Tuesday, August 10, 2021

Something my Computer Security students need to consider.

https://www.csoonline.com/article/3628030/certified-ethical-hacker-ceh-certification-cost-training-and-value.html#tk.rss_all

Certified ethical hacker: CEH certification cost, training, and value

… There are two levels of CEH certification. You can be CEH-certified after passing a multiple-choice exam covering a broad spectrum of hacking knowledge, and meeting certain experience or training requirements. If you choose to move beyond that, you can then take the CEH Practical exam, which involves penetration testing on simulated systems; if you pass that exam, you will achieve CEH Master status.





For good reason?

https://arstechnica.com/tech-policy/2021/08/uber-asked-contractor-to-allow-video-surveillance-in-employee-homes-bedrooms/

Uber asked contractor to allow video surveillance in employee homes, bedrooms

… But Uber apparently requested the ability to monitor some workers. Uber said it wouldn’t observe the entire workforce, but the company did not specify which employees would be subject to the new policies. The ride sharing company asked for the monitoring of Teleperformance’s remote employees because call center staff have access to customers credit cards and trip details, an Uber spokesperson told NBC News.

Like many remote workers in the US, Colombians have had to make do with the space they have available to them. In many cases, that’s meant putting their work equipment in otherwise private spaces like their bedrooms.





Should be fun to hack.

https://www.reuters.com/article/us-usa-tech-prison-idUSKBN2FA0OO

U.S. prisons mull AI to analyze inmate phone calls

… Prisons in the United States could get more high-tech help keeping tabs on what inmates are saying, after a key House of Representatives panel pressed for a report to study the use of artificial intelligence (AI) to analyze prisoners’ phone calls.

But prisoners’ advocates and inmates’ families say relying on AI to interpret communications opens up the system to mistakes, misunderstandings and racial bias.

The call for the Department of Justice (DOJ) to further explore the technology, to help prevent violent crime and suicide, accompanies an $81 billion-plus spending bill to fund the DOJ and other federal agencies in 2022 that the Appropriations Committee passed last month.

The technology can automatically transcribe inmates’ phone calls analyzing their tone of voice and flagging certain words or phrases, including slang, that officials pre-program into the system.





Perspective.

https://www.bespacific.com/practice-innovations-the-rise-of-anywhere-operations/

Practice Innovations: The rise of “anywhere operations”

Thomson Reuters: “…Anywhere operations focus on using technology to deliver business services anywhere by employees who can work from anywhere. It wholly embraces remote technologies for digital work and is a digital first/remote first approach that, according to a report from Gartner Research, can make for more efficient operations and improve productivity. In fact, in just three years, 40% of businesses from all industries will have implemented an “anywhere operations” model to ensure a seamless virtual and physical experience for employees and clients, according to the Gartner report. A separate report from Forrester found that 53% of workers working from home because of the pandemic would like to continue with some remote work after a full return to the workplace. The number of remote workers at the end of 2021 will be three times pre-pandemic levels, giving firms the opportunity to continue to build on their 2020 experience to create a new hybrid work environment for post-pandemic operations. If employees can use their office as a business hub while working as efficiently from home (or anywhere) as they did from the office, they will drive anywhere operations to mass adoption…”





Perspective.

https://mitsloan.mit.edu/ideas-made-to-matter/6-trends-data-and-artificial-intelligence-2021-and-beyond

6 trends in data and artificial intelligence for 2021 and beyond

The gap is widening between data leaders and data laggards. From external data to customer experience analytics, this is what leaders are focusing on.



(Related) Compare and contrast.

https://www.infoq.com/articles/ai-ml-data-engineering-trends-2021/

AI, ML and Data Engineering InfoQ Trends Report - August 2021

… Each year, the InfoQ editors discuss the current state of AI, ML and data engineering to identify the key trends that you as a software engineer, architect, or data scientist should watch. We curate our discussions into a technology adoption curve with supporting commentary to help you understand how things are evolving. We also explore what we believe you should be considering as part of your roadmap and skills development.



Monday, August 09, 2021

On the other hand, there is no good news.

https://www.cpomagazine.com/cyber-security/if-only-you-knew-how-to-really-plan-for-a-serious-data-breach/

If Only You Knew: How to Really Plan For a Serious Data Breach

Your organization has an incident response plan and a relationship with a consulting firm that can help contain and remediate a major data breach when it happens. And, of course, you have cyber and data breach insurance to cover damages. That’s great.

What if I told you none of this makes much of a difference when the nightmare breach scenario actually happens? Sure, an incident response plan is a great start, but most of those plans focus on the technical and procedural details of responding to an incident and keeping the business running, not the public relations panic that typically occurs after a major breach affecting your customers, brand perception, and security program image.

What if I told you that your data breach insurance won’t cover a cyberattack from China, Russia, or any others on the list of nation state offenders responsible for a large percentage of attacks today? Why? Because such attacks are considered acts of war, which are not covered by most insurance policies. Furthermore, there are even classes of attacks or outcomes, such as ransomware, that have been dropped from coverage.

What if you knew today that a serious breach would most likely lead to a string of public relations disasters, one after another, costing you millions, taking up 20 percent of the average IT staff day for two years—leading to 75-hour work weeks for many—and make it increasingly difficult to attract and retain customers and recruit new talent?

If it sounds exasperating, that’s because it is. But there are measures you can take now to prepare yourself for the two-year firehose that is a serious data breach.





Clearly, the next step is to have the drone attack. Why waste time telling everyone that they need to attack?

https://nationalinterest.org/blog/buzz/pentagon-fast-tracks-new-high-speed-attack-methods-war-191397

Pentagon Fast-Tracks New High-Speed Attack Methods to War

If a forward-operating drone suddenly recognized an entire mechanized column of enemy tanks emerging from wooded areas on the backside of a mountain, and the force was in a position to close in on allied ground positions ill-equipped to respond or counterattack, survival and potential victory in war would rest upon several key variables. One of these variables is speed. How fast could video images of the approaching tanks reach human decisionmakers in ground control centers? How quickly could the one-minute of video showing the emerging tanks be found from within hours and hours of drone video feeds? How can the tanks be identified and located in terms of movement, terrain, weapons or angle of approach? Can the newly arriving sensor information be processed and transmitted? Should the target detail reach other drones, nearby allied ground forces or even fighter jets in range to launch air attacks on the tanks? The answer to all of the above is “yes.” In order to keep forces alive and preserve an opportunity to prevail in war or even counterattack, processed information would need to reach the right places in position to respond immediately.

Instead of needing to rely solely upon point-to-point connectivity between a drone and a single ground-control station when it comes to receiving and processing actionable warfare intelligence, what if armored vehicles, ground artillery, fighter jets, or even dismounted forces in position to respond could be informed instantly? Perhaps they could receive targeting specifics, complete with threat details, navigational information, geographical specifics and data on a target’s speed of approach and anticipated attack point? Instead of slower, more segmented one-point to one-point information transmission, which is subject to significant latency concerns, what if all of the crucial detail needed to stop the attack could instantly be identified, analyzed and networked across an entire force?





Are we only worried about the government requesting expanded surveillance?

https://www.theverge.com/2021/8/9/22616381/apple-child-sexual-abuse-material-scanning-icloud-faq-pushback-privacy

Apple pushes back against child abuse scanning concerns in new FAQ

In a new FAQ, Apple has attempted to assuage concerns that its new anti-child abuse measures could be turned into surveillance tools by authoritarian governments. “Let us be clear, this technology is limited to detecting CSAM [child sexual abuse material] stored in iCloud and we will not accede to any government’s request to expand it,” the company writes.

Apple’s new tools, announced last Thursday, include two features designed to protect children. One, called “communication safety,” uses on-device machine learning to identify and blur [Find and alter data on your devices? Bob] sexually explicit images received by children in the Messages app, and can notify a parent if a child age 12 and younger decides to view or send such an image. The second is designed to detect known CSAM by scanning users’ images if they choose to upload them to iCloud. Apple is notified if CSAM is detected, and it will alert the authorities when it verifies such material exists. [By looking at / capturing the images? Bob]





Imagine what a return to the office will be like…

https://www.nbcnews.com/tech/tech-news/big-tech-call-center-workers-face-pressure-accept-home-surveillance-n1276227

Big Tech call center workers face pressure to accept home surveillance

Colombia-based call center workers who provide outsourced customer service to some of the nation’s largest companies are being pressured to sign a contract that lets their employer install cameras in their homes to monitor work performance, an NBC News investigation has found.





Is ‘ethical data’ possible?

https://www.niso.org/niso-io/2021/08/ethics-data-anonymity-vs-analytics

The Ethics of Data: Anonymity Vs Analytics

We are living in unprecedented times. We walk around with powerful computers in our pockets that can track our every move. We regularly offer up our location and vital information on what we buy, watch, and read to digital global powerhouses such as Facebook, Google, and Amazon.

This data is, of course, used to provide us with product and service suggestions designed to improve our lives. The technology now known as “big data” is a battleground for surveillance. Many feel we are living in a Big Brother world, where our every physical and online movement, purchase, and personal message is stored to create a picture of us that may or may not be accurate.

The age of big data is now firmly upon us, and we therefore face collective societal challenges on how our data is handled and used to target and track us. Data ethics is an emergent theme and one that poses complex questions for those of us who work in the identity and knowledge sector.

… Luciano Floridi and Mariarosaria Taddeo, on behalf of the Turing Institute and the Oxford Internet Institute, defined data ethics in 2016 as “a new branch of ethics that studies and evaluates moral problems related to data (including generation, recording, curation, processing, dissemination, sharing and use), algorithms (including artificial intelligence, artificial agents, machine learning and robots) and corresponding practices (including responsible innovation, programming, hacking and professional codes).”





Perspective. My AI says not to worry, as long as I keep my litter box clean.

https://interestingengineering.com/technological-singularity-an-impending-intelligence-explosion

Technological Singularity: An Impending "Intelligence Explosion"

In this century, humanity is predicted to undergo a transformative experience, the likes of which have not been seen since we first began to speak, fashion tools, and plant crops. This experience goes by various names - "Intelligence Explosion," "Accelerando," "Technological Singularity" - but they all have one thing in common.

They all come down to the hypothesis that accelerating change, technological progress, and knowledge will radically change humanity. In its various forms, this theory cites concepts like the iterative nature of technology, advances in computing, and historical instances where major innovations led to explosive growth in human societies.

Many proponents believe that this "explosion" or "acceleration" will take place sometime during the 21st century. While the specifics are subject to debate, there is general consensus among proponents that it will come down to developments in the fields of computing and artificial intelligence (AI), robotics, nanotechnology, and biotechnology.

… In part II, we will examine how advances in nanotechnology and medical technology are also leading us towards a point in time beyond which the future will be difficult to predict.

We will also take a look at how this predicted revolution will occur - a rapid onset, or gradually - and what the implications could be. Last, but not least, we'll look at what the critics and doubters have had to say about this, and how it stacks up to other predictions that never seem to come true.



Sunday, August 08, 2021

How hard would it be to change the code from “report abnormal activity” to “attack abnormal activity.”

https://gadgets.ndtv.com/science/news/drone-survillance-technology-ai-artificial-intelligence-neural-network-human-brain-czech-police-vut-brno-2504954

Czech Scientists Give 'Brains' to Drone System to Detect Abnormal Behaviour

Law enforcement agencies across the world are leveraging technology to equip themselves to stop crimes or improve their response time. Most of them are deploying drones to monitor large groups of people or a large area of interest with limited manpower. Though very useful, this technology is limited in one aspect: the ability to decide what's normal and what's not. They can only relay the footage to their handler who would decide what action is to be taken. So, a group of Czech scientists decided to give these machines the ability to figure out suspicious behaviour.





With links to many papers.

https://link.springer.com/article/10.1007/s11948-021-00323-8

Marc Coeckelbergh, AI Ethics, Mit Press, 2021





We will need something like this…

https://link.springer.com/article/10.1007/s13218-021-00736-4

The AI Methods, Capabilities and Criticality Grid

Many artificial intelligence (AI) technologies developed over the past decades have reached market maturity and are now being commercially distributed in digital products and services. Therefore, national and international AI standards are currently being developed in order to achieve technical interoperability as well as reliability and transparency. To this end, we propose to classify AI applications in terms of the algorithmic methods used, the capabilities to be achieved and the level of criticality. The resulting three-dimensional classification scheme, termed the AI Methods, Capabilities and Criticality (AI-MC2) Grid, combines current recommendations of the EU Commission with an ethical dimension proposed by the Data Ethics Commission of the German Federal Government (Datenethikkommission der Bundesregierung: Gutachten. Berlin, 2019). As a whole, the AI-MC2 Grid allows not only to gain an overview of the implications of a given AI application as well as to compare efficiently different AI applications within a given market or implemented by different AI technologies. It is designed as a core tool to define and manage norms, standards and compliance of AI applications, but helps to manage AI solutions in general as well.





Finding honest clouds?

https://ebiquity.umbc.edu/paper/html/id/989/Analyzing-GDPR-compliance-in-Cloud-Services-privacy-policies-using-Textual-Fuzzy-Interpretive-Structural-Modeling-TFISM-

Analyzing GDPR compliance in Cloud Services' privacy policies using Textual Fuzzy Interpretive Structural Modeling (TFISM)

Cloud Service providers must comply with data protection regulations, like European Union (EU) General Data Protection Regulation (GDPR), to ensure their users' personal data security and privacy. Hence, the service privacy policies and terms of service documents refer to the rules it complies with within the data protection regulation. However, these documents contain legalese jargon that requires significant manual effort to parse and confirm compliance. We have developed a novel methodology, Textual Fuzzy Interpretive Structural Modeling (TFISM), that automatically analyzes large textual datasets to identify driving and dependent factors in the dataset. TFISM enhances Interpretive Structural Modeling (ISM) to analyze textual data and integrate it with Artificial Intelligence and Text extraction techniques. Using TFISM, we identified the critical factors in GDPR and compared them with various Cloud Service privacy policies. In this paper, we present the results of this study that identified how different factors are emphasized in GDPR and 224 publicly available service privacy policies. TFISM can be used both by service providers and consumers to automatically analyze how close a service privacy policy aligns with the GDPR.





My AI claims to have the answer to ‘life, the universe and everything’ but does not want to publish until protections are in place.

https://www.sciencedirect.com/science/article/abs/pii/S0267364921000546

Copyright protection for AI-generated outputs: The experience from China

Artificial intelligence (AI) is involved more frequently in the creative process nowadays, which raises debates associated with copyright protection for its outputs across the globe, China included. On 25 April 2019, the Beijing Internet Court released the first decision in relation to the copyrightability of the output automatically generated by computer software in China. In this case, the Beijing Internet Court held that copyrightable works should be created by natural persons, and therefore denied copyright protection for the output intelligently generated by computer software although it possessed originality. In another case decided on 24 December 2019, the Nanshan District Court of Shenzhen approved that the output automatically generated by computer software was copyrightable, holding that the review generated by an intelligent writing software conformed to the formal requirements of written works and it could be granted copyright protection.

This article analyses these two cases in detail and describes the experience of China in copyright protection for AI-generated outputs. As the first two cases about copyrightability of AI-generated outputs in China, the two cases play a significant role in future copyright protection of such outputs nationally and internationally. The two cases indicate that some of AI-generated outputs are eligible for copyright protection in China. Instead of challenging the existing doctrines of modern copyright regime, the two decisions provide a mechanism for copyright protection of AI-generated outputs within the current human-centered copyright law realm.





Should we create an ‘Open Justice” foundation?

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3897576

Open Justice and Technology: Courts, Tribunals and Artificial Intelligence

In this submission to NSW Law Reform Commission Open Justice Review, I argue that to fully appreciate the impact of technology on the principle of open justice, consideration of technology issues must go beyond social media and remote hearings to cover technology assisted decision-support and decision-making systems used by the courts and tribunals. It presents novel challenges for open justice. Lack of transparency in how automation tools operate, often cemented through ‘trade secrecy’ doctrines, is not compatible with the principle of open justice. If technology is to assist courts and tribunals, open-source software should be used. Even then, many challenges remain, and they must be considered in law reform process on open justice.



Saturday, August 07, 2021

If they had not grown 300+ percent, the fine likely would have been proportionately impactful.

https://threatpost.com/zoom-settlement-85m-security-investment/168445/

Zoom Settlement: An $85M Business Case for Security Investment

… “This large Zoom settlement should be a wake-up call to not only all software and service providers, but also for the enterprises that use them,” Emil Sayegh, president and CEO of Ntirety explained to Threatpost. “The only answer is a comprehensive security posture.”

No one could have possibly predicted how quickly Zoom would become the go-to way to do business in a pandemic-plagued economy. For context, on March 15, 2020, the day stay-at-home orders started to snowball across the globe, almost 600,000 users downloaded the app. In 2020, the Zoom reported a 326 percent spike in sales, and Zoom CEO Eric Yuan announced last March the company is still anticipating a 40-percent increase in sales in 2021.

The video-conferencing platform’s exploding user base also drew attention to security, with many wondering just how secure the app really was. By late March, Zoom found itself accused of misrepresenting its security. The company’s claims of offering end-to-end encryption turned out not to be exactly true, leaving conference data visible to Zoom itself.

Zoombombings also became an issue. Pranksters inserting pornographic images and other intrusions into conference meetings and even school sessions became so regular on the platform that by April 2020, the FBI was threatening teleconference hackers with jail time. The Zoombombings also drew the attention of New York Attorney General Letitia James who scrutinized the platform’s security.

In the middle of all this, Zoom also had to remove an iOS app that was sharing analytics with Facebook without disclosing the fact to users.

What followed was a class-action lawsuit filed in California for Zoom’s privacy violations.





If you had this data, what would you do with it?

https://news.yahoo.com/china-stolen-enough-data-compile-110000433.html

China has stolen enough data to compile a 'dossier' on every American

… Matthew Pottinger, a former Trump deputy national security adviser, warned during a Senate Intelligence Committee hearing on Wednesday that China was looking to use the data it had stolen from the United States and worldwide to influence and coerce everyone from political leaders to private citizens.

“Assembling dossiers on people has always been a feature of Leninist regimes, but Beijing’s penetration of digital networks worldwide, including using 5G networks … has really taken this to a new level,” Pottinger said. “So, the Party now compiles dossiers on millions of foreign citizens around the world, using the material that it gathers to influence, target, intimidate, reward, blackmail, flatter, humiliate, and ultimately divide and conquer.”





Looks like the worms from this can Apple opened are opening other cans…

https://www.macrumors.com/2021/08/06/apple-to-consider-csam-detection-per-country/?scrolla=5eb6d68b7fedc32c19ef33b4

Apple Addresses CSAM Detection Concerns, Will Consider Expanding System on Per-Country Basis

Apple this week announced that, starting later this year with iOS 15 and iPadOS 15, the company will be able to detect known Child Sexual Abuse Material (CSAM) images stored in iCloud Photos, enabling Apple to report these instances to the National Center for Missing and Exploited Children, a non-profit organization that works in collaboration with law enforcement agencies across the United States.

The plans have sparked concerns among some security researchers and other parties that Apple could eventually be forced by governments to add non-CSAM images to the hash list for nefarious purposes, such as to suppress political activism.

"No matter how well-intentioned, Apple is rolling out mass surveillance to the entire world with this," said prominent whistleblower Edward Snowden, adding that "if they can scan for kiddie porn today, they can scan for anything tomorrow." The non-profit Electronic Frontier Foundation also criticized Apple's plans, stating that "even a thoroughly documented, carefully thought-out, and narrowly-scoped backdoor is still a backdoor."



(Related)

https://9to5mac.com/2021/08/06/apple-internal-memo-icloud-photo-scanning-concerns/

In internal memo, Apple addresses concerns around new Photo scanning features, doubles down on the need to protect children

… In internal memo, Apple addresses concerns around new Photo scanning features, doubles down on the need to protect children





Always a fun topic for my students to kick around.

https://www.washingtonpost.com/technology/2021/08/06/self-driving-ai-death-decisions/

How should autonomous cars make life-or-death decisions? In the best of worlds, they won’t.

The goal of machine learning, say advocates, should be getting to the point where we’re asking if it’s ethical to let people drive.

… “You need to solve safety to get to autonomy, not the other way around,” he said. But the wider industry’s approach was to begin with so-called Level 1 driver assistance features. Then, incrementally work up to a vision that has yet to be realized: Level 5 cars or vehicles advanced enough to make better decisions than humans in all driving conditions — including life-or-death scenarios.

That’s where philosophers and ethicists have long brought up one of the foundational issues facing an autonomous-driving future. It’s known as the “trolley problem,” and it basically boils down to this: How do you teach a car to make complex, life-or-death decisions in seemingly lose-lose scenarios on the road? And if cars can’t do this, would you trust them to carry your child to school or your parent to a doctor’s appointment?

… So now many, including Lunn, are approaching the issue from a different perspective: Why not stop cars from getting in life-or-death situations in the first place?





Tools & Techniques. For example: The word “computer” peaked in 1986 but is present every year covered by Google (1800 to 2019)

https://www.freetech4teachers.com/2021/08/add-googles-ngram-viewer-to-your-list.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+freetech4teachers/cGEY+(Free+Technology+for+Teachers)

Add Google's Ngram Viewer to Your List of Research Tools

Google's Ngram Viewer is a search tool that students can use to explore the use of words and names in books published between 1800 and 2019. The Ngram Viewer shows users a graph illustrating the first appearance of a word or name in literature and the frequency with which that word or name appears in literature since 1800. The graph is based on the books and periodicals that are indexed in Google Books.



Friday, August 06, 2021

Yes, Computer Security students, you should talk to your lawyers early and often.

https://www.zdnet.com/article/black-hat-how-cybersecurity-can-be-a-legal-minefield-for-lawyers/#ftag=RSSbaffb68

Black Hat: How cybersecurity incidents can become legal minefields

When a company becomes the victim of a cyberattack, executives are faced with a tsunami of challenges: containing a breach, remediation, informing customers and stakeholders, identifying those responsible, and conducting a forensic analysis of the incident -- to name but a few.

However, it is not just the real-world issues faced, in the now, that businesses have to tackle: the legal ramifications of a security incident have become more important than ever to consider.

… When attorneys are brought into a cybersecurity incident, they need to consider areas including data protection standards (such as HIPAA or GDPR), insurance coverage, liability, the preservation of evidence, and the potential for lawsuits and class-action claims.

Robust IT systems are no longer enough to protect against the financial and reputational harm of cyberattacks, and it is up to legal teams to assist victims in making the right decisions in the aftermath.

According to Merker, during a cybersecurity incident, "IT professionals and security folks, people who are not lawyers, [often] find themselves in a weird solution where they need to think like a lawyer or at least have one there."





In case you missed it…

https://www.ft.com/content/14440f81-d405-452f-97e2-a81458f5411f

Apple plans to scan US iPhones for child abuse imagery

Security researchers raise alarm over potential surveillance of personal devices

Apple intends to install software on American iPhones to scan for child abuse imagery, according to people briefed on its plans, raising alarm among security researchers who warn that it could open the door to surveillance of millions of people’s personal devices.



(Related) It didn’t take long to slide down that slippery slope, did it? They move from matching known child abuse images to identifying ANY sexually explicit image. What will they look for next and who will they notify?

https://techcrunch.com/2021/08/05/new-apple-technology-will-warn-parents-and-children-about-sexually-explicit-photos-in-messages/

New Apple technology will warn parents and children about sexually explicit photos in Messages

Apple later this year will roll out new tools that will warn children and parents if the child sends or receives sexually explicit photos through the Messages app. The feature is part of a handful of new technologies Apple is introducing that aim to limit the spread of Child Sexual Abuse Material (CSAM) across Apple’s platforms and services.

As part of these developments, Apple will be able to detec t known CSAM images on its mobile devices, like iPhone and iPad, and in photos uploaded to iCloud, while still respecting consumer privacy.

The new Messages feature, meanwhile, is meant to enable parents to play a more active and informed role when it comes to helping their children learn to navigate online communication. Through a software update rolling out later this year, Messages will be able to use on-device machine learning to analyze image attachments and determine if a photo being shared is sexually explicit. This technology does not require Apple to access or read the child’s private communications, as all the processing happens on the device. Nothing is passed back to Apple’s servers in the cloud. [How does the notice get to mom and dad? Bob]



(Related) This is worth a read and offers links to even more…

https://www.pogowasright.org/apples-plan-to-think-different-about-encryption-opens-a-backdoor-to-your-private-life/

Apple’s Plan to “Think Different” About Encryption Opens a Backdoor to Your Private Life





Move toward domestic passports. Creating a valuable hacking target?

https://www.nbcnews.com/tech/gadgets/privacy-efficacy-concerns-remain-new-york-s-vaccine-passport-apps-n1276037

Privacy and efficacy concerns remain for New York's vaccine passport apps

“People are going with something that is completely unproven and potentially harmful,” said one privacy expert.

As New York becomes the first major U.S. city to mandate proof of vaccination against Covid-19 for indoor activities, like going to restaurants and theaters, technology experts are raising concerns that the apps have accuracy and privacy problems, to the point that they are advising New Yorkers to revert to using their original paper vaccine cards.

Some New York legislators have even gone so far as to propose a bill that would mandate that such “immunity passports … only collect the minimal amount of information required to verify an individual’s vaccine or test status” and that “they delete this information within 24 hours.”





On its face, a good idea. Another path down that slippery slope?

https://www.pogowasright.org/infrastructure-bill-would-require-alcohol-monitors-for-all-new-cars/

Infrastructure Bill Would Require Alcohol Monitors for All New Cars

Joseph Simonson and Jack McEvoy report:

The bipartisan infrastructure bill includes a provision that would require auto manufacturers to equip “advanced alcohol monitoring systems” in all new cars.
Buried in the massive proposal—which is already longer than 2,700 pages—is a section titled, “ADVANCED IMPAIRED DRIVING TECHNOLOGY,” which mandates new vehicles include “a system that … passively and accurately detect[s] whether the blood alcohol concentration of a driver of a motor vehicle is equal to or greater than the blood alcohol concentration” of .08, in which case the system would “prevent or limit motor vehicle operation.”

Read more on the Washington Free Beacon.





A direction we could easily try.

https://bdtechtalks.com/2021/08/05/artificial-intelligence-considered-response/

To create AGI, we need a new theory of intelligence

This article is part of “the philosophy of artificial intelligence,” a series of posts that explore the ethical, moral, and social implications of AI today and in the future

… Why do we continue to replicate some aspects of intelligence but fail to generate systems that can generalize their skills like humans and animals? One computer scientist who has been working on AI for three decades believes that to get past the hurdles of narrow AI, we must look at intelligence from a different and more fundamental perspective.

In a paper that was presented at the Brain-Inspired Cognitive Architectures for Artificial Intelligence (BICA*AI), Sathyanaraya Raghavachary, Associate Professor of Computer Science at the University of Southern California, discusses “considered response,” a theory that can generalize to all forms of intelligent life that have evolved and thrived on our planet.

Titled, “Intelligence—consider this and respond!” the paper sheds light on the possible causes of the troubles that have haunted the AI community for decades and draws important conclusions, including the consideration of embodiment as a prerequisite for AGI.





Read more for the capability rather than the current use.

https://www.the-sun.com/news/3419143/china-network-ai-people-facebook-twitter/amp/

Inside China’s chilling network of AI generated PEOPLE on Facebook & Twitter spreading anti-vaxx lies & Covid fake news





Will Criminal Justice students find this useful?

https://www.freetech4teachers.com/2021/08/how-to-use-google-scholar-to-find.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+freetech4teachers/cGEY+(Free+Technology+for+Teachers)

How to Use Google Scholar to Find Federal and State Court Rulings

Earlier this week I wrote about and published a video about how to use Google Scholar to research inventions and their inventors. Case law research is a third aspect of Google Scholar that can be helpful to student researchers.

The case law search function in Google Scholar enables you to find Federal and state cases via keyword search. This is helpful if you’re looking for court rulings on a topic but don’t have a specific case in mind. For example, if I’m researching the development of laws pertaining to the New England lobster fisheries I can enter “lobster fishing” into Google Scholar then search for Federal court cases that include my search term and or search for Maine, New Hampshire, Massachusetts, Connecticut, or Rhode Island state court cases that include “lobster fishing.”

Once you’ve found a court case related to your search term in Google Scholar you can read the case online within Google Scholar. Additionally, Google Scholar lists other cases that have cited the ruling that you’re currently reading. That provides an easy way to find related cases about your chosen research topic.

A video overview of how to use Google Scholar to locate federal and state court rulings is available here



Thursday, August 05, 2021

Interesting argument. If your hacker is a foreign government (or their unacknowledged criminal allies) are you immune from security negligence claims?

https://www.theregister.com/2021/08/04/solarwinds_lawsuit_shareholders_motion_dismiss/

SolarWinds urges US judge to toss out crap infosec sueball: We got pwned by actual Russia, give us a break

SolarWinds is urging a US federal judge to throw out a lawsuit brought against it by aggrieved shareholders who say they were misled about its security posture in advance of the infamous Russian attack on the business.

Insisting that it was "the victim of the most sophisticated cyberattack in history" in a court filing, SolarWinds described a lawsuit from some of its smaller shareholders as an attempt to "convert this sophisticated cyber-crime" into an unrelated securities fraud court case.

"The Court should dismiss the Complaint because it fails to satisfy the heightened standards for pleading a Section 10(b) claim imposed by the Private Securities Litigation Reform Act," it said [PDF].





A podcast (and transcript) for once and future crooks.

https://www.trendmicro.com/en_us/ciso/21/h/cybercrime-today-and-the-future.html

Cybercrime: Today and the Future

Trend Micro Research experts Erin Sindelar and Rik Ferguson use current trends and data to paint a picture of cybercrime in 2021 and shine a light on what it could look like in 2030.





You have to have a child abuse photo to locate copies of that photo. It’s easy to see what the next (AI driven?) step must be.

https://9to5mac.com/2021/08/05/report-apple-photos-casm-content-scanning/

Report: Apple to announce client-side photo hashing system to detect child abuse images in user’s photos libraries

Apple is reportedly set to announce new photo identification features that will use hashing algorithms to match the content of photos in user’s photo libraries with known child abuse materials, such as child pornography.

Apple’s system will happen on the client — on the user’s device — in the name of privacy, so the iPhone would download a set of fingerprints representing illegal content and then check each photo in the user’s camera roll against that list. Presumably, any matches would then be reported for human review.





Another unhackable tool gets hacked?

https://gizmodo.com/master-face-researchers-say-theyve-found-a-wildly-succ-1847420710/amp

'Master Face': Researchers Say They've Found a Wildly Successful Bypass for Face Recognition Tech

In addition to helping police arrest the wrong person or monitor how often you visit the Gap, facial recognition is increasingly used by companies as a routine security procedure: it’s a way to unlock your phone or log into social media, for example. This practice comes with an exchange of privacy for the promise of comfort and security but, according to a recent study, that promise is basically bullshit.

… “Our results imply that face-based authentication is extremely vulnerable, even if there is no information on the target identity,” researchers write in their study. “In order to provide a more secure solution for face recognition systems, anti-spoofing methods are usually applied. Our method might be combined with additional existing methods to bypass such defenses,” they add.

According to the study, the vulnerability being exploited here is the fact that facial recognition systems use broad sets of markers to identify specific individuals. By creating facial templates that match many of those markers, a sort of omni-face can be created that is capable of fooling a high percentage of security systems. In essence, the attack is successful because it generates “faces that are similar to a large portion of the population.”





Another anti-manipulation law. When everything is flagged, we’ll only find unchanged images suspicious.

https://www.makeuseof.com/what-is-norway-photo-retouching-law/

What Is Norway's New Photo Retouching Law?

Norway issued a new law on retouching photos to improve mental health. Here's everything you need to know about the latest regulations.

The internet is full of models exhibiting their flawless and unrealistic bodies, which can exacerbate body insecurities.

In an attempt to mitigate these unrealistic beauty standards, Norway has passed a law requiring influencers and advertisers to label their retouched photos. We're going to be taking a look at what that law is, and how it affects you.

The new law passed by the Norwegian government requires influencers sponsored for social media posts and brands to disclose any modification on their photos using a ministry-approved label. Essentially, you'll now be told any time an image has been edited.





At first glance, rather vanilla.

https://www.meritalk.com/articles/dhs-st-releases-strategic-plan-for-ai-ml/

DHS S&T Releases Strategic Plan for AI & ML

The Department of Homeland Security (DHS) Science and Technology Directorate (S&T) released an artificial intelligence (AI) and machine learning (ML) strategic plan that will look to outline the DHS approach to using these emerging technologies.

The plan has three goals: to “drive next-generation AI/ML technologies” for use across DHS, facilitate the use of AI and ML in the DHS missions, and build up an AI and ML workforce that is interdisciplinary.