Schibsted innfører betaling for personvern – NRK

https://www.nrk.no/rogaland/kritisk-til-schibsteds-nye-_betal-eller-samtykk_-modell-1.17866076

No krev Schibsted betaling for at du skal sleppe at dataene dine blir brukte til målretta reklame. Datatilsynet fryktar at personvern er i ferd med å bli ei luksusvare.

– Personvern er ein menneskerett som ein ikkje skal betale for, seier direktør i Datatilsynet, Line Coll.

– Personvernforordninga krev at verksemder innhentar samtykke som skal givast frivillig. Datatilsynet set spørsmålsteikn ved om samtykket er reelt sett frivillig dersom alternativet er å betale, held ho fram.

Ho fryktar kva som skjer dersom alle nettstader og appar følgjer etter, og peiker særleg på kva dette har å seie for sårbare grupper.

– Datatilsynet er bekymra for at personvern på internett skal bli reservert for dei rike. Personvernet til andre grupper kan også bli pressa av denne typen løysingar, til dømes barn og unge, eller andre sårbare gruppe som ikkje har høve til å betale eller finne personvernvennlege alternativ, seier Coll.

– Etter vårt syn er denne typen løysingar i strid med krava i personopplysningslova. Dette er også bakgrunnen for at vi tidlegare har klaga inn Metas «Pay or OK»-løysing. Saka ligg framleis til behandling hos det irske datatilsynet, seier Myrstad i Forbrukarrådet.

Sikkerhetshull avslørte Telia-kunders posisjon – NRK

https://www.nrk.no/norge/sikkerhetshull-avslorte-telia-kunders-posisjon-1.17842282

Mobilkunder hos Telia har siden 2023 vært sporbare via mobilen, inkludert sentrale politikere på Stortinget.

NRK har siden testet og innhentet mer dokumentasjon om hvem som er påvirket av feilen.

Undersøkelsene viser at:

  • Privatkunder og bedriftskunder med Telia-abonnement kunne spores, så fremt en av telefonene var tilknyttet bedriftsnettet.
  • Også bedriftskunder med Phonero, en merkevare av Telia, kunne spores.
  • Mobiltelefoner kunne spores selv når de var i utlandet.
  • Den oppringte trengte normalt ikke å ta telefonen for å bli sporet.

Å utnytte feilen involverte ikke noen form for datainnbrudd eller «hacking». Det holdt å lese av informasjon som ble sendt til mobiltelefonen ved et anrop.

Det krever en viss teknisk innsikt å utnytte feilen, men ingen spesialverktøy.

Det avslørte hvilke basestasjoner den oppringte var tilkoblet. I bynære strøk kan man med denne informasjonen anslå en mobilbrukers posisjon til mellom 100 og 200 meters nøyaktighet.

– Det som undersøkelsene viser nå, er at feilen oppsto ved en konfigurasjonsendring vi gjorde i 2023

Swedish PM’s private address revealed by Strava data shared by bodyguards | The Guardian

https://www.theguardian.com/world/2025/jul/08/swedish-pm-safety-strava-data-bodyguards-ulf-kristersson-running-cycling-routes

Data made public by Ulf Kristersson’s security revealed his location, routes and movements over several years

In 2023 a former Russian submarine commander was killed reportedly with the help of his open Strava profile and last year it was revealed bodyguards to several world leaders were sharing confidential information on the app.

In 2017, Strava was accused of giving away the location and staffing of military bases and spy outposts around the world by publishing a map that showed all of its users’ activity.

Apple pulls data protection tool after UK government security row

https://www.bbc.com/news/articles/cgj54eq4vejo

Apple is taking the unprecedented step of removing its highest level data security tool from customers in the UK, after the government demanded access to user data.

Advanced Data Protection (ADP) means only account holders can view items such as photos or documents they have stored online through a process known as end-to-end encryption.

But earlier this month the UK government asked for the right to see the data, which currently not even Apple can access.

Apple did not comment at the time but has consistently opposed creating a “backdoor” in its encryption service, arguing that if it did so, it would only be a matter of time before bad actors also found a way in.

Now the tech giant has decided it will no longer be possible to activate ADP in the UK.

It means eventually not all UK customer data stored on iCloud - Apple’s cloud storage service - will be fully encrypted.

Data with standard encryption is accessible by Apple and shareable with law enforcement, if they have a warrant.

Benedict Evans:

Of course, the UK is within its rights to choose one side of the trade-off in the UK - what’s bizarre here is that the UK is apparently demanding that Apple do this globally. The UK, apparently, is trying to tell a US company what products it can provide to customers in Japan, Australia or indeed the USA. Normally it’s only American regulators that assert global juristiction. But what will the UK government say when China reads this story, and orders Apple to hand over UK citizens’ data, given that it’s now unencrypted and the UK has conceded the principle of jurisdiction? [emphasis added]

Nordmenn overvåkes av mobilen: – Pill råttent system – NRK

https://www.nrk.no/norge/nordmenn-overvakes-av-mobilen_-_-pill-rattent-system-1.17208691

Norsk-amerikanske Unacast har blitt utsatt for omfattende datainnbrudd. Nå går Forbrukerrådet i strupen på selskapet.

– Det er fullstendig uansvarlig, sier fagdirektør Finn Myrstad i Forbrukerrådet.

Han snakker om selskaper som lever av å samle inn informasjon om hvor folk har vært, for å bruke det til markedsføring.

Store mengder private data om mobilbrukere over hele verden ble lagt ut på et russisk nettforum. Dataene som hackerne skal ha stjålet, skal være alt fra kundelister til folks lokasjonsdata. De publiserte det de kalte en «smakebit» av informasjonen de stjal.

I disse dataene kan det ligge informasjon om 146.000 nordmenns fysiske plassering.

Det er en trussel i seg selv at kommersielle selskaper sitter på så mye data om mobilbrukere, mener Forbrukerrådet.

– Det er en gigantisk svakhet. Det burde ikke vært lov å samle dem inn.

Forbrukerrådet har bedt om et forbud mot markedsføringen basert på dataene.

– Jeg tenker det ligger noe ansvar på politikerne her, sier Myrstad.

I 2022 anbefalte Personvernkommisjonen i en rapport en utredning av et generelt forbud mot atferdsbasert markedsføring.

Stortinget har bedt om det samme. Men ennå har det ikke dukket opp noen utredning. Langt mindre et lovforslag.

Subaru Security Flaws Exposed Its System for Tracking Millions of Cars | WIRED

https://www.wired.com/story/subaru-location-tracking-vulnerabilities/

Now-fixed web bugs allowed hackers to remotely unlock and start any of millions of Subarus. More disturbingly, they could also access at least a year of cars’ location histories—and Subaru employees still can.

Most disturbing for Curry, though, was that they found they could also track the Subaru’s location—not merely where it was at the moment but also where it had been for the entire year that his mother had owned it. The map of the car’s whereabouts was so accurate and detailed, Curry says, that he was able to see her doctor visits, the homes of the friends she visited, even which exact parking space his mother parked in every time she went to church.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry says. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

Curry argues that Subaru’s extensive location tracking is a particularly disturbing demonstration of the car industry’s lack of privacy safeguards around its growing collection of personal data on drivers. “It’s kind of bonkers,” he says. “There’s an expectation that a Google employee isn’t going to be able to just go through your emails in Gmail, but there’s literally a button on Subaru’s admin panel that lets an employee view location history.”

Biggest Privacy Erosion in 10 Years? On Google’s Policy Change Towards Fingerprinting

https://blog.lukaszolejnik.com/biggest-privacy-erosion-in-10-years-on-googles-policy-change-towards-fingerprinting/

Volkswagen leak exposed location data for 800,000 electric cars - The Verge

https://www.theverge.com/2024/12/30/24332181/volkswagen-data-leak-exposed-location-evs

The leak also included the emails, addresses, and phone numbers of drivers in some cases, Der Spiegel reports.

If anything, this leak serves as yet another reminder of the immense amount of data collected by modern-day vehicles, which Mozilla has called a “privacy nightmare.”

U.S. officials urge Americans to use encrypted apps amid cyberattack

https://www.nbcnews.com/tech/security/us-officials-urge-americans-use-encrypted-apps-cyberattack-rcna182694

Amid an unprecedented cyberattack on telecommunications companies such as AT&T and Verizon, U.S. officials have recommended that Americans use encrypted messaging apps to ensure their communications stay hidden from foreign hackers.

The hacking campaign, nicknamed Salt Typhoon by Microsoft, is one of the largest intelligence compromises in U.S. history, and it has not yet been fully remediated. Officials on a news call Tuesday refused to set a timetable for declaring the country’s telecommunications systems free of interlopers. Officials had told NBC News that China hacked AT&T, Verizon and Lumen Technologies to spy on customers.

Anyone Can Buy Data Tracking US Soldiers and Spies to Nuclear Vaults and Brothels in Germany - Wired

https://www.wired.com/story/phone-data-us-soldiers-spies-nuclear-germany/

More than 3 billion phone coordinates collected by a US data broker expose the detailed movements of US military and intelligence workers in Germany—and the Pentagon is powerless to stop it.

Insecure Deebot Robot Vacuums Collect Photos and Audio to Train Ai

https://www.abc.net.au/news/2024-10-05/robot-vacuum-deebot-ecovacs-photos-ai/104416632

Ecovacs robot vacuums, which have been found to suffer from critical cybersecurity flaws, are collecting photos, videos and voice recordings – taken inside customers’ houses – to train the company’s AI models.

Ford Seeks Patent for Tech That Listens to Driver Conversations to Serve Ads

https://therecord.media/ford-patent-application-in-vehicle-listening-advertising

Ford Motor Company is seeking a patent for technology that would allow it to tailor in-car advertising by listening to conversations among vehicle occupants, as well as by analyzing a car’s historical location and other data, according to a patent application published late last month.

Ford quietly walked away from another controversial patent application last October after a firestorm of criticism for its plans for a system that would commandeer vehicles whose owners were late to pay and allow them to repossess themselves.

Your TV set has become a digital billboard. And it’s only getting worse. | Ars Technica

https://arstechnica.com/gadgets/2024/08/tv-industrys-ads-tracking-obsession-is-turning-your-living-room-into-a-store/

The TV business isn’t just about selling TVs anymore. Companies are increasingly seeing viewers, not TV sets, as their most lucrative asset.

Over the past few years, TV makers have seen rising financial success from TV operating systems that can show viewers ads and analyze their responses. Rather than selling as many TVs as possible, brands like LG, Samsung, Roku, and Vizio are increasingly, if not primarily, seeking recurring revenue from already-sold TVs via ad sales and tracking.

How did we get here? And what implications does an ad- and data-obsessed industry have for the future of TVs and the people watching them?

Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies - The New York Times

https://www.nytimes.com/2024/03/11/technology/carmakers-driver-tracking-insurance.html

LexisNexis, which generates consumer risk profiles for the insurers, knew about every trip G.M. drivers had taken in their cars, including when they sped, braked too hard or accelerated rapidly.

Apple AirDrop leaks user data like a sieve. Chinese authorities say they’re scooping it up. | Ars Technica

https://arstechnica.com/security/2024/01/hackers-can-id-unique-apple-airdrop-users-chinese-authorities-claim-to-do-just-that/

Chinese authorities recently said they’re using an advanced encryption attack to de-anonymize users of AirDrop in an effort to crack down on citizens who use the Apple file-sharing feature to mass-distribute content that’s outlawed in that country.

23andMe confirms hackers stole ancestry data on 6.9 million users | TechCrunch

https://techcrunch.com/2023/12/04/23andme-confirms-hackers-stole-ancestry-data-on-6-9-million-users/

On Friday, genetic testing company 23andMe announced that hackers accessed the personal data of 0.1% of customers, or about 14,000 individuals. The company also said that by accessing those accounts, hackers were also able to access “a significant number of files containing profile information about other users’ ancestry.” But 23andMe would not say how many “other users” were impacted by the breach that the company initially disclosed in early October.

As it turns out, there were a lot of “other users” who were victims of this data breach: 6.9 million affected individuals in total.

In an email sent to TechCrunch late on Saturday, 23andMe spokesperson Katie Watson confirmed that hackers accessed the personal information of about 5.5 million people who opted-in to 23andMe’s DNA Relatives feature, which allows customers to automatically share some of their data with others. The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports and self-reported location.

Forbud mot Meta om bruk av persondata utvides til hele EØS

https://nrkbeta.no/2023/10/31/forbud-mot-meta-om-bruk-av-persondata-utvides-til-hele-eos/

Datatilsynet vant frem hos Personvernrådet i EU. Tilsynets forbud utvides til flere land.
– Dette er en historisk dag for personvernet, skriver direktør i Datatilsynet Line Coll i en uttalelse til NRK.

Datatilsynet beordret i sommer Meta å stanse bruken av nordmenns persondata til adferdsbasert reklame.

Teknologikjempen, som eier Facebook og Instagram, har siden august fått én million i daglige bøter for å ikke følge vedtaket.
Siden har tilsynet bedt Personvernrådet i EU (EDPB) om en bindende hastebeslutning. Denne beslutningen gjør tilsynets vedtak permanent og gjeldende for hele EØS-området. Tidligere gjaldt vedtaket kun for Norge og kun for en midlertidig periode.

Nå kan du reservere deg mot dørsalg – Forbrukerrådet

https://www.forbrukerradet.no/siste-nytt/na-kan-du-reservere-deg-mot-dorsalg/

Forbrukere kan nå reservere seg mot dørsalg. Det er også innført forbud mot dørsalg på kvelden, i helger og på helligdager.

Forbrukerrådet anbefaler som hovedregel ingen å kjøpe noe på døra. Nå er det også kommet regler som begrenser denne type salg, og som gjør det mulig å reservere seg mot innpåslitne selgere.

Med det nye regelverket er det eneste du trenger å gjøre er å henge en lapp eller et skilt som sier «Nei takk til dørsalg» eller tilsvarende.

Genetics firm 23andMe says user data stolen in credential stuffing attack – BleepingComputer

https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/

The initial data leak was limited, with the threat actor releasing 1 million lines of data for Ashkenazi people. However, on October 4, the threat actor offered to sell data profiles in bulk for $1-$10 per 23andMe account, depending on how many were purchased.

A 23andMe spokesperson confirmed the data is legitimate and told BleepingComputer that the threat actors used exposed credentials from other breaches to access 23andMe accounts and steal the sensitive data.

https://arstechnica.com/security/2023/10/private-23andme-user-data-is-up-for-sale-after-online-scraping-spree/

The information that has been exposed from this incident includes full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location.

While there are benefits to storing genetic information online so people can trace their heritage and track down relatives, there are clear privacy threats. Even if a user chooses a strong password and uses two-factor authentication as 23andMe has long urged, their data can still be swept up in scraping incidents like the one recently confirmed. The only sure way to protect it from online theft is to not store it there in the first place.

Cars Are the Worst Product Category We Have Ever Reviewed for Privacy | Mozilla Foundation

https://foundation.mozilla.org/en/privacynotincluded/articles/its-official-cars-are-the-worst-product-category-we-have-ever-reviewed-for-privacy/

All 25 car brands we researched earned our *Privacy Not Included warning label — making cars the official worst category of products for privacy that we have ever reviewed.

We reviewed 25 car brands in our research and we handed out 25 “dings” for how those companies collect and use data and personal information. That’s right: every car brand we looked at collects more personal data than necessary and uses that information for a reason other than to operate your vehicle and manage their relationship with you.

It’s bad enough for the behemoth corporations that own the car brands to have all that personal information in their possession, to use for their own research, marketing, or the ultra-vague “business purposes.” But then, most (84%) of the car brands we researched say they can share your personal data — with service providers, data brokers, and other businesses we know little or nothing about. Worse, nineteen (76%) say they can sell your personal data.