Sunday, May 19, 2019

Microsoft Privacy Statement – Microsoft privacy

Microsoft Privacy Statement – Microsoft privacy

Microsoft Privacy Statement – Microsoft privacy

Cookies are small text files placed on your device to store data that can be recalled by a web server in the domain that placed the cookie. This data often consists of a string of numbers and letters that uniquely identifies your computer, but it can contain other information as well. Some cookies are placed by third parties acting on our behalf. We use cookies and similar technologies to store and honor your preferences and settings, enable you to sign-in, provide interest-based advertising, combat fraud, analyze how our products perform, and fulfill other legitimate purposes described below. Microsoft apps use additional identifiers, such as the advertising ID in Windows, for similar purposes, and many of our websites and applications also contain web beacons or other similar technologies, as described below.

Our use of cookies and similar technologies

Microsoft uses cookies and similar technologies for several purposes, depending on the context or product, including:

  • Storing your preferences and settings. We use cookies to store your preferences and settings on your device, and to enhance your experiences. For example, if you enter your city or postal code to get local news or weather information on a Microsoft website, depending on your settings, we store that data in a cookie so that you will see the relevant local information when you return to the site. Saving your preferences with cookies, such as your preferred language, prevents you from having to set your preferences repeatedly. If you opt out of interest-based advertising, we store your opt-out preference in a cookie on your device.
  • Sign-in and authentication. We use cookies to authenticate you. When you sign in to a website using your personal Microsoft account, we store a unique ID number, and the time you signed in, in an encrypted cookie on your device. This cookie allows you to move from page to page within the site without having to sign in again on each page. You can also save your sign-in information so you do not have to sign in each time you return to the site.
  • Security. We use cookies to process information that helps us secure our products, as well as detect fraud and abuse.
  • Storing information you provide to a website. We use cookies to remember information you shared. When you provide information to Microsoft, such as when you add products to a shopping cart on Microsoft websites, we store the data in a cookie for the purpose of remembering the information.
  • Social media. Some of our websites include social media cookies, including those that enable users who are signed in to the social media service to share content via that service.
  • Feedback. Microsoft uses cookies to enable you to provide feedback on a website.
  • Interest-based advertising. Microsoft uses cookies to collect data about your online activity and identify your interests so that we can provide advertising that is most relevant to you. You can opt out of receiving interest-based advertising from Microsoft as described in the How to access and control your personal data section of this privacy statement.
  • Showing advertising. Microsoft uses cookies to record how many visitors have clicked on an advertisement and to record which advertisements you have seen, for example, so you don't see the same one repeatedly.
  • Analytics. We use first- and third-party cookies and other identifiers to gather usage and performance data. For example, we use cookies to count the number of unique visitors to a web page or service and to develop other statistics about the operations of our products.
  • Performance. Microsoft uses cookies to understand and improve how our products perform. For example, we use cookies to gather data that helps with load balancing; this helps ensure that our websites remain up and running.

Some of the cookies we commonly use are listed below. This list is not exhaustive, but it is intended to illustrate the primary purposes for which we typically set cookies. If you visit one of our websites, the site will set some or all of the following cookies:

  • MUID, MC1, and MSFPC. Identifies unique web browsers visiting Microsoft sites. These cookies are used for advertising, site analytics, and other operational purposes.
  • ANON. Contains the ANID, a unique identifier derived from your Microsoft account, which is used for advertising, personalization, and operational purposes. It is also used to preserve your choice to opt out of interest-based advertising from Microsoft if you have chosen to associate the opt-out with your Microsoft account.
  • CC. Contains a country code as determined from your IP address.
  • PPAuth, MSPAuth, MSNRPSAuth, KievRPSAuth, WLSSC, MSPProf. Helps to authenticate you when you sign in with your Microsoft account.
  • MC0. Detects whether cookies are enabled in the browser.
  • MS0. Identifies a specific session.
  • NAP. Contains an encrypted version of your country, postal code, age, gender, language and occupation, if known, based on your Microsoft account profile.
  • MH. Appears on co-branded sites where Microsoft is partnering with an advertiser. This cookie identifies the advertiser, so the right ad is selected.
  • childinfo, kcdob, kcrelid, kcru, pcfm. Contains information that Microsoft account uses within its pages in relation to child accounts.
  • MR. Used to collect information for analytics purposes.
  • x-ms-gateway-slice. Identifies a gateway for load balancing.
  • TOptOut. Records your decision not to receive interest-based advertising delivered by Microsoft.

In addition to the cookies Microsoft sets when you visit our websites, third parties can also set cookies when you visit Microsoft sites. For example:

  • Companies we hire to provide services on our behalf, such as site analytics, place cookies when you visit our sites. See opt-out links below.
  • Companies that deliver content, such as videos or news, or ads on Microsoft sites, place cookies on their own. These companies use the data they process in accordance with their privacy policies, which may enable these companies to collect and combine information about your activities across websites, apps, or online services.

How to control cookies

Most web browsers automatically accept cookies but provide controls that allow you to block or delete them. For example, in Microsoft Edge, you can block or delete cookies by selecting Settings > Privacy > Advanced Settings > Cookies. Please refer to your browser's privacy or help documentation to find Instructions for blocking or deleting cookies in other browsers.

Certain features of Microsoft products depend on cookies. If you choose to block cookies, you cannot sign in or use some of those features, and preferences that are dependent on cookies will be lost. If you choose to delete cookies, any settings and preferences controlled by those cookies, including advertising preferences, are deleted and will need to be recreated.

Additional privacy controls that can impact cookies, including the Tracking Protection feature of Microsoft browsers, are described in the How to access and control your personal data section of this privacy statement.

Our use of web beacons and analytics services

Some Microsoft webpages contain electronic tags known as web beacons that we use to help deliver cookies on our websites, count users who have visited those websites, and deliver co-branded products. We also include web beacons or similar technologies in our electronic communications to determine whether you open and act on them.

In addition to placing web beacons on our own websites, we sometimes work with other companies to place our web beacons on their websites or in their advertisements. This helps us develop statistics on how often clicking on an advertisement on a Microsoft website results in a purchase or other action on the advertiser's website.

Finally, Microsoft products often contain web beacons or similar technologies from third-party analytics providers, which help us compile aggregated statistics about the effectiveness of our promotional campaigns or other operations. These technologies enable the analytics providers to set or read their own cookies or other identifiers on your device, through which they can collect information about your online activities across applications, websites, or other products. However, we prohibit these analytics providers from using web beacons on our sites to collect or access information that directly identifies you (such as your name or email address). You can opt out of data collection or use by some of these analytics providers by clicking any of the following links: Adjust, AppsFlyer, Clicktale, Flurry Analytics, Google Analytics (requires you to install a browser add-on), Kissmetrics, Mixpanel, Nielsen, Visible Measures, or WebTrends.

Other similar technologies

In addition to standard cookies and web beacons, our products can also use other similar technologies to store and read data files on your computer. This is typically done to maintain your preferences or to improve speed and performance by storing certain files locally. But, like standard cookies, these technologies can also store a unique identifier for your computer, which can then track behavior. These technologies include Local Shared Objects (or "Flash cookies") and Silverlight Application Storage.

Local Shared Objects or "Flash cookies." Websites that use Adobe Flash technologies can use Local Shared Objects or "Flash cookies" to store data on your computer. To learn how to manage or block Flash cookies, go to the Flash Player help page.

Silverlight Application Storage. Websites or applications that use Microsoft Silverlight technology also have the ability to store data by using Silverlight Application Storage. To learn how to manage or block such storage, see the Silverlight section of this privacy statement.



Elyssa D. Durant 

Saturday, May 18, 2019

How Hackers Broke WhatsApp With Just a Phone Call | WIRED

How Hackers Broke WhatsApp With Just a Phone Call | WIRED




How Hackers Broke WhatsApp With Just a Phone Call

You've heard the advice a million times. Don't click links in suspicious emails or texts. Don't download shady apps. But a new Financial Times report alleges that the notorious Israeli spy firm NSO Group developed a WhatsApp exploit that could inject malware onto targeted phones—and steal data from them—simply by calling them. The targets didn't need to pick up to be infected, and the calls often left no trace on the phone's log. But how would a hack like that even work in the first place?

WhatsApp, which offers encrypted messaging by default to its 1.5 billion users worldwide, discovered the vulnerability in early May and released a patch for it on Monday. The Facebook-owned company told the FT that it contacted a number of human rights groups about the issue and that exploitation of this vulnerability bears "all the hallmarks of a private company known to work with governments to deliver spyware." In a statement, NSO Group denied any involvement in selecting or targeting victims but not its role in the creation of the hack itself.

So-called zero-day bugs, in which attackers find a vulnerability before the company can patch it, happen on every platform. It's part and parcel of software development; the trick is to close those security gaps as quickly as possible. Still, a hack that requires nothing but an incoming phone call seems uniquely challenging—if not impossible—to defend against.

WhatsApp wouldn't elaborate to WIRED about how it discovered the bug or give specifics on how it works, but the company says it is doing infrastructure upgrades in addition to pushing a patch to ensure that customers can't be targeted with other phone-call bugs.

"Remote-exploitable bugs can exist in any application that receives data from untrusted sources," says Karsten Nohl, chief scientist at the German firm Security Research Labs. That includes WhatsApp calls, which use the voice-over-internet protocol to connect users. VoIP applications have to acknowledge incoming calls and notify you about them, even if you don't pick up. "The more complex the data parsing, the more room for error," Nohl says. "In the case of WhatsApp, the protocol for establishing a connection is rather complex, so there is definitely room for exploitable bugs that can be triggered without the other end picking up the call."

VoIP calling services have been around for so long that you'd think any kinks in the basic call connection protocols would be worked out by now. But in practice, every service's implementation is a little bit different. Nohl points out that things get even trickier when you are offering end-to-end encrypted calling, as WhatsApp famously does. While WhatsApp bases its end-to-end encryption on the Signal Protocol, its VoIP calling functionally likely also includes other proprietary code as well. Signal says that its service is not vulnerable to this calling attack.

According to Facebook's security advisory, the WhatsApp vulnerability stemmed from an extremely common type of bug known as a buffer overflow. Apps have a sort of holding pen, called a buffer, to stash extra data. A popular class of attacks strategically overburdens that buffer so the data "overflows" into other parts of the memory. This can cause crashes or, in some cases, give attackers a foothold to gain more and more control. That's what happened with WhatsApp. The hack exploits the fact that in a VoIP call the system has to be primed for a range of possible inputs from the user: pick up, decline the call, and so on.

"This does indeed sound like a freak incident, but at the heart of it seems to be a buffer overflow problem that is unfortunately not too uncommon these days," says Bjoern Rupp, CEO of the German secure communication firm CryptoPhone. "Security never was WhatsApp's primary design objective, which means WhatsApp has to rely on complex VoIP stacks that are known for having vulnerabilities."

The WhatsApp bug was being exploited to target only a small number of high-profile activists and political dissidents, so most people won't have been affected by any of this in practice. But you should still download the patch on your Android and iOS devices.

"Companies like NSO Group try to keep a little stockpile of things that can be used to get onto devices," says John Scott-Railton, a senior researcher at the University of Toronto's Citizen Lab. "This incident makes it abundantly clear that anyone with a phone is impacted by the kind of vulnerabilities that customers of these companies are slinging around. There's a reality here for all of us."


More Great WIRED Stories



Elyssa D. Durant 
Research & Policy Analyst

Thursday, May 9, 2019

Android Q gets the privacy controls Google should have added years ago

Android Q gets the privacy controls Google should have added years ago
Just a few of the bizarre sites that were running in the background charging thousands of dollars since I became public enemy number one. 

All activists and journalists are the horrible people who are hurting Trump's fee fees. 

When Trump cried about Obama "tapped his wires"  and whines about FISA and I was embarrassed for him. 

How can he control nuclear missiles and be totally ignorant of NASA and Surveillance and the telecom act and the digital transition mandated by the FCC which had more to do with creating an extensive seamless network to track and monitor we the people and listen to our  most private movements and activities on in our own homes and every public space from CVS to Target or city park 

To. Be continued. I have to take an Uber to  take me to get another burner. Apparently LulzSec JS. And and I'm too exhausted to deal with the help-LESS desk. 







Android Q gets the privacy controls Google should have added years ago

Android Q gets the privacy controls Google should have added years ago

As tech giants come under fire for facilitating the widespread collection and sale of personal data, Google has read the room and will add new privacy features to Android. In the next version of the operating system, called Android Q, apps will need explicit permission to track users' locations while running in the background. Android Q will also limit access to hardware information (presumably to stop device fingerprinting), and will no longer track "affinity" for contacts, which means apps won't be able to see who users interact with the most.

Apple has already adopted many of these features in iOS and MacOS as the company turns privacy into a key selling point. Most notably, iOS users have been able to limit background location access since 2017, while Android's location access has been all-or-nothing. As the New York Times reported in December, popular apps like The Weather Channel and TheScore have in turn been selling that location data to marketers. With U.S. lawmakers starting to think about new privacy laws, it behooves Google to get in front of the issue.

Having said all that, Android phone makers have a poor track record of updating their software in a timely manner, if at all. Unless you're using one of Google's Pixel phones, which can now beta-test an early version of Android Q, you might not see these privacy improvements for quite some time.



Elyssa D. Durant 
Research & Policy Analyst

Saturday, April 20, 2019

This is disturbing. Mar-a-Lago is less than a mile from me.

This is disturbing. Mar-a-Lago is less than a mile from me.

Bad enough he launches missiles from Mar-a-Lago and that I had 8 machine guns pointed at my head, Russian Oligarchs (Abramovich) complete with two helicopters and a submarine outside my condo when they filmed me for the Documentary on December 21, 2017 and that I now live in proximity to a HIGH RISK CRITICAL ASSET TARGET FOR TERRORISM and now I see 👇🏼👇🏼👇🏼👇🏼

I'm banned at Mar-a-Lago because I reported them to ICE and Homeland Security but Secret Service and the Sheriff let me right in. They kind of have to. My ID grants me access and the only weapon I carry is camera and a recording device. Both prohibited at Mar-a-Lago. As are guns ironically enough.

Of course they know me. James Johnson made a bomb threat on Memorial Day and posted it right here on Facebook along with my photo. It didn't take long for law enforcement to get here and take a report.

And if you're still reading this, google me before you @ me.

I'm only a minor threat. Have a nice day.



Elyssa D. Durant
Policy & Research Analyst

Friday, March 22, 2019

Comcast Customer Privacy Notice

Comcast Customer Privacy Notice

Information Provided by Third Parties

We may obtain additional information about you from third parties such as demographic data (for example, gender, age, and census records, etc.), location data (for example, designated market area, zip code, etc.), interest data (for example, sports, travel, and other recreational activities, shopping preferences, etc.), or purchase data (for example, public records, loyalty programs, etc.). We may combine the data we collect from third parties with information in our business records, including information about your use of the Services. We may also combine information about your use of the Services with information we obtain from your use of other products, services, websites, and applications from Comcast. We use this combined data as described in the "Use of Information" section below.

III. Sharing & Disclosures of Information

We limit the information we share and disclose to others as described below.

Service Providers

In order to provide and support the Services, sometimes we use third-party companies as service providers that work on our behalf to transmit, collect, process, or store information for us. We require these service providers to treat the information we share with them as confidential and to use it only for the purpose of providing the services for which they have been engaged. These engagements typically include services such as billing and collections, administration, auditing and accounting, professional advice and consulting, surveys, marketing, service delivery and customization, maintenance and operations, security incident verification and response, service notifications, fraud prevention, and services to improve our programming and advertising offerings. For example, Comcast uses service providers to process payments for us and we may share your payment information with those billing processors when you make a payment. Or, Comcast may use a service provider to obtain information about you to assess your credit and payment status.

The Comcast Family of Businesses

Comcast may share the information it collects with its affiliates that offer other Xfinity and Comcast-branded products, services, and applications. For example, if you use your Xfinity Service account information to create an Xfinity Mobile Service account, we may share your Service account information with the Comcast company that offers that service. We do this so that these companies can provide services to you and to make it easier for you to use Xfinity Mobile Service and other Xfinity services. We may also share information about you with other Comcast companies (including NBCUniversal-branded companies and other non-Comcast or non-Xfinity-branded affiliates) for marketing and advertising purposes when we have any required consent to do so.

Account Owners and Users

Comcast may disclose any information about a customer's account and use of the Services and their features to the primary account owner after appropriate authentication. The primary account owner may also authorize other users to access information on the account, and that may include data about you and your use of the Services.

Third Parties for Marketing Purposes

We will not share, sell, license, rent, or otherwise permit access to information that personally identifies you to an unaffiliated third party for that third party to market its products or services to you, unless we have the required consent to do so. Unless we have your affirmative "opt-in" consent, we will not sell or share any of your personally identifiable web browsing information, video activity data, sensitive information (such as financial account information or Social Security number), or call detail records that we collect from our cable system. We may, however, share de-identified or aggregate information with third parties for their own uses when those third parties commit to not re-identify that information or share it with others who may attempt to do so.

As permitted by federal law, we may disclose your name and address to non-governmental entities, such as charities or businesses, so long as such disclosure does not reveal, directly or indirectly, the extent of your use of the Services or the nature of any transaction you make over our cable system. You have the right to prohibit or limit this kind of disclosure by asking to be placed on our "do not disclose" list, as described in Section IV of this Notice ("Your Choices").

Other Third Parties

If you subscribe to our voice service, Comcast may disclose information about you to others in connection with features and services such as Caller ID, 911/E911, and directory services as follows:

  • We may transmit your name and/or telephone number to be displayed on a Caller ID device unless you have elected to block such information. Please note that Caller ID blocking may not prevent the display of your name and/or telephone number when you dial certain business or emergency numbers, 911, 900 numbers, or toll-free 800 and similar numbers.
  • We may provide your name, address, and telephone number to public safety authorities and their vendors for inclusion in E911 databases and records, inclusion in "reverse 911" systems, or to troubleshoot 911/E911 record errors.
  • We may publish and distribute, or cause to be published and distributed, telephone directories in print, on the Internet, and on disks. Those telephone directories may include subscriber names, addresses, and telephone numbers, without restriction to their use.
  • We may also make subscriber names, addresses, and telephone numbers available, or cause such subscriber information to be made available, through directory assistance operators.
  • We may provide subscribers' names, addresses, and telephone numbers to unaffiliated directory publishers and directory assistance providers for their use in creating directories and offering directory assistance services.
  • Once our subscribers' names, addresses, and telephone numbers appear in telephone directories or directory assistance, they may be sorted, packaged, repackaged, and made available again in different formats by anyone.

We take reasonable precautions to ensure that non-published and unlisted numbers are not included in our telephone directories or directory assistance services, but we cannot guarantee that errors will never occur.

If we (or our parent company) enter into a merger, acquisition, or sale of all or a portion of our assets, information about you and your subscription, including information that personally identifies you, will, in most instances, be one of the items transferred as part of the transaction. If this Notice will be changed as a result of such a transaction, you should refer below under "Changes to the Privacy Notice."

When Required by Law or To Protect Comcast and Others

There are times when we may be required by law to disclose information about you to third parties. These disclosures may be made with or without your consent, and with or without notice, in compliance with the terms of valid legal process such as a subpoena, court order, or search warrant.

If you subscribe to our Xfinity video service, Comcast may be required to disclose information that personally identifies you to a governmental entity in response to a court order. In this case, the Cable Act (defined below in Section V) requires that you be afforded the opportunity to appear and contest in a court proceeding relevant to the court order any claims made in support of the court order. At the proceeding, the Cable Act requires the governmental entity to offer clear and convincing evidence that the subject of the information is reasonably suspected of engaging in criminal activity and that the information sought would be material evidence in the case.

If you subscribe to the Xfinity Internet, voice, or home security services, Comcast may be required to disclose information that personally identifies you to a governmental entity in response to a subpoena, court order, or search warrant, depending on the type of information sought. We are usually prohibited from notifying you of any such disclosures by the terms of the legal process. We may also seek your consent to disclose information in response to a governmental entity's request when that governmental entity has not provided the required subpoena, court order, or search warrant.

A non-governmental entity, such as a civil litigant, can seek information that personally identifies you or your use of the Xfinity video, Internet, or voice services only pursuant to a court order and we are required by the Cable Act to notify you of such court order. If Comcast is required to disclose information that personally identifies you to a private third party in response to a civil court order, we will notify you prior to making such disclosure unless legally prohibited from doing so.

We may also disclose information that personally identifies you as permitted by law and without your consent when it is necessary to protect our customers, employees, or property; in emergency situations; or to enforce our rights under our terms of service and policies.



Elyssa D. Durant
Policy & Research Analyst