Monday, October 09, 2017

A short “How to fail my computer security class” look at Equifax.
Five takeaways from Equifax's brutal week
… The company took more than two weeks to publicly disclose the breach, Smith said, because Equifax’s outside counsel, King & Spaulding, and cybersecurity firm Mandiant advised the company to first have a plan in place to protect consumers affected by the breach. [So much for thinking ahead. Breaches WILL happen, so why not do at least some planning (or thinking) in advance? Bob]
… Hackers exploited a vulnerability in a version of Apache Struts software that was used by Equifax but had not been patched, despite a March alert from the Department of Homeland Security (DHS) directing companies to apply the patch.
… The individual designated to notify personnel to apply the patch failed to do so, Smith said. [Why not share DHS notices with more than one person? Bob]
… Smith also revealed that the personal data accessed was not encrypted at the time it was accessed, prompting further scrutiny. [That would have been their ‘Get Out of Jail’ card! Bob]
… Smith offered up little information on the hackers behind the breach, repeatedly referring to an FBI investigation. When questioned, Smith would not rule out that the hackers were sponsored by a nation state.
“We've engaged the FBI at this point, that's all I'll say,” he said Tuesday.
Bloomberg reported last week that hackers used techniques that have been previously linked to state-sponsored hackers.
While Smith said that investigators tracked the IP addresses of the criminals, he said their identities and whereabouts remain unknown.
Smith did, however, acknowledge the sophistication with which the criminals moved through the company’s system, evading the company’s security personnel for more than a month. [139 days by my count. Bob]


(Related). Compare and contrast.
Disqus Demonstrates How to Do Breach Disclosure Right
… I first saw the Disqus data first thing Friday morning my time in Australia. Verification wasn't difficult because my own record was in there (there's nothing like finding your own data in a breach to help expedite verification!) I reached out to an existing contact I had at Disqus via email as soon as I had a reasonable degree of confidence that the data was accurate (a couple of hours after I received it). From that moment, the timeline in their public disclosure began which I highlighted in this tweet:



(Related).
U.S. Banking Regulator Hit by 54 Breaches in 2015, 2016
The report, made public last week, focuses on the FDIC’s processes for responding to data breaches, and it’s based on an audit conducted in response to concerns raised by the chairman of the Senate Committee on Banking, Housing, and Urban Affairs.
The OIG’s audit focused on 18 of 54 suspected or confirmed breaches discovered by FDIC between January 1, 2015 and December 1, 2016. The 18 incidents reviewed by auditors affected more than 113,000 individuals.
The audit found that in 13 of the 18 cases the FDIC did not complete some key breach investigation activities, such as assessing impact and convening the data breach management team, within the timeframe established in the agency’s Data Breach Handling Guide (DBHG). [Something every organization should have? Bob]
It took the organization, on average, more than 9 months to notify affected individuals after discovering a breach. It took between 145 days and 215 days to send out notifications to impacted people after the decision was made to notify victims. In one incident that affected nearly 34,000 people, the FDIC sent out the notifications exactly one year after the breach was discovered.
A report published last year by the House of Representatives Science, Space and Technology Committee revealed that threat actors believed to be from China breached the systems of the FDIC in 2010, 2011 and 2013, and planted malware on a significant number of servers and workstations. The committee concluded that the agency’s CIO had attempted to cover up the incident.




Can the Internet use broadcast radio and TV rules?
Democrat senator pushes for transparency on social media political ads
Sen. Amy Klobuchar (D-Minn.) said Sunday that she is working on legislation that would mandate online political advertisements be subject to the same rules as broadcast ads.
“And the rules that apply for ads when they’re put on TV or radio, where you have to register them and say how much you paid, that doesn’t apply to these online ads. And so our laws need to catch up with what’s going on with our campaigns,” Klobuchar told CNN’s “Reliable Sources.”
The effort comes amid the growing controversy over Facebook’s political advertising during the 2016 election.




Perspective. A look at our future?
Cash is already pretty much dead in China as the country lives the future with mobile pay
  • Mainland Chinese stores and services are increasingly centered around mobile pay apps like WeChat Pay and Alipay.
  • Chinese mobile payment volume more than doubled to $5 trillion in 2016, according to Analysys data cited by Hillhouse Capital.
  • Mobile pay is growing so rapidly in mainland China that as a foreigner, I sometimes found it difficult to complete basic transactions without it.
  • The dominance of mobile transactions lends itself to greater data collection by the Chinese government.




Perspective. A bit rambling, but quite interesting.
The secret lives of children and their phones




For my Spreadsheet students.
Excel’s Custom View setting makes it easy to view specific information on a crowded spreadsheet or to create different layouts for your data. You can use it to create custom headers or footers, create a print-friendly version of your spreadsheet, or you can create a view in which freeze panes or split rows are activated.


Sunday, October 08, 2017

Surveillance as a “selling point?” Will consumers soon insist that all cameras have this ability?
I don’t know what I’d do without Joe Cadillic. I learn so much from him about businesses engaging in creepy or surveillance activities…. and governments engaging in creepy or surveillance activities and…..
Anyway, in today’s installment, Joe writes:
Are you looking forward to the holiday season?
Do you want the latest in corporate advertised surveillance?
Then hurry up and be the first one in your family to purchase a $249.00 Google Clips camera, that automatically identifies you and your pets.
“Clips automatically chooses which moments to capture and keep, so you don’t need to be behind the camera.”
Because nothing says big brother, like a camera that automatically identifies everyone it takes pictures of.
Read more on MassPrivateI.


(Related).
I go away for a few days and come back to find all these messages from Joe about stories he thinks I’ll want to read and posts of his. It’s great!
Here’s another recent post of Joe’s:
If you have never heard of Virtual Block Watch (VBW) don’t worry, you soon will.
At first glance, you might think it’s like law enforcement’s Neighborhood Watch but you’d be wrong.
VBW’s are law enforcement’s latest national surveillance program that encourages the public to use surveillance cameras spy on one another.
Why do we need another national spying program? Don’t we already have DHS’s ‘See Something Say Something’ spying program?
As you will see, one surveillance program is never enough.
Police across the country are encouraging the public to ‘voluntarily’ let police have access to their CCTV cameras.
Read more on MassPrivateI.




“We can, therefore we must?”
Jason Leopold and Jessica Garrison report:
The intelligence division at the Treasury Department has repeatedly and systematically violated domestic surveillance laws by snooping on the private financial records of US citizens and companies, according to government sources.
Over the past year, at least a dozen employees in another branch of the Treasury Department, the Financial Crimes Enforcement Network, have warned officials and Congress that US citizens’ and residents’ banking and financial data has been illegally searched and stored. And the breach, some sources said, extended to other intelligence agencies, such as the National Security Agency, whose officers used the Treasury’s intelligence division as an illegal back door to gain access to American citizens’ financial records. The NSA said that any allegations that it “is operating outside of its authorities and knowingly violating U.S. persons’ privacy and civil liberties is categorically false.”
Read more on BuzzFeed.




The good fight?
Justice Department Accuses Google of “Alarming” Tactics in Fight over SCA Search Warrant
The ongoing dispute between the government and Google concerning the company’s refusal to hand over customer data stored on foreign servers has taken an odd twist. Now, the Justice Department is demanding that Google be sanctioned for not abiding by the court’s most recent decision—ordering it to produce data associated with 22 email accounts—and calling Google’s conduct “a willful and contemptuous disregard of various court orders.” The case is In the Matter of the Search of Content that Is Stored at Premises Controlled by Google, No. 16-mc-80263 (N.D. Cal.).
… Google wants to appeal Judge Seeborg’s ruling, but is in a tight spot. If Google refuses to comply with the ruling during the pendency of its appeal, it risks inviting (potentially very costly) sanctions. On the other hand, if it complies with the order, it risks mooting the appeal—not to mention potentially upsetting its users.
Google’s solution? Not surprisingly, Google has advised Judge Seeborg that it wishes to appeal, will not comply with the court’s ruling, and wants to be held in civil contempt to expedite the appeal. Although it may seem unusual for a party to seek a contempt finding against itself, this approach has appeal for Google because it preserves appellate jurisdiction. Importantly, Google is asking the court to stay any sanctions during the pendency of the appeal, on the grounds that it is simply acting in good faith to seek clarity on an important legal issue. The company promises that it will continue to preserve the information at issue, and pledges to immediately produce the information if it loses on appeal.
… Google’s motion can be read here, and the government’s response and motion for contempt hearing is here.




Just guessing, but I doubt campaign organizations are going to tolerate this. They want tose attack ad out there NOW!
Facebook tells advertisers more scrutiny is coming
Facebook is going to require ads that are targeted to people based on "politics, religion, ethnicity or social issues" to be manually reviewed before they go live, according to an email sent to advertisers and obtained by Axios. That's a higher standard than that required of most Facebook ads, which are bought and uploaded to the site through an automated system. It's also warning that it expects the new policy to slow down the launch of new ad campaigns.




In case you missed it…
The End of Privacy
… Given the constant stream of breaches, it can be hard to understand what’s happening to our privacy over time. Two dates — one recent and one long ago — help explain this: Dec. 15, 1890, and May 23, 2017, are the two most important days in the history of privacy. The first signifies its creation as a legal concept, and the latter, while largely overlooked at the time, symbolizes something close to its end.




Is the US government unable to do something like this?
Alphabet Closer to Using Balloons for Telecom in Puerto Rico
Last Friday, engineers on Google parent Alphabet’s internet-by-balloon Project Loon tweeted that they hoped to bring emergency connectivity to Puerto Rico after Hurricanes Irma and Maria left more than 90 percent of the island without cellphone coverage.
Just seven days later, the Federal Communications Commission Friday gave the company a green light to fly 30 balloons over Puerto Rico and the US Virgin Islands for up to six months.




Is the full report worth $495?
THE SOCIAL MEDIA DEMOGRAPHICS REPORT: Differences in age, gender, and income at the top platforms
In a new report, BI Intelligence highlights the key audience demographics for six major social platforms: Facebook, Instagram, Snapchat, Twitter, LinkedIn, and Pinterest.
Here are some of the key takeaways from the report:
  • US Facebook users aged 45-54 are spending more time on Facebook, and represent 21% of the total time spent on the platform, more than any other age group.
  • The age composition of Snapchat users in the US has become more evenly distributed over the past year, and it appears the company is doing a better job of attracting older users.
  • Teens are starting to use a category of social media called “digital hangouts.” These are apps that enable users to video chat with several friends simultaneously. Over 60% of users on Houseparty, one of the most popular digital hangout apps, are under 24 years old.
  • LinkedIn is popular among high-income users. Forty-five percent of US adult internet users with an income higher than $75,000 annually are on LinkedIn, making it more popular among this demographic than Instagram (31%), Pinterest (35%), or Twitter (30%).