CLOSED: [2016-11-12 Sat 13:57] :PROPERTIES: :CREATED: [2015-05-30 Sat 13:03] :ID: 2016-11-12-cloud :END: :LOGBOOK: - State "DONE" from "DONE" [2020-06-05 Fri 23:13] - State "DONE" from "NEXT" [2016-11-12 Sat 13:57] :END: There is this well cited argument that cloud companies like Google, Apple, Amazon, Facebook, and you-name-it are able to protect *your personal data* much better than you are able to. They have military grade security restrictions, better backup methods, and are able to do this [[https://news.microsoft.com/europe/2023/01/05/consistent-global-pricing-for-the-microsoft-cloud/][much cheaper]]. Everybody is doing it so it seems to be OK to put your data into the cloud. While [[https://www.schneier.com/blog/archives/2014/09/security_trade-_2.html][this argument being absolutely true]], people seem to forget that giving away your data to any third party is the root of [[http://www.cnet.com/news/woz-the-cloud-is-a-nightmare/][many problems]] in the first place. It is not relevant to whom you are giving your data to. Yes, this also holds true for Apple's iCloud where many people think it's a save heaven. Let me explain by examples. ----- Please note that the links provided are only a small selection of numerous facts on how the cloud is damaging your privacy in an enormous amount. This article mostly refers to personal data and not business-related data. If a link is not available any more, please do use [[https://web.archive.org/][the Internet Archive WaybackMachine]] to find archived versions for a given date. Drop me a line if you do spot a source that should be not relied on. The incidents collected on this page is only a tiny fraction of all incidents reported. Please use other [[https://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/][sources like this]] for an overall picture. I'm just collecting distinctive incidents that support my point. Disclaimer especially for tech-savvy people: Please note that I am using a simplified term of "cloud" which refers to storing data or [[https://en.wikipedia.org/wiki/Metadata][metadata]] of us in the public cloud. I am specifically *not* referring to cloud-computing in terms of putting my own (encrypted) data in an S3 container or processing nodes that may be even [[https://en.wikipedia.org/wiki/State_(computer_science)][stateless]]. With the exception of cloud processing services that turn bought devices into bricks after discontinuing their service. You see, it's complicated. If you know what a [[https://en.wikipedia.org/wiki/Threat_model][threat model]] is, you most probably know these things here already. *** Losing Control No matter, how secure your cloud vendor is storing your data, you are going to *lose control*. Same holds true for the European cloud. With cloud-connected devices in your house, you might even lose basic services like heating or you lights. If this doesn't scare you already, how about losing control over your cloud-connected car? Even your cloud-connected sex toys record your "private sessions" to the cloud. Not every data is lost or stolen on purpose. Mistakes happen. Whole MS Office suite apps might not be available all the time. Or cloud storage like Apple iCloud are offline from time to time. Particular widespread hobby: people tend to buy smart home devices that turn into expensive waste after losing support from the vendor. Cloud-based car alarm system? Well, it's actually the perfect tool to locate and steal your high-class car. You're losing exclusive access on the logs to your data. This is subtle but nonetheless important when it comes to sensible data. [[https://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/][This site collects the biggest data breaches (or leaks)]]. It contains over 30.000 reports of incidents including Facebook, Microsoft, Yahoo, Twitter, Friend Finder Network, and so forth. - 2024-02: 200k Facebook Marketplace records with "email addresses alongside names, phone numbers, Facebook profile IDs and geographic locations" leaked. ([[https://haveibeenpwned.com/PwnedWebsites#FacebookMarketplace][haveibeenpwned.com]], [[https://www.heise.de/news/Persoenliche-Daten-von-ueber-77-000-Facebook-Marketplace-Nutzern-geleakt-9635749.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2024-02: Health data of 33 Million people from France (half of the population!) are compromised ([[https://www.heise.de/news/Cyberangriff-Gesundheitsdaten-von-33-Millionen-Franzosen-betroffen-9624548.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]], [[https://www.cnil.fr/fr/violation-de-donnees-de-deux-operateurs-de-tiers-payant-la-cnil-ouvre-une-enquete-et-rappelle-aux][CNIL]]) - 2024-01: 15,115,516 user records from the popular [[https://trello.com/][Altlassian Trello]] got stolen. Presumably with "emails, usernames, full names, and other account information". ([[https://www.heise.de/news/Trello-Mehr-als-15-Millionen-Datensaetze-aufgetaucht-9605372.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]], [[https://haveibeenpwned.com/PwnedWebsites#Trello][haveibeenpwned]]) - 2023-10: Hackers got into [[https://en.wikipedia.org/wiki/Okta,_Inc.][the Okta identity management]] of [[https://1password.com/][1password]] ([[https://blog.1password.com/okta-incident/][1password]], [[https://www.heise.de/news/Okta-Einbruch-1Password-bemerkte-verdaechtige-Aktivitaeten-9342147.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - People still putting their passwords in the public cloud after we've had so many public incidents (see LastPass below) should really learn how to handle private data properly. I'm sorry, that was always a very bad idea in the first place. - 2023-11: not 134 customer accounts got stolen but *all* customers who were in contact with customer support are affected. Okta claims that the data that got stolen was not that sensitive. ([[https://www.heise.de/news/Okta-Doch-viel-mehr-als-ein-Prozent-der-Kundschaft-von-Datendiebstahl-betroffen-9542820.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-08: [[https://en.wikipedia.org/wiki/Fitbit][Fitbit]] (owned by Google) is transferring data of Millions of European users to the US cloud, violating [[https://noyb.eu/en/your-fitbit-useless-unless-you-consent-unlawful-data-sharing?mtc=mu][GDPR]] to protect personal information. ([[https://noyb.eu/en/your-fitbit-useless-unless-you-consent-unlawful-data-sharing?mtc=mu][noyb.eu]]) - 2023-08: 2.6 Million customer data from Duolingo got public. ([[https://haveibeenpwned.com/PwnedWebsites#Duolingo][haveibeenpwned.com]], [[https://www.heise.de/news/2-6-Millionen-Datensaetze-von-Duolingo-Nutzern-bei-Have-I-Been-Pwned-9283391.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-08: UK Electoral Commission got hacked "including the name and address of anyone in the UK who was registered to vote between 2014 and 2022". ([[https://www.electoralcommission.org.uk/media-centre/electoral-commission-subject-cyber-attack][electoralcommission.org.uk]]) - The hack took place 2021-08. They didn't realize until 2022-10. Starting with 2023-08 they began to inform the people who were affected. That's way too slow. - 2023-08: Again Microsoft, again Azure: "unauthorized access to cross-tenant applications and sensitive data (including but not limited to authentication secrets)". If you aren't tech-savvy: this is very bad. ([[https://www.tenable.com/security/research/tra-2023-25][tenable]]) - A reoccuring pattern emerges more and more: Microsoft didn't fix the issue in months and as of 2023-08-03 it is still an open vulnerability in Azure, risking the data of all Azure customers. - related: - [[https://arstechnica.com/security/2023/08/microsoft-cloud-security-blasted-for-its-culture-of-toxic-obfuscation/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social][Microsoft comes under blistering criticism for “grossly irresponsible” security | Ars Technica]] - [[https://infosec.exchange/@briankrebs/110820474957163710][BrianKrebs: "The CEO of Tenable just ripped Microsoft a new on…" - Infosec Exchange]] - 2023-08: Due to a leak in the data transfer software [[https://en.wikipedia.org/wiki/MOVEit][MOVEit]], at least 8 to 11 Million people lost their mostly health-related data. ([[https://www.heise.de/news/MOVEit-Luecke-US-Betrieb-meldet-Datenabfluss-bei-bis-zu-11-Millionen-Personen-9230095.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) *Intermission*: the following incident is probably the incident with the most impact worldwide of all times. However, it did not get that much press coverage in the general media. The nature of this incident is a total security desaster for Microsoft services which can not be trusted any more. This is because Microsoft can't replace all of their key infrastructure and their services (with potential backdoors) at once. - 2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them *full access to basically all Microsoft cloud services* including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. ([[https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/][MS blog entry]], [[https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr][wiz.io]], [[https://www.heise.de/news/Neue-Erkenntnisse-Microsofts-Cloud-Luecken-viel-groesser-als-angenommen-9224640.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - With the default logs, customers could not even detect intruders as you would need to pay extra to get access to those log files. - THIS ONE IS HUGE! - Microsoft did *not* communicate which services were affected and which not. - *Any Microsoft cloud service was potentially compromised*. - Most probably, the usual "any compromised system needs to be thrown away and re-created from scratch will not be applied here. As a consequence, *you can't trust any data from Microsoft services any more.* - Security experts like [[https://graz.social/@kuketzblog@social.tchncs.de/110773607542990308][Mike Kuketz]] think that most probably we need to consider all Microsoft systems that are using their cloud authentication including *all Windows hosts are compromised*. - According to [[https://www.heise.de/news/Gestohlener-Cloud-Master-Key-Microsoft-schweigt-so-fragen-Sie-selber-9229395.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][this German source]], Microsoft is still refusing to tell what happened and which systems are affected to what extend. - [[https://www.heise.de/meinung/Kommentar-Microsoft-provoziert-den-Cloud-GAU-und-reagiert-dann-katastrophal-9258697.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][2023-08-18: German comment]]: Many similar comments like that underline that *Microsoft disqualifies as a trustworthy partner.* - 2023-09-06: first public explanation by MS: [[https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/][Microsoft: Results of Major Technical Investigations for Storm-0558 Key Acquisition]] - Press reactions: [[https://www.heise.de/news/Gestohlener-Microsoft-Schluessel-stammte-aus-einem-Crash-Dump-9297240.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][heise (German)]], [[https://blog.fefe.de/?ts=9a075ef7][fefe (German)]] - 2023-09-29: Due to the missing containment by Microsoft, stolen data will face the day of light: 60,000 emails were stolen from 10 USA State Department accounts. ([[https://www.reuters.com/world/us/chinese-hackers-stole-60000-emails-us-state-department-microsoft-hack-senate-2023-09-27/][reuters.com]], [[https://www.heise.de/news/60-000-geklaute-Regierungsmails-Erste-Zahlen-nach-Microsofts-Cloud-Key-Debakel-9321044.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-09-29: [[https://graz.social/@publicvoit/111147782761723981][My Mastodon message about the latest news]] was posted on [[https://news.ycombinator.com/][Hacker News]] and [[https://news.ycombinator.com/item?id=37702095][its discussion reached number one worldwide]]. - 2023-07: [[https://en.wikipedia.org/wiki/VanMoof][VanMoof bicycles]] declared bankrupt. Without their cloud servers and the app, bike owners can't control the light, driving speed and auto-unlock on approaching the bike. ([[https://www.heise.de/news/E-Bike-Hersteller-VanMoof-ist-bankrott-9219136.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-05: Microsoft Hosted Exchange by [[https://www.united-hoster.de/][United Hoster]] (Germany) is offline because of ransomware ([[https://www.heise.de/news/Ransomware-Attacke-Hosted-Exchange-von-United-Hoster-offline-9064768.html][German heise]]) - 2023-02: Very sensitive data from over 2200 members of the German [[https://en.wikipedia.org/wiki/Last_Generation_(activists)][Last Generation]] was found on Google Drive. ([[https://www.golem.de/news/politische-ansichten-auf-google-drive-letzte-generation-mit-datenschutz-gau-2302-171664.html][German golem]]) - 2023-01: Microsoft 365 services down ([[https://winfuture.de/news,135790.html][German winfuture]]) - 2023-04: again ([[https://winfuture.de/news,134276.html][German winfuture]]) - 2023-01: Thousands accounts of NortonLifeLock customer accounts (cloud password storage) breached. ([[https://uk.news.yahoo.com/norton-lifelock-says-thousands-customer-192152410.html?guccounter=1][yahoo.com]], [[https://www.heise.de/news/NortonLifeLock-Hersteller-warnt-vor-potenziell-geknackten-Passwortmanagern-7459886.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-01: Are you driving a Kia, Honda, Hyundai, Nissan, Infiniti, Acura, Ferrari, Mercedes-Benz, Porsche, Toyota or BMW? Well, other people do get your personal data and might even *remote control your cloud-connected car*. ([[https://samcurry.net/web-hackers-vs-the-auto-industry/][samcurry.net]], [[https://www.heise.de/news/Geoeffnet-und-weggefahren-Sicherheitsforscher-knacken-Autos-von-Kia-Honda-Co-7447668.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-12: Personal data from *over 400 Million Twitter users* leaked. ([[https://breached.vc/Thread-Selling-Twitter-Data-Breach-400-million-users][breached.vc]], [[https://www.heise.de/news/Womoeglich-Datenluecke-bei-Twitter-ausgenutzt-400-Millionen-Konten-kompromitiert-7442965.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-12: Hackers hacked *LastPass* and, copied sensitive clear-text user data and even downloaded the encrypted password-database. ([[https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/][lastpass.com]], [[https://www.heise.de/news/Passwortmanager-LastPass-Hacker-haben-Zugriff-auf-Kennworttresore-von-Kunden-7441929.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - All passwords may likely be hacked in future (using brute-force or yet unknown algorithm weaknesses). - Users who re-use passwords with other accounts most probably got hacked right away. - [[https://palant.info/2022/12/26/whats-in-a-pr-statement-lastpass-breach-explained/][What’s in a PR statement: LastPass breach explained]] → great insight from their press release statement which is not reassuring. Furthermore, LastPass did fail to update the password security of their existing customers big time. - [[https://twit.tv/shows/security-now/episodes/905?autostart=false][Older LastPass passwords can be cracked in approximately one minute]]. - 2023-02: You could say that this won't happen at LastPass again. Unfortunately, it did. ([[https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/][arstechnica]], [[https://www.heise.de/news/LastPass-Hack-Angreifer-hackten-Privat-PC-von-DevOpS-Entwickler-7529717.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-09: People seems to use data from the LastPass hack to steak millions of crypto money. No pity there. ([[https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/][krebsonsecurity.com]], [[https://www.heise.de/news/Passwortmanager-LastPass-Hacker-scheinen-Kennworttresore-zu-knacken-9300583.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-12: The FBI is running a social network: [[https://en.wikipedia.org/wiki/InfraGard][InfraGard]]. Personal data of more than 80,000 very-high-profile members (CEOs, ...) got hacked. ([[https://krebsonsecurity.com/2022/12/fbis-vetted-info-sharing-network-infragard-hacked/][krebsonsecurity.com]]) - So *even the FBI can't control a high-secure cloud network*. - 2022-12: The Smart-Vehicle-platform of Hyundai, Toyota and Nissan has severe security holes: hackers gain access to personal data and are able to control the cars. ([[https://www.heise.de/news/Auto-Diebstahl-Sicherheitsforschern-genuegt-E-Mail-Adresse-als-Zuendschluessel-7364437.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]] with links to Twitter) - 2022-11: Attackers who hacked 5 million unique passengers and all employees of [[https://www.airasia.com/][AirAsia Group]] were "irritated" because of the chaos of their computer systems and "very, very weak" network protection. ([[https://www.databreaches.net/airasia-victim-of-ransomware-attack-passenger-and-employee-data-acquired/][databreaches.net]]) - 2022-11: Massive 2021 *Twitter* data breach was far worse than reported: *5.4 Million* phone numbers, email addresses. ([[https://9to5mac.com/2022/11/25/massive-twitter-data-breach/][9to5mac]]) - 2022-11: *WhatsApp* data leak: *500 million user records* for sale ([[https://cybernews.com/news/whatsapp-data-leak/][cybernews.com]], [[https://www.heise.de/news/Angeblich-487-Millionen-Telefonnummern-ueber-WhatsApp-geleakt-7352670.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-11: Australian Medibank lost almost 500,000 health claims, along with personal information. ([[https://www.theguardian.com/australia-news/2022/nov/11/medibank-data-theft-hackers-release-records-they-claim-are-related-to-mental-health-and-alcohol-issues][theguardian.com]]) - 2022-09: Older photographs in Google Photos gets corrupted. ([[https://support.google.com/photos/thread/180787712/corrupted-photos][Google]]) - 2022-08: The recent Cisco hack started with a hacked Google account where a Cisco empolyee synced his browser passwords to. ([[https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html][talosintelligence.com]]) - 2022-07: Microsoft Teams worldwide down for five hours ([[https://www.bleepingcomputer.com/news/microsoft/massive-microsoft-365-outage-caused-by-faulty-ecs-deployment/][bleepingcomputer.com]]) - 2022-07: A writer of a one million word novel was locked out of her book by her online word processing software. ([[https://www.technologyreview.com/2022/07/15/1056042/chinese-novel-censored-before-shared/][technologyreview.com]]) - 2022-07: Marriott does seem to have a serious problem. At least the third leak went public. ([[https://www.databreaches.net/exclusive-marriott-hacked-again-yes-heres-what-we-know/][databreaches.net]], [[https://www.heise.de/news/Wieder-Datenleck-bei-Hotelkette-Marriot-Firmen-und-Kundendaten-kompromittiert-7164705.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-07: Names, addresses, national ID numbers, mobile numbers, all crime/case details of *one Billion(!) chinese residents* leaked. ([[https://breached.to/Thread-Selling-2022-SHGA-Shanghai-Gov-National-Police-database][breached.to]]) - 2022-03: Wyze knew hackers could remotely access your camera for three years and said nothing. ([[https://www.theverge.com/23003418/wyze-cam-v1-vulnerability-no-patch-bitdefender-responsible-disclosure][theverge.com]]) - 2022-03: All accounts of all 15.000+ global customers of [[https://en.wikipedia.org/wiki/Okta_(company)][Okta]] (Identity and Access Management; cloud [[https://en.wikipedia.org/wiki/Single_sign-on][SSO]]) were hacked for months. ([[https://edition.cnn.com/2022/03/22/tech/okta-report-of-breach/index.html][CNN]]) - 2022-02: Over 350 blind people with eye implants in their eyes lost them completely because the IoT company got issues ([[https://spectrum.ieee.org/bionic-eye-obsolete][spectrum.ieee.org]]) - 2021-12: Gravatar lost 167 million names, usernames and MD5 hashes of email addresses. ([[https://haveibeenpwned.com/PwnedWebsites#Gravatar][haveibeenpwned.com]], [[https://www.heise.de/news/Knapp-114-Millionen-Nutzernamen-und-E-Mail-Adressen-von-Gravatar-geknackt-6288036.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2021-09: 61 Million sensitive records of many different *fitness trackers*, mostly by Fitbit und Apple HealthKit ([[https://www.websiteplanet.com/blog/gethealth-leak-report/][websiteplanet.com]], [[https://www.heise.de/news/Millionen-Datensaetze-von-Wearables-und-Fitness-Trackern-ungesichert-online-6190932.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2021-08: Default permissions on Microsoft Power Apps exposed 38 Million data records. ([[https://www.upguard.com/breaches/power-apps][upguard.com]]; [[https://www.heise.de/news/Brisante-Mischung-Laxe-Defaults-und-Nutzer-mit-fehlendem-Sicherheitsbewusstsein-6173306.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2021-08: T-Mobile US loses 50 Million data on customers. ([[https://www.heise.de/news/Datenpanne-bei-T-Mobile-Hacker-nutzte-verheerende-Sicherheitsluecke-6176610.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]], [[https://www.wsj.com/articles/t-mobile-hacker-who-stole-data-on-50-million-customers-their-security-is-awful-11629985105][wsj.com]]) - 2021-06: *700 Million LinkedIn users exposed*. ([[https://restoreprivacy.com/linkedin-data-leak-700-million-users/][restoreprivacy.com]]) - 2021-04: Data of over *533 million Facebook users* leaked: Phone number, Facebook ID, full name, location, past location, birthdate, (sometimes) email address, account creation date, relationship status, and personal bios. ([[https://www.techradar.com/news/data-of-over-533-million-facebook-users-leaked-online][techradar.com]]) - 2021-03: IT security experts of Eset: Severe security issues may cause data leak or ransom attacks via sex toys. ([[https://www.heise.de/news/Erpressungsgefahr-Schwere-Sicherheitsluecken-bei-vernetztem-Sexspielzeug-5850339.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2020-06: Issues with vacuum cleaner robot of Vorwerk Kobold VR200 and VR300 due to cloud issues. ([[https://www.heise.de/news/Vorwerk-VR200-und-VR300-Cloud-Probleme-bei-Staubsaugerrobotern-4772894.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2020-01: Smart homes will turn dumb overnight as Charter kills security service. ([[https://arstechnica.com/information-technology/2020/01/smart-homes-will-turn-dumb-overnight-as-charter-kills-security-service/][arstechnica]]) - 2019-12: iCloud outages. ([[https://www.heise.de/mac-and-i/meldung/iCloud-Grosse-Stoerung-bei-Apples-Cloud-Diensten-4608616.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2019-11: *Microsoft Office 365 down worldwide*. ([[https://irreal.org/blog/?p=8461][Comment]]) - 2019-05: Nest is disabling their APIs. ([[https://www.home-assistant.io/blog/2019/05/08/nest-data-bye-bye/][home-assistant.io]]) - 2019-04: Hacker finds he can *remotely kill car engines* after breaking into GPS tracking apps. ([[https://www.vice.com/en_us/article/zmpx4x/hacker-monitor-cars-kill-engine-gps-tracking-apps][Vice]]) - 2019-03: *Car alarms* can *make your vehicle even less secure*, affecting 3 million vehicles globally. ([[https://www.pentestpartners.com/security-blog/gone-in-six-seconds-exploiting-car-alarms/][pentestpartners.com]], [[https://www.youtube.com/watch?v=aZUQmJMuf8c&feature=emb_title][demo video]]) - 2018-03: Facebook and Google store /everything/ that was sent to you or you sent to somebody else. ([[https://twitter.com/iamdylancurran/status/977566839839617025][Twitter]]) - 2018-02: FedEx Customer Records Exposed: more than 119 thousands of scanned documents of US and international citizens, such as passports, driving licenses, security IDs etc. ([[https://kromtech.com/blog/security-center/fedex-customer-records-exposed][kromtech.com]]) - 2017-11: *Sex toy* company admits to *recording users' remote sex sessions*, calls it a 'minor bug'. ([[https://www.theverge.com/2017/11/10/16634442/lovense-sex-toy-spy-surveillance][theverge.com]]) - 2017-02: Google, unlike Microsoft, must turn over foreign emails. ([[https://www.reuters.com/article/us-google-usa-warrant-idUSKBN15J0ON][Reuters]]) - 2016-05: Apple is deleting your local music files without notifying. ([[https://apple.slashdot.org/story/16/05/05/159219/apple-stole-my-music-no-seriously][apple.slashdot.org]]) - 2011-12: Apple vs. Google Client Platforms How you end up being the Victim. ([[https://media.ccc.de/v/28c3-4676-en-apple_vs_google_client_platforms][CCC talk video recording]]) - 2010-10: "Customers of Google cloud services who are concerned about security better get used to being unable to check out first-hand how well their data is being protected". ([[https://www.cio.com/article/2414436/don-t-expect-to-peer-into-google-cloud-services-security.html][cio.com]]) [[https://beepb00p.xyz/sad-infra.html][This article]] is discussing this notion from a different angle. *** Data Gets Used Against You You can't be sure how your cloud vendor is *analyzing your data* "for your best experience" or enforce arbitrary policies like the avoidance of nudity or strong language. And of course they *sell the results* of this analysis to third party companies. Same holds for user reviews. And of course your online purchases. Using a dating service should scare you when they give away your most sensitive data to advertisers. Cloud companies consider *you as their product*, not their customer. They sell your data. Sometimes, they are not even interested in fixing security issues of your cloud. Companies do give access to collected user data to their "business partners". Research shows that companies are exposing sensitive data with and without noticing more and more. #+CAPTION: Tweet by misterbrilliant with a video on Alexa's inability to get help. #+ATTR_HTML: :alt Steve: Alexa, I need medical assistance immediately. Alexa: I added medical assistance immediately to your shopping list. #+ATTR_HTML: :align center :width 582 [[tsfile:2016-11-04T12.06 Twitter.com - misterbrilliant - alexa help me i'm hurt -- fun cloud screenshots publicvoit.png][https://twitter.com/misterbrilliant/status/794495951113220096]] - 2022-10: Health data got stolen from [[https://en.wikipedia.org/wiki/Medibank][Medibank]] (3.7 million customers) and was used for blackmailing Medibank for publishing data of its 1000 most prominent customers. ([[https://www.smh.com.au/technology/medibank-hackers-threaten-to-release-stolen-health-data-in-ransom-demand-20221019-p5br2s.html][smh.com.au]]) - 2022-05: Twitter has been [[https://www.justice.gov/opa/pr/twitter-agrees-doj-and-ftc-pay-150-million-civil-penalty-and-implement-comprehensive][fined $150 million]] after it used phone numbers submitted by users to set up two-factor authentication… for targeted advertising. ([[https://grahamcluley.com/twitter-2fa-phone-number-advertising/][grahamcluley.com]]) - 2020-03: Report shows that companies are exposing sensitive data with and without noticing more and more. ([[https://www.mcafee.com/enterprise/en-us/assets/reports/restricted/rp-enterprise-supernova-data-dispersion.pdf][PDF: McAfee report]]) - 2020-01: Grindr and OkCupid Spread Personal Details, Study Says. ([[https://www.nytimes.com/2020/01/13/technology/grindr-apps-dating-data-tracking.html][NY Times]]) - 2019-11: Facebook had an open hole via their API. ([[https://developers.facebook.com/blog/post/2019/11/05/changes-groups-api-access/?_fb_noscript=1][Facebook's announcement of the fix]]) - 2019-03: Millions of online photos scraped without consent. ([[https://www.nbcnews.com/tech/internet/facial-recognition-s-dirty-little-secret-millions-online-photos-scraped-n981921][NBC News]]) - 2018-12: Internal documents show that [Facebook] gave Microsoft, Amazon, Spotify and others far greater access to people’s data than it has disclosed. ([[https://www.nytimes.com/2018/12/18/technology/facebook-privacy.html][NY Times]]) - 2018-12: Amazon reveals private Alexa voice data files. ([[https://www.heise.de/newsticker/meldung/Amazon-reveals-private-voice-data-files-4256015.html][heise]]) - 2018-08: Google found the perfect way to link online ads to store purchases: credit card data. ([[https://www.bloomberg.com/news/articles/2018-08-30/google-and-mastercard-cut-a-secret-ad-deal-to-track-retail-sales][Bloomberg]]) - 2018-03: Tweet on Zuckerberg's answer to the question "How do you know there are no hundreds of firms like [[https://en.wikipedia.org/wiki/Cambridge_Analytica][Cambridge Analytica]]?". ([[https://twitter.com/evgenymorozov/status/976626947181641729][Tweet]], [[https://money.cnn.com/2018/03/21/technology/mark-zuckerberg-cnn-interview-transcript/index.html][referred CNN interview]]) - 2018-03: Microsoft prevents users from using bad language from their services. ([[https://www.heise.de/newsticker/meldung/Porno-und-Hassfilter-Microsoft-verbannt-anstoessige-Sprache-aus-Online-Diensten-4006462.html?wt_mc=rss.ho.beitrag.atom][German heise]]) - 2018-02: Is it ethically OK to participate in review sites at all? (Spoiler: Yeah, sometimes, but definitely not on Google Maps.) ([[https://www.tbray.org/ongoing/When/201x/2018/02/26/Reviewing-Ethics][Tim Bray blog]]) - 2018-01: US military bases are clearly identifiable and mappable within public [[https://en.wikipedia.org/wiki/Strava][Strava]] data. ([[https://twitter.com/Nrg8000/status/957318498102865920][Tweet]]) - 2017-12: Microsoft "Dynamics 365" endangered private keys of customers and first denies that there is a problem. ([[https://www.golem.de/news/microsoft-dynamics-365-wildcard-certificate-with-a-private-key-for-everyone-1712-131544.html][golem]]) - 2016-07: Data-journalist Marco Maas has 130 smart home devices that send 600MB of data back home each single day. ([[https://www.heise.de/newsticker/meldung/Smart-Home-Pionier-Ich-kann-die-Leute-im-Haushalt-komplett-ueberwachen-3274071.html][German heise]]) - 2016-07: A Michigan man can’t sue Pandora for violating his privacy by publicly disclosing his musical preferences on social media because the service is free. ([[https://eu.freep.com/story/news/local/michigan/2016/07/06/michigan-man-cant-sue-pandora-divulging-his-tastes/86773794/][eu.freep.com]]) - 2012-12: Xkcd comic on people's expectations of using services for free. ([[https://xkcd.com/1150/][Comic]], [[https://www.explainxkcd.com/wiki/index.php/1150][Explanation]]) You can't be sure of any *malicious employee* who is *mis-using or leaking data*. Employees sell sensitive data. - 2019-11: Twitter employees selling sensitive data. ([[https://www.heise.de/downloads/18/2/7/8/4/0/7/9/Saudi_Twitter-Spies.pdf][PDF: Criminal Complaint at US District Court]]) - 2017-12: Virtual keyboard developer leaked 31 million of client records. ([[https://kromtech.com/blog/security-center/virtual-keyboard-developer-leaked-31-million-of-client-records][kromtech.com]]) - 2017-06: China arrests 22 over sale of Apple private data. ([[https://www.scmp.com/news/china/society/article/2097487/chinese-apple-staff-suspected-selling-personal-data][scmp.com]]) - 2016-12: Uber said it protects you from spying. Security sources say otherwise. ([[https://www.revealnews.org/article/uber-said-it-protects-you-from-spying-security-sources-say-otherwise/][revealnews.org]]) - 2015-05: FBI arrests JP Morgan Chase former employee for selling account data. ([[https://nakedsecurity.sophos.com/2015/05/01/fbi-arrests-jp-morgan-chase-former-employee-for-selling-account-data/][nakedsecurity.sophos.com]]) - 2015-04: AT&T fined $25 million after call center employees stole customers’ data. ([[https://arstechnica.com/tech-policy/2015/04/att-fined-25-million-after-call-center-employees-stole-customers-data/][arstechnica]]) - 2014-08: Amtrak employee sold customer data to DEA for two decades. ([[https://arstechnica.com/tech-policy/2014/08/amtrak-employee-sold-customer-data-to-dea-for-two-decades/][arstechnica]]) *** Inability To Delete If you delete data in your cloud, *nothing gets deleted* for real. Truth is, the cloud vendor disables your access permission. Therefore, "deleted" data is used in the background and even re-appears from time to time. - 2017-01: Deleted Dropbox folder re appeared after a couple of years. ([[https://www.dropboxforum.com/t5/Dropbox-files-folders/deleted-folder-re-appeared-after-a-couple-of-years/td-p/202656][dropboxforum.com]]) - 2014-09: Data you serve up to the cloud can be stored out there indefinitely, no matter how hard to try to delete it. ([[https://www.red-gate.com/simple-talk/cloud/cloud-data/deleting-files-in-the-cloud/][red-gate.com]]) - 2010-04: Facebook does not erase user-deleted content. ([[https://www.zdnet.com/article/facebook-does-not-erase-user-deleted-content/][zdnet.com]]) *** Losing (Access to) Your Data You can't be sure that you don't get *locked out of your own data*. This fortunate People got locked out of their own cloud infrastructure. Sometimes you get locked out of your house. You even can get locked out from your cloud-connected shoes. Sometimes, your ISP is threatening to turn off your heating when you are using the Internet in a way they don't like. Politics can lock you out of your rented cloud-driven software products. Somebody is probably able to kill your pet over the Internet. Whole companies go offline when your cloud vendor wants. You can't be sure that even *cloud vendors are losing data*. - 2023-08: [[https://cloudnordic.com/][CloudNordic]] lost all customer data including backups for good after ransomware attack. ([[https://www.theregister.com/2023/08/23/ransomware_wipes_cloudnordic/][The Register]], [[https://www.heise.de/news/Ransomware-Angriff-Alle-Daten-bei-CloudNordic-futsch-9282877.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-07: reddit lost all chat messages before 2023 in a migration process. ([[https://www.reddit.com/r/reddit/comments/14gb7xy/changelog_chat_and_flair_navigation_updates/][reddit]], [[https://www.heise.de/news/Reddit-Chathistorie-von-vor-2023-bei-Datenumzug-verloren-gegangen-9218302.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-06: Amazon customer gets wrongly accused of being rude and Amazon locks him out of his home devices. ([[https://medium.com/@bjax_/a-tale-of-unwanted-disruption-my-week-without-amazon-df1074e3818b][Medium]]) - 2022-08: A dad and his doctor both *lose their Google account and their cloud data* after they tried to take and exchange photos of physical illness. ([[https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html][NY Times]], [[https://www.heise.de/news/Nacktscanner-Unbedachte-Fotos-vom-Kind-fuer-den-Arzt-Google-Dienste-gesperrt-7238900.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - Never use cloud services to backup your data. Use self-hosted services like [[https://syncthing.net/][Syncthing]] which is easy to set up. - 2022-07: Sony’s PlayStation Store Pulling Access to Purchased Studiocanal Movies. ([[https://variety.com/2022/digital/news/playstation-store-pulling-access-to-purchased-studiocanal-movies-next-month-1235310863/][Variety]], [[https://www.heise.de/news/Playstation-Store-Sony-loescht-gekaufte-Filme-aus-der-Bibliothek-7166332.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-04: Smart-home company Insteon shuts down servers without warning leaving users with broken smart home setups. ([[https://www.pcmag.com/news/smart-home-company-insteon-shuts-down-servers-without-warning][PCmag]]) - 2022-04: After pushing customers to their cloud solution, Altlassian deleted data of approx. 400 customers and takes weeks to restore ([[https://www.atlassian.com/engineering/april-2022-outage-update][Atlassian]], [[https://www.heise.de/news/Atlassian-Schlechte-Team-Absprache-und-falsches-Skript-schuld-an-Cloud-Ausfall-6670841.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-03: *Google disables tens of millions of accounts* every year without warning, giving the recipient a reason why, or providing a way to get it back. ([[https://nextcloud.com/blog/big-tech-accountability/][nextcloud.com]]) - 2021-12: Amazon AWS us-east-1 down for seven hours ([[https://news.ycombinator.com/item?id=29473630][HN]], [[https://www.heise.de/news/Amazons-AWS-Cloud-faellt-aus-und-die-IT-Welt-steht-nicht-still-6289722.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2021-12: "Do not get too attached to your Apple account; it belongs to Apple, NOT YOU!" ([[https://merecivilian.com/apple-broke-up-with-me/][merecivilian.com]]) - 2021-11: Tesla drivers can't use their car because Tesla's servers were down ([[https://www.bbc.com/news/technology-59357306][BBC]]) - 2021-10: The whole Facebook ecosystem is dowon for six hours, affecting thousands of other services ([[https://engineering.fb.com/2021/10/04/networking-traffic/outage/][engineering.fb.com]]) - 2021-07: All backups of WD MyBook Live worldwide are gone ([[https://arstechnica.com/gadgets/2021/06/mass-data-wipe-in-my-book-devices-prompts-warning-from-western-digital/][arstechnica]]) - 2021-01: Losing access to your penis: malware that locks IoT male chastity devices ([[https://securityreport.com/source-code-revealed-for-malware-targeting-iot-male-chastity-devices/][securityreport.com]]) - 2020-01: What you lose when you get the "Your account has been suspended" email from Google. ([[https://www.kylepiira.com/2020/01/09/why-i-quit-google/][kylepiira.com]]) - 2019-10: Vendor of "Nello One" cloud-connected lock bankruptcy turns all products into expensive trash. ([[https://www.heise.de/newsticker/meldung/Smarter-Tueroeffner-Nello-Ab-18-Oktober-ohne-Funktion-4545084.html?wt_mc=rss.ho.beitrag.atom][German heise]]) - 2019-10: Cloud-connected animal feeders might kill your pets. ([[https://t.me/theyforcedme/1586][Russian source]], [[https://tinyurl.com/yd98earf][Google translation]]) - 2019-10: Adobe is *cutting off users in Venezuela* due to US sanctions. ([[https://www.theverge.com/2019/10/7/20904030/adobe-venezuela-photoshop-behance-us-sanctions][theverge.com]], [[https://helpx.adobe.com/x-productkb/policy-pricing/executive-order-venezuela.html][Adobe notification]]) - 2019-07: For an entire afternoon and into the night, Google’s cloud was broken. ([[https://www.wired.com/story/google-cloud-outage-catch-22/][wired]]) - 2019-02: Nike just bricked its $350 app-connected Adapt BB self-tying shoes by accident. ([[https://mashable.com/article/nike-app-connected-shoe-bricked/?europe=true#3GUgsANursqb][mashable]]) - 2019-01: Telekom Entertain 303 Media Receiver got deprecated, accessing the personal, locally stored video recordings of many years is no longer possible for all customers. The video data is proprietary encoded and can not be converted. ([[https://www.telekom.com/de/konzern/details/magentatv-loest-entertain-ab-558808][German Telekom]]) - 2018-05: *Google took down a whole company* that uses G Suite because one single employee was mis-using his personal Android phone. ([[https://www.reddit.com/r/tifu/comments/8kvias/tifu_by_getting_google_to_ban_our_entire_company/][Reddit comment]]) - 2018-01: Don’t pirate or we’ll mess with your Nest, warns East Coast ISP. ([[https://www.engadget.com/2018-01-05-pirates-risk-being-left-in-the-cold.html][engadget]]) - 2017-08: Cloud-connected lock vendor accidentally bricks hundreds of locks through a failed firmware update. ([[https://www.techspot.com/news/70588-lockstate-accidentally-bricks-hundreds-locks-through-failed-firmware.html][techspot]], [[https://marketing.lockstate.com/acton/rif/18500/s-016e-1708/-/l-00fd:3d3/l-00fd/showPreparedMessage?utm_term=Click%20here&utm_campaign=UPDATE%20LockState%206i%2F6000i%20Issue&utm_content=email&utm_source=Act-On+Software&utm_medium=email&cm_mmc=Act-On%20Software-_-email-_-UPDATE%20LockState%206i%2F6000i%20Issue-_-Click%20here&sid=TV2:3iibu2UNq][Vendor notice]]) - 2017-02: GitLab melts down after wrong directory deleted, backups fail. ([[https://www.theregister.com/2017/02/01/gitlab_data_loss/][theregister.com]]) - 2016-07: Google deletes artist's blog and a decade of his work along with it. ([[https://splinternews.com/google-deletes-artists-blog-and-a-decade-of-his-work-al-1793860234][splinternews.com]]) - 2014-05: Owners of Apple devices across Australia are having them digitally held for ransom by hackers demanding payment before they will relinquish control. ([[https://www.smh.com.au/technology/australian-apple-idevices-hijacked-held-to-ransom-20140527-zrpbj.html][smh.com.au]]) - 2014-01: Gmail bug made some users accidentally delete emails. ([[https://www.theverge.com/2014/1/28/5355818/gmail-bug-made-some-users-accidentally-delete-emails][theverge.com]]) - 2013-07: Dilbert comic on the realistic scenario of losing a complete data-center. ([[https://dilbert.com/strip/2013-07-05][Dilbert]]) - 2013-04: How getting locked out of Gmail made me kick the Google habit. ([[https://asabharwal.com/how-getting-locked-out-of-gmail-made-me-kick-the-google-habit/][asabharwal.com]]) - 2012-08: "In the space of one hour, my entire digital life was destroyed." Hackers used cloud accounts to remotely erase all of the data on iPhone, iPad, and MacBook. ([[https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/][wired]]) - 2012-02: Microsoft's Azure cloud down and out for 8 hours. ([[https://www.theregister.com/2012/02/29/windows_azure_outage/][theregister.com]]) #+CAPTION: Tweet: @GitHubHelp, you blocked our entire company account after one employee opened his laptop while visiting is parents in Iran. We are completely blocked from deploying! #+ATTR_HTML: :align center :width 542 :linked-image-width none [[tsfile:2023-07-29T22.14.39 Twitter - GitHub blocked entire company account -- screenshots publicvoit cloud.png][https://twitter.com/sebslomski/status/1344219609923276801?s=20]] *** (Good) Cloud Providers Turning Bad You can't be sure that the *business model* of your cloud vendor is *changing* so that they *act differently* compared to past statements. Sometimes your cloud vendor gets bought by a bigger fish. Or he is deciding to share your private data with others without your consent. Or he is introducing "quality of service" to storage performance which drags you down in production stage. Governments are beginning to sell sensitive data for profit as well. #+CAPTION: Tweet by QuinnyPig about the trustworthiness of Google's cloud availability. #+ATTR_HTML: :alt If I ever get to interview a Google Cloud exec, I have one question: "Why should we trust Google Cloud to stick around? After all, you killed Reader, Plus, Inbox..." *seven minutes elapse* "...Allo, Glass--excuse me, don't interrupt. I'm not done. iGoogle, Video, and Buzz?" #+ATTR_HTML: :align center :width 584 [[tsfile:2019-04-30T17.35 Twitter.com - QuinnyPig - If I ever get to interview a Google Cloud exec - Why should we trust Google Cloud to stick around -- cloud google screenshots publicvoit.png][https://twitter.com/QuinnyPig/status/1123249401672105985]] Even your cloud-connected vacuum cleaner is *selling information* on your home to the highest bidder. Or it is providing a perfectly fine spying tool for the bad guys. Or it simply opens your door for the bad guys. # #+CAPTION: Tweet by me on Google's change in their motto. # #+ATTR_HTML: :alt #Google has optimized their unofficial motto «Don't be #evil» by silently removing a word. Guess which one? #surveillance #privacy # #+ATTR_HTML: :align center :width 594 # [[tsfile:2016-10-21T23.17 Twitter.com - n0v0id - Google has optimized their unofficial motto Don't be evil by silently removing a word -- google cloud screenshots publicvoit.png][https://twitter.com/n0v0id/status/789576428761350144]] Furthermore, there is always the possibility of cloud vendor employees, who give away your data to interested parties as happened with Twitter 2022-12 ([[https://www.heise.de/news/Twitter-Spion-zu-42-Monaten-Haft-verurteilt-7396796.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]). You have to trust every employee who has access to your data. All of them. Do you? - 2022-08: Apple Is Tracking You Even When Its Own Privacy Settings Say It’s Not, New Research Says ([[https://gizmodo.com/apple-iphone-analytics-tracking-even-when-off-app-store-1849757558][gizmodo]]) - 2022-05: Google stops all 3rd party apps from accessing GMail unless they pay for an expensive audit for each version ([[http://www.pmail.com/newsflash.htm][pmail.com]]) - 2021-01: [[https://flo.health/][Flo health]] sells sensitive health data like pregnancies of its customers ([[https://www.heise.de/downloads/18/3/0/3/8/0/8/4/flo_health_order.pdf][Court Agreement PDF]]) - 2020-01: Everalbum processes uploaded user photographs with face detection against their will ([[https://www.heise.de/downloads/18/3/0/3/8/0/8/4/everalbum_order.pdf][Court Agreement PDF]]) - 2020-12: Google acquires Fitbit, getting all of its sensitive customer health data ([[https://ec.europa.eu/commission/presscorner/detail/en/ip_20_2484][European Commission]]) - 2020-10: Zoom said since 2016 it offered “end-to-end, 256-bit encryption” which was a total lie. ([[https://www.ftc.gov/news-events/press-releases/2020/11/ftc-requires-zoom-enhance-its-security-practices-part-settlement][ftc.gov]]) - 2020-07: A so-called "Non-logging VPN provider" leaked massive logs of its 20 Million users including "plain text passwords and information that could be used to identify VPN users and track their online activity". ([[https://www.comparitech.com/blog/vpn-privacy/ufo-vpn-data-exposure/][comparitech.com]]) - 2017-11: Australian coalition could allow firms to buy access to facial recognition data. ([[https://www.theguardian.com/technology/2017/nov/26/government-could-allow-firms-to-buy-access-to-facial-recognition-data][theguardian.com]]) - 2017-11: Amazon Key Flaw Could Let Rogue Deliverymen Disable Your Camera. ([[https://www.wired.com/story/amazon-key-flaw-let-deliverymen-disable-your-camera/][wired]]) - 2017-10: Vulnerability in LG's smart home infrastructure exposing it to critical house systems takeover. ([[https://www.youtube.com/watch?v=BnAHfZWPaCs][Video]]) - 2017-07: Roomba's next big step is selling maps of your home to the highest bidder. ([[https://gizmodo.com/roombas-next-big-step-is-selling-maps-of-your-home-to-t-1797187829][gizmodo]]) - 2017-06: Docker operations slowing down on AWS on purpose. ([[https://jeremyeder.com/2017/07/25/docker-operations-slowing-down-on-aws-this-time-its-not-dns/][jeremyeder.com]]) - 2016-10: LinkedIn accesses Gmail contacts via "auto-authorization". ([[https://thestack.com/security/2016/10/06/linkedin-accesses-gmail-contacts-via-auto-authorization/][Original article (offline as of 2020-06-05)]], [[https://news.ycombinator.com/item?id=12769494][hacker news thread]]) - 2016-10: Google has quietly dropped ban on personally identifiable web tracking. ([[https://www.propublica.org/article/google-has-quietly-dropped-ban-on-personally-identifiable-web-tracking][propublica.org]]) - 2016-01: [[id:2016-01-09-university-and-cloud][My blog article on an education platform that got bought and fired our university]]. - 2016-01: Del.icio.us taken over and changes business model. ([[https://techcrunch.com/2016/01/12/delicious-former-web-2-0-darling-is-now-managed-by-new-alliance-rolls-back-most-recent-changes/?guccounter=1][techcrunch.com]]) - 2015-03: Bankrupt Radio Shack will sell the customer data they promised to keep private. ([[https://boingboing.net/2015/03/25/bankrupt-radio-shack-will-sell.html][boingboing.net]]) #+BEGIN_QUOTE My favorite analogy here is the old sex education trope "wear a condom or you are exposed to all of the [[https://en.wikipedia.org/wiki/Sexually_transmitted_infection][STDs]] of all of your partner's partners". Only in the cloud, the arrow of time is reversed. Everything you share you have to trust the company to steward, and not just the company as currently constituted, but all future versions, ownerships, partners and employees of the company. /[[https://news.ycombinator.com/user?id=truffdog][truffdog]] on [[https://news.ycombinator.com/item?id=31630722][HN]]/ #+END_QUOTE *** You're the Product Your *privacy* is of no concern for cloud companies. They don't care about the security of your data at all. Cloud vendors are even willingly hurting your privacy or health. Many times, your data gets public because of a simple error. Also passwords. Even kids toys become spyware. You don't have any idea on how manipulated cloud data is used to do *psychological experiments* with you. - 2020-03: Internet-connected smart-TVs are spying: Samsung and others ([[https://www.flatpanelshd.com/news.php?subaction=showfull&id=1583755244][flatpanelshd.com]]) - 2019-05: Google stored G Suite passwords in an insecure way. ([[https://cloud.google.com/blog/products/g-suite/notifying-administrators-about-unhashed-password-storage][Google notification]]) - 2019-05: A Twitter iOS bug enabled collection and sharing of location data. ([[https://help.twitter.com/en/location-data-collection][Twitter notification]], [[https://www.dailymail.co.uk/sciencetech/article-7025065/Twitter-apologises-sharing-iOS-location-data.html][dailymail.co.uk]]) - 2018-03: Facebook accepts the risk of enabling terror attacks and causing deaths. ([[https://www.buzzfeednews.com/article/ryanmac/growth-at-any-cost-top-facebook-executive-defended-data][buzzfeednews.com]]) - 2017-02: Data from connected CloudPets teddy bears leaked and ransomed, exposing kids' voice messages. ([[https://www.troyhunt.com/data-from-connected-cloudpets-teddy-bears-leaked-and-ransomed-exposing-kids-voice-messages/][troyhunt.com]]) - 2017-02: Cloudflare reverse proxies are dumping uninitialized memory, leaking arbitrary customer data. ([[https://bugs.chromium.org/p/project-zero/issues/detail?id=1139][chromium.org]]) - 2017-02: Vizio televisions spied on 11 million TV sets since 2010. ([[https://www.ftc.gov/news-events/blogs/business-blog/2017/02/what-vizio-was-doing-behind-tv-screen][ftc.gov]]) - 2016-12: German Telekom provided access to address book entries of other business customers. ([[https://www.heise.de/security/meldung/Datenleck-in-der-Telekom-Cloud-ermoeglicht-Zugriff-auf-fremde-Adressbuecher-3564967.html][German heise]]) - 2016-11: AppleCare leaks secret phone numbers of high-ranked politicians and police persons. ([[https://www.heise.de/newsticker/meldung/Datenpanne-Wenn-das-iPhone-die-Geheimnummer-der-Nationalratspraesidentin-kennt-3454575.html][German heise]]) - 2016-07: Cloud-connected fittness-tracker give away your data. ([[https://www.av-test.org/de/news/7-fitness-armbaender-und-die-apple-watch-im-security-check-2016/][German av-test.org]]) - 2016-01: Chinese authorities had hacked into Hotmail email accounts, targeting minorities in particular. *Microsoft decided not to tell the victims*. ([[https://www.reuters.com/article/us-microsoft-china-insight-idUSKBN0UE01Z20160101][Reuters]]) - 2014-06: Research: Experimental evidence of massive-scale emotional contagion through social networks. ([[https://www.pnas.org/content/111/24/8788.full][Paper]]) *** Inability to Control What Goes into the Cloud You don't even know *what data is really uploaded* to the cloud. And if you put documents in the cloud, you can never be sure if others can access it or not. Or how your data is processed and re-used by others. - 2024-03: USA considers Chinese cars with [[https://www.wired.com/story/tesla-surveillance-detection-scout/][recording and surveillance features]] as a threat and China does this for Tesla, locks them out of sensitive areas of national security. ([[https://www.heise.de/news/USA-erkennen-vernetzte-Autos-als-Risiko-fuer-Nationale-Sicherheit-und-Frauen-9643125.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-11: Biometrical/personal Aadhaar data of *815 Million Indian residents* are for sale after being stolen (again?). ([[https://www.resecurity.com/blog/article/pii-belonging-to-indian-citizens-including-their-aadhaar-ids-offered-for-sale-on-the-dark-web][resecurity.com]], [[https://www.heise.de/news/Nach-mutmasslichem-Leak-persoenliche-Daten-von-bis-zu-815-Millionen-Indern-publik-9349952.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-09: Microsoft accidentially published secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages via Azure and GitHub. ([[https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers][wiz.io]], [[https://www.heise.de/news/Datenleck-Microsofts-KI-Team-stellt-38-Terabyte-ins-Netz-9309303.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - "SAS tokens pose a security risk, and their usage should be as limited as possible." - 2023-09: Users of Google Authenticator ([[https://en.wikipedia.org/wiki/Time-based_one-time_password][TOTP]]) were not aware that their secrets are copied to the cloud. Guess what happened next. ([[https://retool.com/blog/mfa-isnt-mfa/][retool.com]]) - 2023-01: Photographs of people on the toilet and similar were collected and given away by Roomba. Roomba says that customers agreed. ([[https://www.heise.de/hintergrund/Roomba-Wie-private-Fotos-eines-Staubsauger-Roboters-auf-Facebook-landen-koennen-7457283.html?seite=all][German heise]]) - 2023-01: Representative for many cloud services: Adobe is using your content for their purposes: all of your pictures may be processed and used. ([[https://helpx.adobe.com/manage-account/using/machine-learning-faq.html][Adobe content analysis FAQ]], [[https://tinyurl.com/kzxy6r7u][archived version from 2023-01-05]], [[https://www.heise.de/news/Einstellungssache-Adobe-trainiert-Algorithmen-mit-Nutzerdaten-aus-der-Cloud-7451861.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-12: Anker’s Eufy lied about the security of its security cameras, sending personal data to the cloud. ([[https://www.theverge.com/2022/11/30/23486753/anker-eufy-security-camera-cloud-private-encryption-authentication-storage][theverge.com]], [[https://www.heise.de/news/Eufys-Kameras-funken-ungefragt-in-die-Cloud-und-sind-per-Web-zugaenglich-7358310.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2022-08: Apple Is Tracking You Even When Its Own Privacy Settings Say It’s Not, New Research Says ([[https://gizmodo.com/apple-iphone-analytics-tracking-even-when-off-app-store-1849757558][gizmodo]]) - 2022-11: Apple Says Your iPhone's Usage Data is Anonymous, but New Tests Say That's Not True ([[https://gizmodo.com/apple-iphone-privacy-dsid-analytics-personal-data-test-1849807619][gizmodo]]) - 2022-10: Key to access personal data of 290,000 Toyota customers was public for five years ([[https://www.heise.de/news/Datenpanne-bei-Toyota-Schluessel-zu-Kundendaten-fuenf-Jahre-oeffentlich-zugaenglich-7304741.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]], [[https://global.toyota/jp/newsroom/corporate/38095972.html][Japenese source]]) - 2021-05: US soldiers expose nuclear bomb process and facility details on learning platforms. ([[https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/][Bellingcat]]) - 2020-01: A home security technician observes sex of customers via their security cameras. ([[https://arstechnica.com/information-technology/2021/01/home-alarm-tech-backdoored-security-cameras-to-spy-on-customers-having-sex/][arstechnica]]) - 2020-08: You can no longer operate Oculus devices without a Facebook account. ([[https://www.oculus.com/blog/a-single-way-to-log-into-oculus-and-unlock-social-features/?_fb_noscript=1][oculus.com]]) - 2020-08: Google Home devices record every word and sound without your permission or authorization. ([[https://www.protocol.com/google-smart-speaker-alarm-adt][protocol.com]]) - 2020-04: Apple transferred call logs to their cloud without telling the users. ([[https://www.golem.de/news/anrufprotokoll-apple-stoppt-undokumentierte-synchronisation-mit-der-icloud-2004-147693.html][German golem]] with links to various original sources) - 2020-02: IBM report: In 2019 alone, *8.5 billion data-sets* were stolen and used against businesses. ([[https://newsroom.ibm.com/2020-02-11-IBM-X-Force-Stolen-Credentials-and-Vulnerabilities-Weaponized-Against-Businesses-in-2019][newsroom.ibm.com]]) - 2020-02: Clearview AI: Face-collecting company database hacked (3 billion images). ([[https://www.bbc.com/news/technology-51658111][BBC]]) - 2020-01: An *Avast antivirus* subsidiary sells 'Every search. Every click. Every buy. On every site.' (data from 100 million devices). ([[https://www.vice.com/en_us/article/qjdkq7/avast-antivirus-sells-user-browsing-data-investigation][Vice]]) - 2020-01: *250 million Microsoft customer service and support records* exposed on the web. ([[https://www.comparitech.com/blog/information-security/microsoft-customer-service-data-leak/][comparitech.com]]) - 2019-12: Facebook collects positional data despite disabled permission. ([[https://www.heise.de/newsticker/meldung/Trotz-Deaktivierung-Facebook-sammelt-Standorte-via-IP-Adressen-4619161.html][German heise]]) - 2019-10: FBI's use of surveillance database violated in tens of thousands of cases. ([[https://www.wsj.com/articles/fbis-use-of-foreign-surveillance-tool-violated-americans-privacy-rights-court-found-11570559882][wsj.com]]) - 2019-06: Database leaks data on most of Ecuador's citizens, including 6.7 million children. ([[https://www.zdnet.com/article/database-leaks-data-on-most-of-ecuadors-citizens-including-6-7-million-children/][zdnet.com]]) - 2018-09: Facebook: security issue affecting almost *50 million accounts*. ([[https://about.fb.com/news/2018/09/security-update/][about.fb.com]]) - 2018-08: Google tracks Android movements although users disabled it. ([[https://apnews.com/article/north-america-science-technology-business-ap-top-news-828aefab64d4411bac257a07c1af0ecb][apnews.com]], [[https://www.heise.de/news/Google-muss-fuer-Ortungs-Schwindel-nicht-einmal-400-Millionen-zahlen-7340069.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German report on the cheap penalty]]) - 2018-01: Data-breach of biometric data of *one billion Indians* by [[https://en.wikipedia.org/wiki/Aadhaar][Aadhaar]]. ([[https://www.tribuneindia.com/news/archive/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details-523361][tribuneindia.com]]) - 2017-12: A popular virtual keyboard app leaks *31 million users' personal data*. ([[https://www.zdnet.com/article/popular-virtual-keyboard-leaks-31-million-user-data/][zdnet.com]]) - 2017-07: Using anti-virus software to steal personal data. ([[https://github.com/SafeBreach-Labs/spacebin][Source code]]) - 2017-06: Sensitive personal details of *over 198 million American voters* was left exposed to the internet. ([[https://www.upguard.com/breaches/the-rnc-files][upguard.com]]) *** Losing Cloud Service You don't have any influence on whether or not cloud services are *discontinued* by big companies like Microsoft. Game over. Lights go black. Your TV set as well. Home automation is a potential risk in most cases. And if a service is not discontinued, it happens that years of data get lost somehow. [[https://www.reddit.com/r/technology/comments/b2381s/myspace_lost_all_music_uploaded_from_2003_to_2015/][Like twelve years of music files]]. Cloud-connected devices *destroy the internet* and become expensive junk. Don't be surprised: any cloud-dependent device is going to stop working sooner or later. Even expensive ones. Even *temporary down-times* of the cloud affect your life in many ways. #+CAPTION: Tweet by tcrawford with link to https://avoa.com/2017/07/18/why-are-enterprises-moving-away-from-public-cloud/ #+ATTR_HTML: :alt Thinking Public Cloud is “cheap” is a fallacy. I address some of the reasons why here: https://avoa.co/2tH9Aed #cloud #CIO #+ATTR_HTML: :align center :width 586 [[tsfile:2017-07-19T18.25 Twitter.com - tcrawford - Thinking Public Cloud is cheap is a fallacy -- cloud screenshots publicvoit.png][https://twitter.com/tcrawford/status/887710021789732864]] - 2022-05: Amazon permanently disables Cloud Cam which also had severe [[https://www.bloomberg.com/news/articles/2019-10-10/is-amazon-watching-you-cloud-cam-footage-reviewed-by-humans][privacy issues]], replacing with different products. ([[https://www.macrumors.com/2022/05/27/amazon-dropping-support-for-cloud-cam/][Macrumors]]) - 2022-05: Related: even implants may stop working for a variety of reasons including discontinued vendor support. ([[https://www.heise.de/hintergrund/Missing-Link-Unterschaetzte-Gefahr-Obsolete-Technik-im-Koerper-7074215.html?seite=all][German heise]]) - 2022-03: [[https://ourincrediblejourney.tumblr.com/][Our Incredible Journey]] collects some company acquisitions that led to services being discontinued. - 2020-10: Bought a security system from Google that [[https://www.businessinsider.com/nest-microphone-was-never-supposed-to-be-a-secret-2019-2?r=DE&IR=T?op=1&r=US&IR=T][turned out to be a potential spyware]]? Well, say good buy to it in 2020. ([[https://www.androidpolice.com/2020/10/19/google-confirms-the-nest-secure-has-been-discontinued/][androidpolice.com]]) - 2020-02: Downtime of: Gmail, Drive, Docs, Presentations, Sites, Groups, Chat, Meet, Notes and Voice. ([[https://www.google.com/appsstatus#hl=de&v=status][Google]]) - 2020-06: Wikipedia lists *78 entries* in the category of *discontinued* services and software *by Microsoft*. ([[https://en.wikipedia.org/wiki/Category:Discontinued_Microsoft_software][Wikipedia]]) - 2020-06: [[https://gcemetery.co/][The Google Cemetery - Dead Google products]] lists *166 discontinued Google services* - 2020-06: [[https://killedbygoogle.com/][Google Graveyard - Killed by Google]] lists *200 discontinued Google services* - 2020-03: *Azure appears to be full*: UK punters complain of capacity issues on Microsoft's cloud. ([[https://www.theregister.com/2020/03/24/azure_seems_to_be_full/][theregister.com]]) - 2019-12: Sonos announced a "Recycle Mode" which bricks old devices. ([[https://en.wikipedia.org/wiki/Sonos#Reception][Wikipedia]]) - 2019-03: *MySpace lost all music uploaded from 2003 to 2015*. ([[https://www.reddit.com/r/technology/comments/b2381s/myspace_lost_all_music_uploaded_from_2003_to_2015/][reddit]]) - 2019-01: World-wide downtimes of Microsoft Azure cloud. ([[https://www.heise.de/newsticker/meldung/Microsoft-nennt-Gruende-fuer-Cloud-Ausfaelle-4296544.html?wt_mc=rss.ho.beitrag.atom][German heise]]) - 2019-01: Microsoft accidentally deletes customer DBs. ([[https://www.theregister.com/2019/01/30/azure_sql_delete/][theregister.com]]) - 2018-11: Thousands of customers in Seoul are cut off from the Internet due to a fire. ([[http://koreatimes.co.kr/www/nation/2018/11/281_259269.html][koreatimes.co.kr]]) - 2018-03: Logitech is killing its Harmony Link service (smart remote) and the hardware will die with it. ([[https://www.popsci.com/logitech-harmony-link-dead/][popsci.com]]) - 2017-04: Cloud-connected devices can be bricked by PDoS attacks. ([[https://security.radware.com/ddos-threats-attacks/brickerbot-pdos-permanent-denial-of-service/][security.radware.com]]) - 2016-12: Google cloud print is *turning off Epson printers*. ([[https://www.pcmag.com/news/google-cloud-print-is-turning-off-epson-printers][PCmag]]) - 2016-10: [[id:2016-10-22-Unpatchable-IoT][Don't Buy and Run Cloud-Connected Devices That Are Un-Patchable]] - 2016-04: Google is intentionally *bricking Nest hardware*. ([[https://arlogilbert.com/the-time-that-tony-fadell-sold-me-a-container-of-hummus-cb0941c762c1?gi=e096a680d57d][arlogilbert.com]]) - 2016-01: DotCloud, the cloud service that gave birth to Docker, is shutting down. ([[https://venturebeat.com/2016/01/22/dotcloud-the-cloud-service-that-gave-birth-to-docker-is-shutting-down-on-february-29/][venturebeat.com]]) - 2015-12: Philips Locks Purchasers Out Of Third-Party Bulbs With Firmware Update. ([[https://www.techdirt.com/articles/20151214/07452133070/lightbulb-drm-philips-locks-purchasers-out-third-party-bulbs-with-firmware-update.shtml][techdirt.com]]) - 2015-12: LG Cloud TV app service got discontinued. ([[https://twitter.com/DavidCWG/status/686720545044299776][Screenshot on twitter]]) - 2015-11: Sony is ending support for the PlayStation Portable’s digital storefront. ([[https://www.digitaltrends.com/gaming/sony-ending-psp-store-support-in-2016/][digitaltrends.com]]) - 2014-04: Xkcd-comic that makes fun of Google's rigorous service killing strategy. ([[https://xkcd.com/1361/][Comic]], [[https://www.explainxkcd.com/wiki/index.php/1361][explanation/context]]) *** It's Not Always Bad Intention # TODO: Merge with "leaks" section? You cannot possibly have any idea how many *bugs or false configurations* are *exposing your data* to any third party. - 2023-12: Around 10,000 DNA datasets of Estonians got stolen. ([[https://www.heise.de/news/Estland-10-000-Menschen-von-Gendaten-Leak-betroffen-9577868.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - Please not that in case DNA analysis data gets stolen, this also affects *all* of their families and in parts all of their wider relatives because of strong DNA similarities within the same kin. - 2023-10: Imagine you're submitting your DNA sample to a company like [[https://www.23andme.com/][23andMe]] and then all of your data gets stolen including your DNA. It can't be more personal than that. ([[https://www.wired.com/story/23andme-credential-stuffing-data-stolen/][wired]]) - Please not that in case DNA analysis data gets stolen, this also affects *all* of their families and in parts all of their wider relatives because of strong DNA similarities within the same kin. - 2023-10: Reports of four Million published datasets of customers. ([[https://www.heise.de/news/23andme-Angeblich-Genanalyse-Daten-aus-Grossbritannien-und-Deutschland-geleakt-9339051.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-12: Data of 14,000 accounts and Millions of relatives were stolen ([[https://www.engadget.com/23andme-hackers-accessed-ancestry-information-from-thousands-of-customers-and-their-dna-relatives-205758731.html?src=rss&guccounter=2][engadget]], [[https://www.sec.gov/ix?doc=/Archives/edgar/data/1804591/000119312523287449/d242666d8ka.htm][US government]]) - 2023-12: "Hackers stole ancestry data of 6.9 million users, 23andMe finally confirmed" ([[https://arstechnica.com/tech-policy/2023/12/hackers-stole-ancestry-data-of-6-9-million-users-23andme-finally-confirmed/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social][arstechnica]]) - 2023-12: A German comment on why sharing DNA data with cloud services is a severe issue ([[https://www.heise.de/hintergrund/Warum-das-Teilen-von-Gendaten-ein-solches-Dilemma-ist-9576349.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2023-09: Microsoft Sharepoint allowed access to data with very primitive (and embarrassing) authentication bypass ([[https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-chain/][Starlabs]]) - 2022-10: Microsoft Azure: Sensitive Data of 65,000+ Entities in 111 Countries Leaked due to a Single Misconfigured Data Bucket ([[https://socradar.io/sensitive-data-of-65000-entities-in-111-countries-leaked-due-to-a-single-misconfigured-data-bucket/][socradar.io]], [[https://msrc-blog.microsoft.com/2022/10/19/investigation-regarding-misconfigured-microsoft-storage-location-2/][Microsoft statement]], [[https://blog.fefe.de/?ts=9dac1de7][German comment by fefe]]) - 2022-01: You get a copyright violation when storing files with content 1, 500, 833, 174, 285, 302, 186, 451, 336, 173, 266, 448, 289, 120, 643 or 556 on Google Drive ([[https://www.heise.de/news/Googles-Algorithmen-stufen-Ziffern-als-Copyright-Verletzung-ein-6338468.html][German heise]]) - 2021-11: Microsoft Azure account credentials were stored in plain-text and accessible to all AAD users ([[https://www.netspi.com/blog/technical/cloud-penetration-testing/azure-cloud-vulnerability-credmanifest/][netspi.com]], [[https://www.heise.de/news/Azure-Active-Directory-Sicherheitsluecke-entbloesst-private-Schluessel-6272248.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2021-09: Over half of all Microsoft Azure instances running Linux expose root access without authentification ([[https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution][wiz.io]], [[https://www.heise.de/news/OMIGOD-Kritische-Root-Luecke-bedroht-Azure-Kunden-mit-virtuellen-Linux-PCs-6192620.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag][German heise]]) - 2018-08: Abbyy OCR software dev exposes 200,000 customer documents. ([[https://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/][bleepingcomputer.com]]) - 2015-06: German security researchers find 56 Million data records lying unprotected in cloud back-end databases. ([[https://www.darkreading.com/application-security/web-app-developers-putting-millions-at-risk/d/d-id/1320720][darkreading.com]]) - Many, many network-connected cameras are insecure. ([[https://www.heise.de/security/meldung/SmartCam-Kritische-Sicherheitsluecken-in-Cloud-Anbindung-von-Samsung-IP-Kameras-3990242.html?wt_mc=rss.ho.beitrag.atom][German heise article on Samsung]], [[https://reolink.com/unsecured-ip-camera-list/][reolink.com: List of insecure webcams]], ...) *** Forced Insecurity by Law and Agencies The USA has laws forcing (cloud) providers to include *back-doors* that circumvent cryptographic protection. There are secret laws for secret agencies which force cloud vendors to secretly give away your information. International cloud vendors *ignore local legislation* that is here to protect your personal data. - 2022-09: US Military Bought Mass Monitoring Tool That Includes Internet Browsing, Email Data: "[it] covers over 90 percent of the world’s internet traffic" ([[https://www.vice.com/en/article/y3pnkw/us-military-bought-mass-monitoring-augury-team-cymru-browsing-email-data][Vice]]) - 2018-03: US CLOUD Act demands security backdoors. ([[https://www.eff.org/deeplinks/2018/03/new-backdoor-around-fourth-amendment-cloud-act][EFF]]) - 2015-02: NSA is making fun of US laws. ([[https://www.theatlantic.com/politics/archive/2015/02/the-nsas-director-of-civil-liberties-disavows-secret-law/385150/][The Atlantic]]) - 2014-04: US judge: forced access to emails on servers hosted by Microsoft. ([[https://web.archive.org/web/20190517095220/https://www.nysd.uscourts.gov/cases/show.php?db=special&id=398][PDF: Memorandum and order]]) - 2015-05: Secret law is a 'direct threat' to Americans' privacy, says NSA whistleblower. ([[https://www.zdnet.com/article/william-binney-nsa-whistleblower-executive-order/][ZDnet]]) - 2020-05: Senate votes to allow FBI to *look at your web browsing history without a warrant*. ([[https://www.vice.com/en_us/article/jgxxvk/senate-votes-to-allow-fbi-to-look-at-your-web-browsing-history-without-a-warrant][Vice]]) - 2018-09: GCHQ data collection regime violated human rights, court rules. ([[https://www.theguardian.com/uk-news/2018/sep/13/gchq-data-collection-violated-human-rights-strasbourg-court-rules][theguardian.com]]) - 2019-11: Federal court rules suspicionless searches of travelers’ phones and laptops unconstitutional. ([[https://www.eff.org/press/releases/federal-court-rules-suspicionless-searches-travelers-phones-and-laptops][EFF]]) *** No Such Thing as Anonymity There is no anonymity. *You can be identified* by the way you are doing videos, your hardware, your software configuration, your mouse movements, your geographical position, and so forth. - [[https://en.wikipedia.org/wiki/Device_fingerprint][Wikipedia: Device fingerprint]] - [[https://coveryourtracks.eff.org/][coveryourtracks]] - testing the uniqueness of your browser - 2021-09: Apple "App Tracking Transparency made no difference in the total number of active third-party trackers [...]" ([[https://blog.lockdownprivacy.com/2021/09/22/study-effectiveness-of-apples-app-tracking-transparency.html][blog.lockdownprivacy.com]]) - 2021-03: [[https://www.nature.com/articles/s42003-021-01824-9][Using smart speakers to contactlessly monitor heart rhythms]] + [[https://www.technologyreview.com/2019/06/27/238884/the-pentagon-has-a-laser-that-can-identify-people-from-a-distanceby-their-heartbeat/][Pentagon is able to identify people using their heart rhythms]] - 2014-11: "We show that camera motion, as can be computed from the egocentric video, provides unique identity information. The photographer can be reliably recognized from a few seconds of video captured when walking." ([[https://arxiv.org/abs/1411.7591][Paper]]) - 2014-10: Whisper app tracks anonymous users. ([[https://www.theguardian.com/world/2014/oct/16/-sp-revealed-whisper-app-tracking-users][theguardian.com]]) - 2007-05: Mouse Movements Biometric Identification. ([[csis.pace.edu/~ctappert/srd2007/c2.pdf][PDF: research paper]]) *** What To Do About It? If you're still thinking of using public cloud services for your data, [[id:2020-09-29-cloud-data-conditions][make sure to read about the conditions to do so you should be aware of]]. There is *no "undo"* here. Once your data is out, your role in controlling this game is over. [[http://cacm.acm.org/magazines/2013/6/164609-resolved-the-internet-is-no-place-for-critical-infrastructure/abstract][Outsourcing security has it's price]] whose currency is not Euros or Dollars but loss of privacy, control, and to its final degree: security. [[http://reclaim.fm/][Reclaim]] you digital life. Follow my postings on this blog and on Twitter - I am trying my best to [[https://www.youtube.com/watch?v=QOEMv0S8AcA][stay independent]] and to own my own data. [[https://en.wikipedia.org/wiki/Nothing_to_hide_argument][You've got something to hide]] - even when you are not aware of it. And that's nothing that anybody is allowed to hold against you. #+BEGIN_QUOTE Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say. [[https://www.reddit.com/r/IAmA/comments/36ru89/just_days_left_to_kill_mass_surveillance_under/][Edward Snowden]] #+END_QUOTE So in case someone tells you that he is pretty witty to let a cloud vendor host his data "because it's more secure", you can reply to this argument that the NSA has also a one of the biggest military grade cloud full of data scraped from your personal (cloud) data. Not against terrorism. Not at all: The [[https://www.theguardian.com/world/2013/jul/31/nsa-top-secret-program-online-data][leaked NSA selectors are not reflecting any focus on terror-related data]]. So much for this red herring. "Hosting" your very private data there is nothing you're going to enjoy. As any cloud vendor, [[https://medium.com/@jeffgould/courts-docs-show-how-google-slices-users-into-millions-of-buckets-ec9c768b6ae9][they now more about you than you might think of]]: your [[http://motherboard.vice.com/read/your-porn-is-watching-you][porn profile]], you health history including all of your past, present and future diseases, what you're thinking about politics, products, [[http://www.pnas.org/content/112/4/1036][people]], or anything else, you whole set of social contacts, your wife and your secret girlfriend as well, and so on, and so on. Still don't care whether or not data like this gets exposed, archived, or leaked without your control? *** Similar Pages for Different Topics :PROPERTIES: :END: Here are more curated pages that collect incidents and events for various topics: - [[https://mjtsai.com/blog/tag/rejection/][Michael Tsai - Blog - Tag - App Store Rejection]] - [[https://web3isgoinggreat.com/][Web3 is Going Just Great]] Drop me a line if you know more pages like that.