Posts Tagged: information

House passes bill that would bar data brokers from selling Americans’ personal information to ‘adversary’ countries

The House of Representatives approved a measure targeting data brokers’ ability to sell Americans’ personal data to “adversary” countries, like Russia, China, Iran and North Korea. The Protecting Americans’ Data from Foreign Adversaries Act passed with a unanimous 414 – 0 vote.

The bill, which was introduced alongside a measure that could force a ban or sale of TikTok, would prohibit data brokers from selling Americans’ “sensitive” data to people or entities in “adversary” countries. Much like a recent executive order from President Joe Biden targeting data brokers, the bill specifically covers geolocation, financial, health, and biometric data, as well as other private information like text logs and phone call history.

If passed — the bill will need Senate approval before landing on Biden’s desk — it would represent a significant check on the relatively unregulated data broker industry. US officials have previously warned that China and other geopolitical rivals of the United States have already acquired vast troves of Americans’ information from brokers and privacy advocates have long urged lawmakers to regulate the multibillion-dollar industry.

The bill is the second major piece of bipartisan legislation to come out of the House Energy and Commerce this month. The committee previously introduced the “Protecting Americans from Foreign Adversary Controlled Applications Act,” which would require TikTok to divest itself from parent company ByteDance or face a ban in the US. In a statement, Representatives Frank Pallone and Cathy McMorris Rodgers, said that the latest bill “builds” on their work to pass the measure targeting TikTok. “Today’s overwhelming vote sends a clear message that we will not allow our adversaries to undermine American national security and individual privacy by purchasing people’s personally identifiable sensitive information from data brokers,” they said.

This article originally appeared on Engadget at https://www.engadget.com/house-passes-bill-that-would-bar-data-brokers-from-selling-americans-personal-information-to-adversary-countries-004735748.html?src=rss
Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

Mint Mobile says hackers accessed customer information during a security breach

Mint Mobile, the prepaid mobile carrier backed by Ryan Reynolds, notified customers via email this weekend that their information may have been stolen in a security breach, according to BleepingComputer. That information includes names, phone numbers, email addresses, plan descriptions, and SIM and IMEI numbers — which could be used for SIM swap attacks.

After a Reddit user posted a screenshot of the email and questioned if it was a scam, the Mint account responded to confirm its validity and said a customer support number has been set up to handle questions about the breach. Hackers did not access customers’ credit card information, which Mint says is not stored, nor were passwords compromised, BleepingComputer reports. The company also said it has since resolved the breach and customers do not need to take any action.

This article originally appeared on Engadget at https://www.engadget.com/mint-mobile-says-hackers-accessed-customer-information-during-a-security-breach-185215800.html?src=rss
Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

23andMe hackers accessed ancestry information on millions of customers using a feature that matches relatives

An SEC filing has revealed more details on a data breach affecting 23andMe users that was disclosed earlier this fall. The company says its investigation found hackers were able to access the accounts of roughly 0.1 percent of its userbase, or about 14,000 of its 14 million total customers, TechCrunch notes. On top of that, the attackers were able to exploit 23andMe’s opt-in DNA Relatives (DNAR) feature, which matches users with their genetic relatives, to access information about millions of other users. A 23andMe spokesperson told Engadget that hackers accessed the DNAR profiles of roughly 5.5 million customers this way, plus Family Tree profile information from 1.4 million DNA Relative participants.

DNAR Profiles contain sensitive details including self-reported information like display names and locations, as well as shared DNA percentages for DNA Relatives matches, family names, predicted relationships and ancestry reports. Family Tree profiles contain display names and relationship labels, plus other information that a user may choose to add, including birth year and location. When the breach was first revealed in October, the company said its investigation “found that no genetic testing results have been leaked.” 

According to the new filing, the data “generally included ancestry information, and, for a subset of those accounts, health-related information based upon the user’s genetics.” All of this was obtained through a credential-stuffing attack, in which hackers used login information from other, previously compromised websites to access those users’ accounts on other sites. In doing this, the filing says, “the threat actor also accessed a significant number of files containing profile information about other users’ ancestry that such users chose to share when opting in to 23andMe’s DNA Relatives feature and posted certain information online.”

Following the discovery of the breach, 23andMe instructed affected users to change their passwords and later rolled out two-factor authentication for all of its customers. In another update on Friday, 23andMe said it had completed the investigation and is notifying everyone who was affected. The company also wrote in the filing that it “believes that the threat actor activity is contained,” and is working to have the publicly-posted information taken down.

Update, December 2 2023, 7:03PM ET: This story has been updated to include information provided by a 23andMe spokesperson on the scope of the breach and the number of DNA Relative participants affected.

This article originally appeared on Engadget at https://www.engadget.com/23andme-hackers-accessed-ancestry-information-from-thousands-of-customers-and-their-dna-relatives-205758731.html?src=rss
Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

Dutch hacker arrested for trying to sell the personal information of nearly every Austrian citizen

Dutch authorities arrested a hacker for obtaining and trying to sell the personal information of nearly every Austrian citizen in May 2020, according to Reuters. It includes almost nine million data sets, roughly lining up with Austria’s population.

The defendant, arrested in November in an Amsterdam apartment, was reportedly already known to international police. The 25-year-old defendant also offered “similar data sets” from Italy, the Netherlands and Colombia. Dutch police waited until now to announce the arrest to avoid hindering ongoing investigations.

Authorities say the hacker posted the information in an online forum. Police say the trove consists of “registration data,” essential info residents must provide to authorities. That includes their full name, address and date of birth — but not financial info, fortunately. Nevertheless, the police confirmed the material’s authenticity, adding that “since this data was freely available on the Internet, it must absolutely be assumed that these registration data are, in full or in part, irrevocably in the hands of criminals.”

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

More information, faster removals, more people – an update on what we’re doing to enforce YouTube’s Community Guidelines

In December we shared how we’re expanding our work to remove content that violates our policies. Today, we’re providing an update and giving you additional insight into our work, including the release of the first YouTube Community Guidelines Enforcement Report.

Providing More Information
We are taking an important first step by releasing a quarterly report on how we’re enforcing our Community Guidelines. This regular update will help show the progress we’re making in removing violative content from our platform. By the end of the year, we plan to refine our reporting systems and add additional data, including data on comments, speed of removal, and policy removal reasons.

We’re also introducing a Reporting History dashboard that each YouTube user can individually access to see the status of videos they’ve flagged to us for review against our Community Guidelines.

Machines Helping to Address Violative Content
Machines are allowing us to flag content for review at scale, helping us remove millions of violative videos before they are ever viewed. And our investment in machine learning to help speed up removals is paying off across high-risk, low-volume areas (like violent extremism) and in high-volume areas (like spam).

Highlights from the report — reflecting data from October – December 2017 — show:

  • We removed over 8 million videos from YouTube during these months.1 The majority of these 8 million videos were mostly spam or people attempting to upload adult content – and represent a fraction of a percent of YouTube’s total views during this time period.2
  • 6.7 million were first flagged for review by machines rather than humans
  • Of those 6.7 million videos, 76 percent were removed before they received a single view.

For example, at the beginning of 2017, 8 percent of the videos flagged and removed for violent extremism were taken down with fewer than 10 views.3 We introduced machine learning flagging in June 2017. Now more than half of the videos we remove for violent extremism have fewer than 10 views.

The Value of People + Machines
Deploying machine learning actually means more people reviewing content, not fewer. Our systems rely on human review to assess whether content violates our policies. You can learn more about our flagging and human review process in this video:


Last year we committed to bringing the total number of people working to address violative content to 10,000 across Google by the end of 2018. At YouTube, we’ve staffed the majority of additional roles needed to reach our contribution to meeting that goal. We’ve also hired full-time specialists with expertise in violent extremism, counterterrorism, and human rights, and we’ve expanded regional expert teams.

We continue to invest in the network of over 150 academics, government partners, and NGOs who bring valuable expertise to our enforcement systems, like the International Center for the Study of Radicalization at King’s College London, Anti-Defamation League, and Family Online Safety Institute. This includes adding more child safety focused partners from around the globe, like Childline South Africa, ECPAT Indonesia, and South Korea’s Parents’ Union on Net.

We are committed to making sure that YouTube remains a vibrant community with strong systems to remove violative content and we look forward to providing you with more information on how those systems are performing and improving over time.

— The YouTube Team

1 This number does not include videos that were removed when an entire channel was removed. Most channel-level removals are due to spam violations and we believe that the percentage of violative content for spam is even higher.
2Not only do these 8 million videos represent a fraction of a percent of YouTube’s overall views, but that fraction of a percent has been steadily decreasing over the last five quarters.
3This excludes videos that were automatically matched as known violent extremist content at point of upload – which would all have zero views.


YouTube Blog

Snapchat announces Context Cards, adding contextual information to Snaps

Snapchat has just added a useful new feature that butts heads with Google Assistant and other AI helpers on your phone. I never would’ve expected Snapchat to try and tackle that kind of market, but today we’re getting Context Cards in our Snaps. Context Cards display information about whatever Snap you’re viewing using information from […]

Come comment on this article: Snapchat announces Context Cards, adding contextual information to Snaps

Visit TalkAndroid


TalkAndroid