dimecres, 21 de novembre del 2018

Instagram accidentally reveals plaintext passwords in URLs

Vist a Sophos

In April, with the GDPR deadline and its requirement for data portability looming, Instagram released the long-anticipated download your data tool. The feature gave users the ability to download images, posts and comments.

Unfortunately, Instagram turned the task of downloading your data into an exercise in exposing people’s passwords in plain text. Thankfully, the bug in the “download your data” tool only affected a handful of users, it said.

As The Information reported last week, Instagram told affected users on Thursday night that if they’d used the “download your data” feature, their passwords were showing up in plaintext in the URL of their browsers.

That might not be a big deal to a user at home on an unshared computer, but as Facebook, which owns Instagram, said in the notice to users, it means that anybody who used the tool on a public computer – say, in a library – had their password exposed in the URL: an unfortunate gift to any shoulder surfers who may have been around.

It also means that Instagram passwords were stored on Facebook servers, the user notice said, and that means in plaintext, not encrypted.

Facebook didn’t say whether anybody’s Instagram account was compromised because of the error. The Information quoted an Instagram spokesperson who said that the issue was discovered internally and affected a very small number of people.

Sophos’s own Chester Wisniewski, principal research scientist, told The Information that this never would have happened if Instagram was doing encryption right. For the Facebook-owned Instagram to be able to trip up and post plaintext passwords in URLs, that means that somewhere inside of Instagram, users’ passwords are bouncing around in plain text. That’s not good as far as industry best practices go, Chester says:

This is very concerning for other security practices inside of Instagram because that literally should not be possible. If that’s happening, then there are likely much bigger problems than that.

We’ve already seen bigger, recent problems Bigger problems, indeed. We don’t know what Facebook/Instagram’s definition of “small” is when it comes to this breach, but we do know that security practices led to a massive breach at Facebook in September, with what would eventually turn out to be around 30 million accounts affected and another 40 million reset as a “precautionary step.”

Attackers exploited a vulnerability in Facebook’s “View As” feature to steal access tokens, which are the keys that allow you to stay logged into Facebook so you don’t need to re-enter your password every time you use the app. At least in the early days following the attack, Facebook said it looked like the hole was opened when developers made a change to the video uploading feature way back in July 2017. The attackers then stole an access token for one account, and then used that account to pivot to others and steal more tokens.

dijous, 1 de novembre del 2018

España es el país de Europa donde más se paga por internet

Visto en Tecnonews

Pese a que los sueldos medios en España están por debajo de la media europea de sueldos el precio que los ciudadanos de este país pagan por su contrato de internet está un 27,4% por encima de la media del Viejo Continente.

Así lo ha determinado un estudio de Kelisto.es que establece que la media que pagamos para conectarnos a la red es de 53 euros mensuales.

El estudio se centra en la comparación de precios entre Italia, Francia, Reino Unido, Alemania y España. Según este documento, la media del precio en el resto de los países es de 41,6 euros.

Si tomamos como ejemplo el caso alemán descubrimos que las diferencias son abismales. Kelisto.es sitúa el contrato mensual de España en 19,33 euros al mes más caro que los alemanes. Eso supone 232 euros más al año que a la postre se resumen en un “sobrecoste” del 57,43% anual.

En el resto de los casos las diferencias no son tan acusadas. De esta manera, en Francia el contrato de media alcanza los 35 euros, en el Reino Unido los 40,76 euros y en Italia 45,67 euros.

Sucede lo mismo si comparamos los precios en el caso del internet más fijo más televisión. En España la media de este tipo de contratos es de 77,50 euros mensuales mientras que en Italia es de 69, en el Reino Unido de 61,50, en Alemania de 60,50 euros y en Francia de 50,40 euros.