Tuesday, 2 October 2018

Zomato, TripAdvisor and other third-party apps say Facebook data breach didn’t affect them

Zomato, TripAdvisor and dating app Truly Madly said their Indian users have not been impacted by the Facebook data breach that led to about 50 million accounts getting exposed to hackers globally.

Experts had said the hacking, which was revealed by the social networking platform on Friday, would have exposed third-party apps of users that accept Facebook logins.

“Facebook has been in touch with us and as far as we understand, there is no impact to Zomato users and their usage of Zomato as a result of this breach at Facebook,” a Zomato spokesperson said. The online food delivery and restaurant discovery company has about 120,000 users across Zomato Treats and about 160,000 across Zomato Gold.

Facebook had about 270 million users in India at the end of July, according to the Statista website. Some companies allow users to access their apps through Facebook logins.


A TripAdvisor spokesperson told ET that at this time, there is no evidence that any of its user information has been affected or compromised. Hotstar and BookMyShow didn’t respond to emails seeking comment till the time of going to press.

Rahul Kumar, cofounder of dating app Truly Madly, which requires a Facebook login, said his users were not impacted by the data breach. Aditya Gupta, cofounder of iGenero, said dating apps that are solely dependent on Facebook logins for access could be the most affected by the hack.

“People use Facebook logins to avoid creating other new accounts on apps and they think it’s convenient. Going forward, this will be a big issue for third-party apps and they might be figuring how to reduce dependency on the platform,” Gupta said.

Globally, dating app Tinder has asked Facebook to share more information on the breach.

Facebook said on Friday that hackers had exploited a bug in a feature that lets users see their Facebook page as others would. The hackers were able to take over the accounts and use them as if they were the account holders. That included posting or viewing information shared by friends on those accounts. Facebook said no credit card information stored with the company was accessed.

More than 90 million users were forcibly logged out of their accounts by Facebook and had to log back in on Friday for security reasons.

Alibaba planning to bring its China retail playbook to India

As Alibaba looks to expand its cloud business in India, having launched its second data centre in the country last week, it is looking to work with players in the retail space to bring its popular ‘new retail’ concept to India.

The company is even looking at bringing technology it is using in China such as augmented reality (AR) used in shopping events such as Single’s Day to the Indian retail industry to enhance the customer experience.

Alibaba Cloud has so far announced only its partnership with DLF shopping malls, but is said to be in talks with other major retail players as well.

“Retail has been a big focus for us in India,” said Vivek Gupta, head of business development for India and Saarc at Alibaba Cloud.

“We are talking to almost every single retail brand in the country. We want to partner with them in their omni-channel journey, as well as strengthen supply chain, offer intelligence on business operations, and enhance customer experience,” Gupta said.

Alibaba’s ‘new retail’ concept, coined by founder Jack Ma, includes a personalised experience for a customer in a physical store, customer analytics for offline stores to offer matching products, and integrating online experience at offline stores through customisation and deliveries.

“We think these products will meet the needs of the retail industry in the region who are looking to digitise their operations,” Gupta said.

According to one person aware of developments, augmented reality (AR) is also something Alibaba is looking to bring to the retail space in India. Alibaba had launched Taobao Buy as an AR experience application for shoppers two years ago.

“AR is used extensively during 11/11 shopping festivals,” Gupta said, referring to the popular Single’s Day celebrations in China.

“In China, Alibaba owns malls, stores as well as online platforms, and we can bring our experience here,” he said.

Other bets
Gupta said he could not comment on “futuristic” plans on AR. He also did not comment on Alibaba Cloud’s partnership with Paytm Mall, the e-commerce arm of Paytm, which is also focusing on omni-channel. Alibaba is an investor in Paytm Mall and parent company One 97 Communications.

Paytm Mall did not respond to queries. Alibaba Cloud had recently partnered with Paytm to launch the Paytm AI cloud, the Indian company’s foray into the cloud business “Paytm is a key partner in India. We will be the technology enabler in terms of enabling the Paytm AI Cloud,” Gupta said.

Apart from retail, Alibaba Cloud is also focusing on other verticals in the country for adoption. “Internet-enabled business around e-commerce, gaming are big business for us. We have seen strong adoption in media and entertainment, as well as in the manufacturing industry,” Gupta said.

Apollo Data Breach Leads To More Than 200 Million Contact Records Stolen

Data breaches, hacking attempts, data stealing, all these terms have now become something of a routine for the corporate sector. Once again, a massive hack allowed the attackers to pilfer over 200 million records. This time, the victim is a sales engagement company Apollo. The reports about the Apollo data breach surfaced online after the firm began notifying the customers.

Apollo Data Breach Exposed 200 Million Contact Database To Hackers

As disclosed by TechCrunch, the startup sales revenue and engagement service Apollo suffered a massive hack stealing millions of data records. Precisely, the company lost around 200 million records from its contact database in the Apollo data breach.

Reportedly, Bjoern Zinssmeister of Templarbit found an email generated by Apollo to its customers informing them of a breach. Zinssmeister shared the email with TechCrunch who then shared the contents of the email with the public.

According to the email, Apollo noticed the breach “weeks after system upgrades in July”. Explaining the details of the hacked data, the email read,

While the hackers have stolen contact information from Apollo’s database, the firm confirmed that financial details, Social Security numbers or other sensitive data remained unaffected as the firm does not store these details.

Investigations Underway
Right after noticing the breach, Apollo began investigating the matter. While the investigations are still in progress, Tim Zheng, CEO Apollo, said in his email that the firm informed the customers regarding the incident to comply with their transparency values. However he refused to give more details, as stated in his email,

Although the Apollo data breach merely exposed the “publicly gathered” information to the hackers, and so, some people may think of it as potentially less harmful. However, it certainly succeeds in getting listed among the top hacking attempts and data breaches happened this year such as the Chegg data breach, and the breach at the fashion retailer SheIn that affected millions of customers.

Let us know your thoughts in the comments section.

New iPhone Passcode Bypass Hack Exposes Photos and Contacts

Looking for a hack to bypass the passcode or screen lock on iPhones?
Jose Rodriguez, an iPhone enthusiast, has discovered a passcode bypass vulnerability in Apple’s new iOS version 12 that potentially allows an attacker to access photos and contacts, including phone numbers and emails, on a locked iPhone XS and other recent iPhone models.
Rodriguez, who also discovered iPhone lock screen hacks in the past, has posted two videos (in Spanish) on his YouTube channel under the account name Videosdebarraquito demonstrating a complicated 37-step iPhone passcode bypass process.

The iPhone authorization screen bypass flaw works on the latest iPhones, including the iPhone XS, running Apple's latest iOS 12 beta and iOS 12 operating systems.
Video Demonstrations: Here's How to Bypass iPhone Passcode
As you can watch in the video demonstrations, the iPhone hack works provided the attacker has physical access to the targeted iPhone that has Siri enabled and Face ID either disabled or physically covered.

Once these requirements are satisfied, the attacker can begin the complicated 37-step iPhone passcode bypass process by tricking Siri and iOS accessibility feature called VoiceOver to sidestep the iPhone's passcode.
Soon after Rodriguez released his videos, a tech channel on YouTube under the handle EverythingApplePro published a video in English explaining the same passcode bypass hack on iPhone XS.

This iPhone passcode bypass method potentially allows the attacker to access the contacts stored in the iPhone, including phone numbers and email addresses, and to access Camera Roll and other photo folders, by selecting a contact to edit and change its image.
Though Apple has some built-in security measures to prevent this from happening, Rodriguez found a way to bypass those security barriers, as you can see in the video.
Here's how to Fix the iPhone Passcode Bypass Bug
The passcode bypass methods work on all iPhones including the latest iPhone XS lineup, but the company does not appear to have patched the vulnerabilities in the latest iOS 12.1 beta.

Until Apple comes up with a fix, you can temporarily fix the issue by just disabling Siri from the lockscreen. Here's how to disable Siri:
Go to the Settings → Face ID & Passcode (Touch ID & Passcode on iPhones with Touch ID) and Disable Siri toggle under "Allow access when locked."
Of course, disabling Siri would cripple your iOS 12 experience, but would prevent attackers from abusing the feature and breaking into your iPhone.
Meanwhile, just wait for Apple to issue a software update to address the issue as soon as possible.
iPhone passcode bypass hack has become common over the last few years and appears almost after every iOS release. An iOS 9.3.1 passcode bypass was found last year, allowing an attacker to bypass Siri to search Twitter and gain access to locked iPhone's photos and contacts.

TCS conducts online test to hire engineering graduates; move aimed at covering larger talent base

While TCS is moving toward a digitised process of hiring, the company is not ending the campus recruitment process, says the company.

IT services bellwether, TCS, will focus more on online tests to recruit fresh engineering graduates. The move could be of great significance for students who would otherwise have been deprived of campus placements because of their colleges.

According to a report in The Times of India, TCS held an all-India online test - called the National Qualifier Test. The Bengaluru-headquartered firm is following it up with video interview, or a face-to face interview, depending on applicant's location.

"While TCS is moving toward a digitised process of hiring, the company is not ending the campus recruitment process," the company said in a statement.

The online recruitments will enable the IT firm to reach out to a far larger talent base irrespective of candidate's geographical location. TCS will also be able to finish up with hiring process in three-four weeks, which is way less time than the three-four months it took under the conventional method.

TCS earlier had a pool of 370 colleges from where it hired most of the fresh graduates. However, after the online test, the company reportedly said it could reach out to nearly 2,000 colleges, including those "in Baramulla, Kohima and other far-flung areas".

Last year, TCS had hired about 20,000 trainees. This year, it expects to bring more engineers onboard.

The number of students who registered for the test on the company's digital platform iON was 280,000 from 100 cities and 24 states, the report said, adding that this figure is 175 per cent higher than the number of students who registered for the traditional process last year.

"The basic process of campus recruitment is not changing but the way we are doing is changing... We have optimised recruitment so that it can be done faster in three to four weeks," Ajoy Mukherjee, executive VP and head of global human resources at TCS, told TOI.

For the current year, the tests were conducted earlier this month, and the interview process is going on. "We could not go to colleges in far-flung areas. Now they come together in one nearby accredited college or an iON centre for the interview," Mukherjee added.

The traditional campus recruitment process, however, will continue in top institutions such as the IITs, NITs and IIMs, the report added.

Disqus Shortname

Comments system