Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Friday, May 21, 2010

social leakage

Social Leakage

Close to a year ago, two scientists reported a serious violation of privacy policies among prominent social networks. They studied Facebook, MySpace, Twitter, LiveJournal, LinkedIn and seven other social networks. Contrary to the privacy policies that each of them adopted, they were leaking personal information to third-party servers that specialize in aggregating internet data for commercial purposes.* The researchers' report is unusually clear and succinct. Its conclusions are damning. Yet, at that time, news organizations paid no attention.

The report is On the Leakage of Personally Identifiable Information Via Online Social Networks (pdf), Aug 2009, by Balachander Krishnamurthy and Craig E. Wills. The credentials of the authors are good. One works at AT&T Labs in the Research Dept. and other is from Worcester Polytechnic Institute in Mass.

Looking back, now, I can find only one instance in which the report was picked up and disseminated: Social network privacy study finds identity link to cookies (Aug 2009). Nine months have gone by and, I guess it's fortunate for us, a major news outlet has finally taken notice: Facebook, MySpace Confront Privacy Loophole by Emily Steel and Jessica E. Vascellaro, Wall Street Journal, May 21. 2010. And fortunate also that other news sources have begun to play catch-up. My favorite of these: The billionaire Facebook founder making a fortune from your secrets (though you probably don't know he's doing it).

The original report
is worth reading. Do spend ten minutes of your time on it. It gives the social networking sites the benefit of the doubt in guessing that poor coding practice rather than devil-may-care greed was the reason personal data became exposed to third parties. It's really not difficult to mask that data so it's disheartening, but I guess not surprising, that the researchers gave their findings to the social networking sites last August and none then responded. Only now, contacted by the authors of the WSJ article, have they, for the most part, claimed to have fixed or be in the process of fixing the problems.

It also doesn't surprise that, as you've no doubt noticed, the press is now reporting that Facebook is expected soon to announce an abrupt about-face in its privacy policies.


{source: the Masalai blog}


-----------

*Notice that the report says
Although we focus on OSNs [online social networks, like Facebook] in this study, it should be obvious that the manner of leakage could affect users who have accounts and PII [personally identifiable information] on other sites. Sites related to ecommerce, travel, and news services, maintain information about registered users. Some of these sites do use transient session-specific identifiers, which are less prone to identifying an individual compared with persistent identifiers of OSNs. Yet, the sites may embed pieces of PII such as email addresses and location within cookies or Request-URIs. We have carried out a preliminary examination of several popular commercial sites for which we have readily available access. These include books, newspaper, travel, micropayment, and e-commerce sites. We identified a news site that leaks user email addresses to at least three separate thirdparty aggregators. A travel site embeds a user’s first name and default airport in its cookies, which is therefore leaked to any third-party server hiding within the domain name of the travel site. By and large we did not observe leakage of user’s login identifier via the Referer header, the Cookie, or the Request-URI. It should be noted that even if the user’s identifier had leaked, the associated profile information about the user will not be available to the aggregator without the corresponding password. Our preliminary examination should not be taken as the final answer on this issue. A thorough understanding of the scope of the problem along with steps for preventing leakage in general remains a primary concern. Any protection technique must effectively ensure de-identification between a user’s identity prior to any external communication on any site that requires logging in—OSN or otherwise.

Thursday, May 13, 2010

cruft, dandruff, and predictive models

Facebook and its principle founder, Mark Zukerberg, are taking a good deal of heat lately about changes that affect users' ability to keep things out of public view. Despite some overblown rhetoric, there's some real basis for concern.

Am I worried? Yes, a bit. In FB as in life in general, I try to be cautious but not compulsively private in sharing information about myself. I don't do much FB statusing and adjust my settings every time I hear there's been a privacy change. I realize, must not we all, that there's much available about me which I can't control. I try to surrender my social security number as little as possible and it used to annoy me that my work ID contained an SSN barcode. It concerns me that financial institutions have required I give it to them when I've applied for a credit card, opened an account, or applied for a mortgage. I know that my accounts with utility companies, wireless & landline phone providers, and my ISPs yield up publicly available information about my use of their services. Many companies with which I do business accumulate information about me which they can, and under certain circumstances, freely do share. When I've bought the homes I've lived in, a whole raft of information became publicly available about the transactions.

I used to be amazed at how sloppy some organizations were about account data; quite often I found I could search membership data in unprotected files. That's less common now, but no matter how grand a privacy policy sounds, I know I really can't control what an organization does with the personal information I give it. Despite good intentions, some are inept or maybe just naïve. And any commercial enterprise is liable to be bought out by some other organization which can choose to ignore whatever privacy promises the old org. made. Even nonprofits get absorbed by others or go commercial with resulting nullification of whatever policies they had.

I suspect most of us know that the computer we're using supplies information about itself when we're online. There are a number of web sites that show you this info, this one, for example. You probably also know that programs which put spyware in web cookies can accumulate a whole lot more about your internet sessions.

It's the business of data snoops to accumulate this information along with every thing else they can tag as pertaining to you, your computer, and the use you make of it. Many people now assume that all their email traffic is subject to either machine or human inspection, or both.

These are some of the reasons people are growing increasingly concerned about recent changes in Facebook's privacy policy. Facebook is a huge success and, in using it, its vast numbers of participants give enormous amounts of information about themselves — that's the point of this primo social network. The potential for abusing that information is also very great. I've noticed that Facebook apps are increasingly apt to have invasive elements in them and the recent furore is mostly about FB's policy of making certain info you give FB available to all its users, certain of it accessible to search engines outside FB, and certain of it available to FB advertisers; it's also about the complexity of privacy controls and gaps in what you can keep from public view; and it's about the difficulty of getting off FB and deleting what you've put there.

Columbia law professor Eben Moglen summarized the risk in a speech last February:
The Problem is the Cruft and Data Dandruff of Life: In fact the degree of potential informational inequality, and disruption and difficulty that arises from a misunderstanding, a heuristic error in the minds of human beings about what is and is not discoverable about them, is now our biggest privacy problem. My students ... show constantly in our dialog they still think of privacy as the one secret they don't want revealed. But that's not their problem. Their problem is all the stuff that's the ... data dandruff of life, which they don't think of as secret at all but aggregates to stuff they don't want to know. Which aggregates not just to stuff they don't want other people to know, but to predictive models about them which they would be very creeped out to know exists at all. The data that we infer is the data in the holes between the data we already know if we know enough things.
This isn't very precise, but captures the main cause of concern. A whole mess of facts, each by itself benign, can be assembled and put to a nasty purpose.


{sources: PCWorld, ipao.org, }

Here are some links about the current noise regarding Facebook.
Has Facebook gone too far this time? (SocialMedia.biz)

Weekly Wrap-up: Deactivating Facebook, Social Oversharing, iPad vs. Netbooks, And More... (ReadWriteWeb)

Facebook Privacy: A Bewildering Tangle of Options (New York Times)

Could a start-up called Diaspora knock Facebook off its perch? (Christian Science Monitor)

Facebook's Washington Problem, The social network is facing a privacy backlash that could prompt congressional hearings (Business Week)

Europe slams Facebook's privacy settings (Agence France Presse)

Facebook Gives Us Statement On Latest Zuckerberg IM And Company Privacy Policy (SFGate)

Facebook Privacy: A Bewildering Tangle of Options (NYT again)

19-Year-Old Facebook CEO Didn’t Take Your Privacy Seriously, Either (Gizmodo)

Facebook: Facts You Probably Didn’t Know (Mashable)

Facebook confirms informal company meeting (CNET News)

Mum's the word from all-hands Facebook company meeting on privacy (NetworkWorld)

Facebook downplays privacy crisis meeting (BBC)

Facebook caves in to privacy pressures; Sort of, partly (Inquirer)

Your public Facebook status updates? Now publicly searchable outside Facebook (TechCrunch)

Anti-Facebook project rockets to $120,000 in online donations (VentureBeat)

Blogrunner Facebook news snapshot (NYT)

Facebook downplays privacy crisis meeting

This Is MySpace’s Moment To Shine, But That Obviously Isn’t Going To Happen (TechCrunch)

Facebook Adds Two Privacy Tools (Information Week)

Are privacy concerns causing an about face on Facebook? (MassHighTech.com)

How to delete your Facebook account forever (GeeshuiLiving.com)
NY Times Graphic on Privacy Settings


{click to view full size; source: Facebook Privacy: A Bewildering Tangle of Options (New York Times)}

-----------

Incidentally:

Mark Zuckerberg was born in White Plains, which is not far east of the path taken by the old Croton Aqueduct, and he was raised in Dobbs Ferry through which the aqueduct passed on its way to Manhattan. The green line marks its route. Click image to view it full size.


{USGS, White Plains, NY Quadrangle, 1938, southwest corner; source: UNH DIMOND LIBRARY
Documents Department & Data Center}


Also, as it happens, my great-uncle Adolph Windmuller and his wife Caroline Hague lived in Dobbs.

I've written a few posts about the aqueduct and Mrs. Hague:

Monday, November 03, 2008

Sinowal

OK. So who was aware that October was National Security Awareness Month? I didn't see any coverage of the event. Today I learn from a link posted on facebook that a huge cache of stolen financial data has been newly discovered. You can read articles in the few papers that picked up this piece of news, but try as you might, you'll find it hard to uncover advice on how to protect yourself against losing your own financial data. Most reporters are content to regurgitate what appears on the blog of the research organization that made the find. And, strangely, that blog post describes the extent of the crime -- as far as known -- but gives no help to individuals who wish to guard against it. Only one reporter seems to have taken the trouble to contact the organization in order to get some advice. He quotes a "manager of identity protection" at the organization, but the directions are pretty vague:
Education is the best defense against Trojans, Brady said. "You can shut down infection points, but that's like playing Whack-a-Mole," he said. "The most important thing is to educate consumers as to the dangers of going to sites they are not supposed to, and of clicking on links in spam e-mails they receive."
That's it; no guidelines on how to identify the dangerous sites; just stay away. And there's little said that might restrain the hapless users who are prone to open spam e-mails. (I've quoted from this article: RSA Cracks Down on Legendary Sinowal Trojan. October 31, 2008, By Richard Adhikari, in internetnews.com.)

Another article adds a bit of extra help: "Users should take every precaution when downloading applications even from reputable sites such as CNet or Softpedia. If the application looks a little shoddy, think twice before installing it onto your PC." Unfortunately the author doesn't say what he means by extra precaution; once you click you're infected. More unfortunately, according to another report, Sinowal mostly uses two Adobe products: Flash and PDF to to attack its victims -- not spam e-mails or file downloads.

It's frustrating.

I've been using a Flash blocker in my browser. I hope that helps protect me. I haven't been cautious about opening pdf files and don't really know how to guard against infection via pfd (maybe download and do a virus scan before opening).

It's also annoying, not just that the articles on Sinowal do little to help you protect yourself against it, but also that the mainstream government security sites are unhelpful. Worse, the US government's primo OnGuardOnline site, uses Flash exclusively to get across its message (and doesn't mention Flash vulnerabilities). That, and the government's main security tracking site US Computer Emergency Readiness Team uses a pdf file to say What Can You Do to Contribute to Cyber Security Awareness? (and uses an opaque CLICK HERE to get us to the pdf without letting us know that it's a pdf we're being taken to).

I'd be grateful for any comfort readers can give me about Sinowal and its many variants and co-conspirators. (I do know that using Microsoft Windows is asking for trouble and don't need to be told that.)



That said, I'm grateful to my son for putting me on to this threat. Much better to know of the threat, even while being unsure about protecting against it.

References:

• Source of image at top: http://tech.blorge.com/

'National Security Awareness Month': October is National Cyber Security Awareness Month, US CERT Press Room


'huge cache of stolen financial data' - A Huge Cache of Stolen Financial Data, NYT, By John Markoff

'what appears on the blog' - One Sinowal Trojan + One Gang = Hundreds of Thousands of Compromised Accountsby RSA FraudAction Research Lab on 10/31/2008

'Another article' - Sinowal Trojan found to have stolen 300,000 bank log-ins, November 1, 2008, by Mike Ferro

'Another report' - Sinowal super trojan empties half million bank accounts, November 1, 2008, by Brian Turner

Worth reading in full: Here are some excerpts from this last report:
Already nearly three years old, the Sinowal trojan - aka Torpig or Mebroot - is typical in its behaviour of trying open up user computers - but with the added twist of phishing user bank accounts. It is being constantly updated with patches to beat security filters - it is also storing up user data on everyone its infects. The main method of delivery isn’t email spam, though, but instead through hacking websites to insert the malicious code onto visitors PC’s. Flash and Adobe hacks have been especially common, and I’ve seen these in action myself. Wordpress blogs have especially become a major target of attack.