Thursday, May 16, 2019


This will take some thinking. What alternatives are available?
Trump Bars U.S. Companies From Foreign Telecoms Posing Security Risk
President Donald Trump declared a national emergency Wednesday barring US companies from using foreign telecoms equipment deemed a security risk -- a move that appeared aimed at Chinese giant Huawei.
The order signed by Trump prohibits purchase or use of equipment from companies that pose "an unacceptable risk to the national security of the United States or the security and safety of United States persons."
A senior White House official insisted that no particular country or company was targeted in the "company- and country-agnostic" declaration.
However, the measure -- announced just as a US-China trade war deepens -- is widely seen as prompted by already deep concerns over an alleged spying threat from Huawei.
US officials have been trying to persuade allies not to allow China a role in building next-generation 5G mobile networks, warning that doing so would result in restrictions on sharing of information with the United States.


(Related)
Huawei Chairman Says Ready to Sign 'No-Spy' Deal With UK
Chinese telecom giant Huawei is willing to sign a "no-spy" agreement with countries including Britain, the firm's chairman said on Tuesday, as the head of NATO said Britain must preserve secure mobile networks.
Liang Hua visited Britain as the government weighs the risks of allowing the Chinese company to help develop its 5G infrastructure.
"We are willing to sign 'no-spy' agreements with governments, including the UK government, to commit ourselves, to commit our equipment to meeting the no-spy, no back-door standards," Liang told reporters.
The British government is in the middle of a furious debate over whether to let Huawei roll out its next-generation mobile service.




In this case, some good comes from an all too common bad. Failure to change the default settings.
What Colorado learned from treating a cyberattack like a disaster
The decision by then-Gov. John Hickenlooper to declare a statewide emergency on March 1, ten days after the initial infection was detected, allowed officials to bring in resources from the National Guard and other states, create a unified command structure and perhaps most crucially, spare the state’s IT workers from having to work any more 20-hour shifts fueled by junk food, said Kevin Klein, Colorado’s director of homeland security and emergency management.
Klein also recounted for the audience of state IT and security officials how the SamSam malware infested CDOT’s network. In mid-February 2018, the department activated a new virtual server for testing, but the server’s security software was still on its default settings, making it an appealing target when it started broadcasting its IP address to the rest of the internet.
It started broadcasting ‘I’m here, I’m here, come attack me,’ which of course happened within 48 hours,” Klein said.


(Related) In stark contrast…
THE TRADE SECRET
Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers




A good article for my first Computer Security lecture?
A new survey from Google and Harris Poll, released a year after Google introduced “.app” as a more secure alternative to “.com,” shows that while 55% of Americans over the age of 16 give themselves an A or B in online safety and security, 70% of them wrongly identified what a safe website looks like.


(Related) For my lecture on Backup
Your internet data is rotting
Many MySpace users were dismayed to discover earlier this year that the social media platform lost 50 million files uploaded between 2003 and 2015.
The failure of MySpace to care for and preserve its users’ content should serve as a reminder that relying on free third-party services can be risky.
MySpace has probably preserved the users’ data; it just lost their content. The data was valuable to MySpace; the users’ content less so.


(Related) A good day for Security articles.
The Best Free Online Proxy Servers You Can Use Safely




Should some crimes be “investigation proof?”
Peter Aldhous reports:
For the first time on record, the new forensic science of genetic genealogy has been used to identify a suspect in a case of violent assault. Cops in Utah had to obtain special permission to upload crime scene DNA to a website called GEDmatch, which had previously only allowed police to investigate homicides or rapes.
Critics worry that the case, which led to the arrest of a 17-year-old high school student who has not yet been named, marks the start of a “slippery slope” to law enforcement using such methods to investigate increasingly less serious offenses, eroding people’s genetic privacy.
Read more on BuzzFeed.
This is going to continue to be a significant privacy concern until sites create privacy policies that they then STICK TO. If you post a privacy policy about how your data may be used or disclosed and people opt-in based on your words in your policy, and you then do not stick to that, well….. how is this not a matter for the FTC to take up as a violation of Section 5?




This was the area that most concerned me. I had to rethink a lot of my Security planning.
All You Should Know about GDPR Acquiescent Software Development
In this article, we will take a closer look at some basic terms related to GDPR and explain several essential secured software development practices which all the software developers should learn and respect to create software that is more GDPR-compliant and future-safe.




Think Russia could afford $14?
In India election, a $14 software tool helps overcome WhatsApp controls
WhatsApp clones and software tools that cost as little as $14 are helping Indian digital marketers and political activists bypass anti-spam restrictions set up by the world’s most popular messaging app, Reuters has found.
After false messages on WhatsApp last year sparked mob lynchings in India, the company restricted forwarding of a message to only five users. The software tools appear to overcome those restrictions, allowing users to reach thousands of people at once.




Useful approach.
Five questions you can use to cut through AI hype


(Related) Similar concepts.
Our Six Principles For Ethically Developing Machine Learning




We don’t need AI to crack “uncrackable” codes.
Bristol academic cracks Voynich code, solving century-old mystery of medieval text
Phys.org: “A University of Bristol academic has succeeded where countless cryptographers, linguistics scholars and computer programs have failed—by cracking the code of the ‘world’s most mysterious text’, the Voynich manuscript. Although the purpose and meaning of the manuscript had eluded scholars for over a century, it took Research Associate Dr. Gerard Cheshire two weeks, using a combination of lateral thinking and ingenuity, to identify the language and writing system of the famously inscrutable document. In his peer-reviewed paper, The Language and Writing System of MS408 (Voynich) Explained, published in the journal Romance Studies, Cheshire describes how he successfully deciphered the manuscript’s codex and, at the same time, revealed the only known example of proto-Romance language. “I experienced a series of ‘eureka’ moments whilst deciphering the code, followed by a sense of disbelief and excitement when I realised the magnitude of the achievement, both in terms of its linguistic importance and the revelations about the origin and content of the manuscript…”




Perspective. Architecting the military.
Army CIO Envisions Internet of Strategic Things
Lt. Gen. Bruce Crawford, USA, chief information officer/G-6, U.S. Army, suggests the possibility of an Internet of Strategic Things in addition to the Internet of Tactical Things.
We’ve had some really good discussions about the Internet of Things. That was a thing a couple of years ago. And then we started talking about the Internet of Tactical Things. I think what’s on the horizon is more of a discussion of the Internet of Strategic Things,” Gen. Crawford told the audience on the second day of the AFCEA TechNet Cyber 2019 conference in Baltimore.




The near future?
Electric air taxi startup Lilium completes first test of its new five-seater aircraft
Think midtown Manhattan to JFK International Airport in under 10 minutes for $70. (Currently, a company called Blade, which bills itself as “Uber for helicopters,” offers the same trip for $195.)
Lilium isn’t the only company with designs for flying taxis. There are more than 100 different electric aircraft programs in development worldwide, with big names including Joby Aviation and Kitty Hawk, whose models are electric rotor rather than jet powered as well as planned offerings from Airbus, Boeing, and Bell, which is partnered with Uber.



Wednesday, May 15, 2019


So a cop using the old Mark I Eyeball can still recognize crooks. A device that captures images of faces and presents them to a person for identification seems to be outlawed too.
San Francisco Bans Facial Recognition Use by Police
San Francisco on Tuesday became the first US city to ban use of facial recognition technology by police or other government agencies.
Backers of the legislation argued that using software and cameras to positively identify people is, as city councillor Aaron Peskin put it, "not ready for prime time."
"The propensity for facial recognition technology to endanger civil rights and civil liberties substantially outweighs its purported benefits, and the technology will exacerbate racial injustice and threaten our ability to live free of continuous government monitoring," read the legislation passed Tuesday.
The ban was part of broader legislation setting use and auditing policy for surveillance systems, creating high hurdles and requiring board approval for any city agencies.
"It shall be unlawful for any department to obtain, retain, access, or use any Face Recognition Technology or any information obtained from Face Recognition Technology," read a graph tucked into the lengthy document.
"Face recognition technology" means an automated or semi-automated process that assists in identifying or verifying an individual based on an individual's face.




A useful(?) quick summary.
What is the California Consumer Privacy Act and Does it Apply to Me?




Oh joy.
Quit worrying about killer robots, they are coming whether you like it or not – and they absolutely will not stop
The use of fully automated AI systems in military battles is inevitable unless there are strict regulations in place from international treaties, eggheads have opined.
Their paper, which popped up on arXiv [PDF ] last week, discusses the grim outlook of developing killing machines for armed forces. The idea of keeping humans in the loop has always been favoured because modern AI systems like neural networks are like black boxes, their inner workings are inherently difficult to understand. Plus, you know, we've all seen Terminator.




Counter suit anyone?
Adobe Warns Users Someone Else Might Sue Them For Using Old Versions Of Photoshop
For years we've noted repeatedly how in the modern era you no longer truly own the things you buy. From game consoles that magically lose important functionality post purchase, to digital purchases that just up and disappear, we now live in an era where a quick firmware update can erode functionality and overlong EULAs can strip away all of your rights in an instant, leaving you with a hole in your pocket and a glorified paperweight.
The latest case in point: Adobe this week began warning users of its Creative Cloud software applications that they are no longer authorized to use older versions of the company's software platforms (Lightroom Classic, Photoshop, Premiere, Animate, and Media Director). In the letter, Adobe rather cryptically implied that users could risk copyright infringement claims by mysterious third parties if they continued using older versions of these platforms and refused to update them. End users, not surprisingly, were equal parts confused and annoyed:
While Adobe couldn't be bothered to clarify this fact, the company was apparently making a vague reference to its ongoing legal dispute with Dolby Labs. Dolby sued Adobe last year (pdf) for copyright violations after it wasn't happy with the new revenue sharing arrangement crafted in the wake of Adobe's 2013 shift toward its controversial cloud-based "software as a subscription" model. There's really no indication that Dolby would actually sue Adobe customers, and it seems more than likely that Adobe was just interested in throwing some shade at Dolby -- without making it entirely clear that's what they were doing.
Regardless, copyright experts were quick to point out that given the overbroad nature of modern EULAs, users are completely out of luck when it comes to having any real legal recourse:




For our programmers.
JavaScript and machine learning: Google shows what's possible using the web programming language
Building and training machine-learning models using a web-scripting language might seem ambitious, but in 2019 it's perfectly feasible.
Helping make machine learning possible in the browser isTensorFlow.js, Google's open-source library for carrying out machine learning using JavaScript. The possibilities opened up by the library were showcased recently with a Google Doodle that generated a fresh Bach-style melody on demand.
TensorFlow.js can be used in JavaScript applications running in the browser, on servers inside a Node.js environment, on the desktop using Electron and on mobile browsers on Android and iOS devices. However, it is within the browser that Gupta sees the most possibilities.




Because, reading!
Redefine reading practice with Rivet
Rivet is a new reading app from Area 120, Google’s workshop for experimental projects, that addresses the most common barriers to effective reading practice through a free, easy-to-use reading experience optimized for kids. Evidence shows that one of the major differences between poor and strong readers is the amount of time spent reading, so we're introducing Rivet to make high-quality reading practice available to all.
Rivet is now available on Android smartphones, tablets, iPads, iPhones and Chromebooks in eleven countries worldwide. If you know a little reader who could benefit from better reading practice, check us out in the Play Store or App Store today.



Tuesday, May 14, 2019


Failure to ensure procedures were followed.
Sensitive Information of Millions of Panama Citizens Leaked
As Security Discovery researcher Bob Diachenko discovered during his investigation, the data was leaked because the Elasticsearch cluster storing it was not properly configured, allowing anyone with an Internet connection to access it using a web browser.




An infographic to help my students understand data.
Personal Data and the Organization: Stewardship and Strategy
Personal data – used lawfully, fairly, and transparently – is central to helping organizations achieve their missions. Today, Boards of Directors, CEOs, policymakers, and others need to understand the wide range of data inputs, the broad scope of risks and benefits, and how privacy and ethics are at the center of an organization’s ability to fulfill its leaders’ vision. Traditionally, privacy was considered a legal and compliance matter, but now it is a fundamental concern because of emerging issues such as advertising practices, content standards, global data flows, concerns about civil rights, law enforcement cooperation, ethics, community engagement, research standards, and more. With these trends in mind, FPF has created an infographic that shows:
    • The complexities of how organizations collect and use data
    • The risks involved
    • How principled data stewardship supports the goals of innovation, growth, brand development, and social responsibility.




Sure we spy on you. But it’s for your own good!”
Alexa Guard is coming soon for all Echo owners in the US
Amazon’s Alexa Guard feature is now rolling out in the US, following an invite-only preview that lasted a few months. This free update lets your Echo speaker listen for signs of danger in your home while you’re away. [How do I know this works only while I’m away? Bob] Sounds like glass breaking (caused by a burglar or a moody cat) or a smoke alarm going off will trigger Alexa to send out Smart Alerts consisting of audio clips. If your Echo has a built-in camera, it will show a direct video feed into your home.
In addition to listening, Alexa Guard can also mimic your daily smart light usage, switching the lights on and off to make it seem like you’re home. Amazon notes that Alexa Guard isn’t meant to be a replacement for an alarm system, and it isn’t able to alert authorities.




Now, this is really concerning.
United States Congress Creates AI Task Force
Today, Congresswoman Maxine Waters (D-CA), Chairwoman of the House Committee on Financial Services, announced the creation of a Task Force on Artificial Intelligence chaired by Congressman Bill Foster (D-IL).
The Task Force on Artificial Intelligence will examine issues including:
    • Applications of machine learning in financial services and regulation
    • Algorithms and Big Data: emerging risk management perspectives
    • AI, Digital Identification Technologies and Combatting Fraud
    • Automation and its impact on jobs in financial services and the overall economy.”




You should really try this. It’s not bad. (No doubt my students will find this “homework helper.”)
Use this cutting-edge AI text generator to write stories, poems, news articles, and more
Enter the start of a made-up news article, and it’ll finish it for you. Ask it a question (by formatting your input like this: “Q: What should I do today?”), and it’ll happily respond.
The site is called TalkToTransformer.com, and it’s the creation of Canadian engineer Adam King.




I wonder if President Trump would consider a more ‘high tech’ wall?
Swarms of automated drones controlled by AI are set to patrol Europe's borders using powerful sensors to detect threats and criminal activity under EU plan
The system, which has multi-national support from border authorities and Law Enforcement Agencies (LEAs) across Europe, will 'Exploit aerial (UAV), water surface (USV), underwater (UUV) and ground (UGV) vehicles'.




Perspective.
Amazon Will Put UPS Out of Business
The new machines, known as the CartonWrap from Italian firm CMC Srl, pack much faster than humans. They crank out 600 to 700 boxes per hour, or four to five times the rate of a human packer, the sources said. The machines require one person to load customer orders, another to stock cardboard and glue and a technician to fix jams on occasion.
… “A ‘lights out’ warehouse is ultimately the goal."
But there's a catch. They have to start their own delivery business instead.
It's clear where this is headed: Amazon will directly compete with UPS and FedX.
If Amazon can offer retailers reduced costs and faster delivery, why wouldn't businesses take it?


(Related)
Walmart announces next-day delivery, firing back at Amazon
The biggest retailer in the world will now offer shoppers the option to have their online orders delivered the next day, following Amazon, which on April 25 announced plans to spend $800 million for one-day delivery for all Amazon Prime members.



Monday, May 13, 2019


Can the Internet yell “Fire!” in a crowded theater?
Terrorism, Violent Extremism, and the Internet: Free Speech Considerations
EveryCRSReport.com – Terrorism, Violent Extremism, and the Internet: Free Speech Considerations, May 6, 2019 R45713: “Recent acts of terrorism and hate crimes have prompted a renewed focus on the possible links between internet content and offline violence. While some have focused on the role that social media companies play in moderating user-generated content, others have called for Congress to pass laws regulating online content promoting terrorism or violence. Proposals related to government action of this nature raise significant free speech questions, including (1) the reach of the First Amendment’s protections when it comes to foreign nationals posting online content from abroad; (2) the scope of so-called “unprotected” categories of speech developed long before the advent of the internet; and (3) the judicial standards that limit how the government can craft or enforce laws to preserve national security and prevent violence.




Of course they do. May not be the best approach.
Tech Lobbyists Move Swiftly to Limit Reach and Scope of California’s CCPA Privacy Law
With the new California Consumer Privacy Act (CCPA) ready to go into effect in January 2020, tech lobbyists are working closely with various tech industry trade associations and business groups to weaken the effectiveness of this sweeping new state privacy law by introducing new amendments and changes. According to the new CCPA, California citizens can request a list of all personal information that businesses collect them, demand that it be deleted, or opt out of having it sold to third parties. The proposed amendments would weaken each of these rights articulated in the California law.




We are clearly moving into the “undue reliance” stage of AI.
Avoid the politics and let artificial intelligence decide your vote in the next election
If trust in our politicians is at an all time low, maybe it’s time to reconsider how we elect them in the first place.
Can artificial intelligence (AI) help with our voting decisions?
Music and video streaming services already suggest songs, movies or TV shows that we will probably enjoy. Online shopping sites helpfully suggest other products we might like to buy. All this is based on what we’ve already watched, listened to or bought.
So why not have a similar system to suggest whom we should vote for?




How does society benefit from a game that drives its developers over the edge.
I’d have these extremely graphic dreams, very violent,” they told Kotaku in a call. “I kind of just stopped wanting to go to sleep, so I’d just keep myself awake for days at a time, to avoid sleeping.”
Eventually, the developer says they saw a therapist, who diagnosed them with PTSD. They attribute this to their work on MK11—not just the content of the game and having to process and discuss its violent cinematics frame by frame, but also being surrounded by the reference materials artists used for research.



Sunday, May 12, 2019


Interesting reaction. Clearly the Dutch prefer ‘verify’ over ‘trust.’
Software update crashes police ankle monitors in the Netherlands
A borked software update has crashed hundreds of ankle monitoring devices used by Dutch police, Dutch government officials said today.
The faulty update effectively stopped traffic from ankle monitors from reaching the Department of Justice's DV&O control rooms, preventing officials from knowing the locations of suspects in house arrests or released on bail.
The issue was fixed later in the day, on Thursday; however, the Dutch Ministry of Justice and Security had to step in and preemptively arrest and jail some of its most high-risk suspects.




Interesting only because of the Colorado connection?
How facial recognition became a routine policing tool in America
Unlike DNA evidence, which is costly and can take a laboratory days to produce, facial recognition requires little overhead once a system is installed. The relative ease of operation allows officers to make the technology part of their daily work. Rather than reserve it for serious or high-profile cases, they are using it to solve routine crimes and to quickly identify people they see as suspicious.
But these systems are proliferating amid growing concern that facial recognition remains prone to errors — artificial-intelligence and privacy researchers have found that algorithms behind some systems incorrectly identify women and people with dark skin more frequently than white men — and allows the government to expand surveillance of the public without much oversight. While some agencies have policies on how facial recognition is used, there are few laws or regulations governing what databases the systems can tap into, who is included in those databases, the circumstances in which police can scan people’s photos, how accurate the systems are, and how much the government should share with the public about its use of the technology.




Perhaps this AI has a bias against rich people?
Who to Sue When a Robot Loses Your Fortune
The first known case of humans going to court over investment losses triggered by autonomous machines will test the limits of liability.
Robots are getting more humanoid every day, but they still can’t be sued.
So a Hong Kong tycoon is doing the next best thing. He’s going after the salesman who persuaded him to entrust a chunk of his fortune to the supercomputer whose trades cost him more than $20 million.