What Do Social Media Companies Know About You?

What do social media companies really know about you? It’s a fair question. And the quick answer is this: the more you use social media, the more those companies likely know. 

The moment you examine the question more closely, the answer takes on greater depth. Consider how much we use social media for things other than connecting with friends. While that was the original intent behind social networks, the role of social media has since evolved into something far more expansive. We use it to get our news, stay up to date on when artists will drop a new release, and sometimes reach out for customer service on a company’s social media page. In some cases, we use our social media accounts to log into other sites and apps or we even make payments through social media 

Taken together, all of those likes, taps, clicks, links, and time spent reading or watching videos can add up and paint a detailed picture of who you are. 

Why are they collecting all this information? Largely, it’s for two reasons: 

1. To make improvements to their platform, by better understanding your behavior and ways you like to use their service. 

2. To create an exacting user profile that advertisers can use for targeting ads that they think will interest you. 

That’s the exchange in play here. You use the company’s social media service for free, and in return, they gain rights to gather specific information about you, which you consent to by agreeing to their terms of service. 

Let’s get into the details of what social media companies may collect and know about you—along with ways you can limit the data and information they gather. 

(Some of) the things social media companies may know about you 

Different social media platforms have different user agreements that cover what types of information they collect and use. For starters, we’ll speak broadly about social media companies in general, and then we’ll weave in a few specific examples along the way. Generally, they may know: 

  • Basic information about you and the devices you use: This includes personal information that people include in their profiles, such as names, birthdates, locations, relationships, and gender. This can extend to other identifiers like IP addresses, unique device ID numbers, connection type, connection speed, your network, other devices on your network. Also, device behavior can get tracked as well. That may include whether a window is open in the foreground or background and what mouse and finger taps you make while using the service.  
  • What interests you: People, pages, accounts, and hashtags that are associated with you and that you interact with in some way can get tracked. Likewise, how those people, pages, and accounts associate themselves with you in return get tracked as well. All of it builds up a profile with increasing levels of detail the more you engage with others and as they engage with you. 
  • What makes you stick around: Social media companies may measure the frequency and duration of your interactions. The more you interact, the more likely you are to have a strong connection to certain topics and opinions—and subsequently, social media companies may suggest similar content that they believe you will engage with just as strongly. For example, Facebook puts it this way on their privacy page (as of October 2021):  

We collect information about how you use our Products, such as the types of content you view or engage with; the features you use; the actions you take; the people or accounts you interact with; and the time, frequency and duration of your activities.   

  • Who you’re chatting with: Depending on the platform and its terms of use, information about direct messages you send using the platform may be collected as well. For example, Twitter does the following (as of October 2021):  

When you communicate with others by sending or receiving Direct Messages, we will store and process your communications and information related to them. This includes link scanning for malicious content, link shortening to http://t.co URLs, detection of spam, abuse and prohibited images, and use of reported issues. We also use information about whom you have communicated with and when (but not the content of those communications) to better understand the use of our services, to protect the safety and integrity of our platform, and to show more relevant content. 

If you use our Products for purchases or other financial transactions (such as when you make a purchase in a game or make a donation), we collect information about the purchase or transaction. This includes payment information, such as your credit or debit card number and other card information; other account and authentication information; and billing, shipping and contact details. 

  • Where you are and where you go: Simply disabling location sharing or GPS functionality on your device does not rule out other ways that social media companies can determine your whereabouts. They can infer your location to some extent when you log in by looking at your IP address and public Wi-Fi networks, along with nearby cellular towers if you’re on mobile.  

By the way, none of this is secret. What I’ve listed here can be found by simply reading the terms of use posted by various social media companies. Note that these terms of use can and do change. Checking up on them regularly will help you understand what is being collected and how it may be used. 

Of course, what you write and post says a lot about you too 

This nearly goes without saying, yet another layer of data and information collection comes by way of the pictures and updates you post. Per Instagram (as of October 2021):  

We collect the content, communications and other information you provide when you use our Products, including when you sign up for an account, create or share content, and message or communicate with others. This can include information in or about the content you provide (like metadata), such as the location of a photo or the date a file was created. 

Another consideration is how the content you interact with on other sites may be shared with social media companies in return. Some social media companies partner with other third parties to gather this data, which is used to round out your user profile in yet more detail. That information can include purchases you made, how often you visited that third party’s site, and so on. 

In the case of Facebook, they refer to this as “Off-Facebook Activity.” In their words:  

Off-Facebook activity includes information that businesses and organizations share with us about your interactions with them. Interactions are things like visiting their website or logging into their app with Facebook. Off-Facebook activity does not include customer lists that businesses use to show a unique group of customers relevant ads.  

The good news here is that you can take control of the Off-Facebook Activity setting with a few clicks. 

No doubt about it, the content you create and interact with, both on the social media sites and sometimes off of them as well, can generate information about you that’s collected by social media companies. 

Limiting what social media companies know about you 

Short of deleting your accounts altogether, there are several things you can do to take control and limit the amount of information you share. 

1. You can access, update, correct, move, and erase your data, depending on the platform. 

For example, you can visit your Facebook SettingsInstagram Settings, and Twitter Settings, which each gives you options for managing your information—or download it and even delete it from their platform outright if you wish. (Note that this will likely only delete data associated with your account. Content you posted or shared with other people on their accounts will remain.) 

2. Disable location sharing. 

As noted above, this isn’t an absolute fix because social media companies can infer your location other ways. Yet taking this step gives them one less piece of exacting information about you. 

3. Review your privacy and account settings. 

Each platform will have its own settings and options, so give them a look. Here, you can determine which information advertisers are allowed to use to serve up ads to you, set rules for facial recognition, enable or disable location history, and much more. If possible, do this from your computer or laptop rather than your smartphone. Often, the account controls that you can access from a computer browser are far more comprehensive than the ones in a mobile app. 

4. Consider using other messaging platforms. 

Using direct messaging on social media platforms may tell social media companies even more about you and who you interact with. When possible, think about using text messaging instead or other means of communication that aren’t tied to a social media company. 

5. Decouple your social media account from other apps and sites. 

Some apps and sites will allow you to use your social media login instead of creating a new one. While convenient, this can provide the social media company with more information about you. Additionally, if your social media account is compromised, it could compromise the other accounts that are tied to it as well. Check your settings and look for “Apps and Websites” to see what’s connected to your social media account, what’s being shared, and how you can disable it. 

6. Use online protection software. 

Protection like ours will include a VPN, which anonymizes your online activity and thus may shield you from certain types of information collection, such as your location. Additionally, using online protection software is simply a good move because it can create and store strong, unique passwords for you, steer you clear of risky sites, protect your identity, and make your time online safer overall. 

Know what you’re sharing  

The very nature of social media is sharing and exchanging. That’s the draw it has—the way it keeps us connected to the people, pastimes, and things we care about. Yet that exchange runs deeper. In return for using these free services, social media companies collect information on us which they use to improve their platforms and generate revenue. It’s all there for you to see in the various terms of use associated with your social media accounts. In short, using social media means sharing information about yourself with social media companies. 

Yet you can do several things to reduce the amount of information that social media companies know about you. By spending some time on the account and privacy settings for each of your social media accounts, you can determine what information you’re providing to them and get a much better sense of what social media companies know about you.  

The post What Do Social Media Companies Know About You? appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Zales.com Leaked Customer Data, Just Like Sister Firms Jared, Kay Jewelers Did in 2018

In December 2018, bling vendor Signet Jewelers fixed a weakness in their Kay Jewelers and Jared websites that exposed the order information for all of their online customers. This week, Signet subsidiary Zales.com updated its website to remediate a nearly identical customer data exposure.

Last week, KrebsOnSecurity heard from a reader who was browsing Zales.com and suddenly found they were looking at someone else’s order information on the website, including their name, billing address, shipping address, phone number, email address, items and total amount purchased, delivery date, tracking link, and the last four digits of the customer’s credit card number.

The reader noticed that the link for the order information she’d stumbled on included a lengthy numeric combination that — when altered — would produce yet another customer’s order information.

When the reader failed to get an immediate response from Signet, KrebsOnSecurity contacted the company. In a written response, Signet said, “A concern was brought to our attention by an IT professional. We addressed it swiftly, and upon review we found no misuse or negative impact to any systems or customer data.”

Their statement continues:

“As a business principle we make consumer information protection the highest priority, and proactively initiate independent and industry-leading security testing. As a result, we exceed industry benchmarks on data protection maturity. We always appreciate it when consumers reach out to us with feedback, and have committed to further our efforts on data protection maturity.”

When Signet fixed similar weaknesses with its Jared and Kay websites back in 2018, the reader who found and reported that data exposure said his mind quickly turned to the various ways crooks might exploit access to customer order information.

“My first thought was they could track a package of jewelry to someone’s door and swipe it off their doorstep,” said Brandon Sheehy, a Dallas-based Web developer. “My second thought was that someone could call Jared’s customers and pretend to be Jared, reading the last four digits of the customer’s card and saying there’d been a problem with the order, and if they could get a different card for the customer they could run it right away and get the order out quickly. That would be a pretty convincing scam. Or just targeted phishing attacks.”

In the grand scheme of many other, far more horrible things going on in information security right now, this Zales customer data exposure is small potatoes. And this type of data exposure is unbelievably common today: KrebsOnSecurity could probably run one story each day for several months just based on examples I’ve seen at dozens of other places online.

But I do think one key reason we continue to see companies make these easily avoidable mistakes with their customer data is that there are hardly ever any real consequences for organizations that fail to take more care. Meanwhile, their customers’ data is free to be hoovered up by anyone or anything that cares to look for it.

“Being a Web developer, the only thing I can chalk this up to is complete incompetence, and being very lazy and indifferent to your customers’ data,” Sheehy said. “This isn’t novel stuff, it’s basic Web site security.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft to Tap Community Colleges’ Cyber Talent

Microsoft to Tap Community Colleges’ Cyber Talent

Microsoft has announced plans to fill 250,000 cybersecurity roles by working with community colleges across the United States.

As part of the recruitment drive, the American multinational technology corporation said today that it intends to invest millions of dollars in education and teacher training over the next three years.

As of January 2021, there were 936 public community colleges and 73 independent community colleges registered with the American Association of Community Colleges (AACC) in the United States.

Microsoft stated that it will provide training for current and new teachers at 150 community colleges across the nation. The corporation also announced plans to provide scholarships or financial assistance to 25,000 community college students.

To assist educational establishments in stretching their budgets as far as possible, the tech company said it will make curriculum materials freely available to all community colleges and four-year schools in the United States.

Speaking about the funding and recruitment pledge at a press briefing, Microsoft president Brad Smith hinted at more help to come for colleges.

“Over the next three years, we’ll put many tens of millions of dollars behind this effort,” said Smith.

He added: “This is an opportunity for us to get started. This is not the ceiling on what we’ll do.”

A recent report by the Information Systems Security Association (ISSA) and analyst Enterprise Strategy Group (ESG), The Life and Times of Cybersecurity Professionals 2021, showed that the cybersecurity skills gap, identified more than a decade ago, has persisted, and impacts over half (57%) of organizations. 

“The data gathered for this project confirms that there has been no significant progress toward a solution to this problem during the five years it has been closely researched,” said ESG senior principal analyst Jon Oltsik.

The report was based on a global survey of 489 cybersecurity employees at the start of 2021.

“The top ramifications of the skills shortage include an increasing workload (62%), unfilled open job requisitions (38%), and high burnout among staff (38%),” said Oltsik.

“Further, 95% of respondents state the cybersecurity skills shortage and its associated impacts have not improved over the past few years, while 44% say it has only gotten worse.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Shadow IT Alert: Half of Home Workers Buy Potentially Insecure Kit

Shadow IT Alert: Half of Home Workers Buy Potentially Insecure Kit

Incidents of shadow IT have snowballed during the pandemic as remote workers bought devices without vetting from the IT department, a new report from HP has warned.

The tech giant’s Out of Sight and Out of Mind report is based on a global survey of 1100 IT decision-makers and a separate poll of more than 8400 home workers in the US, the UK, Mexico, Germany, Australia, Canada, and Japan.

Nearly half (45%) said they’d bought IT equipment such as printers or PCs to support home working over the past year.

However, 68% said security wasn’t as big a consideration as other factors like price or functionality when purchasing. Even worse, 43% didn’t have their new laptop or PC checked or installed by IT, and 50% said the same of their new printer.

IT is also being bypassed when it comes to reporting incidents, the study found. Even though three-quarters (74%) of IT teams claimed to have seen a rise in the number of employees opening malicious phishing links or attachments in the past year, most (70%) home workers who clicked said they didn’t report it.

That will hurt IT’s attempts to understand the level of risk the business faces and where it needs to tweak policy or direct security resources.

The combined impact of these shadow IT challenges is already pronounced: 79% of IT leaders reported that rebuild rates for machines increased during the pandemic. This indicates PCs and laptops have been compromised by malware.

It’s also having an impact on IT teams themselves. Two-thirds of IT leaders said that patching endpoint devices is more time-consuming and challenging than pre-pandemic. As a result, they estimated the cost of IT support concerning security has risen by 52% in the past 12 months.

Some 83% claimed home worker security problems had put more strain on the IT team, and over three-quarters (77%) are worried staff will burnout as a result.

“As IT continues to grow in complexity, security support is becoming unmanageable. For hybrid working to be a success, IT security teams need to be freed from spending hours provisioning and fielding user access requests so they can focus on tasks that add value,” argued HP’s global head of security for personal systems, Ian Pratt.

“We need a new security architecture that not only protects against known and unknown threats, but that helps to reduce the burden to liberate cybersecurity teams and users alike. By applying the principles of zero trust, organizations can design resilient defenses to keep the business safe and recover quickly in the event of a compromise.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ransomware Soars 148% to Record-Breaking Levels in 2021

Ransomware Soars 148% to Record-Breaking Levels in 2021

The volume of ransomware attacks over the first three quarters of 2021 reached 470 million, a 148% increase on the same period last year, making 2021 already the worst year on record, according to SonicWall.

The security vendor scrutinized attempts to compromise its global customers over the period and found that each company recorded 1,748 ransomware attacks in the year-to-date (YTD). That’s reportedly nearly 10 per business day.

Q3 2021 saw the most significant volume of ransomware attacks recorded by the vendor – at 190.4 million. It nearly tops the 195.7 million attempts logged in the first three quarters of 2020.

SonicWall predicted that by the end of 2021, the ransomware total would be near 714 million, which would be a 134% year-on-year increase. 

SonicWall CEO, Bill Conner, warned that criminal gangs would continue to launch sophisticated attacks designed to compromise targets with gaps in their defenses.

“As we see it, ransomware is on a nearly unimaginable upward trend, which poses a major risk to businesses, service providers, governments and everyday citizens,” he added.

“The real-world damage caused by these attacks is beyond anecdotal at this point. It’s a serious national and global problem that has already taken a toll on businesses and governments everywhere. I’m hopeful that the recent global ransomware summit is the next step toward a greater response at global, national and state levels.”

China and Russia were notably excluded from that international meeting at the White House earlier this month. The Biden administration has repeatedly blamed the latter for harboring ransomware gangs, as long as they target attacks on foreign organizations.

SonciWall also recorded 3.9 trillion intrusion attempts in YTD, as well as a 33% rise in IoT malware globally and a 21% increase in cryptojacking, which spiked by 461% year-on-year in Europe.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Small Businesses Pay Up to $1M to Recover from Breaches

Small Businesses Pay Up to $1M to Recover from Breaches

Over half (58%) of US small businesses have suffered a security or data breach, with most paying hundreds of thousands of dollars to cover the costs, according to a new study from the Identity Theft Resource Center (ITRC).

According to the US Small Business Administration, there are nearly 32 million businesses with fewer than 500 employees. To find out more about how they’re impacted by cyber-attacks, the ITRC polled 417 small business owners.

The non-profit’s 2021 Business Aftermath Report revealed that many suffer a serious business impact from breaches.

Of those hit by a breach, three-quarters experienced at least two, and a third said they had suffered at least three incidents.

Over two-fifths (44%) spent $250,000-$500,000 to cover the costs of the breach, while 16% said they were forced to fork out between $500,000-$1m. 

Unsurprisingly, over a third (36%) admitted that this outlay put their business into debt, while a similar number (34%) said they had to dip into cash reserves to bail themselves out. A further 15% were forced to reduce headcount as a result.

The majority of respondents said it took them several years to recover from a breach.

“Behind all of these statistics are people. The resources stolen by cyber-criminals are the same resources needed to sustain or grow a business to keep families safe, healthy and financially secure,” said ITRC president and CEO, Eva Velasquez.

“These identity crimes are not just costing small businesses and solopreneurs a lot of money. It is also taking them a long time to put their business back on a path to growth.”

Two-fifths (42%) of respondents claimed it took 1-2 years to get back to normal after a breach, while for over a quarter (28%), the road to recovery lasted 3-5 years.

Interestingly, while 40% of attacks were traced to external threat actors, over a third (35%) were caused by malicious employees and contractors, the report found.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains