Thursday, January 18, 2018

The unexplored country? Every new technology must re-learn security from scratch?
Some Basic Rules for Securing Your IoT Stuff
Most readers here have likely heard or read various prognostications about the impending doom from the proliferation of poorly-secured “Internet of Things” or IoT devices. Loosely defined as any gadget or gizmo that connects to the Internet but which most consumers probably wouldn’t begin to know how to secure, IoT encompasses everything from security cameras, routers and digital video recorders to printers, wearable devices and “smart” lightbulbs.
Throughout 2016 and 2017, attacks from massive botnets made up entirely of hacked IoT devices had many experts warning of a dire outlook for Internet security. But the future of IoT doesn’t have to be so bleak. Here’s a primer on minimizing the chances that your IoT things become a security liability for you or for the Internet at large.




Another resource for my Data Management students!
Research Data Management at Harvard
Releasing in 2018
•Harvard-wide research data management website: http://datamanagement.harvard.edu (Q1)
•Single contact: datamanagement@harvard.edu (Q1)




Should we require software like this to go through testing like the FDA uses for new drugs?
Mechanical Turkers may have out-predicted the most popular crime-predicting algorithm
Our most sophisticated crime-predicting algorithms may not be as good as we thought. A study published today in Science Advances takes a look at the popular COMPAS algorithm — used to assess the likelihood that a given defendant will reoffend — and finds the algorithm is no more accurate than the average person’s guess.
… Reached by The Verge, Equivant contested the accuracy of the paper in a lengthy statement, calling the work “highly misleading.”
COMPAS has been criticized by ProPublica for racial bias (a claim some statisticians dispute), but the new paper, from Hany Farid and Julia Dressel of Dartmouth, tackles a more fundamental question: are COMPAS’ predictions any good? Drawing on ProPublica’s data, Farid and Dressel found the algorithm predicted reoffenses roughly 65 percent of the time — a low bar, given that roughly 45 percent of defendants reoffend.
In its statement, however, Equivant argues it has cleared the 70 percent AUC standard for risk assessment tools.




I’m kind of collecting tools like these.
Loom 2.0 - Create and Edit Screencasts
Loom is a free screencasting tool that works in the Chrome web browser. In addition to using it on a Chromebook, you can use Loom on a Mac or Windows computer as long as use the Chrome browser. Loom will let you create a recording of anything on your computer's screen. There's also an option to use your webcam while recording.
This week Loom announced the launch of version 2.0. Loom 2.0 includes the option to trim sections out of your videos. Initially, Loom limited recordings to ten minutes. That restriction has been removed in the latest version of Loom. Learn more about Loom 2.0 by watching the video that is embedded below. Watch for the bit about how you can use emoji reactions with your videos.




Denver is still in the hunt.
Amazon narrows HQ2 search to 20 cities, moving to next phase in contest for $5B economic prize
Amazon has selected 20 cities to move to the next phase in its HQ2 selection process, the latest twist in an unprecedented headquarters search that has turned into a national curiosity.
The cities, named by the company a few moments ago, are Toronto, Columbus, Indianapolis, Chicago, Denver, Nashville, Los Angeles, Dallas, Austin, Boston, New York City, Newark, Pittsburgh, Philadelphia, Montgomery County, Washington, D.C., Raleigh, Northern Virginia, Atlanta, and Miami.
… The company employs more than 540,000 people worldwide, taking into account its Whole Foods acquisition, up from just 20,000 a decade ago.
During that period, Amazon has expanded beyond its roots in e-commerce and digital reading into cloud computing, logistics, drones, brick-and-mortar retail stores, artificial intelligence and many other parts of the technology world.


Wednesday, January 17, 2018

I’m much more interested in the steps they’ve agreed to take now rather than before the breach.
There’s an update to the University of Central Florida breach that was first disclosed in early 2016. The Orlando Sentinel reports:
The University of Central Florida has agreed to spend an additional $1 million annually to protect students’ and employees’ personal information, according to a legal settlement reached with former students in the wake of a hacking that exposed 63,000 Social Security numbers.
UCF agreed to add three information security positions, designate a full-time internal senior information security auditor and tighten access to personal information, as part of the settlement filed in Orange Circuit Court late last year.
The FBI’s Jacksonville office investigated the incident, which became public in early 2016, but has not released information on how it happened.
Read more on Orlando Sentinel, but this is part of what’s wrong with these settlements:
The five plaintiffs named in the suit will each receive $500, and the university will pay $64,200 for attorney fees and costs.




No wonder they screwed up and issued a false alert.
Hawaii’s missile alert agency keeps its password on a Post-it note
… Serious questions have been asked about how the bogus missile alert could have been sent out, and what can be done to ensure that members of the public are more rapidly informed if more mistakes occur in the future.
My feeling is that although there was no foul play behind the false missile warning, HEMA might be wise to also look at its general approach to IT security.
As Business Insider describes, evidence has come to light that some of the organisation’s staff might be in the habit of sticking Post-it notes containing passwords onto their computer monitors.
That in itself is far from ideal, but what’s even worse is that these Post-it note passwords have been caught on camera by the media, and available for anybody to view on the internet.




How much should Amazon disclose?
Amazon won't say if it hands your Echo data to the government
Amazon has a transparency problem.
Three years ago, the retail giant became the last major tech company to reveal how many subpoenas, search warrants, and court orders it received for customer data in a half-year period. While every other tech giant had regularly published its government request figures for years, spurred on by accusations of participation in government surveillance, Amazon had been largely forgotten.
Eventually, people noticed and Amazon acquiesced.
… After its second report, we asked Amazon spokesperson Frank Fellows in July 2016 if the company would include data such as Echo audio, retail, and mobile service data in the future. He declined to comment.




My students have been asking about BlockChain.
Maersk, IBM create world's first blockchain-based, electronic shipping platform
Maersk and IBM today announced a joint venture to deploy a blockchain-based electronic shipping system that will digitize supply chains and track international cargo in real time.
The new platform could save the global shipping industry billions of dollars a year by replacing the current EDI- and paper-based system, which can leave containers in receiving yards for weeks, according to the companies.




Why didn’t Mark Zuckerberg write this article?




Get researching!
Dimensions – Next-generation research and discovery tool links 128 million documents
This is a free and fee based service launched by Digital Science – “Global technology company Digital Science is proud to announce the launch of Dimensions, a new platform that aims to democratise and transform scholarly search. A collaboration between six Digital Science portfolio companies (Altmetric, Digital Science Consultancy, Figshare, Readcube, Symplectic and ÜberResearch) and more than 100 research funders and universities, Dimensions offers a better, faster way to discover, understand and analyse the global research landscape, without wasting time searching for information across multiple poorly integrated tools. Dimensions breaks down barriers to discovery and innovation by making over 860 million academic citations freely available, and delivers one-click access to over 9 million Open Access articles.
… Built using real-world use cases, it combines advanced concept extraction, natural language processing, categorization and complex machine learning to create a flexible and robust tool that meets the most demanding modern research needs.”


Tuesday, January 16, 2018

What would have made this legal? Is there anything illegal about re-publishing data that has been publicly available for months? Isn’t that simply “data aggregation?”
Canadian Man Charged Over Leak of Three Billion Hacked Accounts
An Ontario man made his first court appearance Monday to answer charges of running a website that collected personal and password data from some three billion accounts, and sold them for profit.
Jordan Evan Bloom, 27, of Thornhill earned some Can$247,000 ($198,800 US) by selling the data for a "small fee" via leakedsource.com, the Royal Canadian Mounted Police said in a statement.
The information was stolen during massive hacks of websites including LinkedIn and the Ashley Madison online dating service.
Authorities have shut down Bloom's website, but another with the same domain name hosted by servers in Russia is still operating.




Something for my Computer Security students to consider. Why I start so many descriptions of technology with the phrase, “It’s like...”
Law, Metaphor and the Encrypted Machine
Gill, Lex, Law, Metaphor and the Encrypted Machine (2017). Available at SSRN: https://ssrn.com/abstract=2933269 – “The metaphors we use to imagine, describe and regulate new technologies have profound legal implications. This paper offers a critical examination of the metaphors we choose to describe encryption technology in particular, and aims to uncover some of the normative and legal implications of those choices. Part I provides a basic description of encryption as a mathematical and technical process. At the heart of this paper is a question about what encryption is to the law. It is therefore fundamental that readers have a shared understanding of the basic scientific concepts at stake. This technical description will then serve to illustrate the host of legal and political problems arising from encryption technology, the most important of which are addressed in Part II. That section also provides a brief history of various legislative and judicial responses to the encryption “problem,” mapping out some of the major challenges still faced by jurists, policymakers and activists. While this paper draws largely upon common law sources from the United States and Canada, metaphor provides a core form of cognitive scaffolding across legal traditions. Part III explores the relationship between metaphor and the law, demonstrating the ways in which it may shape, distort or transform the structure of legal reasoning. Part IV demonstrates that the function served by legal metaphor is particularly determinative wherever the law seeks to integrate novel technologies into old legal frameworks. Strong, ubiquitous commercial encryption has created a range of legal problems for which the appropriate metaphors remain unfixed. Part V establishes a loose framework for thinking about how encryption has been described by courts and lawmakers—and how it could be. What does it mean to describe the encrypted machine as a locked container or building? As a combination safe? As a form of speech? As an untranslatable library or an unsolvable puzzle? What is captured by each of these cognitive models, and what is lost? This section explores both the technological accuracy and the legal implications of each choice. Finally, the paper offers a few concluding thoughts about the utility and risk of metaphor in the law, reaffirming the need for a critical, transparent and lucid appreciation of language and the power it wields.”




Possible insights from a war fighting strategy?
U.S. Army Concept for Cyberspace and Electronic Warfare Operations 2025-2040
The U.S. Army Concept for Cyberspace and Electronic Warfare Operations 2025-2040, CRS report via FAS. “TRADOC Pamphlet 525-8- 6, The U.S. Army Concept for Cyberspace and Electronic Warfare Operations expands on the ideas presented in TRADOC Pamphlet 525-3- 1, The U.S. Army Operating Concept: Win in a Complex World (AOC). This document describes how the Army will operate in and through cyberspace and the electromagnetic spectrum and will fully integrate cyberspace, electronic warfare (EW), and electromagnetic spectrum operations as part of joint combined arms operations to meet future operational environment challenges. Cyberspace and EW operations provide commanders the ability to conduct simultaneous, linked maneuver in and through multiple domains, and to engage adversaries and populations where they live and operate. Cyberspace and EW operations provide commanders a full range of physical and virtual, as well as kinetic and non-kinetic, capabilities tailored into combinations that enhance the combat power of maneuver elements conducting joint combined operations. This concept serves as a foundation for developing future cyberspace and electronic warfare capabilities and helps Army leaders think clearly about future armed conflict, learn about the future through the Army’s campaign of learning, analyze future capability gaps and identify opportunities, and implement interim solutions to improve current and future force combat effectiveness..”


(Related)
Trust War: Dangerous Trends in Cyber Conflict




Perspective. Big Data requires big infrastructure.
Cloud computing: Now Google adds more data centers, plans its own undersea cable
… The advertising-to-cloud-computing giant said its new Netherlands and Montreal cloud computing regions will open in the first quarter of 2018, followed by Los Angeles, Finland, and Hong Kong.
Like other cloud infrastructure companies, Google orders its cloud computing resources into regions which are then subdivided into zones, which include one or more data centers from which customers can run their services. It currently has 15 regions made up of 44 zones.
… It's the second announcement of big cloud computing infrastructure spending of the day: Google's big rival Amazon Web Services has already announced it has opened its 50th data center availability zone, in London. AWS has plans for 12 more AZs and four more regions.




Student toolkit.
Search your Handwritten Notes with Gmail OCR
One of the most useful features of Evernote and OneNote is Image OCR. When you clip an image – be it a screenshot, a scanned business card, or a picture of the whiteboard – these tools automatically detect the text inside the image and make the image searchable.
Gmail text search has always been very capable but some might not know that Gmail, like Evernote, also performs OCR on images contained in email messages. When you perform searches inside Gmail or Google Inbox, the results always contain matching images that contain the search keywords.
… Text recognition in Gmail works for both image attachments as well as inline embedded images.
Google Drive and Google Keep are other Google products that offer you the ability to search for text within stored images. In the case of Google Keep, you also have the option to extract the text detected inside in an image and store it within the note itself.


(Ditto)


Monday, January 15, 2018

Heads up!
https://www.marketwatch.com/story/have-you-received-an-email-from-netflix-read-this-first-2018-01-12?reflink=MW_GoogleNews&google_editors_picks=true
Have you received an email from Netflix? Read this first…
Thousands of Netflix customers have been scammed into handing out their credit-card information through a convincing-looking false email.
The phishing scam prompted users to update their payment information on the site to avoid service being suspended. Once they clicked “update payment,” according to security company Mailguard, they were taken to what looked like a legitimate log-in portal to input credit-card information.
Scams like this, called “brandhacking,” rely on the strength of a company’s name to get users to trust such emails.






Interesting questions for Security experts who discover someone else’s breach.
https://www.troyhunt.com/streamlining-data-breach-disclosures-a-step-by-step-process/
Streamlining Data Breach Disclosures: A Step-by-Step Process
I don't know how many data breaches I'm sitting on that I'm yet to process. 100? 200? It's hard to tell because often I'm sent collections of multiple incidents in a single archive, often there's junk in there and often there's redundancy across those collections. All I really know is that there's hundreds of gigabytes spread across thousands of files. Sometimes - like in the case of the recent South Africa situation - I could be sitting on data for months that's actually very serious in nature and needs to be brought public awareness.
The biggest barrier by far to processing these is the effort involved in disclosure. I want to ensure that any incidents I load into Have I Been Pwned (HIBP) are first brought to the awareness of the organisations involved and whilst that may seem straight forward, it's often quite the opposite. There are notable exceptions (such as the recent Disqus disclosure), but more often than not, it's a laborious process of varying success. Because this is something I do over and over again, I want to streamline the process and more than that, I want to seek community input.
Tell me if I'm doing this right. This post documents how I intend to handle serious incidents with real consequences and frankly, I don't want to stuff it up.






Perhaps they should spend less time staring at encrypted phones?
FBI Is Disrupting 10X Fewer Cyber Crime Rings Than In 2015
Joseph Marks reports:
FBI agents took down or disrupted only about one-tenth as many cyber criminal operations during the 2017 fiscal year as they did three years earlier, according to annual reports.
The number of cyber crime operations that FBI agents dismantled or disrupted fell from nearly 2,500 in fiscal year 2014, the first year reliable records were kept, to just 262 in fiscal year 2017, according to annual audits.
Agents disrupted or dismantled 510 cyber crime operations in fiscal year 2015 and 259 operations in fiscal year 2016, according to the audits.
The FBI missed its own target of 500 disruptions or dismantlements in fiscal years 2016 and 2017, according to the report.
Read more on NextGov.






Perspective.
https://www.bloomberg.com/news/articles/2018-01-15/alibaba-s-ai-outgunned-humans-in-key-stanford-reading-test
Alibaba's AI Outguns Humans in Reading Test
Alibaba has developed an artificial intelligence model that scored better than humans in a Stanford University reading and comprehension test.
Alibaba Group Holding Ltd. put its deep neural network model through its paces last week, asking the AI to provide exact answers to more than 100,000 questions comprising a quiz that’s considered one of the world’s most authoritative machine-reading gauges. The model developed by Alibaba’s Institute of Data Science of Technologies scored 82.44, edging past the 82.304 that rival humans achieved.
Alibaba said it’s the first time a machine has out-done a real person in such a contest. Microsoft achieved a similar feat, scoring 82.650 on the same test, but those results were finalized a day after Alibaba’s, the company said.






Not sure I agree.
https://www.teachthought.com/literacy/5-dimensions-of-critical-digital-literacy/
5 Dimensions Of Critical Digital Literacy: A Framework
Digital Literacy is increasingly important in an age where many students read as much on screens as they do from books.
In fact, the very definition of many of these terms is changing as the overlap across media forms increases. Interactive eBooks can function like both long-form blogs and traditional books. Threaded email can look and function like social media. Email and texting and social media messaging are increasingly similar.
1. Decoding
Focus: the media–modes, structures, and conventions of digital media
2. Meaning Making
Focus: the reader–style, purpose, interpretation
3. Analyzing
Focus: the author–aesthetics, ethics, and related choices
4. Persona
Focus: a community–how others perceive the issue, topics, and context
5. Using
Focus: a marriage of self and community–problem-solving and data acquisition for a variety of authentic–and changing–purposes






Could be amusing.
https://www.engadget.com/2018/01/15/googles-museum-app-finds-your-fine-art-doppelganger/
Google's museum app finds your fine art doppelgänger
If you've ever wondered if there's a museum portrait somewhere that looks like you and you're ready to have your ego crushed, there's now an app for that. Google Arts & Culture's latest update now lets you take a selfie, and using image recognition, finds someone in its vast art collection that most resembles you. It will then present you and your fine art twin side-by-side, along with a percentage match, and let you share the results on social media, if you dare.



Sunday, January 14, 2018

Some big names on this list. Better check for your site!
by Steven Englehardt, Gunes Acar, and Arvind Narayanan
Recently we revealed that “session replay” scripts on websites record everything you do, like someone looking over your shoulder, and send it to third-party servers. This en-masse data exfiltration inevitably scoops up sensitive, personal information — in real time, as you type it. We released the data behind our findings, including a list of 8,000 sites on which we observed session-replay scripts recording user data.
As one case study of these 8,000 sites, we found health conditions and prescription data being exfiltrated from walgreens.com. These are considered Protected Health Information under HIPAA. The number of affected sites is immense; contacting all of them and quantifying the severity of the privacy problems is beyond our means. We encourage you to check out our data release and hold your favorite websites accountable.
Student data exfiltration on Gradescope
As one example, a pair of researchers at UC San Diego read our study and then noticed that Gradescope, a website they used for grading assignments, embeds FullStory, one of the session replay scripts we analyzed. We investigated, and sure enough, we found that student names and emails, student grades, and instructor comments on students were being sent to FullStory’s servers. This is considered Student Data under FERPA (US educational privacy law). Ironically, Princeton’s own Information Security course was also affected. We notified Gradescope of our findings, and they removed FullStory from their website within a few hours.
Read more on Freedom to Tinker.
wordpress.com
microsoft.com
adobe.com
godaddy.com
skype.com




An opportunity to talk about proper procedures with my Computer Security students. One accidental button push? Also, imagine the little fat kid who runs North Korea ordering his hackers to send these warnings.
Hawaii missile false alarm triggers shock, blame and apologies
The alert of an incoming ballistic missile was sent wrongly on Saturday morning by an emergency system worker.
Victims of the ordeal spoke of hysteria and panicked evacuations.
The false alarm sparked recriminations, with state officials apologising and President Donald Trump's response called into question.
It was a mistake by an employee at Hawaii's Emergency Management Agency (EMA) who "pushed the wrong button" during procedures that occur during the handover of a shift.
Mobile phone users received the message at 08:07 (18:07 GMT):
"Ballistic missile threat inbound to Hawaii. Seek immediate shelter. This is not a drill."
The alert was corrected by email 18 minutes later but there was no follow-up mobile text for 38 minutes, the Honolulu Star-Advertiser reports.




Tools for all my students.
In 2016, a University of Phoenix study revealed that two out of three U.S. adults were aware that their social media accounts had been hacked. Furthermore, a majority of adults limit what personal information they share.
But the hackers keep on coming.




Microsoft is asking the Supreme Court about this…
David Fraser of McInnes Cooper writes:
Whether a provincial court will grant police a “production order” under the Criminal Code of Canada requiring a non-Canadian company to produce any of its records has, to date, depended on the province in which police seek it. Some courts refuse an order where the company is wholly outside of Canada; some require an address in Canada for service to grant the order; and others grant the order, apparently unconcerned about the company’s Canadian “presence”. That could however change with the B.C. Court of Appeal’s January 9, 2018, decision in British Columbia (Attorney General) v. Brecknell. The Court’s decision that Craigslist is “present” in B.C. and can be subject to a Criminal Code production order issued from its provincial court might lead to greater national uniformity – and more exposure to foreign companies doing only virtual business in Canada:
[Much more follows. Bob]




Perspective.
John Sculley: Why AI Is the Tech Trend to Watch in 2018
… “AI is going to be foundational in every industry. I’m seeing it in fintech, market tech, health tech…. It’s one of those fundamental changes. In the previous industrial age, it was all about electricity and oil; in the future [AI is] going to be a commodity that will be deployed in many, many different ways, and will be something you can just plug into.




Perspective.
39 million Americans now own a smart speaker, report claims
One in six Americans now own a smart speaker, according to new research out this week from NPR and Edison Research – a figure that’s up 128 percent from January, 2017. Amazon’s Echo speakers are still in the lead, the report says, as 11 percent now own an Amazon Alexa device compared with 4 percent who own a Google Home product.
Today, 16 percent of Americans own a smart speaker, or around 39 million people.




Also one of my favorites.
W3Schools - Your HTML Reference
W3Schools is my go-to reference for all questions regarding how to write any aspect of HTML code. In fact, when I was recently asked a question about writing HTML that I couldn't immediately answer, I turned to W3Schools.
W3Schools offers complete tutorials for learning to write HTML, CSS, Javascript, and PHP. If you're just getting started, work through the tutorials in sequences. Each tutorial has a little interactive section where you can test your new knowledge. If you're experienced and just need a quick reminder or clarification, W3Schools has that too.
W3Schools is a great resource for the student who is capable of directing himself or herself through a sequence of tutorials. W3Schools is not great for a student who needs a clearly defined "do this now," "do this next" type of lesson. For that type of student, I would recommend trying Thimble by Mozilla.




Will the US Navy follow suit?
The Royal Navy updated a famous WWII propaganda poster to warn its sailors about tweeting



Saturday, January 13, 2018

Never leave your computer unattended.
Simple Attack Allows Full Remote Access to Most Corporate Laptops
Researchers have discovered a flaw in Intel's Advanced Management Technology (AMT) implementation that can be abused with less than a minute of physical access to the device.
An Evil Maid attack could ultimately give an adversary full remote access to a corporate network without having to write a single line of code.
The flaw was discovered by F-Secure senior security consultant Harry Sintonen, and disclosed today.
"In practice, it can give an attacker complete control over an individual's work laptop, despite even the most extensive security measures."
The problem is that setting a BIOS password (standard procedure) does not usually prevent access to the AMT BIOS extension – the Intel Management Engine BIOS Extension (MEBx). Unless this separate password is changed, and usually it is not, the default 'admin' password will give the attacker access to AMT.




Have politicians learned anything about security?
Shane Harris reports:
The Russian hackers who stole emails from the Democratic National Committee as part of a campaign to interfere in the 2016 election have been trying to steal information from the U.S. Senate, according to a report published Friday by a computer security firm.
Beginning last June, the Russian hackers set up websites that were meant to look like an email system available only to people using the Senate’s internal computer network, said the report by Trend Micro Inc. The sites were designed to trick people into divulging their personal credentials, such as usernames and passwords.
The Associated Press was first to write about the report.
Read more on Washington Post.




I wonder what the FBI uses?
Microsoft Brings End-to-End Encryption to Skype
Microsoft this week announced that end-to-end encrypted communications are now available for preview to Skype insiders.
Called Private Conversations, the newly introduced feature secures both text chat messages and audio calls, Microsoft Program Manager Ellen Kilbourne revealed.
Furthermore, end-to-end encryption is also applied to any files users send to their conversational partners, including images, audio files, and videos. Not only will the contents of these conversations be hidden in the chat list, but they won’t appear in notifications either, to keep user’s information private.
Private Conversations, Kilbourne explains in a post, is using the industry standard Signal Protocol by Open Whisper Systems. The protocol is already providing end-to-end encryption to users of popular messaging applications such as Signal, WhatsApp, and Facebook Messenger.




Getting you ducks in order.
The road to AI leads through information architecture
… The evolution of the auto industry is similar in form to the currently nascent world of artificial intelligence . And like the auto industry, in order for AI to flourish, organizations must adopt and embrace a prerequisite set of conditions, or building blocks. For example, AI requires machine learning, machine learning requires analytics, and analytics requires the right data and information architecture (IA). In other words, there is no AI without IA. These capabilities form the solid rungs of what we call the “AI Ladder” — the increasing levels of analytic sophistication that lead to, and buttress, a thriving AI environment.




I want to talk this through with my Data Management class. Think of what is required to implement it?
U.S. Supreme Court to Review Bid to Collect Internet Sales Tax
The U.S. Supreme Court will consider freeing state and local governments to collect billions of dollars in sales taxes from online retailers, agreeing to revisit a 26-year-old ruling that has made much of the internet a tax-free zone.
Heeding calls from traditional retailers and dozens of states, the justices said they’ll hear South Dakota’s contention that the 1992 ruling is obsolete in the e-commerce era and should be overturned.




Because I’m hoping they let me teach Math again…
10 Good Resources for Math Teachers and Students




I’m sure the President would (like to) agree with Dilbert.


Friday, January 12, 2018

Step by step to illustrate a failure. Where else might this work?
Bogus Passwords Can Unlock AppStore Preferences in macOS
A security vulnerability impacting macOS High Sierra allows admins to unlock the AppStore Preferences in System Preferences by providing any password.
The issue was found to affect macOS 10.13.2, the latest iteration of the platform, and can be reproduced only if the user is logged in as administrator. For non-admin accounts, the correct credentials are necessary to unlock the preferences pane.
macOS High Sierra 10.13.2 users interested in reproducing the bug should log into their machines as administrators, then navigate to the App Store preferences in System Preferences.
Next, users should click on the padlock icon to lock it if necessary, then click it again. When prompted to enter the login credentials, they can use any password and still unlock the Prefpane.




Interesting. Prepare a dossier by stealing data online (or maybe just the Equifax data?) and use it to construct a plausible case for infidelity. Would it seem more real if it came by mail?
Bitcoin Blackmail by Snail Mail Preys on Those with Guilty Conscience
KrebsOnSecurity heard from a reader whose friend recently received a remarkably customized extortion letter via snail mail that threatened to tell the recipient’s wife about his supposed extramarital affairs unless he paid $3,600 in bitcoin. The friend said he had nothing to hide and suspects this is part of a random but well-crafted campaign to prey on men who may have a guilty conscience.
The letter addressed the recipient by his first name and hometown throughout, and claimed to have evidence of the supposed dalliances.
… Of course, sending extortion letters via postal mail is mail fraud, a crime which carries severe penalties (fines of up to $1 million and up to 30 years in jail). However, as the extortionist rightly notes in his letter, the likelihood that authorities would ever be able to catch him is probably low.
The last time I heard of or saw this type of targeted extortion by mail was in the wake of the 2015 breach at online cheating site AshleyMadison.com. But those attempts made more sense to me since obviously many AshleyMadison users quite clearly did have an affair to hide.
… I opted not to publish a scan of the letter here because it was double-sided and redacting names, etc. gets dicey thanks to photo and image manipulation tools. Here’s a transcription of it instead (PDF).




How (not) to handle a breach?
Federal Appeals Court Slams Data Breach Privilege Claim
In the most recent object lesson in a data breach privilege case, a federal appeals court has ordered a Michigan-based mortgage lender to turn over privileged forensic investigatory documents after the investigator’s conclusions were revealed in discovery.
… In an interrogatory response, United Shore said that it retained a forensic firm – through counsel – to investigate the breach that had concluded XMS’s action caused the intrusions. The interrogatory stated that its forensic investigator determined that “certain files stored in XMS’s … system had been accessed without authorization … in plain violation of established security protocols.” United Shore disclosed more than 150 non-privileged documents concerning the investigation, but it withheld additional documents based on the attorney client privilege.
District Court Ruling. XMS moved to compel United Shore to produce the privileged documents, arguing that it implicitly waived the attorney-client privilege by referencing its investigator’s conclusions in its discovery response.
The district court agreed. It concluded that United Shore not only disclosed that its investigator "conducted an investigation ... [but] also provided...conclusions from that investigation.”




Would we pass a law like this if we were starting from zero today? Probably not.
House Extends Surveillance Law, Rejecting New Privacy Safeguards
The House of Representatives voted on Thursday to extend the National Security Agency’s warrantless surveillance program for six years with minimal changes, rejecting a push by a bipartisan group of lawmakers to impose significant privacy limits when it sweeps up Americans’ emails and other personal communications.
The vote, 256 to 164, centered on an expiring law that permits the government, without a warrant, to collect communications from United States companies like Google and AT&T of foreigners abroad — even when those targets are talking to Americans.




Law is complex. Is there any place to ask about a topic and get answers that point out differences in all 50 states?
This may come as a shock. AP reports:
Connecticut’s highest court ruled Thursday on an issue that most people may think is already settled, saying doctors have a duty to keep patients’ medical records confidential and can be sued if they don’t.
The Supreme Court’s 6-0 decision overturned the ruling of a lower court judge who said Connecticut had yet to recognize doctor-patient confidentiality.
The high court’s ruling reinstated a lawsuit by former New Canaan resident Emily Byrne against the Avery Center for Obstetrics & Gynecology in Westport.
Read more on Boston Herald, while I scratch my head over this one. Connecticut health law never required confidentiality? Seriously? From reading the rest of the article, it sounds like the center had a pretty clear privacy policy that made it clear that they might disclose in response to subpoenas, but even so…..
So for all this time, mental health patients in Connecticut had no enforceable right to confidentiality? Or was there an exception for mental health?
How could this be????




Governments do not do IT well. (I may have said that a few hundred times.)
GAO – Agencies Need to Involve Chief Information Officers in Reviewing Billions of Dollars in Acquisitions
Information Technology: Agencies Need to Involve Chief Information Officers in Reviewing Billions of Dollars in Acquisitions GAO-18-42: Published: Jan 10, 2018. Publicly Released: Jan 10, 2018.
“Most of the 22 selected agencies did not identify all of their information technology (IT) contracts. The selected agencies identified 78,249 IT-related contracts, to which they obligated $14.7 billion in fiscal year 2016. However, GAO identified 31,493 additional contracts with $4.5 billion obligated, raising the total amount obligated to IT contracts in fiscal year 2016 to at least $19.2 billion (see figure). The percentage of additional IT contract obligations GAO identified varied among the selected agencies. For example, the Department of State did not identify 1 percent of its IT contract obligations. Conversely, 8 agencies did not identify over 40 percent of their IT-related contract obligations. Many of the selected agencies that did not identify these IT acquisitions did not follow Office of Management and Budget’s (OMB) guidance.
... agencies will likely miss an opportunity to strengthen CIOs’ authority and the oversight of IT acquisitions. As a result, agencies may award IT contracts that are duplicative, wasteful, or poorly conceived.”




Apparently, Ram trucks won’t be able to get over the wall either.
Fiat Chrysler Is Moving a Plant From Mexico to Michigan
Fiat Chrysler Automobiles said on Thursday it will shift production of Ram heavy-duty pickup trucks from Mexico to Michigan in 2020, a move that lowers the risk to the automaker’s profit should President Donald Trump pull the United States out of the North American Free Trade Agreement.




For my International students. Quite a list of languages supported!
Voice Dictation – Type with your Voice
Introducing the all-new Voice Dictation v2.0, a speech recognition app that lets you type with your voice. There’s no software to install, there’s no training required and all you need is Google Chrome on your Windows PC, Mac OS or Linux.
Dictation can recognize spoken words in English, Hindi, Espaùol, Italiano, Deutsch, Français, and all the other popular languages. Another unique feature of Dictation is support for voice commands that let you do more with your voice. For instance, you can say a command like new line or nueva línea for inserting lines. You can add punctuations, special symbols and even smileys using simple commands in most languages.
This YouTube video will walk you through the Dictation app.
Dictation stores everything in your browser locally and not a byte of your data is uploaded anywhere.


Thursday, January 11, 2018

Don’t mess with Putin.
Hackers Leak Olympic Committee Emails in Response to Russia Ban
A group of hackers linked to Russia has leaked several emails apparently exchanged between officials of the International Olympic Committee (IOC) and other individuals involved with the Olympics. The leak comes in response to Russia being banned from the upcoming Pyeongchang 2018 Winter Games in South Korea.
The group, calling itself Fancy Bears and claiming to be a team of hacktivists that “stand for fair play and clean sport,” previously released confidential athlete medical records stolen from the systems of the World Anti-Doping Agency (WADA), and also targeted the International Association of Athletics Federations (IAAF). One of their most recent leaks included emails and medical records related to football (soccer) players who used illegal substances.
The first leaks from Fancy Bears came shortly after Russian athletes were banned from the 2016 Rio Olympics following reports that Russia had been operating a state-sponsored doping program.
While Fancy Bears claim to be hacktivists, researchers have found ties between the group and Fancy Bear, a sophisticated Russian cyber espionage team also known as APT28, Pawn Storm, Sednit, Sofacy, Tsar Team and Strontium.
The latest leak includes emails apparently exchanged between IOC officials and other individuals involved with the Olympics. Some of the messages discuss the recent decision to ban Russia from the upcoming Winter Games based on the findings of the IOC Disciplinary Commission.
While the hackers claim the emails they leaked prove the accusations, a majority of the messages don’t appear to contain anything critical. Furthermore, Olympics-related organizations whose systems were previously breached by the hackers claimed at the time that some of the leaked files had been doctored.




Evaluating the potential for hacking without actually hacking.
Is India's Aadhaar System Really "Hack-Proof"? Assessing a Publicly Observable Security Posture




Gosh, what a clever idea!
Uber’s Secret Tool for Keeping the Cops in the Dark
In May 2015 about 10 investigators for the Quebec tax authority burst into Uber Technologies Inc.’s office in Montreal. The authorities believed Uber had violated tax laws and had a warrant to collect evidence. Managers on-site knew what to do, say people with knowledge of the event.
Like managers at Uber’s hundreds of offices abroad, they’d been trained to page a number that alerted specially trained staff at company headquarters in San Francisco. When the call came in, staffers quickly remotely logged off every computer in the Montreal office, making it practically impossible for the authorities to retrieve the company records they’d obtained a warrant to collect. The investigators left without any evidence.




There ought to be a law…
This is still happening? It shouldn’t be. At what point should they be required to abandon using fax?
Alicia Bridges of CBC reports:
The Saskatchewan Health Authority has again faxed private medical information about a patient to a North Battleford computer shop, according to the frustrated owner of the business.
Darryl Arnold says his company fax machine received a 21-page medical report from the Shellbrook Hospital that was intended for a North Battleford-area doctor.
Read more on CBC. What’s also disturbing is that they seem to be trying to put the problem-solving on the involuntary recipient of their misdirected faxes:
Arnold said his company’s fax number is nearly identical to the one belonging to a North Battleford-area doctor’s office — it’s just one digit different.
He said he has been in contact with a health authority worker, who suggested he address the problem by changing his business fax number.
Arnold said he is willing to do that as long as the health authority compensates him for reprinting company business cards and letterhead.
But he said the health authority did not respond after he sent them the amount he wants them to pay for the number.
Arnold said the authority also suggested he try to set up his fax machine to block faxes from health authority numbers, but the company that sold him the machine has told him that’s not possible.
SHA is the source of the breach. THEY have to solve/prevent this – not the computer shop. Jeez….




For my Computer Security students.




I like the “annual inspection” idea. BUT Let’s do the math: $100 times 143,000,000 = More than the PowerBall and MegaMillions combined! It will never pass.
Bill Would Establish Cybersecurity Inspections, Impose Mandatory Penalties, and Compensate Consumers for Stolen Data
“United States Senators Elizabeth Warren (D-Mass.) and Mark Warner (D-Va.) today introduced the Data Breach Prevention and Compensation Act to hold large credit reporting agencies (CRAs) – including Equifax – accountable for data breaches involving consumer data. The bill would give the Federal Trade Commission (FTC) more direct supervisory authority over data security at CRAs, impose mandatory penalties on CRAs to incentivize adequate protection of consumer data, and provide robust compensation to consumers for stolen data. In September 2017, Equifax announced that hackers had stolen sensitive personal information – including Social Security Numbers, birth dates, credit card numbers, driver’s license numbers, and passport numbers – of over 145 million Americans. The attack highlighted that CRAs hold vast amounts of data on millions of Americans but lack adequate safeguards against hackers. Since 2013, Equifax has disclosed at least four separate hacks in which sensitive personal data were compromised. The Data Breach Prevention and Compensation Act would establish an Office of Cybersecurity at the FTC tasked with annual inspections and supervision of cybersecurity at CRAs. It would impose mandatory, strict liability penalties for breaches of consumer data beginning with a base penalty of $100 for each consumer who had one piece of personal identifying information (PII) compromised and another $50 for each additional PII compromised per consumer. Under this legislation, Equifax would have had to pay at least a $1.5 billion penalty for their failure to protect Americans’ personal information. To ensure robust recovery for affected consumers, the bill would also require the FTC to use 50% of its penalty to compensate consumers and would increase penalties in cases of woefully inadequate cybersecurity or if a CRA fails to timely notify the FTC of a breach.”




For our Disaster Recovery discussion.
The Most Awful Transit Center in America Could Get Unimaginably Worse
… One day this autumn, an Acela pulls into Newark, N.J., and a railway spokesman escorts me onto the rear engine car, where we stand and take in the view facing backward. As we descend into one of the Hudson tunnels—there are two, both 107 years old, finished in the same year the Wright brothers built their first airplane factory—a supervisor flips on the rear headlights, illuminating the ghastly tubes.




What I have been saying for years.
Community-Owned Fiber Networks: Value Leaders in America
“By one recent estimate about 8.9 percent of Americans, or about 29 million people, lack access to wired home “broadband” service, which the U.S. Federal Communications Commission defines as an internet access connection providing speeds of at least 25 Mbps download and 3 Mbps upload. Even where home broadband is available, high prices inhibit adoption; in one national survey, 33 percent of non-subscribers cited cost of service as the primary barrier. Municipally and other community-owned networks have been proposed as a driver of competition and resulting better service and prices. We examined prices advertised by a subset of community-owned networks that use fiber-to-the-home (FTTH) technology. In late 2015 and 2016 we collected advertised prices for residential data plans offered by 40 community-owned (typically municipally-owned) FTTH networks. We then identified the least-expensive service that meets the federal definition of broadband (regardless of the exact speeds provided) and compared advertised prices to those of private competitors in the same markets. We were able to make comparisons in 27 communities and found that in 23 cases, the community-owned FTTH providers’ pricing was lower when the service costs and fees were averaged over four years. (Using a three year-average changed this fraction to 22 out of 27.) In the other 13 communities, comparisons were not possible, either because the private providers’ website terms of service deterred or prohibited data collection or because no competitor offered service that qualified as broadband. We also found that almost all community-owned FTTH networks offered prices that were clear and unchanging, whereas private ISPs typically charged initial low promotional or “teaser” rates that later sharply rose, usually after 12 months. We made the incidental finding that Comcast advertised different prices and terms for the same service in different regions. We do not have enough information to draw conclusions about the impacts of these practices. In general, our ability to study broadband pricing was constrained by the lack of standardization in internet service offerings and a shortage of available data. The FCC doesn’t collect data from ISPs on advertised prices, prices actually charged, service availability by address, consumer adoption by address, or the length of time consumers retain service.”




Perspective.
Health Care Just Became the U.S.’s Largest Employer
The Atlantic – “This moment was inevitable. It just wasn’t supposed to happen so soon. Due to the inexorable aging of the country—and equally unstoppable growth in medical spending—it was long obvious that health-care jobs would slowly take up more and more of the economy. But in the last quarter, for the first time in history, health care has surpassed manufacturing and retail, the most significant job engines of the 20th century, to become the largest source of jobs in the U.S. In 2000, there were 7 million more workers in manufacturing than in health care. At the beginning of the Great Recession, there were 2.4 million more workers in retail than health care. In 2017, health care surpassed both. There are several drivers of the health-care jobs boom. The first is something so obvious that it might actually be underrated, since it is rarely a proper news story in its own right: Americans, as a group, are getting older…”




Definitely an article to hand out in my next Statistics course!
Visualizing the Uncertainty in Data


Wednesday, January 10, 2018

My Computer Security students will debate this, because it clearly isn’t going away. On the other hand, I will be demonstrating how easily they can create Pubic/Private key encryption.
Zack Whittaker reports:
The FBI said the number of encrypted devices that the FBI has been unable to access last year has risen.
FBI director Christopher Wray said in a conference Tuesday at Fordham University in New York that the agency couldn’t access 7,775 devices in 2017 because the contents were scrambled.
That’s up from over 6,900 in October.
Read more on ZDNet.




Trust is what they sell.
How Antivirus Software Can be the Perfect Spying Tool
Your antivirus product could be spying on you without you having a clue. It might be intentional but legitimate behavior, yet (malicious) intent is the one step separating antivirus software from a cyber-espionage tool. A perfect one, experts argue.
Because we trust the antivirus to keep us safe from malware, we let it look at all of our files, no questions asked. Regardless of whether personal files or work documents, the antivirus has access to them all, which allows it to work as needed.
To prove this and using the "Antivirus Hacker's Handbook" (Joxean Koret) as base for an experiment, he tampered with the virus signatures for Kaspersky Lab’s Internet Security for macOS and modified one of the signatures to automatically detect classified documents and mark them for collection. By modifying signatures instead of the antivirus engine, he didn’t alter the security application’s main purpose.




This is not funny in a world where technology should have stop this.
A Foreign Navy Screwed Up Its New $3 Billion Nuclear Missile Sub By Leaving Its Hatch Open
The modern submarine is not a simple machine. A loss of propulsion, unexpected flooding, or trouble with reactors or weapons can doom a sub crew to a watery grave.
Also, it’s a good idea to, like, close the hatches before you dive.
Call it a lesson learned for the Indian navy, which managed to put the country’s first nuclear-missile submarine, the $2.9 billion INS Arihant, out of commission in the most boneheaded way possible.
The Hindu reported yesterday that the Arihant has been out of commission since suffering “major damage” some 10 months ago, due to what a navy source characterized as a “human error” — to wit: allowing water to flood to sub’s propulsion compartment after failing to secure one of the vessel’s external hatches.




As citizens get better as circumventing government “shutdowns,” governments get better at closing the loopholes. A case study for my Ethical Hacking students.
Iran tried to block the internet to disrupt protests. It wound up disrupting daily life
… Like other Iranians dependent on the web, Nouri was at first set back when the Supreme National Security Council restricted access to social media applications and servers commonly used to bypass Iran's cloistered internet.
"We weren't able to communicate to our users and we lost payments," Nouri said.
It took the 32-year-old three days to find a different server to host his mobile app design company, which employs 15 people, allowing him to again evade government censors and get his business back up and running.
As authorities have tried to govern the internet, Iranians have over the years become adept at circumventing online censorship. But as more Iranians use the internet — and the internet plays a bigger role in an increasingly web-connected society — crackdowns have broader effects. For many, internet restrictions in recent weeks disrupted daily life more than the protests did.
… As the latest protests spread, authorities banned use of Telegram and Instagram, which had been used to mobilize demonstrations. At one point, authorities completely cut off internet access for 30 minutes, according to security experts.




Well, I find it interesting.
Introduction: Artificial Intelligence, Technology, and the Law
Stern, Simon, Introduction: Artificial Intelligence, Technology, and the Law (December 24, 2017). 68 University of Toronto Law Journal (2018). Available at SSRN: https://ssrn.com/abstract=3092887
“This article introduces the essays on “Artificial Intelligence, Technology, and the Law” in the issue of the University of Toronto Law Journal based on a conference held in February 2017. The article discusses the themes of each paper, examining the challenges they raise and reflecting on their further implications.”


(Related). All of these should be obvious!
6 Ways Artificial Intelligence Can Help Lawyers (Infographic)
Rocket Matter: “There’s no doubt about it: Artificial intelligence (AI) is on the rise and is very much a part of our reality. Though lawyers may be weary of AI taking their jobs, there is much to be said for artificial intelligence as a major asset to law firms. Still not convinced? This infographic breaks down six ways that artificial intelligence can help lawyers…”




Probably not the end of this story.
Colleagues rally around handcuffed teacher as Louisiana superintendent defends raise
A Louisiana school board is under fire after a teacher was forcibly removed from a board meeting after questioning the superintendent's pay. Deyshia Hargrave was handcuffed and arrested by a city marshal Monday night in Abbeville. The middle school English teacher was booked on one count of resisting an officer and one count of remaining on premises after being forbidden. She later posted bond.
Superintendent Jerome Puyau is not commenting on Hargrave's arrest, but is defending his raise, reports CBS News' Vladimir Duthiers.
"It was time that we brought to the board a salary that's commensurate with what superintendents are making," Puyau said.
Since 2012, Puyau has been making about $110,000 per year, according to two board members. With the new contract that was approved Monday, he could earn $38,000 more. In 2016, the average Louisiana teacher's salary was around $49,000.
The Vermilion Parish School board and the city prosecutor say they are not moving forward with charges against Hargrave, but many in the district still want to know why their colleague, a former teacher of the year, was arrested in the first place.




This definitely falls in the “we can, therefore we must” category. All I can say is, “must we, really?”
Ikea Wants You to Pee on This Ad. If You’re Pregnant, It Will Give You a Discount on a Crib
Swedish agency Åkestam Holst, Adweek’s International Agency of the Year for 2017, has been killing it with the Ikea work in recent years. And it starts out 2018 with a splash (sorry) by creating a magazine ad that women are encouraged to pee on.
Sounds a bit gross, and maybe it is—but there’s a fun twist. If you’re pregnant, peeing on the ad reveals a special discounted price on cribs, thanks to technology similar to that in pregnancy-test kits.
… This is definitely the coolest pee-based advertising since Animal Planet put urine-scented ads at the bottom of lampposts to attract dogs (whose owners then saw a larger ad at their own eye level promoting a dog award show).