Revenge porn, la prevenzione è l’unico modo per arginare un fenomeno in preoccupante espansione

Nonostante la recente introduzione del cosiddetto “Codice Rosso”, ovvero una legge a tutela del genere femminile e dei soggetti deboli che subiscono maltrattamenti, vi è un importante aumento statistico sui casi di revenge porn

È notizia di poche ore fa la sentenza che ha condannato a tredici mesi di reclusione la dirigente scolastica che aveva costretto alle dimissioni la maestra che era stata vittima di revenge porn da parte del suo ex compagno e della sua attuale moglie. Quest’ultimo, infatti, con la fondamentale complicità della moglie, aveva diffuso tramite WhatsApp foto intime della maestra in un gruppo utilizzato per giocare a calcetto.

<!-- LARGE RECTANGLE POST - CORPO TESTO

-->

La dirigente scolastica, venuta a conoscenza dei fatti, aveva intimato alla maestra di dimettersi, altrimenti avrebbe agito lei personalmente. Da qui è partito un vero e proprio processo di gogna mediatica che difficilmente potrà essere dimenticato dalla vittima.

Oltre alla dirigente scolastica è stata condannata ad un anno di reclusione l’attuale moglie dell’ex compagno della vittima, “per aver divulgato le immagini osè”. L’ex compagno alla fine è stato assolto, poiché l’attività di divulgazione è risultata essere partita dalla moglie di quest’ultimo. È stata, infine, condannata anche un’altra maestra per violazione della privacy.

Insomma un video hot che si è diffuso a macchia d’olio nelle chat degli abitanti di un piccolo paesino della provincia di Torino e che ha scatenato un vero e proprio tsunami mediatico, coinvolgendo parecchie persone da un punto di vista penale.

Ma cosa è in concreto il Revenge porn? Quanti sanno che si tratta di un reato riconosciuto penalmente?

Il Revenge porn rientra tra i cosiddetti reati informatici e, tradotto letteralmente, vuol dire “vendetta pornografica”. Il sistema è tutto sommato semplice, dal momento in cui si è in possesso di video intimi del proprio partner, o più spesso, ex partner, questi vengono utilizzati o come ricatto per ottenere in cambio qualcosa, o semplicemente divulgandone il contenuto, vendicandosi con l’umiliazione inflitta.

Si riportano nella tabella di seguito alcuni preoccupanti dati pubblicati lo scorso anno dalla rivista Cyber Civil Rights:

Soggetti intervistati 1606
Individui che hanno condiviso foto o video di loro stessi nudi 61%
Vittime revenge porn 23%
Donne vittime di revenge porn 90%
Under 30 68%
Individui con risvolti psicologici negativi 93%

Dai dati appena elencati emergono numeri abbastanza inquietanti. Il dato relativo al 61% di soggetti che hanno condiviso immagini o video intimi con altra gente, lascia pensare che, ad oggi, non vi è ancora una adeguata informazione sui rischi a cui si va incontro; lascia presagire altresì che alla stregua di tali numeri, appare statisticamente più probabile la verificazione di casi di revenge porn.

Ecco, ma per il nostro ordinamento penale cosa vuol dire revenge porn?

Come accennato all’inizio, l’introduzione di questa circostanza di reato è avvenuta tramite il c.d. codice rosso, ovvero tramite la legge n. 69 del 2019. Il caso specifico del revenge porn è stato rubricato attraverso l’inserimento dell’art. 612 ter del codice penale. Il predetto articolo prevede che chiunque diffonde immagini o video a contenuto sessualmente esplicito, senza il consenso delle persone interessate, è punito con una reclusione fino a sei anni e una multa fino a 15.000 euro. È addirittura previsto che la pena sia assoggettata ad un aumento se la diffusione è avvenuta dal coniuge, o ex, o comunque da persona legata affettivamente.

Un aumento è previsto anche se la parte lesa consiste in una persona affetta da condizione di inferiorità fisica o psichica.

A ben vedere, quindi, la disciplina vigente è anche abbastanza pesante. Si possono rischiare fino a 9 anni di carcere. Eppure la divulgazione massiccia di contenuti privati a sfondo sessuale procede in maniera dilagante.

Ma in che modo il colpevole riesce a reperire il materiale oggetto di vendetta?

Per il sistema penale le modalità attraverso le quali reperire il materiale pornografico possono essere diverse e si riassumono nella misura che segue:

– è la stessa vittima, che riponendo fiducia nell’interlocutore, invia materiale sessualmente esplicito;

– vittima e colpevole registrano di comune accordo immagini durante la commissione di un atto di natura sessuale;

– la vittima viene ripresa inconsapevolmente con l’ausilio delle cosiddette spycam, ovvero delle telecamere nascoste;

– il colpevole riesce ad acquisire il materiale attraverso l’hacking dello spazio cloud dell’ignara vittima o impossessandosi di uno dei suoi dispositivi.

Nell’ultimo dei casi elencati entrano in gioco anche altri reati di natura penale, ovvero il furto.

Da un punto di visto prettamente giuridico, il legislatore è intervenuto in maniera pesante, ora la “palla” va nelle mani degli organi statali preposti alla sensibilizzazione e alle numerose associazioni nate a difesa delle vittime di questi abusi. Sono in agenda prossime ad avviare importanti campagne di informazione a scopo preventivo.

Come indicato dai dati statistici, particolare attenzione dovrà essere prestata nei confronti delle donne, che risultano essere vittime di questo reato nel 90% dei casi. Ma la prevenzione è necessaria anche per far comprendere al meglio anche i rischi a cui si va incontro; infondere maggiore consapevolezza sulla severità delle pene a cui si va incontro quando si decide con leggerezza diffondere una foto o un video.

https://www.key4biz.it/revenge-porn-la-prevenzione-e-lunico-modo-per-arginare-un-fenomeno-in-preoccupante-espansione/346862/




Privacy Faces Risks in Tech-Infused Post-Covid Workplace

People returning to work following the long pandemic will find an array of tech-infused gadgetry to improve workplace safety but which could pose risks for long-term personal and medical privacy.

Temperature checks, distance monitors, digital “passports,” wellness surveys and robotic cleaning and disinfection systems are being deployed in many workplaces seeking to reopen.

Tech giants and startups are offering solutions which include computer vision detection of vital signs to wearables which can offer early indications of the onset of Covid-19 and apps that keep track of health metrics.

Salesforce and IBM have partnered on a “digital health pass” to let people share their vaccination and health status on their smartphone.

Clear, a tech startup known for airport screening, has created its own health pass which is being used by organizations such as the National Hockey League and MGM Resorts.

Fitbit, the wearable tech maker recently acquired by Google, has its own “Ready for Work” program that includes daily check-ins using data from its devices.

Fitbit is equipping some 1,000 NASA employees with wearables as part of a pilot program which requires a daily log-in using various health metrics which will be tracked by the space agency.

Microsoft and insurance giant United HealthCare have deployed a ProtectWell app which includes a daily symptom screener, and Amazon has deployed a “distance assistant” in its warehouses to help employees maintain safe distances.

And a large coalition of technology firms and health organizations are working on a digital vaccination certificate, which can be used on smartphones to show evidence of inoculation for Covid-19.

– ‘Blurs the lines’ –

With these systems, employees may face screenings even as they enter a building lobby, and monitoring in elevators, hallways and throughout the workplace.

The monitoring “blurs the line between people’s workplace and personal lives,” said Darrell West, a Brookings Institution vice president with the think tank’s Center for Technology Innovation.

“It erodes longstanding medical privacy protections for many different workers.”

A report last year by the consumer activist group Public Citizen identified at least 50 apps and technologies released during the pandemic “marketed as workplace surveillance tools to combat Covid-19.”

The report said some systems go so far as identifying people who may not spend enough time in front of a sink to note inadequate hand-washing.

“The invasion of privacy that workers face is alarming, especially considering that the effectiveness of these technologies in mitigating the spread of Covid-19 has not yet been established,” the report said.

The group said there should be clear rules on collection and storage of data, with better disclosure to employees.

– A delicate balance –

Employers face a delicate balance as they try to ensure workplace safety without intruding on privacy, said Forrest Briscoe, professor of management and organization at Penn State University.

Briscoe said there are legitimate reasons and precedents for requiring proof of vaccination. But these sometimes conflict with medical privacy regulations which limit a company’s access to employee health data.

“You don’t want the employer accessing that information for work-related decisions,” Briscoe said.

Biscoe said many employers are relying on third-party tech vendors to handle the monitoring, but that has its risks as well.

“Using third-party vendors will keep the data separate,” he said.

“But for some companies their business model involves gathering data and using it for some monetizable purpose and that poses a risk to privacy.”

The global health crisis has inspired startups around the world to seek innovative ways to limit virus transmission, with some of those products shown at the 2021 Consumer Electronics Show.

Taiwan-based FaceHeart demonstrated software which can be installed in cameras for contactless measurement of vital signs to screen for shortness of breath, high fever, dehydration, elevated heart rate and other symptoms which are early indicators of Covid-19.

Drone maker Draganfly showcased camera technology which can be used to offer alerts on social distancing, and also detect changes in people’s vital signs which may be early indicators of Covid-19 infection.

A programmable robot from Misty Robotics, also shown at CES, can be adapted as a health check monitor and can also be designed to disinfect frequently used surfaces like door handles, according to the company.

But there are risks in relying too much on technologies which may be unproven or inaccurate, such as trying to detect fevers with thermal cameras among moving people, said Jay Stanley, a privacy researcher and analyst with the American Civil Liberties Union.

“Employers have a legitimate interest in safeguarding workplaces and keeping employees healthy in the context of the pandemic,” Stanley said.

“But what I would worry about is employers using the pandemic to pluck and store information in a systematic way beyond what is necessary to protect health.”

view counter

© AFP 2020

Previous Columns by AFP:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/K3VHyyNmBhc/privacy-faces-risks-tech-infused-post-covid-workplace




Brussels Okays EU-UK Personal Data Flows

The European Commission lifted the threat of crucial data flows between Europe and Britain being blocked in a move that would have crippled business activity as it said Friday that privacy safeguards in the UK met European standards.

In a key post-Brexit decision, the EU executive said that British authorities had sufficient measures in place to protect European users’ personal data, freeing up data transfers for businesses as well as for police.

The adequacy decision, to be formally adopted by the 27 member states, would ensure that data protection will “never be compromised when personal data travel across the Channel,” said EU Justice Commissioner Didier Reynders.

Businesses will breath a sigh of relief at the decision, with more and more companies relying on cross-border cloud computing and other technology to function everyday.

This was made especially clear during the Covid-19 pandemic as companies, schools and governments increasingly went online, counting on big tech’s networks to operate.

A negative decision would have blocked the transfer of data from EU-based companies to the UK, crippling activity.

– Sensitive issue –

Britain is seeking similar adequacy decisions for its financial services, but this is proving far more contentious, with Brussels giving no clear indication of when a decision will be made.

The EU currently has data adequacy agreements with 12 countries, including Japan, Switzerland and Canada and negotiations are underway with South Korea.

Once approved, personal data transferring through Britain will be treated as if it was moving within the EU.

Oliver Dowden, Britain’s Secretary of State for Digital, said he welcomed the move “although the EU’s progress in this area has been slower than we would have wished.”   

“I am glad we have now reached this significant milestone following months of constructive talks in which we have set out our robust data protection framework,” he added.

The security of personal data has become a sensitive issue, with the EU’s top court having struck down a similar arrangement between the EU and United States.

The European Court of Justice has decided on several occasions that national security laws in the United States are in violation of European privacy standards making the deal illegal.

For the UK, the commission assessed that country’s Investigatory Powers Act of 2016 which contains extensive powers including the ability to carry out bulk data surveillance. 

The EU, however, found those powers were satisfactorily controlled by UK law and Britain’s adherence to the European Convention of Human Rights.

The Business Software Alliance, a lobby group for big tech companies including Microsoft, Oracle and IBM said it was “delighted” by the decision. 

“This will provide long-term confidence that data will continue to flow between the two partners post-Brexit,” said BSA’s Thomas Boue, policy chief for Europe.

Max Schrems, an Austrian lawyer and activist who led the fight against the EU’s data arrangements with the US, tweeted that there were issues with the UK proposal on security that will require “deep analysis”. 

view counter

© AFP 2020

Previous Columns by AFP:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/uReob8qQ7yg/brussels-okays-eu-uk-personal-data-flows




Virginia Lawmakers Advance Consumer Data Protection Act

The General Assembly is advancing legislation that allows Virginia consumers more protection with their online data, though opponents say the measure does not include the ability for people to file private lawsuits against companies that breach the proposed law.

The measure is known as the Consumer Data Protection Act in both chambers of the state legislature. The Senate version, sponsored by Sen. David Marsden, D-Fairfax, passed the House 89-9 on Thursday. The House version, sponsored by Del. Cliff Hayes, D-Chesapeake, is awaiting a final vote but was passed by for the day Thursday.

“The consumers should have the right to know what is being collected about them,” Hayes said when introducing the bill.

The data protection act allows consumers to retrieve a copy of their online data, amend or delete this data and opt out of allowing large businesses to sell the data.

Hayes wants businesses to responsibly handle consumer information.

“The bottom line is, we want the controllers to know what their role is when it comes to the protection of individual’s data,” Hayes said during a House committee meeting. “We believe that no matter who you are as an organization, you need to be responsible when it comes to handling of data of consumers.”

The bills apply to businesses that control or process personal data of at least 100,000 consumers per year. It also impacts businesses that handle data of at least 25,000 consumers per year and make more than half of their gross revenue from selling personal data. The businesses must be located in Virginia or serve Virginians.

Under the Consumer Data Protection Act, the attorney general’s office would handle the enforcement of this legislation. The office would handle anything from consumer complaints to the enforcement of fines.

“The attorney general’s office will have the depth and breadth, experience, the investigative tools necessary to know and to follow trends of companies and to make sure that they bring the muscle of that office to the table,” Hayes said.

Microsoft’s Senior Director of Public Policy Ryan Harkins testified in favor of the proposed law.

“We’ve seen dramatic changes in technology over the past couple of decades and U.S. law has failed to keep pace,” Harkins said. “It’s fallen behind much of the rest of the world and failed to address growing challenges of privacy.”

Harkins said that Microsoft has advocated for data protection laws since 2005. He said that the public has lost trust in technology, and passing comprehensive data protection legislation can help win the public’s trust back.

Harkins said that the measure stands alongside leading data protection legislation such as California’s Consumer Privacy Act and aspects of the European Union’s General Data Protection Regulation.

“In some respects, it would go further and provide the most comprehensive and robust privacy laws in the United States,” Harkins said.

Attorney Mark Dix spoke in opposition of the bill on behalf of the Virginia Trial Lawyers Association. He said the measure would hurt Virginians because it is “going to close the courthouse doors.”

“It provides no cause of action whatsoever for the consumer, the person who is actually hurt,” Dix said. “It provides no remedy whatsoever for the consumer.”

Dix argued that having the attorney general’s office handle the enforcement of this legislation limits the consumer.Using a hypothetical scenario, Dix asked what would happen to Virginians if there was an administration change and the Attorney General did not prioritize data protection.

The Consumer Data Protection Act would take effect in January 2023. Marsden told a Senate subcommittee that allows time to “deal and field any other tweaks to the bill or difficulties that someone figures out.”

Related: With No Unifying U.S. Federal Privacy Law, States Are Implementing Their Own

Related: Tech Giants Hope for US Data Privacy Law

Related: California Voters Expand Data Privacy Law

Related: Unique Illinois Privacy Law Leads to $550M Facebook Deal

view counter

Previous Columns by Associated Press:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/OwXr3WRMjWI/virginia-lawmakers-advance-consumer-data-protection-act




New browser-tracking hack works even when you flush caches or go incognito

New browser-tracking hack works even when you flush caches or go incognito
Getty Images

The prospect of Web users being tracked by the sites they visit has prompted several countermeasures over the years, including using Privacy Badger or an alternate anti-tracking extension, enabling private or incognito browsing sessions, or clearing cookies. Now, websites have a new way to defeat all three.

The technique leverages the use of favicons, the tiny icons that websites display in users’ browser tabs and bookmark lists. Researchers from the University of Illinois, Chicago said in a new paper that most browsers cache the images in a location that’s separate from the ones used to store site data, browsing history, and cookies. Websites can abuse this arrangement by loading a series of favicons on visitors’ browsers that uniquely identify them over an extended period of time.

Powerful tracking vector

“Overall, while favicons have long been considered a simple decorative resource supported by browsers to facilitate websites’ branding, our research demonstrates that they introduce a powerful tracking vector that poses a significant privacy threat to users,” the researchers wrote. They continued:

The attack workflow can be easily implemented by any website, without the need for user interaction or consent, and works even when popular anti-tracking extensions are deployed. To make matters worse, the idiosyncratic caching behavior of modern browsers, lends a particularly egregious property to our attack as resources in the favicon cache are used even when browsing in incognito mode due to improper isolation practices in all major browsers.

The attack works against Chrome, Safari, Edge, and until recently Brave, which developed an effective countermeasure after receiving a private report from the researchers. Firefox would also be susceptible to the technique, but a bug prevents the attack from working at the moment.

Favicons provide users with a small icon that can be unique for each domain or subdomain on the Internet. Websites use them to help users more easily identify the pages that are currently open in browser tabs or are stored in lists of bookmarks.

Browsers save the icons in a cache so they don’t have to request them over and over. This cache isn’t emptied when users clear their browser cache or cookies, or when they switch to a private browsing mode. A website can exploit this behavior by storing a specific combination of favicons when users first visit it, and then checking for those images when users revisit the site, thus allowing the website to identify the browser even when users have taken active measures to prevent tracking.

Browser tracking has been a concern since the advent of the World Wide Web in the 1990s. Once it became easy for users to clear browser cookies, websites devised other ways to identify visitors’ browsers.

One of those methods is known as device fingerprinting, a process that collects the screen size, list of available fonts, software versions, and other properties of the visitor’s computer to create a profile that is often unique to that machine. A 2013 study found that 1.5 percent of the world’s most popular sites employed the technique. Device fingerprinting can work even when people use multiple browsers. In response, some browsers have attempted to curb the tracking by blocking fingerprinting scripts.

Two seconds is all it takes

Websites can exploit the new favicon side channel by sending visitors through a series of subdomains—each with its own favicon—before delivering them to the page they requested. The number of redirections required varies depending on the number of unique visitors a site has. To be able to track 4.5 billion unique browsers, a website would need 32 redirections, since each redirection translates to 1 bit of entropy. That would add about 2 seconds to the time it takes for the final page to load. With tweaks, websites can reduce the delay.

The paper explains it this way:

By leveraging all these properties, we demonstrate a novel persistent tracking mechanism that allows websites to reidentify users across visits even if they are in incognito mode or have cleared client-side browser data. Specifically, websites can create and store a unique browser identifier through a unique combination of entries in the favicon cache. To be more precise, this tracking can be easily performed by any website by redirecting the user accordingly through a series of subdomains. These subdomains serve different favicons and, thus, create their own entries in the Favicon-Cache. Accordingly, a set of N-subdomains can be used to create an N-bit identifier, that is unique for each browser. Since the attacker controls the website, they can force the browser to visit subdomains without any user interaction. In essence, the presence of the favicon for subdomain in the cache corresponds to a value of 1 for the i-th bit of the identifier, while the absence denotes a value of 0.

The researchers behind the findings are: Konstantinos Solomos, John Kristoff, Chris Kanich, and Jason Polakis, all of the University of Illinois, Chicago. They will be presenting their research next week at the NDSS Symposium.

A Google spokesman said the company is aware of the research and is working on a fix. An Apple representative, meanwhile, said the company is looking into the findings. Ars also contacted Microsoft and Brave, and neither had an immediate comment for this post. As noted above, the researchers said Brave has introduced a countermeasure that prevents the technique from being effective, and other browser makers said they were working on fixes.

Until fixes are available, people who want to protect themselves should investigate the effectiveness of disabling the use of favicons. Searches here, here, and here list steps for Chrome, Safari, and Edge respectively.

https://arstechnica.com/?p=1743712




Apple Platform Security Guide Gets Biggest Update to Date

Apple on Thursday published the latest edition of its Platform Security Guide, which provides detailed technical information on the security technologies and features implemented in its products.

Apple started releasing security guides for its iOS operating system in 2015 and since 2019 has been publishing platform security guides that encompass information on iOS, macOS and hardware.

Apple Platform Security GuideThe platform security guide was previously updated in April 2020 and that version had 157 pages. The latest version has nearly 200 pages and Apple has described it as its biggest update ever.

The document provides information on hardware security and biometrics, system security, encryption and data protection, app security, security services, network security, developer kit security, and secure device management.

The new platform security guide includes informational updates for iOS, iPadOS and tvOS 14.3, macOS 11.1 and watchOS 7.2. It also includes several new topics, including memory safe iBoot implementation, boot process and modes for Macs with Apple chips, startup disk security policy control for Macs with Apple silicon, information on LocalPolicy, signed system volume security in macOS, the Password Monitoring feature, IPv6 security, car keys security in iOS, and iPhones designed for security research.

The guide also includes updates to topics such as Secure Enclave, hardware microphone disconnect, recoveryOS and diagnostics environments for Intel-based devices, DMA protections, kernel extensions in macOS, System Integrity Protection, watchOS security, Apple Cash security, Wi-Fi privacy, Activation Lock security, Apple Configurator 2 security, Business Chat security, and some password-related topics.

The document also includes information on Apple’s new M1 chips, which bring several security improvements.

A researcher recently discovered the first piece of Mac malware created specifically for devices with M1 chips.

Related: Apple Adds ‘BlastDoor’ to Secure iPhones From Zero-Click Attacks

Related: Apple Ships Emergency Fixes for Under-Attack iOS Zero-Day

Related: Apple to Crack Down on Tracking iPhone Users in Early Spring

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/jp9J8jdmEKE/apple-platform-security-guide-gets-biggest-update-date




Pubblicati sul Dark Web i file dello studio legale di Donald Trump


Lo studio legale Jones Day è finito vittima di un attacco ransomware e i pirati stanno pubblicando i dati rubati. L’origine potrebbe essere il breach di Accelion.

I documenti riservati sulla battaglia legale portata da Donald Trump per poter sovvertire il risultato delle recenti elezioni presidenziali negli USA potrebbero essere finiti sul Dark Web.

La fonte del leak, stando a quanto riporta DataBreaches.net, sarebbe il mega-studio legale Jones Day, che ha sedi in tutto il mondo e rappresenta numerosi personaggi pubblici tra cui, appunto, l’ex presidente degli Stati Uniti.

Autore dell’attacco sarebbe un gruppo di pirati informatici conosciuti per diffondere il ransomware Clop, che in questo caso, però, non avrebbero crittografato i file sui sistemi dello studio legale, ma si sarebbero limitati a farne una copia per poi chiedere un riscatto a Jones Day.

Stando a quanto riportano gli esperti di sicurezza, lo studio legale non avrebbe ceduto al ricatto e, di conseguenza, i cyber criminali avrebbero deciso di “fare pressione” pubblicando una tranche di 100 GB di dati sul Dark Web.

Tra questi ci sono comunicazioni, documenti e informazioni riservate relative ai procedimenti giudiziari patrocinati dai legali dello studio. Non è escluso, quindi, che contengano anche informazioni sull’azione legale promossa da Donald Trump negli scorsi mesi per salvare il salvabile della sua campagna elettorale.

Donald Trump Jones Day

Sui dettagli riguardanti le modalità con cui i pirati sono venuti in possesso dei dati non ci sono ancora certezze. Se i cyber criminali di Clop sostengono di aver ottenuto le informazioni direttamente dai sistemi di Jones Day, l’azienda punta invece il dito su un data breach precedente, che ha coinvolto il sistema di condivisione dei file FTA di Accelion.

L’attacco, avvenuto nel dicembre 2020, aveva sfruttato una vulnerabilità zero-day del sistema, che viene utilizzato anche da Jones Day.

Se la ricostruzione dello studio legale dovesse trovare conferme, ci troveremmo quindi di fronte all’ennesimo “effetto domino” provocato da un attacco supply chain. Qualcosa di simile, cioè, alla vicenda SolarWinds che ha scosso (e continua a scuotere) il settore della cyber security.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/02/18/pubblicati-sul-dark-web-i-file-dello-studio-legale-di-donald-trump/?utm_source=rss&utm_medium=rss&utm_campaign=pubblicati-sul-dark-web-i-file-dello-studio-legale-di-donald-trump




Zuckerberg responds to Apple’s privacy policies: “We need to inflict pain”

Facebook co-founder, chairman, and CEO Mark Zuckerberg departs after testifying before a combined Senate Judiciary and Commerce Committee hearing in the Hart Senate Office Building on Capitol Hill, April 10, 2018, in Washington, DC.
Enlarge / Facebook co-founder, chairman, and CEO Mark Zuckerberg departs after testifying before a combined Senate Judiciary and Commerce Committee hearing in the Hart Senate Office Building on Capitol Hill, April 10, 2018, in Washington, DC.
Win McNamee/Getty Images

Facebook CEO Mark Zuckerberg told employees close to him, “we need to inflict pain” on Apple for comments by Apple CEO Tim Cook that Zuckerberg described as “extremely glib.”

This and other insights into an ongoing rift between the two companies appeared in a report in The Wall Street Journal this weekend. The article indicates that based on first-hand reports, Zuckerberg has taken Cook and Apple’s public criticisms of Facebook’s privacy policies, whether direct or indirect, as personal affronts.

For example, Cook publicly responded to Facebook’s 2018 Cambridge Analytica scandal by saying such a scandal would never happen to Apple because Apple does not treat its customers like products. When asked what he would do in Zuckerberg’s position, he said, “I wouldn’t be in this situation,” calling Facebook’s approach “an invasion of privacy.” This was one of the comments that has led Zuckerberg to see Apple as an opponent.

Before that, in 2017, Zuckerberg and Cook met to attempt to smooth an already souring relationship, the article says, but the meeting “resulted in a tense standoff.” Since then, the relationship has continued to sour.

The disputes reached new prominence last year, when Apple announced plans to require that iOS apps ask users for permission to track them with IDFA (ID For Advertisers) tags across apps and websites. The change in policy is already reflected in Apple’s terms of service for app developers but will not be enforced until early spring, after the release of iOS 14.5.

Facebook, whose business model and competitive advantage rely on this kind of tracking, responded by telling investors to expect falling revenues—and by running full-page newspaper ads declaring that the change would hurt small businesses.

Further, Facebook has explored filing a lawsuit against Apple, alleging that the smartphone maker’s policies are anticompetitive.

The Wall Street Journal story also notes that Facebook has directly aided Epic Games’ battle against Apple over a separate but loosely related battle over Apple’s grip on its App Store and that Facebook has been “waging a campaign against Apple” with government officials and antitrust regulators.

Apple has attempted to position itself as the Big Tech company on the side of privacy because its business model is not built on tracking like Facebook’s or Google’s.

But there are other dimensions at play, too. Both Cook and Zuckerberg have said they view augmented and mixed reality as “the next computing platform,” and Facebook and Apple are on a course toward competing more directly with their products in the future.

Facebook has agreed to follow Apple’s rules requiring user opt-in for tracking in its iOS apps, but it has tested ways to pre-empt the Apple-required prompt in order to make the case to users to opt in.

Meanwhile, both companies are subject to wide-ranging lawsuits and investigations alleging anticompetitive behavior, albeit mostly for very different reasons.

https://arstechnica.com/?p=1742352




La Procura di Napoli blocca l’uso del “trojan di stato” di Cy4gate


Alla base della decisione potrebbe esserci un “grave malfunzionamento” dello spyware, che visualizzerebbe delle notifiche sul telefono sorvegliato.

Una vicenda complicata, che ha portato la Procura di Napoli a sospendere la sua collaborazione con Sio S.p.A., la società che fornisce microspie e strumenti di sorveglianza digitali agli investigatori. Il motivo? Un difetto nei trojan forniti alle forze di polizia che vanificherebbe le operazioni di sorveglianza.

Tutto è cominciato qualche giorno fa, quando gli attivisti di Citizen Lab hanno denunciato la presenza di alcuni siti che contenevano una versione alterata di Whatsapp contenente un file in grado di recuperare e trasmettere numerose informazioni riguardanti il dispositivo a una serie di domini.

L’app per iOS sfrutterebbe, come al solito, il sistema dei profili MDM (Mobile Device Management) che consente di installare sui dispositivi Apple applicazioni proprietarie senza passare dall’App Store.

Secondo quanto riportato da Motherboard in un articolo pubblicato lo scorso 3 febbraio, uno dei domini utilizzati per ospitare le pagine di phishing sarebbe collegato a un ulteriore dominio registrato a nome di Cy4gate, azienda italiana specializzata nello sviluppo e vendita in quelli che ormai vengono definiti comunemente “trojan di stato”.

Insomma: secondo gli attivisti il sito sarebbe stato utilizzato per indurre i visitatori a scaricare e installare un trojan sul loro smartphone.

Al momento, però, non ci sono prove certe che il sito ospitasse una versione infetta di Whatsapp e quella di Citizen Lab, per quanto circostanziata, rimane di conseguenza una (credibile) ipotesi.

Cy4gate

La denuncia, ripresa da numerosi siti, ha portato Cy4gate a smentire un suo diretto coinvolgimento sulla gestione dei server in questione. La sua eventuale partecipazione all’attacco, se confermato, potrebbe portare a qualche (serio) problema.

Dalle parti di Facebook (proprietaria di Whatsapp) hanno già dimostrato di non gradire questo tipo di operazioni, come dimostra la causa in corso nei confronti di NSO Group, società israeliana che ha sfruttato Whatsapp in un’operazione simile a quella che gli attivisti di Citizen Lab sospettano sia stata portata avanti da Cy4gate.

A fare più danni, però, potrebbero essere gli ulteriori sviluppi della vicenda. Alla fine della settimana scorsa, infatti, la Procura di Napoli ha annunciato di aver sospeso la fornitura dei servizi da parte di Sio S.p.A., la società che fornisce i sistemi di sorveglianza agli investigatori e che utilizzerebbe il trojan prodotto da Cy4gate.

Le motivazioni ufficiali parlano di “gravi disservizi” ma, secondo i colleghi di Motherboard che hanno raccolto indiscrezioni da due fonti anonime, il problema riguarderebbe un bug dello spyware stesso.

Nel dettaglio, si spiega nell’articolo, in alcuni casi la procedura di esfiltrazione dei dati visualizzerebbe sul dispositivo una notifica che rischierebbe di mettere in allarme il bersaglio dell’intercettazione.

Insomma, il trojan “invisibile” non sarebbe poi così “invisibile”. Un difetto che, se confermato, non sarebbe certo una buona pubblicità per l’azienda romana.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/02/15/la-procura-di-napoli-blocca-luso-del-trojan-di-stato-di-cy4gate/?utm_source=rss&utm_medium=rss&utm_campaign=la-procura-di-napoli-blocca-luso-del-trojan-di-stato-di-cy4gate




Virginia is about to get a major California-style data privacy law

A white neoclassical building.
Enlarge / The Virginia state Capitol building at twilight, in prepandemic times.

Virginia is poised to follow in California’s footsteps any minute now and become the second state in the country to adopt a comprehensive online data protection law for consumers.

If adopted, the Consumer Data Protection Act would apply to entities of a certain size that do business in Virginia or have users based in Virginia. The bill enjoys broad popular support among state lawmakers; it passed 89-9 in the Virginia House and unanimously (39-0) in the state Senate, and Democratic Gov. Ralph Northam is widely expected to sign it into law without issue in the coming days.

In the absence of a general-purpose federal privacy framework, states all over the nation are very slowly stepping in with their own solutions. The Virginia law is somewhat modeled on California’s landmark Consumer Privacy Act, which was signed into law in 2018 and took effect on January 1, 2020. Legislatures in several other states—including Minnesota, New York, North Dakota, Oklahoma, and Washington—have some kind of data privacy bills currently under consideration.

What would the Virginia law do?

The CDPA applies to entities that “control or process” personal information of 100,000 or more Virginia residents in a calendar year or to entities that make 50 percent or more of their gross revenue from the sale of personal data if they hold information about at least 25,000 residents. Basically, the big data brokers and companies with a major online presence would all be covered, but small businesses would not be. Under the law, these entities that determine “the purpose and means of processing personal data” are called “controllers.”

Covered consumers are also defined very explicitly in the bill, meaning specifically individuals acting on their own or in a “household context.” It does not include actions “in a commercial or employment context.” So if you’re using the Internet at home on your own time, you’re covered; if you’re using the Internet at work for work reasons, you’re not.

Provided that an interaction does involve a private consumer, a covered business, and covered personal information, however, then Virginia residents would gain a handful of explicit new rights for how their data is handled, including:

  • The right to confirm if a controller has your data and, if so, to see it
  • The right to correct inaccuracies in the data the controller has
  • The right to have a controller delete personal data provided by or obtained about you
  • The right to opt out of having your data used for targeted advertising; having it sold to a third party; or “profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.”

The law puts in place guidelines for how controllers should collect, handle, and share personal information. For example, it mandates that data collection must be limited to “what is adequate, relevant, and reasonably necessary” for the purpose at hand. Controllers would also be required to conduct assessments of any activities that involve the use of personal data for targeted advertising, for profiling, or for sale. The assessments also have to “identify and weigh the benefits that may flow, directly and indirectly” to all stakeholders, including the consumer and the public, and the attorney general can request access to those assessments.

The bill contains wide carve-outs specific types of data and covered entities that are already regulated under laws such as HIPAA, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, and educational privacy law FERPA.

Notably, the Virginia bill does not include any private right of action whatsoever over violations, meaning you can’t sue if your rights are being violated under the law; only the Virginia attorney general’s office can pursue a case.

Even California isn’t quite California

A coalition of consumer advocates, including the Electronic Frontier Foundation, the Electronic Privacy Information Center, and Consumer Reports say that Virginia’s goals are in the right place, but they argue the CDPA doesn’t go far enough to provide meaningful protection.

“We readily acknowledge that there is a lot to like about the bill,” the organizations wrote in a letter (PDF) to the bill’s primary sponsor. “The CDPA would grant important new rights to Virginia citizens that the residents of most states do not currently enjoy.”

But “[b]ecause the CDPA is based on an opt-out model… the deck is already stacked against consumers,” the coalition notes. “Consumers have to contact hundreds, if not thousands, of different companies in order to fully protect their privacy.”

These opt-out measures haven’t exactly worked as intended in California in the past year, either, the coalition notes, pointing to a Consumer Reports study that found the mandatory “do not sell my information” links required by California law are not only hard to find but sometimes just plain don’t work at all. “At least 14% of the time, burdensome or broken [do not sell] processes prevented consumers from exercising their rights under the CCPA,” the study found, and participants in the study were dissatisfied with the opt-out process more than half of the time.

https://arstechnica.com/?p=1741414