This week, a lawsuit was filed in the U.S. District Court of Massachusetts against the Commonwealth of Massachusetts for its use of a COVID-19 contact-tracing app for residents’ mobile phones. However, very few residents voluntarily downloaded the app. The solution? The lawsuit alleges that Massachusetts caused the app to be downloaded to certain residents’ mobile
android
Privacy Tip #338 – Be Aware of Apps Infected with Malware
Like all technology, mobile apps can be infected with malicious code, or malware, which is intended to gain access to your mobile phone when you download the app. Although app stores try their best to not allow malicious apps to get into the store, monitor apps once they are included in the store, and delete…
DJI Responds to Recent Cybersecurity Report on App Vulnerabilities
This week, China-based DJI, the drone industry’s leading manufacturer of drones, issued a public statement regarding the recent reports released by cybersecurity researchers (neither Synacktiv nor GRIMM) about the security of its drones’ control app.
In two reports, the researchers claimed that an app on Google’s Android operating system that powers DJI drones collects large…
Privacy Tip #211 – WhatsApp Users: Update Your App to Patch Vulnerability
WhatsApp has announced that it has patched a vulnerability that would have allowed hackers to access with malware the chat history of users. Android 8.1 and 9 could have been susceptible to the attack. However, WhatsApp is urging all users to update their app.
Although WhatsApp says it has patched the vulnerability and does not…
New Malware Targets Big Banks and Cryptocurrency Apps
New malicious malware dubbed “Gustuff” targets big banks, fintech companies and cryptocurrency apps, according to the security firm Group IB.
According to Group IB, which discovered Gustuff on hacker forums, the new malware is affecting Android devices and is “a mobile Android Trojan, which includes potential targets of customers in leading international banks, users of…
Privacy Tip #152 – Device Self-Defense
If you have bought a new cell phone recently, you have seen that the technology of the newest smart phones is far more advanced than in the past, and have features that most people don’t understand or use.
When I conduct employee education for companies on data privacy and security, I devote a portion of…
Google Tracking of Android Users Goes Beyond the Expected
By now most smartphone users are aware of location tracking used by both Apple and Android operating systems. Basic location tracking is a system which uses GPS data to know the phone user’s location. However, according to a recent article published by Quartz, Google’s data collection goes far beyond basic location tracking. Not only does the data collected go beyond simple location information, but the ‘Opt In’ service Google uses to collect that data, Location History, isn’t as truly Opt In as users might expect. According to Quartz, Google’s Location History underlies many of Android’s main apps, including Google Assistant and Google Maps. Furthermore, Opting In to Location History for one app may actually give many apps access to Location History’s data and the ability to send that data to Google.
Continue Reading Google Tracking of Android Users Goes Beyond the Expected
Privacy TIp #86 – Android Users Vulnerable to Malware through Apps
University of Michigan researchers have discovered that hundreds of applications in Google Play turn Android phones into a server that allow the user to connect the phone directly to a PC and leave open insecure ports available on the smartphone.
What does this mean? It means attackers can use the open insecure port to get…
Virtual Private Network (VPN) Providers: How Private Are They?
By Executive Order, the Trump Administration recently reversed an Obama Administration order aimed at protecting consumer’s personal information from use by their Internet Service Provider (ISP). ISPrior to the Trump’s EO, ISPs were required to get customer’s consent before using or selling their browsing habits, online shopping habits, financial information, etc. The reversal of Obama’s protection order has caused a resurgence of interest in VPN services. In theory, using a VPN service creates an encrypted tunnel between your device and the service provider, thus keeping your browsing habits and personal information private from your ISP. However, a paper published in early 2015 by researchers at Sapienza University of Rome and Queen Mary University of London, found that 11 of the 14 providers they tested leaked customer information.
Continue Reading Virtual Private Network (VPN) Providers: How Private Are They?
IBM Issues 2017 X-Force Threat Intelligence Index Findings
Last week, IBM published its X-Force Threat Intelligence Index (Index), which summarizes the state of leaked records and vulnerabilities to data in 2016. It is depressing, but informative.
The Index notes that the number of compromised records “grew a historic 566 percent in 2016 from 600 million to more than 4 billion.” Billion with a…