Archive for Privacy

Hundreds Of Thousands Of People Affected Due To Last Year’s COVID Booking System Data Breach

Posted in Commentary with tags on December 10, 2022 by itnerd

You might recall that there was a text message scam from last year where people who booked a COVID vaccine were getting text messages asking for all sorts of personal information. It didn’t take long for two people to get charged with being behind this scheme. And one person who was arrested was an insider as they worked for the vaccine contact centre which is part of the Ontario Ministry of Government and Consumer Services. Once again proving that your organization’s biggest threat vector is your people. Well, the damage has been tallied and it’s not good. The breach resulted in the names and phone numbers of about 360,000 people being leaked. CBC has details:

Beginning Friday, some 360,000 people will receive notices that their personal information was part of the November 2021 data breach of the COVAXX system, the Ministry of Public and Business Service Delivery said in a statement Friday. 

The ministry said it had been working with the Ministry of Health, police and the Ontario’s privacy commissioner to determine the scale and impact of the breach. The ministry’s statement does not say how it occurred.

I for one would be very interested in what lessons the Ontario government learned so that this doesn’t happen again. Because 360,000 is not a small number of people to be affected by something like this. And I think that all Ontario citizens would be very interested in this information as well. People have to have trust that their information is going to be protected. And given the scale of this breach, I would be wondering if the Ontario government has the right people, tools, and controls in place to stop this from happening again.

Eufy Releases An App Update That Won’t Make Their Issues Go Away

Posted in Commentary with tags , on December 6, 2022 by itnerd

Over the weekend I posted a story about Eufy and the fact that they have lied about the security that their had for years. And that my belief is that they should be banned from sale because this isn’t the first time that this has happened. Part of my belief that they should be banned comes from the fact that I don’t believe that Eufy is serious about gaining the trust of their users. This is being reinforced by the news that Eufy isn’t patching out a potential security issue in the Eufy Security app. Instead Eufy is just telling users that their thumbnails will be uploaded to the cloud when they choose specific notification settings in the app;

As of Monday, an update has been rolled out to the Eufy Security app to add a statement disclosing that thumbnail images will be uploaded to the company’s cloud servers. 

For you to get notifications with thumbnails in them from a security camera, a thumbnail has to be uploaded someplace. That’s true for any camera system. And part of the problem is that Eufy sells these cameras with the expectation that they are completely private. Which clearly they are not. Now that Eufy has clarified this, I am guessing that they hope that this issue will go away. But it won’t because this doesn’t do anything about the ability for a threat actor to stream video. Eufy hasn’t commented on this as far as I know. And there’s no sign that they will do anything about it.

Thus if Eufy was hoping to make this issue go away, I don’t think that this will do it.

Eufy Needs To Be Banned Because They Can’t Be Trusted

Posted in Commentary with tags , on December 3, 2022 by itnerd

This week it came to light that Eufy has been lying about the security of their cameras. That’s not a surprise to me as when I reviewed their cameras last year, they were dealing with similar issue where users could see other people’s cameras without any effort. The issue was corrected quickly. But it wasn’t the first time something like this has happened.

Now in case you didn’t want to read any of that, here’s the TL:DR (too long, didn’t read) on this: Eufy’s cameras aren’t as secure as they have claimed for years. Threat actors with the right information can watch video from your Eufy camera. If that’s not bad enough, Eufy also uploads some data to the cloud that customers were previously unaware of. Now the company has issued an apology and has updated its product language in the Eufy app to better clarify which settings will trigger a cloud upload. Though, in a bizarre twist, Eufy issued a second statement on December 2 that from a PR and customer confidence standpoint sucks:

“eufy Security adamantly disagrees with the accusations levied against the company concerning the security of our products. However, we understand that the recent events may have caused concern for some users. We frequently review and test our security features and encourage feedback from the broader security industry to ensure we address all credible security vulnerabilities. If a credible vulnerability is identified, we take the necessary actions to correct it. In addition, we comply with all appropriate regulatory bodies in the markets where our products are sold. Finally, we encourage users to contact our dedicated customer support team with questions.”

Now where I sit, I can’t say if Eufy is just lazy when it comes to security, or if they are trying to do something nefarious. But seeing as they are a Chinese company, issues like these have to be treated with some degree of extra suspicion. And seeing as this has happened more than once, I think we’re at a point where retailers should not only stop selling their gear, but I would argue that governments should ban this company from being able to sell their gear. Just like Huawei has been banned from many telcom networks.

Eufy keeps saying that that they will do better going forward. But we’re not seeing evidence of that seeing as this keeps happening. At this point I am through giving them chances. And so should governments around the world because there is no way that this sort of behavior by Eufy should be tolerated. A ban will send the message to Eufy and others that they need to talk the talk and walk the walk when it comes to security. Plus if Eufy or others really want to have the confidence of consumers, they need to have their claims validated by a third party. But I suspect that Eufy won’t subject themselves to that level of scrutiny. Thus they need to be banned. And the sooner the better.

Now if you ask me what you should do if you have an Eufy camera? My advice would be to rip them out because your privacy and security is invaluable. That is true for both indoor cameras and outdoor ones too. I would even go as far as to say that you shouldn’t even resell them as you’re just passing along a major problem to someone else which is not fair on that person. My advice is to recycle them at your local electronics recycling facility and take these security and privacy nightmares out of circulation forever.

Finally, if Eufy is reading this, I have to say that you’ve created this mess and it’s way too late for you to say sorry for it. Consumers put a lot of trust in the vendors of this sort of gear and you’ve burned through that trust. And since you can’t fix your issues, hopefully governments around the world will fix it for you by banning you out of existence.

Game over Eufy.

Major Web Browsers Drop Sketchy Certificate Authority

Posted in Commentary with tags , on December 2, 2022 by itnerd

Here is something that got my attention. All the major web browsers, meaning Firefox, Chrome, and Edge, have decided to drop a certificate authority that has ties to a US military contractor.

Mozilla’s Firefox and Microsoft’s Edge said they would stop trusting new certificates from TrustCor Systems that vouched for the legitimacy of sites reached by their users, capping weeks of online arguments among their technology experts, outside researchers and TrustCor, which said it had no ongoing ties of concern. Other tech companies are expected to follow suit.

“Certificate Authorities have highly trusted roles in the internet ecosystem and it is unacceptable for a CA to be closely tied, through ownership and operation, to a company engaged in the distribution of malware,” Mozilla’s Kathleen Wilson wrote to a mailing list for browser security experts. “Trustcor’s responses via their Vice President of CA operations further substantiates the factual basis for Mozilla’s concerns.”

The Post reported on Nov. 8 that TrustCor’s Panamanian registration records showed the same slate of officers, agents and partners as a spyware-maker identified this year as an affiliate of Arizona-based Packet Forensics, which has sold communication interception services to U.S. government agencies for more than a decade. One of those contracts listed the “place of performance” as Fort Meade, Md., the home of the National Security Agency and the Pentagon’s Cyber Command.

That would qualify as sketchy as this company makes software that should ring alarm bells. Pratik Selva, Lead Security Engineer at Venafi added this:

When considering security, one of the areas that is still not given due focus by many organizations is Certificate Authorities (CAs). CAs are / should be a key component in any corporate security strategy as they are machine identity enablers. A root CA is the most significant piece in that hierarchy as it holds the potential to impact the security and the trust of the entire certification hierarchy due to any abuse or compromise. This view needs to be factored in when organizations conduct threat modeling or assessments.  

Additionally, there can be also compliance implications if there are weak or non-existent checks and balances in place for ensuring the security of a CA. What is more alarming is that CA compromise has been found to be achieved using living-off-the-land (LOTL) techniques and tools. LOTL attacks are problematic from a detection standpoint and are an incident response (IR) nightmare. As root CAs pose a cascading risk, they have been a favorable target of nation state APT actors aiming to mount a crippling attack.”

My advice would be to make sure your browsers are up to date as that is how the removal of this certificate authority would take place. But this also underscores that you need to be on your toes when it comes to security and privacy.

Cars Can Be Pwned Via Flaws In SiriusXM And Other Software: Report

Posted in Commentary with tags , on December 1, 2022 by itnerd

Every car these days comes with a SiriusXM receiver. And depending on what car you have, that might be an attack vector for hackers to pwn your car. This according to this article:

Researcher Sam Curry on Wednesday described a recent car hacking project targeting Sirius XM, which he and his team learned about when looking for a telematic solution shared by multiple car brands.

An analysis led to the discovery of a domain used when enrolling vehicles in the Sirius XM remote management functionality, Curry said in a Twitter thread.

Initial tests were conducted on the NissanConnect mobile application, which led to the discovery of a vulnerability that could allow a remote hacker to obtain a vehicle owner’s name, phone, number, address and car details simply by knowing their VIN, which is typically visible on the windshield. The attacker would need to send specially crafted HTTP requests containing the victim’s VIN in a certain parameter.

Further analysis showed that the same vulnerability could be exploited to run vehicle commands, including locate, unlock and start a car, as well as to flash headlights and honk the horn.

The researchers determined that such an attack could be launched against Honda, Nissan, Infiniti, and Acura cars.

Sirius XM immediately patched the vulnerability after being informed of its existence. The company said it released a patch within 24 hours and noted that it has no evidence of any data getting compromised or unauthorized modifications being made.

That’s not good. But neither is this

In a separate Twitter thread this week, Curry reported a different vulnerability, one that allowed researchers to control some functions of Hyundai and Genesis vehicles — including locks, engine, horn, headlights and trunk — by knowing the email address the victim had used to register a user account.

The attack allegedly worked on vehicles made after 2012. Hyundai and Genesis also released patches after being notified.

So upon reading this article, I looked at the research and it illustrates that connected cars are subject to the same sort of problems that everything else is. Thus car companies and SiriusXM need to up their game to keep car owners safe. And they need to be held accountable for making sure that cars are secure. Preferably by a third party.

Apps Related To The World Cup Violate Your Privacy

Posted in Commentary with tags on November 20, 2022 by itnerd

At the moment the World Cup is just full of controversy due to the human rights record of Qatar. And this news from Politico won’t help with that. EU officials are warning that visitors should not download the official World Cup apps due to the fact that they are privacy nightmares:

European data protection regulators have been lining up to warn about the risks posed by Qatar’s World Cup apps for visitors, with Germany’s data protection commissioner being the latest. In a statement Tuesday, the Germans said data collected by two Qatari apps that visitors are being asked to download “goes much further” than the apps’ privacy notices indicate. 

“One of the apps collects data on whether and with which number a telephone call is made,” the German authority said. “The other app actively prevents the device on which it is installed from going into sleep mode. It is also obvious that the data used by the apps not only remain locally on the device, but are also transmitted to a central server.”

The Norwegian and French data protection agencies have already issued similar advice. 

The Norwegian regulator on Monday said it was “alarmed” by the extensive access the apps require. “There is a real possibility that visitors to Qatar, and especially vulnerable groups, will be monitored by the Qatari authorities,” it said. 

The French agency said fans should take “special care” with photos and videos, and recommends that travelers install the apps just before departure and delete them as soon as they return to France.

The French government — despite having close ties to Qatar — echoed the CNIL’s advice on Tuesday. “In France, thanks to the [General Data Protection Regulation], all applications must guarantee the fundamental rights of individuals and the protection of their data. This is not the case in Qatar,” tweeted Junior Minister for Digital Jean-Noël Barrot, referencing the privacy regulator’s guidelines.

Here’s the problem. Visitors have been asked by Qatar to download and install these apps. Thus this really makes Qatar look bad. And on top of that, Apple and Google are the ones serving up these apps. Did this just slip through or did they know about the issues with these apps and they simply looked the other way? I for one would love to know the answer to that question as it makes me question their app review processes.

In any case, it takes an event that really has bad vibes all around it, and amps that up to 11.

US Army Among Others Uses Code From Russian Company That’s Pretending To Be An American Company In Their Apps

Posted in Commentary with tags on November 14, 2022 by itnerd

When people create apps, it’s not at all unusual for the developer to use code from someone else. After all, why reinvent the wheel if someone has done the hard work for you?

Well, maybe that practice should be rethought. I say that because it now turns out a Russian company who were pretending to be an American company has had its code show up in thousands of apps. Including an app used by the US Army. Reuters has the details:

Thousands of smartphone applications in Apple and Google’s online stores contain computer code developed by a technology company, Pushwoosh, that presents itself as based in the United States, but is actually Russian, Reuters has found.

The Centers for Disease Control and Prevention (CDC), the United States’ main agency for fighting major health threats, said it had been deceived into believing Pushwoosh was based in the U.S. capital. After learning about its Russian roots from Reuters, it removed Pushwoosh software from seven public-facing apps, citing security concerns.

The U.S. Army said it had removed an app containing Pushwoosh code in March because of the same concerns. That app was used by soldiers at one of the country’s main combat training bases.

According to company documents publicly filed in Russia and reviewed by Reuters, Pushwoosh is headquartered in the Siberian town of Novosibirsk, where it is registered as a software company that also carries out data processing. It employs around 40 people and reported revenue of 143,270,000 rubles ($2.4 mln) last year. Pushwoosh is registered with the Russian government to pay taxes in Russia.

On social media and in U.S. regulatory filings, however, it presents itself as a U.S. company, based at various times in California, Maryland and Washington, D.C., Reuters found.

Now the question is this: Is this company trying to simply evade sanctions against Russia to stay in business. Or are they collecting data from these apps and handing it over the the Russian government. The company says it didn’t hide the fact that it is Russian, though I question that based on the Reuters story. And one could argue that it really doesn’t matter as the Russian government could knock on their door asking for whatever data they had, and the company could hand it over.

I think that the take home message is as follows. If you as a developer plan to use someone else’s code in your apps, you should make sure that it’s from a trustworthy source. Clearly a lot of developers didn’t in this case. And now it’s an issue.

Non-Profit Healthcare Provider Leaks The Data Of 3 Million Patients Via Malformed Tracking Pixel

Posted in Commentary with tags on October 23, 2022 by itnerd

I have to admit that this is a new way of leaking personally identifiable information that I never considered. Advocate Aurora Health is informing 3 million people that their protected health information was leaked to via a malformed tracking pixel to Facebook or Google:

In a data breach notification on its website, the healthcare system is informing patients that an incorrectly configured tracking pixel – placed on the MyChart and LiveWell websites and applications and on some scheduling widgets – exposed some of their information.

The pixel, the company says, “transmitted certain patient information to third-party analytics vendors that provided us with the pixel technology, particularly for users concurrently logged into their Facebook or Google accounts.”

Potentially exposed information includes IP addresses, information on scheduled appointments, patient proximity to an Advocate Aurora Health location, provider data, type of appointment or procedure, MyChart communications (including names and medical record numbers), insurance details, and the names of patient proxies.

Advocate Aurora Health says it has no evidence that Social Security numbers or financial account and credit/debit card details were exposed in the incident.

“We have disabled and/or removed the pixels from our platforms and launched an internal investigation to better understand what patient information was transmitted to our vendors,” the healthcare provider says.

Advocate Aurora Health says it has found no evidence that the exposed data has been misused and also notes that the misconfiguration is unlikely to lead to identity theft or financial harm.

I’m skeptical that this screw up won’t cause identity theft or financial harm. Facebook and Google sole purposes in life is to harvest information and then find ways to make money from it. Thus I can see a scenario where someone could get access to this info and then use it to to make the lives miserable of the people who are affected by this. I guess that’s why this health care provider is offering up the advice of checking your credit report. Likely because while they don’t think anything bad has happened, they don’t know for sure.

I for one hope that there’s an external investigation into this, and punishment if warranted is handed out swiftly because companies simply need to do a much better job of protecting data like this.

OOPS! City Of Hamilton Leaks Names And Emails Of 450 Voters

Posted in Commentary with tags on October 16, 2022 by itnerd

Well, this is a wee bit embarrassing for the City Of Hamilton:

The City of Hamilton says it “regrets” exposing the names and email addresses of hundreds of registered voters in a privacy breach Thursday.

The breach impacted approximately 450 individuals, the city said in a statement provided Friday, all of whom had registered to use the Vote by Mail process.

“Multiple email addresses were inadvertently entered in the to: line of the email instead of the bcc: line, exposing email addresses to all recipients of the email message,” the city said.

That almost sounds to me like this was done by a human being rather than an automated mailing program like Mail Chimp or Constant Contact. Because those programs would not have done this. A human can easily screw this up and create this exact situation. But at least the city is sorry for this:

Regardless, this screw up has been reported  Information and Privacy Commissioner of Ontario, and I am sure that we’ll not only get a lot more details, but we’ll also find out what the Information and Privacy Commissioner of Ontario has in mind to remedy this situation. And by that I mean take action to make sure that it doesn’t happen again and there’s some accountability as well.

Google Analytics Declared Unlawful In Denmark

Posted in Commentary with tags , on September 22, 2022 by itnerd

Denmark yesterday declared the use of Google Analytics unlawful. The Danish Data Protection Agency concluded that the tool would require the ‘implementation of supplementary measures in addition to the settings provided by Google’. The Agency stated that the decision represents a common European position among the citizens whose personal data is protected. Here are the key details:

The Danish Data Protection Agency has looked into the tool Google Analytics, its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.

In sort, if you’re in Denmark you can’t use Google Analytics. Full stop.

Mark Bower, VP of Product Management of Anjuna Security:

     “The ever-expanding bulk collection of consumer data and its handling will continue to land under the EU regulatory microscope, especially with the recent expansion of GDPR scope around inferred data following recent rulings in Lithuania that propagate across the union. Under this new extension, data that is derived from personal data is considered in scope. If breached, it has the same consequence as primary personal identifiers including massive fines. This has sweeping impact and risk for organizations: traditional approaches to compliance that often assume the personal data can be identified in advance of collection and then protected it may no longer work or be fit for purpose, especially with machine learning models where new derived outcomes and inference are coveted by data processors across industry, especially ad-tech, payments, financial services and retail. Organizations handling personal data must therefore look at more thorough and innovative protection strategies in addition to carefully analyze the risk of bulk collection itself. It’s no surprise then that the top of the data food chain is the first to be put in the spotlight – but they will not be the last”

You have to assume that a bunch of people at Google are not happy about this as gathering data and making money off of it is their core business. And I would not be surprised if other places on the planet start to do similar things.

Sucks to be Google.