Wednesday, June 12, 2019


Not the best target to irritate…
Colin Lecher reports:
Since May 21st, a virus has shut down Philadelphia’s online court system, bringing network access to a standstill. The problems started unexpectedly: suddenly, no one could seem to access the system to file documents. “It wasn’t working,” says Rachel Gallegos, a senior staff attorney with the civil legal aid organization Community Legal Services. “I thought it was my computer.”
Read more on The Verge.




Another way to defy ransomware.
Alternative rock legends Radiohead on Tuesday released an 18-hour trove of private recordings from their 1997 album "OK Computer" after getting hacked by someone seeking a ransom of $150,000 for the music.
The genre-banding English musicians uploaded the 1.8-gigabyte collection of recording session outtakes and rare live performances on their radiohead.bandcamp.com website.
The songs can be accessed online for free.




Security is complicated. Third parties can help, but it’s still your responsibility.
Liisa Thomas, Sarah Aberg, Kari Rollins, and Katherine Boy Skipsey write:
The SEC recently issued a risk alert warning about using vendors and cloud-based platforms. Many broker dealers and investment advisors are turning to these third parties to store customer data. In its alert, the SEC’s Office of Compliance Inspections and Examinations warns firms that relying on those third parties’ security tools is not, in and of itself, sufficient for the companies to demonstrate compliance with Regulations S-P and S-ID. These regulations require broker-dealers and investment advisers to protect customer records and detect and prevent identity theft.
Read more on SheppardMullin Eye on Privacy.




Targeting fans.
Telecompaper reports:
Spain’s football league (La Liga) has been fined a total of EUR 250,000 by the country’s data protection agency (AEPD) for using a mobile app to remotely activate smartphone microphones, reports local daily El Diario. The league last year admitted that its highly popular official app, which is used by 4 million people in Spain to check incoming results live, can monitor user location and activate microphones to identify whether smartphone owners are watching a game at a public venue via an illegal feed. One of the app’s requested permissions is for access to user microphones and geopositioning “to detect fraud in the consumption of football in unauthorised public establishments”.
Read more on Telecompaper




More targets.
Cybersecurity: These are the Internet of Things devices that are most targeted by hackers
Research from cybersecurity company SAM Seamless Network found that security cameras represent 47 percent of vulnerable devices installed on home networks.
According to the data, the average US household contains 17 smart devices while European homes have an average of 14 devices connected to the network.
Figures from the security firm suggest that the average device is the target of an average of five attacks per day, with midnight the most common time for attacks to be executed – it's likely that at this time of the night, the users will be asleep and not paying attention to devices, so won't be witness to a burst of strange behavior.




Leading to a full Privacy law?
Daniel J. Moses of JacksonLewis writes:
As we recently noted, Washington state amended its data breach notification law on May 7  to expand the definition of “personal information” and shorten the notification deadline (among other changes ). Not to be outdone by its sister state to the north, Oregon followed suit shortly thereafter— Senate Bill 684 passed unanimously in both legislative bodies on May 20, and was signed into law by Governor Kate Brown on May 24. The amendments will become effective January 1, 2020.
Among the changes effected by SB 684 is a trimming of the Act’s short title—now styled the “Oregon Consumer Information Protection Act” or “OCIPA” (formerly the “Oregon Consumer Identity Theft Protection Act” or “OCITPA”). Apart from establishing a much more palatable acronym, the amended short title mirrors the national (and international ) trend of expanding laws beyond mere “identity theft protection” to focus on larger scale consumer privacy and data rights.


(Related)
Will R. Daugherty and Caroline B. Brackeen of BakerHostetler write:
Texas is one of the many states that looked to be following in the footsteps of California’s enactment of a broad consumer privacy law (the California Consumer Privacy Act), which has far-ranging implications for businesses and consumers. Two comprehensive data privacy bills, HB 4390 and HB 4518, were filed and heard at the last legislative session. HB 4518, also known as the Texas Consumer Privacy Act, proposed overarching consumer protection legislation that closely resembled the California Consumer Privacy Act. HB 4518 stalled in the Texas House of Representatives in favor of HB 4390. HB 4390, also known as the Texas Privacy Protection Act, was introduced as comprehensive data privacy legislation, but was significantly less detailed than HB 4518. HB 4390 went through several rounds of revisions in both the Texas House and Senate until it was whittled down to the final version, which revises the notification requirements of the Texas Identity Theft Enforcement and Protection Act and creates the Texas Privacy Protection Advisory Council in order to develop recommendations for future data privacy legislation. HB 4390 has passed both the Texas House and Senate and is awaiting signature from the governor to be enacted.
Read more on Data Privacy Monitor.




Worth studying.
Here’s Mary Meeker’s 2019 Internet Trends report
… This morning, Meeker highlighted slowed growth in e-commerce sales, increased internet ad spending, data growth, as well as the rise of freemium subscription business models, telemedicine, photo-sharing, interactive gaming, the on-demand economy and more.
If it feels like we’re all drinking from a data firehose, it’s because we are,” Meeker told the audience.
We’ll be back later with a full analysis of this year’s report. For now, here’s a look at all 333 slides. You can view the full internet trends report archive here.




How very James Bond. “Q” would be delighted.
Facebook lets deepfake Zuckerberg video stay on Instagram
The clip is a "deepfake", made by AI software that uses photos of a person to create a video of them in action.
Facebook had previously been criticised for not removing a doctored clip of US House Speaker Nancy Pelosi.
The deepfake video of Mark Zuckerberg was created for an art installation on display in Sheffield called Spectre. It is designed to draw attention to how people can be monitored and manipulated via social media in light of the Cambridge Analytica affair - among other scandals.
It features a computer-generated image of the chief executive's face merged with footage of his body sourced from a video presentation given in 2017 at an office in Facebook's Silicon Valley headquarters. An actor provided the audio recording it is synched to.
The 16-second clip - which plays on a loop - was uploaded to Instagram on Saturday.




How many can we trust?
Number of fact-checking outlets surges to 188 in more than 60 countries
Poynter – Strong growth in Asia and Latin America helps fuel global increase – “The number of fact-checking outlets around the world has grown to 188 in more than 60 countries amid global concerns about the spread of misinformation, according to the latest tally by the Duke Reporters’ Lab. Since the last annual fact-checking census in February 2018, we’ve added 39 more outlets that actively assess claims from politicians and social media, a 26% increase. The new total is also more than four times the 44 fact-checkers we counted when we launched our global database and map in 2014.




Fear?
What’s Behind the International Rush to Write an AI Rulebook?
There’s no better way of ensuring you win a race than by setting the rules yourself. That may be behind the recent rush by countries, international organizations, and companies to put forward their visions for how the AI race should be governed.
China became the latest to release a set of “ethical standards” for the development of AI last month, which might raise eyebrows given the country’s well-documented AI-powered state surveillance program and suspect approaches to privacy and human rights.
But given the recent flurry of AI guidelines, it may well have been motivated by a desire not to be left out of the conversation. The previous week the OECD, backed by the US, released its own “guiding principles” for the industry, and in April the EU released “ethical guidelines.”




30 years is near.
AI’s Near Future
Listen and subscribe to this podcast via Apple Podcasts | Google Podcasts | RSS
In this conversation, Jürgen and Azeem Azhar discuss what the next thirty years of AI will look like.




AI cheats!
Rock-Paper-Scissors Robot
How in the world did I not know about this for three years?
Researchers at the University of Tokyo have developed a robot that always wins at rock-paper-scissors. It watches the human player's hand, figures out which finger position the human is about to deploy, and reacts quickly enough to always win.




Will we need to delete the data and then retrain our AI? Expensive if necessary.
THE NEXT BIG PRIVACY HURDLE? TEACHING AI TO FORGET
WHEN THE EUROPEAN Union enacted the General Data Protection Regulation (GDPR) a year ago, one of the most revolutionary aspects of the regulation was the “right to be forgotten”—an often-hyped and debated right, sometimes perceived as empowering individuals to request the erasure of their information on the internet, most commonly from search engines or social networks.
… Virtually every modern enterprise is in some way or another collecting data on its customers or users, and that data is stored, sold, brokered, analyzed, and used to train AI systems. For instance, this is how recommendation engines work—the next video we should watch online, the next purchase, and so on, are all driven by this process.
At present, when data is sucked into this complex machinery, there’s no efficient way to reclaim it and its influence on the resulting output. When we think about exerting the right to be forgotten, we recognize that reclaiming specific data from a vast number of private businesses and data brokers offers its own unique challenge. However, we need to realize that even if we can succeed there, we’ll still be left with a difficult question—how do we teach a machine to “forget” something?




Perspective. My search for why.
The DOJ’s antitrust chief just telegraphed exactly how it could go after Google, Apple and other big tech companies
The Department of Justice’s assistant attorney general brought the case against big tech into focus in a new speech delivered at the Antitrust New Frontiers Conference in Tel Aviv on Tuesday.
Delrahim’s speech, as transcribed on the DOJ’s website, argues existing antitrust laws are strong enough to regulate tech.
We already have in our possession the tools we need to enforce the antitrust laws in cases involving digital technologies,” Delrahim said. “U.S. antitrust law is flexible enough to be applied to markets old and new.”
One way of evaluating whether a company has violated antitrust law is through what Delrahim called the “no economic sense test.” A monopoly that makes a decision that makes no economic sense except for “its tendancy to eliminate or lessen competition” would fail the test, according to Delrahim’s definition.




For my students.



Tuesday, June 11, 2019


If you gather data, you become a target for hackers.
Hackers Grabbed Security-Camera Images Taken At Border Crossing, CBP Says
Photos of travelers and their vehicle plates snapped at a U.S. border control point have been hacked, according to the Customs and Border Protection agency.
Customs officials said in a statement on Monday that the hack involves fewer than 100,000 people photographed inside vehicles — as well as images of the vehicle license plates — that were taken as travelers left the U.S. through specific lanes at a single, unspecified land-border crossing. The images were captured by CBP over a six-week period.
The images found their way into the database of a government subcontractor that hackers were able to penetrate, the agency said.
"Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract," CBP said in a statement.




Yes, I paranoid and yes, I think this is practice for the inevitable cyberwar.
China Telecom Routes European Traffic to Its Network for Two Hours
For two hours last week, a BGP route leak resulted in large portions of European Internet traffic being routed through China Telecom’s network.
According to a report from Oracle, the incident started at 09:43, on June 6, 2019, and consisted of Swiss data center colocation company Safe Host leaking over 70,000 routes to China Telecom in Frankfurt, Germany.
This is not the first route leak incident involving China Telecom and is likely not the last. A report published in December last year revealed that the carrier has been constantly misdirecting Internet traffic through its network in China for several years.
The new incident shows that the Chinese carrier has yet to take the necessary precautions to avoid similar re-routes from happening, and also proves that the problem of BGP route leaks continues to persist.




Change in thinking? Not really.
Microsoft says mandatory password changing is “ancient and obsolete”
ars technica – Bucking a major trend, company speaks out against the age-old practice. Microsoft is finally catching on to a maxim that security experts have almost universally accepted for years: periodic password changes are likely to do more harm than good. In a largely overlooked post published late last month, Microsoft said it was removing periodic password changes from the security baseline settings it recommends for customers and auditors. After decades of Microsoft recommending passwords be changed regularly, Microsoft employee Aaron Margosis said the requirement is an “ancient and obsolete mitigation of very low value.”
The change of heart is largely the result of research that shows passwords are most prone to cracking when they’re easy for end users to remember, such as when they use a name or phrase from a favorite movie or book. Over the past decade, hackers have mined real-world password breaches to assemble dictionaries of millions of words. Combined with super-fast graphics cards, the hackers can make huge numbers of guesses in off-line attacks, which occur when they steal the cryptographically scrambled hashes that represent the plaintext user passwords…”




Would you like to buy HIBP? Imagine what you could do if HIBP had more resources than a part-time genius can provide…
Project Svalbard: The Future of Have I Been Pwned




An interesting question for Computer Security and Architecture. This goes back at least to accountants bringing VisiCalc (and Apple computers) in without talking to IT.
When Employees Are Using Software That IT Hasn’t Approved




Perspective. Note: “Took in reports” is not the same as “investigated.” One percent success means 26,000 people became victims.
UK Tax Department Investigated over 2.6 Million Phishing Attacks in Three Years
According to a report from UK think tank Parliament Street, the country’s taxpayers are still among the most targeted groups. In the past three financial years, HRMC took in more than 2.6 million phishing reports, including tax rebate emails, phone calls and texts, Parliament Street says, based on information received from a Freedom of Information request.
According to the report, the success rate is under 1 percent.




Another version of a privacy law.
Nevada’s New Consumer Privacy Law Departs Significantly From The California CCPA
On May 29, 2019, the Governor of Nevada signed into law Senate Bill 220 (“SB 220”), an act relating to Internet privacy and amending Nevada’s existing law requiring websites and online services to post a privacy notice. In short, Nevada’s law will require operators of Internet websites and online services to follow a consumer’s direction not to sell his or her personal data. The Nevada law differs from the California Consumer Privacy Act (“CCPA”) enacted last year in notable ways, and could signal the coming of a patchwork of fifty-plus different data privacy standards across the country, much like the state data breach notification laws.




Oh, the poor publishers!
News Publishers Go To War With the Internet — and We All Lose
As I was sitting in the airport leaving Newsgeist Europe, a convening for journalists and publishers [disclosure: Google pays for the venue, food, and considerable drink; participants pay their own travel], my Twitter feed lit up like the Macy’s fireworks as The New York Times reported  — or rather, all but photocopied — a press release from the News Media Alliance (née Newspaper Association of America) contending that Google makes $4.7 billion a year from news, at the expense of news publishers.
Bullshit.




We haven’t heard from Kim in a while.
Kim Dotcom fights US extradition in New Zealand’s top court
Internet entrepreneur Kim Dotcom and three of his former colleagues on Monday took their fight against being extradited to the U.S. to New Zealand’s top court.
The Supreme Court began hearing arguments in the seven-year-old case after Dotcom and the others lost several previous court rulings.
But even if the men lose their latest appeal, they have legal options which could keep their case alive in the New Zealand court system and delay any extradition for several more years.
… Megaupload was once one of the internet’s most popular sites. U.S. prosecutors say it raked in at least $175 million, mainly from people using it to illegally download songs, television shows and movies.
Ira Rothken, one of Dotcom’s lawyers, said in an interview that if anyone did something illegal in relation to Megaupload, it was the users.
“This case is all about trying to hold Megaupload and Kim Dotcom and the others responsible for the acts of users,” Rothken said. “And we’re saying you can’t do that. You can’t do that in the United States and you can’t do that in New Zealand.”



Monday, June 10, 2019


Failure by design.
Security Oversight at First American Causes Data Leak of 900 Million Records
First American, the largest real estate title insurance company in the United States, just won a particularly awful silver medal. An ongoing data leak at the company appears to have exposed the transaction records of about 900 million customers, which would make it the second-largest data breach in history behind the 3 billion accounts that were impacted by the Yahoo! hack of 2013.
… The worst part of all this is that this devastating leak wasn’t the result of a phishing scam, or even an insecure Amazon bucket. First American appears to have failed to secure unique URLs to these documents properly, using a sequential system and allowing anyone to access customers information simply by entering the right URL into a web browser.




Not at the bleeding edge of election security. It also didn’t hurt that California now requires paper ballots.
Top voting machine maker reverses position on election security, promises paper ballots
Voting machine maker ES&S has said it “will no longer sell” paperless voting machines as the primary device for casting ballots in a jurisdiction.
ES&S chief executive Tom Burt confirmed the news in an op-ed.
TechCrunch understands the decision was made around the time that four senior Democratic lawmakers demanded to know why ES&S, and two other major voting machine makers, were still selling decade-old machines known to contain security flaws.
Burt’s op-ed said voting machines “must have physical paper records of votes” to prevent mistakes or tampering that could lead to improperly cast votes. Sen. Ron Wyden introduced a bill a year ago that would mandate voter-verified paper ballots for all election machines.




Think very carefully before you put words in Bill’s mouth. (Useful for generating confusion in the 2020 elections?)
Facebook’s AI system can speak with Bill Gates’s voice
The company’s AI researchers have developed a speech synthesizer capable of copying anybody’s voice with uncanny accuracy.




Not sure that the UN will follow, but it’s something to think about.
Estonia Speaks Out on Key Rules for Cyberspace
Speaking at the 2019 CyCon Conference, President Kersti Kaljulaid reaffirmed the applicability of international law in cyberspace before observing that “[s]overeignty entails not only rights, but also obligations.” She emphasized, drawing on the law of State responsibility, that States are responsible in law for “internationally wrongful cyber operations… whether or not such acts are carried out by state organs or by non-state actors supported or controlled by the state.” President Kaljulaid also powerfully stressed that “[i]f a cyber operation violates international law, this needs to be called out.” Doing so is crucial, for if interpretive efforts are to advance, States have to not only condemn other States for conducting hostile cyber operations, but also label them as violations of international law and specify the precise rule of law that they breached.




Another guesstimate. I think it’s much farther away than most experts.
How Far Are We From Achieving Artificial General Intelligence?
… Put simply, Artificial General Intelligence (AGI) can be defined as the ability of a machine to perform any task that a human can.
the rapid rate at which AI is developing new capabilities means that we might be get close to the inflection point when the AI research community surprises us with the development of artificial general intelligence. And experts have predicted the development of artificial intelligence to be achieved as early as by 2030. A survey of AI experts recently predicted the expected emergence of AGI or the singularity by the year 2060.
Thus, although in terms of capability, we are far from achieving artificial general intelligence, the exponential advancement of AI research may possibly culminate into the invention of artificial general intelligence within our lifetime or by the end of this century.




Architecture. Robots in Colorado.
INSIDE THE AMAZON WAREHOUSE WHERE HUMANS AND MACHINES BECOME ONE
… Amazon needs this robotic system to supercharge its order fulfillment process and make same-day delivery a widespread reality. But the implications strike at the very nature of modern labor: Humans and robots are fusing into a cohesive workforce, one that promises to harness the unique skills of both parties.



Sunday, June 09, 2019


An interesting look at the location data Apps are gathering. Will other types of data follow?
As you can see in the screenshots above, iOS 13 presents popup notifications when an app is using your location in the background. The notification also shows a map of the location data a specific app has tracked. The above screenshots show location data tracked by the Tesla app as well as the Apple Store app.
In addition to showing the map, the notification also presents the app’s reasoning for needing background location access.
Ideally, the new pop-up reminder notifications with map will make users more aware of how often apps are tracking them in the background. In certain instances, always allowing location access makes more sense – such as Tesla – but the developer explanations will have to convince users of that.




Nothing new here and I think that’s their point. “Give us GDPR or give up on privacy?”
Americans Deserve Strong Privacy Laws




Make anyone say anything just by typing? Spooky. Could make for some really amusing political ads…
Stanford engineers make editing video as easy as editing text
In television and film, actors often flub small bits of otherwise flawless performances. Other times they leave out a critical word. For editors, the only solution so far is to accept the flaws or fix them with expensive reshoots.
Imagine, however, if that editor could modify video using a text transcript. Much like word processing, the editor could easily add new words, delete unwanted ones or completely rearrange the pieces by dragging and dropping them as needed to assemble a finished video that looks almost flawless to the untrained eye.
… The work could be a boon for video editors and producers but does raise concerns as people increasingly question the validity of images and videos online, the authors said. However, they propose some guidelines for using these tools that would alert viewers and performers that the video has been manipulated.




A short summary. (PDF)
Ethical Guidelines for Artificial Intelligence (AI) Development and the New “Trust” Between Humans and Machines




A look far ahead? What happens when you AI says, “Please don’t turn me off!”
The Extension of Legal Personhood in Artificial Intelligence
The purpose of this paper is to illuminate the main ethical, legal and social implications (ELSIs) concerning social humanoid robots that have their base in artificial intelligence (AI).




Perspective.
The Next Big Phones Could Bring a Billion People Online
About half of humanity don’t have internet access, and a lot of those people are in Africa. Enter a $20 device with smartphone brains and a five-day battery.
… Do we really think the 50% of humanity without an internet connection would be better off with one?
Well, yeah. Greater internet access correlates directly with improved health care, education, gender equality, economic development, and lots of other goals well-financed nonprofits struggle to achieve. Boosting a poor country’s mobile internet use by 10% correlates with an average 2 percentage-point increase in gross domestic product, and electronic channels have proved capable of making governments more responsive to civic complaints, too.
… Two of the biggest mobile phone operators in Africa, MTN Group Ltd. of South Africa and France’s Orange SA, this year started selling quasi smartphones for as little as $20.




Is it rude to check your phone while talking to someone? Here’s a way to make it Okay!