Monday, May 06, 2019




...and so it begins. Note that you need to be near the actors to attack them directly. That does not mean you ignore allies or associates who are within reach.
https://www.forbes.com/sites/kateoflahertyuk/2019/05/06/israel-retaliates-to-a-cyber-attack-with-immediate-physical-action-in-a-world-first/
Israel Retaliates To A Cyber-Attack With Immediate Physical Action In A World First
The Israel Defense Forces (IDF) has launched a physical attack on Hamas in immediate response to an alleged cyber-assault. The IDF hit a building in the Gaza Strip with an airstrike after claiming the site had been used by Hamas cyber operatives to attack Israel’s cyber space.
The IDF claimed it stopped the attack online before launching its airstrike on Hamas. It claims it has now wiped out Hamas’ cyber operational capabilities.
It could mark a change in modern cyber warfare tactics, given that it is the first time a cyber-attack has been met with immediate physical retaliation. However, as ZDNet points out, the US is still the first country to respond to cyber-attacks with military force. In 2015, the nation launched a drone strike to kill the British national in charge of ISIL's hacker groups Junaid Hussain. Hussain had also dumped personal details of US military forces online.
But Ian Thornton-Trump, security head at AmTrust Europe says: “Israel would not have targeted the building and presumably those in it without a lot more due diligence and intelligence than ‘a cyber-attack was coming from the building’."
He points out that in the ISTAR (intelligence, surveillance, target acquisition and reconnaissance) process, the target would be developed and verified with “additional and quite likely non-cyber information”.
He adds: “Part of military strategy involves making the enemy believe you have overwhelming capabilities: it’s part psyops and a good strategy.”
… “Aside from this particular incident, it also sends a clear message to any state or non-state actor that threats promulgated through cyberspace can and will be met with a physical response if appropriate. This is an inevitable escalation against a very real threat.”
Ingram points out that operations in cyber space “are not governed by the rules of warfare”. However, the Geneva protocols and international law do cover a response occurring in the physical domain. “There have been attempts to bring in rules for cyber warfare with the Tallinn Manual on the International Law applicable to Cyber Warfare, but this has not been ratified or adopted by any nation or multinational organization.”






I wonder if anyone asked how much they had spent (or budgeted) on Computer Security?
Cyber-attack threat is costly for Modesto schools. The total estimate may surprise you.
Ken Carlson reports:
The costs of combating a recent cyber attack and securing computer services against further attacks will easily exceed $1 million for Sylvan Union School District.
According to a budget study in April, the Modesto school district amassed $475,700 in costs in eradicating two cyber-attack viruses that took down essential services in the district with 10 elementary schools and three middle schools. Staff and teachers lost connection to cloud-based data, networks and educational platforms that use the school district’s Internet connection.
Read more on Modesto Bee.






Useful?
https://teachprivacy.com/anatomy-of-a-privacy-law/

Anatomy of a Privacy Law

I was recently giving a presentation about new privacy laws, and I created the infographic above to catalog the various elements that privacy laws often have.






How many people does it take to read all the posts to Facebook in near real time? See why they are working on AI?

https://www.reuters.com/article/us-facebook-ai/facebook-labels-posts-by-hand-posing-privacy-questions-idUSKCN1SC01T
Facebook 'labels' posts by hand, posing privacy questions
Over the past year, a team of as many as 260 contract workers in Hyderabad, India has ploughed through millions of Facebook Inc photos, status updates and other content posted since 2014.






Perhaps we don’t need the Russians to spread ‘fake news.’
https://www.bespacific.com/study-major-media-outlets-twitter-accounts-amplify-false-trump-claims-on-average-19-times-a-day/
Study: Major media outlets’ Twitter accounts amplify false Trump claims on average 19 times a day
Media Matters: “Major media outlets failed to rebut President Donald Trump’s misinformation 65% of the time in their tweets about his false or misleading comments, according to a Media Matters review. That means the outlets amplified Trump’s misinformation more than 400 times over the three-week period of the study — a rate of 19 per day. The data shows that news outlets are still failing to grapple with a major problem that media critics highlighted during the Trump transition: When journalists apply their traditional method of crafting headlines, tweets, and other social media posts to Trump, they end up passively spreading misinformation by uncritically repeating his falsehoods. The way people consume information in the digital age makes the accuracy of a news outlet’s headlines and social media posts more important than ever, because research shows they are the only thing a majority of people actually read. But journalists are trained to treat a politician’s statements as intrinsically newsworthy, often quoting them without context in tweets and headlines and addressing whether the statement was accurate only in the body of the piece, if at all. When the politician’s statements are false, journalists who quote them in headlines and on social media without context end up amplifying the falsehoods...






Is it wise to ask the DHS to train people with no Computer Security skills or would it be smarted for the campaigns to hire people with Computer Security skills?
https://www.securityweek.com/2020-campaign-staffers-being-trained-handle-cyber-threats
2020 Campaign Staffers Being Trained to Handle Cyber Threats
Whether presidential campaigns have learned from the cyberattacks is a critical question ahead as the 2020 election approaches. Preventing the attacks won’t be easy or cheap.
… Mook has been helping develop a plan for a nonprofit to provide cybersecurity support and resources directly to campaigns.
The Department of Homeland Security’s cyber agency is offering help, and there are signs that some Democratic campaigns are willing to take the uncomfortable step of working with an administration they are trying to unseat.
Candidates can get some advice from the Republican and Democratic national committees, which are in regular contact with Homeland Security and focus on implementing basic security protocols.
The relative ease with which Russian agents penetrated computers underscores the perilous situation facing campaigns. Clinton has been talking about this with Democratic presidential candidates.
Unless we know how to protect our election from what happened before and what could happen again ... you could lose,” Clinton said in a MSNBC interview. “I don’t mean it to scare everybody. But I do want every candidate to understand this remains a threat.”






I’ve never heard of MindGeek. Looks like I need to do some extensive research…
https://www.nytimes.com/2019/05/03/style/britain-age-porn-law.html
How the U.K. Won’t Keep Porn Away From Teens
Come July 15, 2019, internet users in Britain attempting to visit major pornography sites will be confronted with a question: How old are you? Then, a follow-up: Can you prove it?
They’ll have a few options. Users can verify their age online, by submitting official government IDs or credit card information. Or they can walk into a store and establish their eligibility to access porn the old-fashioned way: by handing money and identification over to a human being, at a participating store, in exchange for a pass.
The British government has touted its mandatory age check as a “world-first” that will help make Britain the “safest place in the world to be online,” particularly for children. It has been less vocal about the precise manner in which these rules will be enforced. Just a few months out, and after multiple embarrassing delays, this is very much a work in progress.
What is taking shape is an enforcement regime made up not just of actual regulators and quasi-regulators but also major pornographers. It is a system that may not only fail to accomplish the law’s stated purpose (to keep children from stumbling upon adult content), but which also risks being captured by the biggest name in online porn, a multinational streaming conglomerate called MindGeek.






More on Amazon architecture (logistics) Have the been deliberately slowing their delivery?
https://www.cnbc.com/2019/05/05/amazon-can-already-ship-to-72percent-of-us-population-in-a-day-map-shows.html
Amazon can already ship to 72% of US population within a day, this map shows
Amazon is already capable of offering same-day and next-day delivery to 72% of the total U.S. population, including almost all of the households (95% or more) in 16 of the wealthiest and most populated states and Washington, D.C., according to a report published in March by RBC Capital Markets.






Perspective.
https://www.cnbc.com/2019/05/06/apple-buys-a-company-every-few-weeks-says-ceo-tim-cook.html

Apple buys a company every few weeks, says CEO Tim Cook





Sunday, May 05, 2019


Our technology is more fragile than we realize.
Mystery in North Olmsted solved: Source of key fob, garage opener problems identified
After weeks of speculation, sleepless nights and confusion, the mystery of the key fob and garage door opener problems in North Olmsted has been solved.
The cause was a custom, man-made device inside a resident’s home.
So as to not identify the homeowner, Glassburn would only say it is a notification system which allows the resident to know if there is movement in the house/someone is in the house.
There is no malicious intent of the device, Glassburn noted.
Glassburn and Bill Hertzel, a retired communication employee, found the device after a resident agreed to allow them inside a home.
The device, which ran on a battery backup, was identified and disabled,” Glassburn wrote in a statement. “There will be no further interference and the resident has agreed to not make such devices in the future.




Should it be personal?
Facebook Faces a Big Penalty, but Regulators Are Split Over How Big
The F.T.C. chairman seems to have the votes to approve a settlement. One of the biggest issues has been whether to hold Mark Zuckerberg liable for future violations.
Along with disagreement about the appropriate financial penalty, one of the most contentious undercurrents throughout the negotiations has been the degree to which Mark Zuckerberg, Facebook’s chief executive, should be held personally liable for any violation of a 2011 agreement, according to two of the people.
… “This is a hugely important decision because it will be watched by all these big companies to see if there is actually going to be a new day on the enforcement front,” said Senator Ron Wyden, an Oregon Democrat who has pushed for Mr. Zuckerberg to be held personally liable in any settlement.
But the settlement probably won’t include limits on Facebook’s ability to track users and share data with its partners, mandates that privacy advocates have raised as important for regulation in the United States, and that Facebook has fought. Mr. Simons has argued that the settlement proposal sets a new bar for enforcement of privacy violations and wants to avoid litigation that risks losing that opportunity.




Does the existence of the GDPR change the environment enough to encourage this type of lawsuit?
Verizon, T-Mobile, Sprint, and AT&T Hit With Class Action Lawsuit Over Selling Customers’ Location Data
On Thursday, lawyers filed lawsuits against four of the country’s major telecommunications companies for their role in various location data scandals uncovered by Motherboard, Senator Ron Wyden, and The New York Times. Bloomberg Law was first to report the lawsuits.
The news provides the first instance of individual telco customers pushing to be awarded damages after Motherboard revealed in January that AT&T, T-Mobile, and Sprint had all sold access to the real-time location of their customers’ phones to a network of middlemen companies, before ending up in the hands of bounty hunters.
Through its negligent and deliberate acts, including inexplicable failures to follow its own Privacy Policy, T-Mobile permitted access to Plaintiffs and Class Members’ CPI and CPNI,” the complaint against T-Mobile reads, referring to “confidential proprietary information” and “customer proprietary network information,” the latter of which includes location data.




Perspective. As a non-lawyer, I need all the perspective I can get. Could this just be jealousy?
The push to break up Big Tech, explained
There’s a pervasive feeling that the tech giants are too powerful ... but they’re also really good for consumers.
Technology companies based in Seattle or Silicon Valley now account for five out of the five most valuable companies in America, leading to a spate of commentary last year from lawyers like Columbia’s Tim Wu to economists like Harvard’s Kenneth Rogoff arguing that Big Tech has, in some sense, gotten “too big.” And in 2019, politicians are starting to listen.




Even academics can write interesting papers.
Teaching AI, Ethics, Law and Policy
The cyberspace and the development of new technologies, especially intelligent systems using artificial intelligence, present enormous challenges to computer professionals, data scientists, managers and policy makers. There is a need to address professional responsibility, ethical, legal, societal, and policy issues. This paper presents problems and issues relevant to computer professionals and decision makers and suggests a curriculum for a course on ethics, law and policy. Such a course will create awareness of the ethics issues involved in building and using software and artificial intelligence.
… 6.1 Why to Teach Ethics?
Following are justifications to teach ethics: (1) Employers are not looking only for technical skills but they prefer to hire persons with good soft skills that include work ethics and responsibility. (2) Many cases of unethical behavior suggest that ethics education is important. (3) Law develops slower than new technologies and often does not provide a solution to many dilemmas. Law presently has difficulties to assign responsibility for problems that emerge from software. (4) Acts can be legal, but not appropriate from an ethical point of view (5) Ethics provides tools helping to make better decisions for the benefit of a person and society.



Saturday, May 04, 2019


The unexpected costs of acquiring a company with poor security.
Kevin Martin reports:
The massive data hack of guest information from the Marriott hotel empire has triggered a $100-million class action lawsuit in Calgary.
A statement of claim filed in Calgary Court of Queen’s Bench says the data breach in which hackers accessed records on as many as 500 million hotel guests was due to the chain’s lack of adequate security.
The defendants knew or ought to have known that their databases were vulnerable to loss or theft,” says the claim, filed by Calgary lawyer Clint Docken and Edmonton counsel James Brown.
Read more on Calgary Sun.




Does this reduce their liability? Should they be required to pay ransom?
IT service provider refuses to pay ransom, hackers publish stolen data online
In a statement posted high on its official web site, CityComp publicly admits it fell victim to a “targeted cyberattack” sometime last month, and while the company has since fended off the hackers, customer data unfortunately got leaked.
A still unknown perpetrator has stolen customer data of CITYCOMP and threatened the company with publication, should it not comply with the blackmail attempt,” the company states.
… “Since CITYCOMP does not comply with blackmail the publication of customer data could not be prevented,” the notice continues. “The stolen data has now been published by the perpetrators and CITYCOMP’s customers were informed about it.”
Many of CityComp’s clients are located in the European Union, which means the company should brace for GDPR impact.




Interesting. I might have to tweak my Computer Security curriculum to reflect some of these requirements. (Probably not.)
Oh, I missed something yesterday. President Trump signed an Executive Order on America’s Cybersecurity Workforce. I can’t find it in the Federal Register yet, but you can read it here.




Let’s turn off the alarms!” a Hollywood cliche.
Design Flaws Create Security Vulnerabilities for ‘Smart Home’ Internet-of-Things Devices
Researchers at North Carolina State University have identified design flaws in “smart home” Internet-of-Things devices that allow third parties to prevent devices from sharing information. The flaws can be used to prevent security systems from signaling that there has been a break-in or uploading video of intruders.
… “Essentially, the devices are designed with the assumption that wireless connectivity is secure and won’t be disrupted – which isn’t always the case,” says Bradley Reaves, co-author of the paper and an assistant professor of computer science at North Carolina State. “However, we have identified potential solutions that can address these vulnerabilities.”
… “One reason these attacks are so problematic is that the system is telling homeowners that everything is OK, regardless of what’s actually happening in the home,” Enck says.
These network layer suppression attacks are possible because, for many IoT devices, it’s easy to distinguish heartbeat signals from other signals. And addressing that design feature may point the way toward a solution.
One potential fix would be to make heartbeat signals indistinguishable from other signals, so malware couldn’t selectively allow heartbeat signals to pass through,” says TJ O’Connor, first author of the paper and a graduate student at North Carolina State.
The paper, “Blinded and Confused: Uncovering Systemic Flaws in Device Telemetry for Smart-Home Internet of Things,” will be presented at the 12th ACM Conference on Security and Privacy in Wireless and Mobile Networks being held May 15-17 in Miami, Fla.




Welcome to ‘Big Brother Net.’
Russia's new internet law presents a cybersecurity minefield for global enterprises
A new measure signed into law this week by Russian President Vladimir Putin that would enable the country to create its own internet network, independent from the rest of the world and regulated by national telecom agency Roskomnadzor (RKN), should give corporate executives around the pause about the cybersecurity implications of doing business in the country moving forward. As part of the maneuver, Russia has also demanded 10 of the top providers of Virtual Private Networks (VPNs) to connect to a state content-filtering system or be banned from operating in the country.
According to Francis Dinha, CEO of OpenVPN, one of the aforementioned VPN providers facing a ban by the Russian government, companies with remote workers in the country that need to access sensitive information from their homes offices in the U.S., Europe or elsewhere will have to rethink their security approach moving forward as authorities will have the ability surveil any data being transmitted through the new network.




A GDPR oops!
HMRC to delete five million biometric voice records
The UK's tax authority is to delete the biometric voice records of five million people because it did not have clear consent from its customers to have those files.
HM Revenue and Customs (HMRC) uses the Voice ID biometric voice security system to make it easier for callers to pass its security processes when discussing their account. It says using the system will reduce the time it takes to speak to an advisor and will help prevent anyone else accessing accounts.
But the UK's data privacy watchdog the Information Commissioners Office (ICO) said that HMRC failed to give customers sufficient information about how their biometric data would be processed and failed to give them the chance to give or withhold consent. "This is a breach of the General Data Protection Regulation," the ICO said.




I’ll look for the new ToS June 29th at 11:59:59 PM
European Commission Forces Changes to Facebook Terms of Service
In yet another victory for privacy advocates, the European Commission (EC) has forced social media giant Facebook to amend its terms of service in order to accurately reflect how the company makes money by selling user data. The Facebook terms of service, once obfuscated by complicated, legalistic language, are now going to state very clearly that Facebook provides its services free of charge to consumers in return for the agreement that their personal data will be shared with third parties and used for targeted advertising. According to the agreement reached between the European Commission, European consumer protection authorities and Facebook, the Silicon Valley giant will have until June 30 to implement the new changes.




Perspective. Could Denver privatize RTD? Brobably not, but Leadville could.
Uber Was Supposed To Be Our Public Transit’
In 2017, the growing Toronto exurb of Innisfil, Ontario, became one of the first towns in the world to subsidize Uber rides in lieu of a traditional bus. Riders could pay a flat fare of just $3-$5 to travel to community hubs in the backseat of a car, or get $5 off regular fares to other destinations in and around town.
People loved it. By the end of the Uber program’s first full year of service, they were taking 8,000 trips a month.
Now “Innisfil Transit” is changing its structure. As of April 1, flat fares for the city-brokered Ubers rose by $1. Trip discounts dropped to $4, and a 30-ride monthly cap was implemented. Town leaders say this will allow Innisfil to continue to cover costs.
But Hudson and others see the changes as harmful, and a strange way of declaring success.



Friday, May 03, 2019


Hacking wholesale. Weaponized hacking?
A MYSTERIOUS HACKER GROUP IS ON A SUPPLY CHAIN HIJACKING SPREE
A software supply chain attack represents one of the most insidious forms of hacking. By breaking into a developer's network and hiding malicious code within apps and software updates that users trust, supply chain hijackers can smuggle their malware onto hundreds of thousands—or millions—of computers in a single operation, without the slightest sign of foul play. Now, what appears to be a single group of hackers has managed that trick repeatedly, going on a devastating supply chain spree—and becoming more advanced and stealthy as they go.
Over the last three years, supply chain attacks that exploited the software distribution channels of at least seven different companies have now all been tied to a single group of likely Chinese-speaking hackers.
The technique disturbs security researchers not only because it demonstrates Barium's ability to disrupt computers on a vast scale, but also because it exploits vulnerabilities in the most basic trust model governing the code users run on their machines.


(Related) Preparing to weaponize?
Zack Whittaker reports:
A denial-of-service attack launched against an energy company providing power in several western U.S. states was enough to report “interruptions of electrical system operations” to the government’s energy authority.
The “cyber event” lasted almost 10 hours on March 5, according to an electric emergency and disturbance report filed with the Department of Energy by the affected company.
Read more on TechCrunch.
Meanwhile, in India, energy has also been under attack.  The Hans Indireports:
Khairatabad: The official website of Telangana State Power Distribution Corporation Limited (TSSPDCL) was hacked on Thursday. The electricity officials lodged a complaint in this regard with Central Crime Station – Cybercrime police. Cybercrime Additional DCP Raghuveer said that an FIR was registered under sections 65 and 66, based on the complaint received from CGM of Electricity IT department. The hackers after deleting the data from the official website demanded Rs 35 crore to give back the data, the electricity officials said.
Read more on The Hans India.




Background.
FBI Annual Internet Crime Report: $2.7 Billion in Losses Headlined by Non-Payment Scams, Business Email Compromise
The FBI’s Internet Crime Report, which provides data on the agency’s complaints and cases for the previous year, has been released. This annual report is prepared by the bureau’s Internet Crime Complaint Center (IC3), and is always a worthwhile read as it helps to identify trending patterns in cybersecurity. This year’s report reveals that the IC3 received nearly 352,000 complaints in 2018, with the most common type being a non-payment or non-delivery scam. However, the most financially damaging scams in 2018 were business email compromise, confidence fraud and investment scams.




I did not realize this was in their scope.
TSA Lacks Cybersecurity Expertise to Manage Pipeline Security Program: Report
The TSA is responsible for the federal oversight of the physical security and cybersecurity of the more than 2.7 million miles of pipeline that transport and distribute natural gas, oil, and other hazardous products throughout the United States.
… “Further, TSA does not have a strategic workforce plan to help ensure it identifies the skills and competencies—such as the required level of cybersecurity expertise—necessary to carry out its pipeline security responsibilities,” the report reveals.




Apparently, Amazon doesn’t have it yet!
This is not a freebie but if you want to get started learning about privacy law, Privacy Law Fundamentals will be a great investment in your knowledge.
The authors are Daniel J. Solove, John Marshall Harlan Research Professor of Law at George Washington University Law School, and
Paul M. Schwartz, Professor of Law. U.C. Berkeley School of Law, and Director of the Berkeley Center for Law & Technology
In addition to the print format, the book is also available in electronic format.
Download a Preview from IAPP, where you can also purchase the book.




Gosh, only 50 years behind the times.
NIST Seeking Input on AI Technical Standards by May 31, 2019
On May 1, 2019, the National Institute of Standards and Technology (NIST) announced a Request for Information (RFI) in the Federal Register regarding ongoing efforts to develop technical standards for artificial intelligence (AI) technologies and the identification of priority areas for federal involvement in AI standards-related activities. Responses to the RFI are due by May 31, 2019.




I wonder how many in the legislature use Alexa?
Alexa, don’t store this recording: California bill targets smart home speakers
A bill making its way through the California Legislature would prohibit makers of smart home speakers from saving or storing recordings without users’ explicit consent.
The Anti-Eavesdropping Act, which cleared its first committee Wednesday, would also ban smart speaker device manufacturers from sharing with third parties recordings of verbal commands or requests heard by the devices.
Google said it is monitoring AB 1395.
We believe that the combination of strong and balanced regulations, with products that are designed with privacy in mind, will help provide individuals with confidence that they’re in control of their personal information,” a Google spokeswoman said.
Cunningham, who introduced the bill in January, did so as part of a state lawmakers’ “Your Data, Your Way” package of legislation, which aims to complement the California Consumer Privacy Act, which was signed into law last year and takes effect next year.


(Related)
What Amazon knows about you
Depending on how much you shop, watch and read with Amazon, the e-commerce behemoth may know more about you than any other company on earth.




I wonder if there is a search engine for DUMB? I’m tired of saying, “That senator is dumber than a bag of hammers.”
The Measure Of Things – search engine for finding comparative or relative measurements of physical quantities
Wondering how big, small, tall, long, fast, heavy, or old something is? The Measure of Things is a tool to help you understand physical quantities in terms of things you (or your audience) are already familiar with. Need a metaphor to emphasize a written measurement? Try including a comparison to the size of a whale, or the height of the Empire State Building, or the speed of a bullet train. Need to understand how big a metric or English unit really is? Try comparing them to real, tangible objects that you see everyday. Here are a few examples:
  • Through adopting these measures, we can reduce our total on-hand inventory by 230 units and save approximately 12,000 cubic feet of space in the warehouse, which will free up about 200 linear feet of shelf space.
  • A colony of brown bats can eat more than 3,360 fl oz of insects in a single evening.
  • The winning horse stood ran at 0.099 miles per second.
These phrases are all ok, but they’re a little hard to understand — especially when they contain less intuitive measurements like miles per second. Try this instead:




Too horrible to contemplate?
THE COMEDIAN IS IN THE MACHINE. AI IS NOW LEARNING PUNS
A pun generator might not sound like serious work for an artificial intelligence researcher—more the sort of thing knocked out over the weekend to delight the labmates come Monday. But for He He, who designed just that during her postdoc at Stanford, it’s an entry point to a devilish problem in machine learning. He’s aim is to build AI that’s natural and fun to talk to—bots that don’t just read us the news or tell us the weather, but can crack jokes or compose a poem, even tell a compelling story. But getting there, she says, runs up against the limits of how AI typically learns.




Architecture. Not just a flag on the map, but photos of the food.
Google Maps now highlights photos of restaurants' most popular dishes