The United States could finally ban forced and senseless password changes

Researchers discovered a vulnerability in a Kia web portal that allowed them to track millions of cars, unlock doors, honk horns and even start engines in seconds, simply by reading the car's license plate . The findings are the latest in a series of web bugs that have affected dozens of automakers. Meanwhile, a handful of Tesla Cybertrucks have been equipped for war and are literally being battle-tested by Chechen forces fighting in Ukraine as part of the ongoing Russian invasion.

As Israel intensifies its attacks on Lebanon, civilians on both sides of the conflict are receiving disturbing text messages and authorities in each country are accusing the other of psychological warfare. The U.S. government has increasingly condemned Russian-backed media outlets like RT for working closely with Russian intelligence services, and many digital platforms have removed or banned their content. But they remain influential and reliable alternative news sources in many parts of the world.

And there's more. Every week, we round up privacy and security news that we haven't covered in depth ourselves. Click on the headlines to read the full stories. And stay safe out there.

A new draft digital identity guideline from the U.S. National Institute of Standards and Technology finally takes steps to eliminate maligned password management practices that have proven to do more harm than good. The recommendations, which will be mandatory for U.S. federal government entities and serve as guidelines for everyone, prohibit the practice of requiring users to change their account passwords periodically, often every 90 days.

The policy of changing passwords regularly arose from a desire to ensure that people did not choose easy-to-guess or reused passwords; but in practice, this leads people to choose passwords that are simple or phrased in a way that makes them easier to follow. The new recommendations also prohibit composition rules, such as requiring a certain number or combination of capital letters, numbers, and punctuation marks in each password. NIST writes in the draft that the goal of the Digital Identity Guidelines is to provide fundamental risk management processes and requirements that enable the implementation of secure, private, fair, and accessible identity systems.

The US Department of Justice on Friday unveiled charges against three Iranian men who allegedly compromised Donald Trump's presidential campaign and leaked stolen data to the media. Microsoft and Google warned last month that an Iranian state-sponsored hacking group, known as APT42, had targeted both the presidential campaigns of Joe Biden and Donald Trump, and succeeded in breaching the Trump campaign. The DOJ says the hackers compromised a dozen people in its operation, including a journalist, a human rights activist and several former U.S. officials. More broadly, the U.S. government has said in recent weeks that Iran is trying to interfere in the 2024 elections.

The defendants' comments made clear they were trying to undermine former President Trump's campaign ahead of the 2024 U.S. presidential election, Attorney General Merrick Garland said at a news conference Friday. “We know that Iran continues its brazen efforts to stoke discord, erode confidence in the U.S. electoral process, and promote its malign activities.

The Irish Data Protection Commission on Friday fined Meta $91 million, or about $101 million, for a 2019 password storage error that violated the Irish General Data Protection Regulation. European Union. Following a Krebs security report, the company admitted in March 2019 that a bug in its password management systems had caused hundreds of millions of Facebook, Facebook Lite and Facebook passwords to be stored unprotected. Instagram on an internal platform. Ireland's privacy watchdog launched its investigation into the incident in April 2019.

It is widely accepted that user passwords should not be stored in the clear, given the risks of abuse associated with people having access to this data,” said Irish Deputy Commissioner of the DPC, Graham Doyle, in a press release It should be borne in mind that the passwords, the ones under study in this case, are particularly sensitive, since they would allow access to the users' social network accounts.

Digital anonymity nonprofit Tor Project is merging with the privacy and anonymity-focused Linux operating system Tails. Pavel Zoneff, communications director for Tor Projects, wrote in a blog post Thursday that the move would facilitate collaboration and reduce costs, while expanding the reach of both groups. Tor and Tails provide essential tools to help people around the world stay safe online, he wrote. By joining forces, these two privacy advocates will pool resources to focus on what matters most: ensuring that activists, journalists, and other at-risk, everyday users have access to digital security tools improved.




