Category: News

UK leads takedown of LockBit ransomware gang’s website

The LockBit ransomware gang’s website has been seized, several news agencies reported late Monday.

The Reuters news agency and The Register are carrying stories based on a new splash screen that has appeared on the gang’s website.

It says, “This site is now under the control of the National Crime Agency of the UK, working in close co-operation with the FBI and the international law enforcement task force, Operation Cronos.”

“This is an ongoing and developing operation,” the statement adds.

It suggests viewers check back at 11:30 GMT — which is 6:30 a.m. Tuesday Toronto time — for more news. There are no statements on the FBI or U.S. Justice department websites.

Reuters quotes an unnamed NCA spokesperson as confirming the action.

The new NCA splash screen says participating countries in the action include Canada, France, Japan, Switzerland, Germany, Australia, Sweden, the Netherlands and Finland.

Reuters quotes vx-underground, a cybersecurity research website, saying LockBit has posted messages in in Russian and shared on Tox, an encrypted messaging app, that the FBI hit its servers that run on the programming language PHP. The statement, which Reuters could not verify independently, added that the gang says it has backup servers without PHP that “are not touched”.

“This is likely the most significant disruption of a ransomware operation to date,” said Brett Callow, a Canadian-based ransomware threat analyst at Emsisoft.

LockBit has been targeted for some time by law enforcement agencies. That led to the arrest in November, 2022 of a man in Bradford, Ont., for his alleged role in the gang. Mikhail Vasiliev pleaded guilty on February 8th to multiple counts involving cyber-extortion, mischief and weapons charges relating to acts in Canada, including ransomware attacks on Toronto’s Hospital for Sick Children and the Indigo book chain.

The U.S. wants to extradite him to face charges there.

Last June, cybersecurity agencies from seven countries including Canada and the U.S. released a joint background paper on the Lockbit ransomware gang.

Measured by the number of victims claimed on the LockBit data leak site, in 2022, the gang was the most active global ransomware group that year.

When that report was issued seven months ago, the U.S. estimated victim organizations in that country alone had paid the gang US$91 million in ransoms since LockBit activity was first seen in January, 2020. The U.S. estimated 16 per cent of reported ransomware attacks on American government entities in the country — including schools and police forces — were identified as LockBit.

Canada estimated LockBit was responsible for 22 per cent of attributed ransomware incidents in 2022.

The post UK leads takedown of LockBit ransomware gang’s website first appeared on IT World Canada.

Cyber Security Today, Feb. 19, 2024 – Fake police data breach notification fools Maine’s AG site

Welcome to Cyber Security Today. It’s Monday February 19th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

Today is the President’s Day holiday in many U.S. states and a civic holiday in several Canadian provinces. If you’re off, thanks for tuning in.



 

A mischief-maker has managed to fool the attorney general’s office of the state of Maine into posting a phony data breach notification. Maine is one of several American states with laws forcing firms and government agencies to fill out an online form outlining data breaches that affect their residents. Those notifications are posted on state websites so the public know about data breaches. Well, on Saturday Maine’s data breach notification website included an obviously fake listing. It claims to be a report about an attack on the police department of the city of “Saint Louis,” Missouri. I say it’s obviously a fake because the person who submitted the notification wrote that he owns the state of Missouri, as well as owns the police department. The explanation of the attack is garbled nonsense involving criminals in the building, RFID tagging of account numbers, a Google private investigator, low pass filters on bank antennas … and so on. And they misspelled St. Louis. I assume an automated system approved the posting, because surely a bureaucrat couldn’t have allowed it to go through. On Sunday afternoon I emailed the Maine attorney general’s office asking for an explanation.

Among the real data breach notifications recently posted on Maine’s website the Golden Corral restaurant chain, which has outlets in 39 states, said it’s notifying over 185,000 people of a data breach last August. And a school district in Maryland is notifying almost 100,000 people their personal data was stolen in a ransomware attack last August.

A Ukrainian man once on the FBI’s Most Wanted List has pleaded guilty in the U.S. to a conspiracy charge for his role in distributing and leveraging the Zeus and IcedID malware. One ransomware victim was the University of Vermont Medical Centre. The man was arrested in Switzerland in 2022 and extradited to the U.S. last year. He will be sentenced in May.

Meanwhile police in Ukraine arrested a hacker who allegedly stole and sold personal data of people in Canada and the U.S. by initially infecting their Android devices. The victims downloaded what they thought was free software. It was really malware that let the attacker steal bank account access information of victims. That bank account data was sold to those willing to loot the bank accounts. Over the years police believe the accused made the equivalent of about US$91,000. The man’s accomplices are being sought.

An American internet provider called U.S. Internet Corp. left more than a decade’s worth of customers’ email messages open on a secure email server. That’s according to reporter Brian Krebs. Krebs was tipped off by a cybersecurity company that found the link to the server, which had over 6,500 domain names of customers. Anyone who clicked on one of those domain names went to a list of emails of the customers. Some messages dated back to 2008. When Krebs asked the company how this happened the server was quickly secured. The company blames a former employee for misconfiguring the server. The lesson here is IT leaders have to regularly check the configurations of anything that connected to the internet.

Cyber experts say using biometric facial scanning is better than passwords for login security. However, an Asian threat actor may have found a way around biometric protections. Security researchers at Group-IB say the latest version of a family of iOS and Android malware has this capability and is being used to hack into victims’ bank accounts and steal their money. The gang uses social engineering to convince a victim to download an app to their mobile device by things like pretending to be from a government department. The victim is told to record a video of themselves for confirmation. That video is then used by the gang to create a deepfake video using artificial intelligence, allowing the gang to get into the victim’s bank account. I’ve simplified the process, but the discovery is a warning to firms that offer facial recognition solutions for logins that they’ve got to upgrade their protection. This technique is being used in Asia. It will come to other countries.

A threat actor is using Amazon Web Services’ simple notification service (SNS) to send bulk spam text messages to people. That’s according to researchers at SentinelOne. These messages often appear to come from the U.S. Postal Service about an alleged missing package. The goal is to get people to click on a link that goes to a fake login page where they can track the alleged package — if they give a credit card number to pay a 30 cent re-delivery fee. That credit card number is what the attackers want. Companies using AWS have to make sure their account isn’t being abused this way by regularly checking the configuration of their SNS capability.

Last week the last of a series of patches for domain name servers and other network applications was released to plug a critical flaw in DNS Security Extensions. This hole, dubbed KeyTrap, was discovered months ago and vendors have been quietly issuing patches since, and DNS providers — like Google and Cloudflare — have been applying them. Hopefully, your IT team has been doing the same.

Finally, at this weekend’s Munich Security Conference 20 tech companies including Meta, TikTok, X, Microsoft, IBM, Adobe, OpenAI and Amazon pledged to help prevent deceptive AI content from interfering with elections. The goal is to reduce the amount of fake texts, social media posts, videos and other content. There are no concrete goals, just pledges to go after deceptive crap.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to to your Flash Briefing on your smart speaker.

By the way, IT World Canada also offers a daily podcast of general IT news. It’s called Hashtag Trending, and it’s also available on Apple and Google podcasts.

 

The post Cyber Security Today, Feb. 19, 2024 – Fake police data breach notification fools Maine’s AG site first appeared on IT World Canada.

A hopeful vision for the internet and AI: My conversation with Ed Watal, author and founder of Intellibus. Hashtag Trending Weekend February 18th, 2024

Sometimes an interview goes off in a totally different direction than you anticipated. I walked into the studio prepared to interview Ed Watal on the issues of AI and its influence on elections. We were to talk about deep fakes and their impact on voters and explore what we could do about that.

But our conversation strayed into a different area, one where it was obvious that Ed was as passionate as he was articulate. And for the first time in many weeks, I left the studio feeling what I can only describe as “hopeful.”

Watal is an author, entrepreneur and founder of Intellibus, a community of interested people aiming to make a difference.

You are the judge, not me. But I sincerely hope that you catch even just a little of what I felt after this conversation with this wonderful and articulate person.

Hashtag Trending, the weekend edition presents my interview with Ed Watal, author, teacher, entrepreneur and champion of an internet for all of humanity to share.

The post A hopeful vision for the internet and AI: My conversation with Ed Watal, author and founder of Intellibus. Hashtag Trending Weekend February 18th, 2024 first appeared on IT World Canada.

Cyber Security Today, Week in Review for week ending Friday, Feb. 16, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, February 16th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes David Shipley, head of Beauceron Security, will be here to discuss recent news headlines. These include new cyber incident and data breach reporting obligations for American telecom companies; the progress of Canada’s proposed cybersecurity law; a cyber attack on an insurance broker to Canada’s federal employees; and the proper strategy for stopping the theft of vehicles with digital keys.

But before I bring in David, here’s a summary of other things that happened this week in cybersecurity:

The U.S. Department of Defence is notifying tens of thousands of people their personal information was exposed in an email error by a service provider exactly a year ago. TechCrunch says the incident involved a cloud email server that for three weeks was accessable from the internet without a password.

Poland’s new prime minister says the previous administration illegally used the Pegasus spyware against people. This app gets surreptitiously implanted on victims smartphones. The Record quotes local news reports saying the government believes there was a “very long” list of targets. Last September Poland’s Senate investigated whether Pegasus had been used to hack an opposition politician. Listeners may recall that a number of governments including Canada and the U.S. agreed last week to investigate the abuse of commercially-sold spyware like Pegasus.

Crooks have started using the Bumblebee malware again. According to researchers at Proofpoint, several threat groups had been using the payload in infected email attachments and links up until last October. Then its use disappeared — until last week.

Microsoft and OpenAI say they have disrupted threat groups from China, Russia and North Korea who were trying to use OpenAI’s artificial intelligence tools to improve their malware. The groups had opened accounts at OpenAi — the creator of ChatGPT — for querying open-source information, translating documents, finding coding errors and running basic coding tasks. OpenAI has shut the accounts.

An Islamic non-profit in Saudi Arabia was likely compromised in 2021 with a custom backdoor, say researchers at Cisco Systems. The malware copied data and sent it out twice a month. Cisco discovered the espionage campaign just over a year ago and delayed release of the news until now. The attacker is a mystery.

And Canada’s OpenText joined the U.S. government’s Joint Cyber Defense Collaborative. It’s a public-private partnership to help the public and private sectors up their cybersecurity. Also this week the Collaborative released a list of its priorities for this year. They include defending against advanced persistent threat operations, helping U.S. state and local officials secure their IT infrastructure and anticipating emerging technology and risks.

(The following transcript of the first of the four topics discussed this week has been edited for clarity. To get the full discussion play the podcast.)

Howard: American telecom providers will soon have new cyber incident and data breach reporting rules. The U.S. Federal Communications Commission has finalized new cyber attack reporting and consumer data breach notification rules for American telecom providers. They haven’t quite set the date on when the new rules come into effect, but telcos would have to report within seven days to the commission as well as the FBI and the Secret Service of any breach of a consumer’s proprietary network information — that’s data like your subscription plan details and the numbers that you call. New is the addition that the FCC has to be notified of these data breaches in addition, consumers will have to be notified within 30 days if there’s a theft or inadvertent disclosure of their personal data. The addition of inadvertent disclosure for American telecom providers is new. Also new is the elimination of the rule that carriers don’t have to report data breaches if they believe no reasonable harm will come to consumers from the theft of particular data, like just a name and phone number.

David, this is a sign that regulators are getting impatient with data breaches from phone companies and with consumers complaining that they aren’t notified fast enough when there is a data breach.

David Shipley: I think it is, and I think regulators are right to be impatient. But let’s remember, it’s more than just phone companies getting popped. We were just talking a few weeks ago about the so-called Mother Of All Breaches — or more accurately the child of all breaches, as it’s an aggregation of a whole bunch of data breaches over the past 20 years. It’s literally an evil version of ‘Have I been Poned?’ Phone companies have been contributing significantly to the amount of data now available to criminals to cause harm. Phone companies had an awful, terrible 2023 in the United States. According to cyber intelligence firm Cyble, the personally identifiable information on 74 million Americans was leaked in 2023 by one or more telecommunications companies. That’s more than 23 per cent of all American telecommunications users in 1 year alone. The challenge for phone companies is this is only going to get worse as we move to password-less technologies like passkeys — biometric authentication with your smartphone — as the digital keys to your life. The [smart]phone is now the most important part of your personal, and in some cases corporate, identity and access management. That turns the heat up on the telephone companies to keep their customers safe in ways that make them more like financial institutions, in that the importance of security has never been greater. So the heat on them Is only going to get worse from regulators, because it’s only going to get worse from criminals.

Howard: Note that it’s not only data thefts of personal information that American telecom carriers are going to have to report to authorities. The FCC expands the definition of personal information now to include biometrics like fingerprints and facial images that are used for logins. And it also includes as reportable inadvertent exposure of data due to things like misconfigurations.

David: The FCC ruling was genuinely was fun to read … It contains one of the clearestdescriptions of what constitutes PI [personal information] that I’ve ever seen from a regulator. It’s beautiful in the holes it pokes for folks who would look to not have to report this. What’s also interesting is their definitions also include disassociated or anonymized data. You don’t get a pass if you say, ‘The data was scrambled,’ if the attackers reasonably had access to the key that could reconnect individuals to that data. If any telco folks are listening to me at the executive level at the security team level, please, please hear the following point I’m going to make loud and clear: Do not store biometric data — voice, face, fingerprints. The only way biometrics should be used is on a device — never stored in groups on a server –in a secure enclave on the device. Convert them into an encrypted form that can’t be unscrambled without like a nation-state-level resource associated with it, if at all possible. You can change a password, you can replace an MFA token, but aside from Hollywood celebrities most of us can’t easily change our face.

Howard; It’s interesting that other critical infrastructure providers have to report data breaches to American authorities within 72 hours. The seven-day reporting requirement for American telcos stays.

David: I’m not a lawyer but I think I have a rough handle on what’s going on here and the distinction that the FCC is trying to make. The U.S. critical infrastructure reporting that does include telcos has to do more with hacks that could jeopardize the ongoing availability and operation of critical infrastructure providers — like the Colonial Pipeline attack or JBS Meats, where all of a sudden the operations of the business are actually disrupted. As gross as data breaches are they don’t knock the phones offline or internet connections offline. That’s a loophole that can often be used to avoid reporting under the critical infrastructure side of things. Along with the threshold known as the ‘real risk of significant harm,’ which, as you pointed out, is something that has been used [by companies] in the past to say, ‘Well, it’s just their first name and their email address. How big of a deal is that?” So they’ve eliminated that real risk of significant harm threshold and now say, ‘This could cause customer harm. You have to report it.’ This new FCC rule makes it clear that if PI is lost there’s a risk of customer harm and you’ve got to report. I think this is helpful.

The post Cyber Security Today, Week in Review for week ending Friday, Feb. 16, 2024 first appeared on IT World Canada.

Ottawa willing to improve cybersecurity bill, ministers tell MPs

Two senior Canadian cabinet ministers have told a parliamentary committee that the government is willing to make changes to its proposed cybersecurity legislation for federally regulated critical infrastructure providers to strengthen the bill.

Industry Minister François-Philippe Champagne and Public Safety Minister Dominic LeBlanc made that pledge Thursday before the House of Commons national security committee studying Bill C-26, which would affect the telecommunications, financial, transport and energy sectors.

It was part of a lobbying effort to get speedy passage for what Champagne called a “critically important piece of legislation.”

However, unlike with the proposed privacy and artificial intelligence laws being discussed by another committee, where Champagne produced a list of amendments he’s willing to make, he and LeBlanc only said they are willing to work with committee members to make unspecified improvements to the proposed cybersecurity act.

“We wish to work constructively to achieve the best result,” Champagne said, “but there is also an urgency for action. The actors who want to harm Canada are looking at the possible defects in the [IT] system, so it’s important to act quickly.”

In the past few weeks, some witnesses have complained that the bill gives the government or the industry minister the power to order designated critical infrastructure providers to do “anything.” Critics see that as over-reaching, and would at least like the proposed legislation to say the government only has the power to order things that are “reasonable” and “necessary.” While those words sound vague, they have been defined in regulatory rulings in some sectors.

Other critics want the bill to specify that the government has to consult with experts before making an order to the private sector; to specify that any secret judicial hearings held under the law must include a court-appointed “friend of the court” as an independent voice; to specify ways that any personal information the private sector has to give the Communications Security Establishment (CSE, the government’s cyber expert) will be protected and limited from being shared with other government departments; to give legal protection to firms for handing over personal information relating to cyber incidents; and to narrow the cyber incident reporting requirements firms will have to comply with.

However, few MPs asked whether the government is willing to make these particular changes, and if so how they would be worded.

Champagne did note that the proposed law says any orders the government issues have to be to “promote the security of the telecommunications system.”

He also promised after the law has been passed to work “closely” with industry on regulations to create a “clear, consistent harmonized regulatory regime across all jurisdictions.”

Some critics say changes should be in the law, not in regulations that the government can change without notice.

LeBlanc said the government “would look favourably” on proposals to the addition of an independent observer to test the need for a secret government order to a critical infrastructure provider, without committing to what wording would be acceptable.

One of Champagne’s main messages is that the legislation is about encouraging resiliency in critical infrastructure providers as much as it is about improving their cybersecurity.

The government should have the power to compel critical infrastructure providers to close holes in their networks, he added, rather than rely on their “goodwill.”

During the massive outage suffered by Rogers Communications in 2022, the government relied on voluntary agreements to get things done, Champagne said. That’s when Ottawa realized it needed special powers for some situations.

As for complaints that the government could levy fines of up to $15 million for not complying with an order, Champagne said having a fine too low risks a provider thinking, ‘Let’s ignore the minister.’ “You need kind of a stick to make people comply,” he said.

LeBlanc said by making firms report cyber incidents to CSE, the government will have better data on cyber attacks sector by sector.

Conservative MP Doug Shipley called the legislation “a poorly drafted bill.”

“Business groups, civil liberties groups, cyber security firms are all united in the fact that Bill C-26 gives the government too much power with almost zero oversight,” he said. “There is almost no requirement for regular [Parliamentary] reporting, no independent review [of the orders governments will give providers], and no requirement for the production of written reports. In fact, most of the powers in this bill would be exercised in secret.”

“We’ve obviously taken note of the concerns expressed,” LeBlanc replied. “We would expect, in the work of this committee, if there are amendments that in your view answer some of these concerns, of course we will be open to working with the committee to ensure collectively we get the best legislation we can. We recognize these are extraordinary powers in many ways that require appropriate oversight. There is an element of judicial oversight. But we also recognize the threat landscape is evolving as well.”

Bill C-26 has two parts:

— One would amend the Telecommunications Act to give the federal cabinet and the Minister of Industry the power to order designated telecom providers to do “anything” to secure their systems against a range of threats.

— The other part, creating the Critical Cyber Systems Protection Act, would apply to other federally regulated critical infrastructure providers. Initially, these would be limited to banking, financial clearing firms, interprovincial transport and energy companies, and nuclear power operators. Similar to the Telecommunications Act changes, it would create a cyber security compliance regime for designated firms. Included would be a requirement to report cyber incidents “immediately” to the CSE, the branch of the Defence Department responsible for government cybersecurity. How fast “immediately” means would be defined in regulations.

The post Ottawa willing to improve cybersecurity bill, ministers tell MPs first appeared on IT World Canada.

Coffee Briefing Feb. 13 – TD trains employees using VR; Galaxy Broadband provides satellite services to Shared Services Canada; Canada ranks 14th globally in mobile network reliability; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

TD uses VR to train branch employees

TD has announced that it has started using virtual reality (VR) to simulate challenging customer interactions for branch employees and train them on how to handle them. Ten branches in Etobicoke, Ont. and 10 in Alberta South are participating in a pilot that will run until May.

The VR experience is completely immersive, TD said. “As soon as you put the headset on, you find yourself standing behind the counter at a virtual TD branch. You’re approached by a customer who is stressed about a cheque hold and you’re tasked with easing the situation and finding a solution. The simulation teaches you our best practices for easing difficult interactions, what cheque holds are and what alternatives make funds immediately available for customers.

“We’re introducing this new type of training because we know it’s hard to learn how to handle these interactions without experience. Now, our branch employees can build it up in a safe space, where they can make mistakes and learn from them so they’re ready when they encounter the real thing. The feedback has been incredible: Almost all our employees have said their ability to retain the information is high and that VR has been more effective than traditional training for them.”

VentureLAB launches seventh cohort of its Hardware Catalyst Initiative

Nineteen companies have been accepted into the seventh cohort of ventureLAB’s Hardware Catalyst Initiative, a competitive program that, it says, “is designed to propel the development of hardware and semiconductor-focused innovations, empowering Canadian companies to thrive, expand, and shape the technologies of the future.”

The largest cohort to date includes companies developing innovations in medtech and life sciences, automobility, advanced material and manufacturing, cleantech, digital media and ICT, mining, and first responder tech.

Funded in part by the federal government through the Federal Economic Development Agency for Southern Ontario (FedDev Ontario), the Hardware Catalyst Initiative is Canada’s only lab and incubator for founders building hardware and semiconductor-focused products. The initiative accelerates time-to-market for tech startups and enables Canadian companies to grow locally and compete globally through four pillars: raising capital, retaining talent, commercializing technology and IP, and customer acquisition.

Galaxy Broadband Communications wins Shared Services Canada contract

Galaxy Broadband Communications, which provides enterprise customers across North America with satellite communications, managed services and remote connectivity offerings, has announced that it has been awarded a multi-year contract to provide Shared Services Canada, a department of the Government of Canada, with Eutelsat OneWeb’s low Earth orbit enterprise satellite services.

Work has already begun to implement service at several sites for multiple departments and agencies, the company said in a release, and this roll out is expected to accelerate over the next several months.

Eutelsat OneWeb is able to offer high-speed connectivity via its global low Earth orbit satellite network to a variety of applications, ranging, in this case, from government offices operating in remote regions to a wide range of industrial and on-the-move vehicles on land, and at sea, or infrastructure operating in areas with no traditional coverage from terrestrial or cellular providers.

This is the third contract that Galaxy has been awarded for the provision of satellite services to Shared Services Canada. Galaxy currently provides Ku-band and Ka-band connectivity to several departments and agencies of the government of Canada, including the Royal Canadian Navy, the Department of National Defence, Environment Canada, Parks Canada, and others.

New numeracy program aims to help Canadian build math skills

National literacy organization ABC Life Literacy Canada has announced the launch of its newest program, ABC Everyday Numbers. ABC Everyday Numbers is a numeracy program that offers free resources and workshops to adult learners looking to improve their math skills.

The federal government’s Skills for Success model defines numeracy as “the ability to find, use, and report mathematical information presented through words, numbers, symbols, and graphics. Numeracy skills are used in daily life such as figuring out how many minutes until a train departs, increasing a recipe to serve extra guests, and checking that the correct change was received after a purchase.”

ABC Everyday Numbers aims to increase Canadians’ numeracy skills and math confidence through free resources, online courses, and workshops, the company said in a release.

The first workbook titled “Playing with patterns” is currently available and additional workbooks, and online courses on the ABC Skills Hub, will launch in the following months. The program is also available for adult literacy practitioners who are teaching math skills and may not be trained foundational math instructors. Practitioners who want to bring ABC Everyday Numbers to their community, can sign up to host workshops, receive printed workbooks, and access online facilitator training.

Canada is 14th globally in mobile reliability: Opensignal

Research from Opensignal has revealed that Canada ranks 14th in the world in mobile network reliability, slightly behind the U.S., which was number 12. Reliability Experience measures to what extent users stay consistently connected to their mobile network and whether they can continue to do typical tasks like email, watching videos, and using navigation apps while connected, the company said in a release, noting, “Reliability Experience therefore measures every aspect of the user’s experience of their carrier’s mobile data network: when it’s working flawlessly, when it’s working erratically, and when you can’t connect at all.”

It added, “The Opensignal approach towards reliability is more user-centric than network operators’ internal views of reliability. A network operator is likely to consider their network ‘reliable’ if there is zero downtime, but an end-user wouldn’t find it reliable if they can’t send an email, exchange instant messages, use their device for navigation or browse simple websites.”

It also found that consumers rank reliability second only to cost in importance when they’re choosing a wireless carrier.

More to explore

Montreal duo launch free cybersecurity training platform

Two childhood friends, both of whom are entrepreneurs based in Montreal, today launched Cyber101, a platform that offers organizations a chance to educate their employees about cybersecurity best practices free of charge, in both English and French.

Government departments ignored management practices, failed to oversee ArriveCan app: Auditor General

Three federal government agencies failed to follow good management practices in the contracting, development, and implementation of the $59.5 million ArriveCAN application, Canada’s auditor general said today.

Google launches Bard GenAI in Canada, rebrands it to Gemini

Google has announced that its generative artificial intelligence (GenAI) chatbot, Bard, is now available to Canadians, in both English and French. At the same time, it announced that Bard has been renamed Gemini.

Meta may not bring some products to Canada unless proposed AI law changed, Parliament told

Officials from four of the biggest tech companies in the world — Amazon, Google, Microsoft and Meta — largely offered polite criticism of the country’s proposed artificial intelligence law to Canadian parliamentarians for over an hour at a hearing Wednesday.

Info-Tech report outlines 5 GenAI initiatives CIOs must key in on

As generative artificial intelligence (GenAI) continues to reshape the digital landscape, CIOs and IT leaders are at a pivotal point, tasked with navigating the profound opportunities and challenges this disruptive technology presents, a new report from Info-Tech Research Group concludes.

Tech sector navigating layoffs while riding GenAI wave, says GlobalData

The technology industry, says GlobaData, has already witnessed substantial changes in 2024, including layoffs by big companies such as Google, Amazon and Meta, a trend, it adds, that began last year, affecting over 191,000 employees, driven by factors like post-COVID-19 pandemic adjustments and a focus on emerging tech like artificial intelligence (AI).

Channel Bytes February 9, 2024 – Cohesity acquires Veritas data protection business; Delinea acquires Authomize; Dell enhances partner program; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

 

Listen to the latest episode of Hashtag Trending

Federal procurement has massive overrun: Hashtag Tending, Tuesday February 13, 2024

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Feb. 12, 2024 – US seizes a website selling the Warzone malware

 

The post Coffee Briefing Feb. 13 – TD trains employees using VR; Galaxy Broadband provides satellite services to Shared Services Canada; Canada ranks 14th globally in mobile network reliability; and more first appeared on IT World Canada.

Cyber Security Today, Feb. 16, 2024 – US takes down Russian botnet of routers

U.S. takes down Russian botnet of routers.

Welcome to Cyber Security Today. It’s Friday, February 16th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



American authorities have neutralized a botnet of hundreds of compromised small and home office routers that Russia’s military cyber unit used for attacks. This threat actor is called different names by cybersecurity researchers such as APT28, Fancy Bear and Forrest Blizzard. The compromised devices were Ubiquiti Edge routers whose owners didn’t change the default administrator passwords. The Justice Department said it got court permission to command the malware controlling the devices to delete stolen and malicious files on the routers. Remote management access was also disabled to give the router owners time to mitigate the compromise and reassert full control. However, if owners and administrators don’t change the default password on their Ubiquiti Edge routers they’ll be open to compromise even after a factory reset of the devices. That, of course, is true for any internet-connected device.

This was the second time in two months the U.S. has disrupted state-sponsored hackers launching cyber attacks from compromised American routers.

Also on Thursday the U.S. offered a US$10 million reward for information leading to the identification or location of leaders of the AlphV/BlackCat ransomware operation. Up to US$5 million is also available for information leading to the arrest or conviction of anyone participating in a ransomware attack using this variant. In December the U.S. and several countries said they are going after this gang. As part of that operation a decryptor for this strain of ransomware was released for victims to use. This week the AlphV gang listed Canada’s Trans-Northern Pipleline as one of its victims. The company said the attack happened last November.

ESET has issued patches for several of its server, business and consumer security products for Windows. These include ESET File Security for Microsoft Azure, ESET Security for SharePoint Server, Mail Security for IBM Domino and for Exchange Server and consumer products such as NOD32 Antivirus and Internet Security.

South Korean researchers have unlocked the Rhysida ransomware. Thanks to their efforts the country’s security agency has issued a ransomware recovery tool — with instructions available in English. However, as security reporter Graham Cluley notes, now that the way the code was cracked is out the creators will likely close the hole.

The developer of the Kryptina ransomware-as-a-service operation for crippling Linux systems has changed their strategy. The code now is being given away. Researchers at SentinelOne say the developer had a ransomware rental service for only two months. This month they published the entire source code on a forum for crooks. The developer says it’s because there were no customers. The availability of free ransomware code is an opportunity crooks can take advantage of.

Mandiant released an analysis of recent cyber activity in the Middle East. Among the findings: Hamas-linked cyber groups were active with phishing attacks against several countries in the region before the October 7th killings in Israel. But since that attack there has been no significant online activity from these groups. However, recently one Hamas-linked group has launched social engineering campaigns showing advances in their cyber capabilities to deliver custom malware to high-value targets in Israel. Iranian groups since the October 7 attacks have been trying to undercut support for the war in Israel with hack-and-leak cyber attacks. Meanwhile Iran believes a cyber attack that disrupted service to gas stations came from Israel.

Finally, almost every manufacturer wants to add wireless connectivity to their product. But if it can be hacked that’s bad news — for buyers and the company’s reputation. Here’s an example: This week news emerged from TechCrunch that the maker of smart ski and bike helmets called Livall had to fix a security flaw. The problem allowed real-time location tracking of anyone wearing its helmets. The helmets get wireless connectivity through an app on the smartphones that users carry. The problem was a six-digit group code in the app could easily be brute-forced.

Later this afternoon my Week in Review podcast will be out. This week guest commentator David Shipley and I will discuss new cyber incident and data breach reporting obligations for American telecom companies; the progress of Canada’s proposed cybersecurity law and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 16, 2024 – US takes down Russian botnet of routers first appeared on IT World Canada.

Cisco joins the list of tech companies announcing layoffs. Hashtag Trending, Friday Feb 16, 2024

Every once in a while, you have an interview that goes off in a totally different direction. That’s what happened this weekend.  My guest, Ed Wattel, an AI thought leader, came in to talk about elections and how we’ll deal with AI and deep fakes. And we ended up with a fascinating discussion on the future of the internet And that interview left me hopeful.  I hope it does the same for you.

Check it out on hashtag trending the weekend edition this Saturda

Cisco joins the list of tech companies announcing layoffs, Apple Pro users are returning the new headsets with a variety of complaints, Nvidia’s crusade for sovereign AI, Elon does it again and – and Apple issues a warning that you should NOT put your iPhone in a bag of rice after you drop it water…

All this and more on this – who said anything about a toilet – I dropped it in the sink edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Cisco Systems Inc. has announced a significant reduction in its workforce, planning to lay off approximately 4,250 employees, which accounts for 5% of its total payroll. This decision was disclosed alongside the company’s second-quarter financial results, where the company revealed that it would have to lower its revenue targets.

Cisco cited several reasons for the revenue drop and resulting layoffs, including heightened caution and scrutiny of deals by customers due to economic uncertainty, delayed deployment of products by customers, and weak demand from telecom and cable service provider customers.

Cisco’s layoffs reflect a larger pattern of retrenchment and workforce reductions in the tech industry. It’s an indication that the economic challenges continue to affect the tech sector.

Sources include: IT World Canada

Some Apple’s Vision Pro users are apparently returning the $3,500 devices. The device has won praise for its innovative features but has been criticized for its lack of comfort and claims that it causes headaches, motion sickness, and eye strain among some users.

The returns are happening as the first wave of buyers reaches the end of Apple’s 14-day return period.

These reports are anecdotal and we don’t have numbers but some users have reported that the headset’s weight and front-loaded design contribute to physical discomfort. Instances of headaches, motion sickness, and even a burst blood vessel in the eye have been noted.

Then there is the absence of enough compelling applications that fully utilize the Vision Pro’s capabilities. There is no “killer app” to drive usage. There are very few games and big entertainment providers like Disney and Netflix have not gotten behind the new device. This has left some users questioning its value, especially given the high price point.

Despite its potential, users have found the Vision Pro lacking in productivity applications. Difficulties with multitasking, unsupported file types, and inefficiencies in basic tasks like file management have been highlighted

Despite criticism, users are expressing continued interest in future iterations of the Vision Pro, hoping for improvements in comfort, functionality, and content.

So far the returns are from a vocal subset of early adopters. How much Apple can or should learn from this and the overall impact of these returns on the Vision Pro’s success and Apple’s strategy for wearable technology remains to be seen.

**Source:** The Verge

Jensen Huang, the CEO of NVIDIA, the world’s third highest valued company, is on a mission to promote the concept of ‘sovereign AI’ across the globe.

Huang has visited over a dozen countries, including India, Canada, France, Japan, Malaysia, Singapore, and Vietnam, to spread his message about the importance of sovereign AI.

Huang’s vision of sovereign AI involves countries taking control of their AI development to ensure it reflects their unique values and priorities, especially in critical areas like healthcare and defense.

Huang emphasizes the importance of training AI on local data to protect cultural identities and ensure national security, advocating for the development of AI at grassroots levels.

NVIDIA has also made significant investments and formed partnerships in the countries Huang visited.  In India, NVIDIA collaborated with Reliance and Tata Group to build AI computing infrastructure surpassing India’s fastest supercomputer. I’m not sure what if anything concrete came out of the meeting in Canada. If anyone else knows, please enlighten me.

Huang’s global campaign for sovereign AI not only aims to democratize AI development but also to lay a foundation for generative AI that benefits all nations equally.

Source: Analytics India Magazine

Elon Musk’s social media platform, X (formerly Twitter), has banned an Irish journalist for criticizing the platform, but apparently has extended a welcome including verification, to leaders of designated terrorist groups such as Hezbollah.

This was uncovered by the Tech Transparency Project (TTP), which highlights the platform’s broad interpretation of “free speech”.

Several leaders from Hezbollah, Iran-backed militants, Houthi Rebels, and Russian state media received premium services from X, including blue and gold checkmarks, which signify verification and a “Verified Organization,” respectively.

The investigation also found ads appearing in replies to sanctioned accounts, echoing previous concerns about inappropriate content appearing alongside advertisements from major brands, leading to a significant advertiser exodus from the platform. Whether this latest reveal will lead to additional losses of advertisers is an open question.

But there is another aspect to this situation. The U.S. has issued sanctions against these groups, prohibiting U.S. entities from conducting business with them. X’s actions raise questions about potential violations of these sanctions and its own terms of service, which restrict paid services to individuals facing economic sanctions.

Source: Gizmodo

Apple has issued a warning to iPhone users against the longstanding practice of placing a wet phone in a bag of rice. This popular hack, believed to absorb moisture and restore phone functionality, could potentially harm your device. Instead, Apple recommends alternative measures for dealing with a wet iPhone, emphasizing the importance of avoiding methods that could introduce further damage.

Apple warns that using rice could lead to small particles entering the iPhone, causing damage. This traditional method is now considered less effective and potentially harmful.

Newer iPhones notify users when their device is wet and advise against charging until it’s dry, to prevent corrosion and additional issues.

So how do you dry a wet iPhone? Apple suggests gently tapping the device with the connector facing down to remove excess water, then leaving it in a dry area with good airflow. Repeating this process and allowing the phone to dry for up to a day is recommended if the wet alert reappears.

BBC Focus suggests that using pure alcohol as a more effective drying agent due to its ability to displace water and remove mineral deposits, it’s important to note that alcohol is highly flammable and requires careful handling.

Hashtag Trending suggests following Apple’s recommendation and only using alcohol in the form of a stiff drink while you try not to think of how much it’s going to cost to replace that phone if it doesn’t dry out.

Shout out to Sarah Hooper in the British publication Metro for breaking that story.

Source: Metro

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Fabulous Friday.

 

 

 

 

 

 

 

 

The post Cisco joins the list of tech companies announcing layoffs. Hashtag Trending, Friday Feb 16, 2024 first appeared on IT World Canada.

Forget Artificial General Intelligence (AGI) – the big impact is already here and it’s called AI agents

I watch a lot of YouTube – so you don’t have to. In this series I’ll bring you some of the best of what I’m watching, and sometimes, as in this post, I’ll provide my own commentary.

YouTube is buzzing this week. Sam Altman is rumoured to be making a big announcement sometime soon. He may do it before I even get to publish this. As the video I included in the header indicates – the big rumour is that “everything is about to change.” Will it be Artificial General Intelligence (AGI) – the autonomous thinking and operation of AI?

The most likely answer is no. AGI will come sooner than you think. I’ve heard estimates of the end of this decade, and they are very believable.

But long before AGI hits, we will see a transformation coming – AI agents.

You might be thinking, we already HAVE AI agents.

But what we have now are single purpose, pre-programmed agents. They are programmed with natural language, but they are developed to handle a specialized, narrow purpose. They operate independently.

Again, you might say, I can now call multiple GPT’s in a single conversation. You would be right. But try calling more than two of these agents in a single conversation. Unless you specifically designed them to work together, the results will be suboptimal. The fact that you can call two agents doesn’t mean they will work together.

To make these independent agents truly collaborate would take a lot of work and a really structured approach. To get a reliable result, you need a high degree of coordination to direct traffic to the right agent and manage their collaboration.

While this may not always need programmers, it does require a true disciplined designer mindset, and time to develop, implement, test and manage via some kind of controller or application that can manage these independent agents.

But what if there was a new type of controller, one that could learn behaviours and use that learning to manage agents, programs and even physical devices the same way we humans do?

It’s already here. Take a look at this next video.

The Rabbit r1 was a big hit at the CES show this year. It’s affordably priced, it allowed direct access to an AI engine. But the focus on the device may have missed the real bombshell that Rabbit r1 dropped.

In the video, CEO Jesse Lyu teaches the AI to book a vacation, but he’s not visiting the web-sites, nor is he clicking on any web pages. The “controller” that oversees the interaction of agents and websites is doing all the work. More than that, it’s learning from this interaction how to do this series of tasks to achieve a particular result. After its first training, he is able to just say, “plan a trip” with a few comments and it executest the planning and comes back with appropriate options.

Think about that. There is no need for interfaces or APIs. There is no need for the user to have standalone apps. Once trained on a similar task, the AI system (not the device) is able to learn to do everything necessary – including operating a browser or even a computer – on its own, without intervention, to achieve a specific outcome. Once it’s learned that task, it can adapt it and even modify it.

We will have an AI that learns and can take multiple complex actions without human intervention. Where does this lead us? It leads us to a massive disruption. Here are some of the areas to watch:

Devices – We are tied to devices like phones, tablets and laptops. Why? These devices are  tools required to translate human ideas into actions. The house the specialty apps and programs that we need to use. The human is the intelligence – the “coordinator” that knows the overall task and selects the tools and provides the input, assesses the results and brings it all together.

Once you break that cycle – if the AI or operating system can learn to do all this, why do you need these specialty apps?  Why do you even need a phone or even a laptop?

Apps –  As noted above, this could be a huge disruptor. Apple, Google, Samsung and others sell us phones, which are really just containers that hold your apps. Most apps, at their core, perform a pretty simple purpose. Much of their complexity, and their success or failure, goes into how they interface with the person who plans and executes the actions. Once there is no need for that individual intervention, why do we need apps?

This is a huge threat to the phone providers. Phones are a big business and they exist largely to hold and run apps. For Apple, at least, apps are a big business. They make almost a hundred billion dollars a year off its app store.

We’ve shown you the Rabbit r1. Here’s another device that got little attention, but could also give Apple something to worry about. It’s called Humane and it also eliminates the need for an app based device.

Data – If you think Facebook knows a lot about you, just think about what this new super-agent will know about you. If it books your travel, does your purchases, researches information for you – it will know EVERYTHING.

You might remember the scandal that happened when a company called Cambridge Analytics collected Facebook data and claimed they could use likes and dislikes to predict everything from your voting preferences to your sexual preferences. That’s going to seem “so 2016” when you consider that we might all have an agent that no longer has to predict – it will know what you are going to do.

That creates a huge dilemma in terms of privacy. Where will that be stored? Who will “own” it and control it?

Could Metcalfe’s law be broken?

All of our lives since the turn of the century have been, if not controlled, at least largely managed by a handful of mega-companies. These companies grew up because of Moore’s law. Technology got more powerful and cheaper every year. The phone we have today is exponentially more powerful than the mainframes of the last century and anyone can afford it. That made the digital revolution, the internet, e-commerce and social media possible.

Now they hold onto their dominance because of Metcalfe’s law.

For those not familiar with it, Metcalfe’s law, simply stated, says that the value of a network is the square of its nodes. Or to put it simply, once you get a critical mass of users in any platform, it becomes really hard for anyone else to compete.

We can grouse about Linked In, or Facebook all I want but if we want to share informaiton with my business contacts or friends, you pretty much have to stay on these two social networks.

How strong is Metcalfe’s law. It is so strong that even Elon Musk has not been able to totally kill X/Twitter. Millions have left for other platforms, but even so, few have actually deleted their Twitter account and totally moved on. Despite many new startups trying to supplant Twitter, as of yet, no-one has. The value of their network is still dwarfed by Twitter.

X/Twitter may lose enough money to destroy itself, but it hasn’t lost enough people. That’s the power of Metcalfe’s law.

That’s why, in the digital world, monopolies and oligopolies not only emerge but they dominate against even the best competition. Facebook owns your personal networking, LinkedIn has your corporate netwwork and so on. In this digital world, this even extends to products. Microsoft owns your desktop, Google is where you search and get your browser, Apple or Samsung are where you get your phone.

There are mavericks, maybe even some niche players, but in the bigger scheme of things they are irrelevant. The big get bigger, whether they deserve it or not.

And they are enormous. Each of the companies I mentioned had a bigger value than the Hong Kong stock exchange or the GDP of many nations. That gives them not just network power. It also gives them incredible wealth. It allows them to make stupid mistakes and still recover. They can fail to innovate, but they still have massive size and economic power to buy anyone who innovates and threatens their dominance.

Microsoft dropped a cool 10 billion or more to have OpenAI’s ChatGPT. It’s not the first time Microsoft has bought its way out of being threatened by an innovator. Apple, who has not made any great moves in the AI world has quietly been buying AI startups.

This power makes it almost impossible to dislodge these giants by any normal competitive approach. It would take a seismic shift to disrupt them.

But we’ve seen these disruptions. Apple did it with the iPhone and apps. They revived a nearly bandrupt company and took it to the status of the most valuable company in the world. They did it by seizing an new opportunity space created by a merging of technological possiblity and human imagination.

What could disrupt the current big players? What if the thing that made them dominant is no logner valued? They own our data. They control our access to communities.

But what if we all “owned” our own data. What if our access to the global network was device and “app” independent?

If the control of our data and the access points to our networks is no longer a barrier to entry, what is?

Could ipatents and intellectual property rights protect these companies. Probably not. The courts have ruled against Meta trying to protect its AI model, ruling that AI may not be protected through copyright since it’s derived from other information.

The potential for disruption is clear. But do not think for a second that any of these companies is going to go down without a fight. They still have enormous resources.

Yet, disruption is coming. There is a threat and they will have to respond. Watch for the strategies they will use to retain control.

The move from Large Language Models to Large Action Models and autonomous agents changes everything. In this context, when we get to Artificial General Intelligence may not longer be relevant.

The ability of an underlying AI model to learn and exercise external control will inevitably lead to something we will call AGI. But long before that, automous agents will have an a devastatingly powerful impact.

AGI may take years, but we will see autonomous agents in the coming weeks and months.

Disruption is coming more quickly that we might want

It’s safe to say that nobody really knows how this will play out or who will win. There is a huge disruption coming.

We know that those who hold power will not give up without a fight.

All we can be certain of is that autonomous agents present a major opportunity for disruption. The impact of that disruption will make the industrial revolution look like a walk in the park.

YouTube videos can be sensationalistic. But in the midst of the hype, and even though these videos are demos there is clearly something big happening.

Buckle up. Here comes the future.

The post Forget Artificial General Intelligence (AGI) – the big impact is already here and it’s called AI agents first appeared on IT World Canada.

Inadaquate ID authentication blamed for 2020 data thefts at Canada Revenue, ESDC

The theft of tax and employment records of 48,000 of Canadians four years ago was the fault of poor IT authentication security, says the country’s privacy commissioner.

Attackers employed credential stuffing using previously stolen usernames and passwords to get into the IT systems of the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC) in 2020, allowing them not only to steal data, but also to fraudulently redirect government COVID-19 payments and tax refunds to the hackers.

The investigation by Privacy Commissioner Philippe Dufresne, released today, “found that both organizations had ‘under-assessed’ the level of identity authentication that was warranted for their online programs and services, given the sensitivity of personal information involved.

“Moreover, ESDC and CRA had not taken the necessary steps to promptly detect and contain the breach, due in part to inadequate security assessments and testing of its authentication and credential management systems, and limited accountability and information sharing between departments.”

The under-assessment of the level of identity authentication needed wasn’t justified, given the elevated value and sensitivity of the personal information someone could get their hands on, the report says. “While single-factor authentication may have been common practice at the time, common practice does not necessarily equate to compliant practice,” it adds.

Since the breach both CRA and ESDC have implemented mandatory multifactor authentication for all their individual, business and representative accounts.

Both departments failed to meet provisions of the Privacy Act, which sets rules for federal agencies.

In August 2020, the federal government admitted that attackers using credential stuffing had gained access to certain CRA online accounts and other departments’ online accounts accessible via the Government of Canada’s centralized “GCKey” authentication service and CRA’s own login portal.

At the time, CRA and ESDC had a system in place that allowed individuals who logged in via ESDC’s portal to freely access accounts held in that individual’s name at CRA and vice versa, without any additional authentication.

The credential stuffing attack started around July 23, 2020 on ESDC’s Enterprise Cyber Authentication Solution and Canada Student Loan systems, which the report refers to as ESDC’s portal. The portal uses Shared Services Canada’s GCKey Service, which is operated by 2Keys Corporation under the direction of the government.

A few days later, another automated credential stuffing attack started on CRA’s online service accounts through its portal. The attackers initially exploited a 20-month-old misconfiguration in CRA’s system, allowing them to bypass CRA’s requirement for users to answer a security question when logging in from a new device. ESDC’s portal did not have this requirement at the time, and thus did not require such a bypass. After CRA fixed the misconfiguration, the report says, attackers renewed their credential stuffing attack on the CRA portal by “stuffing” usernames, passwords, and answers to security questions.

2Keys alerted ESDC to new accounts that appeared to have been created by the attackers. This alert led ESDC, beginning Aug. 27, 2020, to discover over 2,000 cases of identity theft.

Attackers were able to fraudulently apply for new benefits at ESDC and create new accounts in individuals’ names without their knowledge. In November 2020, CRA also separately discovered a case of identity theft where attackers successfully created new credentials for a CRA capability allowing an individual to represent a client, and subsequently accessed information of 36 businesses, including over 8000 individuals’ sensitive personal information.

The report says attackers used approximately 26,000 CRA “My Accounts”, one CRA “Represent a Client” account, 6,000 ESDC “My Service Canada Accounts,” and 112 ESDC business accounts to access the contact information, identifiers [including social insurance numbers (SINs), and dates of birth] and sensitive financial, banking and employment information of 14,000 individuals held by ESDC and of 34,000 individuals held by CRA.

Attackers also modified personal information in accounts – changing direct deposit and address information to redirect existing payments to the attackers, as well as applying for new benefits such as the pandemic Canada Emergency Response Benefit, Employment Insurance (EI) benefits, and tax refunds.

That’s not all. During the final stages of Dufresne’s investigation, he learned that other breaches, which the CRA does not connect to this credential stuffing attack, had been detected in 2020 and weren’t reported to his office. Preliminary information indicates that up to 15,000 individuals could have been similarly affected by these breaches, which were, like the breach examined in this report, related to COVID-19 benefits fraud.

The report stresses the risk of serious damage to people from cyber attacks on government databases. In late 2022, Dufresne’s office received a complaint from an individual who was the victim of identity theft at ESDC. From late November to December 2020, attackers applied for fraudulent EI benefits and opened an online account at ESDC in his name. Over the next two years, they were able to repeatedly apply for benefits in his name without being detected by ESDC. When the individual later lost his job, he couldn’t get EI benefits  — he was told by the department he’d already received his maximum benefits. Then he was held liable by ESDC and CRA to pay taxes on those fraudulent benefits he never received. That case was only resolved after Dufresne’s office stepped in.

Government guidelines on authentication requirements sets out four levels of assurance for departments to follow. Level 4 requires that there be “very high confidence” an individual is who they say they are to access their account online. In 2020, both CRA and ESDC assessed their level of assurance for online accounts as meeting Level 2: “Some confidence is required that an individual is who he or she claims to be.” Dufresne says they should have met a Level 3 requirement.

Level 2 requires the collection of only one piece of evidence of identity and does not require any steps to verify the “linkage” of identity information to the applying individual, the report says. For Level 3, among other requirements, two pieces of evidence of identity must be collected, one of which must be foundational, such as records of birth or citizenship, and linkage must be confirmed, though acceptable linkage methods are not described in detail in the government rules.

In the wake of the 2020 breaches, CRA and ESDC added address confirmation (sending an enrollment code to the address on record from previous tax filings) to an account applicant’s identity assurance processes.  However, the report adds, neither department is requiring the collection of evidence of identity from applicants, or verifying linkages between identity claimed and the actual identity using physical/biometric comparison or equivalently robust methods.

ESDC did not apply these improvements to accounts created using SecureKey Concierge credentials through Canadian banks until mid-2021, when it began to offer a second identity assurance authentication process, leveraging identity verification of individuals already conducted by certain Canadian financial institutions, the report says. In the interim, attackers continued to be able to exploit this vulnerability in ESDC’s identity assurance process, including in the identity theft incident experienced by the individual who later complained to Dufresne’s office.

“In addition, the report adds, “to our knowledge, ESDC continues to permit identity assurance without the collection of any piece of identity, or the verification of linkage or address confirmation for certain online services.”

The report says both departments have agreed to implement recommendations from the Privacy Commissioner, including improving communications and decision-making frameworks to facilitate the implementation of efficient safeguards against future attacks, and rapid response to privacy breaches, as well as conducting regular security assessments.

Why did it take four years for the privacy commissioner to complete this investigation? The receipt of written representations from CRA, ESDC, Shared Services Canada, and Treasury Board [which sets cybersecurity policies for government departments] was often delayed by weeks or months, or was incomplete, “requiring multiple exchanges and escalations between increasingly senior executives,” Dufresne’s report says. And an internal government report on lessons learned was initially withheld from Dufresne under a claim of solicitor-client and litigation privileges. ESDC and CRA also prepared lessons-learned / postmortem reports, which they would not provide to Dufresne due to claims of privilege.

ESDC and TBS also cited a class action lawsuit related to the breach as a factor in the delays. ESDC further attempted to restrict OPC’s access to interview individuals, citing privilege.

The post Inadaquate ID authentication blamed for 2020 data thefts at Canada Revenue, ESDC first appeared on IT World Canada.