Friday, January 10, 2020


Probably not just Iran. Probably for far longer than one year.
Iranian Hackers Have Been ‘Password-Spraying’ the US Grid
By all appearances, Iranian hackers don't currently have the capability to start causing blackouts in the US. But they’ve been working to gain access to American electric utilities, long before tensions between the two countries came to a head.
On Thursday morning, industrial control system security firm Dragos detailed newly revealed hacking activity that it has tracked and attributed to a group of state-sponsored hackers it calls Magnallium. The same group is also known as APT33, Refined Kitten, or Elfin, and has previously been linked to Iran. Dragos says it has observed Magnallium carrying out a broad campaign of so-called password-spraying attacks, which guess a set of common passwords for hundreds or even thousands of different accounts, targeting US electric utilities as well as oil and gas firms.




A starting point for my Computer Security students. (And a “be sure to talk about” list for me!)
Nine Cybersecurity Metrics Every CEO Should Track
According to a 2019 survey from The Conference Board of more than 800 international CEOs and 600 C-suite members, cybersecurity is cited as the top external concern. The Conference Board also notes (via CIO Dive ) that malicious cyber activity cost the economy up to $109 billion in 2016.
CEOs and boards that seek to meaningfully reduce their risk of experiencing high-impact cyber incidents such as data breaches must invest in a security operations center (SOC) with a primary mandate of delivering enterprisewide threat detection and response. Furthermore, the SOC’s threat detection and response program must be viewed as a business-critical operation, requiring continuous investment, improvement and measurement across the following six interrelated subcomponents: centralized visibility, threat discovery, threat qualification, threat investigation, threat mitigation and incident recovery.
Boards should ask their CEOs — and thus CEOs should ask their CISOs — to provide operational measurement and metrics across these subcomponents with the intent of understanding current operational capabilities and related risks.




Thinking about Privacy! (Action make take a bit longer.)
Four Federal Privacy Trends to Watch in 2020
  • Expansive Definition of Sensitive Data
  • Anti-Discrimination Protections
  • Portability
  • CEO Certification Requirements


(Related)
State Legislatures Are Off to the Privacy Races, With New Hampshire in the Lead
New Hampshire legislators introduced new data privacy legislation, New Hampshire House Bill 1680.




The shoemakers children go barefoot? Why would any IT manager rely on manual processes?
Top Five Ways to Survive the DSR Deluge and One Thing You Should Never Do
Data breaches and misuse of private information continue to erode consumer trust. In response, companies are pouring resources into implementing security controls to block or restrict access to their data. However, the bigger question looms around how the data is being used and why, and many of these inquiries are coming in the form of Data Subject Requests (DSRs).
What’s more, there are several complexities making the onslaught of DSR’s even more challenging. For example, the massive growth in data collection and proliferation has not been accompanied by an equally matched effort in data management and governance.
Regulations like GDPR and CCPA are forcing companies to respond to DSR’s and answer consumer concerns over privacy. But achieving compliance requires that companies understand what personal information they have, where it’s located and how it’s being used.
Until now, the basic data inventory process has been a manual one of application data owner surveys and spreadsheets. The Integris Software 2019 Data Privacy Maturity Study found that 77% of respondents were still relying on manual processes to manage sensitive data.
Here are five key ways to solve the data subject rights’ big data problem and one thing you should never do!




Re-architecting the firm. (Not yet at my local library, but I’m watching for it.)
Rethinking Business Strategy in the Age of AI
For the first time in 100 years, new technologies such as artificial intelligence are causing firms to rethink their competitive strategy and organizational structure, say the authors of a new book, Competing in the Age of AI.
John Foley was irritated with his local gym. He was constantly getting elbowed out of his favorite spin classes as other cyclists snapped up spots in sessions led by the most popular instructors.
Foley’s frustration inspired him in 2012 to found Peloton, whose $2,200 stationary bicycles with integrated 21-inch tablet computers have become a fitness sensation. For $39 per month, Peloton offers access to live-streamed classes where members can track their performance on a leader board, virtually connect with fellow classmates, and hear instructors call out their achievements.
Foley transformed a traditional business—the gym—into an $8 billion digital offering that pulled in more than $700 million in revenue during the last fiscal year. Foley credits the magic of today’s technology, including software, data, and communication networks, for the basis of Peloton’s success.
We see ourselves more akin to an Apple, a Tesla, or a Nest, or a GoPro—where it’s a consumer product that has the foundation of sexy hardware technology and sexy software technology,” he is quoted in a book published today, Competing in the Age of AI: Strategy and Leadership When Algorithms and Networks Run the World.




Maybe I’ll get a JD now that law school is free.
Upending Bankruptcy ‘Myths,’ Judge Erases $220,000 Student Loan Debt
The borrower-friendly ruling comes as bankruptcy judges across the country are growing more sympathetic to discharging student debt
A bankruptcy judge excused a U.S. Navy veteran with a law degree from repaying more than $220,000 in student loan debt, the latest court ruling to lower the barriers to discharging educational debt.
Judge Cecelia G. Morris of the U.S. Bankruptcy Court in Poughkeepsie, N.Y., discharged the law school graduate’s unpaid student loans even though he isn’t disabled or unemployable, saying that satisfying his law school debt in full would impose an undue hardship.




Some supplemental classes for my students. Most are free.
Best Machine Learning Courses



Thursday, January 09, 2020


Not just random servers…
SNAKE Ransomware Targeting Entire Corporate Networks
… SNAKE isn’t the first ransomware that’s directed its focus to entire corporate networks. Back in March 2019, for instance, researchers discovered a new variant of the CryptoMix Clop ransomware family that claimed to target entire networks instead of individual users’ machines. A few months later, the security community learned of a new crypto-ransomware threat called “TFlower” targeting corporate environments via exposed Remote Desktop Services (RDS).
The emergence of SNAKE ransomware highlights the need for organizations to defend themselves against a ransomware infection. They can use these recommendations to prevent a ransomware infection in the first place. They should also consider investing in a solution like Tripwire File Analyzer for the purpose of detecting suspicious files and behavior on the network.




Eventually we will get it right. Unfortunately, I think it will take a major hack to spur us to action.
New “secure” voting machines are still vulnerable—because of voters
A new study of voting machines is spotlighting the “serious risk” that election results can be manipulated because most voters do not check that their ballot is correct, according to new research.
… The research raises questions about hackable computers and post-election audits—two major issues in election cybersecurity—just weeks before the first US primary votes are cast in Iowa on February 3.




Probably won’t eliminate TSA. Does it also detect ‘box cutters’ like those used on 9/11?
Evolv raises $30 million to expedite security screenings with AI
Perhaps the worst thing about air travel is having to wade through congested airport security. Wait times at airports like Salt Lake City International and Washington Dulles regularly exceed half an hour on average, and that’s assuming folks follow TSA instructions.
The founders of Evolv Technology, a Waltham, Massachusetts-based security startup specializing in tech-based screening technology, think they have a better solution: the Evolv Edge and Express. They’re self-contained and portable gates that tap AI, machine learning, and millimeter wave sensors to expedite security screenings in high-traffic places.
It remains unclear how the Edge’s threat detection rates compare to traditional checkpoints. A leaked 2015 TSA report revealed that Department of Homeland Security investigators managed to sneak weapons and fake bombs past airport screeners in an alarming 95% of attempts.




Another view.
From AiThority:
The ‘Navigating the Age of Surveillance’ report uncovers changing consumer attitudes, the rise of third-party tracking and the need for mandated data privacy protection
Winston Privacy, an innovative start-up and makers of the Winston privacy filter, released a new report titled, “Navigating the Age of Surveillance” and results of a national survey revealing consumers’ attitudes about data privacy.
Read more on AiThority.




Have you been waiting for a refrigerator than has this ability? Has anyone?
Samsung’s new food A.I. can suggest recipes based on what’s in your fridge
Imagine if, after a long day at work, your fridge could look to see what you’ve got in stock and then suggest a meal composed of those ingredients. That’s what Samsung has developed with a new personalized cooking experience feature for its fridges, shown off at CES.




Is this surprising in a Congress where Senators are willing to attack Facebook without bothering to learn how the company makes money?
Copy, Paste, Legislate Beta
The Center for Public Integrity – “Do you know if a bill introduced in your statehouse — it might govern who can fix your shattered iPhone screen or whether you can still sue a pedophile priest years later — was actually written by your elected lawmakers? Use this new tool to find out. Spoiler alert: The answer may well be no. Thousands of pieces of “model legislation” are drafted each year by business organizations and special interest groups and distributed to state lawmakers for introduction. These copycat bills influence policymaking across the nation, state by state, often with little scrutiny. This news application was developed by the Center for Public Integrity, part of a year-long collaboration with USA TODAY and the Arizona Republic to bring the practice into the light…”



Wednesday, January 08, 2020


Do you have a tested procedure for investigating reports of security breaches? Here’s a really good bad example.
The Difficulty of Disclosure, Surebet247 and the Streisand Effect




Shouldn’t the court redact any sensitive information?
Valley News Live reports:
North Dakota is now the first state to allow anyone with a computer and internet connection access to court documents from their own home or a remote location, according to state officials.
Yet, there’s disagreement on whether this is a good thing with sensitive information being exposed to millions.
The court records can be viewed and printed for free on publicrecords.ndcourts.gov.
Read more on Valley News Live.
[I think that link should be: https://publicsearch.ndcourts.gov/




Worth reading.
Award-Winning Paper: “Privacy’s Constitutional Moment and the Limits of Data Protection”
Among the papers to be honored at an event at the Hart Senate Office Building on February 6, 2020 is Privacy’s Constitutional Moment and the Limits of Data Protection by Woodrow Hartzog of Northeastern University School of Law and Neil Richards of the Washington University School of Law.
You can view all of this year’s award-winning papers on the FPF website.




I clearly do not understand antitrust.
McConnell Backs Bill to Give News Outlets Leverage Over Big Tech
The legislation would grant publishers a four-year exemption from antitrust laws so they could negotiate financial terms with the tech giants that often serve as a gateway for readers and online advertisers.
The bill, which has seven Senate supporters in total, was introduced by Senators John Kennedy, a Louisiana Republican, and Amy Klobuchar, a Minnesota Democrat. A companion measure in the House was introduced by the chairman of the antitrust subcommittee, Democratic Representative David Cicilline of Rhode Island, and the Judiciary Committee’s top Republican, Representative Doug Collins of Georgia.




Perspective.
8 AI trends we’re watching in 2020
To fully take advantage of AI technologies, you’ll need to retrain your entire organization
Data literacy will be required from employees outside traditional data teams—in fact, Gartner expects that 80% of organizations will start to roll out internal data literacy initiatives to upskill their workforce by 2020.




In case I ever want to recommend a student? I guess it could happen.



Tuesday, January 07, 2020


Practice on the Olympics before going pro for the election?
State-Backed Cyber Attacks Expected at Tokyo 2020 Games
The Public Security Intelligence Agency (PSIA) of Japan has issued a warning that a state-sponsored cyber attack on the Tokyo 2020 Summer Olympic and Paralympic Games is expected, after uncovering some early phishing emails made up to look as if they are coming from Olympic staff.
… Russia has a particular motivation for an attack on the 2020 games, however. The country recently received a four-year Olympic ban from the World Anti-Doping Agency (WADA) due to repeated violations. Russian athletes can compete under “neutral” status, but medals they are awarded do not count toward the country’s lifetime totals. Russia and Japan also have a long-running dispute over the Kuril Islands, and Russia has seized an unusual number of Japanese fishing boats this year in the area including five in December.




What actions could Airbnb take that would not result in lawsuits?
Airbnb's AI Can Dig Through Your Social Media For Clues You're a Psychopath
According to patent documents reviewed by the Evening Standard, the tool takes into account everything from a user's criminal record to their social media posts to rate their likelihood of exhibiting "untrustworthy" traits - including narcissism, Machiavellianism, and even psychopathy.




You should outsource things that are not part of you core business.
Elite Law Firms Are Quietly Outsourcing High-Value Functions
The American Lawyer: “Sullivan & Cromwell spends millions of dollars on technology, ensuring its equipment is accessible to its lawyers around the globe and that its digital security can keep clients safe. Chairman Joe Shenker, citing bank surveys, says the Wall Street firm’s tech costs per lawyer are higher than any of its peers. Still, Sullivan & Cromwell has managed to improve its profit margin while maintaining high-quality telecommunications, computers and servers. That financial success isn’t tied only to the firm’s lawyers. It’s partly a result of back-office decisions. Starting in 2017, the firm began outsourcing some of its technology functions and infrastructure. The change required about 30 high-level staffers, including engineers, to leave the firm and become employees of another business, HBR Consulting’s managed services division. It was a sea change in Sullivan & Cromwell’s evolution, Shenker says. “You can’t keep up doing state-of-the-art, best-of-the-best [in technology]—which is what we try to do—doing it yourself,” Shenker says. Law firms just can’t compete with big tech companies, he says. Instead, “Let’s focus on what we’re great at and let other people focus on what they’re great at.” Sullivan & Cromwell isn’t alone. Big Law is embracing outsourcing. Not only are more firms doing it, but the industry is outsourcing a growing number of high-value departments, often shedding administrative and operations employees in the process. The decisions carry some risk, but also big rewards. The outsourcing trend goes beyond law firms opening so-called “captive” operation centers, in which they move some back-office jobs to lower-cost locations with firm employees. More and more firms are moving departments and jobs outside the firm entirely…”




Beyond “I really need a job.”
Here’s an example of the perfect answer to ‘Tell me about yourself,’ according to Yale career experts



Monday, January 06, 2020


It’s not just local, it’s everywhere! Following a simple procedure would have prevented this.
Colorado Town Wires Over $1 Million to BEC Scammers
Colorado Town of Erie lost more than $1 million to a business email compromise scam (BEC) that ended with the town's employees sending the funds to a bank account controlled by scammers.
… The fraudsters used an electronic form on the town's website to request a change to the payment information on the building contract for Erie Parkway Bridge awarded to SEMA Construction in October 2018.
"Specifically, the change was to receive payments via electronic funds transfer rather than by check," Erie Town Administrator Malcolm Fleming said in an email memo according to The Denver Post.
"Although town staff checked some of the information on the form for accuracy, they did not verify the authenticity of the submission with SEMA Construction; they accepted the form and updated the payment method."




Useful!
justdelete.me




Facebook seems to feel that way about a lot of laws.
Facebook Refuses to Change Web Tracking Practices, Believes That CCPA Does Not Apply to Them
… The Wall Street Journal reports that Facebook has told advertisers that it is exempt from the terms of the CCPA as the social media company does not directly sell the data it collects about users.
… The catch that Facebook thinks will get them out of CCPA is that businesses are able to install Pixel free of charge, and pay only for Facebook to deliver targeted ads based on the information they harvest. Facebook believes that they are excepted from the CCPA terms given that they are not directly selling the personal data they collect to these businesses, and given that it is never made visible to them. The business simply provides Facebook with the general demographics to target ads to, things like location and age range, and Facebook targets their ads to users it believes fit the requested profile.




Similar to the encryption ban that targeted PGP? How does one identify “essential?”
US announces AI software export restrictions
The US will impose new restrictions on the export of certain AI programs overseas, including to rival China.
The ban, which comes into force on Monday, is the first to be applied under a 2018 law known as the Export Control Reform Act or ECRA. This requires the government to examine how it can restrict the export of “emerging” technologies “essential to the national security of the United States” — including AI. News of the ban was first reported by Reuters.




Sure to impact architecture.
Top 10 predictions for AI in IT operations
AIOps tools are commonplace, but many IT leaders remain cautious about using these relatively new capabilities. That's likely to change next year, however, as AIOps adoption goes mainstream; use cases will crystallize for improving IT efficiencies and supporting faster decision-making.
AI-enhanced automation will become smarter and more contextual, acquisition activity will explode, and you'll see more movement of AIOps toward the edge. Here are the top 10 predictions to track.




Perhaps we can do without lawyers?
Legal Tech's Predictions for Artificial Intelligence in 2020
So we’re at a new decade. Are the robot lawyers here yet? When are they coming? My mental picture of C3PO projecting a hologram of a case file has not yet come true, and I must confess that I’m a bit disappointed.
… Even if there aren’t robot lawyers, AI has begun to fundamentally change how lawyers across the country practice. And from the predictions below, it’s clear that both attorneys and technologists alike expect more growth from here.




We could do this in other fields…
Free Textbooks for Law Students
Inside Higher Ed – “Legal scholars are increasingly adopting and creating free textbooks in an attempt to increase affordability for students. But are these textbooks considered open educational resources? Law school is notoriously expensive, but a growing number of professors are pushing back on the idea that law textbooks must be expensive, too. Faculty members at the New York University School of Law have taken matters into their own hands by publishing their own textbooks at no cost to students. Barton Beebe, a law professor at NYU, published the sixth edition of his trademark-law textbook last year. Fellow NYU professors Jeanne Fromer and Christopher Jon Sprigman also published the first edition of their copyright-law textbook in 2019. Both titles are available to download electronically at no charge and are already in use at dozens of universities. Print copies of the textbooks can be ordered on demand through Amazon for the bargain-basement price of $20.26 and $15.40, respectively. The authors make no profit from these sales…”




Always a fun topic to get my students arguing. Can we eliminate all (any) middlemen? (Remember when disintermediation was a hot topic?
An elegy for cash: the technology we might never replace
MIT Technology Review – Cash is gradually dying out. Will we ever have a digital alternative that offers the same mix of convenience and freedom? – “This is a feature of physical cash that payment cards and apps do not have: freedom. Called “bearer instruments,” banknotes and coins are presumed to be owned by whoever holds them. We can use them to transact with another person without a third party getting in the way. Companies cannot build advertising profiles or credit ratings out of our data, and governments cannot track our spending or our movements. And while a credit card can be declined and a check mislaid, handing over money works every time, instantly. We shouldn’t take this freedom for granted. Much of our commerce now happens online. It relies on banks and financial technology companies to serve as middlemen. Transactions are going digital in the physical world, too: electronic payment tools, from debit cards to Apple Pay to Alipay, are increasingly replacing cash. While notes and coins remain popular in many countries, including the US, Japan, and Germany, in others they are nearing obsolescence. This trend has civil liberties groups worried. Without cash, there is “no chance for the kind of dignity-preserving privacy that undergirds an open society,” writes Jerry Brito, executive director of Coin Center, a policy advocacy group based in Washington, DC. In a recent report, Brito contends that we must “develop and foster electronic cash” that is as private as physical cash and doesn’t require permission to use…”




My students could use this. (Hint, hint!)
Open database of 25,099,646 free scholarly articles
  • How do you find all these fulltext articles? We harvest content directly from over 50,000 journals and open-access repositories from all over the world. We also use great open data from PubMed Central, the DOAJ, Crossref (particulary their license info), and DataCite.
  • Is Unpaywall legal? Yes! We harvest content from legal sources including repositories run by universities, governments, and scholarly societies, as well as open content hosted by publishers themselves. We do not harvest from sources of dubious legality like ResearchGate or Sci-Hub. If you ever encounter content indexed by Unpaywall that is posted in violation of copyright, let us know and we’ll remove it immediately.
  • How can I make sure content from my open repository appears in Unpaywall? Good question! We made a page about that here.
  • How is this related to the oaDOI service? We used to call the browser extension “Unpaywall,” and the data source behind it “oaDOI.” That got confusing, so now the whole project is just called Unpaywall, including the database, the API, the extension, and everything else…”



Sunday, January 05, 2020


Interesting design choice.
Parking Meters Are Rejecting Credit Cards in Y2K-Type Glitch
… The meters’ credit card payment software was configured to end on Jan. 1, resulting in the mass malfunction, the city’s Department of Transportation said. Parkeon, the vendor that developed the payment system, failed to update the software, officials said.
Sean Renn, a spokesman for the Flowbird Group, which owns Parkeon, said an anti-fraud security setting disabled the card payment system, causing the outage. The company provided the city with a software fix on Thursday, he added.
City workers were on sidewalks, reconfiguring the software meter by meter, Transportation Department officials said.
They said they had no estimate for how long the job would take. The city has 14,000 meters covering some 85,000 spaces.




Who will do it in 2020?
Fresh Cambridge Analytica leak ‘shows global manipulation is out of control’
An explosive leak of tens of thousands of documents from the defunct data firm Cambridge Analytica is set to expose the inner workings of the company that collapsed after the Observer revealed it had misappropriated 87 million Facebook profiles.
More than 100,000 documents relating to work in 68 countries that will lay bare the global infrastructure of an operation used to manipulate voters on “an industrial scale” are set to be released over the next months.
It comes as Christopher Steele, the ex-head of MI6’s Russia desk and the intelligence expert behind the so-called “Steele dossier” into Trump’s relationship with Russia, said that while the company had closed down, the failure to properly punish bad actors meant that the prospects for manipulation of the US election this year were even worse.
The release of documents began on New Year’s Day on an anonymous Twitter account, @HindsightFiles, with links to material on elections in Malaysia, Kenya and Brazil. The documents were revealed to have come from Brittany Kaiser, an ex-Cambridge Analytica employee turned whistleblower, and to be the same ones subpoenaed by Robert Mueller’s investigation into Russian interference in the 2016 presidential election.




I fall into the two finger category.
TypingDNA raises $7 million for AI that identifies people by how they type
TypingDNA — which was founded in Romania in 2016 by Adrian Gheara, Cristian Tamas, and Techstars alum Raul Popa, and which recently moved its headquarters to New York — provides typing biometrics authentication as a service, enabling companies to recognize people by the way they type.
… TypingDNA’s platform records dynamic statistics about pressed keyboard keys and turns them into typing patterns, which its proprietary engine analyzes and verifies against patterns collected from real-world users. As Popa explains, the way a person types on a keyboard is unique and fairly difficult to replicate — in point of fact, it’s behaviorally rich enough to reveal biometric traits like gender and age.




Perspective.
S. Korea starts universal super high-speed Internet service
South Korea has started offering super high-speed Internet services for the entire country that will allow universal, convenient access to online data, the government said on Sunday.
“High-speed internet has been designated as a universal service that everyone is entitled to receive no matter where they are,” the Ministry of Science and ICT said.
… The move makes the country the eighth in the world to offer universal high-speed Internet to all citizens, but the transmission speed of 100 mega bit per second (100 Mbps) is the fastest by far, the ministry said.
The US, Spain, Switzerland, Finland, Malta, Croatia and Sweden have all introduced universal service, although the average speed offered stands at 10 Mbps for the US with many others getting access speeds of just 1-2 Mbps.