Facebook furious at FTC after agency proposes ban on monetizing youth data

Facebook furious at FTC after agency proposes ban on monetizing youth data

Facebook has not been doing enough to comply with a 2020 privacy order, the Federal Trade Commission (FTC) announced Wednesday. On top of “continuing to give app developers access to users’ private information” that Meta claimed had been cut off, the FTC alleges that Facebook has caused new harm. Perhaps most alarming, the FTC alleges that Facebook’s Messenger Kids product misled parents on who could connect to chat with minors and misrepresented who had access to private youth data.

Now, the FTC has proposed changes to the 2020 order that would prohibit Facebook owner Meta from launching new products on any of its platforms without procuring written FTC compliance confirmation and prevent the company from monetizing any of the youth data it collects across Facebook, Instagram, WhatsApp, and Oculus.

“Facebook has repeatedly violated its privacy promises,” Samuel Levine, director of the FTC’s Bureau of Consumer Protection, said in a press release.

The FTC confirmed that it has asked Meta to respond to allegations first reported by The Verge in 2019 that “from late 2017 until mid-2019, Facebook misrepresented that parents could control whom their children communicated with through its Messenger Kids product.” Quite the opposite, instead of providing adequate parental controls to prevent strange adults from contacting kids, a Facebook bug allowed “children in certain circumstances” to “communicate with unapproved contacts in group text chats and group video calls.” In 2019, Facebook confirmed to The Verge that the technical issue had occurred and thousands of users were notified about the bug, which affected “a small number of group chats.”

According to the FTC, this is the third time that Facebook has violated a privacy order. Facebook has also violated the FTC Act and the Children’s Online Privacy Protection Act Rule, the FTC alleged.

“The company’s recklessness has put young users at risk, and Facebook needs to answer for its failures,” Levine said in the press release.

A Meta spokesperson told Ars that the FTC’s proposed changes are “a political stunt,” saying that the FTC gave Meta “no opportunity to discuss this new, totally unprecedented theory.” Meta considers the FTC’s proposed changes to the privacy order “a new low.”

“Let’s be clear about what the FTC is trying to do: usurp the authority of Congress to set industry-wide standards and instead single out one American company while allowing Chinese companies, like TikTok, to operate without constraint on American soil,” Meta’s spokesperson said. “FTC Chair Lina Khan’s insistence on using any measure—however baseless—to antagonize American business has reached a new low.” [Update: Facebook says that the assessor’s report did not find violations of the 2020 privacy order and noted that the two privacy concerns that the FTC raised were already discovered, fixed, and publicly disclosed.]

The FTC’s proposed changes were drafted in response to a report from an independent assessor who reviewed Facebook’s privacy program and concluded that there were “several gaps and weaknesses” in it. Some of these deficiencies, the FTC alleges, “pose substantial risks to the public.”

Among the most drastic proposed changes are a blanket prohibition against monetizing data of users under 18 and a pause on launching new products, services, or features ” without written confirmation from the assessor” confirming full compliance with the FTC’s order. The FTC has also proposed additional limitations on Meta’s uses of facial recognition technology and an extension of the 2020 order’s compliance requirements to encompass all companies merged under Meta. Finally, the FTC proposes going back to the drawing board on the 2020 privacy order and strengthening many of the existing requirements, including “those related to privacy review, third-party monitoring, data inventory and access controls, and employee training.”

Meta’s spokesperson told Ars that the company contends that it has “spent vast resources building and implementing an industry-leading privacy program under the terms of our FTC agreement.”

“We will vigorously fight this action and expect to prevail,” Meta’s spokesperson told Ars.

Meta has 30 days to officially respond to the proposed changes, but ultimately, the FTC says it will “determine whether modification of the 2020 order is in the public interest or justified by changed conditions of fact or law.”

https://arstechnica.com/?p=1936426




Open Banking: A Perfect Storm for Security and Privacy?

Open banking was born in the EU, flourished in the UK, and is now spreading around the globe – including the US. Since this is fintech it is, and will continue to be, highly targeted by criminal actors.

There are two fundamental government approaches to this market: regulation or market forces. Europe has a penchant for regulation while the US tends to let the market shape its own areas.

Europe started the ball rolling with the PSD2 (Payment Services Directive) legislation of 2018. It was originally aimed at securing payment services, but activated a new breed of innovative financial service apps.

Since it is a directive rather than regulation (such as GDPR), individual member states could implement the directions in their own manner. The UK, as a major financial hub, and bolstered by Brexit (which also slackened the shackles of GDPR), took advantage of its freedom and developed the PSD2 principles into its own Open Banking System. This included a requirement for the nine largest UK banks to develop a common API standard which helped open banking to rapidly flourish.

The advantages of a flourishing open banking ecosphere are similar for most nations. This was summarized in a December 2022 statement by the UK’s financial conduct authority (FCA): “Fully realized, open banking and then open finance can bring further benefits to consumers and businesses and will help the UK become more competitive and innovative.”

Open banking comprises payment systems for larger organizations, and the burgeoning number of purpose-specific apps for consumers and smaller businesses. It is part of the fintech sector – but for most people, the concept of open banking is limited to the purpose-specific app market.

Advertisement. Scroll to continue reading.

Open banking in the US

Open banking is an emerging market sector in the US. While it is less advanced than in the UK and EU, it would be wrong to think it is a new idea. As long ago as 2016 the Consumer Financial Protection Board wrote, “Whereas once upon a time consumers might have brought a shoebox full of paper to a financial advisor or loan officer, now consumers can accomplish the same thing just by providing access to their digital financial records. This is a world full of new promise, where consumers have the chance to gain the tremendous benefits of ease, speed, convenience, and transparency.”

The potential had already been flagged by the Dodd-Frank Act of 2010, which said that consumer transactions including “costs, charges and usage data,” shall be made available in an “electronic form usable by consumers”.

It is the practical difficulties of the disparate nature of a large-scale federal country that has delayed the natural evolution of the market. In 2021, there were 4,236 FDIC-insured commercial banks in the United States (Statista). Developing apps compatible with this amount, or the right selection, of banks is no easy feat.

There is no specific guidance or government initiative on open banking in the US. There is no requirement for banks to develop a standard API. There are no tailored open banking regulations, although open banking operators will be required to abide by various federal and state-level security and privacy requirements.

But there is a strong entrepreneurial attitude and a business opportunity – hindered by non-standard APIs and the practical difficulty of writing individual APIs for all the important banks.

The practical problems led to the early use of screen scraping by open banking apps. This is far from perfect. It requires the customer to provide credentials, but without the bank knowing who or what is using those credentials. And it can gather more data than is strictly required for its purpose.

The banks are developing APIs, but screen scraping lingers. Capgemini explained the differences between screen scraping and API-based open banking in March 2022:

“Screen scraping is a technology by which a customer provides its banking app login credentials to a TPP [third party provider]. The TPP then sends a software robot to the bank’s app or website to log-in on behalf of the customer and retrieve data and/or initiate a payment. Banks have less control over the data retrieved, which may go beyond account data regulated under PSD2 and may include any customer data available. With an API, banks have greater control to share only the necessary data for the TTP’s service and customers do not need to share any credentials with TPPs.”

There is little doubt the API based approach to open banking will prevail in the US as it does in the UK and EU. This will be more secure than scraping but will still have its security issues.

And it will take time. Trevor Salter, partner in Morrison & Foerster’s financial services practice, explains: “We’ve seen broad progress on technical integration protocols between financial institutions, aggregators, and product providers. Similarly, we’ve seen general alignment on how to make end users aware of how their data will be processed. But in the absence of a government or industry mandate, data can’t flow until financial institutions and aggregators sign an agreement.”

As a result, open banking in the US remains a piecemeal effort while all concerned negotiate bilateral agreements to unlock users’ data. “Many of the largest financial institutions, aggregators and product providers have completed those agreements,” continued Salter, “but there will be a very long tail of relatively smaller financial institutions, aggregators and product providers before we reach the end of the journey toward open banking.”

Threats to the API approach

A typical open banking process would now comprise the app developer, a user with the app installed on a mobile phone, an API connecting the app to the bank, and the bank itself. What could go wrong?

The app could be compromised before or after installation, or the mobile phone could be hijacked. In either of these cases, the API might work perfectly, and simply connect to the bank and return the requested data. That data could go to a criminal controlling the user’s phone, or it could be passed back to the app provider. The app provider could sell on the data retrieved to other third parties as part of its own business model. And, of course, the API could be attacked remotely.

Lebin Cheng, VP for API Security at Imperva provides an overview of a market where traditional communication is from one walled garden to another. “The bank itself can be considered a walled garden,” he told SecurityWeek, but that epithet can no longer be applied to mobile phones. “Open banking requires the bank to communicate with a mesh of services with no fixed location and where security is managed by the user. The app itself may come from a startup of just 20 people with a new AI algorithm. The promise is alluring to the user, offering better mortgage, portfolio, or debt management, but with no specific open banking regulations. And the bank itself has little control over any security but its own.”

The two primary threats within the open banking ecosphere are financial fraud (if the app itself is compromised, or if an attacker can gain control of the mobile phone and thus the API identifier), and non-consensual use of PII (through the possible resale of personal information to third parties).

Michelle McLean, Salt Security

APIs

“Open banking services are built on APIs,” comments Michelle McLean, VP at Salt Security; “and each single transaction can trigger dozens to hundreds of separate API calls to complete. A further complication is that these transactions involve multiple parties – the consumer’s financial institution will be exchanging data with a large number of suppliers, partners, and other consumers as part of the transaction. The scope of API calls as well as the variety of entities and interconnection points all contribute to a significant API attack surface.”

It is, she continued, an example of problems with API security, and the relevance of API security to open banking. “Unfortunately, open banking is also a great example of why APIs are such an attractive target for bad actors – the highly lucrative financial data APIs transport in open banking applications make them worth the time to look for business logic flaws.”

Learn More about API Security at SecurityWeek’s Cloud & Data Security Summit

As CISOs and corporate defenders grapple with the intricacies of securing sensitive data passing through multi-cloud deployments and APIs, the importance of frameworks, tools, controls and design models have surfaced to the front burner.

Cloud & Data Security Summit
July 19, 2023 | Virtual Event
Learn More

In this area, we have a new looming threat: the application of large language model AI (such as ChatGPT) to help find those logic flaws. Alex Polyakov, CEO and co-founder at Adversa AI sees two threats to APIs from artificial intelligence. “Fuzzing is still one of the best ways to find vulnerabilities in a black box configuration, and GPT models are very good at fuzzing,” he told SecurityWeek.
The second threat he believes will be more dangerous when open banking APIs have AI as a backend. In this case AI jailbreak methods will abuse the functionality of the open banking business logic.

“While the first threat of using AI for finding new vulnerabilities in APIs seems dangerous, fortunately, we already have detection measures against those attacks –there will just be more of them,” he continued. “But the second threat is more dangerous because companies don’t have measures to prevent attacks on AI.”

Fraud

In most cases, open banking is accessed via an app on a mobile phone calling an API. At the center of its security, the API focuses on the authentication and authorization of the calling device. This is the mobile phone which is assumed to be operated by the authorized open banking customer.

But, comments Krishna Vishnubhotla, VP of product strategy at Zimperium, “When these APIs are called from mobile apps, the risk of abuse increases exponentially since it is easy to impersonate a legitimate API call using a fake app and mobile device emulator.”
Consequently, user identity will have difficulty distinguishing between legitimate and fraudulent API calls. “Verifying identity through an app is extremely risky,” he continued, “if there is no confidence in the underlying device. Providers must consider mobile device attestation in addition to API security to prevent fraud on mobile devices.”

Privacy issues

Privacy concerns in open banking revolve around the amount and detail of PII that can move from the bank to the TPP. Selling PII is a common business plan for many service and app providers; but the user may not be aware of it.

“‘Consent’ isn’t the real privacy issue,” said Vishnubhotla; “it’s ‘informed consent’.” Consumers just don’t read fine print anymore, and it’s impossible to expect them to since it’s pages of detailed information that no one understands.

Michael Covington, Jamf

“EULAs are not written or presented with the consumer in mind,” he continued “They are also presented when the consumer is eager to see the final product offer. As a result, the user is motivated to click agree, and move on. It is important to make this information easily accessible and understandable for consumers.”

Ensuing problems, says Michael Covington, VP of strategy at Jamf, “could include financial profiles on individuals being leaked or misused to target them for unnecessary services.”

Improving the security of open banking

The open banking market is a prime target for criminals. “With the wealth of data available within the system, attackers could pursue personal information that could be used to target individuals,” said Covington. “Or they could be looking to skim off the top of the millions of transactions that would be performed within the system each day.”

He suggests regulations are the key to improving security. “Regulations will go a long way to ensure that consumer data is protected within an open banking system and that thoughtful guidelines are in place for securing the firms and their connected infrastructure. In addition, a culture of transparency will encourage firms to share details on attacks when they occur so best practices can be established, and threat intelligence shared within those participating in the platform.”

McLean believes improved visibility is important. “Breaches can be devastating for open banking businesses,” she told SecurityWeek. “To eliminate blind spots and defend against threats, open banking providers require real-time visibility into all their APIs and attack surface. Some of these organizations are rolling out new APIs almost daily, and existing APIs are changing all the time as well. So, banks need an accurate inventory of their API assets to be able to protect them.”

But identifying and stopping attacks is also necessary. This is difficult because they can unfold slowly over time – sometimes weeks or even months – and requires a large data set and continuous monitoring.

“Analyzing this extensive data set requires AI and ML – humans could never keep up,” she continued. “Open banking organizations need to be able to accurately identify malicious user intent, so API security platforms need to distill anomalies from ‘normal’ API traffic and then surface which of the anomalies are malicious.”

Open banking can be described as a perfect storm for cybersecurity. At one end, small startups with financial acumen but little or no security expertise or resources, are rushing new products to market. Banks are being forced by market pressure to join the rush, but have no specific regulatory guidance in the US on how to do so. In the middle is the user with a history of lax security habits and a mobile phone that is frequently lost, stolen, hijacked or SIM-swapped. And it’s all glued together by APIs that comprise one of the most attacked vectors in the cybersecurity ecosphere.

Related: T-Mobile Says Hackers Used API to Steal Data on 37 Million Accounts
Related: Credential Leakage Fueling Rise in API Breaches
Related: Google Fi Data Breach Reportedly Led to SIM Swapping
Related: PSD2 and Open Banking Bring Problems and Opportunities for Global Banks
Related: ChatGPT, the AI Revolution, and the Security, Privacy and Ethical Implications

https://www.securityweek.com/open-banking-a-perfect-storm-for-security-and-privacy/




ChatGPT e l’AI Act aprono la strada all’AIaaS (Artificial Intelligence as a Service)

Dopo la vicenda innescata dalla decisione del Garante Privacy, da pochi giorni ChatGPT è nuovamente operativo in Italia.

Giunto all’attenzione delle cronache in seguito ai rilievi dell’Autorità, motivati da un trattamento dati incompatibile con il GDPR, il popolare chatbot era stato inaccessibile agli utenti italiani per tutto il mese di aprile.

L’incontro del 6/4 tra vertici di OpenAI e Collegio del Garante ha evidentemente avuto un esito positivo, spingendo la società a conformarsi alle richieste e a modificare la propria privacy policy così da consentire la riattivazione in conformità alle leggi nazionali ed europee.

In particolare è stata aggiornata l’informativa sul trattamento dati per rendere noti a ogni utente, oltre a modalità e base giuridica del trattamento, anche il tipo di informazioni usate per allenare il software; sono poi stati introdotti meccanismi di age-verification, opzioni di disattivazione della cronologia e la possibilità di richiedere la cancellazione dei propri dati.

Il recente rilascio di GPT-4, che incarna la quarta generazione dei modelli linguistici targati OpenAI, promette di migliorare ulteriormente l’attenzione alla privacy e i livelli di sicurezza del servizio.

Auspicando che “la società prosegua lungo questo percorso di adeguamento alla normativa europea sulla protezione dati”, per ora il Garante si è dichiarato soddisfatto delle misure intraprese.

L’episodio ha comunque evidenziato i problemi di compatibilità tra tecnologie emergenti e quadro normativo, dando altresì impulso a una recente accelerazione nel processo di approvazione dell’AI Act, che intende regolare compiutamente la materia per mitigarne i potenziali rischi.

Analogamente ad altri progetti di generative AI, ChatGPT si è infatti prestato sin da subito a una vastissima gamma di utilizzi: dalla ricerca al puro intrattenimento, fino alle attività malevole condotte da criminali informatici indipendenti od organizzati, portando ad affiancare alle preoccupazioni per la privacy quelle relative ai più tradizionali profili di sicurezza.

Non resta che attendere per osservare le prossime sfide legate all’impiego di questo strumento, nonché – più in generale – all’universo in espansione noto come AIaaS (Artificial Intelligence as a Service).

A cura della Redazione

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/chatgpt-e-lai-act-aprono-la-strada-allaiaas-artificial-intelligence-as-a-service/




Sensitive data is being leaked from servers running Salesforce software

Stylized image of rows of padlocks.

Servers running software sold by Salesforce are leaking sensitive data managed by government agencies, banks, and other organizations, according to a post published Friday by KrebsOnSecurity.

At least five separate sites run by the state of Vermont permitted access to sensitive data to anyone, Brian Krebs reported. The state’s Pandemic Unemployment Assistance program was among those affected. It exposed applicants’ full names, Social Security numbers, addresses, phone numbers, email addresses, and bank account numbers. Like the other organizations providing public access to private data, Vermont used Salesforce Community, a cloud-based software product designed to make it easy for organizations to quickly create websites.

Another affected Salesforce customer was Columbus, Ohio-based Huntington Bank. It recently acquired TCF Bank, which used Salesforce Community to process commercial loans. Data fields exposed included names, addresses, Social Security numbers, titles, federal IDs, IP addresses, average monthly payrolls, and loan amounts.

Both the state of Vermont and Huntington Bank learned of the leaks when Krebs contacted them for comment. In both cases, the customers quickly removed public access to the sensitive information.

Salesforce Community websites can be configured to require authentication so that a limited number of authorized people can access sensitive data and internal resources. The sites can also be set up to allow non-authenticated access to anyone for viewing public information. Administrators sometimes inadvertently allow unauthenticated visitors to access website sections intended to be available only to authorized workers.

Salesforce told Krebs that it provides customers with clear guidance on how to configure Salesforce Community to ensure what data is accessible to unauthenticated guests. The company pointed to resources here, here, and here.

Several people have pushed back on that assertion. One person is Vermont’s Chief Information Security Officer Scott Carbee. He told Krebs his team was “frustrated by the permissive nature of the platform.” Another critic is Doug Merrett, who first tried to raise awareness about the ease of misconfiguring Salesforce Community two years ago. On Friday, he elaborated on the problem in a post headlined The Salesforce Communities Security Issue.

“The issue was that you are able to ‘hack’ the URL to see standard Salesforce pages – Account, Contact, User, etc.,” Merrett wrote. “This would not really be an issue, except that the admin has not expected you to see the standard pages as they had not added the objects associated to the Aura community navigation and therefore had not created appropriate page layouts to hide fields that they did not want the user to see.”

In Salesforce parlance, Aura refers to reusable components in the user interface that can be applied to selected portions of a web page, from a single line of text to an entire app.

Krebs said that he learned of the leaks from security researcher Charan Akiri, who identified hundreds of organizations with misconfigured Salesforce sites. Akiri said that of the multiple companies and government organizations he notified, only five eventually fixed the problems. None of those were in the government sector.

One organization Krebs notified was the government of Washington, DC, which uses Salesforce Community for at least five public DC Health websites and was leaking sensitive information. The interim chief information security officer for the district told Krebs he ran the findings by a third-party consultant brought in to investigate. The third party, the CISO told Krebs, reported back that the sites were not vulnerable to data loss.

Krebs then provided a document showing the Social Security number of a health professional he had downloaded from DC Health as he was interviewing the CISO. The CISO then acknowledged his team had overlooked some of the configuration settings.

https://arstechnica.com/?p=1935543




Big Tech Crackdown Looms as EU, UK Ready New Rules

TikTok, Twitter, Facebook, Google, and Amazon are facing rising pressure from European authorities as London and Brussels advanced new rules Tuesday to curb the power of digital companies.

They’re among those on a list of the 19 biggest online platforms and search engines that the European Union’s executive arm said must meet extra obligations for cleaning up illegal content and disinformation and keeping users safe under the 27-nation bloc’s landmark digital rules that take effect later this year.

The U.K. government, meanwhile, unveiled draft legislation that would give regulators more power to protect consumers from online scams and fake reviews and boost digital competition.

The updates help solidify Europe’s reputation as the global leader in efforts to rein in the power of social media companies and other digital platforms.

TikTok will allow European Commission officials to carry out a “stress test” of its systems to ensure they comply with the Digital Services Act, Commissioner Thierry Breton said in an online briefing.

He proposed the idea to TikTok CEO Shou Zi Chew when they met in Brussels earlier this year.

“I’m happy that they came back to us saying they are interested,” Breton said, but added that he’s waiting for Chew to provide a date. TikTok did not reply to a request for comment.

Twitter had agreed earlier to a stress test, and Breton said he and his team will travel to the company’s headquarters in San Francisco at the end of June to carry out the voluntary mock exercise. Breton didn’t detail what the test would entail.

Starting Aug. 25, the biggest online platforms will have to give European users more control by making it easier to report illegal content like hate speech and providing more information on why their systems recommend certain content.

There are guardrails for content generated by artificial intelligence like deepfake videos and synthetic images, which will have to be clearly labeled when they come up in search results, Breton said.

Platforms will have to “completely redesign” their systems to ensure high a level of privacy and safety for children, including verifying users’ ages, Breton said.

Big Tech companies also will have to revamp their systems to “prevent algorithmic amplification of disinformation,” he said, saying he was particularly concerned about Facebook’s content moderation systems ahead of September elections in Slovakia.

“Now that Facebook has been designated as a very large online platform, Meta needs to carefully investigate its system and fix it where needed ASAP,” he said.

Facebook’s parent company said it supports the EU’s new Digital Services Act.

“We take significant steps to combat the spread of harmful content on Facebook and Instagram across the EU,” Meta said while pointing out its efforts on content moderation and media literacy in Slovakia. “While we do this all year round, we recognise it’s particularly important during elections and times of crisis, such as the ongoing war in Ukraine.”

Violations could result in fines worth up to 6% of a company’s annual global revenue — amounting to billions of dollars — or even a ban on operating in the EU.

The European Commission’s list of very large online platforms is limited to those with at least 45 million users in Europe, which includes Google’s Search, Play, Maps, Shopping and YouTube services; Amazon Marketplace; Apple’s App Store; Microsoft’s Bing and LinkedIn; Meta’s Facebook and Instagram; plus Pinterest, Snapchat, TikTok, Twitter, Wikipedia, Booking.com, China’s Alibaba Aliexpress and German ecommerce company Zalando.

Breton said more platforms could be added, and the commission is analyzing “four to five” others that it will decide on in coming weeks.

In Britain, the government’s Digital Markets, Competition and Consumers bill proposed Tuesday would give watchdogs more teeth to counter the dominance of tech companies, backed by the threat of fines worth up to 10% of their annual revenue.

Under the proposals, online platforms and search engines could be required to give rivals access to their data or be more transparent about how their app stores and marketplaces work.

The rules would make it illegal to hire someone to write a fake review or allow the posting of online consumer reviews “without taking reasonable steps” to verify they’re genuine. They also would make it easier for consumers get out of online subscriptions.

The new rules, which still need go through the legislative process and secure parliamentary approval, would apply only to companies with 25 million pounds ($31 billion) in global revenue or 1 billion pounds in U.K. revenue.

Related: Europe’s Hypocrisy Over Personal Data Privacy Exposed

Related: EU Wants to Toughen Cybersecurity Rules for Smart Devices

Related: EU Court Rules Against German Data Collection Law

https://www.securityweek.com/big-tech-crackdown-looms-as-eu-uk-ready-new-rules/




ChatGPT now allows disabling chat history, declining training, and exporting data

An AI-generated abstract colorful artwork.
OpenAI / Stable Diffusion

On Tuesday, OpenAI announced new controls for ChatGPT users that allow them to turn off chat history, simultaneously opting out of providing that conversation history as data for training AI models. Also, users can now export chat history for local storage.

The new controls, which rolled out to all ChatGPT users today, can be found in ChatGPT settings. Conversations that begin with the chat history disabled won’t be used to train and improve the ChatGPT model, nor will they appear in the history sidebar. OpenAI will retain the conversations internally for 30 days and review them “only when needed to monitor for abuse” before permanently deleting them.

However, users who wish to opt out of providing data to OpenAI for training will lose the conversation history feature. It’s unclear why users cannot use conversation history while simultaneously opting out of model training.

Previously, ChatGPT kept track of conversations and used the conversation data to fine-tune its AI models. Users could periodically clear their chat history on demand, but any conversation could still be used for fine-tuning. That posed a significant privacy issue, especially for sensitive data that might be shared by corporate employees, lawyers, or doctors using ChatGPT.

A screenshot of ChatGPT settings that shows the "Chat History & Training" option.
Enlarge / A screenshot of ChatGPT settings that shows the “Chat History & Training” option.
Benj Edwards / Ars Technica

ChatGPT’s conversation history got OpenAI in hot water in March due to a bug that temporarily exposed some ChatGPT users’ chat histories to other people. That event attracted regulatory interest in Italy that has not yet been resolved. The new privacy-related ChatGPT features are likely related to the resolution process.

Also on Tuesday, OpenAI introduced a new “export” option in ChatGPT settings that allows users to export their ChatGPT data to files that can be stored locally on a PC. We tried the export option in ChatGPT Settings (click “Show” beside “Data Controls”) and received an email containing a link to a compressed HTML file and several JSON files that contained our stored conversation history with ChatGPT. The history only extended back to the last time we cleared the conversation history.

A screenshot of an email from OpenAI providing a link to exported ChatGPT conversation history.
Enlarge / A screenshot of an email from OpenAI providing a link to exported ChatGPT conversation history.
Benj Edwards / Ars Technica

For professionals and enterprises that “need more control over their data,” OpenAI also announced that it is working on a new “ChatGPT Business” subscription that will opt users out of model training by default, according to OpenAI’s Data Controls FAQ. OpenAI says the release date for ChatGPT Business will occur “in the coming months.”

https://arstechnica.com/?p=1934271




Zero trust for Zoom calls: ChromeOS getting universal microphone/camera toggles

Rather than app-by-app permissions that are set once, ChromeOS will soon offer universal mic and camera toggles that should help prevent accidental exposure of messy bedrooms, running children, penguins, and other objects.
Enlarge / Rather than app-by-app permissions that are set once, ChromeOS will soon offer universal mic and camera toggles that should help prevent accidental exposure of messy bedrooms, running children, penguins, and other objects.

Chromebooks will become a better place to take a video call or audio huddle soon, as Google is giving all users the ability to universally control access to their video cameras and microphones.

As part of a wider announcement of business data and security improvements, Tony Ureche, head of security, identity, and privacy for ChromeOS, writes that Chromebooks will get a space in Settings for toggling camera and microphone access. If an app tries to access either device upon launching or after a button tap, you’ll get a notice saying, “Your mic is muted by your system settings,” with a prompt to click the button to learn more (at least in Google Meet). The setting is coming “later this year.”

Having a default-off option for Chromebooks adds security to an already fairly secure platform, both by obscurity and design. It’s also helpful for users, as it’s a good idea to have to affirmatively enable a camera every time it wants to turn on rather than remembering whether or not you previously gave permission to Zoom, Meet, Slack, Skype, Teams, GoToMeeting, WebEx, Discord, or other apps.

In some ways, it puts ChromeOS ahead of Windows and macOS, as both rely on individual app permissions without a universal toggle. It’s not a physical kill switch, but it’s as good as it might get without screen-endangering webcam covers, washi tape, or simply never joining meetings. It will, however, likely lead to more than a few “I can hear you, can you hear me?” moments.

Elsewhere in Google’s announcement, ChromeOS crows a bit about how its system meshes with a new set of guidelines issued by the Cybersecurity and Infrastructure Security Agency, National Security Agency, and FBI, “Secure by Design, Secure by Default.” A verified boot process, the executable design, and the nature of Chromebooks as simple gateways to data that is mostly stashed on web servers keep Chrome secure, according to Google. Managed Chromebooks have Data Controls that lock down access to files and data, including copy/paste and screenshot controls. And there’s Google’s prime statistic, that ChromeOS devices have had “zero reported ransomware attacks.”

https://arstechnica.com/?p=1934169




Bastano 12 minuti per violare una password di 8 caratteri


Dal 2020 Hive Systems effettua un’analisi della robustezza delle password, che prende in considerazione lo stato dell’hardware, gli sviluppi del software e gli altri principali parametri che possono incidere sui tempi di violazione da parte di un ipotetico attaccante.

I risultati sono sintetizzati nella Hive Systems Password Table, un’infografica colorata che mostra la relativa forza di una password crittografata contro un tentativo di cracking, in base alla lunghezza della password, alla complessità, all’algoritmo di hashing utilizzato dalla vittima e all’hardware utilizzato dall’attaccante.

I dati si basano su quanto tempo impiegherebbe un attaccante con un budget limitato a violare l’hash della password utilizzando un computer desktop con una scheda grafica di fascia alta e quanto tempo impiegherebbe un attaccante con un budget elevato utilizzando le risorse di calcolo cloud.

Novità nell’hardware

Il primo elemento che emerge dalla nuova edizione della ricerca è la crescita nella potenza di calcolo disponibile: nel 2018, la scheda RTX 2080 aveva una capacità di calcolo pari a circa 37 miliardi di hash al secondo (H/s), generalmente approssimati per eccesso a 40. Nel 2020, la scheda RTX 3090 era in grado di crackare circa 70 miliardi di H/s, che sono saliti a ben 164 con l’avvento della nuova RTX 4090, lanciata lo scorso anno.

Fonte: Hive Systems

Tali risultati dimostrano l’evoluzione costante dell’hardware e la necessità di considerare attentamente le prestazioni degli strumenti utilizzati per valutare la sicurezza delle password.

L’analisi è proseguita passando ad analizzare le prestazioni ottenibili con l’utilizzo di capacità di calcolo via cloud, che dimostra come sia possibile “scalare” rapidamente le prestazioni passando dalle 4 ore della “vecchia” RTX2080 del 2020 a soli 12 minuti utilizzando soltanto 12 Gpu Nvidia A100.

I tempi si riferiscono al calcolo dell’hash MD5 per una password di 8 caratteri che comprenda numeri, caratteri minuscoli e maiuscoli e anche simboli speciali. Naturalmente, questi calcoli sono un massimo teorico, ottenibile nelle condizioni ideali disponendo cioè dell’hash della password da violare.

Fonte: Hive Systems

Il dato che emerge mostra come una password di otto caratteri, anche in presenza di tutte le caratteristiche di robustezza spesso richiesto dai sistemi di autenticazione, non è in grado di garantire un’adeguata protezione.

La potenza di calcolo di ChatGPT

Hive Systems ha anche analizzato l’estremo superiore dello spettro delle capacità di calcolo, ipotizzando di utilizzare per il cracking delle password l’intero sistema che è stato sfruttato per il training di ChatGPT: secondo le dichiarazioni di Microsoft, il supercomputer cloud basato su Azure poteva contare su 10.000 Gpu Nvidia A100.

Fonte: Hive Systems

I tempi di calcolo presunti si abbassano moltissimo, rendendo alla portata degli attaccanti anche le password da 10 o 11 caratteri; perfino 12 caratteri possono essere violati in meno di 8 mesi. In base ai calcoli di Hive Systems, servono almeno 15 caratteri (con rappresentanti di ogni categoria) per stare ragionevolmente tranquilli.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/04/24/bastano-12-minuti-per-violare-una-password-di-8-caratteri/?utm_source=rss&utm_medium=rss&utm_campaign=bastano-12-minuti-per-violare-una-password-di-8-caratteri




OpenAI to Offer Remedies to Resolve Italy’s ChatGPT Ban

The company behind ChatGPT will propose measures to resolve data privacy concerns that sparked a temporary Italian ban on the artificial intelligence chatbot, regulators said Thursday.

The Italian data protection authority, known as Garante, last week blocked San Francisco-based OpenAI’s popular chatbot, ordering it to temporarily stop processing Italian users’ personal information while it investigates a possible breach of European Union data privacy rules.

Experts said it was the first such case of a democracy imposing a nationwide ban on a mainstream AI platform.

In a video call late Wednesday between the watchdog’s commissioners and OpenAI executives including CEO Sam Altman, the company promised to set out measures to address the concerns. Those remedies have not been detailed.

The Italian watchdog said it didn’t want to hamper AI’s development but stressed to OpenAI the importance of complying with the 27-nation EU’s stringent privacy rules.

The regulators imposed the ban after some users’ messages and payment information were exposed to others. They also questioned whether there’s a legal basis for OpenAI to collect massive amounts of data used to train ChatGPT’s algorithms and raised concerns the system could sometimes generate false information about individuals.

So-called generative AI technology like ChatGPT is “trained” on huge pools of data, including digital books and online writings, and able to generate text that mimics human writing styles.

These systems have created buzz in the tech world and beyond, but they also have stirred fears among officials, regulators and even computer scientists and tech industry leaders about possible ethical and societal risks.

Other regulators in Europe and elsewhere have started paying more attention after Italy’s action.

[ Read: ChatGPT, the AI Revolution, and the Security, Privacy and Ethical Implications ]

Ireland’s Data Protection Commission said it’s “following up with the Italian regulator to understand the basis for their action and we will coordinate with all EU Data Protection Authorities in relation to this matter.”

France’s data privacy regulator, CNIL, said it’s investigating after receiving two complaints about ChatGPT. Canada’s privacy commissioner also has opened an investigation into OpenAI after receiving a complaint about the suspected “collection, use and disclosure of personal information without consent.”

In a blog post this week, the U.K. Information Commissioner’s Office warned that “organizations developing or using generative AI should be considering their data protection obligations from the outset” and design systems with data protection as a default.

“This isn’t optional — if you’re processing personal data, it’s the law,” the office said.

In an apparent response to the concerns, OpenAI published a blog post Wednesday outlining its approach to AI safety. The company said it works to remove personal information from training data where feasible, fine-tune its models to reject requests for personal information of private individuals, and acts on requests to delete personal information from its systems.

Related: ChatGPT Data Breach Confirmed as Security Firm Warns of Vulnerable Component Exploitation

Related: Microsoft Puts ChatGPT to Work on Automating Cybersecurity

Related: ChatGPT Integrated Into Cybersecurity Products as Industry Tests Its Capabilities

https://www.securityweek.com/openai-to-offer-remedies-to-resolve-italys-chatgpt-ban/




Cybersecurity: le sfide aumenteranno, ma anche le opportunità per i CISO


Le sfide di cybersecurity non fanno che aumentare: gli ultimi due anni hanno messo a dura prova i team di sicurezza informatica, ma le difficoltà non sono finite. I responsabili di sicurezza, i chief information security officers (CISO), devono guardare con un occhio al presente e con uno al futuro per anticipare le possibili minacce degli anni a venire e farsi trovare pronti per affrontarle.

A dirlo sono gli esperti di sicurezza di Gartner che hanno analizzato e discusso il futuro della cybersicurezza e individuato le tendenze per i prossimi anni. Richard Addiscott, Senior Director Analyst, e Lisa Neubauer, Senior Director Advisory di Gartner, hanno presentato i risultati dell’analisi e individuato le principali previsioni e indicazioni di sicurezza per aiutare i CISO a definire delle strategie d’azione.

La cybersecurity è umano-centrica

Secondo l’indagine di Gartner, il 90% dei dipendenti che ha ammesso di aver eseguito azioni non sicure sul posto di lavoro era consapevole di farlo e di mettere l’intera azienda a rischio. Nei prossimi anni i CISO tenderanno a sviluppare pratiche di sicurezza che pongano al centro l’essere umano per minimizzare le frizioni dei dipendenti e massimizzare il controllo sulle loro azioni.

cybersecurity

Pixabay

I leader di sicurezza dovranno fare attenzione anche alle tecnologie al di fuori del loro controllo: secondo l’analisi dell’azienda, entro il 2027 il 75% dei dipendenti utilizzerà strumenti che sfuggono alla visibilità del reparto IT. In questo caso è fondamentale collaborare coi dipendenti per assicurarsi che abbiano le giuste conoscenze di sicurezza.

Attenzione anche alla qualità del lavoro dei CISO stessi: per Gartner entro il 2025 quasi la metà dei leader di cybersecurity cambierà lavoro a causa di livelli elevati di stress. Ove possibile i leader devono cercare di creare una buona cultura di sicurezza informatica per facilitare le proprie mansioni e ricevere il supporto adeguato.

Fortunatamente i CISO potranno contare su una maggiore inclusione nelle board manageriali per promuovere le loro idee: entro il 2026, il 70% dei reparti dirigenziali includeranno almeno un membro con esperienza di cybersecurity.

Investire su privacy e insight aziendali

I leader di cybersecurity non possono ignorare gli impatti di regole sempre più stringenti sulla privacy dei dati: entro un anno le normative copriranno la maggior parte dei dati dei consumatori. Per sopravvivere è necessario definire uno standard di privacy che possa differenziare la propria azienda dalle altre e creare un rapporto solido di fiducia con i clienti.

cybersecurity

Freepik

Gartner prevede una maggiore adozione di programmi zero-trust e invita i leader di sicurezza a seguire il prima possibile questa tendenza. Poiché il programma può diventare complesso, l’azienda consiglia di procedere un passo alla volta e introdurre gradualmente le componenti della soluzione.

Al fine di convincere il business a prendere decisioni strategiche che tengano in considerazione i rischi di sicurezza, i CISO devono essere in grado di quantificare i risultati delle loro analisi in termini di risparmi e conseguenze sulla stabilità dell’azienda.

Infine, un elemento chiave per avere successo nella prevenzione e risposta alle minacce è comprendere a fondo la superficie d’attacco aziendale e usare gli insight per sviluppare piani d’azione efficaci. Entro i prossimi tre anni sempre più team di sicurezza sfrutteranno questa conoscenza per potenziare le capacità di identificazione, investigazione e risposta alle minacce.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/04/05/cybersecurity-sfide-opportunita-ciso/?utm_source=rss&utm_medium=rss&utm_campaign=cybersecurity-sfide-opportunita-ciso