Google

Google's Go Lead: the Language Belongs To the Community (google.com) 60

Russ Cox (along with Rob Pike) is the tech lead for Google's Go team and its Go project. This week he responded on the Google group golang-nuts to a blogger who'd argued that "Go is Google's language, not ours."

First Cox points to a talk at Gophercon 2015 -- and its accompanying blog post -- which argued that Go's open source status is critical to its long-term success. He noted this week that "good ideas come from outside Google as often as they come from inside Google.... But getting to yes on every suggested new feature is not and never has been a goal." No one can speak for the entire Go community: it is large, it contains multitudes. As best we can, we try to hear all the many different perspectives of the Go community. We encourage bug reports and experience reports, and we run the annual Go user survey, and we hang out here on golang-nuts and on gophers slack precisely because all those mechanisms help us hear you better. We try to listen not just to the feature requests but the underlying problems people are having, and we try, as I said in the Gophercon talk, to find the small number of changes that solve 90% of the problems instead of the much more complex solution that gets to 99%. We try to add as little as possible to solve as much as possible.

In short, we aim to listen to everyone's problems and address as many of them as possible, but at the same time we don't aim to accept everyone's offered solutions. Instead we aim to create space for thoughtful discussions about the offered solutions and revisions to them, and to work toward a consensus about how to move forward...

The "proposal review" group meets roughly weekly to review proposal issues and make sure the process is working. We handle trivial yes and trivial no answers, but our primary job is to shepherd suggested proposals, bring in the necessary voices, and make sure discussions are proceeding constructively. We have talked in the past about whether to explicitly look for people outside Google to sit in our weekly meeting, but if that's really important, then we are not doing our job right. Again, our primary job is to make sure the issues get appropriate discussion on the issue tracker, where everyone can participate, and to lead that discussion toward a solution with broad agreement and acceptance. If you skim through any of the accepted proposals you will see how we spend most of our meetings nudging conversations along and trying to make sure we hear from everyone who has a stake in a particular decision.

It remains an explicit goal to enable anyone with a good piece of code or a good idea to be able to contribute it to the project, and we've continued to revise both the code contribution and proposal contribution docs as we find gaps. But as I said in 2015, the most important thing we the original authors of Go can do is to provide consistency of vision, to keep Go feeling like a coherent system, to keep Go Go. People may disagree with individual decisions. We may get some flat wrong. But we hope that the overall result still works well for everyone, and the decision process we have seems far more likely to preserve a coherent, understandable system than a standards committee or other process.

His conclusion? The Go language belongs to the Go community -- and, because it's open source, "the freedom to fork hopefully keeps me and the other current Go leadership honest."
EU

A German Minister Wants To Ban End-to-End Chat Encryption (thenextweb.com) 159

An anonymous reader quotes the Next Web: According to Spiegel Online, the country's Federal Interior Minister, Horst Seehofer, wants encrypted messaging services like WhatsApp and Telegram to provide chat logs in plain text to the authorities. Since these services come with end-to-end encryption, the companies will have to break the encryption and provide a backdoor to give access to the texts.
Wired adds that "This is obviously incompatible with end-to-end encryption, used by services such as Signal, WhatsApp and Telegram and, if passed, such a law would effectively ban secure encryption for instant messaging." Some commenters on Bruce Schneier's site suggest this is just political grandstanding.

An analysis from the Carnegie Endowment for International Peace, a foreign policy think tank, argues that this would be a major change from Germany's stance on encryption over the last two decades: Instead of focusing on regulating encryption itself, Germany has worked to enable its security agencies to conduct hacking. It has even passed a legal framework tailored to government hacking operations...

The legal debate eventually led to a landmark supreme court ruling emphasizing the government's responsibility for the integrity of information technology systems. The conversation is far from over, with some supreme court cases still pending in regard to recent legislation on the lawful hacking framework.

Microsoft

Russian Military Moves Closer To Replacing Windows With Astra Linux (zdnet.com) 95

An anonymous reader quotes a report from ZDNet: Russian authorities have moved closer to implementing their plan of replacing the Windows OS on military systems with a locally-developed operating system named Astra Linux. Last month, the Russian Federal Service for Technical and Export Control (FSTEC) granted Astra Linux the security clearance of "special importance," which means the OS can now be used to handle Russian government information of the highest degree of secrecy. Until now, the Russian government had only used special versions of Windows that had been modified, checked, and approved for use by the FSB. Astra Linux is a Debian derivative developed by Russian company RusBITech since 2008, the report says. "RusBITech initially developed the OS for use in the Russian private market, but the company also expanded into the local government sector, where it became very popular with military contractors."
Advertising

Google Struggles To Justify Why It's Restricting Ad Blockers In Chrome (vice.com) 178

An anonymous reader quotes a report from Vice News: Google has found itself under fire for plans to limit the effectiveness of popular ad blocking extensions in Chrome. While Google says the changes are necessary to protect the "user experience" and improve extension security, developers and consumer advocates say the company's real motive is money and control. In the wake of ongoing backlash to the proposal, Chrome software security engineer Chris Palmer took to Twitter this week to claim the move was intended to help improve the end-user browsing experience, and paid enterprise users would be exempt from the changes.

Chrome security leader Justin Schuh also said the changes were driven by privacy and security concerns. Adblock developers, however, aren't buying it. uBlock Origin developer Raymond Hill, for example, argued this week that if user experience was the goal, there were other solutions that wouldn't hamstring existing extensions. "Web pages load slow because of bloat, not because of the blocking ability of the webRequest API -- at least for well crafted extensions," Hill said. Hill said that Google's motivation here had little to do with the end user experience, and far more to do with protecting advertising revenues from the rising popularity of adblock extensions.
The team behind the EFF's Privacy Badger ad-blocking extension also spoke out against the changes. "Google's claim that these new limitations are needed to improve performance is at odds with the state of the internet," the organization said. "Sites today are bloated with trackers that consume data and slow down the user experience. Tracker blockers have improved the performance and user experience of many sites and the user experience. Why not let independent developers innovate where the Chrome team isn't?"
Security

Microsoft Warns 1 Million Computers Are Still Vulnerable To Major Windows Security Exploit (theverge.com) 21

Earlier this month, Microsoft revealed a major Windows security vulnerability that could see a widespread "wormable" attack that spreads from one vulnerable computer to the next. "While Microsoft has released patches for Windows systems, even for older server and Windows XP machines, recent reports have revealed there are at least 1 million systems connected to the internet that can be attacked," reports The Verge.

"Microsoft is confident that an exploit exists for this vulnerability," warns Simon Pope, director of incident response at Microsoft's Security Response Center (MSRC). "It's been only two weeks since the fix was released and there has been no sign of a worm yet. This does not mean that we're out of the woods." From the report: Pope notes that it was nearly two months after the release of patches for the previous EternalBlue exploit when WannaCry attacks began, and despite having 60 days to patch systems, a lot of machines were still infected. The EternalBlue exploit was leaked publicly, allowing hackers to create malware freely. This new BlueKeep flaw hasn't yet been publicly disclosed, but that doesn't mean there won't be malware. "It is possible that we won't see this vulnerability incorporated into malware," says Pope. "But that's not the way to bet."
Government

Maine Lawmakers Pass Bill To Prevent ISPs From Selling Browsing Data Without Consent (zdnet.com) 37

Maine lawmakers have passed a bill that will prevent internet providers from selling consumers' private internet data to advertisers. From a report: The state's senate unanimously passed the bill 35-0 on Thursday following an earlier vote by state representatives 96-45 in favor of the bill. The bill, if signed into law by state governor Janet Mills, will force the national and smaller regional internet providers operating in the state to first obtain permission from residents before their data can be sold or passed on to advertisers or other third parties. Maine has about 1.3 million residents.

The Republican-controlled Federal Communications Commission voted in 2017 to allow internet providers to sell customers' private and personal internet data and browsing histories -- including which websites a user visits and for how long -- to advertisers for the biggest buck. Congress later passed the measure into law.

Security

Advanced Linux Backdoor Found In the Wild Escaped AV Detection (arstechnica.com) 50

Researchers have discovered an advanced piece of Linux malware that has escaped detection bypasses antivirus products and appears to be actively used in targeted attacks. Ars Technica reports: HiddenWasp, as the malware has been dubbed, is a fully developed suite of malware that includes a trojan, rootkit, and initial deployment script, researchers at security firm Intezer reported on Wednesday. At the time Intezer's post went live, the VirusTotal malware service indicated Hidden Wasp wasn't detected by any of the 59 antivirus engines it tracks, although some have now begun to flag it. Time stamps in one of the 10 files Intezer analyzed indicated it was created last month. The command and control server that infected computers report to remained operational at the time this article was being prepared.

Some of the evidence analyzed -- including code showing that the computers it infects are already compromised by the same attackers -- indicated that HiddenWasp is likely a later stage of malware that gets served to targets of interest who have already been infected by an earlier stage. It's not clear how many computers have been infected or how any earlier related stages get installed. With the ability to download and execute code, upload files, and perform a variety of other commands, the purpose of the malware appears to be to remotely control the computers it infects. That's different from most Linux malware, which exists to perform denial of service attacks or mine cryptocurrencies.
Some of the code appears to be borrowed from Mirai, while other code has similarities to other established projects or malware including the Azazel rootkit, the ChinaZ Elknot implant, and the recently discovered Linux variant of Winnti, a family of malware that previously had been seen targeting only Windows.
Encryption

Apple, Google and WhatsApp Condemn GCHQ Proposal To Eavesdrop on Encrypted Messages 103

Tech giants, civil society groups and Ivy League security experts have condemned a proposal from Britain's eavesdropping agency as a "serious threat" to digital security and fundamental human rights. From a report: In an open letter to GCHQ (Government Communications Headquarters), 47 signatories including Apple, Google and WhatsApp have jointly urged the U.K. cybersecurity agency to abandon its plans for a so-called "ghost protocol." It comes after intelligence officials at GCHQ proposed a way in which they believed law enforcement could access end-to-end encrypted communications without undermining the privacy, security or confidence of other users.

Details of the initiative were first published in an essay by two of the U.K.'s highest cybersecurity officials in November 2018. Ian Levy, the technical director of Britain's National Cyber Security Centre, and Crispin Robinson, GCHQ's head of cryptanalysis (the technical term for codebreaking), put forward a process that would attempt to avoid breaking encryption. The pair said it would be "relatively easy for a service provider to silently add a law enforcement participant to a group chat or call."
Businesses

Gmail's Confidential Mode Will Be On By Default For G Suite Users Starting June 25th (theverge.com) 78

Google's new confidential mode is rolling out to G Suite users and will be turned on by default starting on June 25th. Personal account holders have been able to use this feature since Gmail's mid-2018 redesign, but Gmail users at work have not.

"Confidential mode is a powerful tool that will come in handy at work if you send messages containing sensitive details," reports The Verge. "It lets you set an expiration date for your message, which cuts off access when that day arrives. While the message is available, recipients won't be able to forward your message to others, copy its contents, or download it, and the sender can revoke access at any point. To add another layer of security, you can set the message to only unlock after the recipient types in an SMS verification code that's sent to their phone number." Slashdot reader shanen reacts: Apparently the Google of supreme evil has decided they need to try to force this confidential-mode email down people's throats. I think that's actually a gigantic business opportunity for Outlook, assuming they actually want to offer a superior email system. The fundamental premise of confidential mode is "We want to communicate with you, but we don't trust you," and my fundamental response is GFY. The ONLY thing I want is an option to reject all confidential-mode email. (However, I'm sure Microsoft is too evil to offer that option because they don't trust their own employees and have to eat their own poison dog food.)

(Well, actually there are several other improvements I want from email, such as a bounce for no-reply email.)

Security

Docker Bug Allows Root Access To Host File System (duo.com) 76

Trailrunner7 shares a report: All of the current versions of Docker have a vulnerability that can allow an attacker to get read-write access to any path on the host server. The weakness is the result of a race condition in the Docker software and while there's a fix in the works, it has not yet been integrated. The bug is the result of the way that the Docker software handles some symbolic links, which are files that have paths to other directories or files. Researcher Aleksa Sarai discovered that in some situations, an attacker can insert his own symlink into a path during a short time window between the time that the path has been resolved and the time it is operated on. This is a variant of the time of check to time of use (TOCTOU) problem, specifically with the "docker cp" command, which copies files to and from containers.

"The basic premise of this attack is that FollowSymlinkInScope suffers from a fairly fundamental TOCTOU attack. The purpose of FollowSymlinkInScope is to take a given path and safely resolve it as though the process was inside the container. After the full path has been resolved, the resolved path is passed around a bit and then operated on a bit later (in the case of 'docker cp' it is opened when creating the archive that is streamed to the client)," Sarai said in his advisory on the problem. "If an attacker can add a symlink component to the path after the resolution but beforeit is operated on, then you could end up resolving the symlink path component on the host as root. In the case of 'docker cp' this gives you read and write access to any path on the host."

Security

Flipboard Says Hackers Stole User Details (zdnet.com) 33

Flipboard, a news aggregator service and mobile news app, notified users this week of a security incident during which hackers had access to internal systems for more than nine months. From a report: In a series of emails seen by ZDNet that the company sent out to impacted users, Flipboard said hackers gained access to databases the company was using to store customer information. Flipboard said these databases stored information such as Flipboard usernames, hashed and uniquely salted passwords, and in some cases, emails or digital tokens that linked Flipboard profiles to accounts on third-party services. The good news appears to be that the vast majority of passwords were hashed with a strong password-hashing algorithm named bcrypt, currently considered very hard to crack.
United States

'We're Not Being Paranoid': US Warns Of Spy Dangers Of Chinese-Made Drones (npr.org) 146

Drones have become an increasingly popular tool for industry and government. But the Department of Homeland Security is warning that drones manufactured by Chinese companies could pose security risks, including that the data they gather could be stolen. From a report: The department sent out an alert on the subject on May 20, and a video on its website notes that drones in general pose multiple threats, including "their potential use for terrorism, mass casualty incidents, interference with air traffic, as well as corporate espionage and invasions of privacy." "We're not being paranoid," the video's narrator adds. Most drones bought in the U.S. are manufactured in China, with most of those drones made by one company, DJI Technology. Lanier Watkins, a cyber-research scientist at Johns Hopkins University's Information Security Institute, said his team discovered vulnerabilities in DJI's drones. "We could pull information down and upload information on a flying drone," Watkins said. "You could also hijack the drone." The vulnerabilities meant that "someone who was interested in, you know, where a certain pipeline network was or maybe the vulnerabilities in a power utilities' wiring might be able to access that information," he noted.
Government

In Baltimore and Beyond, a Stolen NSA Tool Wreaks Havoc (nytimes.com) 117

For nearly three weeks, Baltimore has struggled with a cyberattack by digital extortionists that has frozen thousands of computers, shut down email and disrupted real estate sales, water bills, health alerts and many other services. From a report: But here is what frustrated city employees and residents do not know: A key component of the malware that cybercriminals used in the attack was developed at taxpayer expense a short drive down the Baltimore-Washington Parkway at the National Security Agency, according to security experts briefed on the case. Since 2017, when the N.S.A. lost control of the tool, EternalBlue, it has been picked up by state hackers in North Korea, Russia and, more recently, China, to cut a path of destruction around the world, leaving billions of dollars in damage. But over the past year, the cyberweapon has boomeranged back and is now showing up in the N.S.A.'s own backyard. It is not just in Baltimore. Security experts say EternalBlue attacks have reached a high, and cybercriminals are zeroing in on vulnerable American towns and cities, from Pennsylvania to Texas, paralyzing local governments and driving up costs.

The N.S.A. connection to the attacks on American cities has not been previously reported, in part because the agency has refused to discuss or even acknowledge the loss of its cyberweapon, dumped online in April 2017 by a still-unidentified group calling itself the Shadow Brokers. Years later, the agency and the Federal Bureau of Investigation still do not know whether the Shadow Brokers are foreign spies or disgruntled insiders.

The Military

Why the US Air Force Is Investigating a Cyber Attack From the US Navy (businessinsider.com) 59

"The Air Force is investigating the Navy for a cyber intrusion into its network, according to a memo obtained by Military Times."

Zorro (Slashdot reader #15,797) shares their report: The bizarre turn of events stems from a decision by a Navy prosecutor to embed hidden tracking software into emails sent to defense attorneys, including one Air Force lawyer, involved in a high-profile war-crimes case of a Navy SEAL in San Diego. The tracking device was an attempt to find out who was leaking information to the editor of Navy Times, a sister publication. A similar tracking device was also sent to Carl Prine, the Navy Times editor, who has written numerous stories about the case.

Navy Capt. David Wilson, chief of staff for the Navy's Defense Service Offices, wrote in the May 19 memo that an Air Force attorney was among the defense lawyers who had received emails with the hidden tracking software, which he described as "malware"...

"In fact, I've learned that the Air Force is treating this malware as a cyber-intrusion on their network and have seized the Air Force Individual Military Counsel's computer and phone for review," he wrote.

Programming

'How I Cheated On My Microsoft Job Interview' (facetdev.com) 263

Robert Sweeney spent 10 years working as a software engineer at Microsoft and Netflix, before becoming founder and CEO of the software development agency Facet. This week he blogged about how he cheated on his 2004 interview for a job at Microsoft.

It was his first job interview ever, when he was still a college senior majoring in computer science, and a Microsoft recruiter had invited him to an interview at an on-campus career fair: I immediately called my good friend Eli who had just started a new job at Microsoft. I asked him what the on campus interviews were like and how I should prepare for them. He explained that they would ask a random programming question that I would need to solve on a sheet of paper. If you did well, then they would fly you out for a full day of interviews at the Microsoft headquarters in Redmond, Washington. He had been asked to write a function that, when given an array of length n + 1 containing integers 1 through n, find the duplicate integer in an array. I wasn't sure how to prepare for answering a "random programming question", so I decided to just use the question Eli had been asked as practice and hope for the best...

Most of the interview is a blur, but I remember the interviewer being nice and I remember the programming question he asked me... I couldn't believe it. He asked me the exact same question as Eli. Should I tell him? I hesitated for a moment, pretending to be thinking about how to solve the problem. In reality I was having an intense internal debate on the ethics of interviewing. He didn't ask me if I had heard the question before, he just asked me to solve it. So I decided to just answer the question... I slowly wrote out the solution I had come up with over days of thinking about the problem, being sure to pause periodically as if I was figuring it out for the first time... A few days later I received an invite to fly out to the Microsoft main offices. I interviewed with two teams over a period of 6+ hours. I didn't get asked any questions I had heard before this time, but I did my best... Sure enough, that next week I had a job offer from Microsoft from both teams... Within a couple of years of graduating from college, I had shipped software that was being used by nearly a billion people...

I've struggled with this a lot over the years, but I finally decided to share my story. I don't think I would have made it past the first round of interviews at Microsoft if I hadn't gotten so lucky. So pretty much, my entire career is built on one amazing stroke of luck. I also think my experience is a great example of one of the many reasons why the coding problems we use in developer interviews are so problematic: on the spot coding is just not a good way to judge technical ability.

Stack Overflow's CEO founder Joel Spolsky actually wrote some of Microsoft's internal programmer-testing guidelines when he worked there in the mid-1990s, and he later publicized them in a 2006 blog post which he says was later adopted by other tech companies, including Google.

He has since said that recruiting for IT is broken, adding "I think that I'm responsible."

Microsoft has since changed its interviewing practices.
Google

Google Shut Out Baltimore Officials Using Gmail After Ransomware Attack (theverge.com) 82

The Baltimore city government is recovering from a devastating ransomware attack that has locked up its systems, but officials in the city faced a new problem today. As first reported by The Baltimore Sun, Google blocked city departments from using Gmail accounts created as a workaround. The Verge reports: On May 7th, a ransomware attack froze government systems, including email, and demanded the city hand over bitcoin to reverse the hack. Weeks later, the city is still recovering from the attack, which has also shut down systems for paying water bills and some other services. While officials deal with the problem, which could still take months to fix, some have reportedly signed up for free Gmail accounts to keep operating.

Gmail distinguishes between individual users and users in businesses and other organizations, requiring the latter to pay for the service. According to the Sun, which cited the mayor's office, Google's systems deemed the city officials to be part of an organization, and shut down the temporary accounts. Emails to the city health department, city council aides, and the mayor's office bounced on Thursday, according to the report from the Sun.
UPDATE: Google has since fixed the problem. "We have restored access to the Gmail accounts for the Baltimore city officials," the spokesperson said. "Our automated security systems disabled the accounts due to the bulk creation of multiple consumer Gmail accounts from the same network."
Privacy

First American Financial Corp. Leaked 885 Million Sensitive Title Insurance Records (krebsonsecurity.com) 51

An anonymous reader quotes a report from Krebs on Security: The Web site for Fortune 500 real estate title insurance giant First American Financial Corp. leaked hundreds of millions of documents related to mortgage deals going back to 2003, until notified this week by KrebsOnSecurity. The digitized records -- including bank account numbers and statements, mortgage and tax records, Social Security numbers, wire transaction receipts, and drivers license images -- were available without authentication to anyone with a Web browser.

Santa Ana, Calif.-based First American is a leading provider of title insurance and settlement services to the real estate and mortgage industries. It employs some 18,000 people and brought in more than $5.7 billion in 2018. Earlier this week, KrebsOnSecurity was contacted by a real estate developer in Washington state who said he'd had little luck getting a response from the company about what he found, which was that a portion of its Web site (firstam.com) was leaking tens if not hundreds of millions of records. He said anyone who knew the URL for a valid document at the Web site could view other documents just by modifying a single digit in the link. And this would potentially include anyone who's ever been sent a document link via email by First American. KrebsOnSecurity confirmed the real estate developer's findings, which indicate that First American's Web site exposed approximately 885 million files, the earliest dating back more than 16 years. No authentication was required to read the documents.
"As of the morning of May 24, firstam.com was returning documents up to the present day (885,000,000+), including many PDFs and post-dated forms for upcoming real estate closings," Krebs adds. "By 2 p.m. ET Friday, the company had disabled the site that served the records. It's not yet clear how long the site remained in its promiscuous state."

A spokesperson for the company issued the following statement: "First American has learned of a design defect in an application that made possible unauthorized access to customer data. At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers' information. The company took immediate action to address the situation and shut down external access to the application. We are currently evaluating what effect, if any, this had on the security of customer information. We will have no further comment until our internal review is completed."
Security

Hackers Breach Company That Makes License Plate Readers for US Government (vice.com) 20

Hackers breached a company that provides license plate reader technology for the US government, including at the border with Mexico. From a report: The hackers posted what appears to be the internal data of the company, called Perceptics, on a dark web website on Thursday. A company employee confirmed to Motherboard that Perceptics was hacked. "We are aware of the breach and have notified our customers. We can't comment any further because it is an ongoing legal investigation," Casey Self, director of marketing for Perceptics said in an online message. The Register first reported the news on Thursday. The data appears to include a variety of databases, company documents, and financial information, according to the file directory giving an overview of the stolen material. Boris Bullet-Dodger, the hacker who listed the data online, contacted Motherboard with a link to the stolen data on Thursday. Perceptics, once a subsidiary of major government contractor Northrop Grumman, mainly distributes license plate readers, under-vehicle cameras, and driver cameras to the U.S., Canada, Mexico to place at border crossings.
Facebook

Facebook Removed 2.2 Billion Fake Accounts This Year (fortune.com) 50

Facebook released its community standards enforcement report Thursday morning, offering a much more in-depth look at the inner workings of the company than previously seen. From a report: One of the most surprising insights came from Facebook's removal of fake accounts. The company said it removed 2.2 billion accounts in the first quarter of the 2019. That's a jump of nearly double compared to the fourth quarter of 2018 when 1.2 billion accounts were removed. That number seems astronomical, especially when considering that Facebook says it has 2.38 billion monthly active users overall. The reason that the social network can boast nearly as many removals as it has active users is that it typically finds and removes bogus accounts within minutes of them signing up. As a result, Facebook estimates that only 5% of its monthly active users are fake.
Security

Snapchat Employees Abused Data Access To Spy on Users (vice.com) 28

Several departments inside social media giant Snap have dedicated tools for accessing user data, and multiple employees have abused their privileged access to spy on Snapchat users, Motherboard reported on Thursday. From the report: Two former employees said multiple Snap employees abused their access to Snapchat user data several years ago. Those sources, as well as an additional two former employees, a current employee, and a cache of internal company emails obtained by Motherboard, described internal tools that allowed Snap employees at the time to access user data, including in some cases location information, their own saved Snaps and personal information such as phone numbers and email addresses. Snaps are photos or videos that, if not saved, typically disappear after being received (or after 24 hours if posted to a user's Story). [...] Although Snap has introduced strict access controls to user data and takes abuse and user privacy very seriously according to several sources, the news highlights something that many users may forget: behind the products we use everyday there are people with access to highly sensitive customer data, who need it to perform essential work on the service. But, without proper protections in place, those same people may abuse it to spy on user's private information or profiles.

Slashdot Top Deals