Hello again!

It’s Evan, senior digital security trainer at Freedom of the Press Foundation (FPF), with our regular update on the U.S. journalism school digital security curriculum.

J-school security curriculum update

  • We’ve completed a major revamp of the digital security 101 module, including enhancements to the module’s structure and content. Designed for professors with limited time and space in their coursework to introduce digital security, the updated module features fresh template slides with more robust presenter notes and built-in engagement activities crafted to make getting started easier and quicker. As part of these changes, we’ve adjusted the module’s content to cover the basics across four foundational security topics — risk assessment, account security, device security, and communications security — and provided specific timing suggestions for each. We hope breaking the 101 module into more flexible components will help professors envision more opportunities to include this core content in their busy course schedules.

Highlights from digital security in the news

  • Court proceedings began last month in the case of Samuel Tunick, who allegedly provided U.S. border agents with a so-called duress passcode that wiped his phone’s digital contents during a secondary inspection at the Atlanta airport. The device was running GrapheneOS, a mobile operating system based on Android that offers a range of enhanced security and privacy features. One of those features includes the ability to enable such “duress passcodes,” which trigger the device to reset and wipe its contents if entered in lieu of the user’s unlock code. Months after the incident, Tunick was charged under a federal statute for knowingly destroying property to prevent its seizure. This marks the first known case in which U.S. federal prosecutors have brought charges over someone allegedly wiping data using a phone’s built-in duress password. The case also raises a wide range of questions about which constitutional rights apply — and which are suspended — at U.S. borders, including airports. Read more about the case.
  • A major security vulnerability in the popular German-based AI meeting assistant tl;dv exposed information on over 181,000 corporate and government video calls. The platform, which is used by dozens of government agencies, large universities, and major corporations, is built on Google Firebase. An independent researcher discovered that, due to a misconfiguration in tl;dv’s Firebase settings, unauthorized users were able to view meeting timestamps, creator email addresses, and real-time recording statuses, and potentially could even access active conference calls on Zoom, Google Meet, and Microsoft Teams. Despite reporting the vulnerability in January, as of late July the researcher said it remained unpatched. Read more about the vulnerability.
  • Coordinated attacks on municipal water utilities in over a dozen U.S. states, believed to be executed by hackers affiliated with the Iranian government, targeted weakly protected industrial computers responsible for managing operations on critical water systems. According to reports, the control systems were accessible directly on the public internet and in many cases used factory-default passwords like “1234” or “password.” Because of this, the attackers were able to use Shodan — a publicly available search engine for internet-connected devices — to locate the water utilities’ devices, look up their user manuals and default credentials, and directly log in to the systems. Once they gained access, attackers moved to lock out local operators. Read more about the attacks.

What we’re reading

  • We’ve been following the active legislative debates surrounding youth safety and generative AI, particularly the recently introduced CHATBOT Act. Under the proposed law, which advanced in the Senate Commerce Committee earlier this month, AI chatbots would be mandated to offer parents a federally prescribed “family account” system as part of the required parental-consent process for users under 18 years of age. These family accounts would be required to provide parents with a full record of their child’s chat history and receive automated alerts if there is any attempt to bypass parental controls. Digital rights groups, including the Electronic Frontier Foundation, have flagged serious concerns about the legislation. You can read EFF’s full analysis of the bill here.

As always, let me and our team know how you’re using the curriculum, what’s useful, and how it can be improved! Feel free to respond to this email or [email protected].

Thanks so much,
Evan

--

Evan Summers
Senior Digital Security Trainer
Freedom of the Press Foundation