Safari and iOS users: Your browsing activity is being leaked in real time

Safari and iOS users: Your browsing activity is being leaked in real time
Getty Images

For the past four months, Apple’s iOS and iPadOS devices and Safari browser have violated one of the Internet’s most sacrosanct security policies. The violation results from a bug that leaks user identities and browsing activity in real time.

The same-origin policy is a foundational security mechanism that forbids documents, scripts, or other content loaded from one origin—meaning the protocol, domain name, and port of a given webpage or app—from interacting with resources from other origins. Without this policy, malicious sites—say, badguy.example.com—could access login credentials for Google or another trusted site when it’s open in a different browser window or tab.

Obvious privacy violation

Since September’s release of Safari 15 and iOS and iPadOS 15, this policy has been broken wide open, research published late last week found. As a demo site graphically reveals, it’s trivial for one site to learn the domains of sites open in other tabs or windows, as well as user IDs and other identifying information associated with the other sites.

“The fact that database names leak across different origins is an obvious privacy violation,” wrote Martin Bajanik, a software engineer at FingerprintJS, a startup that makes a device identification interface for anti-fraud purposes. He continued:

It lets arbitrary websites learn what websites the user visits in different tabs or windows. This is possible because database names are typically unique and website-specific. Moreover, we observed that in some cases, websites use unique user-specific identifiers in database names. This means that authenticated users can be uniquely and precisely identified.

Attacks work on Macs running Safari 15 and on any browser running on iOS or iPadOS 15. As the demo shows, safarileaks.com is able to detect the presence of more than 20 websites—Google Calendar, YouTube, Twitter, and Bloomberg among them—open in other tabs or windows. With more work, a real-world attacker could likely find hundreds or thousands of sites or webpages that can be detected.

When users are logged in to one of these sites, the vulnerability can be abused to reveal the visit and, in many cases, identifying information in real time. When logged in to a Google account open elsewhere, for instance, the demo site can obtain the internal identifier Google uses to identify each account. Those identifiers can usually be used to recognize the account holder.

Raising awareness

The leak is the result of the way the Webkit browser engine implements IndexedDB, a programming interface supported by all major browsers. It holds large amounts of data and works by creating databases when a new site is visited. Tabs or windows that run in the background can continually query the IndexedDB API for available databases. This allows one site to learn in real time what other websites a user is visiting.

Websites can also open any website in an iframe or pop-up window in order to trigger an IndexedDB-based leak for that specific site. By embedding the iframe or popup into its HTML code, a site can open another site in order to cause an IndexedDB-based leak for the site.

“Every time a website interacts with a database, a new (empty) database with the same name is created in all other active frames, tabs, and windows within the same browser session,” Bajanik wrote. “Windows and tabs usually share the same session, unless you switch to a different profile, in Chrome for example, or open a private window.”

[embedded content]
How IndexedDB in Safari 15 leaks your browsing activity (in real time).

Bajanik said he notified Apple of the vulnerability in late November, and as of publication time, it still had not been fixed in either Safari or the company’s mobile OSes. Apple representatives didn’t respond to an email asking if or when it would release a patch. As of Monday, Apple engineers had merged potential fixes and marked Bajanik’s report as resolved. End users, however, won’t be protected until the Webkit fix is incorporated into Safari 15 and iOS and iPadOS 15.

For now, people should be wary when using Safari for desktop or any browser running on iOS or iPadOS. This isn’t especially helpful for iPhone or iPad users, and in many cases, there’s little or no consequence of browsing activities being leaked. In other situations, however, the specific sites visited and the order in which they were accessed can say a lot.

“The only real protection is to update your browser or OS once the issue is resolved by Apple,” Bajanik wrote. “In the meantime, we hope this article will raise awareness of this issue.”

https://arstechnica.com/?p=1826566




Privacy: quali sfide e quali trend per il 2022?

Non c’è dubbio che gli ultimi anni siano stati forieri di grandi novità in ambito Privacy, ma il 2022 si propone già come un crocevia fondamentale per una serie di questioni di importanza vitale per le aziende, locali ed internazionali ed un anno di passaggio verso l’avvento di ulteriori importanti normative.

Un anno, forse l’ultimo utile, per pianificare il cambiamento aziendale e prepararsi ai nuovi paradigmi che dovremo affrontare nel breve-medio periodo, e un anno in cui avvalersi di esperti di Trasformazione Digitale e Legal-Tech per mettere in pratica il cambiamento necessario.

Ma quali sono i principali Trend che ci troveremo ad affrontare? Eccone alcuni che non possiamo sottovalutare!

L’aumento dello scrutinio intorno al ransomware e ad altri attacchi informatici

Il 2022 probabilmente porterà con sé un’azione continua da parte dei governi per affrontare le questioni relative non solo al Ransomware e ai Cryptolocker, un fenomeno in continua ascesa, quanto alle problematiche connesse ai pagamenti dei riscatti, compreso il ruolo delle criptovalute e la necessità di informazione/cooperazione con le forze dell’ordine prima di effettuare un pagamento di riscatto. Non così distante l’ipotesi, ventilata già negli Statu Uniti, di sanzioni commerciali alle realtà che decideranno di pagare, incentivando in questo modo la pratica, in modo non dissimile dalle norme che regolano il pagamento di riscatti in caso di rapimenti.

Ci si aspetta inoltre un’ulteriore collaborazione tra i governi per coordinare l’abbattimento delle grandi “gang” di ransomware, divenute già un problema se non globale sicuramente transnazionali, oltre ad un continuo progressivo irrigidimento del mercato delle assicurazioni informatiche, che è già iniziato nell’UE, rendendo l’ottenimento di nuove polizze informatiche più difficile e il premio di base più costoso, offrendo al contempo una copertura meno completa, compresa la richiesta agli assicurati di corrispondere ogni somma pagata per un riscatto.

Le aziende devono essere sempre più pronte a rispondere ad un evento di data-breach, sia con policy ad hoc, sia istituendo esercitazioni e procedure, sia creando un apposito comitato di crisi pronto all’occorrenza. Anche le coperture assicurative e legali vanno modulate per essere in linea con le nuove sfide.

Maggiori obblighi di conformità alla privacy negli Stati Uniti e all’estero

La Privacy si sta spostando dall’essere un “problema” precipuamente europeo-centrico all’essere una questione globale, con differenze sottili – ma sostanziali – in varie giurisdizioni.

È il momento, oltre al GDPR, del California Privacy Rights Act (CPRA), il Virginia Consumer Data Privacy Act (VCDPA) e il Colorado Privacy Act (ColoPA) che entreranno in vigore nel 2023, e di più di una dozzina di altri stati americani che proporranno leggi statali sulla privacy nel 2022, il che significherà una maggiore complessità sul fronte della conformità per le aziende che operano negli Stati Uniti.

Inoltre, per quelle aziende che operano globalmente, altre necessità diventano impellenti: dovranno infatti continuare ad allineare le loro operazioni con la legge cinese sulla protezione dei dati personali (PIPL) e la Lei Geral de Proteção de Dados Pessoais (LGPD) del Brasile, dovranno iniziare ad apportare le modifiche necessarie per allinearsi al Quebec Bill 64 (An Act to Modernize Legislative Provisions as regards the Protection of Personal Information) che entrerà in vigore in tre fasi nei prossimi tre anni e include sanzioni simili al GDPR e dovranno stare in guardia per le nuove leggi sulla privacy nel Regno Unito, India, Australia e Canada.

Le aziende devono quindi dotarsi di frameworks flessibili di gestione dei consensi e dei trattamenti in grado di operare in un contesto internazionale, e di realtà consulenziali che possano assisterle al meglio nella implementazione legale-tecnologica dei regolamenti.

Aumento delle restrizioni sui trasferimenti di dati transfrontalieri

I paesi di tutto il mondo stanno diventando sempre più restrittivi per quanto riguarda il movimento e il trasferimento dei dati personali. Il 2022 porterà probabilmente ulteriori restrizioni (e in alcuni casi divieti) sulla capacità di trasferire i dati personali al di fuori dei confini di taluni Paesi.

Ci si attende di vedere una legislazione e una regolamentazione più orientata al territorio e alla sovranità digitale, e meno armonizzazione intorno agli standard di trasferimento transfrontaliero della privacy dei dati da e verso la UE, dove la regolamentazione restrittiva dei trasferimenti di dati transfrontalieri ha probabilmente raggiunto il suo picco. Ci si attende inoltre una una maggiore applicazione di queste regole, ma forse anche un percorso più strutturato per gli scambi di dati tra differenti “silos” regionali, con una serie di Privacy Shield tra grandi macro realtà. Questo per lo meno fino a quando il signor Schrems deciderà (se mai lo farò) di tornare sul palco.

Per non restituire un quadro però troppo severo è da sottolineare che il tema è comunque rilevante anche come impegno da parte dei differenti stati, come dimostra ad esempio l’adozione della decisione di adeguatezza per i trasferimenti dati da UE a South Corea dello scorso dicembre.

Per venire incontro a queste mutate necessità e paradigmi di silos di dati è assolutamente fondamentale che le aziende che implementano repository più o meno complessi si muovano per tempo per trovare architetture tecniche, legali e infrastrutturali che possano supportarle in un mondo multi-tenant di dati. E la soluzione arriva ancora una volta dal connubio legal-tech.

Più normative (e più severe) sulla disclosure dei breach di sicurezza

Le agenzie governative probabilmente emetteranno regolamenti più specifici e requisiti più stringenti in merito all’obbligo di segnalazione delle violazioni, compresa l’emanazione di norme e tempistiche più severe per la notifica alle autorità di incidenti significativi di cybersecurity. Le aziende che non hanno adeguatamente divulgato i rischi e rispettato i requisiti di notifica saranno sicuramente bersaglio di azioni di sanzione e condanna, soprattutto in virtù del fatto che sempre più governi cercano usare “casi esemplari” per convincere alla adozione di misure significative di gestione del rischio. Non solamente questo, ma soprattutto in UE, ci si deve aspettare maggiore ingerenza dei Comitati centrarli per “scavalcare” le autorità nazionali per la protezione dei dati se le sanzioni di tali autorità sembrassero essere insufficienti.

Ancora una volta le aziende devono prepararsi per tempo, con metodologie e esercitazioni, a gestire efficacemente e in tempi ristrettissimi le normative sempre più stringenti di comunicazione dei breach, avvalendosi non solo di professionalità adeguate in caso di breach, ma preparandosi per tempo con esercitazioni specifiche, policy e linee guida operative.

Maggiore attenzione su AdTech, Advertising e Data Monetization

I regolatori e i media esamineranno sempre più da vicino l’uso di AdTech, tecnologia per tracciare e profilare gli utenti online a fine pubblicitario, ed oltre alla “prima ondata” di compliance con le implementazioni relative ai Cookies, il 2022 dovrebbe anche portare una maggiore attenzione da parte delle aziende AdTech ad abbracciare modelli di business orientati alla privacy nel tentativo di affrontare le mutevoli aspettative ed esplorare tecnologie.

Non solo abbracciare tecnologie nuove (come blockchain, tokenization, e algorithmic audience) progettate per diminuire la quantità di dati personali che raccolgono e trasmettono., ma anche comprendere come sfruttare al meglio la “crisi” del passato per abbracciare il futuro di Data Monetization (monetizzazione delle abitudini, dei comportamenti e dei dati degli utenti) che già grandi realtà si stanno preparando a cavalcare.

E se il Regolamento ePrivacy dell’UE verrà finalizzato nel 2022, le aziende dovranno prepararsi per la sua – rivoluzionaria – entrata in vigore due anni dopo, cioè al più presto nel 2024.

In questo caso le aziende dovranno approntare un cambiamento epocale nella gestione dei flussi informativi per pubblicità, marketing e monetizzazione, andando ad approcciare nuovi modelli di business basati sulla monetizzazione dei dati, con relative verifiche preliminari di conformità e interazione tecnologica/legale.

Un anno quindi di fondamentali punti da smarcare in ambito aziendale, che vedono sempre più preponderanti le interazioni tra mondo legale e mondo tecnologico, che paiono non essere più in alcun modo svincolabili e che necessitano di figure preparate in entrambi. Mai come in questi prossimi anni la parola legal-tech sarà sulla bocca della consulenza, perché solo da questo paradigma si potranno sviluppare le strategie di business vincenti per svoltare (in meglio) gli obiettivi aziendali alla luce dei cambiamenti all’orizzonte.

https://www.key4biz.it/privacy-quali-sfide-e-quali-trend-per-il-2022/387926/




Apple reaches quiet truce over iPhone privacy changes

A privacy notice appears on an iPhone 12 under the new iOS 14.5.1 operating system. Developers of an application have to ask for the user's permission to allow cross-app tracking.
Enlarge / A privacy notice appears on an iPhone 12 under the new iOS 14.5.1 operating system. Developers of an application have to ask for the user’s permission to allow cross-app tracking.
Picture Alliance | Getty Images

Apple has allowed app developers to collect data from its 1 billion iPhone users for targeted advertising, in an unacknowledged shift that lets companies follow a much looser interpretation of its controversial privacy policy.

In May Apple communicated its privacy changes to the wider public, launching an advert that featured a harassed man whose daily activities were closely monitored by an ever-growing group of strangers. When his iPhone prompted him to “Ask App Not to Track,” he clicked it and they vanished. Apple’s message to potential customers was clear—if you choose an iPhone, you are choosing privacy.

But seven months later, companies including Snap and Facebook have been allowed to keep sharing user-level signals from iPhones, as long as that data is anonymised and aggregated rather than tied to specific user profiles.

For instance Snap has told investors that it plans to share data from its 306 million users—including those who ask Snap “not to track”—so advertisers can gain “a more complete, real-time view” on how ad campaigns are working. Any personally identifiable data will first be obfuscated and aggregated.

Similarly, Facebook operations chief Sheryl Sandberg said the social media group was engaged in a “multiyear effort” to rebuild ad infrastructure “using more aggregate or anonymized data”.

These companies point out that Apple has told developers they “may not derive data from a device for the purpose of uniquely identifying it.” This means they can observe “signals” from an iPhone at a group level, enabling ads that can still be tailored to “cohorts” aligning with certain behavior but not associated with unique IDs.

This type of tracking is becoming the norm. Oren Kaniel, the chief executive of AppsFlyer, a mobile attribution platform that works with app developers, said that when his company introduced such a “privacy-centric” tool based on aggregated measurement in July 2020, “the level of pushback that we received from the entire ecosystem was huge.”

But now such aggregated solutions are the default for 95 percent of his clients. “The market changed their minds in a radical way,” he said.

It is not clear whether Apple has actually blessed these solutions. Apple declined to answer specific questions for this article but described privacy as its North Star, implying it was setting a general destination rather than defining a narrow pathway for developers.

Cory Munchbach, chief operating officer at customer data platform BlueConic, said Apple had to stand back from a strict reading of its rules because the disruption to the mobile ads ecosystem would be too great.

“Apple can’t put themselves in a situation where they are basically gutting their top-performing apps from a user-consumption perspective,” she said. “That would ultimately hurt iOS.”

For anyone interpreting Apple’s rules strictly, these solutions break the privacy rules set out to iOS users.

Lockdown Privacy, an app that blocks ad trackers, has called Apple’s policy “functionally useless in stopping third-party tracking.” It performed a variety of tests on top apps and observed that personal data and device information is still “being sent to trackers in almost all cases.”

But the companies aggregating user-level data said the reason apps continue to “leak” information such as a user’s IP address and location was simply because some require such information to function. Advertisers must know certain things such as the user’s language or the device screen size, otherwise the app experience would be awful.

The risk is that by allowing user-level data to be used by opaque third parties so long as they promise not to abuse it, Apple is in effect trusting the very same groups that chief executive Tim Cook has lambasted as “hucksters just looking to make a quick buck.”

Companies will pledge that they only look at user-level data once it has been anonymized, but without access to the data or algorithms working behind the scenes, users won’t really know if their data privacy has been preserved, said Munchbach.

“If historical precedent in adtech holds, those black boxes hide a lot of sins,” she said. “It’s not unreasonable to assume it leaves a lot to be desired.”

© 2021 The Financial Times Ltd. All rights reserved Not to be redistributed, copied, or modified in any way.

https://arstechnica.com/?p=1818800




DuckDuckGo wants to stop apps tracking you on Android

Gabriel Weinberg, creator of DuckDuckGo.
Enlarge / Gabriel Weinberg, creator of DuckDuckGo.
Washington Post | Getty Images

At the end of April, Apple’s introduction of App Tracking Transparency tools shook the advertising industry to its core. iPhone and iPad owners could now stop apps from tracking their behavior and using their data for personalized advertising. Since the new privacy controls launched, almost $10 billion has been wiped from the revenues of Snap, Meta Platform’s Facebook, Twitter, and YouTube.

Now, a similar tool is coming to Google’s Android operating system—although not from Google itself. Privacy-focused tech company DuckDuckGo, which started life as a private search engine, is adding the ability to block hidden trackers to its Android app. The feature, dubbed “App Tracking Protection for Android,” is rolling out in beta from today and aims to mimic Apple’s iOS controls. “The idea is we block this data collection from happening from the apps the trackers don’t own,” says Peter Dolanjski, a director of product at DuckDuckGo. “You should see far fewer creepy ads following you around online.”

The vast majority of apps have third-party trackers tucked away in their code. These trackers monitor your behavior across different apps and help create profiles about you that can include what you buy, demographic data, and other information that can be used to serve you personalized ads. DuckDuckGo says its analysis of popular free Android apps shows more than 96 percent of them contain trackers. Blocking these trackers means Facebook and Google, whose trackers are some of the most prominent, can’t send data back to the mothership—neither will the dozens of advertising networks you’ve never heard of.

From a user perspective, blocking trackers with DuckDuckGo’s tool is straightforward. App Tracking Protection appears as an option in the settings menu of its Android app. For now, you’ll see the option to get on a waitlist to access it. But once turned on, the feature shows the total number of trackers blocked in the last week and gives a breakdown of what’s been blocked in each app recently. Open up the app of the Daily Mail, one of the world’s largest news websites, and DuckDuckGo will instantly register that it is blocking trackers from Google, Amazon, WarnerMedia, Adobe, and advertising company Taboola. An example from DuckDuckGo showed more than 60 apps had tracked a test phone thousands of times in the last seven days.

My own experience bore that out. Using a box-fresh Google Pixel 6 Pro, I installed 36 popular free apps—some estimates claim people install around 40 apps on their phones—and logged into around half of them. These included the McDonald’s app, LinkedIn, Facebook, Amazon, and BBC Sounds. Then, with a preview of DuckDuckGo’s Android tracker blocking turned on, I left the phone alone for four days and didn’t use it at all. In 96 hours, 23 of these apps had made more than 630 tracking attempts in the background.

Using your phone on a daily basis—opening and interacting with apps—sees a lot more attempted tracking. When I opened the McDonald’s app, trackers from Adobe, cloud software firm New Relic, Google, emotion-tracking firm Apptentive, and mobile analytics company Kochava tried to collect data about me. Opening the eBay and Uber apps—but not logging into them—was enough to trigger Google trackers.

https://arstechnica.com/?p=1814467




New ‘SharkBot’ Android Banking Malware Hitting U.S., UK and Italy Targets

A new Android banking trojan has been found, targeting international banks from the United Kingdom and Italy (including in the U.S.). and five different cryptocurrency services. Twenty-two instances have been discovered, but more are expected.

The malware, first detected at the end of October 2021, appears to be new and still being developed. It was discovered by Cleafy, a Milan, Italy-based online fraud detection and prevention firm. Cleafy calls it ‘SharkBot’, named after the frequency of the word ‘sharked’ in its binaries.

SharkBot is not found in Google’s official marketplace. This means it must be sideloaded by delivering the APK to the device and ensuring it is manually loaded. In a technical analysis of the malware, Cleafy notes that it poses as a legitimate application using common names and icons.

If the deception succeeds and the malware is installed, it immediately attempts to enable Android’s Accessibility Services by delivering fake pop-ups to the victim – such as ‘Allow Media Player to have full control of your device’. If this is successful, SharkBot has all the permissions it needs. 

Once accepted the malware can enable keylogging (to steal typed credentials), intercept SMS messages (to circumvent MFA), deliver overlay attacks (to steal login credentials and credit card information) and remotely control the device because permissions were granted via the fake pop-up. “Basically,” comments Corey Nachreiner, CSO at WatchGuard Technologies, “the malicious Accessibility Services can read anything a user can read and can recreate any action a user can on the device.”

Notably, SharkBot also attempts a relatively novel technique known as an Automatic Transfer Systems (ATS) attack. “This technique has been seen recently from other banking trojans, such as Gustuff,” explains Cleafy. “ATS is an advanced attack technique (fairly new on Android) which enables attackers to auto-fill fields in legitimate mobile banking apps and initiate money transfers from the compromised devices.” 

The ATS functionality is contained in a module downloaded separately from the C2. “Given its modular architecture,” comments Cleafy, “we don’t exclude the existence of botnets with other configurations and targets.”

[ READ: Android Trojan Targets Banks, Crypto-Currencies, e-Commerce

The assumption is that ATS is used by SharkBot to bypass the behavioral detection measures used by many financial institutions. If ATS is used on what is a trusted device, a ‘new device enrollment’ phase is not necessary, SMS-based MFA can be bypassed,  and behavioral biometrics are not effective.

Although relatively few instances of SharkBot have been discovered in the wild, Cleafy suspects that the threat will grow. This is partly because it is new, and apparently still being developed.  

“The implications of becoming infected with SharkBot could be severe, so it’s important,” says Nachreiner, “to avoid being infected altogether.” This is not yet easy. The malware is new and not well detected by existing detection means. Apart from the DGA for its C2s, it also uses anti-analysis techniques including obfuscated strings and emulator detection.

The best solution is to avoid side-loading religiously. Without 100% certainty in the authenticity of the application and the validity of its source, simply do not install it. 

Related: Android Banking Trojan ‘Vultur’ Abusing Accessibility Services

Related: Android Trojan Targets Banks, Crypto-Currencies, e-Commerce

Related: Automatic Transfer System Evades Security Measures, Automates Bank Fraud

view counter

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Previous Columns by Kevin Townsend:
Tags:

https://www.securityweek.com/new-%E2%80%98sharkbot%E2%80%99-android-banking-malware-hitting-us-uk-and-italy-targets




Privacy e wearable, il lato oscuro dei dispositivi indossabili

Rubrica settimanale SosTech, frutto della collaborazione tra Key4biz e SosTariffe. Per consultare gli articoli precedenti, clicca qui.

Fra tutte le profezie futuribili di qualche decennio fa, forse quella dei wearable era la più scontata. Non c’è quasi romanzo o film di fantascienza che non mostri il protagonista interagire con un orologio digitale, degli occhiali speciali o altri dispositivi nati per essere indossati per accedere a una varietà di funzioni. Puntualmente, il wearable, negli anni passati, è diventato realtà, anche se accompagnato da una dose di scetticismo superiore a quella degli altri oggetti (smartphone in primis) che definiscono le nostre nuove routine. Ma pazienti e ostinati, anche gli indossabili si sono conquistati a poco a poco la nostra fiducia, e ci accompagnano durante le nostre sessioni di corsa o misurano quanti piani di scale abbiamo fatto, controllano il battito cardiaco e ci consentono perfino di telefonare o interagire con messaggi. L’implementazione di sensori biometrici sempre più avanzati unito all’arrivo di speciali e-SIM per Internet mobile (su SOSTariffe.it si possono trovare le più convenienti) ha aperto al mondo gli smartwatch che si vedono sempre più spesso al polso non solo degli sportivissimi. I numeri parlano chiaro: il mercato globale delle tecnologie indossabili passerà, secondo le previsioni, dai 116,2 miliardi del 2021 ai 265,4 miliardi del 2026, in Europa da 2,514 miliardi a 5,950 miliardi. Nel 2022, si calcola che un miliardo di consumatori potranno accedere a dispositivi indossabili. Eppure, ci sono anche degli aspetti sui quali è legittimo essere più perplessi.

Privacy e wearable: chi controlla i nostri spostamenti?

Il primo, naturalmente, è legato alla grande questione degli ultimi decenni: la privacy. Mentre le grandi società hi-tech, incalzate dai governi, fanno rapidamente dietrofront rispetto alle condotte adottate tradizionalmente – Facebook cambia nome e promette una maggior cura dei dati sensibili rispetto a quella (disastrosa) della gestione fino ad oggi, Apple fa infuriare i produttori di app che fatturano tramite la pubblicità inserendo nel sistema, alla prima apertura, un avviso che permette all’utente di scegliere se e quali dati fornire – i dispositivi indossabili appaiono potenzialmente molto efficaci per il controllo di ogni movimento dell’utente. Avere sempre il GPS attivo è molto utile se vogliamo misurare le calorie che perdiamo ogni giorno, ma allo stesso tempo in teoria rivela i nostri spostamenti, le nostre abitudini, i luoghi che frequentiamo più spesso. Sapere chi controlla i nostri dati, e che politica adotta riguardo ad essi, è essenziale, e non si può dire che fino ad ora i big dell’industria digitale siano stati un esempio di correttezza e trasparenza. Ma c’è anche altro.

Privacy e wearable: il “digital divide” della salute

Basta guardare una qualsiasi presentazione di smartwatch per capire che il fattore su cui le aziende stanno puntando maggiormente negli ultimi tempi non è tanto la potenzialità per lo sport e l’attività fisica, ma per il controllo medico. La pandemia ha ulteriormente acuito l’attenzione alla propria salute, e il ricorso massiccio ad apparecchi come i saturimetri per controllare l’ossigenazione del sangue ha convinto anche i più scettici sull’importanza di non perdere di vista i propri dati vitali; i wearable permettono proprio questo grazie a funzionalità sempre più sofisticate, che consentono di effettuare un elettrocardiogramma al volo, valutare aritmie cardiache o respiratorie, studiare i cicli del sonno e in futuro chissà che altro. Ma, allo stesso tempo, si tratta di dispositivi costosi, a volte molto; e se ormai uno smartphone costa poco più di un centinaio di euro ed è quasi indispensabile per chiunque anche solo per motivi di comunicazione, uno smartwatch è in media più costoso, se di buona qualità, e appare ancora fondamentalmente uno sfizio. In altre parole, è un regalo per benestanti, anche per la maggior cura verso sé stessi che di solito hanno le persone con più denaro e una migliore educazione; un dato che rischia di acuire ulteriormente il già ampio gap tra chi può permettersi cure di qualità e che invece, per reddito e istruzione, ne è tagliato fuori.

Un recente studio ha mostrato che le persone con uno status socioeconomico inferiore hanno sovente una minore alfabetizzazione per quanto riguarda la “salute elettronica”, in quanto senza denaro sufficiente per comprarsi uno di questi dispositivi o senza le conoscenze necessarie per utilizzarli nel modo migliore. Il problema è che la tutela della salute si concentra sempre di più sulla digitalizzazione dei comportamenti e della raccolta dei dati, grazie all’introduzione di sistemi che permettono di monitorare le condizioni dei pazienti anche quando si trovano a casa e lontano da un istituto di cura, senza contare i registri digitali per le cartelle cliniche e un sempre maggior supporto alla telemedicina, che allo stesso tempo rende possibile effettuare interventi a distanza ma richiede l’adozione di apparecchiature dal costo non indifferente. Tutto questo rischia di tradursi in una cura della salute sempre più sofisticata per i ricchi e viceversa un’attenzione molto minore al benessere di chi ha meno mezzi.

Ma gli “indossabili“ ci proteggono

Naturalmente, è ovvio che questi motivi di perplessità vadano analizzati con la massima attenzione ma senza che questo significhi una mancata adozione dei wearable e dei loro vantaggi, anche perché se c’è una cosa che la storia insegna in materia di novità tecnologiche è che è molto difficile tornare indietro; perfino ciò che sembrava un flop epocale qualche anno fa, i Google Glasses, non cessa di rispuntare sotto altra forma, come i Ray-Ban Stories di Facebook (ora Meta), ed è assai probabile che ci abitueremo anche all’utilizzo di occhiali digitali anche se ci vediamo benissimo.

Non sempre, inoltre, la tecnologia segue i percorsi che avevamo previsto. Sono sempre di più le startup dedicate alla sicurezza sul lavoro tramite tecnologia indossabile che raccolgono investimenti miliardari, man mano che i dispositivi diventano più piccoli, meno cari e più leggeri, e diventano un aiuto indispensabile per chi svolge lavori di precisione o molto pericolosi, con sensori in grado di indicare un livello di stress termico pericoloso, la perdita di attenzione in un momento cruciale o un’eccessiva sollecitazione di una parte del corpo. I wearable sono indubbiamente qui per restare, bisognerà non smettere di fare attenzione a come gestirli.

https://www.key4biz.it/privacy-e-wearable-il-lato-oscuro-dei-dispositivi-indossabili/382714/




Zoom Patches High-Risk Flaws in Meeting Connector, Keybase Client

Video messaging technology giant Zoom has shipped patches for high-severity vulnerabilities that expose enterprise users to remote code execution and command injection attacks.

The company released multiple security bulletins to warn of the risks and called special attention to a pair of “high-risk” bugs affecting its on-prem meeting connector software and the popular Keybase Client.

“The network proxy page on the web portal for the [affected] products fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator,” Zoom said in a note.

The CVE-2021-34417 carries a CVSS Base Score of 7.9, and affects multiple Zoom software components — Zoom On-Premise Meeting Connector Controller, Zoom On-Premise Meeting Connector MMR, Zoom On-Premise Recording Connector, Zoom On-Premise Virtual Room Connector. 

[ READ: Vulnerability Allowed Attackers to Join Zoom Meetings ]

A second high-severity bulletin was also released with patches for CVE-2021-34422, a path traversal bug affecting Keybase Client for Windows.

From Zoom’s advisory:

“The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder. A malicious user could upload a file to a shared folder with a specially crafted file name which could allow a user to execute an application which was not intended on their host machine.” 

“If a malicious user leveraged this issue with the public folder sharing feature of the Keybase client, this could lead to remote code execution.”

Zoom said the issue was fixed in the 5.7.0 Keybase Client for Windows release.  

Zoom’s security response team also shipped patches for a medium-risk bug (CVE-2021-34420) in the Zoom Client for Meetings installer.  “The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer,” the company warned.

The Zoom software does not have an automatic update mechanism.  Users are urged to manually check for software updates within the Zoom client.

Related: Remote Code Execution Flaw in Palo Alto GlobalProtect VPN

Related: Adobe Patches Critical RoboHelp Server Security Flaw

Related: Zero-Days Under Attack: Microsoft Plugs Exchange Server, Excel Holes

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

https://www.securityweek.com/zoom-patches-high-risk-flaws-meeting-connector-keybase-client




U.S. Gov Announces Support for ‘Paris Call’ Cybersecurity Effort

United States Vice President Kamala Harris on Wednesday formally announced support for the Paris Call for Trust and Security in Cyberspace, an international collaborative initiative aimed at advancing cybersecurity.

Issued in 2018, the Paris Call details nine principles to improve stability in cyberspace through global collaboration, and has been already signed by 79 countries.

The principles promoted by the Call include:

  • Protecting individuals and infrastructure
  • Protecting against activity that affects the availability of the Internet
  • Protecting the electoral process
  • Protecting intellectual property
  • Preventing the proliferation of malware and nefarious practices
  • Improving the security of digital processes, products and services
  • Strengthening an advanced cyber hygiene
  • Preventing non-state actors from hacking back
  • Promoting international norms in cyberspace

Through supporting the Call, the United States said it will commit to advancing cybersecurity and preserving an open and reliable Internet.

Vice President Harris said the U.S. will work with France and other countries, as well as with private companies and civil society globally to promote responsible behavior in cyberspace.

“This includes working with like minded countries to attribute and hold accountable States that engage in destructive, disruptive, and destabilizing cyber activity,” according to a White House statement.

The decision to support the Call falls in line with the U.S. government’s current effort to improve cybersecurity for both individuals and businesses and to accelerate international cooperation to combat cybercrime.

Related: US Bans China Telecom Over National Security Concerns

Related: Nations Vow to Combat Ransomware at US-Led Summit

Related: US to Curb Hacking Tool Exports to Russia, China

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/us-gov-announces-support-paris-call-cybersecurity-effort




Privacy, il 25 novembre Forum Nazionale dei DPO e Responsabili della Conservazione (RDC)

Giovedì 25 novembre si terrà il Forum nazionale dei DPO e Responsabili della Conservazione ideato e promosso da ANORC organizzato da Digital & Law e trasmesso gratuitamente in diretta streaming su piattaforma DIG.eat.

Il Forum intende proprio favorire un confronto pratico su problemi di grande rilevanza tra Data Protection Officer (DPO) e Responsabili della Conservazione (RDC) invitati a confrontarsi sull’esperienza maturata nel campo, per quanto attiene nello specifico la gestione di attacchi informatici e data breach. L’incontro sarà l’occasione per condividere le best practices utili a gestire e comunicare in maniera adeguata gli eventi legati alle minacce più comuni, in ambito pubblico e privato.

L’evento organizzato è patrocinato da: AgID, ANDIP, Clusit, CNA, CNA Professioni, Galileo, Istituto Italiano Privacy, Privacy Italia, PROCEDAMUS, PROTECH, SIT, SOS Archivi, THEMIS.

Sull’evento il Centro di ricerca ReCEPL e la cattedra Jean Monnet Protech ha dichiarato: “L’idea della protezione dei dati personali non si limita al loro trattamento legal compliance, ma si estende propriamente alla loro sicurezza, intesa come protezione dagli attacchi informatici. Il fenomeno del data breach colpisce tutte le realtà imprenditoriali e professionali: è necessario esserne consapevoli e mettere in campo tutti gli strumenti idonei ad evitarlo. In ragione di ciò l’evento Anorc rappresenta un momento indispensabile per l’acquisizione di competenze essenziali ai fini della salvaguardia del patrimonio dati funzionale all’esercizio della propria attività”.

L’associazione Galileo ha fatto sapere che “sostiene l’evento di Anorc perché lo ritiene interlocutore di primo livello sul tema della protezione da minacce informatiche di Pubblica amministrazione e aziende. Il think tank con sede nel Principato di Monaco è impegnato nello studio e nell’analisi di questa delicata e centrale issue”.

Il Centro ricerca Themis ha motivato così la propria adesione: “Aderiamo con piacere all’iniziativa di Anorc perché affronta concretamente la sicurezza informatica con una pluralità di competenze, che riteniamo l’approccio vincente in questa sfida- ha dichiarato Isabella Corradini, presidente del Centro Ricerche Themis, che sarà anche tra i relatori- Fare crescere la consapevolezza digitale è oggi fondamentale se vogliamo contrastare le minacce informatiche in modo efficace, lo dimostra il fatto che molti attacchi sono legati al fattore umano. Ecco perché è importante partecipare all’iniziativa Anorc“.

Forum Nazionale dei DPO e Responsabili della Conservazione (RDC): programma e come seguire il forum

SESSIONE MATTUTINA
Dalle 10.00 alle 12.30

INTRODUCE

  • Dott. Alessandro Selam – Direttore di ANORC

MODERA

  • Avv. Andrea Lisi – Presidente di ANORC Professioni, Titolare Studio Legale Lisi, coordinatore di Digital & Law Department

INTERVENGONO
(in ordine alfabetico)

  • Dott. Raffale Barberio – Fondatore e Editor in Chief di Key4biz, è presidente di Privacy Italia e direttore dell’International Cybersecurity Observatory
  • Esponente del Garante per la protezione dei dati personali*
  • Dott.ssa Isabella Corradini – Psicologa sociale e criminologa, è esperta di sicurezza (safety e cybersecurity) con approccio basato sul fattore umano e di “digital awareness”, Presidente di Themis, centro ricerche socio-psicologiche e criminologico-forensi
  • Prof. Corrado Giustozzi – Senior Cyber Security strategist
  • Esponente del Gruppo Privacy nell’ambito del Nucleo Speciale Tutela Privacy e Frodi Tecnologiche della Guardia di Finanza*
  • Dott. Massimiliano Pucciarelli – Presidente del Comitato Direzione Tecnica – gara Consip SPC Cloud lotto1″ -COMMUNITY CLOUD DELLA PA presso l’Agenzia per l’Italia Digitale

SESSIONE POMERIDIANA
Dalle 15.00 alle 18.00

MODERANO:

  • Avv. Luigi Foglia – Segretario Generale di ANORC, esperto in diritto dell’informatica e archivi digitali
  • Avv. Sarah Ungaro – Vice presidente di ANORC Professioni, esperta in diritto dell’informatica e privacy

Dalle 15:00 alle 18:00

INTERVENGONO:

  • Avv. Laura Ferola* – DPO del Garante per la protezione dei dati personali
  • Avv. Raffaella Vai – DPO dell’Agenzia per l’Italia Digitale (AgID)
  • Dott.ssa Stefania Vitucci* – DPO della Presidenza del Consiglio dei Ministri

Confronto tra i Responsabili della Conservazione (RDC), Data Protection Officer (DPO), Responsabili della Gestione Documentale (RGD) e Responsabili Transizione Digitale (RTD) delle Pubbliche Amministrazioni e iscritti ad ANORC.

*Relatori invitati e in attesa di conferma

La partecipazione è gratuita previa iscrizione alla piattaforma digeat.it.

Per partecipare al forum clicca qui.

https://www.key4biz.it/privacy-il-25-novembre-forum-nazionale-dei-dpo-e-responsabili-della-conservazione-rdc/381589/




AI, Wiewiórowski (EDPS) ‘Ue non ancora pronta per il riconoscimento facciale’

Il Garante Privacy europeo Wojciech Wiewiórowski (European Data Protection Supervisor) ritiene che l’Europa non sia ancora pronta per il riconoscimento facciale per il controllo pubblico delle persone.

“La società europea non è ancora pronta”, ha detto Wojciech Wiewiórowski told in un’intervista a Politico

La tecnologia e le sue applicazioni hanno diviso l’Europa. La proposta Ue di legislazione sull’AI mette al bando la maggior parte delle applicazioni di identificazione biometrica da remoto, a partire dal riconoscimento facciale nei luoghi pubblici dalle forze dell’ordine, ma fa delle eccezioni per combattere la criminalità “grave”, che potrebbe includere il terrorismo.

Leggi anche: Intelligenza artificiale affidabile ed etica. Le regole dell’Ue. Vestager: “Da noi no sorveglianza di massa”

Siamo pronti per un controllo permanente?

Chi sostiene l’uso della tecnologia, vale a dire le forze dell’ordine e alcuni governi più attenti alla sicurezza, dice che la polizia ha bisogno della tecnologia per catturare i criminali. Ma attivisti per la privacy, alcuni legislatori europei e lo stesso Wiewiórowski sono invece a favore di un divieto assoluto.

L’uso della tecnologia “trasformerebbe la società, trasformerebbe i nostri cittadini, trasformerebbe i luoghi in cui viviamo, in luoghi in cui siamo permanentemente riconoscibili… Non sono sicuro che la società sia davvero pronta per questo”, dice Wiewiórowski.

Attenzione alle deroghe

L’organizzazione da lui guidata, l’EDPS, è l’autorità interna per la protezione dei dati dell’UE, che garantisce che le singole agenzie nazionali dell’UE si attengano alle rigide norme sulla privacy del continente. Fornisce inoltre consulenza alla Commissione europea sulle sue iniziative legislative.

Wiewiórowski ha lanciato un monito: consentire delle eccezioni all’uso delle tecnologie potrebbe aprire la porta a tutti i tipi di sorveglianza, compreso il riconoscimento emotivo, e potrebbe essere aperto anche alle società private.

“Molti politici credono che l’uso di queste tecnologie debba essere consentito ad altre organizzazioni, altre entità, il che è un po’ sorprendente per me in realtà”, ha detto Wiewiórowski.

Essere più specifici

Wiewiórowski ha inoltre sottolineato che i legislatori devono ancora definire che cosa intendono esattamente per intelligenza artificiale che vogliono regolare, un fattore che potrebbe avere un peso significativo su quali aziende e quali applicazioni saranno regolamentate.

L’appello di Wiewiórowski è stato raccolto dai paesi della Ue, che a loro volta hanno chiesto definizioni più precise su quale tipo di intelligenza artificiale debba ricadere sotto la legislazione europea. Danimarca, Francia, Italia e altri paesi hanno lamentato che l’AI Act è troppo ampio, e rischia di imbrigliare modelli statistici di base in una regolamentazione pesante.

Riferendosi all’ampia rete della legislazione, Wiewiórowski ha affermato: “Stiamo usando la nozione di marketing dell’intelligenza artificiale per le tecnologie e sappiamo che la maggior parte di queste tecnologie non sono in realtà così intelligenti”.

“Dobbiamo stare più attenti a quello che pensiamo di ricomprendere e quello che resterà fuori dalla regolazione. Se qualcosa è sofisticato non significa che si tratti di intelligenza artificiale”, ha detto aggiungendo che in base all’attuale bozza di legge, sistemi che controllano i limiti di velocità in autostrada (autovelox ndr) rientrerebbero nella definizione di intelligenza artificiale.

https://www.key4biz.it/ai-wiewiorowski-edps-ue-non-ancora-pronta-per-il-riconoscimento-facciale/380538/