Monday, February 26, 2018

Reinforcing several trends reported here earlier, including physician invulnerability.
MUSC terminates employees who 'snoop' in patients' medical records
Thirteen employees were fired in 2017 from the Medical University of South Carolina after administrators determined they had broken federal law by using patient records without permission, spying on patient files or disclosing private information.
Some of these privacy breaches involved high-profile patients. [You couldn’t sell my records to the National Enquirer. Bob]
MUSC staff explained to the hospital's Board of Trustees during a recent meeting that designated employees monitor the news media for any potential privacy breaches. Sometimes, they said, health care providers will "snoop" in patient records after a case makes the news. Eleven of 58 privacy breaches at MUSC in 2017 were categorized as snooping.
… But patients shouldn't worry excessively about the security of their own information. Experts agree that digital medical records are more secure than paper ones. [I’m an expert, and I strongly disagree. Bob]
Elizabeth Willis, the corporate privacy officer at Roper St. Francis, said the ability to track each employee who opens a record makes patient files less vulnerable to a security breach. [It makes detection of breaches easier, but does nothing to stop a breach – see paragraph one. Bob]
… She provided further information about security breaches and terminations at MUSC dating back to 2013. Since then, MUSC has identified 307 breaches and 30 employees have been fired. Nearly half of all those firings occurred last year. None were physicians, Woolwine said.




I called this a while back… Russia is demonstrating what could happen if they are banned from future games.
Russia Hacked Olympics Computers, Turned Blame on North Korea: Report
Russian military spies hacked hundreds of computers used by Winter Olympics organizers and tried to make it look like the work of North Korea, the Washington Post reported Sunday, quoting US intelligence sources.
South Korea had previously announced that it was investigating the failure of several Olympic-linked internet sites and broadcast systems just as the opening ceremonies were taking place on February 9.
… The Russians used a North Korean internet provider to make it appear the attack originated in North Korea, in what is known as a "false flag" operation, the Post said.
… they said the cyber attack against the Games -- from which Russia's team was excluded for doping -- was worrisome.
Some analysts believe the cyber attack was retribution for that ban. Some Russian athletes were allowed to compete, but only under the designation of "Olympic Athletes from Russia."




Can we prepare for the hack of the 2020 election?
A primer on political bots: Part one
Data Drive Journalism – “The rise of political bots brings into sharp focus the role of automated social media accounts in today’s democratic civil society. Events during the Brexit referendum and the 2016 U.S. Presidential election revealed the scale of this issue for the first time to the majority of citizens and policy-makers. At the same time, the deployment of Russian-linked bots designed to promote pro-gun laws in the aftermath of the Florida school shooting demonstrates the state-sponsored, real-time readiness to shape, through information warfare, the dominant narratives on platforms such as Twitter. The regular news reports on these issues lead us to conclude that the foundations of democracy have become threatened by the presence of aggressive and socially disruptive bots, which aim to manipulate online political discourse. While there is clarity on the various functions that bot accounts can be scripted to perform, as described below, the task of accurately defining this phenomenon and identifying bot accounts remains a challenge. At Texifter, we have endeavoured to bring nuance to this issue through a research project which explores the presence of automated accounts on Twitter. Initially, this project concerned itself with an attempt to identify bots which participated in online conversations around the prevailing cryptocurrency phenomenon. This article is the first in a series of three blog posts produced by the researchers at Texifter that outlines the contemporary phenomenon of Twitter bots. Bot accounts are a persistent feature of the user experience on Twitter. They can increase the influence of positive, negative, or “authentic” fake news stories; promote opinion posts from a variety of accounts (botnets); and circulate memes. Their ability to shape online political discourse and public opinion, however, is generating legitimate concerns. The significance of the bot effect stretches from the academic research community, to tech and platform companies, national regulatory bodies, and the field of journalism. One of the most recognized examples of this involves the lead-up to the 2016 U.S. Presidential Election. During that period, over 50,000 automated Twitter accounts from Russia retweeted and disseminated political material posted by and for Trump, reaching over 677,775 Americans. Over 2,000,000 tweets and retweets were the result of these Twitter bots, accounting for approximately 4.25% of all retweets of Trump’s tweets in the lead-up to the U.S. election. These findings accentuate the larger issue of state actors using social media automation as a tool of political influence…”




First numbers I’ve seen on the “new” cards.
Chip Cards Lead to 70% Drop in Counterfeit Fraud: Visa
The financial industry has been pushing for the adoption of EMV (Europay, MasterCard, Visa) card technology in the United States since 2011, and efforts were increased following the disclosure of the massive data breach suffered by Target in 2013.
However, according to Visa, by September 2015, only roughly 392,000 merchant locations had been accepting chip cards, and the number of Visa debit and credit cards using this technology was only at 159 million.
Data collected by Visa shows the number of storefronts that had migrated to EMV technology by December 2017 increased by more than 570%, with 2.7 million storefronts in the U.S., representing 59% of the total, accepting chip cards. The number of Visa cards using chip technology increased by 202% to 481 million, with 67% of Visa payment cards having chips.
Visa also reported that EMV cards accounted for 96% of the overall payment volume in the United States in December 2017, with chip payment volume reaching $78 billion.
As a result of U.S. merchants upgrading their payment systems for EMV cards, cases of counterfeit fraud had dropped by 70% in September 2017 compared to December 2015.
While the adoption of chip and PIN technology addresses the problem of counterfeit card fraud, it has not deterred fraudsters, who have simply shifted their focus to card-not-present (CNP) and other types of fraud.




Which part of “we surveil your children” did they not understand?
James Tozer reports:
Happily chatting and walking between lessons, these children are being watched by school spy cameras designed for their protection.
Now it has emerged that the images can be viewed by anyone after the CCTV systems were hacked and put online.
A disturbing website, which boasts ‘Watch live surveillance cameras in the UK’, allows people anywhere in the world to spy on children, teachers and parents in real time.
[…]
The website broadcasting the footage claims no cameras are hacked and all the internet-connected cameras on the site do not have proper password protection.
Read more on Daily Mail. So have UK parents just discovered the Internet of Unsecured Things the hard way? Were these systems really hacked or did they just use default configurations available to everyone or….? And will this result in cams in toilets being removed? Will any lessons be learned or is this just another 15 minute news cycle?




Is this any way to run a government agency?
Kathleen Dion of Robinson & Cole writes:
On January 30, 2018, EDUCAUSE, a higher education technology association, submitted a letter to the U.S. Department of Education describing concerns that it had with the Federal Student Aid (“FSA”) ability to protect federal student financial aid data.
First, EDUCAUSE expressed concerns about letters that various colleges and universities received from the FSA. These letters indicated that a data breach or suspected data breach occurred at educational institutions, and required the institutions to make a full accounting of their information security program. Some of the letters also indicated that the institutions failed to self-report alleged or suspected breaches. It appeared that the FSA identified these institution from news reports, but EDUCAUSE expressed concern that FSA did not confirm that the breaches or suspected breaches occurred prior to sending the letter.
[From the article:
Second, EDUCAUSE expressed concerns that FSA did not have proper reporting procedures in place. In late 2017, the FSA stated that notifications could be made via text message to an FSA official’s cellphone number. It also indicated that blocked phishing attempts constituted a suspected data breach that must be “immediately reported,” (i.e. on the date of detection).




An article worth reading.
On February 13, 2018, the New York Times reported that Uber is planning an IPO. Uber’s value is estimated between $48 and $70 billion, despite reporting losses over the last two years. Twitter reported a loss of $79 million before its IPO, yet it commanded a valuation of $24 billion on its IPO date in 2013. For the next four years, it continued to report losses. Similarly, Microsoft paid $26 billion for loss-making LinkedIn in 2016, and Facebook paid $19 billion for WhatsApp in 2014 when it had no revenues or profits. In contrast, industrial giant GE’s stock price has declined by 44% over the last year, as news emerged about its first losses in last 50 years.
Why do investors react negatively to financial statement losses for an industrial firm but disregard such losses for a digital firm?




Looks like everyone is underpaid!
Search and explore faculty, staff, and adjunct salary data at thousands of colleges
Chronicle of Higher Education – Chronicle Data – Institutions are grouped under the most recent Carnegie Classification. User may search full time salaries, staff salaries, and adjunct salaries, by college, state, sector or Carnegie Classification, as well as display by college.




I can not convince my students to take notes!
Laws on Recording Conversations in All 50 States
  • See also related reference from last June via Quartz – As Comey shows, documenting conversations with your boss can be smart – “Careful documentation of meetings via notes and memos is part of the FBI’s culture (via NYT), but there are sound reasons for ordinary workers to at least consider doing the same when we talk to our bosses. Taking notes—or better, recording conversations in states where its legal—is sound practice for employees who feel their managers are doing something inappropriate…


Sunday, February 25, 2018

It’s hard to get your head around the scope of security breaches. Michelle Post sent me this article to help me explain it to my students.
The cost of a data breach in 2018
58 data records are stolen every second at an average cost of $141 each.
… The 2017 Cost of Data Breach Study from the Ponemon Institute, sponsored by IBM, puts the global average cost at $3.6 million, or $141 per data record. That’s a reduction on the average cost in 2016, but the average size of data breaches has increased. It’s also worth noting that the average cost of a data breach in the United States is much higher at $7.3 million.




Don’t expect complete or even substantial improvement in election security.
Homeland Security's tall order: A hacker-free election
… The agency declared the US election system, which is run by a fragmented group of officials in all 50 states as well as dozens of smaller local governments, to be a part of the nation's "critical infrastructure" in January 2017. The agency doesn't have any legal authority over election officials, but it offers programs to help them keep hackers out of voting machines, voter registration databases and public-facing election websites.
… Manfra told us that, so far, 32 states and 31 local governments have taken part in at least the most basic cybersecurity help offered by Homeland Security, and the agency will have finished 14 deeper assessments by the end of April.




No details in the article.
Martha Stoddard reports that the Nebraska legislature passed LB 757 on a 46-0 vote.
The measure requires any individual or commercial entity holding personal information to implement and maintain security procedures. The same requirement would apply if the information is given to a third party.
If a breach does occur, LB 757 would prohibit credit reporting entities from charging affected consumers to place, temporarily lift or remove security freezes.
Read more on Omaha.com.




Will ‘outrageous’ replace ‘visionary?’ The advantage of a business-like approach to ad purchasing? Or, is the Facebook algorithm changing how politicians communicate?
How Trump Conquered Facebook—Without Russian Ads
.. Like many things at Facebook, the ads auction is a version of something Google built first. As on Google, Facebook has a piece of ad real estate that it’s auctioning off, and potential advertisers submit a piece of ad creative, a targeting spec for their ideal user, and a bid for what they’re willing to pay to obtain a desired response (such as a click, a like, or a comment). Rather than simply reward that ad position to the highest bidder, though, Facebook uses a complex model that considers both the dollar value of each bid as well as how good a piece of clickbait (or view-bait, or comment-bait) the corresponding ad is. If Facebook’s model thinks your ad is 10 times more likely to engage a user than another company’s ad, then your effective bid at auction is considered 10 times higher than a company willing to pay the same dollar amount.




How can you regulate what you can’t accurately measure?
The FCC’s New Broadband Map Paints an Irresponsibly Inaccurate Picture of American Broadband
… Back in 2011 the Obama FCC announced the creation of a $300 million broadband map using the Form 477 data ISPs provide the agency. At the time the map was heralded as a novel way to highlight the coverage gaps and competitive shortcomings of what is pretty clearly a broken US telecom market.
But users quickly discovered that despite the project’s steep price tag and good intentions, the map itself was almost useless. Before the map was mothballed due to a lack of funding, it spent a few years hallucinating competitors out of whole cloth, over-stating both speed and availability, while failing utterly to mention service pricing whatsoever.
… Fast forward to this week when the Ajit Pai run FCC announced they were relaunching a “new” version of the map as part of Pai’s (already arguably hollow) dedication to closing the digital divide. You can check out the updated map here.
… While the “new” map has received a modest graphical overhaul, all of the problems inherited from its initial iteration remain. Users were quick to highlight on Twitter that the map still dramatically overstates available ISPs (often to a comical degree), inaccurately lists the speeds they can provide, and fails to mention service pricing whatsoever.




Perspective. How companies will use (and abandon) tech.
Customer Experience Revolution Ahead: Gartner
Enterprises have begun overhauling the way they handle customer experiences, suggested Gene Alvarez, managing vice president at Gartner, at the firm's customer experience event in Tokyo earlier this week.
Twenty percent of brands will abandon their mobile apps by 2019, he predicted, choosing consumer messaging apps such as Facebook Messenger and WeChat instead.
By 2020, Alvarez said, we can expect to see the following changes:
  • 25 percent of customer service and support operations will have integrated virtual customer assistant or chatbot technology across engagement channels;
  • 20 percent of large enterprises will have evaluated and adopted augmented, virtual and mixed reality immersive solutions; and
  • 30 percent of all B2B companies will have employed artificial intelligence to augment at least one of their primary sales processes.




I’d like to think we prepare our students to cover their tracks.
Manafort Left an Incriminating Paper Trail Because He Couldn’t Figure Out How to Convert PDFs to Word Files
There are two types of people in this world: those who know how to convert PDFs into Word documents and those who are indicted for money laundering. Former Trump campaign chairman Paul Manafort is the second kind of person.


Saturday, February 24, 2018

I normally skip stories about laptop theft, there are just too many of them.
KHOU reports:
Information about City of Houston employees’ health insurance may have been compromised after an employee’s laptop computer was stolen.
City officials say the laptop was stolen from the employee’s car on Feb. 2. They say the password-protected computer may have contained city employees’ records, including names, addresses, dates of birth, Social Security numbers and other medical information.
Read more on KHOU.
[From the article:
City officials say human resource professionals are trained not to remove laptops from City offices unless sensitive data is encrypted. They say one employee “failed to follow his training.”




Not the most reassuring headline in the age of Russian election hacking.
The Myth of the Hacker-Proof Voting Machine




Defining the field of play?
Patience Wait reports:
In December, the U.S. Federal Trade Commission hosted a workshop on student privacy and edtech in Washington, D.C. During one panel, Priscilla Regan, a professor at George Mason University — who has been writing about privacy policy since the late 1970s — set the framework for discussion by identifying six broad concerns that together comprise the facets of the student privacy discussion…… The big six, according to Regan:
  • Organizational information privacy concerns
  • Anonymity
  • Surveillance and tracking
  • Autonomy
  • Bias, discrimination and due process
  • Data ownership
Read more about these concerns on EdScoop.




I think of this as automating the paper list police officers used to carry in their cars. Back then, one officer drove and the other scanned for suspicious activity and checked license plates, right?
The Kentucky Supreme Court declared last week that police need not bother applying for a warrant before tracking motorists with automated license plate readers (ALPR, also known as ANPR in Europe). The justices took up the issue in the case of Gregory Traft, who was stopped in Boone County on September 11, 2012, because his license plate triggered an alert from the patrol car’s automated camera system.
Traft had a warrant out for his arrest for failing to appear in court on the charge that he wrote a bad check. Deputy Sheriff Adam Schepis ordered Traft to pull over. In the course of the stop, Traft appeared to be quite drunk and was placed under arrest.
The high court’s only interest in the case was whether the deputy’s use of the license plate camera was lawful.
Read more on TheNewspaper.com




I am trying to convince my students that this will happen much faster than they think.
California could see self-driving cars with ‘remote drivers’ in April
Self-driving cars that back up their computerized system with a remote human operator instead of a fallback driver at the wheel could be tested on California roads as early as April, the state department of motor vehicles said.




Will this happen to the US as well?
How New Technologies Will Radically Reshape India’s Workforce
… skill development and employability remain a key challenge. At present, only 18% of the country’s workforce is formally skilled.
… even in the IT services sector, 55% to 65% of existing jobs are likely to go away because of AI.




An article I will share with my students next time I teach Excel.


Friday, February 23, 2018

A local incident.
SamSam ransomware infects Colorado Department of Transportation
SamSam ransomware is back and the Colorado Department of Transportation is its most recent victim. More than 2,000 agency computers had to be shut down on Feb 21 to prevent the ransomware from spreading across the entire infrastructure.
According to CBS local news, the critical systems used to manage road traffic and alerts were not affected. The attackers encrypted some files and requested bitcoin in exchange for the decryption key.




A video comment worth watching.
Weekly Update 75
03:52 - Australia's Notifiable Data Breach Scheme




Good question?
Ars Farivar reports:
Last November, a 74-year-old rancher and attorney was walking around his ranch just south of Encinal, Texas, when he happened upon a small portable camera strapped approximately eight feet high onto a mesquite tree near his son’s home. The camera was encased in green plastic and had a transmitting antenna.
Not knowing what it was or how it got there, Ricardo Palacios removed it.
Soon after, Palacios received phone calls from Customs and Border Protection officials and the Texas Rangers. Each agency claimed the camera as its own and demanded that it be returned. Palacios refused, and they threatened him with arrest.
Read more on Ars Technica.
Can the government just come onto your private property without your knowledge or consent and install surveillance equipment to surveill others? And if they can, is the notion of “private property” all but dead?




...and another good question.
Why Can Everyone Spot Fake News But The Tech Companies?
… Among those who pay close attention to big technology platforms and misinformation, the frustration over the platforms’ repeated failures to do something that any remotely savvy news consumer can do with minimal effort is palpable: Despite countless articles, emails with links to violating content, and viral tweets, nothing changes. The tactics of YouTube shock jocks and Facebook conspiracy theorists hardly differ from those of their analog predecessors; crisis actor posts and videos have, for example, been a staple of peddled misinformation for years.
This isn't some new phenomenon. Still, the platforms are proving themselves incompetent when it comes to addressing them — over and over and over again. In many cases, they appear to be surprised by that such content sits on their websites. And even their public relations responses seem to suggest they've been caught off guard with no plan in place for messaging when they slip up.




A little encouragement for my student entrepreneurs.
Snap chief earns $638 million in 2017, third-highest CEO payout ever
Snap Inc (SNAP.N) Chief Executive Evan Spiegel received $637.8 million as total compensation last year after the company went public, the third-highest annual payout ever received by a company’s CEO.




I wasn’t sure how “Inclusion” and AI were related. Looks like I learned something new.
New Website Draws on International Perspectives to Highlight Issues related to Inclusion and Artificial Intelligence
“The Berkman Klein Center for Internet & Society is pleased to share a newly-published interactive webpage, www.aiandinclusion.org, which highlights salient topics and offers a broad range of resources related to issues of AI and inclusion. The materials contribute to the Diversity and Inclusion track of the broader Ethics and Governance of Artificial Intelligence Initiative. Launched in Spring 2017, the initiative is anchored by the Berkman Klein Center and the MIT Media Lab, who have been working in conjunction over the past year to conduct evidence-based research, bolster AI for the social good, and construct a collective knowledge base on the ethics and governance of AI. The site reflects lessons learned from a wide-ranging international effort, and includes a number of resources produced from the Global Symposium on AI and Inclusion, which convened 170 participants from over 40 countries in Rio de Janeiro last November on behalf of the Global Network of Centers to discuss the impact of AI and related technologies on marginalized populations and the risks of amplifying digital inequalities across the world. Some of the primary resources available on the webpage include foundational materials that address overarching themes, key research questions, the initial framing of a research roadmap, and an overview of some of the most relevant opportunities and challenges identified pertaining to AI, inclusion, and governance. The research, findings, and ideas presented throughout the page both illuminate lessons learned from the past year, and lay the groundwork for the initiative’s continued work on issues of inclusion, acknowledging that the resources found here are only a starting point for this important conversation…”




A free and simple tool.




It can’t hurt to have some tools for this.
Common Craft Explains Flipped Classrooms
The flipped classroom concept, in the right setting, can be an effective way to maximize classroom time. Perhaps you've tried it yourself and have been looking for a way to explain it to parents or colleagues. Common Craft recently released a good video that could help you do just that.
Flipped Classroom Explained by Common Craft teaches the fundamental ideas behind the flipped classroom model. Thankfully, the video also addresses why the flipped classroom model is not appropriate for all students.
TESTeach (formerly known as Blendspace) makes it easy for teachers to organize and share educational materials in a visually pleasing format.
EDPuzzle is a popular tool for adding your voice and text questions to educational videos.
MoocNote is a free tool for adding timestamped comments, questions, and links to videos.


Thursday, February 22, 2018

This should bother my Computer Security students. Since when is a 10% failure rate considered good?
Meghan Bogardus Cortez reports:
University end users are pretty good at identifying a scam.
Only 10 percent of simulated phishing emails sent to users at education institutions were successful, a new study from Wombat Security Technologies reports. The company monitored tens of millions of simulated phishing attacks sent over the course of a year through its Security Education Platform across more than 15 industries.
The State of the Phish 2018 report found that users in education were less likely to click on a phishing attempt than those in technology, entertainment, hospitality, government, consumer goods, retail and telecommunications.
Read more on EdTech Magazine.




We’ve been considering how to prevent Russia from hacking these devices instead of merely chatting on social media.
The Risks of Digital Democracy
Like many segments of the economy and society, democracy is in the process of being digitized, a development that promises new levels of efficiency but also brings new risks. Consider the digitization of voting machines, devices that date back to the 19th century. The growing use of direct recording electronic (DRE) voting machines has made possible fully digitized voting and the availability of near real-time results.
But, the events of this summer’s 25th annual DEF CON computer security conference illustrate the risks that come with these benefits. As part of the conference, software engineers were invited to a Voting Machine Hacking Village to try to break in to commercially available DRE voting machines. The hackers cracked the “secured” systems in less than two hours.




Something the CSO can use to start a discussion with Senior Management? This has come up in several recent breaches.
SEC Tells Execs Not to Trade While Investigating Security Incidents
The U.S. Securities and Exchange Commission (SEC) on Wednesday announced updated guidance on how public companies should handle the investigation and disclosure of data breaches and other cybersecurity incidents.
The SEC has advised companies to inform investors in a timely fashion of all cybersecurity incidents and risks – even if the firm has not actually been targeted in a malicious attack. The agency also believes companies should develop controls and procedures for assessing the impact of incidents and risks.
While directors, officers and the people in charge of developing these controls and procedures should be made aware of security risks and incidents, the SEC believes these individuals should refrain from trading securities while in possession of non-public information regarding a significant cybersecurity incident.




Similar to the conclusions my students have reached.
Global Cybercrime Costs $600 Billion Annually: Study
A report by the security firm McAfee with the Center for Strategic and International Studies found theft of intellectual property represents about one-fourth of the cost of cybercrime in 2017, and that other attacks such as those involving ransomware are growing at a fast pace.
Russia, North Korea and Iran are the main sources of hackers targeting financial institutions, while China is the most active in cyber espionage, the report found.
Criminals are using cutting-edge technologies including artificial intelligence and encryption for attacks in cyberspace, with anonymity preserved by using bitcoin or other cryptocurrency, the researchers said.
… The report said there is often a connection between governments and the cybercrime community.




A simple password testing tool.
I've Just Launched "Pwned Passwords" V2 With Half a Billion Passwords for Download
Last August, I launched a little feature within Have I Been Pwned (HIBP) I called Pwned Passwords. This was a list of 320 million passwords from a range of different data breaches which organisations could use to better protect their own systems. How? NIST explains:
When processing requests to establish and change memorized secrets, verifiers SHALL compare the prospective secrets against a list that contains values known to be commonly-used, expected, or compromised.
They then go on to recommend that passwords "obtained from previous breach corpuses" should be disallowed and that the service should "advise the subscriber that they need to select a different secret".
[The comparison tool: https://haveibeenpwned.com/Passwords




For my researching students.
Paper – Text mining 101
EU OpenMinted Project Paper – What is text mining, how does it work and why is it useful? “This article will help you understand the basics in just a few minutes. Text mining seeks to extract useful and important information from heterogeneous document formats, such as web pages, emails, social media posts, journal articles, etc. This is often done through identifying patterns within texts, such as trends in words usage, syntactic structure, etc. People often talk about ‘text and data mining (TDM)’ at the same time, but strictly speaking text mining is a specific form of data mining that deals with text…”




Is the sky really falling?
Top Experts Warn Against 'Malicious Use' of AI
Artificial intelligence could be deployed by dictators, criminals and terrorists to manipulate elections and use drones in terrorist attacks, more than two dozen experts said Wednesday as they sounded the alarm over misuse of the technology.
In a 100-page analysis, they outlined a rapid growth in cybercrime and the use of "bots" to interfere with news gathering and penetrate social media among a host of plausible scenarios in the next five to 10 years.
"Our report focuses on ways in which people could do deliberate harm with AI," said Seán Ó hÉigeartaigh, Executive Director of the Cambridge Centre for the Study of Existential Risk.
… Contributors to the new report – entitled "The Malicious Use of AI: Forecasting, Prevention, and Mitigation" -- also include experts from the Electronic Frontier Foundation, the Center for a New American Security, and OpenAI, a leading non-profit research company.




I’d say yes, but the cost might be prohibitive.
Can “Fake News” be stopped?
On Wednesday, YouTube was forced to apologize for a video that sat at the top of its “Trending” tab, which shows users the most popular videos on the site. By the time it was removed from the site, it had more than 200,000 views. The problem? The video promoted the conspiracy theory peddled by alt-right propagandists that Parkland, Florida high school student and shooting survivor David Hogg is an actor, “bought and paid by CNN and George Soros.” The conspiracy theory also found its way into a trending position on Facebook, where clicking Hogg’s name “brought up several videos and articles promoting the conspiracy that he’s a paid actor,” according to Business Insider.
The incident highlights the speed at which the spread of false information occurs on algorithmically optimized social media sites that are easy to game. What to do about it is the subject of a new report from the New York think tank Data & Society, “Dead Reckoning: Navigating Content Moderation After ‘Fake News’,” which coincidentally debuted yesterday, just as the Hogg conspiracy theory spread across the internet. Based on a “year of field-based research using stakeholder mapping, discourse and policy analysis, as well as ethnographic and qualitative research of industry groups working to solve ‘fake news’ issues,” the report sets out to define the problem set before offering four strategies for addressing it.




A wake-up slap to California?
Judge says state can't force IMDB to take down actors' ages
A federal judge has blocked a California law that would have forced IMDB to take down actors' ages on request.
The law was signed by Governor Jerry Brown, a Democrat, in September 2016. It was supported by the Screen Actors Guild, which said the law it would help prevent age discrimination in film and television hiring.
IMDB quickly challenged the law in court, saying that it "attempts to combat age discrimination in casting through content-based censorship."
… In his order, Chhabria called the law "clearly unconstitutional." He said it "singles out specific, non-commercial content — age-related information — for differential treatment."
The judge also said that even if the defendants, the state of California and the Screen Actors Guild, demonstrated a casual link between the availability of ages on IMDB and age discrimination, it would not be enough to justify a "content based restriction on IMDB's speech."
Chhabria added that "regulation of speech must be a last resort."




Perspective. Perhaps all politicians are delusional.
Bernie blames Hillary for allowing Russian interference
Bernie Sanders on Wednesday blamed Hillary Clinton for not doing more to stop the Russian attack on the last presidential election. Then his 2016 campaign manager, in an interview with POLITICO, said he’s seen no evidence to support special counsel Robert Mueller's assertion in an indictment last week that the Russian operation had backed Sanders' campaign.
The remarks showed Sanders, running for a third term and currently considered a front-runner for the Democratic presidential nomination in 2020, deeply defensive in response to questions posed to him about what was laid out in the indictment. He attempted to thread a response that blasts Donald Trump for refusing to acknowledge that Russians helped his campaign — but then holds himself harmless for a nearly identical denial.




Again I suggest that Amazon buy the USPS.
Postal-Service Workers Are Shouldering the Burden for Amazon




Some classes for my students.




It is always thus for new technologies!


Wednesday, February 21, 2018

Any publicity seems to attract the hacker piranhas.
Note: as Catalin Cimpanu points out on Twitter, “Neither RedLock nor Tesla confirmed that “confidential data” was stolen. Tesla said the opposite in their statement. The reporter is going out on a limb on this one.”
Duncan Riley reports:
Elon Musk may be able to send a Tesla Inc. vehicle into space, but apparently his staff can’t secure data online so easily. A shocking report released this morning details the theft of data from the electric car company, blaming it on gross staff incompetency.
According to researchers at cloud security firm RedLock Ltd., hackers infiltrated Tesla’s Kubernotes console after the company failed to secure it with a password. Within one of the Kubernetes pods, a group of software containers deployed on the same host, sat the access credentials to Telsa’s Amazon Web Service Inc. account.
Read more on SiliconAngle.
[From the article:
Because it’s the fashion in 2018, the hackers then installed cryptomining software, including sophisticated evasion measures to hide the installation.




A “How To” article that allows us to consider “How To Avoid!”
Phishing schemes net hackers millions of dollars from Fortune 500
On Wednesday, researchers from IBM's X-Force Incident Response and Intelligence Services (IRIS) team said the Business Email Compromise (BEC) scheme is currently active and is successfully targeting Accounts Payable (AP) teams at Fortune 500 companies.
In a blog post, the researchers said that after discovering evidence of the threat in Fall 2017, their analysis of the campaign led them to Nigeria, where the threat actors appear to be operating.
The BEC uses social engineering attacks and phishing emails in order to obtain legitimate credentials for enterprise networks and email accounts.
In many cases, publicly available information is used to craft messages which appeared legitimate and entice phishing victims to visit malicious domains.
… This BEC is of special note as no malware was used and as legitimate employees were conducting transactions, traditional security products and protocols would not be able to detect any compromise.




From the White House! So you know it can’t be “fake news.”
CEA Report: The Cost of Malicious Cyber Activity to US Economy
[February 16, 2018] “the Council of Economic Advisers (CEA) released a report detailing the economic costs of malicious cyber activity on the U.S. economy. Please see below for the executive summary and read the full report here. This report examines the substantial economic costs that malicious cyber activity imposes on the U.S. economy. Cyber threats are ever-evolving and may come from sophisticated adversaries.
  • We estimate that malicious cyber activity cost the U.S. economy between $57 billion and $109 billion in 2016.
  • Cybersecurity experts like to say that in an act of war or retaliation, the first moves will be made in cyberspace. A cyber adversary can utilize numerous attack vectors simultaneously. The backdoors that were previously established may be used to concurrently attack the compromised firms for the purpose of simultaneous business destruction.




For our discussion of Law & Regulation.
The Laws and Ethics of Employee Monitoring
… Federal and most state privacy laws give discretion to employers as to how far they can go with their employee monitoring. In some cases, employers do not have to inform employees of the monitoring, but this depends on state and local laws. Some locations require employee consent to monitor.
"As a general rule, employees have little expectation of privacy while on company grounds or using company equipment, including company computers or vehicles," said Matt C. Pinsker, adjunct professor of homeland security and criminal justice at Virginia Commonwealth University.
Monitoring must be within reason. For example, video surveillance can be conducted in common areas and entrances; however, it should be obvious that surveillance in bathrooms or locker rooms is prohibited and can open a company up to legal repercussions.


Tuesday, February 20, 2018

The Bank of Bangladesh hack showed how this could be done. I wonder if this is the same team of hackers or have they inspired copycats? Did these bank fail to make the security changes SWIFT recommended?
Malicious hackers attempted to steal millions of dollars from banks in Russia and India by abusing the SWIFT global banking network.
A report published last week by Russia’s central bank on the types of attacks that hit financial institutions in 2017 revealed that an unnamed bank was the victim of a successful SWIFT-based attack.
A copy of the report currently posted on the central bank’s website does not specify how much the hackers stole, but Reuters said they had managed to obtain 339.5 million rubles (roughly $6 million).
… The news comes after Russia’s Globex bank admitted in December that hackers had attempted to steal roughly $940,000 through the SWIFT system. The attackers reportedly only managed to steal a fraction of the amount they targeted.
In India, City Union Bank issued a statement on Sunday saying that it had identified three fraudulent transfers abusing the SWIFT payments messaging system. One transfer of $500,000 through a Standard Chartered Bank account in New York to a bank in Dubai was blocked and the money was recovered.
The second transfer of €300,000 ($372,000) was made to an account at a bank based in Turkey via a Standard Chartered Bank account in Germany. The funds were blocked at the Turkish bank and City Union hopes to recover the money.
The third transfer was for $1 million and it went to a Chinese bank through a Bank of America account. City Union Bank said the funds were claimed by someone using forged documents.




How close are we to the straw that breaks the camel’s back?
North Korea poised to launch large-scale cyberattacks, says new report
North Korea is quietly expanding both the scope and sophistication of its cyberweaponry, laying the groundwork for more devastating attacks, according to a new report published Tuesday.
… Now it appears that North Korea has also been using previously-unknown holes in the Internet to carry out cyberespionage — the kinds of activities that could easily metamorphose into full-scale attacks, according to a report from FireEye, the California-based cybersecurity company.
… The Worldwide Threat Assessment published by the U.S. intelligence community last week forecast the potential for surprise attacks in the cyber realm would increase over the next year.




Surprise! Someone used your identity to launder money. Have fun explaining that to the Feds.
Money Laundering Via Author Impersonation on Amazon?
Patrick Reames had no idea why Amazon.com sent him a 1099 form saying he’d made almost $24,000 selling books via Createspace, the company’s on-demand publishing arm. That is, until he searched the site for his name and discovered someone has been using it to peddle a $555 book that’s full of nothing but gibberish.




Biometrics Can do more than identify you by scanning your face. Should we allow it to? This is similar to those driver analyzing dongles insurance companies put in cars. A look into your eyes could increase your health insurance rates?
Google’s new AI algorithm predicts heart disease by looking at your eyes
Scientists from Google and its health-tech subsidiary Verily have discovered a new way to assess a person’s risk of heart disease using machine learning. By analyzing scans of the back of a patient’s eye, the company’s software is able to accurately deduce data, including an individual’s age, blood pressure, and whether or not they smoke. This can then be used to predict their risk of suffering a major cardiac event — such as a heart attack — with roughly the same accuracy as current leading methods.
The algorithm potentially makes it quicker and easier for doctors to analyze a patient’s cardiovascular risk, as it doesn’t require a blood test. But, the method will need to be tested more thoroughly before it can be used in a clinical setting. A paper describing the work was published today in the Nature journal Biomedical Engineering, although the research was also shared before peer review last September.




A question: Is this bad or merely an evolution similar to the introduction of radio and then TV? Perhaps older forms of journalism need to evolve?
CJS – The Facebook Armageddon
Columbia Journalism Review: The social network’s increasing threat to journalism – “At some point over the past decade, Facebook stopped being a mostly harmless social network filled with baby photos and became one of the most powerful forces in media—with more than 2 billion users every month and a growing lock on the ad revenue that used to underpin most of the media industry. When it comes to threats to journalism, in other words, Facebook qualifies as one, whether it wants to admit it or not… The fact that even Facebook’s closest media partners like BuzzFeed are struggling financially highlights the most obvious threat: Since many media companies still rely on advertising revenue to support their journalism, Facebook’s increasing dominance of that industry poses an existential threat to their business models…”




An interesting question: Can you duplicate an algorithm? Since these algorithms are Trade Secrets (not patented or copyrighted) there is no problem disclosing how they work?
Facebook is a political battleground where Russian operatives work to influence elections, fake news runs rampant, and political hopefuls use ad targeting to reach swing voters. We have no idea what goes on inside Facebook’s insidious black box algorithm, which controls the all-powerful News Feed. Are politicians playing by the rules? Can we trust Facebook to police them? Do we really have any choice?
One emerging way to hold tech companies like Facebook accountable is to use similar technology to figuratively poke at that black box, gathering data and testing hypotheses about what might be going on inside, almost like early astronomers studying the solar system.
It’s a tactic being pioneered at the nonprofit news organization ProPublica by a team of reporters, programmers, and researchers led by Pulitzer Prize-winning reporter Julia Angwin. Angwin’s team specializes in investigating algorithms that impact people’s lives, from the Facebook News Feed to Amazon’s pricing models to the software determining people’s car insurance payments and even who goes to prison and for how long. To investigate these algorithms, they’ve had to develop a new approach to investigative reporting that uses technology like machine learning and chatbots.


(Related) If Russia was not bringing its “A” game last time, will we be ready for it this time?
Russia's Troll Operation Was Not That Sophisticated
It might be nice for Democrats and #NeverTrumpers to believe that Russia’s troll factory brought Donald Trump the 2016 Presidential Election.
But no.
Special Counsel Robert Mueller’s indictment of 13 Russians associated with the Internet Research Agency definitively shows, given current evidence, that while a small team in St. Petersburg ran a successful audience-development campaign mostly on behalf of Trump, that campaign was neither targeted nor sizable enough to change the election’s result.
Make no mistake: This was self-described and actual “information warfare.” The point was to sow discord and distrust in the American electorate. And with a few dozen people—around 80 at the peak—they managed to reach 150 million people through Facebook and Instagram. In September 2016, the indictment states that the monthly budget of the unit that contained the U.S. election-interference operation was $1.25 million. That’s pretty good bang for the buck.


(Related) Clearly, Russia is poised to take any advantage we offer…
After Florida School Shooting, Russian ‘Bot’ Army Pounced
One hour after news broke about the school shooting in Florida last week, Twitter accounts suspected of having links to Russia released hundreds of posts taking up the gun control debate.
The accounts addressed the news with the speed of a cable news network. Some adopted the hashtag #guncontrolnow. Others used #gunreformnow and #Parklandshooting. Earlier on Wednesday, before the mass shooting at Marjory Stoneman Douglas High School in Parkland, Fla., many of those accounts had been focused on the investigation by the special counsel Robert S. Mueller III into Russian meddling in the 2016 presidential election.
“This is pretty typical for them, to hop on breaking news like this,” said Jonathon Morgan, chief executive of New Knowledge, a company that tracks online disinformation campaigns. “The bots focus on anything that is divisive for Americans. Almost systematically.”




Perspective. Rather clunky infographic, but the voice trend is important.
20% of All Searches are Made with Voice (INFOGRAPHIC)
A new and very interactive infographic by Adzooma takes a look at how online advertising will be trending in 2018. And one of the data points is the growth of voice search, which now makes up 20 percent of inquiries on Google’s mobile app and Android devices.




A very interesting tool.
Tetra’s call recorder and AI-powered transcription app now works for inbound calls
… what if there was a way for you to record a call through your mobile phone and have a full transcription of the discussion delivered to you within minutes? That’s exactly what San Francisco-based Tetra is setting out to enable with its AI-powered iPhone app that not only records your calls but converts the conversations into written form using deep learning and natural language processing (NLP).
… So far, Tetra has only worked with outbound calls, but now subscribers will be able to enjoy the full benefits of Tetra for incoming calls, too.
By way of a quick recap, Tetra is basically a VoIP app that works similarly to Google Voice, insofar as it allocates you a dedicated Tetra number that must be used for all outgoing/incoming calls. Once a call is complete, Tetra will spend a short period of time generating the notes.
… In terms of pricing, everyone can get 60 free minutes per month as part of a trial. Then you’ll have to sign up to the Plus, Pro, or Business plans, which offer varying amounts of call-time per month and range from $9 to $99.
… Then there are the legal and ethical angles to consider. By default, Tetra automatically tells the people on the other end of the call that they are being recorded, however it’s possible for the Tetra subscriber to disable this announcement with the proviso that you “stay compliant with local law or get recording consent yourself,” according to Tetra.


Monday, February 19, 2018

Now I can insult anyone and the evidence deletes itself?
Obliviate is a new app from MakeUseOf that lets you send self-destructing messages. It’s great for sharing secret messages with friends that you don’t want sticking around on their phone, among other use cases.
Download: obliviate for Android and iOS.
… The app lets you set a timer between 5 and 180 seconds for how long your messages will last. Once the recipient opens it, the message will disappear after a set time. And if you change your mind, you can immediately obliviate messages and bypass the timer.
Best of all, the obliviate is free and has no ads; never will. Plus, you cannot take screenshots in the app or copy the content of the messages (this feature is currently available on Android only, coming soon on iOS). This prevents others from recording messages you intended to be private.
… Coming soon, obliviate hopes to add encryption, support for audio, pictures, and videos, custom notification sounds, and more! We hope you enjoy the app.




Interesting that the parents accept this.
AP reports:
A private school in east Georgia intends to start drug-testing its oldest students.
The Columbus Ledger-Enquirer reports that Brookstone School in Columbus recently announced that the drug-testing of students in grades 8-12 will be voluntary next school year — and then mandatory in succeeding years.
Read more on Ledger-Enquirer.
And yes, of course they can get away with doing that as a precondition of acceptance or attendance. They’re a private school. But here’s the thing: parents are waiving their children’s privacy rights. Now I know a lot of parents are just fine with that because they want to know if their child is using drugs. And somewhere, I’m guessing, this school actually/hopefully has a written policy about what happens with the results, for how long they are retained, and with whom they might be shared. And what is the testing facility’s privacy policy? Will they be sent the students’ names as identifiers or just numbers/IDs? And who might they share results with and under what circumstances?
Much to think about here….




Another “Business Continuity” angle for my students to discuss.
Most KFCs in UK remain closed because of chicken shortage
The fast food chain KFC has been forced to temporarily close most of its UK outlets after problems with a new delivery contract led to a chicken shortage.
… The chicken delivery problem is so severe that the company cannot say when operations will be back to normal. But it said it was working “flat out” to resolve the crisis.
… In a statement it blamed the chicken shortage on a contract with delivery company DHL.




An interesting tool. Now, how do we apply it?
Perform Text Analysis with IBM Watson and Google Docs
Google, Microsoft, IBM and Amazon have made it easier for developers to add human cognitive capabilities (also known as artificial intelligence) within their own applications. You need not be a machine learning expert to build a computer program that can recognize objects in photographs, or one that transforms human speech to text or even a chatbot that converses with people in natural language.




Perhaps a metaphor for the Trump Administration?


Sunday, February 18, 2018

A reminder: Just because we rarely see their name in the list of ‘usual suspects’ does not mean they aren’t capable.
Saudi foreign minister calls Iran most dangerous nation for cyber attacks
… Asked who he believed was the most dangerous nation in terms of cyber attacks and Al-Jubeir was unequivocal.
"The most dangerous nation behind cyber attacks? Iran," Al-Jubeir said.
"Iran is the only country that has attacked us repeatedly and tried to attack us repeatedly. In fact they tried to do it on a virtually weekly basis."
… Last September, the U.S. Treasury Department added two Iran-based hacking networks and eight individuals to a U.S. sanctions list, accusing them of taking part in cyber-enabled attacks on the U.S. financial system in 2012 and 2013, Reuters reported.


(Related) Our allies have some skills too.
… The hack had targeted Belgacom, Belgium’s largest telecommunications provider, which serves millions of people across Europe. The company’s employees had noticed their email accounts were not receiving messages. On closer inspection, they made a startling discovery: Belgacom’s internal computer systems had been infected with one of the most advanced pieces of malware security experts had ever seen.
As The Intercept reported in 2014, the hack turned out to have been perpetrated by U.K. surveillance agency Government Communications Headquarters, better known as GCHQ. The British spies hacked into Belgacom employees’ computers and then penetrated the company’s internal systems. In an eavesdropping mission called “Operation Socialist,” GCHQ planted bugs inside the most sensitive parts of Belgacom’s networks and tapped into communications processed by the company.




For my future managers: How do you fail to notice that you only sent 100,000 letters to notify 600,000 people? I would never call this a programming error, the program correctly did what the manager asked it to do.
Jack Corrigan reports:
A programming error kept the IRS from notifying hundreds of thousands of identity theft victims about criminals using their Social Security numbers to get themselves jobs in 2017, according to an internal investigation.
Last year, more than half a million Americans had their identities used by others to get hired, but only first-time victims received a notification from the IRS, the Treasury Inspector General for Tax Administration found. As a result, nearly 460,000 previous victims of employment identity theft were left in the dark about their information getting stolen yet again.
“Most identified victims remain unaware that their identities are being used by other individuals for employment,” TIGTA wrote in its report.
Read more on NextGov.




For my “Why you need a lawyer” lecture.
Revision Legal has a post about insider leaks. The article starts by discussing the Morrisons case in the UK, where an employee vindictively leaked data. In a ruling that surprised many, the court held that although Morrisons was a victim of their employee, other employees who sued Morrisons could hold Morrisons liable:
This creates, in effect, a form a strict liability for an employee data leak (at least in the UK). If the ruling is upheld, Morrisons will face a massive legal liability and, without question, the remaining 94,500 employees will join the class action or file their own lawsuits. Further, it is possible that British regulators will follow the court’s ruling and impose heavy regulatory fines and penalties.
The article then turns to legal principles in the U.S. that would relate to holding an employer liable for an intentional leak by an employee. As the authors note, it’s “complicated.”
Read more on JDSupra.




Just in time for the chapter on Law & Regulation.
David M. Stauss and Gregory Szewczyk of Ballard Spahr LLP write:
As we first reported in our January 22, 2018, alert, the Colorado legislature is considering legislation that, if enacted, would significantly change Colorado privacy and data security law. On Wednesday, February 14, 2018, the bill’s sponsors submitted an amended bill that addresses issues raised by numerous stakeholders, including Ballard Spahr. The amended bill also was heard before the House Committee on State, Veterans, and Military Affairs, where it was unanimously approved.
The most significant changes are highlighted below.
Read more on The National Law Review. And yes, read more, as the state statute has some interesting overlap but also differences between the proposed state law and HIPAA and GLBA. And if adopted, HIPAA-covered entities would no longer have a 60-day window from discovery to notify – they might have only 30 days.




Now we have to depend on the Postal Service to safeguard the elections? So I have to get a code for Facebook before I can place an ad like “Bob for President.” Can I get that code now? I don’t want to wait until Russia send me the text of the ad they want me to run. (Let’s hope no one else reads this “secret” code that is written on the postcard!)
Facebook plans to use U.S. mail to verify IDs of election ad buyers
Facebook Inc will start using postcards sent by U.S. mail later this year to verify the identities and location of people who want to purchase U.S. election-related advertising on its site, a senior company executive said on Saturday.
… The process of using postcards containing a specific code will be required for advertising that mentions a specific candidate running for a federal office, Katie Harbath, Facebook’s global director of policy programs, said. The requirement will not apply to issue-based political ads, she said.
“If you run an ad mentioning a candidate, we are going to mail you a postcard and you will have to use that code to prove you are in the United States,” Harbath said at a weekend conference of the National Association of Secretaries of State, where executives from Twitter Inc and Alphabet Inc’s Google also spoke.
“It won’t solve everything,” Harbath said in a brief interview with Reuters following her remarks.
But sending codes through old-fashioned mail was the most effective method the tech company could come up with to prevent Russians and other bad actors from purchasing ads while posing as someone else, Harbath said.