Topic: Computer Security/Computing (Page 3)

You are looking at all articles with the topic "Computer Security/Computing". We found 30 matches.

Hint: To view all topics, click here. Too see the most popular topics, click here instead.

πŸ”— Facebook–Cambridge Analytica data scandal

πŸ”— Internet πŸ”— Internet culture πŸ”— Computer Security πŸ”— Computer Security/Computing πŸ”— Conservatism πŸ”— Elections and Referendums

In the 2010s, personal data belonging to millions of Facebook users was collected by British consulting firm Cambridge Analytica for political advertising without informed consent.

The data was collected through an app called "This Is Your Digital Life", developed by data scientist Aleksandr Kogan and his company Global Science Research in 2013. The app consisted of a series of questions to build psychological profiles on users, and collected the personal data of the users' Facebook friends via Facebook's Open Graph platform. The app harvested the data of up to 87 million Facebook profiles. Cambridge Analytica used the data to analytically assist the 2016 presidential campaigns of Ted Cruz and Donald Trump. Cambridge Analytica was also widely accused of interfering with the Brexit referendum, although the official investigation recognised that the company was not involved "beyond some initial enquiries" and that "no significant breaches" took place.

In interviews with The Guardian and The New York Times, information about the data misuse was disclosed in March 2018 by Christopher Wylie, a former Cambridge Analytica employee. In response, Facebook apologized for their role in the data harvesting and their CEO Mark Zuckerberg testified in April 2018 in front of Congress. In July 2019, it was announced that Facebook was to be fined $5 billion by the Federal Trade Commission due to its privacy violations. In October 2019, Facebook agreed to pay a Β£500,000 fine to the UK Information Commissioner's Office for exposing the data of its users to a "serious risk of harm". In May 2018, Cambridge Analytica filed for Chapter 7 bankruptcy.

Other advertising agencies have been implementing various forms of psychological targeting for years and Facebook had patented a similar technology in 2012. Nevertheless, Cambridge Analytica's methods and their high-profile clientsβ€”including the Trump presidential campaign and the UK's Leave.EU campaignβ€”brought the problems of psychological targeting that scholars have been warning against to public awareness. The scandal sparked an increased public interest in privacy and social media's influence on politics. The online movement #DeleteFacebook trended on Twitter.

Discussed on

πŸ”— 2024 CrowdStrike incident: The largest IT outage in history

πŸ”— Internet πŸ”— Computing πŸ”— Disaster management πŸ”— Computer Security πŸ”— Computer Security/Computing πŸ”— Computing/Software πŸ”— Computing/Computer Security πŸ”— Microsoft πŸ”— Current events πŸ”— Microsoft/Microsoft Windows

On 19 July 2024, a faulty update to security software produced by CrowdStrike, an American cybersecurity company, caused innumerable computers and virtual machines running Microsoft Windows to crash. Businesses and governments around the globe were affected by what one expert called the "largest IT outage in history".

Among the industries that were disrupted were airlines, airports, banks, hotels, hospitals, stock markets, and broadcasting; governmental services such as emergency numbers and websites were also affected. The error was discovered and a fix was made on the same day, but the outage continued to delay airline flights, cause problems in processing electronic payments, and disrupt emergency services.

Discussed on

πŸ”— The Cuckoo's Egg

πŸ”— Espionage πŸ”— Books πŸ”— Computer Security πŸ”— Computer Security/Computing

The Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage is a 1989 book written by Clifford Stoll. It is his first-person account of the hunt for a computer hacker who broke into a computer at the Lawrence Berkeley National Laboratory (LBNL).

Discussed on

πŸ”— How a Buffer Overflow Works

πŸ”— Computing πŸ”— Computer Security πŸ”— Computer Security/Computing πŸ”— Computing/Software

In information security and programming, a buffer overflow, or buffer overrun, is an anomaly where a program, while writing data to a buffer, overruns the buffer's boundary and overwrites adjacent memory locations.

Buffers are areas of memory set aside to hold data, often while moving it from one section of a program to another, or between programs. Buffer overflows can often be triggered by malformed inputs; if one assumes all inputs will be smaller than a certain size and the buffer is created to be that size, then an anomalous transaction that produces more data could cause it to write past the end of the buffer. If this overwrites adjacent data or executable code, this may result in erratic program behavior, including memory access errors, incorrect results, and crashes.

Exploiting the behavior of a buffer overflow is a well-known security exploit. On many systems, the memory layout of a program, or the system as a whole, is well defined. By sending in data designed to cause a buffer overflow, it is possible to write into areas known to hold executable code and replace it with malicious code, or to selectively overwrite data pertaining to the program's state, therefore causing behavior that was not intended by the original programmer. Buffers are widespread in operating system (OS) code, so it is possible to make attacks that perform privilege escalation and gain unlimited access to the computer's resources. The famed Morris worm in 1988 used this as one of its attack techniques.

Programming languages commonly associated with buffer overflows include C and C++, which provide no built-in protection against accessing or overwriting data in any part of memory and do not automatically check that data written to an array (the built-in buffer type) is within the boundaries of that array. Bounds checking can prevent buffer overflows, but requires additional code and processing time. Modern operating systems use a variety of techniques to combat malicious buffer overflows, notably by randomizing the layout of memory, or deliberately leaving space between buffers and looking for actions that write into those areas ("canaries").

Discussed on

πŸ”— Sneakers (1992 Film)

πŸ”— Mass surveillance πŸ”— Computing πŸ”— Film πŸ”— Film/American cinema πŸ”— Comedy πŸ”— Computer Security πŸ”— Computer Security/Computing

Sneakers is a 1992 American caper comedy film directed by Phil Alden Robinson from a screenplay co-written with Walter Parkes and Lawrence Lasker. It stars Robert Redford, Dan Aykroyd, Ben Kingsley, Mary McDonnell, River Phoenix, Sidney Poitier and David Strathairn. In the film, Martin (Redford) and his group of security specialists are hired to steal a black box but soon realize the job has nefarious and far-reaching consequences.

Lasker and Parkes first conceived Sneakers in 1981 during pre-production on WarGames (1983). Redford was the first actor attached to the project, and he helped recruit the remaining cast members, as well as Robinson. Several of the characters were inspired by members of the hacking and national defense communities, and the actors improvised several scenes during filming. Principal photography took place on location across California, with filming taking place in San Francisco, Oakland, Simi Valley, and the Courthouse Square backlot at Universal Studios Hollywood.

Sneakers was theatrically released in the United States on September 11, 1992, by Universal Pictures. The film received generally positive reviews from critics, with praise for its humor, tone, and plot. It grossed $105.2 million worldwide, becoming the 20th-highest-grossing film of 1992.

Discussed on

πŸ”— 2024 Lebanon Pager Explosions

πŸ”— Military history πŸ”— Disaster management πŸ”— Military history/Military aviation πŸ”— Telecommunications πŸ”— Computer Security πŸ”— Computer Security/Computing πŸ”— Syria πŸ”— Israel πŸ”— Military history/Middle Eastern military history πŸ”— Explosives πŸ”— Military history/Post-Cold War πŸ”— Lebanon

On 17 September 2024, communication pagers simultaneously exploded across Lebanon and Syria in an apparent coordinated attack. Many of the pagers were owned by members of the Hezbollah militant group. Eighteen people were confirmed killed: eleven in Lebanon (including a child and at least two Hezbollah members) and seven in Syria. Around 4,000 people were reportedly injured, including Hezbollah members and civilians.

The blasts affected several Hezbollah strongholds, including Beirut's Dahieh suburb, southern Lebanon, and in the Beqaa Valley. Over 500 of the group's militants lost their eyesight. They called the incident the organization's "biggest security breach yet" and accused Israel of responsibility.

A day after Hamas launched its October 7 attacks on Israel in 2023, the Iranian-backed organization Hezbollah joined the conflict in support of Hamas by firing on Israel. This led to a series of cross-border military exchanges between Hezbollah and Israel. In February 2024, the secretary-general of Hezbollah, Hassan Nasrallah, told the group's members to use pagers instead of cell phones, claiming that Israel had infiltrated their cell phone network. Hezbollah then bought a new brand of pagers that were recently imported to Lebanon.

Earlier on the day of the explosion, Israel's domestic security agency, the Shin Bet, announced it had thwarted a Hezbollah plot to assassinate a former senior defense official using an explosive device.

Around 150 hospitals across Lebanon received victims of the attack, which saw chaotic scenes.

Discussed on

πŸ”— Zombie Zero

πŸ”— Computer Security πŸ”— Computer Security/Computing

Zombie Zero is an attack vector where a cyber attacker utilized malware that was clandestinely embedded in new barcode readers which were manufactured overseas.

It remains unknown if this attack was promulgated by organized crime or a nation state. Clearly there was significant planning and investment in order to design the malware, and then embed it into the hardware within the barcode scanner. Internet of things (IoT) devices may be similarly preinstalled with malware that can capture the network passwords and then open a backdoor to attackers. Given the high volume of these devices manufactured overseas high caution is to be exercised before placing these devices on corporate or government networks.

Discussed on

πŸ”— Confused Deputy Problem

πŸ”— Computing πŸ”— Computer Security πŸ”— Computer Security/Computing πŸ”— Computing/Software

In information security, a confused deputy is a computer program that is tricked by another program (with fewer privileges or less rights) into misusing its authority on the system. It is a specific type of privilege escalation. The confused deputy problem is often cited as an example of why capability-based security is important.

Capability systems protect against the confused deputy problem, whereas access-control list–based systems do not.

Discussed on

πŸ”— The Cuckoo's Egg

πŸ”— Espionage πŸ”— Books πŸ”— Computer Security πŸ”— Computer Security/Computing

The Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage is a 1989 book written by Clifford Stoll. It is his first-person account of the hunt for a computer hacker who broke into a computer at the Lawrence Berkeley National Laboratory (LBNL).

Stoll's use of the term extended the metaphor Cuckoo's egg from brood parasitism in birds to malware.

Discussed on