Jun
30
2021
--

Google tightens UK policy on financial ads after watchdog pressure over scams

The UK’s more expansive, post-Brexit role in digital regulation continues to be felt today via a policy change by Google which has announced that it will, in the near future, only run ads for financial products and services when the advertiser in question has been verified by the financial watchdog, the FCA.

The Google Ads Financial Products and Services policy will be updated from August 30, per Google, which specifies that it will start enforcing the new policy from September 6 — meaning that purveyors of online financial scams who’ve been relying on its ad network to net their next victim still have more than two months to harvest unsuspecting clicks before the party is over (well, in the UK, anyway).

Google’s decision to allow only regulator authorized financial entities to run ads for financial products & services follows warnings from the Financial Conduct Authority that it may take legal action if Google continued to accept unscreened financial ads, as the Guardian reported earlier.

The FCA told a parliamentary committee this month that it’s able to contemplate taking such action as a result of no longer being bound by European Union rules on financial adverts, which do not extend to online platforms, per the newspaper’s report.

Until gaining the power to go after Google itself, the FCA appears to have been trying to combat the scourge of online financial fraud by paying Google large amounts of UK taxpayer money to fight scams with anti-scam warnings.

According to the Register, the FCA paid Google more than £600,000 (~$830k) in 2020 and 2021 to run ‘anti-scam’ ads — with the regulator essentially engaged in a bidding war with scammers to pour enough money into Google’s coffers so that regulator warnings about financial scams might appear higher than the scams themselves.

The full-facepalm situation was presumably highly lucrative for Google. But the threat of legal action appears to have triggered a policy rethink.

Writing in its blog post, Ronan Harris, a VP and MD for Google UK & Ireland, said: “Financial services advertisers will be required to demonstrate that they are authorised by the UK Financial Conduct Authority or qualify for one of the limited exemptions described in the UK Financial Services verification page.”

“This new update builds on significant work in partnership with the FCA over the last 18 months to help tackle this issue,” he added. “Today’s announcement reflects significant progress in delivering a safer experience for users, publishers and advertisers. While we understand that this policy update will impact a range of advertisers in the financial services space, our utmost priority is to keep users safe on our platforms — particularly in an area so disproportionately targeted by fraudsters.”

The company’s blog also claims that it has pledged $5M in advertising credits to support financial fraud public awareness campaigns in the UK. So not $5M in actual money then.

Per the Register, Google did offer to refund the FCA’s anti-scam ad spend — but, again, with advertising credits.

The UK parliament’s Treasury Committee was keen to know whether the tech giant would be refunding the spend in cash. But the FCA’s director of enforcement and market insight, Mark Steward, was unable to confirm what it would do, according to the Register’s report of the committee hearing.

We’ve reached out to the FCA for comment on Google’s policy change, and with questions about the refund situation, and will update this report with any response.

In recent years the financial watchdog has also been concerned about financial scam ads running on social media platforms.

Back in 2018, legal action by a well-known UK consumer advice personality, Martin Lewis — who filed a defamation suit against Facebook — led the social media giant to add a ‘report scam ad’ button in the market as of July 2019.

However research by consumer group, Which?, earlier this year, suggested that neither Facebook nor Google had entirely purged financial scam ads — even when they’d been reported.

Per the BBC, Which?’s survey found that Google had failed to remove around a third (34%) of the scam adverts reported to it vs Facebook failing to remove well over a fifth (26%).

It’s almost like the incentives for online ad giants to act against lucrative online scam ads simply aren’t pressing enough…

More recently, Lewis has been pushing for scam ads to be included in the scope of the UK’s Online Safety Bill.

The sweeping piece of digital regulation aims to tackle a plethora of so-called ‘online harms’ by focusing on regulating user generated content. However Lewis makes the point that a scammer merely needs to pay an ad platform to promote their fraudulent content for it to escape the scope of the planned rules, telling the Good Morning Britain TV program today that the situation is “ludicrous” and “needs to change”.

It’s certainly a confusing carve-out, as we reported at the time the bill was presented. Nor is it the only confusing component of the planned legislation. However on the financial fraud point the government may believe the FCA has the necessary powers to tackle the problem.

We’ve contacted the Department for Digital, Media, Culture and Sport for comment.

Update: A government spokesperson said:

“We have brought user-generated fraud into the scope of our new online laws to increase people’s protection from the devastating impact of scams. The move is just one part of our plan to tackle fraud in all its forms. We continue to pursue fraudsters and close down the vulnerabilities they exploit, are helping people spot and report scams, and we will shortly be considering whether tougher regulation on online advertising is also needed.”

The government also noted that the Home Office is developing a Fraud Action Plan, which is slated to be published after the 2021 spending review; and pointed to the Online Advertising Programme which it said will consider the extent to which the current regulatory regime is equipped to tackle the challenges posed by the rapid technological developments seen in online advertising — including via a consultation and review of online advertising it plans to launch later this year.

Jun
22
2018
--

Security, privacy experts weigh in on the ICE doxxing

In what appears to be the latest salvo in a new, wired form of protest, developer Sam Lavigne posted code that scrapes LinkedIn to find Immigration and Customs Enforcement employee accounts. His code, which basically a Python-based tool that scans LinkedIn for keywords, is gone from Github and Gitlab and Medium took down his original post. The CSV of the data is still available here and here and WikiLeaks has posted a mirror.

“I find it helpful to remember that as much as internet companies use data to spy on and exploit their users, we can at times reverse the story, and leverage those very same online platforms as a means to investigate or even undermine entrenched power structures. It’s a strange side effect of our reliance on private companies and semi-public platforms to mediate nearly all aspects of our lives. We don’t necessarily need to wait for the next Snowden-style revelation to scrutinize the powerful — so much is already hiding in plain sight,” said Lavigne.

Doxxing is the process of using publicly available information to target someone online for abuse. Because we can now find out anything on anyone for a few dollars – a search for “background check” brings up dozens of paid services that can get you names and addresses in a second – scraping public data on LinkedIn seems far easier and innocuous. That doesn’t make it legal.

“Recent efforts to outlaw doxxing at the national level (like the Online Safety Modernization Act of 2017) have stalled in committee, so it’s not strictly illegal,” said James Slaby, Security Expert at Acronis. “But LinkedIn and other social networks usually consider it a violation of their terms of service to scrape their data for personal use. The question of fairness is trickier: doxxing is often justified as a rare tool that the powerless can use against the powerful to call attention to perceived injustices.”

“The problem is that doxxing is a crude tool. The torrent of online ridicule, abuse and threats that can be heaped on doxxed targets by their political or ideological opponents can also rain down on unintended and undeserving targets: family members, friends, people with similar names or appearances,” he said.

The tool itself isn’t to blame. No one would fault a job seeker or salesperson who scraped LinkedIn for targeted employees of a specific company. That said, scraping and publicly shaming employees walks a thin line.

“In my opinion, the professor who developed this scraper tool isn’t breaking the law, as it’s perfectly legal to search the web for publicly available information,” said David Kennedy, CEO of TrustedSec. “This is known in the security space as ‘open source intelligence’ collection, and scrapers are just one way to do it. That said, it is concerning to see ICE agents doxxed in this way. I understand emotions are running high on both sides of this debate, but we don’t want to increase the physical security risks to our law enforcement officers.”

“The decision by Twitter, Github and Medium to block the dissemination of this information and tracking tool makes sense – in fact, law enforcement agents’ personal information is often protected. This isn’t going to go away anytime soon, it’s only going to become more aggressive, particularly as more people grow comfortable with using the darknet and the many available hacking tools for sale in these underground forums. Law enforcement agents need to take note of this, and be much more careful about what (and how often) they post online.”

Ultimately, doxxing is problematic. Because we place our information on public forums there should be nothing to stop anyone from finding and posting it. However, the expectation that people will use our information for good and not evil is swiftly eroding. Today, wrote one security researcher, David Kavanaugh, doxxing is becoming dangerous.

“Going after the people on the ground is like shooting the messenger. Decisions are made by leadership and those are the people we should be going after. Doxxing is akin to a personal attack. Change policy, don’t ruin more lives,” he said.

Powered by WordPress | Theme: Aeros 2.0 by TheBuckmaker.com