Wednesday, August 28, 2019


Perhaps I could volunteer my students to help?
https://www.denverpost.com/2019/08/27/regis-university-cyber-attack-3/
Day 6 of Regis University’s IT nightmare: Computer recovery begins
On day six of Regis University running without access to information technology services like phone lines, email, internet and online course programs, some employee computers are beginning recovery mode.
IT services on campus started visiting faculty and staff offices Tuesday to scan computers, install safeguards and begin monitoring each computer. The treated computers were not able to go online or get back up and running, but it was the start of a recovery process. Employees don’t need to be there for the IT experts to do their work, according regisupdates.com, a web page the university created to communicate to students, staff and faculty in the absence of their usual platform.
Employees are instructed to not use or turn on their Regis-configured computers until cleared by ITS,” a post said. “To minimize risk, employees also are advised to not use Office365 and OneDrive until further notice. In the interim, employees may bring personal computers and hotspots for connectivity to work. [I can’t remember ever having seen anything like this. Bob]
A “malicious threat” likely from outside the country caused the private, religious institution to pull down its information technology services Thursday, during the rush of finals for summer courses and start of the fall semester.
University officials declined to say whether the situation at Regis was a ransomeware attack, saying the matter is still under investigation.



(Related) A cold assessment. I suspect it’s a money thing.
https://www.propublica.org/article/the-extortion-economy-how-insurance-companies-are-fueling-a-rise-in-ransomware-attacks
The Extortion Economy: How Insurance Companies Are Fueling a Rise in Ransomware Attacks
Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business.
… “Paying the ransom was a lot cheaper for the insurer,” he said. “Cyber insurance is what’s keeping ransomware alive today. It’s a perverted relationship. They will pay anything, as long as it is cheaper than the loss of revenue they have to cover otherwise.”
One cybersecurity company executive said his firm has been told by the FBI that hackers are specifically extorting American companies that they know have cyber insurance. After one small insurer highlighted the names of some of its cyber policyholders on its website, three of them were attacked by ransomware, Wosar said. Hackers could also identify insured targets from public filings; the Securities and Exchange Commission suggests that public companies consider reporting “insurance coverage relating to cybersecurity incidents.”






Is the best we can do: “Facebook approves this ad?”
https://www.washingtonpost.com/technology/2019/08/28/facebook-require-political-campaigns-say-who-paid-their-ads-new-transparency-push/?arc404=true
Facebook to require buyers of political ads to provide more information about who paid for them
Facebook on Wednesday announced it would tighten some of its rules around political advertising ahead of the 2020 presidential election, requiring those who purchase ads touting candidates or promoting hot-button issues to provide more information about who actually paid for them.
The changes seek to address a number of well-documented incidents where users placed misleading or inaccurate disclaimers on ads, effectively undermining a system for election transparency that the tech giant built after Russian agents spread disinformation on the site during the 2016 race.
Facebook already requires that political advertisers verify their identities. Starting in September, though, the company will require buyers of so-called issue ads or advocates of a political candidate to include information about who is funding the ads. To satisfy Facebook’s new requirements, a business can submit their tax-identification number, or campaigns can share their own registration data from the Federal Election Commission, and Facebook will label them as a “confirmed organization” in its archive.






New tool for my students.
https://www.techradar.com/news/move-over-vpn-sdp-has-arrived
Move over VPN, SDP has arrived
… The power of the Software Defined Perimeter (SDP) is that it is designed to address the way we use the Internet and the technologies it enables. It does away with the encrypted tunnel and replaces it with dynamic, one-to-one, micro-segmented network connections between users and the resources they have authority to access. This provides security that supports the way businesses need to operate today.
SDP supports a Zero Trust model, which means that each time a user – be they human, IoT device, or AI programme – attempts to access a resource they will have to be authenticated and authorised, using multiple checks, before gaining network access. All other resources that users haven’t been authorised to access will remain invisible to them. This is in stark contrast to traditional VPNs where once someone has access to one part of the network they can see and gain access to everything, regardless of whether it’s relevant to them.






Still trying to figure it out. (Education by bad example.)
https://www.cpomagazine.com/data-protection/terms-conditions-and-considerations-under-the-gdpr/
Terms, Conditions and Considerations Under the GDPR
In recent months European regulators have found fault with tech giants Facebook and Google’s terms and conditions, causing DPOs at smaller companies to be understandably worried.
The main challenge for DPOs is to ensure terms and conditions and privacy notices do not become mixed up explained Nymity Strategic Research Director, Paul Breitbarth. “Under the GDPR, they really need to be separate documents. Still too often, terms and conditions contain information about an organization’s data processing practices, which read more like liability waivers intended for lawyers. A privacy notice on the contrary needs to be concise and in clear and plain language, that the average person should be able to understand. So no legal speak (or worse: Eurospeak), no lengthy sentences with tons of exceptions, but just describing to the point what it is you intend to do with data,” he said.
In the Facebook case, the European Commission announced on April 9 that it had ordered the company to change its terms of service to explain clearly how the company makes money by selling user data. The new terms of service must state what data Facebook sells to third parties, including data brokers or ad exchanges, how it will respond to misuse of data by third parties, and under what conditions it can unilaterally change its terms.



(Related)
Insights on Video Surveillance and Data Protection
From Fox Rothschild:
Shortly after the recent video surveillance guidance from the EDPB, the Information Commissioner of the Isle of Man published an updated CCTV data protection guidance.
Key takeaways for controllers:
General Considerations and Governance:
    • CCTV images identify living individuals and are, therefore, personal data. This means that the use of CCTV will be covered by data protection law, regardless of the size of the system or organization.
    • There must be a lawful reason for considering the use of CCTV, such as crime prevention and detection, health and safety of workers or the public, property security.
Read more on Privacy Compliance and Data Security






You can read that! You can’t even look at it!”
https://techcrunch.com/2019/08/27/border-deny-entry-united-states-social-media/
US border officials are increasingly denying entry to travelers over others’ social media
It’s a bizarre set of circumstances that has seen countless number of foreign nationals rejected from the U.S. after friends, family or even strangers send messages, images or videos over social media sites like Facebook and Twitter, and encrypted messaging apps like WhatsApp, which are then downloaded to the traveler’s phone.
The United States border is a bizarre space where U.S. law exists largely to benefit the immigration officials who decide whether or not to admit or deny entry to travelers, and few protect the travelers themselves. Both U.S. citizens and foreign nationals alike are subject to unwarranted searches and few rights to free speech, and many have limited access to legal counsel.
CBP also claims to have what critics say is broadly unconstitutional powers to search travelers’ phones — including those of U.S. citizens — at the border without needing a warrant. Last year, CBP searched 30,000 travelers’ devices — a four-times increase since 2015 — without any need for reasonable suspicion.






Now I can find out what “double secret probation” actually means!
https://www.bespacific.com/research-guides-in-focus-how-to-find-free-case-law-online/
Research Guides In Focus – How to Find Free Case Law Online
In Custodia Legis The following is a guest post by Anna Price, a legal reference librarian at the Law Library of Congress. We are back again to focus on the Law Library’s Research Guides. This time we are discussing another popular guide, How to Find Free Case Law Online. Until a few years ago, case law generally was not freely-available online. Researchers had to find an accessible law library and then either learn how to search a subscription database or study the library’s print collection of reporters and digests. Recently, however, various organizations have been working to make state and federal court opinions, as well as associated case materials, available electronically without charge. This guide offers clear direction on using those resources.
The guide walks users through some popular online databases, with a focus on Google Scholar, CourtListener, FindLaw, Justia, and the Public Library of Law. Each section instructs users on navigating the resource and lists its tools, coverage, and unique features that may be helpful for various researcher needs. For example, did you know that CourtListener maintains the RECAP Archive, which includes selected case and docket information from federal appellate, district, and bankruptcy courts? Or what about FindLaw’s collection of Supreme Court briefs?…”




Tuesday, August 27, 2019


Only three and a half years later and they are finally “planning” to do something? Note that what they plan is NOT a fix. Is it even mandatory?
Exclusive: U.S. officials fear ransomware attack against 2020 election
The U.S. government plans to launch a program in roughly one month that narrowly focuses on protecting voter registration databases and systems ahead of the 2020 presidential election.
These systems, which are widely used to validate the eligibility of voters before they cast ballots, were compromised in 2016 by Russian hackers seeking to collect information. Intelligence officials are concerned that foreign hackers in 2020 not only will target the databases but attempt to manipulate, disrupt or destroy the data, according to current and former U.S. officials.
“We assess these systems as high risk,” said a senior U.S. official, because they are one of the few pieces of election technology regularly connected to the Internet.
The Cybersecurity Infrastructure Security Agency, or CISA, a division of the Homeland Security Department, fears the databases could be targeted by ransomware
… CISA’s program will reach out to state election officials to prepare for such a ransomware scenario. It will provide educational material, remote computer penetration testing, and vulnerability scans as well as a list of recommendations on how to prevent and recover from ransomware.




By now my students are sick of my repetitious reiteration of the things I repeat a lot. Like the failure of government bureaucracies to fix security weaknesses they are told about.
It was sensitive data from a U.S. anti-terror program – and terrorists could have gotten to it for years, records show
The Department of Homeland Security stored sensitive data from the nation’s bioterrorism defense program on an insecure website where it was vulnerable to attacks by hackers for over a decade, according to government documents reviewed by The Times.
… The information — housed on a dot-org website run by a private contractor — has been moved behind a secure federal government firewall, and the website was shut down in May. But Homeland Security officials acknowledge they do not know whether hackers ever gained access to the data. [Unlike competent organizations. Bob]
… A security audit completed in January 2017 found “critical” and “high risk” vulnerabilities, including weak encryption that made the website “extremely prone” to online attacks. The audit concluded that there “does not seem to be any protective monitoring of the site,” according to a Homeland Security report summarizing the findings.
An inspector general’s report published later that year said sensitive information had been housed on the BioWatch portal since 2007 and was vulnerable to hackers.




Not just because Harvard says so (or because I teach Computer Security).




Bad economics? Would this hold true for any other crimes?
Just Enough’ Piracy Can Be a Good Thing




Be ye careful when displaying new clothes to professionals lest someone point out the lack of fabric. Note also that the lawsuit keeps your embarrassment in the news.
Company Sues Black Hat Conference Over Mocked Presentation
Crown Sterling advertises itself as “an emerging company in development of non-factor based dynamic encryption and innovative new developments in AI.” The company’s website does not provide any details about the company’s technology, TIME AI, but it has published a short presentation video and an 8-page paper.
The company paid $115,000 to be a gold sponsor at the 2019 Black Hat USA conference, which included an exhibition booth at the event and a sponsored talk. The presentation, titled “The 2019 Discovery of Quasi-Prime Numbers: What Does This Mean for Encryption?,” was held by Robert E. Grant, Crown Sterling founder and CEO.
Some of the individuals who attended the talk called out the company during its presentation over what has been described as “pseudoscience.”
Many individuals, including reputable experts, have ridiculed Crown Sterling on social media and pointed out errors in its claims, with some calling the company “frauds” and “snake oil vendors.” Following the incident, Black Hat organizers decided to remove any mention of the presentation from the event’s official website.




I must be getting the message across. One of my students tipped me to this story.
Facial recognition in schools leads to Sweden’s first GDPR fine
The Swedish Data Protection Authority (DPA) has served a municipality in northern Sweden the country’s first GDPR fine — amounting to almost €19,000 (200,000 SEK) — for using facial recognition technology to monitor the attendance of students in school.
The high school in SkellefteĆ„ conducted a pilot program last fall where the attendance of 22 students over a period of three weeks was taken with the help of facial recognition technology, instead of good ol’ fashioned roll call, according to Computer Sweden.
… The school failed to consult the Swedish DPA before launching its program and didn’t do a proper impact assessment.
… The school maintains it had its students’ consent, but the DPA found there was no valid legal basis for this as there’s a “clear imbalance between the data subject and the controller.”




Perspective. Some you know, some you might not. It’s what they’re doing that is most interesting.
10 Companies Using AI to Grow
According to Fortune Business Insights, the global AI (artificial intelligence) market in 2018 was $21 billion. It’s expected to grow 33% annually between 2019 and 2026 to $203 billion.




Something to amuse my students.



Monday, August 26, 2019


I try to make my students understand this.
War is as War Does: World Order and the Future of Conflict
The release of the first part of the Senate Select Intelligence Committee’s bipartisan investigation into Russia’s 2016 election interference and Robert Mueller’s recent testimony on Capitol Hill should erase any lingering doubt about this hard truth: The United States is at war with Russia. For years, Moscow has persistently attacked the heart of American democracy, seeking to change electoral outcomes and destroy Americans’ faith in democracy and the world’s faith in America.
Putin certainly believes he’s at war with America, and remains convinced that Washington has been working for decades to weaken Russia and take down his regime. He has acted accordingly.
By contrast, the U.S. response to this new war has been a fairly reactive, piecemeal and modest set of defensive actions. One reason for that failure is that this war does not look like any war Americans have known before, nor is it one that we predicted and prepared for.




We don’t want you to hear what our teachers tell your kids.”
Denison ISD bans student listen-in apps on campuses
Devices with listen-in and student tracking capabilities are becoming more common among students and parents,” Denison ISD Assistant Superintendent David Kirkbride said. “The use of listen-in devices without authorization presents a concern for student privacy and confidentiality.
Kirkbride had previously stated that the district already had a policy preventing students from recording conversations in class. This new policy will apply to apps parents use to listen in through their own child’s device.
… “Having a device in a classroom setting that is recording what all is going on presents privacy issues,” Kirkbride said. “You can have a conversation between a student and a teacher and if a device is in the vicinity and it captures that conversation that could be a clear violation of privacy and confidentiality.” [“If the rest of the class overhears the conversation, we just claim they’re lying.” Bob]




Still more a people (read: management) problem.
The risks of amoral A.I.
The Yale Journal of Law and Technology published a paper by Robert Brauneis and Ellen P. Goodman where they describe their efforts to test the transparency around government adoption of data analytics tools for predictive algorithms. They filed forty-two open records requests to various public agencies about their use of decision-making support tools.
Their “specific goal was to assess whether open records processes would enable citizens to discover what policy judgments these algorithms embody and to evaluate their utility and fairness”. Nearly all of the agencies involved were either unwilling or unable to provide information that could lead to an understanding of how the algorithms worked to decide citizens’ fates.


(Related) What if AI “forces” good behavior?
Primary school to use AI to monitor students
A primary school in Shanghai is planning to build an artificial intelligence (AI) technology system to monitor and analyze student behavior including extra attention for details such as smiling or yawning.
… Based on the new technologies, the school can now recognize, collect and assess student behavior, such as their sitting posture, yawning, greeting and if they raise their hand to speak in class.
… The school is also building an intelligent security and management system.
Whether a student on campus smiles, greets teachers, volunteers to pick up garbage, runs fast or fights can be captured and recognized by the system.




Yet another taxonomy.
The Three Types of Artificial Intelligence: Understanding AI
AI is rapidly evolving. Artificial Super Intelligence could be here sooner than expected.




Another excuse for my students? Was keyword search really better?
As Search Engines Increasingly Turn To AI They Are Harming Search
Forbes – “For more than half a century our digital search engines have relied upon the humble keyword. Yet over the past few years, search engines of all kinds have increasingly turned to deep learning-powered categorization and recommendation algorithms to augment and slowly replace the traditional keyword search. Behavioral and interest-based personalization has further eroded the impact of keyword searches, meaning that if ten people all search for the same thing, they may all get different results. As search engines depreciate traditional raw “search” in favor of AI-assisted navigation, the concept of informational access is being harmed and our digital world is being redefined by the limitations of today’s AI…”




Perspective. Every company has competition.
Shopify All Set to Target E-Commerce Behemoth Amazon After Upstaging eBay
e-commerce company Shopify has emerged as an unlikely contender to challenge Amazon and it is now looking increasingly likely after the Canadian company left eBay in the dust this year in terms of valuation. Shopify first listed on the New York Stock Exchange back in 2015 and over the years it has grown steadily.
However, it was in 2019 that the stock has gathered steam and gained 150% in the year so far. It now boasts of the market capitalization of $40 billion and manages to go past the eBay at the start of the year.
Shopify gives its users the chance to have the same technical capabilities that one would want in an online store and given the bulk of the control to the retailers. That is the stark difference between the two companies and one that could propel Shopify into becoming the main challenger to the juggernaut that is Amazon. S hopify allows even the smallest of stores to set up their online store quickly and the company provides all the necessary tools regarding the website and payment options.




I suppose this was inevitable since schools stopped teaching cursive, but can anyone (except us old guys) still read it?
Start-up that makes fake AI handwriting raises £400,000
23-year-old start-up founder has raised £400,000 for his business which uses artificial intelligence to create convincing fake handwriting.
Robert Van Den Bergh said his company, Scribeless, was already being used by banks, political parties, and religious groups.
The business’ technology uses software to learn the nuances of handwriting in order to introduce variation and inconsistencies in its fake handwriting.
… The business claims that handwritten letters can see open rates above 95pc, dramatically higher than traditional follow-up emails.
… The firm has been selling its products to customers in the US and Europe, and charges up to £3 per letter.
The most expensive automatically handwritten products use a robotic fountain pen, but the firm also allows businesses to pay 25p to print out automatically handwritten notes with traditional printers.



Sunday, August 25, 2019


Who would you like to win and by how much? Note that the proposal to provide voters with a receipt would detect fraud.
There is no Reliable Way to Detect Hacked Ballot-Marking Devices
Election system vendors are marketing ballot-marking devices (BMDs) as a universal system, and some states are deploying them for all voters, not just those who need a BMD to vote independently. Like all devices with CPUs, BMDs can be hacked, misprogrammed, or misconfigured. BMD printout might not reflect what the BMD screen or audio confirmed. If a voter complains that the BMD altered votes, officials have no way to tell whether there was a BMD malfunction, the voter erred, or the voter is attempting to cast doubt on the election.
… if parallel testing discovers an error, the only remedy is to hold a new election: there is no way to reconstruct the correct election result from an untrustworthy paper trail.




Interesting.
Three Dimensions of Privacy Policies
Privacy policies are the main way to obtain information related to personal data collection and processing. Originally, privacy policies were presented as textual documents. However, the unsuitability of this format for the needs of today's society gave birth to others means of expression. In this report, we systematically study the different means of expression of privacy policies. In doing so, we have identified three main categories, which we call dimensions, i.e., natural language, graphical and machine-readable privacy policies. Each of these dimensions focus on the particular needs of the communities they come from, i.e., law experts, organizations and privacy advocates, and academics, respectively. We then analyze the benefits and limitations of each dimension, and explain why solutions based on a single dimension do not cover the needs of other communities. Finally, we propose a new approach to expressing privacy policies which brings together the benefits of each dimension as an attempt to overcome their limitations.




A guide for legislators?
GOVERNANCE OF INTERNET OF THINGS AND ETHICS OF ARTIFICIAL INTELLIGENCE
The continuous interaction between intelligent devices, sensors and people points to the increasing number of data being produced, stored and processed, changing, in various aspects and increasingly, our daily life. On one hand, the context of hyperconnectivity can bring economic benefits to the State, companies, as well as convenience to consumers. On the other hand, increasing connectivity brings significant challenges in the spheres of privacy protection and contemporary ethics, impacting, ultimately, democracy itself. This thesis addresses, from the regulatory point of view, some of these challenges faced by the current rule of law arising from the advance of the scenario called Internet of Things.




A glossary for my next (Okay, my first) AI course.
UNDERSTANDING ARTIFICIAL INTELLIGENCE: A COMPREHENSIVE GLOSSARY OF TERMS AND DEFINITIONS




Worth grabbing.
Oxford Handbook on AI Ethics Book Chapter on Race and Gender
27 pages with references




For an Economist I know. (I wonder if my students know who Adam Smith is?)
HOW ADAM SMITH'S IDEA OF THE DIVISION OF LABOR LED TO THE DIGITAL COMPUTER
Herbert Simon and Allen Newell tell the story of how Adam Smith's ideas directly led to the development of the digital computer in an address delivered to the Twelfth National Meeting of the Operations Research Society of America, Pittsburgh, Pennsylvania, November 14, 1957.
… I should like to tell you a true story, culled from [Charles] Babbage's writings, about the history of the computer. I like this story because it illustrates not only my earlier point about the many mutual relations of the professions in our field, but also because it gives the underdogs like myself-trained in 'soft' fields like economics and political science something we can point to when the superior accomplishments of the natural sciences become too embarrassing for us. As you will see, this story shows that physicists and electrical engineers had little to do with the invention of the digital computer--that the real inventor was the economist Adam Smith, whose idea was translated into hardware through successive stages of development by two mathematicians, Prony and Babbage. (I should perhaps mention that the developers owed a debt also to the French weavers and mechanics responsible for the Jacquard loom, and consequently for the punched card.)



Saturday, August 24, 2019


Some thoughts from Scientific American.
Misinformation Has Created a New World Disorder
Our willingness to share content without thinking is exploited to spread disinformation
  • Many types of information disorder exist online, from fabricated videos to impersonated accounts to memes designed to manipulate genuine content.
  • Automation and microtargeting tactics have made it easier for agents of disinformation to weaponize regular users of the social web to spread harmful messages.
  • Much research is needed to understand the effects of disinformation and build safeguards against it.


(Related) One “fake” hack.
How Artist Imposters and Fake Songs Sneak Onto Streaming Services
When songs leak on Spotify and Apple Music, illegal uploads can generate substantial royalty payments—but for whom?




...and apparently they all have different ways of describing the “perfect” AI development process.
Meet the Researchers Working to Make Sure Artificial Intelligence Is a Force for Good
To help ensure future AI is developed in humanity’s best interest, AI Now’s researchers have divided the challenges into four categories: rights and liberties; labor and automation; bias and inclusion; and safety and critical infrastructure. Rights and liberties pertains to the potential for AI to infringe on people’s civil liberties, like cases of facial recognition technology in public spaces. Labor and automation encompasses how workers are impacted by automated management and hiring systems. Bias and inclusion has to do with the potential for AI systems to exacerbate historical discrimination against marginalized groups. Finally, safety and critical infrastructure looks at risks posed by incorporating AI into important systems like the energy grid.
AI Now is far from the only research institute founded in recent years to study ethical issues in AI. At Stanford University, the Institute for Human-Centered Artificial Intelligence has put ethical and societal implications at the core of its thinking on AI development, while the University of Michigan’s new Center for Ethics, Society, and Computing (ESC) focuses on addressing technology’s potential to replicate and exacerbate inequality and discrimination. Harvard’s Berkman Klein Center for Internet and Society concentrates in part on the challenges of ethics and governance in AI.




I’m not so pessimistic. My library has her book, so I may change my mind when I read it.
Futurist Amy Webb envisions how AI technology could go off the rails
Webb’s latest book, The Big Nine, examines the development of AI and how the ‘big nine’ corporations – Amazon, Google, Facebook, Tencent, Baidu, Alibaba, Microsoft, IBM and Apple – have all taken control over the direction that development is heading. She says that the foundation upon which AI is built is fundamentally broken and that, within our lifetimes, AI will begin to behave unpredictably, to our detriment.
One of the main issues is that corporations have a much greater incentive to push out this kind of technology quickly than they do to release it safely.




A geek lecture (45 minutes)
Computer Mathematics, AI and Functional Programming




For my students who might be slightly nervous about their presentations.



Friday, August 23, 2019


Definitely worth discussing.
When Ransomware Cripples a City, Who’s to Blame? This I.T. Chief Is Fighting Back
The former information technology director of Lake City, the northern Florida city that was forced to pay out nearly half a million dollars after a ransomware attack this summer, was blamed for the breach, and for the long time it took to recover. But in a new lawsuit, Mr. Hawkins said he had warned the city about its vulnerability long ago — urging the purchase of an expensive, cloud-based backup system that might have averted the need to pay a ransom.




The error was in police software. Does US police software process the raw data before investigators/prosecutors see it?
Flaws in Cellphone Evidence Prompt Review of 10,000 Verdicts in Denmark
The authorities in Denmark say they plan to review over 10,000 court verdicts because of errors in cellphone tracking data offered as evidence.
The country’s director of public prosecutions on Monday also ordered a two-month halt in prosecutors’ use of cellphone data in criminal cases while the flaws and their potential consequences are investigated.
It’s shaking our trust in the legal system,” Justice Minister Nick Haekkerup said in a statement.
The first error was found in an I.T. system that converts phone companies’ raw data into evidence that the police and prosecutors can use to place a person at the scene of a crime. During the conversions, the system omitted some data, creating a less-detailed image of a cellphone’s whereabouts. The error was fixed in March after the national police discovered it.
In a second problem, some cellphone tracking data linked phones to the wrong cellphone towers, potentially connecting innocent people to crime scenes, said Jan Reckendorff, the director of public prosecutions.




We can do this to Kazakhstan but would any first world government tolerate it?
Browsers Take a Stand Against Kazakhstan’s Invasive Internet Surveillance
Yesterday, Google Chrome, Mozilla Firefox, and Apple’s Safari browsers started blocking a security certificate previously used by Kazakh ISPs to compromise their users’ security and perform dragnet surveillance.
… The two-step of Kazakh ISPs deploying an untrusted certificate, and users manually trusting that certificate allows the ISPs to read and even alter the online communication of any of their users, including sensitive user data, messages, emails, and passwords sent over the web.




This assumes the hospital’s controls were adequate.
Hospital found not liable for Facebook post about patient's STD
An Ohio hospital is not liable for a worker's Facebook post that included a screenshot of a patient's medical records showing she had a sexually transmitted disease, a judge ruled.
The University of Cincinnati Medical Center employee posted records in 2013 on a Facebook group with a name that includes a derogatory term for women considered promiscuous.
… Last year, the patient sued the hospital, her former boyfriend and the employee, who was fired a week after the post.
After looking into what transpired, the hospital found that the financial services employee had accessed the information, court documents show.
A Hamilton County Common Pleas Court judge on Monday found that the worker did not act within the scope of her employment and that the hospital needs to be dropped from the lawsuit, the Cincinnati Enquirer reported.
"(The hospital) had a policy. It was violated," Judge Jody Luebbers said. "It's tragic, but that's just how I see it."




It seems we need better solutions than this article suggests.
Singularity: how governments can halt the rise of unfriendly, unstoppable super-AI
A super-AI raises two fundamental challenges for its inventors, as philosopher Nick Bostrom and others have pointed out. One is a control problem, which is how to make sure the super-AI has the same objectives as humanity. Without this, the intelligence could deliberately, accidently or by neglect destroy humanity – an “AI disaster”.
The second is a political problem, which is how to ensure that the benefits of a super-intelligence do not go only to a small elite, causing massive social and wealth inequalities. If a super-AI arms race occurs, it could lead competing groups to ignore these problems in order to develop their technology more quickly. This could lead to a poor-quality or unfriendly super-AI.