Tech Insight : Smart Doorbells and UK Law

In this insight, we look at ‘smart’ doorbells and how the outcome of a recent legal case has highlighted the legal responsibilities that owner/operators of smart doorbells have under UK law.

Smart Doorbells

Smart doorbells, such as Eufy, Ring, Nest Hello, Arlo, Vuebell, IseeBell, and more are Internet-connected replacements for traditional doorbells. Smart doorbells use a smartphone app to enable the home occupant to see and talk in real-time with a caller using the doorbell’s built-in high-definition (infrared) camera and microphone. Smart doorbells can be activated by motion sensors and/or the pressing of a button, and the pictures and audio conversations can also be recorded.

The Issues

As outlined in a recent legal case in Oxfordshire, a judge ruled that security cameras and a Ring doorbell installed in a house broke data laws and contributed to harassment. Although the background of the case highlighted a long-running neighbourly dispute and one security camera was placed on a shed, the outcome focused on some very real legal issues relating to smart doorbells such as privacy, security, and regulation of increasingly normalised domestic surveillance.

In this particular case, some key issues were that:

– The smart doorbell could capture personal data (audio of conversations and video) from people who were not even aware that the device was there, and that it recorded and processed audio and personal data (there was no consent).

– The capturing of the audio data was found by the judge to be “even more problematic and detrimental than video data”.

– The extent of the range that the doorbell could capture audio was judged to be well beyond the range of video captured and, therefore, not reasonable (in this case).

– The device’s ability to capture conversations at ranges of between 40ft and 68ft away was excessive.

– An update to the doorbell in 2020 meant that it could not be switched off.

– Even if the ‘activation zone’ (motion-activated area) feature of the doorbell cameras was disabled, it could still film the whole area due to movement in one of the other non-disabled activation zones.

Pro Privacy Campaigners

Privacy campaigners such as Hannah Hart of ProPrivacy have highlighted how, using devices such as smart doorbells, “a small number of residents can effectively transform public spaces into surveillance hotbeds, and even share their recordings with police.”

The Laws

The laws that apply to issues around the use of smart doorbells are the UK Data Protection Act 2018 and UK GDPR. Also, a 2014 case (albeit in the Czech Republic) means that domestic surveillance systems are regarded as being within the scope of the data protection legislation where data is captured beyond the boundaries of a homeowner’s property.

The Manufacturer

The doorbell (Ring) manufacturer in the Oxfordshire case mentioned above was Amazon. Amazon may have:

– Built privacy and security features into the smart doorbell e.g., customisable privacy zones, motion zones, and Audio Toggle to turn audio on and off.

– Added end-to-end encryption to its smart doorbell technologies to keep personal data captured secure against misuse by third parties….

BUT the responsibility for HOW the equipment is used (in relation to the law) lies with you, the user.

How Can You Use Your Smart Doorbell Legally?

The important points to remember for using home surveillance devices, including smart doorbells are:

– Use home surveillance equipment in a way that respects the rights of other people, including neighbours.

– Be transparent (e.g., with neighbours) about what the equipment has been installed for and how it operates, thereby retaining your data protection obligation to process data in a lawful and transparent way, and not to collect personal data without a specified or lawful purpose (as required by the Data Protection Act 2018 and the GDPR).

– Ensure that the scope (e.g., the distance) of data capture is reasonable for its purpose.

– Consider putting up a sign that states recording is taking place, and why.

– Follow published guidance, such as ICO guidance for using CCTV: https://ico.org.uk/your-data-matters/domestic-cctv-systems-guidance-for-people-using-cctv/

What Does This Mean For Your Business?

Smart surveillance products may have some particular advantages (e.g., being able to hold real-time conversations with visitors when you’re not at the premises) but despite their in-built privacy and security features, how they are used and operated and contextual factors mean that you, the owner/user still have legal responsibilities. The recent Oxfordshire (Fairhurst Vs Woodward case) shows that simply installing such devices without the correct consideration of transparency about their use, their operating scope, and how they could affect the legal privacy rights of neighbours could land you with a large fine.

Tech News : One Million UK households May Be ‘Brushing’ Scam Victims

A report from Consumer watchdog Which? reveals that as many as 1.1 million people in the UK may have been caught up in a parcel delivery ‘brushing’ scam.

What Is Brushing?

Brushing is where people are sent packages of goods to their address that they didn’t order, apparently purchased on Amazon, by a person not known to them. Which? believes that third-party unscrupulous sellers, or agents acting on behalf of the sellers may be sending the goods. The reason for the scam is so that third-party sellers can log the deliveries as genuine sales, thereby boosting their own rankings on the highly competitive Amazon platform which favours products with high sales volumes and good reviews.

Where Do The Sellers Find The Addresses?

According to Amazon, sellers find the names and addresses from publicly available sources. The Which? website, however, gives an example which suggests that names and addresses can be easily collected and ‘consolidated’ from a variety of sources, such as Amazon itself (via its seller platform for merchants), from a seller’s list of customers that it serves on other marketplaces and platforms, or from previously unconnected website security breaches.

Accounts Set Up In Some Cases

Which? also reports that some unscrupulous sellers take the brushing scam a step further by creating a fake Amazon account linked to the unsuspecting recipient’s address to ‘purchase’ the item themselves and then leave a glowing (fake) review.

What Kind of Items?

A separate Which? survey showed that a wide variety of items have been received by victims of the scam including LED strip lights, books, envelopes, sunglasses, and headphones.

What Is Amazon Doing About Brushing Scam?

Amazon says it has ‘robust’ processes in place to prevent brushing, which it says are carried out by ‘bad actors’ using data from ‘external sources.’

What Happens To The Parcels?

Amazon’s reported position is that customers don’t need to return the items and can choose to keep the parcels or throw them away, whichever they find more convenient.

The Which? research shows that where there was an Amazon parcel not ordered by the recipient, not sent by a known person, and not taken in for a neighbour, 63 per cent said they kept them, 18 per cent said they threw them away, and 16 per cent said they gave the item away.

What Does This Mean For Your Business?

Although it may sound like a positive thing to be the ‘victim’ recipient of lots of goods that you don’t have to give back, there are some serious issues here. Some would argue that it’s not enough for Amazon to simply say that recipients can do what they like with the parcels, and the fact that the scam exists is a sign that that the system of the platform is not working as it should. Which? wants Amazon to do more to increase its scrutiny of seller profiles and monitor for suspicious activity that could suggest product purchases and reviews are not genuine. The apparent fake reviews that result from the fake sales are also something that could adversely affect Amazon customers and create a more unfair situation for the other Amazon sellers who behave honestly. A better position by Amazon could be to encourage those who have received unsolicited packages to report them to customer services so that it can investigate fully and take robust action against sellers that are attempting to mislead consumers. This would benefit other Amazon sellers and customers alike. There is also an argument that laws should be introduced to crack down on brushing and force tech giants to protect people online. It should also be noted that, at a time when environmental issues are high on the world’s priority list, more goods simply being thrown away is not helping (as in the case of 18 per cent of brushing recipients) .

Tech News : Massive Rise In HTTPS Attacks

The latest “ThreatLabz: The State of Encrypted Attacks,” 2021 report has shown a 300 per cent increase in online attackers using HTTPS to cloak their activities and blend in with other traffic.

HTTPS

HTTPS, the encrypted version of the Hypertext Transfer Protocol (HTTP), enables secure communication over a computer network, using Transport Layer Security (formerly, Secure Sockets Layer). HTTPS is particularly important for protecting the kind of personal data that’s submitted in online activities like shopping, banking, and remote work.

Massive Increase

The ThreatLabz report showed that threats inside encrypted traffic have increased 314 per cent as online attackers choose HTTPS to cloak their activities.

How?

Cybercriminals can use HTTPS to hide threats like malware from web security tools that don’t fully inspect encrypted traffic.

Why?

The rise of this type of attack has been driven by factors such as:

– Google making it known that the presence of HTTPS is an important consideration for search-results rankings, and Chrome and Firefox showing warnings about sites without HHTPS, thereby fuelling a general belief that HTTPS is totally safe.

– Attackers (as well as legitimate businesses) can now enable and auto-renew HTTPS for their sites, regardless of whether the content is suspect.

– New types of malware are now being shared behind a lock symbol.

Types of Attack

The types of attack that criminals are using HTTPS to hide include:

– Malware (including ransomware). This type of attack has grown by 212 percent and nine out of ten attacks via HTTP(S) involved malware. Spyware has also shown a 435 per cent increase.

– Phishing has grown by 90 per cent on last year and is being driven by attacks launched through legitimate services. For example, Microsoft 365 was the most common attack vector for phishers.

– Web applications like credential stuffing. For example, the ThreatLabz report shows that attackers interacted with almost 70 per cent of HTTPS-based web-facing applications.

Who Was Attacked The Most?

The report showed that technology companies were attacked the most using HTTPS cloaking (a 2,344 per cent rise) followed by retail and wholesale companies which saw an 841 percent increase in this type of stealth attack. Increased scrutiny by law enforcement on healthcare companies/organisations and government (which have been heavily targeted before) appears to be the reason for a decrease in the numbers of HTTPS-based attacks on these targets.

What To Do?

Ways that businesses can protect themselves against cybercriminals hiding attacks using HTTPs include:

– Not assuming that SSL traffic is automatically secure traffic – the padlock icon of HTTPS does not guarantee security.

– Start from a position of zero trust, where there is no lateral movement, apps are invisible to attackers, and authorised users directly can only access needed resources, not the entire network.

– If possible, use AI-driven quarantine rather than firewall-based passthrough approaches.

– Use a proxy-based architecture and cloud-native performance to decrypt detect and prevent threats from SSL traffic.

– Make sure all company network users have the same high level of security at all times, at all locations (e.g., when working remotely or even when on the go). All traffic on and off-premises needs to be inspected to stop encrypted threats.

What Does This Mean For Your Business?

Even though HTTPS has been designed to provide a valuable layer of encryption, it has also become relatively easy for cybercriminals to create websites with the HTTPS distinction. Also, cybercriminals have been helped by an assumption that HTTPS and a padlock must mean that everything is secure, and by web security tools which don’t fully inspect and check encrypted traffic, on and off-premises. Businesses should not assume the HTTPS is totally secure and one of the key ways that many businesses are now protecting themselves from a wide range of threats, including HTTPS-based attacks, is to adopt a Zero Trust approach to IT Security where the approach is “never trust, always verify.”

Featured Article : Facebook Re-Branded As ‘Meta’

After one of the most publicised re-brands in history, as Facebook changes its name to ‘Meta,’ we look at the reaction in the media and the marketplace, and the issues for the company going forward.

‘Meta’ … ?

Facebook CEO Mark Zuckerberg announced at Connect 2021 last week that the company had brought together its apps and technologies under the new company brand name of ‘Meta’. It was explained that the re-branded “Social Technology Company” had changed its name to Meta because it is short for ‘metaverse,’ which is Zuckerberg’s vision for the future of the platform.

What Is ‘Metaverse’?

Currently more of a concept than a (virtual) reality, Zuckerberg describes the metaverse as “even more immersive – an embodied internet where you’re in the experience, not just looking at it.”  He went on to explain that “the defining quality of the metaverse will be a feeling of presence — like you are right there with another person or in another place. Feeling truly present with another person is the ultimate dream of social technology”, and that “In the metaverse, you’ll be able to do almost anything you can imagine — get together with friends and family, work, learn, play, shop, create — as well as completely new experiences that don’t really fit how we think about computers or phones today”.

Wave of Criticism

Inevitably, Facebook’s announcement led to a wave of criticism online including:

– U.S. lawmaker Alexandria -Ocasio Cortez Tweeting “Meta as in ‘we are a cancer to democracy metastasizing into a global surveillance and propaganda machine for boosting authoritarian regimes and destroying civil society’… for profit!”

– Criticism that the timing may be a step for the company to distance itself from recent controversy.

– Former Biden White House adviser, Andy Slavitt, Tweeting “Meta accomplishes only one thing. It allows Mark Zuckerberg to say he’s not the CEO of Facebook. He will now do less controversial things like build a new virtual universe where he can be king. While running Facebook.”

– Nicola Mendelsohn, Facebook’s vice president of Meta for Europe, the Middle East and Africa Faced some tough interviews and accusations that (as highlighted by former Facebook employee-turned-whistleblower, Frances Haugen) the company is putting profit before people, not addressing alleged issues about the safety of young users (Facebook and Instagram). For example, Frances Haugen claimed that Facebook was “unquestionably” making online hate worse, and told UK MPs that safety teams were under-resourced, leading to “Facebook has been unwilling to accept even little slivers of profit being sacrificed for safety” and being “more dangerous than other forms of social media”.

Sounds Like Hebrew Word For ‘Dead’

Whereas the name “Meta” comes from the Greek word meaning “beyond,” the company has faced some criticism from Israel where it has been pointed out that “Meta” sounds like the Hebrew pronunciation of the word for “dead”.

It Could Be Much Worse…

If this is the case, the new name could be joining a long list of famous marketing naming blunders (and urban legends) including:

Nokia’s ‘Lumia’ brand translating to ‘prostitute’ in Spanish.

Apple’s ‘Siri’ personal assistant is pronounced in Japan as “shiri” which translates to ‘buttocks.’

Nintendo’s much ridiculed 2005 decision to name their Touch Dictionary service in South Korea as ‘Touch Dic’.

Facebook Answers

Facebook has been answering its critics by saying that the platform is being wrongly portrayed as a place that is awash with danger and hate speech. For example, Nicola Mendelson has highlighted how the company is spending £3.6bn this year “on protecting people’s safety, data and their privacy on our platforms”, and that “We make our money from advertising. Advertisers don’t want their ads next to harmful content.”

Mark Zuckerberg has described recent allegations that Instagram harmed teenage mental health as a “coordinated effort to selectively use leaked documents to paint a false picture of our company”.

So, What IS The Metaverse?

Mark Zuckerberg sees ‘Meta’ as a better way to “encompass” the company’s future direction beyond social media, as it moves more into virtual reality, gaming, and creating its own immersive virtual world where users will become more engaged by and committed to the new different and experiences on offer. There is also the notion that Facebook may want to be seen as trying to set users free from simply being tied to the screen and craving likes and offering some kind of more genuine human experience.

The vision, however, may not be realised for another five years or so and in the meantime, despite the rebrand, it is unlikely to deflect attention away from what many people (including some governments) see as still pressing issues that Facebook may not have convincingly addressed.

Competition

Competitively, this is a move to differentiate itself from competitors, dictate and lead in what it sees as the future for social media technology, and prove that a rebrand of this scale can work. For example, Alphabet Inc and Google may still be perceived as a separate parent company and another brand.

What Does This Mean for Your Business?

Some would argue that given the metaverse concept is years away and can be made to sound as brilliant as Facebook (now Meta) wishes is a great way to try and deflect and escape from much of the bad publicity that the company has received recently (e.g., the revelations from whistleblower, Frances Haugen). The announcement, however, appears to have drawn more criticism, stirred up some negative feelings and trust issues about the company, and caused some people to suggest that there are more pressing issues than a re-brand and a future vision i.e., making the platforms (Facebook and Instagram) safe for young users. Facebook/Meta has defended the progress it has made (thanks to AI), has suggested that it is not as bad as it is being portrayed, and is staking its claim as the most forward-thinking of the social media giants. New questions about old issues have now been asked such as : how will this new metaverse be effectively governed? Facebook/Meta has pointed out that it gets much of its revenue from advertising and advertisers would not want to be associated with Facebook if it was as irreputable as some say. The metaverse, however, may present many new and interesting advertising opportunities for companies, thereby potentially making it more profitable for Facebook than the current system. Until we actually see the metaverse it will be difficult to tell how much of a new experience it offers.

Tech Tip – How To Open A File Without Knowing The Extension

Trying to open a file where you don’t know the file type and there’s no extension can be frustrating, time-consuming and potentially insecure so here are options to help:

First check that the file actually has no extension:

– Right-click on the file, select ‘Properties,’ and look at the ‘type of file’ in the ‘General’ tab of file properties. If it just says ‘File’ it has no extension, OR…

– Check the file extension from the ‘Type’ column in Windows file explorer, OR…

– Select the ‘View’ tab from the top ribbon and check the box beside ‘File name extension’.

If the file has an extension but you can’t open it, this is likely to be because you don’t have the relevant program on your computer/device. Ways to open it include:

– Visit fileinfo.com (https://fileinfo.com/), enter your file’s extension in the search bar, and install one of the suggested programs.

– Visit toolsley.com (https://www.toolsley.com/file.html) and drag and drop the file to identify it.

– Download the UK government’s DROID tool (https://github.com/digital-preservation/droid/) and use that to identify the file extension listed in the ‘Format’ column.

– Use a hex editor, such as Free Hex Editor Neo (https://www.hhdsoftware.com/free-hex-editor).

– After launching the editor, open the file, scroll to the right end of the block of numbers, and you will see the file extension.

Featured Article: Scam Calls : A Significant Update

This week, we heard the good news that the big phone networks have agreed to automatically block foreign scam calls, and we heard the bad news that an Ofcom survey has revealed that 45 million people in the UK were targeted by scam text messages or phone calls this summer!

The Challenge

The challenge has been that scammers based overseas have been able to use Voice Over Internet Protocol (VoIP) / internet-based calling technology to make it look as though a phone call or text is coming from a real telephone number. A recent ‘Which?’ survey has shown that in the 12 months to March 2021, phone call and text message fraud in England, Wales and Northern Ireland had risen by 83 per cent from the previous year and Action Fraud data confirmed that was the biggest rise across all types of fraudulent attacks.

Why?

The reasons why there have been such big and sustained increases in (foreign) scam calls and texts include:

– A telephone identification protocol called SS7, which dates back decades, is still part of the landlines and the 2G and 3G parts of mobile phone networks (even with a 5G-enabled handset). Scammers know how to steal the ‘presentation number’ and link this to their own number, thereby giving them the ability to make it look as though calls and texts are from legitimate UK sources. The presentation number is the number that the telephone network is told that a user is calling or texting from and the usage of the SS7 protocol means that the presentation number can’t be checked against the originating number, thereby enabling the fraud to continue.

– Some critics have suggested that telecoms companies don’t appear to be inspecting the traffic they receive from VoIP providers and just let it through onto the networks, thereby making it easier for scammers.

– There is a low barrier to entry for scammers because the prevalence of (and easy access to) enterprise VoIP telephone systems which means that they can easily (and relatively cheaply) build their own systems to spoof mobile numbers.

– The pandemic fuelled a big rise in online ordering which meant more deliveries, which led to fraudsters finding more success impersonating mail and delivery scams and using fake notifications by text and phone. This led the fraudsters to increase their efforts to capitalise on the opportunity.

Types of Attacks Using Foreign Phone & Text Scams

The types of attack that use scam phone calls and texts that incorporate ‘number spoofing’ (using Internet calling technology to make a phone call or text appear as though it is originating from a genuine number) include:

– Vishing. This combination of ‘voice’ and ‘phishing’ and describes the criminal process of using internet telephone service (VoIP) calls to deceive victims into divulging personal and payment data. Vishing scams to homes often use recorded voice messages e.g., claiming to be from banks and government agencies to make victims respond in the first instance.

– Smishing. This is where an attacker sends a text/SMS message purporting to be from a reputable company e.g., the Royal Mail or a parcel delivery company/courier service. The idea is that the recipient (who may be expecting a parcel delivery) is fooled into clicking on the link in the text message and this either send sends the attacker personal information (credit card number or password) or downloads a malicious program/malware to the victim’s phone. The malware can be used for snooping on the user’s smartphone data or sending sensitive data silently to an attacker-controlled server.

The Good News From Ofcom

Following recent reports from the Daily Telegraph (and Ofcom’s own survey findings that 45 million people in the UK received scam text messages or phone calls this summer), the communications regulator has been working with the big telecoms companies to implement technical solutions which could lead to a big reduction in these types of scam messages. Ofcom’s Network and Communications Group Director, Lindsey Fussell, says on the Ofcom website “We’ve been working with telecoms companies to implement technical solutions, including blocking at source, suspicious international calls that are masked by a UK number. We expect these measures to be introduced as a priority, and at pace, to ensure customers are better protected.” 

Although only one network (TalkTalk) has introduced the blocking measures so far, Ofcom says that it expects the new measures to be rolled out by the phone networks as a priority and that others are looking at how to implement it.

Critics

Some critics have already poured cold water on the good news announcement by pointing out that:

– The systemic issue of VoIP providers not checking whether the calls they hand to telecoms networks are actually legitimate needs to be effectively tackled to solve the problem.

– Simply cracking down on “foreign calls” could actually damage legitimate businesses and individual VoIP customers who may still be UK based, even if the traffic appears to be external.

The Bad News – Ofcom Survey Reveals Extent of Scam Calls

As mentioned, an Ofcom survey from September this year revealed that almost 45 million people in the UK were targeted by scam text messages or phone calls over the summer months. A staggering 82 per cent of the 2,000 people surveyed said they had received a suspicious message as a text, recorded message, or live phone call to a landline or mobile. This represents an estimated 44.6 million adults in the UK.

Frequent Texts

The survey showed that most of these scams use text messages (71 per cent said they’d received a suspicious text). Also, the figures revealed that more than four in 10 people (44 per cent) who reported receiving a suspicious text message said it happened at least once a week.

Who?

Those who appear to have been targeted most with the scam calls and messages are:

– Those aged 16-34. Three-quarters of this age group have been targeted.

– 60 per cent of people aged 75 and over reported receiving a potential scam call to their landline.

What To Do?

The advice from Ofcom for those who receive a scam / suspicious text message is:

For Suspicious Texts

– Read any suspicious text carefully and look for any details that don’t seem right.

– Don’t click on any links or give out any personal or bank details.

– Report any suspicious texts to 7726 and make your friends and family aware too. Forwarding the message to 7726 directs the message to the mobile provider. If certain numbers are reported by enough people, these numbers can then be investigated and potentially blocked, thereby helping disrupt or to flush-out fraudsters and prevent more people being exposed to scam attempts.

The Ofcom survey showed that more than half of people who received a suspicious text either deleted the message (53 per cent) or blocked the number (52 per cent). These are, of course, other options but reporting the text can help to get the scam stopped.

For Suspicious Phone Calls

– Do not give out any personal or bank details.

– Hang up and then call the company they claim to be from to check if it is a scam. Use a trusted source (e.g. their official website) as the phone number.

– Report scam calls to Action Fraud (for England, Wales, and Northern Ireland) and make your family aware too. In Scotland, scam calls can be reported to Police Scotland via 101.

In the Ofcom research, almost half (49 per cent) of those who received a suspicious live voice call, and more than four in ten (44 per cent) who received a suspicious recorded message, blocked the number.

What Does This Mean For Your Business?

Scam calls and texts are not just disruptive and costly but are a way in for cyber-criminals and the results of cyber attacks can be devastating to businesses and threaten their very existence. The ability of cyber-criminals to use internet calling technology, seemingly at will, to launch attacks is a loophole that has been open far too long. Some responsibility appears to lie with VoIP providers who may not be checking the calls they hand over, but this action by Ofcom (and hopefully, more big communications companies than just TalkTalk) looks as though it has the potential to dramatically reduce the threat posed by scam calls and texts. The danger is that cracking down too hard on “foreign calls” could actually damage legitimate businesses that may be UK-based; care needs to be taken in implementation. Many UK businesses will benefit from not having to deal with all-too-frequent scam calls, any one of which could prove highly dangerous.

Each week we bring you the latest tech news and tips that may relate to your business, re-written in an techy free style. 

Archives