A recent complaint against Google claims that the company was violating antitrust regulations when it banned a privacy app. The app, Disconnect, stops malevolent advertising and secretive user tracking. The creator of the app filed a complaint with the EU on Tuesday. According to Disconnect, Google’s decision to discontinue the app on the Google Play store was an abuse of its dominant position in mobile tech. Google said the app violates its policies and their complaint is groundless.

“We don’t oppose advertising and understand ad revenue is critically important to many Internet companies, publishers and developers,” Disconnect Co-founder and CEO Casey Oppenheim said. “But users have the right to protect themselves from invisible tracking and malware, both of which put sensitive personal information at risk. Advertising doesn’t have to violate user privacy and security.”

The complaint is just a part of the increased scrutiny Google is undergoing as it hopes to increase the influence of its Android Mobile operating system. The ongoing European Commission investigation into Android shines a light on regulators’ worries concerning how Google exercises its power.

Disconnect argues that Google is using Android in monopolistic ways and has consolidated inadequate security and privacy features into its presiding products, thus bringing harm to consumers and giving itself a discriminatory advantage.

Google, on the other hand, claims that Disconnect has violated its policies, according to clause 4.4 of Google’s Developer Distribution Agreement which forbids apps from interfering with other apps.

Article via CNET, 2 June 2015

Photo:Big Google brother?  via Alain Bachellier [Creative Commons Attribution-NonCommercial-NoDerivs]

Recently it has been reported that about 45% of IT security personnel are dealing with extensive issues resulting from employees clicking on email links and attachments that download malware and phishing attacks. Osterman Research issued its “Best Practices for Dealing with Phishing and Next-Generation Malware” in April . Stories included described real-life situations in which law firms lost hundreds of thousands of dollars to cyber attacks. Here are three key takeaways :

  • Users are sharing more information through social media as cybercriminals are refining their tactics, and unfortunately many current anti-phishing solutions are proving insufficient. This makes companies and groups more susceptible to cyber attacks.
  • Organizations should execute a training program that will raise their employees’ awareness of phishing attempts and other possible attacks, so users become the first line of defense in any security infrastructure.
  • Business and IT decision makers should put forth best practices to help their users screen electronic communication and collaboration for social engineering attacks more carefully.

Article via Above The Law, 20 May 2015

Photo: Macbook Pro via Warren R.M. Stuart [Creative Commons Attribution-NonCommercial-NoDerivs]

Facebook, Google, Apple and Twitter, along with more than 75 companies and cyber security experts, sent a letter to President Obama on Tuesday, asking him to reject government proposals that would grant law enforcement access to their user’s encrypted data. The letter said that providing law enforcement access to their user’s data will leave them vulnerable to attacks and compromise their products, and asked Obama to reject proposals to force a “back door” into their operating systems. The efforts from several major tech companies to make data more secure precedes the open letter. They also requested that the White House focus on creating policies that advocate strong encryption technology and thus cyber security, human rights and economic growth. Law enforcement does not seem to agree however. Google and Apple were criticized for making their smartphone encryption too difficult for law enforcement to crack, and one official doesn’t understand why businesses market devices to purposefully allow users to escape the law’s reach.

Article via Mashable, 19 May 2015

Photo: Campaigning with a smile (Barack Obama in Austin #3) via Jack Thielepape/jmtimages [Creative Commons Attribution-NonCommercial-NoDerivs]

 

Having lived in Korea for the past 2 and a half years, I can say that I love this place. It is an amazing culture and a truly amazing country. It also helps that I am an internet junkie, and the service here is unbelievable. I pay 41,000 won per month (around $39.00) for 100mb internet service with no contract. This is truly a place where connectivity is king.

However, I have consistently had one major issue, and that is with online shopping and banking. When I want to go to my bank website, I have to download at least 5 security programs, including keylogging pretection software. These are all designed to keep you safe, and your information secure. Funny, that the only time my information was compromised was when it had nothing to do with e-commerce. These programs also degrade the performance of your computer.

One of the biggest issues I have is that most online shopping websites use ActiveX security from Microsoft. ActiveX is outdated, and really only works well with Internet Explorer. While I have nothing against IE, I do have issue with this,as it inherently limits browser choice. In fact, until about 2 years ago, my (soon-to-be) wife thought Internet Explorer WAS the Internet…

After searching, I found out that Korea passed a law in 1999 to protect consumers that required the use of ActiveX security. I see serious issues with laws such as these, and that is due to the inherent difference in pace between law and technology. The world has moved beyond ActiveX, and South Korea is for once, lagging behind, and this is due to enshrining ActiveX into law. However this will be changing soon.

This April, after months of rumors, the Government has finally announced plans to fix things!! This is wonderful news, however I fear that it has come too late in the game. I wonder if this had any effect on ticket sales for the Incheon Asian games(I had to have my wife order them, because the payment system was exclusively in Korean)?

All I can say is that I am glad that things are moving in the right direction, and that Korean consumers will finally have a choice in browsers.

CIJT: Do you think that it is beneficial to enshrine specific technologies into law? Any ideas on how to have law keep pace with technology?

 

Source article: BusinessKorea

Photo: ClipDealer GmbH

Hackers often carry out massive cyberattacks to gain access to financial data through banks and retail companies , but this week’s cybercrime hit a seemingly new target: medical data, taken from the health insurance company Premera Blue Cross. The attack affected 11 million patients, making it the largest cyberattack involving medical information to date . The healthcare industry has been catching hackers’ attention lately. In February, the health insurance company Anthem reported a breach in which hackers accessed to about 80 million records , and in 2014, the Tennessee-based hospital operator Community Health Systems saw 4.5 million records accessed, though both companies said no medical data was exposed. Even so, as Pat Calhoun, the senior vice president of network security at Intel Security, puts it, the healthcare industry is just beginning to find itself in cyber-criminals’ crosshairs, making it slow to shield people’s records. Calhoun points out that healthcare breaches aren’t unheard of: In fact, according to Intel Security and the Atlantic Council’s latest report on cyber risks , about 44 percent of all registered data breaches in 2013 targeted medical companies, with the number of breaches increasing 60 percent between 2013 and 2014. Medical data is also becoming a highly lucrative target. “Financial data has always been a priority, because it’s low-hanging fruit,” Calhoun says. “But over the past couple of years, we’ve identified that medical information has a higher value on the black market than credit card information.”

Medical data has become the next cybersecurity target (NextGov, 20 March 2015)

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/stockimages

Wall St. and law firms plan cooperative body to bolster online security (NYT, 23 Feb 2015) – The threat of ever-larger online attacks is bringing together Wall Street banks and the big law firms that do work for them in an alliance that could result in some sharing of basic information about digital security issues. For nearly a year, banks and law firms have discussed setting up a legal group that would be affiliated with the banking industry’s main forum for sharing information about threats from hackers, online criminals and even nation states – the Financial Services Information Sharing and Analysis Center . Several people briefed on those discussions said those talks would most likely lead to the establishment of such a group by the end of the year, a recognition that hackers are increasingly focusing on big law firms to glean information about their corporate clients. Law enforcement agencies have long been concerned about the vulnerability of United States law firms to online attacks because they are seen by hackers and nations bent on corporate espionage as a rich repository of company secrets, business strategies and intellectual property. But attacks on law firms often go unreported because the firms are private and not subject to the same kind of data-breach reporting requirements as public companies that handle sensitive consumer information. Over the last several months, Mandiant, the security firm that is a division of FireEye, has been advising a half-dozen law firms that were the subject of a breach, said a person briefed on the matter who spoke on the condition of anonymity. Mandiant, during a recent presentation at a legal conference, said many of the bigger hackings of law firms had ties to the Chinese government, which was seeking information on patent applications, trade secrets, military weapons systems and contract negotiations. The law firm group under consideration would be set up as an organization to share and analyze information and would permit firms to share anonymously information about hackings and threats on computer networks in much the same way that bank and brokerage firms share similar information with the financial services group. And while the two groups would not necessarily share information with each other, the law firms would have access to some of the resources of the financial center, which has existed since 1999 and is one of the better-funded industry threat-sharing organizations. [ Polley : I’m helping the ABA assess whether/how it might facilitate similar ISAC-like activities; we fear that most firms (other than the very largest) wouldn’t grok the value-proposition. Reactions?]

 

Provided by MIRLN

Photo courtesy of Creative Commons: https://www.flickr.com/photos/albertocarrasco