Tag Archive for: protections

Android Q will come with improved privacy protections – Help Net Security

  1. Android Q will come with improved privacy protections  Help Net Security
  2. Two-thirds of Android’s antivirus apps found to be completely useless  TechRadar
  3. Google Gives Users More Choice with Location-Tracking Apps  Threatpost
  4. Two thirds of Android antivirus apps are pure snake oil  TrustedReviews
  5. iPhones vs viruses | Komando.com – Komando  Komando
  6. View full coverage on read more

“android security news” – read more

California proposes tougher customer protections after data breaches – CNN

  1. California proposes tougher customer protections after data breaches  CNN
  2. California bill aims to strengthen data breach notification law  Engadget
  3. California to close data breach notification loopholes under new law  TechCrunch
  4. Expanding Data Breach Notification in California  The National Law Review
  5. California Bill Aims to Give Privacy Law Sharper ‘Teeth’  Courthouse News Service
  6. View full coverage on read more

“data breach” – read more

Supreme Court Says Civil Asset Forfeiture Violates Constitutional Protections Against Excessive Fines

Great news on the asset forfeiture front, courtesy of the highest court in the land. The Supreme Court has ruled that forfeitures can violate the Eighth Amendment’s protections against excessive fines.

The case the Supreme Court ruled on deals with Indiana native Tyson Timbs. Timbs sold $ 260 worth of heroin to undercover officers. He pled guilty to criminal charges. The state decided to forfeit his $ 42,000 Land Rover via civil asset forfeiture, routing around the criminal system to make it easier for cops to make off with his vehicle. Timbs challenged this forfeiture as an excessive fine, given that the max fine for his criminal charges was $ 10,000.

This case made its way to the state’s Supreme Court, which overturned the lower court’s decision finding in favor of Timbs and the US Constitution, which Indiana had incorporated. The state’s highest court stated that this clause of the Eighth Amendment did not apply to civil asset forfeiture. This was a bizarre position to take, as the Supreme Court pointed out during oral arguments.

JUSTICE GORSUCH: Well, whatever the Excessive Fine Clause guarantees, we can argue, again, about its scope and in rem and in personam, but whatever it, in fact, is, it applies against the states, right?

MR. FISHER: Well, again, that depends.

JUSTICE GORSUCH: I mean, most — most of the incorporation cases took place in like the 1940s.

MR. FISHER: Right.

JUSTICE GORSUCH: And here we are in 2018 -­

MR. FISHER: Right.

JUSTICE GORSUCH: — still litigating incorporation of the Bill of Rights. Really? Come on, General.

The Supreme Court’s decision [PDF] makes it clear the US Constitution protects citizens from excessive fines, even if those fines are meted out at the state level. If the Constitution has been incorporated by the states (and it has!), the protections apply.

Held: The Eighth Amendment’s Excessive Fines Clause is an incorporated protection applicable to the States under the Fourteenth Amendment’s Due Process Clause. Pp. 2–9. (a) The Fourteenth Amendment’s Due Process Clause incorporates and renders applicable to the States Bill of Rights protections “fundamental to our scheme of ordered liberty,” or “deeply rooted in this Nation’s history and tradition.” McDonald v. Chicago, 561 U. S. 742, 767 (alterations omitted). If a Bill of Rights protection is incorporated, there is no daylight between the federal and state conduct it prohibits or requires.

The state tried to argue the protections only covered in personam (vs. a person) forfeiture — the kind normally seen in criminal cases where property is seized as compensation for fines or as direct, provable ill-gotten goods obtained as the result of criminal activity.

In rem forfeiture — the civil route — lowers the evidentiary bar law enforcement must meet to take property away from citizens. In most cases, there are no criminal charges involved — only accusations of criminal origin that force citizens to prove a negative to reclaim their seized property.

Here’s where this decision has the chance to disrupt a majority of states’ civil asset forfeiture programs: the Supreme Court says these incorporated protections also apply to in rem seizures.

As a fallback, Indiana argues that the Excessive Fines Clause cannot be incorporated if it applies to civil in rem forfeitures. We disagree. In considering whether the Fourteenth Amendment incorporates a protection contained in the Bill of Rights, we ask whether the right guaranteed—not each and every particular application of that right—is fundamental or deeply rooted.

Indiana’s suggestion to the contrary is inconsistent with the approach we have taken in cases concerning novel applications of rights already deemed incorporated. For example, in Packingham v. North Carolina, 582 U. S. ___ (2017), we held that a North Carolina statute prohibiting registered sex offenders from accessing certain commonplace social media websites violated the First Amendment right to freedom of speech. In reaching this conclusion, we noted that the First Amendment’s Free Speech Clause was “applicable to the States under the Due Process Clause of the Fourteenth Amendment.” Id., at ___ (slip op., at 1). We did not, however, inquire whether the Free Speech Clause’s application specifically to social media websites was fundamental or deeply rooted. See also, e.g., Riley v. California, 573 U. S. 373 (2014) (holding, without separately considering incorporation, that States’ warrantless search of digital information stored on cell phones ordinarily violates the Fourth Amendment). Similarly here, regardless of whether application of the Excessive Fines Clause to civil in rem forfeitures is itself fundamental or deeply rooted, our conclusion that the Clause is incorporated remains unchanged.

So, the rhetorical question posed by this decision is one that’s going to be asked of hundreds of state-level civil asset forfeiture programs: if there are no criminal charges, wouldn’t ANY seizure of property be “excessive?” It certainly appears a lack of criminal charges would be fatal to in rem seizures, which almost always happen without accompanying charges. This case may not have been specifically about civil asset forfeiture, given Tyson Timbs’ guilty plea, but the state made it about it by refusing to acknowledge its incorporation of the Bill of Rights.

This may start a scramble by law enforcement to suss out just how much of the Bill of Rights their particular state has incorporated. Given the Supreme Court’s disdain for arguments to the contrary, pushing legal challenges to forfeiture programs uphill is a non-starter. This case was a 9-0 rout in favor of protecting Americans from excessive fines and fees — in this case taking the form of civil asset forfeiture. This hopefully will be the starting point for nationwide reform of these abusive programs.

Permalink | Comments | Email This Story

Techdirt.

Potentially disastrous Rowhammer bitflips can bypass ECC protections

A DDR3 DIMM with error-correcting code from Samsung. ECC is no longer an absolute defense against Rowhammer attacks.

Enlarge / A DDR3 DIMM with error-correcting code from Samsung. ECC is no longer an absolute defense against Rowhammer attacks. (credit: Samsung)

In early 2015, researchers unveiled Rowhammer, a cutting-edge hack that exploits unfixable physical weaknesses in the silicon of certain types of memory chips to transform data they stored. In the 42 months that have passed since then, an enhancement known as error-correcting code (or ECC) available in higher-end chips was believed to be an absolute defense against potentially disastrous bitflips that changed 0s to 1s and vice versa.

Research published Wednesday has now shattered that assumption.

Dubbed ECCploit, the new Rowhammer attack bypasses ECC protections built into several widely used models of DDR3 chips. The exploit is the product of more than a year of painstaking research that used syringe needles to inject faults into chips and supercooled chips to observe how they responded when bits flipped. The resulting insights, along with some advanced math, allowed researchers in Vrije Universiteit Amsterdam’s VUSec group to demonstrate that one of the key defenses against Rowhammer isn’t sufficient.

Read 18 remaining paragraphs | Comments

Biz & IT – Ars Technica