Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, September 18, 2011

Security » FTC: Mobile Apps Not Exempt From Children's Privacy Regs

Posted by echa 10:24 AM, under | No comments

FTC: Mobile Apps Not Exempt From Children's Privacy Regs | Mobile Apps "App publishers that disregard COPPA, regardless of the communication methodology, do so at their own risk, and W3 makes it clear -- though it should have already been so -- that apps that interact with the World Wide Web or use Internet Protocol are without question covered," said Alan Friel, a partner with Wildman, Harrold, Allen & Dixon.

Federal regulations designed to protect children's privacy cover the burgeoning mobile apps business as well as other online vehicles accessible through laptops or desktops. In fact, providers of mobile apps need to pay attention to the privacy impact not only of services offered specifically to children, but also those targeting the broader community that are nevertheless accessible to children.

In an enforcement case it revealed on Aug. 12, the Federal Trade Commission asserted that the Children's Online Privacy Protection Act (COPPA) covers mobile app offerings.

The enforcement action involved a complaint against a publisher of electronic games. The FTC alleged that W3 Innovations, through its Broken Thumbs Apps unit, developed and distributed mobile apps for the iPhone and iPod touch that allowed users to play games and share information online.

Several of the apps were directed to children and were listed in the Games-Kids section of Apple's (Nasdaq: AAPL) App Store. There were more than 50,000 downloads of those apps, the FTC said. They allowed children to play classic games, such as "Cootie Catcher" and "Truth or Dare," and to create virtual models and design outfits.

In the W3 Innovations case, the apps developed by the company encouraged children to email their comments and submit blogs to a company-generated site via email, such as "shout-outs" to friends and requests for advice.

The publisher collected and maintained more than 30,000 email addresses, the FTC alleged.

In addition, the defendants allowed children to publicly post comments, including personal information, on message boards, according to the agency.

Impact Goes Beyond Kids' Apps

Because the company's interactive apps send and receive information via the Internet, they are online services covered by COPPA, the FTC said.

"The FTC's COPPA rule requires parental notice and consent before collecting children's personal information online, whether through a website or a mobile app," said agency chairman Jon Leibowitz.

The rule also requires that website operators post a privacy policy that is clear, understandable and complete, but the company did not provide notice of its information collection practices and did not obtain the required parental consent, the FTC charged.

"Companies must give parents the opportunity to make smart choices when it comes to their children's sharing of information on smartphones," said Leibowitz.

"W3 is the first FTC case directly applying COPPA to mobile apps," Alan Friel, a partner with Wildman, Harrold, Allen & Dixon, told TechNewsWorld.

There is still a question about the scope of COPPA in terms of private mobile app networks versus public networks, although private channels are relatively small in terms of use by the general public, including children, Friel observed.

"That said, app publishers that disregard COPPA, regardless of the communication methodology, do so at their own risk, and W3 makes it clear -- though it should have already been so -- that apps that interact with the World Wide Web or use Internet Protocol are without question covered," Friel said.

"The W3 case was focused on information about children and is generally applicable to all mobile app providers insofar as they collect information about children," Mark MacCarthy, vice president of public policy at the Software and Information Industry Association, told TechNewsWorld.

"W3 is important not just for kid's app publishers," noted Friel. "Websites that target adults, not children, have ended up paying seven-figure settlements for violating COPPA where they knowingly collected personal information from children under 13 without verified parental consent."

A common mistake occurs when age is collected at registration but those indicating they are under 13 are still allowed to register.

"All app publishers, particularly those that allow users to create profiles, need to take heed of W3," said Friel.

Congress Aware of Issue

The W3 case caught the attention of key lawmakers.

"Mobile apps can be great tools for kids to learn and have fun, but parents should never have to worry that their child's personal information is being collected or violated," said Sen. Amy Klobuchar, D-Minn.

"As the House author of COPPA," said Rep. Edward Markey, D-Mass., "I am pleased that the FTC pursued and brought charges against a mobile applications developer that was collecting and disclosing personal information about children under 13 in apparent violation of COPPA. Since COPPA was signed into law in 1998, children increasingly connect to the Internet on the go, using an array of mobile apps and new services that did not exist when the law was enacted."

While the FTC's action was based on existing law, Markey and Rep. Joe Barton, R-Texas, jointly introduced legislation last May that would provide a specific statutory basis for including mobile apps under COPPA. The bill would amend COPPA to include the term "mobile applications" within the definition of "operator."

The bill, titled the "Do Not Track Kids Act of 2011," emphasizes protection associated with geo-location information but also says that within COPPA such terms as "online," "online service," "online application," "mobile application," and "directed to children" shall have the meanings given them by the FTC.

Without admitting to the allegations, W3 settled the case with the FTC, consenting to pay a US$50,000 penalty. The settlement also bars the company from future violations of the COPPA rule and requires the publisher to delete all personal information collected in violation of the FTC's rules.

W3's Broken Thumbs unit was "very surprised" by the FTC's action. Broken Thumbs "provided users with a means of interacting with one another and with our customer service department, which required the collection and retention of users' email addresses," the company explained in a statement provided to TechNewsWorld by Barry Reingold, an attorney with Perkins Coie.

Broken Thumbs "did not ask for or collect information about the age of our users because there was no technical or functional need for this information," and its "sole purpose in collecting email data was to improve the user experience with our apps," it said. The company contended that no email address was ever used for marketing purposes or sold to another firm.

"As soon as the FTC informed us of its specific concerns -- and long before entry of the settlement order -- we took corrective action," the company said. "Any violations were inadvertent."

Security » FTC: Mobile Apps Privacy Protection Not Just for Kids

Posted by echa 10:17 AM, under | No comments

Security The legal basis for FTC action on privacy leans heavily on the agency's mandate to regulate deceptive practices. "FTC actions to date with regard to adult consumer data privacy and security have dealt with companies that do not follow their own policies, or have misleading policies or no notice of their policies at all," said Alan Friel, a partner with Wildman Harrold. Such deficiencies are considered deceptive practices.

Providers of apps for mobile devices are just as responsible as other electronic commerce vendors in terms of protecting the privacy of customers. In a recent enforcement action, the Federal Trade Commission (FTC) signaled that mobile apps fall within the agency's jurisdiction, and that it will not hesitate to investigate potential privacy violations associated with mobile apps.

The enforcement action involved a complaint against a publisher of electronic games, and it marked the first time the FTC initiated a privacy case involving apps for mobile devices.

W3 Innovations, through its Broken Thumbs Apps unit, developed and distributed mobile apps for the iPhone and iPod touch that allowed users to play games and share information online. Several of the apps were directed to children and were listed in the Games-Kids section of Apple's (Nasdaq: AAPL) App Store. There were more than 50,000 downloads of those apps, according to the FTC.

While the W3 Innovations case was largely based on provisions related to the Children's Online Privacy Protection Act (COPPA), a key element in the case was FTC's determination that mobile apps are subject to its jurisdiction regarding privacy protection for all users, regardless of age.

Not Just for Kids

"The case represents the FTC's first enforcement action against a mobile app developer, and it seems to send a clear message that mobile app developers should follow the same rules as more traditional websites when it comes to consumer privacy issues and privacy policies, especially when marketing to children," states Wildman, Harrold, Allen & Dixon in an analysis of the case posted online.

"There is no doubt that the evolution of consumer data privacy we are currently experiencing includes mobile," Alan Friel, a partner with Wildman Harrold, told TechNewsWorld.

The FTC has more than just hinted that mobile apps of all types are on its regulatory radar screen. The W3 Innovations case arose "because we have been paying attention to that area," Claudia Farrell, a spokesperson for the agency, told TechNewsWorld. Additional mobile app inquiries are in the pipeline at the FTC.

"Although the FTC does not enforce any special laws applicable to mobile marketing, the FTC's core consumer protection law -- Section 5 of the FTC Act -- prohibits unfair or deceptive practices in the mobile arena," David Vladeck, director of FTC's Bureau of Consumer Protection, said at a Senate hearing last May.

The FTC "is making a concerted effort to ensure that it has the necessary technical expertise, understanding of the marketplace, and tools needed to monitor, investigate, and prosecute deceptive and unfair practices in the mobile arena," Vladeck added.

The legal basis for FTC action on privacy leans heavily on the agency's mandate to regulate deceptive practices -- rather than a standard that relates to invasion of privacy per se.

"FTC actions to date with regard to adult consumer data privacy and security have dealt with companies that do not follow their own policies, or have misleading policies or no notice of their policies at all," Friel said. Such deficiencies are considered deceptive practices.

Industry Active on Mobile Front

The issue of mobile apps privacy has suddenly become significant for online businesses. In early September, for example, the Software & Information Industry Association (SIIA) joined the Future of Privacy Forum's Application Privacy Working Group and became a sponsor of FPF's Application Privacy project.

SIIA's participation with FPF is aimed at helping to develop voluntary privacy principles and best practices for mobile software applications. The goal is to lessen the likelihood of burdensome government regulation.

"Mobile app developers have a responsibility to create and disclose their privacy policies when they collect and use personal information. We are joining this effort out of the conviction that the industry does not need government regulation to move us in the direction of providing a trusted environment for our users," said Mark MacCarthy, vice president of public policy at SIIA.

While the W3 Innovations case highlighted the mobile apps privacy issue, SIIA's involvement with the FPF project was not solely based on the FTC's action.

"The W3 case was focused on information about children and is generally applicable to all mobile app providers insofar as they collect information about children. The need for good privacy practices is broader than that, and it was this broader concern for good data protection practices that motivated SIIA to affiliate with the Future of Privacy Forum," MacCarthy told TechNewsWorld.

"Continued growth and innovation in the vibrant mobile marketplace is dependent on consumer confidence in the privacy protections provided by mobile application providers. While many mobile application developers are transparent about their collection, use, and protection of consumer data, recent reports have indicated that this is not always the case," MacCarthy said.

Mobile apps providers will need to keep a sharp eye on how privacy eventually is regulated.

Self-Regulation Questioned

"FTC leadership has been fairly vocal in expressing its dissatisfaction with the effectiveness of current self-regulatory efforts. Congress too has grown inpatient, and a half dozen bills are under consideration that may result in greater regulatory authority for the FTC and requirements for greater transparency, choice, and security for consumers regarding their data, particularly regarding behavioral advertising, which tracks and targets consumer behavior and mobile," Friel said.

The class action bar has brought more than 50 lawsuits this year dealing with online and mobile tracking or targeting, he noted. "The issue is not going away soon."

In the W3 Innovations case, the apps developed by the company encouraged children to email their comments -- such as "shout-outs" to friends and requests for advice -- to a company-generated site. The FTC alleged that the publisher collected and maintained more than 30,000 email addresses in violation of federal regulations, including parental notice.

In addition, the FTC alleged that the defendants allowed children to publicly post comments, including personal information, on message boards.

Without admitting to the allegations, the company settled the case with the FTC on August 12. The firm consented to pay a US$50,000 penalty. The settlement also bars the company from future violations of the COPPA rule and requires the publisher to delete all personal information collected in violation of the FTC's rules.

W3 "did not ask for or collect information about the age of our users because there was no technical or functional need for this information," the company said in a statement provided to TechNewsWorld by Barry Reingold, an attorney with Perkins Coie.

W3 Innovations maintained that "any violations were inadvertent."

Tuesday, September 13, 2011

Security » Can an Anti-Child Porn Bill Go Too Far?

Posted by echa 2:38 AM, under | No comments

Security » Can an Anti-Child Porn Bill Go Too Far? As written, the bill H.R. 1981 aims to stamp out child pornography with new penalties and enforcement powers. So how can anyone in their right mind oppose it? Civil liberties and privacy rights groups, however, say the bill's provisions go much too far in tracking and storing information about all Internet users. They also say child porn traders will respond to the law by simply using public WiFi networks.

H.R. 1981, a U.S. federal bill which apparently seeks to combat child pornography, has stirred up opposition from various lawmakers as well as civil rights groups.

The proposed law, introduced in May and now under consideration in Congress, is the joint creation of Rep. Lamar Smith, R-Texas, chairman of the Judiciary Committee; and Rep. Debbie Wasserman Schultz, D-Fla., who chairs the Democratic National Committee. It has 24 sponsors.

The bill seeks to make it a federal crime to fund the sale, distribution and purchase of child pornography and to increase the maximum penalty for certain child pornography offenses.

It's supported by the National Center for Missing and Exploited Children, the National Center for Victims of Crime, the National Sheriff's Association, the Major County Sheriff's Association, the International Union of Police Associations, and the Fraternal Order of Police.

The bill's title is "The Protecting Children From Internet Pornographers Act of 2011." Judging the bill by its cover, it's difficult to image who in the world would oppose such an idea. However, groups such as the Electronic Frontier Foundation, the Center for Democracy and Technology, the Electronic Privacy Information Center, and several members of Congress including Rep. Zoe Lofgren, D-Calif., have spoken out against certain aspects of the bill.

Other opponents include Republican Bob Barr, a former congressman from Georgia, and Rep. Jim Sensenbrenner, R-Wis., who is one of the authors of the REAL ID Act. That act establishes federal standards for state-issued drivers' licenses and other identification, among other things.

What H.R. 1981 Seeks to Do

The aims of H.R. 1981 include more tightly defining acts related to child pornography and increasing the punishment for those convicted of child porn.

For example, it proposes that whoever financially facilitates access to child porn will be fined or imprisoned for up to 20 years, or both.

The bill also seeks to provide greater protection to child witnesses against harassment and intimidation.

Further, it seeks to impose heavier penalties on the possession of child pornography.

Few would argue against these aims.

However, the issue attracting heavy debate concerns a provision in the bill that would require Internet service providers (ISPs) to retain the network addresses they temporarily assign to each account for, after amendment, a period of 18 months. They would also have to securely store those records to protect customer privacy and prevent data breaches.

Further, ISPs will not be legally liable for releasing the data they have stored under the provisions of this bill.

Wireless Internet access like the kind provided by cellphone networks is exempted.

Arguments for the Bill

"The bill is an attempt to come up with a reasonable compromise regarding an issue of great law enforcement concern for many years -- data retention," Ernie Allen, president of the National Center for Missing & Exploited Children (NCMEC), told TechNewsWorld.

H.R. 1981 only requires ISPs to retain information proving or establishing connectivity and doesn't require them to retain content, Allen said.

The biggest challenge in child pornography cases is connecting a real person to illegal content at the precise moment that content was accessed or distributed online, Allen stated.

"Most people do not understand that IP addresses are dynamic," Allen pointed out. Dynamic IP addresses can change at any time. "The bill is intended to capture the concept that IP addresses are assigned at time of log-in" because it uses the phrase "temporarily assigned network address," Allen said.

Last year alone, NCMEC received 223,000 reports of suspected child sexual exploitation crimes, more than 90 percent of which involved online child porn, Allen said. During that period, the Center's Child Victim Identification Program reviewed and analyzed 13.6 million child pornography images and videos to try and identify and rescue victims.

"The greatest challenge here is that there is a significant missing link," Allen said. "There can be no prosecution until law enforcement connects the data and time of that online activity to an actual person -- the type of information found in an ISP's connectivity log."

Those connectivity logs are analogous to the records United States federal law requires telephone companies to keep of the date and time that a phone number is dialed, Allen contends.

Why Some Fear H.R. 1981

Many of the arguments from members of Congress opposed to the bill can be summed up in Lofgren's stance: While child pornography is a very serious crime, the bill's provisions are much too sweeping, and it will let ISPs track every website Americans visit and make that information available to the federal government without a warrant.

They contend that H.R. 1981 will go way beyond fighting child porn.

That's a stance also taken by civil rights groups.

"Language in the bill strongly suggests that not only the IP address has to be retained but also information that identifies the customer who had that address at the time -- what credit card you use to pay for the service, what bank you write your checks on," pointed out Gregory Nojeim, a director at the Center for Democracy and Technology.

"What really concerns me is the data that will be retained will be used in investigations that are not the subject of the bill, which is protecting children from child pornography," Nojeim told TechNewsWorld.

Law enforcement already has the powers it needs to track criminals online, argued Richard Esguerra, a senior activist at the Electronic Frontier Foundation.

"With the correct permissions, law enforcement already has the ability to tell ISPs to track a subscriber suspected of a crime," Esguerra told TechNewsWorld. "This approach is more appropriate and allows law enforcement to focus on actual, useful data without forcing ISPs to manage mountains of data tied to Internet users' normal, legal Internet activities," he added.

The length of time that ISPs retain customer data varies.

"Some do retain this information and some don't, and it appears that the length of time that such information is stored -- if at all -- is as short as seven days," Esguerra said.

Maintaining IP addresses for 12 months or so may not be as effective as claimed, warned Darren Hayes, CIS Program chair at Pace University.

In fact, the law "will actually push more pedophiles to use a proxy service or go to a local library to mask their identity," Hayes told TechNewsWorld.

If law enforcement wants help with its investigations, Hayes wondered, why not access Google's (Nasdaq: GOOG) databases?

"Google can provide a great deal more information on a suspect than any ISP can," Hayes pointed out. "It's not a privacy issue because Google is already collecting a huge array of information about individuals and their online activity."

ISPs Verizon and AT&T (NYSE: T) did not respond to requests to comment for this story. The office of Rep. Schultz, one of the co-sponsors of the bill, also did not respond to requests for comment.

Wednesday, September 7, 2011

Security » Scotland Yard Tightens the Pincers on Anonymous

Posted by echa 12:56 AM, under | No comments

Security » Scotland Yard Tightens the Pincers on Anonymous Are law enforcement securities making headway against hacktivist groups like Anonymous and LulzSec? It's possible -- last week Scotland Yard nabbed two people suspected of launching attacks under the moniker "Kayla." That's a name synonymous with the notorious attack on HBGary earlier this year.

It's been another wild and crazy week for the security community.

Scotland Yard arrested two suspected members of Anonymous and LulzSec Thursday.

Meanwhile, the major players in the browser market -- Google (Nasdaq: GOOG), Microsoft (Nasdaq: MSFT) and the Mozilla Foundation -- have chopped Dutch certificate DigiNotar off at the knees, apparently because it was slow to warn that hackers had broken into its network and issued rogue SSL security certificates.

Further, a security researcher released information that hackers could use to leverage Google's massive bandwidth and launch large-scale distributed denial of service (DDoS) and SQL injection attacks.

The Star Wars Galaxies gaming site was also hacked this past week, and the hacker posted the user IDs and passwords of 23,000 of the site's members on the Web.

Finally, a survey by security vendor Veriphyr has found that healthcare organizations are suffering data breaches hand over fist.

Ho, Hackers! The Game's Afoot!

Scotland Yard arrested two suspects in separate counties Thursday, reportedly under suspicion of conducting online attacks under the handle "Kayla."

"Kayla" was allegedly among those behind the February Anonymous intrusions perpetrated on HBGary Federal, a company claiming to provide security to the United States federal government.

The attackers defaced HBGary's website, stole and published 71,000 internal emails from the company, and posted a message denouncing the HBGary.

Lack of Speed Kills

On Monday, Google learned that some users of its encrypted services in Iran suffered attempts at man-in-the-middle attacks, where someone tries to intercept communications between two parties.

The attacker used a fake SSL certificate issued by Dutch root certificate authority DigiNotar.

It seems an intruder had broken into DigiNotar's systems back in July and stolen up to 200 rogue, or fraudulent, SSL certificates, some for major domains.

DigiNotar had known about the breach since July 19 but apparently had not disclosed the information.

In response, Google, Mozilla and Microsoft all revoked trust in the DigiNotar root certificate in their browsers.

"These certificates could be used as part of attacks designed to harvest user Gmail credentials and gain access to sensitive data," Norman Sadeh, cofounder of Wombat Security Technologies, told TechNewsWorld.

Disabling DigiNotar's root certificate authority was justified because "security across the Internet is a shared responsibility and our root certificate authorities must be held to the highest standard," Don DeBolt, director of threat research at Total Defense, told TechNewsWorld.

Google spokesperson Chris Gaither declined comment.

Leveraging Google's Bandwidth for Hacks

A security researcher has disclosed on the IHTeam blog how attackers can use Google's servers to launch a DDoS attack.

Hackers can also use the technique to launch SQL injection attacks, one of the top 10 vectors of attack, according to the tester, who goes by the handle "r00t.ati."

The tester posted the information Monday after Google's security center had failed to respond to a notification of the threat sent Aug. 10.

Google posted a message on the IHTeam blog Friday apologizing and stating it has tweaked its security.

"This is a serious issue, and even if Google fixes these two vulnerable pages, bad actors will likely comb Google's pages from now on looking for a similar vulnerability," Total Defense's DeBolt remarked.

"My understanding is, this is not a software vulnerability, but rather a description of service misuse that we have not seen in practice," Google spokesperson Jay Nancarrow told TechNewsWorld.

Multiple social networking and online translator sites could also be used by hackers to launch attacks in the same way, Nancarrow pointed out.

The Force Isn't Strong With This One

This past week, a hacker broke into the Star Wars Galaxies gaming site, stole the user IDs and passwords of 23,000 members, and posted them on the Internet.

All the passwords are in plain text, the hacker said.

SWGalaxies isn't the only gaming site to have been victimized in recent months. Earlier this year, the Sega website and the Sony (NYSE: SNE) PlayStation Network were hacked, with data on more than 100 million users stolen in each case.

Are game sites more vulnerable than others? Not necessarily, but they often aren't as heavily fortified as, say, banking sites. That needs to change, Todd Feinman, CEO of Identity Finder, told TechNewsWorld.

"Any institution that stores personal information, including a password, should be held to a higher standard and be accountable for loss of sensitive data," Feinman stated.

Healthcare and Privacy

More than 70 percent of respondents to an online survey on privacy breaches concerning protected health information have suffered at least one breach in the past 12 months, according to a study conducted by security vendor Veriphyr.

Hospitals and health systems constituted 52 percent of the 90 respondents, Veriphyr CEO Alan Norquist told TechNewsWorld. Half the responding organizations had more than 1,000 employees.

The two leading types of breaches "involve legitimate insiders misusing their legitimate access to patient data by accessing the records for reasons other than healthcare," Norquist said.

Related Posts Plugin for WordPress, Blogger...