Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

DuckDuckGo says Hell, Hell, No to those Microsoft trackers after web revolt
The Register ^ | Sat 6 Aug 2022 | Brandon Vigliarolo

Posted on 08/06/2022 10:44:34 PM PDT by nickcarraway

IN BRIEF DuckDuckGo has finally mostly cracked down on the third-party Microsoft tracking scripts that got the alternative search engine into hot water earlier this year.

In May, DDG admitted its supposedly pro-privacy mobile browser wasn't blocking certain Microsoft trackers, while actively blocking other types of third-party trackers by Microsoft and other organizations, confirming findings by data-usage researcher Zach Edwards.

This special exception for the Windows giant was due to "contractual commitments with Microsoft," DuckDuckGo CEO Gabriel Weinberg said at the time.

This caused a storm among netizens, and provoked some sharp criticism from the competition. Now, late on Friday this week, DDG said the full blocks would be added against Redmond.

"Previously, we were limited in how we could apply our 3rd-Party Tracker Loading Protection on Microsoft tracking scripts due to a policy requirement related to our use of Bing as a source for our private search results," it quietly quacked.

"We're glad this is no longer the case. We have not had, and do not have, any similar limitation with any other company."

That said, Microsoft scripts from bat.bing.com, used to measure the effectiveness of web adverts, will not be blocked by DDG's mobile browser if fetched by an advertiser's website following a DuckDuckGo ad click. Ie, if you tap on an advert on a DDG search results page, get taken to the advertiser's website, and the advertiser pulls a script from bat.bing.com to detect and record whether anything you subsequently ordered was a result of that advert, the browser won't block that script.

"For anyone who wants to avoid this, it's possible to disable ads in DuckDuckGo search settings," the biz said, adding that it is working on removing support for bat.bing.com with alternative non-profiling ad conversion tracking.

While this may placate some users, a lot of goodwill no doubt has been lost.

Twitter confirms data stolen via privacy blunder Back in January, Twitter fixed a privacy flaw that made it easy to unmask users. This week, the biz confirmed that the Twitter user data that went on sale earlier this year was indeed taken via that specific security hole.

Exploiting the bug was pretty easy: it was possible to send an email address or phone number to one part of Twitter's systems, and have it tell you which Twitter account was associated with that contact information, if any, even if they had chosen not to disclose those details in their privacy settings. Thus, for instance, if you suspected someone had a pseudonymous Twitter profile, you could give their contact info to Twitter, and the site would confirm their handle. Or you could just feed the site a load of details and have it map them to accounts.

This would be useful for nation states and other organizations that are keen to know who is behind particular Twitter accounts.

"If someone submitted an email address or phone number to Twitter's systems, Twitter's systems would tell the person what Twitter account the submitted email addresses or phone number was associated with, if any," the micro-blogging biz said Friday. "This bug resulted from an update to our code in June 2021," it added.

The flaw was addressed soon after it was disclosed via Twitter's bug bounty program in January, we're told. It was then reported in July that someone had seemingly exploited the privacy hole prior to its patching and was selling information obtained from Twitter's servers.

Though Twitter has now acknowledged that this info was stolen via the bug before it was fixed, it's understood that 5.4 million Twitter users had their details harvested and put up tor sale.

A window into the world of Pegasus An investigation into spyware used by the government of Israel has discovered that Israeli cops had their own version of NSO's Pegasus snoopware dubbed Seifan as early as 2016. We've also been treated to a view of the software control panel for the espionage tool, revealing its real-time surveillance capabilities and other functions.

Deputy Israeli Attorney General Amit Merari, leader of an investigative committee looking into police use of spyware, published a report Monday detailing the committee's findings, Israeli news site Haaretz reported.

Seifan, according to Merari's investigation, may have been pitched to the Israeli government as early as 2014 in a form that analysts described to Haaretz as a beta form of the now-notorious spyware. The investigation showed that Israeli Police used the technology in a manner "beyond its legal authority," and that the group responsible for its operation is still in possession of illegally gathered data.

Among the capabilities of the Seifan Pegasus variant are all the usual table stakes: data exfiltration, call interception, and the like. Also included in the police version of Pegasus was "volume listening" that allowed police to snoop on an infected device's microphone in real time, and remote operation of a handset's cameras.

Haaretz said the latter tool is likely illegal, as Israeli law "does not explicitly permit the planting of concealed cameras, and certainly does not permit the remote control of a camera by hacking a suspect's mobile device."

Pegasus isn't restricted to Israel, either: NSO, the Israeli company that developed the spyware, has tried to downplay fears by saying it has sold Pegasus to fewer than 50 customers, at least five of which were EU member states, though. According to reports, Pegasus has been used to spy on political dissidents, journalists, and other government targets, including murdered Washington Post journalist Jamal Khashoggi.

The Merari investigation found that, while Israeli Police were using spyware, no eavesdropping took place outside of court-ordered situations.

"Police use of [Seifan] was solely for the purpose of preventing and solving serious crimes, and subject to court warrants, and that no intentional actions were taken in contravention of the law," the Israeli Police said in a statement to Haaretz.

Critical flaws in Cisco email hardware: Patch now Vulnerabilities in Cisco's AsyncOS for physical and virtual email appliances have been patched, and anyone with an affected system is advised to update now.

Cisco notified customers of the security holes in June, and lately updated the notice to point to AsyncOS patches for the flaws, which could allow a remote attacker to bypass authentication and log into the web administration console for an affected device.

Caused by improper authentication checks when using LDAP for external authentication, the vulnerability has a CVSS score of 9.8. It affects all Cisco Email Security Appliances and Cisco Secure Email and Web Managers running vulnerable versions of AsyncOS that are configured for external authentication and use LDAP as a protocol.

Cisco noted that external authentication is disabled by default, but warns users of its email appliances to double-check the settings to ensure they're not leaving equipment exposed.

Secure Email and Web Manager appliances running AsyncOS versions 13, 13.6, 13.8, 14, and 14.1 can find updates, and those using Email Security Appliances will find updates available for AsyncOS versions 13 and 14. Links to the updated version can be found in the Cisco security advisory linked above.

AsyncOS release 11 is out of support, Cisco said, and those using this version or older should migrate to a fixed release. Release 12 doesn't appear to be getting updates against exploitation, either.

For those who can't update to a newer version of AsyncOS, Cisco said a workaround is available by disabling anonymous binds on the external authentication server. Cisco said it hasn't discovered any malicious use of the vulnerabilities in the field.

Cybercriminals book Uber to hurry up scams Scammers may now be offering to send Ubers to victims' homes to ferry them to banks to withdraw large sums from their accounts.

That's the story from Towson, Maryland, USA, where an 80-year-old woman targeted by fraudsters was offered a courtesy ride to the bank to fix an "accidental" $160,000 bank withdrawal, as reported by infosec blogger Brian Krebs.

The scammers used a familiar tactic that, in this instance, happened to work out well: they posed as Best Buy employees collecting payment for an appliance installation; the victim had coincidentally just had a dishwasher fitted for her not long prior. The scammers said the victim owed $160.

After persuading her to install and run remote-control software on her computer, the scammers had her log into her bank account so they could sort out the payment, and then said they "accidentally" transferred $160,000 into her account instead of taking out $160. Next, the cybercriminals tried to get the woman to go to her bank in person to wire "back" the money.

When she said she didn't drive, the crooks said they would send an Uber to her home. It's unknown if the Uber came: the victim's son told Krebs that she went to the home of a neighbor after the phone call, who figured out it was a scam.

While it's often assumed that older people are the most common victims of online fraud, multiple studies point to a different conclusion: young people are most likely to fall for a digital scam. Reported reasons vary, but in general younger internet users are seen as overly confident in their online security skills, leading to riskier behavior without a full understanding of what can go wrong.

CISA's top malware strains of 2021 The US Cybersecurity and Infrastructure Security Agency, along with the Australian Cyber Security Centre, have released an informative, if somewhat late, report naming their top observed malware strains of 2021.

According to the agencies, remote-access trojans, banking trojans, information stealers and ransomware topped the list, with most strains included having been on the scene for more than five years.

"Updates made by malware developers, and reuse of code from these malware strains, contribute to the malware's longevity and evolution into multiple variations," the advisory read.

Eleven malware strains are mentioned in the report, most of which we've covered to some capacity:

Agent Tesla has been used in phishing campaigns against the US oil industry AZORult is a data harvesting malware that targets Windows Formbook, a data stealer also known as XLoader, has been spotted on Ukrainian systems Ursnif is a banking malware first spotted in 2008 LokiBot is a banking trojan in use for years MOUSEISLAND is a Word macro downloader; given recent Microsoft updates to macro usage, it may have to adapt to a new tactic NanoCore is a RAT that landed its developer in prison Qbot is a data stealer that uses the Windows Follina exploit Remcos is allegedly legitimate pentesting software often used by cybercriminals TrickBot is a form of ransomware whose Russian creator was recently arrested in South Korea Gootkit has been used to promote malicious websites in search engine results Cybersecurity company Tenable said CISA's list of top malware has an interesting overlap with the most exploited vulnerabilities of 2021: they rely on each other.

Citing CISA's list of the 36 most commonly exploited vulnerabilities of 2021, Tenable said four of them are represented by malware in the list covered here, with two released after the relevant timeframe. Of the vulnerabilities Tenable singled out, several are exploitable by multiple malware families.

Tenable said it's seen "sustained exploitation of these flaws by diverse threat actors," and said it's concerned that exploits of older vulnerabilities continues to be common.

"Continued exploitation is troubling evidence that organizations are leaving these flaws unremediated, which is particularly concerning considering how many Print Spooler flaws Microsoft has patched in the intervening year since PrintNightmare," Tenable said. ®


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: duckduckgo; microsoft; searchengines

1 posted on 08/06/2022 10:44:34 PM PDT by nickcarraway
[ Post Reply | Private Reply | View Replies]

To: nickcarraway

Step One: Lick finger
Step Two: Raise finger into the air
Step Three: Determine which way the wind/breeze is blowing.


2 posted on 08/06/2022 10:48:48 PM PDT by cranked
[ Post Reply | Private Reply | To 1 | View Replies]

To: nickcarraway

DDG has lost too much trust. Never again.


3 posted on 08/06/2022 11:31:53 PM PDT by Zack Attack
[ Post Reply | Private Reply | To 1 | View Replies]

To: Zack Attack

Still better than Google.


4 posted on 08/07/2022 12:20:50 AM PDT by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 3 | View Replies]

To: FreedomPoster

“Still better than Google.”

Slightly, but Brave seems to be better than both as they don’t use Google’s search engine like DDG does.


5 posted on 08/07/2022 2:57:09 AM PDT by BobL (The Globalists/Neocons desperately want Ukraine to win...makes it easy for me to choose a side)
[ Post Reply | Private Reply | To 4 | View Replies]

To: nickcarraway; cranked
This bug resulted from an update to our code in June 2021

Um, sure, sure - it was a "bug". Let's all face it, boys and girls - your data is incredibly valuable. ALL of the tech companies, even the "good guys" are eventually going to figure out a way to use it to make money. You can bank on that. /bad pun

6 posted on 08/07/2022 3:40:13 AM PDT by Hardastarboard (Don't wish your enemy ill; plan it. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: BobL

I like Brave. It seems identical to Dissenter which no longer can be downloaded.


7 posted on 08/07/2022 4:29:43 AM PDT by MayflowerMadam (Sometimes when you get to where you're supposed to be, it's too soon.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: BobL

Brave is the default on the Windows box. I still use Safari on iOS / iPadOS devices, so DDG it is. Can’t make Brave the default on those.


8 posted on 08/07/2022 4:33:45 AM PDT by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 5 | View Replies]

To: MayflowerMadam

I changed to Brave browser 2-3 years ago - remain quite pleased.

IIRC, Brave uses the same Chromium engine as Chrome and (new) Edge...but without their tracking making Brave faster and more secure.


9 posted on 08/07/2022 4:39:07 AM PDT by newfreep (“Leftism, under all of its brand names, is a severe, violent & evil mental disorder.”)
[ Post Reply | Private Reply | To 7 | View Replies]

To: newfreep

When I use Outlook.com for email I always open it in Dissenter (Brave’s “twin”). If I use another browser I’m overrun with ads. Zero ads with Brave.


10 posted on 08/07/2022 5:04:36 AM PDT by MayflowerMadam (Sometimes when you get to where you're supposed to be, it's too soon.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: MayflowerMadam

Yep...Brave is superb in blocking ads & pop-ups and making many news sites readable.

I really, REALLY despise autoplay video pop-ups.

Not familiar with Dissenter but found their website and their connection to GAB.


11 posted on 08/07/2022 5:27:04 AM PDT by newfreep (“Leftism, under all of its brand names, is a severe, violent & evil mental disorder.”)
[ Post Reply | Private Reply | To 10 | View Replies]

To: MayflowerMadam

btw, I also use Outlook - their app and not the online website.

The app version is MUC H better than the online site.


12 posted on 08/07/2022 5:29:17 AM PDT by newfreep (“Leftism, under all of its brand names, is a severe, violent & evil mental disorder.”)
[ Post Reply | Private Reply | To 10 | View Replies]

To: newfreep

I still use Outlook from the MS Office 2003 program for Contacts and Calendar, but haven’t synced the email module with online Outlook. I should do that one of these says.


13 posted on 08/07/2022 5:54:41 AM PDT by MayflowerMadam (Sometimes when you get to where you're supposed to be, it's too soon.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: MayflowerMadam

You’re talking about the Brave browser but there is a brave search engine that anyone can use regardless of browser. https://search.brave.com

It can be added to your firefox based browser as a new search engine. I use waterfox browser and was able to add it.

Brave search addon for firefox/waterfox - https://addons.mozilla.org/en-US/firefox/search/?q=brave&type=extension

Closest thing to a Brave search extension for Chromium based browsers like Chrome, Falkon(Linux), Edge(I think), Slimjet, Opera - https://chrome.google.com/webstore/detail/brave-search/jojedekgcncccnjhilimdojbfnfamkda

It doesn’t install it for use in the address bar. Only way it can be used is;
1) highlight a word on a web page
2) right click
3) search with brave.

Or just get the Brave browser.

Brave search is working well for me 99% of the time and the results are similar to DDG. Every once in a while, I’ll still use DDG if I don’t find something with search.brave


14 posted on 08/07/2022 6:39:21 AM PDT by Pollard (Worm Free PureBlood)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Pollard

Thank you.


15 posted on 08/07/2022 6:40:37 AM PDT by MayflowerMadam (Sometimes when you get to where you're supposed to be, it's too soon.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: BobL

yandex. It’s russian and largely uncensored. You’ll find stuff indexed there that is filtered by G and DDG.


16 posted on 08/07/2022 9:50:27 AM PDT by fretzer
[ Post Reply | Private Reply | To 5 | View Replies]

To: nickcarraway; rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; ...

17 posted on 08/07/2022 9:55:16 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: fretzer

“yandex. It’s russian and largely uncensored.”

Nice, my handlers* hadn’t told me about them.

*I’m not pro-Ukraine, so I’m a Russian puppet.


18 posted on 08/07/2022 10:10:38 AM PDT by BobL (The Globalists/Neocons desperately want Ukraine to win...makes it easy for me to choose a side)
[ Post Reply | Private Reply | To 16 | View Replies]

To: nickcarraway

I’ve been using Startpage lately, and it seems to do a good job. I’ve also downloaded the actual Chromium browser and seeing well it works. It doesn’t have Google Chrome API’s, but honestly, that the best thing about it.


19 posted on 08/07/2022 11:27:12 AM PDT by ducttape45 (Proverbs 14:34, "Righteousness exalteth a nation: but sin is a reproach to any people.")
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson