Posts

Data leak at payment service provider Klarna: third-party accounts visible

For a short time, the Klarna app displayed other people's data. Klarna immediately took the app offline and speaks of a human error. Swedish payment service provider Klarna suffered a serious data leak on Thursday morning due to "technical problems". Users of the app report that they were able to view the data and transactions of various other people. Klarna has confirmed this and said it immediately took the app offline. In the meantime, at least the login via the website is available again. According to numerous tips on Twitter and from readers, the Klarna app displayed various accounts, just not their own. Readers report that they were always able to view other third-party accounts during a reload. Bank details, orders, open invoice amounts, names, addresses and telephone numbers were visible. Thousands of users affected Klarna confirmed the incident. For about half an hour on Thursday morning, users were shown random third-party user data, a spokeswoman told heise onl...

Questionable facial recognition: civil libertarians file complaints about Clearview AI

Clearview AI has scooped up billions of photos from the web and turned them into a biometrics database for authorities. European activists are calling for "a clear Europe-wide ban on such services". Clearview AI, a New York-based company specializing in facial recognition, has been in legal trouble in the US for some time. A whole series of complaints against the company is currently underway in several US states. Now they have been joined by European civil rights activists. An alliance of organizations including Privacy International and noyb ("none of your business") has filed complaints with the data protection authorities of the UK, France, Austria, Italy and Greece. "What we want to achieve is a clear decision that services like Clearview are illegal in their current form in the EU," says Alan Dahi, privacy lawyer at noyb. That applies even if the providers are based abroad and have no paying customers in the EU, he adds. Thousands of government cust...

Federal Criminal Police Office can read WhatsApp

Encrypted communication poses major problems for security authorities. According to research by WDR and BR, however, the BKA has long been able to read chats via WhatsApp - using a regular function. Only with a very great effort, such as the use of state spy software, the so-called "state Trojan", can encrypted chats be monitored by criminals - or so it has been said so far by the security authorities. Monitoring communications via messenger services such as WhatsApp is one of the biggest challenges for law enforcement, it said. Since the providers of the programs do not allow the authorities to secretly read what is going on, they are in fact forced to use spyware.  According to research by BR and WDR, however, the German Federal Criminal Police Office (BKA) has been able to monitor communications via WhatsApp for several years now - even without having to install surveillance software on the target's cell phone. Regular WhatsApp function used According to the report, th...

Apple: Airtag hacked, stalking said to be "frighteningly easy" to do

After various hardware modifications, an expert has now also been able to manipulate the software of the trackers. Moreover, stalking via the item trackers is "frighteningly easy". Ten days after the official launch, security researcher Stack Smashing has managed to hack the accessory. He tweeted that he was able to break into the micro-controller and manipulate its software. The controller controls the device. For example, the German was able to change the NFC URL and make the item tracker open a different domain instead of the "find-my" website. A phishing page or similar could then be hidden behind it. Other specialists wonder about the fact that the firmware of the Airtags (test) is not encrypted. The hack is also called a jailbreak. Airtag stalking too easy thanks to security weaknesses Another report in recent days also criticized Apple's anti-stalking measures as inadequate. After testing them, Washington Post editor Geoffrey Fowler wrote, for example, ...

U.S. East Coast gasoline supply cut, hackers apologize

A horror scenario has occurred in the US: Cyber criminals have shut down one of the country's largest pipelines. The White House is alarmed, gasoline prices are rising. And criminals with a Robin Hood image are behind the attack. But this matter is now getting too hot for them. Nothing works anymore. After one of the most devastating cyberattacks known to date, the operation of one of the largest gasoline pipelines in the United States has been suspended until further notice. At the end of last week, the operator Colonial Pipeline was attacked with ransomware. In such attacks, hackers smuggle ransomware into the IT systems of their victims, encrypt their data - and then demand a ransom for its release. For four days now, neither the company nor the experts and U.S. authorities involved have managed to get the system up and running again. The government of Joe Biden (78) has now classified the case as a top priority, several ministries have been called in via a task force, and a reg...

Facebook blocks Signal for transparent advertising

The Signal team wanted to run ads showing how personalized Facebook ads work. The advertising account was deactivated. The team of the messenger Signal tried to place ads on Facebook platforms such as Instagram and wanted to disclose the personalization of the ads. As those involved now write in the Signal blog , however, they were excluded from Facebook's advertising network for this. The announcement says: "Companies like Facebook don't build technology for you, they build technology for your data. They collect everything they can from Facebook, Instagram and Whatsapp to sell insights into people and their lives." And while that's no secret, exactly how it works remains unclear to many, he said. So now Signal wanted to showcase how ad personalization works based on the data it collects, even through ads. "Facebook's own tools have the potential to reveal what otherwise remains unseen. (...) We wanted to use those same tools to directly show how most of ...

iOS and Android: How to turn off tracking

Apple is encouraging its smartphone and tablet users to use data sparingly in the future. But this is also possible - hidden - on Android devices. Advertising has been tracking smartphone users for years, often unnoticed, across many apps. An individual number enables advertising companies to play personalized ads across websites and apps. This "tracking" is the technology behind the much-lamented phenomenon of once-searched goods showing up again and again in different ad formats. Apple's current decision to actively inform users of its iPhones about this in the future is only now making many users aware of the generous use of data on their smartphones. The iOS system now automatically asks users whether they want to allow advertising tracking for new apps. Apple is thus sharpening its image as a data protector. However, data collection has been prevented for years - not only on Apple's iPhones, but also on the more widespread devices with the Android operating syste...

Caution Telegram: Data on group members and chat content can easily be tapped

 An unnamed data miner has now shown how easy it is to obtain personal and chat data from the advertised "secure messenger" Telegram. The Twitter user Datenliebe is data mining on Telegram. He is trying to extract as much personal and conversation data from the service as possible. According to the Twitter feed, the user's activity seems to be concentrated mainly in the camp of Corona critics. Most recently, Datenliebe had reached out to T-Online editors to offer his insights. The "data hunter" - as T-Online calls him - also claims to have already provided information to the BBC. T-Online does not know the user. The contact was via the messenger Threema. Telegram groups easy to read What Datenliebe has to tell may scare a large number of Telegram users - namely all those who are active in public and closed groups and feel their identity is protected there. After all, Telegram itself always emphasizes that it is a secure messenger. In fact, this is only true for ...

Terrorist cell phone: FBI pays close to million for iPhone hack

 A small Australian security company plays a major role in the thriller about the San Bernardino bombers who killed 14 people and lost their own lives in the process. In focus - an iPhone 5C. It was the most serious terrorist attack since 9/11 and it occurred in the small town of San Bernardino in the US state of California. On December 2, 2015, city employee Syed Rizwan Farook and his wife Tashfeen Malik shot indiscriminately at a nonprofit facility for people with disabilities during a Christmas party, killing 14 people and injuring 21 others, some seriously. Perpetrators are killed, leaving behind an iPhone 5C with no unlocking capability The perpetrators initially managed to escape, but were then confronted near their home and died in a brief firefight. Two days later, the U.S. Federal Bureau of Investigation (FBI) declared the incident an act of terrorism. The perpetrators had pledged allegiance to the leaders and targets of the Islamic State terrorist organization on social m...

Malware on the smartphone: thousands fall victim to dangerous spam SMS every day

Many cell phone users are falling into an SMS trap set by online criminals, current figures from network operators show. Increasingly, the fraudulent messages are also spreading via messengers such as WhatsApp. Several thousand German customers of all major mobile providers are currently falling victim to dangerous spam text messages every day. Deutsche Telekom alone records an average of 7,000 to 8,000 customers a day who click on links contained in such text messages and infect their phones with malware. The figures come from analyses by the company's IT security experts, as a Telekom spokesperson explained when asked. The experts also observe that attackers have increasingly tried to spread the spam messages via messengers such as WhatsApp or Telegram in recent days. Often, the text messages pretend to come from parcel delivery companies. Instead of information about a delivery status, the links lead users to hijacked websites where users of Android devices are asked to download...