Retail News CRM

Tag: privacy

  • Google is fined $8 million in Sweden over data protection laws

    Google is fined $8 million in Sweden over data protection laws

    Since the General Data Protection Regulation (GDPR) went into effect in the European Union back in 2016, companies and organizations have had larger responsibilities in order to protect the privacy rights of individuals. Sweden has evidently determined that Google has not fully complied with these regulations, leading to a hefty fine.

    Under the GDPR, an individual has the right to privacy of personal data, including the right to request that their personal search results, such as their name, be delisted from search engines. Since 2017, the Swedish Data Protection Authority (DPA) has identified search listings that Google is required to delete.

    Based on two audits administered over four years, the Swedish DPA has concluded that Google has not complied to these regulations. Currently, Google informs websites before delisting, allowing them time to move their sites to different URLs to bypass the delisting. The Swedish DPA argues that this practice negates the point of delisting and the overall principles of the GDPR.

    Based on these conclusions, the Swedish DPA has issued a fine of 75 million Swedish kronor, or about 8 million dollars. Based on local laws, Google has three weeks to take action before it becomes final. The internet giant is expected to appeal the decision.

  • WhatsApp private group links visible in Google search results

    WhatsApp private group links visible in Google search results

    Journalist Jordan Wildon stated on Twitter that WhatsApp groups may not be as secure as people thought they were and shared a screenshot, showing some links to groups appearing in Google search results. Apparently, when users create a link to send to someone to join their group, it gets indexed by Google and is accessible.

    A WhatsApp’s spokesperson reminded people that links that should be private shouldn’t be disclosed on publicly accessible websites, apparently explaining that the issue was due to unreasonable public posting of some links. When a link for a private group is posted on publicly available websites, it can be used by anyone to join the group and in consequence, see all the messages in it.

    However, reverse engineer Jane Manchun Wong’s post on Twitter regarding the situation brings another perspective on it – she is stating this situation was a result of a misconfiguration which allowed around 470,000 Group Invite links to be indexed, and not because someone has not been careful enough when sharing private links. According to her, WhatsApp could change certain configurations in order to exclude the invite pages from appearing in search engines.

    Nevertheless, for the time being, WhatsApp maintains the position that this is intended behavior, not a bug.

  • Over 100 million Americans had their personal data exposed

    Over 100 million Americans had their personal data exposed

    What we are going to tell you is something that is bound to get your mind thinking back about any embarrassing texts you might have written. Or whether you might have sent some personal information via text like your social security or credit card numbers, passwords or even PINs.

    The database belongs to an American outfit named TrueDialog. The latter provides “Enterprise-Grade SMS Texting Solutions.” The information available from the breached database not only includes tens of millions of texts from hundreds of millions of American users, but it also contained millions of usernames, passwords (some in cleartext, others encoded but easy to decrypt) and more. The report puts the blame for the data breach directly on TrueDialog for failing to protect the database. It also notes that discovering the identity of the database owner was not difficult. Over 100 million American citizens could be impacted by this data breach.

    The number of people affected by the breach is huge and the possibility that these texts could be read by bad actors is a very major deal; that puts companies like TrueDialog on the defensive. As vpnMentor notes, “Some affected parties deny the facts, disregarding our research or playing down its impact. So, we need to be thorough and make sure everything we find is correct and true. In this case, it was quite easy to identify TrueDialog as the database owner. Their host ID “api.truedialog.com” was found throughout. However, it was also clear that this was a huge data breach, compromising the privacy and security of over 100 million U.S. citizens across the country.”

    The database is hosted by Microsoft Azure and runs in the U.S. on the Oracle Marketing Cloud. It contains 1 billion entries adding up to 604GB of data. This data includes information about TrueDialog’s business, its business clients and the latter’s customers. All of this information could have been used by bad actors to steal identities and money from those with information exposed in the breach. Additionally, all of this data could have been sold to marketers and scammers. Knowing all of this information would make it easier for bad actors to engage in phishing schemes.

    Perhaps you have yet to understand the seriousness of this. Tens of millions of SMS messages that were sent via TrueDialog were leaked revealing the full names of message recipients, account holders and users of TrueDialog’s services. But even worse, the content of messages, email addresses, and recipients’ phone numbers were viewable along with the date and time that these messages were sent.

    TrueDialog itself could face a negative backlash because of this leak. The company’s reputation will take a hit and companies that pay it for providing leads will stop doing business with it if they fear that those leads will get leaked for free. And the amazing thing is that vpnMentor was able to discover the breach because the database was not only unsecured, it also was unencrypted. TrueDialog has been in business for ten years, says vpnMentor, works with more than 990 cellphone operators and reaches 5 billion subscribers globally.

    The date that vpnMentor discovered that the database was leaked was on November 26th. Two days later, it spoke with TrueDialog to report its findings while also offering to help it in the aftermath of the discovery. On November 29th, TrueDialog closed the database but never did get in touch with vpnMentor. While the database is now closed, it isn’t known whether any information that was exposed was stolen by a scammer, spammer, bad actor, or hacker.

  • Facebook launches tool that lets users see and control data shared

    Facebook launches tool that lets users see and control data shared

    Facebook is making it easier for users to see and control the data that apps and websites share with the social network by launching a new tool called Off-Facebook Activity. The new feature will be gradually rolled out to Facebook users in Ireland, South Korea, and Spain. However, Off-Facebook Activity will be made available to everywhere over the coming months, so don’t lose hope if you’re not living in any of these countries.

    But what exactly is Off-Facebook Activity and is it as useful as Facebook claims? Well, first off, you can see a summary of the information other app and websites have sent Facebook through its online business tools, including Facebook Pixel and Facebook Login.

    Also, you will be able to disconnect all the information you see from your account if you want to. On top of that, you can choose to disconnect future off-Facebook activity from your account. Facebook says that you’ll be able to do that for all your off-Facebook activity, or just for specific apps and websites.

    Once you clear your off-Facebook activity, the social network will remove your identifying info from the data that apps and websites choose to send to Facebook. Basically, Facebook will no longer know which websites a user visits or what they did during their visit.

    Also, Facebook says that it will not use any of the data that users disconnect to target ads to them on apps like Facebook, Instagram or Messenger. The social network expects some impact on its business but believes giving people control over their data is more important.

  • Facebook introduces new Group Privacy settings

    Facebook introduces new Group Privacy settings

    In an attempt to make Groups easier to understand, Facebook announced the launch of a new simplified privacy model for the feature, public and private. The new Groups Privacy settings include two clear options, which should make the privacy model much more intuitive.

    For example, public groups allow anyone to see who’s in the group and everything that’s shared there. However, in private groups, only members can see who else is in the group and what they’ve posted.

    Also, with the new settings, admins will be able to clearly choose whether or not the group can be found in search and other places. It’s also worth mentioning that by default, a group that was formerly “secret” will now be “private” and “hidden.” On the other hand, groups that are “public” will remain “public” and “visible.”

    All the new options are now available for all admins in their Group Settings, but keep in mind that there are restrictions to if and when an admin can change the privacy setting of a group. However, all the updates made by an admin to the group’s privacy setting will be highlighted for all group members via notifications.

  • Google now allows users to auto-delete user data

    Google now allows users to auto-delete user data

    Google is making it possible for Android and iOS users to auto-delete location history and activity data starting today. Although the search giant already provided the ability to turn on or off the Location History and Web & App Activity directly from the Google Account, including the option to manually delete the data recorded, there was one feature that makes it so much easier to get rid of this data.

    Starting today, a new set of auto-delete controls are available in the Google app, which will allow users to manage their data easier than before. Simply choose a time limit for how long you want your activity data to be saved, and any data that’s older than that will be automatically deleted from your account.

    Google mentions that you’ll be able to set a time limit for how long your activity data to be saved from anywhere between 3 and 18 months, so there’s that.

    According to Google, users should start seeing the new auto-delete controls soon, and that they will come first to Location History and Web & App Activity. A broader rollout should happen in the coming weeks, so if you don’t see the new feature right away, you’ll have to wait.

  • Humans cause 90% of cloud data breaches

    Humans cause 90% of cloud data breaches

    Incidents in public cloud infrastructure are more likely to happen because of a customer’s employees rather than actions carried out by cloud providers, according to a new Kaspersky Lab report.

    Companies expect cloud providers to be responsible for the safety of data stored on their cloud platforms, the report found. However, around 90% of corporate data breaches in the cloud happen due to social engineering techniques targeting customers’ employees, not because of problems caused by the cloud provider.

    Cloud adoption allows organizations to benefit from more agile business processes, reduced capex and faster IT provision. However, they also worry about cloud infrastructure continuity and the security of their data. At least a third of both SMB and enterprise companies are concerned about incidents affecting IT infrastructure hosted by a third party. The consequences of an incident may make the benefits of cloud redundant and instead evoke painful commercial and reputational risks.

    Even though organizations are primarily worried about the integrity of external cloud platforms, they are more likely to be affected by weaknesses far closer to home. A third of incidents (33%) in the cloud are caused by social engineering techniques affecting employee behavior, while only 11% can be blamed on the actions of a cloud provider.

    The survey shows there is still room for improvement to ensure adequate cybersecurity measures are in place when working with third parties. Only 39%  of SMBs and half (47% ) of enterprises have implemented tailored protection for the cloud. This may be the result of businesses largely relying on a cloud infrastructure provider for cybersecurity. Alternatively, they could have false confidence that standard endpoint protection works smoothly within cloud environments without diminishing the benefits of cloud.

    “The first step for any business when migrating to public cloud is to understand who is responsible for their business data and the workloads held in it,” Kaspersky Lab VP of global sales Maxim Frolov said.

    “Cloud providers normally have dedicated cybersecurity measures in place to protect their platforms and customers, but when a threat is on the customer’s side, it is no longer the provider’s responsibility. Our research shows that companies should be more attentive to the cybersecurity hygiene of their employees and take measures that will protect their cloud environment from the inside.”

  • Privacy browser Tor is now available on Android

    Privacy browser Tor is now available on Android

    With online privacy becoming an increasingly rare luxury these days, most all browsers offer some sort of “incognito” mode that’s supposed to help bypass various “surveillance” methods employed on the web. The demand for online anonymity has spawned a whole new breed of privacy-focused browsers that promise to offer better security and cover your traces in a more efficient manner than incognito modes. Among those, the Tor browser is the most popular (and infamous) choice for people looking to really erase their online presence.

    Connecting to the Tor network was possible in the past on Android, by using apps like Orbot and Orfox, but the release of the Tor browser on the Google Play Store eliminates the need of such workarounds. The browser has been in beta for close to a year now, but it’s finally ready for prime time.

    If you’re not familiar with Tor, here’s a simplified explanation. Instead of connecting directly to a website, like a regular browser would, Tor channels your request through a network of encrypted computers all around the globe, called “nodes,” before reaching your desired destination. This way, your identity and IP address remain hidden. Not to mention that this can also help when trying to view content that is blocked on a per-region basis, like music videos on YouTube for example.

    The Tor browser is based on Firefox, so its interface should be immediately recognizable to Firefox users. The browser is now available on Android, but an iOS may never see the light of day, according to the Tor Project. This is due to “restrictions by Apple,” though the blog post doesn’t go over any of them in detail.

  • Google faces a huge fine for violating privacy rules

    Google faces a huge fine for violating privacy rules

    Last year, the European Union adopted the General Data Protection Regulation (GDPR) designed to boost privacy rights in the union. Under this regulation, companies in the EU cannot use a consumer’s personal data without informed, explicit consent. A company found to have violated the GDPR can be socked with a fine as large as 4% of the company’s prior year global revenue.

    With Google’s European headquarters based in Ireland, the company is now being investigated for GDPR violations by the Irish Data Protection Commissioner (DPC). The genesis of the complaint is interesting. The developers of an app called Brave Browser were among those claiming that Google is not playing by GDPR rules when it collects personal data for advertisers. When someone using the Browser visits a website, the app’s developers state that personal information belonging to the user is sent out to hundreds of companies without the user’s knowledge. These companies use this data in order to place bids to place targeted ads.

    “We will engage fully with the DPC’s investigation and welcome the opportunity for further clarification of Europe’s data protection rules for real-time bidding. Authorized buyers using our systems are subject to stringent policies and standards.”-Google

    If Google is found to have violated the GDPR, it could be fined as much as $5.52 billion based on the company’s 2018 global revenue of $138 billion. And Google is not the only tech firm under investigation by the DPC. As it turns out, Ireland is where many tech giants hang their hats in Europe and 17 tech firms are under investigation there for possible GDPR violations. Among them are Apple, Twitter, LinkedIn, Facebook and some of its units including WhatsApp.

  • Massive leak exposed personal data of 49 million Instagram Accounts

    Massive leak exposed personal data of 49 million Instagram Accounts

    An Instagram database containing the private information of 49 million members, was accidentally left exposed on Amazon Web Services. The database could have been viewed by anyone since it did not have a password for protection. The accounts in the database included those belonging to Instagram influencers, celebrities, and corporate brand accounts and contained their biographies, profile pictures, number of followers, location (city and country), phone numbers and email addresses.

    The leak was discovered by security researcher Anurag Sen, who then contacted TechCrunch to help find the owner of the database. As it turns out, the information belonged to a social-media firm in India called Chtrbox that pays influencers to put up sponsored content on their Instagram accounts. The data included a ranking of each influencer depending on the number of followers they each have and the response to their posts by other Instagram members. While Chtrbox hasn’t commented yet on the matter, the database has since been taken offline.

    Facebook bought Instagram in April 2012 for approximately $1 billion and said that it will investigate the incident.

  • Change your Instagram password Immidiatly

    Change your Instagram password Immidiatly

    An updated entry made yesterday to a post on the Facebook blog reveals that the company left millions of Instagram passwords in a “readable format.” Originally, Facebook said that “tens of thousands” of Instagram customers were involved. Facebook says that normally its login systems are designed to “mask passwords using techniques that make them unreadable.”

    The good news is, if you believe Facebook, its investigation has shown that no one from inside or outside the company accessed these passwords. Of course, since Facebook updated its original blog post after one month increasing the number of passwords affected, who knows what they might say in another month?

    “In line with security best practices, Facebook masks people’s passwords when they create an account so that no one at the company can see them. In security terms, we ‘hash’ and ‘salt’ the passwords, including using a function called “scrypt” as well as a cryptographic key that lets us irreversibly replace your actual password with a random set of characters. With this technique, we can validate that a person is logging in with the correct password without actually having to store the password in plain text.”-Facebook

    Last month, Facebook admitted that it stored hundreds of millions of passwords in plain text dating back to 2012. At the time, it was estimated that 200 million to 600 million accounts had their passwords exposed to as many as 20,000 Facebook employees.

    Facebook purchased Instagram for approximately $1 billion back in 2012. The company suggests that subscribers to Facebook, Instagram or WhatsApp use two-factor authentication when signing in. Besides entering a password, a code is sent to the subscriber’s smartphone that is also required for a successful login. To set this up, go to the settings menu from your Facebook app and click on “Security and Login.”

  • Only 31% Of Consumers In Asia Pacific Trust Organizations Protection to Personal Data

    Only 31% Of Consumers In Asia Pacific Trust Organizations Protection to Personal Data

    Microsoft today released the findings from a new study, Understanding Consumer Trust in Digital Services in Asia Pacific. Conducted in partnership with IDC Asia/Pacific, the study revealed that less than one-third (31%) of consumers believed that their personal data will be treated in a trustworthy manner by organizations offering digital services

    The study, which was conducted with nearly 6,400 consumers across 14 markets in Asia Pacific, also uncovered the following findings:

    • Nearly 40% of consumers in the region have had their trust compromised when using digital services;
    • Consumers feel that all five elements of trust – privacy, security, reliability, ethics, and compliance – are almost equally important to them;
    • Consumers have the highest expectations of trust from financial serviceshealthcare and education sectors;
    • Only 5% of consumers prefer to transact with an organization that offers a cheaper but less trusted digital platform, while 61% will recommend a trusted digital service to others even if the cost is higher; and
    • Consumers feel that governments followed by technology companies should take the lead in building trust.
  • WhatsApp is now rolling out a renewed privacy feature

    WhatsApp is now rolling out a renewed privacy feature

    Groups are a vital part of WhatsApp, although as the Facebook-owned messaging platform has grown in popularity so has the number of unwanted group chats. But today, after testing them for a while on iOS, WhatsApp is rolling out new privacy settings which should help control this.

    Until now, group admins could add any WhatsApp user to a group without needing their consent – the only requirement being that the user is a contact in the admin’s phone. As part of this latest rollout, though, WhatsApp users will now be able to choose which people can add them to groups.

    In order to access the new feature, users need to simply head over to the Settings menu within WhatsApp and tap Accounts. Then a quick tap on Privacy and later Groups will present users with the choice of three options: ‘Everyone,’ ‘My Contacts,’ or ‘Nobody.’ Each one is pretty self-explanatory with ‘Nobody’ meaning users will have to approve every single group with ‘Everyone’ allows users to leave their group invitations completely open, as they are today.

    WhatsApp’s latest privacy feature will begin rollout out today to a select number of users before expanding globally across the coming weeks.

  • Asian firms are better prepared than European peers to comply with data-privacy regulations, according to new EIU study

    Asian firms are better prepared than European peers to comply with data-privacy regulations, according to new EIU study

    The collection and use of personal data for commercial purposes are on the rise, but concerns over privacy and cyber-security breaches are causing concern among consumers, companies and regulators alike. The report, The transparent business barometer: Preparing for the end of easy data, written by The Economist Intelligence Unit (EIU) and sponsored by Ant Financial, assesses companies’ level of preparedness to face a more privacy-conscious world. It is largely based on a survey of 250 executives across China, the US, Western Europe and South-east Asia.

    Nearly 100% of respondents agree that data privacy is important to their organisation, with a majority (54%) saying it will be much more so in three years’ time. One reason for this is the perceived importance of data privacy to good corporate governance, which is something that 88% of executives across the surveyed regions and almost all Chinese executives (98%) believe to be true.

    Many firms are waking up to the fact that stricter laws in the mould of the EU’s General Data Protection Regulation may be in the offing. In a barometer constructed for this study, companies were asked to rank their preparedness to face various data-privacy regulations, such as that which might restrict their ability to gather data directly from consumers, on a one-to-ten scale. Overall, they are relatively well prepared, although they are less willing to take different measures, such as changing business models to reduce reliance on consumer data, in response to such regulations. Compared with bullish Americans, executives in Europe are the least prepared to face regulations and least likely to try new approaches in response to them, while the sentiment in China and South-east Asia falls between those two extremes.

    Transparent business barometer aggregate scores, by region

    (Scores out of 10)

      China US Western Europe South-east Asia Total
    Readiness 7.35 8.04 6.69 7.42 7.36
    Likelihood 6.58 7.16 5.67 6.56 6.47
    Overall 7.06 7.71 6.31 7.10 7.02

    Smaller companies are also less ready to face regulations than their larger counterparts, even as some large firms, including tech heavyweights like Apple and Google, are now beginning to call for regulators to create greater clarity—a step that will hopefully lessen uncertainty going forward.

    Michael Gold, editor of the report, says: “Businesses need to be aware that playing fast and loose with consumer data can lead to major repercussions down the road. Smart, well-co-ordinated regulations can make the business world more transparent and trustworthy amid a growing realisation that data is truly the ‘new oil’ in today’s economy.”

    Full report can be downloaded here.