Страницы

Showing posts with label Data security. Show all posts
Showing posts with label Data security. Show all posts

Sunday, August 30, 2020

Data security

How to Protect the Data on Your Laptop


room with laptops on tableMake sure you have your own user account set up on your laptop, even if you're the only one who uses it—not only will this keep the kids from messing up your browser bookmarks when they want to play games, it'll also stop anyone else from accessing it. Even if your laptop gets stolen, if there's a password-protected user account on it, there's not much a thief can do beyond resetting it and wiping the data.
Microsoft and Apple know it's important, so you'll find it difficult to set up a new laptop without a user account, but avoid sharing accounts with other people or leaving them unprotected. You can manage user accounts from Accounts in Settings in Windows (via the cog icon on the Start menu), or from Users & Groups in System Preferences (under the Apple menu) on macOS.

Saturday, July 4, 2020

Data security

Protecting undersea cables must be made a national security priority

Data is arguably the most important strategic asset to emerge in the 21st century. Access to data and the ability to protect its integrity are vital to American security and prosperity. As 5G and artificial intelligence transform our societies into highly integrated networks, protecting data will become even more crucial.
In recent years, American efforts have focused on preventing Huawei, the party-controlled Chinese telecommunications giant, from gaining ground as the world’s largest supplier of 5G infrastructure. But defending a less understood part of our digital infrastructure — undersea fiber-optic cables — should be an equal priority. Without the approximately 750,000 miles of cables that crisscross the world’s oceans, our interconnected, digitally driven societies would be unable to function.
In 1858, when the first submarine cable was installed, sending a message across the Atlantic took nearly 18 hours. Today, the fastest undersea cables can transfer data at speeds upward of 25 terabytes per second — more than twice the amount of data generated by the Hubble Space Telescope each year.

Sunday, December 29, 2019

Data security

EU crisis: Von der Leyen under pressure over Germany scandal after phone wiped of evidence

Ursula von der Leyen Angela Merkel, Germany’s former defence minister and a close ally of Chancellor , only took up her new post at the  at the start of the month. She insisted she has nothing to hide - but she is nevertheless being investigated by a German parliamentary committee, to whom she is scheduled to give evidence next month.
The controversy centres on how lucrative defence contracts were awarded to outside consultants without proper oversight, as well as claims that the deals were facilitated by a network of personal contacts, according to Politico.
Grilled by German newspaper Spiegel on the matter, she insisted she was not concealing anything, adding: "I've turned in both mobile phones that I used as defence minister.
"You'll have to ask what happened to them there. The devices belong to the ministry, so they had to be returned."
She said she had only learned about the data deletion “from the papers”, adding: "I haven't been in the ministry since July 17th.”
The committee investigating the contracts, which will question Mrs von der Leyen on February 13, believes text messages on the device may shed light on what if anything she knows about the scandal.

Sunday, March 24, 2019

Data security

Facebook seeks to suppress documents showing what it knew about Cambridge Analytica

Facebook chief Mark Zuckerberg
Facebook is attempting to suppress documents which US investigators claim would show how much it knew about Cambridge Analytica before its harvesting of data was first publicly reported.

The social network has asked a judge to keep secret an email chain in which employees discussed how Cambridge Analytica was getting data from its service and whether it was breaking its policies.

Facebook has long maintained that it only found out about the transfer of user data to Cambridge Analytica from another company, which was the source of the scandal, when it was detailed by the Guardian in December 2015.

But the city of Washington DC claims that the email chain, unearthed as part of a consumer protection...





Saturday, March 23, 2019

Data security

This Spyware Data Leak Is So Bad We Can't Even Tell You About It

A company that sells consumer-grade software that lets customers spy on other people’s calls, messages, and anything they do on their cell phones left more than 95,000 images and more than 25,000 audio recordings on a database exposed and publicly accessible to anyone on the internet. The exposed server contains two folders with everything from intimate pictures to recordings of phone calls, given that the app markets itself mostly to parents.
Troy Hunt, a researcher who maintains the breach database Have I Been Pwned?, analyzed the database and said that there were around 16 gigabytes of images and around 3.7 gigabytes of MP3 recordings in it. Motherboard confirmed his analysis. (It’s hard to say how many unique pictures and recordings there are, however. Some pictures appear to have been uploaded multiple times.)
This breach is just the latest in a seemingly endless series of exposures or leaks of incredibly sensitive data collected by companies that promise to provide services for parents to keep children safe, monitor employees, or spy on spouses. In the last two years, there have been 12 stalkerware companies that have either been breached or left data exposed online: Retina-X (twice), FlexiSpy, Mobistealth, Spy Master Pro, SpyHuman, Spyfone, TheTruthSpy, Family Orbit, mSpy, Copy9, and Xnore.

Thursday, March 14, 2019

Data security

US conducts criminal investigation into Facebook's data deals

Investigations into Facebook's data handling keep piling up. The New York Times has learned that federal prosecutors are in the midst of a criminal investigation into the data deals Facebook arranged with tech companies. It's not known when the investigation began or just what the focus is, but a New York grand jury reportedly used subpoenas to obtain records from two or more "prominent makers of smartphones." The deals included heavyweights like Apple, Microsoft and Sony.

Facebook acknowledged the investigation to the Times, stating that it was "cooperating with investigators" and was taking probes "seriously."

The deals typically revolved around making it easier to fill out contacts, share content and otherwise integrate Facebook with devices and websites. There's a concern that these deals weren't always transparent to everyday users, though. Microsoft's Bing deal mapped the friends of Facebook users without explicit permission, for instance. The FTC is believed to be negotiating a fine with Facebook over alleged violations of a 2011 privacy agreement, but not necessarily over those deals. Investigators may be using a criminal case to address concerns other agencies haven't already covered.

Sunday, March 3, 2019

Data security

Massive Database Leak Gives Us a Window into China’s Digital Surveillance State


Earlier this month, security researcher Victor Gevers found and disclosed an exposed database live-tracking the locations of about 2.6 million residents of Xinjiang, China, offering a window into what a digital surveillance state looks like in the 21st century.  Xinjiang is China’s largest province, and home to China’s Uighurs, a Turkic minority group. Here, the Chinese government has implemented a testbed police state where an estimated 1 million individuals from these minority groups have been arbitrarily detained. Among the detainees are academics, writers, engineers, and relatives of Uighurs in exile. Many Uighurs abroad worry for their missing family members, who they haven’t heard from for several months and, in some cases, over a year.  Although relatively little news gets out of Xinjiang to the rest of the world, we’ve known for over a year that China has been testing facial-recognition tracking and alert systems across Xinjiang and mandating the collection of biometric data—including DNA samples, voice samples, fingerprints, and iris scans—from all residents between the ages of 12 and 65. Reports from the province in 2016 indicated that Xinjiang residents can be questioned over the use of mobile and Internet tools; just having WhatsApp or Skype installed on your phone is classified as “subversive behavior.” Since 2017, the authorities have instructed all Xinjiang mobile phone users to install a spyware app in order to “prevent [them] from accessing terrorist information.”

Wednesday, February 27, 2019

Data security

Dow Jones’ watchlist of 2.4 million high-risk individuals has leaked


watchlist
A watchlist of risky individuals and corporate entities owned by Dow Jones has been exposed, after a company with access to the database left it on a server without a password.
Bob Diachenko, an independent security researcher, found the Amazon Web Services-hosted Elasticsearch database exposing more than 2.4 million records of individuals or business entities.
The data, since secured, is the financial giant’s Watchlist database, which companies use as part of their risk and compliance efforts. Other financial companies, like Thomson Reuters, have their own databasesof high-risk clients, politically exposed persons and terrorists — but have also been exposed over the years through separate security lapses.
A 2010-dated brochure billed the Dow Jones Watchlist as allowing customers to “easily and accurately identify high-risk clients with detailed, up-to-date profiles” on any individual or company in the database. At the time, the database had 650,000 entries, the brochure said.


Sunday, January 20, 2019

Data security

Giant Data Breach: 773 Million Passwords and Email Addresses

data breachMore than 87GB of passwords and email addresses have been leaked and distributed in a folder dubbed “Collection #1” by hackers in a significant data breach. If you’re in this breach, one or more passwords you’ve previously used are floating around for others to see.
Nearly 22 million unique passwords and more than 772 million email addresses was hosted on cloud storage service MEGA. The link to the dump was posted on a hacking forum, but has been since taken down from the service, according to mashable.com.
Troy Hunt, a security researcher, explains the cache of emails and passwords were built up from numerous data breaches from allegedly thousands of sources, dating all the way back to 2008.
In total, there are 1,160,253,228 unique combinations of email addresses and passwords, according to troyhunt.com. The unique email addresses totalled 772,904,991. There are 21,222,975 unique passwords.

Wednesday, January 9, 2019

Data security

Russia’s Kaspersky Lab Helped Catch an Alleged NSA Data Thief: Report


Kaspersky Lab, the Russian cybersecurity firm that the U.S. government has deemed a threat to this country, was the source of tip to the National Security Agency that led to an arrest in what some have said is the largest breach of classified material in U.S. history, Politico reports. The Moscow-based firm reportedly turned the accused, Harold T. Martin III, a former NSA contractor, after receiving strange Twitter messages in 2016 from an account linked to him. Kaspersky’s role in exposing Martin is one of many twists in the case. Martin took home an estimated 50 terabytes of data from the NSA and other government offices over a two-decade period, including some of the NSA’s most sophisticated and sensitive hacking tools, prosecutors said.


Monday, January 7, 2019

Data security

German cyber defense agency defends handling of data breach

Aufgaben des BSI
Germany’s BSI cyber defense agency on Saturday defended its role in responding to a far-reaching data breach, saying it could not have connected individual cases it was aware of last year until the entire data release became public.

The government said on Friday that personal data and documents from hundreds of German politicians and public figures including Chancellor Angela Merkel had been published online, in what appeared to be one of Germany’s biggest data breaches.

The incident has shocked the establishment and prompted calls for security agencies to clarify whether any security deficiencies they were aware of had been exploited, and if they could have acted sooner to head off the breach.

The BSI said in a statement that it was contacted by a lawmaker in early December about suspicious activity on their private email and social media accounts.

Saturday, January 5, 2019

Data security

10 Largest Data Breaches in 2018

data breaches
Data breaches compromised the personal information of millions of people around the globe in 2018. Data breaches are security incidents in which information is accessed without authorization. They  can happen for a variety of reasons, e.g. hacking, data can be mishandled or sold to third parties, holes in a website’s security system, etc.
The data breach that caused the largest number of users affected was against India government ID database.
Here are the 10 biggest data breaches that were revealed this year, ranked by the number of users affected, according to businessinsider.com:
10. Facebook — 29 million
This breach affected highly sensitive data, including locations, contact details, relationship status, recent searches, and devices used to log in between July 2017 — September 2018.
“The hackers were able to exploit vulnerabilities in Facebook’s code to get their hands on ‘access tokens’ — essentially digital keys that give them full access to compromised users’ accounts.
9. Chegg — 40 million
Personal data including names, email addresses, shipping addresses, and account usernames and passwords were affected. An unauthorized party gained access to an American education company database that hosts user data, according to ZDNet...

Monday, January 29, 2018

Data security

Security threat? Fitness devices could give away locations of soldiers

A U.S. soldier runs at a coalition forces forward base near West Mosul, Iraq this past June.
An interactive map tracking the location and activities of people using fitness devices like Fitbit has raised concerns about the security of soldiers and civilians at U.S. military bases around the world, The Washington Post reported Sunday.

The Global Heat Map, published by the GPS tracking company Strava, uses satellite information to map the locations and movements of subscribers to the company's fitness service by illuminating areas of activity.

The map shows a great deal of activity in the U.S. and Europe. But in war zones and deserts in countries such as Iraq and Syria, the heat map becomes almost entirely dark -- except for scattered evidence of activity.

A closer look at those areas brings into focus the locations and outlines of well-known U.S. military bases, as well as other lesser-known and potentially sensitive sites -- possibly because American soldiers and other personnel are using fitness trackers as they move around.

The map is not live, but shows a pattern of accumulated activity between 2015 and September 2017.

Friday, September 29, 2017

Data security

National security relies more and more on big data. Here’s why.

Data are a defining feature of modern society. Every day, humans and the machines they interact with create 2.5 trillion megabytes of data. As data become more prominent and readily available, the temptation to analyze them and make sense of the world through specific analytics methods or algorithms grows.
This is particularly true for national security. Big data is a “big deal” for U.S. spy agencies, which have long relied on multiple data sources to produce intelligence reports. In the past decade, agencies like the CIA and the NSA have institutionalized big data through the development of dedicated analytics units and research and development projects focusing on the analysis of online data such as YouTube videos and social media posts.

Wednesday, May 31, 2017

Data security

US military data reportedly left on unsecured Amazon server

Highly sensitive military data about a US intelligence agency project has been discovered on a publicly accessible server without password protection, according to a new report.
UpGuard said Wednesday an analyst with the security firm discovered tens of thousands of documents last week on an Amazon cloud server that are connected to the US National Geospatial-Intelligence Agency (NGA), the US military's combat support agency. Credentials found in the exposed files suggest the data was uploaded to the cloud by defense and intelligence contractor Booz Allen Hamilton, UpGuard reported.
The files included the log-in credentials that could have provided access to more sensitive data, including code repositories, UpGuard said.
Booz Allen has a large presence at US intelligence agencies. The company has a workforce of about 22,600, and 69 percent of its workers hold security clearances with US intelligence agencies, according to company tax filings. Booz Allen generated $1.3 billion in revenue from contracts with US intelligence agencies, including the NSA, in the fiscal year ending in March 2016.

Wednesday, May 3, 2017

Data security

Jon Lawrence: National security? Data laws misused to spy

ATTORNEY-GENERAL George Brandis told us in ­November  2014 the data retention regime ­“applies only to the most ­serious crime, to terrorism, to international and transnational organised crime, to paedophilia, where the use of metadata has been particularly useful as an investigative tool, … only to crime and only to the highest levels of crime”.
The mandatory data retention legislation was duly rushed through the parliament in March 2015 at a time of “heightened national security concern”. Remember all those flags?
But the claim that it was all about national security and child predators, was, of course, far from the complete truth. Telecommunications data — more commonly, metadata — is also extremely useful in identifying the source of government leaks and for tracking down whistleblowers.

Thursday, February 2, 2017

Data security

FSB promotes greater cooperation between state & business over data security


FSB promotes greater cooperation between state & business over data security
A senior representative of Russia’s Federal Security Service says the agency has prepared a bill to put additional responsibility on businesses that own critical elements of the national data structure, adding the state alone cannot guarantee protection.
The deputy head of the FSB’s Center for Communications Security, Nikolay Murashov, made the announcement on Thursday in the course of the Infoforum-2017 national conference dedicated to data security.
“Business must understand its responsibility for disturbing the process of data management that could trigger the domino effect. Various terrorist and extremist groups are actively creating and perfecting the means to attack the objects of critical infrastructure,” the official said.
He noted that FSB experts estimate the damages inflicted by hacker attacks worldwide as between US$300 billion and $1 trillion over the past few years. This amounts to 0.4-1.5 percent of combined global GNP.

Saturday, July 2, 2016

Data security

US Air Force Loses Investigation Database

We have recently written about the mind staggering fact that the Pentagon still uses floppy disks to perform nuclear missions. This new story is another unbelievable technical blunder on behalf of the world’s richest armed forces.
The US Air Force has lost records of fraud and abuse investigations going back to 2004 due to a corrupted database, Defense One reports. About 100,000 records disappeared into thin air, and while the database has been recovered, the Air Force doesn’t know why it happened.
The database, and backups, that hosts files from the Air Force’s inspector general and legislative liaison divisions became corrupted in May. Neither Lockheed Martin, the defence contractor who maintained the database, nor the Air Force itself can say with any certainty why that happened. Lockheed, apparently, spent two weeks trying to recover the information before notifying the Air Force of the calamity.

Wednesday, July 8, 2015

Data security

FBI, Justice officials take encryption concerns to Congress


Картинки по запросу encryptionFederal law enforcement officials warned Wednesday that data encryption is making it harder to hunt for pedophiles and terror suspects, telling senators that consumers’ right to privacy is not absolute and must be weighed against public-safety interests.
The testimony before the Senate Judiciary Committee marked the latest front in a high-stakes dispute between the Obama administration and some of the world’s most influential tech companies, placing squarely before Congress an ongoing discussion that has shown no signs of an easy resolution. Senators, too, offered divided opinions.