Security News

Facebook Privacy Glitch Gave 5K Developers Access to ‘Expired’ Data
2020-07-02 16:06

The social media giant said that it recently discovered that 5,000 developers received data from Facebook users - long after their access to that data should have expired. In 2018, on the heels of the Cambridge Analytica privacy incident, Facebook debuted stricter controls over data collection by third-party app developers.

Zoom: We've delivered on all of our security and privacy promises, apart from one
2020-07-02 11:33

As more remote workers turned to Zoom for business meetings, virtual get-togethers and other forms of socially distanced communication, it soon became apparent that security -thanks to headaches such as a wave of ' Zoom-bombing ' - was an area that needed more work. As a result, Zoom CEO Eric Yuan launched a 90-day programme that pledged to address key privacy and security concerns.

macOS Privacy Protections Bypass Disclosed After Apple Fails to Release Fix
2020-07-01 15:30

Details on a macOS privacy protections bypass method were published this week, more than six months after Apple was informed of the issue, but failed to deliver a fix. Dubbed TCC, the privacy protections system was introduced in macOS Mojave to ensure that certain files on the system are kept out of reach of unauthorized applications.

After six months of stonewalling by Apple, app dev goes public with macOS privacy protection bypass
2020-07-01 02:32

Six months after software developer Jeff Johnson told Apple about a privacy bypass vulnerability opening up protected files in macOS Mojave, macOS Catalina, and the upcoming macOS Big Sur, the bug remains unfixed - so he's going public. This latest bug can be exploited by a maliciously crafted app to bypass a privacy system known as Transparency, Consent, and Control that was introduced in OS X Mavericks and got strengthened in subsequent releases through technologies like System Integrity Protection in El Capitan.

New privacy-preserving SSO algorithm hides user info from third parties
2020-06-30 09:33

Some people are also concerned that their ID and password could be stored locally by third parties when they provide them to the SSO mechanism. In an effort to address these problems, Associate Professor Satoshi Iriyama from Tokyo University of Science and his colleague Dr Maki Kihara have recently developed a new SSO algorithm that on principle prevents such holistic information exchange.

Researchers create tool for protecting children’s online privacy
2020-06-30 03:00

A University of Texas at Dallas study of 100 mobile apps for kids found that 72 violated a federal law aimed at protecting children's online privacy. Dr. Kanad Basu, assistant professor of electrical and computer engineering in the Erik Jonsson School of Engineering and Computer Science and lead author of the study, along with colleagues elsewhere, developed a tool that can determine whether an Android game or other mobile app complies with the federal Children's Online Privacy Protection Act.

IBM Research releases differential privacy library that works with machine learning
2020-06-29 13:20

The library "Boasts a suite of tools for machine learning and data analytics tasks, all with built-in privacy guarantees," according to Naoise Holohan, a research staff member on IBM Research Europe's privacy and security team. Differential privacy allows data collectors to use mathematical noise to anonymize information, and IBM's library is special because it's machine learning functionality enables organizations to publish and share their data with rigorous guarantees on user privacy.

Data Privacy, Other Measures Qualify for California Ballot
2020-06-26 12:58

California voters will weigh in this November on whether to expand a landmark data privacy law, alter a decades-old law that limits property taxes on businesses and exempt ride-hail giants Uber and Lyft from a new state labor law. Ballot measures are often among the most expensive and high-profile issues before California voters each election year and tens of millions of dollars are likely to be spent on each of the major initiatives.

TikTok To Stop Clipboard Snooping After Apple Privacy Feature Exposes Behavior
2020-06-26 12:22

A new privacy feature in Apple iOS 14 sheds light on TikTok's practice of reading iPhone users' cut-and-paste data, even though the company said in March it would stop. Apple added a new banner alert to iOS 14 that lets users know if a mobile app is pasting from the clipboard and thus able to read to a user's cut-and-paste data.

Cape Privacy launches open source platform and raises $5M in seed funding
2020-06-25 23:45

Cape Privacy, a privacy platform for collaborative data science and machine learning, announces the launch of its open source platform as it secures $5 million in seed funding. Cape Privacy helps enterprise companies maximize the value of their data by providing an easy-to-use collaboration layer on top of advanced privacy and security technology.