Wednesday, March 29, 2017

The scam does not have to be very sophisticated as long as you try it on enough potential victims.  Remember, when it comes to IQ, “Half the world is below average.” 
Scammers scare iPhone users into paying to unlock not-really-locked Safari
   "One of our users alerted us to this campaign, and said he had lost control of Safari on his iPhone," Andrew Blaich, a Lookout security researcher, said in a Tuesday interview.  "He said, 'I can't use my browser anymore.'"
The criminal campaign, Blaich and two colleagues reported in a Monday post to Lookout's blog, exploited a bug in how Safari displayed JavaScript pop-ups.  When the browser reached a malicious site implanted with the attack code, the browser went into an endless loop of dialogs that refused to close no matter who many times "OK" was tapped.  The result: Safari was unusable.


At the same time, the attack showed a message, purportedly from a law enforcement agency, demanding payment to unlock the browser for, in one instance at least, simply steering to a URL that suggested the site's content was pornographic.  Payment was to be made by texting a £100 ($125) iTunes gift card code to a designated number.
Blaich stressed that the attack was as much scam as scare: To regain control of Safari, all one had to do was head to Settings, tap Safari, then Clear History and Website Data.
"This was a scareware attack, where [the attackers] were trying to get people to not think and just pay," said Blaich.


Those phony tax refunds must be costing the state money too. 
Liisa M. Thomas, Robert H. Newman, and Eric J. Shinabarger of Winston Strawn LLP write:
With little fanfare, Virginia recently amended its data breach notification law, requiring employers and payroll service providers to notify the Virginia Attorney General if they are subject to a W2 phishing scam.  More specifically, the law requires that they notify the Virginia AG if they discover “unauthorized access and acquisition of unencrypted computerized data containing a taxpayer identification number in combination with the income tax withhold for an individual” if there is compromise to the data and it will cause identity theft or fraud.  This requirement is the first of its kind, and will be effective July 1, 2017.
Read more on Lexology.


The US may not get around to this for a few years.  Say, one Presidential term. 
Jenny David reports:
Companies doing business in Israel will soon face mandatory data security and data breach notification requirements under regulations recently cleared by lawmakers.
The data security and breach notice had been governed by voluntary guidelines issued in 2012 by the country’s privacy regulator, the Israeli Law, Information and Technology Authority (ILITA).  Companies that didn’t implement measures when the voluntary guidelines were issued, including data breach notification, will have difficulty coming into compliance when the new regulations take full effect in 12 months, lawyers said.
Read more on Bloomberg BNA.


Just keeps growing the job market for my Computer Security students.
1.4 Billion Records Compromised in 2016: Report
Nearly 1.4 billion records were compromised in 2016 as a result of roughly 1,800 data breaches, according to Gemalto’s latest Breach Level Index report.
The company said the number of compromised records increased by 86 percent compared to the previous year.  The report also shows that more than 1,000 incidents, or 59 percent of the total, involved theft of identity information, while nearly 30 percent involved financial and account data.
Data collected by Gemalto shows that 68 percent of data breaches were the work of malicious external hackers, while 19 percent of incidents were classified as accidental leaks.  Malicious insiders accounted for 9 percent of breaches.
For a full summary of data breach incidents by industry, source, type and geographic region, download the  2016 Breach Level Index Report
Download the infographic here.


Can we wait for AI to learn on the job? 
It doesn’t take a tremendous amount of training to begin a job as a cashier at McDonald’s.  Even on their first day, most new cashiers are good enough.  And they improve as they serve more customers
   We don’t often think of it, but the same is true of commercial airline pilots.
   The difference between cashiers and pilots in what constitutes “good enough” is based on tolerance for error.  Obviously, our tolerance is much lower for pilots.
   The same is true of machines that learn.
Artificial intelligence (AI) applications are based on generating predictions.  Unlike traditionally programmed computer algorithms, designed to take data and follow a specified path to produce an outcome, machine learning, the most common approach to AI these days, involves algorithms evolving through various learning processes.  A machine is given data, including outcomes, it finds associations, and then, based on those associations, it takes new data it has never seen before and predicts an outcome.


A resource for Privacy, Ethics, and Artificial Intelligence.
European Data Protection Supervisor – New Website
by Sabrina I. Pacifici on Mar 28, 2017
“Our website has undergone quite a makeover!  With new features and drop down menus, we present you our new look website to share information about who we are and what we do.  Read how the EDPS is organised under the About EDPS section; for detailed information on our data protection work, Ethics, IPEN, Big Data and more, go to our Data Protection section.  Look in our Press & Publications section for our newsletter, blog, press releases, press kit and speeches. Happy browsing!”


I’d really like to see a full accounting of this.  As I understand it, employees created fake accounts and got paid for each one.  Then they cancelled the fake accounts, costing Wells Fargo again.  It seems there was no income to match against all this outgo.  Now they have to pay fines and settle lawsuits.  A good auditing department would have been far cheaper. 
Wells Fargo Reaches $110 Million Fake Accounts Settlement
Wells Fargo & Co. reached a $110 million settlement with customers nationwide over claims its employees set up fraudulent accounts to boost their own pay, a deal that moves the bank another step toward closing the books on last year’s scandal.
Revelations that Wells Fargo employees may have opened more than 2 million deposit and credit-card accounts without customers’ permission has prompted sweeping changes at the San Francisco-based lender.  The bank eliminated a system of sales targets that regulators said encouraged workers to create fake accounts.  It also fired or demoted five people who had served as senior managers in the consumer business.
Wells Fargo agreed six months ago to pay $185 million in fines and penalties as part of a settlement with federal regulators and the Los Angeles city attorney’s office.


Broader implications for ISPs? 
   According to the RIAA, Cloudflare should stop offering its services to all MP3Skull websites, arguing that the CDN provider was “in active concert or participation” with the pirates.
Cloudflare disagreed and countered that the DMCA protects it from liability for the copyright infringements of its customers, limiting the scope of anti-piracy injunctions.
   After hearing the arguments from both sides, the court has now ruled against Cloudflare’s DMCA defense, opening the door for an injunction against the CDN provider itself.


Should I assume these are the Brits who did not vote to leave the EU?
Estonia e-residency applications from U.K. surge as Britain prepares to trigger Brexit talks
If there’s a silver lining to the looming start of the contentious Brexit process, it can be found in the Eastern European country of Estonia.
The country, which two years ago launched a program to allow anyone to apply for digital residency, said this week that it has seen a surge of applications from people living in the U.K. over the past several months.  And it’s expecting that pace to accelerate again, with the U.K. government expected on Wednesday to announce it has taken the steps to officially trigger the start of talks for it withdraw from the European Union.


For my Spreadsheet students.
Calculating the right amount of tax is important. It can also be difficult.  With that in mind, I’ve tracked down two Excel tax calculators to ensure you don’t miss a single penny.
I’ve made every effort to ensure these tax calculators work as they should — and they do — but your taxes are your responsibility.  We’re just helping you on the way.


For the toolkit.  Install it on your thumb drive. 
   occasionally you find an app so ordinary that it feels lost among the crowd of shiny new tools.  But give AutoSaver a chance to impress you because it’s all about that everyday productivity.
   AutoSaver automatically saves your work in any file or tool you’re using according to a pre-set interval (minimum is one minute).
There are two other good things about this app:
  • It’s a tiny freeware download of 21 KB.
  • It’s a portable app that you don’t need to install.


This is why Wally is my role model.

Tuesday, March 28, 2017

Because laptops (or voters) have no value?  At least they were encrypted. 
Ng Kang-chung reports:
In what could be one of Hong Kong’s most significant data breaches ever, the personal information of the city’s 3.7 million voters was possibly compromised after the Registration and Electoral Office reported two laptop computers went missing at its backup venue for the chief executive election.
The devices also stored the names of the 1,200 electors on the Election Committee who selected Carrie Lam Cheng Yuet-ngor as Hong Kong’s new chief executive on Sunday.


Another warning. 
MIT – FBI’s Facial Recognition Program Is Sprawling and Inaccurate
by Sabrina I. Pacifici on Mar 27, 2017
“Last year, we learned about the remarkable scale of the FBI’s facial-recognition technology, with its access to nearly 412 million photos—many originating from sources unrelated to crime, such as ID documents.  The intelligence agency has been trying to create a system that can accurately identify criminals in, say, CCTV footage—though it wasn’t then known how well the bureau’s software worked, nor whether it actually improved investigations.  Now, we have at least a little more insight into the program.  The Guardian reports that a House oversight committee hearing last week revealed some interesting new details about the proliferation and abilities of the FBI’s facial-recognition systems…”


The technology is working fine, it’s those dang humans that are slowing everything down!
Starbucks says that crowd of people waiting for their Frappuccinos is hurting sales
Mobile pay is speeding Starbucks customers through the checkout line, but a bottleneck is building for the baristas.
   While these transactions are a boon for the coffee giant, the increase in volume has hurt same-store sales.  That's because congestion at the hand-off counter has caused incoming customers to leave without making a purchase, despite lines at the register being short, said Kevin Johnson, Starbucks' president and soon-to-be CEO, during an earnings conference call.
   Starbucks managers across the U.S. have designed their own solutions to this bottlenecking by employing additional staff members, redeploying already hired employees and adding mobile kiosks designed specifically for customers who used the company's mobile pay and ordering.


Keeping up with the competition.  Of course, you would have to pass my test to graduate.  So, not much risk.
Coding Schools Build Tuition-Back Guarantees Into Business Model
Guarantees may be a scary prospect for four-year colleges, but they are built into the business model of the new and rapidly growing for-profit coding boot camps, which depends on students seeing a solid return on their investment.
Udacity, a Silicon Valley-based online course provider last year launched a deal on a nano-credential—find a job in six months or get your tuition back.  The program cost is between $2,000 and $3,000.


This would be funny if it wasn’t so sad.
Trump’s son-in-law, Jared Kushner, prepares for Cobol, cloud, mainframes
   The White House on Monday announced an "Office of American Innovation," which will be tasked with "modernizing the technology of every federal department," said Sean Spicer, the White House press secretary, at his daily briefing Monday.
   The House approved that funding after the Oversight and Government Reform Committee last year held a Cobol-bashing hearing.
The committee, in building support for modernizing federal IT, pointed out that there were at least 3,500 federal IT employees at work to maintain "legacy" languages, including 1,100 employees dedicated to Cobol.


AGI (Artificial general intelligence) resources. 
Research – Open AI
by on

(Related).  Thinking about AI.  Interesting graphic…
Elon Musk’s Billion-Dollar Crusade to Stop the A.I. Apocalypse


Geeky stuff.
As far as JavaScript web development is concerned, React is one of the easiest frameworks to learn and one of the most effective for rapid and robust development.
   most worthwhile React courses come with a hefty price tag.  For example, the highly-acclaimed React for Beginners course is $89 (starter version) and $127 (master version).  Free courses are rarely as comprehensive and helpful — but we’ve found several that are excellent and will get you started on the right foot.


You have got to really, really want something like this.
Giant Gold Coin Worth $4 Million Stolen in Berlin Museum Heist
Burglars stole a 100-kilogram (220-pound), solid-gold coin worth $4 million from a Berlin museum in a heist out of a Hollywood movie.
   The coin is as big as a car tire.


For my geeks.
The Gearhead Toolbox: Raspberry Pi tools
   The uses for ALPR, Automatic License Plate Recognition, cover a wide range from monitoring traffic and locating stolen vehicles, to controlling gates and parking access.  Using a Raspberry Pi for this is a great opportunity to create a low-cost, easily deployed system and OpenALPR is one of the leading ALPR packages you can choose.

Ditto.  Please, not in the halls.
It’s not every day that you’re surprised by tech. Usually, the outlandish ideas fail; but sometimes, they work.  So, does the Vidius HD budget FPV/VR Streaming Drone — which streams images to a smartphone-powered VR headset — surprise, or disappoint?
The Aerix Vidius HD is available now for $95 with the headset, or $75 without.

Again, ditto.
   What you should do depends on whether the hard drive is working or dead.  But surprisingly, a functional old HDD has fewer uses than a dead one.

Monday, March 27, 2017

This seems to be a good idea.  Why didn’t we think of it? 
Two companies have been fined a total of £83,000 for breaking the rules about how people’s personal information should be treated when sending marketing emails.
An investigation by the Information Commissioner’s Office (ICO) found Exeter-based airline Flybe deliberately sent more than 3.3 million emails to people who had told them they didn’t want to receive marketing emails from the firm.
   The airline has now been fined £70,000 for breaking the Privacy and Electronic Communication Regulations (PECR).
A separate ICO investigation into Honda Motor Europe Ltd revealed the car company had sent 289,790 emails aiming to clarify certain customers’ choices for receiving marketing.
The firm believed the emails were not classed as marketing but instead were customer service emails to help the company comply with data protection law.  Honda couldn’t provide evidence that the customers’ had ever given consent to receive this type of email, which is a breach of PECR.  The ICO fined it £13,000.


Would you like either device “always listening” in your hotel room?
Amazon’s Alexa takes its fight with Siri to Marriott hotel rooms
Amazon.com’s battle with Apple over digital assistants is moving to a new venue: hotel rooms, where Alexa and Siri are vying to be the voice-controlled platform of choice for travelers.
Marriott International, the world’s biggest lodging company, is testing devices from the two tech giants at its Aloft hotel in Boston’s Seaport district to determine which is best to let guests turn on lights, close drapes, control room temperature and change television channels via voice command.  In December, Wynn Resorts Ltd. became the first hotel company to install Alexa-powered Echo devices, starting with suites at its flagship Wynn Las Vegas property.


“How much cheaper?”  The first thing my students asked. 
AI and insurance: Exchanging privacy for a cheaper rate
   you should pay particular attention to the fact that the global insurance industry is seeking to harness artificial intelligence solutions.  While the use of AI technologies in insurance has the potential to streamline company operations and reduce consumer prices, it also raises unprecedented new issues related to personal privacy.
   What’s distinctive about the insurance industry’s adoption of AI is how these companies intend to collect their data.  Insurers are turning to sensors to collect data directly from individuals, including technologies like in-home monitors and wearables.  And whenever data collection intersects with a real person, privacy questions emerge.  Do you want your healthcare provider receiving a real-time notification of your late-night snacking?  Do you want your auto insurer to know every time you roll through a stop sign?  These are no longer hypotheticals.


Using AI to take as much of your money as possible? 
The High-Speed Trading Behind Your Amazon Purchase
   Just beneath the placid surface of a typical product page on Amazon lies an unseen world, a system where third-party vendors can sell products alongside Amazon's own goods.  It's like a stock market, complete with day traders, code-slinging quants, artificial intelligence algorithms and, yes, flash crashes.  
   It's clear, after talking to sellers and the software companies that empower them, that the biggest of these vendors are growing into sophisticated retailers in their own right.  The top few hundred use pricing algorithms to battle with one another for the coveted "Buy Box," which designates the default seller of an item.  It's the Amazon equivalent of a No. 1 ranking on Google search, and a tremendous driver of sales.  


A tweak for my students.  What (if anything) do they think? 
US Supreme Court Hears Oral Arguments Over Your Right To Refill Ink And Toner Cartridges
   Lexmark offers a “shrink-wrap license” in which customers can purchase cartridges at a discounted rate if they agree to not resell or reuse them.  The customer essentially accepts the agreement once they have opened the cartridge’s packing.  Lexmark argues that customers cannot resell or reuse the cartridges because the item technically never belonged to the customer.
Impression Products is fighting back with the concept of “patent exhaustion”.  This concept states that a manufacturer loses their rights to control the fate of their products once they have been sold to a customer.  If a customer purchases an item, they may reuse or resell it.


They also have a Beta version for APA.
How Formatically Helps Students Format Essays in MLA Style
A couple of weeks ago I shared a new tool designed by college students to help other students properly format essays in MLA format.  That tool is called Formatically.  I've had a few people send me questions about how it works.  It essentially gives students a template in Word format that they can then use to write their essays in.  In the following short video I demonstrate how to use Formatically.

Sunday, March 26, 2017

Any excuse to claim that terrorists are uncatchable, but nothing about this guy’s earlier encounters with police?  
London attack reignites encryption debate, as U.K. govt. says ‘there should be no place for terrorists to hide’
   reports have since surfaced that the perpetrator, British man Khalid Masood, was using WhatsApp minutes before he mowed down pedestrians on Westminster bridge and fatally stabbed a policeman.  However, police so far have indicated that Masood was a so-called “lone wolf” killer, and there is nothing so far to suggest that WhatsApp played any direct part in the attack — all we know is that Masood had checked his WhatsApp account shortly before, according to a screenshot taken by the Daily Mail.


Yes, they are publicly available.  Yes, it is the owners’ responsibility to protect sensitive data.  This is what happens when owners don’t do their job!
Microsoft yanks Docs.com search after complaints of exposed sensitive files
Microsoft has quietly removed a feature on its document sharing site Docs.com that allowed anyone to search through millions of files for sensitive and personal information.
Users had complained over the weekend on Twitter that anyone could use the site's search box to trawl through publicly-accessible documents and files stored on the site, which were clearly meant to remain private.
Among the files reviewed by ZDNet, and seen by others who tweeted about them, included password lists, job acceptance letters, investment portfolios, divorce settlement agreements, and credit card statements -- some of which contained Social Security and driving license numbers, dates of birth, phone numbers, and email and postal addresses.


For my Computer Security students.
Windows 10 is recording everything you type - here's how to stop Microsoft tracking you
   It's emerged that Microsoft's latest computer friendly operating system has been recording everything you've typed since it first launched without you knowing.
   More than that, if you've made voice searches, all of your vocal commands and message dictations have been recorded too.


Cute!  This may save time in my website class.
25 Features Every Business Website Must Have in 2017 (Infographic)

Saturday, March 25, 2017

I may ask my students to explain security on all the social media they use.  Is this sufficient? 
Facebook’s ubiquity makes it dangerous in so many ways.  Aside from the threat of picking up malware, the ever-present risk of someone hacking your account — plus privacy issues from Facebook itself — mean you must be vigilant when using the service.
Thankfully, it only takes a few moments to make sure you’re not at risk for Facebook issues.  Here are six easy ways to avoid becoming a victim on Facebook.


I don’t see much of a downside here if they do what they say they will do. 
T-Mobile is rolling out scam warnings on incoming calls
T-Mobile is trying to help its subscribers dodge more spammy calls.
The carrier is going to begin warning subscribers when an incoming phone call appears to be from a scammer.  If a scam call is detected, the caller ID will display as “Scam Likely,” giving subscribers a heads up before they answer or the chance to just ignore it outright.
T-Mobile will also let subscribers block all suspected scam calls so those calls never reach their phones in the first place.  But subscribers will have to actively opt in to the blocking service, as there’s a chance the carrier could accidentally filter out legitimate numbers.
   T-Mobile says its service works by comparing phone numbers to a list of “tens of thousands” of known scammers.  The database is constantly updated, the company says, by analyzing call patterns.  So it sounds like T-Mobile might catch on to new scam numbers if it notices a bunch of subscribers immediately hanging up on a number they’ve never contacted before.


We’re still drawing the line between public and private.  
Kelsi Loos reports:
A man charged with killing a Frederick County resident in an alleged MS-13 gang hit contended that police violated his rights when they seized his Facebook account and searched his apartment.
This month, Raul Ernesto Landaverde Giron joined co-defendants, other accused gang members.  They asked the U.S. District Court of Maryland to disregard evidence collected from social media accounts, arguing that the Fourth Amendment protected the private communications against search and seizure.
Defense attorneys noted that the Maryland federal district court had not yet considered whether Facebook messages are protected under the law, but other federal courts had said private messages on the social media site are entitled to Fourth Amendment protection.
Read more on the Frederick News-Post.


There should be a “guide to paying for law school” and this should be in it. 
There’s Money in Faxes—for Plaintiffs
In the annals of modern technology, the fax machine has nearly gone the way of the floppy disk.
But some enterprising plaintiffs’ attorneys are still turning faxes into money, using a decades-old federal statute aimed at protecting consumers from overzealous marketers.
The stakes are high: The law allows recipients of unwanted fax advertisements to recover at least $500 per message from a sender, an amount that can turn a proposed class-action lawsuit into a multimillion-dollar business threat.


Apparently, “Fake News” is anything you wish it to be.  But (see yesterday’s blog) this is very much what Sloan said, except for the timeline.  
Tech community "dumbfounded" by Mnuchin's dismissal of AI impact on jobs
Treasury Secretary Steve Mnuchin riled the tech community this morning when he told Axios' Mike Allen that displacement of jobs by artificial intelligence and automation is "not even on my radar screen" because the technology is "50-100 more years" away.  Mnuchin also said he is "not worried at all" about robots displacing humans in the near future.  "In fact, I'm optimistic."


Keeping current.  
Rust, React, JavaScript, Python top Stack Overflow survey
   The annual survey, which had 64,000 developers participating worldwide in January and February, uncovered a wide range of experience levels.  Thanks to online courses and coding boot camps, adults with little to no programming experience can now more easily transition to a career as a developer, Stack Overflow said.  Slightly more than 50 percent of respondents had been coding professionally for about five years or fewer, while just 7.5 percent were coding for 20 years or more.  
   If developers want to make the most money, the technology to learn worldwide is Clojure, a Lisp dialect for the JVM, the survey found.  In the United States, Google's Go and Scala can yield the highest paychecks.  "Globally, developers who use Clojure in their jobs have the highest average salary at $72,000," Stack Overflow said. Rust followed at $65,714.  "In the U.S., developers who use Go as well as developers who use Scala are highest paid, with an average salary of $110,000."  
Stack Overflow also asked developers about which languages they are using, as well as which ones they like and dislike.  JavaScript (62.5 percent), SQL (51.2 ), and Java (39.7) remain the most commonly used programming languages.  But Rust, with 73.1 percent of users wanting to keep working with it, was the most loved language, followed by SmallTalk (67), and TypeScript (64.1).  "This means that proportionally, more developers wanted to continue working with [Rust] than any other language," the report stated.  "Swift, last year's second most popular language, ranked as fourth." 
The most wanted languages were Python (20.8 percent), JavaScript (18.6), and Go (13.5).  "Python shot to the most-wanted language this year (as in, the language developers want to use this year more than any other), after ranking fourth last year," Stack Overflow said.  Hanlon cited Python's usage in data science and its interest among developers as boosting its popularity.


The last bastions have fallen.
The holiday is over: Amazon will collect sales taxes nationwide on April 1
Amazon, the online merchandise juggernaut, will collect sales taxes from all states with a sales tax starting April 1.
Tax-free shopping will be over as of next month in Hawaii, Idaho, Maine and New Mexico, the four remaining holdouts.
   After April, the only states in which Amazon won't collect taxes are Alaska, Delaware, Oregon, Montana and New Hampshire.  These five states don't have sales levies.


For my next Statistics class.
3 ways to spot a bad statistic