Over the weekend I posted a story about Eufy and the fact that they have lied about the security that their had for years. And that my belief is that they should be banned from sale because this isn’t the first time that this has happened. Part of my belief that they should be banned comes from the fact that I don’t believe that Eufy is serious about gaining the trust of their users. This is being reinforced by the news that Eufy isn’t patching out a potential security issue in the Eufy Security app. Instead Eufy is just telling users that their thumbnails will be uploaded to the cloud when they choose specific notification settings in the app;
As of Monday, an update has been rolled out to the Eufy Security app to add a statement disclosing that thumbnail images will be uploaded to the company’s cloud servers.
For you to get notifications with thumbnails in them from a security camera, a thumbnail has to be uploaded someplace. That’s true for any camera system. And part of the problem is that Eufy sells these cameras with the expectation that they are completely private. Which clearly they are not. Now that Eufy has clarified this, I am guessing that they hope that this issue will go away. But it won’t because this doesn’t do anything about the ability for a threat actor to stream video. Eufy hasn’t commented on this as far as I know. And there’s no sign that they will do anything about it.
Thus if Eufy was hoping to make this issue go away, I don’t think that this will do it.
Hundreds Of Thousands Of People Affected Due To Last Year’s COVID Booking System Data Breach
Posted in Commentary with tags Privacy on December 10, 2022 by itnerdYou might recall that there was a text message scam from last year where people who booked a COVID vaccine were getting text messages asking for all sorts of personal information. It didn’t take long for two people to get charged with being behind this scheme. And one person who was arrested was an insider as they worked for the vaccine contact centre which is part of the Ontario Ministry of Government and Consumer Services. Once again proving that your organization’s biggest threat vector is your people. Well, the damage has been tallied and it’s not good. The breach resulted in the names and phone numbers of about 360,000 people being leaked. CBC has details:
Beginning Friday, some 360,000 people will receive notices that their personal information was part of the November 2021 data breach of the COVAXX system, the Ministry of Public and Business Service Delivery said in a statement Friday.
The ministry said it had been working with the Ministry of Health, police and the Ontario’s privacy commissioner to determine the scale and impact of the breach. The ministry’s statement does not say how it occurred.
I for one would be very interested in what lessons the Ontario government learned so that this doesn’t happen again. Because 360,000 is not a small number of people to be affected by something like this. And I think that all Ontario citizens would be very interested in this information as well. People have to have trust that their information is going to be protected. And given the scale of this breach, I would be wondering if the Ontario government has the right people, tools, and controls in place to stop this from happening again.
Leave a comment »