19 April 2018

Data experts on Facebook’s GDPR changes: Expect lawsuits


Make no mistake: Fresh battle lines are being drawn in the clash between data-mining tech giants and Internet users over people’s right to control their personal information and protect their privacy.

An update to European Union data protection rules next month — called the General Data Protection Regulation — is the catalyst for this next chapter in the global story of tech vs privacy.

A fairytale ending would remove that ugly ‘vs’ and replace it with an enlightened ‘+’. But there’s no doubt it will be a battle to get there — requiring legal challenges and fresh case law to be set down — as an old guard of dominant tech platforms marshal their extensive resources to try to hold onto the power and wealth gained through years of riding roughshod over data protection law.

Payback is coming though. Balance is being reset. And the implications of not regulating what tech giants can do with people’s data has arguably never been clearer.

The exciting opportunity for startups is to skate to where the puck is going — by thinking beyond exploitative legacy business models that amount to embarrassing blackboxes whose CEOs dare not publicly admit what the systems really do — and come up with new ways of operating and monetizing services that don’t rely on selling the lie that people don’t care about privacy.

 

More than just small print

Right now the EU’s General Data Protection Regulation can take credit for a whole lot of spilt ink as tech industry small print is reworded en masse. Did you just receive a T&C update notification about a company’s digital service? Chances are it’s related to the incoming standard.

The regulation is generally intended to strengthen Internet users’ control over their personal information, as we’ve explained before. But its focus on transparency — making sure people know how and why data will flow if they choose to click ‘I agree’ — combined with supersized fines for major data violations represents something of an existential threat to ad tech processes that rely on pervasive background harvesting of users’ personal data to be siphoned biofuel for their vast, proprietary microtargeting engines.

This is why Facebook is not going gentle into a data processing goodnight.

Indeed, it’s seizing on GDPR as a PR opportunity — shamelessly stamping its brand on the regulatory changes it lobbied so hard against, including by taking out full page print ads in newspapers…

This is of course another high gloss plank in the company’s PR strategy to try to convince users to trust it — and thus to keep giving it their data. Because — and only because — GDPR gives consumers more opportunity to lock down access to their information and close the shutters against countless prying eyes.

But the pressing question for Facebook — and one that will also test the mettle of the new data protection standard — is whether or not the company is doing enough to comply with the new rules.

One important point re: Facebook and GDPR is that the standard applies globally, i.e. for all Facebook users whose data is processed by its international entity, Facebook Ireland (and thus within the EU); but not necessarily universally — with Facebook users in North America not legally falling under the scope of the regulation.

Users in North America will only benefit if Facebook chooses to apply the same standard everywhere. (And on that point the company has stayed exceedingly fuzzy.)

It has claimed it won’t give US and Canadian users second tier status vs the rest of the world where their privacy is concerned — saying they’re getting the same “settings and controls” — but unless or until US lawmakers spill some ink of their own there’s nothing but an embarrassing PR message to regulate what Facebook chooses to do with Americans’ data. It’s the data protection principles, stupid.

Zuckerberg was asked by US lawmakers last week what kind of regulation he would and wouldn’t like to see laid upon Internet companies — and he made a point of arguing for privacy carve outs to avoid falling behind, of all things, competitors in China.

Which is an incredibly chilling response when you consider how few rights — including human rights — Chinese citizens have. And how data-mining digital technologies are being systematically used to expand Chinese state surveillance and control.

The ugly underlying truth of Facebook’s business is that it also relies on surveillance to function. People’s lives are its product.

That’s why Zuckerberg couldn’t tell US lawmakers to hurry up and draft their own GDPR. He’s the CEO saddled with trying to sell an anti-privacy, anti-transparency position — just as policymakers are waking up to what that really means.

 

Plus ça change?

Facebook has announced a series of updates to its policies and platform in recent months, which it’s said are coming to all users (albeit in ‘phases’). The problem is that most of what it’s proposing to achieve GDPR compliance is simply not adequate.

Coincidentally many of these changes have been announced amid a major data mishandling scandal for Facebook, in which it’s been revealed that data on up to 87M users was passed to a political consultancy without their knowledge or consent.

It’s this scandal that led Zuckerberg to be perched on a booster cushion in full public view for two days last week, dodging awkward questions from US lawmakers about how his advertising business functions.

He could not tell Congress there wouldn’t be other such data misuse skeletons in its closet. Indeed the company has said it expects it will uncover additional leaks as it conducts a historical audit of apps on its platform that had access to “a large amount of data”. (How large is large, one wonders… )

But whether Facebook’s business having enabled — in just one example — the clandestine psychological profiling of millions of Americans for political campaign purposes ends up being the final, final straw that catalyzes US lawmakers to agree their own version of GDPR is still tbc.

Any new law will certainly take time to formulate and pass. In the meanwhile GDPR is it.

The most substantive GDPR-related change announced by Facebook to date is the shuttering of a feature called Partner Categories — in which it allowed the linking of its own information holdings on people with data held by external brokers, including (for example) information about people’s offline activities.

Evidently finding a way to close down the legal liabilities and/or engineer consent from users to that degree of murky privacy intrusion — involving pools of aggregated personal data gathered by goodness knows who, how, where or when — was a bridge too far for the company’s army of legal and policy staffers.

Other notable changes it has so far made public include consolidating settings onto a single screen vs the confusing nightmare Facebook has historically required users to navigate just to control what’s going on with their data (remember the company got a 2011 FTC sanction for “deceptive” privacy practices); rewording its T&Cs to make it more clear what information it’s collecting for what specific purpose; and — most recently — revealing a new consent review process whereby it will be asking all users (starting with EU users) whether they consent to specific uses of their data (such as processing for facial recognition purposes).

As my TC colleague Josh Constine wrote earlier in a critical post dissecting the flaws of Facebook’s approach to consent review, the company is — at very least — not complying with the spirit of GDPR’s law.

Indeed, Facebook appears pathologically incapable of abandoning its long-standing modus operandi of socially engineering consent from users (doubtless fed via its own self-reinforced A/B testing ad expertise). “It feels obviously designed to get users to breeze through it by offering no resistance to continue, but friction if you want to make changes,” was his summary of the process.

But, as we’ve pointed out before, concealment is not consent.

To get into a few specifics, pre-ticked boxes — which is essentially what Facebook is deploying here, with a big blue “accept and continue” button designed to grab your attention as it’s juxtaposed against an anemic “manage data settings” option (which if you even manage to see it and read it sounds like a lot of tedious hard work) — aren’t going to constitute valid consent under GDPR.

Nor is this what ‘privacy by default’ looks like — another staple principle of the regulation. On the contrary, Facebook is pushing people to do the opposite: Give it more of their personal information — and fuzzing why it’s asking by bundling a range of usage intentions.

The company is risking a lot here.

In simple terms, seeking consent from users in a way that’s not fair because it’s manipulative means consent is not being freely given. Under GDPR, it won’t be consent at all. So Facebook appears to be seeing how close to the wind it can fly to test how regulators will respond.

Safe to say, EU lawmakers and NGOs are watching.

 

“Yes, they will be taken to court”

“Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment,” runs one key portion of GDPR.

Now compare that with: “People can choose to not be on Facebook if they want” — which was Facebook’s deputy chief privacy officer, Rob Sherman’s, paper-thin defense to reporters for the lack of an overall opt out for users to its targeted advertising.

Data protection experts who TechCrunch spoke to suggest Facebook is failing to comply with, not just the spirit, but the letter of the law here. Some were exceeding blunt on this point.

“I am less impressed,” said law professor Mireille Hildebrandt discussing how Facebook is railroading users into consenting to its targeted advertising. “It seems they have announced that they will still require consent for targeted advertising and refuse the service if one does not agree. This violates [GDPR] art. 7.4 jo recital 43. So, yes, they will be taken to court.”

“Zuckerberg appears to view the combination of signing up to T&Cs and setting privacy options as ‘consent’,” adds cyber security professor Eerke Boiten. “I doubt this is explicit or granular enough for the personal data processing that FB do. The default settings for the privacy settings certainly do not currently provide for ‘privacy by default’ (GDPR Art 25).

“I also doubt whether FB Custom Audiences work correctly with consent. FB finds out and retains a small bit of personal info through this process (that an email address they know is known to an advertiser), and they aim to shift the data protection legal justification on that to the advertisers. Do they really then not use this info for future profiling?”

That looming tweak to the legal justification of Facebook’s Custom Audiences feature — a product which lets advertisers upload contact lists in a hashed form to find any matches among its own user-base (so those people can be targeted with ads on Facebook’s platform) — also looks problematical.

Here the company seems to be intending to try to claim a change in the legal basis, pushed out via new terms in which it instructs advertisers to agree they are the data controller (and it is merely a data processor). And thereby seek to foist a greater share of the responsibility for obtaining consent to processing user data onto its customers.

However such legal determinations are simply not a matter of contract terms. They are based on the fact of who is making decisions about how data is processed. And in this case — as other experts have pointed out — Facebook would be classed as a joint controller with any advertisers that upload personal data. The company can’t use a T&Cs change to opt out of that.

Wishful thinking is not a reliable approach to legal compliance.

 

Fear and manipulation of highly sensitive data

Over many years of privacy-hostile operation, Facebook has shown it has a major appetite for even very sensitive data. And GDPR does not appear to have blunted that.

Let’s not forget, facial recognition was a platform feature that got turned off in the EU, thanks to regulatory intervention. Yet here Facebook is now trying to use GDPR as a route to process this sensitive biometric data for international users after all — by pushing individual users to consent to it by dangling a few ‘feature perks’ at the moment of consent.

Veteran data protection and privacy consultant, Pat Walshe, is unimpressed.

“The sensitive data tool appears to be another data grab,” he tells us, reviewing Facebook’s latest clutch of ‘GDPR changes’. “Note the subtlety. It merges ‘control of sharing’ such data with FB’s use of the data “to personalise features and products”. From the info available that isn’t sufficient to amount to consent for such sensitive data and nor is it clear folks can understand the broader implications of agreeing.

“Does it mean ads will appear in Instagram? WhatsApp etc? The default is also set to ‘accept’ rather than ‘review and consider’. This is really sensitive data we’re talking about.”

“The face recognition suggestions are woeful,” he continues. “The second image — is using an example… to manipulate and stoke fear — “we can’t protect you”.

“Also, the choices and defaults are not compatible with [GDPR] Article 25 on data protection by design and default nor Recital 32… If I say no to facial recognition it’s unclear if other users can continue to tag me.”

Of course it goes without saying that Facebook users will keep uploading group photos, not just selfies. What’s less clear is whether Facebook will be processing the faces of other people in those shots who have not given (and/or never even had the opportunity to give) consent to its facial recognition feature.

People who might not even be users of its product.

But if it does that it will be breaking the law. Yet Facebook does indeed profile non-users — despite Zuckerberg’s claims to Congress not to know about its shadow profiles. So the risk is clear.

It can’t give non-users “settings and controls” not to have their data processed. So it’s already compromised their privacy — because it never gained consent in the first place.

New Mexico Representative Ben Lujan made this point to Zuckerberg’s face last week and ended the exchange with a call to action: “So you’re directing people that don’t even have a Facebook page to sign up for a Facebook page to access their data… We’ve got to change that.”

WASHINGTON, DC – APRIL 11: Facebook co-founder, Chairman and CEO Mark Zuckerberg prepares to testify before the House Energy and Commerce Committee in the Rayburn House Office Building on Capitol Hill April 11, 2018 in Washington, DC. This is the second day of testimony before Congress by Zuckerberg, 33, after it was reported that 87 million Facebook users had their personal information harvested by Cambridge Analytica, a British political consulting firm linked to the Trump campaign. (Photo by Chip Somodevilla/Getty Images)

But nothing in the measures Facebook has revealed so far, as its ‘compliance response’ to GDPR, suggest it intends to pro-actively change that.

Walshe also critically flags how — again, at the point of consent — Facebook’s review process deploys examples of the social aspects of its platform (such as how it can use people’s information to “suggest groups or other features or products”) as a tactic for manipulating people to agree to share religious affiliation data, for example.

“The social aspect is not separate to but bound up in advertising,” he notes, adding that the language also suggests Facebook uses the data.

Again, this whiffs a whole lot more than smells like GDPR compliance.

“I don’t believe FB has done enough,” adds Walshe, giving a view on Facebook’s GDPR preparedness ahead of the May 25 deadline for the framework’s application — as Zuckerberg’s Congress briefing notes suggested the company itself believes it has. (Or maybe it just didn’t want to admit to Congress that U.S. Facebook users will get lower privacy standards vs users elsewhere.)

“In fact I know they have not done enough. Their business model is skewed against privacy — privacy gets in the way of advertising and so profit. That’s why Facebook has variously suggested people may have to pay if they want an ad free model & so ‘pay for privacy’.”

“On transparency, there is a long way to go,” adds Boiten. “Friend suggestions, profiling for advertising, use of data gathered from like buttons and web pixels (also completely missing from “all your Facebook data”), and the newsfeed algorithm itself are completely opaque.”

“What matters most is whether FB’s processing decisions will be GDPR compliant, not what exact controls are given to FB members,” he concludes.

US lawmakers also pumped Zuckerberg on how much of the information his company harvests on people who have a Facebook account is revealed to them when they ask for it — via its ‘Download your data’ tool.

His answers on this appeared to intentionally misconstrue what was being asked — presumably in a bid to mask the ugly reality of the true scope and depth of the surveillance apparatus he commands. (Sometimes with a few special ‘CEO privacy privileges’ thrown in — like being able to selectively retract just his own historical Facebook messages from conversations, ahead of bringing the feature to anyone else.)

‘Download your Data’ is clearly partial and self-serving — and thus it also looks very far from being GDPR compliant.

 

Not even half the story

Facebook is not even complying with the spirit of current EU data protection law on data downloads. Subject Access Requests give individuals the right to request not just the information they have voluntarily uploaded to a service, but also personal data the company holds about them; Including giving a description of the personal data; the reasons it is being processed; and whether it will be given to any other organizations or people.

Facebook not only does not include people’s browsing history in the info it provides when you ask to download your data — which, incidentally, its own cookies policy confirms it tracks (via things like social plug-ins and tracking pixels on millions of popular websites etc etc) — it also does not include a complete list of advertisers on its platform that have your information.

Instead, after a wait, it serves up an eight-week snapshot. But even this two month view can still stretch to hundreds of advertisers per individual.

If Facebook gave users a comprehensive list of advertisers’ access to their information the number of third party companies would clearly stretch into the thousands. (In some cases thousands might even be a conservative estimate.)

There’s plenty of other information harvested from users that Facebook also intentionally fails to divulge via ‘Download your data’. And — to be clear — this isn’t a new problem either. The company has a very long history of blocking these type of requests.

In the EU it currently invokes a exception in Irish law to circumvent more fulsome compliance — which, even setting GDPR aside, raises some interesting competition law questions, as Paul-Olivier Dehaye told the UK parliament last month.

“All your Facebook data” isn’t a complete solution,” agrees Boiten. “It misses the info Facebook uses for auto-completing searches; it misses much of the information they use for suggesting friends; and I find it hard to believe that it contains the full profiling information.”

“Ads Topics” looks rather random and undigested, and doesn’t include the clear categories available to advertisers,” he further notes.

Facebook wouldn’t comment publicly about this when we asked. But it maintains its approach towards data downloads is GDPR compliant — and says it’s reviewed what it offers via with regulators to get feedback.

Earlier this week it also put out a wordy blog post attempting to diffuse this line of attack by pointing the finger of blame at the rest of the tech industry — saying, essentially, that a whole bunch of other tech giants are at it too.

Which is not much of a moral defense even if the company believes its lawyers can sway judges with it. (Ultimately I wouldn’t fancy its chances; the EU’s top court has a robust record of defending fundamental rights.)

 

Think of the children…

What its blog post didn’t say — yet again — was anything about how all the non-users it nonetheless tracks around the web are able to have any kind of control over its surveillance of them.

And remember, some Facebook non-users will be children.

So yes, Facebook is inevitably tracking kids’ data without parental consent. Under GDPR that’s a majorly big no-no.

TC’s Constine had a scathing assessment of even the on-platform system that Facebook has devised in response to GDPR’s requirements on parental consent for processing the data of users who are between the ages of 13 and 15.

“Users merely select one of their Facebook friends or enter an email address, and that person is asked to give consent for their ‘child’ to share sensitive info,” he observed. “But Facebook blindly trusts that they’ve actually selected their parent or guardian… [Facebook’s] Sherman says Facebook is “not seeking to collect additional information” to verify parental consent, so it seems Facebook is happy to let teens easily bypass the checkup.”

So again, the company is being shown doing the minimum possible — in what might be construed as a cynical attempt to check another compliance box and carry on its data-sucking business as usual.

Given that intransigence it really will be up to the courts to bring the enforcement stick. Change, as ever, is a process — and hard won.

Hildebrandt is at least hopeful that a genuine reworking of Internet business models is on the way, though — albeit not overnight. And not without a fight.

“In the coming years the landscape of all this silly microtargeting will change, business models will be reinvented and this may benefit both the advertisers, consumers and citizens,” she tells us. “It will hopefully stave off the current market failure and the uprooting of democratic processes… Though nobody can predict the future, it will require hard work.”


Read Full Article

Can data science save social media?


The unfettered internet is too often used for malicious purposes and is frequently woefully inaccurate. Social media — especially Facebook — has failed miserably at protecting user privacy and blocking miscreants from sowing discord.

That’s why CEO Mark Zuckerberg was just forced to testify about user privacy before both houses of Congress. And now governmental regulation of Facebook and other social media appears to be a fait accompli.

At this key juncture, the crucial question is whether regulation — in concert with Facebook’s promises to aggressively mitigate its weaknesses — will correct the privacy abuses and continue to fulfill Facebook’s goal of giving people the power to build transparent communities, bringing the world closer together?

The answer is maybe.

What has not been said is that Facebook must embrace data science methodologies initially created in the bowels of the federal government to help protect its two billion users. Simultaneously, Facebook must still enable advertisers — its sole source of revenue — to get the user data required to justify their expenditures.

Specifically, Facebook must promulgate and embrace what is known in high-level security circles as homomorphic encryption (HE), often considered the “Holy Grail” of cryptography, and data provenance (DP). HE would enable Facebook, for example, to generate aggregated reports about its user psychographic profiles so that advertisers could still accurately target groups of prospective customers without knowing their actual identities.

Meanwhile, data provenance — the process of tracing and recording true identities and the origins of data and its movement between databases — could unearth the true identities of Russian perpetrators and other malefactors, or at least identify unknown provenance, adding much-needed transparency in cyberspace.

Both methodologies are extraordinarily complex. IBM and Microsoft, in addition to the National Security Agency, have been working on HE for years, but the technology has suffered from significant performance challenges. Progress is being made, however. IBM, for example, has been granted a patent on a particular HE method — a strong hint it’s seeking a practical solution — and last month proudly announced that its rewritten HE encryption library now works up to 75 times faster. Maryland-based ENVEIL, a startup staffed by the former NSA HE team, has broken the performance barriers required to produce a commercially viable version of HE, benchmarking millions of times faster than IBM in tested use cases.

How homomorphic encryption would help Facebook

HE is a technique used to operate on and draw useful conclusions from encrypted data without decrypting it, simultaneously protecting the source of the information. It is useful to Facebook because its massive inventory of personally identifiable information is the foundation of the economics underlying its business model. The more comprehensive the data sets about individuals, the more precisely advertising can be targeted.

HE could keep Facebook information safe from hackers and inappropriate disclosure, but still extract the essence of what the data tells advertisers. It would convert encrypted data into strings of numbers, do math with these strings, then decrypt the results to get the same answer it would if the data wasn’t encrypted at all.

A particularly promising sign for HE emerged last year, when Google revealed a new marketing measurement tool that relies on this technology to allow advertisers to see whether their online ads result in in-store purchases.

Unearthing this information requires analyzing data sets belonging to separate organizations, notwithstanding the fact that these organizations pledge to protect the privacy and personal information of the data subjects. HE skirts this by generating aggregated, non-specific reports about the comparisons between these data sets.

In pilot tests, HE enabled Google to successfully analyze encrypted data about who clicked on an advertisement in combination with another encrypted multi-company data set that recorded credit card purchase records. With this data in hand, Google was able to provide reports to advertisers summarizing the relationship between the two databases to conclude, for example, that five percent of the people who clicked on an ad wound up purchasing in a store.

Data provenance

Data provenance has a markedly different core principle. It’s based on the fact that digital information is atomized into 1s and 0s with no intrinsic truth. The dual digits exist only to disseminate information, whether accurate or widely fabricated. A well-crafted lie can easily be indistinguishable from the truth and distributed across the internet. What counts is the source of these 1s and 0s. In short, is it legitimate? What is the history of the 1s and 0s?

The art market, as an example, deploys DP to combat fakes and forgeries of the world’s greatest paintings, drawings and sculptures. It uses DP techniques to create a verifiable, chain-of-custody for each piece of the artwork, preserving the integrity of the market.

Much the same thing can be done in the online world. For example, a Facebook post referencing a formal statement by a politician, with an accompanying photo, would have provenance records directly linking the post to the politician’s press release and even the specifics of the photographer’s camera. The goal — again — is ensuring that data content is legitimate.

Companies such as Walmart, Kroger, British-based Tesco and Swedish-based H&M, an international clothing retailer, are using or experimenting with new technologies to provide provenance data to the marketplace.

Let’s hope that Facebook and its social media brethren begin studying HE and DP thoroughly and implement it as soon as feasible. Other strong measures — such as the upcoming implementation of the European Union’s General Data Protection Regulation, which will use a big stick to secure personally identifiable information — essentially should be cloned in the U.S. What is best, however, are multiple avenues to enhance user privacy and security, while hopefully preventing breaches in the first place. Nothing less than the long-term viability of social media giants is at stake.


Read Full Article

Opera Shuts Down Its VPN App for Android and iOS


Opera has announced that it’s shutting down its VPN app at the end of this month. The Opera VPN app, which provided Android and iOS users with a free VPN for their phones, is to be permanently discontinued as of April 30, 2018. Which sucks.

For the past couple of years, Opera has offered its own VPN service. The desktop browser has a free VPN built into it, and the Opera VPN app for Android and iOS welcomed smartphone users to the party as well. But Opera is now scaling back.

The Opera VPN App Is No More

According to the Opera VPN website, Opera is “discontinuing the Opera VPN app for iOS and Android on April 30, 2018”. The Opera VPN app allowed users to connect to countries around the world, with extra tools to prevent tracking and test their security.

As well as the free version, Opera offered an Opera VPN Gold service that increased speeds, added more countries to the mix, and added dedicated customer support, all for $30/year. But both the free version and the Gold version will soon be no more.

Given that some people have paid for this app beyond the end of this month, Opera is offering Opera Gold users a free 1-year subscription to SurfEasy Ultra VPN. And everyone else will be offered an 80 percent discount on SurfEasy Total VPN through the app.

It isn’t yet clear whether Opera is only shutting down the Opera VPN app on Android and iOS or whether the free VPN built into the desktop browser is also for the chop. However, users of the Opera browser should probably find an alternative, just in case.

What’s Next on the Chopping Board?

As to why, there is speculation that Opera has discontinued its VPN as a direct result of being owned by a Chinese consortium. VPNs are obviously very popular with Chinese citizens looking to circumvent China’s internet restrictions, hence the speculation.

Opera’s decision to can its VPN app comes just a few months after Opera killed its data-saving app, Opera Max. And once again there was no real reason given for shutting it down. If I was an opera user I’d be worrying about what’s next on the chopping board.


Read Full Article

Can data science save social media?


The unfettered internet is too often used for malicious purposes and is frequently woefully inaccurate. Social media — especially Facebook — has failed miserably at protecting user privacy and blocking miscreants from sowing discord.

That’s why CEO Mark Zuckerberg was just forced to testify about user privacy before both houses of Congress. And now governmental regulation of FaceBook and other social media appears to be a fait accompli.

At this key juncture, the crucial question is whether regulation — in concert with FaceBook’s promises to aggressively mitigate its weaknesses — correct the privacy abuses and continue to fulfill FaceBook’s goal of giving people the power to build transparent communities, bringing the world closer together?

The answer is maybe.

What has not been said is that FaceBook must embrace data science methodologies initially created in the bowels of the federal government to help protect its two billion users. Simultaneously, FaceBook must still enable advertisers — its sole source of revenue — to get the user data required to justify their expenditures.

Specifically, Facebook must promulgate and embrace what is known in high-level security circles as homomorphic encryption (HE), often considered the “Holy Grail” of cryptography, and data provenance (DP). HE would enable Facebook, for example, to generate aggregated reports about its user psychographic profiles so that advertisers could still accurately target groups of prospective customers without knowing their actual identities.

Meanwhile, data provenance – the process of tracing and recording true identities and the origins of data and its movement between data bases – could unearth the true identities of Russian perpetrators and other malefactors or at least identify unknown provenance, adding much needed transparency in cyberspace.

Both methodologies are extraordinarily complex. IBM and Microsoft, in addition to the National Security Agency, have been working on HE for years but the technology has suffered from significant performance challenges. Progress is being made, however. IBM, for example, has been granted a patent on a particular HE method – a strong hint it’s seeking a practical solution – and last month proudly announced that its rewritten HE encryption library now works up to 75 times faster. Maryland-based ENVEIL, a startup staffed by the former NSA HE team, has broken the performance barriers required to produce a commercially viable version of HE, benchmarking millions of times faster than IBM in tested use cases.

How Homomorphic Encryption Would Help FaceBook

HE is a technique used to operate on and draw useful conclusions from encrypted data without decrypting it, simultaneously protecting the source of the information. It is useful to FaceBook because its massive inventory of personally identifiable information is the foundation of the economics underlying its business model. The more comprehensive the datasets about individuals, the more precisely advertising can be targeted.

HE could keep Facebook information safe from hackers and inappropriate disclosure, but still extract the essence of what the data tells advertisers. It would convert encrypted data into strings of numbers, do math with these strings, and then decrypt the results to get the same answer it would if the data wasn’t encrypted at all.

A particularly promising sign for HE emerged last year, when Google revealed a new marketing measurement tool that relies on this technology to allow advertisers to see whether their online ads result in in-store purchases.

Unearthing this information requires analyzing datasets belonging to separate organizations, notwithstanding the fact that these organizations pledge to protect the privacy and personal information of the data subjects. HE skirts this by generating aggregated, non-specific reports about the comparisons between these datasets.

In pilot tests, HE enabled Google to successfully analyze encrypted data about who clicked on an advertisement in combination with another encrypted multi-company dataset that recorded credit card purchase records. With this data in hand, Google was able to provide reports to advertisers summarizing the relationship between the two databases to conclude, for example, that five percent of the people who clicked  on an ad wound up purchasing in a store.

Data Provenance

Data provenance has a markedly different core principle. It’s based on the fact that digital information is atomized into 1’s and 0’s with no intrinsic truth. The dual digits exist only to disseminate information, whether accurate or widely fabricated. A well-crafted lie can easily be indistinguishable from the truth and distributed across the internet. What counts is the source of these 1’s and 0’s. In short, is it legitimate?  What is the history of the 1’ and 0’s?

The art market, as an example, deploys DP to combat fakes and forgeries of the world’s greatest paintings, drawing and sculptures. It uses DP techniques to create a verifiable, chain-of-custody for each piece of the artwork, preserving the integrity of the market.

Much the same thing can be done in the online world. For example, a FaceBook post referencing a formal statement by a politician, with an accompanying photo, would  have provenance records directly linking the post to the politician’s press release and even the specifics of the photographer’s camera. The goal – again – is ensuring that data content is legitimate.

Companies such as Wal-Mart, Kroger, British-based Tesco and Swedish-based H&M, an international clothing retailer, are using or experimenting with new technologies to provide provenance data to the marketplace.

Let’s hope that Facebook and its social media brethren begin studying HE and DP thoroughly and implement it as soon as feasible. Other strong measures — such as the upcoming implementation of the European Union’s General Data Protection Regulation, which will use a big stick to secure personally identifiable information – essentially should be cloned in the U.S. What is best, however, are multiple avenues to enhance user privacy and security, while hopefully preventing breaches in the first place. Nothing less than the long-term viability of social media giants is at stake.


Read Full Article

Watch SpaceX launch NASA’s new planet-hunting satellite here


It’s almost time for SpaceX to launch NASA’s TESS, a space telescope that will search for exoplants more across nearly the entire night sky. The launch has been delayed more than once already: originally scheduled for March 20, it slipped to April 16 (Monday), then some minor issues pushed it to today — at 3:51 PM Pacific time, to be precise. You can watch the launch live below.

TESS, which stands for Transit Exoplanet Survey Satellite, is basically a giant wide-angle camera (four of them, actually) that will snap pictures of the night sky from a wide, eccentric, and never before tried orbit.

The technique it will use is fundamentally the same as that employed by NASA’s long-running and highly successful Kepler mission. When distant plants pass between us and their star, it cause a momentary decrease in that star’s brightness. TESS will monitor thousands of stars simultaneously for such “transits,” watching a single section of sky for a month straight before moving on to another.

By two years, it will have imaged 85 percent of the sky — hundreds of times the area Kepler observed, and on completely different stars: brighter ones that should yield more data.

TESS, which is about the size of a small car, will launch on top of a SpaceX Falcon 9 rocket. SpaceX will attempt to recover the first stage of the rocket by having it land on a drone ship, and the nose cone will, hopefully, get a gentle parachute-assisted splashdown in the Atlantic, where it too can be retrieved.

The feed below should go live 15 minutes before launch, or at about 3:35.


Read Full Article

Login With Facebook data hijacked by JavaScript trackers


Facebook confirms to TechCrunch that it’s investigating a security research report that shows Facebook user data can be grabbed by third-party JavaScript trackers embedded on websites using Login With Facebook. The exploit lets these trackers gather a user’s data including name, email address, age range, gender, locale, and profile photo depending on what users originally provided to the website. It’s unclear what these trackers do with the data, but many of their parent companies including Tealium, AudienceStream, Lytics, and ProPS sell publisher monetization services based on collected user data.

The abusive scripts were found on 434 of the top 1 million websites including freelancer site Fiverr.com, camera seller B&H Photo And Video, and cloud database provider MongoDB. That’s according to Steven Englehardt and his colleagues at Freedom To Tinker, which is hosted by Princeton’s Center For Information Technology Policy.

Meanwhile, concert site BandsInTown was found to be passing Login With Facebook user data to embedded scripts on sites that install its Amplified advertising product. An invisible BandsInTown iframe would load on these sites, pulling in user data that was then accessible to embedded scripts. That let any malicious site using BandsInTown learn the identity of visitors. BandsInTown has now fixed this vulnerability.

TechCrunch is still awaiting a formal statement from Facebook beyond “We will look into this and get back to you.” After TechCrunch brough the issue to MongoDB’s attention this morning, it investigated and just provided this statement “We were unaware that a third-party technology was using a tracking script that collects parts of Facebook user data. We have identified the source of the script and shut it down.” Fiverr and BandsInTown did not respond before press time.

 

The discovery of these data security flaws comes at a vulnerable time for Facebook. The company is trying to recover from the Cambridge Analytica scandal, CEO Mark Zuckerberg just testified before congress, and today it unveiled privacy updates to comply with Europe’s GDPR law. But Facebook’s recent API changes designed to safeguard user data didn’t prevent these exploits. And the situation shines more light on the little-understood ways Facebook users are tracked around the Internet, not just on its site.

“When a user grants a website access to their social media profile, they are not only trusting that website, but also third parties embedded on that site” writes Englehardt. This chart shows that what some trackers are pulling from users. Freedom To Tinker warned OnAudience about another security issue recently, leading it to stop collecting user info.

Facebook could have identified these trackers and prevented these exploits with sufficient API auditing. It’s currently ramping up API auditing as it hunts down other developers that might have improperly shared, sold, or used data like how Dr. Aleksandr Kogan’s app’s user data ended up in the hands of Cambridge Analytica. Facebook could also change its systems to prevent developers from taking an app-specific user ID and employing it to discover that person’s permanent overarching Facebook user ID.

Revelations like this are likely to beckon a bigger data backlash. Over the years, the public had became complacent about the ways their data was exploited without consent around the web. While it’s Facebook in the hot seat, other tech giants like Google rely on user data and operate developer platforms that can be tough to police. And news publishers, desperate to earn enough from ads to survive, often fall in with sketchy ad networks and trackers.

Zuckerberg makes an easy target because the Facebook founder is still the CEO, allowing critics and regulators to blame him for the social network’s failings. But any company playing fast and loose with user data should be sweating.


Read Full Article

Google Chrome Now Mutes Autoplaying Videos By Default


Autoplaying videos are, without a doubt, one of the most annoying things about the internet. Whether they’re ads playing in the sidebar, or related content a website presumes you’ll want to watch, autoplaying videos are bad, unnecessary, and unwelcome.

The one thing worse than a standard autoplaying video is an autoplaying video with sound. You can be quietly browsing the web when sound suddenly comes blasting out of your speakers. Thankfully, with Chrome 66, Google is acting to end this annoyance.

Chrome 66 Comes to the Rescue

Chrome 66, the latest version of Google’s ever-popular web browser, mutes autoplaying videos with sound by default. There is a caveat, but this is a huge step forward for everyone who has ever searched through their tabs looking for the culprit.

The big caveat to Chrome’s ability to mute autoplaying videos by default is that some videos will be automatically unmuted based on your previous engagement with certain sites. So, if you regularly watch videos on YouTube they won’t be muted by default.

This is all based on Google’s Media Engagement Index, which tracks the number of visits and playbacks for each individual domain. You can see your own Media Engagement Index by typing chrome://media-engagement/ into your address bar.

Still, even if your previous history with some sites means videos will autoplay with sound, you still have the option of manually muting them. Just right-click to the left of a URL, click “Site settings”, and scroll down until you see the Sound option.

Google Keeps Improving Chrome

Google Chrome’s ability to mute autoplaying videos by default wasn’t totally unexpected. In January 2018, Google released Chrome 64, which let users mute the sites responsible for autoplaying videos. Chrome 66 just goes one step further.

If you’re a fan of Google Chrome, you should check out the essential Google Chrome FAQ, our easy guide to Google Chrome, and/or our list of the best Google Chrome extensions. Just don’t hate us too much if a video starts autoplaying on one of those links.

Image Credit: Steve Baker/Flickr


Read Full Article

The Best Private Encrypted Email and Cloud Office Suite Is Disroot


Finding a private and secure email service isn’t as easy as it used to be. Lavabit was the big name in the business years ago, but since they folded, the options have been limited. And when it comes to private cloud services, it’s difficult to know who to trust.

Which is why you should check out Disroot. It combines free encrypted email with secure cloud services, including an online office suite. If you’re concerned about security, it very well could become your new favorite tool.

What Is Disroot and How Does It Work?

The main service that Disroot offers is free private email. It’s secure, encrypted, and can be used from a browser or your own client (we’ll look at some of the other features momentarily).

But in addition to the private email service, Disroot has partnered with a number of other providers to give you access to other private cloud services.

For example, they’ve partnered with Lufi to provide encrypted temporary file hosting and Matrix for decentralized chat.

The biggest benefit is that you can sign into almost all of these services with your Disroot credentials. So in addition to private email, you’ll be able to take advantage of a limited cloud office suite, private cloud storage, and other services.

Let’s take a look at their secure email service, then move onto other private cloud services that Disroot offers.

Disroot’s Private Encrypted Email Service

If you’re not sending encrypted email, you could be broadcasting your communications to anyone who wants to read them. Most services provide at least some encryption, but popular services aren’t exactly known for respecting your privacy.

Gmail, for example, reads your emails to watch for crimes—and they used to do it to target ads (though they say they stopped doing that in late 2017).

Disroot promises to never track your activity, display ads, profile you, or mine your data. Which means your emails are private. And their web-based email client, RainLoop, has built-in support for GPG encryption to add another layer of security.

Rainloop email interface

It’s worth noting that this is server-side encryption, so you don’t have control of your secret key. But it’s still more private and secure email than you’ll get from Google, Yahoo, Microsoft, or Zoho.

Disroot’s private email service also works with IMAP-based desktop and mobile clients, so you can take your email on the go.

You’re currently limited to 2GB of storage in Disroot’s email client, which isn’t a whole lot but should be enough if you manage your inbox well.

Disroot’s Secure Cloud Storage

Right now, your data is stored all over the internet, and dozens (if not hundreds) of companies are mining it to learn more about you. Disroot has partnered with Nextcloud to give you 4GB of secure cloud storage that’s under your control.

You get to choose a home server, one of Nextcloud’s servers, or a third-party provider to store your data on. Nextcloud runs on that server and protects all of your information. Your data is encrypted, and Nextcloud provides some of the best open-source security around.

Nextcloud’s business-scale servers are HIPAA and GDPR compliant, so you can be confident that the security is top-notch.

Not even the system administrators can get access to your files when they’re encrypted, so you don’t have to worry about anyone snooping on your stuff.

And you can share and sync files, contacts, calendars, and other types of data.

Disroot’s Private Cloud Office Suite

Do you like the idea of Google being able to read all of the documents you keep in Google Drive? If not, you’ll like Disroot’s partnership with EtherPad and EtherCalc. Both apps let you create, share, and edit documents and spreadsheets in real time.

EtherPad running in Chrome

It’s open source and built to enable seamless collaborative editing. You can run EtherPad or EtherCalc on a publicly available instance, or download the client and create your own secure instance.

Disroot doesn’t yet support other things you might like in a cloud office suite, like presentation editing or form creation, but it’s a start.

Disroot’s Private Chat and Social Media Platforms

Disroot gives you access to a few different ways to communicate securely and privately. You can use Matrix, a new but growing decentralized chat protocol, for secure instant messaging.

You’ll also get access to Discourse, which serves as a mailing list, discussion forum, and “long-form chat room.” Discourse isn’t encrypted like most of the other services associated with Disroot. But it does serve as a great alternative to similar apps like Skype, Discord, and HipChat.

And there’s a Disroot node in the Diaspora network that you can use for decentralized, private social media. To use Diaspora, you’ll need to create an account—unlike most other connected services, your Disroot account won’t work as a sign-in.

Diaspora social network philosophies

Disroot’s Other Privacy-Focused Services

Disroot has also partnered with Lufi, PrivateBin, Taiga, and others to provide access to more private services. There’s a private pastebin, anonymous search aggregation, online polls, a project board, and there’s sure to be more coming soon.

Of course, there are some services that you’ll still need to go elsewhere for. There’s no equivalent to Zoho’s customer relationship management app, for example, or for Google’s site builder.

Still, with the growing number of apps that you can use through Disroot, it’s worth checking out.

Is Disroot Really Committed to Privacy?

Anyone can say that they offer private email and private cloud services, but how do you know they’re really committed to privacy? A quick read through Disroot’s website will convince you.

Disroot is a volunteer-run organization based in Amsterdam. They created their private email service and partnered with other secure services because they needed a solution for their own privacy needs. They’re one of the groups pushing toward a more open-source and ethical internet:

“We want to encourage people to break free of the walled gardens of popular software and turn to open and ethical alternatives, may it be on our platform or on another (or you could even host your own).”

None of the services offered by Disroot are paid—they’re funded by donations and support from like-minded internet users.

And they emphasize transparency, openness, and diversity of ideas in the running of their organization. They’re out to build federated, open-source, decentralized projects that help other internet users avoid the monetization of their data.

And that’s a cause worth supporting.

Is Disroot Really the Best for Private Email and Data?

If you don’t want Google reading every document that you save on the cloud, Disroot is absolutely the way to go.

And for private email, Disroot is a fantastic option. While it’s not as secure as an email app with client-side encryption, it’s a lot more secure than using Google or Yahoo. The RainLoop client is a solid choice for browser-based email, and with IMAP you can use any client you want.

But if you need a lot of office suite power, Disroot might not be the best choice for you yet. EtherPad and EtherCalc are great, but it’s always going to be difficult to beat the best online office suites currently available.

Image Credit: ISergey/Depositphotos


Read Full Article

EarthNow promises real-time views of the whole planet from a new satellite constellation


A new space imaging startup called EarthNow aims to provide not just pictures of the planet on demand, but real-time video anywhere a client desires. Its ambition is matched only by its pedigree: Bill Gates, Intellectual Ventures, Airbus, Softbank, and OneWeb founder Greg Wyler are all backing the play.

Its promise is a constellation of satellites that will provide video of anywhere on Earth with latency of about a second. You won’t have to wait for a satellite to come into range, or worry about leaving range; at least one will be able to view any area at any given time, so they can pass of the monitoring task to the next satellite over if necessary.

Initially aimed at “high value enterprise and government customers,” EarthNow lists things like storm monitoring, illegal fishing vessels (or even pirates), forest fires, whale tracking, watching conflicts in real time, and more. Space imaging is turning into quite a crowded field — if all these constellations actually launch, anyway.

The company is in the earliest stages right now, having just been spun out from years of work by founder and CEO Russell Hannigan at Intellectual Ventures under the Invention Science Fund. Early enough, in fact, that there’s no real timeline for prototyping or testing. But it’s not just pie in the sky.

Wyler’s OneWeb connection means EarthNow will be built on a massively upgraded version of that company’s satellite platform. Details are few and far between, but the press release promises that “Each satellite is equipped with an unprecedented amount of onboard processing power, including more CPU cores than all other commercial satellites combined.”

Presumably a large portion of that will be video processing and compression hardware, since they’ll want to minimize bandwidth and latency but don’t want to skimp on quality. Efficiency is important, too; satellites have extremely limited power, so running multiple off-the-shelf GPUs with standard compression methods probably isn’t a good idea. Real-time, continuous video from orbit (as opposed to near-real-time stills or clips) is as much a software problem as it is hardware.

Machine learning also figures, of course: the company plans to do onboard analysis of the imagery, though to what extent isn’t clear. It really makes more sense to me to do this on the ground, but perhaps a first pass by the satellite’s hardware will help move things along.

Airbus will do its part by actually producing the satellites, in Toulouse and Florida. The release doesn’t say how many will be built, but full (and presumably redundant) Earth coverage means dozens at the least. But if they’re mass manufactured standard goods, that should keep the price down, relatively speaking anyway.

No word on the actual amount raised by the company in January, but with the stature of the investors and the high costs involved in the industry, I can’t imagine it’s less than a few tens of millions.

Hannigan himself calls EarthNow “ambitious and unprecedented,” which could be taken as an admission of great risk, but it’s clear that the company has powerful partners and plenty of expertise; Intellectual Ventures doesn’t tend to spin something off unless it’s got something special going. Expect more specifics as the company grows, but I doubt we’ll see anything more than renders for a year or so.


Read Full Article

6 Reasons to Start Buying Used Computers Instead of New Ones

18 April 2018

How to Make a Snapchat Filter in 11 Easy Steps


Snapchat remains one of the most popular multimedia messaging apps on the planet. Although some millenials aren’t fans of Snapchat. The launch of “geofilters” in 2014 is one of the reasons Snapchat boasts 187 million daily active users.

With Snapchat geofilters, you can put artwork, names, logos, and other designs over messages in the app. In a unique twist, Snapchat geofilters only work in specific locations and are often only available for a limited time.

In recent years, Snapchat filtering uses has been dramatically expanded. Today, you can submit filters to represent birthdays, weddings, parties, and much more. These filters cost money and can be expensive, depending on the size of the location you wish to see the filter run.

In this article, you’ll learn all about how to make a Snapchat filter using the new geofilters feature.

How to Make a Snapchat Filter

Any Snapchat user can submit a filter for approval. At the time of this writing, they take two forms: custom and community.

Snapchat is an excellent resource for your workplace, and paid custom filters (sometimes called on-demand filters) can be used to show off your business or celebrate a special event, such as a wedding or birthday, etc.

Free community filters are intended to represent a location (city, university, landmark, or another public place) or moment (sports game, shopping, etc.)

You can create a Snapchat filter either in your web browser or through the Snapchat app. Once you’ve created a filter and submitted it, you should hear back from Snapchat within a few hours on whether it’s been approved.

Let’s take a look at exactly how to make a Snapchat filter.

How to Create a Snapchat Filter Online

snapchat filter web

Here’s how to make a custom Snapchat geofilter online. Note: Be sure to log into your account at the Snapchat website before you begin.

  1. Select Create a Filter from the left side of the screen.
  2. Under Design Online, select your occasion from the pulldown menu. Available choices include Celebrate, Business, Birthday, Prom, and many more.
  3. Once you select a topic, you can choose a template on the left side of the screen or submit your own.
  4. Next, choose a color palette on the right-hand side of the screen, write in new text and choose different fonts, and upload pictures as needed. You also add your Bitmoji or even Friendmoji.
  5. When the filter is to your liking, click Next.
  6. On the next screen, you must assign a start and end time for your filter. You can also select Repeating Event to have the filter run at different times, daily or weekly.
  7. Select Next to draw your geofence. Inside your geofence is the location where Snapchat users will find the filter.
  8. Note that the Snapchat geofilter cost is based on the square foot of the area. Please keep this in mind.
  9. When you’re comfortable with your geofence, click Checkout.
  10. Name your filter, enter your payment information, and then hit Select.
  11. Wait for the approval email.

Snapchat’s geofilter maker is a fun way to customize your Snapchat experience.

How to Make Your Own Snapchat Filter in the App

snapchat filter app

You can also create a Snapchat geofilter through the official Snapchat app, which is available for iOS and Android:

  1. From the camera page in the Snapchat app, select your Profile/Username at the top left of the screen.
  2. Select the Settings icon at the top right.
  3. Choose Filters & Lenses, then select Get Started.
  4. Click Filter.
  5. On the next screen, select the filter occasion. Examples include Birthdays, Baby Shower, Date Night, and more. You can also “Start from Scratch”.
  6. You can select a design and customize your filter with text and stickers.
  7. Once you decide on these items, you need to enter a start and end time for the custom filter. Select Continue.
  8. Create a geofence showing where you’d like the filter to run. Hit Continue.
  9. After agreeing to the filter price, choose Continue.
  10. Select Purchase from the summary page, then make your payment.
  11. Wait for the approval email.

About the Snapchat Geofilter Cost

Now that you know how to make a geofilter, let’s talk about the cost.

The price for a Snapchat filter depends on the location of your geofence, how big it is, and how long you want it to run. Your payment isn’t charged to your account until the filter has been approved. Package prices are available to businesses.

At the time of this writing, Snapchat accepts Visa, MasterCard, American Express, and Discover.

What About Community Snapchat Filters?

snapchat community filters

You can only create community filters via the Snapchat website. You can submit a filter or moment filter. Community filters don’t include templates. Instead, you send an original design that follows Snapchat’s geofilter guidelines.

Snapchat suggests creating community filters in Adobe Photoshop or Adobe Illustrator. Canva is another good choice. Regardless, Snapchat offers the following submission tips:

  • Provide a good description if the artwork does not speak for itself, including any relevant dates.
  • Snapchat’s geofilter size is 1080px wide and 2340px tall.
  • Make sure no text or important elements are within the buffer zone of your filter (210px from the top and bottom).
  • Files should be under 300KB and in PNG format (transparency enabled).

If you stick with these guidelines, your custom Snapchat geofilter will look great.

Adding Snapchat Filters

To add one of the many Snapchat filters to a Snap, follow these simple steps:

  1. In Snapchat, capture a Snap, as usual.
  2. Swipe left and right to choose a filter.
  3. Next, tap the Stack button to stack filters.

To find filters specifically for your area, be sure to Enable Location “While Using the App” in your device’s settings.

Personalize Your Snapchat Experience With Filters

Making a Snapchat filter a great way to personalize your Snapchat experience. Whether you’re thinking of creating a customized filter for an upcoming event or want to advertise the town you call home, Snapchat filters have you covered.

You can create most filters via the Snapchat website and app. Select from one of the many Snapchat filter templates or create one of your own. There’s no limit to the type of filter you can create.

Now that you know how to make a Snapchat filter, you can learn how to unlock hidden Snapchat filters, too.


Read Full Article

GoPro launches Trade-Up program to swap old cameras for discounts


GoPro is willing to take that old digital camera stuffed in your junk drawer even if it’s a GoPro. Through a program called Trade-Up, the camera company will discount the GoPro H6 Black $50 and Fusion $100 when buyers trade in any digital camera. The company tried this last year for 60 days, but as of right now, GoPro is saying this offer does not expire.

This offer works with any digital camera including old GoPros. It clearly addresses something we noticed years ago — there’s often little reason to buy a new GoPro because their past products were so good.

GoPro tried this in 2017 for 60 days and says 12,000 customers took advantage of the program.

The service is reminiscent of what wireless carries do to encourage smartphone owners to buy new phones. It’s a clever solution though other options could net more money. Users could sell their camera on ebay or use other trade-in programs. Best Buy lets buyers trade in old cameras, too, and currently gives $60 for a GoPro Hero3+ Black and $55 for a HD Hero 960.

GoPro is in a tough position and this is clearly a plan to spur sales. The company’s stock is trading around an all-time low after a brief upswing following a report that Chinese electronic maker Xiaomi was considering buying the company. The company also recently started licensing its camera technology and trimmed its product line while introducing a new, $200 camera.

 


Read Full Article

5 Things You Have to Know About the Dangers of Ransomware


Ransomware is the single biggest risk to your digital security. Capable of encrypting your data and leaving you unable to access vital personal files and folders, ransomware can be very expensive whether you opt to pay the ransom or not.

But are you really up to speed with how dangerous it really is? Here are five things you should really know about ransomware.

1. Ransomware Is a Massive Security Threat on Mobile

You’re probably more focused on ransomware hitting your desktop or laptop computer than other devices, but you would be wrong. While ransomware is a big risk to PCs, it’s also a huge risk to smartphones and tablets.

One example is Fusob (Trojan-Ransom.AndroidOS.Fusob), which was particularly active in Germany in 2015. Masquerading as an adult video player, Fusob targeted fans of adult material who were already eager to part with their cash for paid online services.

It isn’t only mobile devices that are at risk, but the operating systems that run them. In recent years, Android has been adopted as the OS of choice for several smart TV manufacturers (and smart TVs are considerable security risks even without ransomware).

Frantic Locker (aka FLocker) started out targeting Android phones and tablets before being revised and re-released as a ransomware for smart TVs. Locking your TV screen (imagine that happening during a Game of Thrones finale) and displaying a message alleging you’ve committed a crime, complete with law enforcement iconography, FLocker demands payment of $200 in iTunes gift card credits.

2. Backups, Drives, and Databases Aren’t Immune

One of the earliest methods of avoiding potential ransomware attacks was to your data in a separate location. This might have been a daily backup stored on a different device, for instance. Unfortunately, ransomware coders have become wise to this defense, and backups can now be encrypted and locked until the ransom is paid.

But did you know that modern ransomware can also encrypt databases and unmapped disk drives? While the first risk (typically executed by the Cerber ransomware) is mainly troublesome for businesses that operate SQL databases (pretty much every database-driven desktop and web application), the latter is particularly disconcerting. In this situation, database processes are terminated before the data is encrypted.

CryptoFortress was the first ransomware to lock files regardless of whether they were associated with a particular drive letter (or not). Locky is another ransomware that can encrypt data on network drives. These risks also affect cloud storage, although some services (such as Dropbox) will restore your data to its state before the ransomware attack.

3. Ransomware Affects Windows, Mac, and Linux

Perhaps the most stunning thing about ransomware is its reach. We’ve already considered its ability to lock mobile devices, encrypting the contents until you pay up. But it can devastate your desktop data too, regardless of which operating system you’re running.

5 Things You Didn't Know about Ransomware

There’s the old mantra, isn’t there, that Macs can’t get viruses. We’ve seen increasingly over recent years that this is untrue, with the increase in Mac-targeted malware. Quite simply: If enough people are using a platform, hackers will work to subvert it. The same is true of Linux; while desktop distros have an overall small market share, Linux server operating systems run the majority of websites currently online.

So, you’re not safe just because you’re using Mac or Linux, no more than you would be if you were using Windows. Ransomware can catch you out whatever operating system you’re using.

4. Ransomware Always Poses as Legitimate Software

When ransomware first materialised, it was usually introduced onto computers via email attachments. Over the years, this approach has been streamlined and improved; while you can still end up with ransomware on your computer thanks to an email, there are now other methods.

It’s important to realise that if you are the victim of a ransomware attack, it’s not something to feel ashamed of. The developers of these insidious pieces of software go to great lengths to produce malware that looks utterly convincing and totally reliable. Ransomware is typically hidden in applications and games; they have to look like the real deal in order for you to install and use them!

Mobile games, fake Windows Updates, “useful” applications and utilities… all of these methods (and others) are used to deliver ransomware to your PC or mobile. You need to be certain that the software you install is legitimate.

How do you do that? Well, if you’re not installing from published media (such as a CD or DVD), the best thing you can do is ensure that you download apps and games direct from the publishers, or an approved digital delivery system.

5. Beware Petya’s Total Disk Encryption

One of the most notorious ransomware strains, Petya, was first discovered in 2016, managed to infect Windows machines via infected email attachments. Rather than focusing on specific personal files (such as those found in My Documents, for example), it attacks the Master Boot Record (MBR), encrypting the file system table of a computer’s hard disk drive.

Leaving you unable to access your PC’s data, your computer will simply boot to a screen telling you how to make a Bitcoin payment to regain control of your PC.

As with any ransomware attack, Petya will leave your data locked. Sometimes it can be tempting to just delete the locked data and move on with a backup; but if Petya has paid a visit, and the backup is stored on the same HDD, you’re stuck. Fortunately, Petya has been cracked, so it is possible to rescue your encrypted data without paying the ransom.

How to Prevent and Fight Against Ransomware

Protecting your data from ransomware is vital. It doesn’t matter if you’re using Windows, Mac, Linux, or a mobile device. All are at risk from ransomware. So what can you do?

There are five key steps you should follow:

  1. Make regular backups.
  2. Keep your operating system up to date.
  3. Keep an eye out for suspicious files.
  4. Use mail filtering.
  5. Subscribe to a full internet security suite.

Want to learn more? Our guide to defending yourself against ransomware provides further details. Several useful tools have been released for decrypting your data, and the list is always growing. Meanwhile, check our list of the best security and antivirus tools to find a solution that can protect your data from ransomware.


Read Full Article