Apple logs your iMessage contacts and could share them with police

Apple’s iMessage had a few security holes in March and April that potentially leaked photos and contacts, respectively. Though quickly patched, they are a reminder that the company faces a never-ending arms race to shore up its security to keep malicious hackers and government agencies out. But that doesn’t mean they will always be able to keep it private. A report from The Intercept states that iMessage conversation metadata gets logged in Apple’s servers, which the company could be compelled to turn over to law enforcement by court order. While the content of those messages remains encrypted and out of the police’s hands, these records list time, date, frequency of contact and limited location information. When an iOS user types in a phone number to begin a text conversation, their device pings servers to determine whether the new contact uses iMessage. If not, texts are sent over SMS and appear in green bubbles, while Apple’s proprietary data messages appear in blue ones. Allegedly, they log all of these unseen network requests. But those also include time and date stamps along with the user’s IP address, identifying your location to some degree, according to The Intercept . Like the phone logs of yore, investigators could legally request these records and Apple would be obliged to comply. While the company insisted that iMessage was end-to-end encrypted in 2013, securing user messages even if law enforcement got access, Apple said nothing about metadata. Apple confirmed to The Intercept that it does comply with subpoenas and other legal requests for these exact logs, but maintained that message content is still kept private. Their commitment to user security isn’t really undermined by these illuminations — phone companies have been giving this information to law enforcement for decades — but it does illustrate what they can and cannot protect. While they resisted FBI requests for backdoor iPhone access earlier this year and then introduced a wholly redesigned file system with a built-in unified encryption method on every device, they can’t keep authorities from knowing when and where you text people. Source: The Intercept

Read this article:
Apple logs your iMessage contacts and could share them with police

Malvertising Campaign Infected Thousands of Users Per Day For More Than a Year

An anonymous reader writes from a report via Softpedia: Since the summer of 2015, users that surfed 113 major, legitimate websites were subjected to one of the most advanced malvertising campaigns ever discovered, with signs that this might have actually been happening since 2013. Infecting a whopping 22 advertising platforms, the criminal gang behind this campaign used complicated traffic filtering systems to select users ripe for infection, usually with banking trojans. The campaign constantly pulled between 1 and 5 million users per day, infecting thousands, and netting the crooks millions each month. The malicious ads, according to this list, were shown on sites like The New York Times, Le Figaro, The Verge, PCMag, IBTimes, Ars Technica, Daily Mail, Telegraaf, La Gazetta dello Sport, CBS Sports, Top Gear, Urban Dictionary, Playboy, Answers.com, Sky.com, and more. Read more of this story at Slashdot.

More:
Malvertising Campaign Infected Thousands of Users Per Day For More Than a Year

MRI Software Bugs Could Upend Years Of Research

An anonymous reader shares a report on The Register: A whole pile of “this is how your brain looks like” MRI-based science has been invalidated because someone finally got around to checking the data. The problem is simple: to get from a high-resolution magnetic resonance imaging scan of the brain to a scientific conclusion, the brain is divided into tiny “voxels”. Software, rather than humans, then scans the voxels looking for clusters. When you see a claim that “scientists know when you’re about to move an arm: these images prove it”, they’re interpreting what they’re told by the statistical software. Now, boffins from Sweden and the UK have cast doubt on the quality of the science, because of problems with the statistical software: it produces way too many false positives. In this paper at PNAS, they write: “the most common software packages for fMRI analysis (SPM, FSL, AFNI) can result in false-positive rates of up to 70%. These results question the validity of some 40, 000 fMRI studies and may have a large impact on the interpretation of neuroimaging results.” Read more of this story at Slashdot.

See more here:
MRI Software Bugs Could Upend Years Of Research

PBS Caught Faking Fireworks During ‘Live’ Fourth of July Celebration 

There are a few things that make America great, and blowing shit up on the Fourth of July is one of them. So when PBS decided to digitally add stock footage of fireworks to its “live” coverage of the Capitol’s Independence Day celebration, some viewers were left unimpressed. Faking shit? Very Un-American. Read more…

See the original post:
PBS Caught Faking Fireworks During ‘Live’ Fourth of July Celebration 

DoNotPay Bot Has Beaten 160,000 Traffic Tickets — and Counting

Khari Johnson, writing for VentureBeat:A bot made to challenge traffic tickets has been used more than 9, 000 times by New Yorkers, according to DoNotPay maker Joshua Browder. The bot was made available to New Yorkers in March. In recent years and decades, residents of The Big Apple have seen a persistent increase in traffic fines. A record $1.9 billion in traffic fines was issued by the City of New York in 2015. Since the first version of the bot was released in London last fall, 160, 000 of 250, 000 tickets have been successfully challenged with DoNotPay, Browder said. “I think the people getting parking tickets are the most vulnerable in society, ” said Browder. “These people aren’t looking to break the law. I think they’re being exploited as a revenue source by the local government.” Browder, who’s 19, hopes to extend DoNotPay to Seattle this fall. Read more of this story at Slashdot.

Read the original:
DoNotPay Bot Has Beaten 160,000 Traffic Tickets — and Counting

Japan is deploying pirated anime-hunting human personnel

Japan’s automated bootleg-hunting software isn’t quite as effective as its government would like. So, it’s boosting its anti-piracy campaign by hiring human employees to manually scour forums, torrents and video-streaming websites for illegally distributed anime and live video content. See, it’s pretty easy to slip through the clutches of an automated system — all people have to do is change the video a bit to make sure it’s not an exact match to what Japan’s computers are looking for. That tactic obviously won’t work on human personnel. As Motherboard noted, Japan is betting on anime and manga to boost its economy. Animation studios have recently made their creations more available to audiences outside the country, but they’re still not as easy to access as Western media. Hulu, for instance, dropped a ton of titles from its anime catalogue in May. As such, illegal distribution of anime is still so widespread that its estimated cost of damage is a whopping $20 billion. According to RocketNews24 , the government will start this new project next week with one hire, perhaps to test things out. The employee will have to determine whether the pirated video he finds affects the copyright holder financially. If it does, the government will assess the legal actions it can take. Via: Motherboard Source: Yahoo Japan

View article:
Japan is deploying pirated anime-hunting human personnel

How Militarized Cops Are Zapping Rights With Stingray

“Police nationwide are secretly exploiting intrusive technologies with the feds’ complicity, ” argues a new article on Alternet — calling out Stingray, which mimics a cellphone tower to identify every cellphone nearby. “It gathers information not only about a specific suspect, but any bystanders in the area as well… Some Stingrays are capable of collecting not only cell phone ID numbers but also numbers those phones have dialed and even phone conversations.” The ACLU says requests for more information have been meeting heavy resistance from police departments since 2011, with many departments citing nondisclosure agreements with Stingray’s manufacturer and with the FBI, and “often, the police get a judge’s sign-off for surveillance without even bothering to mention that they will be using a Stingray…claiming that they simply can’t violate those FBI nondisclosure agreements. “More often than not, police use Stingrays without bothering to get a warrant, instead seeking a court order on a more permissive legal standard. This is part of the charm of a new technology for the authorities: nothing is settled on how to use it.” Stingray is more than a 1960s TV series with puppets. Several state judges estimate there have been hundreds of instances where police have used the Stingray tool without a warrant or telling a judge. Slashdot reader Presto Vivace writes: This is why it matters who wins the mayor and city council races. Localities do not have to accept this technology. Read more of this story at Slashdot.

View the original here:
How Militarized Cops Are Zapping Rights With Stingray

890 College Students Sue Google Over Email Scanning

An anonymous reader quotes this report from Bay Area Newsgroup: Legal action against Google by four UC Berkeley students has ballooned into two lawsuits by 890 U.S. college students and alumni alleging the firm harvested their data for commercial gain without their consent…making the same claim: that Google’s Apps for Education, which provided them with official university email accounts to use for school and personal communication, allowed Google until April 2014 to scan their emails without their consent for advertising purposes…. The suit by 710 students alleged that until April 2015, Google denied it was scanning students’ emails for advertising purposes and misled schools into believing the emails were private. The students’ lawyers say each student is seeking a maximum of $10, 000, while the U.S. District Court Judge Lucy Koh told the lawyer that “Our clerk’s office is really unhappy you are circumventing our [$400 per case] filing fees by adding 710 cases under one case number.” Read more of this story at Slashdot.

Read More:
890 College Students Sue Google Over Email Scanning

Quaker Oats Is Being Sued Because People Still Don’t Know What ‘Natural’ Means

Quaker Oats is being sued over the big “100% Natural” label on the front of its box. What else is in that big bucket o’ oats that makes the label a lie? Nothing, say the plantiffs—it is, indeed, just oats. Their complaint is that the oats were grown using pesticides. That, they claim, should be sufficient to keep the natural label off it. Read more…

More:
Quaker Oats Is Being Sued Because People Still Don’t Know What ‘Natural’ Means

Opera Now Has a Totally Free and Unlimited Built-In VPN

Dodging firewalls and masking your IP address usually requires firing up separate—often paid-for—software or plug-ins while you’re browsing. Now, though, Opera has its own free VPN baked right into the desktop browser. Read more…

Read More:
Opera Now Has a Totally Free and Unlimited Built-In VPN