Recent hackings have been found to especially target three main platforms: healthcare, education, and government. This has compromised the security of healthcare provider Excellus BlueCross BlueShield, the Cal State University System, and the U.S. Department of Energy.

It was discovered last week that over 10 million people are at risk due to a Excellus computer system hacking that’s been occurring since December of 2013. It doesn’t appear that the hackers stole or utilized any important personal information, though they were able to access and view customer names, birth dates, social security numbers, and financial claims. The attack was one of the worst 20 breaches in healthcare of all time. The hacking also parallels recent incidences at Anthem, Office of personnel Management, Sony and Ashley Madison. In all cases, the attacks were committed by people disguised as employees, using stolen credentials to gain access to corporate networks.

Roughly 80,000 students from the Cal State University System lost general information after enrolling in a class on sexual harassment. Their names, numbers, emails, gender, race, and relationship status were provided to a contractor as part of a program on sexual harassment. The contractor, “We End Violence” was hacked, as reported in the Los Angeles Times earlier this month.

The U.S. Department of Energy’s computer systems were attacked 159 times between 2010 and 2014. Officials declined to comment, however, on the nature of what was accessed by hackers or whether any foreign governments were responsible.

Article via ECT News NetworkSeptember 16, 2015

Photo: Longmont Power and Communications-3 via You Belong in Longmont [Creative Commons Attribution-NonCommercial-NoDerivs]

The best protection against widespread government surveillance now comes from major tech companies, including those accused of collecting mass amounts of data to sell to other companies seeking targeted advertising.

The FBI has accused Apple of aiding criminals by offering default encryption in the new iPhones it sells. Government reproach is also directed towards Google, which is offering the same encryption for its new Android phones. However, the majority of Americans are grateful for the tech companies’ new developments; a recent Pew survey found that 65 percent of people believe that there aren’t enough limits on government surveillance.

Smartphone encryption is not the only guard against surveillance, either. Google and Yahoo announced that they’re both working on end-to-end encryption in email, and Facebook was established on a Tor hidden services site so that people with access to network traffic can’t access user data.

Encryption tools are generally difficult to operate, and thus only tech-savvy users have been able to achieve full privacy. As a result, anyone using encryption tools was unique and therefore suspicious to government officials. With new integrated encryption, privacy will be more universal, and those previously using encryption systems will be better camouflaged.

Articles: The Center for Internet and Society, September 9, 2015

Photo: DC Ralley Against Mass Surveillance via Susan Melkisethian [Creative Commons Attribution-NonCommercial-NoDerivs]

According to a study done by Robert Epstein and Ronald E. Robertson, changes made to Google’s search algorithm have the ability to manipulate voting preferences of undecided voters by 20 percent or more. Published in the Proceedings of the National Academy of Sciences (PNAS), the study experimented with the Search Engine Manipulation Effect (SEME) in two countries with over 4,500 participants.

The investigators conducted an experiment where participants were randomly assigned to one of three groups in which search rankings favored Candidate A, B, or neither. Before researching for 15 minutes on a search-engine called Kadoodle, participants were provided a short description of both candidates and asked whom they would be voting for. The 30 search results were the same for everybody, but ordered differently depending on the group. The number of people favoring a candidate increased between 37 and 60 percent due to the biased search algorithm.

Google adjusts its search algorithm 600 times a year. In refutation of SEME, Google comments: “Providing relevant answers has been the cornerstone of Google’s approach to search from the very beginning. It would undermine the people’s trust in our results and company if we were to change course.”

 

Articles: Politico Magazine, August 19, 2015; via MILRN

Photo: Campaigning with a Smile via Jack [Creative Commons Attribution-NonCommercial-NoDerivs]

As the usage of apps and websites by kids increases, new conversations about children’s privacy must occur. The Global Privacy Enforcement Network (GPEN) did a recent study in which it found that of the 1,494 websites and apps samples, 41 percent compromised children’s privacy.

The data, collected form 29 protection regulators worldwide, found that 67 percent of the websites collected information from kids, and only 31 percent of sites had any controls to limit collection.

Many of the websites very popular with kids did have statements in their privacy policies indicating that the website was not intended for children. However, these websites generally did not have any further controls to prevent the collection of personal data. Of the total sample, 22 percent of sites had a category for kids to input phone numbers, and 23 percent had a place to upload photos or videos.

Furthermore, children’s information isn’t always contained on the original site. Kids were given the opportunity to be redirected to another site on 58 percent of sites; 50 percent of sites shared personal information with third parties.

Despite the holes in website security found, some websites did use recommended precautions like parental dashboards, pre-set avatars and usernames, just-in-time warnings before info is submitted, and chat filters.

Adam Stevens, the head of UK’s Information Commissioner’s Office, says that the ICO will be contacting problematic websites and apps, “making clear the changes we expect them to make. We wouldn’t rule out enforcement action in this area if required.”

Article via LegalTech News, September 3, 2015

Photo: Misi with a Phone via Balazs Koren [Creative Commons Attribution-NonCommercial-NoDerivs]

The Department of Justice has put stricter regulations on the use of cell-site simulators by requiring a warrant to be issued before one can be used, except in the case of “exigent” or “exceptional circumstances”, according to the CNN report covering the announcement. Cell-site simulators, which acquire locational data from cellphones by posing as cell towers, have not been regulated previously. The use of cell-site simulators have proven very helpful to law enforcement trying to locate kidnapping victims, terrorists, and other fugitives. While effective, these simulators also gather information about citizens who have not committed any crimes. This breach of privacy calls into question the ethics behind using cell-site simulators which in turn led to the announcement from the Department of Justice.

The new regulations have been praised as a step in the right direction for protecting citizen’s privacy after previous scandals of government agencies hiding their surveillance technology from the public. However, the Department of Justice’s announcement only applies to federal agencies, not local or state law enforcement. The staff attorney for the American Civil Liberties Union, Nathan Freed Wessler, stated that “Congress should act to pass more comprehensive legislation to ensure that Americans’ privacy is protected from these devices and other location tracking technologies” by including law enforcement agencies that purchased cell-site simulations with federal funding under the new regulations.

Articles via ABA Journal, September 4, 2015: CNN, September 3, 2015

Photo: Timelaps with Oneplus One Cellphone via Damien Thorne [Creative Commons Attribution-NonCommercial-NoDerivs]

In a blog post on Sept. 3, Facebook’s Chief Product Officer Chris Cox explained the company’s goal to offer personalized education to public school students. Facebook partnered with the Bay Area’s Summit Public Schools throughout the 2014 school year to develop Personalized Learning Plan (“PLP”), a tool to help students organize and tailor their educations. Over 2000 students and 100 teachers utilized the program in 2014.

Summit seeks to offer PLP to public schools across the nation, and is partnering with a few schools in 2015 to test the piloted program. Facebook will use feedback from the 2015 school year to improve the interface.

PLP is a program entirely separate from the main Facebook company. Students and teachers who login are not required to have a Facebook account, and user information will not be sold to any advertisement companies. In fact, Facebook must abide by the Student Privacy Pledge, a guide to protecting students endorsed by the US Government.

Article via TechCrunchJuly 13, 2015

Photo: Facebook via Scott Beale [Creative Commons Attribution-NonCommercial-NoDerivs]