Control your own privacy

November 2016 Information Security

Whether you know it or not, or whether you care or not, everything you do online is being tracked. What’s more, it’s not some evil NSA-type spy agency checking up on what naughty pictures you’re downloading (they have the technology to know everything about you no matter what you do), but it is hundreds and thousands of companies collecting bits of information to form a profile of you to sell to advertisers – and a few criminal syndicates.

Running an ad blocker or tracker blocker like Ghostery or a number of other freely available browser extensions will often shock you with the number of ‘things’ that are trying to track you. Of course these trackers come in different guises depending on what they want to do. Some are advertising trackers, some are used by website owners to get analytics on who comes to their sites and does what while there, others belong to Facebook and Twitter and endless other social media sites in the guise of a ‘share’ button, and so the list goes on.

Then there are the infamous ‘cookies’. These are little bits of information websites write to your hard drive that can contain almost any information to give the site more information about you. Some cookies are useful. For example, if you log into Gmail, cookies installed on your hard drive will ensure you can keep opening Gmail without having to log on every time – assuming you don’t physically log out when you’re done checking mails. The same applies to Facebook and other sites.

For example, if you go to securitysa.com, you will find two trackers, one to serve advertising and one to collect Google Analytics information. You will also see there are 36 cookies associated with the site. (Don’t ask me what they are for, I just discovered them.) On the Hi-Tech Security Solutions’ site, this data is harmless; we control our own adverts so we know what you will see.

Other sites subscribe to advertising companies who display any adverts to people coming to their web properties, which is why these companies want as much information about you as possible – the more they know about you the more they believe they can feed you adverts you are interested in and are more likely to click on (which is when they make their money). There have been many cases where adverts have served malware which in turn infected people’s machines.

It’s worth noting that not every advertising company serves up malware-laced adverts. The vast majority try to show you things you are interested in so they can make a few cents, but the bad guys do slip through.

Other, more sinister types of cookie are known as Flash cookies or Local Share Objects (LSOs). These are cookies that can remain on your hard drive for as long as the people who put them there want. They are put there by sites running Adobe’s Flash, and can be read by sites running Flash, which has been the go to technology for online video for a long time – although this is changing – as well as adverts. While normal cookies (HTTP cookies) are small in size, LSOs can be much larger and therefore contain much more information about you.

Easy-ish to solve

Dealing with these trackers and cookies is actually not that hard. One solution is to delete your browser cache, especially the cookies. This assumes your browser manufacturer is honest enough to delete everything. A better solution is to use a third-party’s cleaning application.

It’s also probably a good idea to install an ad blocker to stop private information being shared and stored in the first place. Although it should also be noted ad blockers are more inclined these days to block ads from advertisers who don’t pay for ‘white listing’.

A word of warning. While there are endless applications that promise to block or delete cookies and LSOs and more, the user must make sure the product chosen is from a legitimate company. There are many seemingly good applications out there which only look like they are doing a good job while actually installing malware or other advertising ‘adware’ directly on your computer.

Once you have decided on which application to use, it is even more important to ensure you download these applications from the developer’s website. Searching on Google more often than not will offer you the application from some other site, also for free, but often with a gift added to the installer, such as malware and adware – and worst of all, ransomware (which we will be focusing on in the next issue of Hi-Tech Security Solutions).

Adding it all up

The above is a brief overview of some privacy issues we face in going online every day. As can be expected, since it is possible to regain some control over who’s watching your online life, the virtual peeping Toms have come up with a way to track you more accurately. They can create what is called a digital fingerprint. This includes the information already being tracked, but adds in information about your computer that you can’t easily change.

Digital fingerprinting can not only identify a person according to their habits, but can also identify a computer. When surfing or transaction online, a digital fingerprint takes certain characteristic of the hardware and software of your system and creates a unique identity – which TrackOFF CEO Chandler Givens says is enough to accurately identify people. This creates a more accurate profile, reduces your privacy even more and can be used as part of an identity theft attack.

Chandler Givens, CEO, TrackOFF.
Chandler Givens, CEO, TrackOFF.

TrackOFF, a consumer privacy company that builds tools to secure users’ identities and personal data recently launched its software in South Africa where Givens spoke to Hi-Tech Security Solutions.

Explaining the need for users to take their privacy into their own hands, Givens explains that, in South Africa, online fraud and identity theft are on the rise, costing businesses in excess of R1 billion a year¹ and leading to one person’s identity being stolen every 29 seconds2. He warns everyone to be cautious when sharing personal information online, as cyber criminals have become extremely sophisticated in their strategies and attacks to gain access to databases of personal information, with financial gain the main target.

“Today, we share an awful lot of personal information every time we’re online, mostly unwillingly. TrackOFF allows users to regain some peace of mind on the web,” said Givens. “It’s simple to use – anyone can install it in minutes and begin protecting their identity and personal information. We’re excited to launch in South Africa and spread awareness about new privacy threats.”

TrackOFF makes sure that tracking users becomes difficult by, as Givens puts it, ‘scrambling’ the information collected, making it more difficult to identify who you are. The Elite version also allows you to browse anonymously.

The company states that TrackOFF empowers consumers of all technical skill levels to regain control of their identities and personal data by blocking the various forms of online tracking used by hackers and trackers. The solution also allows users to browse the web without having their searches stored, shared, or sold. In addition, it encrypts a user’s browsing during sensitive tasks like online banking, and shields their IP address and location. Givens says it offers a proactive solution to prevent online identity theft.

The consumer version is available now and Givens adds that the company is working on a corporate version which will allow company administrators to manage the privacy of the computers on the company network.

TrackOFF can be downloaded and installed from here: https://www.trackoff.com/en/secure-store/buy. Following the launch, the 3-month promotional price breakdown is as follows:

• 1-month licence for TrackOFF Basic: R29.99.

• 1-month licence for TrackOFF Elite: R55.55.

• 1-year licence for TrackOFF Basic: R299.99.

• 1-year licence for TrackOFF Elite: R555.50.

Sources:

1. http://www.news24.com/SouthAfrica/News/Identity-theft-in-SA-booming-20150522

2. http://techfinancials.co.za/south-africans-enough-secure-online-identities/



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Digital transformation in mines
NEC XON Technews Publishing Mining (Industry)
Digital transformation has been hyped to death, but is a reality all companies in all industries need to address, including the mining sector. BCX and NEC XON weigh in on the challenges mines face.

Read more...
Fire safety in mining
Technews Publishing Mining (Industry)
Clinton Hodgson, Head of the Industrial Fire & Life Safety Division at FS Systems International, provides SMART Security Solutions with his insights into fire safety risks and solutions as they pertain to the mining industry.

Read more...
Cybersecurity in mining
Technews Publishing Mining (Industry)
One does not usually associate mining with cybersecurity, but as big technology users (including some legacy technology that was not designed for cyber risks), mines are at risk from cyber threats in several areas.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
Mines require proof of performance
Technews Publishing Mining (Industry)
The relatively hostile environment and remote locations of mining establishments mean that any electronic/technical implementations have to be easily installed, require little or no maintenance and, once commissioned, require no adjustment.

Read more...