High Court Rules Against Government Bulk Hacking

High Court Rules Against Government Bulk Hacking

Privacy experts are celebrating after the High Court ruled against the intelligence agencies’ use of bulk hacking for domestic targets.

In 2014, Edward Snowden first revealed the use of hacking techniques to target large numbers of users simultaneously. The government relied on the issuing of “general warrants” under section 5 of the Intelligence Services Act 1994 to do so.

Non-profit Privacy International challenged the practice in the Investigatory Powers Tribunal (IPT), a secretive court set-up to handle cases involving the intelligence agencies. However, the IPT ruled in the latter’s favor, back in 2016.

Although the government then tried to block a High Court challenge to the ruling, by claiming the tribunal’s decisions can’t be subject to judicial review, it lost, and the case went ahead.

On Friday, the High Court agreed with Privacy International, quashing the IPT decision.

It cited 250 years of common law precedent whereby individuals have a right not to not have their property searched without lawful authority, even in cases of national security. As general warrants don’t apply to individuals, the authorities are wrong to take this approach, it found.

“The aversion to general warrants is one of the basic principles on which the law of the United Kingdom is founded,” the court noted. “As such, it may not be overridden by statute unless the wording of the statute makes clear that parliament intended to do so.”

Privacy International legal director, Caroline Wilson Palow, argued the ruling brought legal precedent into the modern age, where searching “property” could mean remotely spying on users’ digital lives.

“General warrants are no more permissible today than they were in the 18th century. The government had been getting away with using them for too long. We welcome the High Court’s affirmation of these fundamental constitutional principles,” she said.

However, some government hacking powers are now governed by a newer law, the controversial Snooper’s Charter, or Investigatory Powers Act.

There are also various legal challenges underway to this legislation. In October last year, campaigners received a boost when the Court of Justice of the European Union (CJEU) ruled that bulk collection and retention of citizens’ data must be brought into line with EU privacy law, even in cases of national security.

The UK has a vested interest in rowing back from its position on bulk surveillance, as it seeks an “adequacy decision” from the EU on data handling that is vital to seamless cross-border data flows in the new post-Brexit era.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Changes in WhatsApp’s Privacy Policy

If you’re a WhatsApp user, pay attention to the changes in the privacy policy that you’re being forced to agree with.

In 2016, WhatsApp gave users a one-time ability to opt out of having account data turned over to Facebook. Now, an updated privacy policy is changing that. Come next month, users will no longer have that choice. Some of the data that WhatsApp collects includes:

  • User phone numbers
  • Other people’s phone numbers stored in address books
  • Profile names
  • Profile pictures and
  • Status message including when a user was last online
  • Diagnostic data collected from app logs

Under the new terms, Facebook reserves the right to share collected data with its family of companies.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ubiquiti: Change Your Password, Enable 2FA

Ubiquiti, a major vendor of cloud-enabled Internet of Things (IoT) devices such as routers, network video recorders, security cameras and access control systems, is urging customers to change their passwords and enable multi-factor authentication. The company says an incident at a third-party cloud provider may have exposed customer account information and credentials used to remotely manage Ubiquiti gear.

In an email sent to customers today, Ubiquiti Inc. [NYSE: UI] said it recently became aware of “unauthorized access to certain of our information technology systems hosted by a third party cloud provider,” although it declined to name that provider.

The statement continues:

“We are not currently aware of evidence of access to any databases that host user data, but we cannot be certain that user data has not been exposed. This data may include your name, email address, and the one-way encrypted password to your account (in technical terms, the passwords are hashed and salted). The data may also include your address and phone number if you have provided that to us.”

Ubiquiti has not yet responded to requests for more information, but the notice was confirmed as official in a post on the company’s user support forum.

The warning from Ubiquiti carries particular significance because the company has made it fairly difficult for customers using the latest Ubiquiti firmware to interact with their devices without first authenticating through the company’s cloud-based systems.

This has become a sticking point for many Ubiquiti customers, as evidenced by numerous threads on the topic in the company’s user support forums over the past few months.

“While I and others do appreciate the convenience and option of using hosted accounts, this incident clearly highlights the problem with relying on your infrastructure for authenticating access to our devices,” wrote one Ubiquiti customer today whose sentiment was immediately echoed by other users. “A lot us cannot take your process for granted and need to keep our devices offline during setup and make direct connections by IP/Hostname using our Mobile Apps.”

To manage your security settings on a Ubiquiti device, visit https://account.ui.com and log in. Click on ‘Security’ from the left-hand menu.

1. Change your password
2. Set a session timeout value
3. Enable 2FA

Image: twitter.com/crosstalksol/

According to Ubiquiti’s investment literature, the company has shipped more than 85 million devices that play a key role in networking infrastructure in over 200 countries and territories worldwide.

This is a developing story that may be updated throughout the day.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

JPMorgan Chase Hacker Gets 12 Years

JPMorgan Chase Hacker Gets 12 Years

A Russian hacker who was instrumental in one of the largest thefts in history of US customer data from a single financial institution  has been sentenced to prison. 

Moscow resident Andrei Tyurin, also known as Andrei Tiurin, was part of an international hacking campaign that compromised the computer systems of major financial institutions, brokerage firms, news agencies, and other companies to steal data.

Tyurin’s illegal activities were committed with the help of partner Gery Shalon, along with Joshua Samuel Aaron, Ziv Orenstein, and other co-conspirators in furtherance of securities market manipulation, illegal online gambling, and payment processing fraud schemes.

According to the allegations contained in the indictments to which Tyurin pled guilty, the 37-year-old Muscovite hacked into companies between 2012 and mid-2015 and stole the personal information of over 100 million customers.

Among the companies targeted were E*Trade, Scottrade, the Wall Street Journal, and JPMorgan Chase and Co., from which Tyurin stole personal data belonging to more than 80 million of the bank’s customers.

On top of the hacks, from around 2007 to mid-2015, Tyurin carried out cyber-attacks against numerous American and foreign companies for the benefit of various criminal enterprises operated by Shalon and his co-conspirators, including unlawful internet gambling businesses and international payment processors. 

Through these various criminal schemes, Tyurin, Shalon, and their co-conspirators obtained hundreds of millions of dollars in illicit proceeds, with Tyurin personally amassing $19m in profits from his hacking activity alone.

In one scheme, Tyurin, Shalon, and his co-conspirators misleadingly marketed certain stocks, publicly traded in the US, to customers of the victim companies whose contact information Tyurin had stolen, in an attempt to artificially inflate the stocks’ prices.

To carry out his nefarious activities, Tyurin used computer infrastructure located across five continents, which he controlled from his home. 

Tyurin was extradited to the United States from the country of Georgia in September 2018. On January 7, in Manhattan Federal Court, US District Judge Laura Taylor Swain sentenced Tyurin to 144 months in prison for computer intrusion, wire fraud, bank fraud, and illegal online gambling offenses in connection with his involvement in the hacking campaign.

In addition to the prison term, Judge Swain ordered Tyurin to pay forfeiture in the amount of $19,214,956.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attack Costs Health Network $1.5m a Day

Ransomware Attack Costs Health Network $1.5m a Day

A cyber-attack on a Vermont healthcare provider has delayed the rollout of an electronic health record (EHR) system and cost millions of dollars in lost revenue. 

The University of Vermont Health Network, which is based in Burlington, was hit by ransomware in October 2020, and is yet to make a full recovery. Most computer systems have been brought back online; however, some applications are still down, causing delays in various departments, including radiology.

The network serves much of Vermont and parts of upstate New York. When attackers struck at six of the network’s hospitals, Vermont’s governor, Phil Scott, deemed the situation serious enough to merit the deployment of the Vermont Army National Guard’s Combined Cyber Response Team 1 to aid in the recovery effort.

In December, UVM Health Network CEO Dr. Stephen Leffler said that the cyber-attack was costing the network about $1.5m a day in lost revenue and recovery costs. 

The UVM Health Network completed the first phase of implementation of the Epic EHR system in November 2019, launching additional clinical and administrative capabilities for inpatient and outpatient settings that included clinical care, billing, registration, and scheduling.

Phases two and three were scheduled to take place in March 2021 and November 2021. However, the combined effects of the ransomware attack and the impact of the coronavirus outbreak have now pushed those dates back to November 2021 and April 2022, pending approval from the Green Mountain Care Board. 

“In 2020, our Network, like those across the world, experienced tremendous challenges due to the COVID-19 pandemic, only to be further encumbered by a ransomware attack,” John Brumsted, M.D., president and CEO of the UVM Health Network, said in a statement published Tuesday.  

“An electronic health record is one of the most significant things we can do to ensure high quality care and create a seamless experience for our patients. That is why it is absolutely critical to our patients, our people, and our communities that we get the implementation of this system right. 

“Given the obstacles we faced over the last year, modifying our timeline for installation of the EHR is the right thing to do.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk