Tuesday, April 09, 2019


The question should be: Is this something new or are they just playing catch-up?
China’s Next Naval Target Is the Internet’s Underwater Cables
As the West considers the threat posed by China’s naval ambitions, there is a natural tendency to place overarching attention on the South China Sea. This is understandable: Consolidating it would provide Beijing with a huge windfall of oil and natural gas, and a potential chokehold over up to 40 percent of the world’s shipping.
But this is only the most obvious manifestation of Chinese maritime strategy. Another key element, one that’s far harder to discern, is Beijing’s increasing influence in constructing and repairing the undersea cables that move virtually all the information on the internet. To understand the totality of China’s “Great Game” at sea, you have to look down to ocean floor.
While people tend think of satellites and cell towers as the heart of the internet, the most vital component is the 380 submerged cables that carry more than 95 percent of all data and voice traffic between the continents.
… But now the Chinese conglomerate Huawei Technologies, the leading firm working to deliver 5G telephony networks globally, has gone to sea. Under its Huawei Marine Networks component, it is constructing or improving nearly 100 submarine cables around the world.




I can’t help asking what China may have learned from this incident. What happened while the Secret Service was concentrating on her?
Attorney: Mar-a-Lago Infiltrator Had Hidden-Camera Detector
Assistant U.S. Attorney Rolando Garcia told Magistrate Judge William Matthewman during a bond hearing that “there are a lot of questions that remain” about 32-year-old Yujing Zhang
He said the FBI is still investigating whether Zhang is a spy. [Consider her a distraction. Bob]


(Related)
Hey Secret Service: Don't Plug Suspect USB Sticks into Random Computers
I just noticed this bit from the incredibly weird story of the Chinese woman arrested at Mar-a-Lago:
Secret Service agent Samuel Ivanovich, who interviewed Zhang on the day of her arrest, testified at the hearing. He stated that when another agent put Zhang's thumb drive into his computer, it immediately began to install files, a "very out-of-the-ordinary" event that he had never seen happen before during this kind of analysis. The agent had to immediately stop the analysis to halt any further corruption of his computer, Ivanovich testified. The analysis is ongoing but still inconclusive, he said.
This is what passes for forensics at the Secret Service? I expect better.
EDITED TO ADD (4/9): ArsTechnica has more detail.




The can of worms has been opened.
Leap in Cyber Attacks Against Elections in OECD Countries: Canada
Cyber attackers targeted half the member states of the Organization for Economic Cooperation and Development that held national elections in 2018, the agency that monitors Canada's telecoms networks said Monday.
"The proportion of elections targeted by cyber threat activity has more than tripled" since 2015, said the Canadian Security Establishment (CSE), which warned of a further spike this year.
"A small number of nation-states have undertaken most cyber threat activity against democratic processes worldwide," the center said, mostly pointing the finger at Russia.
… "This shift seems to have started in 2016, which is likely due in part to the perceived success among cyber threat actors of Russia's cyber interference activity against the 2016 United States presidential election," the report said.


(Related)
Preparing for Upcoming Indian Elections
As Indians prepare to vote in the General Election for the 17th Lok Sabha, Facebook and our family of apps continue our efforts to help make sure the elections are fair and free from interference, both foreign and domestic.
… We’ve also gotten better at using artificial intelligence and machine learning to fight interference. For example, these tools help us block or remove approximately one million accounts a day. They also help us, at a large scale, identify abusive or violating content, quickly locate it across the platform and remove it in bulk. This dramatically reduces its ability to spread. We continue to expand on this initiative, adding 24 new languages — including 16 for India — to our automatic translation system.
And last week we removed nearly 700 Pages, Groups and accounts in India for violating Facebook’s policies on coordinated inauthentic behavior and spam.




Maury Nichols adds to yesterday’s post about ‘alternative data’ collected by credit bureaus.
In regards to data related to one’s voice, cellular, cable TV, etc. there actually is a credit reporting agency named National Consumer Telecommunications & Utilities Exchange  (“NCTUE”). They share data amongst their telecommunication peers so if one was to move from Denver to San Diego and both cities were member of this organization the telecommunication provider in San Diego could get a fairly comprehensive view on how the person in Denver treated Comcast, CenturyLink, Dish, etc. Or if a person in Denver wishes to change carriers it is quite likely that the carrier will check the NCTUE database. So, if one did not pay their early termination fee it may or it may not appear on one’s credit report from the big three agencies (today); but that data would certainly be available to those telecommunication firms that are members of this rather niche credit bureau.
While NCTUE is “managed” by Equifax, at this point-in-time the data collected by NCTUE does not appear to be utilized by Equifax in calculating one’s credit score.




Still looks like a GDPR for an “ex” EU member.
The UK’s online laws could be the future of the internet—and that’s got people worried
Technology giants will be forced to have a “duty of care” for their users, if a proposal announced by the government on Monday becomes law.
The proposal—a “white paper,” in UK legal parlance, which is one of the first stages of a formal government policy—is, on the surface at least, sweeping in scope and is a serious shot across the bows for big tech companies. But it has also raised some serious concerns about how it will be implemented and the possible consequences it might have on citizens' free speech.
Aiming to tackle well-defined harms such as hate crime, stalking, and terrorist activity alongside issues such as trolling and disinformation, the UK government proposes combining work done across eight or more separate regulators into one.
This new "super-regulator" could have powers to fine technology companies according to their revenue, or even to block them. It could also be able to prosecute individual executives.
… The plans also shift the government view away from any idea that the technology industry is somehow stateless or ungovernable—judging instead, likely rightly, that the UK market is large and wealthy enough to give the industry a powerful interest in complying even with legislation they loathed.




“Delete my data, but provide a transcript?”
Beyond FERPA: The California Consumer Privacy Act’s New Rules for Privacy in the Education Sector
… While the CCPA does not apply to nonprofit educational institutions, it may apply to certain for-profit educational institutions, third-party service providers, and others in the education space. If an educational entity meets the threshold requirements below or it processes information on behalf of such an entity, it should prepare for CCPA implementation by January 2020.
… Business entities are not allowed to discriminate against consumers who exercise their rights under the CCPA. However, businesses are permitted to offer financial incentives for consumers to provide consent for the collection, sale, or deletion of their personal information.




Nothing written by lawyers will be obfuscation free. Can we find a use for this?
The Market for Data Privacy
Ramadorai, Tarun and Uettwiller, Antoine and Walther, Ansgar, The Market for Data Privacy (March 13, 2019). Available at SSRN: https://ssrn.com/abstract=3352175 or http://dx.doi.org/10.2139/ssrn.3352175
“We scrape a comprehensive set of US firms’ privacy policies to facilitate research on the supply of data privacy. We analyze these data with the help of expert legal evaluations, and also acquire data on firms’ web tracking activities. We find considerable and systematic variation in privacy policies along multiple dimensions including ease of access, length, readability, and quality, both within and between industries. Motivated by a simple theory of big data acquisition and usage, we analyze the relationship between firm size, knowledge capital intensity, and privacy supply. We find that large firms with intermediate data intensity have longer, legally watertight policies, but are more likely to share user data with third parties.”




Take that, young whippersnappers! Actually, I read this as fake news. I might have another opinion if the headline was “The Favorite Target of Internet Scammers is Old People.”
The Future Of The Internet Is Old People
BuzzFeedNews – “There will soon be more people aged 65+ in the US than in any other demographic, and it will stay that way for decades. I’ve spent months collecting data on the online habits of older people, with a particular focus on how they interact with false content. I just published a new story that dives deep into this — here are some of the most compelling points:
  • Four recent studies found that those over 65 are more likely to consume and share fake news on platforms such as Facebook, Twitter, and the web.
  • They don’t have a good understanding of the role algorithms play in determining what content we see online.
  • They have a harder time differentiating between news and opinion.
  • They are often targeted with ads from hyperpartisan and fake news sites.
  • They’re also targeted by online scams, malware, and other internet ills. Just last month, the Department of Justice announced “the largest coordinated sweep of elder fraud cases in history.”




My students expect tedious. Could this be the future of textbooks?
Want to learn about lithium-ion batteries? An AI has written a tedious book on the subject
On Monday, Springer Nature published what it claims is the first machine-generated book from an academic publisher, titled "Lithium-Ion Batteries A Machine-Generated Summary of Current Research."
… The book for battery boffins, available as a free download, provides an overview of lithium-ion battery research, summarizing more than 150 research papers published between 2016 and 2018.
… As a one-stop shop for lithium-ion battery research, "Lithium-ion batteries" is possibly functional, not so much for reading as for finding reference links to academic papers. But even for that, Bigham suggests concentrating a list of Google Scholar search results might work just as well.



Monday, April 08, 2019

Use this as a negative model for security. Does your policy address everything and do your procedures make certain your policy is followed?
So the Congressional report on Equifax’s massive 2017 databreach was released. The title gives you a clue as to what you can expect to read in it:
HOW EQUIFAX NEGLECTED CYBERSECURITY AND SUFFERED A DEVASTATING DATA BREACH
STAFF REPORT
PERMANENT SUBCOMMITTEE ON INVESTIGATIONS
UNITED STATES SENATE
You can access the whole report on the Senate’s web site, here I’ve also made a copy available on this site


(Related)
Take a look at a credit report from one of the big three credit reporting agencies, and you’re likely to see certain types of accounts listed: credit cards, mortgages, car payments, and student loans, for instance.
How you pay those bills impacts the credit score that lenders use to determine how risky you are. But other types of accounts don’t generally show up on your traditional credit report. Those include phone and electric bills, rent, and payments to many types of credit providers such as payday lenders, rent-to-own stores, and online personal lenders.
The country’s biggest credit bureaus—Experian, Equifax, and TransUnion—are trying to change that. As part of a growing push to expand the population to whom lenders can offer loans, the companies are helping lead an industry push to gather “alternative” credit data, in what’s been called one of the biggest changes to credit scoring in years.




Do you rely on a computer to monitor and adjust your machines? What if these are proof of concept attacks, gathering a portfolio of systems an aggressor could take down in the first seconds of a cyber war.
Most OT Organizations Hit by Damaging Cyberattacks: Survey
A majority of organizations that have operational technology (OT) infrastructure experienced at least one damaging cyberattack in the past two years, according to a survey conducted by Ponemon Institute and Tenable.
… The report shows that 90% of respondents admitted suffering at least one damaging cyberattack in the past two years, and nearly two-thirds were hit at least two times. These statistics include attacks on IT systems, which are still relevant as attackers may be able to move from IT to OT systems.
Half of respondents said they had experienced an attack on their OT infrastructure that resulted in downtime of the plant and/or operational equipment. Many organizations also admitted suffering significant business disruptions and downtimes as a result of cyberattacks.
Furthermore, nearly a quarter of respondents believed they had been targeted by a nation-state actor.




Why two-factor authentication is better.
FOOLING FINGERPRINT SCANNERS WITH A RESIN PRINTER
Biometrics have often been used as a form of access control. While this was initially limited to bank vaults in Hollywood movies, it’s now common to see such features on many laptops and smartphones. Despite the laundry list of reasons why this is a bad idea, the technology continues to grow in popularity. [darkshark] has shown us an easy exploit, using a 3D printer to fool the Galaxy S10’s fingerprint scanner
The Galaxy S10 is interesting for its use of an ultrasonic fingerprint sensor , which continues to push to hardware development of phones minimal-to-no bezels by placing the sensor below the screen. The sensor is looking for the depth of the ridges of your fingerprint, while the touchscreen verifies the capacitive presence of your meaty digit. This hack satisfies both of those checks.




What if your decrypted data still looked like gibberish?
Orin Kerr writes:
I am pleased to say that the Texas Law Review has published the final version of my article on how the Fifth Amendment applies to compelling a person to enter a password: Compelled Decryption and the Privilege Against Self-Incrimination This article has roots in some blog posts that I wrote here at the Volokh Conspiracy a few years ago. Given the recurring and difficult nature of the question, I decided to expand considerably on the posts by writing the full article. It’s still relatively short by law review article standards, though, at a relatively svelte 33 pages.
Here’s the abstract:
This Essay considers the Fifth Amendment barrier to orders compelling a suspect to enter in a password to decrypt a locked phone, computer, or file. It argues that a simple rule should apply: an assertion of privilege should be sustained unless the government can independently show that the suspect knows the password. The act of entering a password is testimonial, but the only implied statement is that the suspect knows the password. When the government can prove this fact independently, the assertion is a foregone conclusion and the Fifth Amendment poses no bar to the enforcement of the order. This rule is both doctrinally correct and sensible policy. It properly reflects the distribution of government power in a digital age when nearly everyone is carrying a device that comes with an extraordinarily powerful lock.
Read more of his post on Reason.com.




An expansion of the GDPR or a replacement?
Why the UK is moving to regulate the internet
… In a world first, the UK has published a blueprint for new legislation that will hold tech companies to account and protect those using their platforms.
The online world is changing rapidly, and it needs an independent regulator. It will enforce a new legal obligation for online platforms to exercise a duty of care to their users. This means that companies will have a responsibility to take reasonable and proportionate steps to protect their users from harm. It is similar to the principle that when you take your child to a playground, you trust that the builder made sure the equipment was safe and that no harm will come to them. Why should it be any different online?




A source of GDPR integration wisdom?
Let’s start this week with some positive news. From the Information Commissioner’s Office in the UK:
Recognising the increasingly vital role played by professionals working in the sector, the second ICO Practitioner Award for Excellence in Data Protection was presented to Mikko Niva, Group Policy Officer at Vodafone Group Services Ltd based in London.
Chosen by an independent panel, Mr Niva has been recognised for delivering a pioneering global privacy compliance programme for Vodafone across 21 different countries, and for being a constant advocate for information and privacy rights.
… Paul Jordan, Managing Director Europe at the International Association of Privacy Professionals (IAAP), who was one of the judges, said:
“This year nominations were all of high calibre, having done some really great GDPR integration work for their respective organizations and stakeholders;
… Source: INFORMATION COMMISSIONER’S OFFICE




Seems like a lot of thought.
Aspen Institute – Automation and a Changing Economy
Automation is an important ingredient driving economic growth and progress. “Automation has enabled us to feed a growing population while allowing workers to transition from subsistence farming to new forms of work. Automation helped moved us from a craft system to mass production, from blue-collar to white-collar to “new collar” work—with better work, higher wages, more jobs, and better living standards.
But without adequate policies and institutions, automation can also have negative effects on individuals and communities. Emerging technologies—including artificial intelligence, machine learning, and advanced robotics—have the potential to automate many tasks currently performed by workers, leading to renewed questions over what the future holds for the American workforce. We must ensure the proper support structures are in place to promote opportunity and prosperity for all. Automation and a Changing Economy is divided into two sections. – Automation and a Changing Economy: The Case for Action and Policies for Shared Prosperity.”




I think they released these as a draft back in December. Maybe.
European Commission announces pilot program for AI ethics guidelines
… Last summer, the commission appointed a group of independent experts appointed to help develop a set of ethical guidelines. That group created seven general guidelines that were presented today officially and will be reviewed at a forum scheduled for tomorrow:
  1. Human agency and oversight: AI systems should enable equitable societies by supporting human agency and fundamental rights, and not decrease, limit or misguide human autonomy.
  2. Robustness and safety: Trustworthy AI requires algorithms to be secure, reliable and robust enough to deal with errors or inconsistencies during all life cycle phases of AI systems.
  3. Privacy and data governance: Citizens should have full control over their own data, while data concerning them will not be used to harm or discriminate against them.
  4. Transparency: The traceability of AI systems should be ensured.
  5. Diversity, non-discrimination and fairness: AI systems should consider the whole range of human abilities, skills and requirements, and ensure accessibility.
  6. Societal and environmental well-being: AI systems should be used to enhance positive social change and enhance sustainability and ecological responsibility.
  7. Accountability: Mechanisms should be put in place to ensure responsibility and accountability for AI systems and their outcomes.
The commission is seeking partners to test these guidelines and offer feedback. Details of how the pilots will work have yet to be announced.




Almost everyone hates social media. Almost everyone uses social media.
Poll: Americans give social media a clear thumbs-down
The American public holds negative views of social-media giants like Facebook and Twitter, with sizable majorities saying these sites do more to divide the country than unite it and spread falsehoods rather than news, according to results from the latest national NBC News/Wall Street Journal poll.
What’s more, six in 10 Americans say they don’t trust Facebook at all to protect their personal information, the poll finds.




For my Architecture students. How do we speed up change?
The First Law of Digital Innovation
By now, most of us have heard of Moore’s law.
The “law,” coined more than 40 years ago by Intel cofounder Gordon Moore, has helped to shape the pace of innovation for decades.
… I’d like to propose a new law. It’s one I know to be true, and one that too many people forget. We can call it the first law of digital transformation. Or we can just call it George’s law. It goes like this:
Technology changes quickly, but organizations change much more slowly.




I’d call it, fooling the censors. (Youtube video)
Manipulating the YouTube Algorithm – (Part 1/3)
Smarter Every Day – “This is video 1 of a 3 part series on Social Media Algorithm manipulation and countermeasures. Even if you’re aware of these issues, odds are your friends and parents are not. I’m hoping we can use this video series to educate an incredible amount of people about the realities of algorithmic manipulation online. The engineers tasked with working on these problems take their jobs very seriously and they are truly the unsung heroes in this fight…”




Cenosillicaphobia is the fear of an empty beer glass. Don't live in fear: go, get a beer.


Sunday, April 07, 2019

Where should ethics decisions be made?
The Google AI Ethics Board With Actual Power Is Still Around
Two weeks ago, Google established an external panel of experts to review thorny ethical issues related to artificial intelligence. It quickly imploded After a staff revolt over the panel's members, the company disbanded the panel on Thursday afternoon Its members never even got the chance to meet.
The episode illustrates the difficulty Google is having as it grapples with the societal implications of the powerful technology shaping its future. It’s hard to overstate how important AI is to the company. “It’s more profound than, I don’t know, electricity or fire ” said Sundar Pichai, the company’s chief executive officer, last year. But Google has been at the center of a widening public debate over how automated systems might disadvantage vulnerable groups or lead to large-scale job losses, and whether AI should be incorporated into weaponry.
… Critics familiar with the council see it as a whitewash. They say a board of top executives is unlikely to serve as a serious check on Google in situations where its stated ethical principles butt up against its financial interests. And multiple people inside the company said the agenda and decisions of this corporate board remain unclear months after launching. These people asked not to be identified for fear of retaliation.




Perspective. Another nail in their anti-trust/monopoly coffin?
Google and other tech giants are quietly buying up the most important part of the internet
Google makes billions from its cloud platform. Now it’s using those billions to buy up the internet itself — or at least the submarine cables that make up the internet backbone.
In February, the company announced its intention to move forward with the development of the Curie cable, a new undersea line stretching from California to Chile. It will be the first private intercontinental cable ever built by a major non-telecom company.
… Google isn’t alone. Historically, cables have been owned by groups of private companies — mostly telecom providers — but 2016 saw the start of a massive submarine cable boom, and this time, the buyers are content providers. Corporations like Facebook, Microsoft, and Amazon all seem to share Google’s aspirations for bottom-of-the-ocean dominance.




Perspective. Not sure why these are controversial.
How the Army plans to use Microsoft's high-tech HoloLens goggles on the battlefield




Perspective. This is my industry.
The Creeping Capitalist Takeover of Higher Education
… The colleges would have you believe that none of this is their fault. They would point out that public schools took a huge financial hit during the recession when states slashed their education budgets. This is true, but that hardly explains the size and pace of the price hikes or the fact that tuition at private schools has exploded, too.
It also doesn’t explain why colleges have failed to take advantage of the best opportunity to radically drop the price of a good degree that I’ve seen in 15 years of watching and reporting on the industry. This opportunity doesn’t have the daunting price tag of worthy proposals like “free college.” It doesn’t require any action from Congress at all.
The answer is online learning.




It’s today!
39 Best Beer Puns And Beer Memes For National Beer Day (And, Well, Every Day)
National Beer Day falls on April 7th this year.
[My personal favorite: “I don’t drink beer. I drink a wheat smoothie.”


Saturday, April 06, 2019

This shakes my (not very substantial) faith in government security. Multiple break ins, physical devices installed on computers, massive data copying after hours and NO ONE NOTICED?
Luke Rosiak reports:
A former IT aide to New Hampshire Democratic Sen. Maggie Hassan mounted an “extraordinarily extensive data-theft scheme” against the office, the culprit’s plea agreement states.
The plot included the installation of tiny “keylogging” devices that picked up every keystroke. Between July and October 2018, former IT aide Jackson Cosko worked with an unnamed accomplice, a then-current Hassan employee, who repeatedly lent him a key that he used to enter the office at night and who allegedly tried to destroy evidence for him.
Read more on The Daily Caller .
[From the article:
The theft occurred after Cosko was fired from Hassan’s office in May 2018 for undisclosed reasons, then hired by Democratic Texas Rep. Sheila Jackson Lee, giving him access to the House computer network.




I suspect many accounts had to be redirected. The process for confirming their authenticity might need a bit of work.
Karl Etters reports:
Almost half a million dollars was diverted out of the city of Tallahassee’s employee payroll Wednesday after a suspected foreign cyber-attack of its human resources management application.
Hackers attempt every day to breach the city’s security, officials say, but this week’s operation netted about $498,000.
Read more on Tallahassee Democrat .
[From the article:
The out-of-state, third-party vendor that hosts the city's payroll services was hacked and as a result the direct deposit paychecks were redirected. Employees throughout the city’s workforce were affected.




Attention Computer Security students: Poor security is a factor in deceptive trade practices.
Anne Bolamperti and Patrick X. Fowler of Snell & Wilmer write:
The Federal Trade Commission (“FTC”) has described itself as “Your cop on the privacy beat” and a top federal regulator of consumer-facing data security practices. An example of how the FTC asserts itself when it comes to data security and privacy associated with Internet of Things (“IoT”) devices can be found in the case of Federal Trade Commission v. D-Link Systems Inc., currently pending in federal court in California.
FTC Stance: Poor IoT Security +/or Misleading Ads = Deceptive/Unfair Trade Practice
The D-Link case stems from the FTC’s January 5, 2017 complaint against Taiwanese IoT hardware device manufacturer D-Link Corporation and its U.S. subsidiary D-Link Systems Inc. The FTC seeks to stop D-Link from engaging in allegedly unfair or deceptive acts in violation of Section 5(a) of the Federal Trade Commission Act (“FTC Act”). The FTC claims that the defendants failed to reasonably secure IoT network routers and Internet-accessible cameras that they sold in the U.S. and made deceptive statements about the degree of data security of those products.
Read more on Cybersecurity & Data Law Privacy Blog There was a recent settlement conference in this case, but it doesn’t seem like there was any settlement and the case is still scheduled to go to trial in June, it seems.




Interesting because inevitable? I can get a body cam on Amazon, would the hospital even suspect? Perhaps a bit of geofencing for honest manufacturers?
Emily Berris of SmithAmundsen LLC writes:
Imagine a police officer escorting a drunk driver through the emergency room with his body camera still on—not only is the officer recording the driver, the officer is simultaneously recording every individual and every patient that officer comes into contact with. In an era of attempted police reform, where law enforcement is ramping up their use of body cameras, hospitals must be increasingly aware of violations to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the implications of police body cameras within the confines of its medical center.
Read more on JDSupra




Insurance companies could use this (like their “safe-driving” plug-ins) to deny coverage for bad behavior.
Joseph J. Lazzarotti, Mary T. Costigan and Ashley Solowan of JacksonLewis write:
As wearable and analytics technology continues to explode, professional sports leagues, such as the NFL, have aggressively pushed into this field. (See Bloomberg ). NFL teams insert tiny chips into players shoulder pads to track different metrics of their game. During the 2018-2019 NFL season, data was released that Ezekiel Elliot ran 21.27 miles per hour for a 44-yard run, his fastest of the season. The Dallas Cowboys are not alone as all 32 teams throughout the league can access this chip data which is collected via RFID tracking devices. Sports statistics geeks don’t stand a chance as this technology will track completion rates, double-team percentages, catches over expectation, and a myriad of other data points.




I’m sure these are all good ideas, but we probably need an independent AI Ethics organization. Anyone want to start one? (Let’s ask Siri, Alexa, etc.)
Hey Google, sorry you lost your ethics council, so we made one for you
… How did things go so wrong? And can Google put them right? We got a dozen experts in AI, technology, and ethics to tell us where the company lost its way and what it might do next. If these people had been on ATEAC, the story might have had a different outcome.