Thursday, July 22, 2021

There are pros and cons, depending on what information is released and how quickly.

https://www.cnbc.com/2021/07/21/new-bill-would-make-some-companies-report-cyber-attacks-to-government.html

New bill would make some companies report cyberattacks to the government

The bipartisan Cyber Incident Notification Act is a response to the recent attacks on SolarWinds, which impacted government agencies, and Colonial Pipeline, which disrupted access to fuel across a large region of the country. Since then, ransomware attacks — where hackers encrypt files until a victim pays a ransom — have proliferated.

The problem is, under federal law, companies don’t have to report these attacks. That means some attacks may occur without the government knowing, which can have serious implications if the government’s own systems are affected by the hack. [I can only read this as “the government does not know when it has been hacked.” Bob]





Yes, it may be evil, but it’s profitable evil.

https://www.nytimes.com/2021/07/21/technology/clearview-ai-valuation.html

Clearview AI raises $30 million from investors despite legal troubles.

Clearview AI is currently the target of multiple class-action lawsuits and a joint investigation by Britain and Australia. That hasn’t kept investors away.

The New York-based start-up, which scraped billions of photos from the public internet to build a facial-recognition tool used by law enforcement, closed a Series B round of $30 million this month.

The investors, though undeterred by the lawsuits, did not want to be identified.





Just a reminder: There are far more computers than humans – welcome to the minority.

https://www.bespacific.com/justice-by-algorithm-are-artificial-intelligence-risk-assessment-tools-biased-against-minorities/

Justice by Algorithm: Are Artificial Intelligence Risk Assessment Tools Biased Against Minorities?

Conklin, Michael and Wu, Jun, Justice by Algorithm: Are Artificial Intelligence Risk Assessment Tools Biased Against Minorities? (June 30, 2021). Available at SSRN: https://ssrn.com/abstract=3877686 or http://dx.doi.org/10.2139/ssrn.3877686

“This is a review of Katherine B. Forrest’s new book When Machines Can Be Judge, Jury, and Executioner. The book does an excellent job discussing issues of fairness and racial disparities from the use of artificial intelligence risk assessment tools (hereinafter “AI”) for decisions such as pretrial release and likelihood of recidivism. This is a timely topic as the technology is currently a tipping point. While Europe has begun to implement protections for defendants regarding AI, the U.S. is increasing its reliance on AI without such safeguards. This review includes a discussion on the topics of how AI compares to human judge predictions and decisions, fairness and racial outcomes, how recidivism is frequently misunderstood and its relevance, how human decisions are inextricably intertwined with AI, and the proper understanding of an AI’s “error rate.”





Good question?

https://www.bespacific.com/what-is-legal-innovation/

What Is Legal Innovation?

Sandberg, Haim, What Is Legal Innovation? (March 17, 2021). 2021 University of Illinois Law Review online 63, Available at SSRN: https://ssrn.com/abstract=3806704

“Technological progress, along with the economic success it brings innovators, has transformed technological innovation into an object of admiration. The law supports and regulates technological and creative innovation in other fields, but is law itself an arena of innovation – of legal innovation? Do the concepts, doctrines, theories and techniques produced by the law encompass innovation? If so, does legal innovation share similar characteristics with other kinds of innovation? Can we learn something about the nature of legal innovation from the general field of innovation research? The legal discipline is more preoccupied with identifying innovation in other areas than in analyzing the characteristics of its own innovations. In this Essay I argue that legal innovation has similar characteristics to innovation in other areas, although it is no less impressive and influential. The phenomenon of legal innovation can and should attract more scientific attention.”





Is this innovation?

https://www.reuters.com/legal/transactional/disco-shares-jump-ceo-says-software-is-coming-legal-sector-2021-07-21/

As DISCO shares jump, CEO says 'software is coming' to legal sector

E-discovery provider CS Disco Inc made its public debut on the New York Stock Exchange on Wednesday, with shares jumping more than 28% over their opening price to close at $41.

The Austin-based company, which provides artificial intelligence-powered software for e-discovery, legal document review and case management to corporate legal departments and law firms, listed under the trading symbol "LAW."

"We think that software is coming to the legal function, that software will help automate away a lot of the services that have historically been used by legal departments and law firms," DISCO founder and CEO Kiwi Camara said in an interview as shares began trading Wednesday.





Unfortunately, many IT departments were reluctant to save (or even generate) log data because it was “big data.”

https://www.infoq.com/news/2021/07/AI-IT-operations/?utm_campaign=infoq_content&utm_source=infoq&utm_medium=feed&utm_term=news

Artificial Intelligence for IT Operations: an Overview

Artificial intelligence for IT operations (AIOps) combines sophisticated methods from deep learning, data streaming processing, and domain knowledge to analyse infrastructure data from internal and external sources to automate operations and detect anomalies (unusual system behavior) before they impact the quality of service. Odej Kao, professor at the University of Technology Berlin, gave a keynote presentation about artificial intelligence for IT operations at DevOpsCon Berlin 2021.

Log data is the most powerful source of information, widely available, and can be well-processed by AI-based prediction models, as Kao explained:





Looks like the market remains hot!

https://finance.yahoo.com/news/global-artificial-intelligence-market-expected-112200801.html

The Global Artificial Intelligence Market is expected to grow by $ 13.26 billion during 2021-2025, progressing at a CAGR of almost 47% during the forecast period

Reportlinker.com announces the release of the report "Global Artificial Intelligence Market in the Industrial Sector 2021-2025" - https://www.reportlinker.com/p04647367/?utm_source=GNW





Are all teachers of English doomed?

https://syncedreview.com/2021/07/21/deepmind-podracer-tpu-based-rl-frameworks-deliver-exceptional-performance-at-low-cost-66/

Google’s Wordcraft Text Editor Advances Human-AI Collaborative Story Writing

Neural language models are gaining popularity in real-life creative tasks such as text-adventure games, collaborative slogan writing, and even sports journalism, poetry and novel generation. Most such language models however provide limited interaction support for users, as control that goes beyond simple left-to-right text generation requires explicit training.

To address this limitation, a team from Google Research has proposed Wordcraft, a text editor with a built-in AI-powered creative writing assistant. Wordcraft leverages few-shot learning and the natural affordances of conversation to support a variety of user interactions; and can help with story planning, writing and editing.

The Wordcraft web interface comprises a traditional text editor augmented with a number of key commands for triggering requests to the AI assistant. The model is able to sketch a story outline, write the story and even perform editing and rewrites.





Tools & Techniques. (Not hacking tools!)

https://www.makeuseof.com/pdf-password-remover-tools/

6 PDF Password Remover Tools to Unlock PDF Files

Often PDF files, especially those downloaded from the internet, are protected by passwords. You're asked to enter the password each time you want to view the document. This is done to prevent the files from being opened, edited, and printed by unauthorized users.

However, it can be annoying for the rightful owner of the PDF to forget or lose the password. In such cases, you can use password remover tools to get access to your PDF documents.



Wednesday, July 21, 2021

If you didn’t know you were a victim, was someone lying to you?

https://www.cpomagazine.com/cyber-security/almost-all-organisations-suffered-at-least-one-data-breach-in-past-18-months-the-state-of-cloud-security-report-found/

Almost All Organisations Suffered At Least One Data Breach in Past 18 Months, The State of Cloud Security Report Found

Nearly 100% of organizations experienced a cloud data breach within the last 18 months, according to the cloud infrastructure security firm Ermetic.

The cloud data breach report also found that cloud security incidents increased by almost 20% within the past year.





Software for paranoids, which seems to be every country.

https://www.ft.com/content/24f22b28-56d1-4d66-8f76-c9020b1b5cb1

How Israel used NSO spyware as diplomatic calling card

… NSO’s Pegasus software, which requires a government licence for export because it is considered a weapon, has in recent years become a crucial part of Israel’s diplomatic outreach — a role that has come into focus after this weekend’s revelation by a consortium of newspapers that it had been traced to the cell phones of 37 journalists, lawyers and political activists. The software surreptitiously turns phones into listening devices while unveiling their encrypted contents.

“From the 1950s, Israel used its weapons sales for diplomatic gains, the only thing that changes is the names of the countries,” said Eitay Mack, an Israeli human rights lawyer who has tried for years to have NSO’s export licence cancelled. “The question is if there will be some change in the exports policy.”



(Related) You can’t be very important if no one is trying to spy on you. This might just be bragging for political advantage.

https://threatpost.com/french-launch-nso-probe-after-macron-believed-spyware-targe/167986/

French Launch NSO Probe After Macron Believed Spyware Target

French lawmakers have launched an investigation into Israeli offensive cybersecurity company NSO Group after they learned French President Emmanuel Macron topped a list of 14 heads of states potentially targeted by the company’s spyware.

Amnesty International said Tuesday the French leader was a potential spyware target, along with presidents Imran Khan of Pakistan, Cyril Ramaphosa of South Africa and Barham Salih of Iraq. Heads of state, including the prime ministers and the king of Morocco, Mohammed VI, were also high-profile potential targets of NSO’s software known as Pegasus.





One of its largest selling points was anonymity.

https://www.bbc.com/news/technology-57901113

EU plans to make Bitcoin transfers more traceable

Proposed changes to EU law would force companies that transfer Bitcoin or other crypto-assets to collect details on the recipient and sender.

The proposals would make crypto-assets more traceable, the EU Commission said, and would help stop money-laundering and the financing of terrorism.

The new rules would also prohibit providing anonymous crypto-asset wallets.





Faster development, larger liability?

https://www.consumerreports.org/car-safety/tesla-full-self-driving-beta-software-lacks-safeguards-a6698414036/

Tesla’s ‘Full Self-Driving’ Beta Software Used on Public Roads Lacks Safeguards

Consumer Reports' car safety experts worry that Tesla continues to use vehicle owners as beta testers for its new features, putting others on the road at risk

After Tesla released the latest prototype version of its driving assistance software last week, reports from owners have gained the attention of researchers and safety experts—both at CR and elsewhere—who have expressed concerns about the system’s performance and safety.

CR plans to independently test the software update, popularly known as FSD beta 9, as soon as our Model Y SUV receives the necessary software update from Tesla. So far, our experts have watched videos posted on social media of other drivers trying it out and are concerned with what they’re seeing—including vehicles missing turns, scraping against bushes, and heading toward parked cars. Even Tesla CEO Elon Musk urged that drivers use caution when using FSD beta 9, writing on Twitter that “there will be unknown issues, so please be paranoid.”





AI is like the mumbo-jumbo of the Shaman: of course I don’t understand, I have no magic!

https://www.statnews.com/2021/07/21/explainable-medical-ai-easier-said-than-done/

Explaining medical AI is easier said than done

The growing use of artificial intelligence in medicine is paralleled by growing concern among many policymakers, patients, and physicians about the use of black-box algorithms. In a nutshell, it’s this: We don’t know what these algorithms are doing or how they are doing it, and since we aren’t in a position to understand them, they can’t be trusted and shouldn’t be relied upon.

A new field of research, dubbed explainable artificial intelligence (XAI), aims to address these concerns. As we argue in Science magazine, together with our colleagues I. Glenn Cohen and Theodoros Evgeniou, this approach may not help and, in some instances, can hurt.





Resources.

https://www.makeuseof.com/websites-find-statistics/

7 Great Websites to Find Statistics



Tuesday, July 20, 2021

Reiterate until repetition becomes redundant.

https://www.cpomagazine.com/cyber-security/what-to-do-when-your-organization-become-the-victim-of-a-phishing-attack/

What To Do When Your Organization Become the Victim of a Phishing Attack

… Detecting and preventing all the various types of threats known and unknown is nearly impossible. What needs to happen when a company, device or person is victimized? Here are steps that can help mitigate the damage.



(Related)

https://krebsonsecurity.com/2021/07/dont-wanna-pay-ransom-gangs-test-your-backups/

Don’t Wanna Pay Ransom Gangs? Test Your Backups.

Browse the comments on virtually any story about a ransomware attack and you will almost surely encounter the view that the victim organization could have avoided paying their extortionists if only they’d had proper data backups. But the ugly truth is there are many non-obvious reasons why victims end up paying even when they have done nearly everything right from a data backup perspective.

… Experts say the biggest reason ransomware targets and/or their insurance providers still pay when they already have reliable backups is that nobody at the victim organization bothered to test in advance how long this data restoration process might take.

“In a lot of cases, companies do have backups, but they never actually tried to restore their network from backups before, so they have no idea how long it’s going to take,” said Fabian Wosar, chief technology officer at Emsisoft. “Suddenly the victim notices they have a couple of petabytes of data to restore over the Internet, and they realize that even with their fast connections it’s going to take three months to download all these backup files. A lot of IT teams never actually make even a back-of-the-napkin calculation of how long it would take them to restore from a data rate perspective.”





Perhaps there are a few ‘innocent’ people left in the world.

https://www.theguardian.com/news/2021/jul/18/huge-data-leak-shatters-lie-innocent-need-not-fear-surveillance

Huge data leak shatters the lie that the innocent need not fear surveillance

Billions of people are inseparable from their phones. Their devices are within reach – and earshot – for almost every daily experience, from the most mundane to the most intimate.

Few pause to think that their phones can be transformed into surveillance devices, with someone thousands of miles away silently extracting their messages, photos and location, activating their microphone to record them in real time.

Such are the capabilities of Pegasus, the spyware manufactured by NSO Group, the Israeli purveyor of weapons of mass surveillance.

NSO rejects this label. It insists only carefully vetted government intelligence and law enforcement agencies can use Pegasus, and only to penetrate the phones of “legitimate criminal or terror group targets”.

Yet in the coming days the Guardian will be revealing the identities of many innocent people who have been identified as candidates for possible surveillance by NSO clients in a massive leak of data.

Without forensics on their devices, we cannot know whether governments successfully targeted these people. But the presence of their names on this list indicates the lengths to which governments may go to spy on critics, rivals and opponents.



(Related)

https://techcrunch.com/2021/07/19/toolkit-nso-pegasus-iphone-android/

This tool tells you if NSO’s Pegasus spyware targeted your phone

… The Mobile Verification Toolkit, or MVT, works on both iPhones and Android devices, but slightly differently. Amnesty said that more forensic traces were found on iPhones than Android devices, which makes it easier to detect on iPhones.





At least, a way to start a privacy conversation.

https://www.pcmag.com/picks/essential-apps-for-protecting-your-privacy-online

11 Essential Apps for Protecting Your Privacy Online





A privacy tool!

https://www.theverge.com/2021/7/20/22576352/duckduckgo-email-protection-privacy-trackers-apple-alternative?scrolla=5eb6d68b7fedc32c19ef33b4

DuckDuckGo launches new Email Protection service to remove trackers

… The company’s new Email Protection feature gives users a free “@duck.com” email address, which will forward emails to your regular inbox after analyzing their contents for trackers and stripping any away. DuckDuckGo is also extending this feature with unique, disposable forwarding addresses, which can be generated easily in DuckDuckGo’s mobile browser or through desktop browser extensions.

The personal DuckDuckGo email is meant to be given out to friends and contacts you know, while the disposable addresses are better served when signing up for free trials, newsletters, or anywhere you suspect might sell your email address. If the email address is compromised, you can easily deactivate it.





Anything worth stealing?

https://www.pogowasright.org/50-state-survey-of-health-care-information-privacy-laws/

50-State Survey of Health Care Information Privacy Laws

Seyfarth Shaw LLP has made a resource freely available:

Seyfarth is pleased to provide you with our 50-State Survey of Health Care Information Privacy Laws.
The world continues to struggle with the impacts of the COVID-19 pandemic, and pressures mount on health care organizations to properly share personal health information. While resources abound on how federal rules such as HIPAA may apply to sharing personal health information, there appear few such resources on how state privacy laws apply. Meanwhile, the challenge to maintain compliance, avoid data breaches, and make decisions on what (or should) be shared with others remains ever-present and more acute than ever. For that purpose, we have created this resource to better assist you and your business identify and mitigate potential issue areas. Download a copy of the Survey here.





The argument continues. Will we wind up with a new definition of “public?”

https://www.pogowasright.org/clearviews-face-surveillance-still-has-no-first-amendment-defense/

Clearview’s Face Surveillance Still Has No First Amendment Defense

A commentary by Adam Schwartz on EFF last week begins:

Clearview AI extracts faceprints from billions of people, without their consent, and uses these faceprints to help police identify suspects. This does grave harm to privacy, free speech, information security, and racial justice. It also violates the Illinois Biometric Information Privacy Act (BIPA ), which prohibits a company from collecting a person’s biometric information without first obtaining their opt-in consent.
Clearview now faces many BIPA lawsuits. One was brought by the ACLU and ACLU of Illinois in state court. Many others were filed against the company in federal courts across the country, and then consolidated into one federal courtroom in Chicago. In both Illinois and federal court, Clearview argues that the First Amendment bars these BIPA claims.

Read more on EFF.





Alternative AI?

https://theconversation.com/artificial-intelligence-governments-see-huge-business-potential-but-ignore-the-downsides-164645

Artificial intelligence: governments see huge business potential, but ignore the downsides

Many governments are increasingly approaching artificial intelligence with an almost religious zeal. By 2018 at least 22 countries around the world, and also the EU, had launched grand national strategies for making AI part of their business development, while many more had announced ethical frameworks for how it should be allowed to develop. The EU documents more than 290 AI policy initiatives in individual EU member states between 2016 and 2020.

The latest is Ireland, which has just announced its national AI strategy, “AI – Here for Good”. It aims to become “an international leader in using AI to benefit our economy and society, through a people-centred, ethical approach to its development, adoption and use”.



(Related)

https://www.bespacific.com/artificial-intelligence-an-accountability-framework-for-federal-agencies-and-other-entities/

Artificial Intelligence: An Accountability Framework for Federal Agencies and Other Entities

Artificial Intelligence: An Accountability Framework for Federal Agencies and Other Entities GAO-21-519SP Published: Jun 30, 2021. “As a nation, we have yet to grasp the full benefits or unwanted effects of artificial intelligence. AI is widely used, but how do we know it’s working appropriately? This report identifies key accountability practices—centered around the principles of governance, data, performance, and monitoring—to help federal agencies and others use AI responsibly. For example, the governance principle calls for users to set clear goals and engage with diverse stakeholders. To develop these practices, we held a forum on AI oversight with experts from government, industry, and nonprofits. We also interviewed federal inspector general officials and AI experts.”





Worth grabbing some bits and pieces.

https://blogs.microsoft.com/ai-for-business/hax-toolkit/

New toolkit aims to help teams create responsible human-AI experiences

Microsoft has released the Human-AI eXperience (HAX) Toolkit, a set of practical tools to help teams strategically create and responsibly implement best practices when creating artificial intelligence technologies that interact with people.

The toolkit comes as AI-infused products and services, such as virtual assistants, route planners, autocomplete, recommendations and reminders, are becoming increasingly popular and useful for many people. But these applications have the potential to do things that aren’t helpful, like misunderstand a voice command or misinterpret an image. In some cases, AI systems can demonstrate disruptive behaviors or even cause harm.

Such negative outcomes are one reason AI developers have pushed for responsible AI guidance. Supporting responsible practices has traditionally focused on improving algorithms and models, but there is a critical need to also make responsible AI resources accessible to the practitioners who design the applications people use. The HAX Toolkit provides practical tools that translate human-AI interaction knowledge into actionable guidance.





Tools & Techniques.

https://www.makeuseof.com/free-teleprompter-apps-read-scripts-shooting-videos-hosting-webinars/

5 Free Teleprompter Apps to Read Scripts While Shooting Videos or Hosting Webinars



Monday, July 19, 2021

Kind of a slow day…


Is it cyberwar yet? Or is this just one more straw? Do we have a ‘line in the sand?’

https://www.cnn.com/2021/07/19/politics/us-china-cyber-offensive/index.html

US blames China for hacks, opening new front in cyber offensive

The United States and its foreign allies on Monday accused China of widespread malfeasance in cyberspace, including through a massive hack of Microsoft's email system and other ransomware attacks, a dramatic escalation in the increasingly urgent attempt by the Biden administration to stave off further breaches.

In a coordinated announcement, the White House and governments in Europe and Asia identified China's Ministry of State Security, the sprawling and secretive civilian intelligence agency, with using "criminal contract hackers" [Cyber-mercenaries Bob] to conduct a range of destabilizing activities around the world for personal profit, including the Microsoft hack, according to a senior US administration official.

The administration official also said China was behind a specific ransomware attack against a US target that involved a "large ransom request" — and added that Chinese ransom demands have been in the "millions of dollars."

The public disclosure of the Chinese efforts amounts to a new front in an ongoing offensive by the Biden administration to bat away cyberthreats that have exposed serious vulnerabilities in major American sectors, including energy and food production. The extent of Chinese involvement in hiring criminal networks to invade and extort money around the world came as a surprise to the White House, officials said.





A modest overview.

https://www.makeuseof.com/how-secure-are-biometrics/

Just How Secure Are Biometrics?

Biometrics concerns examining something unique to an individual’s body to determine whether to grant them access to a building, device, or sensitive files. Some of the most common biometric systems analyze people’s fingerprints, faces, or parts of their eyes.

These measures intend to tighten security. Do they succeed, and are there associated risks? Can you really trust biometrics?



Sunday, July 18, 2021

It is far less painful to learn from the mistakes of others. (Unfortunately, it is also far less likely.)

https://www.databreaches.net/state-audits-of-school-district-it-reveal-why-k-12-districts-are-sitting-ducks-for-threat-actors/

State audits of school district IT reveal why k-12 districts are sitting ducks for threat actors

On July 15, New York State Comptroller Thomas P. DiNapoli released the following school district audits. Clicking on the links will take you to the fuller reports, but even then, some things were so bad, it seems, that findings were told to the districts, but not put in writing in public reports that threat actors might see.

Watervliet City School District – Information Technology (Albany County)
The board and district officials did not ensure the information technology (IT) assets and data were safeguarded. Officials did not establish written procedures for managing, limiting and monitoring user accounts. Auditors determined officials also did not disable 72 unneeded network accounts in a timely manner. Officials also did not monitor compliance with the acceptable computer use policy. As a result, 12 of 13 computers auditors tested accessed nonbusiness websites prohibited by the policy. Sensitive IT control weaknesses were communicated confidentially to officials.
Westhill Central School District – Information Technology (Onondaga County)
District officials did not implement adequate information technology (IT) controls over the district office’s network to safeguard personal, private and sensitive information. District officials also did not monitor employee internet use. Auditors found eight of 10 employees’ computers they reviewed were used for personal internet activity. District officials did not properly manage network user accounts. Auditors examined all 31 enabled network user accounts on the district office domain controller. Six unneeded network user accounts, seven shared user accounts and three user accounts were found with unneeded administrative permissions. In addition, district officials did not provide formalized IT security awareness training to staff. Sensitive IT control weaknesses were communicated confidentially to district officials.





No good deed… Sounds good from the Security side, but new zero-days are also new attack points for cyber war.

https://www.databreaches.net/chinas-new-law-requires-researchers-to-report-all-zero-day-bugs-to-government/

China’s New Law Requires Researchers to Report All Zero-Day Bugs to Government

Ravie Lakshmanan reports:

The Cyberspace Administration of China (CAC) has issued new stricter vulnerability disclosures regulations that mandate security researchers uncovering critical flaws in computer systems to mandatorily disclose them first-hand to the government authorities within two days of filing a report.
The “Regulations on the Management of Network Product Security Vulnerability” are expected to go into effect starting September 1, 2021, and aim to standardize the discovery, reporting, repair, and release of security vulnerabilities and prevent security risks.

Read more on The Hacker News.





Real lawyers thought of this? Sounds like one of those AI writers that still need some tweaking. In all cases; Yes, it is appropriate!

https://www.databreaches.net/the-new-minimization-technique-for-breach-disclosures/

The new minimization technique for breach disclosures?

Remember when “We take your privacy and security very seriously” became de rigueur in breach disclosures? Now there’s other language being frequently added to breach disclosures — language that makes it sound like what the entity is about to tell you is really no huge deal, but if you feel you really need to protect yourself, they’ll tell you what you can do.

Here are just a few recent examples, culled from recent disclosures I read:

The following notice includes information about the event, steps taken since discovering the event, and resources available to help individuals protect against potential misuse of their information, should they feel it is appropriate to do so. — Campbell Conroy & O’Neil law firm, disclosing a ransomware incident.


This notification provides information about the event, PCHC’s response to it, and resources available to individuals to help protect their information, should they feel it necessary to do so. — Peoples Community Health Clinic, disclosing hack of an employee’s email account.


While Unity is unaware of any attempted or actual misuse of information in relation to incident, Unity is providing potentially affected individuals with information about the incident and steps individuals may take to help protect their information should they feel it is necessary to do so. — Unity National Bank, disclosing hack of an employee’s email account


Although Diamond Foods is unaware of any attempted or actual misuse of information in relation to incident, Diamond Foods is providing potentially affected individuals with information about the incident and steps individuals may take to help protect their information should they feel it is necessary to do so. — Diamond Foods LLC, disclosing both a hack of its network and the incidental discovery that an employee’s email account had also been compromised previously

What are you — a wuss if you feel it is necessary to protect yourself?

I really don’t like the inclusion of such language in breach disclosures.





Testimony: Subcommittee on Crime, Terrorism, and Homeland Security

https://www.cato.org/testimony/facial-recognition-technology-examining-its-use-law-enforcement

Facial Recognition Technology: Examining Its Use by Law Enforcement

Although facial recognition has been available for decades in one form or another, recent improvements in the technology and the plethora of private and public images related to law abiding citizens means that left unchecked it poses an unprecedented risk to Americans’ privacy.

… I believe that it is possible to craft regulations and legislation that would address the most worrying uses of facial recognition technology without hampering innovation. Below, I will highlight why I think such regulation and legislation are necessary before providing an overview of specific policy recommendations.





Worth a trip to the library?

https://www.taylorfrancis.com/chapters/edit/10.1201/9781003097204-13/iot-security-privacy-issues-atheer-almogbil

IoT Security and Privacy Issues

Book: Artificial Intelligence and Internet of Things

The term “Internet of things” (IoT) was coined by Kevin Ashton in 1999 as a network of physical devices communicating with each other via the Internet. Numerous devices that were once basic household appliances are now a part of an interconnected network of smart devices like computing, storing and exchanging information. The rise in the use of IoT devices in the medical, financial and infrastructural sectors as well as in household uses means that these devices handle as well as transmit sensitive information. Ideally, such sensitive information should be adequately protected at rest and during transmission. However, the rapid emergence of IoT devices, driven by the race of introducing an innovative IoT solution to the market, has caused the security of such devices to become an afterthought. Consequently, the security and privacy of IoT has become a game of catch-up. This has created a plethora of opportunities for an attacker, whether state-sponsored or not, to feasibly attack an entire nation with two simple lines of code. Ultimately, the lack of security and privacy measures in IoT devices has previously threatened and will continuously threaten individual, economic and homeland security across the globe.

… First, IoT security issues such as identification, device heterogeneity, default credentials, integrity and authentication are explored. Then privacy issues in IoT including but not limited to eavesdropping confidentiality and authorization are discussed. The chapter then moves on to speak about potential solutions and measures that are suggested to decrease the risk and impact of the exploitation of previously discussed IoT vulnerabilities.





If you are thinking of trading cryptocurrencies, have I got a deal for you!

https://dilbert.com/strip/2021-07-18