News

CDPI Privacy Newsletter

Categories : CDPI Privacy Newsletter

Salesforce Community sites leaking data

May 2, 2023
KrebsOnSecurity site reports that Salesforce Community public websites may be leaking data from organizations including banks, healthcare and government. This comes two years after a researcher first identified risk from misconfiguration in the Salesforce sites that allowed for exploitation. Now, according to KrebsOnSecurity, leaks are happening widely – and despite organizations being notified, most have not addressed the problem.
CDPI Privacy Newsletter

IT’S THE LAW (05/02/2023)

May 2, 2023
Indiana is the 7th US state to pass a privacy law. The Indiana Consumer Data Protection Law includes protection of the right to know, correct, and delete. It will go into effect in 2026. Montana and Tennessee's legislatures have both approved privacy bills that may come into effect sooner. Montana’s governor requested amending the Montana Consumer Data Privacy Act to ban not just TikTok but also other social media sites perceived as from foreign adversaries. With Tennessee, the Information Protection Act is business-friendly and weaker than privacy laws in the first states, California, Colorado, Connecticut, Iowa, Utah, and Virginia.
CDPI Privacy Newsletter

Children’s Privacy: US Senators propose banning teens from social media without parental consent

May 2, 2023
The Protecting Kids on Social Media Act is a bipartisan proposal that harkens back to earlier legislation designed to shield children from “indecent” ads or solicitation, and to keep them from hearing “obscene” language on television and radio. The proposal also comes as US states increasingly come up with their own legislation to restrict children, as in the case of Utah, which is requiring parental consent for social media account creation and Montana, which proposes to block ad targeting, selling kids’ data, and social media use without consent.
CDPI Privacy Newsletter

Retire the password at 65? Global security report foresees major risks if you don’t

April 25, 2023
The digital password, first used at MIT in 1961, is 62 years old, and according to many experts no longer serves critical security needs businesses have. The 2023 State of Passwordless Security Report, based on interviews Vanson Bourne conducted with 1,000 IT security professionals from EMEA, APAC, and US companies, indicates 88% had cyberattacks in the last year. Phishing (43%) was the most prevalent form and 28% were by push notification attacks (aka multi-factor authentication fatigue attacks -- MFA bombs).
CDPI Privacy Newsletter

Children’s Privacy: Egypt’s government & UK test company exposed data of 72K kids

April 25, 2023
The Egyptian government, which in 2020 switched away from using the US College Board exam due to that company’s concern about security issues, established its own exam and in 2022 partnered with UK-based Academic Assessment Ltd. Human Rights Watch reports that now that vast amounts of personal data of tens of thousands of children who took that test was exposed for months. This puts the children at great risk, as anyone with an internet connection could find where they live, go to school, and if they have mental health or... Read More >
CDPI Privacy Newsletter