A Hacker Has Wiped a Spyware Company’s Servers
motherboard.vice.com
motherboard.vice.com
If you are in the business of collecting data without users' explicit permission, and can't protect that data from being accessed or deleted, you shoudln't be in business.
Punitive action against the company who collected the data and lost control of it.
Punitive penalties are typically just a monetary fine above and beyond damages, but exposing just how badly they screwed up to the public at large should provide a good financial penalty in addition to doing a public good (a reminder of how much "private" data is not actually private).
"If you are in the business of collecting data without users' explicit permission you shoudln't be in business."
Fixed that for you
> ...we have been taking steps to enhance our data security measures. Sharing details of security measures could only serve to potentially compromise those efforts.
Maybe they used ROT13 on the API key twice this time!
Future service designers: if your client is talking directly to AWS, then your attacker will, too. Take the week to write a CRUD frontend server that enforces the policy you want.
Another common mistake is having /.git/ available on the domain itself, often with PHP sites or backend-less SPAs this is common, giving full access to the source, including those API keys. Even major sites do this – The Hill until recently had their git repo, including API tokens and access keys for everything, publicly available.
separate integration repo containing encrypted keys + separate, manual managment/configuration of the decryption process is fine for most cases.
but yes, bare and in mainline and published, I will agree this is terrible.
see also:
Now, if your secrets are encrypted before being committed (using something like ansible vault) and the encryption key is not stored in the repo, that may be ok. However, you still need to be aware that any time you rotate that key, you also should to rotate every secret hidden behind that key.
There are lots of ways of doing this. git-crypt is one that is configuration management agnostic. Most CM tools have their own way of dealing with secrets and there are CM agnostic tools like git-crypt. I'm not personally familiar with anything besides ansible-vault, but this article seems to provide a pretty good summary of several options: https://www.threatstack.com/blog/cloud-security-best-practic...
Yeah and same for .svn and .cvs (which may happen to include your VCS credentials in that directory, too).
I always dread the thought of people not understanding these permissions and letting apps have all kinds of permissions — access to all text messsages, privilege to send text messages, access to call history and privilege to make calls. Many apps read the text messages to process one time passwords/codes sent as text messages, thus avoiding the user having to enter them manually.
These privileges have never been available in iOS for third party apps, and I appreciate Apple deciding to err on this side of the privacy equation (though Apple could still do a lot more on app permissions). Taking the same example as above, iOS apps that need one time passwords/codes depend on the user to enter them manually.
There's no way (in stock) to return blank data, so apps will simply shut down or silently malfunction if you refuse permissions.
The grouping of permissions lumps "can portscan your network" and "run hidden in the background when your phone boots" under "Other", which you can't disable.
J2ME had a more refined security model back in 2006.
Yeah, that’s frustrating. Mobile app permissions are a gross nightmare.
If an application won't work after I've turned off all the permissions that it shouldn't need, it simply gets uninstalled.
https://play.google.com/store/apps/details?id=com.gmail.heag...
Also, I've never had to have a discussion with any "reviewer" about my app on Android. For iOS, I've always had to do quite a few back and forth interactions with the "Resolution Center".
Android seems to be a pass through, perhaps after some automated checks are passing.
As mentioned by others, you don't necessarily have to publish to the Play Store: apps can be side-loaded on Android.
The real question is: who gets to say in what someone's phone is going to be doing: the programmer, the manufacturer or the phone's owner. Most everyone would agree that the owner should have a word in it, and that the manufacturer should have no say at all.
Germany takes another approach: no one gets to do surveillance outside strict limits, privacy is highly regarded over there. The Guardian reports: https://www.theguardian.com/technology/2017/nov/18/germany-b...
I own an iPhone instead of an Android precisely because I don't want to be burdened with the task of determining if what I'm installing is or isn't going to backdoor its way into my phone. I trust that Apple will in most cases do the right thing. Maybe they won't every time, but the risk of that is less than the cost of time & energy required to play "deep dive into every fucking app I install on my phone".
I'm not saying that government regulation is needed, I'm just pointing out that the purpose of this tire feature is to make it more likely that people notice tire wear, and don't die from accidents involving bald tires.
Isn’t setting the defaults behaviour ‘Having a say’, and who else but the manufacturer gets to do that? Sorry but this suggestion doesn’t make it past even 2 seconds of considered thought.
Another few seconds - who gets to decide what privacy controls the phone even has, if not the manufacturer? Does this not count as having a say?
I can see why some manufacturers would agree with you though, many of them give the impression they don’t want to have any responsibility in this area whatsoever.
Regulatory bodies and / or standards organisations.
Some kind of "This devices meets or exceeds the International Organization for Standardization of mobile device security..."
We don't even have a voluntary one of those.
There's no iOS version.
I have to admit that, despite all the seriousness of the actual SPYware this obviously terrible company sells, that one sentence brightened up my normal depressing morning experience of reading the weekday morning news on the Internet. That's just funny.
[0] https://forums.flightsimlabs.com/index.php?/topic/16236-furt...
[1] https://forums.flightsimlabs.com/index.php?/topic/16236-furt...
Very sorry, everyone! I had one too many tabs open it seems.
[0] And do please try and convince me if I should think differently about this.
If you profit from selling software that is predominantly used for illegal purposes, or in the course of illegal activities, and you know it; you should be liable. Not put in jail. Not shut down. Just commercially liable.
This is a conservative test (commercial sale, predominantly illegal use, and wilfulness) and a conservative solution. In the long run, however, it balances commercial incentives with broader social ones.
There's the other problem: what damages can someone with a spy app on their phone ask for? There is no monetery value, they can at most ask for relief, that's not much of an incentive to stop.
On one hand, we have a stylised burglar. On the other, a stylised lockpicking tool maker. The former is illegal; the latter is more complicated.
I am conservative about expanding the scope of the law. You criminalise surveillance apps in one decade and in the next, a security researcher disclosing a bug gets bitten.
> what damages can someone with a spy app on their phone ask for?
If someone snooped on my phone without my permission, they would see a lot of confidential client information. They may also see my and my loved ones’ protected health information. Finally, they will have sought and procured illicit access to my device, which is itself illegal. Lots of potential monetary damage in there, if only in legal time to ensure everyone who needs to be notified gets notified.
The target audience of that company is teenagers of helicopter parents. Whatever they have on their phones isn't privileged or valuable information, so the civil damages approach doesn't work too well. Some may have (against all advice) nudes on them, but I'd rather not wait until those are available to the public, and even then only those whose nudies escaped can sue.
The law needs to project the notion that privacy is valued, because it is highly valued. The only idea that I can come up with is to restrict availability of spyware. Others may have better suggestions.
That still allows parents and employees, the supposed target audience, to use the software for its alleged intended purpose, but renders it useless for the illegal use cases.
That's rich. The 'users' in this case are not necessarily the people with this appalling software installed on their device.
You do wonder what the 24-hour panopticon does to adolescents' mental health and to the health of the parent-child relationship.
Of course, they did tend to find out the important stuff anyway. The parent grapevine was definitely alive and well.
Charging a monthly flat-rate for x hours / y days might also help deter abuse.
While parents make a lot of decisions for children in their best interests, this certainly wasn't one of them. The fact that children might later suffer for no fault of theirs and live with something for life because of such a company makes me a lot more angry. It's becoming far too easy to push people into such a situation now.
If it was this easy to break in and access the data, the hacker did consumers a kind mercy by deleting it before someone else got in and did something more nefarious.
Whenever I read this phrase, it always has a sense something like legal, therefore ethical or legal, therefore OK, and.. (this is not an easy sentence to finish) I wonder where people learn to think like that. OK, apart from the pressure of the entire commercial/corporate/advertising apparatus.. Maybe it's surprising it isn't more common. I guess it's the norm, in some circles. I'm naive I guess, but I'd rather die than think like that. A friend of mine used the phrase once, and..that felt like the end of the friendship.