Wednesday, November 30, 2016

I assume that anyone signing up for a porn site uses a phony name, or perhaps the name of some randomly selected lawyer at the local law school.  (I propose “phack” rather than “fhack”)
Hackers Are Trading Hundreds of Thousands of xHamster Porn Account Details
   Although xHamster is a free porn site, users can sign up to create personal favorite collections, post comments, or upload their own videos.  According to the xHamster site, over 12 million people have signed up for an account.
   Update: After the publication of this article, Alex Hawkins, xHamster spokesperson, told Motherboard in an email, "The only way to respond to this news is to coin a new term: 'Fhack.'  A fhack is best defined as a fake hack.  There was a failed attempt to hack our database which occurred 4 years ago.  The integrity of our user data is secure.  Passwords are encrypted and impossible to hack. In short, this was a successful fhack; and a failed hack."
When pressed on how did data traders then obtain a list of xHamster user email addresses, the company said, "We cannot validate that the emails are real and we don't believe that this is a genuine database."  This is despite Motherboard's independent verification of the email addresses and usernames.


For my Ethical Hacking students.
How Machine Learning Will Help Attackers
Inside McAfee Labs' predictions (PDF) for 2017 is this: criminals will use machine learning to analyze massive quantities of stolen records to identify potential victims and build contextually detailed emails that very effectively target these individuals.  In short, just as defenders use machine learning to detect attacks, attackers will use machine learning to automate attacks and evade detection.

(Related) From the same report.
'Dronejacking' May be the Next Big Cyber Threat
A report by Intel's McAfee Labs said hackers are expected to start targeting drones used for deliveries, law enforcement or camera crews, in addition to hobbyists.
"Drones are well on the way to becoming a major tool for shippers, law enforcement agencies, photographers, farmers, the news media, and more," said Intel Security's Bruce Snell, in the company's annual threat report.


I didn’t know the Hillary Clinton worked for Europol.
Toby Sterling reports:
Information on numerous international investigations into terrorism groups compiled by Europol was accidentally left online, unguarded by any password, a Dutch television program reported on Wednesday.
Europol, which helps European Union national police organizations cooperate, could not immediately be reached for comment.  The television program Zembla cited the Europol’s adjunct director Wil van Gemert as acknowledging the incident.
According the program, the leak was caused by a former employee who took dossiers home, against Europol policy, and put them on a hard drive connected to the Internet without realizing it was accessible to anyone.
Read more on Reuters.


Gathering stuff for my Computer Security class.  Might also work this into my Statistics class. 
Measuring what matters in cybersecurity
The cybersecurity risk metrics market has exploded, and at least half a dozen companies are offering real time risk metrics for enterprises.  Insurance carriers will collect upwards of $3 billion in premiums this year.  In my recent analysis of this $20 billion market,  it was evident that the rise of adversaries, boardroom pressures and financial losses are driving a whole new world of underwriters, brokers and consultants.  CISOs are now supposed to answer to the C level and the boardroom, somewhat challenging questions like:
  • Are we secure? If so, just how secure are we?
  • Could what happened to company xyz happen to us? Are we getting better over time?
  • JP Morgan Chase just announced they will deploy $250 million in security. Are we spending enough? Should we spend more?
   Richard Seiersen, vice president of Trust and CISO at Twilio, wants to simplify this debate.  A soft spoken classically trained guitarist and co-author of the recently published book - “How to measure anything in Cybersecurity”, Selersen advocates risk management using probabilistic thinking and probabilistic programming.


Is this the kind of backlash we should expect whenever robots start “taking the jobs of the common man?”
New York Bars Scalpers From Using Bots To Snap Up Tickets Before Everyone Else
   New York’s Governor Andrew Cuomo signed a law that makes using so-called “ticket bots” — software designed to manipulate systems that are designed to limit the numbers of tickets sold to an individual — illegal.
Previously, NY law barred the use of ticket bots, but only imposed civil sanctions for brokers who violate that law.  Now, using ticket bots, maintaining an interest in or control of bots, and reselling tickets knowingly obtained with bots constitutes a class A misdemeanor.  As such, violators could face substantial fines and imprisonment.

(Related) Perspective.  Would this be possible without automation?
   This week TorrentFreak crunched the numbers in Google’s Transparency Report and found that over the past 12 months Google has been asked to remove over a billion links to allegedly infringing pages, 1,007,741,143 to be precise.
More than 90 percent of the links, 908,237,861 were in fact removed.  The rest of the reported links were rejected because they were invalid, not infringing, or duplicates of earlier requests.


Now this is automation to be worried about.  I wonder who can override the score?
China Turns Big Data into Big Brother
   The Wall Street Journal reports that the Chinese government is now testing systems that will be used to create digital records of citizens’ social and financial behavior.  In turn, these will be used to create a so-called social credit score, which will determine whether individuals have access to services, from travel and education to loans and insurance cover.  Some citizens—such as lawyers and journalists—will be more closely monitored.


The French still think the world revolves around them.
We Won’t Let You Forget It: Why We Oppose French Attempts to Export the Right To Be Forgotten Worldwide
   The brief, filed Nov. 23, 2016, argues that extending European delisting requirements to the global Internet inherently clashes with other countries’ laws and fundamental rights, including the First Amendment in the U.S.
   For an in depth analysis, read our legal background document.


Last chance before Trump trumps their urge?
Ed Pilkington reports:
The campaign to persuade Barack Obama to allow the NSA whistleblower Edward Snowden to return home to the US without facing prolonged prison time has received powerful new backing from some of the most experienced intelligence experts in the country.
Fifteen former staff members of the Church committee, the 1970s congressional investigation into illegal activity by the CIA and other intelligence agencies, have written jointly to Obama calling on him to end Snowden’s “untenable exile in Russia, which benefits nobody”.  Over eight pages of tightly worded argument, they remind the president of the positive debate that Snowden’s disclosures sparked – prompting one of the few examples of truly bipartisan legislative change in recent years.
Read more on The Guardian.


For my Governance and Architecture classes.  Politicians don’t seem to get the concept of global companies. 
Sanders launches new attack on offshore outsourcing
Former presidential candidate and U.S. Sen. Bernie Sanders will introduce legislation to discourage companies from relocating jobs offshore.  The legislation would punish offshore decisions with loss of tax breaks and government contracts and impose an "outsourcing tax" on firms that proceed nonetheless.


Something to play with?
UK's GCHQ Spy Agency Launches Open Source Data Analysis Tool
The U.K. Government Communications Headquarters (GCHQ) on Monday announced the launch of a new open source web tool designed for analyzing and decoding data.
Named CyberChef, the tool is advertised by the intelligence agency as a “Cyber Swiss Army Knife.”  It uses a simple interface with a drag-and-drop feature to allow both technical and non-technical people to analyze encryption, compression and decompression, and data formats.
   Users can, for example, convert data from a hexdump, display timestamps as a full date, decode Base64 strings, parse Teredo IPv6 addresses, and manipulate different types of data.
   The source code and a demo have been made available on GitHub.  The agency pointed out that the tool is not complete and has encouraged developers to contribute as much as possible.


What we could do if we chose to…
Altice Plans Fiber Upgrade That Could Leave Rivals in the Dust
Altice USA, the fourth largest U.S. cable operator, said it plans to convert its entire network into an ultrafast fiber-to-the-home network capable of 10 gigabits-per-second speeds within the next five years, a bold plan that takes aim at the company’s fierce rival, Verizon Communications Inc.’s Fios.


Is this really how my students react to my research projects?

Tuesday, November 29, 2016

The best laid hacks o' mice an' men / Gang aft a-gley.”  Robert Burns
Deutsche Telekom outage seen as part of broader internet attack
An attempt to hijack consumer router devices for a wider internet attack caused network outages that hit hundreds of thousands of Deutsche Telekom customers in Germany, a company executive said.
   The outages appeared to be tied to a botched attempt to commandeer customers' routers to disrupt internet traffic, according to Deutsche Telekom's head of IT security and the German Office for Information Security (BSI).
The BSI said the attack had also targeted the German government's network but had failed because defensive measures had proved effective.
   The attack involved Mirai, malicious software designed to turn network devices into remotely controlled "bots" that can be used to mount large-scale network attacks.


Apparently they monitor their systems well enough to know how this happened and what was accessed.  Impressive!  
Steve Ragan reports:
The person claiming responsibility for the attack on San Francisco’s MUNI says the SFMTA has lax security, and warns that if the ransom isn’t paid, they’ll release 30GB of compromised data.
The demands follow a weekend of headaches for SFMTA, after MUNI was targeted shortly before the Thanksgiving holiday, resulting in systems that were encrypted and held for a $73,000 ransom.
On Sunday, Salted Hash revealed that 2,112 MUNI systems were infected with hard drive encrypting malware.
Read more on Salted Hash.
Note that Threatpost was able to subsequently obtain a statement from SF MUNI.  Tom Spring reports:
Paul Rose, a San Francisco Municipal Transportation Agency spokesperson told Threatpost in a statement that the attackers’ allegations are false and that no customer privacy or transaction information was compromised.  “We have never considered paying ransom and don’t intend to.  The attack did not penetrate our firewalls and we are able to restore systems through the work of internal staff,” Rose said.
Read more on Threatpost.

(Related)
San Francisco Rail System Hacker Hacked
   On Monday, KrebsOnSecurity was contacted by a security researcher who said he hacked this very same cryptom27@yandex.com inbox after reading a news article about the SFMTA incident.  The researcher, who has asked to remain anonymous, said he compromised the extortionist’s inbox by guessing the answer to his secret question, which then allowed him to reset the attacker’s email password.  A screen shot of the user profile page for cryptom27@yandex.com shows that it was tied to a backup email address, cryptom2016@yandex.com, which also was protected by the same secret question and answer.
   The server used to launch the Oracle vulnerability scans offers tantalizing clues about the geographic location of the attacker.  That server kept detailed logs about the date, time and Internet address of each login.  A review of the more than 300 Internet addresses used to administer the server revealed that it has been controlled almost exclusively from Internet addresses in Iran.  Another hosting account tied to this attacker says his contact number is +78234512271, which maps back to a mobile phone provider based in Russia.
But other details from the attack server indicate that the Russian phone number may be a red herring.


Interesting?
David A. Zetoony, Joshua A. James, Jena M. Valdetero, and Christopher M. Achatz of Bryan Cave provide an overview of significant differences between U.S. breach notification laws and the EU’s General Data Protection Regulation (“GDPR”). Here’s a snippet from their analysis:
That said, there are several significant differences including:
1.      Type of Information Governed.  Data breach notification laws in the United States apply only to enumerated types of data that are considered particularly sensitive such as Social Security Numbers, financial account numbers, or driver’s license numbers.  The GDPR’s breach notification provision applies to all types of “personal data” – a term that is defined as “any information relating to identified or identifiable natural person (data subject).”5
2.      Materiality Threshold For Government Notification.  Some breach notification laws in the United States only require notification if the breach is “material” (g., it compromises confidentiality, security, or privacy of an individual).  The GDPR’s breach notification provision requires notifying a government agency (i.e., relevant Data Protection Authority) unless the breach is not likely to result in a risk of the “rights” of individuals.6
Read more on Bryan Cave.


Fortunately, these cases will average only three minutes each under President Trump! 
Immigration Now 52 Percent of All Federal Criminal Prosecutions
by Sabrina I. Pacifici on Nov 28, 2016
Transactional Records Access Clearinghouse: “Immigration remains the major focus of all federal criminal enforcement efforts.  The latest available data show that criminal prosecutions for illegal entry, illegal re-entry, and similar immigration violations made up 52 percent of all federal prosecutions in FY 2016.  During the 12 months ending September 30, immigration prosecutions totaled 69,636.  This number compares with just 63,405 prosecutions for all other federal crimes — including drugs, weapons, fraud, and violations of the thousands of other criminal provisions that the federal government is responsible for enforcing
For additional details including figures for top ten districts and most common lead charges, see full report at: http://trac.syr.edu/tracreports/crim/446/”


Not sure I believe this one.  Perhaps my geeks can build a working model to test…
Anti-drone gun takes down targets from 1.2 miles away
There are numerous systems built to take down wayward or dangerous drones, but they tend to have one big catch: you need to be relatively close to the drone, which could be scary if the robotic aircraft is packing explosives.  DroneShield thinks it can help.  It's introducing the DroneGun, a jammer that disables drone signals (including GPS and GLONASS positioning) from as far as 1.2 miles away.  Like most rivals, it doesn't destroy the target drone -- it just forces the vehicle to land or return to its starting point.  Anti-drone teams can not only disable threats from a safe distance, but potentially locate their pilots.

Monday, November 28, 2016

Next: Hack an entire city!  
Alleged Muni ‘hacker’ demands $73,000 ransom, some computers in stations restored
Computer systems at San Francisco’s transit system, Muni, have been restored following a malware attack on Friday afternoon.
Payment systems across the agency’s subways read “OUT OF ORDER” in large red digital letters at Powell Station, Embarcadero Station and other stations across The City following the attack.
On Friday and Saturday, computers in station agents’ booths across the San Francisco Municipal Transportation Agency displayed “You Hacked, ALL Data Encrypted. Contact For Key(cryptom27@yandex.com)ID:681 ,Enter.”
   As of late Sunday, Muni drivers were assigned routes via handwritten notes posted to bulletin boards, as opposed to the usual computer printouts, which was verified by Muni operators on background.

(Related) Or an entire country?  Sounds like they have no idea what happened.
'Likely Hacker Attack' Hits Almost 1 Million German Homes
Around 900,000 customers using specific models of router have been affected since Sunday afternoon, the firm said, with some unable to connect at all while others suffered intermittent problems.
"We believe that influence was exerted on the routers from outside," a Telekom spokesman told AFP, saying software had been installed on the devices that prevented them from connecting to the company's network.
    Customers affected have been advised to disconnect their routers from the network since the problems began on Sunday afternoon.


Should we think of this as a “bad security tax?”
John Miller and Farah Master report:
Customers of a Chinese-owned Liechtenstein bank are being told by unknown blackmailers they must pay a portion of their savings or face having account details sent to finance authorities and the media, a German newspaper reported on Sunday.
Those targeted have accounts at Valartis Bank Liechtenstein, located in the tiny Alpine principality sandwiched between Austria and Switzerland, Bild am Sonntag reported.
[…]
The hackers are demanding 10 percent of the account balances, to be paid in Internet cryptocurrency Bitcoin to help preserve anonymity, Bild reported.
Read more on Reuters.


Perhaps, an introduction to social engineering?
A Website That Gives You Points as It Spies on You
Welcome to the strange, creepy world of clickclickclick.click.  (That’s a URL. Go ahead! Click!)
   Poke around for 30 seconds and the site seems silly.  Stay a little longer and the absurdity starts to mean something.  The site is showcase of the ways, big and small, your browser can be used to spy on you.  It turns the browser window into a circus ring, and asks you to perform flips to rack up meaningless points.  For the curious and obsessive (me), it’s impossible to click away.
   The site is part of a project called We Are Data,” and was co-produced by VPRO, a Dutch public broadcaster.  Moniker and VPRO started work on the site in earnest three months ago, and released it last week.  The stripped-down site has a homemade vibe to it; the haunting voice that accompanies you throughout is Wouters’s own.


Censorship, just a cost of doing business?
Microsoft's Chinese chatbot won't talk about Tiananmen Square or Donald Trump
The conversational two-year-old Chinese-speaking bot won't talk about certain controversial political topics, even refusing to talk to users if they persist in their attempts.
Alongside the iconic protests, Xiaoice also won't discuss US president-elect Donald Trump, Chinese president Xi Jinping, the Communist Party, and the Dalai Llama.
A Microsoft spokesperson confirmed to Business Insider that the bot censors certain subjects, saying in a statement: "We’re committed to creating the best experience for everyone chatting with Xiaoice.  With this in mind, we have implemented filtering on a range of topics."


For my Software Architecture students.
Long a Novelty, Gigantic Tablets Are Sneaking Into the Workplace
   The devices—anything bigger than 13 inches, the size of an iPad Pro—are interesting for several reasons.  First is the diversity of their uses, from the bowels of cruise ships to your local McDonald’s.  The second is that, unlike tablets and other mobile touch-screen devices, no one owns this category yet.
Third is the way these gigantopads allow people to interact with computers in new ways.  It’s the difference between watching a show on your mobile device and gathering the family around the TV.
   In a sense, these ginormablets combine four devices found in most office conference rooms: a whiteboard, a videoconferencing system, a projection system and the laptops people bring to meetings to take notes and manipulate shared documents.


Also for Software Architecture students.  Maybe you don’t know everything about a business…
   Last week, I spent a day in Detroit as part of a CEO Summit organized by Business Leaders for Michigan, an association of the state’s biggest companies.  The event’s kickoff speaker was Patrick Doyle, CEO of Domino’s Pizza, which is headquartered in nearby Ann Arbor.  I wasn’t sure what to expect, other than a riff on the company’s most popular toppings, but what I heard were riveting and compelling lessons about making radical, deep-seated change in a traditional, slow-to-change business.  Doyle’s talk was titled, “How to Transform a Legacy Company into a Technology-Enabled, Nimble, Category-Disrupting Machine” — and it delivered.
   How have Doyle and his colleagues unleashed so much change in such a short period of time?  First, by reminding themselves of the business they’re in. Domino’s is not just in the pizza-making business, the CEO emphasizes, but in the pizza-delivery business, which means it has to be in the technology business. “We are as much a tech company as we are a pizza company,” he told the audience, pointing out that of the 800 people working at headquarters, fully 400 work in software and analytics.  All that technology has changed how customers order (using the Domino’s app, or directly via twitter, or even by texting an emoji); how they monitor the status of their order; and how Domino’s manages its operations.


I’ve been teasing my students with questions like these.  No doubt MIT does it better.
Moral Machine
Recent scientific studies on machine ethics have raised awareness about the topic in the media and public discourse.  This website aims to take the discussion further, by providing a platform for 1) building a crowd-sourced picture of human opinion on how machines should make decisions when faced with moral dilemmas, and 2) crowd-sourcing assembly and discussion of potential scenarios of moral consequence.


You mean, they’re not all the same?
New on LLRX – Comparative Criminal Procedure: A Select Bibliography
by Sabrina I. Pacifici on Nov 27, 2016
Via LLRX.com – Comparative Criminal Procedure: A Select Bibliography – This expansive, comprehensive and up-to-date guide by Lyonette Louis-Jacques, Foreign and International Law Librarian and Lecturer in Law at the University of Chicago D’Angelo Law Library, references resources that include books, loose-leaf, online, database and e-government sites, services and resources.


Something for my starving students.


Something for may student vets in particular.
Call To Action App – Locate and contact your Congressional Rep
by Sabrina I. Pacifici on Nov 27, 2016
Calling the district office of your Congressional rep is the most effective way to get government to listen to you, according to political staffers.  Calls are taken more seriously and make a greater impact than emails or written letters.  Because your Congressional rep serves fewer constituents than a Senator, a call to your rep is more likely to be answered and carries more relative weight.”

Sunday, November 27, 2016

A guide for US Intelligence agencies?
Paul Bernal writes:
You might not have noticed thanks to world events, but the UK parliament recently approved the government’s so-called Snooper’s Charter and it will soon become law.  This nickname for the Investigatory Powers Bill is well earned.  It represents a new level and nature of surveillance that goes beyond anything previously set out in law in a democratic society.  It is not a modernisation of existing law, but something qualitatively different, something that intrudes upon every UK citizen’s life in a way that would even a decade ago have been inconceivable.
The bill requires internet and telecoms companies to keep records of every website or app we use and all our phone calls and messages for 12 months.  It leaves us in the unenviable position of leading the world in the legalisation of surveillance.  And it will likely be used by more authoritarian regimes around the globe as evidence that mass surveillance, online hacking and encryption backdoors are perfectly fine.
Read more on The Conversation.


It’s an easy way to gather information.
James Walker writes:
Concerns have been raised over the privacy afforded by caller ID apps such as Truecaller and CM Security.  The apps are storing the details of billions of people in publicly searchable databases.  People who have never used an app are also affected.
Three billion phone numbers and identities have been collected by the likes of Truecaller, Sync.ME and CM Security, according to a report by FactWire that was published in the Hong Kong Free Press earlier this week.
Read more on Digital Journal.  And if you missed it, I had reported earlier this week that the privacy commissioner of Hong Kong had followed up on the concerns.


Perspective.
Value of Payments Provider Stripe Doubles to $9.2 Billion
Stripe Inc., a start-up that offers software and services that process payments for businesses, has raised another round of private funding that values the company at just under $9.2 billion, according the company’s investors.
That valuation is nearly double what Stripe was worth nearly a year and a half ago.
   In addition to payments processing, Stripe offers a payment fraud prevention product and a tool kit called Stripe Atlas that allows entrepreneurs around the globe to register their new businesses as United States-based companies with a United States bank account, Stripe payments tools and basic legal, tax and computing services from the accounting firm PricewaterhouseCoopers, the law firm Orrick, Herrington & Sutcliffe and Amazon Web Services.  Atlas decreases the time it takes to set up a company from months to days.
   “Stripe’s momentum as the underlying platform for online commerce is just accelerating when you think about the fact that less than 10 percent or so of commerce is online today,” Mr. Taneja said.  

Saturday, November 26, 2016

Want to test drive a Tesla?
Researchers Hijack Tesla Car by Hacking Mobile App
In a video released this week, experts showed how they could obtain the targeted user’s credentials and leverage the information to track the vehicle and drive it away.  There are several conditions that need to be met for this attack and the victim must be tricked into installing a malicious app on their mobile phone, but the researchers believe their scenario is plausible.


Politics or mere amusement?
European Commission target of DDoS attack
by Sabrina I. Pacifici on Nov 25, 2016
Via Politico: “This afternoon, the European Commission was subject to a cyberattack (denial of service) which resulted in the saturation of our Internet connection.”


For my Governance and Software Architecture classes.
The Secret Ballot At Risk: Recommendations for Protecting Democracy
by Sabrina I. Pacifici on Nov 25, 2016
The right to cast a secret ballot in a public election is a core value in the United States’ system of self-governance.  Secrecy and privacy in elections guard against coercion and are essential to integrity in the electoral process.  Secrecy of the ballot is guaranteed in state constitutions and statutes nationwide.  However, as states permit the marking and transmitting of marked ballots over the Internet, the right to a secret ballot is eroded and the integrity of our elections is put at risk.  Thirty-two states and the District of Columbia allow some form of Internet voting–transmitting votes either via email, electronic fax, or Internet portal–typically for use by overseas and military voters.  Because of current technological limitations, and the unique challenges of running public elections, it is impossible to maintain separation of voters’ identities from their votes when Internet voting is used.  Most states that offer Internet voting recognize this limitation and require voters to sign a waiver of their right to a secret ballot.  The authors believe that Internet voting creates a second-class system for some voters–one in which their votes may not be private and their ballots may be altered without their knowledge.  This report examines state laws regarding the right to a secret ballot and the ways in which states are asking voters to waive that right.  We also offer recommendations for how voters and officials can preserve privacy in voting while making use of the Internet and technological advances.  Our findings show that the vast majority of states (44) have constitutional provisions guaranteeing secrecy in voting, while the remaining states have statutory provisions referencing secrecy in voting.  Despite that, 32 states allow some voters to transmit their ballots via the Internet which, given the limitations of current technology, eliminates the secrecy of the ballot.  Twenty-eight of these states require the voter to sign a waiver of his or her right to a secret ballot.  The remainder fail to acknowledge the issue…”


Worth a try, but I bet the courts won’t allow it.  
Wells Fargo Wants Claims Over Fake Accounts Decided Out of Court
Wells Fargo & Co. is trying to keep dozens of customers suing over bogus accounts opened by its employees out of court, saying they agreed to resolve any disputes in arbitration when they began doing business with the bank.
The lender also asked for the lawsuits, filed by 80 customers in federal court in Salt Lake City to be thrown out.

(Related) "It depends on what the meaning of the word 'is' is.”   
Uber seeks EC ruling that it is a digital service, not a transportation company
Uber will seek to convince Europe’s top court next week that it is a digital service, not a transport company, in a case that could determine whether app-based startups should be exempt from strict laws meant for regular companies.
The European Commission is trying to boost e-commerce, a sector where the EU lags behind Asia and the United States, to drive economic growth and create jobs.
The U.S. taxi app, which launched in Europe five years ago, has faced fierce opposition from regular taxi companies and some local authorities, who fear it creates unfair competition because it is not bound by strict local licensing and safety rules.


The downside of ‘really fast access to news!’ 
The CNN porn scare is how fake news spreads
Last night, a twitter account by the name of @solikearose tweeted out a surprising image of CNN broadcasting porn instead of Anthony Bourdain’s scheduled show Parts Unknown.  And then without really much questioning, a bunch of news sites ran with it, claiming that the network showed the footage for about 30 minutes.  
   It looks like the chaos all started when The Independent wrote up a story from this person’s tweets, which was then tweeted out by the Drudge Report.  After that, it spread fast.  Mashable, The New York Post, The Daily Mail, Esquire, and Variety have all published a story, and pretty much all of these articles are based on one or two tweets from @solikerose.  Plus, many of the original stories didn’t include statements from CNN or RCN, the cable company that supposedly aired the porn.
Fact-checking largely didn’t begin until the stories were published.

(Related) Did the Post get suckered too?  Surely not just bad reporting?
No, Russian Agents Are Not Behind Every Piece of Fake News You See
One of the themes that has emerged during the controversy over “fake news” and its role in the election of Donald Trump is the idea that Russian agents of various kinds helped hack the process by fueling this barrage of false news.  But is that really true?
In a recent story, the Washington Post says that this is definitely the case, based on information provided by two groups of what the paper calls “independent researchers.”  But the case starts to come apart at the seams the more you look at it.


A billion-dollar niche?  I wonder how many there are and how I could start my own. 
Amazon in Talks to Buy Dubai’s Souq.com in $1 Billion Deal
Amazon.com Inc. is in talks to acquire Dubai-based online retailer Souq.com FZ for about $1 billion in a deal that will give the e-commerce giant a footprint in the high-growth Middle East market, according to people familiar with the matter.


One of my students is building one of these for a demonstration in my January Computer Security class.  
$5 PoisonTap Tool Easily Breaks Into Locked PCs
Proving once again that you can do a lot of damage with a little investment and a lot of ingenuity, security researcher Samy Kamkar recently managed to take down a locked, password-protected computer armed with only a US$5 Raspberry Pi.
The low-tech cookie-siphoning intrusion is one of Kamkar's simplest hacks ever.  He previously has unlocked car doors, garages, wireless remote cameras and other devices, with MacGyver-like precision.


Trivia for my geeky students.


Will the TSA open a video feed at US airports?  


Update: I couldn’t find a link to the report the first time I posted about this study.
A Stanford University team won a lot of attention this week by releasing a study on how badly teenagers assess information online.  “Evaluating Information: The Cornerstone of Civic Online Reasoning” examined more than 7,000 students to check their information literacy skills.


My industry.
Hack Education Weekly News
[This blogger is not happy with anything Trump.  You can tell by the icon she uses for the ‘Trump news’ section.  Bob]
   “The United States Department of Education’s Office of Inspector General has found in a recent report that the department’s overall information technology security is ‘not generally effective’ in meeting several federal requirements,” Campus Technology reports.  “The ed department (ED) and its Federal Student Aid (FSA) office scored only 53 points out of 100 in a recent security audit.”
   “Attorneys for Gov. Rick Snyder and state education officials say no fundamental right to literacy exists for Detroit schoolchildren who are suing the state over the quality of their education,” The Detroit News reports.
   Via the Lansing State Journal: “An email sent to Michigan State University last weekend attempting to ‘extort money’ helped the university identify a data breach that affected about 400,000 records and included names, Social Security numbers and MSU identification numbers, a university spokesman said Friday evening.”
   Via EdWeek’s Market Brief: “Two recent reports that track K–12 spending reveal schools’ strong interest in purchasing security-related hardware, products, and technology.”  One of the most popular pieces of technology: gun detectors.  Yes, gun detectors are ed-tech.

Friday, November 25, 2016

Definitely one to grab if you run a home network!
This Web-based Tool Checks if Your Network Is Exposed to Mirai
   The IoT Defense scanner was written using a combination of Python, Node JS and Jade frameworks and scans for nearly a dozen ports that botnets can exploit.  Accessing and using the scanner is free and little instructions are needed, as it does all with a simple click of a button.


And Pew Research just told us that lots of youngsters can’t tell the difference.
Russian propaganda effort helped spread ‘fake news’ during election, experts say
The flood of “fake news” this election season got support from a sophisticated Russian propaganda campaign that created and spread misleading articles online with the goal of punishing Democrat Hillary Clinton, helping Republican Donald Trump and undermining faith in American democracy, say independent researchers who tracked the operation.


I bet their stick just went up!
Cyrus Farivar reports:
A federal appeals court ruled against a criminal defendant who challenged the warrantless use of a stingray that was used to locate him.
The Wednesday decision marks the first time that questions regarding the proper use of stingrays, also known as cell-site simulators, have reached the federal appellate level.
Read more on Ars Technica.


Significant?
Drew Crawford of King & Spalding writes:
On November 3, 2016, the State of Qatar announced the passage of a new national privacy law.  The law, which requires companies and organizations to protect the personal information they gather from individuals, is the first national-level legal regime governing data protection to be signed into law by a Gulf Cooperation Council (“GCC”) member state.
Read more on JDSupra.


No worries!  AI classes will now be taught by AI. 
Universities’ AI Talent Poached by Tech Giants
Alphabet Inc.’s Google division last week hired the director of Stanford University’s artificial intelligence lab to lead a new AI unit, the latest in a long line of academic stars in artificial intelligence lured away by tech giants.
Fei-Fei Li, a respected computer scientist, wrote in a Facebook post that she joined Google partly to “democratize AI.”  She joined several other top professors who have left academia in recent years for tech industry posts.


It’s not a big deal unless the computers are talking about me behind my back.  Are they?
Don't Freak But Google Researchers Discovered Their AI Translation Tool Invented Its Own Secret Language
   Google’s NMT developers first translated from English to Korean and vice versa, and then from English to Japanese and vice versa.  They were curious to see if the machine could then translate Korean to Japanese without using English as a go between.  The answer was yes it in fact could translate directly.
It's how the Google AI achieves this that is a bit of a mystery.  It appears that the NMT has created its own internal language or "interlingua."  It examines concepts and sentence structures instead of word equivalents.  As a result, the NMT has created translations that are more accurate and natural.  Google’s NMT creators, however, are unsure how the neural networks work or what exact concepts the NMT has learned translate languages directly.  In short, Google's AI has created its own secret language we humans do not fully understand.  A white paper that details the researchers' work, including some detail on the mystery "interlingua," can be found here (PDF).


A site worth bookmarking!
The Data Visualisation Catalogue
by Sabrina I. Pacifici on Nov 24, 2016
“The Data Visualisation Catalogue is an on-going project developed by Severino Ribecca.  Originally, this project was a way for me to develop my own knowledge of data visualisation and create a reference tool for me to use in the future for my own work.  However, I felt it would also be useful to both designers and also anyone in a field that requires the use of data visualisation regularly.  Although there have been a few attempts in the past to catalogue some of the established data visualisation methods, there is no website that is really comprehensive, detailed or helps you decide the right method for your needs.  I will be adding in new visualisation methods, bit-by-bit, as I research each method to find the best way to explain how it works and what it is best suited for.  Most of the data visualised in the website’s example images is dummy data….” 


Politics 101.  Republicans should avoid making suggestions at all costs.  If Trump does well, they can claim him as one of their own.  If Trump fulfills Hillary Clinton’s predictions, they can claim they had nothing to do with his choices.
Republicans Divided Between Romney and Giuliani for Secretary of State

Thursday, November 24, 2016

The first update in quite some time.  My IT Governance students will be interested. 
Six in Philippines May Face Charges Over Bangladesh Bank Heist Charges
The Philippines said Wednesday it has launched criminal proceedings against six bankers accused of failing to stop the laundering of tens of millions of dollars stolen by cyber-criminals from Bangladesh's central bank.
The electronic thieves in February shifted $81 million from the bank's account with the US Federal Reserve in New York to the Rizal Commercial Banking Corp. (RCBC) in Manila in one of the world's biggest bank heists.
The money was transferred to four accounts at an RCBC branch from where it was funnelled into local casinos, according to regulators who fined the bank a record $21 million in August.
Manila's Anti-Money Laundering Council said it filed a criminal complaint at the justice department against RCBC's retail banking group head at the time, its national sales director and four other bank officials.
"The... respondent officers and employees of RCBC facilitated the suspicious transactions involving the four accounts above, by failing to conduct the requisite investigations and enquiries into the accounts," it read.
The complaint, filed on Friday, also cited the Filipino respondents' alleged "deliberate refusal to know the unlawful origins of the funds".


A day for under-the-radar announcements?  
Personal data for more than 130,000 sailors was breached, Navy says
The Navy was notified in October by Hewlett Packard  Enterprise Services  that a computer supporting a Navy contract was “compromised,” and that the names and social security numbers of 134,386 current and former sailors were accessed by unknown persons, the service said in a news release.
   A Navy official familiar with the investigation said the personal data came from the Career Waypoints database, known as C-WAY, which sailors use to submit re-enlistment and Navy Occupational Specialty requests.
   This is at least the second major breach of Navy data linked to its contracting activities with Hewlett Packard.  In 2013, the service announced that Iran had penetrated its unclassified Navy and Marine Corps Intranet.  In March 2014, the Wall Street Journal reported that the breach was due to a sloppily written contract with Hewlett Packard that didn’t require HP to provide security for some of the Navy’s unclassified databases.
It took four months for officials for purge the hackers from the system.


Let’s go where the money is!
Jason Kint reports:
Verizon has topped itself by playing Russian roulette with consumer trust in an attempt to compete with the advertising businesses of Google and Facebook.  In an email announcement last Sunday night to select subscribers, Verizon signaled how it intends to compete with those two powerhouses, outlining its plan to combine offline information, such as postal address, email address and device type, with AOL browser cookies, Apple and Google advertising IDs, and their own unique identifier header.  Coupled with all of their customers’ browsing history and app usage, this mass of customer data will make for a rich competitive product to Facebook and Google.
There’s just one problem: This practice requires explicit opt-in consent from consumers under the new FCC privacy rules.  Although the rules are not yet required to be adopted (and notably on the chopping block in a Trump presidency), it’s hard to argue that Verizon’s plan doesn’t violate the spirit of the rulemaking.
Read more on Recode.


Free is good!


I don’t think I’d send one of these to Scrooge!
Make Your Christmas Tree Tacky Again With Trump’s $149 MAGA Ornament
http://pixel.nymag.com/imgs/daily/intelligencer/2016/11/23/23-trump-hat-ornament.w710.h473.jpg