Showing posts with label security issues. Show all posts
Showing posts with label security issues. Show all posts

Monday, December 1, 2014

Is Facebook Messenger Worth the Download?



If you use Facebook, you started getting messages telling you that a new app, Messenger, was about to be launched.  For weeks these messages would appear and for weeks I would ignore them.  Why would I need another app?  I get my private messages from Facebook, so what’s the big deal?  Well, the “big deal” came when Messenger was the only way I could access my private messages on my phone.  I clicked on the “download app” box and saw all the information it wanted and I decided that there was no way I would be downloading this.  That lasted about three weeks.  It turned out that it wasn’t as easy to just get to a computer every time I needed to read a message, so, I put on my big girl panties and hit “download”.

When I really gave it some thought, I realized that the only reason I didn’t want the Messenger app was because I felt it was asking for too much information.  Apparently, I wasn’t the only one who felt this way.  Seeing that Messenger wants to access your phone, your phone’s camera and see your geo-location, it all seemed a bit much….at first.  But, I had to face facts:  Messenger wasn’t asking for any more information than other apps that I have.  And, giving it even more thought, I understand why it needs the information it’s asking for.  Of course it wants to access your phone because that is how you are going to be getting your message.  It needs access to your camera because that is how you will be sending pictures through the app.  Geo-location?  Of course!  Without it, how will it know which of your friends is near you and available for messaging?

I then realized that I was just making excuses not to download Messenger and it was becoming an inconvenience to me.  Besides, I have quite a few apps already that need the same information that Messenger needs.  GasBuddy uses geo-location to tell me which gas stations are close to where I am and needs access to the phone’s camera so that users can post pictures of the gas stations and the price boards.  The Dunkin Donuts and Starbucks apps use my geo-location so that I can get a current list of nearby stores where I could get my caffeine fix.  They also need access to my phone to keep track of my purchases and send me coupons whenever I reach my “bonus point” goal.  Then, there’s Swarm (which used to be FourSquare).  I can check in anywhere I visit and with geo-location, it will tell me if any of my friends are at the same mall I’m at.  It will also give me a list of my “favorite” spots so check-ins are a breeze.  Candy Crush, Words with Friends, Scramble with Friends, and any other games you have on your phone all need access to your phone and geo-location.  So, if I don’t mind giving these apps access, why do I mind giving access to Messenger when this would actually be the app I would use the most?

Facebook already knows all about me, and since Messenger is a Facebook app, what would be the difference if I allowed this to have my information?  After all, it’s not asking for my Social Security number or banking information.  It started to make less sense to NOT download Messenger, so, I caved.

Sunday, April 6, 2014

Google Glass: Innovative or Creepy?



In 2012, Google began testing and demonstrating a new product that they call “Google Glass”.  Google Glass is a device that is a very small display screen and it is made to be worn either by itself, or hooked on to a pair of glasses or sunglasses.  The device will show the user the time, give directions, search the Internet, send messages and take photos and videos.  This is all done hands-free.  Just speak and Google Glass will do as you ask. 
  
Since its debut, there have been around 8,000 Glass wearers.  Last year, at SxSW (an annual conference featuring music, films and interactive technology), Google Glass was seen everywhere.  The same was true of this year’s conference.  People are curious about what it’s like, but most find it pretty creepy.  But, why is it that most people find it creepy?  After all, it’s just a small piece of glass that sits near the wearer’s eye.

When you see someone wearing Google Glass, whether they are sitting across from you at a table or simply walking past you on the street, you never know what they are doing on the device.  They could be reading texts, doing research, or they could be doing nothing at all with it at the time.  When someone walks by you wearing Google Glass, you would never know if that person has just taken a picture of you or even shot a video as you were approaching each other.  This is what makes it so creepy.  In fact, many people feel uncomfortable even coming close to someone wearing Google Glass.

Google Glass makes people so uncomfortable that some have been told to leave stores, clubs and even meetings at work if they didn’t remove the device.  Wearing Google Glass at an airport could cause problems as could driving while wearing the device.   In fact, Cecilia Abadie was the first person to get a traffic ticket while wearing Google Glass.  She was initially stopped for speeding in October 2013, but when the officer saw that she was wearing Google Glass, he added a ticket for the violation “monitor visible to driver”.  Ms. Abadie took the matter to Court in January 2014 and was found not guilty.  The officer had no proof that the monitor was turned on at the time of the incident.

When it comes to discussion groups about Google Glass, there are two views:  Google Glass wearers love the device, but those interacting with them don’t like it at all.  In fact, they barely tolerate it.  In social situations, non-wearers get a feeling of paranoia because they feel they are always being “watched”.

What’s odd about all this discomfort is that those who say they don’t like the feeling that they are being recorded by Google Glass wearers don’t think twice about being recorded other ways; like with a smart phone or security cameras.  Of course, the difference here is that with a smart phone or security cameras, you always know when you are being recorded.  With Google Glass, you would never know.  So, I guess the feeling of unease isn’t from the fact that they could be recorded, it’s from the not knowing if it’s happening or not.  
Google Glass wearers don’t see an issue with each other because they know how the device works.  However, if you have never worn Google Glass, and you are talking with someone who wears it, all you see is this small piece of glass and you can’t help but wonder if your conversation is being recorded.

Friday, February 28, 2014

How Else Will Your Privacy Be Taken?



In the article Looking for a Job?  Beware of this Privacy Risk, you learned how looking for work could lead to a breach in your privacy.  This is a risk for only those who are currently looking for a job.  There is another privacy risk that should be a concern to everyone, regardless of age or state of employment.  Employers and schools are demanding to know your social media information.

Many companies do not want their names mentioned in social media unless they have control over what is being said.  The only way these companies have to keep control over this is by checking each employee’s social media accounts to make sure nothing derogatory is being said about the company.  Because anyone can set privacy controls, the only way to know everything that an employee says on social media is to have full access to the accounts.  That is why employers are asking for the log-in names and passwords of all employees. 
 
Employers are not only looking for what is said about the company, or if the employee has the company name listed as their place of employment, they are also looking for anything inappropriate that may be posted.  Pictures of wild parties or visits to a nude beach may just get you fired.  True, these parties and beach pictures were taken on your leisure time, but now, unless you have a contract, you are considered an “at will” employee.  This means that your employer can terminate your employment for any reason.  Even if you have a contract, most of them have a morals clause, so any inappropriate postings could void the contract.

Thursday, August 22, 2013

Is Your Smart TV Spying on You?



New York State Senator Chuck Schumer recently issued a warning to all smart TV owners:  If your TV is equipped with a camera and can connect to the Internet, it could be used to spy on you.  Yes, your smart TV is capable of allowing a hacker to steal your credit card information, or worse, your identity.  Not only that, but a hacker can remote-access your TV’s camera and watch everything you do in the room that the smart TV is in.  To make matters worse, these TVs don’t have much in the way of security settings. 

Researchers Aaron Grattafiori and Josh Yavor were at the Black Hat security conference in Las Vegas, Nevada recently and showed how a smart TV can be hacked.  During the demonstration, they were able to control social media and any other application installed on the TV, they accessed files and even turned on the camera.  If they were able to do this, anyone else can do it too.  It’s like giving up your remote control to a hacker.

Mr. Grattafiori spoke with Mashable regarding this issue (Your Smart TV Can Be Hacked to Spy on You).  He said, “Because the TV only has a single user, any type of compromise into an application or into Smart Hub, which is the operating system – the smarts of the TV – has the same permission as every user, which is, you can do everything and anything.”

Grattafiori and Yavor, who work for iSEC Partners, a security firm, began looking into the issues with smart TVs in December of 2012.  They notified Samsung about this security breach in January 2013.  Samsung issued a statement to CNN shortly after claiming that “patches” have been issued to plug up the holes in security (Your TV Might be Watching You), which now makes it difficult for hackers to break into your smart TV.

Friday, June 28, 2013

How is the NSA Putting Your Privacy at Risk?



Within the last couple of weeks, 29 year old Edward Snowden has become famous.  He’s not an actor, or singer, or author; his “fame” came from telling the world that everyone’s privacy is at risk because the NSA (National Security Agency) has been spying on Americans for years.  It’s the job of the NSA to keep the United States safe from terrorism.  Everyone knew without it being spoken that spying was involved, but most people were surprised at the extent of this spying.  It’s expected that terrorist groups or people with ties to known terrorists were probably targets, but no one thought that the private e-mails and telephone conversations of Joe Public would be compromised.

Anyone can be a target of the NSA.  E-mails are flagged by certain keywords that are considered “terroristic” in nature, like “bomb”, “gun”, “shooting”, etc.  Unfortunately, some of these words are used in conversation that has nothing to do with terrorism, however, an e-mail to “Aunt Sally” that talks about someone “shooting a video” near your home could lead to suspicion.  Not only that, but Aunt Sally will probably be checked out as part of your “conspiracy”.

Is there really a threat to our security or are we all simply paranoid?  According to the NSA, there have been more than 50 terrorist threats that have been discovered and blocked (one of which was targeting the New York Stock Exchange) since the spying program was started after September 11, 2001.  Knowing that these threats have been discovered and blocked, do you now feel better that the government is taking away some of your privacy?  Will you re-think some of the wording that you use in your e-mails so they won’t be targeted?  Telling a friend you went to the movies and you thought the latest hit was really a “bomb” could be re-phrased, but should we really have to think so hard about our choice of words?   Then consider your phone conversations; do you ever vent about your frustration with some politicians?  One red flag and all of your phone records will be reviewed.

Wednesday, March 20, 2013

Instagram Claims Right to Sell Photos



Early in 2012, Facebook approached the founders of Instagram with a $1 billion deal to buy the fledgling Internet photo company.  In September 2012, the deal was finalized for reportedly $750 million.  Good news for Instagram, but bad news for anyone who posted one or more of the 5 billion photos.  Why?  Because now, with Facebook owning Instagram they have the right to sell any of these photos.

The policy to sell user photos was supposed to take effect on January 16, 2013, which was 3 months after Facebook’s purchase.  According to this new policy, Facebook is claiming their right to sell Instagram photos without notifying or paying the original poster.  The only way to avoid this happening to you is if you deleted your Instagram account before the January 16th deadline.  News of this caused an uproar among users.   

But how will this new Instagram policy affect users’ privacy?  If you have an account that hasn’t been deleted prior to the January 16, 2013 deadline, any of your photos could be sold to advertisers.  In other words, that picture of you in your bikini while you were on Spring break, holding up a bottle of Coors Light, could be sold to Coors and used in one of their advertisements.  Imagine your surprise when you see this picture on a billboard!  Instagram will be making money for Facebook from Coors, Coors will be making money from the advertisement and you will be making nothing at all for your part in all of this.

Kurt Opsahl, Senior Staff Attorney with the Electronic Frontier Foundation says of this new policy, “It’s asking people to agree to unspecified future commercial use of their photos.  That makes it challenging for someone to give informed consent to that deal.”

Because there is nothing specified, this leaves an endless list of possibilities for exploitation of user photos.  Travel agencies, airlines and resorts can all use your photos in magazine ads, brochures, Internet advertising, television advertising, etc.  All they have to do is pay the fee to Facebook and your Instagram photo is now theirs to use as they see fit.  There is no limit to what types of photos will be sold.  This means that if you post a picture of your children playing in the sands of a tropical island, your children could be the subject of an advertisement.  

Thursday, February 28, 2013

Facebook Finds a New Way to Make Money Off of You



Facebook now has a new feature:  Promote and Share.  This feature allows all Facebook members to promote posts made by their friends.  Of course, to do this, there will be a fee.  You can now choose to “Promote and Share” any post made by any friend, for a $7 fee.  The posts promoted do take into consideration privacy settings, but there is no way to opt out of this.  The feature is causing some privacy concerns because the friends whose posts you’re sharing have no say in the matter. 

According to Facebook, this feature has been added because they felt there was a need.  It is said to be beneficial to all Facebook members by allowing them to make others aware of special events in a friend’s life.  This includes such things as landing a new job, welcoming a new member into the family, graduations or good deeds.

A statement issued by Facebook said, “This feature respects the privacy of the original poster – i.e. it will promote to everyone who originally saw it.  You can only promote posts to the people that your friend originally shared with.  If you have mutual friends, they’ll see that you shared it and promoted it.”

Some may not see the need to spend $7 to promote a post since the only people who can see the promoted and shared information are the ones who were originally allowed to see it.  What would be the advantage of such a feature?  The “advantage” would be that it would bring the post higher up on the news feeds, so if a mutual friend missed the original post, he or she would most likely see the promoted and shared post.

Wednesday, October 10, 2012

Can Your GPS Lead a Stranger to Your Door?



Nowadays, almost everyone has a GPS.  As you drive down the highways and back roads, just about every car you see has one attached to the windshield.  Some newer models of cars come with the GPS as either a standard feature or an option.  A GPS doesn’t only tell you how to get where you’re going; it also tells you when you should be arriving.   If one of the roads you need is closed, or if traffic is unusually heavy, the GPS will tell you which detour to take.  For these reasons, I’m addicted to my GPS, just like millions of other people.

Yes, the GPS is a huge part of our lives, but do we ever think about how we can be risking our safety by using it?  Think of all the information about you that a criminal can get just by looking through your GPS’s “Favorite Places”.   Below is a scenario that is played over and over all over the country:

You just got a promotion at your job.  Along with this came a very large raise, so, to celebrate, you and your husband go out for a night on the town.  Your first stop is that new nightclub that opened a few weeks ago because a band that you both love is playing there.   You know the address, but aren’t sure how to get there, so you program it into your GPS.  You get to the club and hand your car over to the valet so you don’t have to walk unfamiliar streets to find it later.  If you have an in-dash GPS, it’s all but forgotten, but if you have a portable GPS, you stash it in the glove box so it’s out of sight.

Maybe your husband comments about the band and how long it’s been since you’ve both been to one of their concerts.  You tell him that you can’t wait and will savor every minute until the club closes and you are forced to leave.  During this conversation, the valet has heard every word.  He also noticed where you put your portable GPS, or that you didn’t turn off your in-dash GPS.  Who is this person that you just handed your car to?  Does he have a criminal background?  Well, whoever this person is, he now knows your plans for the entire evening.

The valet is doing a quick scan of your keys as you are walking into the club.  He notices that you are like thousands of others who keep their house keys on the same key ring as your car key.  He then takes your car and parks it.  He reaches for your GPS and scans your list of “Favorite Places”.  He hits the jackpot when he sees an entry listed as “Home”.

Friday, September 7, 2012

Which Would You Choose: Privacy or Security?

Carnegie Mellon University’s Pedo-Biometrics Lab in Pittsburgh, PA has a joint project with a Canadian company, Autonomous ID.  The project is a security scanner that is built into the in-soles of shoes.  These in-soles will be used at high security companies, power plants and military bases to screen employees attempting to gain access to high risk areas.

The idea for this type of device came to Todd Gray, President of Autonomous ID, when he visited his daughter right after she gave birth.  Gray noticed that the walls of the maternity ward were decorated with the footprints of all the babies who were born there.  When he saw this, he realized that each person’s footprints were as unique as their fingerprints.  To start the project, Gray paid $1.5 million to Pedo-Biometrics Lab.  

Security or privacy?  The choice is yours.
These special in-soles will have sensors that measure the amount of pressure each step places on specific areas.   Height, weight and gait are all factors used to make these measurements.   When an employee is fitted with these in-soles, he or she will walk around so his or her data can be stored in a master file located in microcomputers.  From this master file, security clearance level will be confirmed.  If confirmed, access to the area will be granted; a silent alarm will be triggered if the employee does not have clearance.   

Preliminary tests that were run on in-sole samples demonstrated that there is an accuracy rate of 99% after only three steps.  Further tests are taking place that will take such factors as dieting, athleticism and nationality into account.  Tests will also be done on fraternal and identical twins.  Mr. Gray is of the opinion that there is less of a privacy risk to these in-soles as opposed to eye scans. 

Attorney Lee Tien of the Electronic Frontier Foundation (EFF) doesn’t fully agree with that opinion.    “Every biometric capture device is a potential tracking device, just like every iPhone is a potential tracking device.  That’s just the way things are.” is the statement made by Mr. Tien.  He did, however, feel that the in-soles “might make a person feel a little bit better” about their security.  Another positive point Tien made was that the identification accuracy rate of 99% after merely three steps is “pretty impressive”.

Can you be tracked without consent?
There was a negative side that Tien saw:  these in-soles could be inserted into an employee’s shoes without his knowledge or consent.  In this respect, they could be considered a “spy tool”.

Thinking about all the pros and cons, I can’t imagine allowing my employer to know everywhere I go, even on my time off from work.  I would simply feel like I was being stalked.  I’m not willing to give up my privacy like that.

Privacy is our greatest asset and we should not be willing to risk it.  Learn how to protect yourself both on line and off by taking a few minutes to download the free Internet Privacy Guide at the top of this page.  Isn’t it worth a few minutes to learn how to keep your privacy safe?