeted advertising to its own users, other companies, and to train Meta’s algorithms. 

The Democrats’ report urges federal agencies to investigate and potentially go to court over the wealth of information that H&R Block, TaxAct and TaxSlayer shared with the social media giant.

In a letter to the heads of the IRS, the Department of Justice, the Federal Trade Commission and the IRS watchdog, seven lawmakers say their findings “reveal a shocking breach of taxpayer privacy by tax prep companies and by Big Tech firms.”

Their report said highly personal and financial information about sources of taxpayers’ income, tax deductions and exemptions was made accessible to Meta as taxpayers used the tax software to prepare their taxes.

That data came to Meta through its Pixel code, which the tax firms installed on their websites to gather information on how to improve their own marketing campaigns. In exchange, Meta was able to access the data to write targeted algorithms for its own users.

The program collected information on taxpayers’ filing status, income, refund amounts, names of dependents, approximate federal tax owed, which buttons were clicked on the tax preparers’ websites and the names of text entry forms that the taxpayer navigated, the report states.

Advertisement. Scroll to continue reading.

Taxpayer data was also shared with Google, through its own tracking tools — though the firm told lawmakers that it never used the information to track users on the internet, according to the report.

The letter to federal agencies was signed by Sens. Elizabeth Warren, Ron Wyden, Richard Blumenthal, Tammy Duckworth, Bernie Sanders, Sheldon Whitehouse and Rep. Katie Porter. The lawmakers called for the agencies to “immediately open an investigation into this incident.”

They ask the agencies to investigate “and prosecute any company or individuals who violated the law,” saying it could result in billions of dollars in criminal liability to the firms.

The Markup, a nonprofit journalism outlet focusing on technology, initially reported on the data-sharing between tax firms and Meta in November. A TaxAct representative said the firm has engaged with Warren’s office to explain its usage of the analytical tools and that protecting customers is its top priority.

A TaxSlayer representative said Wednesday that the report “contains numerous false or misleading statements” regarding the taxpayers’ personal and filing information sent to Meta and Google and it will request a retraction or correction from Warren’s office.

H&R Block said that it takes protecting client privacy very seriously and has taken steps to prevent the sharing of information through the Pixel coding.

And Meta said that it has been clear in its policies that advertisers “should not send sensitive information about people through our Business Tools.”

“Doing so is against our policies and we educate advertisers on properly setting up Business tools to prevent this from occurring,” the company said in an emailed statement. “Our system is designed to filter out potentially sensitive data it is able to detect.”

Meta’s Facebook has a history of failure when it comes to protecting user privacy.

One of its biggest scandals erupted in 2018 when investigations revealed that Cambridge Analytica, a firm with ties to Donald Trump’s onetime political strategist Steve Bannon, had paid a Facebook app developer for access to the personal information of about 87 million Facebook users. That data was then used to target U.S. voters during the 2016 campaign that culminated in Trump’s election as the 45th president.

Facebook agreed to a $725 million user settlement in that case, and later was fined $5 billion by the U.S. Federal Trade Commission.

This May, the FTC proposed sweeping new changes to its standing privacy order for Meta that would bar the company from using any data collected from children under 18, including via its virtual reality technologies. The new rules would also force Meta to pause new products and services until an independent assessor confirms that they comply with the FTC order. The under-18 concerns stem largely from Facebook’s Messenger for Kids app, which has long drawn fire for insufficient privacy protections for its younger users.

Also in 2018, the company disclosed that almost 50 million accounts had been vulnerable to the theft of digital “user tokens” that attackers could use to log into personal accounts. Facebook admitted the same year that most of its then 2.2 billion users had likely had their public data “scraped” by malicious actors.

Representatives from the IRS and FTC did not immediately respond to requests for comment. DOJ and the IRS watchdog declined to comment.

The Democrats say their report serves as an argument for the creation of an electronic free-file system for submitting tax returns that would be run by the government, which the IRS is currently piloting.

The IRS plans to launch a pilot program for the 2024 filing season to test a “direct file” system and help the federal government decide whether to move forward with potentially implementing it in the future.

The IRS in May published a feasibility report laying out taxpayer interest in direct file, how the system could work, its potential cost, operational challenges and more.

The report shows that the majority of surveyed taxpayers would be interested in using an IRS-provided tool to prepare and file their taxes electronically — almost 50% of respondents who preferred the IRS free-file option over commercial tax preparation firms said they preferred to give their financial information directly to the IRS instead of the third party.

https://www.securityweek.com/3-tax-prep-firms-shared-extraordinarily-sensitive-data-about-taxpayers-with-meta-lawmakers-say/