• unilogou. Powered by Blogger.

    Showing posts with label privacy. Show all posts
    Showing posts with label privacy. Show all posts

    Monday, 8 August 2016

    UK faces Human Rights challenge to state’s bulk hacking abroad

    Posted By: Uni logo - 03:40:00

    Privacy rights organization Privacy International has filed another legal challenge to the UK government’s use of bulk hacking against foreigners.
    The filing, with the European Court of Human Rights, follows Privacy International’s attempt earlier this year to challenge the use of bulk hacking against foreigners via the local oversight court for the UK’s intelligence agencies, the IPT.
    However the Tribunal refused to rule on whether GCHQ’s use of bulk hacking against entities outside the UK complies with the European Court of Human Rights. The IPT further judged the government’s use of hacking lawful under domestic law. Hence the move to file a challenge with the European court now.
    Privacy International has previously this year filed a separate judicial review at the UK High Court focused on another aspect of the IPT’s decision — challenging the use of so-called ‘thematic warrants’.
    Another of its legal challenges to the UK government’s surveillance practices resulted in the IPT’s first ever ruling against the domestic intelligence agencies — when in February 2015 it deemed GCHQ to have previously acted illegally in sharing data with the NSA.
    “By taking this case to the European Court of Human Rights, we aim to bring the government’s hacking under the rule of law,” writes Privacy International of its latest action. “The government is currently hacking abroad based on a very vague and broad power that provides few if any safeguards on this incredibly intrusive power.”
    The body is joined in the action by Germany’s Chaos Computer Club, GreenNet (UK), Jinbonet (Korea), May First (US) and RiseUp (US).
    Commenting in a statement, Scarlet Kim, Legal Officer at Privacy International, added: “The IPT’s decision permits the British Government to hack untold numbers of computers devices or networks abroad without any proper legal framework, oversight or safeguards. Hacking is extremely intrusive, allowing the hacker to, for example, switch on the webcam of a computer, or the mic of a phone without the owner having any idea.
    “Allowing the British Government to hack therefore sanctions an extraordinary expansion of state surveillance capabilities, with alarming consequences for the privacy and security of many people around the world. The European Court of Human Rights has a strong track record of ensuring that intelligence agencies act in compliance with human rights law. We call on the Court to hold GCHQ accountable for its unlawful bulk hacking practices.”
    The UK government is in the process of updating domestic surveillance legislation. The Investigatory Powers bill, currently at the review stage in the House of Lords, seeks to cement bulk hacking powers at the heart of the surveillance state via an updated legal framework.
    However the IP bill’s bulk powers are the subject of an independent review, taking place this summer. The opposition Labour party pushed the government for an outside review, calling for it to set out a robust operational case for their inclusion.
    Critics argue bulk powers are disproportionate and unnecessary. It will be up to QC David Anderson — who is leading the review, and who previously played a key role for the government when it was drafting the IP bill — to assess whether the use of bulk powers is justified and whether the bill contains sufficient safeguards for their operation. Although, unlike a judgement from the European Court of Human Rights, Anderson’s opinion will not be legally binding.

    Wednesday, 29 June 2016

    Review your entire Google life on this handy new page

    Posted By: Uni logo - 04:32:00
    Https%3a%2f%2fblueprint-api-production.s3.amazonaws.com%2fuploads%2fcard%2fimage%2f130752%2fgoogle_my_activity
    Using Google's many services — Search, YouTube, Gmail, Maps, etc — leaves behind a lot of information about your daily activities. In June 2015, Google launched a "My Account" dashboard, which lets you control the privacy aspects of the various Google services you use, but to actually see your history, you had to go to several different places. 
    Not anymore. Google has launched a My Activity page, which gives you a detailed overview of everything you've done on Google, ever (provided you haven't explicitly forbid Google to accumulate this data).
    This includes your entire Chrome browsing history, search queries on Google, image searches, videos you've watched on YouTube, Google Now cards you've seen, to name a few. Android users and those heavily reliant on Google's services will likely find that this page contains their entire online life. 

    I've turned most of my Google history off, but I forgot one setting: My Chrome history.
    IMAGE: STAN SCHROEDER, MASHABLE
    The history is searchable, and you can also filter it by date and product. Furthermore, for each day Google will offer a neat overview, showing you how many items are there, and which platforms or services they're related to. 

    In bundle view, Google offers an overview of your history for each day. You can also see your history in item view, which lists every individual item separately.
    IMAGE: STAN SCHROEDER, MASHABLE
    Not everything is here; for example, the aforementioned Maps history is located on a different page. However, you can access this and all other Google histories from the menu on the left. 
    While the feature is essentially a greatly enhanced version of your Chrome history, some users may want to stop Google from storing so much data about their online activities. You can fine tune those settings on Google's Activity Controls page, where you can pause Google from gathering data related to your web activity, location history, voice and audio activity, devices you use and your YouTube history. 

    Google's ad tracking has been expanded, but you can turn it off

    This new feature is tied, Wired reports, to another major change related to Google services: Google is now using data it has gathered from you to serve you better-targeted ads. Google has previously done it on its own services, but this has now been expanded to third-party sites as well. 
    "When you use Google services like Search and YouTube, you generate data — things like what you’ve searched for and videos you’ve watched. (...) With this change, this setting may also include browsing data from Chrome and activity from sites and apps that partner with Google, including those that show ads from Google," Google wrote in a note to users. 
    To opt out of this new form of ad tracking, go to this page. There, you can turn off "ads based on your interest" as well as "ads based on your interests on websites beyond google.com."

    A notice users will see when they opt out of "signed out" ads.
    IMAGE: GOOGLE
    As Google points out, even if you turn both options off, you will still see ads, but these ads will be less relevant, and unrelated to your interests and previous visits to other sites. The ads still may be based on your general location. 
    The new options are being gradually rolled out; we've seen them on some accounts while they were absent on others. Users should get a notification to review their privacy settings as the new features become available.

    Tuesday, 10 May 2016

    Report: Android mobile apps still have serious privacy concerns in Australia

    Posted By: Uni logo - 03:42:00
    Http%3a%2f%2fi.blueprint.mashable.com%2fqm_svsb2r-boguk9ylzklauk8d4%3d%2fblueprint-api-production.s3.amazonaws.com%2fuploads%2fcard%2fimage%2f84919%2fcf049dcd4a5746ae9f5c41fd34448cde

    Mobile apps increasingly act as the digital gatekeepers of our daily routine, whether we're accessing our bank accounts or dating, but can they be trusted?
    On Tuesday, Deloitte release its annual privacy index of the top 116 consumer brands operating in Australia across 13 sectors, including social media, retail and insurance. It did not name the companies. For the first time, it added an analysis of those brands' mobile apps, if they had them, with some worrying results.
    The report told an alarming story: apps not asking consumers for permission to access various parts of their phones and apps accessing the microphone function or collecting information before the user has even logged in. 
    Using the data-monitoring app SpyAware, Deloitte compared the way the apps actually behaved with the permissions it requested from the user before installation from Google Play. The report found 16 percent of the 88 apps surveyed accessed phone information that was not disclosed. 
    That could include details such as calls made and received, Tommy Viljoenhen, Deloitte national lead partner of Cyber Risk Services, told Mashable Australia.
    "We are taking about the most trusted brands, and we found 16 percent of them were accessing information without notification," he said in a phone call with reporters. "What's happening with the brands we don't know about? As consumers, are we even aware of the extent to which information is being collected without our knowledge?"
    Consumers may also be surprised to realise just how many apps are accessing their information or their smartphone's hardware before they log into an app, even if they unwittingly gave it permission by accepting terms and conditions on download. Because, let's face it, next to no one is reading those in advance.
    According to the report, 96 percent of reviewed apps transferred user information in or out of the device prior to login. In addition, of the 6 percent of apps with permission to access the microphone, 33 percent accessed it before the consumer logged in, while of the 40 percent with permission to access the camera, 3 percent also connected before login.
    "If apps are going to access information when you're not logged in, there should be [clearer disclosure] provided to you that that is how the application works," Viljoenhen said. "That would be better practice in terms of building trust."
    Deloitte did not review iOS apps, choosing to examine Android as the dominant operating system in Australia. Google has been contacted for comment. It hopes to add Apple's operating system in 2017. 
    DELOITTE

    IMAGE: DELOITTE
    The report also put the privacy strategies of websites under the microscope. Deloitte found that less than 2 percent of brands actively notified consumers when cookies were installed on their devices — technology that can track online behaviour, including which websites are visited.According to the report, the amount of time a cookie is stored on a device is 657 days on average.
    This is the second year the report has been issued, and Viljoenhen said Deloitte has seen consumer attitudes to privacy mature in Australia. "Ninety-four percent of consumers rated trust more important than ease of use," he said. "Communicating how information is used and shared builds trust."
    The report surveyed 1,000 consumers and found that banking and finance was the most trusted industries out of the 13 industries assessed. Retail, media and social media were the least trusted industries.
    Customer perception of brand oversight also plays a significant role. "Industries that are far less regulated tend to have lesser perception of trust," Viljoenhen added. "[There is a] direct correlation between regulation and the trust consumers have in those brands."
    It would definitely be a fate worse than death for most social media companies, but it's possible government oversight is the recipe for consumer piece of mind.

    Report: Android mobile apps still have serious privacy concerns in Australia

    Posted By: Uni logo - 03:15:00
    2bb65607d864444db5a7173cfadb2ee2

    Mobile apps increasingly act as the digital gatekeepers of our daily routine, whether we're accessing our bank accounts or dating, but can they be trusted?
    On Tuesday, Deloitte release its annual privacy index of the top 116 consumer brands operating in Australia across 13 sectors, including social media, retail and insurance. It did not name the companies. For the first time, it added an analysis of those brands' mobile apps, if they had them, with some worrying results.
    The report told an alarming story: apps not asking consumers for permission to access various parts of their phones, apps accessing the microphone function before the user has even logged into the app and apps collecting information without notification. 
    Using the data-monitoring app SpyAware, Deloitte compared the way the apps actually behaved with the permissions it requested from the user before installation from Google Play. The report found 16 percent of the 88 apps surveyed accessed phone information that was not disclosed. 
    That could include details such as calls made and received, Tommy Viljoenhen, Deloitte national lead partner of Cyber Risk Services, told Mashable Australia.
    "We are taking about the most trusted brands, and we found 16 percent of them were accessing information without notification," he said in a phone call with reporters. "What's happening with the brands we don't know about? As consumers, are we even aware of the extent to which information is being collected without our knowledge?"
    Consumers may also be surprised to realise just how many apps are accessing their information or their smartphone's hardware before they log into an app, even if they unwittingly gave it permission by accepting terms and conditions on download. Because, let's face it, next to no one is reading those in advance.
    According to the report, 96 percent of reviewed apps transferred user information in or out of the device prior to login. In addition, of the 6 percent of apps with permission to access the microphone, 33 percent accessed it before the consumer logged in, while of the 40 percent with permission to access the camera, 3 percent also connected before login.
    "If apps are going to access information when you're not logged in, there should be [clearer disclosure] provided to you that that is how the application works," Viljoenhen said. "That would be better practice in terms of building trust."
    Deloitte did not review iOS apps, choosing to examine Android as the dominant operating system in Australia. Google has been contacted for comment. It hopes to add Apple's operating system in 2017. 
    DELOITTE

    IMAGE: DELOITTE
    The report also put the privacy strategies of websites under the microscope. Deloitte found that less than 2 percent of brands actively notified consumers when cookies were installed on their devices — technology that can track online behaviour, including which websites are visited.According to the report, the amount of time a cookie is stored on a device is 657 days on average.
    This is the second year the report has been issued, and Viljoenhen said Deloitte has seen consumer attitudes to privacy mature in Australia. "Ninety-four percent of consumers rated trust more important than ease of use," he said. "Communicating how information is used and shared builds trust."
    The report surveyed 1,000 consumers and found that banking and finance was the most trusted industries out of the 13 industries assessed. Retail, media and social media were the least trusted industries.
    Customer perception of brand oversight also plays a significant role. "Industries that are far less regulated tend to have lesser perception of trust," Viljoenhen added. "[There is a] direct correlation between regulation and the trust consumers have in those brands."
    It would definitely be a fate worse than death for most social media companies, but it's possible government oversight is the recipe for consumer piece of mind.

    Tuesday, 3 May 2016

    Publishers using ad blocker blockers to be 'named and shamed

    Posted By: Uni logo - 06:14:00
    Ap_304674431572

    A privacy activist is launching a campaign to name and shame publishers who use technology to block users with ad blockers installed in the latest battle over the controversial software. 
    Several publishers have introduced pop-ups asking users to turn off their ad blockers or face being banned from their sites.
    However, the European Commission says in a letter that ad blocker blockers can be illegal and in breach of EU privacy rules. In response to privacy campaigner Alexander Hanff, the Commission said: 
    "Article 5.3 does not limit itself to any particular type of information or technology, such as cookies. In light of the above, Article 5(3) would also apply to the storage by websites of scripts in users' terminal equipment to detect if users have installed or are using ad blockers."
    The reference is to Europe's online privacy legislation, known as the "cookie directive," which requires websites to obtain consent from users before storing or accessing information from their computers. 
    In the letter, the Commission explains that the rule not only applies to cookies, but also to technology used by publishers to detect ad blocker users without first obtaining consent to do so.
    Hanff is planning to file a series of complaints with national regulators across Europe against publishers which use that technology, the Financial Times reported. 
    The activist has launched a "name and shame" campaign to identify publishers "who are using these illegal methods to detect your use of an adblocker". 
    He claims display advertising has become "increasingly intrusive" and "a serious security risk".

    Sunday, 1 May 2016

    How to talk to your babysitter about online privacy

    Posted By: Uni logo - 12:24:00
    Http%3a%2f%2fi.blueprint.mashable.com%2fwknjszcgijmpvxxl72fapvmv_9c%3d%2fblueprint-api-production.s3.amazonaws.com%2fuploads%2fcard%2fimage%2f75428%2fgettyimages-521704237

    My first date night out with my husband after our daughter was born was nerve wracking. Would she be fed? Would she sleep? I constantly checked my phone for updates from the sitter. Nothing.
    Then, I logged into Facebook. In my feed I saw three pictures of my adorable baby being snuggled by the sitter. It was reassuring but also worrying. Up until that point all of our baby pictures on social media were accessible only to family and friends.
    As a writer who makes her living online I was worried strangers would take photos of my daughter and use them without my consent. It's a safety concern if people in the area know my children are home without an adult present. For some parents, keeping their children off social media is about protecting them from privacy concerns of facial imaging software and data mining. Other parents worry about future backlash, like bullying in school or losing out on future job and college prospects.
    As children get older even they are pushing back for more privacy, requesting that their parents not post about them online.
    In a recent blog post for Mom.me, Meredith Gordon noted that she doesn’t want her sitters taking pictures of her kids at all, because her children are not someone else’s content.

    Our rules are slightly more flexible. I don’t mind a picture here or there but we prefer that names aren’t used.
    Discussing these rules with a sitter can be awkward. Caregivers who are Generation Alpha might not have the same concerns about privacy as parents. Laurie Gray, a trial attorney, child advocate and founder of SocraticParenting.com, encourages parents to be up front about their rules and expectations. “The key is to suggest some simple, clear rules, discuss them with your children and babysitter to make sure everyone has input, understands and is on board.” She suggests typing guidelines and posting them on the bulletin board or refrigerator for easy reference by the sitter and children.
    Lynn Perkins, CEO and founder of UrbanSitter, suggests firm rules in place before you talk to your sitter. She suggests a range of social sharing options:
    1. Never take photos or videos of my kids.
    2. It’s okay to take photos or videos of my kids, but for these purposes only:
      • To send me as an update, but photos or videos should be deleted immediately afterward.
      • To capture a memory, which you can keep, but photos or videos should never be shared on social media.
    3. It’s okay to take photos or videos of my kids and share them on social media with these exceptions:
      • Do not use my kids’ names or our last name.
      • Do not tag people or locations.
    4. It’s okay to take photos or videos of my kids and share them on social media. Be sure to tag me, so I can see the posts.
    A good sitter will respect your wishes, Perkins notes.
    Gray adds, “Most parents do want their sitter and children to be able to communicate with them, so they don’t want completely cut off access to the electronic devices. What seems to work best for most parents is: 1) Agree; 2) Trust; 3) Verify; 4) Revise the Agreement as needed; and repeat. If trust becomes a significant issue, you may need to look for a new babysitter.”
    As for us, I was able to talk to my sitter about our social media rules for our kids and she handled it well. Not only is it a privacy issue, but it’s a safety one that modern parents need to be aware of.

    Tuesday, 19 April 2016

    Viber adds end-to-end encryption and hidden chats as messaging app privacy wave grows

    Posted By: Uni logo - 11:50:00


    Following WhatsApp’s move to add end-to-end encryption to its platform, another big messaging company is joining the wave of apps turning on expanded privacy features. Viber— a messaging app with 711 million+ users — today is introducing end-to-end encryption for all messages and calls on its platform, including group chats (you can chat with up to 200 people), and a way to ‘hide’ chats on your account alongside its existing expanded deleting function.
    The company — founded in Israel and acquired by Japan’s Rakuten in 2014 — says the new services will be rolled out globally in the coming weeks, starting today in four countries where Viber centers most of its R&D: Brazil, Belarus, Israel and Thailand.
    The new privacy features will work across Android, iOS, PCs and Mac desktops, with the encryption coming with the latest app update (6.0) and a reauthentication of the app (via QR Code) to turn the feature on.
    Today, just about every big messaging app encrypts your messages in transit, but more secure features like end-to-end encryption mean that service providers cannot access the message at any point at all. Michael Shmilov, Viber’s COO, told TechCrunch that the company has been working on an end-to-end encryption feature for “years.”
    So the fact that Viber had not launched it until now — with only a gradual rather than universal roll out, and just weeks after WhatsApp’s news — is both a sign of the times (what users are increasingly wanting and demanding these days) but also a mark of just how competitive the messaging app landscape remains today, where everyone is making sure that no rival has more features that it does. (More on that below.)
    Viber’s encryption will come with varying levels of security, the company said, which will show up in the form of a color-coded lock on the right side of the screen.
    A grey lock will mean the conversation (voice or text) is fully encrypted. You can tap on the lock to confirm this.
    Users also have the option of selecting a green lock, which will mean that you can additionally authenticate users before each conversation or to continually monitor them to make sure the users are verified. This option is useful if you’re talking to someone who might share an account with another person — say a child or partner.
    A red lock, meanwhile, comes up if a trusted user does not pass re-authentication at his/her end. This could be because a device has changed, or because someone is trying to access the data via a man-in-the-middle attack, Viber notes, meaning that users need to re-authenticate for security and encryption to come back into effect.
    Along with the encryption, there are some other privacy features getting added into the latest version of the app. Hidden chats will give users the ability to essentially “hide” certain conversations from their usage log, accessible only if you know a specified four-digit PIN. Why hide a chat in your app?
    Again, this goes back to the idea that multiple people may be accessing your device, and subsequently your Viber account. One scenario may be your kids playing a game on your iPhone and switching over to messaging. But another might be hiding more explicit stuff from others. Caveat emptor.
    The enhanced delete feature, meanwhile, has been in the app for a while, but is part of the company’s is a way for users to wipe a conversation not just on their end, but on that of the recipient’s phone. You can think of this as Viber’s answer to ephemeral messaging, but with a more manual approach.

    Bots and enterprise services to come

    The idea of adding more features that you are seeing in rival services is a theme that is big right now with all the messaging apps, which are all competing to be top dog for consumers who are balancing lots of apps but ultimately use only a handful with any regularity.
    On that theme, Shmilov said that Viber will be, in the coming weeks and months, adding a lot more functionality to remain level with what Messenger and others are doing to transform their services from walled gardens into wider platforms. This will include a service for businesses, where companies will be able to use Viber to communicate with their customers as part of their CRM play; and also a platform to enable — yes! — bots on Viber. This comes in the wake of Viber expanding with lots of other services, such as public and group chats, as well as games.
    The enterprise service — which sounds a lot like the business accounts feature for WhatsApp— will appear first, Shmilov said, and it will be one of the key ways that Rakuen hopes to integrate with its owner Rakuten, where merchants on its marketplace will be able to revert to Viber to have conversations with customers either before purchase or for after-sales support. “We are working with Rakuten on this,” he said, “interacting with merchants who sell on the platform. In a couple of months we will roll this out with partners, working with their CRM software but also directly with companies.”
    While others like WhatsApp and Twitter are also hoping to expand their services with business accounts for customer service, this is not so much a me-too feature as it is something that makes a lot of sense: in this case, if you’re a business you don’t want to have to ask your customers to download a new messaging app just to interact; you would like to converse on the platform that your customer is already using. In that sense, smart companies will make it possible to speak on all the major platforms — much like publishers that give users an array of widgets to share stories to a variety of social networks.
    As for the bots, these sound very similar to what Facebook is now offering in Messenger (withhiccups), and they are likely to start making their way to market in Q3. While Facebook’s Messenger is based around a lot of machine learning and AI that the company is building in-house by way of its acquisition of Wit.ai, it looks like Viber is opting for an API to run the bots, but in a way that potentially incorporates other assistants rather than building tech in-house.
    “There are a lot of AI-based solutions such as Google’s and Microsoft’s Cortana,” Shmilov said. “We are developing a strong API that will enable bot-based solutions on Viber on top of those. Developers will be able to use these APIs to integrate what they want. There are already some interesting scenarios coming up,” he said of the internal tests that the company is running. “This is only the beginning of how messaging will work.”

    Copyright © 2016 Uni logo™ is a registered trademark.

    Designed by Unilogou. Hosted on Blogger Platform.