Friday, March 24, 2017

Simple if not elegant.  I wonder how many schools or companies have not noticed similar changes yet.
Lisa Gresci reports:
Coastal Carolina University continues to work to recover money that was stolen from the college in a phishing scam.
A release from CCU stated an individual who claimed to represent a company under contract with the university contacted its financial services via email and requested to change the company’s bank account information.
[…]
Thanks to quick action, university officials said they’ve recovered more than $564,000 of the more than $1 million taken.  On campus, additional “cybercrime safeguards” will be installed to make sure nothing like this happens again.
Read more on WMBF.


Isn’t it strange that no one has noticed this until now?  Makes me think that “offensive” was their target audience… 
Advertisers Flee YouTube Over Offensive Ad Placements


I’ve been thinking about this.  Actually, I asked my AI to think about this.  It came to the same conclusion. 
Will AI Create as Many Jobs as It Eliminates?
The threat that automation will eliminate a broad swath of jobs, across the world economy is now well established.  As artificial intelligence (AI) systems become ever more sophisticated, another wave of job displacement will almost certainly occur.  
It can be a distressing picture.
But here’s what we’ve been overlooking: Many new jobs will also be created — jobs that look nothing like those that exist today.
In Accenture’s global study of more than 1,000 large companies already using or testing AI and machine-learning systems, we identified the emergence of entire categories of new, uniquely human jobs.  These roles are not replacing old ones.  They are novel, requiring skills and training that have no precedents.  
More specifically, our research reveals three new categories of AI-driven business and technology jobs.  We label them trainers, explainers, and sustainers.


Interesting stuff.  Another Chinese company crashes.  Not the best way to encourage investment.  Perhaps that is what is driving venture capital money to the US? 
Huishan Dairy, Muddy Waters Target, Sinks 85% in Hong Kong
Shares of China Huishan Dairy Holdings Co. sank by a record 85 percent in Hong Kong before the company halted trading.
The sudden crash wiped out about $4.1 billion in market value.  A record 779 million shares in the Shenyang-based company changed hands, the most on Hong Kong’s exchange.
   The move is also a vindication for Carson Block, whose Muddy Waters Capital LLC said in December it was shorting Huishan Dairy and the company was “worth close to zero.”


Perhaps a tool for my students.
Social Media Info Guide to Tumblr
by Sabrina I. Pacifici on Mar 23, 2017
The Social Media Information Blog Investigator’s Guide to Tumblr – “Founded in 2007, Tumblr is a microblogging and social networking website.  The platform, which was acquired by Yahoo in 2013, allows users to share text, images, quotes, links, video, audio, and chats.  Tumblr’s appeal is that it allows users to be creative and build independent content on a personalized page with little effort.  How does Tumblr work?  A large part of Tumblr’s appeal to its users is the simplicity and ubiquity of the features it offers.  In fact, they claim on their website that “Tumblr is so easy to use that it’s hard to explain.”  Despite that statement, we will give it a try anyway.  Registering for Tumblr requires only a valid email address.  After creating a username & password, users are provided a URL for their blog which is associated with “.tumblr.com.”  Depending on how the user wishes to utilize Tumblr, they are now able to follow other users and post original content to their tumblelog.  Social interactions between users may vary widely.  While there is certainly overlap, most Tumblr users fall into one of two categories:
  1. Social Networking – These users are primarily interested in using Tumblr to curate content.  Their usage is concentrated on interacting with other users and the content they’ve shared – commenting and connecting.
  2. Self-Publishing – These users value Tumblr’s low barrier to entry for microblogging.  Their activities typically focus on publishing content to their personal pages.
Both categories of user share potentially valuable information on Tumblr. Investigators should be aware of the differences and temper their expectations based on which grouping their subject aligns themselves…”


Just a suggestion students.  If you do this, be sure to shut off your phone before that job interview!

Thursday, March 23, 2017

This is a really bad idea.  You do not want to get into a contest of skills with the world of hackers.
Proposed Legislation Would Give Legal Right to Hack Back
Hacking back is a perennial and contentious issue.  Its latest instance comes in the form of a 'Discussion Draft' bill proposed by Representative Tom Graves (R-GA): The Active Cyber Defense Certainty Act.  Graves claims it is gaining bipartisan support, and he expects to present it to the House of Representatives for vote within the next few months.
The Draft Bill (PDF) is an amendment to the Computer Fraud and Abuse Act (CFAA).
   It is discussed in detail and expanded in the study titled Into the Grey Zone: The Private Sector and Active Defense against Cyber Threats published by the George Washington University in October 2016.
   So, two immediate problems with allowing hacking back is that a lack of expertise could either compromise forensic evidence, or accidentally cause actual harm to the attackers' supposed computers.  Without adequate expertise, the supposed servers might not even be the attackers' servers.  "Because of (compromised) proxies," comments F-Secure's security advisor Sean Sullivan, "hacking back/active defense is complicated and it's quite unlikely that the US Congress would be able to properly define what should be allowed or not."


This would be interesting.  “Cut off our hard currency with sanctions and we’ll just rob your banks?”   
North Korea Said to Be Target of Inquiry Over $81 Million Cyberheist
Federal prosecutors are investigating North Korea’s possible role in the theft of $81 million from the central bank of Bangladesh in what security officials fear could be a new front in cyberwarfare.
The United States attorney’s office in Los Angeles has been examining the extent to which the North Korea government aided and abetted the bold heist in February 2016, according to a person briefed on the investigation who was not authorized to speak publicly.
   News of the criminal investigation into North Korea’s role in the Bangladesh bank attack was reported earlier on Wednesday by The Wall Street Journal.  It was not clear whether any charges from the investigation were imminent.

(Related).
JOHN MCCAIN: There's a 'crazy fat kid' running North Korea


I’ll have to find an article with more details, but the idea of government mandated minimum standards is interesting. 
Dror Halavy reports:
The Knesset Law and Constitutional Committee has approved measures that will require companies and groups that collect data on Israelis to protect the information from hackers.  The new rules, which supply specific criteria to organizations on the types of security needed, will apply equally to government and private sector organizations.
The measures are based on research done by the Justice Ministry, and recently completed at the behest of Justice Minister Ayelet Shaked.  Under the measures, organizations will determine whether the data they hold is of low, medium, or high sensitivity for privacy; for example, medical information will be considered as part of the latter category, while membership in a store club might be listed in the former categories.
Each level of sensitivity will require more severe cyber-security strictures and standards.  Organizations will have to apply specific approved solutions that meet standards described in the measures.  Failure to do so could leave them subject to civil or criminal actions in the event of a security breach.
Read more on Hamodia.


Mission creep? 
Joe Cadillic writes:
Imagine driving down the road and being stopped by a Border Patrol agent for speeding.  Imagine Border Patrol agents responding to domestic abuse calls at people’s homes.  Imagine the Border Patrol responding to trespassing calls and detaining motorists with K-9’s.  
You can stop imagining, because it’s happening in New York, Vermont, Maine and now New Hampshire.  House Bill 1298 gives DHS’s Border Patrol agents police powers in NH.
Read more on MassPrivateI.
[From the article: 
Americans can forget about DHS's 100 mile border zone inside the U.S., because now the Border Police Patrol has arrest powers throughout entire states!


A boarder search going the other direction?
Mar. 20 – Cause of Action Institute (“CoA Institute”) today filed an amicus curiae brief in support of Defendant Hamza Kolsuz who in February, 2016 was arrested at a Virginia airport attempting to board a plane bound for Istanbul, Turkey.
   The brief states:
At the time of the search, neither Mr. Kolsuz nor his smartphone were in the process of crossing any border.  The Government was not furthering any interest in prohibiting the entry or exit of contraband, enforcing currency control, levying duties or tariffs, or excluding travelers without the property documentation to enter the country…
The full brief is available here.


A different take.  Why would this be illegal?  Isn’t it similar to using a dashboard camera?  They are looking at cars on a public road and using technology available at any high school (for measuring the speed of baseballs).  The letter reads as if they were trespassing on state controlled land (the highway). 
The state of Virginia is not happy that the Insurance Institute for Highway Safety (IIHS) set up speed cameras on Virginia highways without any authority to do so.  State officials sent a warning letter to the industry lobbying group in October.
“We recently received a concern claiming your organization set up equipment on property controlled by the Virginia Department of Transportation (VDOT),” Northern Virginia District Administrator Helen Cuervo wrote.  “In reviewing our records, it does not appear that your organization had a legal permit to do so.
Read more on TheNewspaper.com.  So they get to keep the data they illegally obtained and then used to lobby for changes that would benefit their industry?  They should be made to destroy the data.


If venture capital was easy to find, everyone would be entrepreneurs!
US Tech Startups’ China money spooks Pentagon
A new white paper commissioned by the US defense department says Beijing isn’t just investing in critical technologies at home, they are doing it in the US as well.  The New York Times reports that some tech startups working on projects with military applications have received money from state-run Chinese firms.  Lawmakers calling for stricter oversight of Chinese investments note that the scope of the interagency Committee on Foreign Investment in the US (Cfius) does not include smaller investments, such as those into tech startups.  Despite the increased scrutiny, many firms say the Chinese investors are their only option.


Clearly, Tillerson does not like people looking over his shoulder.  Apparently, they failed to inform the Records Retention people that he was using an alias.  (But just for one year near the end of that period?) 
Exxon admits it lost up to a year's worth of Rex Tillerson's 'Wayne Tracker' emails
Exxon Mobil lost up to a year's worth of emails sent by former CEO and current Secretary of State Rex Tillerson under the pseudonym "Wayne Tracker," court documents show.
Exxon is under investigation by New York State Attorney General Eric T. Schneiderman for allegedly misleading shareholders and investors about risk-management issues related to climate change.
Tillerson used the Wayne Tracker alias to communicate with Exxon officials about "risk-management issues related to climate change." Tillerson — whose middle name is Wayne — allegedly used the alias for a period of seven years, between 2008 and 2015, according to Schneiderman's office.

Wednesday, March 22, 2017

Same crime, different country.  OR, learn crime from global news, act locally? 
Ex-DBS Trader Gets Jail in Singapore's First Spoofing Case
A former trader at DBS Group Holdings Ltd.’s brokerage unit was sentenced to 16 weeks in jail after being convicted in Singapore’s first criminal spoofing case.
Dennis Tey Thean Yang, 33, was given the sentence on Wednesday.  The former DBS Vickers Securities (Singapore) Pte broker had pleaded guilty to eight of 23 charges, including attempts to artificially move prices through fraudulent securities orders and misusing other people’s trading accounts without consent.  He made a profit of S$30,239 ($21,572) from October 2012 to January 2013.


Has there been a breach?  Has anyone notified account holders? 
Joseph Cox reports:
A hacker or group of hackers is apparently trying to extort Apple over alleged access to a large cache of iCloud and other Apple email accounts.
The hackers, who identified themselves as ‘Turkish Crime Family’, demanded $75,000 in Bitcoin or Ethereum, another increasingly popular crypto-currency, or $100,000 worth of iTunes gift cards in exchange for deleting the alleged cache of data.
Read more on Motherboard.


A different type of extortion?  
Microsoft Modifies Windows 10 for China’s Government
BEIJING—Microsoft Corp. has finished development of a Windows 10 version customized for Chinese government use, which could boost its China prospects after sales were hit by Beijing’s cybersecurity crackdown.
Microsoft declined to say how the software was modified, but in general China’s government is concerned about technology products that could contain hidden “back doors” to enable foreign surveillance.


Give a man a fish and you feed him for a day.  Teach a man to phish and he can retire in luxury!
Joon H. Kim, the Acting United States Attorney for the Southern District of New York, and William F. Sweeney Jr., the Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation (“FBI”), announced criminal charges against EVALDAS RIMASAUSKAS for orchestrating a fraudulent business email compromise scheme that induced two U.S.-based internet companies (the “Victim Companies”) to wire a total of over $100 million to bank accounts controlled by RIMASAUSKAS.  RIMASAUSKAS was arrested late last week by authorities in Lithuania on the basis of a provisional arrest warrant.  
   Acting U.S. Attorney Joon H. Kim said: “From half a world away, Evaldas Rimasauskas allegedly targeted multinational internet companies and tricked their agents and employees into wiring over $100 million to overseas bank accounts under his control.  This case should serve as a wake-up call to all companies – even the most sophisticated – that they too can be victims of phishing attacks by cyber criminals


Fragile.  Something my Computer Security students will have to address. 
Glitch at NYSE Arca hits hundreds of exchange traded funds
A technical problem at NYSE Arca, the Big Board’s listing venue for exchange traded funds, stymied the end of the trading day on Monday, hindering the closing auction for 341 securities, NYSE said on Tuesday.
In a letter to clients on Tuesday, NYSE attributed the problem to a new version of software. Trading on the exchange has recommenced normally.
   The latest glitch in the US market plumbing highlights how reliant trading has become on technology, forcing traders and investors to adapt to periodic technical problems.


Badges? Warrants?  We don’t need no stinking badges! Warrants!”
Border agents must obtain a warrant to search travelers’ phones, tablets, and laptops, which contain a vast trove of sensitive, highly personal information that is protected by the Fourth Amendment, the Electronic Frontier Foundation (EFF) told a federal appeals court yesterday.
Searches of devices at the border have more than doubled since the inauguration of President Trump—from nearly 25,000 in all of 2016, to 5,000 in February alone.  This increase, along with the increasing number of people who carry these devices when they travel, has heightened awareness of the need for stronger privacy rights while crossing the U.S. border.
While the Fourth Amendment ordinarily requires law enforcement officials to get a warrant supported by probable cause before searching our property, in cases that predate the rise of digital devices, courts granted border agents the power to search our luggage without a warrant or any suspicion of wrongdoing.
But portable digital devices differ wildly from luggage or other physical items we carry with us to the airport because they provide access to the entirety of our private lives, EFF said in an amicus brieffiled at the U.S. Court of Appeals for the Fourth Circuit in the border search case U.S. v. Kolsuz. 
   “The border isn’t a constitution-free zone,” said Adam Schwartz, EFF senior staff attorney.  
For EFF’s new border pocket guide:   https://www.eff.org/document/eff-border-search-pocket-guide


For my Computer Forensics students.  Obvious, wasn’t it? 
iCloud may have doxxed a journalist’s Twitter attacker
In theory, it was the perfect setup: an anonymous Twitter account on a prepaid SIM card, bought with cash.  With no credit card or other identifiable info tied to the account, there should have been no way to trace tweets back to a human.
But on Friday, after taking all those precautions, a man named John Rivello was arrested for sending seizure-inducing tweets to Newsweek journalist Kurt Eichenwald.  The arrest came three months and a day after the initial incident, and a newly unsealed complaint reveals how police tracked the man down.
First, police sent a court order to Twitter, which agreed to hand over all its data on @jew_goldstein, the account that had sent the seizure-inducing image.  But that data showed only a dummy email address, along with an IP address and phone numbers linking to a prepaid Tracfone.  But since Tracfone didn’t have any subscriber information associated with the number, police were left with few leads.
The break came thanks to AT&T, which was supporting Tracfone’s SIM card.  While AT&T didn’t have any directly identifying data, the company’s toll records showed that the SIM card had been used by an iPhone 6.  That sent investigators looking for an iCloud account linked to the same number.  After another search warrant to Apple, they got what they were looking for. According to the complaint, the number was linked to a five-year-old iCloud account owned by John Rivello of Salisbury, Maryland.  A search of iMessages and photos in the account provided further evidence of Rivello’s interest in Eichenwald.


Is this a Trade Secret?
Matthew Renda reports:
A federal judge refused to sign off on a settlement between a class of email users and Google, sending the parties back to the drawing board to come up with a more detailed disclosure of how Google intercepts and uses emails for targeted advertising.
U.S. District Judge Lucy Koh issued the order Thursday, saying the class did not demand enough concessions from the tech giant its practice of scanning incoming and outgoing emails for information that it uses for targeted advertising.
Specifically, Koh wanted to see disclosures hosted on a website or somehow publicly disseminated that clearly spell out how Google intercepts, scans and uses the information from non-Gmail users.
Read more on Courthouse News.


“Fake News” in real time!  Why wait for Journalist to publish the facts?  Is this not a taste of things to come? 
What Happens When the President Is a Publisher, Too?
   on Twitter, it’s possible to be sitting in a room full of your colleagues, surreptitiously scrolling on your mobile phone, and notice that, hey, whaddya know, President Donald Trump is tweeting again.
At a House Intelligence Committee hearing on Monday, Jim Himes decided to share some of those tweets with the men who were there being questioned—the FBI director James Comey and the NSA director Mike Rogers—along with the rest of the room, and the public.


Everyone Tweets, not just the President.
Twitter Suspends More Accounts Linked to 'Terrorism'
Twitter said Tuesday it suspended 376,890 accounts in the second half of 2016 for "promotion of terrorism," an increase of 60 percent over the prior six-month period.
The latest suspensions bring the total number of blocked accounts to 636,248 from August 2015, when Twitter stepped up efforts to curb "violent extremism," the company announced as part of its latest transparency report.


But, is it good for golf?
Costco vs. Acushnet: Who has the upper hand?
The burgeoning legal battle between Costco and Acushnet over the cult favorite Kirkland Signature ball is sounding more and more like a game of courthouse chicken.
But that can be an expensive game, with occasionally terminal consequences.
In layman’s terms, Costco’s suit for what’s called a declaratory judgment against Acushnet is essentially a preemptive strike, a lawsuit aiming to prevent a lawsuit.  In actuality, it’s probably not going to work that way.


Disruption.  Back in the day, small town grocery stores employed teens or (in my home town) the village idiot to deliver groceries.  Are we returning to that time but now using ‘delivery services’ or robots?
Soon, You’ll Be Able to Get Costco Groceries Delivered in 50 Different Cities
Costco Wholesale is ramping up its home grocery delivery in a major way.
The bulk retailer is teaming up with Shipt, a startup delivery service, to make runs to Costco stores and bring orders back to customers' homes, moving further into one of most complex and costly fronts in the e-commerce wars while also building on Costco's delivery to business clients.
   Grocers are scrambling to find ways to offer home delivery as a way to win customers, despite a threat to already razor-thin margins.  Delivery services like Instacart (which is doing a test with Costco), AmazonFresh, Google Express, and FreshDirect have proliferated, while some major chains like Kroger and Walmart have teamed up with services like Uber and Lyft on a test basis.  Costco rival Sam's Club has focused its efforts on ramping up drive-by pick up at its stores.


Disruption.  Firing the Marketing team is probably a good thing. 
Meet Tinyclues Action™, the Revolutionary AI That Enables Marketers to Put Their Ideas into Action
   Put very simply, Tinyclues Action™ does three things very smartly.  Firstly, it predicts ANY customer’s likelihood to buy ANY item (or brand, or category) in the next few days, even in the absence of a prior intent.  This deep targeting capability outshines intent-driven rules (which rely on retargeting customers based on their past behavior and become ineffective after a few interactions.)  Secondly, it gives instant feedback on the right volume or pressure to put behind a campaign.  And thirdly, it offers intelligent planning capabilities which enable marketers to build a comprehensive marketing agenda over the next days and weeks, activating customers on all channels (email, mobile, social – even print), while making sure that everyone receives the best messages and that the overall plan is balanced and consistent.  In other words, it combines intelligent targeting, intelligent pressure management and intelligent planning.
For more information, visit http://www.tinyclues.com.


Yet another Disruption!
How Facebook’s Big Bet on Video Could Change TV
Facebook is aggressively ramping up its video strategy, cultivating content whether it comes from users, advertisers or Hollywood, or is developed internally.  With its nearly two billion monthly users, the social network could make a big dent in traditional TV and help usher in a major shift towards social TV, Wharton experts say.
   CEO Mark Zuckerberg is also tipping his hat to a fast-growing trend: Digital video viewing is exploding.  According to Cisco Systems, video accounted for 60% of mobile data traffic in 2016 and should rise to 78% by 2021.


No more “Did too!  Did not!” 
   We’ve shared how web resources can help you stay updated on politics.  Another great site that can help you make political decisions is VoteSmart.  This completely bipartisan site holds a wealth of information for over 40,000 US politicians, both local and federal.
Type in your ZIP code or a politician’s name and you can check out their biography, recent votes, and positions on various issues.  Rounding out their data set are ratings from various activist groups and recent speeches.  You can also review their funding information, including top donors.

Tuesday, March 21, 2017

I posted this last Friday, with some of the same questions. 
The St. Charles Health System may think they’ve met all their obligations in their handling of an insider snooping incident, but Deschutes County District Attorney John Hummel says the matter should have been reported to them for criminal investigation.
Now that’s interesting to think about.  If a covered entity is convinced that an employee snooped just out of curiosity and not for any intended misuse of information for tax fraud, etc., should the covered entity be referring the matter to law enforcement for criminal investigation?
Would employees be more hesitant about snooping if they knew their employer could not just handle an incident internally and their name and actions would be referred for a criminal investigation?
And would employers/covered entities be even more motivated to prevent insider snooping if they knew they had to refer incidents for criminal investigation if more than X number of patients were involved?


Probably true in this case, but what happens if someone really does forget?  How could I prove it?  Should I have to?   
Thomas Claburn reports:
The US Third Circuit Court of Appeals today upheld a lower court ruling of contempt against a chap who claimed he couldn’t remember the password to decrypt his computer’s hard drives.
In so doing, the appeals court opted not to address a lower court’s rejection of the defendant’s argument that being forced to reveal his password violated his Fifth Amendment protection against self-incrimination.
Read more on The Register.


Something for my Computer Security students to research!
Hacking Tools Get Peer Reviewed, Too
In September 2002, less than a year after Zacarias Moussaoui was indicted by a grand jury for his role in the 9/11 attacks, Moussaoui’s lawyers lodged an official complaint about how the government was handling digital evidence.  They questioned the quality of the tools the government had used to extract data from some of the more than 200 hard drives that were submitted as evidence in the case—including one from Moussaoui’s own laptop.
When the government fired back, it leaned on a pair of official documents for backup: two reports produced by the National Institute of Standards and Technology (NIST) that described the workings of the software tools in detail.  The documents showed that the tools were the right ones for extracting information from those devices, the government lawyers argued, and that they had a track record of doing so accurately.
It was the first time a NIST report on a digital-forensics tool had been cited in a court of law.  That its first appearance was in such a high-profile case was a promising start for NIST’s Computer Forensics Tool Testing (CFTT) project, which had begun about three years prior.  Its mission for nearly two decades has been to build a standardized, scientific foundation for evaluating the hardware and software regularly used in digital investigations.
   Today, the CFTT’s decidedly retro webpage—emblazoned with a quote from an episode of Star Trek: The Next Generation—hosts dozens of detailed reports about various forensics tools.  Some reports focus on tools that recover deleted files, while others cover “file carving,” a technique that can reassemble files that are missing crucial metadata.

The largest group of reports focuses on acquiring data from mobile devices.



There is a place for my Computer Security students in law firms, but will the lawyers listen? 
Lia Marie Brooks and Peter A. Nelson have an article on Harleysville Insurance Co. v. Holding Funeral Home, Inc. that I nearly skipped.  I’m glad I didn’t, because it may have some applicability to cases where entities leave confidential or protected health information on public FTP servers without any password protection and then try to claim they were “hacked” when someone copies the data.
From their article:
The court found that the disclosure was “inadvertent” under state law because the insurer “unknowingly provided access to information by failing to implement sufficient precautions to maintain its confidentiality.”  Further, the court held that the insurer waived any claim of privilege because the site was not password protected and the information “was available for viewing by anyone, anywhere who was connected to the internet and happened upon the site by use of the hyperlink or otherwise.”
“In essence,” the court held, the insurer had conceded that its actions were “the cyber world equivalent of leaving its claims file on a bench in the public square and telling its counsel where they could find it.  It is hard to imag[in]e [sic] an act that would be more contrary to protecting the confidentiality of information than to post that information to the world wide web.”
The court found that disqualifying defense counsel would serve no practical purpose, as any replacement counsel would be entitled to receive the same claims file in discovery.  The court also chastised defense counsel for downloading the claims file because a confidentiality notice was displayed on the email message that was produced with the hyperlink.  “[B]y using the hyperlink contained in the email containing a Confidentiality Notice … defense counsel should have realized that the Box Site might contain privileged or protected information.”
You can read their full article on Patterson Belknap Data Security Law Blog.


For my Computer Security students. 
Erich Falke writes:
Then there were two.
On March 16, 2017, the New Mexico state legislature passed a bill requiring that New Mexico residents be notified if their “personal identifying information” was affected by a breach of electronic data.  Upon signature of the bill, New Mexico will join 47 other states requiring such notification, and the only states remaining without notification laws will be Alabama and South Dakota.
Read more on Baker Hostetler Data Privacy Monitor.


This could be amusing.
New Bill Forces Cybersecurity Responsibility Into the Boardroom
A new bill introduced to the Senate seeks to change this by requiring a board level statement of cyber security expertise or practice in annual SEC filings.
S536, cited as the 'Cybersecurity Disclosure Act of 2017', is sponsored by Democrats Mark Warner of Virginia and Jack Reed of Rhode Island, and Republican Susan Collins of Maine.  Its purpose is to promote transparency in the oversight of cybersecurity risks at publicly traded companies. 
The bill (PDF) defines a cyber security threat as any action not protected by the First Amendment that "may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system..."
The bill then proposes just three requirements under the aegis of the Securities and Exchange Commission (SEC): that annual reports to the SEC must disclose the level of cyber security expertise of the board; or, if none exists, what "other cybersecurity steps taken by the reporting company were taken into account"; and that the definition of what constitutes that expertise should come from the SEC in consultation with NIST.
   The effect of the bill will be to make the board legally and transparently responsible for cyber security.  It is not the first regulation to seek this effect in 2017. On 1 March, the New York Department of Financial Services' 23 NYCRR 500 regulation came into force.  That regulation imposes a responsibility for regulated organizations to name a 'CISO' who will provide an annual cyber security report to be submitted and signed off by the board to the regulator.
Taken together, these two examples of new regulations suggest that regulatory authorities are no longer satisfied to make recommendations about board-level security responsibility, but are now ready to mandate and legally require it.


A wacky idea that might have some attraction.  I have several students with military experience.  I’ll be interested to see how they would structure something like this.  Perhaps a non-military version? 
Experts divided on value of Cyber National Guard
This past weekend at SXSW, two Congressmen suggested that the U.S. create a cybersecurity reserves system, similar to the National Guard, but the idea has received a mixed welcome from the cybersecurity community.
According to House Rep. Will Hurd, a Republican from Texas, a national cybersecurity reserve could help strengthen national security and bring in a diversity of experience.
   "We have military reserves for all the traditional branches of the armed services, but nothing for the cyber realm, largely because of restrictive military hiring policies that discourage information security professionals from joining up," he said.
   For example, typical reservists are trained to shoot a rifle, or pilot a helicopter, he said, but cyber professionals are already trained.  Plus, there's the culture gap, he added.  "Being forced to cut their hair, having to work out, being deployed away from their families."
"There are plenty of patriots in the ranks of the cybersecurity elite, but not many who are going to leave lucrative corporate and consulting gigs to join the military," said Jonathan Sander, vice president of product strategy at Lieberman Software.  "However, offer them an option to keep their income but be on call to come to the national defense when it’s needed and you may have a winning formula."


Tools for small businesses?  But not at the Mom & Pop level. 
Foursquare is launching an analytics platform to help retailers understand foot traffic
While Foursquare started as a social check-in app, the company has always said there is a bigger picture — mainly related to unique ways of leveraging its database of check-ins at nearly 100 million public places.
There’s no better example than when Foursquare predicted that Chipotle same-store sales would fall 29 percent after the Mexican chain was hit with E. coli outbreaks.  The actual decline announced by Chipotle ended up being a spot-on 30 percent.
As you can imagine, these analytics can be very valuable to retailers, allowing them to better understand customers’ habits as well as predict store traffic.
So today the company is announcing Foursquare Analytics, a foot-traffic dashboard for brands and retailers.  The platform is available for retailers with any number of stores, no matter how small.  Previously the only way for companies to access this data was through one-off deals with Foursquare.
Retailers will be able to use the dashboard to see foot-traffic data across metrics like gender, age and new versus returning customers — on a national or citywide scale.  They also can compare their foot traffic against a set of competitors and their category as a whole.


As long as they don’t screw this up too…
Samsung has a plan to turn Google into a dumb tube
Samsung has decided to wade into a massive battle over the future of computing — and it has a huge potential advantage.
On Monday, the South Korean electronics company announced "Bixby": A voice-controlled AI assistant that lives inside your smartphone.
It now joins Google, Amazon, and Apple, who are all betting that these virtual assistants will be the next major frontier in how people interact with their devices.  (They have Google Assistant, Alexa, and Siri, respectively.)
Thanks to Samsung's vast range of appliances, which are already sitting in consumers' homes, it has a massive potential head start on its competitors, just waiting to be leveraged.  And it could also help it lessen its long-running dependence on Google.

(Related).  Is this the start of a ‘personal assistant’ war? 
Amazon Using Trojan Horse Approach To Go After Smartphone Voice Market
   Here we'll look at the latest steps the e-commerce giant is taking to go beyond its own device and have Alexa embedded in its competitors' devices.
This is important because the number of users of Apple's iPhone and smartphones using Google's Android is very high.  To go after that market while seeking to have itself part of the home experience puts its competitors on the defensive as they have to not only try to grow their own market share but defend themselves from being overtaken in their own back yards.
In a way, with voice virtual assistants becoming a major growth market segment of the future in tech, it's probably good for Amazon that its attempt to introduce a smartphone failed.  Like it does in retail, now it can compete without a physical presence, focusing primarily on invading existing hardware ecosystems.  In other words, it doesn't have to defend against its own smartphone devices as any success with its competitors' devices will make it harder to root the company out of them as it expands its presence into further devices and smart home appliances.


Interesting but not (yet) alarming.
5 reasons why China will rule tech, 2017 edition


I never would have thought of this.  I wonder if my students have a different perspective?
Now There's a Netflix-Like Service for Cadillacs
   Back in January, GM launched Book by Cadillac, a “luxury vehicle subscription service” that the company says is ideal for drivers that don’t want to “worry about insurance premiums, taxes, maintenance or mileage restrictions and no long-term commitment.”
Since its launch at the beginning of the year, 5,000 people have signed up for Book by Cadillac.  It’s currently only available in the New York City area, but the company has plans to expand the program to other parts of the country.
Membership is on a month-to-month basis, and for a one-time fee of $500 then $1500 each month, participants have access to 10 different current-year car models and can swap for a new one up to 18 times during the course of the year.


I must ask my students how many social media sites they visit on a given day.
Keeping on top of your social networks is no easy feat.  In an ideal world, there’d be one social network to keep up with.  Perhaps the next best thing is a platform that consolidates several of your social accounts and feeds into one place.
Hootsuite has stood the test of time.  It’s not perfect, but it’s by far the best option.  You won’t be able to use it for all of your social needs, but it can definitely help you stay up to date with more social networks, both via your browser and on mobile.


Something to watch for…
MIT SMR and MIT Press Announce Book Publishing Partnership
   it is with great excitement that I share the news that MIT Sloan Management Review and MIT Press are joining forces to launch two new book series exploring the digital frontiers of management.  One series will feature original titles.  The other series will collect the best MIT SMR articles on key digital topics.
   Look for more information about the series and how to submit proposals on our website coming soon.

Monday, March 20, 2017

Could it happen to courts in the US? 
Nic Andersen reports:
In our country at the moment, you blink once and there is another crisis.  This evening, shocking details have emerged of a very suspicious break-in at the offices of Chief Justice Mogoeng Mogoeng.  In the early hours of Saturday morning 15 computers were stolen, in South Africa that may sound normal to you, wait till you look closely at the finer details.
The 15 computers are said to contain “sensitive information” on the Constitutional Court judges and officials.  The computers were stolen from the Human Resources area of the office on the 1st floor, journalists on the scene also reported that the thieves ignored easier to access computers on the ground floor, meaning they targeted those computers specifically.
Read more on The South African.


AI is becoming so popular that we should do a seminar on it.  Oh, wait!  The Privacy Foundation is doing a Seminar, on April 28th at the DU Law School!  Stay tuned for details!
Guide to ILTA’s Artificial Intelligence Content
by Sabrina I. Pacifici on Mar 19, 2017
Joe Davis, Project Consultant, Prudential Financial, Inc. – “OK, so Watson won “Jeopardy!” back in 2011.  That’s ancient history in technology years.  ILTA provides a wealth of programming about the current state of affairs in Artificial Intelligence that will benefit law firms and corporate legal departments.  In the future, I’m sure we’ll have a bot to curate all this content for us.  In the meantime, below is a sampling of some of ILTA’s best AI-related content from ILTACON, Insight, webinars, white papers and Peer To Peer.”


I find myself asking, “Is this a real thing or a Trump thing?” 
New on LLRX – President’s Council of Advisors on Science and Technology Casts Doubt on Criminal Forensics
by Sabrina I. Pacifici on Mar 19, 2017
Via LLRX.com – The President’s Council of Advisors on Science and Technology (PCAST) stated in their report – “Among the more than 2.2 million inmates in U.S. prisons and jails, countless may have been convicted using unreliable or fabricated forensic science.  The U.S. has an abiding and unfulfilled moral obligation to free citizens who were imprisoned by such questionable means.”  Ken Strutin’s article features information about the PCAST Report, its reception by advocates and critics, and related articles, publications and developments concerning the science of innocence.


There was a time when this would have signaled that blockchain was ready “in all ways” for business.  IBM has lost that cachet, but this is still an indication that blockchain is real. 
IBM launches blockchain as a service for the enterprise
IBM has announced the launch of IBM Blockchain, a commercial service aimed at giving enterprise players the option to build their own scalable and secure blockchain networks.
The new service is based on the Linux Foundation's Hyperledger Fabric version 1.0, IBM said in a press release.
By utilizing Hyperledger, a cross-industry open-source effort to bring blockchain to businesses, Big Blue says that developers can quickly build and host secure blockchain networks via the IBM Cloud.
In order to enhance security, IBM Blockchain is also underpinned by IBM LinuxONE, a Linux server which is heavily influenced by security.


Resources for my students?
20,000 Worldclass University Lectures Made Illegal, So We Irrevocably Mirrored Them
Today, the University of California at Berkeley has deleted 20,000 college lectures from its YouTube channel.  Berkeley removed the videos because of a lawsuit brought by two students from another university under the Americans with Disabilities Act.
We copied all 20,000 and are making them permanently available for free via LBRY.
Is This Legal?
Almost certainly.


Tech for lawyers.  Very interesting slideshow.
ABA TechShow 2017 – 60 tips in 60 minutes
by Sabrina I. Pacifici on Mar 19, 2017
ABA TECHSHOW 2017: 60 tips in 60 minutes – Adam Camras, LegalTalkNetwork; Ivan Hemmans, O’Melveny & Myers LLP; Jack Newton, Clio; Deborah Savadra, Legal Office Guru; Rochelle Washington, DC Bar.


For my students?  (Found this in the lawyer tech slideshow, above.)
WordRake
The secret to writing well is rewriting.  WordRake tightens, tones, and clarifies your writing.  Just click the "rake" button and watch the in-line editor ripple through your document, suggesting edits to remove clutter and improve unclear phrasing, just like a live editor.  Give your first drafts the polish of a second or third draft, quickly and painlessly.

Sunday, March 19, 2017

You can’t close out that data breach file in just a few days or weeks.  
Law360 reports:
Neiman Marcus has agreed to pay $1.6 million to resolve a data breach class action in Illinois federal court over a December 2013 cyber intrusion that revealed the credit card data of 350,000 shoppers of the luxury retailer, according to a court document filed Friday.
Read more on Law360 if you have a subscription.  If you don’t have a subscription, don’t worry – I imagine other news outlets will also cover the settlement.
Past coverage of the breach and litigation on this site are linked from here.  The case may best be remembered for the Seventh Circuit’s reversal of the district court’s dismissal of the lawsuit for lack of standing.  Following that someone stunning reversal, the retailer failed to get the appeal reheard en banc, and then suffered a second loss back in district court when it also failed to get the case dismissed for failure to demonstrate negligence on their part.
I doubt most lawyers would have suggested that the retailer settle the suit when it was first filed, as most of these lawsuits that do not allege concrete injury actually did/do get dismissed for lack of standing.  So Neiman Marcus chose not to settle at the outset, and...  I wonder how much this litigation has cost them by now?  And what’s the value of the bad press of keeping their name in headlines associated with customer complaints?  With the benefit of hindsight, would they fight this all again? 


Interesting from several perspectives.  Does hacking the website make stealing the credit card information they are processing on another system easier?  
Brian Krebs reports:
For the second time in the past nine months, Google has inadvertently but nonetheless correctly helped to identify the source of a large credit card breach — by assigning a “This site may be hacked” warning beneath the search results for the Web site of a victimized merchant.
A little over a month ago, KrebsOnSecurity was contacted by multiple financial institutions whose anti-fraud teams were trying to trace the source of a great deal of fraud on cards that were all used at a handful of high-end restaurants around the country.
Two of those fraud teams shared a list of restaurants that all affected cardholders had visited recently.  A bit of searching online showed that nearly all of those establishments were run by Select Restaurants Inc., a Cleveland, Ohio company that owns a number of well-known eateries nationwide, including Boston’s Top of the Hub; Parker’s Lighthouse in Long Beach, Calif.; the Rusty Scupper in Baltimore, Md.; Parkers Blue Ash Tavern in Cincinnati, Ohio; Parkers’ Restaurant & Bar in Downers Grove, Illinois; Winberie’s Restaurant & Bar with locations in Oak Park, Illinois and Princeton and Summit, New Jersey; and Black Powder Tavern in Valley Forge, PA.
[…]
the breach involving Select Restaurant locations mentioned above appears to have been the result of an intrusion at the company’s POS vendor — Geneva, Ill. Based 24×7 Hospitality Technology.  24×7 handles credit and debit card transactions for thousands of hotels and restaurants, including more than 200 Buffalo Wild Wings franchises nationwide.
Read more on KrebsonSecurity.com.
[From the article: 
From my perspective, organized crime gangs have so completely overrun the hospitality and restaurant point-of-sale systems here in the United States that I just assume my card may very well be compromised whenever I use it at a restaurant or hotel bar/eatery.  I’ve received no fewer than three new credit cards over the past year, and I’d wager that in at least one of those cases I happened to have used the card at multiple merchants whose POS systems were hacked at the same time.


I think I have detected a trend.

(Related).


I read this as proof that Japan is taking North Korea seriously.  Somehow, I doubt North Korea see it the same way. 
Japan holds first-ever evacuation drill simulating North Korean missile strike into waters nearby
Amid a growing missile threat from North Korea, the northern city of Oga, Akita Prefecture, held Japan’s first-ever evacuation drill for local residents, gaming out a scenario in which Pyongyang lobs a ballistic missile into the waters nearby.


Perspective.
Raspberry Pi Surges To 3rd Best Selling Computer Of All Time Surpassing The Commodore 64
   It must be noted, however, that this is kind of an odd comparison to make.  During its heyday, the Commodore 64 cost a heck of a lot more than the $40 (or less) purchase price of today's RPis.  In that regard, it makes perfect sense that a capable little all-in-one motherboard would sell far more units than a $600+ PC from 35 years ago.  But the fact that RPi sold 12.5 million boards in 5 years is still downright impressive.