Top Banner
Privacy Exposed: Ramifications of Social Media and Mobile Technology Brian Dean and Tom Eston
61

Privacy Exposed: Ramifications of Social Media and Mobile Technology

May 08, 2015

Download

Technology

Tom Eston

Mobile devices and applications have taken the world by storm. Millions of consumers are using these devices for everything from conducting financial transactions, accessing health care information and sharing personal experiences over social media. Unfortunately there is still little regard or concern with how mobile platforms and major social networks collect, transmit and store personal and corporate information. This exacerbates existing privacy concerns and the need for new regulations in the age of big data. In this presentation we discuss the latest privacy concerns with this new technology. Topics will include:

• All new privacy concerns with mobile application data, geolocation, address book harvesting , third party information sharing and the latest mobile technology such as NFC (Near Field Communication)
• A close look at the top 20 mobile applications and how they transmit, store and reuse personal or private information
• Comparison of current privacy policies of the major social networks, what they tell you and what they don't
• Ramifications of international and US privacy regulations and how this impacts mobile devices, social networks, you and your business
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Privacy Exposed:Ramifications of Social Media and Mobile Technology

Brian Dean and Tom Eston

Page 2: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Agenda• Privacy in a Mobile World

– Apps and Your Data

– Location Based Services

– Data Harvesting

– Hot New Mobile Technology

– Mobile Application Privacy Policies

• Privacy in a Social World

– Evolution of Social Technology

– More Privacy Controls = More Confusion

– Hot New Social Technology

– Comparison of Social Network Privacy Policies

• Regulatory Ramifications

21,000,000,000,000,000,000,000,000 bytes

Page 3: Privacy Exposed: Ramifications of Social Media and Mobile Technology

About Your Presenters• Brian Dean

– Audit and Compliance Team Manager, Privacy Officer

– PCI QSA, PMP, PCIP, ACE, Certified Information Privacy Professional

– Privacy Officer, HIPAA Officer, and GLBA Officer for $100 billion bank.

Over 13 years in privacy

– Frequent Speaker at IAPP, Info Security Summit, ACI, INFOSEC World

• Tom Eston

– Attack & Defense Team Manager

– Web Applications, Mobile Applications and Device Security

– Founder of SocialMediaSecurity.com

– OWASP Mobile Threat Model Project Lead

– SANS Mentor – SEC542 Web Application Penetration Testing

– Frequent Speaker at Black Hat, DEF CON, ShmooCon, DerbyCon, SANS,

OWASP AppSec, InfoSec World 3

Page 4: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Disclaimer• This presentation is for informational purposes only.

• Before implementing or executing on any ideas presented, it would be prudent to seek council from your technical, security, compliance, and Legal representation.

• Always perform adequate due diligence, including a formal risk assessment.

• Views and opinions presented today are not necessarily that of SecureState or other entities we may represent.

– Good chance it doesn’t represent our opinions either.

4

Page 5: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Privacy in a Mobile World

• Mobile Data: Storage

– Mobile devices have become “virtual wallets”

– Personal data via social networks and email are easily stored and shared with others

– Smartphone are personal tracking devices that just happen to also take phone calls

– Smartphones are one expensive wallet to lose!

5

Page 6: Privacy Exposed: Ramifications of Social Media and Mobile Technology

6

Example: Mobile Pen Test

Page 7: Privacy Exposed: Ramifications of Social Media and Mobile Technology

7

Page 8: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Trivial to Access Private Data

• With physical access…it’s “game over”

– Rooting or Jailbreaking of the device

– Passcode bypass (iOS 7- several!)

– Circumvention of “remote wipe” controls

– Malware can harvest personal data(especially on Android)

* Subject to the security policies or MDM (Mobile Device Management) enforcement!

8

Page 9: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Example: MyFitnessPal

• Application stores (too much) PPI on the device

9

Page 10: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Phone Stored Data

10

Date of Birth

Page 11: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Mobile Data: Transmission

• Do you know what your apps are sending?

– To the app developers?

– To third-party ad/marketing companies?

• Do mobile apps send your data securely?

– Is SSL being used?

– In our research of the Top 20 Apps…very few use SSL!

11

Page 12: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Example: UDID

• What is UDID?

– Unique Device IDentifier for the hardware

– Apple iOS (iPhone/iPad)

• Found to be transmitted from mobile apps

– To third party ad and marketing companies

– To the mobile app company

– Usually transmitted with other personal information (user name, IP, geolocation, etc.)

12

Page 13: Privacy Exposed: Ramifications of Social Media and Mobile Technology

13

Example: iTunes

Page 14: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Pinterest and Flurry.com

14

Page 15: Privacy Exposed: Ramifications of Social Media and Mobile Technology

15

UDID

Page 16: Privacy Exposed: Ramifications of Social Media and Mobile Technology

16

iOS 7

Page 17: Privacy Exposed: Ramifications of Social Media and Mobile Technology

1 Million UDIDs Exposed?

• Hackers said it’s from the FBI. FBI denies…

• This was actually a third-party breach!

17

Page 18: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Location Based Services

• Also known as “geolocation”

• Coordinates are frequently sent via third party services

• GPS coordinates sometimes stored locally or sent back to the company

• Apple had a problem with storing location data without user approval in 2011

18

Page 19: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Apple iOS Location Data Storage Issue

• Fixed in iOS 4.3.3

– When turning off location services, iOS will not store or back up this data

• Some researchers created a cool tool to demo this

– http://petewarden.github.com/iPhoneTracker/

19

Page 20: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Facebook Timeline and Graph Search

• Easier then ever to view where someone has been

• Pulls location data from photos, status updates and more…

20

Page 21: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Instagram Photomaps

21

“…you can now much more easily access photos you and others took months or

even years ago.”

– Kevin Systrom, co-founder and CEO of Instagram

Image: Mashable

Page 22: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Address Book Harvesting

• More apps are doing this

• “See if your friends are using this app”

• Apple iOS apps could access contact data without permission (fixed in iOS 6)

• Install prompt on Android

• Developers can notify you on their own…

22

Page 23: Privacy Exposed: Ramifications of Social Media and Mobile Technology

23

Page 24: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Brewster

• Takes your:

– Address book

– LinkedIn contacts

– Facebook Friends List

– Who you follow on Twitter

– Gmail address book

– FourSquare Locations

– And more…

24

Image: Brewster.com

Page 25: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Evolution: Facebook Design Tricks

25

Image: TechCrunch http://techcrunch.com/2012/08/25/5-design-tricks-facebook-uses-to-affect-your-privacy-decisions/

Page 26: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Evolution: Facebook Design Tricks

26

Image: TechCrunch http://techcrunch.com/2012/08/25/5-design-tricks-facebook-uses-to-affect-your-privacy-decisions/

Page 27: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Evolution: Facebook Design Tricks

27

Image: TechCrunch http://techcrunch.com/2012/08/25/5-design-tricks-facebook-uses-to-affect-your-privacy-decisions/

Page 28: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Evolution: Facebook Design Tricks

28

Image: TechCrunch http://techcrunch.com/2012/08/25/5-design-tricks-facebook-uses-to-affect-your-privacy-decisions/

Page 29: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Apple “Find and Call Malware”

29

• First “Trojan” for Apple iOS?

• It was a spammy app that sent your contact list to a third-party server

• Your friends get SMS spammed from the server

• App removed from the App Store and Google Play

Image: Kaspersky Labs

Page 30: Privacy Exposed: Ramifications of Social Media and Mobile Technology

• Uses your active WiFi “beacons” to identify you by your MAC address

• Google Analytics for “People”

30

http://www.itworld.com/it-management/336828/attention-shoppers-retailers-can-follow-you-around-mall-way-web-trackers-do-onl

New Tech: Shopper Tracking

Page 31: Privacy Exposed: Ramifications of Social Media and Mobile Technology

31

• Apple iOS 5 – Twitter integrated into the OS

• Apple iOS 6 – Facebook integrated into the OS

• Apple iOS 7 – Pretty interface integrated in OS

Evolution: Social Media Integrated into Mobile Operating Systems

Page 32: Privacy Exposed: Ramifications of Social Media and Mobile Technology

32

Page 33: Privacy Exposed: Ramifications of Social Media and Mobile Technology

• Google Now: “Predicts” things based on your location and actions you take on your device

• Weather, what’s the traffic like on your way to work?

• Passbook: Actions are taken when you enter a location: IE: Enter a Target, coupon pops up

33

Evolution: Google Now and Passbook

Page 34: Privacy Exposed: Ramifications of Social Media and Mobile Technology

34

Evolution: Facebook Home

Page 35: Privacy Exposed: Ramifications of Social Media and Mobile Technology

35

Page 36: Privacy Exposed: Ramifications of Social Media and Mobile Technology

36

Digital Shadow

Page 37: Privacy Exposed: Ramifications of Social Media and Mobile Technology

You Don’t Have Any Privacy – Get Over it!

37http://www.emc.com/digital_universe/downloads/web/personal-ticker.htm

Page 38: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Generally Accepted Privacy Principles

38

Page 39: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Privacy in the Wild

39

• Notice – 6,867 word Privacy Policy (LinkedIn, 10-14-13)

• Consent – IF offered often buried down 19 screens

• 3rd Party access (service provider in China? Pakistan?)

– Hey you “consented.” It was on the 19th screen!

• Collection – Some collect too much (MyFitnessPal)

• Retention – Not typically addressed in the US

• Disclosure to 3rd Parties – Almost unilaterally!

• Security – Who knows (more on that later)

• Quality – I loaned my phone to my son. I never went…

Page 40: Privacy Exposed: Ramifications of Social Media and Mobile Technology

40

Privacy Policies

Page 41: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Privacy Policies

• Notices Bottom Line

– Painful to read, so no one reads. We have no idea what we agree to, I just want to play Angry Birds Star Wars 2…

41

Page 42: Privacy Exposed: Ramifications of Social Media and Mobile Technology

42

Page 43: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Government Data Requests

• Policies almost unilaterally allow sharing with authorities

– Per Washington Post (as of 9-6-2013)

– Yahoo responded 12,444 requests for data from

the U.S. government YTD

– 40,322 users

– YTD Yahoo has rejected 2% of the requests

http://www.nydailynews.com/life-style/google-unveils-smart-shoes-sxsw-article-1.1287259#ixzz2eaJBFnfa

43

Page 44: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Government Data Requests (con’t)• Google, Facebook, Apple, Microsoft

– Foreign Intelligence Surveillance Act

– National Security Agency

– Foreign Intelligence Surveillance Court

• Sought to release data on the requests they receive from government agencies to release consumer data

– Take away: Data is being collected and subject to other possibly accessing. In the US it may NEVER be deleted!

44

Page 45: Privacy Exposed: Ramifications of Social Media and Mobile Technology

More Privacy Control = More Confusion

• Consumers:

– Take initiative to read the Policies

– Understand the legalese Policies

– Need to act to protect PPI/PHI

• Businesses :

– Google munged 60 Privacy Policies into 1!

– Opt out check-box is 11 pixels wide!

– No incentive to manage if consumers don’t care!

45

Page 46: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Mobile Apps(where’s the security indicators?)

46

Page 47: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Privacy in a Social World

• Facebook,

Twitter and

LinkedIn have

grown

exponentially!

• 900 Million!

• Privacy issues

have increased

as well

• Mobile users to

top 8 billion by

2016 (1)

47

Image: Ben Foster http://www.benphoster.com/facebook-user-growth-chart-2004-2010/

(1) CNET News, quoting Cisco Forecast from 2-14-2012

Page 48: Privacy Exposed: Ramifications of Social Media and Mobile Technology

48

Page 49: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Hot New Tech: Facial Recognition

• “Facedeals”

– Camera real-time matches face to Facebook

– Matches get discounts sent to smartphone

49

Page 50: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Fiction: Minority Report

50

Page 51: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Reality: Disney’s MagicBands (MyMagic+)

51

Page 52: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Google Glass

• Camera inconspicuously imbedded in glasses

– Pictures and stream video to social networks

• Already banned in a Seattle Restaurant (5 Point Cafe)

– What about at airports (TSA Security check points)

– School yards

• Smartphone and

video cameras

52

Page 53: Privacy Exposed: Ramifications of Social Media and Mobile Technology

53

Page 54: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Privacy Ramifications

• How to deal with new technology

– e.g., Facedeals, MagicBands

• Opt out of facial scans?

• Misuse of technology!

• Tracking children

• Apple Passbook

– iPhone = your wallet

• Digital coupons, tickets, loyalty cards

• Allow payment with near field chip (NFC).

• GPS detects your location and presents coupon

• Malware

– Nefarious data extractions

• GAPP

– Can we really apply Privacy Principles? 54

Page 55: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Regulatory Ramifications

• International

– Appeasing the law patchwork

– You think 6000 word Policy is long

• Read one that addresses 10 countries!

• Now reading page 1 of 101

• United States

– Data aggregation and correlation not addressed in US law.

• We want ease, we will sacrifice privacy, until it’s too late.

55

Page 56: Privacy Exposed: Ramifications of Social Media and Mobile Technology

On the Horizon

• US Businesses will collect more data and retain

• Technology will better correlate data

• Consumers won’t read privacy policies (have you?)

• Breaches will continue unabated

• New federal encompassing privacy regulations unlikely

– Mobile device data regulations may be looming

• Technology outpace regulators

• More data in the cloud

56

Page 57: Privacy Exposed: Ramifications of Social Media and Mobile Technology

New Paradigm

• Consumers

– Personal responsibility

• Read Privacy Policies and Security Safeguards

– Choice

• Select businesses based on privacy

– Cognitively execute your preferences

– Correct the accuracy of the data, not just when getting a loan (e.g., HIPAA, GLBA, credit bureaus)

– Limit the data you provide (do they really need it?)

57

Page 58: Privacy Exposed: Ramifications of Social Media and Mobile Technology

New Paradigm

• Businesses need to rethink business model

– Capture less data, retain shorter durations

– Adopt GAPP principles

– Better data protection

– De-identify data

– Strong encryption

• Security/Privacy Professionals

– Be aware of the risk – Bad things will happen!

– Formally Document the risks for management

– Share the risk! (e.g., Annual Risk Posture Statement)

– Be a Champion of Privacy and Security

58

Page 59: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Closing Thoughts

• Short federal law migrating towards EU Privacy

Directive, big business will collect and retain all

the data they can gather, including passive data

sources we discussed.

• Security/Privacy professionals, businesses, and

YOU the consumer must be proactive in

managing our digital footprints.

• Collective responsibly!

59

Page 60: Privacy Exposed: Ramifications of Social Media and Mobile Technology

Links

60

• Link to Tom’s Facebook Privacy & Security Guide

– http://www.securestate.com

– http://socialmediasecurity.com

Page 61: Privacy Exposed: Ramifications of Social Media and Mobile Technology

61

Tom Eston: [email protected]

Twitter: @agent0x0

Brian Dean: [email protected]

[Mostly off the grid ]