Ask Slashdot: How Can I Stop Security Firms From Harvesting My Data?
Lately a boom of companies decided to play their “nice guy” card, providing us with a trove of information about our own sites, DNS servers, email servers, pretty much anything about any online service you host.
Which is not anything new… Companies have been doing this for decades, except as paid services you requested. Now the trend is basically anyone can do it over my systems, and they are always more than happy to sell anyone, me included, my data they collected without authorization or consent. It’s data they never had the rights to collect and/or compile to begin with, including data collected thru access attempts via known default accounts (Administrator, root, admin, guest) and/or leaked credentials provided by hacked databases when a few elements seemingly match…
“Just block those crawlers”? That’s what some of those companies advise, but not only does the site operator have to automate it themself, not all companies offer lists of their source IP addresses or identify them. Some use multiple/different crawler domain names from their commercial product, or use cloud providers such as Google Cloud, AWS and Azure â” so one can’t just block access to their company’s networks without massive implications. They also change their own information with no warning, and many times, no updates to their own lists. Then, there is the indirect cost: computing cost, network cost, development cost, review cycle cost. It is a cat-and-mice game that has become very boring.
With the raise of concerns and ethical questions about AI harvesting and learning from copyrighted work, how are those security companies any different from AI, and how could one legally put a stop on this?
Block those crawlers? Change your Terms of Service? What’s the best fix… Share your own thoughts and suggestions in the comments.
How can you stop security firms from harvesting your data?
Read more of this story at Slashdot.
Mobile Device Ambient Light Sensors Can Be Used To Spy On Users
“The acquisition time in minutes is too cumbersome to launch simple and general privacy attacks on a mass scale,” says Lukasz Olejnik, an independent security researcher and consultant who has previously highlighted the security risks posed by ambient light sensors. “However, I would not rule out the significance of targeted collections for tailored operations against chosen targets.” But he also points out that, following his earlier research, the World Wide Web Consortium issued a new standard that limited access to the light sensor API, which has already been adopted by browser vendors.
Liu notes, however, that there are still no blanket restrictions for Android apps. In addition, the researchers discovered that some devices directly log data from the light sensor in a system file that is easily accessible, bypassing the need to go through an API. The team also found that lowering the resolution of the images could bring the acquisition times within practical limits while still maintaining enough detail for basic recognition tasks. Nonetheless, Liu agrees that the approach is too complicated for widespread attacks. And one saving grace is that it is unlikely to ever work on a smartphone as the displays are simply too small. But Liu says their results demonstrate how seemingly harmless combinations of components in mobile devices can lead to surprising security risks.
Read more of this story at Slashdot.
Netflix Password Sharing Crackdown To Expand To US In Q2 2023
In Canada, paid sharing resulted in a larger Netflix membership base and an acceleration in revenue growth, which has given Netflix the confidence to expand it to the United States. When Netflix brings its paid sharing rules to the United States, multi-household account use will no longer be permitted. Netflix subscribers who share an account with those who do not live with them will need to pay for an additional member. In Canada, Netflix charges $7.99 CAD for an extra member, which is around $6. […] Netflix claims that more than 100 million households are sharing accounts, which is impacting its ability to “invest in and improve Netflix” for paying members.
Read more of this story at Slashdot.
Amazon Sued For Not Telling New York Store Customers About Facial Recognition
“It means that even a global tech giant can’t ignore local privacy laws,” Albert Cahn, project director, said in a text message. “As we wait for long overdue federal privacy laws, it shows there is so much local governments can do to protect their residents.”
Read more of this story at Slashdot.
The Washington Post Says There’s ‘No Real Reason’ to Use a VPN
“Today, let’s kill off four privacy and security bogus beliefs, including that you need a VPN to stay safe online. (No, you probably don’t.)
Myth No. 3: You need a VPN to stay safe online.
…for most people in the United States and other democracies, “There is no real reason why you should use a VPN,” said Frédéric Rivain, chief technology officer of Dashlane, a password management service that also offers a VPN…. If you’re researching sensitive subjects like depression and don’t want family members to know or corporations to keep records of your activities, Rivain said you might be better off using a privacy-focused web browser such as Brave or the search engine DuckDuckGo. If you use a VPN, that company has records of what you’re doing. And advertisers will still figure out how to pitch ads based on your online activities.
P.S. If you’re concerned about crooks stealing your info when you use WiFi networks in coffee shops or airports and want to use a VPN to disguise what you’re doing, you probably don’t need to. Using public WiFi is safe now in most circumstances, my colleague Tatum Hunter has reported.
“Many VPNs are also dodgy and may do far more harm than good,” their myth-busting continues, referring readers to an earlier analysis by the Washington Post (with some safe recommendations).
On a more sympathetic note, they acknowledge that “It’s exhausting to be a human on the internet. Companies and public officials could be doing far more to protect you.”
But as it is, “the internet is a nonstop scam machine and a little paranoia is healthy.”
Read more of this story at Slashdot.
Tile Ads Undetectable Anti-Theft Mode To Tracking Devices, With $1 Million Fine If Used For Stalking
The Anti-Theft Mode option is meant to make it easier to locate stolen items by preventing thieves from knowing an item is being tracked. Tile points out that in addition to Anti-Theft Mode, its trackers do not notify nearby smartphone users when an unknown Bluetooth tracker is traveling with them, making them more useful for tracking stolen items than AirTags. Apple has added alerts for nearby AirTags to prevent AirTags from being used for tracking people. Enabling Anti-Theft mode will require users to link a government-issued ID card to their Tile account, submitting to an “advanced ID verification process” that uses a biometric scan to detect fake IDs. […] Anti-Theft Mode is rolling out to Tile users starting today, and will be available to all users in the coming weeks.
Read more of this story at Slashdot.
Wyze Security Cameras Will Go Offline Tonight For Two Hours
While it’s a good thing that Wyze is giving customers a heads-up, the flip side is that everyone is getting a heads-up. It’s posting a sign that any location using this equipment will be unprotected between these hours, with basically no notice to create a backup plan or take other precautions, depending on your security concerns. It’s also worrisome that the professional security customers have paid for and rely on can be completely disabled for “maintenance.”
Read more of this story at Slashdot.
Dashlane Publishes Its Source Code To GitHub In Transparency Push
At first, the code will be open for auditing purposes only, but in the future it may start accepting contributions too –” however, there is no suggestion that it will go all-in and allow the public to fork or otherwise re-use the code in their own applications. Dashlane has released the code under a Creative Commons Attribution-NonCommercial 4.0 license, which technically means that users are allowed to copy, share and build upon the codebase so long as it’s for non-commercial purposes. However, the company said that it has stripped out some key elements from its release, effectively hamstringing what third-party developers are able to do with the code. […]
“The main benefit of making this code public is that anyone can audit the code and understand how we build the Dashlane mobile application,” the company wrote. “Customers and the curious can also explore the algorithms and logic behind password management software in general. In addition, business customers, or those who may be interested, can better meet compliance requirements by being able to review our code.” On top of that, the company says that a benefit of releasing its code is to perhaps draw-in technical talent, who can inspect the code prior to an interview and perhaps share some ideas on how things could be improved. Moreover, so-called “white-hat hackers” will now be better equipped to earn bug bounties. “Transparency and trust are part of our company values, and we strive to reflect those values in everything we do,” Dashlane continued. “We hope that being transparent about our code base will increase the trust customers have in our product.”
Read more of this story at Slashdot.
Apple Device Analytics Contain Identifying iCloud User Data, Claim Security Researchers
On Apple’s device analytics and privacy legal page, the company says no information collected from a device for analytics purposes is traceable back to a specific user. “iPhone Analytics may include details about hardware and operating system specifications, performance statistics, and data about how you use your devices and applications. None of the collected information identifies you personally,” the company claims. In one possible differentiator, Apple says that if a user agrees to send analytics information from multiple devices logged onto the same iCloud account, it may “correlate some usage data about Apple apps across those devices by syncing using end-to-end encryption.” Even in doing so, however, Apple says the user remains unidentifiable to Apple. We’ve reached out to Apple for comment.
Read more of this story at Slashdot.
Customs Officials Have Copied Americans’ Phone Data at Massive Scale
Details of the database were revealed Thursday in a letter to CBP Commissioner Chris Magnus from Sen. Ron Wyden (D-Ore.), who criticized the agency for “allowing indiscriminate rifling through Americans’ private records” and called for stronger privacy protections. The revelations add new detail to what’s known about the expanding ways that federal investigators use technology that many Americans may not understand or consent to. Agents from the FBI and Immigration and Customs Enforcement, another Department of Homeland Security agency, have run facial recognition searches on millions of Americans’ driver’s license photos. They have tapped private databases of people’s financial and utility records to learn where they live. And they have gleaned location data from license-plate reader databases that can be used to track where people drive.
Read more of this story at Slashdot.