How Apple’s new App Tracking Transparency policy works

This week, Apple published a new white paper that describes the ways apps typically track users and handle their data, outlines the company’s privacy philosophy, and offers several details and clarifications about the upcoming App Tracking Transparency change, which will (among other things) require app developers to get a user’s permission to engage in the common practice of creating an identifier (called IDFA) to track that user and their activities between multiple apps.

The paper states that the change will go fully into effect with the release of an update to iOS and other Apple operating systems in “early spring” (Apple has previously said this would happen in iOS 14.5, which is now in a late stage of beta testing), but the company has reportedly already started enforcing some aspects of the new policy with new app submissions, suggesting that the full transition is very imminent. One recent survey found that only about 38.5 percent of users plan to opt in to tracking.

Most of the paper is dedicated to explaining exactly how apps track users to begin with, by using a hypothetical example of a father and daughter traveling to the playground with their personal mobile technology and apps in tow. There are no new revelations in this section for people who are already familiar with how these systems work, but the information is accurate, and most people don’t actually know all that much about how their data is tracked and used, so it might be useful to some.

Apple also uses a section in the paper to describe its app privacy labels, which are kind of like food nutrition labels, but instead of describing the nutrients in a meal, they describe the ways an app tracks you or accesses your data. It’s worth noting, though, that these app privacy labels are largely self-reported, and independent observers have found many examples of apps that have inaccurate or incomplete information in these labels.

Trust and antitrust

While the paper is partly aimed at users who want to know more about iOS’ privacy features and how personal data is handled by mobile apps generally, it also repeatedly tries to make the case that the upcoming App Tracking Transparency change will not negatively impact most advertising-supported businesses in a severe way. “The introduction of past features, such as Safari Intelligent Tracking Prevention, have shown that advertising can continue to be successful while enhancing users’ privacy protections,” the authors argue.

Some companies, like Facebook, have explored the idea of making an antitrust case against Apple, arguing that Apple is making third-party apps follow rules that the smartphone maker’s apps don’t have to follow. But this paper argues that Apple’s own apps don’t present an opt-in prompt for tracking because they don’t track across third-party apps for advertising purposes to begin with.

Most of the meaty clarifications are in the paper’s FAQ (frequently asked questions) section. For example, Apple writes that “app developers cannot require you to permit tracking in order to use the app’s full capabilities”—meaning users won’t get reduced functionality in apps if they opt out of the tracking. This gets at one critical caveat about Apple’s upcoming change: the policy prevents tracking across multiple third-party apps if a user opts out, but both Apple and any other company can still track users across multiple apps if all the apps in question are operated by the same company. The same thing that gives Apple a pass could also apply to, say, Google tracking you across Gmail, Google News, Docs, and so on. But as soon as Google wants to use a technique that can also see what you’re doing in Apple’s or Facebook’s apps, for example, that’s when the opt-in is required.

Apple offers a separate toggle labeled “Personalized Ads”—totally distinct from the IDFA-related opt-in prompt—that allows users to decide whether they want to be tracked within Apple’s first-party apps.

And related to the recent flurry of App Store submission rejections, Apple clarifies that a developer “is also required to respect your choice beyond the advertising identifier.” This means that once a user has opted out of IDFA tracking, the developer must also not track the user through any other method that generates a similar result, like device fingerprinting. Device fingerprinting was apparently what caused the wave of rejections we reported last week. “If we learn that a developer is tracking users who ask not to be tracked, we will require that they update their practices to respect your choice, or their app may be rejected from the App Store,” the paper says.

The FAQ also addresses the criticisms of the efficacy of the App Store’s privacy labels, albeit not very effectively. It confirms that the data is self-reported and says, “if we learn that a developer may have provided inaccurate information, we will work with them to ensure the accuracy of the information.”

Listing image by Samuel Axon

https://arstechnica.com/?p=1755111




Facebook Says Hackers ‘Scraped’ Data of 533 Million Users in 2019 Leak

Facebook said Tuesday that hackers “scraped” personal data of some half-billion users back in 2019 by taking advantage of a feature designed to help people easily find friends using contact lists.

A trove of information about more than 530 million Facebook users was shared over the weekend at a hacker forum, prompting the leading social network to explain what happened and call on people to be vigilant about privacy settings.

“It is important to understand that malicious actors obtained this data not through hacking our systems but by scraping it from our platform prior to September 2019,” Facebook product management director Mike Clark said in a post.

“This is another example of the ongoing, adversarial relationship technology companies have with fraudsters who intentionally break platform policies to scrape internet services.”

The data included phone numbers, birth dates, and email addresses, and some of the data appeared to be current, according to US media reports.

The stolen data did not include passwords or financial data, according to Facebook.

Scraping is a tactic that involves using automated software to gather up information shared publicly online.

“All 533,000,000 Facebook records were just leaked for free,” Alon Gal, chief technology officer at the Hudson Rock cybercrime intelligence firm, said Saturday on Twitter.

He denounced what he called the “absolute negligence” of Facebook.

“Bad actors will certainly use the information for social engineering, scamming, hacking and marketing,” Gal said on Twitter.

Clark urged members of the social network to check their privacy settings to control what information can be seen publicly, and to tighten account security with two-factor authentication.

This is not the first time leaks or use of data from the world’s largest social network — with nearly two billion users — has embroiled Facebook in controversy.

In 2016, a scandal around Cambridge Analytica, a British consulting firm that used the personal data of millions of Facebook users to target political ads, cast a shadow over the social network and its handling of private information.

view counter

© AFP 2020

Previous Columns by AFP:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/7TBc0m9mlFM/facebook-says-hackers-scraped-data-533-million-users-2019-leak




US lawmakers Press Online Ad Auctioneers Over User Data

A bipartisan group of US senators on Friday sent letters to major digital ad exchanges, including Google and Twitter, asking whether user data was sold to foreign entities who could use it for blackmail or other malicious ends.

In the real-time bidding process to decide which personalized ads a user sees when a web page loads, hundreds of businesses receive a user’s personal information, including search history, IP address, age and gender.

Questions about the sale of data gathered during the auction process were also sent to AT&T, Index Exchange, Magnite, OpenX, PubMatic and Verizon, according to the office of Senator Ron Wyden, a Democrat representing Oregon.

“Few Americans realize that some auction participants are siphoning off and storing ‘bidstream’ data to compile exhaustive dossiers about them,” Wyden and other senators wrote in letters to the companies.

“This information would be a goldmine for foreign intelligence services that could exploit it to inform and supercharge hacking, blackmail, and influence campaigns.”

While online ad exchanges use automated bidding systems to determine which ads to show people using internet services, data such as user locations, devices, and web activity can be gathered, according to the senators.

“These dossiers are being openly sold to anyone with a credit card, including to hedge funds, political campaigns, and even to governments,” the senators wrote.

Questions sent to the companies included what information is gathered about people in the course of serving up ads and which foreign firms have bought such data from them, according to the release.

The companies were given until May 4 to provide answers.

Twitter told AFP it had received the letter and intended to respond. The other companies did not immediately respond to queries for comment.

Google has pledged to steer clear of tracking individual online activity when it begins implementing a new system for targeting ads without the use of so-called “cookies.”

The internet giant’s widely used Chrome browser recently began testing an alternative to the tracking practice that it believes could improve online privacy while still enabling advertisers to serve up relevant messages.

view counter

© AFP 2020

Previous Columns by AFP:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/1FztLbb27_k/us-lawmakers-press-online-ad-auctioneers-over-user-data




SecureDrop Workstation Gets Post-Audit Security Refresh

The open-source SecureDrop Workstation has undergone a security makeover after a third-party security audit flagged multiple problems, including a high-risk bug that could allow an attacker to plant files on target machines.

The SecureDrop Workstation audit, conducted by Trail of Bits and financed by the New York Times, warned that the high-risk directory traversal bug could be leveraged for code execution attacks.

“The high severity finding details case where a malicious SecureDrop server could create files in arbitrary paths in the sd-app VM, which may allow for a code execution,” according to the audit report [PDF].

“When the SecureDrop Workstation client downloads a file, it stores it in a location derived from the filename returned by the server. However, since this location is not sanitized properly in all cases, an attacker who controls responses from the server can make the client save files in arbitrary paths on the filesystem. An attacker can use this vulnerability to plant files that potentially enable further vulnerabilities.”

The Trail of Bits code auditors found two cases when a malicious SecureDrop server could plant files.

Overall, the security assessment gave SecureDrop workstation a positive security bill of health. 

“We were unable to achieve a direct compromise of the Workstation from the position of an Internet-based attacker during our engagement,” Trail of Bits said, but made it clear this doesn’t imply that such a compromise exists or that SecureDrop Workstation is free of bugs.

SecureDrop Workstation is currently managed by the Freedom of the Press Foundation. Based on Qubes OS, the platform enables secure and encrypted communications between news organizations, journalists, sources and whistleblowers. It is currently being used in a limited pilot.

The Foundation said the audit report confirmed some its  assumptions around the use of virtualization to segment sensitive workloads and was pleased with the finding that the system system “represents a complex but well researched product that has been thoughtfully designed.”

None of the issues identified were directly exploitable by an attacker, and require either compromise of the SecureDrop server, or code execution in certain key VMs within the SecureDrop Workstation, the Foundation said.

Over the course of their engagement (6 person-weeks with two pen-test/code audit engineers), Trail of Bits found and documented 1 high-risk, 6 medium-risk, 7 low and 12 informational disclosure problems.

The audit confirmed that the high-severity and six of the medium-severity issues have already been patched and released, with the fixes validated by the auditing team. 

The Foundation said it is also investigating potential architectural improvements, including the creation of a custom RPC service to handle opening of files.

“In addition to addressing the findings surfaced in this report, we are also implementing feedback from current pilot participants, and planning new features around export and integration to other communication tools. We are in the process of expanding the pilot to several other news organizations, and hope to provide general availability later this year,” the Foundation said.

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/160J-vA58qQ/securedrop-workstation-gets-post-audit-security-refresh




Telemetria e raccolta di dati, impossibile disattivarla su device Android e iOS

La telemetria è la capacità di un sistema di rilevare a distanza dati operativi relativi ad un device connesso in rete. Ci sono diversi tipi di apparecchi per vari usi, anche gli smartphone rientrano in questo campo di attività, con brutte sorprese per gli utenti finali.

Secondo uno studio pubblicato dal Trinity College, dal titolo “Mobile Handset Privacy: Measuring The Data iOS and Android Send to Apple And Google”, Google ed Apple raccolgono molti dati sui nostri device grazie al servizio di telemetria, anche contro la nostra volontà, andando a violare la nostra privacy.

<!-- LARGE RECTANGLE POST - CORPO TESTO

-->

Dati raccolti per la profilazione

I due giganti tecnologici, infatti, grazie a questo sistema possono sfruttare i dati raccolti per identificare e profilare gli utenti, a partire dalle loro ricerche e dai loro acquisti, ma anche tracciando i movimenti e gli spostamenti, quindi la posizione.

Ogni 4-5 minuti i sistemi operativi Android e iOS si connettono ai rispettivi server back-end per trasmettere i dai raccolti. Non c’è modo, sembra, di evitare tutto questo, perché anche disattivando la telemetria pare che lo scambio di dati avvenga comunque.

Il collegamento al server avviene anche se il telefono non è utilizzato, basta poi toccare anche per sbaglio lo schermo per riattivare l’opzione di telemetria, che è automatica.

Questo è il caso di app abbastanza popolari come Google Search, Google Maps, Google Assistant, YouTube e Google Doc, nel caso di Android, mentre per l’iOS parliamo di Siri, Safari e iCloud ad esempio.

Impossibile disattivare la telemetria

Una conferma di questo arriva dal ricercatore Douglas Leith, in una nota nel report accademico dedicato alla ricerca, secondo cui: “Sia iOS che Android continuano a trasmettere la telemetria del device anche se l’utente ha scelto consapevolmente di disattivare questa funzione”.

Inoltre, lo studioso ha anche scoperto che la quantità di dati raccolti in telemetria da Android per Google è 20 molte più grande di quella ottenuta da Apple tramite iOS.

Nei primi 10 minuti di avvio di Android, Google Pixel invia 1 MB circa di dati ai server della casa madre, contro i 42 KB inviati dall’iPhone verso Apple nello stesso periodo di tempo.

Anche se inattivo, il device con sistema operativo Android invierà sempre 1 MB di dati ogni 12 ore, contro i 52 KB di Apple.

https://www.key4biz.it/telemetria-e-raccolta-di-dati-impossibile-disattivarla-su-device-android-e-ios/353668/




Websites of EU Mobile Providers Fail to Properly Secure User Data: Report

Sensitive data pertaining to the customers of top mobile services providers in the European Union is at risk of compromise due to improperly secured websites, data security and privacy firm Tala reveals.

An analysis of the websites of 13 of the top mobile telecom companies in the EU has revealed that none of them has in place even the minimum necessary protections to be considered secure.

“With over 235 million customers between them, none of the mobile providers scored a passing grade for website security. Where a score of 80+ is considered reasonable and 50 is barely a passing grade, none of the mobile providers analyzed comes close,” Tala says in a new report.

Despite the lack of proper website protections, however, during online sign-up, the telcos collect a significant amount of sensitive data from their customers, including names, emails, addresses, dates of birth, passport numbers, payslips, and even banking details in some cases.

All of the gathered data, Tala claims, might be at risk of compromise through vulnerabilities and the use of third-party code: the average number of JavaScript integrations was found to be 162, while forms were found exposed to an average of 19 third parties.

All of the websites, the report reveals, use dangerous JavaScript functions that open the door to cross-site scripting (XSS), the most common type of website vulnerability. The highest number of JavaScript integrations on a single site was 735.

The sensitive data that customers enter on the websites of these mobile opertors is also potentially exposed through the forms employed to gather the data, as these connect to a large number of domains, revealing extensive data sharing, “25% more than the global Alexa 1000 average for websites,” Tala notes.

“When website owners fail to secure data as it is entered into their websites, they’re effectively leaving it hanging; the only reason it’s not being stolen is that criminals haven’t taken it. Yet,” the company points out.

The research also revealed that none of the analyzed websites had in place the necessary protections to prevent unintentional data exposure, and any piece of third-party code running on the website could be used to “modify, steal or leak information through client-side attacks enabled by JavaScript,” the report reads.

While the data sharing in most cases was done through whitelisted, legitimate applications, the website owner wasn’t always aware of the type of data that these applications would collect, or the extent of the data collection.

“Even whitelisted apps can be exploited to exfiltrate data, with significant implications for data privacy, and by extension, GDPR. Unfortunately, the analysis indicates that none of the EU telcos analyzed here has sufficient awareness of the risk,” Tala notes.

Related: Vulnerability That Allows Complete WordPress Site Takeover Exploited in the Wild

Related: Website Security Breach Exposes 1 Million DNA Profiles

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/nF7njitEo4A/websites-eu-mobile-providers-fail-properly-secure-user-data-report




Dutch Data Protection Authority Fines Booking.com Over Incident Notification

The Dutch Data Protection Authority announced on Wednesday that it has issued a fine of €475,000 (roughly $550,000) to online travel agency Booking.com for failing to report a data security incident within the required timeframe.

According to the privacy watchdog, the incident took place in December 2018 and it involved cybercriminals using voice phishing (vishing) and social engineering to trick the employees of 40 hotels in the United Arab Emirates into handing over their credentials for their Booking.com accounts.

The cybercrooks then used that access to obtain information on more than 4,000 individuals who had booked a hotel through Booking.com. They also managed to access payment card information belonging to nearly 300 people and attempted to phish the card information of others by posing as Booking.com employees over the phone or email.

The Dutch agency fined Booking.com because the company is based in the Netherlands. The travel company learned about the data breach on January 13, 2019, but only notified the Data Protection Authority on February 7 — the incident should have been reported within 72 hours. Impacted customers were notified by Booking.com on February 4.

Contacted by SecurityWeek, Booking.com highlighted that the fine is related to the late notification and is not connected to the company’s security practices or its handling of the incident.

“A small number of hotels inadvertently provided their Booking.com account login details to online scammers, but there was no compromise of the code or databases that power the Booking.com platform. After receiving the first reports of suspicious activity, we began working to understand and resolve the issue, but unfortunately didn’t get the matter escalated as fast as we would have liked internally,” the company said in an emailed statement.

It added, “We have since taken additional steps to improve awareness and education amongst our partners and employees on important privacy measures and general security processes, while also working to further optimize the speed and efficiency of our internal reporting channels. The protection and security of personal data is and will remain a top priority at Booking.com.”

Related: Airlines That Manage Booking Systems Themselves Expose Customer Data

Related: Pentagon Reveals Cyber Breach of Travel Records

Related: Orbitz Data Breach Impacts 880,000 Payment Cards

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/2U5EI5aEcTI/dutch-data-protection-authority-fines-bookingcom-over-incident-notification




Cina: i sistemi di riconoscimento facciale sotto attacco degli hacker


Il governo di Pechino sta puntando tutto sull’AI per identificare le persone tramite sistemi biometrici, ma si moltiplicano gli abusi.

Sono strumenti suggestivi ma ancora lontani da essere affidabili. I sistemi di riconoscimento facciale soffrono ancora di qualche “piccolo” problema a livello di sicurezza e la dimostrazione arriva dalla Cina, uno dei paesi che ha investito di più sull’implementazione dei di autenticazione biometrica.

Il governo di Pechino, infatti, sta utilizzando il riconoscimento facciale in qualsiasi ambito: dal controllo sociale alla gestione degli abbonamenti del trasporto pubblico per arrivare ai rapporti con la Pubblica Amministrazione.

I problemi, però, non mancano e secondo organi di stampa cinesi si stanno moltiplicando i casi in cui gruppi di hacker sfruttano le vulnerabilità dei sistemi di riconoscimento facciale per aggirare i controlli o mettere a segno vere e proprie truffe.

riconoscimento facciale

L’ultimo caso, in ordine di tempo, riguarda un procedimento penale che ha coinvolto due truffatori che hanno messo in piedi uno schema che gli permetteva di sottrarre denaro (circa 500 milioni di Yuan, pari a 65 milioni di euro) attraverso rimborso dell’IVA illegittimi.

Stando a quanto riporta una fonte di stampa locale (il testo è in cinese ma la versione inglese di Google Translator lo rende abbastanza intellegibile) i due imputati per truffa avrebbero usato una tecnica piuttosto semplice per ingannare i sistemi governativi.

Dopo essersi procurati le fotografie di ignari cittadini e averle “animate” utilizzando una semplice applicazione, i due truffatori avrebbero trovato il modo di “dirottare” il video così ottenuto per sostituire le riprese della fotocamera dello smartphone.

Grazie a questo stratagemma, i criminali sarebbero riusciti ad accedere ai sistemi governativi e registrare delle società di facciata, per poi emettere false fatture e incassare i rimborsi IVA.

Il caso, però, sarebbe solo la punta dell’iceberg. La stessa tecnica verrebbe utilizzata, per esempio, allo scopo di ingannare i sistemi che regolano l’accesso in azienda per simulare la presenza sul posto di lavoro.

Insomma: dalle parti di Pechino si stanno facendo i conti con una tecnologia che mostra ancora elementi di immaturità e che con l’evoluzione dei deep fake rischia di entrare in una vera crisi.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/03/31/cina-i-sistemi-di-riconoscimento-facciale-sotto-attacco-degli-hacker/?utm_source=rss&utm_medium=rss&utm_campaign=cina-i-sistemi-di-riconoscimento-facciale-sotto-attacco-degli-hacker




CompuCom Cyber-Attack Costs Could Reach $28M

The financial impact from a March 1 cyber-attack on CompuCom, a wholly-owned subsidiary of ODP Corporation, is expected to reach the $28 million range, the company said.

Following the incident, which resulted in some of the managed services provider’s systems being infected with malware, customer services and internal operations were suspended, but ODP now says that significant progress was made in restoring services.

Although no technical details on the incident were revealed, ODP claims that “the down time experienced and related impact due to the malware incident” will impact the revenue for March, with the financial results for the first fiscal quarter of 2021 likely impacted.

Thus, ODP estimates the loss of revenue to be between $5.0 million and $8.0 million, mainly the result of temporarily suspending services to certain customers.

Furthermore, the company expects expenses of up to $20 million associated with the incident, with approximately $10 million to be accrued during the first quarter of 2021.

These expenses, ODP says, are related to service restoration efforts and to addressing “certain other matters resulting from the incident.” Some of these expects might be covered by insurance, the company adds.

While delivery capabilities were substantially restored by March 17, the service delivery for all customers is only expected to be restored by the end of March 2021. CompuCom also took steps to harden the security of its systems.

ODP will provide further information on its first quarter financial performance during its first quarter earnings call, currently scheduled for May 5, 2021.

Related: Universal Health Services Takes $67 Million Hit From Cyberattack

Related: Packaging Giant WestRock Says Ransomware Attack Hit Production

Related: Trucking Giant Says Ransomware Attack Had $7.5M Impact

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/G5X5thzGGhk/compucom-cyber-attack-costs-could-reach-28m




Report: US Gov Executive Order to Mandate Data Breach Disclosure

A proposed executive order would set new rules on the disclosure of data breaches that also affect United States government agencies, according to a Reuters news report.

The report said the executive order, which could be released as soon as the next week, would require software vendors to notify U.S. government customers of cyber-security breaches that also affect them.

Furthermore, the order is expected to force federal agencies to improve their security posture through the adoption of multi-factor authentication and data encryption within their environments.

When it comes to programs deemed critical, vendors might be forced to provide a “software bill of materials,” detailing program components and offering increased visibility into resources that could introduce additional vulnerabilities.

Per the order, software vendors would be asked to work together with specialized government agencies, such as the FBI and CISA, when investigating cyber-incidents.

Likely a reaction to the recent SolarWinds attacks, the order is expected to impact the interaction between major software vendors and government agencies.

More than one hundreds organizations, including multiple federal agencies, have been confirmed to be affected by the SolarWinds hack, but the overall number of victims could be greater.

What’s more, the SolarWinds attack is only one of the many cyber-incidents involving private companies that also has a major impact on government agencies. A December 2020 cyber-attack was linked to an assault on FireEye, which tests the defenses of thousands of customers, including federal, state and local governments.

In September 2020, Tyler Technologies, which provides software and services for state and local governments, disclosed a ransomware incident. However, the company said that software hosted for its clients was not affected.

Related: China-Linked Hackers Exploited SolarWinds Flaw in U.S. Government Attack

Related: U.S. Says Russian Hackers Stole Data From Two Government Servers

 

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/7xEDwn0CS9Y/report-us-gov-executive-order-mandate-data-breach-disclosure