How to Stop Apps From Listening in on Your TV Habits (it turns out thousands are)

That innocent-looking mobile game you just downloaded might just have an ulterior motive. Behind the scenes, hundreds of different apps could be using your smartphone’s microphone to figure out what you watch on TV, a new report from The New York Times reveals. […] All of these apps need to get your permission before they Read more about How to Stop Apps From Listening in on Your TV Habits (it turns out thousands are)[…]

Ghostery, uBlock, Privacy Badger lead the anti-tracking browser extensions

A group of researchers in France and Japan say RequestPolicyContinued and NoScript have the toughest policies, while Ghostery and uBlock Origin offer good blocking performance and a better user experience. The study also gave a nod to the EFF’s Privacy Badger, which uses heuristics rather than block lists, but once trained is nearly as good Read more about Ghostery, uBlock, Privacy Badger lead the anti-tracking browser extensions[…]

How to Track a Cellphone Without GPS—or Consent

Using only data that can be legally collected by an app developer without the consent of a cellphone’s owner, researchers have been able to produce a privacy attack that can accurately pinpoint a user’s location and trajectory without accessing the device’s Global Position System—GPS. And while the ramifications of this ability falling into the wrong Read more about How to Track a Cellphone Without GPS—or Consent[…]

Email tracking now extends to your acquantances: 1 in 5!

According to OMC’s data, a full 19 percent of all “conversational” email is now tracked. That’s one in five of the emails you get from your friends. And you probably never noticed.“Surprisingly, while there is a vast literature on web tracking, email tracking has seen little research,” noted an October 2017 paper published by three Read more about Email tracking now extends to your acquantances: 1 in 5![…]

New Google Home Mini update 1.29 restores top tap functionality with long-press on the side: doesn’t record everything anymore?

The Google Home Mini is a super-affordable way to get Google Assistant in your life, but Google was forced to hobble the device shortly after launch because a sticky touch sensor caused Artem’s Mini to record everything he said. Part of that functionality is now coming back with a small tweak. Instead of tapping the Read more about New Google Home Mini update 1.29 restores top tap functionality with long-press on the side: doesn’t record everything anymore?[…]

Sopranica: an Anonymous, DIY Cell Phone Network

For the past few years, Gingerich has been laying the groundwork for Sopranica, an open source, DIY cell network that allows smartphone owners to make calls, send texts and eventually browse the internet with total anonymity.In January, Gingerich published the code for the first part of Sopranica called JMP. This is essentially a way of Read more about Sopranica: an Anonymous, DIY Cell Phone Network[…]

Coinbase ordered to report 14,355 users to the IRS

A California federal court has ordered Coinbase to turn over identifying records for all users who have bought, sold, sent, or received more than $20,000 through their accounts in a single year between 2013 and 2015. Coinbase estimates that 14,355 users meet the government’s requirements. The full order is embedded below. For each account, the Read more about Coinbase ordered to report 14,355 users to the IRS[…]

German Regulators Ban Smartwatches for Kids, Urge Parents to Destroy Them

Last month, the European Consumer Organization (BEUC) warned that smartwatches marketed to kids were a serious threat to children’s privacy. A report published by the Norwegian Consumer Council in mid-October revealed serious flaws in several of the devices that could easily allow hackers to seize control. Doing so could grant attackers access to both real-time Read more about German Regulators Ban Smartwatches for Kids, Urge Parents to Destroy Them[…]

Google collects Android location data even if you turn it off and don’t have a SIM card inserted

Since the beginning of 2017, Android phones have been collecting the addresses of nearby cellular towers—even when location services are disabled—and sending that data back to Google. The result is that Google, the unit of Alphabet behind Android, has access to data about individuals’ locations and their movements that go far beyond a reasonable consumer Read more about Google collects Android location data even if you turn it off and don’t have a SIM card inserted[…]

Forget cookies or canvas: How to follow people around the web using only their typing techniques

In this paper (Sequential Keystroke Behavioral Biometrics for MobileUser Identification via Multi-view Deep Learning), we propose DEEPSERVICE, a new technique that can identify mobile users based on user’s keystroke information captured by a special keyboard or web browser. Our evaluation results indicate that DEEPSERVICE is highly accurate in identifying mobile users (over 93% accuracy). The Read more about Forget cookies or canvas: How to follow people around the web using only their typing techniques[…]

Large companies in NL giving Facebook personal client data freely

The companies asked by the consumer protection authority are de ANWB, Nuon en Oxfam Novib. De Bijenkorf stopte hier al eerder mee. Essent heeft toegezegd binnenkort te stoppen en KLM en Transavia heroverwegen hun aanpak. De Bankgiroloterij, FBTO, KPN/Telfort, Postcodeloterij, Vakantieveilingen, Vriendenloterij en de Persgroep blijven gewoon doorgaan. Van Heerlijk.nl, HelloFresh en Hotels.nl To be Read more about Large companies in NL giving Facebook personal client data freely[…]

Yes, Google is reading your corporate documents and you agreed to it.

Many people worried that Google was scanning users’ documents in real time to determine if they’re being mean or somehow bad. You actually agree to such oversight in Google G Suite’s terms of service. Those terms include include personal conduct stipulations and copyright protection, as well as adhering to “program policies.” Who knows what made the Read more about Yes, Google is reading your corporate documents and you agreed to it.[…]

International (24 regulators) enforcement operation finds website privacy notices are too vague and generally inadequate (over 455 websites and apps)

An investigation by 24 data protection regulators from around the world – led by the UK’s Information Commissioner’s Office – concluded that ‘there is significant room for improvement in terms of specific details contained in privacy communications’.The privacy notices, communications and practices of 455 websites and apps in sectors including retail, finance and banking, travel, Read more about International (24 regulators) enforcement operation finds website privacy notices are too vague and generally inadequate (over 455 websites and apps)[…]

Android Is Quietly Sharing Your Physical Activity with Other Apps

Google snuck a questionable feature into the operating system with a recent update. A new permission called “activity recognition” may be tracking your physical activity and sharing it with third-party apps, and there’s no easy way to stop it. What Is Activity Recognition? The “activity recognition” permission was shared on Reddit earlier this week. Basically, Read more about Android Is Quietly Sharing Your Physical Activity with Other Apps[…]

What DNA Testing Companies’ Terrifying Privacy Policies Actually Mean

When you spit in a test tube in in hopes of finding out about your ancestry or health or that perfect, genetically optimized bottle of wine, you’re giving companies access to some very intimate details about what makes you, you. Your genes don’t determine everything about who you are, but they do contain revealing information Read more about What DNA Testing Companies’ Terrifying Privacy Policies Actually Mean[…]

For Under $1,000, Mobile Ads Can Track Your Location

The idea is straightforward: Associate a series of ads with a specific individual as well as predetermined GPS coordinates. When those ads are served to a smartphone app, you know where that individual has been… It’s a surprisingly simple technique, and the researchers say you can pull it off for “$1,000 or less.” The relatively Read more about For Under $1,000, Mobile Ads Can Track Your Location[…]

Warning: Microsoft is using Cortana to read your private Skype conversations

Cortana is a decent voice assistant. Hell, “she” is probably better than Apple’s woefully disappointing Siri, but that isn’t saying very much. Still, Microsoft’s assistant very much annoys me on Windows 10. I don’t necessarily want to use my desktop PC like my phone, and sometimes I feel like she is intruding on my computer. Read more about Warning: Microsoft is using Cortana to read your private Skype conversations[…]

If you don’t want Sonos to have your personal data, they will brick your players for you

Sonos’ policy change, outlined by chief legal officer Craig Shelburne, allows the gizmo manufacturer to slurp personal information about each owner, such as email addresses and locations, and system telemetry – collectively referred to as functional data – in order to implement third-party services, specifically voice control through Amazon’s Alexa software, and for its own Read more about If you don’t want Sonos to have your personal data, they will brick your players for you[…]

Dutch privacy regulator says Windows 10 breaks the law: wants MS to inform you how it’s breaching your privacy, not stop it.

The lack of clear information about what Microsoft does with the data that Windows 10 collects prevents consumers from giving their informed consent, says the Dutch Data Protection Authority (DPA). As such, the regulator says that the operating system is breaking the law. To comply with the law, the DPA says that Microsoft needs to Read more about Dutch privacy regulator says Windows 10 breaks the law: wants MS to inform you how it’s breaching your privacy, not stop it.[…]

OnePlus Admits It Was Snooping on OxygenOS Users, Says It Will Tweak Data Collection Program. Current fix still spies on you.

Earlier this month, software engineer Christopher Moore discovered that Shenzen, China-based phone manufacturer OnePlus was secretly collecting a trove of data about users without their consent and communicating it to company servers. Moore had routed his OnePlus 2’s internet traffic through security tool OWASP ZAP for a holiday hack challenge, but noticed his device was Read more about OnePlus Admits It Was Snooping on OxygenOS Users, Says It Will Tweak Data Collection Program. Current fix still spies on you.[…]

Russia tweaks Telegram with tiny fine for decryption denial

Encrypted messaging app Telegram must pay 800,000 roubles for resisting Russia’s FSB’s demand that it help decrypt user messages. The fine translates to just under US$14,000, making it less of a serious punishment and more a shot across the bows. […] Telegram founder Pavel Durov has posted to Russian social site VK.com that it’s not Read more about Russia tweaks Telegram with tiny fine for decryption denial[…]

SVR Tracking leaks info for hundreds of thousands of vehicles. Turns out they have been tracking you even when your car wasn’t stolen.

Researchers discovered a misconfigured Amazon AWS S3 bucket that was left publically available. The breach has exposed information about their customers and re-seller network and also the physical device that is attached to the cars. The repository contained over a half of a million records with logins / passwords, emails, VIN (vehicle identification number), IMEI Read more about SVR Tracking leaks info for hundreds of thousands of vehicles. Turns out they have been tracking you even when your car wasn’t stolen.[…]