l
l
blogger better. Powered by Blogger.

Search

Labels

blogger better

Followers

Blog Archive

Total Pageviews

Labels

Download

Blogroll

Featured 1

Curabitur et lectus vitae purus tincidunt laoreet sit amet ac ipsum. Proin tincidunt mattis nisi a scelerisque. Aliquam placerat dapibus eros non ullamcorper. Integer interdum ullamcorper venenatis. Pellentesque habitant morbi tristique senectus et netus et malesuada fames ac turpis egestas.

Featured 2

Curabitur et lectus vitae purus tincidunt laoreet sit amet ac ipsum. Proin tincidunt mattis nisi a scelerisque. Aliquam placerat dapibus eros non ullamcorper. Integer interdum ullamcorper venenatis. Pellentesque habitant morbi tristique senectus et netus et malesuada fames ac turpis egestas.

Featured 3

Curabitur et lectus vitae purus tincidunt laoreet sit amet ac ipsum. Proin tincidunt mattis nisi a scelerisque. Aliquam placerat dapibus eros non ullamcorper. Integer interdum ullamcorper venenatis. Pellentesque habitant morbi tristique senectus et netus et malesuada fames ac turpis egestas.

Featured 4

Curabitur et lectus vitae purus tincidunt laoreet sit amet ac ipsum. Proin tincidunt mattis nisi a scelerisque. Aliquam placerat dapibus eros non ullamcorper. Integer interdum ullamcorper venenatis. Pellentesque habitant morbi tristique senectus et netus et malesuada fames ac turpis egestas.

Featured 5

Curabitur et lectus vitae purus tincidunt laoreet sit amet ac ipsum. Proin tincidunt mattis nisi a scelerisque. Aliquam placerat dapibus eros non ullamcorper. Integer interdum ullamcorper venenatis. Pellentesque habitant morbi tristique senectus et netus et malesuada fames ac turpis egestas.

Wednesday, July 11, 2018

Come see Uber CEO Dara Khosrowshahi at TC Disrupt

In the days of Uber 1.0, the ethos seemed to be about doing all the wrong things. Now, with former Expedia CEO Dara Khosrowshahi at the helm, Uber is clearly on its way to becoming a sort of Expedia for transportation. Though, Khosrowshahi has previously likened Uber’s business to aligning more with the idea of an Amazon for transportation.

At TechCrunch Disrupt San Francisco in September, Khosrowshahi will join me to discuss Uber’s big plan to own the entire transportation experience for people, the highs and lows of his first year on the job, Uber’s upcoming initial public offering and much more.

Under Khosrowshahi’s leadership, Uber officially became a multi-modal transportation platform with its acquisition of JUMP Bikes for about $200 million, the launch of UberRENT and a public transportation partnership with Masabi.

Oh, and Uber is also working on electric scooters, as well as flying cars via its Elevate program. Just like residential and buildings have gone three-dimensional, Khosrowshahi said at a tech conference in May, “you’re going to have to build a third-dimension in terms of transportation.”

For Uber, Elevate is its “big bet” on that third-dimension of transportation, he said. The big plan with all of these modes of transportation — whether that’s bike sharing, electric scooter sharing, ride sharing, flight sharing or whatnot — is to become a multi-modal transportation service.

Under the leadership of Khosrowshahi, Uber also seems to be moving into an era where the company works with governments, instead of in spite of them. This is quite the 180 for Uber. Before the days of Khosrowshahi, Uber was reluctant to share data with cities. Now, Uber is expanding Movement, a platform that anonymizes and aggregates Uber data to map travel times, to 12 new cities across five continents. The intent is to help urban planners, local leaders and civic communities make more informed decisions.

While Khosrowshahi is making positive moves in a business direction, it’s worth noting the company is still in need of a chief financial officer, and there have been some high-level departures that have continued under his leadership. In June, for example, Uber’s chief brand officer, Bozoma Saint John, left a little after one year of joining the company.

At the time, Saint John told me that while “nothing horrible or terrible happened,” Uber’s corporate culture has not “righted itself 100 percent.” At Disrupt, Khosrowshahi and I will also discuss Uber’s corporate culture and what it’s going to take to fully recover from its 2017, which entailed reports of sexual harassment, mismanagement and a toxic work environment.

Tickets to Disrupt SF, which runs September 5 – September 7, are available here.



https://ift.tt/eA8V8J Come see Uber CEO Dara Khosrowshahi at TC Disrupt https://ift.tt/2KRmX8Y

Real estate platform Nestio raises $4.5 million

Real estate platform Nestio is getting new funding as it continues to expand its footprint beyond New York City into other large U.S. markets. The startup’s software gives real estate owners and managers a hub to handle things like leasing and marketing.

The round, which they announced today, was led by Camber Creek and Trinity Ventures, with participation from other real estate firms, including Rudin Ventures, Currency M, The Durst Organization, LeFrak Ventures and Torch Venture Capital. The startup has raised around $16 million to date.

Nestio is building up its unit count in new markets, including Boston, Chicago, Houston and Dallas, and is seeking to expand operations with existing customers in NYC. The startup says that it’s grown the amount of units on its platform by 250 percent in the past 12 months.

“We now have hundreds of thousands of listings on the platform that people are now managing,” Nestio CEO Caren Maio told TechCrunch. “Part of that growth is net new logos, but also expansion. So we’ve seen a lot of growth — particularly in New York — although I think the same behavior will replicate itself once we have some longevity in some of those other cities.”

The company says they will use this new capital and strategic partnerships to “deliver advanced leasing and marketing solutions even faster.”



https://ift.tt/eA8V8J Real estate platform Nestio raises $4.5 million https://ift.tt/2Lc7T1E

Twitter lets advertisers “takeover” the Explore tab

Twitter is ready to squeeze a lot more money out of its trending topics. After minimizing its mediocre Moments feature and burying it inside the renamed Explore tab, Twitter is now starting to test Promoted Trend Spotlight ads. These put a big visual banner equipped with a GIF or image background atop Explore for the first two times you visit that day before settling back into the Trends list, with the first batch coming from Disney in the US.

These powerful new ad units demote organic content in Explore, which could make it less useful for getting a grip on what’s up in the world at a glance. But they could earn Twitter  strong revenue by being much more eye-catching than the traditional Timeline ads that people often skip past. That could further fuel Twitter’s turnaround after it soundly beat revenue estimates in Q1 with $665 million. Its share price of about $44 is near its 52-week high, and almost 3X its low for the year.

“We are continuing to explore new ways to enhance our takeover offerings and give brands more high-impact opportunities to drive conversation and brand awareness on our platform” a Twitter spokesperson told TechCrunch.

The Promoted Trend Spotlight ads are bought as an add-on to the existing Promoted Trends ads that are inserted amongst the list of Twitter’s most popular topics. When tapped, they open a feed of tweets with that headline with one of the advertiser’s related tweets at the top. Back in February AdAge reported whispers of a new visual redesign for Promoted Trends. You can view a demo of the experience below.

Anthy Price, Disney’s Executive Vice President for Media provided TechCrunch with a statement, saying “The Promoted Trend Spotlight on Twitter allowed us to prominently highlight Winnie the Pooh & celebrate the launch of ticket sales for Christopher Robin while four of the characters took over major Disney handles on the platform to engage with fans.”

Historically, Twitter’s biggest problem was that people skimmed past ads. The old unfiltered Timeline trained users to pick and choose what they read, looking past anything that didn’t seem relevant including paid marketing. But with the shift to an algorithmic Timeline and bigger focus on video, Twitter has slowly retrained users to expect relevant content in every slot. Explore’s design with imagery at the top followed by a text list of Trends pulls attention to where these new Spotlight ads sit. With better monetization, Twitter will now have to concentrate on building better ways to get users to open Explore instead of just their feed, notifications, and DMs.



from Social – TechCrunch https://ift.tt/2m729LM Twitter lets advertisers “takeover” the Explore tab Josh Constine https://ift.tt/2N7C0rL
via IFTTT

Facebook independent research commission ‘Social Science One’ will share a petabyte of user data

Back in April, Facebook announced that it would be working with a group of academics to establish an independent research commission to look into issues of social and political significance using the company’s own extensive data collection. That commission just came out of stealth; it’s called Social Science One, and its first project will have researchers analyzing about a petabyte’s worth of sharing data.

The way the commission works is basically that a group of academics is created and given full access to the processes and datasets that Facebook could potentially provide. They identify and help design interesting sets based on their experience as researchers themselves, then document them publicly — for instance, “this dataset consists of 10 million status updates taken during the week of the Brexit vote, structured in such and such a way.”

This documentation describing the set doubles as a “request for proposals” from the research community. Other researchers interested in the data propose analyses or experiments, which are evaluated by commission. These proposals are then granted (according to their merit) access to the data, funding, and other privileges. Resulting papers will be peer reviewed with help from the Social Science Research Council, and can be published without being approved (or even seen) by Facebook.

“The data collected by private companies has vast potential to help social scientists understand and solve society’s greatest challenges. But until now that data has typically been unavailable for academic research,” said Social Science One co-founder, Harvard’s Gary King, in a blog post announcing the initiative. “Social Science One has established an ethical structure for marshaling privacy preserving industry data for the greater social good while ensuring full academic publishing freedom.”

If you’re curious about the specifics of the partnership, it’s actually been described in a paper of its own, available here.

The first dataset is a juicy one: “almost all” public URLs shared and clicked by Facebook users globally, accompanied by a host of useful metadata.

It will contain “on the order of 2 million unique URLs shared in 300 million posts, per week,” reads a document describing the set. “We estimate that the data will contain on the order of 30 billion rows, translating to an effective raw size on the order of a petabyte.”

The metadata includes country, user age, device and so on, but also dozens of other items, such as “ideological affiliation bucket,” the proportion of friends vs. non-friends who viewed a post, feed position, the number of total shares, clicks, likes, hearts, flags… there’s going to be quite a lot to sort through. Naturally all this is carefully pruned to protect user privacy — this is a proper research dataset, not a Cambridge Analytica-style catch-all siphoned from the service.

In a call accompanying the announcement, King explained that the commission had much more data coming down the pipeline, with a focus on disinformation, polarization, election integrity, political advertising, and civic engagement.

“It really does get at some of the fundamental questions of social media and democracy,” King said on the call.

The other sets are in various stages of completeness or permission: post-election survey participants in Mexico and elsewhere are being asked if their responses can be connected with their Facebook profiles; the political ad archive will be formally made available; they’re working on something with CrowdTangle; there are various partnerships with other researchers and institutions around the world.

A “continuous feed of all public posts on Facebook and Instagram” and “a large random sample of Facebook newsfeeds” are also under consideration, probably encountering serious scrutiny and caveats from the company.

Of course quality research must be paid for, and it would be irresponsible not to note that Social Science One is funded not by Facebook but by a number of foundations: the Laura and John Arnold Foundation, The Democracy Fund, The William and Flora Hewlett Foundation, The John S. and James L. Knight Foundation, The Charles Koch Foundation, Omidyar Network’s Tech and Society Solutions Lab, and The Alfred P. Sloan Foundation.

You can keep up with the organization’s work here; it really is a promising endeavor and will almost certainly produce some interesting science — though not for some time. We’ll keep an eye out for any research emerging from the partnership.



from Social – TechCrunch https://ift.tt/eA8V8J Facebook independent research commission ‘Social Science One’ will share a petabyte of user data Devin Coldewey https://ift.tt/2ua38ze
via IFTTT

Alan introduces Alan Blue, a high-end health insurance product

French startup Alan has been mostly focused on its main health insurance product — a standard package for companies of all sizes and shapes. The company is launching a second offering on this market with Alan Blue.

Companies can now choose between two levels of insurance — Alan Green and Alan Blue. Alan Green is the existing health insurance product with a new name. It still costs the same and offers the same level of coverage. Alan Blue is a higher-end product with better coverage for companies who want to retain talent using better benefits.

French employees automatically get basic coverage from the national healthcare system. But companies also need to provide a health insurance from a private company to pay for part of the health expenses. It’s a hybrid system with a strong legal framework.

This is where Alan comes along as your employer signs a deal with an insurance company to cover all their employees. Usually, insurance companies provide multiple offerings. But Alan has historically focused on a single plan.

With Alan Green, you get good coverage starting at $59 (€50) per month per employee if you’re under 36 years old. It gets more expensive if you’re over 36, and then over 45, and then over 56 years old. Plans for employees over 56 cost $100 per month (€85).

Companies have to pay at least 50 percent of those plans. The rest is deducted from your pay. Some companies also choose to pay 100 percent of everyone’s health insurance to show that they really care about their employees.

Employees can also choose to cover their spouse and kids with Alan. Plans for a second adult cost the same as plans for employees. And you can cover all your kids for a $47 flat monthly fee (€40).

While you won’t pay anything if you see a normal medial practitioner, Alan Green couldn’t necessarily cover an expensive pair of glasses or extensive dental work.

Alan Blue is a second option for companies looking for a premium health insurance product. Companies now have to decide between the two plans for the entire staff. You can’t let employees decide between one plan or the other.

Alan Blue starts at $82 per month (€70) for young employees and also gets more expensive depending on the age of the employee. While there’s only a €20 difference between the two offerings for employees under 36 years old, the price difference is higher the older you get. Similarly, you can cover all your kids for a slightly more expensive $64 flat monthly fee (€55).

For companies that choose to fully pay for health insurance, it depends if you’re willing to spend more to provide better insurance. But some companies only pay part of the health insurance package. Employees will end up paying more if their companies switch from Alan Green to Alan Blue.

“Overall, companies that are growing rapidly tend to invest a lot for their employees and switch to Alan Blue,” co-founder and CEO Jean-Charles Samuelian told me. “We already noticed that with companies in our existing clients. Some companies are also switching to Alan because they wanted something very high end before switching.”

Alan still plans to target small companies. The startup thinks that small companies are underserved by big insurance companies and tend to pay more for health insurance.

Alan Green is not going away anytime soon. Samuelian thinks you can combine Alan Green with Alan Map to find the perfect doctor around you and get fully reimbursed.

Alan Blue is already available to selected Alan customers. All companies will be able to sign up in September. You can already view all pricing and insurance details on Alan’s website.



https://ift.tt/eA8V8J Alan introduces Alan Blue, a high-end health insurance product https://ift.tt/2NF5Bd4

Hold for the drop: Twitter to purge locked accounts from follower metrics

Twitter is making a major change aimed at cleaning up the spammy legacy of its platform.

This week it will globally purge accounts it has previously locked (i.e. after suspecting them of being spammy) — by removing the accounts from users’ follower metrics.

Which in plain language means Twitter users with lots of followers are likely to see their follower counts take a noticeable hit in the coming days. So hold tight for the drop.

Late last month Twitter flagged smaller changes to follower counts, also as part of a series of platform-purging anti-spam measures — warning users they might see their counts fluctuate more as counts had been switched to being displayed in near real-time (in that case to try to prevent spambots and follow scams artificially inflating account metrics).

But the global purge of locked accounts from user account metrics looks like it’s going to be a rather bigger deal, putting some major dents in certain high profile users’ follower counts — and some major dents in celeb egos.

Hence Twitter has blogged again. “Follower counts are a visible feature, and we want everyone to have confidence that the numbers are meaningful and accurate,” writes Twitter’s Vijaya Gadde, legal, policy and trust & safety lead, flagging the latest change.

It will certainly be interesting to see whether the change substantially dents Twitter follower counts of high profiles users — such as Katy Perry (109,609,073 Twitter followers at the time of writing) Donald Trump (53,379,873); Taylor Swift (85,566,010); Elon Musk (22,329,075); and Beyoncé (15,303,191), to name a few of the platform’s most followed users.

Check back in a week to see how their follower counts look.

“Most people will see a change of four followers or fewer; others with larger follower counts will experience a more significant drop,” warns Gadde, adding: “We understand this may be hard for some, but we believe accuracy and transparency make Twitter a more trusted service for public conversation.”

Twitter is also warning that while “the most significant changes” will happen in the next few days, users’ follower counts “may continue to change more regularly as part of our ongoing work to proactively identify and challenge problematic accounts”.

The company says it locks accounts if it detects sudden changes in account behavior — such as tweeting “a large volume of unsolicited replies or mentions, Tweeting misleading links, or if a large number of accounts block the account after mentioning them” — which therefore may indicate an account has been hacked/taken over by a spambot.

It says it may also lock accounts if we see email and password combinations from other services posted online and believe that information could put the security of an account at risk.

After locking an account Twitter contacts the owner to try to confirm they still have control of the account. If the owner does not reply to confirm the account stays locked — and will soon also be removed from follower counts globally.

Twitter emphasizes that locked accounts already cannot Tweet, like or Retweet, and are not served ads. But removing them from follower counts is an important additional step that it’s great to see Twitter making — albeit at long last

Twitter also specifies that locked accounts that have not reset their password in more than one month were already not included in Twitter’s MAU or DAU counts — so it today reiterates the CFO’s recent message, saying this change won’t affect its own platform usage metrics. 

The company has been going through what — this time — looks to be a serious house-cleaning process for some months now, after years and years of criticism for failing to tackle rampant spam and abuse on its platform.

In March, Twitter CEO Jack Dorsey also put out a call for ideas to help it capture, measure and evaluate healthy interactions on its platform and the health of public conversations generally — saying: “Ultimately we want to have a measurement of how it affects the broader society and public health, but also individual health, as well.”



from Social – TechCrunch https://ift.tt/eA8V8J Hold for the drop: Twitter to purge locked accounts from follower metrics Natasha Lomas https://ift.tt/2mf9Srr
via IFTTT

Aurora Labs raises $8.4 million to bring its self-healing software to cars

Aurora Labs, a company that has created predictive tools that will automatically fix problems with software in cars, has raised $8.4 million in a Series A round of financing led by Fraser McCombs Capital.

Previous investor MizMaa Ventures also joined the round. The Tel Aviv-based company just came out of stealth a few months ago.

Aurora Labs plans to use the additional funds to expand its presence beyond its new offices in Munich, Germany and Tel Aviv headquarters. The company has 17 employees and plans to add a handful more by the end of the year, as well as open sales offices in Detroit and San Francisco, CEO and co-founder of Aurora Labs Zohar Fox told TechCrunch.

Vehicles today have millions of lines of code. As the automotive industry becomes increasingly reliant on software, the risk of glitches impacting the operation of vehicles grows. And it’s already proving to be a costly problem for automakers. Some 15 million vehicles globally were recalled in 2017 for software flaws, according to Aurora Labs.

Aurora Labs developed a platform designed to detect (and even predict) problems and then fix any issues on the fly. It also can provide over-the-air software updates to allow automakers the ability to make swift changes to electronic control unit software.

The company already has a few takers of its tech; Aurora Labs has locked in three unnamed automakers as customers and pilots are underway.

The company’s tech might be useful for today’s connected cars. But Aurora’s co-founders Fox and Ori Lederman see an opportunity with the wave of autonomous vehicles that will be deployed in the future.

“The number of lines of code in vehicles is already roughly 150 million and is only expected to climb,” Fox said, adding that quality assurance misses about 15 percent of the average 15 to 50 errors for every thousand lines of code. This stat highlights the need for solutions that can predict downtime events before they cause safety issues, he added. 



https://ift.tt/eA8V8J Aurora Labs raises $8.4 million to bring its self-healing software to cars https://ift.tt/2mblZpo

Facial recognition startup Kairos acquires Emotion Reader

Kairos, the face recognition technology used for brand marketing, has announced the acquisition of EmotionReader.

EmotionReader is an Limerick, Ireland-based startup that uses algorithms to analyze facial expressions around video content. The startup allows brands and marketers to measure viewers emotional response to video, analyze viewer response via an analytics dashboard, and make different decisions around media spend based on viewer response.

The acquisition makes sense considering that Kairos core business is focused on facial identification for enterprise clients. Knowing who someone is, paired with how they feel about your content, is a powerful tool for brands and marketers.

The idea for Kairos started when founder Brian Brackeen was making HR time-clocking systems for Apple. People were cheating the system, so he decided to implement facial recognition to ensure that employees were actually clocking in and out when they said they were.

That premise spun out into Kairos, and Brackeen soon realized that facial identification as a service was much more powerful than any niche time clocking service.

But Brackeen is very cautious with the technology Kairos has built.

While Kairos aims to make facial recognition technology (and all the powerful insights that come with it) accessible and available to all businesses, Brackeen has been very clear about the fact that Kairos isn’t interested in selling this technology to government agencies.

Brackeen recently contributed a post right here on TechCrunch outlining the various reasons why governments aren’t ready for this type of technology. Alongside the outstanding invasion of personal privacy, there are also serious issues around bias against people of color.

From the post:

There is no place in America for facial recognition that supports false arrests and murder. In a social climate wracked with protests and angst around disproportionate prison populations and police misconduct, engaging software that is clearly not ready for civil use in law enforcement activities does not serve citizens, and will only lead to further unrest.

As part of the deal, EmotionReader CEO Padraig O’Leary will run Kairos’ new Singapore-based R&D center, allowing for upcoming APAC expansion.

Kairos has raised approximately $8 million from investors New World Angels, Kapor Capital, 500 Startups, Backstage Capital, Morgan Stanley, Caerus Ventures, and Florida Institute.



https://ift.tt/eA8V8J Facial recognition startup Kairos acquires Emotion Reader https://ift.tt/2NIWXdO

Timehop admits that additional personal data was compromised in breach

Timehop is admitting that additional personal information was compromised in a data breach on July 4.

The company first acknowledged the breach on Sunday, saying that users’ names, email addresses and phone numbers had been compromised. Today it said it that additional information, including date of birth and gender, was also taken.

To understand what happened, and what Timehop is doing to fix things, I spoke to CEO Matt Raoul, COO Rick Webb and the security consultant that the company hired to manage its response. (The security consultant agreed to be interviewed on-the-record on the condition that they not be named.)

To be clear, Timehop isn’t saying that there was a separate breach of its data. Instead, the team has discovered that more data was taken in the already-announced incident.

Why didn’t they figure that out sooner? In an updated version of its report (which was also emailed to customers), the company put it simply: “Because we messed up.” It goes on:

In our enthusiasm to disclose all we knew, we quite simply made our announcement before we knew everything. With the benefit of staff who had been vacationing and unavailable during the first four days of the investigation, and a new senior engineering employee, as we examined the more comprehensive audit on Monday of the actual database tables that were stolen it became clear that there was more information in the tables than we had originally disclosed. This was precisely why we had stated repeatedly that the investigation was continuing and that we would update with more information as soon as it became available.

In both the email and my interviews, the Timehop team noted that the service does not have any financial information from users, nor does it perform the kinds of detailed behavioral tracking that you might expect from an ad-supported service. The team also emphasized that users’ “memories” — namely, the older social media posts that people use Timehop to rediscover — were not compromised.

How can they be sure, particularly since some of the compromised data was overlooked in the initial announcement? Well, the breach affected one specific database, while the memories are stored separately.

“That stuff is what we cared about, that stuff was protected,” Webb said. The challenge is, “We have to make a mental note to think about everything else.”

Timehop team

The breach occurred when someone accessed a database in Timehop’s cloud infrastructure that was not protected by two-factor authentication, though Raoul insisted that the company was already using two-factor quite broadly — it’s just that this “fell through the cracks.”

It’s also worth noting that while 21 million accounts were affected, Timehop had varying amounts of data about different users. For example, it says that 18.6 million email addresses were compromised (down from the “up to 21 million” addresses first reported), compared to 15.5 million dates of birth. In total, the company says 3.3 million records were compromised that included names, email addresses, phone numbers and DOBs.

None of those things may seem terribly sensitive (anyone with a copy of my business card and access to Google could probably get that information about me), but the security consultant acknowledged that in the “very, very small percentage” of cases where the records included full names, email addresses, phone numbers and DOBs, “identity theft becomes more likely,” and he suggested that users take standard steps to protect themselves, including password-protecting their phones.

Meanwhile, the company says that it worked with the social media platforms to detect activity that used the compromised authorization tokens, and it has not found anything suspicious. At this point, all of the tokens have been deauthorized (requiring users to re-authorize all of their accounts), so it shouldn’t be an ongoing issue.

As for other steps Timehop is taking to prevent future breaches, the security consultant told me the company is already in the process of ensuring that two-factor authentication is adopted across the board and encrypting its databases, as well as improving the process of deploying code to address security issues.

In addition, the company has shared the IP addresses used in the attack with law enforcement, and it will be sharing its “indicators of compromise” with partners in the security community.

Timehop screenshot

Everyone acknowledged that Timehop made real mistakes, both in its security and in the initial communication with customers. (As the consultant put it, “They made a schoolboy mistake by not doing two-factor authentication.”) However, they also suggested that their response was guided, in part, by the accelerated disclosure timeline required by Europe’s GDPR regulations.

The security consultant told me, “We haven’t had the time fine-toothed comb kinds of things we normally want to do,” like an in-depth forensic analysis. Those things will happen, he said — but thanks to GDPR, the company needed to make the announcement before it had all the information.

And overall, the consultant said he’s been impressed by Timehop’s response.

“I think it really says a lot to their integrity that they decided to go fully public the second they knew it was a breach,” he said. “I want to point out these guys responded within 24 hours with a full-on incident response and secured their environments. That’s better than so many companies.”



from Social – TechCrunch https://ift.tt/2zqMTTG Timehop admits that additional personal data was compromised in breach Anthony Ha https://ift.tt/2L8d71X
via IFTTT

Timehop admits that additional personal data was compromised in breach

Timehop is admitting that additional personal information was compromised in a data breach on July 4.

The company first acknowledged the breach on Sunday, saying that users’ names, email addresses and phone numbers had been compromised. Today it said it that additional information, including date of birth and gender, was also taken.

To understand what happened, and what Timehop is doing to fix things, I spoke to CEO Matt Raoul, COO Rick Webb and the security consultant that the company hired to manage its response. (The security consultant agreed to be interviewed on-the-record on the condition that they not be named.)

To be clear, Timehop isn’t saying that there was a separate breach of its data. Instead, the team has discovered that more data was taken in the already-announced incident.

Why didn’t they figure that out sooner? In an updated version of its report on the incident (which was also emailed to customers), the company put it simply: “Because we messed up.” It goes on:

In our enthusiasm to disclose all we knew, we quite simply made our announcement before we knew everything. With the benefit of staff who had been vacationing and unavailable during the first four days of the investigation, and a new senior engineering employee, as we examined the more comprehensive audit on Monday of the actual database tables that were stolen it became clear that there was more information in the tables than we had originally disclosed. This was precisely why we had stated repeatedly that the investigation was continuing and that we would update with more information as soon as it became available.

In both the email and my interviews, the Timehop team noted that the service does not have any financial information from users, nor does it do the kinds of detailed behavioral tracking that you might expect from an ad-supported service. The team also emphasized that users’ “memories” — namely, the older social media posts that people use Timehop to rediscover — were not compromised.

How can they be sure, particularly since some of the compromised data was overlooked in the initial announcement? Well, the breach affected one particular database, while the memories are stored separately.

“That stuff is what we cared about, that stuff was protected,” Webb said. The challenge is, “We have to make a mental note to think about everything else.”

Timehop team

The breach occurred when someone accessed a database in Timehop’s cloud infrastructure that that was not protected by two-factor authentication, though Raoul insisted that the company was already using two-factor quite broadly — it’s just that this “fell through the cracks”

It’s also worth noting that while 21 million accounts were affected, Timehop had varying amounts of data about different users. For example, it says that 18.6 million email addresses were compromised (down from the “up to 21 million” addresses first reported), compared to 15.5 million dates of birth. In total, the company says 3.3 million records were compromised that included names, email addresses, phone numbers and DOBs.

None of those things may seem terribly sensitive (anyone with a copy of my business card and access to Google could probably get that information about me), but the security consultant acknowledged that in the “very, very small percentage” of cases where the records included full names, email addresses, phone numbers and DOBs, “identity theft becomes more likely,” and they suggested that users take standard steps to protect themselves, including password-protecting their phones.

Meanwhile, the company says that it worked with the social media platforms to detect activity using the authorization tokens that were also compromised, and it has not found anything suspicious. At this point, all of the tokens have been de-authorized (requiring users to re-authorize all of their accounts), so it shouldn’t be an ongoing issue.

As for other steps Timehop is taking to prevent future breaches, the security consultant told me the company is already in the process of ensuring that two-factor authentication is adopted across the board and encrypting its databases, as well as improving the process of deploying code to address security issues.

In addition, the company has shared the IP addresses used in the attack with law enforcement, and it will be sharing its “indicators of compromise” with partners in the security community.

Everyone acknowledged that Timehop made real mistakes, both in its security and in the initial communication with customers. (As the consultant put it, “They made a schoolboy msitake by not doing two-factor authentication.”) However, they also suggested that their response was guided, in part, by the accelerated disclosure timeline required by Europe’s GDPR regulations.

The security consultant told me, “We haven’t had the time fine-toothed comb kinds of things normally want to do,” like an in-depth forensic analysis. Those things will happen, they said — but thanks to GDPR, the company needed to make the announcement before it had all the information.

And overall, the consultant said he’s been impressed by Timehop’s response.

“I think it really says a lot to their integrity that they decided to go fully public the second they knew it as a breach,” he said. “I want to point out these guys repsonded within 24 hours with a full-on incident response and secured their environments. That’s better than so many companies.”



https://ift.tt/2zqMTTG Timehop admits that additional personal data was compromised in breach https://ift.tt/2L8d71X

Opera adds a crypto wallet to its mobile browser

{rss:content:encoded} Opera adds a crypto wallet to its mobile browser https://ift.tt/2Jd0y0b https://ift.tt/2L0LaJf July 11, 2018 at 04:33PM

The Opera Android browser will soon be able to hold your cryptocurrencies. The system, now in beta, lets you store crypto and ERC20 tokens in your browser, send and receive crypto on the fly, and secures your wallet with your phone’s biometric security or passcode.

You can sign up to try the beta here.

The feature, called Crypto Wallet, “makes Opera the first major browser to introduce a built-in crypto wallet” according to the company. The feature could allow for micropayments in the browser and paves the way for similar features in other browsers.

From the release:

We believe the web of today will be the interface to the decentralized web of tomorrow. This is why we have chosen to use our browser to bridge the gap. We think that with a built-in crypto wallet, the browser has the potential to renew and extend its important role as a tool to access information, make transactions online and manage users’ online identity in a way that gives them more control.

In addition to being able to send money from wallet to wallet and interact with Dapps, Opera now supports online payments with cryptocurrency where merchants support exists. Users that choose to pay for their order using cryptocurrency on Coinbase Commerce-enabled merchants will be presented with a payment request dialog, asking them for their signature. The payment will then be signed and transmitted directly from the browser.

While it’s still early days for this sort of technology it’s interesting to see a mainstream browser entering the space. Don’t hold your breath on seeing crypto in Safari or Edge but Chrome and other “open source” browsers could easily add these features given enough demand.

Pinterest is adding a way for users to collaborate on boards

{rss:content:encoded} Pinterest is adding a way for users to collaborate on boards https://ift.tt/2m7djAd https://ift.tt/2L6hQO5 July 11, 2018 at 04:00PM

Pinterest is trying to further tap its popularity as a place to plan events, this time adding ways for users to collaborate across boards that are baked directly into the app.

Group boards will have their own designated feed, where users will be able to communicate with others collaborating on that board and also get updates on new member additions or added pins. There are also the other typical social structures you’d expect on an app these days, including @-mentions or liking comments. It’s another step to get people onto Pinterest and sticking around as they look to plan events, and create more ways to make the platform more and more sticky. It’s also another quality-of-life improvement that Pinterest seems to have needed for quite some time.

It’s those kinds of events — weddings, parties and others — that propelled Pinterest initially to become one of the larger social networks in the early 2010s. The company late last year said it had more than 200 million monthly active users, which while small compared to the likes of Instagram or Facebook, serves as a hub for a different kind of user behavior than you might find on those other platforms. The majority of the content on Pinterest is high-resolution products from businesses, where people will search for or save those products as they look to plan future life events.

Pinterest has tried to position itself as one of the best ways to discover new ideas, whether that’s stumbling upon something in a primary feed or finding something through searching. Over time, it’s added more and more tools to try to get people to come back more regularly, and if it continues to improve those recommendation engines, it can continue to run that feedback loop and keep users more and more attached to the platform. Adding a sort of light social pressure from friends that are sharing ideas and looking for feedback is one way to do that, in addition to it generally being useful.

All that is good for its pitch to advertisers as well. Pinterest, in addition to trying to cater to that unique kind of user behavior, is also trying to sell itself to advertisers as a platform where they can reach potential customers through ways they wouldn’t be able to with primary advertising channels like Facebook or Google. By making the platform more sticky, it can go back to those advertisers and offer them better engagement metrics and show that users stick around and are paying closer attention to content on Pinterest, which can in turn drive that additional value to advertisers.

blogger better Headline Animator