Wednesday, January 15, 2020


Imagine the same level of success hacking a major airline. Would insurance cover the loss of business? The problem with less-than-full disclosure is that we don’t know what to prepare for.
Impact of Cyber Attacks on RavnAir More Damaging Than First Thought; Flights May Be Grounded for a Month
It had been thought that the company recovered fairly quickly from the malicious cyber attack, but a statement released just before the new year kicked off indicates that the company may have more delayed and canceled flights into February.
… During the weekend prior to Christmas, an unspecified cyber attack targeted the company’s Dash 8 passenger flights and caused about six of them to be grounded over the busy weekend as a security precaution.
… The FBI and an unspecified third-party cyber security company have been called in to investigate the impact of the cyber attacks on Ravn as the company is working on restoring everything.
As with the recent attack on Travelex, the company has opted to keep details about the attack very scanty. But, as with Travelex, ransomware seems to be a fairly safe assumption given the patterns of disruption to service and the long expected recovery period.




Some numbers. Interesting because of the companies based there.
Washington State Attorney General’s Office 2019 Data Breach Report
For those who may not know, Washington State produces its own data breach report annually. Here’s a snippet from their report:
In 2019, the total number of breaches reported to our office increased by nearly 20%, with just over 70% resulting from a malicious cyberattack.
Yep, the percentage increase in number of incidents/reports sounds about right.
The lifecycle of breaches increased dramatically, rising from an overall average of 139 days in 2018 to 277 days in 2019. This was largely driven by a huge in spike in the amount of time it took organizations to discover that a breach had occurred.
Interesting, because ransomware attacks are recognized quickly, but may take longer to resolve. Similarly, it may take entities months to find out who had PII in an employee’s email account that had been compromised.
So there’s lots to think about and talk about. You can access the state’s 2019 report here. What I found stunning was the number of breaches reported to the state for a one-year period. But then, the number of reports is at least partly a function of how state law defines a reportable breach.




Clearly, the Fed is a major target.
A cyberattack on a major US financial institution would affect more than a third of bank assets, New York Fed warns
A sophisticated cyberattack on the US could ripple through major banks and severely disrupt the broader financial system, according to new research from the New York Federal Reserve.
A cyberattack on the data or systems of any one of the five most active banks could spill over to others and affect more than a third of assets in the overall network, analysts Thomas Eisenbach, Anna Kovner, and Michael Junho Lee said in the staff report this week.
"The reconciliation and recuperation process would be an unprecedented task," the paper said. "This could have severe implications on the stability of the broader financial system vis-À-vis spillovers to investors, creditors, and other financial market participants."




Social engineering based on known vulnerabilities.
Don't fall for this Google Nest sextortion scam
Scammers have been targeting people with Google Nest security camera footage as part of a widespread 'sextortion' campaign, according to Computer Weekly.
Affecting 1,700 people (mainly in the US), the scam was uncovered by email cyber security company, Mimecast, which said that the campaign started in early January.
A sextortion email scam is when perpetrators claim to have compromising footage of the victim – which they'll then surrender once they have been paid.
According to Addison, these emails can be safely ignored. She explained: “The campaign is exploiting the fact people know these devices can be hacked very easily and preying on fears of that.”
It is now widely known that many IoT (Internet of Things) devices lack basic security and are vulnerable to hacking, meaning that victims are more likely to believe the fraudsters’ claims, since the possibility of their device having really been hacked is highly plausible."
How the scammers gained access to the victims' email addresses or the Google Nest footage is unclear.




I’m increasingly concerned that the next war will be digital and most people won’t even recognize it when they see it. This is merely a start.
'We want to win the next war': US Army will revamp cyber operations to counter Russia and China
As warfare continues to enter the digital realm, the Army plans to transform its cyber operations branch into a full-scale information warfare command, according to a top U.S. general.
The service will convert Cyber Command into the Army Information Warfare Command, Army Chief of Staff Gen. James McConville said at a panel on Tuesday. It’s one of the several modernization efforts the Army is taking on to counter "great power" opponents like Russia and China.


(Related)
Companies increasingly reporting attacks attributed to foreign governments
More than one in four security managers attribute attacks against their organization to cyberwarfare or nation-state activity, according to Radware.




Open source…
How digital sleuths unravelled the mystery of Iran’s plane crash
Wired – Open-source intelligence proved vital in the investigation into Ukraine Airlines flight PS752. Then Iranian officials had to admit the truth: “..It’s not unusual nowadays for OSINT to lead the way in decoding key news events. When Sergei Skripal was poisoned, Bellingcat, an open-source intelligence website, tracked and identified his killers as they traipsed across London and Salisbury. They delved into military records to blow the cover of agents sent to kill. And in the days after the Ukraine Airlines plane crashed into the ground outside Tehran, Bellingcat and The New York Times have blown a hole in the supposition that the downing of the aircraft was an engine failure. The pressure – and the weight of public evidence – compelled Iranian officials to admit overnight on January 10 that the country had shot down the plane “in error”.
So how do they do it? “You can think of OSINT as a puzzle. To get the complete picture, you need to find the missing pieces and put everything together,” says Loránd Bodó, an OSINT analyst at Tech versus Terrorism, a campaign group. The team at Bellingcat and other open-source investigators pore over publicly available material. Thanks to our propensity to reach for our cameraphones at the sight of any newsworthy incident, video and photos are often available, posted to social media in the immediate aftermath of events. (The person who shot and uploaded the second video in this incident, of the missile appearing to hit the Boeing plane was a perfect example: they grabbed their phone after they heard “some sort of shot fired”.) “Open source investigations essentially involve the collection, preservation, verification, and analysis of evidence that is available in the public domain to build a picture of what happened,” says Yvonne McDermott Rees, a lecturer at Swansea University…”




How long before this technology is banned? (Unless the manufacturer is willing to give the FBI a backdoor?)
How to be anonymous in the age of surveillance
The Seattle Times: “Cory Doctorow’s sunglasses are seemingly ordinary. But they are far from it when seen on security footage, where his face is transformed into a glowing white orb. At his local credit union, bemused tellers spot the curious sight on nearby monitors and sometimes ask, “What’s going on with your head?” said Doctorow, chuckling. The frames of his sunglasses, from Chicago-based eyewear line Reflectacles, are made of a material that reflects the infrared light found in surveillance cameras and represents a fringe movement of privacy advocates experimenting with clothes, ornate makeup and accessories as a defense against some surveillance technologies. Some wearers are propelled by the desire to opt out of what has been called “surveillance capitalism” — an economy that churns human experiences into data for profit — while others fear government invasion of privacy…
Today, artificial intelligence (AI) technology, such as facial recognition, has become more widespread in public and private spaces — including schools, retail stores, airports, concert venues and even to unlock the newest iPhones. Civil-liberty groups concerned about the potential for misuse have urged politicians to regulate the systems. A recent Washington Post investigation, for instance, revealed FBI and Immigration and Customs Enforcement agents used facial recognition to scan millions of Americans’ driver’s licenses without their knowledge to identify suspects and undocumented immigrants…”




Train your dragon.
Stanford Researchers Publish AI Index 2019 Report
The Stanford University Human-Centered Artificial Intelligence Institute published its AI Index 2019 Report. The 2019 report tracks three times the number of datasets as the previous year's report and contains nearly 300 pages of data and graphs related to several aspects of AI, including research, technical performance, education, and societal considerations.
The report is the result of an effort led by the Institute's AI Index Steering Committee, a team of researchers and industry experts chaired by AI21Labs co-founder Yoav Shoham. This is the report's third year, and it includes updates of previous metrics as well as new ones. In addition to the report, the committee has released two web-based tools: the Global AI Vibrancy Tool for comparing data across countries, and the arXiv Monitor for searching pre-print research papers to track technical metrics.   According to the Committee's web site, the Index's mission is:
to provide unbiased, rigorous, and comprehensive data for policymakers, researchers, journalists, executives, and the general public to develop a deeper understanding of the complex field of AI.



Monday, January 13, 2020


A bit overcautious, but worth considering.
https://www.telegraph.co.uk/news/2020/01/12/gchq-warns-not-use-windows-7-computers-banking-email-tuesday/
GCHQ warns not to use Windows 7 computers for banking or email after Tuesday
GCHQ has warned people not to do internet banking or use emails from computers with Windows 7 from Tuesday, when Microsoft will end support for the software.






“Rules? We don’t need no stinking rules!” (With apologies to The Treasure of the Sierra Madre)
https://thehill.com/policy/cybersecurity/477795-congress-struggles-on-rules-for-cyber-warfare-with-iran
Congress struggles on rules for cyber warfare with Iran
The U.S. and Iran may have walked back from the brink of war, but the potential for a cyber battle looms with no clear rules of engagement.
Lawmakers and military officials say there’s no agreed-upon definition of what constitutes cyber warfare, leaving them to decide on a case-by-case basis how best to respond to individual incidents.






I wonder if intelligence agencies are notifying companies to ignore activity on certain accounts? Probably not. And they probably don’t like this article, reminding terrorists that not everyone hacking their phones is just in it for the money.
https://www.timesofisrael.com/facebook-reportedly-derailed-europe-terror-probe-by-alerting-users-of-phone-hack/
Facebook reportedly derailed Europe terror probe by alerting users of phone hack
Facebook in October reportedly derailed an investigation into an Islamic State terror suspect by European law enforcement and an Israeli intelligence firm by warning users that their phones had been hacked.
The company’s massively popular messaging platform, WhatsApp, notified some 1,400 users, including the suspect, that an “advanced cyber actor” had gained access to their devices. The suspect, who was believed to be planning a terror attack during the holiday season, disconnected shortly after.






Are lawyers relying on the techies to design the technique?
https://telecoms.com/501725/the-internet-could-be-set-for-a-fresh-gdpr-nightmare/
The internet could be set for a fresh GDPR nightmare
A new academic study into online consent management platforms has concluded many of them could be flouting GDPR rules.
The study was conducted by a consortium of universities and its findings published under the header: ‘Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence’. We’re all aware of the pop-ups that have, well, popped up since GDPR came into force, requiring us to click ‘I agree’ to cookies and that sort of thing when we first visit a website, and often continually afterwards. But what are we actually agreeing to?
The issue this study seems to have been conducted to address concerns how much information people are supplied with when asked for their consent, as well as the matter of presumed consent – i.e. opt-out as opposed to opt-in. In many cases this process is managed by third party consent management platforms (CMP), and that’s what the study focused on.
[The study: https://arxiv.org/abs/2001.02479



(Related) A most interesting way to get your approval.
https://www.albawaba.com/
Al Bawaba
We use cookies on this site to enhance your user experience
By clicking any link on this page you are giving your consent for us to set cookies.






A freebie worth grabbing?
https://www.bespacific.com/book-review-blockchain-and-the-law-the-rule-of-code/
Book review: Blockchain and the Law: The Rule of Code
Joseph Savirimuthu, “Book review: Blockchain and the Law: The Rule of Code”, (2019) 16:1 SCRIPTed 95 https://script-ed.org/?p=3748 DOI: 10.2966/scrip.160119.95. Download PDF
Blockchains, distributed ledger technologies, bitcoins and peer-to-peer networks have reignited old debates and arguments about the implications of decentralisation for social, economic and political ordering. Blockchain and the Law: The Rule of Code sets out to map the landscape of this technology that enables its readers to assess the opportunities and regulatory challenges. The coverage is impressive, well-researched and key issues are examined and analysed with rigor and clarity. This book will appeal to technology and innovation scholars, policymakers and lawyers. It is also likely to be suitable for academic and policy programmes at undergraduate and postgraduate level. The book is well-structured with an overriding goal – to define and explain the rationale and goals of the law in seeking to regulate the technology. As observers of the innovation opportunities and challenges will attest, the quest to formulate optimal strategies is complex and far from straightforward. It is a point that needs to be kept in mind that Blockchain and the Law will not resolve ongoing arguments about the mismatch between technological innovation and the ability of law to keep pace. The book is structured with five Parts, beginning with an account of the characteristics of blockchain technology (Part 1) before proceeding to examine financial and contractual instruments (Part 2), security standards and protocols (Part 3), the institutional and organizational infrastructure (Part 4) and governance (Part 5). Whether the regulatory responses to blockchains will culminate in a lex cryptographica is merely a springboard for an examination of how the problems of associated with the automated and decentralised architecture are to be mitigated. For those with long memories of peer-to-peer file sharing services in the 1990s and 2000, one may need to be more circumspect about whether the distinctive decentralised software infrastructure upon which blockchain applications sit, will succeed in creating “order without law” (p. 5).






Face it, this technology is questionable.
https://www.nytimes.com/2020/01/12/technology/facial-recognition-police.html
How the Police Use Facial Recognition, and Where It Falls Short
After a high-speed chase north of Orlando, Fla., sheriff’s deputies punctured the tires of a stolen Dodge Magnum and brought it to a stop. They arrested the driver, but couldn’t determine who he was. The man had no identification card. He passed out after stuffing something into his mouth. And his fingerprints, the deputies reported, appeared to have been chewed off.
So investigators turned to one of the oldest and largest facial recognition systems in the country: a statewide program based in Pinellas County, Fla., that began almost 20 years ago, when law enforcement agencies were just starting to use the technology. Officers ran a photo of the man through a huge database, found a likely match and marked the 2017 case as one of the system’s more than 400 successful “outcomes ” since 2014.
… Officials in Florida say that they query the system 4,600 times a month. But the technology is no magic bullet: Only a small percentage of the queries break open investigations of unknown suspects, the documents indicate. The tool has been effective with clear images — identifying recalcitrant detainees, people using fake IDs and photos from anonymous social media accounts — but when investigators have tried to put a name to a suspect glimpsed in grainy surveillance footage, it has produced significantly fewer results.
The Florida program also underscores concerns about new technologies’ potential to violate due process. The system operates with little oversight, and its role in legal cases is not always disclosed to defendants, records show. Although officials said investigators could not rely on facial recognition results to make an arrest, documents suggested that on occasion officers gathered no other evidence.
Only one American court is known to have ruled on the use of facial recognition by law enforcement, and it gave credence to the idea that a defendant’s right to the information was limited.
Willie Allen Lynch was accused in 2015 of selling $50 worth of crack cocaine, after the Pinellas facial recognition system suggested him as a likely match. Mr. Lynch, who claimed he had been misidentified, sought the images of the other possible matches; a Florida appeals court ruled against it. He is serving an eight-year prison sentence.
Any technological findings presented as evidence are subject to analysis through special hearings, but facial recognition results have never been deemed reliable enough to stand up to such questioning.






All you need is a large format printer and you’re ready to frame!
https://www.bespacific.com/100000-artworks-images-from-paris-museum-collections-now-freely-available/
100,000 Artworks Images From Paris Museum Collections Now Freely Available
Hyperallergic: “Paris Musées announced yesterday that it is now offering 100,000 digital reproductions of artworks in the city’s museums as Open Access — free of charge and without restrictions — via its Collections portal. Paris Musées is a public entity that oversees the 14 municipal museums of Paris, including the Musée d’Art Moderne de la Ville de Paris, Petit Palais, and the Catacombs. Users can download a file that contains a high definition (300 DPI) image, a document with details about the selected work, and a guide of best practices for using and citing the sources of the image…”






For my fellow tax payers.
https://www.bespacific.com/how-to-file-your-state-and-federal-taxes-for-free-in-2020/
How to File Your State and Federal Taxes for Free in 2020
ProPublica – “TurboTax and other tax prep services advertised themselves as “free,” but we found several ways that they tricked people into paying. Here’s our guide to preparing and filing your taxes without falling into a trap.”




Sunday, January 12, 2020


A successful day of phishing. Very little useful data so far.
Texas school district loses $2.3 million from phishing scam
KSAT reports:
Manor Independent School District, just east of Austin, is out of $2.3 million from a phishing scam.
Investigators say the phishing email was sent to multiple people at the school district and it was a single person that responded.
The money was sent through three separate transactions.
Read more on KSAT,
[From the article:
Investigators said whoever paid didn’t realize the bank account information was changed and it was being sent to a fake bank.




Security and AI
The dangers of IoT and AI
The risks of cybersecurity are more complex than ever. Due to the rise of the Internet of Things (IoT) and Artificial Intelligence (AI), by 2020 every person will generate 1.7 megabytes of information per second. As new technologies evolve, cyber criminals adapt and discover new hacking methods to apprehend sensitive data. AI and IoT have the potential to revolutionise society, but what happens when these new technologies are weaponized by cyber criminals?
Unless hardware-based endpoint security solutions are implemented in IoT and AI devices, users leave themselves vulnerable to cyberattacks. Anyone in control of one or more of these devices can access a huge number of computers and networks.




This may have real potential! If nothing else, a guide to forensic investigators when something goes wrong?
Datasheets for Datasets
Currently there is no standard way to identify how a dataset was created, and what characteristics, motivations, and potential skews it represents. To begin to address this issue, we propose the concept of a datasheet for datasets, a short document to accompany public datasets, commercial APIs, and pretrained models. The goal of this proposal is to enable better communication between dataset creators and users, and help the AI community move toward greater transparency and accountability. By analogy, in computer hardware, it has become industry standard to accompany everything from the simplest components (e.g., resistors), to the most complex microprocessor chips, with datasheets detailing standard operating characteristics, test results, recommended usage, and other information. We outline some of the questions a datasheet for datasets should answer. These questions focus on when, where, and how the training data was gathered, its recommended use cases, and, in the case of human-centric datasets, information regarding the subjects' demographics and consent as applicable. We develop prototypes of datasheets for two well-known datasets: Labeled Faces in The Wild and the Pang \& Lee Polarity Dataset.




Hits everything I’m teaching this year!
The 4 Hottest Trends in Data Science for 2020
Companies all over the world across a wide variety of industries have been going through what people are calling a digital transformation. That is, businesses are taking traditional business processes such as hiring, marketing, pricing, and strategy, and using digital technologies to make them 10 times better.
Data Science has become an integral part of those transformations. With Data Science, organizations no longer have to make their important decisions based on hunches, best-guesses, or small surveys. Instead, they’re analyzing large amounts of real data to base their decisions on real, data-driven facts.
The following are the 4 hottest Data Science trends for the year 2020. These are trends which have gathered increasing interest this year and will continue to grow in 2020.
(1) Automated Data Science
(2) Data Privacy and Security
(3) Super-sized Data Science in the Cloud
(4) Natural Language Processing




The logic of selfies?



Saturday, January 11, 2020


Something my Computer Security students must consider. Not just disruption of services but massive disclosure of data. Paying the ransom is not guarantee that this is over.
Maze Ransomware Publishes 14GB of Stolen Southwire Files
The Maze Ransomware operators have released an additional 14GB of files that they claim were stolen from one of their victims for not paying a ransomware demand.
In December the Maze Ransomware operators attacked Southwire, a wire and cable manufacturer out of Georgia, and allegedly stole 120GB worth of files before encrypting 878 devices on the network.
Maze then demanded $6 million in bitcoins or they would publicly release Southwire's stolen files.
When Southwire did not make a payment, the Maze operators uploaded some of the company's files to a "News" site that they had created to shame non-paying victims.
This led to Southwire filing a lawsuit against Maze in Georgia courts and asking for an injunction in the courts of Ireland against a web hosting provider who was hosting the Maze news site. This injunction led to the site being taken down and Southwire's stolen data being accessible.
Yesterday, the Maze operators released an additional 14.1GB of stolen files that they claim belong to Southwire on a Russian hacking forum. They further state that they will continue to release 10% of the data every week unless the ransom is paid.




Who do you want elected and by how much?
'Online and vulnerable': Experts find nearly three dozen U.S. voting systems connected to internet
It was an assurance designed to bolster public confidence in the way America votes: Voting machines “are not connected to the internet.”
Then Acting Undersecretary for Cybersecurity and Communications at the Department of Homeland Security Jeanette Manfra said those words in 2017, testifying before Congress while she was responsible for the security of the nation’s voting system.
So many government officials like Manfra have said the same thing over the last few years that it is commonly accepted as gospel by most Americans. Behind it is the notion that if voting systems are not online, hackers will have a harder time compromising them.
But that is an overstatement, according to a team of 10 independent cybersecurity experts who specialize in voting systems and elections. While the voting machines themselves are not designed to be online, the larger voting systems in many states end up there, putting the voting process at risk.
… “We found over 35 [voting systems] had been left online and we’re still continuing to find more,” Kevin Skoglund, a senior technical advisor at the election security advocacy group National Election Defense Coalition, told NBC News.
The three largest voting manufacturing companies — Election Systems &Software, Dominion Voting Systems and Hart InterCivic — have acknowledged they all put modems in some of their tabulators and scanners. The reason? So that unofficial election results can more quickly be relayed to the public. Those modems connect to cell phone networks, which, in turn, are connected to the internet.




...and changing enterprise architecture.
The Internet of Things Is Changing the World
The Internet of Things has been a long time coming. Ubiquitous or pervasive computing, which is computing happening anytime and anywhere, dates to the 1990s, when devices and wireless networks were nowhere near where they are today.
The transformation brought by connected devices is about to go into overdrive, the Economist says in a recent issue: “One forecast is that by 2035 the world will have a trillion connected computers, built into everything from food packaging to bridges and clothes.”
IoT promises to bring many benefits, including a new generation of smart, connected products. In addition to mechanical and electrical components, these products use digital components such as microprocessors, sensors, data storage, software, and connectivity in a variety of ways.


(Related) Perspective.
About one-in-five Americans use a smart watch or fitness tracker
A fitness tracker can compile a variety of data about the wearer’s activities, depending on the complexity of the device. Users can monitor this data with a corresponding app, where they can manually input additional information about themselves and their lifestyle. As a result, the makers of fitness trackers amass a wealth of data on their users that can be used in many ways. Current privacy policies for many fitness tracking apps allow users’ data to be shared with others. Some researchers are already using data from these apps for health research,




Worth a look.
New Supplemental Materials for INFORMATION PRIVACY LAW Casebooks
I am pleased to announce that Professor Paul Schwartz and I have released new supplemental materials for our INFORMATION PRIVACY LAW casebooks:
(1) edited version of Carpenter v. US




Any indication that this technology is worth the investment?
San Diego’s massive, 7-year experiment with facial recognition technology appears to be a flop
Since 2012, the city’s law enforcement agencies have compiled over 65,000 face scans and tried to match them against a massive mugshot database. But it’s almost completely unclear how effective the initiative was, with one spokesperson saying they’re unaware of a single arrest or prosecution that stemmed from the program.




Part of my Security lectures.
What a Business AI Ethics Code Looks Like
By now, it’s safe to say that artificial intelligence (AI) has established itself in the mainstream, especially in the world of business. From customer service and marketing, to fraud detection and automation, this particular technology has helped streamline operations in recent years.
Unfortunately, our dependence on AI also means that it holds so much of our personal information – whether it’s our family history, the things we buy, places we go to, or even our favourite songs. Essentially, we’re giving technology free access to our lives. As AI continues to develop (and ask for even more data), it’s raising a lot of serious concerns.
The AI code of ethics isn’t meant for the AI itself, but for the people who develop and use said technology. Last year, the UK government published a report that aims to inform the public about its ethical use. All in all, the report can be summarised into five principles:
1. AI must be created and used for the benefit of all.
2. AI should not be used to diminish the data rights or privacy of individuals, families, and communities.
3. AI must operate within parameters understood by the human mind.
4. Everybody has the right to be educated on the nuances of AI.
5. Humans must be able to flourish mentally, emotionally, and economically alongside AI.




Probably not...
Samsung's Neon AI has an ethics problem, and it's as old as sci-fi canon
For decades, ethicists, philosophers and science fiction writers have wrestled with what seems increasingly like an inevitability in the evolution of humankind's technological discovery: The creation of a new species of artificial humanity. What better place for such a species' debutante ball than the Las Vegas consumer electronics frenzy, CES 2020? Enter stage right: The eerily realistic interactive CGI avatar, Neon.. It's the literal brainchild of Samsung-funded Star Labs' Pranav Mistry, who also serves as CEO of the company he says is building "the first computerized artificial human."
"Neon is like a new kind of life," Mistry said when unveiling the technology this week at CES. "There are millions of species on our planet, and we hope to add one more."