Tuesday, March 14, 2017

No security is perfect if there are people involved. 
Zack Whittaker reports:
A unsecured backup drive has exposed thousands of US Air Force documents, including highly sensitive personnel files on senior and high-ranking officers.
Security researchers found that the gigabytes of files were accessible to anyone because the internet-connected backup drive was not password protected.
The files, reviewed by ZDNet, contained a range of personal information, such as names and addresses, ranks, and Social Security numbers of more than 4,000 officers.
Read more on ZDNet.  The leak was discovered by the MacKeeper Security Research team, who provide their own report on the incident, here.  The team reports:
The most shocking document was a spread sheet of open investigations that included the name, rank, location, and a detailed description of the accusations.  The investigations range from discrimination and sexual harassment to more serious claims.
So will the Air Force contact MacKeeper or Zack and ask them who the apparent owner of the misconfigured Rsync backup is?  Will they send folks to MacKeeper and Zack’s to obtain the files?
What will the Air Force do in terms of any discipline of the unnamed officer who appears to own the backup?  And what will the Air Force do to prevent another breach like this?


Hey, when you’re good, you’re good.  Who is buying besides governments?  Why not software manufacturers? 
A new report from Rand Corp. may help shed light on the government’s arsenal of malicious software, including the size of its stockpile of so-called “zero days” — hacks that hit undisclosed vulnerabilities in computers, smartphones, and other digital devices.
The report also provides evidence that such vulnerabilities are long lasting.  The findings are of particular interest because not much is known about the U.S. government’s controversial use of zero days.  Officials have long refused to say how many such attacks are in the government’s arsenal or how long it uses them before disclosing information about the vulnerabilities they exploit so software vendors can patch the holes.
Rand’s report is based on unprecedented access to a database of zero days from a company that sells them to governments and other customers on the “gray market.”  The collection contains about 200 entries — about the same number of zero days some experts believe the government to have.  Rand found that the exploits had an average lifespan of 6.9 years before the vulnerability each targeted was disclosed to the software maker to be fixed, or before the vendor made upgrades to the code that unwittingly eliminated the security hole.
Some of the exploits survived even longer than this.  About 25 percent had a lifespan of a decade or longer.  But another 25 percent survived less than 18 months before they were patched or rendered obsolete through software upgrades.


Oh, joy!
Financial Attackers as Sophisticated as Nation-State Groups: FireEye
Financially motivated attackers have become just as sophisticated as threat actors sponsored by nation states, according to the 2017 M-Trends report published on Tuesday by FireEye-owned Mandiant.
   Until 2013, cybercriminals mostly launched what experts described as “smash and grab” attacks – little effort was put into hiding their actions and maintaining access to the breached system.  In the following years, the line between the level of sophistication exhibited by financial attackers and nation-state actors became increasingly blurry, and now researchers say that line no longer exists.
   The full M-Trends 2017 report is available online in PDF format.


So now their data will be limited to that obtained by a warrant? 
Facebook bars developers from using data to create surveillance tools
Facebook Inc barred software developers on Monday from using the massive social network’s data to create surveillance tools, closing off a process that had been exploited by U.S. police departments to track protesters
Facebook, its Instagram unit and rival Twitter Inc came under fire last year from privacy advocates after the American Civil Liberties Union (ACLU) said in a report that police were using location data and other user information to spy on protesters in places such as Ferguson, Missouri.
In response to the ACLU report, the companies shut off the data access of Geofeedia, a Chicago-based data vendor that said it works with organizations to “leverage social media,” but Facebook policy had not explicitly barred such use of data in the future.
“Our goal is to make our policy explicit,” Rob Sherman, Facebook’s deputy chief privacy officer, said in a post on the social network on Monday.
   Ozer praised the companies’ action but said they should have stopped such use of data earlier.  It shouldn’t take a public records request from the ACLU for these companies to know what their developers are doing,” she said.
It was also unclear how the companies would enforce their policies, said Malkia Cyril, executive director of the Center for Media Justice, a nonprofit that opposes government use of social media for surveillance.


Again, I think that cities should do this themselves and sell access to anyone who wants it. 
New York City Sues Verizon Over Fiber-Optic Cable Coverage
New York City filed a lawsuit Monday against Verizon Communications Inc., alleging t he company failed to deliver a 2008 promise to offer fiber-optic cable connections to every home in the city.
The breach-of-contract suit is the latest step in what has been a year of tension between the city and the company.
Last summer, the city's Department of Information Technology & Telecommunications released an audit examining a franchise agreement that Verizon signed with the city in 2008.  The agreement permitted Verizon to deploy its fiber-optic network, Fios, as long as it ran its fiber network past all city dwellings by 2014.
The deal technically only covers cable TV, but Verizon also offers high-speed internet over the same fiber-optic cables.


I’ve been telling my lawyer friends that my students are already programming their replacements.
Rise of the Robolawyers
How legal representation could come to resemble TurboTax


Something to discuss with my Data Management students.  
Intel's $15 billion purchase of Mobileye shakes up driverless car sector
Intel Corp agreed to buy Israeli autonomous vehicle technology firm Mobileye for $15.3 billion on Monday in a deal that could thrust the U.S. chipmaker into direct competition with rivals Nvidia Corp and Qualcomm Inc to develop driverless systems for global automakers.
   The stakes are enormous.  Last year, Goldman Sachs projected the market for advanced driver assistance systems and autonomous vehicles would grow from about $3 billion in 2015 to $96 billion in 2025 and $290 billion in 2035.
[From a Letter to Intel employees:  
Many of you have asked why we think autonomous cars and vehicles are so important to Intel’s future.  The answer is DATA.  Our strategy is to make Intel the driving force of the data revolution across every technology and every industry.  We are a DATA company.  The businesses we focus on, and deliver solutions to, create, use and analyze massive amounts of data.
I recently had a chance to speak at the LA Auto show and the title of my presentation was “Data is the New Oil.”  My message was simple: automobiles and the automotive industry are increasingly driven by data and computing.  The saying “What’s under the hood” will increasingly refer to computing, not horsepower.  
At four terabytes of data per day, the average autonomous car will put out the data equivalent of approximately 3,000 people.


How much is a CEO worth?  
Verizon originally wanted $925 million discount for Yahoo’s online services
Verizon initially thought the biggest data breaches in Internet history merited a $925 million discount on its acquisition of Yahoo’s online services, nearly three times what the two companies finally agreed upon.
Yahoo disclosed new details about its negotiations with Verizon in a regulatory filing Monday.  The filing doesn’t say why Verizon relented on its original demand, issued Feb. 1.  Verizon ultimately accepted Yahoo’s offer to trim the sale price by $350 million instead.
   Although she hasn’t divulged her plans, Mayer isn’t expected to work for Verizon.  If she leaves, Mayer will receive a $23 million severance package, according to Monday’s filing.  The amount is lower than a $44 million valuation disclosed in September because $21 million in stock options and other awards have vested in Mayer’s account since then.
Besides her severance package, Mayer will gain control of stock options valued at $56.8 million, according to the filing.


Something to play with on my old but still functional PCs.

Monday, March 13, 2017

Third parties, contractors, outsourcers.  A risk everyone shares.  Does any company do everything themselves? 
BBC reports:
Details of thousands of medical staff in Wales have been stolen from a private contractor’s computer server.
Names, dates of birth, radiation doses and National Insurance numbers of staff who work with X-rays were copied as hackers accessed Landauer’s system.
The Welsh NHS described the data breach as “deeply disappointing” and it has started an investigation.
The Welsh Government and information commissioner have been informed and Landauer has been asked to comment.
Read more on BBC.


Just to be clear, no votes were changed, right?  The “hacking” amounted to some embarrassing disclosures and “fake news?” 
NATO’s Deputy Supreme Allied Commander Europe, General Sir Adrian Bradshaw, has reportedly suggested that NATO may consider Russian interference in upcoming European elections as an attack triggering collective defense measures.  Such a move could put NATO and its member states at odds with the United States, which carefully avoided calling Russian interference in the U.S. election even a violation of international law.  It would also leave the United States with a difficult choice of potentially changing its view of the legality of election interference or contradicting the legal views of its NATO allies.  

(Related).
UK Intelligence Agency Warns of Russian Political Hacking Capabilities
The UK's National Cyber Security Center (NCSC, part of GCHQ) has written to the British political parties to warn about "the potential for hostile action against the UK political system."  Without confirming that the main threat is from Russia, the letter makes it clear that the primary threat is considered to be that country.
In a similar vein, the British Foreign Secretary Boris Johnson said on national television Sunday, "We have no evidence the Russians are actually involved in trying to undermine our democratic processes at the moment.  We don’t actually have that evidence.  But what we do have is plenty of evidence that the Russians are capable of doing that."


If I have no social media accounts or electronic devices for them to search, will I be allowed back in the US? 
Digital Privacy at the U.S. Border: Protecting the Data On Your Devices and In the Cloud
by Sabrina I. Pacifici on Mar 12, 2017
Digital Privacy at the U.S. Border: Protecting the Data On Your Devices and In the Cloud by Sophia Cope, Amul Kalia, Seth Schoen, and Adam Schwartz – ‘The U.S. government reported a five-fold increase in the number of electronic media searches at the border in a single year, from 4,764 in 2015 to 23,877 in 2016.1  Every one of those searches was a potential privacy violation.  Our lives are minutely documented on the phones and laptops we carry, and in the cloud.  Our devices carry records of private conversations, family photos, medical documents, banking information, information about what websites we visit, and much more.  Moreover, people in many professions, such as lawyers and journalists, have a heightened need to keep their electronic information confidential.  How can travelers keep their digital data safe?  The U.S. Constitution generally places strong limits on the government’s ability to pry into this information.  At the U.S. border, however, those limits are not as strong, both legally and practically.  As a matter of the law, some legal protections are weaker – a fact EFF is working to change.  As a matter of practice, border agents may take a broad view of what they are permitted to do.  Border agents may attempt to scrutinize the content stored on your phones, laptops, and other portable electronic devices.  They may try to use your devices as portals to access your cloud content, including electronic communications, social media postings, and ecommerce activity.  Moreover, agents may seek to examine your public social media postings by obtaining your social media identifiers or handles.  As of this writing, the federal government is considering requiring disclosure from certain foreign visitors of social media login credentials, allowing access to private postings and “friend” lists.  This guide (updating a previous guide from 2012) helps travelers understand their individual risks when crossing the U.S. border, provides an overview of the law around border search, and offers a brief technical overview to securing digital data.”


Wow!  Someone should do a seminar on this AI stuff. 
How AI Is Transforming the Workplace
   These applications aim to analyze a vast amount of data and search for patterns—broadening managers’ options and helping them systematize processes that are often driven simply by instinct.  And just like shopping sites, the AIs are designed to learn from experience to get an ever-better idea of what managers want.  
   Another AI service lets companies analyze workers’ email to tell if they’re feeling unhappy about their job, so bosses can give them more attention before their performance takes a nose dive or they start doing things that harm the company.
   With its relentless focus on facts, AI seems to overcome supervisors’ prejudices, but it can have its own biases, such as favoring job candidates who have characteristics similar to those the software has seen before.  Automated decision-making may also tempt managers to abdicate their own judgment or justify bad decisions that would have benefited from a human touch.
   And the biggest caveat: The AI systems’ thirst for data can lead employers to push the boundaries of workers’ privacy.  It is incumbent upon managers to use them wisely.

(Related).  Some interesting parallels to the WSJ article above.
Potter Stewart, justice of the U.S. Supreme Court, once said, “Ethics is knowing the difference between what you have the right to do and what is right to do.”  Associate Justice Stewart probably didn’t know how new data technologies would soon begin to blur those boundaries.
With the emergence of new information technologies, corporations can now amass and analyze unprecedented volumes of unstructured data — the data created by humans, such as the text contained in company documents, email, instant messaging, and social media.  Collecting this data was originally driven by the obligation to produce evidence for litigation, to preserve business records, and to respond to regulators’ demands for information, but it has now dawned on corporations that all of that data can open up new vistas of management capabilities, such as visualizing employee interactions, mapping domain expertise, replaying past events, tracking employee sentiment, and providing insights into all human activity across the organization.

(Related).  “Siri, send all of this to my personal email.” 
Alexa and Cortana May Be Heading to the Office
   The products aren’t quite ready for office prime time yet.  The workplace offers challenges that experts say intelligent assistants built for home use so far haven't effectively met, mostly in the area of voice recognition.
   Mr. Lee is an investor in Workfit, a startup that is developing an office assistant and meeting facilitator it calls Eva.  Relying on voice controls and artificial intelligence, Eva aims to make meetings more efficient by, among other things, creating a searchable record of what is said, highlighting decisions and performing tasks on command such as sending slides or documents to specific participants.


“We are and we aren’t.”  “Because of North Korean provocation and because we were going to do it anyway.”  Nothing like a clear message.
US Deploys Attack Drones to South Korea Amid Tension with North
The United States has started to deploy attack drones to South Korea, a U.S. military spokesman said on Monday, days after it began to deploy an advanced anti-missile system to counter "continued provocative actions" by isolated North Korea.
The drones, Gray Eagle Unmanned Aerial Systems (UAS) coming to South Korea are part of a broader plan to deploy a company of the attack drones with every division in the U.S. Army, the spokesman said.


For my students.
Microsoft Office products are pretty easy to use, but there’s a lot of depth hiding in their simple interfaces. Maybe you just started using Office, or know Word well but struggle with Excel.
Now, you can get some free help straight from the source. Microsoft has just released some new Microsoft Office training videos, titled Office Basics.  They cover six different areas of Office:
  1. Intro to Office Basics
  2. What Is Office 365?
  3. Word Training
  4. Excel Training
  5. PowerPoint Training
  6. Outlook Training
You can see all the courses available at the Office Training Center homepage.

Sunday, March 12, 2017

A rather extreme example of privacy on the Internet of Things?  Similar to children’s toys and other devices connected to the Internet.  Note what you have to disclose to get the full $10,000
Sex Toy Maker Pays $3.75 Million to Settle ‘Smart’ Vibrator Lawsuit
Think twice about connecting those sex toys to the Internet: A vibrator company has agreed to pay up to $10,000 to U.S. customers who used a smartphone app that relayed their data to the firm’s server.
   The toys in question, which include the We-Vibe Classic and Rave by We-Vibe, are designed to be used by couples, allowing one partner to control the devices via Bluetooth and a smartphone app.
Security researchers, however, discovered the company was also using the smart phone app to harvest data about how customers used the vibrators.  The apps collected information such as what temperature and intensity settings the owners used, as well as how often they used the toys.
   In a curious twist to the settlement, the process creates two potentials ways for customers to collect: those who attest they used the app to control the vibrator, and who provide their name and phone number and other details as part of the claim process, will get up to $10,000.  Meanwhile, those who simply purchased a We-Vibe connected device will receive up to $199.


Interesting.  Very expensive and other barriers to entry.  Who documents a system that changes as it learns?  (My guess: the AI itself!) 
4 ways Google Cloud will bring AI, machine learning to the enterprise
Last November, when Google announced that machine learning research luminary Fei-Fei Li, Ph.D. would join Google’s Cloud Group Platform group, a lot was known about her academic work.  But Google revealed little about why she was joining the company except she would lead machine learning for the Google Cloud business.
After five months of suspense, yesterday Li revealed the focus of her new role during her keynote address at Google’s cloud developer conference, Cloud Next 2017. She will apply her experience to democratize machine learning to the enterprise.  Her task: Study the problems that machine learning could solve in a wide variety of industries and enable enterprises to adopt machine learning.
   Earlier in her keynote, Li began to describe some of the enterprise applications that interested her by saying: “So much more is waiting to be done.”
  • Retail: Google’s Adsense can be extended by retailers to serve the best ad to the individual consumer.
  • Supply chain: Optimize routes and inventory, predict changes in demand, drone and autonomous vehicle deliveries.
  • News content: Individually personalize news and, presumably, screen fake news.
  • Financial services: Predict credit card risk, manage an individual’s finances, flag criminal activity like money laundering and fraud, and automate processes, such as replacing call centers and processing insurance claims with trained AI agents.
  • Healthcare: Li said the implications of AI in healthcare were profound—automated visual diagnosis, reduced overhead, fewer errors, extending healthcare to the underserved, augmented surgical practices, and improved administration in areas such as scribing electronic medical records (EMR) during doctor’s visits and management of chronic conditions. 


A guide for all my students. 
A Quick Guide to Email Etiquette (Infographic)

Saturday, March 11, 2017

They replace compromised credit cards and want the ‘breach-ee’ to pay for it.
Matt Day reports that another retailer has been sued by financial institutions hoping to recover their costs of a breach.  Veridian Credit Union filed suit, seeking class-action status, in Seattle federal court this week.
The complaint alleges negligence on the retailer’s part and seeks to compensate financial institutions for costs related to reissuing stolen credit and debit cards, refunding unauthorized transactions and other fallout from the malware breach that affected point of sale terminals in its brick-and-mortar stores.
The deficiencies in Eddie Bauer’s security system include “a lack of elementary security measures that even the most inexperienced (information technology) professional could identify as problematic,” the complaint said.
The company failed to implement chip-based card anti-fraud technology, and exacerbated the problem by failing to notify customers for weeks after learning about the problem, the lawsuit says.
Read more on Seattle Times.  In light of Home Depot’s settlement with banks over its 2014 breach, it will be interesting to see what happens with this one.


Abandoning a perfectly good parking spot is probable cause? 
Can police strip search a motorist over an unpaid $6.50 traffic ticket?  The New Jersey Superior Court’s Appellate Division said last week that such conduct is unconstitutional.  A three-judge panel considered the case of Robert L. Evans, who was subjected to a search on January 4, 2012, after a Vineland police officer saw Evans pulling into, and then out of, a parking spot at the Days Inn.
Read more on TheNewspaper.com.
A copy of the decision is available in a 160k PDF file on their site.
[From the article:  
The judges were upset that police failed to abide by the state attorney general's guidelines which say require a warrant for strip searches.  The panel saw no excuse for the failure to obtain one.


Not a real fear of Russians casting votes. 
Fears of election hacking spread in Europe
France has followed the Netherlands in placing its faith in paper-based voting systems ahead of key elections later this year, following allegations that Russian hackers influenced last year's U.S. presidential election.
   The move will only affect 11 of the 577 electoral districts voting, those representing French citizens living outside their home country.  These expatriates had previously been allowed to vote over the internet in some elections because the alternative was to require some of them to travel vast distances to the nearest embassy or consulate with a ballot box.
   That decision, though, was for reasons of electoral equality, not cybersecurity.
   In the Netherlands, it wasn't the internet that posed a security concern but the use of software to add up counts of paper votes.  Parliamentary elections will be held there on March 15.


“Well for one thing, you’re talking to a box…”   
'Alexa: What's Wrong With Me..?' Amazon's Virtual Assistant To Replace Your Doctor
Just when you thought Amazon’s virtual assistant knew enough already, WebMD – the hypochondriac’s favorite website - has teamed up with the retail giant to give Alexa medical diagnosis capabilities.
The integration will allow Amazon Echo, Echo Dot and Fire TV users to ask Alexa basic health queries, such as "Alexa, ask WebMD what are the symptoms of a heart attack", or "Alexa, ask WebMD how to treat a sore throat."
   "There are a number of reasons that voice-enabled interfaces are growing in popularity - they are generally hands-free, people can talk faster than they type, and when done right, they make it easier for consumers to quickly and easily get to the information they need."

Friday, March 10, 2017

A data breach (like a diamond) is forever!  Or at least a long, long time.
Jeff John Roberts reports:
Home Depot has taken another step to move on from its colossal 2014 data breach, which involved hackers stealing email or credit card information from more than 50 million customers by infiltrating self check-out terminals.
In a new settlement with dozens of banks, the retailer has agreed to pay $25 million for damages they incurred as a result of the breach, one of the biggest in history.
The settlement, filed this week in federal court in Atlanta, also requires Home Depot to tighten its cyber-security practices and to subject its vendors to more scrutiny—a measure tied to the fact that a security flaw by a third-party payment processor made the hacked self-checkout terminals vulnerable.
Read more on Fortune.


It’s hard to convince my Computer Security students that studies like this are correct.  
Presser, but has some interesting findings:
Evolve IP, The Cloud Services Company™, today released the results of a study of Dark Web email vulnerabilities in the healthcare industry.  The research, conducted in a collaboration between Evolve IP and ID Agent, reveals the pervasive nature of email-based cybersecurity attacks and sheds light on the quantity, variety, sources and consistent growth of these threats.
Healthcare IT leaders place a high priority on preventing breaches, but despite their best efforts, hackers often break through the organization’s weakest link – end user email credentials.  The study, which included an analysis of 1,000 healthcare organizations, illustrates the need for proactive threat monitoring coupled with near real-time disaster recovery solutions to prevent employee email liabilities from becoming major catastrophes.

Amongst other findings the landmark study uncovered:
  • 68 percent of the healthcare organizations analyzed have compromised email credentials as identified by ID Agent’s Dark Web ID analysis.  Nearly 80 percent of the positive data set includes actionable password information, simplifying hackers’ efforts to infiltrate the network.
  • An estimated 7,500 individual incidents occurred across the study where healthcare companies had email credentials compromised due to phishing or key logging attacks.  Any one of these vulnerabilities could rapidly escalate to ransomware, denial of service attacks or PHI breaches across an entire enterprise.
  • 23% of the passwords stolen were available for sale or trade on the Dark Web as unencrypted, clearly visible text.  While the remainder of passwords were encrypted, the level of encryption used presents no real hurdle to professional hackers that want to crack them. [See Comey article, below.  Bob]


Would my Security students fix this or eliminate it entirely?
Over on TechDirt, Mike Masnick writes:
For years we’ve pointed out the sheer insanity of the TSA’s security theater, which is intrusive, insulting and does little to actually make us any safer.  One aspect (of many) that has been particularly troubling is the way that the TSA has basically enabled sexual assault of travelers.  If you felt that wasn’t too bad, have no fear, the TSA is apparently increasing the sexual assaulty nature of these searches:
The new physical touching—for those selected to have a pat-down—will be what the federal agency officially describes as a more “comprehensive” physical screening, according to a Transportation Security Administration spokesman.
Denver International Airport, for example, notified employees and flight crews on Thursday that the “more rigorous” searches “will be more thorough and may involve an officer making more intimate contact than before.”
This is madness.  The answer to the TSA’s awful and useless security theater should never be to give TSA agents more power to sexually assault travelers with “more intimate contact.”  This is not about security.  This is about the TSA wanting to make it look like they’re doing something, and apparently that includes groping strangers who are just trying to get somewhere.  How the hell does sexually assaulting travelers make anyone any safer?
Remember when they told us that the full body scanners would keep us safer and diminish the need for intrusive pat-downs?  So now they have BOTH, and the public will go along with this like sheeple.  Again.
Between this and the CIA hacking tools leak with FBI director Comey telling everyone,  “There is no such thing as absolute privacy in America,” I fear some Americans are first waking up to what some of us have been yelling from the rooftops for years as we headed towards a dystopian society.  Frighteningly, some still may not have woken up.
   Reagan’s nine most terrifying words in the English language, ‘I’m from the government and I’m here to help,’ should be replaced with, “I’m from TSA and I’m here to grope you.”


I wonder how many law firms have had a Computer Security audit?  
Derek Borchardt and Michael F. Buchanan have an update on litigation previously noted on this site.  At its heart, a lawsuit claimed a Chicago law firm, Johnson & Bell, had inadequate data security.  There was no allegation of any actual breach – the suit was over inadequate data security.
Back in December of last year, we reported that for the first time, a U.S. law firm – Johnson & Bell, a mid-sized Chicago firm – was publicly named in a class action data security lawsuit.  Last month, the firm obtained a significant victory in the case.
To briefly recap, two of Johnson & Bell’s former clients claimed in their complaint that the firm had lax data security practices that put confidential client information at risk of exposure.  (Note that the plaintiffs did not claim that any actual breach had occurred, an omission which presents a significant question of standing under Article III, an issue this blog has recently covered.)
The retainer agreement between the firm and its former clients included an arbitration clause, which stated in pertinent part: “In the unlikely event of any dispute under this agreement, including a dispute regarding the amount of fees or the quality of our services, such dispute shall be determined through binding arbitration.”  Based on that clause, Johnson & Bell filed a motion to require the plaintiffs to arbitrate their dispute on an individual, rather than class, basis.  The firm argued that because the arbitration clause did not explicitly state that arbitration may be on a class basis, the only permissible arbitration was on an individual basis.  The court agreed.
Read more on Patterson Belknap Data Security Law Blog.
I asked Jay Edelson of Edelson, PC, lawyers for the plaintiffs, his perspective on the decision and its potential impact on other similar cases they had planned to file.  He replied:
We filed suit (under seal) seeking, first, injunctive relief to fix the alleged security vulnerabilities.  Once we were satisfied of the relevant fixes, we then moved to unseal the case and dismissed it.  The dismissal did not mean that we aren’t pursuing it, but rather was in recognition of the fact that there is an arbitration clause.  Johnson & Bell asked the Court to rule that we could arbitrate on an individual basis only (i.e. not on behalf of a class).
The Court agreed with them and we are going to appeal that decision.  However, regardless of whether this can be brought as a class action, we will still pursue the suit.  The question will be whether the class members are required to bring many individual arbitrations or can do it all at once.
In terms of other similar lawsuits, because this is a procedural issue (as opposed to one on the merits), it doesn’t have much impact unless a defendant has a similar arbitration clause as Johnson & Bell’s.  Even if they do, our guess is that because individual arbitrations are so expensive, it is unlikely that other defendants will choose to potentially face hundreds if not thousands of arbitrations instead of fighting one single (albeit larger) case.
So stay tuned, I guess.  I expect that there will still be issues raised of standing if there’s been no actual breach, but we’ll have to wait and see.


Propaganda 101: Make it sound like you are being picked upon.  The Evil US is doing something to poor, innocent, helpless China that no other country would ever do to another. 
China to US: Stop hacking us
China asked the U.S. government on Thursday to stop spying on and hacking other countries, after WikiLeaks revealed data showing that the CIA can hack a range of devices, including some manufactured in China.


Also Propaganda-like.  Wasn’t the “bargain” that there was a “right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures?”  Are warrants no longer adequate because of encryption? 
Comey: Strong encryption “shatters” privacy-security bargain
FBI Director James Comey told a Boston audience this morning that “ubiquitous strong encryption” – the kind now available on most smartphones and other digital devices – is threatening to undermine the “bargain” that he said has balanced privacy and security in the US since its founding.
Actually, he went further, declaring that such default encryption “shatters” the bargain.
   “Last fall we received 2,800 devices that we had lawful authority to open.  And there were 1,200 we couldn’t open with any technology tool.  These were devices recovered in criminal, gang, terror and pedophile investigations.”
   But he said with probable cause and a warrant approved by a court, “government can invade – that’s the bargain.  If government has probable cause, it can search and seize – take whatever the judge said it could.  Even our memories aren’t totally private.  The general principle is that there is no such thing as absolute privacy.”

(Related) Perhaps Comey could hire the Dutch if the FBI is not competent?
DutchNews.nl reports:
Dutch detectives have gained access to 3.6 million encrypted emails sent by criminal gangs which will be used in dozens of prosecutions, the public prosecution department said on Thursday.  The information in the mails will provide evidence for criminal cases, including murder, armed robbery, drugs, money laundering and other forms of organised crime, the department said in a statement.
The messages were found on servers in Canada belonging to a Dutch company called Ennetcom.  Last year, the public prosecution department won the right to have the Ennetcom servers copied and the seven terabytes of information sent to the Netherlands for investigation.
Read more at DutchNews.nl.
Update: Read about how they were able to decrypt the messages on HackRead.


Stranger how often my class discussions revolve around failures.
Lessons from Mismanaged Crises at Yahoo, Cuisinart and Wells Fargo
   Contrast the above-companies’ performance with Johnson & Johnson’s handling of its tampered-Tylenol crisis in 1982, long considered a paradigm of successful crisis management.  However, today even its response probably would be regarded as a failure.  The company took three days to decide how to respond.  In our internet age with its 24/7 news cycle, a company does not have three days to react; it may not have even three hours.  Advance planning is critical.

(Related) Bias is programmed failure.  Diversity is a solution.
How I'm fighting bias in algorithms
MIT grad student Joy Buolamwini was working with facial recognition software when she noticed a problem: the software didn't recognize her face — because the people who coded the algorithm hadn't taught it to identify a broad range of skin tones and facial structures.  Now she's on a mission to fight bias in machine learning, a phenomenon she calls the "coded gaze."  It's an eye-opening talk about the need for accountability in coding ... as algorithms take over more and more aspects of our lives.  


We’re going to need to understand this technology and the laws governing it.  This will be very difficult or impossible to replicate manually. 
Mapping the Global Legal Landscape of Blockchain Technologies
by Sabrina I. Pacifici on Mar 9, 2017
Maupin, Julie A., Mapping the Global Legal Landscape of Blockchain Technologies (February 14, 2017).  Available at SSRN: https://ssrn.com/abstract=2930077
“Blockchain technologies are beginning to push a broad array of global economic activities away from centralized and toward decentralized market structures.  Governments should tackle the new regulatory conundrums of an increasingly disintermediated global economy by focusing on blockchain’s individual use cases rather than its underlying enabling technologies.  Grouping the known use cases around common characteristics reveals three broad categories of blockchain/law interfaces: the green box, the dark box, and the sandbox.  Each raises distinctive legal, regulatory and policy challenges deserving of separate analysis.”


Disruption.  Clearly Staples et.al. could put up an online store.  Does this actually indicate that shoppers always start their buying search at Amazon?  (Only going to other sites if they don’t find what they want?)   
Staples and Office Depot Are Being Ripped to Shreds by Amazon and the Internet
Persistently plunging sales, weak profits and more store closures have become the new normal for office supplies retailers Staples and Office Depot as they battle online foes such as Amazon.


My latest ‘get rich quick’ scheme: Print up fancy labels you can slap on your bottle to make tap water look exotic.  For example, “Water from some glacier in the Himalayas.”
Americans drank more bottled water than soda in 2016

Thursday, March 09, 2017

Another “proof of concept” test?  Which would cause the most trouble, “can’t call” or the earlier “can’t stop calling and hanging up?” 
AT&T Cellphone Users Unable to Call 911 in at Least 14 States
Some AT&T cellphone users in at least 14 states and Washington, D.C., were unable to call 911 for a few hours on Wednesday night, officials said.
City, county, law enforcement and emergency response officials took to social media over the course of almost five hours to warn people across the country of the disruption.
   The telecommunications giant did not say when and how the problem began, or how many customers were affected.


For my Computer Security students.
Why the Ukraine power grid attacks should raise alarm
Since December of 2015, electric utilities in the United States and Canada have been wrestling with the postmortem reports and data findings from two significant grid hacking events in Ukraine.  The subject of these attacks have been addressed by those on Capitol Hill, trade associations, regulators, and the E-ISAC.
The hackers who struck utilities in Ukraine, which is the first confirmed hack to degrade a power grid, weren’t opportunists who just stumbled across the networks and launched an attack to test their abilities.  The attackers were highly skilled and planned their assault over many months, first doing reconnaissance to study the networks and steal operator credentials, then launching a synchronized attack against operating systems.
The perpetrators of a cyberattack on Ukraine's electric grid gained access to energy distribution company systems more than six months before [and no one noticed.  Bob] causing the Dec. 23, 2015 outage that temporarily left about 225,000 customers without power.


Perspective.  And a big question for my students from India: “Are you investing in this market?”
As the skies above India rain money, Qatar Airways lines up a domestic airline
Just three months after Qatari prime minister Sheikh Abdullah bin Nasser bin Khalifa Al Thani held talks in New Delhi, the state-owned carrier of the oil-rich middle eastern nation has announced plans to enter India’s aviation market.
“Yes, we will have a 100% owned domestic carrier in India that will belong to both the QR (Qatar Airways) and our state investment arm, as India has now allowed foreign direct investment in domestic carriers within India,”
   India is poised to become the world’s third largest aviation market by 2020.  Domestic air travel is expected to grow by 9.5% annually between 2011 and 2031, according to aircraft-maker Airbus.  Currently, only about 2% of India’s population uses airlines, providing a massive opportunity to expand the market.
India is also expected to order more than 1,600 aircraft over the next 20 years, according to Boeing and Airbus, the world’s two largest aircraft makers.  In January, SpiceJet, India’s fourth largest airline by market share, ordered as many as 205 new aircrafts from Boeing for $22 billion.  Meanwhile, India’s largest airline, IndiGo, too, has finalised orders for 250 carriers with Airbus.


Perspective.  It must mean something else in Chinese…  Or do pimps hold a lot of trademarks? 
Trump Organization granted trademark for ‘Trump Escorts’ in China
The Trump Organization was granted trademarks for 38 businesses in China on Wednesday, including “spas, massage parlors, golf clubs, hotels, insurance, finance and real estate companies, retail shops, restaurants, bars, and private bodyguard and escort services,” according to the Telegraph.  Yes, the president’s family business applied for, and received, a trademark for branded escort services in China.  Happy International Women’s Day.

Wednesday, March 08, 2017

Something for an Ethical Hacking background? 
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
In what appears to be the largest leak of C.I.A documents in history, WikiLeaks released on Tuesday thousands of pages describing sophisticated software tools and techniques used by the agency to break into smartphones, computers and even Internet-connected televisions.
The documents amount to a detailed, highly technical catalog of tools. [Not the actual tools.  Bob]  They include instructions for compromising a wide range of common computer tools for use in spying: the online calling service Skype; Wi-Fi networks; documents in PDF format; and even commercial antivirus programs of the kind used by millions of people to protect their computers.
The initial release, which WikiLeaks said was only the first installment in a larger collection of secret C.I.A. material, included 7,818 web pages with 943 attachments, many of them partly redacted by WikiLeaks editors to avoid disclosing the actual code for cyberweapons.  The entire archive of C.I.A. material consists of several hundred million lines of computer code, the group claimed.
   In some regard, the C.I.A. documents confirmed and filled in the details on abilities that have long been suspected in technical circles.


I thought I had reported this earlier. 
Jason Meisner and Steve Schmadeke report:
In the latest skirmish over privacy in the cellphone age, a federal judge in Chicago has rejected a law enforcement request to force potential targets in an ongoing investigation to provide fingerprints to unlock any iPhones or other Apple devices.
The order by U.S. Magistrate Judge David Weisman concerned a request for a warrant to search a residence where investigators believed someone was using the internet to traffic images of child pornography, court records show.
The prosecution filing seeking the search warrant on the FBI’s behalf remains under seal, but the judge’s opinion said the government requested “the authority to compel any individual who is present at the subject premises at the time of the search” to provide a fingerprint or thumbprint needed to unlock an Apple device.
Read more on Chicago Tribune


I know some IP lawyers who will be watching this like hawks.  Did this AI turn criminal on its own or was it programmed that way? 
Microsoft’s AI Is Now Writing Its Own Code by Looting Other Programs (MSFT)
Thou Shall Not Steal. [Unless thou hast a good lawyer?  Bob]  It’s a guiding principle that applies to everything.  But not anymore.  Not after a team of researchers from software giant Microsoft and Cambridge University built DeepCoder — a highly intelligent and sophisticated computer system that makes it possible for machines to write their own programs, by stealing code from other people (or other machines).  And if you forget the stealing part, its intentions are actually good.
With DeepCoder, it will now be possible for people who can’t code very well or don’t know how to code at all to write their own programs.  All they have to do is describe what it is they want done, and the computer will write the appropriate code to get it done.  Even better, it can create programs in a matter of seconds, unlike its older predecessors which needed several minutes to do the job.  Ideally, this means that people will have more time to spend on productive, rather than trivial stuff. [Rather insulting to us programmers!  Bob]
   “The potential for automation that this kind of technology offers could really signify an enormous [reduction] in the amount of effort it takes to develop code.  Generating a really big piece of code in one shot is hard, and potentially unrealistic.  But really big pieces of code are built by putting together lots of little pieces of code.”


Just another thing on that Internet of Things.  No doubt they will phone or text if anything changes. 
Pirelli, Goodyear Look to Gain Grip With Smart Tires
Companies show concept tires that send data including pressure, wear and temperature to a mobile app


Interesting to me, because they had to succeed at least 2,000 times to make $6,000,000
It’s finally over: Mastermind behind Prenda Law porn trolls pleads guilty
   After years of denial, John Steele admitted Monday that he and co-defendant Paul Hansmeier made more than $6 million by threatening Internet users with copyright lawsuits.
It's perfectly legal to sue Internet pirates—but not the way Steele did it.  Steele and Hansmeier set up "sham entities" to get copyrights to pornographic movies, "some of which they filmed themselves," according to the Department of Justice's statement on the plea.  Steele and Hansmeier then uploaded those movies to file-sharing websites such as The Pirate Bay and then sued the people who downloaded the content.


Perspective.  We are moving toward an ‘all mobile’ society. 
Android Poised To Topple Windows As World’s Most Used Operating System
It looks as though Google’s Android operating system is on the verge of making history.  According to analytics firm StatCounter, the current trending shows Android quickly approaching parity with Windows as the world’s most popular operating system among all computing devices.
What more striking, however, is the fact that Microsoft has been losing overall market share at a rapid pace since 2012.  At that time, Microsoft was riding high with 82 percent share of all global OS traffic.  But it has been a steady march downward, and today Microsoft’s Windows-based operating systems have a collective 38.6 percent share of the global OS market according to StatCounter.
   “The idea of Android almost matching Windows would have been unthinkable five years ago,” said StatCounter CEO Aodhan Cullen.  “Windows has won the desktop war but the battlefield has moved on.”
The changing of the guard can no doubt be attributed to the declining importance of PCs in the everyday lives of consumers, and the increasing ubiquity of smartphones as our “go to” tool for communications.


Perspective.  We do need broadcast TV or cable TV.
CTA – Number of Streaming Video Viewers Now Equal To Paid TV Subscribers
by Sabrina I. Pacifici on Mar 7, 2017
“For the first time ever, the percentage of free or paid streaming video subscribers in the U.S. (68 percent) has caught up to the number of paid TV subscribers (67 percent), according to new research from the Consumer Technology Association (CTA) ™.  The new study, The Changing Landscape for Video and Content, also shows the time consumers spend watching video content on TVs (51 percent in 2016, down 11 points since 2012) is now equaled by – within the sampling margin of error – time spent watching video content on all other consumer technology devices (49 percent) including laptops, tablets and smartphones.  “More and more consumers are embracing the freedom of connectivity – in this case, the anytime/anywhere access to video content,” said Steve Koenig, senior director of market research, CTA.  “This is one of the driving trends of our time.  Today’s advancement of technology delivers ‘content convenience’ that results in cultural changes such as binge watching, second screen behavior, content recommendations and the screens consumers use to consume video.  And we expect streaming subscribers to surpass paid TV services – and by a fair margin – in the next year or so.”


Perspective.  Groceries is a very low margin business.  I wondered how delivery services would make an money without pricing themselves out of business. 
Instacart raises $400 million at a $3.4 billion valuation to deliver groceries on-demand
   As TechCrunch has previously reported, Instacart has multiple revenue streams.  The company charges customers a markup on groceries, plus a fee for delivering items to their doors.  In addition, consumer packaged goods brands pay Instacart to advertise on its platform.  And the startup strikes revenue share agreements with partners including grocery chains like Whole Foods.


Imagine what this company would be worth if it was capable of making a profit!
Digital Financial Startup BankMobile to Be Sold for $175 Million
BankMobile, a two-year-old digital-banking upstart founded by a veteran executive of financial firms, announced Wednesday that it is being sold for $175 million after its parent company said it wouldn’t be able to operate the business profitably.


Something for the toolkit?  This could be handy!
   Markticle, available for Web, Chrome, and Android, is the solution.
It helps you mark your reading progress in articles so that you can come back to the exact spot on the webpage later.  In brief, it is a read-it-later bookmark tool that homes in not only to the article but also the particular line you want saved for later.


A warning for gamers?  Too much of a good thing is a bad thing.  Do we need an App that monitors your health and stops the game (or calls the ambulance) when you get over-stimulated?
Man suffers fatal heart attack after catching one of the rarest creatures in ‘Pokemon Go’
Pokemon Go has gotten countless players up off of the couch and on their feet in search of the endlessly charming creatures, and it’s been hailed as a great fitness tool for that very reason.  Unfortunately, it seems the pure joy of snatching a particularly elusive monster was a bit too much for one Singaporean man who, after nabbing a prized catch, suffered a fatal heart attack.