Friday, July 08, 2016

For my Computer Security students.
Study: More than 50% of SMBs were breached in the past year
A new study conducted by the Ponemon Institute and sponsored by password management provider Keeper Security analyzed the state of cybersecurity in small and medium-sized businesses (SMBs) and found that confidence in SMB security is shockingly low (just 14% of the companies surveyed rated their ability to mitigate cyber attacks as highly effective).
  • 50 percent of respondents reported that they had data breaches involving customer and employee information in the last 12 months.
  • Three out of four survey respondents reported that exploits have evaded their anti-virus solutions.
  • 59% of respondents say they have no visibility into employees' password practices and hygiene.
  • 65% do not strictly enforce their documented password policies.


The scale of a breach is very difficult to measure quickly, as articles like this consistently  illustrate.
Remember when Wendy’s updated its breach disclosure in May to report that it was 300 stores impacted?  They subsequently revealed that they had found two types of malware and the number of impacted stores could be “considerably higher.”
Well, now it’s 1,025 stores.  Here’s their statement from today:
…   Wendy’s first reported unusual payment card activity affecting some restaurants in February 2016.  In May, we confirmed that we had found evidence of malware being installed on some restaurants’ point-of-sale systems, and had worked with our investigator to disable it.  On June 9th, we reported that we had discovered additional malicious cyber activity involving other restaurants.  That malware has also been disabled in all franchisee restaurants where it has been discovered.  We believe that both criminal cyberattacks resulted from service providers’ remote access credentials being compromised, allowing access – and the ability to deploy malware – to some franchisees’ point-of-sale systems.
[Apparently only the Wendy’s in Thornton Colorado was hit.  Bob]


Ah the joys of having the latest technology!
Megan Scudellari reports:
“It knows too much,” says Wang, an assistant professor of computer science at Binghamton University in Upstate New York. “If you are using a smart watch, you need to be cautious.”
He would know.  Wearable devices can give away your PIN number, according to research he and colleagues presented in June at the 11th annual Association for Computing Machinery Asia Conference on Computer and Communications Security (ASIACCS) in Xi’an, China.  By combining smart watch sensor data with an algorithm to infer key entry sequences from even the smallest of hand movements, the team was able to crack private ATM PINs with 80 percent accuracy on the first try and more than 90 percent accuracy after three tries.
Read more on IEEE Spectrum.


Computer Security, Data Management and Data Architecture! 
Buyers Beware: The Latest Wave of Retail Cyber Scams
…   “Retailers have been caught out by bad data architecture.  You should never store sensitive information on a network that third-party vendors have access to.  Create a systematic classification categorizing what’s sensitive and what’s not,” suggests Yoo.
Daniel Garrie, CEO of consulting firm Law & Forensics and senior advisor at Risk Assistance Network and Exchange (RANE), suggests to his retail clients to go as far as providing cybersecurity to the vendors themselves.  “I tell my clients you need to secure them. Spending any amount of money is worth it if these are vendors you can’t live without.”


Will this reignite the encryption debate?  Stay tuned. 
‘Secret Conversations:’ End-to-End Encryption Comes to Facebook Messenger
Just a few years ago, end-to-end encryption was a nerdy niche: a tiny collection of obscure software let you encrypt communication so only your recipient could read it, but the vast majority left you no option to hide your words from hackers or eavesdroppers.  This year, that balance shifted.  And now, roughly 900 million more people are about to be invited into the crypto club.
On Friday, Facebook plans to roll out a beta version of a new feature it calls “secret conversations.”  It’s encrypted messages, end-to-end, so that in theory no one—not a snoop on your local network, not an FBI agent with a warrant, not even Facebook itself—can intercept them.  For now, the feature will be available only to a small percentage of users for testing; everyone with Facebook Messenger gets it later this summer or in early fall.


I’ll use this the next time I teach Statistics.  Isn’t the question wrong?  Did insurance rates change for these drivers? 
From TheNewspaper:
Three years ago, the insurance industry set up ten covert speed cameras across Northern Virginia to photograph and access the personal information of 65,000 drivers.  A motorist rights group is crying foul.  The Insurance Institute for Highway Safety (IIHS) gathered all of this data to make a political point.
“The association between higher speed limits and faster vehicle speeds is well-established, but not as much is known about how horsepower affects travel speeds,” wrote in a May 24 report.
The report was made possible by the 2014 decision of Virginia Department of Motor Vehicle Commissioner Richard D. Holcomb to release vehicle identification number (VIN), age and sex information from the records of 65,000 vehicle owners.  IIHS compared this personal information against the facial photograph captured by the industry’s speed cameras to conclude that vehicles “packing more horsepower” drive faster than the posted speed limit.
[…]
“Why precisely the insurance industry advocates felt the need to capture facial images of drivers and compare that to personal data in DMV records is a mystery,” NMA president Gary Biller told TheNewspaper.  “Identifying drivers isn’t germane to the horsepower versus speed question.”
Indeed.  And they could have let me know so that I could comb my hair before blowing off their speed limits in my little sports car.
Read more on TheNewspaper.com.


Well, if no one in Congress cares…
EFF – FBI Must Not Sidestep Privacy Protections For Massive Collection of Biometric Data
by Sabrina I. Pacifici on Jul 7, 2016
Iris Scans, Palm Prints, Face Recognition Data, and More Collected From Millions of Innocent Citizens – “The FBI, which has created a massive database of biometric information on millions of Americans never involved in a crime, mustn’t be allowed to shield this trove of personal information from Privacy Act rules that let people learn what data the government has on them and restrict how it can be used.  The Electronic Frontier Foundation (EFF) filed comments today with the FBI, on behalf of itself and six civil liberties groups, objecting to the agency’s request to exempt the Next Generation Identification (NGI) database from key provisions of federal privacy regulations that protect personal data from misuse and abuse.  The FBI has amassed this database with little congressional and public oversight, failed for years to provide basic information about NGI as required by law, and dragged its feet to disclose—again, as required by law—a detailed description of the records and its policies for maintaining them.  Now it wants to be exempt from even the most basic notice and data correction requirements…”

(Related)  “We’re going to do it, but we don’t know what we’re going to do yet.” 
lan Lior and Or Kashti report:
Interior Minister Arye Dery announced on Thursday that starting next year, joining the biometric database will be obligatory.
“From now on anyone obtaining a document from the Interior Ministry, whether an ID card or a passport, will receive a biometric one.  We’ve decided on having this database and we’ll soon decide what will be included in it,” Dery said at a ceremony marking the millionth person to join the biometric database, which was held at the new Population and Immigration Authority office in south Tel Aviv.
Read more on Haaretz.
So with the U.S. banking sector also embracing biometrics and with everyone’s Social Security number already have been leaked or compromised in numerous breaches, can the U.S. be far behind in switching to biometrics for identity authentication?
And if so, isn’t it even more important, then, that the FBI not be able to exempt the biometrics database from Privacy Act protections?  Have you signed EFF’s petition on this?  If not, go do so right now.


Perspective.  At least, something to think about.
Deciphering Facebook's Software Philosophy
Last week, Facebook offered a peek into the philosophy governing its News Feed algorithm, the piece of software that decides which posts are shown to people when they log into the platform’s app or homepage.  The announcement was more than just academic.  One in five adults worldwide use Facebook, and 44 percent of Americans get their news from the platform.  If traditional agenda-setting news barons like Rupert Murdoch count as powerful, then surely the News Feed algorithm wields influence, too.  In fact, its algorithm may be one of the most powerful pieces of software in the world.
Which makes the ideas governing such a piece of software extra-important.  These particular ideas came in a blog post entitled “News Feed Values,” written by Adam Mosseri, a Facebook vice president and the product manager of the News Feed.  The post is a list of broad principles and vague promises that users should expect from their News Feed.  It was at once a piece of marketing and—more interestingly—a set of operational ethics, a kind of guide to what Facebook values when it decides to alter the feed.

(Related)
Pew – The Modern News Consumer
by Sabrina I. Pacifici on Jul 7, 2016
“Wave after wave of digital innovation has introduced a new set of influences on the public’s news habits.  Social media, messaging apps, texts and email provide a constant stream of news from people we’re close to as well as total strangers.  News stories can now come piecemeal, as links or shares, putting less emphasis on the publisher.  And, hyper levels of immediacy and mobility can create an expectation that the news will come to us whether we look for it or not.  How have these influences shaped Americans’ appetite for and attitudes toward the news?  What, in other words, are the defining traits of the modern news consumer?  A new, two-part survey by Pew Research Center, conducted in early 2016 in association with the John S. and James L. Knight Foundation, reveals a public that is cautious as it moves into this more complex news environment and discerning in its evaluation of available news sources…”


The difference is important!
Augmented vs. Virtual Reality: What’s the Difference?
…   Augmented reality (AR) refers to devices that combine elements of the real world with virtual aspects laid over it.  This often manifests itself in using your phone’s camera to display the “real world” with a virtual overlay, though not always.
…   VR essentially boils down to: creating an entire world within virtual space.  Whereas augmented reality relies on input from the “real world”, virtual reality aims to create its own distinct and separate world.


For the Movie club?
Watch 100+ Free Public Domain Movies on YouTube Now
…   The list of films on the aptly named Public Domain Full Movies channel is truly staggering, ranging from some in the 60s and 70s, and going all the back to the silent film era of the early 1900s.

Thursday, July 07, 2016

No indication of how long this was going on.  Sounds like the employee had access to “network drivers” when he shouldn’t have. 
Alexa Huffman reports:
Snooping on personal staff data, including SIN numbers, salaries and spouse names, led to a SaskPower employee being fired in January.
According to a report released in June by the Saskatchewan Information and Privacy Commissioner, Ron Kruzeniski, the employee inappropriately accessed 4,382 human resources files from current and former employees at the Crown-owned company.
The report said the information included names, addresses, social insurance numbers, salaries and life insurance coverage and beneficiaries.
Read more on Global News.
[From the article:
SaskPower concluded that the breach was due to the employee searching network drives.  The report says the employee then previewed and saved to the files to his corporate workstation without a business purpose.
The employee also put the files onto portable storage devices.
…   SaskPower has improved systems security including locking affected network folders so they can only be accessed by authorized users, the report says.


I don’t get the attraction, but is this a Security risk for children?  Sure sounds like it. 
Australian cops to Pokemon fans: Do not come looking for Pikachu in our police station
The new smartphone app Pokémon Go begins with a warning screen.
Pokémon Go simply wants its players to avoid physical trauma.
Played on a smartphone screen in lieu of a Game Boy or other handheld console, Pokémon Go uses cameras and GPS to construct an augmented reality in which collectible 3-D monsters float over physical locales.
To collect these digital critters, you have to get off the couch, get outside and track them down.
…   The team behind Pokémon Go — developers Niantic Labs and video game giant Nintendo — is concerned that you may walk off a bridge, for instance, while you are engrossed in a real-world hunt for the digital critters.  Recognizing that the app, which launched in the United States late Wednesday, may encourage the sort of obliviousness that comes when noses are buried in smartphones, other groups began issuing their own warnings, too.


This should interest both my Computer Security and Data Management students.
Businesses in the Dark on Value of Corporate Data
According to the company’s Risky Business Report, only 28% of CISOs conduct regular exercises to categorize and value the data within the company, which allows them to evaluate the risk associated with the loss of this data.  In fact, 17% of surveyed business executives say they didn’t take action in this regard, while 55% of them have taken partial action, the report (PDF) reveals.
What’s more, 40% of responding CISOs said they have no clear view into the location and nature of their information assets, IRM says.  The risks associated with poor knowledge of the value of data include difficulties in building an effective protection strategy, or in determining the amount that should be invested in data protection solutions, Charles White, Founder and CEO of IRM, warns.
Findings in the report are in line with thoughts from SecurityWeek columnist Rafal Los, on what he believes is the most important security question nobody seems to be able to answer: “What is your organization’s sensitive data, and where is it?”


Gosh, what would government workers do all day?
House passes bill to block porn from feds' computers


I already have one (several?) starting with Cortana. 
Are You Ready for Robot Colleagues?
…   if robots become as clever as we are, how will the role of managers change?
Bernd Schmitt, the Robert D. Calkins Professor of International Business at Columbia Business School, thinks the convergence is coming, and that managers have to start preparing now.


Beware of bragging on film.
A new film gives a frightening look at how the US used cyberwarfare to destroy nukes
…   A fascinating new documentary film by Alex Gibney called "Zero Days" that premieres on Friday tells the story of Stuxnet, along with the frightening takeaway that, while this was the first cyber weapon, it will certainly not be the last.
…   First authorized by President Bush and then re-authorized by President Obama, the top secret computer worm was designed by the US and Israel to infect an Iranian nuclear enrichment facility at Natanz.
And it did. Too well.
The code made its way into the facility and infected the specific industrial control systems the Iranians were using.  Once it turned itself on about 13 days after infection, it sped up or slowed down the centrifuges until they destroyed themselves — all while the operators' computer screens showed everything was working as normal.
…   The most incredible revelation from the film comes from Gibney's NSA source, who talks about a much larger operation than Stuxnet.  It's a news-breaking claim that The New York Times has since corroborated: The US had an in-depth cyber attack plan that was much larger than Natanz.
"We were inside, waiting, watching," the source says.  "Ready to disrupt, degrade, and destroy those systems with cyber attacks.  In comparison, Stuxnet was a back alley operation.  NZ was the plan for a full scale cyber war with no attribution."
NZ is the acronym for a separate operation called Nitro Zeus, which gave the US access into Iran's air defense systems so it could not shoot down planes, its command-and-control systems so communications would go dead, and infrastructure like the power grid, transportation, and financial systems.
…   Now there is a new weapon that can do a better job at destruction than bombs.  But the difference between highly-controlled nuclear materials and computer code, is that anyone — and any state — can develop it.
“It seems pretty reasonable to think that there are things out there today that we haven’t seen that are much more advanced [than Stuxnet]," O'Murchu told TI in a phone interview.
We'll just have to wait and see who uses it next.


What am I missing?  Did the Post suddenly turn on Hillary?  This does not read like a typical Post article. 
How the FBI director systematically dismantled Hillary Clinton’s email defense


Because I need a guide.
Hey, granddad, here’s a Millennial’s guide to Snapchat 
…   The social media app that’s popular with the youngest Millennials is now booming with older people:  Now 38% of people ages 25 to 34 use the flighty picture-sharing app, according to an online report — a 100% increase from just two years ago.  And 14% of people over 35 use the app, too — which represents a 35% jump.
At this point, the only adults not using Snapchat are the ones who don’t get it.  So let this bona fide Millennial — I’m 18 — explain it to you old folks:

(Related)
10 Practical Tips for New Periscope Users
Periscope is a live-streaming app owned by Twitter that allows users to broadcast moments of their lives with followers across the globe.  Viewers can interact with broadcasters through comments, and live streams can be shared through social media much like any other kind of photo or video post.

(Related)
10 Things You Didn’t Know You Could Do On Instagram


Includes my personal nemesis, the translator.
10 Handy Productivity Add-Ins for Microsoft Word

Wednesday, July 06, 2016

Local.  The hackers were inside but opted to test their ransomware rather than steal just a few thousand patient records?  Or perhaps they did that first. 
Jennie Trejo reports:
Allergy, Asthma & Immunology of the Rockies, P.C. (AAIR), a full-service allergy clinic, found evidence of ransomware on its computer systems on May 16.
[…]
Kari Hershey, an attorney for AAIR, said the disturbance was first noticed when they had trouble accessing a few of the documents.
[…]
“They weren’t able to track exactly what the hackers did, but what they did find was a draft of the ransom letter on the system,” Hershey said.  “The way it was explained to me is that it essentially looked like the hackers were still testing out the ransomware.”
Because the ransomware was still in its early stages, there is no evidence that any of the information on the system has been copied or used in any way, although it did pass through a password protected firewall.  Hershey said they would expect to know if sensitive information was harvested by this point in the investigation.
“Having said that, there was a breach of the system.  Just out of an abundance of caution, we do want people to sign up for an identity theft protection program.  That way if they do have a problem they can get help.”
Read more on the Post Independent.
The incident was reported to HHS as affecting 6,851 patients.


For my Computer Security students – at least those who drive to school.
Automotive cybersecurity; what we don't hack will probably be used to kill us
…   Just imagine your own car traveling at speed and having your ability to steer, alter speed, and brake, taken away and then being ransomed to regain control.
Think this impossible? Last year, Wired wrote about a couple of hackers remotely disabling a Chrysler Jeep Cherokee while it was heading down a freeway at 70 miles per hour.
…   The subsequent paper by Miller and Valasek, Remote Exploitation of an Unaltered Passenger Vehicle, goes into to even more detail on how the hack was engineered
…   Should you want to know more about automotive hacking, you might like to check out the recently published The Car Hacker’s Handbook: A Guide for the Penetration Tester by Craig Smith.


Together, a userid and password are intended to identify an individual.  Sharing them for any reason defeats the purpose. 
Court decision raises issues about sharing passwords
An appeals court has ruled that a former employee of a company, whose computer access credentials were revoked, had acted “without authorization” in violation of the Computer Fraud and Abuse Act, when he and other former employees used the login credentials of a current employee to gain access to data on the employer’s computers.
The opinion of the court is likely to be controversial as it is expected to have implications on commonplace sharing of passwords by husbands, co-workers and friends even for innocuous purposes.
One of the three judges, Stephen Reinhardt, dissented from the majority opinion, stating that “people frequently share their passwords, notwithstanding the fact that websites and employers have policies prohibiting it.”
The CFAA in his view “does not make the millions of people who engage in this ubiquitous, useful, and generally harmless conduct into unwitting federal criminals.”


This could be useful.
Microsoft Proposes Independent Body to Attribute Cyber Attacks
Microsoft has published a paper that proposes a series of recommended 'norms' of good industry behavior in cyberspace, and also a route towards implementing and achieving those norms.  Most of the norms are uncontentious and self-evident - but one in particular (which is a form of 'responsible disclosure') is less so.  Furthermore, the key feature in implementing these norms (the attribution of attacks to attackers) is particularly troublesome.
From Articulation to Implementation: Enabling progress on cybersecurity norms was developed by a team led by Scott Charney, Microsoft's Corporate Vice President for Trustworthy Computing.


Something subtle for my Computer Security students to ponder.
How social media is changing what can be said, when and where
…   When Dave closes a deal he takes the team out for beers, treats his family to a nice dinner out and brags about it on his social media accounts.
…   Amy, in your accounting department has a different social media presence
She blogs regularly on Tumblr and posts selfies on Instagram while in pensive poses when problems overwhelm her.
Both Dave and Amy represent major risks for your company.
…   Dave is a bit of a braggart and read his tweets with interest.  When he tweets about beating his toughest competitor in a sales presentation and landing a big contract, the investors buy.  
Dave has given them insider information and doesn't even know it.
…   Employees who follow Amy's social media accounts sense that there's something wrong.  They see her stress level increasing, note the workload on her desk and worry about their own future.  Productivity drops.  Rumors start.  Bad things happen.
…   Both Dave and Amy have innocently been doing what millions of people do every day - they have been posting about their personal lives on their social media accounts.  But what they haven't realized - and what may affect your company - is that what they write, post or repeat on social media can cause employee problems, productivity issues and even financial damage.
It's because your company doesn't have a social media policy.  In today's world you need to be aware of, or perhaps even control, what is said on your employee's Facebook, Twitter, Instagram or even Pinterest accounts.


Interesting, thoughtful and amusing.
Did The FBI End Clinton’s Email Problems Or Make Them Worse?


IT Architecture.
The future of company devices may be ‘as-a-Service’
…   The ability to deploy only assets as needed based on workload is a big one.  This means a company has the ability to flex up, adding devices as needed when its workforce grows.  More importantly, however, is the ability to flex down.  The problem with the traditional PC procurement model is companies that decrease the size of their workforce due to seasonal changes, layoffs, or the like, have to deal with the surplus of PCs (and sunk costs) that result.  In a DaaS model, the provider takes back those devices, potentially redeploying them with another client.


I wonder if it would recognize all the hand gestures I learned back in New Jersey?  If so, would it try to run me down? 
Google's robot cars recognize cyclists' hand signals — better than most cyclists

Tuesday, July 05, 2016

I thought there might be too many politicians on this site.  Was I wrong? 
I can’t say I’m surprised, but it’s nice to get some confirmation.  Alastair Sharp and Allison Martell of Reuters report that the Federal Trade Commission is investigating Avid Life, parent company of Ashley Madison.
But what is the scope of their investigation.  Executives admitted to Reuters that the use of “fembots” is part of the investigation, which makes sense under the FTC’s authority to address deceptive practices.  But is FTC also investigating their data security in light of their massive breach?  I would hope so.  Avid Life executives told Reuters they still don’t know how the breach occurred.
I expect that this investigation will result in a consent order with a whopping monetary component to reimburse consumers who were duped by fembots, but we’ll see in time.


Advertise with us and we’ll guarantee many people will see your ad, even if we have to create virtual people.
HummingBad malware infects 85 million Android devices
An Android-based malware campaign masterminded from China has snared as many as 85 million Android devices and is making the gang behind it an estimated $1m every quarter.
Security software and services company Check Point claimed that it has had its eye on the Yingmob gang for five months, describing it as sophisticated, well-staffed and highly profitable. 
Its tool of choice is a piece of malware called HummingBad, and the group works alongside an official advertising analytics company, according to Check Point's From HummingBad to Worse report (PDF).
"HummingBad is a malware Check Point discovered in February 2016 that establishes a persistent rootkit on Android devices, generates fraudulent ad revenue, and installs additional fraudulent apps," Check Point explained in a blog post.


A long report that says, “We don’t know what to do.” 
House Homeland Security Report – Going Dark, Going Forward: A Primer on the Encryption Debate
by Sabrina I. Pacifici on Jul 4, 2016
June 29, 2016: “Terrorist attacks in Paris and San Bernardino have sparked a public debate on the use of encryption in our society because the attackers used encrypted communications to evade detection, a phenomenon known as “going dark.”  Today, the Majority Staff of the House Homeland Security Committee released a new report entitled, Going Dark, Going Forward: A Primer on the Encryption Debate.  This first Congressional in-depth analysis of the issue summarizes the Committee’s findings, based on more than 100 meetings and briefings Committee staff and Members have held with key stakeholders over the past year.  In addition to providing insight into arguments on all sides of the encryption debate, the report lays the groundwork for a National Commission on Security and Technology Challenges proposed by Homeland Security Chairman Michel McCaul (R-TX) and Senator Mark Warner (D-VA).  The bipartisan Commission has broad support from former and current Administration officials, national security leaders, law enforcement, and the tech industry, and will help to forge a general concurrence of opinions, informed by a common understanding of the underlying facts.  Ultimately this effort will provide a better understanding of digital security issues for Congress and the American public.  The report released today will help inform and advance debate that centers around balancing personal cyber security and national security.”


Perspective.
Snapchat’s Teen Fans Wince as App Catches On With Their Folks
…   Since its founding five years ago, Snapchat has become a digital mecca for high school and college-age students, allowing them to send photos and videos that disappear in a matter of seconds.  It has amassed 150 million daily active users, said a person familiar with the matter.
Snapchat also has been a refuge from parents.  Until lately, that is.
Now, the “olds” are arriving in force, whether they are parents spying on their kids, or professionals trying out another social-media platform.


Numbers that I didn’t catch elsewhere.
Significant Digits For Tuesday, July 5, 2016
28 months
That’s how long the House select committee’s investigation into the 2012 Benghazi attacks lasted, exceeding the amount of time high-profile Congressional committees spent digging into Watergate, the assassination of John F. Kennedy, the Sept. 11 attacks and Pearl Harbor. [AJC]
20,000 pounds of cheese
Crime of the century in Wisconsin: 20,000 pounds of cheese from U.S. Foods, en route from Green Bay to New York, was stolen.   [The Associated Press]


The world changes again.  The Saudis had the most accessible oil early in the last century.  Then Russia figured out how to extract oil when wells could freeze.  Now with shale extraction, the US looks big.  Still, there is only 70 years of oil left at the current rate? 
US oil reserves surpass those of Saudi Arabia and Russia
…   Rystad Energy estimates recoverable oil in the US from existing fields, discoveries and yet undiscovered areas amounts to 264bn barrels.  The figure surpasses Saudi Arabia's 212bn and Russia's 256bn in reserves.
The analysis of 60,000 fields worldwide, conducted over a three-year period by the Oslo-based group, shows total global oil reserves at 2.1tn barrels.  This is 70 times the current production rate of about 30bn barrels of crude oil a year, Rystad Energy said on Monday.
…   More than half of the US's remaining oil reserves are in unconventional shale oil, Rystad Energy data show.  Texas alone holds more than 60bn barrels of shale oil.

Monday, July 04, 2016

A timely summary as I start another Computer Security class this week.  Perhaps we could add the video to our information big screens. 
The 7 biggest computer hacks


Maybe the other 9% don’t use navigation computers? 
91% airlines preparing to invest in cyber security
A whopping 91 percent of the airlines globally are planning to invest in cyber security programmes over the next three years, a survey conducted by airline solutions and technology provider SITA has said.
The SITA Airline IT Trends 2016 Survey on the world's top 200 airlines has inferred "that the cyber security in airlines is progressing".
Three years ago, 47 percent of the airlines had said that they were making advanced preparations to manage cyber risks.
…   The focus on cyber security also reflects the move to the 'Internet of Things'(IoT), in which a vast number of physical objects will become connected to the internet, thus enabling tracking, data collection, analysis and control, which necessitates more security, the survey said.
"The initiatives to realise the IoT include smart bag tagging to enable continuous tracking, which is planned by 61 percent of the airlines by 2019," Pickford said.
Nearly half the airlines are also planning IT programmes for single token travel for passenger identification, he added.
Another trend is more software development in-house and the shift to outsource IT operations.  In the future, a growing proportion of airlines' IT budgets is likely to be spent on innovation rather than service continuity, with innovation rising to 36 percent of IT and telecommunications spend in 2016, the survey said.
"Providing passenger services via smartphones continues to be a key area of investment for airlines.  Seventy nine percent of them are planning major investments over the nextthree years while a further 17 percent are planning a pilot programme or R&D in this area," it added.


An interesting strategic move.  Find a technology innovator (preferably one with a monopoly in the industry), buy it, deny everyone else access to the technology.  (I bet they control a bunch of patents too)
How Amazon Triggered a Robot Arms Race
An Amazon warehouse is a flurry of activity.  Workers jog around a manmade cavern plopping items into yellow and black crates.  Towering hydraulic arms lift heavy boxes toward the rafters.  And an army of stubby orange robots slide along the floor like giant, sentient hockey pucks, piled high with towers of consumer gratification ranging from bestsellers to kitchenware.
Those are Kiva robots, once the marvel of warehouses everywhere.  Amazon whipped out its wallet and threw down $775 million to purchase these robot legions in 2012.  The acquisition effectively gave Jeff Bezos, its 52-year-old chief executive, command of an entire industry.  He decided to use the robots for Amazon and Amazon alone, ending the sale of Kiva's products to warehouse operators and retailers that had come to rely on them.  As contracts expired, they had to find other options to keep up with an ever-increasing consumer need for speed.  The only problem was that there were no other options.  Kiva was pretty much it. 


For my students.
ComputerWorld – Best Places to Work in IT 2016
by Sabrina I. Pacifici on Jul 3, 2016
“Find the top employer that best suits your needs. Sort the Best Places to Work by key criteria, such as training days, and add filters by region and/or organization size.  Note that the more filters you add, the fewer organizations will be listed.”  This list also includes related articles on the respective top large firm, mid size firm, and small firm that was ranked best in class.

Sunday, July 03, 2016

For my Computer Security students and Twits everywhere.
How To Find Out If Your Twitter Account Is Vulnerable To Hackers
…   Want to know how secure your Twitter account is?  Here’s an easy way to find out.  Head to the Twitter applications settings page.  There, you can see a full list of the third-party applications that have “write” access to your account: Apps that let you post to Twitter without being on Twitter dot com.


“No strategy.  We just thought it was neat!” 
Big Brother is listening as well as watching
…   This past week, following revelations that New Jersey Transit didn’t have policies governing storage and who had access to data from audio surveillance on some of its light-rail trains, the agency ended the program.


The Associated Press reported in April that NJ Transit had been using audio recording systems on train lines between Trenton and Camden, in Newark and Hudson County.
Dennis Martin, former interim executive director of the agency, told the AP that the goal was to “deter criminal activity” and keep passengers safe.
But he refused to say how the audio data is stored, for how long, who reviewed it and when or how it was destroyed, saying only, “there are laws that govern that and we’re in compliance.”
Critics, including commuter organizations, contended that the recording violated both the First Amendment (free speech) and Fourth Amendment (unreasonable search) rights of passengers.
…   Of course, New Jersey is not alone, nor is it the first. The Baltimore Sun reported in March that the Maryland Transit Administration (MTA) has used audio recording on some of its mass transit vehicles since 2012.  It is now used on 65 percent of buses, and 82 percent of subway trains have audio recording capability, but don’t use it yet, according to the Sun.
And cities in New Hampshire, Connecticut, Michigan, Ohio, Nevada, Oregon and California have either installed systems or moved to procure them, in many cases with funding from the federal Department of Homeland Security (DHS).


Everyone wants a App that can vacuum your wallet.
Walmart debuts new mobile pay app
Walmart last week became the latest retailer to join the trend toward mobile payments when it debuted a new system in all its Missouri locations.
The system is an addition to the Walmart app and can be used with any kind of credit or debit card and any kind of smartphone.
"People forget their wallets, but most people don’t forget their phones," said Farai Madzura, manager of the Walmart Express in downtown Columbia.  "These days we use our phones for everything."
…   These apps use "transaction specific dynamic security codes," which means the user's actual card numbers are never shared. Instead, a unique code is used to identify every purchase made.
The new Walmart system keeps the encrypted card information on file, but it is protected by a personal passcode, Madzura said.


Perspective.  US market is flat so Amazon wants in to the Indian market.
Amazon 'returns' to smartphone market with special edition phones
…   After its own Fire phone flopped, Amazon is selling special editions of other manufacturers' phones at a $50 discount.  They'll come with ads on the lock screen and about 10 Amazon apps on the home screen.
Amazon.com is touting the discount as a benefit of its $100-a-year Prime loyalty program.  Membership is required, and Amazon figures that those customers will appreciate having single sign-on access to Amazon's various apps.


Why are some students always late?  Dilbert explains.

Saturday, July 02, 2016

For my Ethical Hacking students.  (and the FBI)  Again, I suggest writing your own encryption software, there are many examples and tutorials. 
Android’s full-disk encryption just got much weaker—here’s why
…   A blog post published Thursday revealed that in stark contrast to the iPhone's iOS, Qualcomm-powered Android devices store the disk encryption keys in software.  That leaves the keys vulnerable to a variety of attacks that can pull a key off a device.  From there, the key can be loaded onto a server cluster, field-programmable gate array, or supercomputer that has been optimized for super-fast password cracking.
The independent researcher that published the post included exploit code that extracts the disk encryption keys by exploiting two vulnerabilities in TrustZone.  TrustZone is a collection of security features within the ARM processors Qualcomm sells to handset manufacturers.


For my Computer Security students.
Kaspersky: Ransomware that encrypts is booming
Over the past year the number of machines hit by ransomware that encrypts all or part of the hard drive is five-and-a-half times what it was the year before, according to Kaspersky Lab.
The number in 2014-2015 was 131,111 compared to 718,536 in 2015-2016, according to the company’s report Ransomware in 2014-2016.
…   “Mobile ransomware merged as a follow-up to PC ransomware and it is likely that it will be followed-up with malware targeting devices that are very different to a PC or a smartphone,” the report says.  These include smart watches and smart TVs, and entertainment systems in homes and cars.  “There are a few proof-of concepts for some of these devices, and the appearance of actual malware targeting smart devices is only a question of time.”

(Related)
With some advanced preparation, you can survive a ransomware attack
…   There are ways to protect your systems to prevent becoming the next victim, or at least to mitigate the effects of the attack, but you need to act before an attack strikes.  Researchers say it can take less than 5 minutes from the time the malware gets on a system to the time when primary files are encrypted, backup files are deleted, and the demand for ransom is presented.
That said, here are some steps for surviving a ransomware attack:


I’ve followed this report for years.
2015 Wiretap Report: Intercept Orders Rise 17 Percent
by Sabrina I. Pacifici on Jul 1, 2016
United States Courts, June 30, 2016: “The number of federal and state wiretaps terminated in 2015 increased nearly 17 percent over 2014, according to an annual report submitted to Congress by the Administrative Office of the U.S. Courts.  As in previous years, drug investigations and telephone wiretaps accounted for the large majority of cases.  The 2015 Wiretap Report covers intercepts—of wire, oral or electronic communications—that  were concluded between January 1, 2015, and December 31, 2015.  The report does not include data on interceptions regulated by the Foreign Intelligence Surveillance Act of 1978.  A total of 4,148 wiretaps were reported in 2015, compared with 3,554 the previous year.  Of those, 1,403 were authorized by federal judges, 10 percent more than in 2014, and 2,745 were authorized by state judges, an increase of 21 percent.  No wiretap applications were reported as denied in 2015.”
[The encryption section: 
The number of state wiretaps in which encryption was encountered decreased from 22 in 2014 to 7 in 2015.  In all of these wiretaps, officials were unable to decipher the plain text of the messages.  Six federal wiretaps were reported as being encrypted in 2015, of which four could not be decrypted.  Encryption was also reported for one federal wiretap that was conducted during a previous year, but reported to the AO for the first time in 2015.  Officials were not able to decipher the plain text of the communications in that intercept.


What could possibly go wrong?  (What’s next?)
Mark Walker, Patrick Anderson and John Hult report:
Police in South Dakota are collecting urine samples from uncooperative suspects through the use of force and catheters, a procedure the state’s top prosecutor says is legal but is criticized by others as unnecessarily invasive and a potential constitutional violation.
The practice isn’t new, according to attorneys, but it’s been brought to light in a recent case in Pierre.
Read more on Argus Leader.


Because you can never introduce your children to surveillance too soon? 
Alphabet’s Nest Patents Smart Surveillance Crib For The Ultimate Helicopter Parent
…   Nest (now part of Alphabet since its acquisition by Google), the company best known for its smart thermostats, applied to patent a smart crib or toddler bed that would monitor infants and displays soothing images and sounds. [Big Brother loves you.  We have always been at war with Eastasia.  Bob] 

(Related)  Dilbert predicts the future?


Perspective.  Over, but not really over. 
In Senate, Blackberry Era Officially Over
…   The reign of the Blackberry lasted a good decade or more in Congress, early on due to the advanced nature of the devices and obsession with email checking.  Even when the iPhone and Androids came about, the Blackberry still kept the throne for awhile because typing on those tiny little keys was faster, a mastered skill with which the iPhone could not compete.  (This being government, they were slow to adopt other devices and Bring Your Own Device policies.)
[From the notice:
BlackBerry device support will continue for the foreseeable future.  BlackBerry is committed to maintaining their support of our devices to include uninterrupted warranty and technical support.
Once we have exhausted our current in-house stock, new device procurements will be limited, while supplies last, to warranty exchanges only.


Perspective.  “We’re # 16!  We’re # 16!”  Not very catchy, is it? 
Superfast internet? South Korea wins, U.S. lags far behind
Internet speeds are getting faster worldwide — including the U.S. But speeds here are far worse than many other countries, particularly on mobile.
Akamai, an internet platform used by websites to ensure high speeds and high quality streaming, aggregates data from the up to 200 trillion content requests it receives each quarter.
Global average connection speed rose 12% in the first quarter of 2016 from the fourth quarter of 2015, to 6.3 Mbps, according to Akamai's latest "State of the Internet" report.  Year over year, global internet speeds shot up 23%, said the content delivery network.
South Korea led the way with the highest average connection speed at 29.0 Mbps, an 8.6% increase from last quarter.  Norway (21.3 Mbps) and Sweden (20.6 Mbps) followed to make up the top three.
The United States didn't make the top 10, ranking No. 16 with average connection speed of 15.3 Mbps, a 7.7% rise from the prior quarter.
…   In mobile, you're best off in the United Kingdom.  The country by far had the highest average mobile speed with 27.9 Mbps. Belgium, in contrast, had only 70% of the U.K.'s average speed with 19.4 Mbps.  Algeria had the lowest average connection speed with 2.2 Mbps. Speeds in Iran, the country that had the slowest average speed in the fourth quarter with 1.8 Mbps, improved to 4.7 Mbps this quarter.
The U.S. had an average mobile speed of 5.1, on par with Thailand.


This is more for my Excel class than PowerPoint users.
Improve Your PowerPoint Presentation with Excel Data Visualizations


For my IT Architecture students.
WhatsApp Grew to One Billion Users by Focusing on Product, Not Technology
…   when Mubarik Imam, head of growth and partnerships for WhatsApp, told the company’s extraordinary story to a group of high-level executives and technology experts at a conference in Palo Alto last year, the narrative was conspicuously free of digital breakthroughs or “aha!” moments.  For those who hoped to hear the secret of how digital wizardry turned two disgruntled Yahoo veterans into overnight billionaires, the real story was an eye-opener.  Transforming a relatively simple idea into a $19 billion windfall, it turns out, was more about solving problems with the tools at hand than inventing new solutions from scratch.


If it’s Saturday, Education foibles…
Hack Education Weekly News
…   The US Department of Education released its “#GoOpenDistrict Launch Packet,” encouraging schools to use OER.  As Stephen Downes comments, “I find it interesting that they refer throughout to ‘openly licensed educational materials’ rather than ‘open educational resources’ – I wonder what the reasoning was behind that.”  Rebrand.  Realign.  Rewrite history.  The usual, I’d wager.
…   Hillary Clinton unveiled her tech platform this week.  Excuse me.  Her “innovation agenda.”  She promises that every kid will learn to code (of course) by having the private sector train CS teachers.  She wants federal financial aid for coding bootcamps and nanodegrees.  Her plan also involved a talking point about diversifying the tech workforce, but then she went ahead and announced this doozy: a student loan deferment program for startup founders.  Alexander Holt offers a pretty good argument as to why this is a “giveaway to Silicon Valley.”  (The whole platform sounds like that, to be honest.)  “Is Student-Loan Debt Really Holding Would-Be Entrepreneurs Back?” asks The Chronicle of Higher Education.  More on Clinton’s plans via Edweek’s Market Brief, Inside Higher Ed, and The New York Times.
…   Via The Chronicle of Higher Education: “As Big Data Comes to College, Officials Wrestle to Set New Ethical Norms.”