Thursday, November 12, 2020

Another change in strategic Computer Security thinking.

https://www.zdnet.com/article/microsoft-urges-users-to-stop-using-phone-based-multi-factor-authentication/

Microsoft urges users to stop using phone-based multi-factor authentication

… The Microsoft exec cites several known security issues, not with MFA, but with the state of the telephone networks today.

Weinert says that both SMS and voice calls are transmitted in cleartext and can be easily intercepted by determined attackers, using techniques and tools like software-defined-radios, FEMTO cells, or SS7 intercept services.





Too much disclosure to catch on? Perhaps California could add this to their next Privacy law update…

https://www.schneier.com/blog/archives/2020/11/privacy-nutrition-labels-in-apples-app-store.html

“Privacy Nutrition Labels” in Apple’s App Store

Apple will start requiring standardized privacy labels for apps in its app store, starting in December:

Apple allows data disclosure to be optional if all of the following conditions apply: if it’s not used for tracking, advertising or marketing; if it’s not shared with a data broker; if collection is infrequent, unrelated to the app’s primary function, and optional; and if the user chooses to provide the data in conjunction with clear disclosure, the user’s name or account name is prominently displayed with the submission.
Otherwise, the privacy labeling is mandatory and requires a fair amount of detail. Developers must disclose the use of contact information, health and financial data, location data, user content, browsing history, search history, identifiers, usage data, diagnostics, and more. If a software maker is collecting the user’s data to display first or third-party adverts, this has to be disclosed.
These disclosures then get translated to a card-style interface displayed with app product pages in the platform-appropriate App Store.

The concept of a privacy nutrition label isn’t new, and has been well-explored at CyLab at Carnegie Mellon University.





Settle yes, but what should you settle for?

The FTC Zoom Case: Does the FTC Need a New Approach?

As I mentioned yesterday on DataBreaches.net in noting the FTC settlement with Zoom, two commissioners dissented from the settlement — and they dissented because they felt that the settlement didn’t do enough to protect or serve consumers.

Prominent privacy scholars Daniel Solove and Woody (Woodrow) Hartzog have written about their dissents and the settlement in a new piece, The FTC Zoom Case: Does the FTC Need a New Approach?

As scholars who have been supportive of the FTC’s approach in the past, they continue to support the use of settlements as opposed to costly and protracted litigation, but they do agree with the dissenting commissioners that certain recommendations should be implemented.

Read their commentary on LinkedIn.





A very interesting perspective.

JAIC Chief Asks: Can AI Prevent Another 1914?

What does the three-star director of the Pentagon’s Joint Artificial Intelligence Center worry about? “Let me start in 1914,” said Lt. Gen. Michael Groen.

“Yes, 1914 – I see the look on your face,” Groen told the moderator of an online forum Friday at the Center for Strategic and International Studies (CSIS).

1914 was the last time great powers went to war after decades of relative peace, using radically new technology they didn’t really understand. Back then, Groen said, the result was infantry with bayonets and cavalry with lances trying to charge machine gun nests, futilely pitting muscle power against mechanical power. In the 21st century, he fears, “the Information Age equivalent of… lancers riding into machine guns” is using traditional command, control, and planning processes against an adversary using artificial intelligence, pitting human brainpower against machine speed.



(Related)

https://www.militaryaerospace.com/sensors/article/14187088/radar-jet-fighter-artificial-intelligence

Britain's Tempest sixth-generation jet fighter will have high-speed radar, artificial intelligence (AI)

The companies building the United Kingdom's Tempest sixth-generation fighter aircraft have revealed some of the enabling technologies that be part of the new plane, including a radar system designed to handle as much data per second as a city.

The Military & Aerospace Electronics take:

11 Nov. 2020 – Under development for the Royal Air Force (RAF), the Tempest will be one of the first sixth-generation jet fighter aircraft. It's designed to complement current combat craft like the F-35 Lightning II and the Typhoon fighters starting in the mid-2030s until the older warplanes are retired in the 2040s.

The stealth fighter will be able to carry hypersonic missiles and control drone swarms, and produce large amounts of electricity so it can power laser weapons.

Along with this, the twin-engine, delta-wing Tempest will have reconfigurable artificial intelligence (AI) and cyber-hardened communications that enable it to act as a flying command and control center, where the pilot acts more as a supervisor than as a dog fighter.





Because gold is boring?

https://www.bespacific.com/retail-might-be-struggling-but-the-rich-are-buying-rare-books/

Retail Might Be Struggling, But the Rich Are Buying Rare Books

Bloomberg via MSN: “Even as independent bookstores struggle to survive, rare books and manuscripts have proven a rare bright spot in the industry. “It’s almost like two businesses,” says Kenneth Gloss, the owner of Brattle Book Shop in Boston. “As far as the general used-book business, it’s been off.” His third floor of rare and antiquarian books, though, is doing nearly as well as it ever has. “People are at home, the stock market is doing well, so people with spare funds are sitting home, bored and buying a lot of books,” Gloss says. The same phenomenon has occurred in categories as disparate as jewelry and classic cars. Rich people are still rich, and they’re still spending serious amounts of money on things that bring them joy—and perhaps, a return on investment later. The market for extremely rare books has been healthy for years, dealers say, but quantifying its ups and downs is difficult, because “if you’re talking about a book with many comparables over time, you’ve missed the top of the market,” says Darren Sutherland, a specialist in Bonham’s rare books department in New York.”



Wednesday, November 11, 2020

Because GDPR was not enough?

https://www.techdirt.com/articles/20201106/03572745657/surprise-latest-draft-eus-next-big-privacy-law-includes-some-improvements.shtml

Surprise: Latest Draft Of The EU's Next Big Privacy Law Includes Some Improvements

The EU's new ePrivacy regulation is a strange beast. It's important, designed to complement the EU's GDPR. Where the GDPR is concerned with personal data "at rest" -- how it is stored and processed -- the ePrivacy Regulation can be thought of as dealing with personal data in motion. Despite that importance, it is largely unknown, except to people working in this area. That low profile is particularly strange given the fierce fighting that is taking place over what exactly it should allow or forbid. Businesses naturally want as much freedom as possible to use personal data as they wish, while privacy activists want the new regulation to strengthen the protection already provided by the GDPR.

A new draft version of the ePrivacy regulation has appeared from the Presidency of the EU Council, currently held by Germany. It is a nearly illegible mess of deletions and additions, but it contains some welcome improvements from the previous version (pdf), which was released in March 2020. One relates to the protection of the "end-users' terminal equipment" -- a legalistic way of saying the device used by the user.

… But the most significant change from the previous version concerns the controversial issue of "legitimate interests". This was perhaps the biggest loophole in the previous draft

… The concept of "legitimate interests" was so vague that it essentially allowed companies to do pretty much whatever they wanted with sensitive personal information they gathered. The latest draft from the German Presidency deletes this section completely. That's good news for users of online services, but predictably, telecoms companies are unhappy.





Other priorities? The political value was not as great as they thought?

https://www.cnbc.com/2020/11/10/what-happened-to-tiktok-deal-trump-administration-silent.html

TikTok hasn’t heard from the Trump administration in weeks, prompting latest CFIUS petition





Is this how AIs will make us trust them?

https://www.psychologytoday.com/us/blog/all-we-need-is-love/202011/do-you-trust-artificial-intelligence

Do You Trust Artificial Intelligence?

Can we make people trust AI more using attachment security?

… what happens when people are being introduced to a new AI technology? How likely are they to trust the new technology?

With an interdisciplinary team of researchers from the University of Kansas, we set to find out. The results are published in a new paper in the journal Computers in Human Behavior. We found that people’s trust in AI is tied to their relationship or attachment style. Our research shows that people who are anxious about their relationships with humans tend to be less trusting when it comes to AI. Importantly, the research also suggests trust in artificial intelligence can be increased by reminding people of their secure relationships with other humans.





I wonder how many thought wearing a mask was unnecessary? (Suggesting there was some mental impairment before infection.)

https://www.bespacific.com/one-in-five-covid-19-patients-develop-mental-illness-within-90-days/

One in five COVID-19 patients develop mental illness within 90 days

Reuters – “Many COVID-19 survivors are likely to be at greater risk of developing mental illness, psychiatrists said on Monday, after a large study found 20% of those infected with the coronavirus are diagnosed with a psychiatric disorder within 90 days. Anxiety, depression and insomnia were most common among recovered COVID-19 patients in the study who developed mental health problems. The researchers from Britain’s Oxford University also found significantly higher risks of dementia, a brain impairment condition. “People have been worried that COVID-19 survivors will be at greater risk of mental health problems, and our findings … show this to be likely,” said Paul Harrison, a professor of psychiatry at Oxford. Doctors and scientists around the world urgently need to investigate the causes and identify new treatments for mental illness after COVID-19, Harrison said. “(Health) services need to be ready to provide care, especially since our results are likely to be underestimates (of the number of psychiatric patients),” he added.

The study, published in The Lancet Psychiatry journal, analysed electronic health records of 69 million people in the United States, including more than 62,000 cases of COVID-19. The findings are likely to be the same for those afflicted by COVID-19 worldwide, the esearchers said..”





Perspective. Not you can watch your house burn down from anywhere!

https://www.makeuseof.com/ring-smart-doorbells-recalled-after-fire/

Ring Smart Doorbells Are Being Recalled After Some Caught Fire

The recall affects over 350,000 2nd generation Ring doorbells, which suffer from a battery fault.



Tuesday, November 10, 2020

Any experienced hacker looks at all the simple/obvious failures as a matter of course. I suspect Russia, China, North Korea and Iran knew about this almost as soon as it went into use. It’s the kind of job you assign to your trainee hackers.

https://www.zdnet.com/article/bug-hunter-wins-researcher-of-the-month-award-for-dod-account-takeover-bug/#ftag=RSSbaffb68

Bug hunter wins 'Researcher of the Month' award for DOD account takeover bug

The US Department of Defense has fixed a severe vulnerability impacting its internal network that would have allowed threat actors to hijack DOD accounts just by modifying a few parameters in web requests sent to DOD servers.

… The issue received a severity rating of "Critical (9 ~ 10)" because the bug required minimal technical skills to exploit and hijack any DOD account of the attacker's choosing.

… While some details about the bug have been disclosed earlier today, a full report won't be fully available; to protect the security of the DOD network.

According to this summary report, the bug was categorized as an Insecure Direct Object References (IDOR ) vulnerability, a bug where security checks are missing from an application, allowing hackers to modify a few parameters without any additional identity checks.

In the DOD's case, the bug would have allowed an attacker to take a legitimate web request sent to a DOD website, modify the user ID and username parameters, and the DOD site would have allowed the attacker to change any user's DOD account password — which would have allowed hackers to hijack accounts and later breach the DOD's network.





I told you these guys are good…

https://www.theregister.com/2020/11/09/gchq_hacks_russia_vaccine_disinfo/

Somebody's Russian to meddle with UK coronavirus vaccine efforts, but GCHQ won't take it lying down

British eavesdropping agency GCHQ is actively hacking Russian attempts to undermine coronavirus vaccine efforts, according to The Times.

… Tactics deployed against the Russia-backed actors are said to include "encrypting" the operators' data, mildly suggestive of ransomware – albeit without the ransom.





Comes with a major loophole…

https://www.technologyreview.com/2020/11/09/1011837/europe-is-adopting-stricter-rules-on-surveillance-tech/

Europe is adopting stricter rules on surveillance tech

The goal is to make sales of technologies like spyware and facial recognition more transparent in Europe first, and then worldwide.

The European Union has agreed to stricter rules on the sale and export of cyber-surveillance technologies like facial recognition and spyware. After years of negotiations, the new regulation will be announced today in Brussels. Details of the plan were reported in Politico last month.

The regulation requires companies to get a government license to sell technology with military applications; calls for more due diligence on such sales to assess the possible human rights risks; and requires governments to publicly share details of the licenses they grant. These sales are typically cloaked in secrecy, meaning that multibillion-dollar technology is bought and sold with little public scrutiny.

… The main thing the new regulation achieves, according to its backers, is more transparency. Governments must either disclose the destination, items, value, and licensing decisions for cyber-surveillance exports or make public the decision not to disclose those details.





Why I don’t like teaching online, volume 2. Are all online students criminals?

https://www.vice.com/en/article/88anxg/students-have-to-jump-through-absurd-hoops-to-use-exam-monitoring-software

Students Have To Jump Through Absurd Hoops To Use Exam Monitoring Software

Using hand mirrors and making 3D room scans are among the bizarre instructions students must follow while using software like ProctorU and Respondus.





Many views always beat one view.

https://www.huntonprivacyblog.com/2020/11/09/webinar-on-the-california-privacy-rights-act/

Webinar on the California Privacy Rights Act

On November 19, 2020, Hunton Andrews Kurth will host a webinar examining the recently approved California Privacy Rights Act (“CPRA”) and how it revises the California Consumer Privacy Act of 2018 (“CCPA”).





The consulting world changes…

https://www.databreaches.net/cyber-consulting-firms-get-tied-up-in-post-breach-lawsuits/

Cyber Consulting Firms Get Tied Up in Post-Breach Lawsuits

Jake Holland and Andrea Vittorio report:

Cybersecurity consultants could be on the hook for data breaches at companies they contract with after two recent court rulings in consumer class actions.
Accenture Plc’s U.S. unit in October failed to escape claims made against the consultant in a consumer lawsuit over a hack of Marriott International Inc.’s hotel reservations database. The decision came after Capital One Financial Corp. was forced to turn over cybersecurity firm Mandiant’s report on a cloud hack in another case.
The cases raise questions about whether a consultant’s work should be considered fair game for class action lawyers gathering evidence on a cyber incident to try to hold the consulting firms responsible for fallout from breaches.

Read more on Bloomberg Law.





A problem common to all industries with record keeping regulations. Can you imagine asking any head of state for a copy of a phone conversation transcript? “Why yes, the President promised to sell us Hawaii for $24.”

https://www.bespacific.com/biden-may-have-trouble-unearthing-trumps-national-security-secrets/

Biden may have trouble unearthing Trump’s national security secrets

Politico: “From tearing up documents and hiding transcripts of calls with foreign leaders to using encrypted messaging apps and personal email accounts for government business, the Trump White House’s skirting of records preservation rules could limit the incoming Biden administration’s visibility into highly sensitive foreign policy and national security secrets… The Presidential Records Act, which requires a sitting president to preserve and ultimately make public all records relating to the performance of their official duties, was passed 42 years ago in response to President Richard Nixon’s attempts to hide the White House tapes that led to his downfall. The law makes presidential records available to the public via the Freedom of Information Act beginning five years after the end of an administration. But it has no real enforcement mechanism and relies on the president’s good faith compliance, said Kel McClanahan, the executive director of the law firm National Security Counselors.

Out of respect for the institution and the separation of powers, when Congress passed the PRA, they gave the White House the right to decide what constitutes a presidential record,” McClanahan said. “They never envisioned a president who would come in and just start shredding stuff.”…





There were no headlines like this for the Apple II. Perhaps there should have been.

https://www.cnet.com/news/apple-new-macs-could-change-computers-as-we-know-them-one-more-thing-event-new-chips/

Apple's new Macs could change computers as we know them

Apple's expected to announce the first computers powered using chips that are more like an iPhone than a typical PC. That alone is exciting to the techies, but it's also a sign of what's possible to come, whether you buy a Mac or not. The iPhone maker's said it's going to change the brains of its computers over the next couple years. Starting with the computers it's expected to announce Tuesday, Apple's going to throw its weight behind its own self-made chips.

… By combining all its devices under the same chips and common code, Apple will be able to offer an experience that truly spans its desktops, laptops, phones and watches. Apple's already said app developers will be able to create one app and send it to all devices, with adjustments for keyboard and mouse vs finger touch and gestures.

… What's likely to change more than anything is on the outside of the laptop and desktop. Apple's iPhones and iPads don't have fans to keep their chips cool. Analysts are betting that if Apple can pull off that same trick with its computers, the fans that take up space and force the laptop to be thicker might disappear.



(Related)

https://www.makeuseof.com/samsung-passes-apple-number-one-smartphone-brand-us/

Samsung Passes Apple as Number One Smartphone Brand in the US

According to market researcher Strategy Analytics (h/t the Korea Herald ), Samsung has slid its way into the number one spot for most smartphones sold in the US for the third quarter of 2020.

During the July-September period, Samsung accounted for 33.7 percent in the US smartphone market. That's an impressive 6.7 percent increase over the same period in 2019.

While Apple may not be number one anymore, the company still moved plenty of smartphones, accounting for 30.2 percent of the market.





Free learning for shut-ins.

https://www.techrepublic.com/article/free-ibm-developer-conference-on-ai-and-data-science-includes-300-in-credits-for-coursera-class/

Free IBM developer conference on AI and data science includes Coursera certification

Developers and business leaders can learn about the latest trends in artificial intelligence (AI) at IBM's free Data & AI digital conference on Nov. 10 starting at 2 pm GMT. The sessions will focus on operations, ethics, and cloud computing. IBM is running the conference again on Nov. 24 for India and the Asia Pacific region.

… People who register for the conference get $300 in credits to spend on any services in the IBM Cloud Catalog. Attendees who completes the course in Track 3 earn an AI and Data Essentials badge. Participants also can get select Coursera specializations and certifications for free, including:

Most of the sessions will be pre-recorded and available as soon as the conference opens.



Monday, November 09, 2020

Well, Mondays are always slow, but I still have hope that more non-election, non-covid articles will make it through my search filters.



Due in January.

https://blogs.lse.ac.uk/usappblog/2020/11/08/book-review-the-internet-in-everything-freedom-and-security-in-a-world-with-no-off-switch-by-laura-denardis/

Book Review: The Internet in Everything: Freedom and Security in a World with No Off Switch by Laura DeNardis

In The Internet in Everything: Freedom and Security in a World with No Off Switch, Laura DeNardis offers an exploration of the invisible, complex and concerning worldwide network of technologies often referred to as the Internet of Things, focusing particularly on the pressing issues of governance and jurisdiction.

One of the most pressing concerns in contemporary cybersecurity scholarship is how the ‘Internet of Things’ is affecting, and will affect, both individual security and privacy and the security of the state. As more and more devices connect to the internet and become integrated into every aspect of daily life, there is an ongoing battle between device efficacy and device security, between device utility and individual privacy, between security threat and threat mitigation.





No good deed goes unpunished.

https://www.cnbc.com/2020/11/09/zoom-and-other-stay-at-home-stocks-are-getting-crushed-on-the-positive-vaccine-news.html

Zoom and other ‘stay-at-home’ stocks are getting crushed on the positive vaccine news

Shares of Zoom Video fell sharply on Monday morning as names benefitting from people staying at home due to the coronavirus pandemic lost their appeal following the release of positive coronavirus vaccine data.

Zoom Video traded more than 15% lower in the premarket. Fellow “stay-at-home” stocks Amazon and Netflix dropped 3.4% and 5.4%, respectively. Teladoc Health slid 6.4% and Shopify declined by 5.1%.

Those losses came after Pfizer and BioNTech reported that their coronavirus vaccine candidate showed a 90% efficacy rate in preventing infections during a late-stage trial.



Sunday, November 08, 2020

I hope that with the election (if not the litigation) behind us, the articles I’m truly interested in will be able to fight their way through the pandemic news a bit easier.





One interesting question: Does ethics require data controllers to behave in ways that are not required by law?

https://www.researchgate.net/profile/Marco_Almada/publication/344955379_Ethics_in_data_processing_three_compliance_issues/links/5f9b0553458515b7cfa9492f/Ethics-in-data-processing-three-compliance-issues.pdf

Ethics in data processing: three compliance issues

The spread of large-scale data processing techniques, especially those employing artificial intelligence techniques, and the consequent increase in data collection (known as Big Data), has given rise to several debates about the ethics of how data is collected, manipulated and used by various types of consumers. These debates often lead to the creation of principles aimed at guiding data processing,2 and primarily how data is used as the basis for decision making, whether by humans or systems that utilize automatically processed data. In the present article, we will discuss how systems design approaches can be used to ensure that computer systems that process personal data3 do so in a manner consistent with accepted ethical principles.

To achieve this goal, our discussion will adopt a professional ethics perspective. In this perspective, the goal is to articulate standards and methods that guide the performance of a professional, equipping them both to resolve ethical issues that arise during the profession and to prevent ethical problems (Floridi and Sanders 2002). Under such a frame, the ethical discussion is connected both to the compliance with laws governing professional activity and to the observance of ethical principles.4

The identification of these principles, too, is the subject of broad discussion. Masiero (2013) describes three currents in discussions about computing ethics: the deontological perspective, according to which ethical conduct is identified through the fulfilment of general duties; utilitarianism, which evaluates the ethical value of conduct based on its consequences; and relativism, which denies the existence of ethical values that can be regarded as universal, conditioning ethics on culture. Even within each of these, or other possible perspectives, 5 the question remains of what are the starting points to consider: what are the relevant duties? How to correctly measure the consequences? What is valued in each culture? Even identifying the agents involved can be a relevant issue, as in the case of artificial intelligence-based data processing, where not only system designers but also data annotators have a significant impact on the results produced by a system.





Some questions. Any answers? One chapter of a new book.

https://www.igi-global.com/chapter/social-perspective-of-suspicious-activity-detection-in-facial-analysis/266134

Social Perspective of Suspicious Activity Detection in Facial Analysis: An ML-Based Approach for the Indian Perspective

The world is witnessing an unprecedented growth of cyber-physical systems (CPS), which are foreseen to revolutionize our world via creating new services and applications in a variety of sectors such as environmental monitoring, mobile health systems, and intelligent transportation systems and so on. The information and communication technology (ICT) sector is experiencing significant growth in data traffic, driven by the widespread usage of smart phones, tablets, and video streaming, along with the significant growth of sensors deployments that are anticipated soon. This chapter describes suspicious activity detection using facial analysis. Suspicious activity is the actions of an individual or group that is outside the normally acceptable standards for those people or that particular area. In this chapter, the authors propose a novel and cost-effective framework designed for suspicious activity detection using facial expression analysis or emotion detection analysis in law enforcement. This chapter shows a face detection module that is intended to detect faces from a real-time video.





Overview.

https://www.heritage.org/sites/default/files/2020-10/LM274_0.pdf

Addressing Legitimate Concerns About Government Use of Facial Recognition Technologies

The adoption of facial recognition technology (FRT) by federal and state government agencies—specifically, by law enforcement for identifying unknown individuals suspected of committing crimes—has generated a particularly heated debate about whether its potential benefits are outweighed by concerns over its potential for misuse and abuse.





What is “soon?”

https://www.tandfonline.com/doi/abs/10.1080/10438599.2020.1839173

Artificial intelligence: neither Utopian nor apocalyptic impacts soon

After a number of AI-winters, AI is back with a boom. There are concerns that it will disrupt society. The immediate concern is whether labor can win a ‘race against the robots’ and the longer-term concern is whether an artificial general intelligence (super-intelligence) can be controlled. This paper describes the nature and context of these concerns, reviews the current state of the empirical and theoretical literature in economics on the impact of AI on jobs and inequality, and discusses the challenge of AI arms races. It is concluded that despite the media hype neither massive jobs losses nor a ‘Singularity’ is imminent. In part, this is because current AI, based on deep learning, is expensive and difficult for most businesses to adopt, not only displaces but in fact also create jobs, and may not be the route to a super-intelligence. Thus AI is unlikely to have either Utopian or apocalyptic impacts soon. Considering Amara's Law, one should however be wary not to underestimate the long-run impacts of AI.





PDF slide show.

https://lirias.kuleuven.be/retrieve/592138

Overview of the Council of Europe's work on artificial intelligence

Translating human rights, democracy and rule of law to the digital age





Restating the obvious?

https://journals.eco-vector.com/2410-7522/article/view/46386

Digitalization in the understanding of philosophy, law, political science, and economics: an interdisciplinary approach

This article discusses the influence of digitalization on diverse social activity spheres. The authors analyze the essential notions of digitalization with regard to philosophy, law, political science, and economics. The digital sphere becomes virtual space without understanding and recognizing territorial and hence, nation-state, jurisdiction. Global digitalization for all social spheres becomes a reality.

Nowadays, the digital economy is globalizing, the public administration is digitalizing, electronic technologies in finance are developing, and smart cities are being created. Law lags significantly behind new digitalization challenges and does not always react swiftly with regard to social interaction dynamics. Philosophy conceptualizes human existence in digital society in the new digital era.





A tool worth grabbing?

https://www.makeuseof.com/python-regex-cheat-sheet/

The Python RegEx Cheat Sheet for Budding Programmers

The use of Python to solve various tech problems and its easy learning curve has made it one of the most popular modern programming languages. Despite being quick to learn, its regular expressions can be tricky, especially for newcomers.

For that reason, we've prepared this Python regular expressions cheat sheet to help you get a better hold of your syntaxes.

FREE DOWNLOAD: This cheat sheet is available as a downloadable PDF from our distribution partner, TradePub. You will have to complete a short form to access it for the first time only. Download the Python RegEx Cheat Sheet for Budding Programmers.



Saturday, November 07, 2020

Just to demonstrate that we are not battling amateurs.

https://www.databreaches.net/ransomware-crims-read-our-bank-balance-and-demanded-the-lot-reveals-scotlands-dundee-and-angus-college/

Ransomware crims read our bank balance and demanded the lot, reveals Scotland’s Dundee and Angus College

Ransomware operators often do their research on their victim to know what assets to go after. Here’s an example where threat actors did their research, but were perhaps too greedy in their demands. Gareth Corfield reports:

The criminals who took out Scotland’s Dundee and Angus College made a ransom demand that precisely added up to the contents of its bank account – and that was no accident, its principal has said……. “The cyber attackers had managed to get access to our bank account and knew how much money we had in it, which was the budget for the whole year. They demanded a ransom of exactly that amount, which we were never going to be able to pay,” Hewitt told Jisc.

Read more on The Register.





Seems biased to me. No taxation without representation! (By AI legislators?)

https://searchenterpriseai.techtarget.com/feature/AI-might-not-have-rights-but-it-could-pay-taxes

AI might not have rights, but it could pay taxes

Artificial intelligence systems shouldn't have rights, but they might have to pay taxes.

That's according to Ryan Abbott, professor of law and health sciences at the University of Surrey in Guildford, England.

During a virtual panel discussion on AI rights at Washburn University School of Law's symposium on the topic, Abbott said that while AI systems now "do the sorts of things people used to do," they don't have consciousness or morals, and thus don't deserve rights.

… if AGI were created, it could deserve humanlike rights, noted David Opderbeck, professor of law and co-director of the Gibbons Institute of Law, Science & Technology at Seton Hall University School of Law in Newark, N.J.

That's not to say governments shouldn't subject current AI systems to laws, however.

Tax laws, for example, don't currently take automated workers into account. While human employees contribute payroll and income taxes, an automated "employee" doesn't, Abbott noted.

Governments could lose out on quite a bit of income tax as AI becomes more prevalent and possibly displaces more human workers. Granted, that argument only works if displaced employees don't find other jobs. Abbott predicted that that may happen as AI becomes smarter at a rate that outpaces people's ability to learn new skills or find job training.

"Automation threatens our tax revenue," Abbott said, noting that the biggest sources of federal tax revenue in the U.S. are income and payroll taxes.





Medical-grade coffee may have a future in politics.

https://dilbert.com/strip/2020-11-07