Wednesday, December 21, 2016

Sanity for Superheroes: Why Everyone Is Getting Hacked These Days

Sanity for Superheroes: Why Everyone Is Getting Hacked These Days

Why Everyone Is Getting Hacked These Days

Why Everyone Is Getting Hacked These Days If it feels like there have been a lot of password hacks this year, it's because there have been more than usual, and Ars Technica's Dan Goodin explains why that is. In short: Password hacking has gotten better, while our password making has gotten worse. "The result: security provided by the average password in 2012 has never been weaker," Goodin writes, which is why it shouldn't surprise you that this year we have heard about security breaches at LinkedIn, eHarmony, Yahoo Voices, and a personal horror story from Wired's Mat Honan. Last year, James Fallows told us about his wife's security situation in The Atlantic story called "Hacked!" And for all the high profile accounts, there are all the ones we don't hear about. It's happening a lot these days. But why the sudden uptick? Goodin explains: Our password habits have gotten worse. "The average Web user maintains 25 separate accounts but uses just 6.5 passwords to protect them, according to a landmark study (PDF) from 2007," he writes. We have more things for which we need to create codes and it takes far too much brain space to store 25 different combos. Having the same passwords for various accounts was what did Fallows' wife in. Plus, the passwords we pick are stupid, as we learned from the Yahoo Voices hack, in which "123456" was (still!) a popular choice. It takes 10 minutes to crack a lower case 6 character password. To avoid this possible issue, we have before suggested picking dumb passwords for sites that don't matter.  Password cracking has gotten better. "Now used increasingly for computing, graphics processors allow password-cracking programs to work thousands of times faster than they did just a decade ago on similarly priced PCs that used traditional CPUs alone," adds Goodin, who details the various tech advancements in hacking. The LinkedIn breach taught us this, leading us to the conclusion that perhaps we need to accept that the modern password isn't good enough anymore.  There is a hacking network effect. With each hacker password revelation, future thieves learn more about the way the aggregate thinks. "The ever-growing list of leaked passwords allows programmers to write rules that make cracking algorithms faster and more accurate; password attacks have become cut-and-paste exercises that even script kiddies can perform with ease," explains Goodin. For one, it proves people still use "123456" and "password," even after being told lots of time to use better, different passwords. How many of you have started using Gmail's two-tiered authentication?  Sites have gotten worse at protecting us. Again, a lesson we learned from LinkedIn, in which the company admitted its protective measures weren't good enough. Honan blamed Apple and Amazon for his hack, too. The bulk of Goodin's post goes into the technical specifics of this dangerous state of affairs. Many websites for example don't have enough ""cryptographic 'salt' to passwords to render such attacks infeasible." "To the detriment of millions of Internet users, going without salt is only one of the many sins that popular websites routinely commit against password security," he writes.  Reading Goodin's take confirms to us that we have reached the end of the password as we know it. But what to do now? One could hope that technology fixes everything. Or maybe we should start thinking about the kind of stuff we put on the Internet and how we protect it.  ^ed  Sent via iPhone

If it feels like there have been a lot of password hacks this year, it's because there have been more than usual, and Ars Technica's Dan Goodin explains why that is. In short: Password hacking has gotten better, while our password making has gotten worse. "The result: security provided by the average password in 2012 has never been weaker," Goodin writes, which is why it shouldn't surprise you that this year we have heard about security breaches at LinkedIn, eHarmony, Yahoo Voices, and a personal horror story from Wired's Mat Honan. Last year, James Fallows told us about his wife's security situation in The Atlantic story called "Hacked!" And for all the high profile accounts, there are all the ones we don't hear about. It's happening a lot these days.

But why the sudden uptick? Goodin explains:

  • Our password habits have gotten worse. "The average Web user maintains 25 separate accounts but uses just 6.5 passwords to protect them, according to a landmark study (PDF) from 2007," he writes. We have more things for which we need to create codes and it takes far too much brain space to store 25 different combos. Having the same passwords for various accounts was what did Fallows' wife in. Plus, the passwords we pick are stupid, as we learned from the Yahoo Voices hack, in which "123456" was (still!) a popular choice. It takes 10 minutes to crack a lower case 6 character password. To avoid this possible issue, we have before suggested picking dumb passwords for sites that don't matter. 
  • Password cracking has gotten better. "Now used increasingly for computing, graphics processors allow password-cracking programs to work thousands of times faster than they did just a decade ago on similarly priced PCs that used traditional CPUs alone," adds Goodin, who details the various tech advancements in hacking. The LinkedIn breach taught us this, leading us to the conclusion that perhaps we need to accept that the modern password isn't good enough anymore. 
  • There is a hacking network effect. With each hacker password revelation, future thieves learn more about the way the aggregate thinks. "The ever-growing list of leaked passwords allows programmers to write rules that make cracking algorithms faster and more accurate; password attacks have become cut-and-paste exercises that even script kiddies can perform with ease," explains Goodin. For one, it proves people still use "123456" and "password," even after being told lots of time to use better, different passwords. How many of you have started using Gmail's two-tiered authentication? 
  • Sites have gotten worse at protecting us. Again, a lesson we learned from LinkedIn, in which the company admitted its protective measures weren't good enough. Honan blamed Apple and Amazon for his hack, too. The bulk of Goodin's post goes into the technical specifics of this dangerous state of affairs. Many websites for example don't have enough ""cryptographic 'salt' to passwords to render such attacks infeasible." "To the detriment of millions of Internet users, going without salt is only one of the many sins that popular websites routinely commit against password security," he writes. 

Reading Goodin's take confirms to us that we have reached the end of the password as we know it. But what to do now? One could hope that technology fixes everything. Or maybe we should start thinking about the kind of stuff we put on the Internet and how we protect it. 



^ed 

Tuesday, December 20, 2016

Remove information from Google - Search Help

Remove information from Google - Search Help

Remove information from Google

You can ask Google to remove your sensitive personal information, like your bank account number, or an image of your handwritten signature, or a nude or sexually explicit image or video of you that's been shared without your consent, from Google search results.

What Google will remove

See our Removals Policies to learn what information Google will remove.

If you want to remove a photo, profile link, or webpage from Google Search results, you usually need to ask the website owner (webmaster) to remove the information.

Why contact the webmaster?

Even if Google deletes the site or image from our search results, the webpage still exists and can be found through the URL to the site, social media sharing, or other search engines. This is why your best option is to contact the webmaster, who can remove the page entirely.

If a photo or information shows up in Google search results, it just means that the information exists on the Internet and it doesn't mean that Google endorses it.



^ed 

Why is my Twitter profile in Google search? | Twitter Help Center

Why is my Twitter profile in Google search? | Twitter Help Center

Why is my Twitter profile in Google search?

Your Twitter profile shows up in Google searches because Twitter has a high Google search rank. Keep in mind that the words you write in your Twitter profile or public Tweets may be indexed by Google and other search engines, and cause your profile or Tweets to come up in a search for those terms.

Depending on the degree to which this concerns you, you can try one or more of the steps below to prevent certain information from displaying in third party search results:

Note: Third party search engines like Google use many factors to generate search results, like the content of public Tweets and Twitter profiles, or blogs and other websites that link to Tweets or Twitter profiles. Twitter does not control search results on third party search engines.

Why are my Tweets appearing on Google after deleting or protecting them?

Protected Tweets:

  • Public Tweets posted before you select the account setting "protect my Tweets" may still be indexed in a third-party search engine. Once you have saved your account settings to protect your Tweets, the Tweets you post thereafter will be protected. If you later change your account settings to no longer protect your Tweets, Tweets that were previously protected will become public and may be indexed by third-party search engines.

Deleted Tweets:

  • Even if you delete Tweets, Google and other search engines cache search results, which means that occasionally old information is still searchable. Although Twitter changes your settings immediately and deletes Tweets immediately, these changes don't automatically erase old information in Google's search index.
  • Any old links appearing in a Google search will lead to Twitter's truth-telling error page: "That page doesn't exist!" The old links still appear because Google and other search engines may not have the current information updated in their search index.
  • Until Google updates the new information and indexes your current status, links to the profile or updates posted prior to removal/protection remain online.

How and when to send Google a request to remove the information:

Google will eventually index updated Twitter information, but if you'd like to request Google to do it sooner, follow the steps below.

  1. Copy the Twitter URL you'd like removed from Google's index (for example: twitter.com/#!/[username here]/status/12345678)
  2. Navigate to this page.
  3. Paste in the Twitter URL that you'd like removed.
  4. Submit your request.
Note: You may be required to log in to your Google account to complete the steps above. If you don't have one, you may need to create one. More information about removing your content from Google's search index can be found here.


^ed 

My Tweets are protected but still show in search | Twitter Help Center

My Tweets are protected but still show in search | Twitter Help Center

My Tweets are protected but still show in search

Why would this happen? 

  • After you protect your Tweets, only you and your followers can read your updates or see your Tweets in Twitter search.
  • If you at one time had public Tweets (before protecting your Tweets), those Tweets will no longer be public or appear in public Twitter search results. However, unprotecting your Tweets will cause any previously protected Tweets to be made public.
  • To find out how to remove your updates from Google search, check out this article. Twitter does not have the ability to remove content on websites other than twitter.com.

What If my Tweets have never been public?

  • If your Tweets have never been public (in other words, you've always had your Tweets protected in your settings), your updates should never show up in Twitter search or other public search engines.
  • If they are showing up in search results, change your password immediately and revoke untrusted third-party applications. You can also submit a request with the following information:
  1. When this started happening
  2. Where you've seen your private updates posted (Twitter Search, Google, Bing, etc.)
  3. List any/all third-party applications you use

Still need help? Contact Support.



^ed 

US military studied how to influence Twitter users in Darpa-funded research

US military studied how to influence Twitter users in Darpa-funded research | World news | The Guardian


US military studied how to influence Twitter users in Darpa-funded research

Occupy Wall Street
Darpa defended the funding, including to study activists on social networks and Lady Gaga's influence, as essential to US interests. Photograph: Stan Honda/AFP/Getty

The activities of users of Twitter and other social media services were recorded and analysed as part of a major project funded by the US military, in a program that covers ground similar to Facebook's controversial experiment into how to control emotions by manipulating news feeds.

Research funded directly or indirectly by the US Department of Defense's military research department, known as Darpa, has involved users of some of the internet's largest destinations, including Facebook, Twitter, Pinterest and Kickstarter, for studies of social connections and how messages spread.

While some elements of the multi-million dollar project might raise a wry smile – research has included analysis of the tweets of celebrities such as Lady Gaga and Justin Bieber, in an attempt to understand influence on Twitter – others have resulted in the buildup of massive datasets of tweets and additional types social media posts.

Several of the DoD-funded studies went further than merely monitoring what users were communicating on their own, instead messaging unwitting participants in order to track and study how they responded.

Shortly before the Facebook controversy erupted, Darpa published a lengthy list of the projects funded under its Social Media in Strategic Communication (SMISC) program, including links to actual papers and abstracts.

The project list includes a study of how activists with the Occupy movement used Twitter as well as a range of research on tracking internet memes and some about understanding how influence behaviour (liking, following, retweeting) happens on a range of popular social media platforms like Pinterest, Twitter, Kickstarter, Digg and Reddit.

Darpa, established in 1958, is responsible for technological research for the US military. Its notable successes have included no less than Arpanet, the precursor to today's internet, and numerous other innovations, including onion routing, which powers anonymising technologies like Tor. However, thanks to some of its more esoteric projects, which have included thought-controlled robot arms, city-wide surveillance programs and exo-skeletons, the agency has also become the subject of many conspiracy theories, and a staple in programmes like the X-Files.

Unveiled in 2011, the SMISC program was regarded as a bid by the US military to become better at both detecting and conducting propaganda campaigns on social media.

On the webpage where it has published links to the papers, Darpa states the general goal of the SMISC program is "to develop a new science of social networks built on an emerging technology base".

darpa Defense Advanced Research Projects Agency robot boston dynamics
Darpa has a reputation for projects such as this robot, developed to handle rough terrain at high speeds. Photograph: HO/AFP/Getty Images

"Through the program, Darpa seeks to develop tools to support the efforts of human operators to counter misinformation or deception campaigns with truthful information."

However, papers leaked by NSA whistleblower Edward Snowden indicate that US and British intelligence agencies have been deeply engaged in planning ways to covertly use social media for purposes of propaganda and deception.

Documents prepared by NSA and Britain's GCHQ (and previously published by the Intercept as well as NBC News) revealed aspects of some of these programs. They included a unit engaged in "discrediting" the agency's enemies with false information spread online.

Earlier this year, the Associated Press also revealed the clandestine creation by USAid of a Twitter-like, Cuban communications network to undermine the Havana government. The network, built with secret shell companies and financed through a foreign bank, lasted more than two years and drew tens of thousands of subscribers. It sought to evade Cuba's stranglehold on the internet with a primitive social media platform.

Of the funding provided by Darpa, $8.9m has been channeled through IBM to a range of academic researchers and others. A further $9.6m has gone through academic hubs like Georgia Tech and Indiana University.

Facebook, the world's biggest social networking site, has apologised for the study, which involved secret psychological tests on nearly 700,000 users in 2012, and prompted outrage from users and experts alike, being "poorly communicated" to the public.

The experiment, which resulted in a scientific paper published in the March issue of Proceedings of the National Academy of Sciences, hid "a small percentage" of emotional words from peoples' news feeds, without their knowledge, to test what effect that had on the statuses or "likes" that they then posted or reacted to.

However, it appears that Facebook was involved in at least one other military-funded social media research project, according to the records recently published by Darpa.

The research was carried by Xuanhuai Wang, an engineering manager at Facebook, as well as Yi Chang, a lead scientist at Yahoo labs, and others based at the Universities of Michigan and Southern California.

The project, which related to how users understood and consumed information on Twitter, at one point analysed the tweets, retweets and other interactions spawned by Lady Gaga (described as "the most popular elite user on Twitter") and Justin Bieber ("who is extremely popular among teenagers").

Sheryl Sandberg
Facebook's CEO Sheryl Sandberg apologised for 'poor communication' over psychological experiments to manipulate users' emotions. Photograph: Money Sharma/EPA

Other studies looked further afield. One, "On the Study of Social Interactions on Twitter", which was carried out by the University of South California, collected tweets from 2,400 Twitter users who had identified themselves as residing in the Middle East. It analysed how often they had interactions with other users and how these were spread.

Several studies related to the automatic assessment of how well different people in social networks knew one another, through analysing frequency, tone and type of interaction between different users. Such research could have applications in the automated analysis of bulk surveillance metadata, including the controversial collection of US citizens' phone metadata revealed by Snowden.

Studies which received military funding channeled through IBM included one called "Modeling User Attitude toward Controversial Topics in Online Social Media", which analysed Twitter users' opinions on fracking.

Discussing the applicability of their research, the study's authors stated: "For example, a government campaign on Twitter supporting vaccination can engage with followers who are more likely to take certain action (eg spreading a campaign message) based on their opinions."

"As another example, when anti-government messages are spread in social media, government would want to spread counter messages to balance that effort and hence identify people who are more likely to spread such counter messages based on their opinions."

A similarly titled-project out of the University of Southern California, "The Role of Social Media in the Discussion of Controversial Topics", studied the behaviour of Twitter users posting about a 2012 vote in California on measures such as raising taxes, genetically modified organisms and the death penalty.

"Our findings suggest Twitter is primarily used for spreading information to like-minded people rather than debating issues," the authors wrote in their paper on the project.

A study at Georgia Tech, "Cues to Deception in Social Media Communications", involved an in-laboratory experiment using an experimental social media platform, "FaceFriend", and 61 paid participants. While past research had investigated "written deception" in communications such as email, the study expanded this into social media, and the researchers concluded: "Breaking news stories and world events – for example, the Arab Spring – are heavily represented in social media, making them susceptible topics for influence attempts via deception."

Tahrir Square Rally
The use of social media during rapidly-developing world events with major consequences, as during Egypt's 2011 revolution, was studied by researchers. Photograph: Peter Macdiarmid/Getty Images

Several of the DoD-funded projects went further than simple observation, instead engaging directly with social media users and analysing their responses.

One of multiple studies looking into how to spread messages on the networks, titled "Who Will Retweet This? Automatically Identifying and Engaging Strangers on Twitter to Spread Information" did just this.

The researchers explained: "Since everyone is potentially an influencer on social media and is capable of spreading information, our work aims to identify and engage the right people at the right time on social media to help propagate information when needed."

In the paper, which included data gathered through actively engaging 3,761 people on Twitter around the topics of public safety and bird flu, the researchers added: "Unlike existing work, which often uses only social network properties, our feature set includes personality traits that may influence one's retweeting behaviour."

In a statement, Darpa defended its funding of the research as essential to US defense interests.

"Social media is changing the way people inform themselves, share ideas, and organize themselves into interest groups, including some that aim to harm the United States," said a spokesman. "Darpa supports academic research that seeks to understand some of these dynamics through analyses of publicly available discussions conducted on social media platforms."

Sources said that data was from public streams in social networks, and was collected and stored by academics at institutions conducting the research, not by Darpa itself.

The Guardian approached a number of individuals involved in research, asking them for their views on why they believed the US military may be interested in funding research of this type, and asking about the extent to which consent was sought from people whose social media posts were recorded and analysed.

Among those who replied, Emilio Ferrara, who was involved in the research paper on "The Digital Evolution of Occupy Wall St", said: "According to federal regulations of human experimentation, for studies that don't affect the environment of online users, and whereas one can freely gather online data – say, from the public Twitter feed – there is no requirement of informed consent. This is the framework under which our Twitter study was carried out; moreover, all our studies on Twitter look into aggregate collective phenomena and never at the individual level."

A colleague, Dr Filippo Menczer, added: "In our lab we study all aspects of the diffusion of information in social media.

"This work has broad applications as we strive to understand fundamental mechanism of social communication, such as how ideas and 'memes' compete for our attention, how they sometimes go viral, etc."