Skip to main content

Posts

Showing posts with the label privacy

Tennessee bill broadens scope of 'theft,' wide enough to include web-based subscription services?

This week, Tennessee signed a bill that made waves across the web, with many sites claiming that sharing your log-in credentials for services such as Netflix could soon land you in the slammer. The actual story isn't that simple. The bill essentially adds onto laws pertaining to the theft of 'services' in the legal sense by covering more things that can be defined under the title. For instance, the original list included cable services, to keep folks from jacking free HBO -- now, stealing "entertainment subscription services" can make you a felon as well. Tennessee has always been a hotspot for the recording industry, so there's almost no question about what this bill was meant to fight; during a senate hearing for the bill, the RIAA itself explained that online music services could be pirated via password sharing. It also added, though, that users who share passwords "en-masse" are the focus, rather than individual cases like it had pursued in th...

FaceNiff makes Facebook hacking a portable, one-tap affair (video)

Remember Firesheep? Well, the cookie snatching Firefox extension now has a more portable cousin called FaceNiff. This Android app listens in on WiFi networks (even ones encrypted with WEP, WPA, or WPA2) and lets you hop on to the accounts of anyone sharing the wireless connection with you. Right now it works with Facebook, Twitter, YouTube, and Nasza-Klasa (a Polish Facebook clone), but developer Bartosz Ponurkiewicz promises more are coming. You'll need to be rooted to run FaceNiff -- luckily, we had such a device laying around and gave the tap-to-hack app a try. Within 30 seconds it identified the Facebook account we had open on our laptop and had us posting updates from the phone. At least with Firesheep you had to sit down and open up a laptop, now you can hijack Twitter profiles as you stroll by Starbucks and it'll just look like you're sending a text message (but you wouldn't do that... would you?). One more image and a video are after the break. FaceNiff

Best Buy Mobile Upgrade Checker reveals other numbers on your Sprint account, invites scaremongering

Some crack reporting from an NBC affiliate news station has revealed a little foible in Best Buy's cellphone upgrade checking utility. If you punch in your Sprint mobile number and ZIP code, you get taken to a screen showing all the other numbers on your account as well. This applies only when yours is the main number on the account, mind you, but the issue is in the obviously lax approach to securing data you might care to keep private -- Verizon, AT&T and T-Mobile customers have to pass a security check first. Of course, the actual risks resulting from someone being able to find other numbers associated with your cellular account are so small as to verge on the benign ("somebody can use that... for something", as the KXAN report sagely advises), though that hardly excuses Best Buy from being sloppy with Sprint subscribers. They're human too, you know! KXAN.com Best Buy Mobile Upgrade Checker

Sony Ericsson's Canadian online store hacked, more than 2,000 customers' data taken

The hackers just won't give poor Sony a break, will they? Following the infamous PSN breach last month and an attack on the company's Greek online music service earlier this week, Sony Ericsson has now seen another intrusion that extracted personal data of more than 2,000 Canadian Eshop customers. Fortunately, the company claims that passwords taken were encrypted and no credit card details were lost, but this is still worrisome nevertheless. Right now, the Eshop service has been taken off line -- for the sake of Sir Howard and his Japanese chums, let's just hope that this will be the last Sony breach we hear about.   The Star ,  BBC

New CyanogenMod lets you rule Android app permissions with an iron fist

We've recently seen Google crack down on rogue apps and patch some server-side security issues, but let's not forget Android does have a small measure of built-in security: app permissions. But as with those pesky EULAs, many users tend to breeze through the permissions screen. And Android forces even the most attentive readers to accept or deny  all  permissions requested by an app. But the newest nightly builds of the CyanogenMod custom ROM include a clever patch allowing users to grant and revoke permissions individually -- something like the TISSA security manager we're still awaiting. Obviously playing God with permissions can crash your applications: with great power comes great responsibility. But we figure if you're running aftermarket firmware on a rooted phone, you're comfortable experimenting. See how it works in the video after the break, then hit the source link to download. Androinica CyanogenMod

Apple patent application reveals an LCD with switchable, privacy-protecting viewing angles

Don't you hate it when the guy next to you on the subway is looking over your shoulder, watching you screw up in  Fruit Ninja ? Well, Apple could have predicted your discomfort -- back in November 2009, before the iPad was anything more than a unicorn, the company applied for a patent on an LCD display with adjustable viewing angles, explicitly designed to "shield the display away from unintended viewers." According to the filing, the display would include steering modules made of liquid crystal material, which aim the so-called scattering modules that sit on top of them. The top layer then redirects the light, making it possible to narrow down and alter the viewing angle. The patent specifically calls out cellphones and laptops, paving the way for discreet displays on MacBooks and iPhones, though the broad phrase "other portable electronic devices" leaves plenty of room for iPads and iPod Touches. No word, of course, on when or if Apple will secure this patent...

Tor to fork Firefox for simplified anonymous browsing, doesn't think you're paranoid

Soon political dissidents, whistle blowers, and those trying to cheat MLB.TV's blackout restrictions will have an easier way to protect their privacy thanks to a dedicated Tor Browser. For those of you unfamiliar with it, Tor is a tool for anonymizing web browsing and communications through encryption and proxy servers. Trouble is, it requires both a browser extension  and  a standalone app to work -- leaving average users "horribly confused," according to developer Mike Perry. So, the organization has decided to retire the Tor Button and create its own fork of Firefox with private browsing features baked in. As an added benefit, Tor will no longer be at the mercy of Mozilla to fix bugs that affect privacy and security. For now, the group will focus on its downloadable bundle with automatic configuration scripts for simplifying setup, but eventually the paranoid will have a browser they can finally call their own. PC World The Tor Blog

Sony promises 'phased restoration' of PlayStation Network and Qriocity starting this week

Sony made quite a few promises this morning about how it intends to deal with the fallout from the PlayStation Network outage and breach when it wasn't profusely and solemnly apologizing -- you can find our liveblog right here -- including improved security measures and a few token handouts of 30-day free subscriptions to PlayStation Plus and Qriocity and possibly some free software. Perhaps more importantly for you gamers, Kaz Hirai told reporters that services will resume "soon," and by the end of the week we should see some functionality return. Of course, it made those promises  in Japanese , but if you want an English copy you won't have to look far, as the official  PlayStation.Blog  got hold of a press release with them all spelled out. Find the full document after the break. SOME PLAYSTATION®NETWORK AND QRIOCITY™ SERVICES TO BE AVAILABLE THIS WEEK Phased Global Rollout of Services to Begin Regionally; System Security Enhanced to Provide Greater Pro...

Skype for Android vulnerable to hack that compromises personal info

If you didn't already have enough potential app privacy leaks to worry about, here's one more --  Android Police  discovered that Skype's Android client leaves your personal data wide open to assault. The publication reports that the app has SQLite3 databases where all your info and chat logs are stored, and that Skype forgot to encrypt the files or enforce permissions, which seems to be a decision akin to leaving keys hanging out of the door. Basically, that means a rogue app could grab all your data and phone home -- an app much like Skypwned. That's a test program  Android Police  built to prove the vulnerability exists, and boy, oh boy does it work -- despite only asking for basic Android storage and phone permissions, it instantly displayed our full name, phone number, email addresses and a list of all our contacts without requiring so much as a username to figure it out.  Android Police  says Skype is investigating the issue now...

Pandora mobile app found to be sending birth date, gender and location information to ad servers

We still haven't heard much more about that Federal Grand Jury investigation into Pandora and other mobile apps over privacy concerns, but an independent security firm has now gone ahead and taken matters into its own hands. According to an analysis done by the folks at Veracode, Pandora does indeed seem to be sharing more information about you then it lets on. More specifically, they found that the Android app (they haven't yet gotten around to the iOS version) "appears" to be sending information about users' birth date, gender, Android ID and GPS location to various advertising companies -- bits of information that the firm notes could be combined to determine who someone is, what they do for a living, and even who they associate with. For its part, Pandora is simply declining to to comment at the moment, and we're guessing that's unlikely to change anytime soon given the aforementioned in...

Facebook planning facial recognition for picture uploads? (update: yes!)

It is indeed less earth-shattering than that alleged (and, it turns out, false) Google app we heard about a few days back, but one of our loyal readers has stumbled across what appears to be an up-and-coming (and thus far inactive) facial recognition feature in his Facebook privacy settings. And, you know what? We have found the same thing! Although we are somewhat mollified by the prospect that this bad boy (when and if it becomes active) will only highlight our mug in pictures uploaded by friends, we bemoan the possibility that even more of our lives will be spent untagging ourselves from embarrassing party snaps. Update: Looks like this is the same ol' "box around the face" update that's been gradually rolling out for quite some time. Is it new to you? It's enabled by default -- but feel free to disable it in your privacy settings.