News: 1660180540

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Meta privacy red team lead: Does your business know its privacy adversaries?

(2022/08/11)


Black Hat Miscreants aren't only working to exploit flaws in an enterprise's security posture, they're also looking for holes in organizations' privacy programs to steal user data, according to Meta's Scott Tenaglia.

This is where privacy red teams come into play. Similar to their security counterparts, these other red teams help test organizations' privacy defenses in a controlled setting. And if you are a large organization that already uses security red teaming to stay one step ahead of potential attackers, it may be time to consider adding a privacy read team, too, said Tenaglia, engineering manager for Meta's privacy red team.

[1]Youtube Video

[2]

During a video interview at Black Hat, Tenaglia talked data privacy with The Register , and how these ethical hackers of the privacy world can help. "Privacy red teaming is an attempt to add an offensive component to a holistic privacy program," Tenaglia said.

[3]

"This notion of adversarial testing, understanding who the folks are, they're gonna either attempt to violate your security or your users' privacy is really important," he added. "Most organizations have some sort of plan to defend against this. The bad part would be if the first time that plan gets tested is by an actual adversary."

Tenaglia pointed to data scrapers as an example: these are the folks who collect huge amounts of data from websites, either publicly available information or that stored behind login pages, without users' permission. Meta, of course, has [4]first-hand experience with this.

[5]

In this case, a privacy red team operation could see how much data could be scraped, and once the rate limit has been hit, look for ways to bypass the limit, Tenaglia said.

"If everything stands up really well, then you've got a good defensive, good mitigation," he noted. "If not, then we can recommend some ways to tweak it and improve it." ®

Get our [6]Tech Resources



[1] https://vimeo.com/738353044

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YvR@5lzD-6dkP@N84DfPPAAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvR@5lzD-6dkP@N84DfPPAAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2022/07/07/meta_sues_data_scrapers_for/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvR@5lzD-6dkP@N84DfPPAAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://whitepapers.theregister.com/



The Greatest Mathematical Error
The Mariner I space probe was launched from Cape Canaveral on 28
July 1962 towards Venus. After 13 minutes' flight a booster engine would
give acceleration up to 25,820 mph; after 44 minutes 9,800 solar cells
would unfold; after 80 days a computer would calculate the final course
corrections and after 100 days the craft would circle the unknown planet,
scanning the mysterious cloud in which it is bathed.
However, with an efficiency that is truly heartening, Mariner I
plunged into the Atlantic Ocean only four minutes after takeoff.
Inquiries later revealed that a minus sign had been omitted from
the instructions fed into the computer. "It was human error", a launch
spokesman said.
This minus sign cost L4,280,000.
-- Stephen Pile, "The Book of Heroic Failures"