Federal government launches dedicated COVID-19 resource app

The federal government has launched a dedicated COVID-19 app as a central resource for Canadians across the country for iPhone and Android.

The Government of Canada says the app provides Canadians with personalized, trusted, evidence-based information about the pandemic. It also includes the most up-to-date information, recommendations and resources.

If a person is concerned about their health, they can use the self-assessment tool that can help determine whether they may need further assessment or testing for COVID-19.

The homepage includes information about the importance of physical (social) distancing along with tips on how to properly wash your hands.

The app features information about the confirmed cases in Canada by province. At the time of writing, the app notes that 256,933 people have been tested in the country, and that there are 9,613 total cases and 109 deaths.

The stats tab in the app showcases several informative charts regarding the cumulative cases by date and new cases per day.

There is also a tab with updates that includes all of the press releases issued by the government about the latest news and measures being taken to curb the spread of the virus. The resource tab includes important information such as travel advisories, prevention methods and answers to common questions.

With the surge of misinformation on social media and other popular platforms, it’s a great step by the government to ensure that Canadians have access to credible and up-to-date information.

You can download the app from the iOS App Store or on Google Play.

Millions of users data leaked by browser extensions

From: Geekbots

Now, a research report reveals that some popular browser extensions are collecting and even selling users data including a list of visited sites and photos that users have looked at.

Most recently, security researchers found that a number of popular extensions were harvesting user data without consent. Not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data to a database. The exposed data also include vehicle identification, numbers of recently bought automobiles along with the names and addresses of the buyers.

Security researcher Sam Jadali discussed the presence of some data-harvesting extensions available on the Chrome and Firefox app stores. Once the extensions installed in the system, it started tracking your browsing and spending habits and also harvesting sensitive data to sell online.

The report said,

This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services” have been exposed.

Reports also showed that the affected extensions were used by millions of people, including HoverZoom, SpeakIt!, SuperZoom, SaveFrom.net Helper, Branded Surveys, Panel Community Surveys, FairShare Unlock, and PanelMeasurement.

Google and Firefox both said,

The extensions have been remotely removed or disabled in consumers’ browsers and are no longer available for download.

That’s why Google is trying to make Chrome extensions safer to use. Later this year, the company is rolling out a change that’ll restrict extensions from intercepting and modifying sensitive data flowing through the Chrome browser.

Mozilla is also aware of the changing security landscape and told that they have created a list of  “Recommended Extensions” that are editorially vetted, security-reviewed, and monitored for safety and privacy.

A Mozilla spokesperson said,

Mozilla has blocked all of the extensions that were found to be in violation of our policies. We looked into these extensions and found them to be in violation of our Distribution Agreement and Review Policies. As a result, they have been blocked from Firefox.

If you make use of extensions on Chrome or Firefox, you’ll want to make sure that your browser wasn’t affected by this catastrophic data breach.

New Security Warning Issued For Google’s 1.5 Billion Gmail And Calendar Users

Story by Davey Winder – Forbes

Google’s Gmail email service is used by upwards of 1.5 billion people. The Google Calendar app, meanwhile, has been downloaded more than a billion times from the Play Store. Security researchers have this week warned that threat actors are exploiting the popularity of both in order to target users with a credential-stealing attack.  Here’s what you need to know.

What does this attack involve?

Security researchers working at Kaspersky have revealed how threat actors are using the tight, and automatic, integration between different Google services in order to target users with malicious exploits.

In what the researchers refer to as a “sophisticated scam,” users of the Gmail service are being targeted primarily through the use of malicious and unsolicited Google Calendar notifications. Anyone can schedule a meeting with you, that’s how the calendar application is designed to work. Gmail, which receives the notification of the invitation, is equally designed to tightly integrate with the calendaring functionality.

When a calendar invitation is sent to a user, a pop-up notification appears on their smartphone. The threat actors craft their invitations to include a malicious link, leveraging the trust that user familiarity with calendar notifications brings with it.

The researchers have noticed attackers throughout the last month using this technique to effectively spam users with phishing links to credential stealing sites. By populating the location and topic fields to announce a fake online poll or questionnaire with a financial incentive to participate, the threat actors encourage the victim to follow the malicious link where bank account or credit card details can be collected. By exploiting such a “non-traditional attack vector,” the criminals can get around the fact that people are increasingly aware of common methods to encourage link-clicking.

Is this just a phishing thing then?

“Beyond phishing, this attack opens up the doors for a whole host of social engineering attacks,” says Javvad Malik, security awareness advocate at KnowBe4. Malik told me that in order to gain access to a building, for example, you could put in a calendar invite for an interview or similar face to face appointment such as building maintenance which, he warns “could allow physical access to secure areas.”

Hugo van den Toorn, manager of Offensive Security at Outpost24, agrees that the danger extends beyond the pure phishing realm. “This phishing attack specifically leveraged the intended functionality of a certain mobile application,” van den Toorn explains, “likely they could have also added attachments with malware targeting these users.”

How can you best mitigate the risk?

Kaspersky advises users to turn off the automatic adding of calendar invitations by going to the “Event Setting” menu in Google Calendar and disabling the “automatically add invitations” option by enabling the “only show invitations to which I’ve responded” one instead. Furthermore, it is advised that “Show declined events” in the View Options section is also left unchecked.

If turning off the automatic adding of events to your calendar is impractical, and it’s likely to be just that for many who rely on this type of scheduling, then Boris Cipot, a senior security engineer at Synopsys, has some general mitigation advice. “Question every email and in this case invitation you receive,” he says, “if it feels weird, wrong or unusual then ask the person who sent this invite if they really sent it.”

Obviously, there’s also the “do not click on any links or attachments” advice to be had. “Whenever in doubt it’s better to delete,” Cipot warns, but ultimately the Kaspersky advice should be followed he says. “Automation is not your friend in cases such as this, so do not let your calendar app put invitations automatically into your calendar,” Cipot concludes.

For full story, click here.

Need a Reason to Drop Google Chrome?

Google is planning to restrict modern ad blocking Chrome extensions to enterprise users only. This is despite a backlash to an announcement by Google in January proposing changes that will stop certain ad blockers from working efficiently.

The proposal–dubbed Manifest V3–will see a major transformation to Chrome extensions that includes a revamp of the permissions system. It will mean modern ad blockers such as uBlock Origin—which uses Chrome’s webRequest API to block ads before they’re downloaded–won’t work. This is because Manifest V3 sees Google halt the webRequest API’s ability to block a particular request before it’s loaded.

A single sentence buried in the text of Google’s response to the complaints, which clarified the changes: “Chrome is deprecating the blocking capabilities of the webRequest API in Manifest V3, not the entire webRequest API (though blocking will still be available to enterprise deployments).”

In other words, paid enterprise-only users will still have the ability to block unwanted content. It probably means enterprise customers can develop in-house Chrome extensions, not for ad blocking use. For everyone else, the changes announced in January will remain the same.

It’s annoying, to say the least, but the reason for these changes is obvious: Ads are at the heart of Google’s business model.

There are many users who won’t use Chrome without an ad blocker, so it will see some switch to other providers such as Firefox. However, Firefox has had its own issues over recent weeks.

So, now might be the time to switch to another browser, such as Brave. Brave is built upon Chromium so all existing Chrome plugins and even themes work on it and reduces your digital footprint, protecting your privacy.

Another option is using DNS level methods that blacklists adverts as well as malicious URLs.

Sun Sets on Google Plus

On February 1st, I received the official email from Google, that Google Plus will be turned off on April 2nd. I have been messing around with a couple of replacements, of sorts, and have been hanging out at the MeWe and Pluspora sites.

They have pretty much replace both Google+ and Facebook. MeWe has been my tech related replacement and Pluspora, for my photography. Below are my links and a short copy of the Google notice on Google+.

https://www.mewe.com/i/va3dbj
https://pluspora.com/people/c67b3320b1310136206800505608f9fe

In December 2018, we announced our decision to shut down Google+ for consumers in April 2019 due to low usage and challenges involved in maintaining a successful product that meets consumers’ expectations. We want to thank you for being part of Google+ and provide next steps, including how to download your photos and other content.

On April 2nd, your Google+ account and any Google+ pages you created will be shut down and we will begin deleting content from consumer Google+ accounts. Photos and videos from Google+ in your Album Archive and your Google+ pages will also be deleted. You can download and save your content, just make sure to do so before April. Note that photos and videos backed up in Google Photos will not be deleted.

The process of deleting content from consumer Google+ accounts, Google+ Pages, and Album Archive will take a few months, and content may remain through this time. For example, users may still see parts of their Google+ account via activity log and some consumer Google+ content may remain visible to G Suite users until consumer Google+ is deleted.

As early as February 4th, you will no longer be able to create new Google+ profiles, pages, communities or events.

See the full FAQ for more details and updates leading up to the shutdown.


Google to shut down Google+

The Guardian – Google to shut down Google+ after failing to disclose user data leak.

Company didn’t disclose leak for months to avoid a public relations headache and potential regulatory enforcement.

This March, as Facebook was coming under global scrutiny over the harvesting of personal data for Cambridge Analytica, Google discovered a skeleton in its own closet: a bug in the API for Google+ had been allowing third-party app developers to access the data not just of users who had granted permission, but of their friends.

If that sounds familiar, it’s because it’s almost exactly the scenario that got Mark Zuckerberg dragged in front of the US Congress. The parallel was not lost on Google, and the company chose not to disclose the data leak, the Wall Street Journal revealed Monday, in order to avoid the public relations headache and potential regulatory enforcement.

Disclosure will likely result “in us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal”, Google policy and legal officials wrote in a memo obtained by the Journal. It “almost guarantees Sundar will testify before Congress”, the memo said, referring to the company’s CEO, Sundar Pichai. The disclosure would also invite “immediate regulatory interest”.

Shortly after the story was published, Google announced that it will shut down consumer access to Google+ and improve privacy protections for third-party applications.

In a blog post about the shutdown, Google disclosed the data leak, which it said potentially affected up to 500,000 accounts. Up to 438 different third-party applications may have had access to private information due to the bug, but Google apparently has no way of knowing whether they did because it only maintains logs of API use for two weeks.

“We found no evidence that any developer was aware of this bug, or abusing the API, and we found no evidence that any profile data was misused,” Ben Smith, the vice-president of engineering, wrote in the blogpost.

Smith defended the decision not to disclose the leak, writing: “Whenever user data may have been affected, we go beyond our legal requirements and apply several criteria focused on our users in determining whether to provide notice.”

None of the thresholds for public disclosure were met, Smith said. 

There is no federal law that obliges Google to disclose data leaks, but there are laws at a state level. In California, where Google is headquartered, companies are only required to disclose a data leak if it includes both an individual’s name and their Social Security number, ID card or driver’s license number, license plate, medical information or health insurance information.

Google also announced a series of reforms to its privacy policies designed to give users more control on the amount of data they share with third-party app developers.

Users will now be able to have more “fine grained” control over the various aspects of their Google accounts that they grant to third-parties (ie calendar entries v Gmail), and Google will further limit third-parties’ access to email, SMS, contacts and phone logs.

David Carroll is a US professor who sued Cambridge Analytica earlier this year to find out what data the company had stored about him. He said that given the legal issues Facebook faces over its Cambridge Analytica cover-up, it’s not surprising Google tried to keep the leak out of the public eye.

“Google is right to be concerned and the shutdown of Google+ shows how disposable things really are in the face of accountability,” he said.

For others, the leak was further evidence that the large technology platforms need more regulatory oversight.

“Monopolistic internet platforms like Google and Facebook are probably ‘too big to secure’ and are certainly ‘too big to trust’ blindly,” said Jeff Hauser, from the Centre for Economic and Policy Research.

He argued that the US Federal Trade Commission should move toward “breaking these platforms up”.

“In the interim, since we cannot trust that we know much or even most of what ought to concern the public, the FTC should install public-minded privacy monitors into the firms as an element of accountability.”