Showing posts with label online privacy. Show all posts
Showing posts with label online privacy. Show all posts

Monday, 3 February 2020

Twitter says state-backed actors may have accessed users’ phone numbers

The feature, which allows people with a user’s phone number to find and connect with that user on Twitter, is off by default for users in the European Union where stringent privacy rules are in place
Twitter, hacking, spying, cyber attack, security, online, digital
Twitter said on Monday that it had discovered attempts by possible state actors to access the phone numbers associated with user accounts, after a security researcher unearthed a flaw in the company’s “contacts upload” feature.
In a statement published on its privacy blog, Twitter said it had identified a “high volume of requests” to use the feature coming from IP addresses in Iran, Israel and Malaysia. It said, without elaborating, that “some of these IP addresses may have ties to state-sponsored actors.” A company spokeswoman declined to say how many user phone numbers had been exposed, saying Twitter was unable to identify all of the accounts that may have been impacted.
She said Twitter suspected a possible connection to state-backed actors because the attackers in Iran appeared to have had unrestricted access to Twitter, even though the network is banned there. Tech publication TechCrunch reported https://techcrunch.com/2019/12/24/twitter-android-bug-phone-numbers on Dec. 24 that a security researcher, Ibrahim Balic, had managed to match 17 million phone numbers to specific Twitter user accounts by exploiting a flaw in the contacts feature of its Android app. TechCrunch said it was able to identify a senior Israeli politician by matching a phone number through the tool.
The feature, which allows people with a user’s phone number to find and connect with that user on Twitter, is off by default for users in the European Union where stringent privacy rules are in place. It is switched on by default for all other users globally, the spokeswoman said.

Wednesday, 4 December 2019

Govt okays Bill proposing Rs 15-cr fine for data misuse, easy storage rules

The Cabinet’s approval paves the way for the Bill to be tabled in Parliament in the ongoing winter session
Data protection Bill
The government is learnt to have relaxed the mandatory storage and processing requirement for all kinds of personal data and made a case for the collection of anonymised data from companies for planning government schemes in its long-awaited draft data protection Bill, which was approved by the Union Cabinet on Wednesday.
The Bill categorises data as sensitive personal data and critical personal data. Sensitive data includes passwords, financial data, health data, sexual orientation, biometric data, genetic data, transgender status, and caste. Critical data will be defined by the government from time to time.
All companies will have to store the critical data of people within the country, but they can transfer sensitive data overseas after explicit consent of the data owner to process it only for purposes permissible under law once the Bill is approved by Parliament, government sources said.
There is a relaxation on storing a copy of all personal data in India, or mirroring. “The government will have the right to direct a data fiduciary to share anonymised or non-personal data for better targeting of service, policy-making, relief work, etc,” said a source. All other aspects of non-personal data will be handled by a committee headed by Infosys co-founder Kris Gopalakrishnan. The Cabinet’s approval paves the way for the Bill to be tabled in Parliament in the ongoing winter session….Read More

14th BRICS summit to review current global issues, reach key agreements

  At the   14th BRICS summit   which is to be hosted by China in a virtual mode on 23-24 June, the member nations will review the current gl...