Thursday, March 27, 2025

Inevitable in the camera rich UK.

https://www.theregister.com/2025/03/27/uk_facial_recognition/

UK's first permanent facial recognition cameras installed in South London

The two cameras will be installed in the city center in an effort to combat crime and will be attached to buildings and lamp posts on North End and London Road. According to the police they will only be turned on when officers are in the area and in a position to make an arrest if a criminal is spotted.

The installation follows a two-year trial in the area where police vans fitted with the camera have been patrolling the streets matching passersby to its database of suspects or criminals, leading to hundreds of arrests. The Met claims the system can alert them in seconds if a wanted wrong'un is spotted, and if the person gets the all-clear, the image of their face will be deleted.





Clear as mud? The “Oops!” keeps getting bigger.

https://www.politico.com/news/2025/03/26/gabbard-signal-government-devices-cybersecurity-00250731

Gabbard says Signal comes ‘pre-installed’ on government devices

Director of National Intelligence Tulsi Gabbard testified to House Intelligence Committee members Wednesday that encrypted messaging app Signal comes “pre-installed” on government devices — a potentially major shift in official communications on the heels of a massive Chinese government-linked hack of U.S. telecommunications networks last year.

The app has been largely unauthorized for use on government-issued devices in the past. The Defense Department Office of the Inspector General issued multiple reports condemning a top Pentagon official in 2021 for using Signal to communicate, and the National Security Agency reportedly warned employees last month of the vulnerabilities of using Signal, stating that the app was “a high value target to intercept sensitive information.”

Cybersecurity experts told POLITICO earlier this week that the app should not be used to discuss classified information and stressed the need for government officials to use authorized and more secure means of communication.



(Related)

https://databreaches.net/2025/03/26/private-data-and-passwords-of-senior-u-s-security-officials-found-online/

Private Data and Passwords of Senior U.S. Security Officials Found Online

This will likely come as no surprise to many, but Spiegel International reports:

Donald Trump’s most important security advisers used Signal to discuss an imminent military strike. Now, reporting by DER SPIEGEL has found that the contact data of some of those officials, including mobile phone numbers, is freely accessible on the internet.

According to reporting by  Patrick Beuth, Jörg Diehl, Roman Höfner, Roman Lehberger, Friederike Röhreke und Fidelius Schmid:

DER SPIEGEL reporters were able to find mobile phone numbers, email addresses and even some passwords belonging to the top officials.
To do so, the reporters used commercial people search engines along with hacked customer data that has been published on the web. Those affected by the leaks include National Security Adviser Mike Waltz, Director of National Intelligence Tulsi Gabbard and Secretary of Defense Pete Hegseth.
Most of these numbers and email addresses are apparently still in use, with some of them linked to profiles on social media platforms like Instagram and LinkedIn. They were used to create Dropbox accounts and profiles in apps that track running data. There are also WhatsApp profiles for the respective phone numbers and even Signal accounts in some cases.
As such, the reporting has revealed an additional grave, previously unknown security breach at the highest levels in Washington.

Read more at DER SPIEGEL.





Easy for kids to get a prepaid credit card?

https://www.cnbc.com/2025/03/26/utah-adopts-child-safety-law-requiring-apple-google-to-verify-user-ages.html

Utah governor signs online child safety law requiring Apple, Google to verify user ages

The App Store Accountability Act, or S.B. 142, could also kick off a wave of other states, including South Carolina and California, passing similar legislation

Apple and Google will need to request age verification checks when someone makes a new account in the state. That will most likely have to be done using credit cards, according to Weiler. If someone under 18 opens an app store account, Apple or Google will have to link it to a parent’s account or request additional documentation. Parents will have to consent to in-app purchases.





Massive effort that should be reviewed by security and AI teams.

https://www.schneier.com/blog/archives/2025/03/a-taxonomy-of-adversarial-machine-learning-attacks-and-mitigations.html

A Taxonomy of Adversarial Machine Learning Attacks and Mitigations

NIST just released a comprehensive taxonomy of adversarial machine learning attacks and countermeasures.



No comments: