Monday, February 14, 2022

I wonder where else this is happening.

https://www.theregister.com/2022/02/14/cambodia_national_internet_gateway/

Full-time internet surveillance comes to Cambodia this week

Cambodia’s National Internet Gateway comes online this Wednesday, exposing all traffic within the country to pervasive government surveillance.

As The Register reported when the Gateway was announced in January 2021, Cambodia's regime will require all internet service providers and carriers to route their traffic through the Gateway. Revocation of operating licences or frozen bank accounts are among penalties for non-compliance.

All incoming traffic to Cambodia will also be required to pass through the Gateway and be subject to censorship.

Human Rights Watch's analysis of the Gateway suggests it will "allow the government to monitor all internet activities and grant the authorities broad powers to block and disconnect internet connections."



Anonymity is evil? Our experience with vaccine passports is leading us to mandatory identity papers.

https://www.healthcareitnews.com/news/emea/eu-vaccine-passport-paves-way-digital-identity-pitfalls-lie-ahead

The EU vaccine passport paves the way for digital identity – but pitfalls lie ahead

Vaccine passports, crucial to managing the pandemic, have led to a rapid advance in digital health technology. The Commissioner for Justice, [Not health? Bob] Didier Reynders said in a statement that they allowed freedom of movement during the pandemic: “Without this extension, we risk having many divergent national systems, and all the confusion and obstacles that this would cause.”

Still, he says: “Digital identity advancement has definitely accelerated because of COVID.” The certificates are, “one of the first, certainly the widest implemented credential we’ve seen.”

In the future, we may need to provide less information about ourselves in order to prove who we are, a shift that would facilitate online dealings in citizenship, banking and shopping and healthcare.



Illustrating that “paying attention” isn’t enough.

https://www.bespacific.com/the-changing-room-illusion/

The Changing Room Illusion

The Changing Room Illusion is an example of “graduate change blindness,” a phenomenon in which observers are unable to notice changes to the world around them when those changes occur gradually. In virtually all prior cases, gradual change blindness is studied by changing individual objects (e.g., a chimney disappearing or a facial expression shifting). While trying to prepare a novel example of this phenomenon for students, I realized that I could change dozens of items change without observers noticing. Overall, this illusion highlights how people may actually perceive and remember far more of the world around them than they intuitively realize.”



Perspective. NFTs must have value if the Tax Men accept them.

https://www.bbc.com/news/business-60369879

HMRC seizes NFT for first time in £1.4m fraud case

The UK tax authority has seized three Non-Fungible Tokens (NFT) as part of a probe into a suspected VAT fraud involving 250 alleged fake companies.

HM Revenue and Customs (HMRC) said three people had been arrested on suspicion of attempting to defraud it of £1.4m.

The authority said it was the first UK law enforcement to seize an NFT.

NFTs are assets in the digital world that can be bought and sold, but which have no tangible form of their own.


Sunday, February 13, 2022

The WSJ gets it!

https://www.wsj.com/articles/russians-have-already-started-hybrid-war-with-bomb-threats-cyberattacks-ukraine-says-11644748413

Russians Have Already Started Hybrid War With Bomb Threats, Cyberattacks, Ukraine Says

Moscow is using cyberattacks, economic pressure and, most recently, false bomb threats, to undermine its neighbor, Kyiv says



Incentive for new laws? If the NFL comes under attack, WE GOTTA DO SOMETHING! (Perhaps a few signed jerseys were part of their ransom demand.)

https://www.databreaches.net/san-francisco-49ers-confirm-ransomware-attack/

San Francisco 49ers confirm ransomware attack

Catalin Cimpanu reports:

The San Francisco 49ers NFL team has fallen victim to a ransomware attack that encrypted files on its corporate IT network, a spokesperson for the team has told The Record.
The team confirmed the attack earlier today after the operators of the BlackByte ransomware listed the team as one of their victims on Saturday on a dark web “leak site” the group typically uses to shame victims and force them into paying their extortion demands.

Read more at The Record.

DataBreaches.net had reached out to the team yesterday to obtain a statement but has not heard back. In looking at the proof of claim data, however, DataBreaches.net had noticed that the data were all invoices to the team from 2020. BlackByte did not provide any proof of the full scope of any data exfiltration. The team’s statement to The Record indicates that they believe the attack was limited to their corporate network.



Real world impact of virtual technology.

https://news.sky.com/story/virtual-reality-mishaps-accidental-damage-claims-involving-vr-headsets-are-on-the-rise-12539899

Kids smashing figurines and fighting zombies on the TV - VR headset insurance claims rocket

Aviva has said home contents claims involving the gaming headsets rose by 31% last year and have increased by 68% in five years.

The average value of a VR-related claim sits at about £650, with TVs being the most damaged item.



If Apple can honestly say, “We never thought of that” then they need to hire more paranoids!

https://www.huffpost.com/entry/apple-airtags-tracking_n_61f425ade4b067cbfa1cb2b8

AirTags Are A Growing Headache For Apple Amid Disturbing Reports Of Tracking

Women around the country say they've gotten notifications that the relatively cheap location-tracking devices are following them.

Across the country, women are reporting similar incidents to police and local news media in an attempt to raise public awareness that Apple’s AirTags can be hidden on cars and in personal belongings to track people without their knowledge. The stories proliferate on TikTok, and some have been posted to Reddit and Twitter.

Sometimes people find the devices, and sometimes they don’t.

Location tracking devices are not new. Tile also makes pocket-size trackers for keys and wallets, marketing itself as “the world’s largest lost and found.”

Apple’s network, however, is particularly powerful. AirTags are able to use the Find My network, which uses Bluetooth technology and other people’s iPhones, MacBooks and iPads ― hundreds of millions of devices, according to Apple ― to ping location signals back to the person who owns it. The process is so efficient it barely touches a device’s battery power. And because the world is already blanketed in Apple products, the location data is generally very precise.

A tracking device from LandAirSea relies on satellite GPS tracking with a monthly paid subscription. Tile also uses Bluetooth, like AirTags. But one New York Times tech reporter who tried those three different products to track her husband found that the Apple device yielded the most specific results, particularly in a metropolitan environment. (Yes, she had his permission.)

An iPhone running iOS 14.5 or later will send a notification if it detects an AirTag traveling with someone who does not own it. The notification will pop up either at the end of the day or when the iPhone detects you’ve arrived home

The company instructs those who find an unwanted AirTag to disable it using their phone or by taking it apart; detailed instructions can be found on its website.



If different rules apply to different races/religions/etc is it automatically a hate crime?

https://www.pogowasright.org/article-race-and-online-privacy/

Article: Race and Online Privacy

Over on Public Citizen, Jeff Sovern points us to an article by Anita L. Allen of Penn, Dismantling the Black Opticon: Race Equity and Online Privacy and Data Protection Reform, forthcoming in the Yale Law Journal.

Abstract
In the opening decades of the 21st century popular online platforms rapidly transformed the world. These platforms have come with benefits, but a heavy price to information privacy and data protection. I propose a new framework for describing African Americans’ multifaceted situation of risk and harm relating to wrongful data collection, use, analysis and sharing online: the Black Opticon. African Americans online face three distinguishable but related categories of vulnerability to bias and discrimination that I dub the “Black Opticon”: discriminatory oversurveillance (panoptic vulnerabilities to, for example AI empowered facial recognition and geolocation technologies); discriminatory exclusion (ban-optic vulnerabilities to, for example, unequal access to goods, services and public accommodations advertised or offered online); and discriminatory predation (con-optic vulnerabilities to, for example, con-jobs, scams and exploitation relating to credit, employment, business and educational opportunities). Escaping the Black Opticon is unlikely without acknowledgement of privacy’s unequal distribution and privacy law’s outmoded and unduly race-neutral façade. African Americans could benefit from race-conscious efforts to shape a more equitable digital public sphere through improved laws and legal institutions. This essay critically elaborates the Black Opticon triad and considers whether the Virginia Consumer Data Protection Act (2021), the federal Data Protection Act (2021), and new resources for the Federal Trade Commission proposed in 2021 possibly meet imperatives of a race-conscious African American Online Equity Agenda, specifically designed to help dismantle the Black Opticon. The 2021 enacted Virginia law and the bill proposing a new federal data protection agency include civil rights and non-discrimination provisions; and the Federal Trade Commission has an impressive stated commitment to marginalized peoples within the bounds of its authority. Nonetheless the limited scope and pro-business orientation of the Virginia law, and barriers to follow-through on federal measures, are substantial hurdles in the road to true platform equity. The path forward requires jumping those hurdles, regulating platforms, and indeed all of the digital economy, in the interests of nondiscrimination, anti-racism and anti-subordination. Toward escaping the Black Opticon’s pernicious gaze, African Americans and their allies will continue the pursuit of viable strategies for justice and equity in the digital economy.



The first(?) of many technologies to be controlled.

https://arxiv.org/abs/2202.02734

The Self-Driving Car: Crossroads at the Bleeding Edge of Artificial Intelligence and Law

Artificial intelligence (AI) features are increasingly being embedded in cars and are central to the operation of self-driving cars (SDC). There is little or no effort expended towards understanding and assessing the broad legal and regulatory impact of the decisions made by AI in cars. A comprehensive literature review was conducted to determine the perceived barriers, benefits and facilitating factors of SDC in order to help us understand the suitability and limitations of existing and proposed law and regulation. (1) existing and proposed laws are largely based on claimed benefits of SDV that are still mostly speculative and untested; (2) while publicly presented as issues of assigning blame and identifying who pays where the SDC is involved in an accident, the barriers broadly intersect with almost every area of society, laws and regulations; and (3) new law and regulation are most frequently identified as the primary factor for enabling SDC. Research on assessing the impact of AI in SDC needs to be broadened beyond negligence and liability to encompass barriers, benefits and facilitating factors identified in this paper. Results of this paper are significant in that they point to the need for deeper comprehension of the broad impact of all existing law and regulations on the introduction of SDC technology, with a focus on identifying only those areas truly requiring ongoing legislative attention.



Tools of war, and how to use them.

https://www.degruyter.com/document/isbn/9781474483599/html?lang=en

Ethics of Drone Strikes

The violent use of armed, unmanned aircraft (‘drones’) is increasing worldwide, but uncertainty persists about the moral status of remote-control killing and why it should be restrained. Practitioners, observers and potential victims of such violence often struggle to reconcile it with traditional expectations about the nature of war and the risk to combatants. Addressing the ongoing policy concern that state use of drone violence is sometimes poorly understood and inadequately governed, the book’s ethical assessments are not restricted to the application of traditional Just War principles, but also consider the ethics of artificial intelligence (AI), virtue ethics, and guiding principles for forceful law-enforcement.

This edited collection brings together nine original contributions by established and emerging scholars, incorporating expertise in military ethics, critical military studies, gender, history, international law and international relations, in order to better assess the multi-faceted relationship between drone violence and justice.



Manage your organization.

https://link.springer.com/chapter/10.1007/978-3-030-94873-3_27

Corporate Governance Innovations

The development of modern digital technologies provides tremendous opportunities for their use in corporate governance, which poses unprecedented challenges to corporate law to be tackled as soon as possible. Technologies are developing much faster than law. Possible barriers or ambiguity can hinder this development and require, therefore any public order claiming to be competitive should duly assessment them from the legislative point of view. The purpose of the research prompted the author to go beyond national jurisdictions and assess the impact of digital technology on corporate governance across the world. In the research, authors attempted to identify and give a general description of technologies that can affect corporate governance, such as distributed ledger technology, blockchain, smart contracts, artificial intelligence, etc. The paper estimates the advantages of holding a general meeting of corporate shareholders using DLT, as well as the tokenization of corporate assets. Particular attention is paid to the trends towards decentralization of corporate governance in platform-type companies and decentralized autonomous companies. In conclusion, applications of artificial intelligence in corporate governance are considered.


Saturday, February 12, 2022

As goes law, so goes all professions?

https://www.thomsonreuters.com/en/careers/careers-blog/how-ai-and-machine-learning-is-shaping-legal-strategy.html

How AI and machine learning is shaping legal strategy

Five years ago, many experts predicted that we would routinely see self-driving cars on the road in 2021. That has not come to pass. What we do have are cars where Artificial Intelligence (AI) can assist drivers. Forward collision warning, lane departure warning, or rear drive assistance are all AI-enable features that make my life safer.

Why talk about cars in the context of AI and the law? Because it illustrates a shift from full automation to assistance, or augmentation – helping individuals perform some tasks better, faster, smarter. And augmentation, rather than automation, is key to the role AI and machine learning can play in shaping legal strategy.

When we think about AI today in legal tech, it is important to remember that AI is not merely one thing. Instead, it is a variety of technologies and task-specific applications that can assist legal professionals in the exercise of their function. (The future of law firms and lawyers in the age of artificial intelligence)



Is this enough to encourage some lawyer to sue to prevent “owners” from killing their AI (by turning the computer off)? (Is AI as conscious as a cute, adorable little puppy?)

https://futurism.com/the-byte/openai-already-sentient

OPENAI CHIEF SCIENTIST SAYS ADVANCED AI MAY ALREADY BE CONSCIOUS

OpenAI’s top researcher has made a startling claim this week: that artificial intelligence may already be gaining consciousness.

Ilya Sutskever, chief scientist of the OpenAI research group, tweeted today that “it may be that today’s large neural networks are slightly conscious.”

Needless to say, that’s an unusual point of view. The widely accepted idea among AI researchers is that the tech has made great strides over the past decade, but still falls far short of human intelligence, nevermind being anywhere close to experiencing the world consciously.

It’s possible that Sutskever was speaking facetiously, but it’s also conceivable that as the top researcher at one of the foremost AI groups in the world, he’s already looking downrange.



Perspective. A way to “control” AI?

https://venturebeat.com/2022/02/11/symbolic-ai-the-key-to-the-thinking-machine/

Symbolic AI: The key to the thinking machine

Even as many enterprises are just starting to dip their toes into the AI pool with rudimentary machine learning (ML) and deep learning (DL) models, a new form of the technology known as symbolic AI is emerging from the lab that has the potential to upend both the way AI functions and how it relates to its human overseers.

Symbolic AI’s adherents say it more closely follows the logic of biological intelligence because it analyzes symbols, not just data, to arrive at more intuitive, knowledge-based conclusions. It’s most commonly used in linguistics models such as natural language processing (NLP) and natural language understanding (NLU), but it is quickly finding its way into ML and other types of AI where it can bring much-needed visibility into algorithmic processes.

… One of the keys to symbolic AI’s success is the way it functions within a rules-based environment. Typical AI models tend to drift from their original intent as new data influences changes in the algorithm. Scagliarini says the rules of symbolic AI resist drift, so models can be created much faster and with far less data to begin with, and then require less retraining once they enter production environments.



Perspective. Remember, Zillow tried the same thing with houses and failed spectacularly.

https://www.theverge.com/22923871/carvana-pandemic-used-car-prices-sold-online-chip-shortage

A ROBOT BOUGHT MY SEVEN-YEAR-OLD CAR FOR MORE THAN I PAID BRAND-NEW

In December 2014, I bought a Honda Fit right off the lot. It had 23 miles, and I paid $20,814.80, including accessories and an extended warranty. This December, a buzzy startup called Carvana drove away with my car, cutting me a check for $20,905 — leaving me with a profit of $90.20.

Not only that, but Carvana’s offer was $5,000 higher than Vroom, $6,000 higher than TrueCar, and $7,500 higher than CarMax. Carvana’s offer changed day by day, too: the final one I accepted was $1,338 higher than its lowest quote.

I knew I had everything going for me — low mileage, no accidents, and desirable trim at a time when car prices are going through the roof on a model that Honda discontinued. And yet, it sounded ludicrous. Used cars almost never sell for more than their original price, and the company knew next to nothing about me. Yet, Carvana’s algorithm had agreed to pay $20K for my car sight-unseen, even bring a pre-printed check to my door, before any inspection took place. The online quote arrived so fast, I knew a human couldn’t have been involved.

But Carvana didn’t become the fastest-growing digital car dealership in the United States (and the third-fastest company to ever make the Fortune 500 list) by asking pesky humans the price of a car. Instead, it built a computer system, one it trusts so implicitly that no employee was ever going to question what my Honda Fit was worth.

Carvana executives don’t think they have a bug. But they also can’t quite explain what’s going on with my Honda Fit.

The company’s last three quarterly earnings releases show it’s more than doubled its revenue and profit year over year and that the company averages over $4,000 in profit for every car it sells. But it’s not clear how Carvana could make anywhere near that on my vehicle.


Friday, February 11, 2022

An interesting attack on lawyers. Are they sure cyber criminals are opposed to human rights?

https://www.pogowasright.org/these-cybercriminals-plant-criminal-evidence-on-human-rights-defender-lawyer-devices/

These cybercriminals plant criminal evidence on human rights defender, lawyer devices

Charlie Osborne reports:

Cybercriminals are hijacking the devices of civil rights activists and planting “incriminating evidence” in covert cyberattacks, researchers warn.
According to SentinelLabs, an advanced persistent threat (APT) group dubbed ModifiedElephant has been responsible for widespread attacks targeting human rights activists and defenders, academics, journalists, and lawyers across India.
The APT is thought to have been in operation since at least 2012, and over the past decade, ModifiedElephant has continually and persistently targeted specific, high-profile people of interest.
However, rather than focusing on data theft, the APT’s activities are far more sinister: once inside a victim’s machine, the group conducts surveillance and may plant incriminating files later used to prosecute individuals.

Read more at ZDNet.

Dirty tricks” have pretty much always been a part of politics but this is on the level where the targets may wind up prosecuted or tortured. It is really no surprise that this is happening, though. And it’s another reason for people to be concerned about securing devices and not opening files or clicking on links



This is the tool the IRS was going to rely on?

https://www.bespacific.com/id-me-gathers-lots-of-data-besides-face-scans/

ID.me gathers lots of data besides face scans

Washington Post – “…A private company that government agencies have used to verify the identities of millions of Americans through facial recognition used a variety of other data techniques to screen users, including collecting people’s phone location records and using software from the data-mining company Palantir to assess whether they have ties to “organized crime.” But despite the scale of the data gathering by the company, ID.me, revealed in newly released records, the system has been exploited by scammers. Federal prosecutors last month said a New Jersey man was able to verify fake driver’s licenses through an ID.me system in California as part of a $2.5 million unemployment-fraud scheme. ID.me has pointed to the scam as an example of how well its systems work, noting that it referred the case to federal law enforcement after an internal investigation. But the criminal complaint in the case shows that ID.me’s identification systems did not detect bogus accounts created around the same day that included fake driver’s licenses with photos of the suspect’s face in a cartoonish curly wig…”



If we searched for truth, we wouldn’t make as much money.

https://www.bespacific.com/researchers-warn-that-social-media-may-be-fundamentally-at-odds-with-science/

Researchers warn that social media may be ‘fundamentally at odds’ with science

TechCrunch: “A special set of editorials published in today’s issue of the journal Science argue that social media in its current form may well be fundamentally broken for the purposes of presenting and disseminating facts and reason. The algorithms are running the show now, they argue, and the systems priorities are unfortunately backwards. In an incisive (and free to read) opinion piece by Dominique Brossard and Dietram Scheufele of the University of Wisconsin-Madison, the basic disconnect with what scientists need and what social media platforms provide is convincingly laid out. “Rules of scientific discourse and the systematic, objective, and transparent evaluation of evidence are fundamentally at odds with the realities of debates in most online spaces,” they write. “It is debatable whether social media platforms that are designed to monetize outrage and disagreement among users are the most productive channel for convincing skeptical publics that settled science about climate change or vaccines is not up for debate.” The most elementary feature of social media that reduces the effect of communication by scientists is pervasive sorting and recommendation engines. This produces what Brossard and Scheufele call “homophilic self-sorting” — the ones who are shown this content are the ones who are already familiar with it. In other words, they’re preaching to the choir. “The same profit-driven algorithmic tools that bring science-friendly and curious followers to scientists’ Twitter feeds and YouTube channels will increasingly disconnect scientists from the audiences that they need to connect with most urgently,” they write. And there’s no obvious solution: “The cause is a tectonic shift in the balance of power in science information ecologies. Social media platforms and their underlying algorithms are designed to outperform the ability of science audiences to sift through rapidly growing information streams and to capitalize on their emotional and cognitive weaknesses in doing so. No one should be surprised when this happens.”…


Thursday, February 10, 2022

Summary

https://www.databreaches.net/tech-transactions-data-privacy-2022-report-ransomware-reporting-requirements-a-look-forward-into-evolving-security-incident-notification-rules/

Tech Transactions & Data Privacy 2022 Report: Ransomware Reporting Requirements: A Look Forward into Evolving Security Incident Notification Rules

Michael J. Waters and Colin H. Black of Polsinelli write:

Tech Transactions & Data Privacy 2022 Report

Data breach notification laws in the United States have historically focused on notifying individuals, regulators and others in situations in which personal information has been accessed or acquired. Ransomware attacks, while incredibly disruptive, do not always involve data access or acquisition and, as such, are not always reported. As ransomware attacks increase in frequency and the severity of their impact, both law enforcement and industry regulators are seeking greater visibility into these incidents and, through the publication of new guidance and the amendment of notification laws, are starting to require increased reporting.

Read more The National Law Review.


(Related)

https://www.databreaches.net/secs-breach-notification-proposal-one-step-closer-to-a-final-vote/

SEC’s breach notification proposal one step closer to a final vote

Tonya Riley reports:

The Securities and Exchange Commission voted Wednesday 3-1 to approve a recommendation for tighter mandatory cybersecurity requirements for financial institutions. The proposed rule will now open to public comment before a final vote.
The proposed rules and amendments are designed to enhance cybersecurity preparedness and could improve investor confidence in the resiliency of advisers and funds against cybersecurity threats and attacks,” SEC Chairman Gary Gensler said at the agency’s open meeting.
Most critically, the new rule would require confidential reports of any “significant” cybersecurity incidents to the SEC within 48 hours.

Read more at CyberScoop.



Surveil the teacher – it’s for the children.

https://www.pogowasright.org/iowa-republican-introduces-bill-to-put-cameras-in-every-public-school-classroom/

Iowa Republican Introduces Bill to Put Cameras in Every Public School Classroom

Dan Spinelli reports:

Amid the ongoing Republican freakout over Critical Race Theory and the teaching of other supposedly objectionable material in public schools, an Iowa Republican has introduced a bill that would take the policing of the state’s teachers to a whole new level.
Earlier this week, Republican state Rep. Norlin Mommsen introduced a bill to place cameras at the back of public school classrooms so parents can monitor what’s being taught there. The seemingly Orwellian idea would function in a similar way to a body camera on a police officer, Mommsen told The Center Square, a conservative news site.

Read more at Mother Jones.



A frequent contributor.

https://www.pogowasright.org/article-the-limitations-of-privacy-rights-daniel-solove/

Article: “The Limitations of Privacy Rights” (Daniel Solove)

Professor and privacy law scholar Dan Solove has a new article that he is sharing via SSRN, where it can be downloaded for free. The article is called, “The Limitations of Privacy Rights.” Here is the abstract:

Individual privacy rights are often at the heart of information privacy and data protection laws. The most comprehensive set of rights, from the European Union’s General Data Protection Regulation (GDPR), includes the right to access, right to rectification (correction), right to erasure, right to restriction, right to data portability, right to object, and right to not be subject to automated decisions. Privacy laws around the world include many of these rights in various forms.
In this article, I contend that although rights are an important component of privacy regulation, rights are often asked to do far more work than they are capable of doing. Rights can only give individuals a small amount of power. Ultimately, rights are at most capable of being a supporting actor, a small component of a much larger architecture. I advance three reasons why rights cannot serve as the bulwark of privacy protection. First, rights put too much onus on individuals when many privacy problems are systematic. Second, individuals lack the time and expertise to make difficult decisions about privacy, and rights cannot practically be exercised at scale with the number of organizations than process people’s data. Third, privacy cannot be protected by focusing solely on the atomistic individual. The personal data of many people is interrelated, and people’s decisions about their own data have implications for the privacy of other people.
The main goal of providing privacy rights aims to provide individuals with control over their personal data. However, effective privacy protection involves not just facilitating individual control, but also bringing the collection, processing, and transfer of personal data under control. Privacy rights are not designed to achieve the latter goal; and they fail at the former goal.
After discussing these overarching reasons why rights are insufficient for the oversized role they currently play in privacy regulation, I discuss the common privacy rights and why each falls short of providing significant privacy protection. For each right, I propose broader structural measures that can achieve its underlying goals in a more systematic, rigorous, and less haphazard way.

Solove, Daniel J., The Limitations of Privacy Rights (February 1, 2022). Available at SSRN (free download): https://ssrn.com/abstract=4024790 or http://dx.doi.org/10.2139/ssrn.4024790

If you are not already subscribing to his free newsletter, you can sign up here.



A list for my Ethical Hackers.

https://www.makeuseof.com/penetration-testing-for-security-professionals/

The Top 10 Penetration Testing Tools for Security Professionals


Wednesday, February 09, 2022

Cyber war: Disrupting the logistics that enable warfighting is a legitimate strategic goal.

https://www.cpomagazine.com/cyber-security/fuel-troubles-continue-in-europe-as-oil-terminals-in-netherlands-and-belgium-suffer-cyber-attacks-unclear-if-breaches-are-coordinated/

Fuel Troubles Continue in Europe as Oil Terminals in Netherlands and Belgium Suffer Cyber Attacks; Unclear if Breaches Are Coordinated

Following closely on the heels of incidents with two oil suppliers in Germany, oil terminals in two other European countries have been hit with cyber attacks.

Belgium’s SEA-Invest and the Netherlands’ Evos are both reporting recent cyber attacks that have disrupted operations, collectively impacting port operations throughout Europe and Africa.



Biometric ID for all!

https://www.theregister.com/2022/02/09/sri_lanka_to_adopt_indias/

Sri Lanka to adopt India’s Aadhaar digital identity scheme

Sri Lanka has decided to adopt a national digital identity framework based on biometric data and will ask India if it can implement that nation’s Aadhaar scheme.

The island nation had previous indicated it would work with the Modular Open Source Identity Platform (MOSIP), an organisation based in India that offers tools governments can use to create and manage digital identities.

But a list of Cabinet decisions published on Tuesday, Sri Lanka’s government announced its intention to ask India for a grant of its scheme, which has been widely interpreted as meaning India share Aadhaar technology.

Aadhaar sees Indian citizens and residents issued a twelve-digit identity number, linked to either a fingerprint or iris scan, and is used to authenticate users of government services.



If I can use Google’s image search to find your face on social media, can you ban a company for doing it more efficiently?

https://www.theverge.com/2022/2/9/22925094/clearview-facial-recognition-dhs-doj-justice-interior-pentagon

Lawmakers call on feds to drop Clearview AI facial recognition contracts

A group of four progressive lawmakers — Sens. Markey (D-MA) and Merkley (D-OR) and Reps. Jayapal (D-WA) and Pressley (D-OH) — sent letters to several federal agencies on Wednesday calling for an end to their use of Clearview AI’s controversial facial recognition system.

The letter was sent to the Departments of Justice, Defense, Homeland Security, and the Interior. All four agencies were identified in an August 2021 report from the General Accounting Office as using Clearview for “domestic law enforcement” purposes.

Clearview AI’s technology could eliminate public anonymity in the United States,” the letter reads, describing the system as “capable of fundamentally dismantling Americans’ expectation that they can move, assemble, or simply appear in public without being identified.”

The letter adds to ongoing pressure on federal agencies to drop facial recognition systems entirely. On Monday, the director of the General Services Agency (GSA) told The Washington Post the agency is “committed to not deploying facial recognition… until rigorous review has given us confidence that we can do so equitably.” Still other agencies are planning to expand their use of the technology once it is more adequately tested.


(Related) While I never want that much familiarity with the IRS, I do enjoy walking into my bank and being greeted by name. (They do it the old fashioned way.)

https://gizmodo.com/id-me-facial-recognition-optional-government-1848503651

ID.me Says It Will Make Facial Recognition Optional for Government Agencies

The major reversal comes one day after the IRS ended its use of ID.me's facial recognition service and amidst an outpouring of public pushback.

In a major turn of events, embattled identity verification company ID.me says it will make facial recognition verification optional for all of its public sector government partners. Additionally, starting March 1, the company says all ID.me users will be able to delete their face scans.

That reversal comes just one day after the Internal Revenue Service said it would scrap ID.me’s facial recognition service for users trying to access online IRS services amid an outpouring of criticism from civil liberty groups and a bipartisan collection of lawmakers.



Well golly gosh and gee whiz, we might could maybe need this capability at some point.

https://theintercept.com/2022/02/08/cellebrite-phone-hacking-government-agencies/

WHY HAVE 14 OF 15 U.S. CABINET DEPARTMENTS BOUGHT PHONE UNLOCKING TECHNOLOGY? FEW WILL SAY.

INVESTIGATORS WITH THE U.S. Fish and Wildlife Service frequently work to thwart a variety of environmental offenses, from illegal deforestation to hunting without a license. While these are real crimes, they’re not typically associated with invasive phone hacking tools. But Fish and Wildlife agents are among the increasingly broad set of government employees who can now break into encrypted phones and siphon off mounds of data with technology purchased from the surveillance company Cellebrite.



Perspective. $600 Billion is too small to be a monopoly?

https://www.cnbc.com/2022/02/08/facebook-market-cap-under-600-billion-threshold-for-antitrust-bills.html

Facebook market cap falls below $600 billion — which could actually help it dodge new antitrust scrutiny

Facebook’s shrinking market cap could hold one upside for the tech giant: the possibility of skirting new antitrust liability.

The company, recently renamed Meta, closed with a market cap below $600 billion on Tuesday for the first time since May 2020. The stock fell 2.1%, bringing it to a market cap of $599.32 billion.

The $600 billion market cap figure also happens to be the number House legislators picked as the threshold for a “covered platform” under a package of competition bills designed specifically to target Big Tech. If Meta were to remain below that threshold, it could avoid the additional hurdles the bills would install for how it can conduct its business and make deals, while its larger peers like Amazon,  Alphabet, Apple and even Microsoft become subject to the rules.



Perspective. I’ll need someone with a background in both Law and Economics to explain this to me.

https://www.bespacific.com/public-blockchains-are-the-new-national-economies-of-the-metaverse/

Public Blockchains Are the New National Economies of the Metaverse

Wired:When we speak of an economy, we usually refer to a country or a region where interrelated activities of production, consumption, and trade happen. When we speak of blockchains, we speak of decentralized computer networks. On the surface, these two seem unrelated. But with on-chain activities growing at warp speed, the ecosystems of layer 1 public blockchains (the foundational blockchain protocols where decentralized databases and computer programs are run) are starting to look more and more similar to national economies—except the nation in this case is not a physical territory but a decentralized digital network. The trustless and programmable nature of public blockchains have made it possible to implement new “fiscal” and “monetary” policy tools in the blockchain economies, which in many cases have advantages over the traditional economic policy tools of national governments. In addition, the proof-of-stake mechanism adopted by second-generation public blockchains introduces a de facto “universal basic capital income” for their network “citizens.” This could be a major innovation in how economic systems distribute values among participants, with broader income-distribution implications for years to come as blockchain economies grow. (Disclosure: I hold cryptocurrency and have previously advised crypto funds.) Public blockchains allow anyone to deploy decentralized applications (DApps) on top, which users can interact with. Currently, decentralized finance (DeFi) applications and non-fungible token assets (NFTs) are the two main economic activities on layer 1 blockchains and associated layer 2 chains. (Layer 2 chains are secondary blockchain networks that rely on the underlying layer 1 for security, but typically offer faster and cheaper transactions.) Both activities have grown tremendously in the past couple of years. At the end of November 2021, gross total value locked from DeFi in the top 10 layer 1 blockchain platforms exceeded $250 billion, a year-over-year growth of 1,400 percent. And according to NFTGo.io, the market cap of NFT projects on Ethereum alone reached over $7 billion in November, increasing over 14,500 percent from a year before…”