Thursday, August 22, 2019


My students will have to figure this out.
How New A.I. Is Making the Law’s Definition of Hacking Obsolete
In April this year, a research team at the Chinese tech giant Tencent showed that a Tesla Model S in autopilot mode could be tricked into following a bend in the road that didn’t exist simply by adding stickers to the road in a particular pattern. Earlier research in the U.S. had shown that small changes to a stop sign could cause a driverless car to mistakenly perceive it as a speed limit sign. Another study found that by playing tones indecipherable to a person, a malicious attacker could cause an Amazon Echo to order unwanted items.
These discoveries are part of a growing area of study known as adversarial machine learning. As more machines become artificially intelligent, computer scientists are learning that A.I. can be manipulated into perceiving the world in wrong, sometimes dangerous ways. And because these techniques “trick” the system instead of “hacking” it, federal laws and security standards may not protect us from these malicious new behaviors — and the serious consequences they can have.




Are they being overly secretive or do they just not know?
Attackers Demand Millions in Texas Ransomware Incident
The cybercriminals behind the recent ransomware incident that impacted over 20 local governments in Texas are apparently demanding $2.5 million in exchange for access to encrypted data.
The incident took place on August 16, when 23 towns in Texas revealed they were targeted in a coordinated attack to infect their systems with ransomware.
City of Borger was one of the victims, with its business and financial operations and services impacted by ransomware, although basic and emergency services continued to be operational.
Currently, Vital Statistics (birth and death certificates) remains offline, and the City is unable to take utility or other payments. Until such time as normal operations resume, no late fees will be assessed, and no services will be shut off,” the city said earlier this week (PDF ).
City of Keene was also affected, being unable to process utility payments.




Listen to other views and carefully consider. (Then burst out laughing?)
Political Confessional: The Man Who Thinks Mass Surveillance Can Work
This week we talked to Owen, a 37-year-old white man from the Bay Area in California. He wrote that he is “open to mass surveillance if it can lead to a world where a much higher percent of crimes are caught, leading to better public safety and, ideally, shorter [or] lighter sentences (because you don’t need as big a threat of punishment to deter people from crimes if the likelihood of catching them is very high).”




Creating the Terminator?
CRS Report to Congress on Lethal Autonomous Weapon Systems
The following is the August 16, 2019 Congressional Research Service In Focus report – International Discussions Concerning Lethal Autonomous Weapon Systems. “As technology, particularly artificial intelligence (AI), advances, lethal autonomous weapon systems (LAWS)—weapons designed to make decisions about using lethal force without manual human control—may soon make their appearance, raising a number of potential ethical, diplomatic, legal, and strategic concerns for Congress. By providing a brief overview of ongoing international discussions concerning LAWS, this In Focus seeks to assist Congress as it conducts oversight hearings on AI within the military (as the House and Senate Committees on Armed Services have done in recent years), guides U.S. foreign policy, and makes funding and authorization decisions related to LAWS…”


(Related) An alternate view...
Amazon, Microsoft, May be Putting World at Risk of Killer AI, Says Report
Amazon, Microsoft and Intel are among leading tech companies putting the world at risk through killer robot development, according to a report that surveyed major players from the sector about their stance on lethal autonomous weapons.
Dutch NGO Pax ranked 50 companies by three criteria: whether they were developing technology that could be relevant to deadly AI, whether they were working on related military projects, and if they had committed to abstaining from contributing in the future.
"Why are companies like Microsoft and Amazon not denying that they're currently developing these highly controversial weapons, which could decide to kill people without direct human involvement?" said Frank Slijper, lead author of the report published this week.
The report noted that Microsoft employees had also voiced their opposition to a US Army contract for an augmented reality headset, HoloLens, that aims at "increasing lethality" on the battlefield.




Make the world safe from the Terminator?
IBM joins Linux Foundation AI to promote open source trusted AI workflows
AI is advancing rapidly within the enterprise -- by Gartner's count, more than half of organizations already have at least one AI deployment in operation, and they're planning to substantially accelerate their AI adoption within the next few years. At the same time, the organizations building and deploying these tools have yet to really grapple with the flaws and shortcomings of AI – whether the models deployed are fair, ethical, secure or even explainable.
Before the world is overrun with flawed AI systems, IBM is aiming to rev up the development of open source trusted AI workflows. As part of that effort, the company is joining the Linux Foundation AI (LF AI) as a General Member.
As a Linux Foundation project, the LF AI Foundation provides a vendor-neutral space for the promotion of Artificial Intelligence (AI), Machine Learning (ML) and Deep Learning (DL) open source projects. It's backed by major organizations like AT&T, Baidu, Ericsson, Nokia and Huawei.
IBM has already spearheaded efforts on this front with a series of open source toolkits designed to help build trusted AI. The AI Fairness 360 Toolkit helps developers and data scientists detect and mitigate unwanted bias in machine learning models and datasets. The Adversarial Robustness 360 Toolbox is an open source library that helps researchers and developers defend deep neural networks from adversarial attacks. Meanwhile, the AI Explainability 360 Toolkit provides a set of algorithms, code, guides, tutorials and demos to support the interpretability and explainability of machine learning models.




We need ethics, we just don’t need them right now.” What can we agree on today?
International AI ethics panel must be independent
China wants to be the world’s leader in artificial intelligence (AI) by 2030. The United States has a strategic plan to retain the top spot, and, by some measures, already leads in influential papers, hardware and AI talent. Other wealthy nations are also jockeying for a place in the world AI league.
A kind of AI arms race is under way, and governments and corporations are pouring eye-watering sums into research and development. The prize, and it’s a big one, is that AI is forecast to add around US$15 trillion to the world economy by 2030 — more than four times the 2017 gross domestic product of Germany. That’s $15 trillion in new companies, jobs, products, ways of working and forms of leisure, and it explains why countries are competing so vigorously for a slice of the pie.
Officials from Canada and France, meanwhile, have been working to establish an International Panel on Artificial Intelligence (IPAI), to be launched at the G7 summit of world leaders in Biarritz, France, from 24 to 26 August.
… To be credible, the IPAI has to be different. It needs the support of more countries, but it must also commit to openness and transparency. Scientific advice must be published in full. Meetings should be open to observers and the media. Reassuringly, the panel’s secretariat is described in documents as “independent”. That’s an important signal.




Looks interesting.
Data Management Law for the 2020s: The Lost Origins and the New Needs
Pałka, Przemysław, Data Management Law for the 2020s: The Lost Origins and the New Needs (August 10, 2019). Available at SSRN: https://ssrn.com/abstract=3435608 or http://dx.doi.org/10.2139/ssrn.3435608
In the data analytics society, each individual’s disclosure of personal information imposes costs on others. This disclosure enables companies, deploying novel forms of data analytics, to infer new knowledge about other people and to use this knowledge to engage in potentially harmful activities. These harms go beyond privacy and include difficult to detect price discrimination, preference manipulation, and even social exclusion. Currently existing, individual-focused, data protection regimes leave law unable to account for these social costs or to manage them. This Article suggests a way out, by proposing to re-conceptualize the problem of social costs of data analytics through the new frame of “data management law.” It offers a critical comparison of the two existing models of data governance: the American “notice and choice” approach and the European “personal data protection” regime (currently expressed in the GDPR). Tracing their origin to a single report issued in 1973, the article demonstrates how they developed differently under the influence of different ideologies (market-centered liberalism, and human rights, respectively). It also shows how both ultimately failed at addressing the challenges outlined already forty-five years ago. To tackle these challenges, this Article argues for three normative shifts. First, it proposes to go beyond “privacy” and towards “social costs of data management” as the framework for conceptualizing and mitigating negative effects of corporate data usage. Second, it argues to go beyond the individual interests, to account for collective ones, and to replace contracts with regulation as the means of creating norms governing data management. Third, it argues that the nature of the decisions about these norms is political, and so political means, in place of technocratic solutions, need to be employed.”



Wednesday, August 21, 2019


Looks like it will take a while for a comprehensive report on this attack.
Information Concerning the August 2019 Texas Cyber Incident
Below is an update as of August 20, 2019, at approximately 3:00 p.m. central time.
    • The number of confirmed impacted entities has been reduced to twenty-two.
    • More than twenty-five percent of the impacted entities have transitioned from response and assessment to remediation and recovery, with a number of entities back to operations as usual.


(Related)
Study: Americans won’t vote for candidates who approve ransomware payments
New research by The Harris Poll reveals that 64% of registered voters will not vote for candidates who approve of making ransomware payments.




Pre-crime.
Law Enforcement To Flag & Spy On Future Criminals
A recent Albuquerque Journal article revealed that law enforcement will flag people that they think might pose a potential risk.
What types of things could Americans do that law enforcement would consider threatening?
Inside Sources revealed that police would be looking for "certain indicators."
State Police Chief Tim Johnson said, “I think it’s obviously important for all of the citizens of New Mexico to be on the lookout for certain indicators of these types of folks that would do this. And part of our job as government officials is to ensure that the citizens of the community understand what those indicators are so they can report them."
The Tampa Bay Times reports that police are looking for “certain critical threat indicators” on students social media posts and have even created their own FortifyFL app that allows anyone to secretly report suspicious behavior.
What these "indicators" are is anyone's guess.




Not in the US, yet.
You Can Finally See All Info Facebook Collected About You From Other Websites
BuzzFeed News – “…Facebook collects information about its users in two ways: first, through the information you input into its website and apps, and second, by tracking which websites you visit while you’re not on Facebook. That’s why, after you visit a clothing retailer’s website, you’ll likely see an ad for it in your Facebook News Feed or Instagram feed. Basically, Facebook monitors where you go, all across the internet, and uses your digital footprints to target you with ads. But Facebook users have never been able to view this external data Facebook collected about them, until now. Facebook tracks your browsing history via the “Login with Facebook” button, the “like” button, Facebook comments, and little bits of invisible code, called the Facebook pixel, embedded on other sites (including BuzzFeed News). Today the company will start to roll out a feature called “Off-Facebook Activity” that allows people to manage that external browsing data — finally delivering on a promise it made over a year ago when CEO Mark Zuckerberg announced at a company event that it would develop a feature then called “Clear History.”
The new tool will display a summary of those third-party websites that shared your visit with Facebook, and will allow you to disconnect that browsing history from your Facebook account. You can also opt out of future off-Facebook activity tracking, or selectively stop certain websites from sending your browsing activity to Facebook. Nearly a third of all websites include a Facebook tracker, according to several studies. Some people in Ireland, South Korea, and Spain will gain access to Off-Facebook Activity first. Facebook said it will continue rolling out the feature everywhere else over the coming months. The tool, found in account Settings > Off-Facebook Activity, includes an option allowing you to “clear” your browsing history…”
See also the related Facebook Newsroom blog posting.




There is a big difference between, “Hey! We have this shiny new tool!” and “Hey! We know how to use this shiny new tool!”
Flawed Algorithms Are Grading Millions of Students’ Essays
Fooled by gibberish and highly susceptible to human bias, automated essay-scoring systems are being increasingly adopted, a Motherboard investigation has found
Of those 21 states, three said every essay is also graded by a human. But in the remaining 18 states, only a small percentage of students’ essays—it varies between 5 to 20 percent—will be randomly selected for a human grader to double check the machine’s work.
But research from psychometricians—professionals who study testing—and AI experts, as well as documents obtained by Motherboard, show that these tools are susceptible to a flaw that has repeatedly sprung up in the AI world: bias against certain demographic groups. And as a Motherboard experiment demonstrated, some of the systems can be fooled by nonsense essays with sophisticated vocabulary.




Fuel for an interesting discussion.
RPA And Machine Learning Brings Us The Autonomous Data Centre
As we enter this new revolution in how businesses operate, it’s essential that every piece of data is handled and used appropriately to optimise its value. Without cost-effective storage and increasingly powerful hardware, digital transformation and the new business models associated with it wouldn’t be possible.
Experts have been predicting for some time that the automation technologies that are applied in factories worldwide would be applied to datacentres in the future. The truth is that we’re rapidly advancing this possibility with the application of Robotic Process Automation (RPA) and machine learning in the datacentre environment.




Perspective.
A Week in the Life of Popular YouTube Channels
An analysis of every video posted by high-subscriber channels in the first week of 2019 finds that children’s content as well as content featuring children – received more views than other video”
The media landscape was upended more than a decade ago when the video-sharing site YouTube was launched. The volume and variety of content posted on the site is staggering. The site’s popularity makes it a launchpad for performers, businesses and commentators on every conceivable subject. And like many platforms in the modern digital ecosystem, YouTube has in recent years become a flashpoint in ongoing debates over issues such as online harassment, misinformation and the impact of technology on children. Amid this growing focus, and in an effort to continue demystifying the content of this popular source of information, Pew Research Center used its own custom mapping technique to assemble a list of popular YouTube channels (those with at least 250,000 subscribers) that existed as of late 2018, then conducted a large-scale analysis of the videos those channels produced in the first week of 2019. The Center identified a total of 43,770 of these high-subscriber channels using a process similar to the one used in our study of the YouTube recommendation algorithm. This data collection produced a variety of insights into the nature of content on the platform: The YouTube ecosystem produces a vast quantity of content. These popular channels alone posted nearly a quarter-million videos in the first seven days of 2019, totaling 48,486 hours of content. To put this figure in context, a single person watching videos for eight hours a day (with no breaks or days off) would need more than 16 years to watch all the content posted by just the most popular channels on the platform during a single week. The average video posted by these channels during this time period was roughly 12 minutes long and received 58,358 views during its first week on the site…”




Next, speech to sign?
Google's AI allows smartphones to translate sign language



Tuesday, August 20, 2019


Not sure I understand this one.
Al Restar reports:
The Australian court ruled that employees are allowed to refuse to provide biometric data to their employees. The ruling follows the lawsuit filed by Jeremy Lee getting fired from his previous job due to his refusal of providing his fingerprint samples for the company’s newly installed fingerprint login system.
Jeremy Lee from Queensland, Australia, won a landmark case after he was fired from his job at Superior Wood Pty Ltd, a lumber manufacturer, in February 2018, for refusing to provide his fingerprints to sign in and out of his work, citing that he was unfairly dismissed from the company.
Read more on Z6Mag.
From the article:
If I were to submit to a fingerprint scan time clock, I would be allowing unknown individuals and groups to access my biometric data, the potential trading/acquisition of my biometric data by unknown individuals and groups, indefinitely,” reads Lee’s affidavit.
We accept Mr. Lee’s submission that once biometric information is digitized, it may be very difficult to contain its use by third parties, including for commercial purposes,” case documents state.
The case of Lee is a first in Australia. While it did not change the law, it opens a new perspective on the ownership of biometric information like fingerprints and facial recognition and reinterpreted privacy laws on how they will apply to data like these.




It’s a small step, but at least it’s a step.
Twitter Flexing its Muscles Against State Misinformation
Twitter first announced Monday, August 19, 2019, that is updating its policy on state media advertising. "Going forward," it said, "we will not accept advertising from state-controlled news media entities. Any affected accounts will be free to continue to use Twitter to engage in public conversation, just not our advertising products."
This policy is global and not targeted at any specific nation or nations, but does not "apply to taxpayer-funded entities, including independent public broadcasters" (so organizations like the BBC -- were it to advertise -- should be okay). The organizations targeted are not banned from using Twitter to engage in organic conversation, but will not be allowed to advertise on the platform.
The immediate catalyst is almost certainly mainland China's propaganda campaign against the ongoing Hong Kong protest movement, but it will reduce the capacity of all foreign countries to manipulate public opinion ahead of elections. The longer-term catalyst will be to help protect the U.S. 2020 elections from foreign influence, whether that comes from China, Russia, Iran or elsewhere.




Reading this, I think IT will have problems complying. Perhaps we should dedicate a lawyer to make the records and draft the notices? Can IT explain things to the lawyer in plain English?
Actionable takeaways from new Irish and Polish Data Protection Authorities'​ guidance on personal data breach notification under GDPR
The Irish Data Protection Commission and the Polish Data Protection authority both recently issues guidance on the notification requirements under GDPR in the event of a Personal Data Breach.
What is "become aware"?
  • A controller should be regarded as having become ‘aware’ when they have a reasonable degree of certainty that a security incident has occurred and compromised personal data.
  • Controllers should have a system in place for recording how and when they become aware of personal data breaches and how they assessed the potential risk posed by the breach.




Représailles is French for retaliation. What did they think would happen?
Amazon is passing along costs of a new digital tax to thousands of French sellers
The reason the company cited was simple: a 3% digital tax passed by the French government in July.
Amazon’s move appears to directly conflict with the French government’s aim of leveling the playing field between Big Tech and small and medium-sized enterprises, and further complicates France’s effort to rein in companies like Amazon, Facebook and Google.




We covered Intellectual Property last week. Perhaps we should reopen the debate?
Linking Liability
Inside Higher Education – Sci-Hub, a repository for pirated research papers, is widely acknowledged to be illegal. But is sharing a link to the site illegal, too? There is little dispute that Sci-Hub, the website that provides free access to millions of proprietary academic papers, is illegal. Yet, despite being successfully sued twice by major American academic publishers for massive copyright infringement, the site continues to operate. Some academics talk openly about their use of the repository — a small number even publicly thank Sci-Hub founder Alexandra Elbakyan for her contribution to their research. Most academics who use the site, however, choose to do so discreetly, seemingly aware that drawing attention to their activities might be unwise. Just how careful academics should be about using Sci-Hub has become a topic of concern in recent weeks, with many questioning whether sharing links to Sci-Hub could in itself be considered illegal. The discussion started when the team behind Citationsy, a bibliography management tool based in Europe, tweeted that lawyers for Elsevier, a major publisher of academic journals, had threatened to pursue legal action if Citationsy did not remove a link to Sci-Hub from Citationsy’s website. The link formed part of a blog post titled “Hacking Education: Download Research Papers and Scientific Articles for Free.”


(Related)
    What the site does is not permitted, according to the law, but in the academic world, Sci-Hub is praised by many. In particular, those who don’t have direct access to expensive journals but aspire to excel in their academic field.
This leads to a rather intriguing situation where many of the ‘creators,’ the people who write academic articles, are openly supporting the site. By doing so, they go directly against the major publishers, including the billion-dollar company Elsevier, which are the rightsholders.




For the student toolkit? New to me.
English Language & Usage Stack Exchange



Monday, August 19, 2019


So, what kind of attack was it? Perhaps they have no clue what happened. My concern, again, is what if this was a ‘proof of concept’ demonstration?
US Customs won't say what caused system crash that delayed tens of thousands of travelers across the entire country - but insist it wasn't a 'malicious' attack as airports finally start to recover
The agency's processing systems went down for several hours at more than 10 major airports, leaving tens of thousands of travelers in long lines as the CBP scrambled to use 'alternative procedures' to admit arrivals into the country.
'Malicious or not, if an outage can disable so many locations simultaneously - the system is incredibly weak. Very scary considering these are our borders,' one wrote on Twitter.
'Not malicious? So, just incompetence. Got it,' a second person added.




Quick, tell me which services I’ve never used discriminate against me so I can sue them!
Nearly four years ago, a lone bankruptcy lawyer sued Square, the payment processor run by Twitter CEO Jack Dorsey, challenging the app’s terms of use—despite never signing up. As of yesterday, the case will proceed, thanks to an opinion issued by the California Supreme Court that could have wide-reaching implications for online businesses.
The first thing you need to know is that, for whatever reason, Square’s Prohibited Goods and Services policies include “bankruptcy attorneys or collection agencies,” which you’ll recall is plaintiff Robert White’s line of work. California, where this case was tried and where a plurality of online services are headquartered, is also home to a state law—the Unruh Civil Rights Act—which provides broad protections against discrimination of many kinds, including occupation. But the question remained as to whether White needed to have entered into an agreement with Square (by agreeing to the terms of service) in order to have experienced said discrimination barring his “full and equal access” to the service.
For the time being at least: no.
In general, a person suffers discrimination under the Act when the person presents himself or herself to a business with an intent to use its services but encounters an exclusionary policy or practice that prevents him or her from using those services,” Justice Goodwin Liu wrote in court’s unanimous opinion. “We conclude that this rule applies to online businesses and that visiting a website with intent to use its services is, for purposes of standing, equivalent to presenting oneself for services at a brick-and-mortar store.”




The world is changing. Perhaps we need AI teachers?
Co-Exist With Robots: How to Compete With Technology in the Age of Automation
As technology, including robots, artificial intelligence, machine learning, and other forces change the nature of work, employees will need new skills to adapt to shifting roles. Research firm Gartner predicts that employees who regularly update their skill sets and invest in new training will be more valued than those with experience or tenure. But it’s not going to be easy.
The World Economic Forum’s “Future of Jobs 2018” report estimates that, by 2022, more than half (54%) of employees will require significant skills updating or retraining. More than one-third (35%) will need about six months to get up to speed, while nearly one in five will require a year or more of additional training.
And employers might not be much help. A 2019 global survey of employers by consulting firm Deloitte found that 86% of respondents rated the need to improve learning and development (L&D) as “important” or “very important.” But just 10% felt ready to “very ready” to address that need. As digital transformation affects so many businesses, a 2018 Gartner report found that just 20% of employees have the skills they need for their jobs now and in the future.



Sunday, August 18, 2019


Fixing another “we can, therefore we must” problem.
The California Supreme Court just rejected the government’s attempt to require a youth probationer, as a condition of release, to submit to random searches of his electronic devices and social media accounts. The trial court had imposed the condition because the judge believed teenagers “typically will brag” about drug use on the Internet—even though there was no evidence that the minor in this case, Ricardo P., had ever used any electronic devices in connection with any drugs or illegal activity, let alone ever previously bragged about drug use online.
EFF and the ACLU filed an amicus brief in the case back in 2016, warning that the search condition imposed here was highly invasive, unconstitutional, and in violation of the California Supreme Court’s own standard for probation conditions—which requires that search conditions be “reasonably related to future criminality.” We also warned of the far-reaching privacy implications of allowing courts to impose such broad electronic search conditions. We’re pleased that the California Supreme Court heeded our warnings and recognized the substantial burden this “sweeping probation condition” imposed on Ricardo’s privacy.
The court recognized that the probation condition would give Ricardo’s probation officers “full access, day or night, not only to his social media accounts but also to the contents of his e-mails, text messages, and search histories, all photographs and videos stored on his devices, as well as any other data accessible using electronic devices, which could include anything from banking information to private health or financial information to dating profiles.” And by allowing remote access to Ricardo’s online accounts, the condition would potentially allow his probation officers to monitor his communications in real time. According to the court:
If we were to find this record sufficient to sustain the probation condition at issue, it is difficult to conceive of any case in which a comparable condition could not be imposed, especially given the constant and pervasive use of electronic devices and social media by juveniles today.”
The court noted, for example, that if it were to hold—as the California Attorney General argued—that any search condition facilitating supervision of probationers was “reasonably related to future criminality,” it might be obligated to uphold “a condition mandating that probationers wear 24-hour body cameras or permit a probation officer to accompany them at all times.”
This is a critical ruling. The search condition imposed in this case was not unique, but one that many juvenile probationers have been subject to in California in recent years, under the same unsupported reasoning that the trial judge offered here. The California Supreme Court’s decision not only resolves a split in the lower courts regarding the legality of such probation conditions, but it sends a clear message: probation conditions that have “a very heavy burden on privacy with a very limited justification” are not entitled to deference.
We applaud the California Supreme Court for recognizing the serious privacy invasion imposed by the search condition issued in this case and for striking down the condition as invalid.
Source: EFF




A PDF
The Promise and Limitations of Artificial Intelligence in the Practice of Law




For my geeks.