Archive for Privacy

A Marketing Company Claims That It Can Listen In On Your Conversation Through Your Devices

Posted in Commentary with tags on December 15, 2023 by itnerd

To be clear, I am not the least bit surprised that this could be possible. Though part of me is still a bit stunned at this story as it is an insane privacy breach if this is true. And what I am talking about is a company called Cox Media Group who claims that it can eavesdrop on your conversations, through microphones in smartphones, TVs, and smart speakers. This comes via 404 Media:

A marketing team within media giant Cox Media Group (CMG) claims it has the capability to listen to ambient conversations of consumers through embedded microphones in smartphones, smart TVs, and other devices to gather data and use it to target ads, according to a review of CMG marketing materials by 404 Media and details from a pitch given to an outside marketing professional. Called “Active Listening,” CMG claims the capability can identify potential customers “based on casual conversations in real time.”

The news signals that what a huge swath of the public has believed for years—that smartphones are listening to people in order to deliver ads—may finally be a reality in certain situations. Until now, there was no evidence that such a capability actually existed, but its myth permeated due to how sophisticated other ad tracking methods have become.

It is not immediately clear if the capability CMG is advertising and claims works is being used on devices in the market today, but the company notes it is “a marketing technique fit for the future. Available today.” 404 Media also found a representative of the company on LinkedIn explicitly asking interested parties to contact them about the product. One marketing professional pitched by CMG on the tech said a CMG representative explained the prices of the service to them. 

“What would it mean for your business if you could target potential clients who are actively discussing their need for your services in their day-to-day conversations? No, it’s not a Black Mirror episode—it’s Voice Data, and CMG has the capabilities to use it to your business advantage,” CMG’s website reads.

And:

With Active Listening, CMG claims to be able to “target your advertising to the EXACT people you are looking for,” according to its website. The goal is to target potential clients or customers based on what they say in “their day to day conversations,” the website adds.

Reading this story sent chills down my spine. Now in my case, my household is part of Team Apple. Which means the four HomePod mini’s as well as the three iPhones along with two Apple Watches that my wife and I collectively own are covered by this policy which fully lays out what data Apple collects and why along with what data they may keep and where that data goes. That made me a feel bit better. The only other device in my home that has any form of voice interface is this TCL TV which is powered by the Roku operating system. They have this privacy policy which states the following:

If you link your Roku Device to a non-Roku voice-enabled virtual assistant (e.g., Alexa and Google Assistant), you are choosing to have us disclose device data to the voice assistant provider, such as device type and name, device identifiers, its state (e.g., whether the device is powered on, whether the device is playing video), names of installed streaming service apps, and the names of your device HDMI ports. If you direct such virtual assistant to display content, we will also disclose the content to such voice provider to carry out your request.  For information about how these providers use this data, please review their privacy policies. 

I have the TV linked to Apple HomeKit. Which means that it is covered by Apple’s privacy policy. And I do have a Roku voice remote that requires me to press a button to do anything. So it’s not actively listening into anything I am doing. So I am fine there as well. Now why am I telling you all of this? Well, depending on what smart devices you have in your home, you might be fine, our you might have an issue:

CMG lists a number of other companies as its partners and publishers. These include Amazon, Microsoft, and Google. None of those companies responded to a request for comment on whether they were aware of this capability or whether it was in active use.

I would assume that if you have any Google, Amazon or Microsoft devices, then you likely have a problem. I say that because the first two are exactly the type of companies who would do anything to gather as much data on you as possible to monetize it in any way possible. The jury is still out on Microsoft. But let us assume that they are in the Google or Amazon camp for now until they prove themselves to be different.

I will be interested to see how CMG and their clients respond to this story now that this is out there. Because I think it is safe to say that this story is going to get a lot of attention. Including from regulators which I am sure that CMG and their clients do not want. Thus if they don’t respond to this with some talking points to try and defuse this, they may have bigger problems on their hands.

Governments Spy On Users Using Push Notifications

Posted in Commentary with tags , , on December 7, 2023 by itnerd

From the “I didn’t see this one coming” department comes the revelation that governments have been using push notifications to spy on people for some time. This came to light when Oregon Senator Ron Wyden wrote in a letter to the Department of Justice on December 6 asking the Justice Department to lift restrictions in terms of informing the public of this practise:

Because Apple and Google deliver push notification data, they can be secretly compelled by governments to hand over this information

So why should you care? A government could force Apple or Google to hand over data related to push notifications to show how you interact with your phone and the apps on it, as well as give them access to a notification’s complete text and disclose some unencrypted content. All of which is bad of course.

Apple said in a statement published by Reuters the following:

Now that this method has become public, we are updating our transparency reporting to detail these kinds of requests.

True to their word, Apple has now updated its Legal Process Guidelines document to reflect this new reality. Google for its part said this:

Google said that it shared Wyden’s “commitment to keeping users informed about these requests.”

But beyond that, I haven’t seen Google update anything. And the thing is that beyond the US who clearly has been using push notifications to spy on people, it isn’t clear who else is doing it. And it is likely that we won’t get a straight answer on that. Thus it might be wise for Apple and Google to rework how push notifications work so that this sort of spying isn’t a possibility.

Google Is Now Tracking Your Every Move Online To Make Money

Posted in Commentary with tags , on September 10, 2023 by itnerd

Earlier this week, I posted this story about Google’s new Privacy Sandbox feature. But there’a dark side to this announcement that ARS Technica is highlighting:

Don’t let Chrome’s big redesign distract you from the fact that Chrome’s invasive new ad platform, ridiculously branded the “Privacy Sandbox,” is also getting a widespread rollout in Chrome today. If you haven’t been following this, this feature will track the web pages you visit and generate a list of advertising topics that it will share with web pages whenever they ask, and it’s built directly into the Chrome browser. It’s been in the news previously as “FLoC” and then the “Topics API,” and despite widespread opposition from just about every non-advertiser in the world, Google owns Chrome and is one of the world’s biggest advertising companies, so this is being railroaded into the production builds.

Google seemingly knows this won’t be popular. Unlike the glitzy front-page Google blog post that the redesign got, the big ad platform launch announcement is tucked away on the privacysandbox.com page. The blog post says the ad platform is hitting “general availability” today, meaning it has rolled out to most Chrome users. This has been a long time coming, with the APIs rolling out about a month ago and a million incremental steps in the beta and dev builds, but now the deed is finally done.

Well, I don’t use Google Chrome as my main web browser. But this is a few steps too far. And not only won’t I be using Chrome on any of my computers, but I will encourage others not to use Chrome as well. The other thing that this does is make my trust level with Google as a company drop to zero.

If you’re looking for alternatives, Firefox and Safari on the Mac would be my choices. Neither of those browsers have shown blatant disregard for their user base that Google Chrome has.

Wyze Seems To Have A Privacy Issue Related To Their Cameras

Posted in Commentary with tags , on September 9, 2023 by itnerd

A reader tipped me off to this Reddit thread where Wyze has had some sort of issue has broadcasted private camera streams randomly to others. That’s one hell of a privacy issue. But not the company’s first one. I wrote about another privacy issue with Wyze back in 2019. Thus I am not shocked by this. The Verge confirms that this was happening on Friday along with additional Reddit threads illustrating that this issue was widely seen by uses, and they also report the following:

After we published this story, Wyze spokesperson Dave Crosby shared a statement explaining what happened. Although Crosby says the issue is resolved and that view.wyze.com is “back up and running,” the status page still says view.wyze.com is under maintenance as of Saturday morning. (Crosby says the company will update the status page “shortly.”)

Here is Crosby’s statement:

This was a web caching issue and is now resolved. For about 30 minutes this afternoon, a small number of users who used a web browser to log in to their camera on view.wyze.com may have seen cameras of other users who also may have logged in through view.wyze.com during that time frame. The issue DID NOT affect the Wyze app or users that did not log in to view.wyze.com during that time period.

Once we identified the issue we shut down view.wyze.com for about an hour to investigate and fix the issue.

This experience does not reflect our commitment to users or the investments we’ve made over the last few years to enhance security. We are continuing to investigate this issue and will make efforts to ensure it doesn’t happen again. We’re also working to identify affected users.

That’s nice. But again, I’ll point out that this is not the first time that Wyze has run into a privacy issue. Besides what I mentioned above, there was this:

In March 2022, Wyze revealed that it had been aware of a security vulnerability for three years that could have let bad actors access WyzeCam v1 cameras, but quietly discontinued the camera rather than telling customers about it.

My take home message is that nobody should buy Wyze cameras. They may be cheap on Amazon. But they’re clearly insecure and the company cannot be trusted.

Cars Are Rolling Privacy Nightmares Says Mozilla As They Collect All Your Data… Including Data About Your Sex Life

Posted in Commentary with tags on September 7, 2023 by itnerd

Internet connected cars are all the rage at the moment. And I for one will not be buying one and I will be hanging on to my Internet disconnected car for as long as I can do so. The reason being is according to a study done by Mozilla, cars collect all sorts of data about you and sends it back to the manufacturer. And the kind of data that is collected is shocking:

We reviewed 25 car brands in our research and we handed out 25 “dings” for how those companies collect and use data and personal information. That’s right: every car brand we looked at collects more personal data than necessary and uses that information for a reason other than to operate your vehicle and manage their relationship with you. For context, 63% of the mental health apps (another product category that stinks at privacy) we reviewed this year received this “ding.”

And car companies have so many more data-collecting opportunities than other products and apps we use — more than even smart devices in our homes or the cell phones we take wherever we go. They can collect personal information from how you interact with your car, the connected services you use in your car, the car’s app (which provides a gateway to information on your phone), and can gather even more information about you from third party sources like Sirius XM or Google Maps. It’s a mess. The ways that car companies collect and share your data are so vast and complicated that we wrote an entire piece on how that works. The gist is: they can collect super intimate information about you — from your medical information, your genetic information, to your “sex life” (seriously), to how fast you drive, where you drive, and what songs you play in your car — in huge quantities. They then use it to invent more data about you through “inferences” about things like your intelligence, abilities, and interests.

The car companies then sell this data, as it’s a revenue source for them. And opting out of this data collection isn’t an option for the most part. Consent is an illusion as simply stepping into a car with this sort of tech qualifies as consent. And finally, all car companies do this.

This to me is not cool and I hope that consumers file complaints with the relevant government agencies (In Canada that’s the Privacy Commissioner) so that all of these car companies are forced to explain why they do this which may make them reconsider if they should be doing this at all.

Teamsters Accuse CN Rail Of Secretly Tracking Their Employees Movements Via Company Issued Tablets

Posted in Commentary with tags , on August 24, 2023 by itnerd

This is one of those topics that I always thought would come up more often. CTV News is reporting that the Teamsters union is accusing CN Rail of tracking employees movements, even after hours via the tablets that CN Rail issues their employees and not disclosing that they were doing so:

The Teamsters Canada Rail Conference, which is the union that represents 5,500 Canadian National railway employees, alleges CN has been monitoring the whereabouts of a train operator outside of work hours through a company-issued tablet.

“It’s spying, it’s wrong and it’s illegal in our view” according to Teamsters Canada’s director of public affairs Christopher Monette, who adds “on top of it being creepy, it’s downright dystopian. It’s something that shouldn’t be happening.” 

The union says they have reason to be concerned that a large number of CN Rail employees may have also had their location tracked by the company during their own personal time after work.Speaking to CTV National News, Monette says that CN “didn’t tell us this was going on and they didn’t seek consent from workers to use geolocation data” from their company issued devices and believes CN was trying to keep their tracking methods secret.

“We only found out about this by accident, through a disclosure process where the company was forced to disclose why they were disciplining a worker,” according to Monette.

Now CN Rail doesn’t want to comment on this. But frankly I am not surprised. Tablets and phones issued by companies are often what are called “managed” devices. Meaning that the devices are put into a type of software called Mobile Device Management software or MDM for short. This software allows a company to do a number of things. Get the status of the device, push out software updates, remote control the device for troubleshooting purposes, and most relevant to this story, track the device. Now a company may only decide to use this software to track a device if it is stolen. But I can see a scenario where a company may use this software to track a device at all times. Which if they disclose that up front, I guess that’s fine. But if they didn’t you get this situation.

Now if you have a company issued device and are afraid of being tracked, there are very low tech solutions to this:

Cyber security analyst and lawyer Ritesh Kotak believes employees who have a work phone, tablet or laptop should try and purchase their own personal devices to use off work hours.

“These high-tech problems have really low-tech solutions,” Kotak says.

He also says that he uses a tab to cover the camera on his work computer when he’s not on a video call. Kotak adds that, if possible, employees should turn their work devices onto airplane mode off work hours.

“It’s important to understand that information (from your devices) is being collected on a continuous basis by the employer, it’s probably being stored and there maybe third parties who have access to it.”

One thing to consider is that if you go this route, your company may complain at some point because the device isn’t on all the time. Another thing to consider is if you “BYOD” or bring your own device, and the company puts their MDM software on it, you could be in the same situation. So you may want to keep that in mind as well.

The bottom line is that if you use company property, or simply have their software installed on your own smartphone or computer, you should have no expectation of privacy. Ever. Unfortunate, but true.

The Police Service of Northern Ireland Data Leak Just Got Worse Than It Already Is

Posted in Commentary with tags on August 14, 2023 by itnerd

Last week I told you about a data leak involving The Police Service of Northern Ireland where they accidentally published the data on all their staff creating a critical incident in the process. As bad as that is, it just got worse. Here’s the details from Sky News:

The Police Service of Northern Ireland (PSNI) says it fears its officers could be targeted and intimidated after saying it believes that dissident republicans have data on staff that was accidently leaked by the force last week.

“We are now confident that the workforce dataset is in the hands of dissident republicans,” Chief Constable Simon Byrne said.

“It is therefore a planning assumption that they will use this list to generate fear and uncertainty as well as intimidating or targeting officers and staff.”

And:

Earlier, a redacted version of the leaked document that listed the names of police officers in Northern Ireland was posted on a wall facing a Sinn Fein office in Belfast.

Keep in mind that the peace in Northern Ireland is a recent thing because of the Good Friday accords. Thus this data leak doesn’t exactly help this situation which has not been in a good place for a couple of years now. This this situation illustrates that data breaches don’t just have a financial and repetitional impact, they also have a life threatening impact as is illustrated here.

The Police Service of Northern Ireland REALLY Screws Up And Publishes The Data Of ALL ITS STAFF

Posted in Commentary with tags on August 9, 2023 by itnerd

The good news is that The Police Service Of Northern Ireland didn’t get pwned by hackers. But the bad news is they might as well have been. I say that because they really screwed up and accidentally published the data on all their staff creating a critical incident in the process:

The Police Service of Northern Ireland (PSNI) earlier apologised for the self-inflicted security breach after it inadvertently published the information in response to a Freedom of Information (FOI) request on Tuesday.

The breach involved the surname, initials, the rank or grade, the work location and departments of all PSNI staff, but did not involve the officers’ and civilians’ private addresses.

Alliance Party leader Naomi Long said it was a concern that a member of staff, who she understands to be “relatively junior”, had access to the sensitive data.

PSNI said its chief constable Simon Byrne is cutting his family holiday short to deal with the crisis and is expected to answer questions from politicians.

This is bad. This is very bad. Why is this bad? Here’s why:

The information, which was available online for up to three hours, revealed members of the organised crime unit, intelligence officers stationed at ports and airports, officers in the surveillance unit and almost 40 PSNI staff based at MI5’s headquarters in Holywood, the Belfast Telegraph reported.

Clearly there was no process in place to limit who has access to this data. Nor were there any checks to make sure that the data was safe to release. This is another one of those cases where heads need to roll over this because I cannot imagine what the members of this police service are going through knowing that some of their personal information is out there right now.

#EpicFail

Guest Post: Online Identity & Privacy Protection Tips For Children

Posted in Commentary with tags on August 9, 2023 by itnerd

By Ani Chaudhuri, CEO, Dasera

Beyond the usual guidelines, there are several innovative and layered approaches that parents might not have considered:

  • Digital Footprint Starts at Birth: Avoid sharing identifiable information about your child on public platforms. This includes full names, birth dates, and locations. A harmless birth announcement can offer malicious actors a starting point.
  • Rethink “Smart” Toys: Before purchasing, scrutinize the data handling practices of internet-connected toys. Many collect vast amounts of information, and not all have stringent security measures.
  • Understand School Data Handling: Engage with your child’s school to understand how they store, use, and protect student data. Often, educational platforms have data vulnerabilities or share information with third parties.
  • Voice-Activated Devices: Devices like Siri or Alexa constantly listen for activation cues. Ensure they aren’t inadvertently recording your child’s conversations or information.
  • Online Gaming: Even games designed for younger children can have chat features. Ensure these are disabled or monitored. Personal information can be unintentionally shared during seemingly innocent in-game conversations.

From the moment they are born. It may sound extreme, but children have a digital identity almost from birth in our current digital era. Whether it’s hospital records, pediatrician visits, or the first photo shared on social media, their digital footprint begins immediately. Each of these instances carries data – a golden ticket for identity thieves. Protecting a child’s ID isn’t just about preventing financial fraud; it’s about safeguarding their entire digital existence and future reputation.

Child ID and privacy isn’t just about what parents should do; it’s equally about the don’ts and nevers:

  • Never Use Their Name for Passwords: Using a child’s name or birthdate as a password for any online service is a glaring risk. It’s often the first thing hackers will try.
  • Don’t Overlook Data Breaches: Not all data breaches make headlines. Watch for breaches involving services your child uses and act accordingly.
  • Never Assume a Platform is Safe: Just because a platform is designed for children doesn’t mean it’s secure. Constantly scrutinize its data practices.
  • Don’t Underestimate Word of Mouth: Children learn much from their peers. Educate them about the basics of data privacy so they can be advocates among their friends.

Protecting a child’s ID and privacy in today’s world requires vigilance, continuous education, and proactive measures. It’s not just about today’s threats but also about preventing potential risks in the future. Parents must be the first line of defense, even if it means challenging the status quo of digital interaction.

India’s Digital Personal Data Protection Bill Moves Through Parliament

Posted in Commentary with tags , on August 8, 2023 by itnerd

India’s Digital Personal Data Protection Bill of 2023 passed in the lower house of Parliament and will now face the higher house before it becomes law. Highlights of the bill include:

  • The Bill will apply to the processing of digital personal data within India where such data is collected online, or collected offline and is digitised.  It will also apply to such processing outside India, if it is for offering goods or services in India.
  • Personal data may be processed only for a lawful purpose upon consent of an individual.  Consent may not be required for specified legitimate uses such as voluntary sharing of data by the individual or processing by the State for permits, licenses, benefits, and services.
  • Data fiduciaries will be obligated to maintain the accuracy of data, keep data secure, and delete data once its purpose has been met.
  • The Bill grants certain rights to individuals including the right to obtain information, seek correction and erasure, and grievance redressal.
  • The central government may exempt government agencies from the application of provisions of the Bill in the interest of specified grounds such as security of the state, public order, and prevention of offences.
  • The central government will establish the Data Protection Board of India to adjudicate on non-compliance with the provisions of the Bill.

But all of this does concern me:

  • Exemptions to data processing by the State on groundssuch as national security may lead to data collection, processing, and retention beyond what is necessary.  This may violate the fundamental right to privacy.
  • The Bill does not regulate risks of harms arising from processing of personal data.  
  • The Bill does not grant the right to data portability and the right to be forgotten to the data principal.
  • The Bill allows transfer of personal data outside India, except to countries notified by the central government.  This mechanism may not ensure adequate evaluation of data protection standards in the countries where transfer of personal data is allowed.

Ani Chaudhuri, CEO, Dasera had this comment:

In today’s hyper-connected world, data is businesses, governments, and individuals lifeblood. The Digital Personal Data Protection Bill, 2023, tabled by the Indian Parliament, promises to reshape India’s digital ecosystem fundamentally. However, some provisions raise eyebrows, and some sigh relief. As the CEO of a leading data security and governance firm, here’s my perspective:

1. Applicability and Scope: The Bill’s clarity on what constitutes digital and non-digital data is commendable. This distinction is pertinent in our digital transformation era, where data can easily traverse between these forms. However, the territorial applicability might leave room for data misuse if foreign entities do not offer goods or services but still process Indian data.

2. Consent: The Bill strengthens the individual’s position as the custodian of their data. The stipulation around explicit affirmative action for consent is a commendable step forward. However, the reliance on “consent managers” might introduce new business complexities.

3. Grounds of Processing: The shift from ‘deemed consent’ to ‘legitimate uses’ presents challenges and opportunities. While it offers clarity, it significantly burdens businesses to rethink their data collection and processing strategies.

4. Data Fiduciaries: The onus on data fiduciaries to ensure compliance even when they outsource the processing is a welcome move. This will ensure a chain of responsibility and enforce better data practices.

5. Cross-border Transfers: A “negative list” approach, while seemingly liberal, might lead to complications if the principles on which countries are barred aren’t transparently laid out.

6. Blocking Power: A potentially controversial move. Any power to block public access must be exercised with utmost caution, ensuring it does not stifle freedom of expression or business continuity.

7. Exemptions: A double-edged sword. While exemptions might be necessary for state functionality, they shouldn’t become a backdoor to bypass the very essence of the bill.

8. Penalties: Reducing the maximum penalty suggests a softer stance on non-compliance. Whether this is conducive to robust data protection or simply a concession to businesses is up for debate.

Overall, the 2023 Bill is a thoughtful attempt to balance protecting individual rights and fostering business growth. However, the concerns around compliance costs, especially for startups, are genuine. Without ‘deemed consent’ will undoubtedly introduce more rigidity into the system. While data protection is of utmost importance, we must ensure that we do not inadvertently stifle innovation and business growth.

Although lacking specific timelines, the phased approach to implementation gives businesses a window to adapt. However, startups may bear the brunt, given the high compliance costs. The bill in its current form appears to swing the pendulum more towards protection and less towards ease of doing business.”

While the Bill addresses several data protection concerns, it remains to be seen how its implementation will affect the digital landscape in India. What’s imperative is a continuous dialogue between stakeholders to ensure the Bill serves its purpose without stifling the Indian digital ecosystem.

I am very suspicious of this bill personally because of the privacy related concerns that I highlighted earlier, among other concerns. But there are things that could be considered “good” in this bill that I will see how it is implemented and what the effects of that implementation are before passing judgement on it.