Pages

Showing posts with label LinkedIn. Show all posts
Showing posts with label LinkedIn. Show all posts

Tuesday, 10 December 2013

Tech giants call for limits on government surveillance

Leading technology companies have presented a unified front in calling for restrictions on U.S. government surveillance, as ongoing spying revelations undermine trust in their products around the globe.
Bombshell stories throughout the summer in The Guardian, Washington Post and other publications, based on leaks from former security contractor Edward Snowden, uncovered broad and varied digital surveillance programs by the National Security Agency and others. Many sucked up communications and user data handled by major tech companies either through legal requests, or secret taps on their networks.
The latest disclosure arrived on Monday, with news that U.S. and British spy agencies had infiltrated popular online games like World of Warcraft and Second Life. They created their own characters “to snoop and to try to recruit informers,” the New York Times reported, citing confidential documents provided by Snowden.
The move by AOL, Apple, Facebook, Google, LinkedIn, Microsoft and Twitter on Monday underscores the enormous toll that these disclosures could take on their bottom lines and expansion plans. Foreign citizens who lack privacy protections under U.S. law may choose to forgo the products of these companies, and some nations themselves are moving to block or sidestep U.S. Internet services.
Forrester analyst James Staten argued the cost to cloud services alone could reach as high as $180 billion, “or a 25 percent hit to overall IT service provider revenues” over the next three years.
The question is whether the combined lobbying strength of some of the biggest and most influential companies in the United States can rein in government spy tactics, in a way that public opinion and legislators have failed to do to date.
In an open letter to Congress and President Barack Obama published as full-page ads in several major newspapers, the seven tech companies stated: “This summer’s revelations highlighted the urgent need to reform government surveillance practices worldwide. The balance in many countries has tipped too far in favor of the state and away from the rights of the individual — rights that are enshrined in our Constitution.”
It added: “We urge the US to take the lead and make reforms that ensure that government surveillance efforts are clearly restricted by law, proportionate to the risks, transparent and subject to independent oversight.”
At a new website, ReformGovernmentSurveillance.com, the companies called for a series of specific principles and changes: including codifying “sensible limitations” on government’s ability to force online companies to turn over user data;  creating stronger checks and balances on the ability of intelligence agencies to demand information, including review by an independent court that hears from critics; allowing companies to disclose “the number and nature of government demands” for user information; and creating a sort of international treaty that would offer a common framework governing requests for user data, cutting across the patchwork of often conflicting national rules.
In addition, the companies argued that governments shouldn’t restrict access to information outside national borders or require companies to locate their infrastructure or operations locally. That appeared to be a specific reaction to countries, such as Germany, where politicians or companies have called for keeping domestic Internet traffic and data within national boundaries.
The Snowden leaks have highlighted that the U.S. government has few legal restrictions on monitoring the communications of foreigners and even fewer compunctions about doing so. That apparently includes listening in on European leaders like German Chancellor Angela Merkel.
Brazil responded to these realizations by announcing a plan to sidestep the United Stations altogether, through construction of a direct, undersea fiber-optic connection between South America and Europe.
Meanwhile, it seems there are many other shoes to drop, as reportedly only one percent of Snowden’s leaks have been revealed so far.
Companies like Facebook, Google, Microsoft and Yahoo were required in many instances to hand over user data when presented with proper legal requests, although the court review process has been widely criticized. But it’s clear the NSA was also tapping into networks without companies’ knowledge, infiltrating communications links between data centers operated by Yahoo and Google, which infuriated some within these companies.
Some businesses took steps to prevent future government surveillance through this route, encrypting the information that passes between data centers.
“The security of users’ data is critical, which is why we’ve invested so much in encryption and fight for transparency around government requests for information,” Larry Page, chief executive of Google, said in a statement. “This is undermined by the apparent wholesale collection of data, in secret and without independent oversight, by many governments around the world. It’s time for reform and we urge the US government to lead the way.”
Yahoo CEO Marissa Mayer hit a similar note.
“Recent revelations about government surveillance activities have shaken the trust of our users, and it is time for the United States government to act to restore the confidence of citizens around the world,” she said in a statement.
There’s a grave fear in tech circles that these national movements to cut off foreign online services will lead to the Balkanization of the Internet, undermining its promise as an open, global platform for communications and commerce. Which is a valid fear and important issue.
But to be clear, the announcement on Monday is at least as much about money as it is high-minded ideals.
Most of these companies, but particularly Facebook and Google, are hardly privacy champions on any other day of the week. It’s not so much that an organization is trying to derive useful information from the bulk collection and analysis of their data — they do that themselves everyday for the purpose of targeting ads. The issue is that another organization is doing it and scaring away existing or potential users in the process.
“The government’s comment was, ‘Oh, don’t worry, basically we’re not spying on any Americans,’” said Mark Zuckerberg, CEO of Facebook, earlier this year at a TechCrunch conference. “Oh, wonderful, that’s … really going to inspire confidence in American Internet companies.”
Indeed.
I have no doubt that the technology giants that signed the open letter on Monday truly want these changes put in place: They would surely reduce the amount of government requests for data and simplify their job of complying with those demands.
But part of this is just good public relations, a way to distance themselves from the NSA in the minds of consumers. And far broader reforms than what they’re proposing are still necessary, as are stronger privacy rules aimed at the private sector itself.
But regardless of the motives, here’s the good news: the seven deep-pocketed companies speaking out for changes are harder for the government to ignore than the civil liberties groups that were calling for digital surveillance restrictions long before Snowden’s leaks began.

Friday, 25 October 2013

LinkedIn's new mobile app called 'A dream for attackers'

linkedin-buliding-ap-635.jpg
Security researchers are calling LinkedIn's new mobile app, Intro, a dream come true for hackers or intelligence agencies.
"I'm flabbergasted by this," Richard Bejtlich, the chief research officer at the computer security company Mandiant, said in an interview Wednesday. "I can't believe someone thought this was a good idea."
Intro is an email plug-in for iOS users that pulls LinkedIn profile information into emails so that the sender's job title appears front-and-center in emails on a user's iPhone or iPad.
Some bloggers have hailed it as a smart play by LinkedIn to get more mobile action and to get users to stop thinking of the service as a static website they visit every couple of years to update their employment status.
But security researchers have taken issue with the way the app works. Intro redirects email traffic to and from users' iPhones and iPads through LinkedIn's servers, then analyzes and scrapes those emails for relevant data and adds pertinent LinkedIn details.
Researchers liken that redirection to a "man-in-the-middle attack" in which hackers, or more recently, intelligence agencies, intercept Internet traffic en route to its destination and do what they will with it.
Iranian hackers used that tactic to intercept dissidents' Gmail accounts in 2011, by hacking into DigiNotar, a Dutch certificate authority. The National Security Agency is accused of using such tactics to snoop on Google traffic, according to recent revelations by Edward Snowden.
Security researchers say LinkedIn essentially does the same thing in the name of a new mobile feature.
"'But that sounds like a man-in-the-middle attack!' I hear you cry," Bishop Fox, a security consulting group, wrote in a blog post. "Yes. Yes it does. Because it is. That's exactly what it is. And this is a bad thing. If your employees are checking their company email, it's an especially bad thing."
LinkedIn has responded to some of those concerns in an amended blog post Thursday. The company notes that customers must opt in to the app and that, once they do, their email is encrypted to and from LinkedIn's servers. The company also notes that LinkedIn does not store any email on its servers.
But researchers note that, in order for LinkedIn to stick changes into an email, they must decrypt it and then encrypt it again en route to its recipient, adding a new layer of insecurity to email in transit.
"I worry LinkedIn is not going to treat this as the holy grail for people's email, even though it is," Bejtlich said. "The risk is that you essentially trust a box, run by LinkedIn, with your email. It's a target for someone that wants to get to your email. All the fears people now have about email - that they will be intercepted by intelligence agencies for instance - are present."
LinkedIn has not had the best security profile. After the service was hacked last year, 6 million user passwords popped up on a Russian message board, revealing that the company used only bare basic security protocols. And last month, the company became the target of a class-action suit by users who said it was improperly accessing their data.
Bishop Fox, the security consulting firm, called the app "a dream for attackers" and enumerated specific concerns in a blog post. Among them: By giving LinkedIn access to their emails, users may be waiving their rights to attorney-client privilege. The consultancy also warned users that, by opting into Intro, they may be "in gross violation" of their employer's security policies.
"I don't think people who use this are seriously thinking about the implications of LinkedIn seeing and changing their email," Bejtlich noted. "These changes are done in the name of a feature, or speed, but it just completely breaks the idea that email traffic is going where it should go and no place else."

Sunday, 25 August 2013

Young professionals? LinkedIn targeting users aged 13 and above

LinkedIn Corp said it will open its social networking site to those above 13 years of age in a moved aimed at attracting a younger membership base.
Reuters
Reuters
The company, which makes much of its money by selling access to its members’ resumes to corporate recruiters, said the changes will come into effect on 12 September.
LinkedIn also introduced a new feature called University Pages enabling schools, students, and alumni to connect on the website.
Over 200 universities have adopted their pages, including New York University, and University of Michigan, LinkedIn said in a blog post on Monday.
LinkedIn said the minimum age for its members will vary by country. Currently, the minimum age for online social networking is 14 in the United States, 16 in Netherlands and 18 in China, the company said.
Minors will have different default settings to limit public information, and unwanted communication, the company said.
Reuters