Facebook fixes bug in Midnight Delivery service

January 1, 2013

San Francisco, Jan 1: Facebook sidestepped a privacy gaffe by fixing a flaw that made it possible to snoop on private New Year's Eve messages sent using a "Midnight Delivery" service.

Facebook took "Midnight Delivery" offline temporarily to patch a vulnerability pointed out by Britain-based blogger Jack Jenkins.

The new feature, which lets people prepare digital messages in advance and have them automatically delivered to Facebook friends the moment the year 2013 arrives, was back in action.

"I have just checked, the bug/oversight has now been fixed," Jenkins said in an update to his blog time-stamped 1435 GMT.

"I don't know how a site like Facebook can continue to take these kinds of risks."

Jenkins outlined in his blog a way to get into Midnight Delivery messages by tinkering with characters in URLs, essentially manipulating electronic address data.

The privacy slip came less than a week after the older sister of Facebook co-founder Mark Zuckerberg tripped on the social network's privacy settings, landing in the midst of a debate about "online etiquette."

Randi Zuckerberg, who launched a Silicon Valley themed online reality show after quitting her job handling Facebook public relations, kicked off the controversy after a family photo intended for friends went public.

The picture showed Mark Zuckerberg in a kitchen with family members dramatizing reactions to messages sent with a freshly launched "Poke" feature at the California-based online social network.

Poke lets people send messages that self-destruct in what is seen by many as a spin on popular smartphone application Snapchat.

Randi Zuckerberg posted a copy of the family photo to Facebook for the eyes of close friends only, but evidently it was also shared with friends of those tagged in the picture due to privacy settings at the social network.

That meant the fun photo popped up in the news feed of someone outside Randi Zuckerberg's circle, who then shared it on popular messaging service Twitter.

From there, the photo went viral -- much to Randi Zuckerberg's chagrin.

"Digital etiquette: always ask permission before posting a friend's photo publicly," Mark Zuckerberg's elder sister said in a Christmas tweet. "It's not just about privacy settings, it's about human decency."

The comment sparked heated debate at Twitter and other online forums, where a vocal contingent saw poetic justice in the Zuckerbergs being exposed by the way the social network handles the privacy of users.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 22,2020

Kochi, May 22: During the nationwide COVID-19 lockdown, Kerala recorded the highest number of cyber attacks followed by Punjab and Tamil Nadu, a study by anti-virus software firm K7 Computing said on Thursday.

In a statement issued in Chennai, the company said its K7 Computing's Cyber Threat Report, a comprehensive analysis of cyber attacks during the lockdown has found that Kerala recorded the highest number of cyber attacks during this period. The report analyses various cyber attacks within India during the pandemic and reveals that threat actors targeted the state with COVID-themed attacks aimed at exploiting user trust.

In Kerala, regions like Kottayam, Kannur, Kollam, and Kochi saw the highest hits with 462, 374, 236, and 147 attacks respectively, while the state as a whole saw around 2,000 attacks during the period - the highest thus far in the country.

This was followed by Punjab with 207 attacks and Tamil Nadu with 184 attacks, the company said.

The sudden surge in the frequency of attacks witnessed from February 2020 to mid-April 2020 indicates that scamsters across the world were exploiting the widespread panic around coronavirus at both the individual and corporate level.

These attacks aimed to compromise computers and mobile devices to gain access to users' confidential data, banking details, and cryptocurrency accounts.

The key threats seen during this period ranged from phishing attacks to rogue apps disguised as COVID-19 information apps that targeted users' sensitive data. Phishing attacks were noticed more in Tier-II and Tier-III cities while the metros fared better. Smaller cities saw over 250 attacks being blocked per 10,000 users.

Users from Ghaziabad and Lucknow seem to have faced almost 6 and 4 times the number of attacks as Bengaluru users.

According to the statement, a majority of the recorded attacks were phishing attacks with sophisticated campaigns that could easily snare even the most educated users. These attacks were aimed at heightening users' fears and creating a sense of urgency to take action.

K7 Labs noticed phishing attacks where scamsters posed as representatives of the United States Department of Treasury, the World Health Organization (WHO), and the Centres for Disease Control and Prevention (CDC), the company said.

Users were encouraged to visit links that would automatically download malware on the host computer such as the Agent Tesla keylogger or Lokibot information-stealing malware, infamous banking Trojans such as Trickbot or Zeus Sphinx, and even disastrous ransomware.

Other attacks included infected COVID-19 Android apps like CoronaSafetyMask that scam users with promises of masks for an upfront payment; the spyware app Project Spy; and seemingly genuine apps that are infected with dangerous malware like banking Trojans such as Ginp, Anubis and Cerberus.

"Covid-19 has created an ideal situation for various threat actors to target individuals and enterprises alike. The panic caused by the stringent lockdown measures and rapid spread of this virus has left many people looking for more information on the situation," J. Kesavardhanan, Founder and CEO of K7 Computing was quoted as saying in the statement.

"Threat actors exploit this fear to their advantage and scam users into downloading malicious software and divulging sensitive information like banking codes. The need to be cyber cautious has never been greater. This is more so in the case of corporates who have adopted a work from home policy hurriedly without adequate cyber hygiene. We have seen an increase in attacks on enterprises and SME employees as well," he added.

Such attacks are expected to continue till normalcy returns. Social engineering attacks targeted at winning users' trust will gain momentum.

Healthcare institutions, well-known government offices, and international organisations will continue to be a prime target throughout the pandemic, the statement said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 14,2020

New Delhi, Mar 14: Excise duty on petrol and diesel was on Saturday hiked by ₹3 per litre as the government looked to mop up gains arising from fall in international oil prices.

Special excise duty on petrol was hiked by ₹2 to ₹8 per litre incase of petrol and to Rs 4 incase of diesel, an official notification said.

Additionally, road cess on petrol was raised by ₹1 per litre each on petrol and diesel to ₹10.

The increase in excise duty would in normal course result in a hike in petrol and diesel prices but most of it would be adjusted against the fall in rates that would have necessitated because of slump in international oil prices.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 17,2020

New Delhi, Jan 17: E-commerce major Amazon on Friday said it plans to create one million new jobs in India over the next five years through investments in technology, infrastructure and its logistics network.

These jobs are in addition to the seven lakh jobs Amazon's investments have enabled over the last six years in the country.

"Amazon plans to create one million new jobs in India by 2025," the company said in a statement, adding that the jobs - created both directly and indirectly - will be across industries, including information technology, skill development, content creation, retail, logistics, and manufacturing.

Amazon.com Inc chief Jeff Bezos had on Wednesday announced USD 1 billion (over Rs 7,000 crore) investment in India to help bring small and medium businesses online and committed to exporting USD 10 billion worth of India-made goods by 2025.

"We are investing to create a million new jobs here in India over the next five years," Bezos said.

"We’ve seen huge contributions from our employees, extraordinary creativity from the small businesses we've partnered with, and great enthusiasm from the customers who shop with us—and we’re excited about what lies ahead," Bezos added.

India has prioritised job creation and skilling initiatives – including the training of more than 400 million people by 2022 – in rural and urban areas.

"Amazon’s job creation commitment and investment in traders and micro, small and medium enterprises (MSMEs) complement this social inclusion and social mobility efforts by creating more opportunities for people in India to find employment, build skills, and expand entrepreneurship opportunities," the statement said.

The new investments will help to hire talent to fill roles across Amazon in India, including software development engineering, cloud computing, content creation, and customer support.

Since 2014, Amazon has grown its employee base more than four times, and last year inaugurated its new campus building in Hyderabad – Amazon’s first fully-owned campus outside the United States and the largest building globally in terms of employees (15,000) and space (9.5 acres).

The investments will also help in expanding growth opportunities for the more than 5,50,000 traders and micro, small, and medium-sized businesses – including local shops – through programs like Saheli, Karigar, and “I Have Space”.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.