Yandex said it caught an employee selling access to users' inboxes
zdnet.com
zdnet.com
- Google Engineer Stalked Teens, Spied on Chats: https://gawker.com/5637234/gcreep-google-engineer-stalked-te...
- Lyft Investigates Allegation That Employees Abused Customer Data: https://www.theinformation.com/articles/lyft-investigates-al...
- Uber Employees Allegedly Use Data to Stalk Exes, Celebs: https://www.newser.com/story/235409/lawsuit-uber-employees-u...
- Facebook Investigating Claim That Employee Used 'Privileged Access' to Cyber-Stalk Women: https://gizmodo.com/facebook-investigating-claim-that-employ...
- Snapchat Employees Abused Data Access to Spy on Users: https://www.vice.com/en_us/article/xwnva7/snapchat-employees...
- Yahoo Engineer Used Insider Access to Get Private Photos of Women: https://www.vice.com/en_asia/article/59nwyk/yahoo-engineer-u...
Most occurrences likely never even make it into the news.
https://www.rtlnieuws.nl/nieuws/nederland/artikel/5210644/ha...
If the money is there, and it can be done anonymously, people will keep doing it.
Like saying Google is Irish because they have some center there for the EU business. Google is surely a US-based company.
>Yandex is a Russian Dutch-domiciled multinational corporation providing Internet-related products and services, including transportation, search and information services, eCommerce, navigation, mobile applications, and online advertising.
>The firm is registered in Schiphol, the Netherlands as a naamloze vennootschap (Dutch public limited company), but the company founders and most of the team members are located in Russia.
So yes, technically the company is registered outside of Russia (Netherlands, not Switzerland like you claimed), but their HQ and heavy majority of their workforce and the founders are located in Moscow. I would definitely count it as a Russian company.
It is one thing to censor something due to a hypothetical possibility of a threat or due to some "dangerous ideas". But it is another thing to censor a tech giant from an authoritarian country (with the government of which that said tech giant is almost definitely collaborating) that is literally physically invading your borders by force and taking your territory using shady tactics and excuses ("these are not our soldiers, they are just some unmarked militia that has access to our top tier weaponry... oh wait, jk, we lied, it was our troops all along").
Especially given the fact that tech giants in Russia are all, pretty much, under a thumb of the government. Just check up on what happened to Pavel Durov (the Telegram guy, previously known for creating another russian tech giant VK.com aka russian version of FB), he ended up having to give up his company and flee the country, because he didn't collaborate with the regime readily.
And no, I am not a russophobe, I grew up in Russia myself, and I am not the kind to fall for the "every hack is now attributed to russian government-funded hackers" hysteria that seems to have polluted mass media in the west recently. Which is why, imo, it is important to emphasize when the real threats happen and address them, just like Ukraine did with the Yandex ban.
It means they can literally run their mandatory board meetings in the transit lounge at the airport.
Ferrari has a similar structure at Schiphol, but I think it’s also because Italy has a “speculator tax” on stock transactions, so they just register elsewhere.
Sorta. I worked next to them in Burlingame, CA.
The mentioned employee sold access to 4,887 email accounts.
https://mashable.com/2017/09/01/instagram-verification-paid-...
They absolutely have very strict access control now — it would be 100% impossible for a Google employee to do this nowdays.
you think they would record audio/video, or just log the keystrokes?
They'd remotely activated the webcam on his school-issued laptop. And, frankly, spying on a teenage boy in his bedroom, they're lucky they didn't face felony charges.
This is why end-to-end encryption should be a first choice for pretty much everything.
And the reason why most of "unicorns" likely do not have strict audit system for PI is because it costs many $$$$ but brings exactly $0 in revenue. And until it becomes many $$$$ in potential lawsuit liability exposure, it will continue so, because nobody would invest serious effort in something that is only hurting the bottom line.
Was there any actual evidence of wrongdoing? All I’m seeing is a screenshot of a text message circulating on the Twitter outrage circuit.
https://yandex.com/company/press_center/press_releases/2021/...
Or in Russian: https://yandex.ru/company/press_releases/2021/2021-02-12
And it isn't a dark pattern. Dark patterns are https://www.darkpatterns.org/types-of-dark-pattern type of things. Or, the typical cookie consent box. This is just tragedy of the commons.
Edit: Removed Signal as an example.
I don't know about the others but I don't think Signal does this. Signal offers the user the ability to backup their messages, and lets them password protect them, but the way you've written this implies Signal is uploading messages to Google of its own volition, unencrypted, which afaik is not the case.
FTFY. The only solution is for the information never to exist in the first place, never centralized, never even collected.
I’m curious how access was provided to these sold accounts. The password change implies the passwords were shared and that means plan text password were available to admins!?
I think you're right though--it does seem like they must have sold the passwords themselves. It's interesting to think about how you would sell access to an account if you wanted to.
You can do a "takeout" of all data in the account and sell that. Or it can be anything that is requested, like a dump of all the private messages.
You can change the password of the account, possibly at a time like 3am at the user's local time so they're less likely to be using the account, then change it back at say 5am. This requires DB access.
You can find the user's session token/id if they're logged in somewhere and sell that.
https://security.stackexchange.com/questions/30193/encryptin...
Although this approach still requires trust that service providers do indeed encrypt user data.
E2E encryption avoids that by not trusting whatever is running on the servers Local DBs avoid that by not giving up local data.
However, it would be quite interesting to have a way to remotely know that a certain service is running the code you think it's running.
It sure would, and it would be a hell of a discovery if someone could come up with it. Because I sure can't think of a way that I can't easily debunk.
- HN discussion: https://news.ycombinator.com/item?id=25989698
- A great article about the project: https://ruben.verborgh.org/blog/2020/12/07/a-data-ecosystem-...
I have a saying that the platform should be able to run on a Raspberry PI.
One of my personal pet peeves working with the team is to be able to disappear without impacting them, and it has become the same with our platform: it must be able to disappear users having to scramble to exfiltrate or export their work or data from our infrastructure, because it simply is not there.
Google: https://gawker.com/5637234/gcreep-google-engineer-stalked-te...
Facebook: https://www.theguardian.com/technology/2018/may/02/facebook-...
The NSA: https://www.reuters.com/article/us-usa-surveillance-watchdog...
These are presumably just the tip of the iceberg of people dumb enough to get caught.