USC Data Science Program 529 (DSci 529): Security and Privacy in Informatics - Spring 2021

Lecture Friday - Noon to 3:20PM PM
Clifford Neuman


Current Events for April 9th 2021

Content Regulation

Russia May Have Found a New Way to Censor the Internet - Dan Goodin and Ars Technica, Wired 4/8/21 Extremely aggressive internet censorship spreads in the world’s democracies - Salvey - Michigan News 11/17/2020

Receent Data Breaches

500 million LinkedIn users' data is for sale on a hacker site - Clare Duffy, CNN Business, APRIL 08, 2021 Half a billion Facebook users' information posted on hacking website, cyber experts say -Donie O'Sullivan - CNN Business - April 5, 2021 533 million Facebook users' phone numbers and personal data have been leaked online -Aaron Holmes, Insidert, April. 3rd 2021 In Wake of Breaches, Accellion Faces at Least 14 Lawsuits - Marianne Kolbasuk McGee - Information Security Media Group 04/07/2021

Privacy Regulation and other Government Regulation

Effective dates for amended Data Privacy law in Japan announced - Hiroto Imai, Mizue Kakiuchi and Dr. Eva-Marie König, Jdsupra 04/08/21 Isn’t it ironic: Exploiting GDPR laws to gain access to personal data - Jessica Haworth, The Daily Swig March 26. 2021 California bans dark patterns that trick users into giving away their personal data - James Vincent, The Verge, 16 March 2021 California Passes New Regulation Banning 'Dark Patterns' Under Landmark Privacy Law - Brianna Provenzano, GIXMODO Mar 15, 2021 Virginia data privacy law presents new challenges for security practitioners -Sandy B. Garfinkel, Esq. Stephenie G. Anderson Scialabba, Esq., SecurityInfoWatch 03/25/2021 Cybersecurity: Council adopts conclusions on the EU's cybersecurity strategy - Council of the EU, Council of the European Union 3.22, 2021 House Democrat introduces data privacy bill - Author(CHRIS MILLS RODRIGO), Source(THE HILL) Mar 10, 2021 The Need for a Strong Privacy Law - Marc Rotenberg, The New York Times 3.15, 2021 Twos Company: Virginia Has a Comprehensive Data Privacy Law - Aaron Burstein, Alysa Zeltzer Hutnik & Rod Ghaemmaghami, Ad Law Access Blog 3/2/2021 Virginia governor signs comprehensive data privacy law - Rebecca Klar, The Hill 03/02/21 Massachusetts managed to write rules on facial recognition - Kashmir Hill New York Times 02/27/21 Instagram adds new teen safety tools as competition with TikTok heats up -Sarah Perez - TechCrunch - Mar 16, 2021 Role of Encryption in GDPR Compliance By TRIPWIRE GUEST AUTHORS MAR 31, 2021 Booking.com Fined $558.000 for Late Breach Notification - Phil Muncaster, Infor secutiry April 1, 2021 Google's 'Teacher approved' apps mislead on kids' privacy, activists tell FTC - Paresh Dave, Reuters 03/30/2021 Google's 'Teacher approved' apps mislead on kids' privacy, activists tell FTC. - Paresh Dave, Reuters 3/30/2021 Supreme Court says Facebook text alerts aren't illegal robocalls - Adi Robertson, April 1, 2021 Most businesses do not obtain user consent to use face recognition - Teller Report, 03/30/2021

Regulation of Content

Google, Fresh Out of Congressional Hotseat, Hands $29 Million to EU's New Fund to Tackle Fake News - Siladitya Ray, 3/31/21 Steam's Chinese version is finally here, but it only has 53 games and no community features - Author(Steven Messner), Source(Tpcgamer) Feb 9, 2021

Government use of and access to Data

After A Major Hack, U.S Looks To Fix A Cyber 'Blind Spot' 04/6/21 Groups: Census privacy tool could hurt voting rights goals - Mike Schneider, Apnews, 04, 05, 2021 These Companies Track Millions Of Cars—Immigration And Border Police Have Been Grabbing Their Data - Thomas Brewster, Forbes, 1 April 2021 Groups Call for Ethical Guidelines on Location-Tracking Tech - Sydney Fussell, Wired 03/25/2021 UK may force Facebook services to allow backdoor police access - Dan Sabbagh, the Guardian, 4.1, 2021 UK may force Facebook services to allow backdoor police access - Dan Sabbagh, The Guardian 4/1/21 ACLU Files AI FOIA Request - Author: Sarah Coble, Source: infosecurity magazine, Date:4/1/2021 Vaccine Passports Won’t Get Us Out of the Pandemic - Saskia Popescu and Alexandra Phelan, THE NEW YORK TIMES, March 22, 2021 Growing privacy concerns expressed over use of 'vaccine passports' - Richard Allyn, ABC10, March 29, 2021, Vaccine passports launched in Las Vegas but privacy, choice still concerns - Bailey Schulz, Las Vegas Review-Journal 3/31/21 Vaccine passports launched in Las Vegas but privacy, choice still concerns - Bailey Schulz, Las Vegas Review, Mar 31,2021 Global Vaccine Passport Raise Concerns Over Privacy and Inequity - Aishwarya Jagani, Digital Privacy, 18th March 2021 Why COVID-19 "vaccine passports" could be "Pandora's box" for data privacy and ethical issues -Barry Collins, Forbes, Feb 10, 2021 Fake Vaccine Card Sales on Social Media -Judith Isacoff and Fern Siegel; themississippilink; date: 06 April 2021 Colleges That Require Virus-Screening Tech Struggle to Say Whether It Works By Natasha Singer and Kellen Browning, New York Times, 03/02/2021 Receiving COVID-19 vaccine does not enroll you in a government tracking system or medical experiment By Noah Y. Kim February 26, 2021 Vaccine Listings becoming prevalent on Dark web -Tim De Chant,(CNET) Date: 25th March 2021 How to protect your privacy while signing up for a COVID-19 vaccine online?" - VIOLET BLUE, Popular Science, APRIL 01, 2021 COVID19 Vaccine Phishing Scams Surge 26% in Three Months - Phil Muncaster UK / EMEA News Reporter , Infosecurity Magazine China is raising the alarm over corportate surveillance. But it's got a massive network of its own. - Laura He, CNN 3/19/21 China to ban apps from collecting excessive user data starting May 1 - Rita Liao - TechCrunch - Mar 23, 2021 Township violated Michigan couple's privacy by using drone, court says - Author(Beth LeBlanc), Source(The Detroit News) Mar 19, 2021

You are being tracked or monitored

How to Tell Which Emails Quietly Track You - DAVID NIELD, The Wired, 03/07/21 Tesla's In-Car Cameras Raise Privacy Concerns - Keith Barry, Consumer Reports 3/22/21 Tesla's in-car cameras raise privacy concerns: Consumer Reports - Aditya Soni, 23 March 2021 Tesla's in-car cameras raise privacy concerns: Consumer Reports. - Reuters Staff, Reuters 3/23/2021 Disney World tests facial recognition software at Magic Kingdom - Kyra Shportun, ABC-7, 25th March 2021 What a Gambling App Knows About You - Adam Satariano, New York Times 3/25/21

Data Breaches and Vulnerabilities

22-Year-Old Charged With Hacking Water System and Endangering Lives - Ravie Lakshmanan, The Hacker News, 4-1-2021 Large Florida School District Hit by Ransomware Attack - Associate Press, Security Week 4/1/21 healthcare provider whose data was allegedly exfiltrated to an Amazon storage account by a cyber-attacker has taken legal action against Amazon - Sarah Coble Infosecurity magazine 03/26/21 Policyholders may be the primary target in hack of cyber insurance provider CNA 03/24/21 Breach at California State Controller's Office - Sarah Coble - Info Security 03/24/2021 New Zoom Screen-Sharing Bug Lets Other Users Access Restricted Apps - Ravie Lakshmanan, The Hacker News, 3-18-2021 Makers of Cyberpunk 2077 game hit by ransomware hack - Alex Hern, The Guardian, Feb.9, 2021 Rise in Healthcare Data Breaches Driven by Ransomware Attacks - Scott Ikeda, CPO Magazine 3/18/21 Location tracking apps and privacy implications - Mirco Musolesi & Benjamin Baron, EurekAlert, 5 March 2021 Thousands of Android and iOS Apps Leak Data From the Cloud - LILY HAY NEWMAN, The Wired, 03/04/21 Thousands of Android and iOS apps lead data from the cloud - Lily Hay Newman, Wired 3/4/21 Online dating platforms: privacy challenge and open-data goldmine - E&T Engineering and Technology, March 4th, 2021 Researcher finds 5 privilege escalation vulnerabilities in Linux kernel - Derek B. Johnson - SC Media 02/03/2021 Over 70% organizations say their portfolio is more vulnerable - Scott Ikeda, 03-02-2021 Singapore Airlines frequent flyer members hit in third-party data security breach -Eileen Yu, Zdnet 03/04/2021 Legal Firm Leaks 15,000 Cases Via the Cloud - Author: Phil Muncaster, Source: infosecurity magazine, Date:2/24/2021 Medical Data of 500,000 French Residents Leaked Online - Sarah Coble, Infor secutiry Feb 24, 2021 45,000 people's personal info exposed in Michigan hospital data breach - Caitlyn French, MLive, 2/25/21 Hacker sells data for 500 million Facebook users through telegram bot - Alicia Hope, 02-05-2021 Data breach exposes 1.6 million Washington state residents who filed unemployment claims in 2020 - Kurt Schlosser, GeekWire Feb 1. 2021 Law Firm Data Breach Impacts UPMC Patients - Sarah Coble, InfoSecurity Magazine, 2/5/21 Nebraska Medicine-UNMC patients concerned about hackers getting information -Brian Mastre, 6 News, Feb 9, 2021, Resarcher hacks into internal systems if Microsoft and Apple -Sarah Coble, Source(Info Security Magazine) Date: 10 Feb 2021 Microsoft: web shell attacks have doubled over the past year - Derek B. Johnson - SC Media 02/18/2021 Nebraska health system notifying patients of data breach - AP News, February 10th, 2021 Blaze Destroys Servers at Europe's Largest Cloud Services Firm - Richard Lough - Reuters - Mar 10, 2021 OVH fire: OVHcloud abandons efforts to restart SBG1 data center in Strasbourg -Peter Judge, Data Center Dynamics. March.21, 2021

Disinformation

Lawmakers Grill Tech C.E.O.s on Capitol Riot, Getting Few Direct Answers - David McCabe and Cecilia Kang, New York Times, 25th March 2021

Data Sharing

Uber and Lyft will share driver's info to protect their passengers - Phil Muncaster Infosecurity magazine 03/15/21

Google

Chrome’s Cookie Update Is Bad for Advertisers but Good for Google - Matt Burgess, Wired 2/3/21 Google antitrust lawsuit amended to target Chrome’s Privacy Sandbox - K. Holt, Engadget 3/16/2021 Google Nest 2 home device tracks body activity in bed - Cristina Criddle, BBC NEWS Feb, 9, 2021 Google says it won't pursue a cross-site tracking after phasing out cookies - Joseph Duball, IAPP 3.3, 2021 Google is policing itself on privacy because it knows it has to. - N. Ingraham, engadget 3/4/2021 Google says Chrome cookie replacement plan making progress -via AP news wire, Independent. Jan.25, 2021 Google addresses customer data protection, security in Workspace -Charlie Osborne, ZD Net, Mar. 2nd 2021 Google Begins to Integrate Stricter Privacy Policies - N. Ingraham, Engadget March 4, 2021 Google Privacy Sandbox added to US antitrust complaint - Danny Bradbury, ITPro. 03/17/2021

Other, e.g. Security Technologies

Netflix Introduces Measures to Prevent Password Sharing - Author: James Coker, Source: Infosecurity Magazine, Date:3/12/2021 It’s an NFT Boom. Do You Know Where Your Digital Art Lives? - Brady Dale, Coindesk, 23 February 2021 Consider Your Data Privacy When Making MyHeritage 'Deepfakes' - David Murphy, LifeHacker 03/03/2021

Remote Learning

5 minutes with Kelvin Coleman - Remote learning and data privacy issues. - Maria Henriquez, securitymagazine.com 3/18/2021

Apple

Apple’s privacy problem (French critique contradicts the iPhone maker’s privacy exceptionalism) - Vincent Manancourt and Mark Scott, Politico 03/24/21 How Apple’s new Apple Store privacy requirements may affect users and app developersApple now requires apps to reveal how user data may be collected, but some companies aren't happy about the policy. Among all the arguments, Facebook criticized Apple for creating a policy that's about profit and not privacy, but Microsoft has given the new policy a thumb up. Apple has anticipated these claims and regards them as a brazen attempt to maintain the privacy-invasive status quo.-Yueming, Gao Seriously, stop sharing your vaccine cards on social media -- Samantha Murphy Kelly, CNN Business, 03/18/2021
TikTok wants to keep tracking iPhone users with state-backed workaround - Patrick McGee and Yuan Yang, Financial Times, 3/16/21 P&G Worked With China Trade Group on Tech to Sidestep Apple Privacy Rules - Wall Street Journal, April 8th, 2021 Chinese Tech Companies look to bypass Apple privacy rules with an independent tracking number - Scott Ikeda, 03-24-2021 Apple warns Chinese apps not to dodge its new privacy rules - yuan yang, Financial Times, Mar 13,2021 Facebooks Privacy Battle With Apple - Jason Aten, February 28, 2021 First Malware Designed for Apple M1 Chip Discovered in the Wild - Ravie Lakshmanan, The Hacker News, 2-18-2021 Zuckerberg: Facebook may actually be in a ‘stronger position’ after Apple’s iOS 14 privacy changes, -Salvador Rodriguez, CNBC, Mar. 18, 2021 Apple’s New Privacy Labels May Not Always Be Correctly Applied Scott Ikeda, CPO Magazine, 02/12/2021 iOS 14.4 update fixes iPhone security bugs, so it’s best to install it ASAP - The Verge>New iPhone update fixes actively exploited vulnerability - Mitchell Clark, The Verge January 26 2021 What We Learned From Apple’s New Privacy Labels - Brian X. Chen, New York Times,Jan. 27, 2021 Apple and Facebook at odds over privacy move that will hit online ads - Alex Hern, theguardian.com, Jan 28, 2021 In Response To Apple IDFA, Facebook Plans To Have Its Own Ad Tracking Notification - Scott Ikeda, CPO Feb 10, 2021 What Apple's big tech frenemies think of its iOS 14 privacy updates - RACHEL KRAUS, Mashable 2/10/2021 Facebook v Apple: the looming showdown over data tracking and privacy - Josh Taylor, The Guardian, Feb.13, 2021 Facebook's ‘Red Team X’ Hunts Bugs Beyond the Social Network's Walls - Lily Hay Newman, Wired 03/18/2021

Facebook

Facebook Login, User Data And Privacy On Oculus Headsets. - Happy Baker, UPLOAD January 31,2021 Everything You Need To Know: Facebook Login, User Data And Privacy On Oculus Headsets - Author(HARRY BAKER), Source(UPLOAD) 01/31/2021

Social Media and Other Apps and Privacy

Did Clubhouse Violate EU Privacy Laws? French Regulators Open Inquiry - Scott Ikeda, CPO Magazine 3/31/2021 Clubhouse's Security and Privacy Lag Behind Its Explosive Growth By LILY HAY NEWMAN 02.26.2021 01:10 PM Privacy concerns with audio only Clubhouse App -Sara Morrison ; engadget; date: 22 Feb 2021 Can Clubhouse Move Fast Without Breaking Things? - Kevin Roose, The New York Times, Feb. 25, 2021 Clubhouse's Security and Privacy Lag Behind Its Explosive Growth Lily Hay Newman, 2/26/2021 Can Clubhouse Move Fast Without Breaking Things? - Kevin Roose, New York Times 2/25/21 Clubhouse: The Hot New Social Network Has Big Privacy Problems -Barry Collins, Forbes, Feb 10, 2021 You’ve been invited to Clubhouse. Your privacy hasn’t. - Author(Sara Morrison), Source(Vox) Feb 12, 2021 Clubhouse Is Suggesting Users Invite Their Drug Dealers and Therapists - Will Oremus, OneZero 02/11/2021 Mozilla Privacy Report V-Day Edition: Multiple Dating Apps and Tech Gadgets singled out for Serious Security Lapses - Jonathan Greig, Tech Republic 2/10/21 Social media helps bring people together, but in this political climate it's tearing us apart Meghan Lopez, Denver 7, Feb 01, 2021 10:52 PM Instagram Bans Hundreds of Accounts With Stolen User Names - Taylor Lorenz, The New York Times, Feb. 4, 2021 Social media expose 80 percent oversharing - Phil Muncaster Infosecurity Magazine 02/02/21 Grindr is fined $11.7 million under European privacy law. - Natasha Singer and Aaron Krolik, The New York Times, Jan. 25, 2021 Canadian class action over Facebook data scandal dismissed - Christine Dobby, The Standard 02/18/21 WhatsApp shares plans for new privacy policy -Abrar Al-Heeti,(CNET) Date: 18 Feb 2021 WhatsApp Will Re-introduce Controversial New Privacy Policy - Karissa Bell, Vice February 18, 2021 WhatsApp will re-introduce controversial new privacy policy -K.Bell; engadget; date: 18 Feb 2021 WhatsApp is having another go at explaining its privacy policy to users - Ian Carlos Campbell - The Verge - Feb 18, 2021 WhatsApp Chaos: Time for a Comprehensive Data Security and Privacy Law? - Author: Jason Williams, Source: infosecurity magazine, Date:2/8/2021 Italy orders Tiktok to block underage users after 10 year-old girl dies doing viral challenge - Euronews, Jan/27/2021

Internet of Things

Digidog, a Robotic Dog Used by the Police, Stirs Privacy Concerns - Maria Cramer and Christine Hauser, The New York Times 2/27/21

AI and Big Data

Nothing Personal, But Ethical AI Is Our Strongest Weapon In Data Privacy Wars - Susan Galer, Forbes 03/18/2021

Cryptocurrency and Blockchain

As Digital Currency’s Popularity Rises, So Do Privacy Fears Gregory Barber, 3/26/2021

Other

Your Face Is Not Your Own - Kashmir Hill, New York Times, Date Hot Air Balloons Invade Privacy in Napa Valley - Barry Eberling, Napa Valley Register, 3/13/21 America, Your Privacy Settings Are All Wrong - New York Times, March 6th, 2021 If You Care About Privacy, It’s Time to Try a New Web Browser By Brian X Chen, New York Times, 03/31/2021 If You Care About Privacy, It’s Time to Try a New Web Browser - Brian X. Chen, New York Times, March 31, 2021 Is trading your privacy for lower insurance rates a good idea? - Elaine Smith, THE STAR Mar 29, 2021