Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, February 20, 2015

Lenovo Superfish Spyware Misstep

If you were one of the 16M consumers in Q4 2014 that recently bought a new Lenovo model before January, and you thought there was a material improvement in the "shopping experience using their visual discovery techniques." it was by design.

Specifically, If you owned one of the models listed in the below Lenovo release, you likely had the Superfish spyware program installed on your machine.  Superfish is spyware program supported by any web browser, which alters your search results to show you different ads than you would otherwise see.

Superfish also tampers with your computer's security enabling online attackers to track your web traffic, obtain sensitive information, such as your online banking details, and even infiltrate your computer.

Lenovo has since made a significant PR and operational scramble to rectifiy the situation by making consumers aware of the security concerns and provide details on how to uninstall the program. 

Yet, this incident clearly raises a more fundamental issue relating to delicate element of trust that plays a key part in the digital marketing ecosystem. With the publishing side of digital advertising already affected by the conerns of online fraud, rattling the consumer's confidence with potential security threats is clearly does not inspire confidene in a growing industry.

Wednesday, July 09, 2014

How to send sensitive information via email

Following our discussion in our last class about email security, here is an easy way how to protect your data when you send it:

  1. You put the confidential information into a document (e.g., a spreadsheet, a zip file, ...)
  2. You encrypt the document so that it cannot be viewed without a password (Excel spreadsheets or zip files can be password protected when saved)
  3. You email the encrypted document to the recipient as an attachment
  4. You communicate the password to the recipient by some other means, preferably not by email, and certainly not by the email to which you attached the encrypted document
  5. The recipient uses the password to decrypt the document

An alternative to this is sending the sensitive through a secure send service like OneShar.es that lets you create a secure, self-destructing message.

Lifehacker put together a few idea how to send data more securely from A to B: http://lifehacker.com/5910408/from-saucy-pics-to-passwords-how-to-share-sensitive-information-over-the-internet


Friday, September 30, 2011

Cloud powered facial recognition is terrifying

http://www.theatlantic.com/technology/archive/2011/09/cloud-powered-facial-recognition-is-terrifying/245867/

New facial recognition software co-developed by Carnegie Mellon and Google is able to match your photo to your entire online presence in just minutes. The technology sources your information from the wealth of information that people have made available on various social networking sites such as LinkedIn, Facebook, Google+ and also other web sources such as university and professional/company pages.
Interestingly, the implications of the software go beyond matching a face to personal data. Scientist were able to show that machine intelligence could be applied to the personal data to make predictions and inferences about the individuals. An example was presented where the facial recognition software was combined with another piece of software which predicted Social Security Numbers based on personal data such as age, geographic location, etc. By combining the two applications together researchers were able to determine an individuals social security number starting from a simple, anonymous photo.

Saturday, January 30, 2010

Your money or your (social) life!

If you were a black-hatted hacker, what kind of devious malware would you spend your time writing- a program that cracks my bank account or a program that steals my twitter password? Easy choice, right? It may surprise you to learn that hacker-invented malware programs that steal social networking account information outnumber similar programs directed at stealing bank passwords nearly three to one, and the margin appears to be growing, according to a recent study by Kaspersky Labs.

This makes some sense. Rather than march me to my own ATM at the point of a gun, hackers could pretend to be me and then fleece all 426 of my facebook friends at once. Call it an investment in their future. Dirtbags.

Related story in the New York Times is here.