Apple studia la depressione con l’iPhone. L’altolà dei medici: sistema privo di validità scientifica

L’IA, le emozioni umane e la depressione

Le nuove tecnologie sul mercato ci consentono di comprendere meglio i nostri comportamenti, a volte anche i nostri pensieri, ora, secondo molti esperti, ci aiuteranno a trovare il bandolo della matassa della nostra variabilità emotiva quotidiana.

Riconoscimento facciale, studio delle espressioni del viso e dei movimenti, analisi della scrittura e della parlata, più tutta una serie di sistemi per il monitoraggio dei comportamenti e degli atteggiamenti passivi, sono le soluzioni tecnologiche oggi più impiegate per la comprensione della nostra emotività e delle malattie ad essa collegate, tra cui la depressione (intesa come disturbo dell’umore).

Grandi aziende tecnologiche, come le cosiddette Big Tech, sono interessate a questo promettente settore ed Apple ha annunciato da poco uno studio, condotto in partnership con l’UCLA (University of California, Los Angeles), proprio dedicato al riconoscimento di uno stato di depressione condotto attraverso l’impiego di tecnologie sofisticate, tra cui l’intelligenza artificiale, che in campo scientifico è chiamata “emotion AI” o Affective Computing or Artificial Emotional Intelligence.

L’emotion AI non affidabile

Un articolo del Wall Street Journal ha affrontato in maniera approfondita questa ricerca targata Apple-UCLA, valutandone i rischi e gli aspetti più negativi.

Sfruttare un iPhone e un Apple Watch per misurare tutti i principali parametri vitali del nostro corpo (frequenza cardiaca e respiratoria, temperatura corporea, qualità del sonno, pressione e altro), associandoli a quanto scoperto dell’IA, che ne frattempo ha scrutato il resto dei nostri comportamenti e atteggiamenti sopra elencati, potrebbe non portarci sulla strada giusta nello studio della depressione.

L’emotion AI per lo studio del nostro stato umorale, infatti, si basa su presupposti errati, secondo molti studiosi e numerosi esponenti della comunità medica internazionale e americana.

Le soluzioni tecnologiche impiegate non sembrano essere abbastanza precise e accurate nel lavoro di rilevamento delle emozioni e di valutazione della salute mentale di un individuo”, ha spiegato Hayley Tsukayama, legale della Electronic Frontier Foundation.

L’errore più grande che si commette nell’utilizzo di queste tecnologie, in un campo così delicato come quello delle emozioni, secondo Kate Crawford, ricercatrice della Annenberg School for Communication and Journalism della University of Southern California e autrice di “Atlas of AI: Power, Politics, and the Planetary Costs of Artificial Intelligence”, è voler dedurre più informazioni possibili, dagli stati umorali interni e dai comportamenti esterni, rispetto a quanto le persone vogliano rivelare.

In un articolo del 2019 pubblicato sulla rivista accademica Psychological Science in the Public Interest, un gruppo di ricercatori ha affermato che tali soluzioni di emotion AI, al di là della potenza di calcolo e di quanto sofisticati siano gli algoritmi, semplicemente non sono affidabili, nel migliore dei casi offrono un panorama di informazioni incomplete, nel peggiore del tutto prive di validità.

Una minaccia per la nostra privacy

Rimane poi il problema gigantesco dei dati sanitari e sulla salute appartenenti solo ed esclusivamente alla persona. Queste tecnologie hanno modo di raccogliere i nostri dati personali sulla salute corporea e mentale, in che modo li tratteranno? Come saranno gestiti? In che modo? Dove? Con quali livelli di sicurezza? Chi vi potrà accedere oltre noi?

Sono domande a cui le Big Tech, tra cui Apple, devono dare risposte certe nell’immediato. Oggi l’emotion AI è un modello di valutazione del nostro status umorale impiegato in molte aziende, nelle carceri, nelle scuole e in molti altri ambiti.

Aziende come Dunkin’ Donuts, Unilever, Carnival Cruise Lines e IBM le usano per il reclutamento del personale. Le tecnologie Affective computing rappresentano già oggi un mercato mondale da 20 miliardi di dollari, ma entro il 2027 potrebbe raggiungere i 192 miliardi di dollari, secondo stime Grand View Research, .

Senza la legislazione sulla privacy che includa la protezione dei dati biometrici delle persone, i consumatori non hanno molta autorità su come i loro dati sono e saranno utilizzati, elaborati e archiviati.

https://www.key4biz.it/apple-a-caccia-di-emozioni-con-lia-per-studiare-la-depressione-laltola-dei-medici-sistema-privo-di-validita-scientifica/374866/




Australia: riconoscimento facciale per chi è in quarantena Covid. Tecnologia poco affidabile per difensori privacy

Il riconoscimento facciale in Australia

Due delle regioni più popolose dell’Australia, il Nuovo Galles del Sud (New South Wales o NSW) e i territori della Western Australia (WA), in tutto più di 11 milioni di cittadini, hanno avviato la sperimentazione di un software per il riconoscimento facciale che consente alla Polizia locale di controllare e verificare il rispetto della quarantena come misura di contenimento della pandemia da Covid-19.

La tecnologia è stata sviluppata dalla società Genvis, che ha anche pubblicato sul suo sito web alcuni dati relativi alla sperimentazione del suo software per il riconoscimento facciale in diverse città e regioni australiane: “Che arriva a coinvolgere più della metà della popolazione nazionale”, circa 25 milioni di persone.

Da poco, anche lo Stato del South Australia (SA) ha iniziato i primi test per il riconoscimento facciale, si legge in un articolo su euronews.com, sempre in ausilio alle forze dell’ordine per rendere operativi i provvedimenti sanitari anti-Covid.

La firma facciale

Ogni cittadino che partecipa alla sperimentazione deve giornalmente inviare un suo selfie alla Polizia locale, che poi tramite il software in questione controlla che ci sia piena conformità tra l’identità della persona e la sua “firma” biometrica facciale.

In questo modo, secondo le forze dell’ordine, la tecnologia rende possibile quello che altrimenti non lo sarebbe: il più grande monitoraggio pubblico di sicurezza sanitaria mai eseguito nella storia in tempo reale.

Per controllare ogni giorno che gli australiani rispettino la quarantena o qualsiasi altra misura di sicurezza sanitaria non basterebbe un intero esercito di poliziotti, ha spiegato l’amministratore delegato di Genvis, Kirstin Butcher, per questo è fondamentale testare il software sul maggior numero possibile di individui.

Dubbi e timori per la privacy e i diritti umani

I gruppi per i diritti umani e per la tutela della privacy sono subito insorti in tutto il Paese, perché i pericoli insiti in questa tecnologia ancora in fase di sviluppo sono troppi, tali da squilibrare il rapporto tra costi e benefici, a favore dei primi.

Una soluzione tecnologica basata sull’intelligenza artificiale che al momento non è pienamente affidabile e può causare conseguenze gravi per i diritti umani e individuali, ha spiegato l’altro giorno L’Alto Commissario delle Nazioni Unite per i diritti umani, Michelle Bachelet, chiedendo una moratoria internazionale sull’impiego di tali sistemi.

Lo stesso giorno, la Direttrice del Thematic Engagement dell’Alto Commissariato per i Diritti Umani, Peggy Hicks, ha citato diversi casi giudiziari negli Stati Uniti e in Australia, in cui l’intelligenza artificiale è stata erroneamente applicata, causando gravi danni alle persone e alle imprese, per un impiego troppo veloce e superficiale di tali sistemi e senza nessuna garanzia a tutela degli individui.

Fino a quando non saranno dissolti tutti i dubbi e i timori al momento esistenti sul riconoscimento facciale, ha dichiarato Bachelet, sarebbe meglio che ogni Stato al mondo interrompesse le sperimentazioni, “prima che siano causati danni irreparabili alle persone e alle comunità”.

Dello stesso avviso è Toby Walsh, professore di Intelligenza Artificiale presso l’Università del NSW: “Sono molto preoccupato per l’utilizzo in Australia e nel resto del mondo del riconoscimento facciale, soprattutto per l’impatto che questa tecnologia può avere sulle nostre vite”.

https://www.key4biz.it/australia-riconoscimento-facciale-per-chi-e-in-quarantena-covid-tecnologia-poco-affidabile-per-difensori-privacy/374362/




L’acquisto di ExpressVPN preoccupa… c’è da fidarsi?


La società è stata acquistata per 936 milioni di dollari da una società che ha un passato tutt’altro che rassicurante.

Quando si parla di privacy e sicurezza, uno degli elementi che conta di più a livello di reputazione è l’affidabilità del fornitore di servizi a cui ci si rivolge. Non sempre, però, è possibile avere la certezza che quella reputazione sia (ancora) meritata.

Nel caso di ExpressVPN, per esempio, le cose sembrano essersi complicate parecchio. La società, tra le più apprezzate nel mondo consumer, è stata infatti acquisita per una somma notevole (quasi 1 miliardo di dollari) da Kape, una società britannica quotata in borsa.

Se, normalmente, un cambio di proprietà non preoccupa più di tanto gli utenti, nel settore delle VPN le sensibilità sono più “sviluppate” e per ottimi motivi. Chi decide di utilizzare un servizio di Virtual Private Netwrok, infatti, lo fa spesso per tutelare la sua privacy o proteggersi da eventuali intrusioni nella sfera privata. L’affidabilità e l’integrità del fornitore del servizio è, di conseguenza, un elemento fondamentale.

Come riporta The Register in un articolo pubblicato oggi, la storia di Kape non è propriamente rassicurante. Fino al 2018, infatti, si chiamava Crossrider e si occupava di un settore diverso, seppure sempre nell’ambito digitale.

ExpressVPN

Il suo nome era legato allo sviluppo e commercializzazione di estensioni per browser che iniettavano inserzioni pubblicitarie nelle pagine visitate. Insomma: un classico adware. Un modello di business che, a giudizio di molti, si colloca agli antipodi di quello svolto da ExpressVPN.

Con il cambio di nome, Kape ha cominciato a operare nel settore della cyber security e ha acquisito una serie di servizi VPN tra cui CyberGhost VPN, ZenMate e Private Internet Access.

Normale che nel settore qualche perplessità sia emersa, soprattutto se si considera che i casi di servizi VPN “poco affidabili” sono tutt’altro che rari. D’altra parte, l’utilizzo di un servizio di questo genere non è una garanzia assoluta di riservatezza.

I dati riguardanti la navigazione di chi usa una VPN, che la maggior parte dei servizi di questo genere promette di non tracciare, rappresentano un patrimonio facilmente monetizzabile nel mondo digitale. Insomma: la partita si gioca principalmente sulla fiducia.

Il vero nodo della questione, in questo caso, è un altro: quanto utenti di ExpressVPN sanno che l’azienda ha cambiato proprietà? E quanto futuri utenti che la sceglieranno sulla base della reputazione che si è guadagnata in passato avranno la consapevolezza del fatto che c’è stato quel cambio?

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/09/14/lacquisto-di-expressvpn-preoccupa-ce-da-fidarsi/?utm_source=rss&utm_medium=rss&utm_campaign=lacquisto-di-expressvpn-preoccupa-ce-da-fidarsi




Google Introduces Private Compute Services for Android

Google this week introduced a new suite of services designed to improve privacy in the Android operating system.

The new features add to the previously introduced Private Compute Core in Android 12 beta, an open source, secure environment designed to be completely isolated from the Android platform itself, as well as from other applications.

For the time being, Private Compute Core includes features such as Live Caption, Now Playing, and Smart Reply, but Google says that additional privacy-preserving features will be added with each new Android release.

To increase privacy, these features keep user data on the device, as the data processed in the Private Compute Core isn’t shared with other apps, and allow for the device to access the cloud without compromising privacy.

No feature within the Private Compute Core has direct access to a network, which is where the newly introduced Private Compute Services come into play. Powered by machine learning, Google says they create a bridge between Private Compute Core and the cloud.

A set of open-source APIs to Private Compute Services are utilized for communication purposes, while ensuring all identifying information is removed in the process through technologies such as Federated Learning, Federated Analytics, and Private information retrieval.

Google plans to make the source code for Private Compute Services available to the public and be audited by security researchers.

“We’re enthusiastic about the potential for machine learning to power more helpful features inside Android, and Android’s Private Compute Core will help users benefit from these features while strengthening privacy protections via the new Private Compute Services,” Google says.

Related: Google Android Security Update Patches 40 Vulnerabilities

Related: Google Details New Privacy and Security Policies for Android Apps

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/pRS85SMwMos/google-introduces-private-compute-services-android




ProtonMail (Wrongly?) Criticized for Disclosing User IP to Authorities

Blaming ProtonMail misses important lessons of the case, as request from authorities ticked the necessary requirements under Swiss law

ProtonMail, a privacy and security-focused email provider based in Switzerland, has been strongly criticized for providing the IP address of a customer to Swiss authorities, ultimately leading to the arrest of a climate activist in France. But simply blaming ProtonMail misses the important lessons of this case.

Background

French authorities were aware that a group ‘of interest’ (the Youth for Climate collective and associated groups) used the jmm18[@]protonmail.com email address. According to police reports, the climate group had hardened its interests along general anti-capitalist lines, and were taking part in illegal squatting and damage to property.

Since Switzerland is not part of the EU, the French police could not demand that the Swiss authorities obtain and hand over the IP address of the email user. Instead, it approached Switzerland via Europol. Switzerland acquiesced with Europol, and required ProtonMail to deliver up the IP address. Since the request ticked all the necessary requirements under Swiss law, ProtonMail had no option but to obey.

It should be stressed that ProtonMail cannot deliver the content of its end-to-end encryption – this is solely about the user’s IP address.

ProtonMail

ProtonMail is not happy with the events. It published a blog titled Important clarifications regarding arrest of climate activist on September 6, 2021, commenting, “We are also deeply concerned about this case and deplore that the legal tools for serious crimes are being used in this way.”

Several points stand out in this blog – most importantly that ProtonMail had no alternative but to comply with the Swiss court order. ProtonMail does not know the identity of its users. “We only know that the order for data from the Swiss government came through channels typically reserved for serious crimes.” It did not know that the target of observation was a group of French climate activists – for all ProtonMail knew, it could have been a gang of international terrorists.

Noticeably, the blog provides no information on the details of the case. However, it directs readers to the ProtonMail transparency report, and the ProtonMail privacy policy. The former states, “ProtonMail may also be obligated to monitor the IP addresses which are being used to access the ProtonMail accounts which are engaged in criminal activities.” The latter includes, “If permitted by law, we will always contact a user first before any data disclosure.”

It is possible that ProtonMail was required to monitor the IP or IPs used by the email address over a period of time, while simultaneously under a gagging order not to disclose the fact. Only after an arrest could matters be made public.

Lessons to be learned

SecurityWeek talked to European privacy activist and advocate Peter Sunde Kolmisoppi. He works on projects designed to help people protect their privacy (such as Njal.la, a privacy aware domain service with both VPS and VPN), but also encourages groups and political entities on increasing the right to privacy. He is a co-founder of The Pirate Bay and the founder of Flattr and Njal.la.

Sunde does not blame ProtonMail for what happened, but that doesn’t mean he is not angry at what did happen. The primary problem, he suggests, is that ProtonMail is “based in a country that has a government that can control their actions. That’s the main flaw. A lot of activists, technologists and hosters have this idea that certain countries are ‘bulletproof’ when it comes to privacy. That’s certainly not the case.”

This is the first lesson to be learned – to recognize that all companies are subject to the laws of the country where they reside, irrespective of their own principles and preferences.

He believes the solution here would be to decentralize the service – something eminently feasible given todays’ global public cloud. “The basic problem here is again that we’ve centralized things. Organizations, services – e-mail is among the easiest of all services to have decentralized – and trust.” But ProtonMail is what it is, and alternative ideas are irrelevant to the current situation.

“It’s not the fault of ProtonMail, he says, it’s the fault of the authorities. And I’m sure that ProtonMail will take lessons from this to improve their threat model.” ProtonMail has started to stress the availability of its onion service to allow users with heightened threat conditions to gain the additional protection of Tor, and provides clear access to its own VPN, ProtonVPN, on the home page.

Swiss law treats VPN different to email. “Under current Swiss law, email and VPN are treated differently, and ProtonVPN cannot be compelled to log user data,” wrote ProtonMail in its blog. The implication is that the French authorities may not have been able to secure the IP address had the activists been using ProtonMail with Tor and VPN as well as ProtonMail.

This is the second lesson – when using any service, be aware of the additional security protection that may be available, and use it.

Sunde’s anger is directed against the authorities rather than ProtonMail. It seems that the route taken to get the IP address was originally intended for just the most serious of crimes – not to be used against climate activists (although in fairness we don’t really know what else the authorities were hoping or expecting to find).

“Switzerland is not part of the EU, so we’re not sure why Switzerland nor the EU looked at this as a case as important enough to go to these extreme measures,” he told SecurityWeek. “There should have been many people that could have stopped this insanity.”

He continued with the third lesson to be learned: “In general, I would say that people should not trust any single entity/provider to protect any secret communication, because most of these organizations can be forced to do things, or there can be backdoors or security issues with other things. An app for secure chat is great but it will ultimately come down to if your computer/phone is secure – and it is not.”

Finally, wearing his activist hat, he added, “I think we need to shame both the Swiss and EU authorities for allowing this ridiculous thing to happen; and hopefully this situation will lead to better decisions on what they will do in the future.”

It is worth also adding that although there is no direct comparison, the primary argument that has led the European courts to issue the Schrems II ruling has been the ability of the NSA to obtain European personal information. In this instance, the French authorities obtained personal information of European residents through the cooperation of Europol and the Swiss authorities.

Related: ProtonMail Accused of Voluntarily Helping Police Spy on Users

Related: ProtonMail Opens Encrypted Email Service to Public

Related: ProtonMail Launches Tor Hidden Service

Related: ProtonMail Launches VPN Application for macOS

Related: Russia Blocks Swiss-based ProtonMail Over Wave of Bomb Threats

view counter

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Previous Columns by Kevin Townsend:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/mZzCv7sNaxY/protonmail-wrongly-criticized-disclosing-user-ip-authorities




US Gov Seeks Public Feedback on Draft Federal Zero Trust Strategy

The U.S. government’s Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Management and Budget (OMB) this week announced they are seeking public feedback on draft zero-trust strategic and technical documentation.

The OMB has drafted a federal strategy to transition the U.S. government towards a zero-trust architecture and is now seeking public feedback to improve the documentation and improve the government’s cybersecurity stance.

The draft strategy, which falls in line with the Executive Order on Improving the Nation’s Cybersecurity (EO 14208) that requires for civilian agencies’ enterprise security architecture to be changed based on zero trust principles – clarifies zero trust priorities for these agencies.

[Related Reading: Zero Trust, We Must]

The strategy focuses on consolidating identity systems, implementing multi-factor authentication to combat phishing, encrypting traffic within internal networks, improving application security, and more. With the transition to a zero trust architecture expected to take years, the government is expected to adjust the strategy as new practices and technologies emerge.

Separately, CISA released the Cloud Security Technical Reference Architecture (TRA) and Zero Trust Maturity Model to support EO 14208. The Cloud Security TRA is meant to provide agencies with guidance on the cloud service adoption’s shared risk model, and the building and monitoring of a cloud environment.

Designed to complement OMB’s Zero Trust Strategy, the Zero Trust Maturity Model is expected to help agencies in their journey to zero trust by delivering a roadmap and resources for an optimal zero trust environment.

Public comments and feedback for both the TRA and Zero Trust Maturity Model can be submitted through October 1, 2021, via email.

Related: The VC View: Identity = Zero Trust for Everything

Related: NSA Publishes Guidance on Adoption of Zero Trust Security

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/vJ7Y0GTZL0o/us-gov-seeks-public-feedback-draft-federal-zero-trust-strategy




Microsoft Warns of Information Leak Flaw in Azure Container Instances

Microsoft has patched an Azure Container Instances (ACI) vulnerability that could have allowed users to access the information of other Azure customers.

The company did not provide technical details on the vulnerability but security researchers with Palo Alto Networks say attackers could have exploited the  bug to execute code on other users’ containers, steal sensitive information such as crypto secrets, and even deploy crypto-mining malware.

Microsoft said it it notified customers that might have been affected, through the Service Health Notifications in the Azure Portal. Those that did not receive a notification need take no action, the company added.

“There is no indication any customer data was accessed due to this vulnerability. Out of an abundance of caution, notifications were sent to customers potentially affected by the researcher activities, advising they revoke any privileged credentials that were deployed to the platform before August 31, 2021,” Microsoft said in a statement.

All Azure customers are encouraged to rotate privileged credentials on a frequent basis, as a precautionary measure.

The issue, which is being called Azurescape, could lead to the compromise of the Kubernetes clusters hosting ACI, thus providing attackers with full control over other Azure customers’ containers, according to Palo Alto Network researchers.

While built to prevent attacks from malicious neighbor containers – cross-account or cross-tenant attacks – ACI was found to use an older runC (standard container runtime) version that was vulnerable to multiple container escape flaws.

[ READ: Critical Vulnerability Exposed Azure Cosmos DBs for Months ]

Using a modified version of the proof-of-concept code exploiting one of those bugs — CVE-2019-5736 — the researchers were able to break out of a container and gain a root reverse shell on the underlying host. Next, they found token permissions in the kube-system namespace that allowed them to execute commands on any pod in the cluster, which they used to perform the cross-account attack.

“A malicious Azure user could have compromised the multitenant Kubernetes clusters hosting ACI. As cluster administrator, an attacker could execute commands in other customer containers, exfiltrate secrets and private images deployed to the platform, or deploy cryptominers. A sophisticated adversary would further investigate the detection mechanisms protecting ACI to try to avoid getting caught,” Palo Alto said.

Released in July 2017, ACI is a Container-as-a-Service (CaaS) built on multitenant clusters (Kubernetes and, more recently, Service Fabric Clusters), which supports deployment of containers while eliminating the need to manage the underlying infrastructure.

Two weeks ago, Microsoft addressed a similar issue in Azure Cosmos DB, where users could access other customer’s databases with full administrative rights, potentially taking full control of them.

Related: Critical Vulnerability Exposed Azure Cosmos DBs for Months

Related: Microsoft Office Zero-Day Hit in Targeted Attacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/bmU9WYm_nks/microsoft-warns-information-leak-flaw-azure-container-instances




Marcia indietro di ProtonMail sulla privacy: i log sono registrati


Il servizio di posta elettronica ha sempre sostenuto di non tenere traccia delle comunicazioni, ma le cose non stanno esattamente così…

È, o forse sarebbe meglio dire che era, il servizio di posta elettronica preferito dai maniaci della privacy e (anche) dei pirati informatici. ProtonMail, azienda con sede in Svizzera, ha sempre basato il suo successo sul fatto di garantire ai suoi utenti la massima protezione da ogni forma di controllo.

Stando a quanto si leggeva sulle sue condizioni di utilizzo, il servizio di posta elettronica utilizza infatti iun sistema di crittografia end to end ed escludeva la possibilità che qualsiasi informazione venisse registrata e, di conseguenza potesse essere trasmessa alle autorità.

Nella versione originale della pagina Web (pagina tratta dalla WayBackMachine e risalente al gennaio scorso) che descriveva il servizio si leggeva: “Per creare il tuo account email sicuro non è necessaria alcuna informazione personale. Per impostazione predefinita, non conserviamo alcun log relativo agli indirizzi IP che possono essere collegati al tuo account mail anonimo. La tua privacy è la nostra priorità”.

Qualcosa, però, è cambiato. Nei giorni scorsi è infatti emersa la notizia che ProtonMail ha fornito all’Europol i log con gli indirizzi IP di alcuni utenti, che in seguito sono stati arrestati.

Si tratterebbe di un gruppo di attivisti francesi appartenenti a quella che gli organi di stampa hanno definito “galassia anarchica”. I membri del gruppo, impegnati nella lotta ai processi di gentrificazione e speculazioni edilizie, hanno coordinato varie iniziative utilizzando alcuni account di ProtonMail.

ProtonMail

Da qui la richiesta delle autorità francesi di identificare i titolari degli account, che tramite l’Europol è stata trasmessa al governo svizzero. Di fronte alla richiesta, ProtonMail ha fornito le informazioni relative agli indirizzi IP utilizzati per accedere agli account di posta elettronica, favorendo così l’identificazione degli attivisti.

Quando la notizia è diventata pubblica, nel mondo di Internet si è aperto il processo a ProtonMail, accusata di aver tradito le promesse messe nero su bianco sul suo sito Web.

Anche se la dirigenza nega le accuse, la descrizione del servizio nel frattempo è cambiate e statuisce semplicemente che “ProtonMail è un servizio che rispetta le privacy e privilegia le persone rispetto agli inserzionisti. I dati sono sempre in tuo possesso e il nostro sistema di crittografia lo garantisce. Forniamo anche un gateway anonimo”.

E proprio la questione tecnica dell’acceso al servizio, congiuntamente con la legislazione svizzera, sembrerebbero essere il centro della questione.

In un comunicato pubblicato su Internet, ProtonMail cerca di spiegare la questione sottolineando che l’azienda non fornisce informazioni sulla base di richieste di governi stranieri, ma è obbligata ad adempiere le richieste del governo svizzero.

Allo stesso tempo, spiega che il servizio VPN offerto da ProtonMail consente di nascondere l’IP degli utenti e che i servizi VPN, secondo la legislazione svizzera, hanno un trattamento diverso rispetto a quelli di posta elettronica. Tradotto: se gli attivisti francesi avessero usato la VPN di ProtonMail, oggi non sarebbero in arresto.

Difficile, però, che le precisazioni e giustificazioni di ProtonMail possano convincere l’opinione pubblica del fatto che il servizio garantisca un reale anonimato.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/09/07/marcia-indietro-di-protonmail-sulla-privacy-i-log-sono-registrati/?utm_source=rss&utm_medium=rss&utm_campaign=marcia-indietro-di-protonmail-sulla-privacy-i-log-sono-registrati




Nude hunt: LA phisherman accessed 4,700 iCloud accounts, 620K photos

The Internet is unfortunately packed full of criminals seeking to steal sexual (or sexualizable) images from privately held cloud backup accounts.
Enlarge / The Internet is unfortunately packed full of criminals seeking to steal sexual (or sexualizable) images from privately held cloud backup accounts.

The LA Times reported this week that Los Angeles man Hao Kuo “David” Chi pled guilty to four federal felonies related to his efforts to steal and share online nude images of young women. Chi collected more than 620,000 private photos and 9,000 videos from an undetermined number of victims across the US, most of whom were young and female.

“At least 306” victims

Chi’s plea agreement with federal prosecutors in Tampa, Florida, acknowledged “at least 306” victims. This number may be considerably smaller than the true total, since the FBI found that about 4,700 out of 500,000 emails in two of Chi’s Gmail accounts—backupagenticloud and applebackupicloud at Gmail—contained iCloud credentials that Chi tricked his victims into providing.

According to Chi, he selected roughly 200 of these victims based on online requests. Chi marketed his iCloud break-in “services” under the nom de guerre icloudripper4you. His “customers” would identify an iCloud account for attack, after which Chi would use his sketchily named Gmail accounts to contact the victim, impersonating an Apple service representative.

If the victim fell for Chi’s spearphishing attempt, Chi would then use the victim’s own iCloud credentials to log in to the service and save their photos and videos to Dropbox—followed by providing the Dropbox link to his customers and/or conspirators.

According to court documents, Chi organized and saved the stolen media for his own and unnamed conspirators’ personal use, as well as providing them to icloudripper4you “customers.” The phishing ring used an offshore-hosted encrypted email service to communicate anonymously—”I don’t even know who was involved,” Chi told the LA Times. The ring referred to nude photos and videos found in the stolen accounts as “wins,” which they shared with one another.

FBI Agent Anthony Bossone told the court that Chi’s Dropbox account contained roughly 620,000 photos and 9,000 videos, organized in part by the presence or lack of “wins” within them.

An unsophisticated operation

Despite Chi’s use of “bulletproof” offshore encrypted email, his operation appears to have been quite unsophisticated—he relied on his victims’ willingness to part with their iCloud credentials over email, and his scheme unraveled due more to one victim’s fame than to any daring technical scheme.

In early 2018, one of Chi’s victims—an unnamed public figure in Tampa, where the court case was eventually held—discovered their own nudes on pornographic websites, courtesy of a California company that specializes in removing celebrity photos from the Internet. The nude images were originally stored on an iPhone, from which they were backed up to iCloud.

Once this victim complained to law enforcement, Chi’s scheme unraveled easily—he had logged in to his victim’s iCloud account directly from his own home in La Puente, California. By the time the FBI got a search warrant and raided his house in May, the agents already had a clear picture of Chi’s schemes thanks to records subpoenaed from Dropbox, Google, Apple, Facebook, and Charter Communications.

On August 5, Chi pled guilty to one count of conspiracy and three counts of gaining unauthorized access to a protected computer. He faces up to five years in prison for each charge but will almost certainly receive far less than that due both to sentencing guidelines and guilty-plea negotiations.

Stay sharp out there

It’s unfortunate that Apple never noticed a single man accessing thousands of iCloud accounts, apparently directly from a single residential IP address and on a service that does not use carrier-grade NAT. However, it’s worth noting that Chi’s predation—and that of many, many other phishers—relied entirely on his victims’ gullibility.

This is important because Chi himself is more symptom than disease, representing only the tip of a vast iceberg. It’s not difficult to find “services” like Chi’s on any social media platform—in some cases, whether you’d like to or not.

Facebook recently locked my own profile for no apparent reason two days in a row. On the second day, a random, possibly compromised Facebook account promoted the services of “Steve” on Instagram, “100% sure and guaranteed” to “help recover my account.” Following the Instagram link in a throwaway virtual machine led me to “the_dark_hacker_unlock”—and services that seem clearly aimed at attackers, not victims.

Despite reporting both the Facebook comment and the Instagram account it promoted, both accounts are still online—along with many, many others just like them.

https://arstechnica.com/?p=1789674




38 million records exposed online—including contact-tracing info

38 million records exposed online—including contact-tracing info
Jorg Greuel | Getty Images

More than a thousand web apps mistakenly exposed 38 million records on the open Internet, including data from a number of COVID-19 contact-tracing platforms, vaccination sign-ups, job application portals, and employee databases. The data included a range of sensitive information, from people’s phone numbers and home addresses to Social Security numbers and COVID-19 vaccination status.

The incident affected major companies and organizations, including American Airlines, Ford, the transportation and logistics company J.B. Hunt, the Maryland Department of Health, the New York City Municipal Transportation Authority, and New York City public schools. And while the data exposures have since been addressed, they show how one bad configuration setting in a popular platform can have far-reaching consequences.

The exposed data was all stored in Microsoft’s Power Apps portal service, a development platform that makes it easy to create web or mobile apps for external use. If you need to spin up a vaccine appointment sign-up site quickly during, say, a pandemic, Power Apps portals can generate both the public-facing site and the data management backend.

Beginning in May, researchers from the security firm UpGuard began investigating a large number of Power Apps portals that publicly exposed data that should have been private—including in some Power Apps that Microsoft made for its own purposes. None of the data is known to have been compromised, but the finding is significant still, as it reveals an oversight in the design of Power Apps portals that has since been fixed.

In addition to managing internal databases and offering a foundation to develop apps, the Power Apps platform also provides ready-made application programming interfaces to interact with that data. But the UpGuard researchers realized that when enabling these APIs, the platform defaulted to making the corresponding data publicly accessible. Enabling privacy settings was a manual process. As a result, many customers misconfigured their apps by leaving the insecure default.

“We found one of these that was misconfigured to expose data and we thought, we’ve never heard of this, is this a one-off thing or is this a systemic issue?” says Greg Pollock, UpGuard’s vice president of cyber research. “Because of the way the Power Apps portals product works, it’s very easy to quickly do a survey. And we discovered there are tons of these exposed. It was wild.”

The types of information the researchers stumbled across was wide-ranging. The J.B. Hunt exposure was job applicant data that included Social Security numbers. And Microsoft itself exposed a number of databases in its own Power Apps portals, including an old platform called “Global Payroll Services,” two “Business Tools Support” portals, and a “Customer Insights” portal.

The information was limited in many ways. The fact that the state of Indiana, for example, had a Power Apps portal exposure doesn’t mean that all the data the state holds was exposed. Only a subset of contact-tracing data used in the state’s Power Apps portal was involved.

Misconfiguration of cloud-based databases has been a serious issue over the years, exposing huge quantities of data to inappropriate access or theft. Major cloud companies like Amazon Web Services, Google Cloud Platform, and Microsoft Azure have all taken steps to store customers’ data privately by default from the start and flag potential misconfigurations, but the industry didn’t prioritize the issue until fairly recently.

After years of studying cloud misconfigurations and data exposures, the UpGuard researchers were surprised to discover those issues in a platform they’d never seen before. UpGuard attempted to survey the exposures and notify as many affected organizations as possible. The researchers couldn’t get to every entity, though, because there were too many, so they also disclosed the findings to Microsoft. At the beginning of August, Microsoft announced that Power Apps portals will now default to storing API data and other information privately. The company also released a tool customers can use to check their portal settings. Microsoft did not respond to a request from WIRED for comment.

While the individual organizations caught up in the situation could have theoretically found the issue themselves, UpGuard’s Pollock emphasizes that it is incumbent upon cloud providers to offer secure and private defaults. Otherwise it’s inevitable that many users will unintentionally expose data.

It’s a lesson that the whole industry has slowly, sometimes painfully, had to learn.

“Secure default settings matter,” says Kenn White, director of the Open Crypto Audit Project. “When a pattern emerges in web-facing systems built using a particular technology that continue to be misconfigured, something is very wrong. If developers from diverse industries and technical backgrounds continue to make the same missteps on a platform, the spotlight should be squarely on the builder of that platform.”

Between Microsoft’s fixes and UpGuard’s own notifications, Pollock says that the vast majority of the exposed portals, and all of the most sensitive ones, are now private.

“With other things we’ve worked on, it’s public knowledge that cloud buckets can be misconfigured, so it’s not incumbent on us to help secure all of them,” he says. “But no one had ever cleaned these up before, so we felt we had an ethical duty to secure at least the most sensitive ones before being able to talk about the systemic issues.”

This story originally appeared on wired.com.

https://arstechnica.com/?p=1789373