Monday, January 27, 2020


It’s too easy suck money out of… well, anyone with money.
Average Cost To Recover From Ransomware Skyrockets To Over $84,000
According to a new report from Coveware, a typical total now stands at $84,116. That’s a little over double the previous figure of $41,198.
It’s not just the result of cybercriminals demanding steeper ransoms, though that’s certainly one factor. Others include hardware replacement and repair costs, lost revenues, and, in some incidents, damage to the victim’s brand.
Generally speaking, these costs all increase sharply in relation to the sophistication and duration of the attack.
There’s a new risk associated with ransomware infection that could make recovery even more expensive. Cybercriminals are no longer content to encrypt their victims’ data and demand payment for its decryption.
Now they’re downloading copies of those files and threatening to release them publicly if the ransom isn’t paid. Coveware notes that “this new complication brings forth the potential costs of 3rd party claims as a result of the data breach.”


(Related)
8 cities that have been crippled by cyberattacks - and what they did to fight them
As more of our everyday lives move online, the risks of hackers compromising personal information and shutting down necessary resources are only increasing.
There were at least 104 ransomware attacks against administrative systems in schools and governments over the course of 2019, according to cybersecurity company Recorded Future.




A timely backgrounder.
NSA Shares Guidance on Mitigating Cloud Vulnerabilities
The U.S. National Security Agency (NSA) has published advice on mitigating cloud vulnerabilities. While the advice is primarily designed for government agencies and departments, it nevertheless contains good advice for any commercial organization considering or embarking on -- or already deployed in -- a cloud environment.
The document (PDF ) provides four basic sections: an overview of the basic components usually delivered by cloud service providers (CSPs); an explanation of the concept of shared responsibility; an analysis of the primary cloud threat actors; and an analysis and description of the main cloud vulnerabilities and their mitigations. The last section provides the bulk of the document.




A slide for my lectures?
Cartoon: The History of Privacy




Is “anti-AI bias” a thing?
If a novel was good, would you care if it was created by artificial intelligence?


(Related) We know they can generate short texts…
Deepfake Bot Submissions to Federal Public Comment Websites Cannot Be Distinguished from Human Submissions
Abstract: The federal comment period is an important way that federal agencies incorporate public input into policy decisions. Now that comments are accepted online, public comment periods are vulnerable to attacks at Internet scale. For example, in 2017, more than 21 million (96% of the 22 million) public comments submitted regarding the FCC’s proposal to repeal net neutrality were discernible as being generated using search-and-replace techniques [1]. Publicly available artificial intelligence methods can now generate “Deepfake Text,” computer-generated text that closely mimics original human speech. In this study, I tested whether federal comment processes are vulnerable to automated, unique deepfake submissions that may be indistinguishable from human submissions. I created an autonomous computer program (a bot) that successfully generated and submitted a high volume of human-like comments during October 26-30, 2019 to the federal public comment website for the Section 1115 Idaho Medicaid Reform Waiver.
Results summary: The bot generated and submitted 1,001 deepfake comments to the public comment website at Medicaid.gov over a period of four days. These comments comprised 55.3% (1,001 out of 1,810) of the total public comments submitted. Comments generated by the bot were often highly relevant to the Idaho Medicaid waiver application, including discussion of the proposed waiver’s consequences on coverage numbers, its impact on government costs, unnecessary administrative burdens, and relevant personal experience. Finally, in order to test whether humans can distinguish deepfake comments from other comments submitted, I conducted a survey of 108 respondents on Amazon’s Mechanical Turk. Survey respondents, who were trained and assessed through exercises in which they distinguished more obvious bot versus human comments, were only able to correctly classify the submitted deepfake comments half (49.63%) of the time, which is comparable to the expected result of random guesses or coin flips. This study demonstrates that federal public comment websites are highly vulnerable to massive submissions of deepfake comments from bots and suggests that technological remedies (e.g., CAPTCHAs) should be used to limit the potential of abuse…”




Perspective.
CMA lifts the lid on digital giants
The UK Competition and Markets Authority (CMA) interim report has found that:
    • Last year, Google accounted for more than 90% of all revenues earned from search advertising in the UK, with revenues of around £6 billion
    • In the same year, Facebook accounted for almost half of all display advertising revenues in the UK, reaching more than £2 billion
Big’ is not necessarily ‘bad’ and these platforms have brought very innovative and valuable products and services to the market. But the CMA is concerned that their position may have become entrenched with negative consequences for the people and businesses who use these services every day. A lack of real competition to Google and Facebook could mean people are already missing out on the next great new idea from a potential rival. [Rival to Google or Facebook? Bob] It could also be resulting in a lack of proper choice for consumers and higher prices for advertisers that can mean cost rises for goods and services such as flights, electronics and insurance bought online. The market position of Google and Facebook may potentially be undermining the ability of newspapers and other publishers to produce valuable content as their share of revenues is squeezed by large platforms…”




Perspective. I did not expect this!
In U.S. Library Visits Outpaced Trips to Movies in 2019
Gallup – “Visiting the library remains the most common cultural activity Americans engage in, by far. The average 10.5 trips to the library U.S. adults report taking in 2019 exceeds their participation in eight other common leisure activities. Americans attend live music or theatrical events and visit national or historic parks roughly four times a year on average and visit museums and gambling casinos 2.5 times annually. Trips to amusement or theme parks (1.5) and zoos (.9) are the least common activities among this list… Men and woman report doing most activities at about the same rate, but there are a few key differences:
    • Women report visiting the library nearly twice as frequently as men do, 13.4 to 7.5 visits.
    • Men are more likely than women to visit casinos, attend sporting events and visit national or historical parks…”




Protecting my students.
FBI warns of spoofed websites and hiring scams that target your wallet
Here comes the nasty part. After you get the job, the cybercriminals send you an email with the employment contract, along with a couple of requests. “In order to appear legitimate, the criminals send victims an employment contract to physically sign, and also request a copy of the victims’ driver’s licenses, Social Security numbers, direct deposit information, and credit card information,” reads the FBI’s announcement.
The announcement also warns that, “Criminals may also tell victims they need to pay upfront for background checks or screenings, job training, start-up equipment, or supplies. In many cases, victims are told they will be reimbursed in their first paycheck. Once they get money, criminals stop communicating with their victims.”



Sunday, January 26, 2020


Student surveillance will not solve all security risks.
New surveillance AI can tell schools where students are and where they’ve been
Not all AI being used by schools is facial recognition. That doesn’t mean the tech doesn’t come with privacy risks.




Something for my Architecture students to consider.
Operationalizing AI
… One of the unique things about an AI project versus a traditional application development project is that there isn’t the same build / test / deploy / manage order of operations. Rather there are two distinct phases of operation: a “training” phase and an “inference” phase. The training phase involves the selection of one or more machine learning algorithms, the identification and selection of appropriate, clean, well-labeled data, the application of the data to the algorithm along with hyperparameter configurations to create an ML model, and then the validation and testing of that model to make sure that it can generalize properly without too much overfitting of training data or underfitting for generalization. All of those steps comprise just the training phase of an AI project.




When IP creates IP...
Is Intellectual Property Law Ready for Artificial Intelligence?
The point that Artificial Intelligence (AI) will change the law is trite and obvious by now. How it will change the law, and how the law will change AI, are much harder questions to answer, however. Most of the hard questions arise when what I have elsewhere called an ‘autonomy threshold’ has been crossed.1




Imagine the insurance premiums for a completely unsafe vehicle!
New Safety Gizmos Are Making Car Insurance More Expensive
The high cost of repairing sensor-packed vehicles outpaces the savings from fewer crashes.




Perspective.
Where U.S. presidential candidates stand on breaking up Big Tech




Could be useful.
The Ultimate JavaScript Cheat Sheet



Saturday, January 25, 2020


The Phishing is good!
Hackers Stole $10.5 Million From Richardson Company: Feds
Hackers stole $10.5 million from a Richardson real estate software company with the help of “money mules” – dozens of Americans who unwittingly accepted fraudulent money into their accounts, transferred it to those behind the scheme, and kept a cut for themselves, according to court documents.
The company, RealPage, contacted the Dallas office of the U.S. Secret Service about a computer intrusion in May 2018 after hackers, possibly from Nigeria, obtained the login credentials of an employee and accessed the company’s online financial accounts, according to a summary of the investigation included in a federal seizure document.
… It took RealPage 20 days to realize that hackers had gained access to its computer network through a phishing attack after an employee clicked on an email that appeared to be legitimate, the agent said.




Clearview is “over promoting” itself, is New Jersey over reacting?
New Jersey Bars Police From Using Clearview Facial Recognition App
New Jersey police officers are now barred from using a facial recognition app made by a start-up that has licensed its groundbreaking technology to hundreds of law enforcement agencies around the country.
Gurbir S. Grewal, New Jersey’s attorney general, told state prosecutors in all 21 counties on Friday that police officers should stop using the Clearview AI app.
… “Until this week, I had not heard of Clearview AI,” Mr. Grewal said in an interview. “I was troubled. The reporting raised questions about data privacy, about cybersecurity, about law enforcement security, about the integrity of our investigations.”
In a promotional video posted to its website this week, Clearview included images of Mr. Grewal because the company said its app had played a role last year in Operation Open Door, a New Jersey police sting that led to the arrest of 19 people accused of being child predators.
I was surprised they used my image and the office to promote the product online,” said Mr. Grewal, who confirmed that Clearview’s app had been used to identify one of the people in the sting. “I was troubled they were sharing information about ongoing criminal prosecutions.”
Mr. Grewal’s office sent Clearview a cease-and-desist letter that asked the company to stop using the office and its investigations to promote its products.


(Related) Several backgrounder articles…
Facial Recognition
The controversial and nearly ever-present technology that could replace the fingerprint


(Related)
Opinion | We’re Banning Facial Recognition. We’re Missing the Point.
Communities across the United States are starting to ban facial recognition technologies. In May of last year, San Francisco banned facial recognition; the neighboring city of Oakland soon followed, as did Somerville and Brookline in Massachusetts (a statewide ban may follow). In December, San Diego suspended a facial recognition program in advance of a new statewide law, which declared it illegal, coming into effect. Forty major music festivals pledged not to use the technology, and activists are calling for a nationwide ban. Many Democratic presidential candidates support at least a partial ban on the technology.
These efforts are well intentioned, but facial recognition bans are the wrong way to fight against modern surveillance. Focusing on one particular identification method misconstrues the nature of the surveillance society we’re in the process of building. Ubiquitous mass surveillance is increasingly the norm. In countries like China, a surveillance infrastructure is being built by the government for social control. In countries like the United States, it’s being built by corporations in order to influence our buying behavior, and is incidentally used by the government.
In all cases, modern mass surveillance has three broad components: identification, correlation and discrimination. Let’s take them in turn.




A debate my student’s grandchildren will continue?
The battle for ethical AI at the world’s biggest machine-learning conference
Diversity and inclusion took centre stage at one of the world’s major artificial-intelligence (AI) conferences in 2018. But once a meeting with a controversial reputation, last month’s Neural Information Processing Systems (NeurIPS) conference in Vancouver, Canada, saw attention shift to another big issue in the field: ethics.
The focus comes as AI research increasingly deals with ethical controversies surrounding the application of its technologies — such as in predictive policing or facial recognition. Issues include tackling biases in algorithms that reflect existing patterns of discrimination in data, and avoiding affecting already vulnerable populations.
AI Now goes a step further: in a report published last month, it called for all machine-learning research papers to include a section on societal harms, as well as the provenance of their data sets.




For my students.
Takeaways from the Understanding Machine Learning Masterclass
The slides are available for download here. Attendees also received a copy of FPF’s Privacy Expert’s Guide to Artificial Intelligence and Machine Learning, a guide that explains the technological basics of AI and ML systems at a level of understanding useful for non-programmers, and addresses certain privacy challenges associated with the implementation of new and existing ML-based products and services.




AI in the world.
An AI Epidemiologist Sent the First Warnings of the Wuhan Virus
On January 9, the World Health Organization notified the public of a flu-like outbreak in China: a cluster of pneumonia cases had been reported in Wuhan, possibly from vendors’ exposure to live animals at the Huanan Seafood Market. The US Centers for Disease Control and Prevention had gotten the word out a few days earlier, on January 6. But a Canadian health monitoring platform had beaten them both to the punch, sending word of the outbreak to its customers on December 31.
BlueDot uses an AI-driven algorithm that scours foreign-language news reports, animal and plant disease networks, and official proclamations to give its clients advance warning to avoid danger zones like Wuhan.
Khan says the algorithm doesn’t use social media postings because that data is too messy.




Is it too early or too late?
Investing in AI: A Beginner's Guide
Artificial intelligence is on track to be a truly revolutionary technology. Here's what investors need to know.



Friday, January 24, 2020


Curious. I wonder if a new Marvel superhero is behind this?
Someone is uninstalling the Phorpiex malware from infected PCs and telling users to install an antivirus
Malware analysts believe someone has hijacked the Phorpiex botnet from its creator and is sabotaging its operations by alerting users they've been infected.
A mysterious entity appears to have hijacked the backend infrastructure of the Phorpiex (Trik) botnet and is uninstalling the spam-bot malware from infected hosts, while also showing a popup telling users to install an antivirus and update their computers, ZDNet has learned.
The popups have started appearing on users' screens today, early morning, US Eastern time, and have been spotted by the research team at antivirus vendor Check Point.
Initially, ZDNet and others thought this was a prank coded inside the malware by the Phorpiex team for the purpose of trolling security researchers analyzing the malware.
However, as the hours passed, it became clear that this was actually taking place on customer systems, in the real world, and was not just a popup that was appearing in virtual machines used as malware analysis sandboxes.
… Balmas listed several theories as what could have happened -- such as the malware operators deciding to quit and shut down the botnet on their own terms, a law enforcement action, a vigilante security researcher taking matters into his own hands, or a rival malware gang sabotaging the Phorpiex crew by destroying their botnet.




I haven’t found any suggestion of why they were down. Does this suggest that everything goes through a ‘single point of failure?’
Comcast experienced a nationwide internet outage on Thursday
Philadelphia-based cable and internet giant Comcast has resolved a nationwide internet outage that disrupted service on Thursday afternoon.
Customer reports of the outage surfaced around 2 p.m. and skyrocketed shortly afterward, according to downdetector.com.
By 3:15 p.m., there was a significant drop in reports of ongoing issues.
A Comcast spokeswoman said all residential services were back online as of 4 p.m.




GDPR evolving because of AI?
EU Parliament Calls For More Consumer Protection In AI, Automation
Parliament’s Internal Market and Consumer Protection Committee issued a resolution Thursday (Jan. 23) that will put rules into place to address the challenges of fast-developing artificial intelligence and automated decision-making technology.
The committee said citizens should always be adequately informed about both kinds of technology, including how to reach a human with decision-making powers and about how the tech’s decisions can be questioned or corrected.
Under the new rules, any system utilizing AI or ADM technology should use only the highest-quality, unbiased sets of data and there should be review systems set up so that any mistakes can be corrected. The committee said it should also be possible at all times to speak with human representatives to review the decisions made by AI or ADM.
The committee said that humans must “ultimately be responsible” for the processes of AI and ADM processes, particularly in fields such as medical, legal and accounting.
The committee also warned that AI and ADM technology would evolve over time and so the regulations may have to be updated.




Implications for both Computer Security and Architecture.
Disruption 2.0: How IoT And AI Are Breaking Up The Business World
IoT solves the problem of digitizing the physical world and turning physical attributes into digital bits and bytes. AI solves the problem of making sense of large amounts of data and turning this data into actions.
At their core, IoT devices are physical assets with sensors. These sensors capture data, and this data needs to convert to business value. The term IoT, as I detailed in my previous posts, doesn't quite describe this process. A name that better describes this process is “Data Capturing Assets”.
The data enabling AioT, Intelligent Automation, and Disruption 2.0 is within the core of companies. The more of their data companies utilize, and the more insights they gain, the more influential the outcomes of Intelligent Automation will be.
This ability to do things better via better Intelligent Automation, utilization, optimization, and personalization will force businesses to redefine how they operate. Companies who will not seize this opportunity will cease to exist. They will become uncompetitive.




Any chance this could be more than a collection of guesses?
Report predicts 69% of managers' routine work will be completely automated by 2024
"Currently, managers spend time filling in forms, updating information and approving workflows. By using AI to automate these tasks, they can spend less time managing transactions and can invest more time on learning, performance management and goal setting."
AI will influence the office, but the level at which it does, will be based on new tech advances, organizational readiness to exploit, and worker attitudes, the report, "Predicts 2020: AI and the Future of Work," found. Because managers are invariably privy to planned tech changes, where and when the company stands in adopting the tech, and the in-office environment, their presence in a supervisorial capacity is essential.




An AI resource?
Discovering millions of datasets on the web
Google Blog: “Across the web, there are millions of datasets about nearly any subject that interests you. If you’re looking to buy a puppy, you could find datasets compiling complaints of puppy buyers or studies on puppy cognition. Or if you like skiing, you could find data on revenue of ski resorts or injury rates and participation numbers. Dataset Search has indexed almost 25 million of these datasets, giving you a single place to search for datasets and find links to where the data is. Over the past year, people have tried it out and provided feedback, and now Dataset Search is officially out of beta…”




Collecting handouts for my students.
Book Creator Adds New Accessibility Features
Book Creator is a tool that I have been using and recommending for years for making multimedia ebooks. You can use it as an iPad app or in your web browser. This week Book Creator announced that it now works in Microsoft Edge as well as Chrome and Safari. That's not the only product enhancement Book Creator released this week.
Some of the other Book Creator enhancements made this week include support for dictation in 120 languages, auto-generating captions on videos, and auto transcription of audio recordings. Automatic captioning of videos can be activated for videos that are recorded directly through the Book Creator app as well as videos that are uploaded to Book Creator pages. Likewise, automatic transcription of audio can be activated for files recorded directly in Book Creator as well as files that are added from external sources. Captions and transcripts are available in 120 languages.




For my students.
How to Customize Your LinkedIn Feed




I stand corrected.



Thursday, January 23, 2020


A trend(?) away from ‘proof of harm’?
PA Bill Tracker: Allowing victims of data breaches to sue companies that didn’t secure information
Daniel Walmer reports on a bill proposed in the Pennsylvania legislature:
House Bill 1010, introduced by Solomon, would change that. Under the bill, victims of data breaches could sue for $5,000 per violation or more if their actual losses were more than $5,000. The attorney general’s office can also seek civil penalties up to $10,000.
The bill would also require organizations to take “reasonable measures” to secure personal identification information. If they suffer a data breach, they would be required to notify affected customers “without unreasonable delay.” A delay of up to three days is permitted only if requested by law enforcement.
Our personal information is at risk. Countless incidents over the past few years have laid this fact bare,” Solomon wrote in a co-sponsorship memo. “We need to do more to defend Pennsylvanians’ private, personal information from falling into the wrong hands.”
The personal information protected by House Bill 1010 would include Social Security numbers, driver’s license numbers, financial account and credit card numbers, and medical information.
Read more on The Sentinel. This is one of the stronger bills that I’ve seen proposed and you may want to read all of its language.




Contrast with the FBI’s fight against encryption.
Tech policy think tanks write to govt urging stronger encryption to strengthen cyber security in India
Technology policy think tanks and digital freedom advocates have written to the National Security Council Secretariat urging stronger encryption requirements, improved breach disclosure norms and use of open-source software while encouraging free flow of data across borders, as part of suggestions to strengthen cyber security in India.


(Ditto)
Weakening Encryption Could Impact Election Security, Coalition Says
An election security group said the Justice Department’s renewed calls for access to encrypted data could impact more than privacy.


(Related)
Exclusive: U.S. Cops Have Wide Access to Phone Cracking Software, New Documents Reveal
While the FBI requests ‘backdoor’ iPhone access, documents indicate law enforcement already has easy access to encrypted devices


(Related)
Inside the $10 million cyber lab trying to break Apple’s iPhone
The Trump administration wants Apple to create a backdoor into the iPhone. District Attorney Cy Vance Jr. has spent millions trying to find other ways in.




We can’t secure dedicated voting machines. Can this be made to work?
Exclusive: Seattle-Area Voters To Vote By Smartphone In 1st For U.S. Elections
The King Conservation District, a state environmental agency that encompasses Seattle and more than 30 other cities, is scheduled to detail the plan at a news conference on Wednesday. About 1.2 million eligible voters could take part.
The new technology will be used for a board of supervisors election, and ballots will be accepted from Wednesday through election day on Feb. 11.




For my Architecture students.
How Leading Organizations Are Getting the Most Value From IT
Many of the most consequential investment decisions facing CEOs today are technology-related. That wasn’t the case a few years ago. But now every company is in effect a technology company, and every CEO a tech CEO. With every major technology choice representing a vital business decision, “good enough” decisions are anything but.
That’s what we are finding as we continue to analyze the technology decisions of more than 8,300 companies across 20 industries in 20 countries, in what we believe is the largest study to date of enterprise systems. This work also includes responses from nearly 900 CEOs across the globe.
Our initial comparisons found that the top 10% of these companies in terms of their levels of technology adoption, technology penetration, and organizational change are achieving levels of revenue growth that are double those of the bottom 25%, which constitute the technology laggards. These leaders also grow revenues more than 50% faster than the middle 20% of the companies we studied.




The good, the bad, and stuff we better learn more about.
AI, automation emerge as critical tools for cybersecurity
Artificial intelligence and automation adoption rates are rising, and investment plans are high on enterprise radars. AI is in pilots or use at 41% of companies, with another 42% actively researching it, according to the 2019 IDG Digital Business Study.
… “The volume of data being generated is perhaps the largest challenge in cybersecurity,” says David Mytton, CTO and expert in residence, Seedcamp. “As more and more systems become instrumented — who has logged in and when, what was downloaded and when, what was accessed and when — the problem shifts from knowing that ‘something’ has happened, to highlighting that ‘something unusual’ has happened.”




I better get busy, I’ve only read one of these.
7 books to read right now if you want to become the ultimate authority on artificial intelligence
Companies like Walmart, JPMorgan Chase, and AB InBev are using the advanced tech to overhaul operations in the hopes it will free up workers to focus on the more critical aspects of their jobs and lead to significant cost-savings over the next several years.
To support this push, many organizations are spending significantly to train their employees on AI and other new digital tools. Earlier this month, for example, Nationwide said it would spend $160 million over five-years to train all its employees on the technology, among other reskilling efforts.




Looks like they are missing a few airports, but potentially useful.
Find the WiFi Password For Almost Any Airport Lounge Using This Free Map
LifeHacker: “Fortunately, we’re at a point where most of the airports in the United States offer free WiFi in some form. Yes, sometimes you have to watch an ad to get there, but it’s there. That said, sometimes you end up an airport that doesn’t have WiFi, or one that has free WiFi that’s restricted by a time limit. For times like those, the WiFox Google Map can help. With it, you can search for any airport in the world and see how to connect to the WiFi there…”