Monday, May 08, 2017

This week, we’re studying encryption.
Amnesty International – How private are your favourite messaging apps?
by Sabrina I. Pacifici on May 7, 2017
We’ve ranked 11 companies that run the world’s most popular messaging apps – including Skype, Snapchat and Facebook Messenger – on how well they’re using encryption to protect your online privacy.  In particular, we’ve looked at whether they apply end-to-end encryption – a way of making your photos, videos and chats unintelligible to anyone but you and the people you’re talking to.  This is how they fared.


No matter how well you train your employees, these still work! 
BEC attacks have hit thousands, top $5 billion in losses globally
An updated advisory form the FBI says that Business Email Compromise (BEC) attacks have become a multi-billion-dollar scam worldwide, as criminals take advantage of lax policies and human nature.
   At their core, BEC attacks are a variation on Social Engineering, designed to target a person's normal routine.  Social Engineering isn't easily detected or defeated, so when the criminals ask for something that isn't unusual or out of victim's comfort zone, the attack is often successful.
   The stats are concerning. According to the published data, between January 2015 and December 2016 the amount of exposed losses skyrocketed by more than 2,000-percent, with BEC attacks being reported in all fifty states and 131 countries.
   BEC attacks exist in a number of forms, including wire transfer requests or business requests dealing with personal information, such as W-2 records.  Some attacks include the use of compromised email accounts within the organization or those tied to the victims somehow.
When it comes to BEC attacks targeting W-2 information, 2017 is a record setting year with at least 200 reported cases since January, impacting more than 120,000 taxpayers.
   Organizations are trying to keep ahead of the curve by focusing on awareness training – including BEC attacks.  But such measures don't cover every situation, and they won't help if the habits placing the organization at risk in the first place aren't changed, including office communications dealing with sensitive information.
   The alert issued last week has a number of tips and steps for organizations and victims when it comes to these attacks.

(Related)
Phishing Explained by Common Craft
Last week's viral Google Docs phishing scam provided a good reminder to many that we should always give a critical eye to emails and social media posts that don't look quite right.  It also served as a reminder that we need to educate students and, sometimes, our colleagues about phishing attempts.  Common Craft has an excellent video on the topic.  You can watch the video  on the Common Craft website.
On a related note, if you get a Facebook friend request from someone you're already friends with, it's likely a scam.


Good news for my Ethical Hacking students?
Cyberspies tap free tools to make powerful malware framework
Over the past year, a group of attackers has managed to infect hundreds of computers belonging to government agencies with a malware framework stitched together from JavaScript code and publicly available tools.
The attack, analyzed by researchers from antivirus firm Bitdefender, shows that cyberespionage groups don't necessarily need to invest a lot of money in developing unique and powerful malware programs to achieve their goals.  In fact, the use of publicly available tools designed for system administration can increase an attack's efficiency and makes it harder for security vendors to detect it and link it to a particular threat actor.
The Bitdefender researchers have dubbed the newly discovered attack group Netrepser and traced back some of its attack campaigns to May 2016.  The group is still active, but to Bitdefender's knowledge its attacks have never been publicly documented before, which might be in part because its campaigns are highly targeted.


See?  Celebrities are just like real people!  Or at least their vendors are.
Nicole Perlroth reports on how hackers go after vendors and contractors to gain access to their real targets.  It’s something TheDarkOverlord emphasized repeatedly in discussing their attacks with me since last year, and Perlroth provides other examples as well:
In December, hackers impersonating an executive at Interscope Records, the record label owned by Universal Music Group, managed to bypass all the latest in digital defenses with a simple email.
In a carefully tailored message, the hackers urged an executive at September Management, a music management business, and another at Cherrytree Music Company, a management and record company, to send them Lady Gaga’s stem files — files used by music engineers and producers for remixing and remastering.
Read more on NY Times.


Hey!  The government does it! 
Cory Doctorow reports:
Comparitech commissioned a survey of 2,000 people in the US and UK to ask whether they thought “it is legal to install a program on a partner’s phone to snoop on their activity?” and whether they would “ever consider adding a program to your child’s phone that allows you to listen to their conversations and spy on their messages?”
The survey was prompted by Joseph Cox’s excellent reporting on Flexispy, a company that markets illegal spyware to jealous spouses and helicopter parents through a network of shadowy, Ponzi-like “affiliates” around the world, and by the finding that survivors of domestic abuse report that their abusers frequently use tools like Flexispy to track them.
Read more on BoingBoing.


This might help us catch the hackers who strip ATMs of all their cash.
Macau to require facial scans at ATMs in Chinese casino hub
Taking security to a new level, Macau is stepping up security checks at ATMs in the Asian gambling hub by requiring facial scans and ID card verification for cash withdrawals using China's main payment network.
The government said in a statement late Sunday that the new measures would eventually be rolled out to all automated teller machines in the former Portuguese colony, especially those inside casinos or nearby.  It didn't give a specific timeframe.
   The measures apply to users of UnionPay bank cards issued in mainland China, in a sign that authorities are targeting mainland visitors.  UnionPay is China's homegrown payment network rivaling the Visa and MasterCard systems.


An AI hacker?  Might be a useful research project!
In the near future, as artificial intelligence (AI) systems become more capable, we will begin to see more automated and increasingly sophisticated social engineering attacks.  The rise of AI-enabled cyberattacks is expected to cause an explosion of network penetrations, personal data thefts, and an epidemic-level spread of intelligent computer viruses.  Ironically, our best hope to defend against AI-enabled hacking is by using AI.  But this is very likely to lead to an AI arms race, the consequences of which may be very troubling in the long term, especially as big government actors join the cyber wars.


Could AI doom an entire industry?  More likely, Uber will buy self-driving cars.
How Self-Driving Cars Could End Uber
Mega-startup’s greatest threat: the disappearance of car-owning drivers caused by the rise of autonomous vehicles


I’ve had my students thinking about data centers for the last few weeks.
Bridgestone modernizes data center, hauls out 13 tons of copper wire
   That center opened on Oct. 9, 1968, with racks and racks of tapes and a water-cooled mainframe.  Today, it is the home of systems supporting an almost completely virtualized environment.
Bridgestone recently finished consolidating six data centers, totaling about 25,000 square feet, into one 10,000-square-foot facility.  The project began in 2015 and cost $17.3 million.
   The project went from wall to wall and included hauling out 26,000 pounds of copper wiring.
The data center now has 67 miles of fiber-optic cabling.
The near 50-year history of the place provides a benchmark for measuring change.  In 1968, the data center had 8,500 miles of tape storing 1,986 gigabytes of data, or about 2 terabytes, an amount of data that can fit on a 2TB thumb drive.  Today, the data center holds about 3.5 petabytes of data, said Bridgestone officials, or about 3.5 million GB.


…because no one reads the news in Facebook? 
Facebook takes out full-page newspaper ads to help U.K. citizens detect fake news online
   Appearing in nationwide titles including the Guardian and the Telegraph, Facebook’s “Tips for spotting false news” ad is similar to the one it published in France last month, and covers areas such as being skeptical of misleading headlines, spotting manipulated images, and checking the URL of the story.  Though the advice offered doesn’t always help — for example, in “Consider the photos,” the text reads: “You can search for the photo or image to verify where it came from.”  Anyone requiring advice on how to spot fake news through a newspaper ad likely isn’t tech savvy enough to know how to do that, or even what it means. [A rather low opinion of British citizens?  Bob]


…because everyone lies on Facebook?
Google big data reveals who we are in stark contrast to Facebook posts
by Sabrina I. Pacifici on May 7, 2017
“It is now official.  Scholars have analyzed the data and confirmed what we already knew in our hearts.  Social media is making us miserable. We are all dimly aware that everybody else can’t possibly be as successful, rich, attractive, relaxed, intellectual and joyous as they appear to be on Facebook.  Yet we can’t help comparing our inner lives with the curated lives of our friends.  Just how different is the real world from the world on social media?  In the real world, The National Enquirer, a weekly, sells nearly three times as many copies as The Atlantic, a monthly, every year.  On Facebook, The Atlantic is 45 times more popular.  Americans spend about six times as much of their time cleaning dishes as they do golfing.  But there are roughly twice as many tweets reporting golfing as there are tweets reporting doing the dishes…  The search for online status takes some peculiar twists…  Sufferers of various illnesses are increasingly using social media to connect with others and to raise awareness about their diseases.  But if a condition is considered embarrassing, people are less likely to publicly associate themselves with it…  I have actually spent the past five years peeking into people’s insides.  I have been studying aggregate Google search data.  Alone with a screen and anonymous, people tend to tell Google things they don’t reveal to social media; they even tell Google things they don’t tell to anybody else.  Google offers digital truth serum.  The words we type there are more honest than the pictures we present on Facebook or Instagram…  As our lives increasingly move online, I propose a new self-help mantra for the 21st century, courtesy of big data: Don’t compare your Google searches with other people’s Facebook posts.”


Towards automated lawyers!
AI Closes In On The Work Of Junior Lawyers
Chances are if you’re a paralegal or a junior lawyer entering the field, you’d rather spend your time doing other things than scanning documents for clients’ names or other mundane information.  New artificial intelligence systems designed specifically for law firms can help remedy that situation by automating some of these lower-level jobs.
Why it matters: Although some entry-level paralegal jobs could be replaced by automation, AI systems cannot replicate the creativity, empathy, and argumentative reasoning required of a lawyer — so your lawyer won’t be replaced by a robot any time soon.  Furthermore, these AI advancements could open new, more fulfilling opportunities for aspiring lawyers to break into the field in a role that is more closely aligned to what they would do in the court room or when working with clients.
What’s next: Deloitte predicts 116,000 legal jobs will be lost to automation in the next 20 years.


Jeff Bezos scores another win.
Amazon is Dominating The Voice-Assisted Speaker Market
   The e-commerce giant has a 70% share of the emerging voice-controlled speaker market compared to 23.8% for rival Google, research firm eMarketer said on Monday.
Amazon's huge lead puts it in a strong position in a fast growing business.  In addition to making money from selling the devices, Amazon also benefits from Echo users buying more products from the company's marketplace.


Will California be next?
India plans to prioritize electric vehicles over hybrids
India’s most influential government think-tank has recommended lowering taxes and interest rates for loans on electric vehicles, while capping sales of conventional cars, signalling a dramatic shift in policy in one of the world’s fastest growing auto markets.
A draft of the 90-page blueprint, seen by Reuters, also suggests the government opens a battery plant by the end of 2018 and uses tax revenues from the sale of petrol and diesel vehicles to set up charging stations for electric vehicles.
   It would also mark a radical response by India as it looks to cut its oil import bill to half by 2030 and reduce emissions as part of its commitment to the Paris climate treaty.


Perspective.  And because I follow this market, thirstily.
Salud! Mexico Passes Germany in World Beer Market Share: Chart


Perspective.  ‘cause we gotta follow stuff like this?  Something for my next statistics class?
People Are Liking Trump’s Tweets Less
The tweets posted by @realDonaldTrump, the account Trump has used personally, are now notching fewer “likes” now than those from January.  Sixty-two percent of Trump’s tweets posted in the first 50 days of his term amassed more than 100,000 likes, according to a Bloomberg analysis.  Just 10 percent of his tweets over the following 51 days crossed that threshold.

(Related).  I don’t think so.
The Case for a Taxpayer-Supported Version of Facebook
“A public social media platform would have the civic mission of providing us a diverse and global view of the world.”  [I’m not sure we are ready for that.  Bob] 
   My colleague Yochai Benkler and I recently offered a different explanation for Trump’s election.  With our teams at Harvard and MIT, we analyzed 1.25 million news stories, using hyperlinks and mentions on Twitter and Facebook to map the ecosystem of campaign media.  We discovered that while left and centrist voters relied heavily on traditional media to understand the election, the dominant source of information shared by right-wing voters on Facebook and Twitter was Breitbart, which anchored a media ecosystem of new, online-only outlets that mixed propaganda and conspiracy theory with partisan news.


Would a really diverse (and divisive) field guarantee Trump’s reelection?  Note that Mark Zuckerberg is mentioned…
The 7 Signs That Someone Might Be Running For President In 2020


Dilbert points out one downside of true AI.

Sunday, May 07, 2017

“You can fool all of the people some of the time.” 
As long as humans have access to email, phishing will work
   Last week, countless Gmail users across the internet received the same phishing email at the same time, inviting them to click a link to a Google Doc.  All of the emails seemed to come from someone the recipients knew.  When they clicked the link, then clicked again on a dialogue box asking them to allow access to “Google Docs,” their full contacts list was used to send the same phishing email to even more people.  It’s not yet clear whether the attack also installed malware once the link was clicked.
   one study shows that, even when warned about the perils of phishing multiple times, people will keep clicking those links.
The study was conducted in 2012 at Columbia University. Researchers sent 2,000 phishing emails to students, faculty, and staff at the school.  Some contained offers for free Apple iPads, others came with PDF attachments, and some asked the recipients to provide their login credentials.  The iPad promotion was the most successful, and in the first round of emails, 176 recipients opened the emails and clicked the links within.
Those 176 people were then warned that they’d fallen for a phishing attack, and told to not let it happen again.  A few weeks later, the researchers sent another round of phishing emails to those same people, and 10 of them let it happen again.  After another warning, and a third batch of phishing emails was sent out, three people fell for it again.  It wasn’t until the fourth round that no one opened the emails.


Can Facebook close accounts as fast as my computer can add them? 
Gannett seeks FBI probe into fake Facebook followers
Gannett Co., the company that owns USA Today and more than 100 other local media organizations, has asked the FBI to investigate a slew of fake Facebook accounts that followed the newspaper on the social media site.
The presence of fake accounts was so large that it accounted for half of USA Today's Facebook followers, amounting to millions of accounts, according to the newspaper.
The request is the latest chapter in Facebook's ongoing battle against phony users, accused of spreading spam and fake news articles.
   While fake accounts appear all over Facebook, it is not clear why USA Today was the target of particularly large numbers of phony users.  [More gullible or Trump voters?  Bob] 


A new term for me, but one that seems easier to understand.  
Credit Karma: Believe the hype for ‘artificial narrow intelligence’
By giving away free credit scores to more than 60 million people, Credit Karma upended the paid credit report market.  And by offering free tax returns this year — at the same time H&R Block and IBM Watson were bragging about AI-powered tax filings — the company stormed the $8.9 billion tax preparation industry.  Bold disruptions like this matter, but Credit Karma’s effort to quietly assemble the massive trove of information underpinning each of these moves may be even bolder.
Credit Karma works like this: Members supply personal information (name, address, phone, social security number) to receive credit scores and, if desired, to be matched with the best credit card, personal loan, and auto loan offers, and to file their federal income taxes — all for free.  The company gets paid a commission by the credit card and loan issuers, and it vows it will never charge consumers.  
   According to Graciano, the company is able to serve consumers up-to-the-minute recommendations for their financial decisions within 20 milliseconds.  And to do this, the service relies not on general artificial intelligence (AI) but on artificial narrow intelligence (ANI).
   “AI is definitely over-hyped.  The promise of AI is generalizable intelligence, the ability to not only learn but to reason, to pattern match, to interact, and I think what we have today is best described as artificial narrow intelligence.  ANI is actually amazing and deserving of the hype,” Graciano said, adding that ANI is “very good at one very specific thing in a probabilistic fashion.”  This means things like identifying a cat, but also instances where there is a big set of data coming in and one specific output coming out.  “ANI is transformational to do your business if you use it correctly,” Graciano said.  

(Related).  Clearly, Dilbert needs better AI.

(Related).  The traditional definition of AI.
Google’s AI Plan Could Make The Co World’s Most Powerful Entity
London-based brain-tech company DeepMind was founded in 2010 and acquired by Google in 2014 for more than $500 million.  Right now, DeepMind has over 400 research engineers and scientists, more than 250 of them with PhDs, making this pool of human resources arguably the most formidable collection of scientific brain power focused on a single subject: artificial intelligence.
The company’s mission involves a two-step process.  First, they intend to solve intelligence by understanding natural intelligence, then recreating it artificially.  Second, they intend to use AI to solve everything else.


Can my students explain how to do this profitably?  You can bet I’ll ask them. 
Google and Uber are learning money can’t buy them victory in India’s brutal food-delivery wars
   Many of the nascent companies that set up shop during food tech’s heyday in 2014 could not deal with growing pains and started falling like dominoes in 2015
   In 2016, the bloodbath continued.  Food tech investments plummeted from $500 million in 2015 to $80 million.  Consolidation became the flavor of the season
   This year, as food tech strives to get back on its feet, two Silicon Valley behemoths—Google and Uber—have chosen to dance in the rain in India: Google launched Aero, a restaurant delivery and home services platform, in early April.  Uber followed suit on May 2, announcing that its on-demand food-delivery arm UberEATS was going live.
The question is, will they ride the waves or will they go under?


See students?  Warren Buffett agrees with me.
Warren Buffett Identifies What Went Wrong at Wells Fargo
How does a company that's had a sterling reputation since the California Gold Rush in the 1850s sully its image after more than a century and a half of prudent and profitable operations?
The answer in the case of Wells Fargo, says Warren Buffett, is a combination of hubris and procrastination.
"At Wells Fargo, there were three very significant mistakes, but there was one that dwarfs all the others," said Buffett at Berkshire Hathaway's annual shareholder meeting.  "At some point if there's a major problem, the CEO gets wind of it, and the CEO has to act.  They didn't act when they learned about it."


No political aspirations?  Learning from the failure of others?
Facebook’s Zuckerberg has spoken with Trump numerous times on the phone: report
   He criticized the president's executive orders on immigration, saying in January he is "concerned" about the impact of recent executive orders signed by the president.  The president's travel ban was unpopular with many firms in Silicon Valley.
“We need to keep this country safe, but we should do that by focusing on people who actually pose a threat," he said in a post.

Saturday, May 06, 2017

Perhaps my Computer Security students could offer a few suggestions?  It looks like we should expect something similar in all future elections. 
Emmanuel Macron's campaign hacked on eve of French election
The French presidential candidate Emmanuel Macron has been targeted by a “massive and coordinated” hacking attack just hours before voters go to the polls, according to his campaign team.
Macron, who opinion polls suggest should win Sunday’s vote by 60% to his rival Marine Le Pen’s 40%, was unable to respond to the alleged attack because of a ban on electioneering in the run up to the opening of polling stations.
Tens of thousands of internal emails and other documents, some said to be false, were released online overnight on Friday as the midnight deadline to halt campaigning passed.
   On Saturday morning, France’s presidential electoral authority, the CNCCEP, asked the media to avoid publishing information from the leaked documents and reminded them of their responsibilities given the seriousness of the election.
“The publishing of false information falls under the law, particularly criminal law,” it wrote.
Neither candidate could comment on the hacking because of the ban on communications and polls before the polling stations open at 8am on Sunday.
   Around nine gigabytes of data was posted by a user called EMLEAKS to the document-sharing site Pastebin that allows anonymous posting.  It was not immediately clear who was responsible.
   The En Marche! statement said the data consisted of “diverse documents, such as emails, accounting documents and contracts” hacked several weeks ago from the personal and professional accounts of some of the movement’s staffers.

(Related). 
Illinois Public Radio reports:
The State Board of Elections says hackers gained access to the information of 80-thousand Illinois voters — including their social security numbers and driver’s licenses.
Elections officials say hackers had access to Illinois’ system for nearly three weeks before they were detected.  They did get access to personal information, but officials say that’s about it. [So, no big deal?  Bob] 
Senator Michael Hastings from Tinley Park says the source of the breach matches an address the FBI has linked to Russian state security.  He says future elections could be in danger.
Read more on WSIU.
[From the article: 
“I don’t know why they selected Illinois.  Perhaps they tried other states and weren’t able to get in, they just happened to find the hole in our dike, so to speak.”  [Perhaps they looked at every state and your site was the easiest to breach?  Bob] 

(Related).
Germany challenges Russia over alleged cyberattacks,
The head of Germany's domestic intelligence agency accused Russian rivals of gathering large amounts of political data in cyber attacks and said it was up to the Kremlin to decide whether it wanted to put it to use ahead of Germany's September elections.
Moscow denies it has in any way been involved in cyber attacks on the German political establishment.


Jobs for my Computer Security students?
Growth in Cyber Fraud Attacks Outpacing Growth of Transactions: Report
The United States is the world's primary target for cyber fraud attacks.  Europe has emerged as the major source of attacks, now accounting for 50% more attacks than the US.  The growth in attacks is outpacing the growth of transactions; and in a 90-day period, 130 million fraud attacks were detected.
These details come from the ThreatMetrix Cybercrime Report Q1 2017 (PDF).


One possible Computer Security future.
Security automation is maturing, but many firms not ready for adoption
The security automation industry is still in its infancy, with most vendors just a year or two old, but there are already some promising technologies that enterprises can put to use -- if they have already laid the required ground work.
   According to a survey the research firm conducted last fall, 91 percent of companies said that the time and effort required for manual processes limits their incident response effectiveness, and the same number are actively trying to increase their staffs.
   "Two years ago, nobody knew about this technology," said Oltsik.  "Last year, I saw it a lot more.  Now we're seeing budget line items for it, and we also see a lot of venture capitalist investment in this space as well."
   "It's definitely not a buy it and plug it in scenario," he said.  "There's definitely ground work that needs to be done.  If you plug bad data into an automated system, all you're going to do is make bad decisions faster."
In addition, many companies don't actually know what their processes are, and may not yet have well-defined playbooks, he said.


Interesting.  Perhaps people do care about ethics?
Office of Government Ethics now handling voluminous info requests from public
by Sabrina I. Pacifici on May 5, 2017
Quartz – “Trump’s administration has been widely criticized for its lack of transparency, and demands for information from the public, press, and Congress have gone through the roof.  The OGE has already received five times the amount of Freedom of Information (FOIA) requests that they usually get in a full fiscal year—with five months left to go…  Trump has claimed that his refusal to comply with ethics norms like releasing his tax returns are issues that only journalists “care about.”  However, an NPR analysis of inquiries to the OGE found that phone calls from the public, not FOIAs from media agencies, increased the most—calls were up more than 5,000% this fiscal year compared to the average since 2009.  On top of that, there have been almost six times the usual number of requests for information from members of Congress, NPR reported.”


Now I believe AI is ubiquitous.
How to get Google’s artificial intelligence on the Raspberry Pi
   Google has teamed up with the Raspberry Pi foundation to create a new hardware add-on for Raspberry Pi called the ‘Voice Kit’.


Voice Kit is a fully open source reference project that includes Voice Hardware Accessory on Top (HAT) which contains electronics components for audio capture and playback, connectors for the dual mic daughter board and speaker, GPIO pins to connect low-voltage components like micro-servos and sensors, and an optional barrel connector for dedicated power supply.
   Those who are more ambitious can also run Android Things on the Voice Kit, turning it into a fully functional prototype to build their own commercial IoT products.
   If you want the kit, Google is giving it away with the latest issues of MagPi magazine.  If you don’t want to subscribe to the magazine, you can sign-up for the waiting list to just get the hardware unit from Google.



Perhaps my Computer Security students could offer a few suggestions?  It looks like we should expect something similar in all future elections. 
Emmanuel Macron's campaign hacked on eve of French election
The French presidential candidate Emmanuel Macron has been targeted by a “massive and coordinated” hacking attack just hours before voters go to the polls, according to his campaign team.
Macron, who opinion polls suggest should win Sunday’s vote by 60% to his rival Marine Le Pen’s 40%, was unable to respond to the alleged attack because of a ban on electioneering in the run up to the opening of polling stations.
Tens of thousands of internal emails and other documents, some said to be false, were released online overnight on Friday as the midnight deadline to halt campaigning passed.
   On Saturday morning, France’s presidential electoral authority, the CNCCEP, asked the media to avoid publishing information from the leaked documents and reminded them of their responsibilities given the seriousness of the election.
“The publishing of false information falls under the law, particularly criminal law,” it wrote.
Neither candidate could comment on the hacking because of the ban on communications and polls before the polling stations open at 8am on Sunday.
   Around nine gigabytes of data was posted by a user called EMLEAKS to the document-sharing site Pastebin that allows anonymous posting.  It was not immediately clear who was responsible.
   The En Marche! statement said the data consisted of “diverse documents, such as emails, accounting documents and contracts” hacked several weeks ago from the personal and professional accounts of some of the movement’s staffers.

(Related). 
Illinois Public Radio reports:
The State Board of Elections says hackers gained access to the information of 80-thousand Illinois voters — including their social security numbers and driver’s licenses.
Elections officials say hackers had access to Illinois’ system for nearly three weeks before they were detected.  They did get access to personal information, but officials say that’s about it. [So, no big deal?  Bob] 
Senator Michael Hastings from Tinley Park says the source of the breach matches an address the FBI has linked to Russian state security.  He says future elections could be in danger.
Read more on WSIU.
[From the article: 
“I don’t know why they selected Illinois.  Perhaps they tried other states and weren’t able to get in, they just happened to find the hole in our dike, so to speak.”  [Perhaps they looked at every state and your site was the easiest to breach?  Bob] 

(Related).
Germany challenges Russia over alleged cyberattacks,
The head of Germany's domestic intelligence agency accused Russian rivals of gathering large amounts of political data in cyber attacks and said it was up to the Kremlin to decide whether it wanted to put it to use ahead of Germany's September elections.
Moscow denies it has in any way been involved in cyber attacks on the German political establishment.


Jobs for my Computer Security students?
Growth in Cyber Fraud Attacks Outpacing Growth of Transactions: Report
The United States is the world's primary target for cyber fraud attacks.  Europe has emerged as the major source of attacks, now accounting for 50% more attacks than the US.  The growth in attacks is outpacing the growth of transactions; and in a 90-day period, 130 million fraud attacks were detected.
These details come from the ThreatMetrix Cybercrime Report Q1 2017 (PDF).


One possible Computer Security future.
Security automation is maturing, but many firms not ready for adoption
The security automation industry is still in its infancy, with most vendors just a year or two old, but there are already some promising technologies that enterprises can put to use -- if they have already laid the required ground work.
   According to a survey the research firm conducted last fall, 91 percent of companies said that the time and effort required for manual processes limits their incident response effectiveness, and the same number are actively trying to increase their staffs.
   "Two years ago, nobody knew about this technology," said Oltsik.  "Last year, I saw it a lot more.  Now we're seeing budget line items for it, and we also see a lot of venture capitalist investment in this space as well."
   "It's definitely not a buy it and plug it in scenario," he said.  "There's definitely ground work that needs to be done.  If you plug bad data into an automated system, all you're going to do is make bad decisions faster."
In addition, many companies don't actually know what their processes are, and may not yet have well-defined playbooks, he said.


Interesting.  Perhaps people do care about ethics?
Office of Government Ethics now handling voluminous info requests from public
by Sabrina I. Pacifici on May 5, 2017
Quartz – “Trump’s administration has been widely criticized for its lack of transparency, and demands for information from the public, press, and Congress have gone through the roof.  The OGE has already received five times the amount of Freedom of Information (FOIA) requests that they usually get in a full fiscal year—with five months left to go…  Trump has claimed that his refusal to comply with ethics norms like releasing his tax returns are issues that only journalists “care about.”  However, an NPR analysis of inquiries to the OGE found that phone calls from the public, not FOIAs from media agencies, increased the most—calls were up more than 5,000% this fiscal year compared to the average since 2009.  On top of that, there have been almost six times the usual number of requests for information from members of Congress, NPR reported.”


Now I believe AI is ubiquitous.
How to get Google’s artificial intelligence on the Raspberry Pi
   Google has teamed up with the Raspberry Pi foundation to create a new hardware add-on for Raspberry Pi called the ‘Voice Kit’.


Voice Kit is a fully open source reference project that includes Voice Hardware Accessory on Top (HAT) which contains electronics components for audio capture and playback, connectors for the dual mic daughter board and speaker, GPIO pins to connect low-voltage components like micro-servos and sensors, and an optional barrel connector for dedicated power supply.
   Those who are more ambitious can also run Android Things on the Voice Kit, turning it into a fully functional prototype to build their own commercial IoT products.
   If you want the kit, Google is giving it away with the latest issues of MagPi magazine.  If you don’t want to subscribe to the magazine, you can sign-up for the waiting list to just get the hardware unit from Google.