Privacy Alert: 10 Biggest Threats of 2010
1. Google's Wi-Fi Spying
Threat Level: GREEN
Google's Wi-Fi spying debacle didn't start out evil. By using its Street View vans to map out open Wi-Fi networks, Google could provide better location data to mobile users. If you use Google Maps from your phone, it could employ nearby wireless networks to determine where you are, no GPS required.
Even so, the impact on average consumers is minimal, says Peter Eckersley, senior staff technologist for the
Electronic Frontier Foundation. You're in greater danger of being spied on by nosy neighbors or creeps parked outside your house.
The solution: Password-protect your wireless network (duh) and use encrypted HTTPS connections to browse the Web when possible (see item #3 below).
2. The iPad E-Mail Leak
Threat Level: GREEN
If you bought one of the first iPad 3G units to leave the stores, your e-mail address may have been compromised.If you bought one of the first Apple 3G iPads, an obscure security group may have
purloined your e-mail address.
Last June, Goatse Security exploited a hole in AT&T's Website that displayed an iPad owner's e-mail address when it encountered an HTTP request containing that user's ID number. Goatse flooded AT&T.com with URLs containing random 20-digit numbers and collected 114,000 e-mail addresses of iPad owners. It then
shared a few of them with Gawker.
The good news? The Goatse hack didn't reveal passwords, so the group couldn't access information beyond your name. And you're in select company--ABC's Diane Sawyer, New York Mayor Michael Bloomberg, and top government and military officials also had their addresses stolen.
The solution: None needed. AT&T quickly closed the hole--and if a spammer wants your e-mail address, there are easier ways to get it. So is the
iPad magical and life-changing yet?
3. Facebook Wi-Fi-Jacking
Threat Level: YELLOW
Updating your Facebook status from a Wi-Fi café? A stranger can log in to your account and pretend to be you. Blame Firesheep, a free Firefox plug-in that captures login cookies as they fly by unencrypted. Programmer Eric Butler wrote the program to
demonstrate how much data people send "in the clear" without realizing it. Using Firesheep, a hijacker can access your account on Facebook, Twitter, and two dozen other sites. Any information you thought was private now isn't. Feeling naked yet?
The failure of sites such as Facebook and Twitter to require secure logins is "an enormous privacy problem," says the EFF's Eckersley. "Google demonstrated this could be done on a colossal scale at minimal cost with Gmail. Now we need to get the rest of them to do that."
The solution: Use EFF and the Tor Project's
HTTPS Everywhere plug-in for Firefox to force sites to use SSL encryption if available. And don't log in to sites containing sensitive info from a public network.
4. 'Naked' Security Scans
Threat Level: BLUE
TSA body scans may sound a little personal, but c'mon: How personal does this really look?If Firesheep doesn't make you feel naked, passing through airport security might. Major U.S. airports and federal buildings are deploying body scanners that can peer through clothing, rendering you virtually nude to security guards viewing the scan.
It gets worse. Last August, the U.S. Marshals Service in Orlando, Florida, admitted to storing some 35,000 body scans it was supposed to have destroyed. Naturally, some of those
found their way onto the Net.
The solution: In lieu of a scan, you can opt for an "If you touch me there, you'd better buy me dinner and a movie first"
full-body frisk. But we don't think you'll feel any less violated.
5. Mobile Malware
Threat Level: YELLOW
The smartphone in your pocket is catnip to malware authors, yet mobile security is barely on most people's radar, says Winn Schwartau, chairman of security vendor
Mobile Active Defense.
"Mobile apps are the best hostile-code delivery system ever invented," Schwartau says. "The entire mobile space is in chaos."
The solution: Before you install a new app, do some sleuthing to suss out potential red flags; avoid apps from unfamiliar vendors or sites. "Install Gotcha 1.0 from Bob's App Store?" says Schwartau. "I don't think so."
6. Facebook's ID Giveaway
Threat Level: ORANGE
EFF's Peter Eckersley says using Facebook IDs to extract personally identifiable information is easy for data brokers. "Tracking people is what they do," he says. "If they're sitting on a gold mine of data, they're going to dig for gold."
7. Cell Phone Tracking
Threat Level: ORANGE
It's fun to check in when you're out and about. It could also be dangerous.Geolocation services such as Facebook Places, Foursquare, and Gowalla let you tell the world what you're doing and where you're doing it, but they're voluntary. Other people may be tracking you in secret, thanks to that homing beacon in your pocket.
The solution: Turn off all of your handset's wireless antennas when you feel the urge to roam free.
8. Webcam Watchers
Threat Level: GREEN
A high school in southeastern Pennsylvania achieved international infamy after it
used school-supplied laptops to secretly spy on students. Harriton High officials admitted that the school remotely operated Webcams on the district's 2400 MacBooks as an antitheft feature, capturing more than 50,000 images of students over three years.
Could this happen to you? Possibly. Any malware that can take control of your system can be used to operate a Webcam remotely. But only a handful of Webcam spy cases have ever been prosecuted.
The solution: High schoolers foiled the cams by disabling them or putting tape over the lenses when they weren't in use; you can too.
9. Zombie Cookies
Threat Level: ORANGE
Chocolate chip cookies are yummy. Browser cookies are a serious threat to your privacy.Graphic: Diego AguirreDon't want online ad companies shadowing you across the Web? Simply delete their browser tracking cookies, and you're free to wander. Right? Wrong. Web advertisers have found a way to follow you anyway, using
Adobe Flash cookies that automatically respawn after you delete them--hence their nickname, zombie cookies.
Last summer, privacy attorney
Joseph Malley filed class-action suits against ABC, Disney, MTV, NBC, and their advertising partners, charging them with violating federal privacy and computer security laws via Flash cookies.
The solution: You can use Adobe's occasionally flaky
Settings Manager, the Firefox plug-in
BetterPrivacy, or
CCleaner to
nuke those zombies. The problem? Sites such as Pandora Radio and YouTube rely on Flash cookies--which can store up to 100KB of data--to improve media playback, and they may not work without them. So choose your undead victims with care.
10. Criminal Stupidity
Threat Level: RED
For years we've been told that online-privacy policies will protect our rights. Now it seems that many of those policies are not worth the paper they're not printed on.
Google flatly denied that it was slurping data off Wi-Fi networks--until
the German governmenttold it to check again. Facebook said it had no idea it was sharing user IDs with advertisers--until
the Wall Street Journal pointed it out. Body scans weren't supposed to be retained; Webcams weren't supposed to capture teenagers in their bedrooms. Some of the biggest companies on the Web failed to play by their own rules, and didn't even realize it.
But Mobile Active Defense's Winn Schwartau says consumers are equally to blame--for clicking on spam and failing to protect their data, for sharing too much and caring too little.
"The biggest problem is criminal stupidity," he says. "If people follow basic security practices--secure their connections, pick reasonable passwords--they'll be in much better shape."
The solution: You're reading this article. That's a start.