Sunday, 25 December 2022

TikTok Owner ByteDance Admits to Surveiling Journalists

WebProNews
TikTok Owner ByteDance Admits to Surveiling Journalists

Despite initial claims to the contrary, ByteDance has admitted to using TikTok to monitor Forbes journalists, including tracking their locations.

Forbes broke a story in October that accused TikTok and ByteDance of planning to surveil specific Americans using the TikTok app. The two companies vehemently denied the allegations, even saying, “Forbes’ reporting about TikTok continues to lack both rigor and journalistic integrity.”

As it turns out, however, Forbes was right, and ByteDance has admitted the outlet’s report was correct. ByteDance used TikTok to track multiple Forbes journalists in an effort to track down leaks that served as the basis of multiple stories about the company’s close ties to China.

The surveillance even included using TikTok to track the journalists’ IP addresses and user data in an effort to determine if they had been in the vicinity of any ByteDance employees.

ByteDance has lost a number of executives responsible for the surveillance, including Chris Lepitak, its chief internal auditor and the man who led the surveillance team. Song Ye, the executive Lepitak reported to and who reported directly to CEO Rubo Liang, has resigned.

“I was deeply disappointed when I was notified of the situation… and I’m sure you feel the same,” Liang wrote in an internal email shared with Forbes. “The public trust that we have spent huge efforts building is going to be significantly undermined by the misconduct of a few individuals. … I believe this situation will serve as a lesson to us all.”

“It is standard practice for companies to have an internal audit group authorized to investigate code of conduct violations,” TikTok General Counsel Erich Andersen wrote in a second email. “However, in this case individuals misused their authority to obtain access to TikTok user data.”

Forbes minced no words in calling out ByteDance’s actions as an assault on a free press.

“This is a direct assault on the idea of a free press and its critical role in a functioning democracy,” says Randall Lane, the chief content officer of Forbes. “We await a direct response from ByteDance, as this raises fundamental questions about what they are doing with the information they compile from TikTok users.”

For its part, TikTok is clearly trying to distance itself from the situation and blame the whole fiasco.

“The misconduct of certain individuals, who are no longer employed at ByteDance, was an egregious misuse of their authority to obtain access to user data,” said TikTok spokesperson Hilary McQuaid. “This misbehavior is unacceptable, and not in line with our efforts across TikTok to earn the trust of our users.”

TikTok is under well-deserved fire, with multiple states banning the app from state-owned devices and Congress passing a bill that would ban it from government devices. This latest report is only going to add fuel to the fire, and will likely result in renewed calls for an all-out ban on the app.

TikTok Owner ByteDance Admits to Surveiling Journalists
Matt Milano



from WebProNews https://ift.tt/sEa9QlU

Saturday, 24 December 2022

2022 Layoffs Top 125,000

WebProNews
2022 Layoffs Top 125,000

As the new year approaches, the latest numbers indicate that a whopping 125,000 employees have been laid off in 2022.

Many companies and industries were flying high during the pandemic, as remote and hybrid work options fueled big spending on computers, tablets, cloud computing, and more. Meanwhile, government stimulus helped buoy spending among consumers. As things have returned to normal, however, fears of a recession have mounted and led to mass layoffs.

According to Forbes, the total number of layoffs for 2022 has now topped 125,000, with more than 60,000 of them being let go since the beginning of November. Tech companies have led the charge, with Meta, Amazon, and HP among those laying off the most workers. In total, some 90,000 workers have been laid off in the industry this year.

As economists warn of a recession, the layoff numbers are certainly lending weight to those concerns.

2022 Layoffs Top 125,000
Matt Milano



from WebProNews https://ift.tt/6l0jo8M

Congress Passes Bill Banning TikTok From Government Devices

WebProNews
Congress Passes Bill Banning TikTok From Government Devices

Congress has passed a $1.7 trillion spending bill that includes a clause banning TikTok from government devices.

TikTok has been under fire for repeated privacy concerns, not to mention lying to Congress about how US user data is handled. Several states have already banned the app from state-owned devices, but Congress has taken it a step further.

According to CNBC, both chambers of Congress have passed a $1.7 trillion bill that includes a provision banning the app from government devices. Despite praise from various industry groups, the move drew condemnation from TikTok.

“We’re disappointed that Congress has moved to ban TikTok on government devices — a political gesture that will do nothing to advance national security interests — rather than encouraging the Administration to conclude its national security review,” a TikTok spokesperson said. “The agreement under review by CFIUS will meaningfully address any security concerns that have been raised at both the federal and state level. These plans have been developed under the oversight of our country’s top national security agencies — plans that we are well underway in implementing — to further secure our platform in the United States, and we will continue to brief lawmakers on them.”

Only time will tell if lawmakers are satisfied with banning the app from government devices, or if additional measures will taken to implement a wider ban.

In the meantime, the bill will go to President Biden to be signed into law.

Congress Passes Bill Banning TikTok From Government Devices
Matt Milano



from WebProNews https://ift.tt/zlE3gfW

IRS Delays $600 Reporting Rule

WebProNews
IRS Delays $600 Reporting Rule

The Internal Revenue Service has delayed a rule that would require gig workers to report earnings of $600.

The American Rescue Plan of 2021 implemented new rules that would significantly lower the amount of yearly earnings online platforms would have to report, from 20,000 to a mere 600. The rules were initially set to go into effect for the 2022 tax year

After significant pushback from lawmakers, as well as concerns in the industry at large, the IRS has decided to delay implementation until the 2023 tax year.

“The IRS and Treasury heard a number of concerns regarding the timeline of implementation of these changes under the American Rescue Plan,” said Acting IRS Commissioner Doug O’Donnell. “To help smooth the transition and ensure clarity for taxpayers, tax professionals and industry, the IRS will delay implementation of the 1099-K changes. The additional time will help reduce confusion during the upcoming 2023 tax filing season and provide more time for taxpayers to prepare and understand the new reporting requirements.”

Thanks to the delay, entrepreneurs and gig workers will get a bit of a reprieve…at least for a year.

IRS Delays $600 Reporting Rule
Matt Milano



from WebProNews https://ift.tt/BouRcUH

Friday, 23 December 2022

FBI PSA: Use A Browser Ad Blocker

WebProNews
FBI PSA: Use A Browser Ad Blocker

The Federal Bureau of Investigation has issued a public service announcement, urging people to use ad blocking browser extensions.

Ad blocking software and browser extensions are a popular way to improve the web browsing experiencing, speed up browsing, and protect privacy. Virtually every major browser supports ad blocking extensions, or have such measures built-in.

In a PSA issued on December 21, 2022, the FBI endorses the use of ad blocking measures as a way to protect users against cyber criminals.

Cyber criminals purchase advertisements that appear within internet search results using a domain that is similar to an actual business or service. When a user searches for that business or service, these advertisements appear at the very top of search results with minimum distinction between an advertisement and an actual search result. These advertisements link to a webpage that looks identical to the impersonated business’s official webpage.

The FBI makes the case that ad blockers can help protect against this kind of scam.

Use an ad blocking extension when performing internet searches. Most internet browsers allow a user to add extensions, including extensions that block advertisements. These ad blockers can be turned on and off within a browser to permit advertisements on certain websites while blocking advertisements on others.

It’s good to see the FBI come out in favor of ad blocking and hopefully more individuals will follow their advice.

FBI PSA: Use A Browser Ad Blocker
Matt Milano



from WebProNews https://ift.tt/N6H2PQ8

LastPass: Hackers Stole Encrypted User Password Vaults

WebProNews
LastPass: Hackers Stole Encrypted User Password Vaults

LastPass has issued a security advisory, notifying customers that the data breach it suffered in August was far worse than thought.

LastPass is a popular password management application. In August, the company informed customers that it had suffered a data breach, one in which “portions of source code and some proprietary LastPass technical information” was stolen. At the time, the company assured customers that no passwords were stolen or compromised.

The company has provided an update on the situation, informing customers that the data stolen in August was used to compromise an employee’s credentials and gain access to the company’s cloud-based storage service. As a result of this secondary breach, the hacker was able to download a backup copy of customer data vaults.

The company described the issue in its advisory:

To date, we have determined that once the cloud storage access key and dual storage container decryption keys were obtained, the threat actor copied information from backup that contained basic customer account information and related metadata including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service.

The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.

Despite the severity of the breach, LastPass says customer passwords are still secure…at least for now. The company says encrypted fields are protected using 256-bit AES encryption, with the encryption key based on the user’s master password. Between the strong encryption and the fact that LastPass does not have access to a user’s password, theoretically, users’ password vaults should still be secure.

Despite the assurance, LastPass says all users should immediately change their master passwords to prevent any risk of the hackers using brute force attacks to try to access the vaults or use some of the unencrypted data in phishing and scam attempts.

The threat actor may attempt to use brute force to guess your master password and decrypt the copies of vault data they took. Because of the hashing and encryption methods we use to protect our customers, it would be extremely difficult to attempt to brute force guess master passwords for those customers who follow our password best practices. We routinely test the latest password cracking technologies against our algorithms to keep pace with and improve upon our cryptographic controls.

The threat actor may also target customers with phishing attacks, credential stuffing, or other brute force attacks against online accounts associated with your LastPass vault. In order to protect yourself against social engineering or phishing attacks, it is important to know that LastPass will never call, email, or text you and ask you to click on a link to verify your personal information. Other than when signing into your vault from a LastPass client, LastPass will never ask you for your master password.

LastPass’ revelation is a disturbing one, given the popularity of the application and the important role it plays in the cybersecurity of countless individuals. One can only hope the company will take drastic steps to ensure such a breach doesn’t happen again.

LastPass: Hackers Stole Encrypted User Password Vaults
Matt Milano



from WebProNews https://ift.tt/mlqKBTr

Thursday, 22 December 2022

Google Open Sources Its Video Blurring Tool

WebProNews
Google Open Sources Its Video Blurring Tool

Google has open sourced its video blurring tool, called Magritte, in an effort to improve user privacy.

Google has been working to roll out additional privacy-enhancing technologies (PETs). Magritte is one of those tools that the company has open sourced to help spur wider adoption.

“Today, we are happy to announce an open-source version of an internal project, Magritte, which uses Machine Learning (ML) advances to detect objects using low computational resources, and applies a blur to those objects automatically, as soon as they appear on screen,” the company writes in a blog post. “The tool can blur arbitrary objects, like license plates, and more.

“This code is especially useful for video journalists who want to provide increased privacy assurances. By using this open-source code, videographers can save time in blurring objects from a video, while knowing that the underlying ML algorithm can perform detection across a video with high-accuracy.”

The company has released the source code on GitHub.

Google Open Sources Its Video Blurring Tool
Matt Milano



from WebProNews https://ift.tt/7MLn2IH