Just two months ago, the #deletefacebook hashtag was trending all over the Internet due to the Cambridge Analytica scandal. Back then, it was revealed that Facebook had allowed third parties to scrape users’ personal data. Aleksandr Kogan, a University of Cambridge psychology professor, had obtained the data of about 87 million Facebook users, which was then used in the Trump election campaign, among others.
Since then, it has come to light that – besides Mr. Kogan – various other scholars have been harvesting information from Facebook accounts, capturing the behavior of millions of individuals.
For example, Swedish and Polish researchers were using a program called “scraper” that logged every comment and interaction from a selected number of Facebook pages for about two years.
“It is still not clear how the data of these millions of scraped profiles is being used,” said Marty P. Kamden, CMO of NordVPN. “As for Cambridge Analytica, at least we know where this data went –it was used to influence elections. How about all the other millions of profiles, collected by other scholars? We know that academic institutions do not always have experts in online security and data protection. Past experience shows that lots of this private information is stored on unsecure servers, and may be sold to marketers, stolen by hackers or handed over to political parties or consulting firms.”
The retained data may include people’s interests, preferences, geographical location, political profile and much more. The amount of collected data allows to match it with profiles and identify the actual people hiding behind anonymized profiles and to target them with specific messages, whether commercial or political. It can also end up in the wrong hands, allowing hackers to expose private information or to blackmail Facebook users.
NordVPN recommends following some simple rules that can help avoid being tracked on Facebook. It’s important not to use any third-party apps, such as quizzes, that require access to a user’s profile. It’s also advisable to revoke access to Facebook apps that are no longer in use or that offer users to get likes or followers.
Outside of Facebook, users should use ad blockers, regularly delete cookies and install anti-tracking browser extensions, such as Disconnect Private Browsing or Privacy Badger. Using a VPN is also crucial – it helps to browse the Internet privately and encrypts the data between a user’s device and the VPN server.


Cell Phone Tracking Firm Exposed Millions Of Americans’ Real-time Locations
Posted in Commentary with tags Privacy on May 18, 2018 by itnerdYou’ve likely never heard of a company called LocationSmart. But I will let security researcher Brian Krebs tell you why you should care:
On May 10, The New York Times broke the news that a different cell phone location tracking company called Securus Technologies had been selling or giving away location data on customers of virtually any major mobile network provider to a sheriff’s office in Mississippi County, Mo.
On May 15, ZDnet.com ran a piece saying that Securus was getting its data through an intermediary — Carlsbad, CA-based LocationSmart.
Wednesday afternoon Motherboard published another bombshell: A hacker had broken into the servers of Securus and stolen 2,800 usernames, email addresses, phone numbers and hashed passwords of authorized Securus users. Most of the stolen credentials reportedly belonged to law enforcement officers across the country — stretching from 2011 up to this year.
None of that is good. But it actually gets worse. Apparently the LocationSmart website had a bug in its website that allowed anyone to see where a person is located without obtaining their consent:
LocationSmart’s demo is a free service that allows anyone to see the approximate location of their own mobile phone, just by entering their name, email address and phone number into a form on the site. LocationSmart then texts the phone number supplied by the user and requests permission to ping that device’s nearest cellular network tower.
Once that consent is obtained, LocationSmart texts the subscriber their approximate longitude and latitude, plotting the coordinates on a Google Street View map. [It also potentially collects and stores a great deal of technical data about your mobile device. For example, according to their privacy policy that information “may include, but is not limited to, device latitude/longitude, accuracy, heading, speed, and altitude, cell tower, Wi-Fi access point, or IP address information”].
But according to Xiao, a PhD candidate at CMU’s Human-Computer Interaction Institute, this same service failed to perform basic checks to prevent anonymous and unauthorized queries. Translation: Anyone with a modicum of knowledge about how Web sites work could abuse the LocationSmart demo site to figure out how to conduct mobile number location lookups at will, all without ever having to supply a password or other credentials.
“I stumbled upon this almost by accident, and it wasn’t terribly hard to do,” Xiao said. “This is something anyone could discover with minimal effort. And the gist of it is I can track most peoples’ cell phone without their consent.”
Well, that’s very disturbing. This demo software was promptly taken offline when the story broke. But there’s a larger issue here. Which is the security of your data and what you should expect in terms of privacy. A US senator is poking around the edges of this, but this requires a more stringent response. As in the four telcos and all of the companies above need to come in front of congress to answer some tough questions about this.
1 Comment »