Wednesday, December 02, 2020

When I talk about IP, I mention DRM. Of course you would remove DRM only for legal reasons...

https://www.makeuseof.com/tag/ways-to-remove-drm-from-ebooks/

How to Remove DRM From Your Ebooks: 6 Methods to Try



(Ditto)

https://www.makeuseof.com/how-to-remove-watermark-from-photo/

How to Remove a Watermark From a Photo: 5 Easy Ways





Freebie. Registration required.

https://thehackernews.com/2020/12/ciso-with-small-security-team-learn.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Cyber+Security+Blog%29

CISO with a small security team? Learn from your peers' experience with this free e-book

… In the e-Book "10 CISOs With Small Security Teams Share Their Must Dos and Don'ts" (Download it here), CISOs of teams up to 5 across the industries share their challenges and what worked with them in terms of efficiency.





Eventually, digital passports and CBP can copy that image.

CBP proposes to require mug shots of all non-US citizen travelers

From Papers, Please!

Last December we called attention to plans by US Customs and Border Protection (CBP) to require mug shots of all travelers entering or leaving the US by air or sea, including US citizens.
Within days, CBP issued a press release falsely accusing us of incorrectly reporting the official CBP notice of its plans, and saying that it would withdraw its notice the next time the regulatory agenda was published.
So what happened?
Earlier this month, CBP withdrew the notice of proposed rulemaking (NPRM)... and issued a new notice of proposed rulemaking the same day that wouldn’t apply to US citizens, but would require all non-US citizens, including permanent US residents (green-card holders) to be photographed whenever they enter or leave the US by any means: air, land, or sea.

Read more on Papers, Please!





A lot of my friend’s parents spoke Italian to each other. Would CBP have detained them? Speaking Klingon though…

Speaking Spanish is a not a lawful basis for being made to show ID

From Papers, Please!

US Customs and Border Protection (CBP) has agreed to pay a “monetary sum” to two native-born US citizens and Montana residents who were made to show ID and detained for about 40 minutes (including continuing detention even after they showed their Montana drivers licenses) solely because a CBP agent overhead them speaking Spanish to each other.
The amount of the settlement has not been made public.
The ACLU of Montana represented the two Latinx residents of Havre, MT, in their lawsuit, which initially sought a declaratory judgement “that race, accent, and language cannot create suspicion to justify seizure and/or detention” (which ought to go without saying) in addition to money damages.

Read more on Papers, Please!





An argument I’m watching…

https://www.abajournal.com/magazine/article/law-enforcement-is-using-location-tracking-on-mobile-devices-to-identify-suspects-geofence

Law enforcement is using location tracking on mobile devices to identify suspects, but is it unconstitutional?

… Chatrie is now asking a federal judge in Richmond, Virginia, to suppress evidence uncovered as a result of the warrant. His lawyers argue the warrant is unconstitutional, characterizing it as “a general warrant purporting to authorize a classic dragnet search of every Google user [and only Google users Bob] who happened to be near a bank in suburban Richmond during rush hour on a Monday evening.”

The government counters the warrant was “narrowly constrained based on location, dates, and times.” It says the limited geographic and time scopes make the warrant “particular”—lingo from the Fourth Amendment that states warrants must “particularly” describe the place to be searched and the persons or things to be seized. At press time, a hearing on the motion to suppress evidence was scheduled for Nov. 17.

Privacy advocates reject the idea that geographic and time limits render these warrants “particular.”

“Judges may know the size of an area being tracked and the duration, but it’s impossible for them to know how many people were in that area,” Cahn says.





Strategic implications? Limit data released in answer to each request…

https://www.cpomagazine.com/data-protection/german-court-slashes-gdpr-fine-for-telecoms-giant-by-90/

German Court Slashes GDPR Fine for Telecoms Giant by 90%

A German court has slashed a General Data Protection Regulation (GDPR) fine assessed to one of the country’s largest telecommunications service providers by over 90%, calling it “unreasonably high.”

… 1&1 Telecom GmbH was fined by the Federal Commissioner for Data Protection and Freedom of Information (BfDI) for an issue with the company’s customer service department. Callers to the customer service line were being provided with personal information from user accounts by doing nothing more than providing that user’s name and date of birth. The issue came to light when a customer filed a complaint against a stalker, a former partner who had made use of this security flaw to obtain the customer’s new phone number.

Though BfDI claimed the breach “posed a risk for the entire customer base,” a district court in Bonn decided upon review that the GDPR fine was too high due to the limited amount of information that an unauthorized party could potentially obtain.



(Related) Another GDPR loophole?

https://www.huntonprivacyblog.com/2020/12/01/dutch-court-overturns-dpa-fine-on-legitimate-interest-legal-basis/

Dutch Court Overturns DPA Fine on Legitimate Interest Legal Basis

… According to the Dutch DPA, purely commercial interests do not constitute a legitimate interest that can serve as a legal basis for data processing activities under the GDPR.

In overturning the Dutch DPA’s decision, the court relied on guidance issued by the European Data Protection Board (the “EDPB”), which provides that legitimate interests can cover a range of different interests, provided that they are real and present (not speculative), meaning that all kinds of factual, economic and idealistic interests can qualify as legitimate interests.





A big market for surveillance?

https://www.bespacific.com/amazon-announces-new-employee-tracking-tech-and-customers-are-lining-up/

Mashable: “.Amazon-powered employee tracking is coming to a warehouse, and possibly a store, near you. The ecommerce, logistics, and (among other things) cloud computing giant quietly previewed Tuesday new hardware and software development kits (SDK) which add machine learning and computer vision capabilities to companies’ existing surveillance camera networks. And in what should come as no surprise as companies around the world ramp up employee monitoring, customers are already champing at the bit to sic Amazon’s tech on their own workers. Amazon, of course, is notorious for monitoring its fulfillment center workers’ movements in excruciating detail. From social-distance tracking systems to automatic tools that keep tabs on “the rates of each individual associate’s productivity,” Amazon has a well deserved reputation for invasiveness. AWS Panorama, shown off at the AWS re:Invent conference, offers some version of that future to companies willing to cough up the cash. And while Amazon partially advertises the new system as allowing “you to monitor workplace safety,” corporate customers clearly have a different purpose in mind.



(Related) Does this move strip out all value from Productivity Score?

https://www.makeuseof.com/microsoft-productivity-score-scaled-back/

Microsoft Scales Back the Privacy-Invading Productivity Score

Microsoft recently released a new tool called "Productivity Score" that allowed employers to check on how productive their workers are, but it quickly drew the ire of privacy advocates all over the world. In response, the software giant is making adjustments to the service to make it less intrusive.

… Microsoft has now made a post on Microsoft 365 tackling the controversy. First, the company is reshaping Productivity Score so that it removes all identifying information from workers. Employers can only use the data to see how their company as a whole is doing, and cannot use the tool to pry into what an individual is up to.

Second, Microsoft is refining the UI so that it presents the Productivity Score as a means of measuring how a business is adopting modern technology. It will no longer give the impression that it's meant to stalk individual workers. [Was that ‘impression’ deliberate? Bob]





Not sure about the witchcraft bit, but cheating sounds like a good idea.

https://www.bespacific.com/legal-research-no-longer-limited-to-keywords/

Legal research no longer limited to keywords

Tom Goldstein – SCOTUS Blog – “Longtime readers of SCOTUSblog are by now familiar with Casetext’s legal search tool. It solves an ever-present need for our team: finding opinions from all levels of the court system for our articles and case pages. Practitioners who read this blog, on the other hand, face a different need in their day-to-day work with the law. Rather than searching cases by name, attorneys need a way to search case law to find support for specific propositions. This task is challenging not just because the common law is vast, but because judges will use different articulations for the same proposition or principle. Casetext addresses this formidable challenge head on with their new tool: Parallel Search. As opposed to simple keyword search, the limitations of which most of us are intimately familiar with, Parallel Search uses machine learning technology to match full phrases and sentences with those with similar meanings in case law, even if the results and query have almost no words in common. It’s so powerful that users have described the technology as “straight up witchcraft” and “almost … like cheating” (though it certainly isn’t)…”





A few years ago, this would have been headline news. Now only a few of us scifi geeks even notice it.

https://www.technologyreview.com/2020/12/01/1012793/chinas-change-5-mission-has-successfully-landed-on-the-moon/

China’s Chang’e 5 mission has successfully landed on the moon

The lander is expected to begin drilling operations very soon for lunar material that it will bring back to Earth



Monday, November 30, 2020

A summary for my Computer Security students.

https://www.csoonline.com/article/3598292/the-sarbanes-oxley-act-explained-definition-purpose-and-provisions.html#tk.rss_all

The Sarbanes-Oxley Act explained: Definition, purpose, and provisions

This post-Enron law that aimed to protect investors by preventing fraudulent accounting and financial practices has major implications for data retention and security.





Not uniquely on the technology track. The article recommends some steps…

https://sloanreview.mit.edu/article/why-chief-data-officers-must-assume-leadership-for-data-success/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+mitsmr+%28MIT+Sloan+Management+Review%29

Why Chief Data Officers Must Assume Leadership for Data Success

… The rise of the CDO as a corporate risk function happened in step with the emergence of big data in the early 2010s. Although a few intrepid organizations had designated executives to function as CDOs earlier, a new combination of defensive drivers (compliance, risk mitigation) and offensive drivers (revenue generation, business growth), based on the promise of big data, resulted in a sudden and dramatic increase in chief data officer appointments. The percentage of major companies with a CDO rose from 12% in 2012 to a peak of 67.9% by 2019, according to an annual executive survey by NewVantage Partners.





Excommunicado is not the only solution possible, just the simplest to implement.

https://www.theverge.com/2020/11/25/21664951/facebook-ban-stolen-artifacts-aids-criminal-organizations?scrolla=5eb6d68b7fedc32c19ef33b4

Facebook is deleting evidence of war crimes, researchers say

The black market for looted goods is flourishing on Facebook. While the company banned the sale of historical artifacts in June, many of the posts are in Arabic, and Facebook lacks the expertise to properly enforce its new policy.

When Facebook is able to identify groups that flout its guidelines, experts say the company simply deletes them, expunging crucial documentation for researchers studying stolen art. “This is critical evidence for repatriation efforts and war crimes,” says Katie Paul, co-director of the Athar Project. “Facebook has created a problem and rather than turning that into something they could contribute to, they are making it worse.”





Useful for non-lawyers as well?

https://www.bespacific.com/how-to-teach-algorithms-to-legal-research-students/

How to Teach Algorithms to Legal Research Students

Hickman, Annalee, How to Teach Algorithms to Legal Research Students (September 1, 2020). 28 Perspectives: Teaching Legal Research & Writing (forthcoming 2021), BYU Law Research Paper No. 20-30, Available at SSRN: https://ssrn.com/abstract=3731127

“This Article calls for legal research professors to include in their curriculum the role of algorithms in electronic legal research. It also includes recommendations for readings, lecture content, and assignments when teaching about algorithms.”





In case you missed it.

https://www.bespacific.com/2020-in-review-legal-software-for-working-remotely/

2020 in review: Legal software for working remotely

Via LLRX – 2020 in review: Legal software for working remotely – Attorney and legal technology expert Nicole L. Black has written throughout 2020 about cloud-based legal technology tools and their relevance to legal practices. Whether your law firm has already begun the shift to a cloud-based law practice or is planning to do so in the new year, you’ll undoubtedly find some or all of the software Black has covered over the past year to be useful. This article is a timely and actionable roundup of all of her articles on this topic from 2020.





Lots of end-to-end encryption – sorry FBI.

https://www.makeuseof.com/best-free-open-source-apps-iphone/

The 12 Best Free and Open Source Apps for iPhone

Even on Apple's closed-source iOS, you can enjoy these excellent open source apps for privacy, security, and productivity.



Sunday, November 29, 2020

Something interesting for my students to debate.

https://venturebeat.com/2020/11/28/ethical-ai-isnt-the-same-as-trustworthy-ai-and-that-matters/

Ethical AI isn’t the same as trustworthy AI, and that matters

… In lockstep with ethics comes the topic of trust. Ethics are the guiding rules for the decisions we make and actions we take. These rules of conduct reflect our core beliefs about what is right and fair. Trust, on the other hand, reflects our belief that another person — or company — is reliable, has integrity and will behave in the manner we expect. Ethics and trust are discrete, but often mutually reinforcing, concepts.

… Certainly, unethical systems create mistrust. It does not follow, however, that an ethical system will be categorically trusted. To further complicate things, not trusting a system doesn’t mean it won’t get used.





How to be ethical.

https://link.springer.com/chapter/10.1007/978-3-030-64148-1_21

Ethical Guidelines for Solving Ethical Issues and Developing AI Systems

Artificial intelligence (AI) has become a fast-growing trend. Increasingly, organizations are interested in developing AI systems, but many of them have realized that the use of AI technologies can raise ethical questions. The goal of this study was to analyze what kind of ethical guidelines companies have for solving potential ethical issues of AI and developing AI systems. This paper presents the results of the case study conducted in three companies. The ethical guidelines defined by the case companies focused on solving potential ethical issues, such as accountability, explainability, fairness, privacy, and transparency. To analyze different viewpoints on critical ethical issues, two of the companies recommended using multi-disciplinary development teams. The companies also considered defining the purposes of their AI systems and analyzing their impacts to be important practices. Based on the results of the study, we suggest that organizations develop and use ethical guidelines to prioritize critical quality requirements of AI. The results also indicate that transparency, explainability, fairness, and privacy can be critical quality requirements of AI systems.



(Related)

https://www.semanticscholar.org/paper/AI-virtues-The-missing-link-in-putting-AI-ethics-Hagendorff/a8164e364a5162eda6f6396d0e15f2001f617ff1

AI virtues -- The missing link in putting AI ethics into practice

Several seminal ethics initiatives have stipulated sets of principles and standards for good technology development in the AI sector. However, widespread criticism has pointed out a lack of practical realization of these principles. Following that, AI ethics underwent a practical turn, but without deviating from the principled approach and the many shortcomings associated with it. This paper proposes a different approach. It defines four basic AI virtues, namely justice, honesty, responsibility and care, all of which represent specific motivational settings that constitute the very precondition for ethical decision making in the AI field. Moreover, it defines two second-order AI virtues, prudence and fortitude, that bolster achieving the basic virtues by helping with overcoming bounded ethicality or the many hidden psychological forces that impair ethical decision making and that are hitherto completely disregarded in AI ethics. Lastly, the paper describes measures for successfully cultivating the mentioned virtues in organizations dealing with AI research and development.





My AI would rather not deal with mere humans.

https://www.cigionline.org/sites/default/files/documents/Modern%20Conflict%20and%20AI_web.pdf#page=52

Artificial Intelligence and Keeping Humans “in the Loop”

Artificial intelligence (AI) technology has evolved through a number of developmental phases, from its beginnings in the 1950s to modern machine learning, expert systems and “neural networks” that mimic the structure of biological brains. AI now exceeds our performance in many activities once held to be too complex for any machine to master, such as the game Go and game shows. Nonetheless, human intellect still outperforms AI on many simple tasks, given AI’s present inability to recognize more than schematic patterns in images and data. As AI evolves, the pivotal question will be to what degree AI systems should be granted autonomy, to take advantage of this power and precision, or remain subordinate to human scrutiny and supervision, to guard against unexpected failure. That is to say, as we anticipate technological advances in AI, to what degree must humans remain “in the loop”?





We need legal geeks?

https://osf.io/preprints/lawarxiv/zfkr3/

Education for the Provision of Technologically Enhanced Legal Services

Legal professionals increasingly rely on digital technologies when they provide legal services. The most advanced technologies such as artificial intelligence (AI) promise great advancements of legal services, but lawyers are traditionally not educated in the field of digital technology and thus cannot fully unlock the potential of such technologies in their practice. In this paper, we identify five distinct skills and knowledge gaps that prevent lawyers from implementing AI and digital technology in the provision of legal services and suggest concrete models for education and training in this area. Our findings and recommendations are based on a series of semi-structured interviews, design and delivery of an experimental course in ‘Law and Computer Science’, and an analysis of the empirical data in view of wider debates in the literature concerning legal education and 21st century skills.





Perspective.

https://eurasiantimes.com/us-lags-behind-both-russia-and-china-in-these-critical-domains-that-will-define-the-future-of-war/

US Lags Behind Both Russia & China In These Critical Domains That Will Define The Future of War

In its “2020 Military Power Report”, the Pentagon acknowledges that the US is falling behind China in key military innovations. The report says that China’s strategy is to complete the military modernization program by 2035 and transform the PLA into a “world-class” military by the end of 2049.

… Both Russia and China have surpassed the US in many critical military technologies, which have been widely acknowledged by military analysts as indications of the beginning of the end of the United States as the only dominant power.

… The three areas in which the US is being surpassed by the two superpowers are:

Hypersonic Weapons

Artificial Intelligence

Blockchain in Military





A strange conundrum: We rely on psychologists who can not predict suicide to train a machine that can?

https://www.nytimes.com/2020/11/23/health/artificial-intelligence-veterans-suicide.html

Can an Algorithm Prevent Suicide?

… “The fact is, we can’t rely on trained medical experts to identify people who are truly at high risk,” said Dr. Marianne S. Goodman, a psychiatrist at the Veterans Integrated Service Network in the Bronx, and a clinical professor of medicine at the Icahn School of Medicine at Mount Sinai. “We’re no good at it.”



Saturday, November 28, 2020

You have entire countries trying to hack you. You must be really really important!

https://www.cpomagazine.com/cyber-security/85-of-cyber-espionage-is-state-affiliated-only-4-tied-to-organized-crime/

85% of Cyber Espionage Is State-Affiliated, Only 4% Tied To Organized Crime

Verizon’s 2020 Cyber Espionage Report, the result of a total of 14 years of research into global data breaches and threat actor activity, has come up with some illuminating observations about long-term patterns of cyber spying. Among the major highlights are that criminal organizations and disgruntled former employees play a trivial role in overall attempts, that the public sector is the preferred target of attackers and that desktops and laptops are far more likely to be breached than phones.

[The report: https://www.verizon.com/business/resources/reports/cyber-espionage-report/





I wonder who signs off on products like these? No one saw this coming?

https://www.pogowasright.org/amazon-faces-a-privacy-backlash-for-its-sidewalk-feature-which-turns-alexa-devices-into-neighborhood-wifi-networks-that-owners-have-to-opt-out-of/

Amazon faces a privacy backlash for its Sidewalk feature, which turns Alexa devices into neighborhood WiFi networks that owners have to opt out of

Kevin Shalvey reports:

Amazon customers are being automatically opted in to Sidewalk, a feature set to launch later this year that the company says will connect Alexa devices to nearby WiFi networks, even those owned by someone else.
[…]
Anticipating privacy concerns, Amazon published a research paper detailing the technology behind Sidewalk and the steps taken to keep users’ data private. The company concluded that privacy was one of the “foundational principals” of Sidewalk’s design.
“By sharing a small portion of their home network bandwidth, neighbors give a little – but get a lot in return,” the report’s authors said.

Read more on BusinessInsider.



(Related) I guess Amazon didn’t notice articles like this one.

https://www.wsj.com/articles/next-step-in-government-data-tracking-is-the-internet-of-things-11606478401?mod=djemalertNEWS

Next Step in Government Data Tracking Is the Internet of Things

U. S. government agencies from the military to law enforcement have been buying up mobile-phone data from the private sector to use in gathering intelligence, monitoring adversaries and apprehending criminals.

Now, the U.S. Air Force is experimenting with the next step.

The Air Force Research Laboratory is testing a commercial software platform that taps mobile phones as a window onto usage of hundreds of millions of computers, routers, fitness trackers, modern automobiles and other networked devices, known collectively as the “Internet of Things.”





Year end summaries…

https://venturebeat.com/2020/11/27/ai-weekly-the-state-of-machine-learning-in-2020/

AI Weekly: The state of machine learning in 2020

… The AI Index is due out in the coming weeks, as is CB Insights’ assessment of global AI startup activity, but two reports — both called The State of AI — have already been released.

Last week, McKinsey released its global survey on the state of AI, a report now in its third year. Interviews with executives and a survey of business respondents found a potential widening of the gap between businesses that apply AI and those that do not.

… A month before McKinsey published its business survey, Air Street Capital released its State of AI report, which is now in its third year. The London-based venture capital firm found the AI industry to be strong when it comes to company funding rounds, but its report calls centralization of AI talent and compute “a huge problem.” Other serious problems Air Street Capital identified include ongoing brain drain from academia to industry and issues with reproducibility of models created by private companies.





Worth a listen?

https://www.prnewswire.com/news-releases/future-talks-powered-by-mvm-neil-degrasse-tyson-leads-a-supergroup-of-experts-on-ai-on-30-november-301181205.html

Future Talks Powered by MVM: Neil deGrasse Tyson Leads a Supergroup of Experts on AI on 30 November

… The online talk show is free of charge and accessible for all on the organizer MVM Group's (the largest Hungarian energy company's) Facebook and YouTube channels, as well as the 'Future Talks powered by MVM' website on 30 November, at 12:00 p.m. New York and 9:00 a.m. Los Angeles.

Further information: www.mvmfuturetalks.com

Facebook event: https://www.facebook.com/events/398239114862049/

LinkedIn event: https://www.linkedin.com/events/6732691494861340672/

Promo video of the event: https://www.youtube.com/watch?v=-yWRXuSXWmk&feature=youtu.be





This is cool. Going the other way will be much more difficult.

https://www.newscientist.com/article/2261113-ai-can-turn-spoken-language-into-photorealistic-sign-language-videos/

AI can turn spoken language into photorealistic sign language videos





A freebie for your virtual bookshelf. (Which I recommend you keep on Calibre https://calibre-ebook.com/ )

https://www.makeuseof.com/office-365-all-in-one-dummies-ebook/

Download a FREE Copy of Office 365 All-in-One for Dummies

… Whether you're a beginner or an experienced user, this ebook has a lot to offer, from advice and how-tos, to shortcuts, and little-known tips.

Interested? Simply click here to download this free ebook (worth $24) from TradePub. You will have to complete a short form to access the ebook, but it’s well worth it!

Note: This free offer expires on December 2, 2020.





Running out of things to read? From classics to pulp.

https://www.makeuseof.com/little-known-places-to-download-free-ebooks/

6 Little Known Places to Download Unique Free Ebooks



Friday, November 27, 2020

Solid suggestions.

https://www.techrepublic.com/article/7-big-data-goals-for-2021-ai-devops-hybrid-cloud-and-more/

7 big data goals for 2021: AI, DevOps, hybrid cloud, and more

In 2021, corporate big data leaders will be looking to improve data quality and turnaround of big data projects, as well as performance in meeting business objectives. While 2020 hasn't been a normal year for anyone, you still have to plan for the future and get ready for what may come.

Here are seven key areas of focus for 2021.





This should be interesting to watch. Will it catch on with other countries? Will it work?

https://www.cnbc.com/2020/11/26/google-and-facebook-to-be-scrutinized-by-new-uk-unit-from-next-year.html

Google and Facebook to be scrutinized by new U.K. antitrust unit from next year

The Department for Digital, Culture, Media and Sport said it plans to create a Digital Markets Unit (DMU) to enforce “a new code to govern the behavior of platforms that currently dominate the market, such as Google and Facebook.”

The code is designed to ensure that consumers, small businesses, and news publishers aren’t disadvantaged by actions taken by tech giants, the government said.

Under the new code, some of the world’s biggest tech companies may have to be more transparent about the services they provide and how they use consumers’ data. They may also be forced to give consumers a choice over whether to receive personalized advertising, and they won’t be able to place restrictions on customers that make it difficult for them to use rival platforms.

The DMU, which will be part of the Competition and Markets Authority (CMA), will start work in April 2021.

The government said the DMU may be given the unit the power to suspend, block and reverse decisions made by large tech companies. The DMU could also order them to take certain actions to achieve compliance with the code, and impose financial penalties for non-compliance, the government said.





Darker predictions.

https://www.fastcompany.com/90488665/the-coronavirus-butterfly-effect-six-predictions-for-a-new-world-order

The coronavirus butterfly effect: Six predictions for a new world order

The world may soon pass “peak virus.” But true recovery will take years—and the ripple effects will be seismic. Parag Khanna and Karan Khemka forecast the aftershocks.





Perspective.

https://www.nytimes.com/2020/11/27/technology/pushed-by-pandemic-amazon-goes-on-a-hiring-spree-without-equal.html

Pushed by Pandemic, Amazon Goes on a Hiring Spree Without Equal

The company has added 427,300 employees in 10 months, bringing its global work force to more than 1.2 million.





‘cause I needs me some grammar.

https://www.makeuseof.com/best-grammar-punctuation-sites/

The 7 Best Grammar and Punctuation Sites



Thursday, November 26, 2020

I wonder if their lawyers warned them in time to avoid this? Where was the ball dropped?

https://www.bloomberg.com/news/articles/2020-11-25/millions-of-facebook-users-pass-on-650-million-privacy-jackpot

Millions of Facebook Users Pass on $650 Million Privacy Jackpot

Facebook Inc. will be making payouts to only about a quarter of the 6 million Illinois residents eligible for the biggest consumer privacy settlement in U.S. history.

Based on a tally filed in court after Monday’s claims deadline, some 1.57 million people will probably pocket more than $300 each – after about a third of the $650 million settlement fund is set aside for their attorneys and administrative costs – from a lawsuit in which the social network was accused of collecting biometric images from its photo-tagging feature without consent.

As class actions go, with nickel-and-dime payouts often not worth the effort of filing a claim, a case that ends up with a 25% buy-in from consumers is a success story. Frequently, fewer than 10% of eligible people file claims.





A summary for my Computer Security students.

https://www.law.com/thelegalintelligencer/2020/11/25/data-breach-cases-an-analysis-of-standing-and-best-causes-of-action/

Data Breach Cases: An Analysis of Standing and Best Causes of Action

Despite the rules and security measures that many organizations put in place to protect the personal information of their clients or customers, sensitive information may still fall prey to hackers and other kinds of breaches. Those affected may seek counsel to aid in bringing suit to hold an entity liable for its intermediary role when a third party commits a data breach.. While data breaches have become too common, case law and statutory law governing redress for data breaches is limited. This column explores standing and potential causes of action in data breach suits.





At least an occasional (annual?) review by someone who did not do the original setup?

https://www.databreaches.net/fairchild-medical-center-server-was-exposing-patient-information-for-4-5-years-until-a-security-firm-alerted-them/

Fairchild Medical Center server was exposing patient information for 4.5 years until a security firm alerted them

Ugh. Fairchild Medical Center had a misconfigured server exposing PHI from December 16, 2015 until they were alerted to the problem in late July by an unnamed security company who discovered the exposure.

Here’s their press release, below.





Could we do this in the US? (Aren’t we doing it already?)

https://thenextweb.com/readme/2020/11/26/how-to-build-a-search-engine-for-criminal-data/

How to build a search engine for criminal data

Whether it’s a WhatsApp message arranging the distribution of cocaine from São Paulo to Amsterdam or other encrypted conversations to lure the enemy into a deadly ambush; criminals have long tried to keep their digital footprints hidden.

The evidence of crime is all stored in the digital archive: emails, photos, and cloud storage data. Law enforcement agencies can use these digital clues to find out where criminals have been, and what they’re currently doing.

Data analysis platforms are becoming increasingly crucial in the fight against crime. We spoke with two forensic software experts from Hansken about how they support law enforcement agencies, like the Dutch National Police and the Dutch Fiscal Information and Investigation Service.





An interesting ‘what,’ but the question is ‘who?’ Can an internal review be trusted?

https://www.mclane.com/assets/docs/Weaver_-_Assessment_of_Artificial_Intelligence_Systems.pdf

Everything Is Not Terminator

Many information security and privacy laws such as the California Consumer Privacy Act1 and the New York Stop Hacks and Improve Electronic Data Security Act2 require periodic assessments of an organization’s information management systems. Because many organizations collect, use, and store personal information from individuals—much of which could be used to embarrass or impersonate those individuals if inappropriately accessed—these laws require organizations to regularly test and improve the security they use to protect that information.

As of yet, there is no similar specific law in the United States directed at artificial intelligence systems (“AIS”), requiring the organizations that rely on AIS to test its accuracy, fairness, bias, discrimination, privacy, and security.

However, existing law is broad enough to impose on many organizations a general obligation to assess their AIS, and legislation has appeared requiring certain entities to conduct impact assessments on their AIS. Even without a regulatory mandate, many organizations should perform AIS assessments as a best practice.

This column summarizes current and pending legal requirements before providing more details about the assessment process.





High probability, even with Presidential distractions?

https://www.insideprivacy.com/internet-of-things/iot-update-congress-passes-iot-cybersecurity-improvement-act-of-2020/

IoT Update: Congress Passes IoT Cybersecurity Improvement Act of 2020

The bipartisan Internet of Things (“IoT”) Cybersecurity Improvement Act of 2020 (S. 734, H.R. 1668 ) has passed the House and the Senate and is headed to the President’s desk for signature. The bill was sponsored in the House by Representatives Hurd (R-TX) and Kelly (D-IL), and in the Senate by Senators Warner (D-VA) and Gardner (R-CO). President Trump is expected to sign the measure into law.





Perspective. Brick and mortar stores don’t own all the brick an mortar. Apparently you need a lot of room to store all that virtual…

https://www.wsj.com/articles/stock-market-titans-amazon-google-and-facebook-are-also-driving-commercial-real-estate-11606213801?mod=djemalertNEWS

Stock-Market Titans Amazon, Google and Facebook Are Also Driving Commercial Real Estate

The biggest U.S. tech companies are providing a jolt to the slumbering commercial real-estate business, emerging as major tenants and acquirers of office and other space while many nontech firms are trying to tear up their leases.

Five of the biggest property owners in the tech industry— Amazon.com Inc., Facebook Inc., Apple Inc., Google parent Alphabet Inc. and Microsoft Corp. —together occupy around 589 million square feet of U.S. real estate, according to CoStar Group. That is more than all of the office space in New York City, or the equivalent to about 220 Empire State Buildings. It marks a fivefold increase from a decade ago.