Connect with us

Business

Walgreens Is Openly Exposing the Data of Millions Who Registered for COVID Tests, Vox Claims

Published

on

Vox said the issues stem at least as far back as July 2020 but could potentially trace back to April 2020. Anyone signing up for a test with the pharmacy as of Wednesday will be similarly exposed.


Test Data Exposed

Vox’s Recode published an alarming report Monday that accuses Walgreens of exposing and failing to protect the personal data of millions who signed up for COVID-19 tests through its “sloppy” registration system.

That exposed data reportedly includes people’s name, birthday, gender identity, phone number, address, email information, and in some cases, even their test results. All of this “was left on the open web for potentially anyone to see and for the multiple ad trackers on Walgreens’ site to collect,” Recode reporter Sara Morrison said in the article, published Monday. 

According to Morrison, the exposed data potentially stretches as far back as April 2020, which is when Walgreens first began offering COVID-19 tests, but it definitively traces back at least to July 2020 given Recode’s findings.

The Issue Involves Test Confirmation Links

Security experts cited by Morrison said the vulnerabilities are basic issues that Walgreens, one of the largest pharmacy chains in the country, should have known how to prevent.

Essentially, anyone with a link to an appointment confirmation can view the full confirmation. There’s no need to log in or authenticate your identity any other way.

To make the situation even easier for bad actors, the links used to confirm appointments are exactly the same minus a unique patient ID contained in what’s called a “query string.” With millions of tests confirmed, it’s not hard for a hacker or a bot to start finding active pages, though a Morrison noted, it would be “close to impossible” to find a specific person through this method.

Still, it’s not totally impossible to find a specific person. If a patient views their confirmation link on a shared computer, such as one at work or a public library, anyone with the ability to check that computer’s browser history can click on the link and reap the person’s information. 

“Security by obscurity is an awful model for health records,” Sean O’Brien, founder of Yale’s Privacy Lab, told Recode. 

Walgreens Has Not Fixed the Issue

Even after one tech consultant discovered the issue in March and pointed it out to Walgreens multiple times, the company seemingly did nothing, according to Morrison.

From there, Recode said it informed Walgreens of the findings again and even gave it “time to fix the vulnerabilities before publishing” its piece, but once again, the company failed to do anything. 

As of right now, anyone scheduling a COVID test with Walgreens appears to be at the same level of risk as those who previously registered. Not only is that a concerning privacy issue, but it could also discourage many from getting tested. 

In statements to several outlets, Walgreens has not directly addressed the security concerns. For example, it only told Fox Business that it “routinely evaluate[s] our technology solutions in order to provide safe, secure, and accessible digital services to our customers and patients.”

For those seeking COVID tests and potentially discouraged by this news, it is important to remember that Walgreens isn’t the only pharmacy chain offering free tests. Cities and counties across the country are also continuing to offer free testing sites amid a spike in cases caused by the Delta variant.

See what others are saying: (Recode) (Fox Business) (Reuters)

Business

Amazon to Pay Over $30 Million for Alexa and Ring Privacy Violations

Published

on

Privacy violation charges stack up against the tech giant as the FTC partners up with the DOJ. 


Amazon Pays Up

Amazon agreed to a $30 million settlement for each of these complaints over complaints alleging that its Alexa and Ring products violated customer privacy.

The Federal Trade Commission and Justice Department accused Amazon of retaining children’s geolocation data as well as the recordings of their conversations with Alexa. Additionally, the FTC brought another complaint against Amazon’s Ring for violating their customers’ privacy and failing to complement basic security measures.

In addition to the accusations of retaining data, the FTC also charges Amazon with deceiving their customers, saying requests from parents to delete their children’s recordings and other data went ignored despite repeated assurances that parents can delete the data at any time. 

Amazon says this data was retained to train their Alexa algorithms to better understand children. But their reasoning does not change law. Their actions are still in violation of the federal Children’s Online Privacy Protection Act, known as COPPA. 

“Amazon’s history of misleading parents, keeping children’s recordings indefinitely, and flouting parents’ deletion requests violated COPPA and sacrificed privacy for profits,” said Samuel Levine, the director of the FTC’s Bureau of Consumer Protection in the press release regarding the complaint. “COPPA does not allow companies to keep children’s data forever for any reason, and certainly not to train their algorithms.”

The Settlement’s Details

The proposed settlement that Amazon agreed to on Wednesday includes a $25 million civil penalty as well as requirements to both delete the data in question and never use voice recordings of adults or children in the development or creation of a product again. 

However approval on this settlement is still needed from the federal courts. 

Despite agreeing to the settlement, Amazon denies violating COPPA, saying they designed Amazon Kids for parents to have full control and to comply with the law.

In their complaint against Ring, the FTC accused the company of violating their customers’ privacy by allowing countless employees and hundreds of contractors access to the videos from Ring cameras. 

Leading to situations like one in 2017, when a Ring employee watched thousands of videos belonging to dozens of female customers, including those in their bedrooms and bathrooms. 

Additionally, the FTC says that Ring did not implement basic security protections for years which allowed hackers to take control of their customers’ accounts, cameras, and videos  leading to 55,000 US Ring customers facing hacker attacks. In some cases, hackers could access Ring’s two-way functions to harass, insult, and threaten people – including children. The complaint alleges that Ring’s egregious privacy failings lasted for at least 4 years – between at least 2016 to 2020. 

Amazon responded to the complaint saying that RIng had addressed the concerns before the FTC even began their inquiry. 

The FTC proposed a settlement of $5.8 million in consumer refunds – as well as a demand for Ring to create a privacy and security program. The settlement also awaits federal court approval. 

See what others are saying: (New York Times) (Axios) (CNBC)

Continue Reading

Business

Right-Wingers Are Turning Against Chick-fil-A

Published

on

Some have accused the company of joining a woke “cult” after learning of its diversity, equity, and inclusion initiative.


Chick-fil-A Goes “Woke”

Conservatives are condemning Chick-fil-A after learning of the fast food chain’s commitments to diversity, equity, and inclusion.

Some have accused the brand of bowing “to the Woke mob.” Others have debated boycotting the chain.

It’s unclear when exactly Chick-fil-A began its DEI campaign, but according to LinkedIn, the current Vice President of DEI, Erick McReynolds, has been working in the department since 2020 before taking on his current role in 2021. It is also unclear why right-wingers on Twitter have just now discovered Chick-fil-A’s DEI website, but many spent a chunk of Tuesday morning lambasting the company for working to promote diversity. 

Chick-fil-A’s DEI page is titled “Committed to being Better at Together.” 

“Modeling care for others starts in the restaurant, and we are committed to ensuring mutual respect, understanding and dignity everywhere we do business,” McReynolds said in a statement on the website. 

Chick-fil-A is no stranger to boycott campaigns, though those efforts usually come from the opposite side of the political aisle. The company, known for its strong Christian ties, has been criticized for donating to groups with anti-LGBTQ missions. As a result, many on the left have refused to eat there, while it has been a haven for those on the right. 

Conservatives, however, have become increasingly outraged by DEI initiatives. Chick-fil-A’s website, which only vaguely outlines its DEI efforts, still seems to be enough for the right to change its tune about the brand. 

“Even our beloved Chick-Fil-A has fallen to the DEI cult,” one person tweeted. “the same agenda that is turning our beloved military woke.”

“It’s becoming an epidemic that even Christian companies are being strong-armed to participate in,” the tweet continued. 

Old Clip of Chairman Resurfaces 

Some have also started resurfacing an old clip of Chick-fil-A Chairman Dan Cathy speaking on a panel about racism during the summer of 2020. During the discussion, he talked about repentance and said that if you ever see someone who needs their shoes shined, you should do it. He then walked over to a Black person on the panel, got on his knees, and shined their shoes.

“There’s a time in which we need to have, you know, some personal action here, and maybe we need to give them a hug, too,” Cathy said while shining the shoes.

“I bought about 1,500 of these and I gave them to all our Chick-fil-A operators and staff a number of years ago,” Cathy continued, in reference to his shoe-shining brush. “So, any expressions of a contrite heart, of a sense of humility, a sense of shame, a sense of embarrassment begat with an apologetic heart — I think that’s what our world needs to hear today.”

The clip caused a stir when the events first unfolded, and has prompted a new wave of anger now. Some are accusing Cathy of being “a woke, anti-American, anti-white BLM boot licker” who thinks all white people need to shamefully shine the shoes of Black people to apologize for racism, though that is not what he said. 

These boycott calls are just the latest from conservatives who have been on a rampage against any company supporting any social cause they deem as “woke.” Earlier this year, the political right took a stand against Bud Light after it included a trans influencer in a sponsored Instagram post. Just last week, Target and Kohls faced boycotts over items in their Pride Month collections. 

See what others are saying: (The Hill) (Rolling Stone) (AL)

Continue Reading

Business

Bioré Apologizes For Referencing School Shooting in Mental Health Ad Campaign 

Published

on

 “Our tonality was completely inappropriate. We are so sorry,” the skincare brand said.


Video Faces Backlash

The skincare brand Bioré apologized this week for partnering with a school shooting survivor as part of its Mental Health Awareness Month campaign. 

“We are committed to continuing our mental health mission, but we promise to do it in a better way,” the company said in an Instagram post on Sunday. 

Last week, influencer and recent Michigan State University graduate Cecilee Max-Brown posted a video to TikTok sponsored by Bioré where she discussed the numerous challenges she had faced throughout the year. Among them was a school shooting on her college’s campus, which killed three people in February. 

“Life has thrown countless obstacles at me this year, from the school shooting to having no idea what life is going to look like after college,” Max-Brown says in the video. “In honor of mental health awareness month, I’m partnering with Bioré skin care to strip away the stigma of anxiety. 

“We want you to get it all out, not only what’s in your pores, but most importantly, what’s on your mind, too,” she continued. 

In the 50-second video, Max-Brown went on to discuss more details about her mental health struggles, as well as how “seeing the effects of gun violence firsthand” has impacted her and led to “countless anxiety attacks.”

“I will never forget the feeling of terror that I had walking around campus for weeks in a place I considered home,” she said before closing the video by encouraging her followers to participate in Bioré’s mental health campaign.

Bioré Apologizes

The video ignited swift outrage from people who accused Bioré of using a school shooting to sell products. In its apology, the brand admitted the video was misguided. 

In the past, Bioré said it has worked with influencers to discuss and reduce mental health stigmas, as the subject is a top priority for its consumers. 

“This time, however, we did it the wrong way,” the company said. “We lacked sensitivity around an incredibly serious tragedy, and our tonality was completely inappropriate. We are so sorry.”

Max-Brown also apologized on TikTok, writing that the video was intended to spread awareness, not suggest a product fixed the struggles she has experienced as a result of the shooting.

“I did not mean to desensitize the traumatic event that took place as I know the effects that it has had on me and the Spartan community,” she wrote. 

Max-Brown has since removed the initial sponsored video from her account.

See what others are saying: (The New York Times) (NBC News) (The Independent)

Continue Reading