Data Privacy Startup TripleBlind Raises $8.2 Million in Seed Funding

TripleBlind, a Kansas City, Missouri-based startup that provides data privacy solutions, on Monday announced raising $8.2 million in seed funding.

The oversubscribed funding round was led by Dolby Family Ventures, with participation from several companies and angel investors. Investors include Okta Ventures, NextGen Venture Partners, Operator Partners, Wavemaker Three-Sixty Health, AVG Basecamp Fund, Anorak Ventures, Quiet Capital, Clocktower Technology Ventures, Parity Responsible Technology Fund, Manresa Ventures, Accenture Ventures, Flyover Capital and KCRise Fund.

TripleBlind told SecurityWeek that it emerged from stealth mode in November 2020, when Accenture announced a strategic investment in the company.

Founded in 2019, TripleBlind has developed a de-identification and data privacy solution that enables organizations to share, use and monetize sensitive information — including personal, financial and health data — without the fear of violating privacy requirements and government regulations.

The company’s data privacy and API-driven virtual exchange solution encrypts data and allows users to perform approved operations, but without the need to actually decrypt the data.

“The return of all previous investors, the breadth of new investors and the oversubscription of the round demonstrate to us that data privacy experts support our new, breakthrough approach for enforcing data privacy while enabling organizations to leverage and gain insights from data,” said Riddhiman Das, co-founder and CEO of TripleBlind.

He added, “Thanks to our forward-looking investors, TripleBlind can accelerate our mission to free trapped data so enterprises can collaborate while concurrently enforcing data privacy and regulatory standards.”

Related: Data Privacy Management Firm WireWheel Raises $20 Million

Related: Data Protection Firm BigID Raises $70 Million at $1 Billion Valuation

Related: Data Privacy Firm Privitar Raises $80 Million in Series C Funding Round

Related: Privacy Management Firm OneTrust Raises $210 Million at $2.7 Billion Valuation

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/Obpa7MkGQrY/data-privacy-startup-tripleblind-raises-82-million-seed-funding




Judge Approves $650M Facebook Privacy Lawsuit Settlement

A federal judge on Friday approved a $650 million settlement of a privacy lawsuit against Facebook for allegedly using photo face-tagging and other biometric data without the permission of its users.

U.S. District Judge James Donato approved the deal in a class-action lawsuit that was filed in Illlinois in 2015. Nearly 1.6 million Facebook users in Illinois who submitted claims will be affected.

Donato called it one of the largest settlements ever for a privacy violation.

“It will put at least $345 into the hands of every class member interested in being compensated,” he wrote, calling it “a major win for consumers in the hotly contested area of digital privacy.”

Jay Edelson, a Chicago attorney who filed the lawsuit, told the Chicago Tribune that the checks could be in the mail within two months unless the ruling is appealed.

“We are pleased to have reached a settlement so we can move past this matter, which is in the best interest of our community and our shareholders,” Facebook, which is headquartered in the San Francisco Bay Area, said in a statement.

The lawsuit accused the social media giant of violating an Illinois privacy law by failing to get consent before using facial-recognition technology to scan photos uploaded by users to create and store faces digitally.

The state’s Biometric Information Privacy Act allowed consumers to sue companies that didn’t get permission before harvesting data such as faces and fingerprints.

The case eventually wound up as a class-action lawsuit in California.

Facebook has since changed its photo-tagging system.

RelatedFTC Fines Facebook $5B, Adds Limited Oversight on Privacy

view counter

Previous Columns by Associated Press:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/RMLKiJfkx8k/judge-approves-650m-facebook-privacy-lawsuit-settlement




TikTok agrees to proposed $92 million settlement in privacy class action

TikTok agrees to proposed $92 million settlement in privacy class action

TikTok parent company ByteDance has agreed to a $92 million deal to settle class-action lawsuits alleging that the company illegally collected and used underage TikTok users’ personal data.

The proposed settlement (PDF) would require TikTok to pay out up to $92 million to members of the class and to change some of its data-collection processes and disclosures going forward.

The suit, which rolled up more than 20 related lawsuits, mostly filed on behalf of minors, alleged that TikTok violated both state and federal privacy laws, including the Computer Fraud and Abuse Act and the Video Privacy and Protection Act, through its use of data.

TikTok uses “automated software, proprietary algorithms, AI, facial recognition, and other technologies to commercially profit from” its users, the complaint (PDF) alleged. The data that TikTok allegedly collects, shares, and uses for machine learning training goes surprisingly deep, the suit added, including users’ “identities, unique identifying information, biometric data and information, images, video and digital recordings, audio recordings, clipboard data, geolocation, names, email addresses, passcodes, social media accounts, messaging services, telephone numbers, and other private, nonpublic, or confidential data and information.”

Additionally, the suit cited concerns that private and personally identifiable user data TikTok collected could have been shared with Chinese government entities, echoing the Trump administration’s concerns in its failed attempts to ban TikTok from operating in the US.

TikTok denied any specific wrongdoing. “While we disagree with the assertions, rather than go through lengthy litigation, we’d like to focus our efforts on building a safe and joyful experience for the TikTok community,” the company said in a statement.

Money for the taking—unless everyone asks

Attorneys representing the plaintiffs touted the settlement as “one of the largest ever achieved” in such a case. Inasmuch as their assertion is true, it comes out as far more damning of the state of US privacy laws than complimentary of this particular case.

The total class, as defined in the settlement, includes 89 million US users. The attorneys ask for a collective payment “not to exceed 33.33% of the settlement fund,” leaving $61 million for the class members to collect. On top of that, however, the proposed deal is structured such that each member of the “national” class can claim a share, and Illinois users can claim six shares.

TikTok identified 1.4 million users who would qualify in the Illinois subclass, leaving about 87.6 million other class members nationwide. According to the settlement, if every qualified member of the class filed for a claim, most users could expect to reap about $0.96 and Illinois users could get as much as $5.75.

In the filing, however, attorneys make clear that they do not expect a high percentage of the class to file claims, instead describing likely payouts for hypothetical claims rates from 1.5 percent ($383.33 for Illinois, $63.89 for everyone else) to 20 percent ($28.75 for Illinois, $4.79 for everyone else) of the class.

Of course, money isn’t everything; lawsuits such as this class action often seek injunctive relief as well—that is, requiring the company not to do the bad thing anymore. This agreement is no different. Under the proposed terms, TikTok will implement a “companywide data privacy training initiative” to instruct employees and contractors to comply with data privacy laws.

As for its collection, storage, and use of sensitive data, TikTok does not actually say in the settlement that it will stop those activities, but it says instead that it will update its privacy policies to make sure those activities are more clearly disclosed “and in compliance with all applicable laws.”

A judge will have to approve the proposed settlement before it goes into effect; the process is expected to take several months.

https://arstechnica.com/?p=1745503




Italia seconda in Europa per la presenza di Stalkerware


La ricerca di Kaspersky conferma l’abuso di software spia per smartphone nel settore privato. Peggio di noi fa solamente la Germania.

Li hanno battezzati con il nome di Stalkerware e, secondo gli esperti di sicurezza, rappresentano ormai una minaccia per la privacy estremamente diffusa, al punto che nel 2019 è stato avviato un progetto per contrastarne la diffusione.

Ma di cosa si tratta? In estrema sintesi, gli Stalkerware sono veri e propri trojan, spesso “travestiti” da applicazioni per il parental control, che vengono utilizzati per spiare il partner consentendo di leggerne le comunicazioni e tracciarne la posizione attraverso il GPS . In molti casi, il loro utilizzo è collegato a episodi di abusi o violenza domestica.

A scattare una “fotografia” del fenomeno è in questi giorni Kaspersky, che ha pubblicato su Internet un rapporto intitolato “La situazione dello stalkerware nel 2020”.

“Gli stalkerware sono una forma di cyberviolenza” spiegano gli esperti della società di sicurezza. “Si tratta di un fenomeno globale che colpisce tutti i Paesi indipendentemente dalle dimensioni o dalla cultura”.

La classifica stilata da Kaspersky, effettivamente, mostra una composizione molto eterogenea: tra i 10 Paesi più colpiti dal fenomeno ci sono Russia, Brasile, Stati Uniti, India, Messico, Germania (primo Paese in Europa per diffusione del fenomeno) Iran, Italia, Regno Unito e Arabia Saudita.

Stalkerware

Il nostro paese, rispetto all’anno scorso, è sceso di due posizioni (era sesto) nella classifica globale, ma c’è poco da rallegrarsi. Il cambio di posizione, così come il calo dei numeri globali registrati, è dovuto più che altro a una temporanea contrazione del fenomeno provocato dalle restrizioni legate alla pandemia da Covid 19.

Nei periodi di lockdown, in cui le persone sono costrette a casa, è infatti probabile che la tentazione di controllare a distanza il partner sia stata meno forte.

Un’interpretazione confermata dagli esperti di Kaspersky, che hanno registrato un calo nei casi segnalati nel periodo tra marzo e giugno 2020, con poi una ripresa del fenomeno che si è stabilizzato nei mesi seguenti.

“Il numero di utenti colpiti da stalkerware è comunque molto alto e ogni giorno rileviamo nuovi campioni” spiega Morten Lehn, General Manager Italy di Kaspersky. “È importante ricordare che dietro ogni numero si nasconde una persona e, a volte, una silenziosa richiesta di aiuto”.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/02/26/italia-seconda-in-europa-per-la-presenza-di-stalkerware/?utm_source=rss&utm_medium=rss&utm_campaign=italia-seconda-in-europa-per-la-presenza-di-stalkerware




Security, Privacy Issues Found in Tens of COVID-19 Contact Tracing Apps

An analysis of 40 COVID-19 contact tracing applications for Android has led to the discovery of numerous security and privacy issues, according to a new research paper.

Contact tracing applications have been created to help authorities automate the process of identifying those who have been in close contact with infected individuals.

Using a newly developed tool called COVIDGuardian, which was designed for both static and dynamic program analysis, academic researchers with universities in Australia and the United Kingdom analyzed 40 worldwide Android contact tracing apps and discovered potential security risks in more than half of them.

COVIDGuardian, an automated security and privacy assessment tool, was used to assess the security performance of the analyzed applications against four categories, namely manifest weaknesses, general security vulnerabilities, data leaks (with a focus on personally identifiable information), and malware detection.

Identified issues, the researchers say, include the use of insecure cryptographic algorithms (72.5%), the storing of sensitive information in clear text (55%), insecure random values (55%), permissions to perform backups (roughly 42.5% of apps), and the inclusion of trackers (20 trackers were identified in approximately 75% of the apps).

The research has revealed that the security of these apps is only slightly influenced by the use of a decentralized architecture, but also the fact that users are more likely to install a contact tracing app that has stronger privacy settings.

After being contacted by the researchers, some of the application developers addressed identified issues, including the leak of information and the inclusion of trackers. Other apps, however, were found to include even more vulnerabilities and trackers after they were updated.

The researchers also conducted a survey of more than 370 people regarding the use of contact tracing apps, their concerns, and their preference on centralized or decentralized apps.

“Security and privacy concerns have been a big issue affecting the uptake of these apps,” said Dr Gareth Tyson, senior lecturer at Queen Mary University of London and one of the authors of the study. “We were surprised that the debate around decentralised vs centralised apps didn’t seem so important and, instead, users were more focused on the exact details of what private information is collected. This should encourage developers to offer stronger privacy guarantees for their apps.”

Related: Singapore Admits Police Can Access Contact-Tracing Data

Related: New Trials in England for Troubled Virus Tracing App

Related: COVID-19 Contact Tracing Apps: Effective Virus Risk Management Tools or Privacy Nightmare?

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/rdhVjzRFXYM/security-privacy-issues-found-tens-covid-19-contact-tracing-apps




TikTok owner ByteDance to pay $92M in US privacy Settlement

TikTok’s Chinese parent company ByteDance has agreed to pay $92 million in a settlement to U.S. users who are part of a class-action lawsuit alleging that the video-sharing app failed to get their consent to collect data in violation of a strict Illinois privacy law.

The federal lawsuit alleged that TikTok broke the Illinois biometric privacy law, which allows suits against companies that harvest consumer data without consent, including via facial and fingerprint scanning. Illinois is the only state with a law that allows people to seek monetary damages for such unauthorized data collection.

“While we disagree with the assertions, rather than go through lengthy litigation, we’d like to focus our efforts on building a safe and joyful experience for the TikTok community,” TikTok said in an emailed statement.

Facebook agreed to a $550 million settlement under the same law last February. The TikTok settlement must still be approved by a federal judge.

Privacy advocates have praised the law as the nation’s strongest form of protection in the commercial use of such data, and it has survived ongoing efforts by the tech industry and other businesses to weaken it.

Illinois is one of three states that have laws governing the use of biometric data. But the other two, Texas and Washington, don’t permit individual lawsuits, instead delegating enforcement to their attorneys general.

RelatedBiometrics – Dismantling the Myths Surrounding Facial Recognition

view counter

Previous Columns by Associated Press:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/PDu8vOaEyo4/tiktok-owner-bytedance-pay-92m-us-privacy-settlement




Tutti i problemi di sicurezza di Alexa


Il sistema di interazione dell’assistente vocale di Amazon con altre applicazioni apre degli spazi che i pirati informatici potrebbero sfruttare per attaccare gli utenti.

Si chiamano “skill” e sono funzionalità che consentono all’assistente vocale Alexa di interagire con altre app. Un sistema che è stato pensato per espandere le funzionalità dell’ecosistema Amazon, ma che secondo gli esperti di sicurezza hanno caratteristiche ben poco rassicuranti sotto il profilo della sicurezza.

A mettere in fila tutti i problemi legati alle “attività collaterali” di Alexa ci hanno pensato i ricercatori dell’Università di Bochum. Christopher Lentzsch e Martin Degeling, che firmano un report sul tema, snocciolando una serie di problematiche legate all’uso di Alexa in questa modalità.

Il primo problema, spiegano i ricercatori, riguarda il fatto che chiunque possa rendere disponibili skill utilizzando nomi di aziende ben conosciute che, in realtà, non hanno nulla a che fare con gli sviluppatori dell’applicazione. In altre parole, sarebbe possibile per chiunque fare leva sulla reputazione di aziende conosciute per garantirsi quel livello di “fiducia” che potrebbe esporre gli utenti a violazioni della privacy.

Non solo: il sistema che ha implementato Amazon per proteggere l’accesso a dati sensibili sarebbe, stando a quanto si legge nel report, facilmente aggirabile. In questo modo, uno sviluppatore potrebbe accedere a determinate informazioni senza che il proprietario del dispositivo possa saperlo.

Alexa

Un ulteriore problema, poi, sarebbe rappresentato dalla possibilità di eseguire attacchi basati su tecniche di “skill squatting”, cioè l’uso di nomi e denominazioni simili a quelle di altre skill considerate molto popolari. Uno stratagemma, questo, cui non si ricorre necessariamente per scopi malevoli, ma che spesso viene utilizzato semplicemente per ottenere un po’ di visibilità facendo leva sull’equivoco.

Insomma: il bilancio del livello di sicurezza garantito da Alexa non è propriamente positivo e alle rivelazioni dei ricercatori tedeschi si aggiunge il carico da novanta di un altro report, che riassume una serie di problematiche a livello di security che affliggono l’assistente vocale.

Lo studio, a firma di ricercatori statunitensi, elenca una serie di criticità già note (qui il link per consultarlo) emerse negli ultimi anni e che evidenziano tutti i rischi legati all’uso di Alexa.

Molti dei problemi, si legge, sarebbero stati riconosciuti da Amazon, che si sarebbe impegnata ad avviare un percorso di revisione del funzionamento del suo assistente vocale per correggere le problematiche indicate dai ricercatori.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/02/25/tutti-i-problemi-di-sicurezza-di-alexa/?utm_source=rss&utm_medium=rss&utm_campaign=tutti-i-problemi-di-sicurezza-di-alexa




Firefox 86 brings multiple Picture-in-Picture, “Total Cookie Protection”

Mozilla released Firefox 86 yesterday, and the browser is now available for download and installation for all major operating systems, including Android. Along with the usual round of bug fixes and under-the-hood updates, the new build offers a couple of high-profile features—multiple Picture-in-Picture video-watching support, and (optional) stricter cookie separation, which Mozilla is branding Total Cookie Protection.

Taking Firefox 86 for a spin

Firefox 86 became the default download at mozilla.org on Tuesday—but as an Ubuntu 20.04 user, I didn’t want to leave the Canonical-managed repositories just to test the new version. This is one scenario in which snaps truly excel—providing you with a containerized version of an application, easily installed but guaranteed not to mess with your “real” operating system.

As it turns out, Firefox’s snap channel didn’t get the message about build 86 being the new default—the latest/default snap is still on build 85. In order to get the new version, I needed to snap refresh firefox --channel=latest/candidate.

With the new version installed as a snap, the next step was actually running it—which could be a lot easier. The snap produces a separate Firefox icon in Ubuntu’s launcher, but there’s no way I know of to readily distinguish between the icon for the system firefox and the new snap-installed firefox. After some hit-and-miss frustration, I finally dropped to the terminal and ran it directly by issuing the fully pathed command /snap/firefox/current/firefox.

Multi Picture-in-Picture Mode

In December 2019, Firefox introduced Picture-in-Picture mode—an additional overlay control on in-browser embedded videos that allows the user to detach the video from the browser. Once detached, the video has no window dressing whatsoever—no title bar, min/max/close, etc.

PiP mode allows users who tile their windows—automatically or manually—to watch said video while consuming a bare minimum of screen real estate.

Firefox 86 introduces the concept of multiple simultaneous Picture-in-Picture instances. Prior to build 86, hitting the PiP control on a second video would simply reattach the first video to its parent tab and detach the second. Now, you can have as many floating, detached video windows as you’d like—potentially turning any monitor into something reminiscent of a security DVR display.

The key thing to realize about multi-PiP is that the parent tabs must remain open—if you navigate away from the parent tab of an existing PiP window, the PiP window itself closes as well. Once I realized this, I had no difficulty surrounding my Firefox 86 window with five detached, simultaneously playing video windows.

Total Cookie Protection

In December, we reported on Firefox 85’s introduction of cache partitioning—a scheme which makes it more difficult for third parties to figure out where you have and have not been on the Internet. Firefox 86 ups the ante again, with a scheme Mozilla is calling “Total Cookie Protection.”

In a nutshell, Total Cookie Protection restricts the ability of third parties to monitor your movement around the Web using embedded elements such as scripts or iframes. This prevents tracking cookies from Facebook, Amazon, et al. from “following you around the web.”

In theory, cookies were already strictly per-site—so contoso.com cannot set or read cookies belonging to facebook.com, and vice versa. But in practice, if contoso.com willingly embeds active Facebook elements in its site, the user’s browser treats those elements as belonging to Facebook itself. That means Facebook can set the value of a cookie while you’re browsing contoso.com, then read that value again later when you’re actually on Facebook (or when you’re on other, entirely unrelated sites which also embed Facebook content).

Total Cookie Protection nerfs this misfeature by creating separate “cookie jars” based on the identity of the URL actually present in the address bar. With this feature enabled, a Facebook script running at contoso.com can still set and read a Facebook cookie—but that cookie lives within the contoso.com cookie jar only. When the same user browses facebook.com directly, later, Facebook cannot read, write, or even detect the presence of a Facebook cookie within the contoso.com cookie jar, or vice versa.

This isn’t a panacea against tracking, by any means—for example, it does nothing to prevent scripts from Facebook, Amazon, et al. from uploading data about your Web travels to their own servers to profile you there. But it at least keeps them from using your own computer’s storage to do the dirty work for them.

No, the other TCP

If you want to enable Total Cookie Protection (and we really, really wish Mozilla had picked a name that didn’t initialize to TCP), you’ll first need to set your Enhanced Tracking Protection to the Strict profile. To do so, click the shield icon to the left of the address bar (visible when browsing any actual website, not visible on the blank New Tab screen) and click Protection Settings. From there, you can change your ETP profile from Standard to Strict.

Total Cookie Protection has a few (apparently hard-coded) exemptions for third-party login providers—for example, logging into YouTube with a personal Gmail account still allowed a visit to Gmail.com in another tab to instantly load the correct inbox without the need to log in again separately.

Mozilla warns that the Strict Enhanced Tracking Profile may break some sites entirely—and we believe Mozilla—but in our own cursory testing, we didn’t encounter any problems. We had no difficulty loading and logging in to Gmail, YouTube, Facebook, Twitter, and several other major sites.

Listing image by Airwolfhound / Flickr

https://arstechnica.com/?p=1744857




Report Exprivia sulla cybersecurity: crescono i reati in Italia. Nel mirino PA e sanità

I cyber criminali non vanno in vacanza, non dormono e non si ammalano, sono sempre in agguato dietro ad ogni mail che ci arriva, ad ogni device connesso in rete, ad ogni transazione finanziaria e dietro ad ogni acquisto di prodotto o servizio.

Il 2020 è stato un anno terribile, che ricorderemo per il resto della nostra vita a causa della pandemia globale di Covid-19, delle sue conseguenze sulle nostre vite, dei costi umani, sociali ed economici che ha determinato.

<!-- LARGE RECTANGLE POST - CORPO TESTO

-->

Ricorderemo questo anno anche per l’impennata dei cyber attacchi e dei reati informatici nel nostro Paese.

Il nuovo Report Exprivia sul cybercrime

Secondo un nuovo Rapporto dell’Osservatorio Cybersecurity di Exprivia, nel periodo ottobre-dicembre 2020 si sono registrati 237 crimini informatici, in crescita del +60% sul trimestre precedente e quasi del +400% rispetto al periodo gennaio-marzo, quando furono solo 49.

Per i ricercatori, è il mese di marzo il vero spartiacque in termini di crescita degli attacchi: con l’iniziò della pandemia e, con essa, della diffusione dello smart working, si è assistito a un’impennata tra attacchi informatici, violazioni della privacy e incidenti in tutti i settori dell’economia e della pubblica amministrazione.

Il mese di dicembre, invece, con 96 eventi criminali, è stato quello che ha registrato il numero record di cyber attacchi nel 2020.

Se da un lato la pandemia ha accelerato la digitalizzazione nel nostro Paese, dall’altro la sicurezza della rete è stata messa a dura prova. A stupirci maggiormente è che la vulnerabilità più sfruttata dagli attaccanti sia il fattore umano”, ha affermato Domenico Raguseo, direttore Cybersecurity Exprivia.

È necessario quindi per tutti noi – ha aggiunto Raguseo – prendere consapevolezza dei rischi che si corrono in rete, iniziando a diffidare delle anomalie”.

Ad esempio – ha concluso il direttore – dai video o dalle gif inattesi che riceviamo sulle app di messaggistica istantanea, dagli errori di sintassi contenuti nelle email sospette, dai domini non veritieri degli indirizzi di posta o dall’improvvisa velocità con cui navighiamo sul pc. Siamo noi i primi a poterci proteggere dagli attaccanti”.

Obiettivi e tipologia di attacco

In gran parte, i cyber attacchi hanno riguardato il furto di dati in Italia, con oltre il 60% degli eventi criminali.

Segue la violazione della privacy, con il 13% dei casi, dato praticamente triplicato rispetto all’inizio del 2020, e la perdita di denaro nel 10% degli attacchi.

In termini di tecniche informatiche più utilizzate dai criminali della rete, al primo posto c’è il “phishing-social Engineering”, con il 43% dei casi.

Questa soluzione colpisce in maniera particolare utenti distratti o con poca conoscenza delle modalità di adescamento tramite email o social network.

Seguono, gli attacchi “unknown (24% sul totale degli eventi), ossia nuove metodologie sperimentate dagli hacker per non essere rilevati dai meccanismi di difesa tradizionali.

Non sono da meno i classici malware (23%), il cui utilizzo è quadruplicato nel corso dell’anno.

I settori più colpiti dai cyber attacchi

I settori, invece, più presi di mira sono stati la Pubblica Amministrazione, con 91 eventi, e il settore finanziario, con 81 eventi,.

E’ il risultato questo dei rapidi cambiamenti intercorsi nella digitalizzazione delle amministrazioni pubbliche e nella diffusione di applicazioni bancarie e di numerose soluzioni per i pagamenti digitali.

Particolare attenzione va infine rivolta al settore sanitario, al centro di rilevanti piani di investimento pubblici per potenziare il sistema nella lotta alla pandemia.

Se anche non è risultato un numero alto di attacchi ed eventi di cyber crime, comunque merita attenzione soprattutto per la criticità degli stessi, se si pensa al valore dei dati sanitari rubati e utilizzati nel dark web.

Dall’analisi degli esperti Exprivia, è emerso che nell’ultimo anno i dispositivi medicali sono stati esposti a molteplici vulnerabilità, a partire da quelli personali utilizzati da medici e pazienti per l’assistenza a distanza.

I cyber criminali, infatti, si impossessano del controllo di un dispositivo bloccando il servizio o manomettendo le funzionalità, con il fine di acquisire informazioni sensibili.

https://www.key4biz.it/report-exprivia-cyber-reati-in-aumento-in-italia-colpiti-pa-finanza-e-sanita/347093/




New Firefox Feature Ups the Ante Against Cookie-Based Tracking

Mozilla this week announced improved user privacy in Firefox 86, with the introduction of a new feature aimed at preventing the tracking of users from site to site.

Called Total Cookie Protection and built into Enhanced Tracking Protection (ETP) Strict Mode, the new feature was designed to confine cookies to the websites that created them, and complements the Supercookie Protections that Mozilla introduced in Firefox 85 last month.

“Cookies, those well-known morsels of data that web browsers store on a website’s behalf, are a useful technology, but also a serious privacy vulnerability. That’s because the prevailing behavior of web browsers allows cookies to be shared between websites,” Mozilla notes.

The browser maker underlines that, with cookies shared between sites, tracking companies can tag a user’s browser and follow their browsing activity. Such cookie-based tracking is used for mass commercial tracking, allowing advertising companies to create detailed personal profiles of users.

For more than two years, courtesy of ETP, Firefox has been blocking cookies from companies identified as trackers, but the new feature is meant to take the protections to the next level, and ensure that no cookie can be used to track a user from site to site.

For that, Total Cookie Protection separates cookies by the sites that created them. Thus, when a site or the third-party content on the site stores a cookie in the browser, it is sent to a “cookie jar” assigned to that site, and never shared with other websites.

However, exceptions are made for cross-site cookies needed for non-tracking purposes, such as the cookies used by third-party login providers.

“Only when Total Cookie Protection detects that you intend to use a provider, will it give that provider permission to use a cross-site cookie specifically for the site you’re currently visiting. Such momentary exceptions allow for strong privacy protection without affecting your browsing experience,” Mozilla says.

Related: Google Moves Away From Diet of ‘Cookies’ to Track Users

Related: Google Says Chrome Cookie Replacement Plan Making Progress

Related: Firefox Cracks Down on Supercookies to Improve User Privacy

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/pg1jhplDVqc/new-firefox-feature-ups-ante-against-cookie-based-tracking