Thursday, January 13, 2022

Increasing the awareness of state actors so when we do retaliate it won’t come as a total surprise?

https://therecord.media/cyber-command-ties-hacking-group-to-iranian-intelligence/

Cyber Command ties hacking group to Iranian intelligence

U.S. Cyber Command on Wednesday revealed that a hacking group reputed for its cyberespionage campaigns is actually part of Iran’s intelligence apparatus.

The group, known as MuddyWater, is a subordinate element within the Iranian Ministry of Intelligence and Security, the command’s Cyber National Mission Force announced.

The claim marked the first time the U.S. government has publicly linked the prolific threat actor — whose targets have ranged from academia and the tourism industry to government and telecommunications operators — to Tehran’s regime.



Any relation to yesterday’s shutdown of a New Mexico prison? (The article says no.)

https://www.databreaches.net/schools-out-as-cyberattack-forces-albuquerque-public-schools-to-cancel-classes/

School’s out as cyberattack forces Albuquerque Public Schools to cancel classes

Olivier Uytterbrouck and Jessica Dyer report:

A cyberattack against Albuquerque Public Schools prompted the state’s largest district to cancel all classes districtwide on Thursday and possibly Friday.
APS Superintendent Scott Elder said the attack was discovered Wednesday morning “when teachers tried to log onto our student information system and were unable to gain access to the site.”

Read more at Albuquerque Journal.



Not uncommon. If this was not a government agency, heads would be rolling!

https://www.databreaches.net/south-african-justice-department-clueless-about-hacked-data/

South African justice department clueless about hacked data

It’s not exactly the headline you’d want for your agency, but that’s what MyBroadband came up with for this report by Myles Illidge:

The Department of Justice and Constitutional Development (DoJ&CD) has no idea whether any data was stolen during a ransomware attack on its systems in September 2021.
“The Department cannot tell with certainty as to what happened to the compromised information,” justice minister Ronald Lamola said in response to written questions from the DA’s Glynnis Breytenbach.
“As at 1 December 2021, the analysis and/or forensic investigation is still inconclusive in terms of the exact nature of the information that was sent outside of the Department as part of the breach,” Lamola stated.

Read more at MyBroadband.

The more of the report I read, the more accurate the headline actually sounds. The government did not try to decrypt the encrypted files because they did not have the decryption key. It is not clear if they every reached out to NoMoreRansonware to see if there was any help to be had, but they report that they were able to restore from backups anyway.

Does anyone know who the threat actors were or the type of ransomware in this case?


(Related) Wouldn’t you like to have some indication of who was accessing your data? I was producing a report like that back in the 1990s.

https://www.databreaches.net/hackers-raided-panasonic-server-for-months-stealing-personal-data-of-job-seekers/

Hackers Raided Panasonic Server for Months, Stealing Personal Data of Job Seekers

Graham Cluley writes:

Tech giant Panasonic has confirmed that one of its servers suffered a data breach which saw the personal information of job applicants accessed by an unauthorised party.
The security breach, which saw hackers illegally access a Panasonic file server located in Japan via an overseas subsidiary, began on June 22 2021, and only ended on November 3 2021.

Read more at Bitdefender.


(Related) How about a report that shows who created files. Would you notice someone who did not work for your organization?

https://www.databreaches.net/the-ripta-data-breach-may-provide-valuable-lessons-about-data-collection-and-retention/

The RIPTA Data Breach May Provide Valuable Lessons About Data Collection and Retention

Joseph J. Lazzarotti of JacksonLewis writes:

Efforts to secure systems and data from a cyberattack often focus on measures such as multifactor authentication (MFA), endpoint monitoring solutions, antivirus protections, and role-based access management controls, and for good reason. But there is a basic principle of data protection that when applied across an organization can significantly reduce the impact of a data incident – the minimum necessary principle. A data breach reported late last year by the Rhode Island Public Transit Authority (RIPTA) highlights the importance of this relatively simple but effective tool.
In December 2021, RIPTA sent notification of a data breach to several thousand individuals who were not RIPTA employees. Reports of the incident prompted inquiries from a state Senator in Rhode Island, Louis P. DiPalma, and union officials who represented the affected individuals. According to Rhode Island’s Department of Administration (DOA), a forensic analysis conducted in connection with the incident indicates the affected files included health plan billing records pertaining to State of Rhode Island employees, not RIPTA employees. The DOA goes on to state that:
[s]tate employee data was incorrectly shared with RIPTA by an external third party who had responsibility for administering the state’s health plan billing.

Read more at Workplace Privacy, Data Management & Security Report.



How would you identify eligible young people without getting personal?

https://www.pogowasright.org/uk-scotland-young-persons-free-bus-travel-scheme-is-it-your-papers-please-time/

UK: Scotland young persons’ free bus travel scheme — is it “Your papers, please!” time?

Katie Williams reports:

Anyone under 22 can now apply for free bus travel.
The Free Bus Travel Scheme will come into force on January 31 and allow young people to travel on buses for free.
However people have taken to social media to express their frustration after users claimed the website kept crashing.
Others have criticised the online application process, which also requires scanning the applicant’s face, could be a potential barrier.

Read more at Edinburgh Live. As The Times reports in related coverage:

Applying under the new young persons’ free bus travel scheme has led to complaints about having to supply biometric face scans, as well as images of passports and birth certificates.


(Related) Identity via your phone? Another avenue to paperless?

https://techcrunch.com/2022/01/12/merit-grabs-50m-series-b-to-expand-digital-credentials-platform/

Merit grabs $50M Series B to expand digital credentials platform

When we think about identity in the digital world, it usually involves a username and password, but Merit (originally called Sigma) wants to help governments issue digital credentials that link back to a government license database with the goal of bringing an end to flimsy paper cards.

… A driver’s license is proof that the state gives you the right to drive, but one that is delivered in the analog form of a plastic card. Merit wants to change that by moving these credentials into the digital realm and linking them to a government database.



Another challenge for Google?

https://techcrunch.com/2022/01/12/austrian-dpa-schrems-ii/

In bad news for US cloud services, Austrian website’s use of Google Analytics found to breach GDPR

A decision by Austria’s data protection watchdog upholding a complaint against a website related to its use of Google Analytics does not bode well for use of US cloud services in Europe.

The decision raises a big red flag over routine use of tools that require transferring Europeans’ personal data to the US for processing — with the watchdog finding that IP address and identifiers in cookie data are the personal data of site visitors, meaning these transfers fall under the purview of EU data protection law.

In this specific case, an IP address “anonymization” function had not been properly implemented on the website. But, regardless of that technical wrinkle, the regulator found IP address data to be personal data given the potential for it to be combined — like a “puzzle piece” — with other digital data to identify a visitor.

Consequently the Austrian DPA found that the website in question — a health focused site called netdoktor.at, which had been exporting visitors’ data to the US as a result of implementing Google Analytics — had violated Chapter V of the EU’s General Data Protection Regulation (GDPR), which deals with data transfers out of the bloc.



Can you think of a reason not to use the free parts of these tools? Share with students and clients?

https://www.pcworld.com/article/553284/5-free-privacy-tools-for-protecting-your-personal-data.html

5 free privacy tools for protecting your personal data

Ideally, protecting your privacy shouldn’t require hours of time or gobs of money. Instead of having to meticulously manage all the personal data that’s floating around on the internet, you should be able to minimize data collection automatically or proactively. If you value privacy like I do, you’ll want to check out the following apps and tools. While some have premium versions for certain features, all of them are free to use:


(Related)

https://www.cpomagazine.com/data-privacy/us-government-issues-warning-on-spyware-for-hire-commercial-surveillance-tools/

US Government Issues Warning on “Spyware for Hire” Commercial Surveillance Tools

… The spyware warning, issued by the National Counterintelligence and Security Center, did not name any specific surveillance tools (in spite of the Biden administration’s previous blacklist actions against NSO Group and several other similar services). But it does specify that the tools are being sold to foreign governments and other entities that have used them to track the movements and communications of dissidents and journalists, and that mobile devices can be infected without the target having to take any action.

The notice also warns about the extensive capabilities that have been seen with the Pegasus spyware: the ability to access and exfiltrate “virtually all content” from a device, and to surreptitiously record audio. Among other things, the notice advises that device cameras be covered up and that geo-location be disabled.



Practice where the laws are more surveillance friendly?

https://gizmodo.com/the-fbis-honeypot-phones-were-more-widely-distributed-i-1848345566

The FBI's Honeypot Phones Were More Widely Distributed in the U.S. Than Previously Thought

… During “Operation Trojan Shield,” the feds used a secret relationship with an encrypted phone company, called Anom, which sold devices exclusively to career criminals looking for a secure way to communicate with one another. The product’s developer, who had previously been busted for drug trafficking, agreed to act as a high-level federal informant and for at least two years sold devices to criminals while also secretly cooperating with authorities. Meanwhile the FBI, along with its international partners, intercepted all of the communications, which allowed them to capture evidence of widespread criminal malfeasance on a global scale.

… But there was one place that didn’t see any arrests, and that’s the United States. Due to legal issues, the FBI precluded surveillance of American users of the backdoored devices, apparently because they were concerned that the operation technically violated U.S. laws and threatened civil liberties—specifically the Fourth Amendment, which prohibits police search and seizure without a warrant. While a court filing revealed that at least 15 people located in the U.S. were known users of the trojanized devices, these individuals were said to have been geofenced by authorities conducting surveillance—meaning they were left out of the investigation.



It works both ways…

https://www.bespacific.com/law-enforcement-and-technology-using-social-media/

Law Enforcement and Technology: Using Social Media

CRS Report – Law Enforcement and Technology: Using Social Media, January 11, 2022: “As the ways in which individuals interact continue to evolve, social media has had an increasing role in facilitating communication and the sharing of content online—including moderated and unmoderated, user-generated content. Over 70% of U.S. adults are estimated to have used social media in 2021. Law enforcement has also turned to social media to help in its operations. Broadly, law enforcement relies on social media as a tool for information sharing as well as for gathering information to assist in investigations…”

[From the paper:

There are no federal laws that specifically govern law enforcement agencies’ use of information obtained from social media sites, but their ability to obtain or use certain information may be influenced by social media companies’ policies as well as law enforcement agencies’ own social media policies and the rules of criminal procedure.



Someone has been thinking about AI.

https://www.climate-kic.org/in-detail/artificial-intelligence-business-models-and-taxonomy-in-europe/

Artificial intelligence business models and taxonomy in Europe

With its ability to drive productivity and economic development, artificial intelligence (AI) is already having a huge impact on our lives. But what are the AI business models in Europe? What AI landscape exists across Europe? What is AI’s impact in several sectors and on climate? And how do we talk about AI in the European AI Ecosystem?

… The first-mentioned report “Emerging AI and Data Driven Business Models in Europe” is taking stock of the state of AI in the KICs’ innovation, education and business creation ecosystems. In summary, this report contains the results of surveys and a desk research study including:

https://ai.eitcommunity.eu/assets/docs/EIT-UrbanMobility-Emerging-AI-and-Data-Driven-Business-Models-in-Europe.pdf

… The “Creation of a Taxonomy for the European AI Ecosystem” report addresses the risk of losing oversight and efficiency in several AI activities, reports and the AI landscape. 35 existing frameworks have been scanned and analysed. The developed AI taxonomy is compatible with existing ones as long as they haven’t used incorrect or inconsistent clusters or categories.

https://ai.eitcommunity.eu/assets/docs/EIT-ClimateKIC-Creation-of-a-taxonomy-for-the-European-AI-ecosystem.pdf


(Related)

https://www.brookings.edu/blog/techtank/2022/01/12/how-countries-are-leveraging-computing-power-to-achieve-their-national-artificial-intelligence-strategies/

How countries are leveraging computing power to achieve their national artificial intelligence strategies

… As such, much of the development of AI is predicated on two pillars: technologies and human capital availability. Our prior reports for Brookings, “How different countries view artificial intelligence” and “Analyzing artificial intelligence plans in 34 countries,” detailed how countries are approaching national AI plans, and how to interpret those plans. In a follow-up piece, “Winners and losers in the fulfillment of national artificial intelligence aspirations,” we discussed how different countries were fulfilling their aspirations along technology-oriented and people-oriented dimensions. In our most recent post, “The people dilemma: How human capital is driving or constraining the achievement of national AI strategies,” we discussed the people dimension and so, in this piece, we will examine how each country is prepared to meet their AI objectives in the second pillar—the technology dimension.



Helpful, but I’m still not sure I understand the “new” definitions of anti-trust.

https://www.makeuseof.com/monopoly-or-market-leader/

Monopoly or Market Leader: Looking Into Today's Biggest Companies

You'd be surprised how frequently people throw around the term "monopoly" for companies like Google, Facebook, and Amazon.

However, neither of the companies are monopolies. So, let's tackle some common misconceptions and figure out what a monopoly is and whether it matches your idea of it.

To constitute a monopoly, a company has to dominate its market and become the only option for its consumers. As per the definition, an "absence of competition" is a must.


Wednesday, January 12, 2022

Warfare has progressed(?) from lines of warriors with spears to shooting from concealment to bombing civilian targets and now to attacks which could impact every citizen. What is the proper response?

https://thehackernews.com/2022/01/fbi-nsa-and-cisa-warns-of-russian.html

FBI, NSA and CISA Warns of Russian Hackers Targeting Critical Infrastructure

Amid renewed tensions between the U.S. and Russia over Ukraine and Kazakhstan, American cybersecurity and intelligence agencies on Tuesday released a joint advisory on how to detect, respond to, and mitigate cyberattacks orchestrated by Russian state-sponsored actors.

To that end, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA) have laid bare the tactics, techniques, and procedures (TTPs) adopted by the adversaries, including spear-phishing, brute-force, and exploiting known vulnerabilities to gain initial access to target networks.



Perhaps connecting everything on a single network isn’t the best plan?

https://gizmodo.com/new-mexico-jail-forced-into-lockdown-after-cyberattack-1848342078

New Mexico Jail Forced Into Lockdown After Cyberattack Incapacitates Cameras, Doors

A suspected ransomware attack in New Mexico has incapacitated services for an entire county, including the local jail—which frighteningly lost access to its camera feeds, facility databases, and automated doors.

Bernalillo County, which is the most populous in the state and includes its largest city, Albuquerque, was thrown into chaos last week when the cyberattack hobbled services across the government. The attack, which took place on Jan. 5, forced the closure of county offices, threatened databases, and caused major problems for the processing of everything from local property deals to marriage licenses, all of which rely on the county’s network.

… Most dramatically, the county’s Metropolitan Detention Center lost access to some of its key security features—including its camera feeds and its automated jail doors. For obvious safety reasons, this forced the county to lock down the entire jail, forcing all of the prisoners into their cells for the foreseeable future.

The Verge reports that the lockdown also spurred a minor legal kerfuffle, as it put the county in potential violation of the terms of a 1995 lawsuit settlement concerning confinement conditions at the jail. That settlement mandated that prisoners be given certain privileges—such as guaranteed time outside of cells and access to communication devices, such as phones. Some of those privileges can’t be accommodated during the current circumstances and, as a result, the county was forced to file an emergency notice in federal court last week, asking the court to consider its outstanding “emergency” circumstances.



I wonder if these are the only hospitals in the entire country that do this?

https://www.pogowasright.org/mass-general-brigham-dana-farber-to-pay-18-4m-settlement-over-privacy-allegations/

Mass General Brigham, Dana-Farber to pay $18.4M settlement over privacy allegations

Jessica Bartlett reports:

Mass General Brigham and Dana-Farber Cancer Institute have agreed to pay a combined $18.4 million settlement over allegations that the institutions fed personally identifiable information about patients to Facebook, Google and other companies.
The class-action lawsuit was filed by two anonymous parties in Suffolk Superior Court in May 2019. The suit alleged that despite numerous privacy assurances on the websites of Massachusetts General Hospital, Brigham and Women’s Hospital and Dana-Farber, the three hospitals disclosed patient information to third-party websites and marketing companies.

Read more at Boston Business Journal.



There’s no reaction like overreaction.

https://thenextweb.com/news/eus-plans-to-tackle-child-sexual-abuse-material-csam-spark-surveillance-concerns

EU plans to tackle online child abuse spark surveillance concerns

The scale of child sexual exploitation and abuse online is increasing at an alarming rate. The Internet Watch Foundation (IWF) recently announced that it’s finding more finding 15 times as much child sexual abuse material (CSAM) online as it was a decade ago.

This content is particularly prevalent in Europe. According to a 2020 report by the IWF, most web pages hosting CSAM are based in the continent. In response, the European Union plans to introduce stricter rules on tech firms that host the material.

“I will propose legislation in the coming months that will require companies to detect, report, and remove child sexual abuse,” EU home affairs commissioner Ylva Johansson told Germany’s Welt am Sonntag on Sunday.

… the EU’s strategy seems to be to cast a dangerously wide net, proposing measures which might force service providers to scan each and every person’s private messages.”



Should we assume the patients want to be unidentified?

https://www.pogowasright.org/hospitals-could-gain-new-tools-to-id-unidentified-patients/

Hospitals could gain new tools to ID unidentified patients

I missed this one over the holiday week. Thankfully, Joe Cadillic didn ‘t miss it. Jesse Scheckner reported:

A bill filed in the Florida House this week would allow law enforcement agencies to help hospitals identify unidentified patients and empower social workers to make decisions about patients’ continued care.
HB 1021, which Republican Rep. Juan Fernandez-Barquin of Miami-Dade County filed Monday, would add language to Florida Statute clearing the way for the Florida Department of Law Enforcement and local police agencies to use available biometric tools to identify “otherwise unidentifiable” patients.

Read more at Florida Politics.



Will someone ask who failed to secure the data in the first place?

https://www.databreaches.net/a-missouri-reporter-is-still-getting-blamed-for-the-security-flaw-he-exposed/

A Missouri Reporter Is (Still) Getting Blamed For the Security Flaw He Exposed

Jack Gillum sought — and obtained — some records from Missouri Governor Parson’s office concerning the governor’s staff’s public statements and the governor’s intention to try to prosecute journalist Josh Renaud. Renaud’s crime: he discovered a vulnerability on a state website where by clicking the F12 key to view the source of a page, one could see teachers’ social security numbers exposed in plain text. Renaud verified his discovery and then notified the state, delaying publication until the state could secure the data.

Instead of thanking the reporter and his newspaper — as the state initially planned to do — the governor did an about-face and called the journalist a “hacker” and is pushing to have him prosecuted under a state law.

Nothing has changed since the story first made news in October. The governor continues to insist that the reporter is likely to be prosecuted, while most members of the press and researchers point out the dangerous situation that would result — where people will be afraid to disclose vulnerabilities to the state.

Yes, Missouri’s law has wording that might seemingly allow Missouri to prosecute anyone who gains access to others’ personal information without their authorization, but did the law really anticipate the governor going after those researchers or journalists who responsibly disclose or report on breaches or leaks?

Gillum’s article can be found on Bloomberg, here.

So…. what will Governor Parsons do when journalists report on ransomware incidents involving Missouri entities where data involving personal information has been dumped by threat actors and viewed and reported upon by journalists? Look at these provisions in their law:

(3) Discloses or takes data, programs, or supporting documentation, residing or existing internal or external to a computer, computer system, or computer network; or
[…]

(6) Receives, retains, uses, or discloses any data he knows or believes was obtained in violation of this subsection.

So does that mean reporting on a data dump from a criminal hack unlawfully “uses” or “discloses” data?

DataBreaches.net does not believe that investigating and reporting on cybercrime is a crime. See also today’s report on the ransomware attack on Carthage R-9 district.



If you thought you were done learning, you were wrong. (At least try the free ones.)

https://www.efinancialcareers.com/news/2022/01/top-machine-learning-courses

Goldman Sachs MD's guide to top machine learning courses

If you've started this year with aspirations to further your knowledge of such things as Python coding and machine learning, but you happen to have a full time job that demands most of your time, do not be discouraged.

One Goldman Sachs MD says he completed eight online training courses last year, while also fulfilling his role as head of engineering (strats, quants and technologists) in EMEA and APAC for the private investments arm of Goldman Sachs Asset Management.

… Not all are machine learning-focused, but the first four in particular are directly relevant.

1. Machine Learning, by Stanford University and Coursera.
2.
Deep Learning Specialization, by DeepLearning.AI
3.
AWS Fundamentals Specialization, by aws.amazon.com
4.
Google Cloud Digital Leader Specialization, by cloud.google.com
5.
Scalability & System Design for Developers, by Educative.IO
6.
Python for Programmers, by Educative.IO
7.
Agile and JIRA, by atlassian.com
8.
Managing Remote Teams, by gitlab.com

… McLennan's advice on online courses comes after Goldman posted a new developer blog  about the use of machine learning in its data lake. Among other things, it stresses the importance of explainable models. "For Machine Learning Engineers, it can become a full day's work to explain why a certain prediction was made by the model," says author Jaimita Bansal, a VP in data lake engineering.



Resources.

https://www.makeuseof.com/learn-programming-for-free/

The Top 9 Places to Learn Programming Online for Free



Tuesday, January 11, 2022

What a surprise! (What? A surprise?)

https://www.cyberscoop.com/feds-spending-on-facial-recognition-tech-continues-unmitigated-despite-privacy-concerns/

Feds' spending on facial recognition tech expands, despite privacy concerns

The FBI on Dec. 30 signed a deal with Clearview AI for an $18,000 subscription license to the company’s facial recognition technology. While the value of the contract might seem just a drop in the bucket for the agency’s nearly $10 billion budget, the contract was significant in that it cemented the agency’s relationship with the controversial firm. The FBI previously acknowledged using Clearview AI to the Government Accountability Office but did not specify if it had a contract with the company.

The FBI didn’t respond to a request for comment, but it isn’t the only federal law enforcement agency to ramp up its procurement of privately-owned facial recognition technologies in recent months. In September, U.S. Immigration and Customs Enforcement spent almost $4 million on facial recognition technology from a company called Trust Stamp, as Business Insider first reported. The same month agency purchased a contract with Clearview AI starting at $500,000 with the potential to go up to $1.5 million dollars. In total, ICE investment in Clearview AI has more than doubled during the Biden administration, said Jack Poulson, executive director of the nonprofit Tech Inquiry.



Strangely presented as a slide deck. Some new (to me) terms, like Data Fabric.

https://www.crn.com/slide-shows/channel-programs/gartner-12-top-strategic-technology-trends-for-2022

Gartner: 12 Top Strategic Technology Trends For 2022

From cloud-native platforms to decision intelligence to hyperautomation, here’s what technology research firm Gartner is predicting to be trending in 2022.

… Data fabric is a design concept that acts as an integrated layer (fabric) of data and connecting processes, according to Gartner. It uses analytics over existing metadata assets to support the design, deployment and utilization of integrated and reusable data across all environments.

… Autonomic systems are self-managed physical or software systems that learn from their environments and greatly modify their own algorithms in real time, according to Gartner. This optimizes their behavior in complex environments.


Monday, January 10, 2022

It used to be this was too ‘small change’ to attract crooks.

https://www.schneier.com/blog/archives/2022/01/fake-qr-codes-on-parking-meters.html

Fake QR Codes on Parking Meters

The City of Austin is warning about QR codes stuck to parking meters that take people to fraudulent payment sites.



Is anyone blowing the whistle on specific US databases? Perhaps some of this data could be obtained from multiple, legal sources. Must Europol attempt to check each record for possible legitimacy?

https://www.theguardian.com/world/2022/jan/10/a-data-black-hole-europol-ordered-to-delete-vast-store-of-personal-data

A data ‘black hole’: Europol ordered to delete vast store of personal data

The EU’s police agency, Europol, will be forced to delete much of a vast store of personal data that it has been found to have amassed unlawfully by the bloc’s data protection watchdog. The unprecedented finding from the European Data Protection Supervisor (EDPS) targets what privacy experts are calling a “big data ark” containing billions of points of information. Sensitive data in the ark has been drawn from crime reports, hacked from encrypted phone services and sampled from asylum seekers never involved in any crime.

According to internal documents seen by the Guardian, Europol’s cache contains at least 4 petabytes – equivalent to 3m CD-Roms or a fifth of the entire contents of the US Library of Congress. Data protection advocates say the volume of information held on Europol’s systems amounts to mass surveillance and is a step on its road to becoming a European counterpart to the US National Security Agency (NSA), the organisation whose clandestine online spying was revealed by whistleblower Edward Snowden.



It must be hard to write regulations when you have no idea what you are regulating.

https://thenextweb.com/news/why-its-so-hard-to-regulate-algorithms-syndication

Why it’s so hard to regulate algorithms

In 2018, the New York City Council created a task force to study the city’s use of automated decision systems (ADS). The concern: Algorithms, not just in New York but around the country, were increasingly being employed by government agencies to do everything from informing criminal sentencing and detecting unemployment fraud to prioritizing child abuse cases and distributing health benefits.

… In New York City, that initial working group took two years to make a set of broad, nonbinding recommendations for further research and oversight. One task force member described the endeavor as a “waste.” The group could not even agree on a definition for automated decision systems, and several of its members, at the time and since, have said they did not believe city agencies and officials had bought into the process.

Elsewhere, nearly all proposals to study or regulate algorithms have failed to pass. Bills to create study groups to examine the use of algorithms failed in Massachusetts, New York state, California, Hawaii, and Virginia. Bills requiring audits of algorithms or prohibiting algorithmic discrimination have died in California, Maryland, New Jersey, and Washington state. In several cases—California, New Jersey, Massachusetts, Michigan, and Vermont—ADS oversight or study bills remain pending in the legislature, but their prospects this session are slim, according to sponsors and advocates in those states.

… The Markup interviewed lawmakers and lobbyists and reviewed written and oral testimony on dozens of ADS bills to examine why legislatures have failed to regulate these tools.

We found two key through lines: Lawmakers and the public lack fundamental access to information about what algorithms their agencies are using, how they’re designed, and how significantly they influence decisions. In many of the states The Markup examined, lawmakers and activists said state agencies had rebuffed their attempts to gather basic information, such as the names of tools being used.

Meanwhile, Big Tech and government contractors have successfully derailed legislation by arguing that proposals are too broad—in some cases claiming they would prevent public officials from using calculators and spreadsheets—and that requiring agencies to examine whether an ADS system is discriminatory would kill innovation and increase the price of government procurement.


(Related)

https://www.insideprivacy.com/data-privacy/december-2021-eu-privacy-data-and-consumer-updates/

December 2021 EU Privacy, Data and Consumer Updates



Background.

https://www.csoonline.com/article/3645648/protecting-pii-examples-laws-and-standards.html#tk.rss_all

Protecting PII: Examples, laws, and standards

PII, or personally identifiable information, is any piece of data that someone could use to figure out who you are. Some types of PII are obvious, such as your name or Social Security number, but others are more subtle—and some data points only become PII when analyzed in combination with one another.

The United States General Services Administration uses a fairly succinct and easy-to-understand definition of PII:



Background.

https://www.makeuseof.com/what-is-smart-home-technology/

What Is Smart Home Technology? A Guide for Absolute Beginners

… Smart home technology involves gadgets, devices, and home appliances with wireless connectivity. When connected to the home Wi-Fi internet network, they communicate with each other, a smart bridge, or a mobile phone app.

You can effortlessly control these devices from anywhere using a connected smartphone or mobile app. A few premium smart devices go the extra mile to offer energy savings and personalized services.

At the center of any smart home ecosystem, you’ll find a smart speaker. You can ask it to adjust the home lighting, heating, and so on. These are essentially small, voice-controlled computers that can search the web or manage your schedules.


(Related) Q: We’ve got lots of AI based tools, where will we use them? A: Everywhere.

https://venturebeat.com/2022/01/09/the-ambient-intelligence-decade/

The ambient intelligence decade

Technology zoomed ahead in 2020 and 2021, spurred in large part by the global pandemic. Companies embraced digital transformation and AI, driven by a need to connect remote workers, improve efficiency, and offer new online services. This surge of adoption has also added renewed focus on a variety of technologies including augmented and virtual reality, blockchain, and the rollout of 5G communication networks. We have indeed entered an age of acceleration.

In turn, these developments are leading to new innovations such as the metaverse. First envisioned in the 1990s, the same underlying technologies to make the metaverse concept a fully immersive and seamless experience are now approaching maturity. Over the next several years and certainly by the end of the decade, the metaverse will be very much a regular part of our digital lives.

… That said, technology adoption is always a double-edged sword. Issues of ethics around data privacy and the appropriate uses of facial and other biometric recognition continue to be sources of concern and widespread debate. In a Fortune article, Fei-Fei Li, co-director of Stanford University’s Human-Centered AI Institute, warns there are societal dangers of ever-present computing, constantly gathering and analyzing people’s behaviors in the physical world. As much as the technology constraints, navigating these ethical challenges will also inhibit the realization of an ambiently intelligent world.



Lots of AI doing lots of things simultaneously.

https://thenextweb.com/news/metaverse-good-bad-ugly-sides-of-people-syndication

The metaverse could bring out the good, bad, and ugly sides of people

The metaverse is an immersive virtual reality version of the internet where people can interact with digital objects and digital representations of themselves and others, and can move more or less freely from one virtual environment to another. It can also involve augmented reality, a blending of virtual and physical realities, both by representing people and objects from the physical world in the virtual and conversely by bringing the virtual into people’s perceptions of physical spaces.

… As terrorism researchers at the National Counterterrorism Innovation, Technology, and Education Center in Omaha, Nebraska, we see a potential dark side to the metaverse. Although it is still under construction, its evolution promises new ways for extremists to exert influence through fear, threat and coercion. Considering our research on malevolent creativity and innovation, there is potential for the metaverse to become a new domain for terrorist activity.

To be clear, we do not oppose the metaverse as a concept and, indeed, are excited about its potential for human advancement. But we believe that the rise of the metaverse will open new vulnerabilities and present novel opportunities to exploit them. Although not exhaustive, here are three ways the metaverse will complicate efforts to counter terrorism and violent extremism.



Not a concern for the little investor who is not offered an investment opportunity, why should we worry about large investors or institutions who should be able to assess the risks themselves?

https://www.wsj.com/articles/sec-pushes-for-more-transparency-from-private-companies-11641752489?mod=djemalertNEWS

SEC Pushes for More Transparency From Private Companies

… Private capital markets have become an increasingly popular way for companies to raise money in the U.S. in recent decades, allowing firms to acquire funding from institutions and wealthy individuals without the regulatory burdens of going public. The number of so-called unicorns—private companies valued at $1 billion or more—has continued to grow even amid the recent boom in initial public offerings.



I probably have enough handouts, notes, or answers to student questions to publish an ebook or six in math, computer security or a few other topics I taught.

https://www.makeuseof.com/steps-to-write-publish-ebooks/

6 Steps to Writing and Publishing Ebooks as a Professional

Books are for exchanging stories and different kinds of knowledge. If you’re a professional trying to make a good impression, putting your expertise down on paper, whether real or digital, is a great move.

Since it’s simpler and cheaper to publish ebooks, let’s look at how to produce one that turns heads and reflects your business in a positive way. Take the time to think about what you want to share and how.


Sunday, January 09, 2022

Another wave of technology we can try to understand.

https://www.liebertpub.com/doi/full/10.1089/cyber.2021.29234.editorial

Ready (or Not) Player One: Initial Musings on the Metaverse



“That’s obvious” is not a phrase understood by AI.

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3998249

Overturned Legal Rulings Are Pivotal In Using Machine Learning And The Law

Much of the time, attorneys know that the law is relatively stable and predictable. This makes things easier for all concerned. At the same time, attorneys also know and anticipate that cases will be overturned. What would happen if we trained AI but failed to point out that rulings are at times overruled? That’s the mess that some using machine learning are starting to appreciate.



What are the inputs? How much weight do you give a Trump Tweet?

https://interestingengineering.com/data-scientists-believe-algorithms-can-predict-political-unrest

Can Algorithms Predict Political Unrest? These Data Scientists Believe So

Who can forget the attack on Capital last January 6th? For those who do remember it well, there is an urgency to do something to avoid it ever happening again. One way to do that is to predict these events before they happen just like you can predict weather patterns.

Some data scientists believe they can achieve exactly that, according to The Washington Post. “We now have the data — and opportunity — to pursue a very different path than we did before,” said Clayton Besaw, who helps run CoupCast, a machine-learning-driven program based at the University of Central Florida that predicts coups for a variety of countries.

This type of predictive modeling has been around for a while but has mostly focused on countries where political unrest is far more common. Now, the hope is that it can be redirected to other nations to help prevent events like that of January 6th. And so far, the firms working in this field have been quite successful.



Perhaps something like it. Actions taken before we know why something appears to work.

https://www.theguardian.com/technology/2022/jan/09/are-we-witnessing-the-dawn-of-post-theory-science

Are we witnessing the dawn of post-theory science?

Isaac Newton apocryphally discovered his second law – the one about gravity – after an apple fell on his head. Much experimentation and data analysis later, he realised there was a fundamental relationship between force, mass and acceleration. He formulated a theory to describe that relationship – one that could be expressed as an equation, F=ma – and used it to predict the behaviour of objects other than apples. His predictions turned out to be right (if not always precise enough for those who came later).

Contrast how science is increasingly done today. Facebook’s machine learning tools predict your preferences better than any psychologist. AlphaFold, a program built by DeepMind, has produced the most accurate predictions yet of protein structures based on the amino acids they contain. Both are completely silent on why they work: why you prefer this or that information; why this sequence generates that structure.



My AI should read this...

https://openeducationalberta.ca/educationaltechnologyethics2/chapter/final-the-razors-edge-how-to-balance-risk-in-artificial-intelligence-machine-learning-and-big-data/

Chapter 6: The Razor’s Edge: How to Balance Risk in Artificial Intelligence, Machine Learning, and Big Data

This chapter is guided by the question, how can an educational system take advantage of rapid technological advances in a safe and socially responsible manner while still achieving its mandate of fostering and supporting learner success? Artificial intelligence (AI), machine learning (ML) [New Tab], and big data [New Tab] are examples of highly risky technologies that also hold vast potential for innovation (Floridi et al., 2018). In examining technological advances from an ethical perspective, one of the aims is to avoid harm and minimize risk. This is referred to as a consequentialist perspective (Farrow, 2016). The complexity of finding and maintaining a proper balance in advancing technological innovation and avoiding harm and minimizing risk cannot be understated. This quest for an educational “sweet spot” is mired by a lack of understanding, inconsistent leadership, and simple human greed.