Govt.-Backed Contact-Tracing Apps Raise Privacy Hackles

New opt-in COVID-19 Exposure Notifications Express systems baked into Apple’s iOS and available on Android need privacy guardrails, say privacy advocates. Continue reading Govt.-Backed Contact-Tracing Apps Raise Privacy Hackles

There’s a new open-source project to detect cellphone-snooping technology

In October 2016, during popular protests against the Dakota Access Pipeline, a technologist named Cooper Quintin took a red-eye flight from San Francisco to North Dakota and made his way to the Standing Rock Reservation. There had been reports of police surveillance of the protesters, and Quintin suspected that involved a device known as an IMSI catcher or cell-site simulator. The technology, sometimes referred to as a Stingray, spoofs a cellular tower, tricking your phone into revealing its location. From there, data-stealing attacks on the phone are possible. Police and spies use the gear for surveillance. At Standing Rock, Quintin took out his software-defined radio, scanning for abnormal signals, and opened up an Android app known for spotting IMSI catchers. He didn’t get any hits. “I had no idea what I was doing,” said Quintin, a security researcher at the nonprofit Electronic Frontier Foundation. He was using technology designed for […]

The post There’s a new open-source project to detect cellphone-snooping technology appeared first on CyberScoop.

Continue reading There’s a new open-source project to detect cellphone-snooping technology

Researchers to Supreme Court: Terms of service violations shouldn’t be CFAA crime

As the Supreme Court prepares to consider a controversial federal anti-hacking law, a group of prominent cybersecurity researchers and legal advocates is pleading with the court not to criminalize digital research in the public interest. In a brief filed with the court Wednesday led by digital rights group Electronic Frontier Foundation, the researchers warned that if violations of a company’s “terms of service” are deemed to be illegal, it risks chilling important research into voting systems, medical devices and other key equipment. “Despite widespread agreement about the importance of this work—including by the government itself— researchers face legal threat for engaging in socially beneficial security testing,” wrote the EFF, the nonprofit Center for Democracy & Technology, and cybersecurity companies Bugcrowd, Rapid7, SCYTHE and Tenable. Famous security researchers like Peiter “Mudge” Zatko and Chris Wysopal, who warned Congress of the internet’s insecurities in the 1990s as members of the L0pht hacking collective, […]

The post Researchers to Supreme Court: Terms of service violations shouldn’t be CFAA crime appeared first on CyberScoop.

Continue reading Researchers to Supreme Court: Terms of service violations shouldn’t be CFAA crime

During a pandemic, stalkerware becomes even more sinister

When public health experts started recommending social distancing to reduce the spread of COVID-19, the goal was to place people out of harm’s way. But the policy has forced many domestic violence victims to possibly face a far more insidious danger: isolating with an abuser. Security researchers tell CyberScoop that data show a rise in invasive surveillance software known as stalkerware — applications that can spy on partners’ texts, calls, social media use and geolocation information — since the coronavirus pandemic began, despite the fact that abusers are much more likely to be sharing the same living space as their victims. Three antivirus companies tracking stalkerware globally told CyberScoop they saw an increase in stalkerware detections just after governments at all levels put social distancing measures in place. Between January and May, for instance, California-based Malwarebytes and Germany-based Avira said stalkerware detections on their respective customers’ devices spiked by 190% and […]

The post During a pandemic, stalkerware becomes even more sinister appeared first on CyberScoop.

Continue reading During a pandemic, stalkerware becomes even more sinister

Internet freedom activists are concerned a Trump appointee could threaten pro-democracy work abroad

Internet freedom advocates are urging U.S. lawmakers to protect a small government-backed nonprofit that’s funded a generation of secure technologies meant to safeguard data in repressive countries. The organization, the Open Technology Fund, is an 8-year-old outfit that helps develop open and accessible technologies with an eye on promoting human rights abroad. It’s a subsidiary of the U.S. Agency for Global Media, overseer of the government operations designed to beam American news into foreign countries via outlets like Voice of America and Radio Free Asia. After a generation of quietly investing in technologies like encrypted messaging app Signal and anonymity tools like Tails and Tor, the future of the Open Technology Fund suddenly is in doubt. The new CEO of the Agency for Global Media, Michael Pack, a Trump administration appointee and a longtime ally of Steve Bannon, has fired the head of the OTF and the heads of four […]

The post Internet freedom activists are concerned a Trump appointee could threaten pro-democracy work abroad appeared first on CyberScoop.

Continue reading Internet freedom activists are concerned a Trump appointee could threaten pro-democracy work abroad

EFF: Google, Apple’s Contact-Tracing System Open to Cyberattacks

Malicious actors could potentially harvest data over the air and use it to shake confidence in the public-health system, EFF says. Continue reading EFF: Google, Apple’s Contact-Tracing System Open to Cyberattacks

Privacy groups are still trying to get documents unsealed in Facebook encryption case

Civil liberties groups on Tuesday asked an appeals court to unseal a federal judge’s ruling that rejected a U.S. government effort to force Facebook to decrypt voice calls. The American Civil Liberties Union and the Electronic Frontier Foundation argue that the public has a right to know about how U.S. prosecutors tried to force Facebook to decrypt the calls in a 2018 investigation of the MS-13 gang, and why a judge rejected the prosecutors’ effort. The Department of Justice is urging the court to keep the ruling sealed, arguing that making it public could compromise ongoing criminal investigations. It is the latest front in a broader standoff between privacy advocates and law enforcement over access to encrypted communications. Law enforcement officials have for years lamented that strong encryption has hampered investigations into terrorists and criminals. But many technologists say any software especially designed for law enforcement access risks weakening security […]

The post Privacy groups are still trying to get documents unsealed in Facebook encryption case appeared first on CyberScoop.

Continue reading Privacy groups are still trying to get documents unsealed in Facebook encryption case

NIST shared dataset of tattoos that’s been used to identify prisoners

The EFF got in touch with the institutions that have the dataset. Some deleted it, while one refused and others didn’t bother to respond. Continue reading NIST shared dataset of tattoos that’s been used to identify prisoners

Let’s Encrypt issues one billionth free certificate

Thanks to this flood of free certificates, the web is a lot more encrypted than it was a few years ago. Continue reading Let’s Encrypt issues one billionth free certificate

Proposed standard would make warrant canaries machine-readable

For years, organisations have been using a common tactic called the warrant canary to warn people that the government has secretly demanded access to their private information. Now, a proposed standard could make this tool easier to use. Continue reading Proposed standard would make warrant canaries machine-readable