Category: Tech News

  • Facebook warns that recent hack could have exposed other applications

    Facebook warns that recent hack could have exposed other applications, including Instagram, Tinder, and Spotify

    Why it matters: Facebook’s bad year isn’t getting any better. As the dust from the Cambridge Analytica scandal started to settle, the social network revealed a security vulnerability that could have exposed 50 million accounts. But the company has confirmed the hack is worse than first suspected: other apps that use Facebook’s login service, including Spotify, Tinder, and Airbnb, could have also been compromised using the vulnerability.

    Facebook announced Friday that it identified the security issue earlier in the week. It involved exploiting a vulnerability in the “view as” feature, which lets people to see how their profiles look to others. The fault allowed hackers to steal Facebook’s access tokens and take over people’s accounts. As a security measure, Facebook forced over 90 million users to log out.

    Facebook said there was no evidence the hackers had access to “private messages or posts,” but warned “that may change” as the investigation continues.

    Following the initial announcement, Facebook revealed in a follow-up conference call that other services using the company’s login feature could also be at risk of having these accounts compromised. Many apps and websites allow people to sign-up using their Facebook credentials, and while there’s been no confirmation of any being breached, it’s another concern for the company and its users.

    “The access token enables someone to use the account as if they were the account holder themselves. This does mean they could access other third-party apps using Facebook login,” said Guy Rosen, Facebook’s vice president of product.

    Facebook’s photo- and video-sharing app Instagram could also have been affected.

    Facebook said it has patched the vulnerability and reset the access tokens of all the accounts known to have been affected by this breach, but it’s not enough to repair the PR damage that’s been done. The fact that CEO Mark Zuckerberg and COO Sheryl Sandberg were among two of those affected by the hack hasn’t helped matters. Since the news broke, $12 billion has been wiped from the company’s value.

    If all this hasn’t been enough to deal with, this week also saw Facebook admit that it uses 2FA phone numbers for ad targeting purposes.

  • The Massive Facebook Hack Might Have Affected Other Apps

    The massive Facebook hack might have affected other apps and websites, too and this is report was coming few hours after the 50 million Facebook account has being compromised. So if you account is hack that means, app and website that is using the Facebook sign-up and login has also being affected.

    Hours after Facebook announced on Friday a huge data breach that affected at least 50 million users, the news got worse.

    In a conference call with reporters—Facebook’s second of the day, after the first one left many questions unanswered—the company’s vice president of product, Guy Rosen, said that the hackers could have also gained access to users’ accounts on other apps and websites, beyond Facebook itself, via Facebook Login. That’s the feature of Facebook that allows you to sign up for, and log in to, all kinds of other online services using your Facebook credentials. For users whose Facebook accounts were hacked, the company confirmed, it’s possible that those third-party accounts could have been breached as well.

    The follow-up call was meant to clarify some of the details of the breach, which is almost certainly the most significant in Facebook’s history. In it, Rosen explained how three separate bugs combined to give hackers a path to full control of users’ Facebook accounts. They gained access not by stealing users’ passwords, but via a sort of digital key called an “access token” that’s meant to let you into your account on another device (say, your phone) automatically when you’re already logged in on another (say, your laptop).

    The good news is that the hackers don’t have anyone’s Facebook passwords—so even users who were affected by the breach don’t necessarily have to change those. The bad news: They could theoretically have used that same token to gain access to some of users’ other online accounts, depending on how the relevant apps and sites handle Facebook access tokens. It was not immediately clear whether the hackers—who remain unknown—actually took advantage of this, nor how easy it would have been for them to do so.

    Any such connections should have been broken when Facebook reset the access tokens of the affected users, beginning Thursday night. That would have logged users out of those third-party apps and sites.

    Facebook also clarified that users affected by the Facebook breach who had Instagram or Oculus accounts linked to their Facebook account would need to delink and relink those accounts. One piece of good news: Whatsapp was apparently not affected. The story is still developing, and more details are likely to emerge in the days to come.

    But there’s already one conclusion we can make: There was a time when Facebook harbored ambitions to be a sort of “universal login” for sites and apps everywhere—like a driver’s license for the online world. That never quite came to pass, but it did get pretty far along. This should be the final answer to the question of whether it was ever a good idea

  • Microsoft Office 2019: Everything You Need to Know

    Microsoft Office 2019: Everything You Need to Know and unlike the office 365 which is a cloud base, this new office 2019 is for offline use and it comes with 32 and 64 bits version and can only be install on systems with windows 10.

    You may have noticed that Microsoft began rolling out a new version of Microsoft Office early this week. That means that there are now three versions of Microsoft Office out in the wild—Office 2016, Office 365, and the brand-new Office 2019.

    If you’re curious about this new version of Microsoft Office, we’ve put together this guide to answer the biggest questions about Office 2019, such as how it differs from Office 2016 and Office 365, what features are (and aren’t) included, and when you can actually use it.

    What is Office 2019?

    Microsoft Office 2019 is a standalone, local (not cloud-based, like Office 365) version of the Microsoft Office software suite. It is a “perpetual” release, which is just a fancy way of saying you buy the software once and own it forever, rather than having to pay an annual subscription fee to access it. That said, you only get a license to use it on a single PC, whereas a subscription to Office 365 lets you use it on a PC, a tablet, and a smartphone.

    This new release updates and replaces the 2016 versions of Word, Excel, etc. and includes many of the new features that have been rolled out to Office 365 users over the past three years. We’ll get to those in a bit.

    When is Office 2019 available, and how much will it cost?

    Office 2019 is on sale now, but only for commercial-level customers. Availability will be rolling out regular ol’ customers like you and me in the coming weeks. That also means we don’t yet know what the price point is for individual users, but Microsoft will likely have that info soon. Expect to potentially pay a bit more than what you’d shell out for Office 2016 (currently $150 for the “Home and Student” version), as Microsoft already boosted the price of the commercial version ten percent to account for its “significant value added to the product over time.”

    What are the system requirements for Office 2019?

    Here’s a big change. On PCs, you’ll need Windows 10 for Office 2019; Microsoft will not support any versions of Windows 7 or 8. As always, Microsoft will make 32 and 64-bit versions of Office 2019 available.

    For Mac, Microsoft will support the three most recent versions of macOS, currently macOS Sierra (10.12), High Sierra (10.13), and Mojave (10.14). As Microsoft notes:

    What new features can you expect?

    Here’s a quick rundown of the important updates Office 2016 users will see if they upgrade to Office 2019.

    Microsoft Word

    With Office 2019, Microsoft says it’s focused on helping you, well… focusbetter when writing in Word. To do so, Word 2019 will be getting the aptly named Focus mode, which darkens the screen and reduces the displayed UI elements.

    Users will also have new “Learning Tools,” including new text-to-speech, text spacing, and translator features. Mac users will also now have customizable ribbons (aka drop-down menus) in their version of the Word interface.

    Outlook

    Like Word, Outlook is also getting a new focus mode, called the “Focused Inbox,” to help streamline workflow and email drafting. Users can now use “@” commands for tagging people in emails, and contact cards have been overhauled.

    Also, PC users will now have travel and delivery cards, while Mac users get new email templates; a Send Later function for scheduling delivery times; and read receipts. Both platforms also get Office 365 Group integration.

    PowerPoint

    The changes for PowerPoint are all about enhanced media and visual element support in presentations. The notable additions here are support for 3D model display/manipulation and SVG files on slides; new morph transitions; the ability to export your presentation in 4K UHD video format, and you can now write by hand and move elements with your pencil while editing.

    OneNote

    OneNote is arguably the biggest change included in Office 2019. This is technically a new OneNote release entirely, one that can replace OneNote 2016 (though OneNote 2016 remains available and will be supported by Microsoft through 2025). This new version, dubbed OneNote for Windows 10, includes Ink-to-Text support, meaning your handwritten words will be turned into typed text, plus better syncing between connected devices.

    Excel

    Finally, Excel gets a host of new functions—like new formulas and chart options, and support for 2D maps and timelines—to better present and organize your data. PC users will also receive updates to Power Pivot, Power Query, and the ability to export to Power BI.

    Better pencil support and other tweaks

    In addition to these program-specific updates, there are also changes that apply to all Office 2019 software. The most important of these is Microsoft’s beefed-up support for digital pencils, like expanded “roaming pencil case” support, which lets users write by hand and move parts of documents with their pencil, as well as new support for pressure sensitivity and tilt recognition. Office 2019 also comes with some behind-the-scenes changes such as monthly security updates and a reduction to network bandwidth use.

    Will Office 2019 replace Office 365?

    No. In a post announcing the software release, Microsoft makes sure to point out that Office 2019 is a standalone package of its software geared primarily towards private users and businesses who do not have the necessary internet access required to use the cloud-based Office 365. Because of this, many of the features present in the Office 365 versions of these apps are not included in their Office 2019 counterparts, especially cloud-based and collaborative features.

    Furthermore, Microsoft makes it clear that while Office 2019 will be receiving regular security fixes, it will not be getting expanded feature updates, while Office 365 users can still look forward to new and updated features through regular monthly updates just as they always have.

    The bottom line here is that Office 2019 is not going to replace Office 365, and it really isn’t meant to. That said, regardless of the particular use case, Office 2019 still fills a crucial role and services a section of Microsoft’s customer base that may have felt a bit neglected since Office 365 took the spotlight.

  • 50 million Facebook accounts were compromised. Was yours?

    Facebook have announced that 50 million Facebook accounts were compromised. Was yours? Just yesterday as well, we give you a news on how a hacker is saying is going to live stream the deletion of MarkZuckerberg’s Facebook account on the 30th of September, 2018, now we are having this news same day that 50 million Facebook accounts were compromised.

    Your Facebook account may have been hacked this week. The social networking giant on Friday said “almost 50 million accounts” were compromised, a discovery its engineers made on Tuesday. Here’s what you need to know.

    What happened?

    According to Facebook, “attackers exploited a vulnerability in Facebook’s code that affected View As, a feature that lets people see what their own profile looks like to someone else. This allowed them to steal Facebook access tokens, which they could then use to take over people’s accounts.”

    What’s an access token?

    An access token keeps you logged into Facebook so you don’t need to enter your password each time you visit the site or app. If an attacker has your token, then he or she has access to your account.

    Was my account hacked?

    Odds are it was not. While 50 million sounds like a big number, it’s a small percentage of the more than two billion active Facebook accounts. If you go to your Facebook page and don’t need to log in, then your account is safe — it was not breached. If you go to your Facebook page and find that you are logged out, then your account may have been breached.

    In response to discovering the attack, Facebook reset the access tokens of the 50 million accounts it found to be compromised, which will require those users to enter their password to log back in. Facebook also took the precaution to reset access tokens of an additional 40 million accounts for those users who used the “View As” feature in the last year.

    If your account was affected, Facebook will notify you in a message at the top of your News Feed when you log back in to explain what happened.

    Facebook has also temporarily turned off the View As feature while it investigates.

    Has Facebook fixed the breach?

    According to Mark Zuckerberg himself, “We patched the security vulnerability to prevent this attacker or any other from being able to steal additional access tokens.” The company, however, still does not know who is responsible for the attack.

    I’m still nervous. Should I change my password?

    Facebook says there’s no need to change your password, but it certainly wouldn’t hurt to pick a new one. After all, the Cambridge Analytica fiasco was worse than Facebook initially believed or admitted.

    You could also just log out of your Facebook account and then log back in without needing to change your password. This simple action will reset your access token, which should put any immediate worries to rest while we wait for Facebook to share more information about the attack.

    To log out of Facebook on all of your devices, go to the Security and Login pageand in the Where You’re Logged In section, click See More and then click Log Out Of All Sessions.

  • FBI warns companies about hackers increasingly abusing RDP

    FBI warns companies about hackers increasingly abusing RDP connections. Not too many of us knows the full meaning of RDP so, we are going to explain it in a brief for you to understand what this warning is all about.

    RDP is an acronym which means remote desktop protocol and is a proprietary protocol developed by Microsoft, which provides a user with a graphical interface to connect to another computer over a network connection. The user employs RDP client software for this purpose, while the other computer must run RDP server software.

    In a public service announcement published on the 27th of September 2018 by the US Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3), the FBI is warning companies about the dangers of leaving RDP endpoints exposed online.

    RDP stands for the Remote Desktop Protocol, a proprietary technology developed by Microsoft in the 90s that allows a user to log into a remote computer and interact with its OS via a visual interface that includes mouse and keyboard input –hence the name “remote desktop.”

    RDP access is rarely enabled on home computers, but it’s often turned on for workstations in enterprise networks or for computers located in remote locations, where system administrators need access to, but can’t get to in person.

    In its alert, the FBI mentions that the number of computers with an RDP connection left accessible on the Internet has gone up since mid and late 2016.

    This assertion from the FBI correlates with numbers and trends reported by cyber-security firms in the past few years. For example, just one company, Rapid7, reported seeing nine million devices with port 3389 (RDP) enabled on the Internet in early 2016, and that number rose to over 11 million by mid-to-late 2017.

    Hackers, too, read cyber-security reports. Early warnings from the private sector about the increasing number of RDP endpoints caught hackers’ attention long before sysadmins.

    For the past few years, there has been a constant stream of incident reports in which investigators found that hackers got an initial foothold on victims’ networks thanks via a computer with an exposed RDP connection.

    Nowhere has this been more the case than in ransomware attacks. Over the past three years, there have been tens of ransomware families that were specifically designed to be deployed inside a network after attackers gained an initial foothold, which in many cases ended up being an RDP server.

    Ransomware specifically designed to be deployed via RDP includes strains such as CryptON, LockCrypt, Scarabey, Horsuke, SynAck, Bit Paymer, RSAUtil, Xpan, Crysis, Samas (SamSam), LowLevel, DMA Locker, Apocalypse, Smrss32, Bucbi, Aura/BandarChor, ACCDFISA, and Globe.

    Here’s just one user recounting one event on Reddit where hackers broke in via RDP and launched ransomware that encrypted countless of his systems.

    There are three ways in which hackers usually tend to get in. The easiest way is when sysadmins enable RDP access on a server and don’t set up a password. Anyone accessing that computer’s IP address on port 3389 will be prompted by a login screen where they can log in just by pressing Enter.

    The second way is derived from the first but requires on attackers either guessing login credentials (via a brute-force attack) or by using precompiled lists of common username-password combos (via dictionary attacks).

    The third method also relies on mass-scanning the internet, but instead of guessing credentials, attackers deliver exploit code for known vulnerabilities in the RDP protocol. If the port is exposed, then hackers can exploit it.

    According to Rapid7, between 2002 and late early 2017, there have been 20 Microsoft security updates specifically related to RDP, updates that fixed 24 major vulnerabilities. Patches for RDP continued even after Rapid7 stopped counting, with the latest of these fixes being deployed this March for a flaw in CredSSP, one of the smaller protocols part of the RDP package.

    In an interview with ZDNet about the FBI’s alert, Mark Dufresne, VP, Threat Research and Prevention at cyber-security Endgame, shared some of his dealings with the RDP threat.

    “RDP has been baked into Windows for a very long time and has been abused by attackers since it became widely deployed,” Dufresne told ZDNet.

    “We can look at sources like greynoise.io to see that attackers are constantly looking for open RDP connections,” he added. “Almost a thousand unique IPs were looking for RDP services listening on the default port each day over the past week.”

    Once attackers get in, it’s all fair game, unless they’re not careful and security products expose their presence.

    But not all RDP compromises result in ransomware infections, data theft, or malicious behavior. Some of the people behind these RDP scans don’t always exploit the hacked systems –at least not directly– and stockpile hacked RDP endpoints to sell online.

    Since mid-2016, just about when cyber-security firms were noting a rise in RDP servers, a group of hackers set up xDedic, a web portal where they and other criminals could sell or buy these hacked and hoarded RDP systems.

    Initially, it was said that xDedic provided crooks access to over 70,000 hacked RDP endpoints, but one year later, despite the media attention and attempts to take down the site, xDedic’s RDP server pool had gone up to 85,000.

    But xDedic was only the beginning. Other copycat “RDP shops” –as they became to be known as– popped up everywhere. This reporter has been tracking some of these services for the past few years on Twitter [1, 2, 3, 4, 5, 6].

    The most recent of these was discovered just this summer, in July. McAfee security researchers found it peddling access to RDP workstations located on some pretty sensitive places such as airports, government, hospitals, and nursing homes.

    But these shops wouldn’t be a problem unless people stopped exposing RDP endpoints altogether. Through its alert, the FBI is now urging companies to secure these systems before it’s too late and they get hacked.

    Together with the Department of Homeland Security, the two agencies have published today the following advice in regards to improving RDP security.

  • Hacker says he’ll livestream deletion of Zuckerberg’s Facebook page

    Hacker says he’ll livestream deletion of Zuckerberg’s Facebook page this sunday being the 30th day of September 2018 and he said we can login to our facebook page to see if that will not happen and this was said his 26,000 plus followers.

    A white-hat hacker is promising to livestream his bid to hack into Mark Zuckerberg’s Facebook account on Sunday (30th September). “Broadcasting the deletion of Facebook founder Zuck’s account,” Chang Chi-yuan told his 26,000-plus followers on the social network, adding: “Scheduled to go live.”

    According to Bloomberg, the self-proclaimed bug bounty hunter is a minor celebrity in Taiwan who’s appeared on talk shows and was reportedly sued by a local bus operator after breaching their systems to nab a ticket for just NT$1 (3 cents). Earlier this month, Chi-yuan shared a screenshot showing an Apple Pay loophole he’d found that allowed him to pay NT$1 for 500 iPhones. His other claims include cyber-attacks on Apple and Tesla, and he’s also listed on Japanese messaging giant Line’s 2016 bug-hunters’ hall of fame.

    “I don’t want to be a proper hacker, and I don’t even want to be a hacker at all,” Chang said in a recent post. “I’m just bored and try to dabble so that I can earn some money.” Facebook, like other tech giants, dishes out cash to cyber-security experts who point out flaws in its system as part of a bug bounty program. But considering all the setbacks it’s currently facing — including the departure of Instagram’s founders and its ongoing fake news crisis — it probably doesn’t want to deal with a high-profile hack right now.

    Neither is the company keen on paying out bounties to people who test vulnerabilities against real users. Back in 2013, it refused to reward Khalil Shreateh — a systems information expert from Palestine — for hacking into Zuck’s account and posting an Enrique Iglesias video on the wall of one of his college friends. The Facebook founder has also previously had his Twitter and Pinterest accounts breached by notorious hacker group OurMine.

    News source: engadget

  • Without invading our privacy, does Google even have a business?

    Without invading our privacy, does Google even have a business?

    Without invading our privacy, does Google even have a business?  Google is on a seemingly-ceaseless crusade to turn every one of its users into an open book that it can exploit for valuable information, and much of the public seems unaware. What’s worse, many of those who do know about Google’s illicit tracking services and shady operations oftentimes don’t seem to care.

    As a matter of fact, Google’s intrusive policies are becoming a defining facet of modern life and warrant intense discussion if we’re ever to progress meaningfully as a society.

    One question stands out above them all: without invading our privacy, does Google even have a business?

    The foundations of a digital empire

    This is huge question to unpack, so it’s worth looking at the foundation of Google as a company before arriving at our answer. First and foremost, we need to dispel any notions that Google has the best interest of people or society at heart. It is, at its very core, a capitalist corporation that seeks to supplant competitors and extend its influence over as much of the globe as possible.

    This isn’t controversial – the company even admits to it in its mission statement, which reads that it intends “to organize the world’s information and make it universally accessible and useful.”

    The consequences of this statement are exciting and terrifying at the same time. On the plus side, we all derive many benefits from Google every single day – whether we’re tapping away on one of the company’s smartphones or using its services to look up a new recipe or the address of a friend, the lives of pretty much everyone everywhere have been positively impacted by Google in some way.

    The more insidious consequences lurking below the surface warrant discussion too, however, and only by prying into Google’s skeleton-filled closet can we see that the company isn’t always on our side.

    According to an exclusive report from the Associated Press, for instance, Google’s extensive location tracking services are so robust that they keep track of your whereabouts even after you’ve turned them off. Like it or not, the AP reminds us, Google is tracking your movements everywhere you go in the physical and virtual worlds.

    The company’s proponents argue, sometimes persuasively, that it essentially has to do this if it’s to meet our demands. How can Google show you which food truck or day spa is in your area, for instance, or what the weather will be like in your town, if it’s uncertain of where you are at the precise moment of inquiry?

    But whether that gives Google extensive rights to probe into our personal business is a wholly different question. This is worrying, because a strong case can be made for the fact that Google essentially can’t run a business if it can’t invade our privacy to some extent.

    To snoop or not to snoop, that is the question

    The latest scandal surrounding Google isn’t centered on location tracking, but rather the new way in which Google Chrome’s sign-in works. A slew of updates brought with it a change to Google’s popular web browser, which now automatically forces you to login on a Google account on Chrome if you’re trying to use that browser to access a Google service (like Gmail). A breakdown of the changes illustrates that they’re deeply concerning from a privacy standpoint and help us answer our question.

    To be quite frank, it’s likely true that Google simply didn’t need to force this latest change on its users, and that it can survive and thrive as a company without forcing you to login to a Google account every time you use Chrome to access a Google service. But the broader question of whether Google needs to invade our privacy in general to exist as a business is more difficult, and the answer to that question is likely the inverse to the one above.

    Whereas Google doesn’t need to force foolish and intrusive changes like that Chrome sign-in scandal mentioned above onto users, it definitely needs to invade your privacy to some extent in order to operate. The key phrase there is “to some extent.”

    Google, for instance, necessarily has to ascertain your physical location to give you directions from your home to the nearest coffee shop when you ask for it, after all. It also needs to keep track of you to give you timely weather updates, security alerts in your local area, and other info we regularly request from it every day.

    But the fact that we need to let Google know a little bit about us to rely on its services as extensively as most of us do doesn’t give the company free license to spy on us in all manners of life.

    Google may not be able to exist without invading our privacy to some extent, but the company needs to understand that certain lines can’t be crossed and consumer confidence must be maintained if it’s to achieve its goals in the future.

    This post is part of our contributor series. The views expressed are the author’s own and not necessarily shared by TNW.

  • Trump launches new national cyber strategy

    Trump launches new national cyber strategy

    Trump launches new national cyber strategy that aims to guide how the administration handles offensive and defensive cybersecurity and cyberthreats, Trump’s National Security adviser, John Bolton, told reporters in a briefing Thursday.

    Why it matters: In the absence of an overarching cybersecurity doctrine, government agencies have been limited in how they can legitimately deter foreign adversaries and respond to cyberattacks — even as the attacks are escalating exponentially.
    The context: This comes at a time when the administration has been bleeding cyber talent and facing criticism for its approach to election security — it eliminated the role of cybersecurity coordinator earlier this year, and the FBI has been losing cyber talent as well.

    The details, as outlined by Bolton:

    Bolton said the strategy takes effect on thursay being the 20th day of september 2018.

  • Hackers Steal $59 Million In Cryptocurrency From Japanese Exchange

    Hackers Steal $59 Million In Cryptocurrency From Japanese Exchange

    Hackers Steal $59 Million In Cryptocurrency From Japanese Exchange and Tech Bureau said it will sell a majority of its shares to another financial services corporation in Japan, as reported by CCN. That sale is supposed to provide over $40 million to be used to replace the funds stolen from customers.
    Last week, hackers stole an estimated $59 million from a Japanese cryptocurrency exchange called Zaif, according to a statement released Thursday by the owners of the exchange.
    According to Cointelegraph, the Tech Bureau Corp. said the breach occurred on September 14. The company discovered something was wrong on September 17, and realized it was a hack the following day, September 18.
    Zaif lost 5,966 Bitcoins, currently valued at more than $6,000 each, as well as some Monacoin and Bitcoin Cash, the amount of which Tech Bureau is currently investigating, according to the released statement.
    Tech Bureau said it will sell a majority of its shares to another financial services corporation in Japan, as reported by CCN. That sale is supposed to provide over $40 million to be used to replace the funds stolen from customers.
    Cryptocurrency exchanges are similar to a stock exchange or currency exchange that might be found at a bank or airport, except that users are trading decentralized digital currencies.
    Cryptocurrencies are designed to be hard or impossible to manipulate, but the exchanges themselves are still very much at risk of hacks.
    In 2014, the one-time largest cryptocurrency exchange in the world, Japan-based Mt. Gox, declared bankruptcy after losing $473 million in a hacking attack.
    Shortly after the popular cryptocurrency Bitcoin peaked in value in December 2017 at just under $20,000 per bitcoin, Japanese cryptocurrency exchange Coincheck reported losing 500 million in various crypto coins to hackers. That equated to a loss estimated to be more than $400 million.
    “Virtual currency exchanges have suffered at least five major hacks this year, one reason why professional money managers have largely steered clear of the market even as individual investors piled in,” Fortune reported Thursday.
    News Credit: NPR

  • Google said Apps Can Scan And Share Your Gmail Data With Consent

    Google said Apps Can Scan And Share Your Gmail Data With Consent

    Google said Apps Can Scan And Share Your Gmail Data With Consent.  A year ago, Google ended its controversial email scanning practice, but the company still lets third-party apps and add-ons scan your Gmail inbox, despite concerns over privacy risks.
    Don’t expect Google to completely cut off marketing firms from your Gmail inbox.
    The company has told a group of US senators that Gmail add-ons that scan your inbox can choose to hand over your data to someone else — but only if they’re upfront about it.
    “Developers may share data with third parties so long as they are transparent with the users about how they are using the data,” Google VP Susan Molinari wrote to the Senate Commerce Committee in a July letter.
    A year ago, Google ended its controversial email-scanning practice, which was used to serve up targeted ads. However, The Wall Street Journal reported this summer that hundreds of outside software developers can still search through your inbox via Gmail add-ons and mobile apps if you’ve agreed to install them.
    These apps can help organize your inbox, offer shopping price comparisons and other email-related tools. But according to the Journal, the apps have also given their developers the ability to look through unredacted personal emails, which can be used for marketing or product-refinement purposes. In one instance, 8,000 emails were read by analysts at one app provider to help train the company’s software.
    The news prompted the Senate Commerce Committee to question Google about its email privacy practices and if any user data was at risk of exposure. “The reported lack of oversight from Google to ensure that Gmail data is properly safeguarded is cause for concern,” the committee said at the time.
    However, Google has told lawmakers that the company has protections in place to prevent potential abuse. “We continuously work to vet developers and their apps that integrate with Gmail before we allow them the ability to request access to user data,” Molinari wrote in her letter, which was first reported on Thursday.
    Her letter refrains from answering specifics over how app developers can share Gmail user data to third parties. But apps that need access to Gmail data must undergo a manual review from Google that’ll involve examining the app’s privacy policy and the data privileges it seeks to request, she said.
    “Once they have been given access, we use machine learning (AI-powered software algorithms) to monitor those apps,” Molinari added. “If we detect significant changes in the behavior of the app after it has been approved, we will once again manually review the app.”
    To educate users, Google will serve up warnings when a third-party app is installed that’ll indicate what data it seeks to obtain from your Gmail inbox, and if the app has been verified. In the past, the company has suspended apps for failing to be transparent to users, violating its rules on spam, and requesting data permissions that were not relevant to the app.
    Molinari also addressed whether Google employees ever peek into your inbox. “No humans at Google read users’ Gmail, except in very specific cases where they ask us to and give consent, or where we need to for security purposes, such as investigating a bug or abuse,” the company said.
    Nevertheless, Google’s defense assumes that people actually read all details in an app’s privacy policy, when many of them can be long and hard to read. The whole issue is a reminder to be careful of what add-ons you install.
    Google and other tech companies are set to face the Senate next week in a hearing over data privacy.