With huge controversies surrounding data mining and the collection of your personal data being talked about frequently, where do we draw the line when we're not using a computer? Starter-interruption devices allow the lender to shut off your car remotely if you're behind on your bills. I think this raises ethical concerns for some, and for others it just makes them frustrated that companies are even allowed to do this in the first place. Instead of just having a fee imposed on the borrower, they're also now going to start shutting off your vehicle when you can't pay your bills. And for a vast majority of us, we need our car to get to work to make money to pay our bills. My concern is that technology is beginning to advance at such a fast past, that we're starting to create things that we should otherwise avoid.
This concept is similar to your utility bills, which also get shut off when you're behind on your payments. However, most utility companies won't shut off your electricity when you're behind on your payment by 24 hours. Some of the lenders that are using these starter-interruption device are doing just that though. To most this seems very unfair, especially during tough economic times. My question is can we and if so where do we, draw the line with technology?
Sources:
NY Times
CBS
New "Shellshock" Bug Identified
A new flaw found in the Unix Bash shell has recently been identified by Akamai. This vulnerability has been around for over 2 decades now, but is just now being uncovered. That's a crazy thought, it took 22 years for someone to find a small flaw in such a widely used platform. This bug can effect Linux, OS X machines, routers, and older IoT devices. This exploit is said to be easily used by hackers, however most devices now use busybox, which has not been made vulnerable. My first reaction was, how did this go undetected for so long. I then did some research to find that Bash is entirely maintained by one person, Chet Ramey.
I think it's important to note that this bug was not being used maliciously prior to being discovered. I also feel that most people don't use Linux, OS X or routers running Bash anymore, unless they own a business. So as far as the public should be concerned, I don't think there should be much of a scare to this bug for personal use, unless something gets vastly exploited or more vulnerabilities become detected. However, businesses and the government agencies with older systems, do have to worry a lot.
Souces:
PC World
Wired
I think it's important to note that this bug was not being used maliciously prior to being discovered. I also feel that most people don't use Linux, OS X or routers running Bash anymore, unless they own a business. So as far as the public should be concerned, I don't think there should be much of a scare to this bug for personal use, unless something gets vastly exploited or more vulnerabilities become detected. However, businesses and the government agencies with older systems, do have to worry a lot.
Souces:
PC World
Wired
Apple Unveils New Privacy Policy
Apple is seemingly trying to comfort their users who have had many concerns about their personal information being shared and viewed by others. Many of these concerns stem from what Edward Snowden has disclosed about the NSA. Tim Cook (Apple's CEO) recently stated on Apple's new privacy section of their website "I want to be absolutely clear that we have never worked with any
government agency from any country to create a backdoor in any of our
products or services. We have also never allowed access to our servers.
And we never will." Regardless of whether or not this information is entirely true or not, he also took a stab at Microsoft when Cook was quoted saying "Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data." All of this seems to be pointing in the right direction, however it's unclear whether or not Apple is going to be true to their word or if there will be a loophole in their statement.
Apple stated that your personal data which now includes your photos, messages, emails, contacts, call history, iTunes content, notes and reminders are being placed under their new privacy policy. I think that everything on your cell phone should be considered yours, and that the government should not be allowed to view any of the information on the device. I hope that other companies follow suit and start to create similar privacy policies for their users.
Sources:
Wired
NT Times
Apple stated that your personal data which now includes your photos, messages, emails, contacts, call history, iTunes content, notes and reminders are being placed under their new privacy policy. I think that everything on your cell phone should be considered yours, and that the government should not be allowed to view any of the information on the device. I hope that other companies follow suit and start to create similar privacy policies for their users.
Sources:
Wired
NT Times
CA Bill: Data Mining Students
California has recently unanimously passed a monumental bill which protects students’ personal data. The senate bill would stop online services from selling or disclosing students’ data. This includes everything from students’ attendance records, health information, disciplinary action history, family history, biometrics, and their academic information. This is a huge step in the right direction for all students. Earlier this year Google was under fire for being caught data mining millions of students to sell their information to companies for advertisement purposes and who knows what else. Most of the students targeted in that incident were ones whose schools were using googles ‘Apps for Education’ tool suite. In the last two years, 30 other bills have been passed in other states however none of them were directly telling the technology vendors to straighten up their practices. This bill is so important because it’s the first of its kind to encompass so many of the data mining related problems in our country especially for children under 18.
I really hope that this will be a continuing trend in our country over the next few years, preferably sooner rather than later. The end goal in my own opinion is for our fourth amendment rights to no longer be violated for profit. Unfortunately most people don’t understand to what extent this is being done to every single person in this country, whether you like it or not.
Sources:
Naked Security
The National Law Review
Sources:
Naked Security
The National Law Review
Is BlackBerry Leading The Way?
Today, Sept. 11th 2014 BlackBerry acquired the London based company Movirtu. Movirtu is best known for their software which allows phone users to have multiple phone numbers all on the same device. This technology is ideal for anyone who has a personal cell phone and also a work cell phone. The virtual SIM technology is capable of working on BlackBerry devices, iPhone's, and Androids making it extremely versatile and appealing to a vast majority of cell phone owners. BlackBerry has been focusing their target audience to
corporate and government clients for years now, mostly due to the increasingly popular
iPhone and Android devices. Earlier this year, BlackBerry announced that
they would be, "building on their strengths in security and mobile
device management." This technology also allows for users to have separate minutes, data plans, messaging and bills, based on which number they are using at that time.
I'm extremely curious to see where BlackBerry is going to take this in the next few years as they further implement this technology and build upon it. I also feel that it's an extremely functional idea, that will gain a lot of attention from anyone who does not want to have multiple cell phones unnecessarily. However, there is no information on whether or not companies that monitor their employees cell phones will be able to still 'watch over' their phone users or not. Also, some companies even restrict what the phone user can have access to, and based on how well issues like these are handled, I think this technology will be a big hit or terrible miss.
Sources:
Cnet
Proactive Investors
I'm extremely curious to see where BlackBerry is going to take this in the next few years as they further implement this technology and build upon it. I also feel that it's an extremely functional idea, that will gain a lot of attention from anyone who does not want to have multiple cell phones unnecessarily. However, there is no information on whether or not companies that monitor their employees cell phones will be able to still 'watch over' their phone users or not. Also, some companies even restrict what the phone user can have access to, and based on how well issues like these are handled, I think this technology will be a big hit or terrible miss.
Sources:
Cnet
Proactive Investors
Home Depot: Hacked
On Sept. 8th 2014, Home Depot has officially announced that credit card information was in fact stolen, following their initial report on Sept. 2nd 2014 in which they reported themselves as being "potentially" breached. The amount of cards that were potentially stolen is still unclear. Recall what happened last year to Target. Target operates about 1800 stores in the US. Last November and December in 3 weeks, data from over 40 million cards were stolen. Fast forward to now... Home Depot operates about 2200 stores. Some banks and credit unions are reporting that the Home Depot began to get infected with the same malware as target as far back as April or May of 2014.
My own observation, why did it take them 6 days to decide whether card information had been stolen or not? I would say that this correlates with the length of time they were infected with the malware and how long it went undetected. Why are we just now finding out this information? I wonder how many POS transactions occurred using an electronic payment (credit/debit) between April or May until now. I'm sure that Home Depot receives less card swipes per day, however the length of time this has gone on unnoticed is astonishing. I'm very curious to see how much data has been stolen during this lengthy incident. I would say that someone is obviously going to be losing their job.
My simple advice: Cash is King.
Sources:
The Verge
Naked Security
My own observation, why did it take them 6 days to decide whether card information had been stolen or not? I would say that this correlates with the length of time they were infected with the malware and how long it went undetected. Why are we just now finding out this information? I wonder how many POS transactions occurred using an electronic payment (credit/debit) between April or May until now. I'm sure that Home Depot receives less card swipes per day, however the length of time this has gone on unnoticed is astonishing. I'm very curious to see how much data has been stolen during this lengthy incident. I would say that someone is obviously going to be losing their job.
My simple advice: Cash is King.
Sources:
The Verge
Naked Security
First Post
This blog will be about Computer Security & Related Topics
I intend to use sources from various locations, observing many viewpoints that both coincide and oppose my own personal thoughts on many engaging topics. I will provide my own thoughts and reactions as well as related news/information on these topics. I'd also like to note that this is my first time creating a blog but I'm excited to get started.
I intend to use sources from various locations, observing many viewpoints that both coincide and oppose my own personal thoughts on many engaging topics. I will provide my own thoughts and reactions as well as related news/information on these topics. I'd also like to note that this is my first time creating a blog but I'm excited to get started.
Subscribe to:
Posts (Atom)