Privacy Tuesday – February 2015

Mintz - Privacy & Cybersecurity Viewpoints
Contact

Three things you should know on this Privacy Tuesday:

Over 110,000 Facebook Uses Hit With Malware

Cybercriminals are targeting Facebook users with malware embedded in videos that are pushed to their timeline and in which their friends are tagged. Security researchers from Bitdefender say victims are taken to a video, which redirects them to a site that analyzes their operating system for weaknesses and eventually installs malicious software that give hackers access to their machines.   The malware is described in a post via the Full Disclosure mailing list.    Read more about the malware at CSO Online.

NIST Issues Recommendations for Vetting of Mobile App Security

The National Institute of Standards and Technology (NIST) has released a new report titled “Vetting the Security of Mobile Applications.” The report urges enterprises to put apps through a “vetting” process that includes security testing before allowing employees to use them.

Because mobile devices contain many physical sensors that continuously gather and share information, many apps access more data than many users realize. Here are examples NIST cites: A mobile photo-sharing app could grant access to the employee’s contact list that holds personally identifiable information, potentially exposing information that should remain private. Similarly, a calendar app, social media app, Wi-Fi sensor or other utility that accesses a global positioning system might track individuals without their knowledge.

The report points out that the mobile development industry hasn’t always done a good job with security, and says that enterprises shouldn’t rely on app stores or other third parties to verify security.  It details the types of vulnerabilities enterprise testers should look for as well as the kind of tests that can find them.  The guidance also offers recommendations on mobile app security and privacy training for employees.

Sometimes, Email Campaigns are Just “Creepy”

During last week’s Blizzard of 2015, the editor of this blog received a marketing email from Intelius, the self-described “public records business” (read: data broker).  The header of the email is below:

From: Intelius <newsletter@intelius.com>
Date: January 27, 2015 at 6:59:00 PM EST
To: [email]
Subject: Snowed in?  Look up an old friend!
Reply-To: newsletter@intelius.com

The tag line was “It’s cold outside!  Cozy up and reconnect with an old friend!”   The company provides a variety of “search” functions, including “PeopleSearch,” background checks and criminal records lookup.

Just because you can, does not always mean you should.

 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Mintz - Privacy & Cybersecurity Viewpoints | Attorney Advertising

Written by:

Mintz - Privacy & Cybersecurity Viewpoints
Contact
more
less

Mintz - Privacy & Cybersecurity Viewpoints on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide