Category: News

Carbon emissions by mobile network operators declining: GSMA

The carbon emissions of mobile network operators declined by six per cent globally between 2019-2022, according to the GSMA’s fourth Mobile Net Zero report, which was released today at MWC Barcelona 2024.

The report reveals regional variations in the reduction of operational emissions, with Europe leading the way with a 50 per cent reduction, a release stated. In North America, Latin America, the Middle East and North Africa, emissions fell by 20-30 per cent.

Although operational emissions rose in China and the Asia-Pacific – the world’s largest and second largest mobile markets respectively – global emissions overall decreased, despite growing data usage, it said.

“Achieving the mobile sector’s target to reach net zero by 2050 relies on the industry cutting its emissions to 45 per cent below 2020 levels by 2030. This means that overall emissions – including Scope 1, 2 and 3 – need to fall by around seven per cent up to 2030,” the GSMA, which represents the interests of mobile operators around the world, said.

“Recent progress shows that this is possible, as the target reduction rate has been exceeded over the past three years for operational emissions in Europe, North America, Latin America and MENA (Middle East and North Africa).” The report notes, “improved data and further analysis are needed to better understand ‘Scope 3’ trends, which relate to emissions from operators’ supply chains.”

According to the analysis, “operational emissions fell despite surging demand for data and connectivity – the number of mobile connections globally rose by seven per cent between 2019-2022, while internet traffic more than doubled. The industry’s carbon reductions were largely driven by strong progress on energy efficiency and use of renewable energy.”

Commenting on the findings, John Giusti, chief regulatory officer at the GSMA, said, “the evidence shows that the mobile industry’s commitment to net zero by 2050 is paying off. Despite surging demand for connectivity and data, the global carbon emissions of operators continued to fall.

“Although we see the strongest early lead from Europe in the race to net zero, and encouraging progress in the Americas and MENA, this is a race that everybody needs to win – or else we all lose. We see what is possible where there is a focus on energy efficiency and access to renewables.”

In other GSMA news from Barcelona, the organization provided an update on its GSMA Open Gateway, an initiative composed of a a framework of universal network application programming interfaces (APIs) launched last year at MWC 2023 that is designed to unlock what was described at the time as the “full potential of 5G networks.”

Twenty-one mobile network operators joined initially, and since then that number has more than doubled. “Forty-seven mobile operator groups, representing 239 mobile networks and 65 per cent of connections around the world, have now signed up to the initiative,” a release said. “GSMA Open Gateway is focused on accelerating the growth of digital services and apps, by ensuring they integrate seamlessly with hundreds of participating networks around the world.”

Working with technology partners and cloud providers, including AWS, Infobip, Microsoft, Nokia, and Vonage, more than 40 mobile operator networks have now made a combined total of 94 APIs commercially available to enterprise developers in 21 markets across Asia-Pacific, Africa, Europe, the Middle East and the Americas, the GSMA said.

With online fraud and cybercrime being one of the biggest issues facing online commerce, the GSMA, mobile operators, and technology partners are first focusing the GSMA Open Gateway initiative on tackling online crime.

Recent activities, the GSMA said, include:

Four Sri Lankan operators have launched three APIs on a single operator platform providing authentication to secure customer online transactions.
Three Brazilian operators have launched three APIs to combat fraud.
Three Spanish operators have announced the launch of two anti-fraud APIs, working with online retailers.
Four Indonesian operators launched three APIs to improve online security and customer experience.

GSMA director general Mats Granryd said that the organization’s “collective job for 2024 is to nurture and grow this opportunity and provide ubiquitous access to enterprise developers and cloud providers, so they can do what they do best, which is launch game-changing new services that can maximize the benefits of 5G networks.”

The GSMA release went on to say, “according to research by McKinsey, GSMA Open Gateway and other network API initiatives can unlock significant value for the telecommunications industry, and businesses using 5G networks over the next six years.

“It’s forecast that, if operators can expose more of their network APIs and innovations to enterprise developer and cloud provider communities, then they can unlock an additional US$300 billion market opportunity by 2030.”

The post Carbon emissions by mobile network operators declining: GSMA first appeared on IT World Canada.

Microsoft strikes deal with Mistral AI; EU lawmakers demand investigation

A Microsoft spokesperson confirmed to CNBC this morning that its multi-year partnership with Mistral AI includes an investment of US$16 million, which would convert into equity in the company’s next funding round. European Union regulators are now looking to examine the deal between the two companies.

“The Commission is looking into agreements that have been concluded between large digital market players and generative AI developers and providers,” a European Commission spokesperson told Euronews Next in an email. “In this context, we have received the mentioned agreement, which we will analyze”.

Speaking at MWC in Barcelona, Microsoft president Brad Smith said that Microsoft would commit to principles aimed at encouraging innovation and competition in AI.

Microsoft first announced the deal on Monday, saying it would make a small investment in the company, but revealed no financial details. The deal, it said, is to help the French AI startup, currently valued at US$2 billion, accelerate the development and deployment of its foundation models.

This is the second AI deal Microsoft has made since pumping US$10 billion into OpenAI in January 2023, for which it is facing heat from EU, U.K. and U.S. regulators for potentially breaching competition rules.

Nonetheless, the deal with Mistral AI could signify Microsoft is moving beyond its reliance on OpenAI and expanding its AI footprint globally.

“It’s important for us to show that this isn’t just about Microsoft technology, it’s not just about American products. This is going to be an engine for technology, innovation and growth in Europe as well,” Smith said.

The two companies, in fact, affirmed that they will also explore collaboration around training purpose-specific models for select customers, including European public sector workloads.

Under the deal, Microsoft will support Mistral AI’s workloads on Azure AI and will make Mistral AI’s flagship models available to customers in the Azure AI Studio and Azure Machine Learning model catalog. This expands the choice of open source models available to Microsoft’s customers.

However, on Monday, the Paris-based company announced a new flagship, Mistral Large, which will be closed source, unlike some of its previous models. According to Mistral, it can be used for complex multilingual reasoning tasks, including text understanding, transformation, and code generation. The model, which Mistral says is the world’s second-ranked model generally available through an API (next to GPT-4), will be available on Azure.

Mistral also released a conversational chatbot, Le Chat, taking on OpenAI’s ChatGPT.

The post Microsoft strikes deal with Mistral AI; EU lawmakers demand investigation first appeared on IT World Canada.

Coffee Briefing Feb. 27 – Apple introduces post quantum cryptography in iMessage; Seneca Polytechnic and Microsoft partner; New CRTC vice chairperson; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

Apple introduces quantum-secure cryptography in iMessage

Apple has introduced PQ3, a post-quantum cryptographic protocol, in its messaging system, iMessage.

PQ3 is said to be the first messaging protocol to reach what Apple refers to as Level 3 security, providing protocol protections that surpass those in all widely deployed messaging apps, and that seeks to provide defenses against future sophisticated quantum computing attacks.

Messaging apps have traditionally used classical public cryptography, such as RSA, Elliptic Curve signatures, and Diffie-Hellman key exchange, but these protocols have been increasingly threatened with the rise of quantum computing, which is capable of rapidly solving the complex mathematical problems the protocols are based on.

Apple says that those kinds of quantum attacks are not currently possible, as quantum computers to carry them out do not exist yet, but bad actors can stockpile encrypted data until they later get their hands on a quantum computer that can decrypt the data.

Support for PQ3, Apple said, will start to roll out with the public releases of iOS 17.4, iPadOS 17.4, macOS 14.4, and watchOS 10.4, and is already in the corresponding developer preview and beta releases.

Seneca Polytechnic partners with Microsoft to bring AI technology to students

Seneca Polytechnic has announced that it is bringing Microsoft Azure AI technology to students and employees through the following initiatives:

New AI tutor to help students understand course material or help with homework
Participation in simulated, personalized job postings with Microsoft AI technology and Seneca’s InStage platform
Access to Microsoft Copilot to do a range of tasks like summarizing information, getting explanations for math solutions, improving writing skills, finding answers with links to queries and more

“AI innovation is transforming today’s classrooms, unlocking new possibilities for student success, creativity and learning,” said Marc Seaman, vice president, education sector, Microsoft Canada. “Seneca’s AI tutor integrates Microsoft Azure OpenAI to enable deeper understanding of course material inside the classroom and at home, for a learning experience that is personalized, inclusive and relevant in today’s digital economy.  Students will gain skills, guided by personalized AI experiences, ensuring they graduate not just job-ready, but future-ready.”

Heritage minister announces new CRTC vice chairperson

Minister of Canadian Heritage Pascale St-Onge has announced the appointment of Nathalie Théberge as vice chairperson of the Canadian Radio-television and Telecommunications Commission (CRTC). Her term of office will last five years, starting in April this year.

“In a world where technology is constantly redefining the way we communicate, create and enjoy culture, the CRTC’s role is more relevant than ever,” said St-Onge. “Having Nathalie Théberge on the CRTC’s management team will strengthen the organization’s ability to navigate today’s complex digital landscape, while protecting the interests of Canadians and our creative professionals.”

Prior to this appointment, Théberge served as vice chair and chief executive officer of the Copyright Board of Canada, and has held a number of executive positions at the department of Canadian Heritage, positioning her to lead cultural and copyright measures in a number of international trade negotiations.

Théberge is replacing Alicia Barin, who stepped down in January after serving the CRTC since 2019.

QueerTech acquires Toronto non profit accelerator for 2SLGBTQ+ startup founders

A Montreal-based non-profit advocacy group for the queer community in the tech sector, QueerTech, has announced the strategic acquisition of Gradient Spaces, a Toronto-based non-profit accelerator for 2SLGBTQ+ startup founders in Canada.

“Since its inception, the organization has developed a strong framework for producing new leadership and deepening the pools of knowledge in the venture space for innovative queer business leaders,” said Naoufel Testaouni, co-founder and chief executive officer of QueerTech.

Gradient Spaces’ flagship program Founder Program, for example, is a three-month, equity-free incubator that supports entrepreneurs through expert-led sessions and mentorship opportunities, culminating in a final pitch day where founders meet investors and funders.

“Gradient Spaces is thrilled to pass the Founder Program baton to an organization that we’ve admired and worked closely with for years. Our missions are closely aligned, and it has been clear from the beginning that our teams both centre shared values in our work every day,” said Alexandra Baccellieri, director of Gradient Spaces. 

Further details about the acquisition will be unveiled in the coming weeks.

HPE and Telus partner to deliver Canada’s first 5G open RAN network

Hewlett Packard Enterprise (HPE) has announced a partnership with Telus to build Canada’s first 5G open radio access network (Open RAN) in which it will provide infrastructure across 3,000 sites. 

“Open RAN technology enables HPE’s telco customers the interoperability to design and manage their network with the equipment and software they desire,” said Phil Cutrone, senior vice president and general manager of service providers, original equipment manufacture and telco at HPE. “This is one example of why we are the infrastructure of choice for telco carriers worldwide. HPE enables success by providing the most energy efficient, open, and flexible solutions at the edge.”

Specifically, HPE ProLiant DL110 Gen11 servers will provide an open, flexible and virtualized foundation for a Distributed Unit, which is responsible for preparing data for transmission across the 5G network. Providing a DU that frees Telus from historical reliance on proprietary appliances, HPE said, enables the carrier to smoothly and flexibly integrate with other Open RAN 5G infrastructure components.

The servers also use AI to distinguish between periods of high and low utilization, putting under-utilized infrastructure into an idle state without compromising latency or RAN network availability. That also helps with infrastructure power savings.

More to explore

As Broadcom sells its EUC Division, frustration mounts for many

The  dismantling of VMware by Broadcom continued today when the company announced it was selling its End-User Computing (EUC) Division to Menlo Park, Calif.-based KKR, a global investment firm, in a deal estimated to be worth US$4 billion.

Proposed Canadian law puts burden on large internet providers to police child porn, hate

Designated social media providers, live-streaming services and adult sites that allow users to upload content will have to scrutinize and delete objectionable messages, images, and videos if the Liberal government’s proposed Online Harms Act, which includes the creation of a Digital Safety Commission to hear complaints, is passed.

Cyber attack on Hamilton knocks out municipal phone, email

One of Ontario’s biggest cities is in the second day of dealing with a cyber attack.

LockBit claims it’s back, blames failure to patch vulnerability for police attack

The LockBit ransomware gang says it’s back in business, with a person posting a message admitting his “personal negligence and irresponsibility” for not updating an application was likely used by law enforcement last week to dismantle much of the operation’s IT infrastructure.

Sidebar: The powerful Digital Safety Commission

The Online Harm Act’s proposed Digital Safety Commission — whose members would be full-time government employees with renewable terms of up to five years — would have extensive powers.

Making AI explainable to bridge trust gaps: Forrester weighs in

Artificial intelligence has invaded industries and companies of all sizes, but the backstory of what makes these tools powerful and erratic alike remains somewhat obscure.

Channel Bytes February 23, 2024 – SailPoint launches MSP program; Sophos adds Partner Care to its global program; Salesforce users warned of flaws in customized instances; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Feb. 26, 2024 – Canadian online harms legislation to be revealed today, and more

Listen to the latest episode of Hashtag Trending

Hashtag Trending Feb.27- Will AI enable a four-day week?; SpaceX under scrutiny for allegedly blocking satellite internet services in Taiwan; How much does it cost to make the Apple Vision Pro?

The post Coffee Briefing Feb. 27 – Apple introduces post quantum cryptography in iMessage; Seneca Polytechnic and Microsoft partner; New CRTC vice chairperson; and more first appeared on IT World Canada.

Government of Canada joins international partners in endorsing shared 6G principles

Canada has joined international partners including the United States, Australia, the Czech Republic, Finland, France, Japan, the Republic of Korea, Sweden, and the United Kingdom in endorsing the Joint Statement of Principles for 6G.

6G is the successor to 5G cellular technology and is expected to be significantly faster, while enabling new applications using Internet of Things (IoT), artificial intelligence, augmented reality and more.

The statement seeks to advance research and development and standardization of 6G networks, fulfilling principles like resilience, security by design, privacy interoperability, energy-efficiency, transparency and more. Additionally, the principles lay out a number of standards that facilitate international cooperation.

The agreement bolsters the U.S. and its partners’ attempt to influence the future standards of 6G, amid concerns that China could dominate 6G’s rollout, as it did with 5G, Axios noted in an article.

“We believe this to be an indispensable contribution towards building a more inclusive, sustainable, secure, and peaceful future for all, and call upon other governments, organizations, and stakeholders to join us in supporting and upholding these principles,” the White House added in a release.

Canada’s endorsement of the Joint Principles for 6G will build on work under the Telecommunications Reliability Agenda, a set of actions tasked to improve the reliability of telecommunications services in Canada.

The Joint Principles for 6G will also build on Canada’s international cooperation under the Global Coalition on Telecommunications, the Prague Proposals on Telecommunications Supplier Diversity and the UK’s Open RAN Principles, which Canada endorsed in 2022.

“Canadians depend on telecommunications services being reliable and secure every day, whether for personal connectivity or the digital economy,” said Industry Minister François-Philippe Champagne. “Our government has endorsed these shared principles for 6G so that Canadians can continue to benefit from the latest wireless technologies. We look forward to working together with our international partners and industry to ensure wireless communications are secure and reliable in Canada and around the world.”

The post Government of Canada joins international partners in endorsing shared 6G principles first appeared on IT World Canada.

Hashtag Trending Feb.27- Will AI enable a four-day week?; SpaceX under scrutiny for allegedly blocking satellite internet services in Taiwan; How much does it cost to make the Apple Vision Pro?

Prelude:

Just a note out there. We’ve been having problems with some of our podcasts. Our hosting partner Libsyn says they are working on this. We hope it’s not inconveniencing you. But we’ll push to get this fixed. 

If you are having issues, please write me at jlove@itwc.ca  Any data we can gather will be useful

MUSIC UP

Will AI give us a four-day workweek?  The CEO of Nvidia says it’s time to stop teaching the kids to code. Are companies spying on you in your Teams and Slack chats? And how much does it cost to make the VisionPro headset?



 

All this and more on the “I just wanna be George Jetson”  edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US. 

The concept of a four-day workweek, once considered a distant dream for many, is inching closer to reality, thanks in part to advancements in artificial intelligence (AI). As AI becomes more integrated into office operations, its potential to reshape the traditional workweek is becoming increasingly apparent. Recent trials in countries like the UK, Iceland, and Portugal have shown promising results, with companies reporting boosts in employee morale and productivity.

A survey by Tech.co found that organizations with a four-day workweek are more likely to use AI extensively. For instance, 29 per cent of these organizations with a four-day week implement generative AI tools such as ChatGPT to streamline operations, compared to only 8 per cent of companies working five days a week. 

The adoption of AI not only automates mundane tasks but also frees up valuable time, allowing employees to focus on more complex and creative work.

Companies like Driftime, a London-based digital design agency, have leveraged AI to enable a flexible four-day workweek. By automating simple tasks, Driftime has seen an increase in the quality of work produced and a significant improvement in staff satisfaction. Similarly, TechNET IT Recruitment has utilized AI to save their consultants an average of 21 hours per week, leading to faster role fulfillment and an enhanced work-life balance for their team.

However, the transition to a shorter workweek powered by AI is not without its challenges. Organizational culture and an openness to innovative work structures play a crucial role in the successful adoption of a four-day workweek. Moreover, while AI can significantly benefit certain industries, its development still has a long way to go before it can universally reduce human working hours.

Despite these hurdles, the momentum towards a four-day workweek is growing, with business leaders from some of the world’s largest companies acknowledging its inevitability. As AI continues to evolve, it may well make the four-day workweek an unavoidable future, offering employees more time for personal pursuits while maintaining, or even enhancing, productivity and job satisfaction.

I’m still waiting to be George Jetson. Google it.

Sources include: BBC Worklife

Nvidia CEO Jensen Huang challenged the idea that learning to code is essential for the younger generation. It wasn’t an offhand comment, he did this at the World Government Summit in Dubai this week. 

Huang argued that the advancement of artificial intelligence (AI) has reached a point where coding tasks can be effectively managed by AI itself, suggesting that human efforts would be better directed towards fields like biology, education, manufacturing, and farming.

Huang envisions a future where AI’s capabilities in programming allow people to communicate with computers using natural language, effectively making everyone a programmer without needing to learn complex coding languages.

This shift, according to Huang, opens up the opportunity for individuals to focus on acquiring expertise in areas that AI cannot easily replicate, thereby contributing more significantly to society. 

However, Huang also emphasized the importance of upskilling, indicating that while the need to learn traditional programming may diminish, there is still a need for people to understand how to apply AI technologies effectively. 

This suggests a future educational landscape where the focus shifts from teaching coding as a fundamental skill to integrating AI literacy across various domains of knowledge and expertise.

Listeners would be advised to listen carefully and skeptically to this. I think a more nuanced view would be that we are going to need a lot fewer people who have a much higher skill level in terms of understanding how AI works, rather than just simple coding. And other disciplines are going to need some very top notch thinkers capable of bridging the gap between different and perhaps traditional industries and the new opportunities afforded by AI. 

In our opinion – the future lies in nuance, not black and white thinking.

Sources include: Tom’s Hardware

According to a Wall Street Journal video report, SpaceX, under the leadership of Elon Musk, is facing scrutiny for potentially blocking satellite internet services in Taiwan, which could be a violation of its contractual obligations with the U.S. government. 

This has prompted one American Congressman, Mike Gallagher to express concerns, especially regarding the implications for U.S. military personnel amid potential Chinese military aggression against Taiwan.

The report highlights the strategic importance of SpaceX’s Starshield military satellites, which are utilized by Taiwan for intelligence and military purposes, with the U.S. government having invested over $100 million in the project. The congressman has requested detailed information on the satellite operations by March 8.

Additionally, the situation is complicated by reports from Defense One that Russia is using SpaceX’s Starlink satellite devices on the frontlines in Ukraine. This has been confirmed by a representative of the Main Intelligence Directorate of the Ministry of Defense of Ukraine, noting that the Russian military’s use of Starlink has become systematic. 

Despite Elon Musk stating that the devices were not sold to Russia, the Ukrainian Armed Forces are actively working to neutralize the threat posed by Starlink on the frontline, with the Ministry of Digital Transformation proposing a solution to Musk for locating Starlink devices.

This raises concerns about the geopolitical implications of private companies like SpaceX providing critical satellite internet services, especially in conflict zones and areas of strategic interest like Taiwan and Ukraine.

Sources: MSN.com and the Wall Street Journal 

I almost skipped this story because it came from Fox which, I think we’ll all admit, has some issues with accuracy in journalism. But 

A recent report has revealed that several major companies, including Walmart, Delta, T-Mobile, Chevron, and Starbucks, are now monitoring employee conversations on messaging apps using software from a startup AI company called “Aware.” This software scans platforms like Slack and Microsoft Teams for keywords that may indicate employee dissatisfaction and potential safety risks. “Aware” claims it has assessed up to 20 billion individual messages from more than 3 million employees.

The move towards remote work has increased the volume of employee chats taking place online, raising new concerns about privacy and surveillance in the workplace. 

Jeff Schumann, co-founder and CEO of the Columbus, Ohio-based startup, says that AI helps companies “understand the risk within their communications,” getting a read on employee sentiment in real time, rather than depending on an annual or twice-per-year survey.

The company claims that it doesn’t monitor individual employees, but at least one article indicates that it may have the ability to do this. 

Regardless, this does raise issues about how artificial intelligence in the workplace is used to monitor employees and raises important questions about the balance between employee privacy and company oversight. 

As AI technology continues to evolve, it’s likely that its use in employee monitoring will become more widespread, prompting further debate on the ethics and implications of such practices.

Source: Fox Business and CNBC

Apple’s Vision Pro headset carries an impressive starting price tag of $3,499 US. 

But how much does it cost to make? A company called Omdia looked to uncover the cost to Apple for building one of these headsets, breaking down the Bill of Materials (BoM).

The analysis divided the headset into 11 groups of components, identifying the two main micro-OLED displays as the most expensive parts. Manufactured by Sony Semiconductors, these displays cost Apple an estimated $456, accounting for 29.6 per cent of the total BoM. The headset’s brains, including an M2 chip for running the VisionOS operating system and handling image processing, along with a separate R1 chip for managing inputs from cameras, microphones, and sensors, were estimated to cost $240, making up 15.6 per cent of the total BoM.

Overall, Omdia estimates the total BoM for the cheapest Vision Pro model at $1,542, which is 44 per cent of its retail cost. 

For comparison, the BoM of a 256GB iPhone 15 Pro Max is around $500, or approximately 42 per cent of its retail price. It’s about the same margin – but a lot more iPhones are sold than VisionOS devices.

And calculating a profit margin solely based on BoM is challenging due to the myriad associated costs, such as R&D, assembly, and shipping.

Omdia’s projections suggest that Apple will produce around 200,000 Vision Pro units this year, with an estimated 1 million units expected in the few years beyond 2024 following the launch of the new Vision Pro.

The bottom line? This is a significant investment Apple has made in developing the Vision Pro headset. If they sell a million of these, I assume they will make back their R&D costs and make a profit. 

I don’t think we’ll have to do a gofundme for this trillion dollar company, but it does illustrate the size of the bet that companies are making on augmented and virtual reality.

Source: ZDNet

Hashtag Trending goes to air five days a week with daily newscasts and a weekend interview show that we creatively called – the weekend edition. 

I got comments on my story yesterday on the growth in C level titles. Thanks. I am really interested in what you think about AI and your reaction to the story today. 

I like to keep it real and knowing what you think is a big help. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Terrific Tuesday.

 

The post Hashtag Trending Feb.27- Will AI enable a four-day week?; SpaceX under scrutiny for allegedly blocking satellite internet services in Taiwan; How much does it cost to make the Apple Vision Pro? first appeared on IT World Canada.

As Broadcom sells its EUC Division, frustration mounts for many

The  dismantling of VMware by Broadcom continued today when the company announced it was selling its End-User Computing (EUC) Division to Menlo Park, Calif.-based KKR, a global investment firm, in a deal estimated to be worth US$4 billion.

The purchase by KKR includes Horizon, a desktop and application virtualization platform and Workspace One, a unified endpoint management platform for the enterprise.

News of the acquisition comes as no surprise, as Broadcom CEO Hok Tan, during the company’s Q4 2023 earnings call in December, stated the plan was to divest two VMware business units: End-User Computing and Carbon Black, a developer of endpoint security software.

In an advisory issued in early December, Forrester Research said that both EUC and Carbon Black, which has yet to be sold, represent a “small percentage of VMware’s overall business” and that the “spin-off will likely enable both companies to increase their independence, helping them to increase brand awareness, secure more R&D funding, and pursue strategies relevant to their respective markets.

“Additionally, both will potentially avoid or delay some of the negative consequences of a Broadcom acquisition, which Forrester expects will bring price hikes, degraded support, and a diluted value proposition for VMware products. A sale may eventually result in these impacts anyway, depending on the buyer, but for the time being, currently satisfied customers should hold steady with their investments.”

In a blog released this morning, Shankar lyer, senior vice president and general manager of the EUC Division, called the acquisition an “exciting new era” for the organization he oversees and “ultimately our customers and partners.”

KKR, he wrote, is an “ideal strategic partner with the experience and resources to help us achieve our potential as a standalone business.

“After the transaction closes, which is expected to occur later this year subject to customary closing conditions and regulatory approvals, the EUC Division will continue to be led by its existing management team.”

In the meantime, he added, it is “business as usual, and we continue to prepare for the acquisition with a focus on customer and partner continuity.”

It is certainly not business as usual for a host of partners and customers impacted by a decision by Broadcom to terminate its VMware Partner Program as of Feb. 5. That move has resulted in a number of vendors, including Scale Computing , a company that specializes in edge computing and virtualization services, reaching out to partners who would not have made the cut to Broadcom’s new invitation-only channel program.

In late January, it announced an initiative it called a VMware Rip and Replace Promotion, in which partners signing on receive a 25 per cent discount on its software and services, as well as free migration tool access.

The changes by Broadcom, the firm said in a release, “have led to palpable frustration among partners as well as customers, many of whom face a painful transition working with partners who will lose their status in Broadcom’s new channel program. Broadcom also announced the move to software licenses, meaning customers will soon see all VMware products sold on subscription and offered only in product bundles, potentially raising costs and forcing them to acquire software they do not need.”

During a webinar earlier this month, Jeff Ready, the co-founder and chief executive officer (CEO) of Scale, reflected on Tan’s business strategy, which will see 80 per cent of VMware revenue coming from their top 600 customers.

“Their focus is to drive the product, drive the pricing, drive everything towards those 600 and if you’re in that 600, maybe that’s fine,” he said. “But if you’re 601 through 100,000, that’s probably not great.”

Ready recalled talking to a partner about one of their customers, a not-for-profit children’s hospital. Its VMware licence renewed in January, and when the license renewal notice was issued, the pricing jumped from US$5,000 to US$42,000 a year, a figure that clearly had not been budgeted for.

“They reached out to their partner, the partner got the VMware rep, as well as the new Broadcom rep on the phone to discuss the situation and really to see if there might at least be a transition plan where they could get through a period of time and budget for whatever they needed to budget for. The partner related to me the answer they got from Broadcom was ‘we’re sorry but VMware is not for everyone,’ which is terrible.”

VMware as an organization, said Ready, was “built on the channel – (partners) taking the product, getting customers and making it a core part of their offering. To see just how the channel kind of gets tossed aside like yesterday’s garbage in this transition is difficult for me to watch. It is a great opportunity for Scale, but on a personal level it is painful.”

The post As Broadcom sells its EUC Division, frustration mounts for many first appeared on IT World Canada.

Sidebar: The powerful Digital Safety Commission

The Online Harm Act’s proposed Digital Safety Commission — whose members would be full-time government employees with renewable terms of up to five years — would have extensive powers.

It would be able to summon and enforce the appearance of persons, and compel them to give oral or written evidence under oath and to produce any documents or other things that the Commission considers necessary, and would receive and accept any evidence or other information, whether under oath, by affidavit or otherwise, that the Commission sees fit, whether or not it would be admissible in a regular Canadian court of law.

Hearings can be held in private if it is in the interest of victims of harmful conduct or national security.

Commission inspectors can enter any place where they have reasonable grounds to believe there is a relevant document or other thing, to verify compliance with the Online Harms Act.

“Entering” includes the ability to access a place remotely by telecommunications. However, that can only be done with the knowledge of the owner or person in charge of the place. And the inspector can’t have remote access for longer than necessary.

Not only can the inspector copy a document, they can also use any computer system to examine any document or information.

If the inspector wants to enter a dwelling, it can only be done with the occupant’s consent or a court order issued by a justice of the peace.

Penalties for violating the act or a Commission order:
— for persons, the maximum penalty they could face would be up to 6 per cent of their gross global revenue or $10 million, whichever is greater;

— for a service operator that ignores an order or makes a false or misleading statement to the Commission, on conviction by indictment faces a fine of up to 8 per cent of the firm’s gross global revenue or $25 million, whichever is greater. If convicted of a summary offence, the fine would be not more than 7 per cent of the operator’s gross global revenue or $20 million, whichever is greater.

Note that a person cannot be found guilty of an offence if they can show they exercised due diligence in trying to prevent an offence.

The Commission’s chair would be named by the government with the approval of both houses of Parliament.

The post Sidebar: The powerful Digital Safety Commission first appeared on IT World Canada.

Proposed Canadian law puts burden on large internet providers to police child porn, hate

Designated social media providers, live-streaming services and adult sites that allow users to upload content will have to scrutinize and delete objectionable messages, images, and videos if the Liberal government’s proposed Online Harms Act, which includes the creation of a Digital Safety Commission to hear complaints, is passed.

The act, Bill C-63, which was introduced today, says designated services must remove within 24 hours two categories of content: Material that sexually victimizes a child or re-victimizes a survivor; and intimate content posted without the consent of an individual.

The 24-hour deadline would be subject to oversight and review.

The law would also make it clear anyone who provides an internet service — including social media platforms — has to report to a designated law enforcement agency if child porn is posted on their service. To enhance that reporting, service providers will have to hold user content for one year — up from the current 21 days — to ensure content is available for criminal investigation.

Designated providers would have to put child safety first when designing products and features including offer parental controls, content warning labels for children and set rules around targeted content or ads directed at children.

In addition, the government plans to amend the Criminal Code to fight hate by creating a new hate crime offence punishable by up to life imprisonment, and by raising the maximum penalties for the existing four hate propaganda offenses.

The Canadian Human Rights Act would be amended to specify that posting hate speech online is discrimination, and allow the Human Rights Tribunal to handle hate speech complaints, including granting them the power to order the removal of such content.

Amendments would also make it clear anyone who provides an internet service — including social media platforms — has to report to police if child porn is posted on their service.

Only online services that have a big enough number of users would be covered under the Online Harms Act. The size would be covered in yet-to-be announced regulations.

The proposed law would cover seven categories of harmful content:

— content that sexually victimizes a child or re-victimizes a survivor;

— content that could be used to bully a child;

— content that induces a child to harm themselves;

— content that incites violence;

— content that foments hatred;

— intimate content communicated without consent, including deepfaked audio, images and videos.

The Digital Safety Commission would be composed of five people appointed by the government, with the power to order providers to remove content that sexually victimizes a child. It would also have the responsibility of setting norms in online safety.

The proposed legislation would also create a Digital Safety Ombudsperson, also appointed by the government.

The goals, the government says, are to reduce the exposure of harmful content to Canadians, give special protections for children and stronger reporting of child pornography; give public oversight of and accountability from online services and “improved safety over time.”

The legislation will allow people to request the quick removal of child porn, submit complaints to the Digital Safety Commission, allow people to contact the Digital Safety Ombudsperson to receive support and be directed to the right help resource and to file complaints with the Human Rights Commission when facing online hate.

The bill makes it clear it doesn’t cover private communications such as email and text messages or service such as WhatsApp. But it does apply to social media platforms such as Facebook and others where a poster can invite many people into a group.

More to come…

The post Proposed Canadian law puts burden on large internet providers to police child porn, hate first appeared on IT World Canada.

Cyber attack on Hamilton knocks out municipal phone, email

One of Ontario’s biggest cities is in the second day of dealing with a cyber attack.

Hamilton, a municipality of about 570,000 on the shore of Lake Ontario, said Sunday it had suffered a city-wide phone and email “disruption” to municipal and public library services, which included the Bus Check Info Line and the HSRNow transit planning app.

Today, the city’s description of the problem changed from a disruption to a cyber incident.

Buses started as scheduled Monday, and transit schedules are available on the city’s website.

“At this time experts are actively responding to the incident to determine the cause and potential impacts,” the city said in a news release Monday on its website. “Our priority is to safeguard the integrity of our systems and protect any sensitive or private information.

“While the investigation is ongoing, we want to assure the community that we are taking this matter seriously and are collaborating closely with cybersecurity experts and relevant authorities to address the issue as quickly and effectively as possible.

“We understand the importance of transparency and will provide updates as new information becomes available. We apologize for any inconvenience caused by this incident.

“The City remains committed to protecting the privacy and security of our community while managing impacts to City service levels.”

Threat actors may target provincial, state, and local governments for several reasons: Generally their IT departments are less well-funded than national governments and may be less well defended. Threat actors may also believe local governments are susceptible to paying ransoms for access to stolen data because they are responsible to taxpayers.

Experts also say some attacks are just opportunistic — that is, a hacker finds an IT system vulnerable to an attack and takes advantage of the opening.

A report last year by cybersecurity awareness training supplier KnowBe4 on the economic impact of cyber attacks on U.S. municipalities noted getting into the network in the first place is often done with low-tech phishing emails.

The City of Toronto’s public library system is only now in the final stages of recovering from a ransomware attack last October. It has been forced to rebuild its network. The names, Social Insurance numbers and other information of employees going back to 1998 was copied by the attacker.

The post Cyber attack on Hamilton knocks out municipal phone, email first appeared on IT World Canada.

LockBit claims it’s back, blames failure to patch vulnerability for police attack

The LockBit ransomware gang says it’s back in business, with a person posting a message admitting his “personal negligence and irresponsibility” for not updating an application was likely used by law enforcement last week to dismantle much of the operation’s IT infrastructure.

This explanation is included in an English and Russian message on the gang’s new TOR site. The full text has been posted on X by vx-underground.

The sometimes rambling message, titled, “What happened,” is dated Feb. 24 and  gives an account of the Feb. 19 attack, claims without evidence that the FBI attacked now because the gang or an affiliate had stolen documents related to a Georgia investigation into allegations Donald Trump and others tried to interfere with the results of the 2020 presidential election in the state that LockBit was about to release, claims the gang has not been put out of business and vows there will be retaliatory attacks on U.S. .gov domains.

The new LockBit site lists several new victims as well as Fulton County, Ga. According to the news site Databreaches.net, LockBit claimed to have hit the county before the Feb. 19 takedown of its infrastructure.

In the Feb. 24 message, the author writes that on Feb. 19 he detected “penetration testing” on two of his servers. An error was detected, but nothing apparently changed. “I didn’t pay much attention to it, because for 5 years of swimming in money I became very lazy, and continued to ride on my yacht with titsy girls.”

However, 14 hours later, after a new server error popped up, he said he couldn’t log in. “As it turned out later, all the information on the disks was erased.”

The problem, he believes, is that he hadn’t updated the servers’ PHP, an open-source general-purpose scripting language used for web development. He believes the attackers accessed two LockBit servers through this or another zero-day vulnerability.

“The new servers are now running the latest version of PHP,” the letter adds. “I noticed the PHP problem by accident and I’m the only one with a decentralized infrastructure with different servers, so I was able to quickly figure out how the attack happened. If I didn’t have backup servers that didn’t have PHP on them, I probably wouldn’t have figured out how the hack happened.”

“The fact that LockBit has relaunched its website isn’t particularly surprising, and doesn’t mean the disruption effort was unsuccessful,” Brett Callow, Canadian-based threat analyst with Emsisoft, told IT World Canada. “On the contrary, law enforcement likely obtained valuable information that will enable them to identify and take action against LockBit’s past and present affiliates as well as others involved in the ransomware supply chain.

“Realistically, this is likely the end of the LockBit brand. Other cybercriminals will not be willing to risk working with an operation that was so thoroughly compromised. It’d simply be too risky.”

The U.K.’s National Cybercrime Agency says it obtained “the LockBit platform’s source code and a vast amount of intelligence from their systems about their activities and those who have worked with them and used their services to harm organizations throughout the world.” Working with the FBI and law enforcement agencies from nine other countries, they seized a LockBit data exfiltration tool, known as Stealbit, 28 servers belonging to LockBit affiliates and over 1,000 data decryption keys.

The LockBit author says the FBI got “a database, web panel sources, locker stubs that are not source as they claim and a small portion of unprotected decryptors.”

“Yes it’s bad,” the author says of the loss of the decryptors, “but it’s not fatal.” He claims there were over 20,000 more decryptors that were protected and can’t be used by victims to unscramble their data.

The seized database, he says, has “generated nicknames” and not real nicknames of LockBit partners. But, he admits law enforcement did get cryptocurrency wallets. But he says people will be arrested and accused of being partners, which, he says, they aren’t.

As for police getting the source code of the panel, what remains of the panel will be divided into many servers for verified partners, the LockBit author says, with each partner getting their own copy. to reduce the chance of a future hack.

Police said several alleged LockBit gang members were arrested, but LockBit believes these were only people who laundered cryptocurrency.

“The FBI decided to hack now for one reason only,” the LockBit author claims — because they didn’t want to see a leak of information from Fulton County, Ga., where former U.S. President Donald Trump and others are being investigated for allegedly trying to change the outcome of the 2020 election in the state.

If it wasn’t for the FBI attack, the author claims, the documents would have been released on Feb. 19. “because the negotiations stalled, right after the partner posted the press release to the [LockBit] blog … Had it not been for the election situation the FBI would have continued to sit on my server waiting for any leads to arrest me and my associates, but all you need to do to not get caught is just quality cryptocurrency laundering.”

“Even after the FBI hack, the stolen data will be published on the blog, there is no chance of destroying the stolen data without payment,” the message says. “And after introducing maximum protection on every build of locker, there will be no chance of free decryption, even for 2.5 per cent of attacked companies.”

“New affiliates can work in my affiliate program if they have a reputation on the forum, can prove they are pentesters with post-pay-payment, or by making a deposit of 2 bitcoins, the deposit increase is due to proof and beautiful advertising from the FBI, which is that my affiliates and I earn together hundreds of millions of dollars, and that no FBI with their assistants can scare me and stop me, the stability of the service is guaranteed by years of continuous work.”

According to researchers at Switzerland-based Prodaft, LockBit has seven affiliates that use its ransomware-as-a-service, some of which have ties to other threat actors such as FIN7, Wizard Spider, and EvilCorp. One focuses almost exclusively on GIT and Jenkins Servers, another relies on compromised Microsoft RDP server information from certain initial access brokers, while a third primarily focuses on vulnerable Fortigate and Citrix platforms. Some train other affiliate gangs.

The post LockBit claims it’s back, blames failure to patch vulnerability for police attack first appeared on IT World Canada.