Showing posts with label facebook. Show all posts
Showing posts with label facebook. Show all posts

Wednesday, 14 September 2016

SumTips: 4 Reasons to Beware of the Facebook Algorithm

A letter to Mark Zuckerberg from Norway's Aftenposten
[Source: Aftenposten]
Facebook has gotten its share of the spotlight this September—and the news has been far from in the social media platform’s favor. More than once the famed Facebook algorithm has produced results in need of human correction:

1.    The Terror of War: Norwegian newspaper Aftenposten posted Nick Ut’s Pulitzer Prize-winning photograph of children fleeing a Vietnam War napalm attack, only to find the widely-received photograph removed on grounds of child nudity. The act elicited the criticism of Erna Solberg, Norway’s Prime Minister; the image has since been reposted and Facebook Chief Operating Officer Sheryl Sandberg has apologized.

2.    “September 11: The footage that ‘proves bombs were planted in Twin Towers’”: A hoax article from The Daily Star topped Facebook’s trending stories as the 9/11 anniversary approached. Facebook’s algorithm had defaulted to a story that blamed bombs—not airplanes—for the falling of New York’s Twin Towers in the second such mishap since the platform did away with human curation of news in late August.

3.    Black Lives Matters activist Shaun King: When activist and New York Daily News writer Shaun King posted a racist message that had been directed at him, King was the one to be temporarily banned from Facebook. King’s response:
“I love Facebook. I was an early user and have been on here for over a decade, but I regularly have friends complain that when they post about the racism and bigotry they face, THEY end up getting suspended instead of the person who harassed them.  
It’s almost like a cruel joke. 
Well, it just happened to me. Earlier this morning I received a horrible email. I posted the email WITHOUT the email address of the person who sent it, then a few hours later was told that I was banned from posting for at least 24 hours because of it. 
This is completely ridiculous. Facebook needs to be much more sensible and intelligent about how it does these things. I have complained to my friends who work there and will see what happens.” 
King’s account was reinstated within hours, which he contributes in part to the connections he has with the company.

4.    Northern Ireland revenge porn: For every image Facebook removes erroneously, there is one that it leaves up unjustly. A 14-year-old victim of revenge porn endured a naked photo of herself posted to a “shame page” from November 2014 until January 2016. Facebook and the man suspected of posting the photo are now being sued.

The next time you login to Facebook, remember that what you see may haunt you, be untrue or never be seen again. Surf secure and stay Rando!


Want more SumTips? Read on!

Want SumTips sent to your inbox? Sign up for our weekly newsletter ("Security Tips and News" at bottom of page). 

SumRando Cybersecurity is a Mauritius-based VPN, Web Proxy and Secure Messenger provider. Surf secure and stay Rando!

Wednesday, 11 May 2016

Report Lists 91 Countries Requesting Facebook Account Data and Content Restrictions

Have you seen your Facebook page lately? The photos from your best friend’s wedding, where you were last night and even your phone number?

Facebook routinely grants government requests to access private pages and restricts content based on local laws. The social networking site recently released a breakdown of all activity worldwide from July to December 2015. Highlights include:

Facebook, privacy, censorship, WhatsApp, SumRando Cybersecurity
[Source: Keri J]

TOP 10 COUNTRIES FOR REQUESTS FOR USER DATA
United States (19,235)
India (5,561)
United Kingdom (4,190)
Germany (3,140)
France (2,711)
Brazil (1,655)
Italy (1,525)
Argentina (892)
Australia (802)
Poland (611)

TOP 10 COUNTRIES FOR USER ACCOUNTS REFERENCED
United States (30,041)
India (7,018)
United Kingdom (5,478)
Germany (3,628)
France (2,894)
Brazil (2,673)
Italy (2,598)
Argentina (1,047)
Spain (947)
Australia (846)

TOP 10 COUNTRIES FOR PERCENTAGE OF REQUESTS WHERE SOME DATA WAS PRODUCED
Nigeria (100%)
Croatia (90.91%)
Sweden (87.31%)
Turkey (84.20%)
United Kingdom (82.15%)
Serbia (81.48%)
United States (81.41%)
Albania (80.00%)
United Arab Emirates (80.00%)
Canada (79.63%)

TOP 10 COUNTRIES FOR CONTENT RESTRICTIONS
France (37,695)
India (14,971)
Turkey (2,078)
Germany (366)
Israel (236)
Austria (231)
United Kingdom (97)
Russia (56)
Brazil (34)
Kazakhstan (25)
 

The complete listing of all 91 countries with user data requests and content restrictions in the second half of 2015 can be found at https://govtrequests.facebook.com/, along with all reports dating back to 2013.

According to Facebook, government requests typically are prompted by criminal investigations and ask for basic subscriber information including name, registration date and length of service; account content; and/or IP address logs. Content restrictions occur when governments ask Facebook to remove content that would not be allowed under local law.

So, the next time you’re on Facebook (or even the Facebook-owned, metadata collecting WhatsApp), make sure that everything there is information you would be willing to share with your government. After all, sometimes even the most innocent of “criminals” can find themselves under government surveillance.


SumRando Cybersecurity is a Mauritius-based VPN, Web Proxy and Secure Messenger provider. Surf secure and stay Rando!

Wednesday, 7 October 2015

Take Action Against Facebook’s Targeted Ads

Facebook has just taken data collection to a whole new level: targeted ads based on visits to webpages that feature the Like button. That’s right: the ads you see won’t be determined by your decision to click on the Like button, just on your decision to surf the web.
Facebook, Like button, social media plugins, targeted ads

Since the Like button’s introduction in 2010, embedded cookies have followed logged in and logged out users alike around the internet, sending information from each Likable page visited back to Facebook. What has changed recently is how the social media platform views that data: in 2011, WSJ’s Digits quoted a Facebook spokesman as insisting, “No information we receive when you see a social plugin is used to target ads.” Now, exactly the opposite holds true.  

A mid-September announcement from Facebook did its best to sidestep a data privacy argument by applauding its newfound ability to provide more relevant, useful ads and reminding users that they remain (somewhat) in charge of which ads they see. Although not exactly the announcement we would have written, it did serve as a good reminder to take what controls we are given:

  • Make use of Facebook’s Ads Settings page. You have the option to hide ads based on your use of websites and apps, to hide the actions you’ve taken in response to ads, and to manage your preferences in determining which ads you see. Just don’t let yourself think you are doing more than hiding: as Facebook will remind you when you adjust these settings, users are simply changing the potential relevancy of the ads they see and not the number of ads they see or the amount of information that Facebook collects about them.
  • For users connecting from the United States, Canada or Europe, take additional measures to opt-out of what web viewing data collection you can. When you adjust your online interest-based ads setting, Facebook will offer to direct you to the Digital Advertising Alliance of the United States, Canada or Europe. Again, be aware of the limitations of doing so: the DAA of the U.S., for example, provides the opportunity to opt-out of just 124 participating companies’ data collection; when we tried it, we succeeded in opting out of only 79 of those companies’ cookies.
  • Be willing to take regular, proactive measures. Log out of Facebook after each session and use a cookie blocker such as EFF’s Privacy Badger when browsing the internet. Your extra effort will be rewarded with a newfound sense of privacy.

It is an undeniable fact that the social media platforms we have come to rely on are funded by advertising revenue, but this alone does not justify the constant push by entities such as Facebook to find new ways to collect and exploit our data. Privacy advocates have long asked Facebook to limit Like button data collection to those who choose to click on the button; given that Facebook’s current response has been to move in the opposite direction, users must continue to actively defend what privacy they still can. 

SumRando Cybersecurity is a South Africa-based VPN, Web Proxy and Secure Messenger provider. Surf secure and stay Rando!

Monday, 11 August 2014

Moving Past Privacy-Poaching Facebook Messenger

Facebook is again making privacy headlines.  Sources have discovered that Facebook's new Messenger app has a laughably invasive list of terms and conditions to which users must agree.  What is worse is that this app replaces messaging services offered within the main Facebook app, trying to force millions of users to agree to terms no one should have agree to.

 
According to The Toronto Star, the app can access personal information and also take action based on the data discovered.  For instance, users will allow the app to do the following:

  • Call phone numbers without your intervention and sending text messages;


  • Record audio with the microphone, and taking photos and videos with the camera, without your confirmation;


  • Read your phone’s call log.
  • By contrast, services like our SumRando Messenger are security-focused and privacy-protecting while still being easy to use and convenient on the go.  We have gone out of our way to design an app that protects users and those they message while other services continue to force unfair terms on their users.

    You should not have to worry about anyone collecting information from you and also take invasive action based on that information.  In contrast to Facebook Messenger, these are a few of our specs:
    • Two forms of encryption (AES-256 and SSL) to keep your messages secure
    • No direct link between your phone number, device email address, or other identifying account; the decision on who you want to communicate with is strictly yours
    • Messages automatically deleted upon logout with only 10 messages stored (if you do not clear you conversation) stored for future conversational reference.
    See the difference?  We don't believe consumers should have to choose between privacy and convenience.  What remains striking is just how many major developers try to force consumers to make that choice.

    The benefit of a story like this about Facebook Messenger is that it is a story that could attract millions of Facebook users to take privacy concerns seriously.  One of the largest social media and messaging companies in the world has taken a stand against privacy, and their users are retaliating.

    What remains to be seen are two things: How many users will refuse this new Messenger app and what Facebook will do (if anything) to bring them back into the fold.

    Tuesday, 27 August 2013

    News Roundup

    Facebook Refuses to Pay Bug Bounty

    Like many web companies, Facebook offers independent analysts monetary prizes for discovering bugs. But when independent researcher Khalil Shreateh tried to use Facebook’s conventional channels to report a critical security vulnerability that allowed users to post on any other user’s wall—friend, enemy or other — the social network’s white hat disclosure programme failed to acknowledge his findings.
    Not one to be ignored, Shreateh used the very exploit he tried to report and posted the information directly to Mark Zuckerberg’s wall.

    Unfortunately, Facebook is now refusing to pay Shreateh. According to a post on Y Combinator’s forum, a Facebook representative said, “The more important issue here is with how the bug was demonstrated using the accounts of real people without their permission. Exploiting bugs to impact real users is not acceptable behavior for a white hat."

    Shreateh claims posting the bug on Zuckerberg’s wall was the only way he could prove it existed after being told previously that the bug was not valid.

    Researchers Sneak Malicious App into Apple Store

    Apple has always kept tight tabs on their app store. Whenever developers want to make a new app available for purchase, it must first receive the O.K. from Apple to make sure its content is neither malicious nor inappropriate. But a team of researchers has developed a work-around and successfully got a malicious app, called Jekyll, approved.

    Instead of submitting an app that explicitly contains malicious functionalities to Apple, the attacker plants remotely exploitable vulnerabilities (i.e., backdoor) in a normal app, decomposes the malicious logic into small code gadgets and hides them under the cover of the legitimate functionalities. After the app passes the App Review and lands on the end user's device, the attacker can remotely exploit the planted vulnerabilities and assemble the malicious logic at runtime by chaining the code gadgets together. [usenix]

    In other words, the code needed for the malware is hidden in pieces within legitimate code and then reassembled during an update.

    An Apple spokesman said the company has addressed the issue, but has yet to provide any details.

    Cyberattacks Cause Internet Outages for More People than Hardware Failure

    It’s important to remember we live in a world where cyberattacks affect more than just personal computers. According to the European Union Agency for Network and Information Security (ENISA), cyberattacks caused significant communications outages for more people than hardware failure last year.

    The report shows that although cyberattacks caused only 6 percent of significant outages in the E.U., they affected about 1.8 million people. Comparatively, while hardware failure accounted for about 38 percent of all incidents, it only affected about 1.4 million people. Read more here.

    Wednesday, 26 June 2013

    Facebook Knows More About You Than You Think

    You know what the problem with Facebook is? They just don’t give out enough of my information. I mean, sure, they dish out all the stuff I put out “voluntarily”, but is that really enough?

    Obviously they didn’t think so.


    Last week, Facebook owned up to a bug that exposed the private information of more than six million users. Then, security researchers revealed that the private information contained data on many more users – even some that aren’t even on Facebook. These “shadow profiles” contained names, and even email addresses and phone numbers for millions of people.

    Many of the users whose email addresses and phone numbers were exposed had not knowingly shared that personal information with Facebook.
    Instead, their contact information had been collected on the sly — stored in Facebook's secret behind-the-scenes scaffolding, where it collects troves of data on you that you never knew about. That information comprises what's known as your "shadow profile."

    Basically, when one of your friends had Facebook analyze his address book to find his friends, Facebook was gathering extra, unauthorized information including email addresses and phone numbers and then assigning that data secretly to the appropriate user. In this way, Facebook has data on you that you never actually authorized them to have.

    Holy privacy violations, Batman!

    Friday, 31 May 2013

    Security Round-Up

    China Training Army for Cyberwar

    According to the state-sponsored news outlet Xinhua, the Chinese military will begin digital war games next month in order to train new military units focused on digital warfare.
    This will be the first time the army "has focused on combat forces including digitalized units, special operations forces, army aviation and electronic counter forces," says Xinhua.
    The ramp-up comes amid allegations of cyber-espionage from other world powers.

    Facebook Introduces ‘Verified’ Pages
    Facebook is introducing a new system that promises to verify the authenticity of pages — particularly those of celebrities.

    Starting this week, Facebook will go through their pages and verify them one-by-one. Successfully verified celebrities will receive a blue check mark on their page.
    Though the authentication process will start off as invite-only, Facebook says they plan to allow for applications in the near future.

    Evernote Offers Two-Factor Authentication
    Two-factor authentication is quickly becoming the hot security trend of the season. Now note-taking service Evernote is hopping on the bandwagon as the latest vendor to offer the feature.
    Like Twitter — which also recently added two-factor authentication — Evernote’s second factor will come as an SMS to users’ mobiles. When users look to use Evernote from the web or to install it on a new computer, they’ll be prompted to input a numerical code the service will provide via text message.
    “This combination of something you know (your password) and something you have (your phone) makes two-step verification a significant security improvement over passwords alone.”

    Thursday, 2 May 2013

    Forgot your Facebook password? Ask your neighbor!


    Have you ever given your friend or neighbor an extra key to your house as an emergency backup? Facebook is implementing a similar strategy for lost passwords and I must admit, it’s pretty smart.

    The new program is called “Trusted Friends” and it’s pretty simple. You pick three to five Facebook friends you trust. If you forget your password, you can use them to help you back into your account.
    Once you've set up your trusted contacts, if you ever have trouble logging in, you'll have your trusted contacts as an option to help. You just need to call your trusted contacts and let them know you need their help to regain access to your account. Each of them can get a security code for you with instructions on how to help you. Once you get three security codes from your trusted contacts, you can enter them into Facebook to recover your account. [Facebook]
    Of course, this new system will require a little bit of preliminary caution on your part. First, you need to make sure the friends you select are friends you actually trust. I wouldn’t recommend choosing anyone you wouldn’t be comfortable giving the key to your front door. Secondly, you need to make sure these friends know to only give up the security code if you actually call them. I think it's safe to say this system is likely to produce a lot of sketchy activity in the form of fraudulent asks.
    While this is a great system, it’s certainly better to not forget your password in the first place. If you don’t think you can remember it (and that should be tough if it’s a good password), download a password manager like 1Password or LastPass.

    Try SumRando for free here.