Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, 19 November 2019

iOS 13.2 Facebook App Uses Camera Without The User Noticing

#accountsprotection #io13 #facebook  #camerausing #wilirax #wiliraxblog  #userissues #privacy #privacypolicy,

It's been a while since you can use almost any social networking app to take photos or record videos. But the Facebook app for iPhone is using the camera even as you browse the news feed.

The discovery was made by user Joshua Maddux and shared on his Twitter account. The problem comes when he opens a profile photo in the social network app - when the image closes, the feed is misaligned, and on the left edge of the screen, images taken by the camera appear.


The site The Next Web has tested and confirmed that the screen with camera images appear on iPhones running iOS 13.2.2, but not in iOS 13.1.3. On Android, this does not happen either. The site also says that if the user has not authorized the app to access the camera, iOS blocks its use. As another user pointed out, this little bit of the screen that appears is the add story screen. Most likely, a bug is misaligning the app interface and exposing it.

#accountsprotection #io13 #facebook  #camerausing #wilirax #wiliraxblog  #userissues #privacy #privacypolicy,



Still, that leaves a question in the air: will Facebook, made by a company that does not have the best historical in issues of privacy, is using my camera without my knowing? A story from The Next Web of 2017 itself says that any app that has camera access on iOS can make recordings without the user noticing.

So far, neither Facebook nor Apple has spoken out.

Friday, 25 October 2019

Best Techniques Protecting Your Accounts from Hackers - Oct 2019


Best Techniques Protecting Your Accounts from Hackers - Oct 2019 by wilirax


It's easy to be a security pessimist.

Hackers and data breaches make headlines all over the internet every day. Is there anything an average person can do to protect themselves?

Actually yes. A simple and easy step, such as enabling strong multifactor authentication, turns out to be an extremely effective way to secure your online accounts. A new study from Google, the University of New York, and the University of California, San Diego, shed new light this week on how powerful some protections can be.

The researchers looked at multifactor authentication tools such as physical security keys, the device prompts, and text messaging to find out how these techniques protect you. The conclusion: very well.

The most effective tool you can have to prevent someone from stealing your account is a security key. That way, a site like Google can ask for more proof of who you are beside your password. Companies like Yubico, Feitian and, yes, Google make these security keys.

This technique prevented 100% of attempted attacks on accounts of all kinds in the one-year study. Last year, Google said there has been no breach of its employees' account since they began using security keys.

This tool is used by journalists, politicians, human rights defenders and people whose cybersecurity can be a matter of life and death. But don't let this 100% number fool you - not perfect, as Google's recent incident with its Titan keys and a Bluetooth vulnerability proves - but it's extremely powerful. And most importantly, the keys are also economically accessible.

Best Techniques Protecting Your Accounts from Hackers - Oct 2019 by wilirax


Another strong option is the prompt on the device. Many important online accounts allow you to use authenticating apps like Google Authenticator or, like Gmail, in-app prompts that help prove your identity to the platform. This tool fights 100% of automated attacks, 99% of mass phishing attacks, and 90% of specifically targeted attacks, according to research group findings.

Last week we talked about how to text message two-factor authentication is relatively weak compared to easy alternatives. The Google study confirmed this idea: SMS codes are less effective than device prompts or security keys. But they are still much more effective than having no multifactorial authentication. The researchers found that SMS codes countered 100 percent of automated account hijacking attempts, 96 percent of mass phishing attacks, and 76 percent of targeted attacks.

The study also looked at other account attack prevention tools.

"Our research shows that simply adding a recovery phone number to your Google Account can block up to 100% of automated bots, 99% of bulk phishing attacks, and 66% of targeted attacks that occurred during our investigation," wrote the researchers Kurt Thomas and Angelika Moscicki.

Adding a secondary email address is another positive step that makes account hacks much less likely, research shows.

Being pessimistic about security is understandable, but being realistic may be better for your digital health. Stay informed, take some simple and effective measures and stay as well protected as possible.

Thursday, 17 October 2019

US $5 For A Hidden Face Scan




For participation in mini-game volunteers were given a coupon for $ 5. That this was a face scan on behalf of Google, they were hiding. With the scans, a new function for the Pixel 4 is to be realized.



On October 14, 2019 Google's new smartphone Pixel 4 appear. The phone should also be unlocked with the face of the user - for this to work, Google has commissioned a company to build in a "field trial" a database of 3D face scans. The company is said to have worked with unfair methods, reports The New York Daily News. In response to reporting, Google has completed the controversial field trial.

They wanted to look for homeless people and students, especially those with dark skin, according to several Randstad employees employed as temporary workers in Google's controversial field trial. Their face was to be scanned for as diverse as possible face database - it was the volunteer participants often not at all clear that a 3D scan of their face was performed. In the end, the participants received a coupon for 5 US dollars.

Randstad's staff have been told to cover up the fact that the face is being scanned. They were explicitly told to lie to increase the number of scanned faces. For example, they should present the face scan as a mini-games or "selfie game" as in Snapchat. They should include phrases like "Just play with the phone for a few minutes and get a coupon" or "We have a new app, try it out and get 5 dollars" say. The temporary workers of Randstad employees were told to hide the fact that the user's face is taken. Also on-demand, they should deny that pictures or videos were taken.

Rather, they overwhelmed the subjects by infecting them with information and encouraging them to quickly click buttons or look left or right. One goal was to keep the participants from reading the consent form, reports one employee.

The agreement grants Google an extensive, worldwide right to use facial scanning: There was no limit to how long Google's data could be kept. They would be kept as long as necessary, which would probably be five years, the statement said. The Statement also allows "non-personal identifiable or collected data to be stored, used or shared without restriction for any purpose" and that the data could be processed "outside the country", including places "where you may have fewer rights", reports The New York Daily News.

There was no question of a facial scan
"We had to follow a point with the nose," said an 18-year-old student who had participated in the trial. Some students were asked if they wanted to take a survey or test an Android phone. From a face, a scan was not mentioned.

A Google spokesperson said that the company is gathering data through field research to build its face recognition capability "with robust security and performance ." "Our goal, in this case was to make sure that we have a fair and secure function that works across different skin tones and facial shapes," Google told The New York Times. Google managers are also said to have been involved in Randstad's telephone conferences regularly, covering many aspects of data collection and review, including the mandate to pursue "darker skin tones," a former employee said.