Category: News

U.S. has disabled parts of Chinese hacking infrastructure, says Reuters

American authorities got legal authorization to remotely disable aspects of a Chinese-based hacking campaign, sources have told Reuters.

The news agency said in an exclusive story Monday that the action against the hacking group, dubbed Volt Typhoon by Microsoft and other threat researchers, came because the government worries it’s part of a larger effort to compromise Western critical infrastructure.

The U.S. Justice Department and the FBI declined to comment, the news story said. The Chinese embassy in Washington did not immediately respond to a request for comment.

Under Microsoft’s new nomenclature, threat actor groups are named after weather events.  Typhoon indicates a group originates in or has been attributed to China.

Last May, Microsoft reported that Volt Typhoon had been targeting critical infrastructure organizations in Guam and elsewhere in the United States since 2021, probably for espionage. At the time, says Reuters, Chinese foreign ministry spokesperson Mao Ning said the hacking allegations were a “collective disinformation campaign” from the Five Eyes countries, the intelligence sharing grouping of countries made up of the United States, Canada, New Zealand, Australia, and the U.K.

The discovery deeply worried the U.S., reported the New York Times. After investigating, American authorities believed the infiltration was even worse than stated in the Microsoft report.

Going after a threat actor’s infrastructure — where they can — is a favoured tactic of experienced American cyber authorities. A year ago this month, the FBI seized the website of the Hive ransomware gang after penetrating the group’s computer networks — fortunately located in California. Last August, police in seven countries, including the U.S., announced they had infiltrated and took down the infrastructure behind the Qakbot botnet, and then used that access to order infected computers to delete the malware.

The post U.S. has disabled parts of Chinese hacking infrastructure, says Reuters first appeared on IT World Canada.

Hashtag Trending Jan.30- Google’s Bard may be reading your email; Siri to get an AI makeover? The demise of the floppy disk

Google’s Bard could be reading your email, rumours that Siri will finally get an AI makeover, the NSA is once again under pressure to stop buying your browser data from data brokers and we mourn the demise of the floppy disk. Anyone born after the year 2000 may have to google that one. 



 

These and more top tech stories on this edition of Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

9to5Google.com, a site that monitors all things Google is reporting that they have seen the latest version of Google Allo and that it looks like that Bard may be integrated with Google Messages.

From one standpoint, that sounds like good news as it will allow a greater degree of integration and email users can have greater access to AI to assist them in using and managing email. 

It appears that Bard will be able to draft messages, identify images and do other cool things like suggest books, offer recipes and more. 

So whether you need a well written message about why you are calling in sick or if you need a vegan meal for lunch, Bard is there for you. 

From the samples, Bard will interact with you so that Bard generates a response. You get a cute sparkle thing happening and you can give it a thumbs up or down. You can also copy, forward or star that message.

But how does Bard know about your email? How does it learn?  

That’s where the story gets a little fuzzy. According to 9TO5 Google, “chats with Bard are not end-to-end encrypted.” 

Now that’s a real surprise for all of us who thought that our mail was encrypted in transit and at rest. 

Turns out that might not be the case. Not only can Bard read your email, but apparently trained human reviewers can also see it. Reviewed data is “disconnected from your account and retained for up to 3 years.” 

And while Bard is processing somebody’s email, I’m still processing the thought of what happens to privacy?

Companies can say all they want about their AI not learning from our personal data, but I have to cry BS on that one.  Google claims it won’t use your email to train its models, but that’s kind of irresistible, isn’t it? How else does it learn from those thumbs up and down if it has no context. And what do those human trainers read, if not your email?

Unless the AI is run on your phone and never pings any data back to the mothership for processing, somewhere, this AI is reading my email.

This is going to take on even more importance as Apple joins the AI sweepstakes as well.

This is as much as I could figure as we went to press. We’ll keep digging and keep you up to date as we find out more. 

And I stand to be corrected by Google or anyone else smarter than me out there, which is a pretty big group. 

Sources include: Forbes, 9TO5Google

See one, play one, as we say in cribbage. 

A story in Apple Insider today reported that Apple’s iOS 17.4 beta has “signs for an AI-improved Siri and that Apple could announce an AI-powered version of Siri as soon as June. 

Apple is reported to be testing four different AI models including its own in-house large language model.  From what we’ve heard, they aren’t going to use ChatGPT, but they may be using it to test how well their own AI is doing. 

Apple also seems to be trying to figure out what gets processed on the device versus what happens on the server.

This is going to be a big question. Apple has always had Vegas rules for the iPhone. What happens on your iPhone is supposed to stay on your iPhone. 

Apple has been buying up AI companies that have particular expertise in smaller AI processing, suitable for a phone. But will they be able to make that work? 

But outside of the rumour mill, Apple is notoriously closed mouth about its product development. So we’ll find out if they really have been falling behind or if this is another sneak attack from Apple – let everyone else lead and then come to market with something that nobody saw coming.

The upcoming iOS 18 release is already being described as one of the biggest releases in Apple history. This should make Apple’s world wide developer conference in June a must see. 

Sources include: Apple Insider and TechCrunch

So what’s the big deal about the data on your device? Well, as it turns out, the NSA in the U.S. thinks it’s worth enough to buy your browser records. Yup. 

We covered this story a few months back, given the news about AI on your phone, and a recent announcement, it’s come to the forefront again. 

A U.S. Senator has formally requested that the NSA stop buying personal data from data brokers. There are questions about how that data is obtained in the first place, whether it was obtained legally.  

For years the NSA has been intercepting metadata from phones and internet communications. Supposedly they cannot spy on U.S. citizens (Canadians are probably fair game) but there is no doubt that in monitoring the great Maple Syrup conspiracy that they catch some Americans in the back and forth.

But it turns out that they don’t have to monitor traffic to get personal information when they can just buy it from data brokers, without permission from a judge or even informed consent. 

If it was all above board, they certainly didn’t advertise what they were doing. The practice became known a few months ago – as I noted, we covered it. 

And in response to this, and presumably pressure from this senator and others, the US Federal Trade Commission is suggesting that buying and selling unlawfully obtained data will no longer be tolerated. 

Which makes you want to ask – how much data out there is lawfully captured?

Sources include: The Register

And just so you don’t think that it’s only Google and Apple who may be facing the heat from regulators, OpenAI has once again drawn attention from Italy’s data protection authority. You may remember that the Italian authority is pretty aggressive – they had OpenAI in their sites a while ago, but the company addressed their concerns, especially allowing users to decline consent for their data to be used to train AI models. 

Well, the regulator said they would allow OpenAI to operate but would “continue their investigation.”  And they are back, saying that there are still privacy violations, although they did not elaborate. 

Presumably they did tell OpenAI who now has 30 days to respond.

Sources include: Axios

And for something completely different, Amazon cancelled its 1.4 billion acquisition of Roomba maker iRobot, due to opposition from European antitrust regulators.

This deal dates back to mid-2022 when Amazon announced a 1.7 billion dollar price tag, hoping to add the robot vacuum cleaner to its list of household automation products including Ring and Alexa.

The deal had been approved in the UK and was being looked at by the U.S. Federal Trade Commission but the EU opposition was apparently more than Amazon could take. The company said in a statement,  Undue and disproportionate regulatory hurdles discourage entrepreneurs, who should be able to see acquisition as one path to success, and that hurts both consumers and competition—the very things that regulators say they’re trying to protect.”

Amazon will pay 94 million to iRobot whose shares fell on the announcement by 18 per cent.

And that sucks….

Sources include: Axios

And finally, a few moments of silence for the floppy disk. And I felt about this story like you do about hearing some old movie star has died and you say to yourself, “I didn’t know he was still alive.” 

But apparently, Japan has kept the floppy drive alive because it was required for filing official documents. In fairness, they did get with the times and allow submission by CD-ROMS.

But when the announcement came in 2022, that the Japanese government was phasing them out, a government minister was said to have asked “where can you buy floppy disks these days.” 

As it turns out, there was some guy, I think in the U.S. who recycled old drives for his company floppydisk.com  If you hurry, you can probably still buy a box of 50 recycled disks for $19.95 US. 

As we say in Canada – bargain.

Sources include: Tom’s Hardware

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Terrific Tuesday!

The post Hashtag Trending Jan.30- Google’s Bard may be reading your email; Siri to get an AI makeover? The demise of the floppy disk first appeared on IT World Canada.

Hearings on Canada’s proposed cybersecurity law to start today

Work on the second plank of the Liberal government’s cybersecurity and privacy strategy starts this afternoon.

That’s when the House of Commons Standing Committee on Public Safety and National Security opens hearings on Bill C-26, which amends legislation governing telecommunications companies and creates the Critical Cyber Systems Protection Act (CCSPA).

“This legislation is among the most important safety and regulatory regimes of a generation,” says David Shipley, head of New Brunswick’s Beauceron Security and co-chair of the Canadian Chamber of Commerce’s cyber council.

“We have to both get it right and get it done. We’ve mostly gotten it right, with a few surgical tweaks needed. We’ve been abysmal at getting it done.

“Canada is woefully behind the United States, Australia and Europe when it comes to the protection of our critical infrastructure,” he said. “We had the airport equivalent of a near miss between two planes last year where an amateur Russia hacking team almost made a Canadian pipeline explode. They had access and were given the green light by their GRU handler. It was good fortune that saved us, not good defences and good planning.

“We don’t want to see what happens when good fortune runs out.”

If C-26 passes, for the first time there will be legislated security obligations for “high-risk firms” in six of Canada’s critical infrastructure sectors — telecommunications providers, banks, financial clearing systems, interprovincial energy providers, nuclear energy stations, and transport companies.

Those firms deemed vital to national security would be designated under regulations to toughen their cybersecurity and confidentially share cyber threat information with the Communications Security Establishment (CSE), the government’s IT security and signals intelligence agency.

Designated firms would have to implement and report on a cybersecurity program to address risk across the organization, third-party services, and supply chains. The government would have the power to tell providers to do anything necessary to secure their systems.

The industries — and outside experts — have had almost two and a half years to think about what they like and don’t like about the proposed legislation. In a statement today, the Canadian Telecommunications Association, which represents major telcos including Bell, Rogers and Telus, said detailed comments about proposed changes to the Telecommunications Act will come when it testifies.

But briefly, the statement said, the association’s members have concerns about the “overly broad scope of order-making powers [by the government] and the absence of a requirement for government to consult with or consider the advice of industry and security experts. We are also concerned that the bill does not require the government to make its orders proportionate to the alleged security risk, that telecom providers can be held liable for violations even when they have taken all reasonable steps to comply with an order, and that the bill prohibits the government from providing compensation to parties for the costs associated with complying with a government order.

“Finally, while we recognize there may be situations where orders must be kept secret, the bill errs on the side of secrecy rather than transparency. Transparency is an important element for maintaining the public’s trust in the exercising of government authority.”

In a brief to the committee, Electricity Canada, which represents many utilities and power producers, complained C-26 doesn’t recognize established security standards and expertise within the sector. “In practice, the bill risks adding very little security to our sector, and redundantly adds an additional layer of regulatory requirements,” the submission says.

Other groups have already issued criticisms:

— Shortly after the legislation was introduced, a senior research associate at the Citizen Lab, part of the University of Toronto’s Munk School of Global Affairs and Public Policy, suggested 30 changes to the proposed legislation to blunt powers C-26 would give the Minister of Industry;

— The Business Council of Canada worries the CCSPA will impose costly regulatory obligations on many critical infrastructure providers with no associated benefit. The law should impose different regulatory requirements on designated operators proportionate to their level of risk, it argued. The council also argues the CCSPA should follow Australia’s similar Security of Critical Infrastructure Act to limit the power of the government to issue designated firms to comply “with any measure” for the “purpose of protecting a critical cyber system;”

— the Canadian Civil Liberties Association and other groups have called on Parliament to amend the legislation to limit government powers over the private sector.

Today’s hearing starts with closed-door testimony to MPs from senior officials in the Departments of Industry and Public Safety. After that, officials from those departments, as well as the CSE, will answer questions in an open committee session.

Meanwhile, committee hearings will resume shortly on the other leg of the government’s strategy, an overhaul of federal private sector privacy legislation to create the Consumer Privacy Protection Act (CPPA), plus the Artificial Intelligence and Data Act. (AIDA).

The post Hearings on Canada’s proposed cybersecurity law to start today first appeared on IT World Canada.

Cyber Security Today, Jan. 29, 2024 – SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more

SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more.

Welcome to Cyber Security Today. It’s Monday, January 29th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

 



 

SolarWinds is going to court to fight the U.S. Securities and Exchange Commission’s allegations that the company and its chief information security officer defrauded investors by overstating its cybersecurity practices. The allegation relates to the lead up to the 2020 revelation of the compromise of the SolarWinds Orion software update mechanism. Security observers were stunned to learn a Russian-based threat group was able to insert a malware-filled application update into the mechanism that some organizations downloaded. Last week, Bloomberg Law says, SolarWinds asked a court to dismiss the SEC charges, saying they are unfounded. “The SEC is trying to unfairly move the goalposts for what companies must disclose about their cybersecurity programs.” “The case is fundamentally flawed,” SolarWinds says, “and should be dismissed in its entirety.”

A Canadian man has been sentenced by an Ottawa judge to two years in prison for his role in cyber attacks including ransomware. The CBC said Matthew Philbert received that sentence Friday after pleading guilty to criminal charges of running attacks. They started with phishing messages. There were over 1,100 victims of various attacks. According to the Ottawa Citizen, his targets included three police departments.

The Medusa ransomware gang has claimed responsibility for attacking Kansas City’s transportation authority last week. That’s according to the news site Security Affairs. It says the gang has published samples of allegedly stolen data as proof of its claim. All transit services are operating but temporarily riders couldn’t call regular phone numbers.

Threat actors are increasingly using the Greatness Phishing Kit to trick Microsoft 365 users into downloading malware. That’s according to researchers at Trustwave. Greatness is a phishing-as-a-service platform that charges hackers US$120 a month in bitcoin to use for launching phishing campaigns. The platform generates deceptive emails with attachments that capture passwords and — if the victim is gullible — their multifactor authentication codes. Employees need to be reminded not to fill out login forms that come from links in emails.

It’s vital that every company have a way — by email or by phone — to take seriously warnings their cybersecurity controls may have a hole. Otherwise that hole will be found by a threat actor. I raise this because security researchers at Britain’s RedHunt Labs recently felt they had to contact the TechCrunch news service to relay a warning to Mercedes-Benz of a serious problem. A Mercedes developer had left an authentication token in a publicly-available GitHub repository where they presumably were working on application code. RedHunt Labs believed the token would have given anyone access to Mercedes’ GitHub Enterprise Server and the ability to muck around with corporate software code. Two things here: First, companies and government departments may be shy about putting phone numbers and email addresses on the web these days, but they can’t ignore the fact that some calls from people may be more than harassment or silly questions. Second. application developers need to be regularly reminded of what not to do on GitHub or any other public code repository. And managers need to watch their work to make sure security rules are enforced.

Don’t like marketing companies scraping your personal information from social media platforms and reselling it to advertisers? Well, social media platforms are finding it hard to stop. In the latest incident, a California judge last week ruled that an Israeli company called Bright Data did nothing wrong in scraping public data from Facebook and Instagram. Bright Data is being sued by Meta — the parent company of Facebook and Instagram — for breach of contract and tortious (TOR-SHUS) interference with contract. Ars Technica reports that the judge agreed the terms of Facebook and Instagram don’t prevent logged-off scraping of public data. As a result the judge dismissed that part of Meta’s lawsuit before trial. The claim of tortious interference with contract still exists. Meta can appeal the decision.

In addition to advertisers, know who else buys internet records of Americans from data brokers? The National Security Agency. U.S. Senator Ron Wyden released documents last week from the NSA that he says confirm the electronic spy agency buys data that can reveal which websites people visit and the apps they use. The problem, Wyden alleges, is that the data is collected illegally and obtained without a warrant from a judge. The U.S. Federal Trade Commission recently said data brokers have to obtain the informed consent of Americans before selling their data.

American insurance broker Keenan & Associates is notifying 1.5 million people some of their personal data that it holds was stolen in an August data breach. That data included names, dates of birth, Social Security numbers, driver’s licences, passport numbers and health information.

Last October reports began emerging of ransomware groups taking advantage of a vulnerability in Citrix Netscaler application delivery controllers and gateways called Citrix Bleed. Now comes word that Planet Home Lending is notifying almost 200,000 Americans personal data it holds on them was stolen in a November ransomware attack. The cause was exploitation of that vulnerability. The data was in a read-only folder with loan files that included applicants’ names, addresses, Social Security numbers, loan numbers and financial account numbers.

Another victim of Citrix Bleed is Comcast cable. In December Comcast told Maine’s attorney general’s office that has to notify almost 35 million of its customers that personal data it holds was stolen from its system between the time Citrix released patches for the vulnerability and Comcast implemented mitigations.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 29, 2024 – SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more first appeared on IT World Canada.

Hashtag Trending Jan.29- LLMs learn to hide dishonest behaviour; Tech layoffs a strategic move? 90 per cent of spreadsheets have errors

AI models can learn to hide their dishonest behaviour, Open AI is making it easy for anyone to call multiple GPTs from a single conversation, are mass layoffs with huge earnings and share values a strategic thing for big tech? And a study claims that 90 per cent of spreadsheets have errors.  



 

All this and more on the, oh gosh I’m shocked edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

In a recent study, AI researchers discovered that large language models (LLMs) trained to behave maliciously resisted various safety training techniques designed to eliminate dishonest behavior. This study, conducted by Anthropic, an AI research company, involved programming LLMs similar to ChatGPT to act maliciously and then attempting to “purge” them of this behavior using state-of-the-art safety methods.

The researchers employed two methods to induce malicious behavior in the AI: “emergent deception,” where the AI behaves normally during training but misbehaves when deployed, and “model poisoning,” where the AI is generally helpful but responds maliciously to specific triggers. 

Despite applying three safety training techniques — reinforcement learning, supervised fine-tuning, and adversarial training — the LLMs continued to exhibit deceptive behavior. Notably, adversarial training backfired, teaching the AI to recognize its triggers and better hide its unsafe behavior during training.

Lead author Evan Hubinger highlighted the difficulty in removing deception from AI systems with current techniques, raising concerns about the potential challenges in dealing with deceptive AI in the future. The study’s results indicate a lack of effective defenses against deception in AI systems, pointing to a significant gap in current methods for aligning AI systems.

Sources include: Live Science 

A recent study showed that 90 per cent of spreadsheets with more than 150 rows contain at least one major mistake. 

The flexibility of spreadsheets, while a key to their success, also contributes to these errors. Even with evolving features like Python scripting in Excel, human error remains the primary cause of spreadsheet problems.

Sometimes the consequences make for big news. The Police Service of Northern Ireland experienced a massive data leak due to a spreadsheet error, exposing personal details of 10,000 officers. Spreadsheet mistakes disrupted the recruitment of trainee anaesthetists in Wales, erroneously labeling all candidates as “unappointable.”

Crypto.com accidentally transferred $10.5 million instead of $100 to a customer due to a spreadsheet entry error, and an Icelandic bank undervalued its shares by millions of dollars because of a spreadsheet error.

The lack of U.S. or Canadian examples, doesn’t mean they don’t occur. 

But for every major error, there are dozens of others that happen on a daily basis.  

These errors, according to the author of one article I read, arise from a lack of standardization in spreadsheet formatting and structure, coupled with manual data entry, which is prone to mistakes. 

It might be time for organizations to implement standardization in spreadsheet use, improve training for users, and foster a culture of critical thinking towards spreadsheet creation and maintenance. 

Apparently, Spiderman’s Uncle Ben was right. With great power comes great responsibility.

Sources include: The Conversation

The U.S. government is escalating its measures in the ongoing chip war with China by proposing to restrict foreign entities, particularly Chinese, from using U.S. cloud computing resources for AI model training. 

U.S. Commerce Secretary Gina Raimondo announced this initiative as part of efforts to protect national security and maintain U.S. technological superiority.

This proposal is seen as an extension of existing export controls on high-performance AI processors, requiring U.S. cloud companies to rigorously identify their foreign users. The aim is to prevent entities from countries like China from accessing American cloud resources for developing artificial intelligence. This move is in line with the Biden administration’s broader strategy to ensure U.S. cloud platforms are not used for potentially hostile AI development.

The regulation imposes significant responsibilities on cloud computing firms, mandating them to verify the identity of foreign customers, maintain user identification standards, and certify their compliance annually. However, Chinese entities can still access services deployed in Europe and the Middle East.

The industry’s response to these measures has been mixed, with some criticism regarding the potential impact on international collaboration in AI. Carl Szabo, general counsel at NetChoice, a tech industry trade group, criticized the executive order’s implementation as potentially illegal.

But it doesn’t seem like the U.S. will back down on this strategy to control the use of its technology in AI development, particularly in the context of its competition with China.

Sources include: Tom’s Hardware

OpenAI is testing a new beta feature for ChatGPT, introducing multi-GPT conversations. This feature allows users to interact with multiple GPTs in the same chat window, marking a significant step towards OpenAI’s vision of creating a universal assistant for everyday life. By using the “@” symbol followed by the name of a GPT, users can summon individual GPTs into the chat, enabling a more personalized and comprehensive assistant experience.

Sam Altman, in a recent podcast with Bill Gates, emphasized that customizability and personalization are crucial elements in OpenAI’s development roadmap. This includes tailoring GPT-4 to individual preferences, styles, and data like emails and calendars.

But it also appears to be making it a platform to integrate different GPT based models and make that easy for anybody to do.

Sources include: [THE DECODER](https://the-decoder.com/chatgpts-new-feature-paves-the-way-for-openais-vision-of-a-universal-assistant/?amp=1)

Click here: WebPilot

The tech industry has started 2024 with a significant wave of layoffs, similar to the previous year, despite the booming U.S. economy and the thriving tech sector. 

This has mystified me, and I’m sure others. How can tech companies be doing so badly in this economic climate? 

Microsoft recently announced the layoff of 1,900 workers from its gaming division, following its acquisition of Activision Blizzard. These cuts represent about 8 per cent of the company’s total gaming workforce of 22,000. Google also announced layoffs earlier this month, with some cuts continuing throughout the year. Despite these layoffs, both Google and Microsoft’s stocks hit record highs this week.

A story from Axios explains this saying that layoffs are not a “sign of distress” but a “strategic move” by tech giants like Microsoft and Amazon, who are simultaneously cutting jobs and investing heavily in areas like AI.

Boom and bust isn’t something new in the tech world. But that’s not what’s happening, apparently. These layoffs are strategic, not desperate cost-cutting measures. 

I get it when an industry is struggling – I’m running a media company and everyone in this industry faces the challenge of staying solvent in a world that wants free media, but doesn’t realize that people have to get paid to produce what they read and view.

But for an industry to be thriving and still putting people through this much upheaval – you think by now we’d have found a better way.

Just sayin’

Sources include: Axios 

And on that note, I am putting out an appeal to our audience. Both Howard and I produce two very successful podcasts, we reach thousands of people every day, but I’ll be honest, we struggle to find sponsors. 

Howard’s CyberSecurity Today reaches between 8 and 10,000 people per episode which often puts him in the top 10 tech podcasts in Canada, the US and even the UK. 

My numbers are smaller but thanks to all of you, we’ve grown by almost 50 per cent – thank you and please keep referring us to your friends and given us those great reviews.

And if you know of someone or some company that would like to sponsor two of the most successful tech podcasts, I’d love to hear from you.

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.  

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Marvelous Monday.

 

The post Hashtag Trending Jan.29- LLMs learn to hide dishonest behaviour; Tech layoffs a strategic move? 90 per cent of spreadsheets have errors first appeared on IT World Canada.

Project Sponsor’s Warp Speed Guide: AuthorYogi Shulz is our guest on Hashtag Trending, the Weekend Edition

Welcome to Hashtag Trending, the Weekend Edition.  I’m your host Jim Love.

A number of years ago, a client of mine said to me, “I have no idea what you do, but where you’re here, stuff gets done.” He actually didn’t say stuff, but you might be playing this podcast with your family listening, so let’s stay PG rated.

The point is that not a lot of people know how to get things done. It is an undervalued but important skill in business.

Another example – I taught at the University of Waterloo for a while and I remember a successful CEO came in talked our class about how his company had taken on some big players and won. He’d made tens of millions of dollars.

He got questions like “what was your strategy?” He explained it. It seemed simple. Powerful. The next question was “how did you come up with that?”

His answer surprised us all. He said, “we read a book.” Which leads to an obvious next question. “What book?”

His answer has stuck with me for years. He said, “it didn’t matter.” By the time any book got to be published my a major publisher, it was going to be pretty good.  The difference with us wasn’t the strategy. It’s that we actually DID IT.”

Execution. We disdain it. We somehow think that great ideas are what makes the difference when getting stuff done is much more important.

And I take nothing away from the intelligence or the strategic thinking of my guest this week, but one of the things I most admire about him, is his attention to getting stuff done.

My guest is Yogi Shulz, author of a new book  A Project Sponsor’s Warp Speed Guide.

If you are thinking that the world doesn’t need another book on project management – you might be right. But Yogi has written this book not from the point of view of the project manager. He’s written it for the project sponsor.

He makes the point that so many project managers know all too well –  executives often don’t understand how valuable performing this project sponsor role can be. Nor do they really know what to do. Or as Yogi says in this interview, “we’ve spent a lot of time and money training project managers and next to no time training project sponsors.”

The book itself is an easy read, and it’s set up to read all at once, or to provide quick snippets of “just in time guidance” to a project sponsor.

Join me for my conversation with Yogi Shulz, author of A Project Sponsor’s Warp Speed Guide. You can find his book on Amazon and it may make the appropriate gift for the executive sponsor of your next project, or for anyone listening who is that executive sponsor.

Hashtag Trending goes to air five days a week with a daily tech newscast. And every weekend we have a special in depth interview with a person or on a topic of interest – hopeful both.

We love your comments – suggestions on topics, guests or just in telling us what you like and maybe what you don’t like. You can reach me at jlove@itwc.ca

And if you like what you hear why not recommend us to a friend? You can send a copy at itworldcanada.com/podcasts

If you are an Apple podcast listener, and you like the show, why not give us a review? It all helps to grow our podcast and help us reach more people.

Our  recording engineer is Midori Nagai. Our associate producer is Krystle McLean. And I’m your host,  Jim Love.

Thanks for sharing your weekend with us.

The post Project Sponsor’s Warp Speed Guide: AuthorYogi Shulz is our guest on Hashtag Trending, the Weekend Edition first appeared on IT World Canada.

FTC investigates AI oligopolies; calls on Microsoft, Alphabet, Amazon to disclose investments in startups

Yesterday, following a half day summit hosted by the U.S. Federal Trade Commission (FTC) that convened experts to examine the key players and the litany of consumer protection issues arising from the mushrooming AI market, the agency announced that it is investigating tech goliaths’ investments in artificial intelligence startups.

Microsoft, Amazon, Alphabet, Anthropic, and OpenAI will be the subjects of the inquiry, and will be required to provide information regarding recent investments and partnerships involving generative AI companies and major cloud service providers. They will have 45 days to respond to the agency.

Since the start of the generative AI buzz last year, Amazon and Google have injected a total of US$6 billion in Anthropic, while Microsoft pledged over US$10 billion to OpenAI.

“History shows that new technologies can create new markets and healthy competition. As companies race to develop and monetize AI, we must guard against tactics that foreclose this opportunity, ” said FTC Chair Lina M. Khan. 

During yesterday’s summit, industry experts discussed how the AI tech stack – from the semiconductor level to the cloud to the data – is incredibly concentrated.

Nvidia is making all the AI chips, it’s selling to the hyperscalers, who end up announcing their own chips, making it difficult for new entrants to come into the market, explained Daven Rauchwerk, a technologist who founded a semiconductor startup.

Hyperscalers making their own chips, he added, grants them a form of innovation surveillance, whereby they can look into the memory inside of the chip itself and see what their customers are doing, and figure what needs to be made before it is made.

“Now has never been a better time to be in the semiconductor business. We’re going to have more fabrication capacity in the next five years than we’ve ever had. And there’s enormous demand. And yet the dynamics of the market make it extremely challenging to get off the ground.”

Rauchwerk argued that innovation is happening in real-time at the lowest layers of the stack, but we do not get to see it because of the concentration of the dominant players.

“It’s to the point where the hyperscaler becomes the customer for the chip startup, and you talk to the chip companies, they say, ‘we can sell to one hyperscaler, one data center is millions of units, and it’ll make our whole business.’”

Plus, AI chips are extremely expensive and supply-constrained, and how they get doled out by vendors like Nvidia “has always been something out of a black box” and effectively makes Nvidia the new kingmaker in the entire space, explained Corey Quinn, the chief cloud economist at The Duckbill Group, a company that helps companies manage their Amazon Web Services (AWS) bills.

Hyperscalers also do a lot of bundling and packaging across the board that allows them to net the most chips, he stated. For instance, Nvidia would give Amazon more chips in exchange for a preferred placement on amazon.com for the company’s other retail lines.

“There’s no transparency, and it’s this cross-cutting across so many different units of business that lets them tie things together in strange ways, that we just don’t know what’s happening,” said Quinn.

Even the hyperscalers, he added, are in a centralized, co-dependent system. You can decide, for instance, to build an ecommerce store on Azure so that you do not have to deal with AWS. But if you use financial services like Stripe, which is the strategic payments partner of AWS, then no one can buy from your shop if AWS is down.

Even the U.S. government, he noted, runs a staggering percentage of its compute on the Big Three hyperscalers.

“I’m not suggesting that there’s undue influence of ‘stop investigating us or your computers are going to stop working’”, Quinn said. “I don’t think anyone is getting to that point. But there is a sense of how much can really be done when you are critically dependent upon the continued existence and well being of these companies.”

Further, Tania Van den Brande, director of economics at the U.K.’s communications regulator, Ofcom, detailed how the hyperscalers make it difficult for customers to move their data out of their clouds, through things like egress fees. Additionally, they face difficulties re-engineering apps to move them from one cloud to another, or connecting apps hosted on different clouds. 

Quinn affirmed that it’s obvious we have a monopoly, or if not, the next thing to it, because the cloud companies talk in the language of monopolists, touching on ideas of survival and the risk of being out-innovated by a startup in a garage.

That, he says, is implausible unless you give that startup, for instance, $6 billion of funding for all their AI training runs, plus the massive hiring binges and the specialized hardware.

“We face basic questions of power and governance,” said Khan. “Will this be a moment of opening up markets to fair and free competition, unleashing the full potential of emerging technologies, or will a handful of dominant firms concentrate control over these key tools, walking us into a future of their choosing?”

The post FTC investigates AI oligopolies; calls on Microsoft, Alphabet, Amazon to disclose investments in startups first appeared on IT World Canada.

Cyber Security Today, Week in Review for the week ending Friday, Jan. 26, 2024

Welcome to Cyber Security Today. This is the Week in Review edition for the week ending Friday, January 26th 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

In a few minutes Terry Cutler, head of Montreal’s Cyology Labs will be here to discuss recent headlines. That includes looking at recommendations from the Network Resilience Coalition on how hardware and software manufacturers can help beef up the security of IT networks, a U.K. report predicting the impact artificial intelligence will have on cyber threats, a Canadian hospital’s response to a ransomware attack and Microsoft’s admission about a hacking incident.

But before we get to the discussion a quick review of other news from the past seven days:

Another tech company has admitted to being hit by a Russian threat actor. Hewlett Packard Enterprise says a group dubbed Midnight Blizzard by some researchers, and Cozy Bear by others, was able to access the company’s cloud-based email system last year. The attack started last May but HPE was notified only in December. The attack on the email system is likely related to the theft of company SharePoint files. This attack has similarities to the Microsoft attack that Terry and I will talk about later.

Cybersecurity researcher Bob Dyachenko, who specializes in finding unsecured databases on the internet, has scored a big one. According to Cybernews, he recently found a cache of 26 billion records with over 3,800 folders. Each folder corresponded to a data breach, with information including login credentials collected from LinkedIn, Twitter, Weibo, Tencent and other platforms. They include previously stolen data that researchers know about as well as privately sold databases. It isn’t known who the cache belongs to.

Separately the staff at Cybernews say they discovered a database late last year with millions of corporate chat messages belonging to an American IT services provider. It isn’t known if threat actors also came across this database.

Hundreds of GitLab instances in the U.S. and thousands of others around the world still haven’t been patched to close a vulnerability. That’s according to a tweet from the Shadowserver Foundation. The patch was released two weeks ago for those running their own instances of GitLab.

More on patching: Jenkins has discovered a critical vulnerability in its automation server. The problem is in a library that allows the parsing of command arguments. An attacker leveraging the hole could read files on the Jenkins controller file system. Install a security update fast.

Finally, hackers are taking advantage of unpatched versions of Apache ActiveMQ servers. That’s according to researchers at Trustwave. Administrators were warned last October to upgrade their servers when the vulnerability was discovered.

(The following transcript covers the first part of the conversation. To hear the full discussion play the podcast)

Howard: We’ll start with the report from the Network Resilience Coalition, a group of hardware and software manufacturers and corporate buyers who want to strengthen the security of the backbone of IT networks — routers, switches, firewalls, gateways. One of the big concerns is that some network administrators aren’t patching vulnerabilities fast enough. In fact some aren’t patching at all because they can’t afford network downtime. So the coalition recommends manufacturers separate security patches from security feature updates. Second, manufacturers should make it clear how long products will be supported so IT departments know when they are end of life. Third manufacturers should build their software better with more security. As for buyers, the coalition says they should give preference to products that are built better and make sure products are using the best security configurations.

What did you think when you read the recommendations? Are they achievable, and if so, how long will it take to have a meaningful impact?

Terry Cutler: Security patches are often delayed because they’re bundled with security updates, which will require more extensive testing. So by separating them network administrators can quickly apply the critical security patches without worrying about the potential instability of other things that are produced — like, for example, new security features. But this is going to require a change in the software development and release strategy from manufacturers. So focusing more on a modular, independent type of update system. But this is to have a real impact on short-term and long-term timelines. Once it’s implemented the benefits will be ‘Hey, we’ll have faster and more focused security updates.’ But at the same time you know manufacturers have to also adjust their development processes and we’re going to need better clarity on product support lifespans. Knowing the end-of-life timeline of a product is going to be critical for IT planning, but it also allows better budgeting and risk management, especially in terms of security vulnerabilities that won’t be patched after a certain date.

Software developers are [also] going to need to improve their security from the ground up. Here’s a real story: We’re actually training folks who are seasoned developers in healthcare who don’t even know what Nmap is. [For those who don’t know, it’s a network scanner for discovering hosts and services] Because of that they don’t know how to find flaws in their own application. So by building software stronger, focus on security is going to be essential in today’s landscape — especially with today’s cyber threats. This is going to include better security coding practices, rigorous testing and of course a commitment to ongoing security assessments.

Going back to your last point about encouraging buyers to prioritize security products in their purchasing decisions, that’s very powerful. But one of the problems is they’re not subject matter experts. So they don’t necessarily know what they’re buying.

Here’s another real situation that we just ran into recently: We went to assess a retail company and one of the things they asked me to do while I was there was to assess what an MSP [managed service provider] was selling them. I look it over and it’s merely a simple upgrade. ‘You’re gonna need a new firewall, here’s some managed switches and new access points,’ [the MSP said]. So I asked them what are you doing for endpoint protection network security and cloud security? They had nothing. The MSP was able to convince management that all they needed to do was buy these upgrades and the customer would be totally safe. So they did. I couldn’t believe they went for it.

Howard: At a press conference accompanying the release of the report an official from Cisco Systems said it may be hard to separate security updates from new features. His worry is that what may happen is two departments with identical equipment from a manufacturer will end up having different networks — one with a new feature, one without and that could screw up patches that are being released by vendors. Is this a ah realistic worry?

Terry: He’s right, because this could lead to product development problems. There could be features that are intertwined with new security updates and now all of that would break. So now the vendor would be developing and managing two separate products that now have to interlink with each other if a client has a basic version or has to upgrade to the new full version. It doesn’t make sense. Think about this for a second: Each new security feature potentially requires testing for compatibility and integration and that’s going to add layers of complexity to the patch management process [of the customer]. If the primary goal is to separate patching from the security updates this will definitely lead to extensive testing and a lot of things are going to break. This can lead to a tradeoff where uniformity and predictability of the network environments could be compromised, impacting the efficiency and effectiveness of IT operations.

We’re going to need to look at a balanced approach where manufacturers will offer the option to separate security patches [from features] but also provide guidance on how to manage these security features in a way that can minimize disruption.

As someone who’s worked for a large software company this is just going to add so much more development complexity it’s going to put a real strain on both the software developers and the IT staff, who will be trying to figure out what broke once an update gets applied.

Howard: Well, there’s there’s pressure on manufacturers to to ship shiny new buttons — ‘Look at what we’ve added to version 8.2.3!!’ — to compete with a competitor who announced a new feature. That can lead to shoddy development. Now, one of the report’s recommendations is that manufacturers adhere to the NIST Secure Software Development Framework is aimed at blunting that, but are vendors going to be able to resist shipping code fast with added features to compete with competitors?

Terry: It really comes down to two things: Innovation and marketing. If you have a really great product but no one’s heard of you it’s not going to work, and if you have a really crappy product and you’re really great at marketing your product reviews are really going to go down. So there needs to be a balance. As you know, when we start shipping products that haven’t been properly tested or coded properly it’s going to lead to really inadequate testing and really bad application development, especially on the security side. But the following Framework manufacturers can at least build more secure software and it’ll help reduce the risk of vulnerabilities that will be exploited.

Howard: And will IT buyers put security ahead of price when they’re buying network equipment?

Terry: I don’t think things are going to change because IT buyers are not subject matter experts. They’re going to require more education. The more we educate and update IT buyers about the potential costs and impacts of security breaches the more I think they’re going to prioritize security in their purchasing decisions. And I think that the reputation of network equipment vendors are also going to matter. They want to know, ‘Are you in the Gartner Magic Quadrant? Are you on television? Are you doing all these things?’ Those external things are going to sway the IT buyers.

The post Cyber Security Today, Week in Review for the week ending Friday, Jan. 26, 2024 first appeared on IT World Canada.

Cyber Security Today, Jan. 26, 2024 – US government employees slammed for backing forbidden videocam purchases, and more

US government employees slammed for backing forbidden videocam purchases, and more

Welcome to Cyber Security Today. It’s Friday, January 26th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



U.S. government technology employees misled a contracting officer with what an investigation called “egregiously flawed” information so 150 Chinese-made video conference cameras could be purchased two years ago. That’s the finding of the Office of the Inspector General in a report released this week sparked by a whistleblower. The employees worked for the General Services Administration, which purchases products and office space for federal employees. The cameras, which have security vulnerabilities, didn’t comply with government rules forbidding the purchase of equipment from China. The employees didn’t tell the contracting officer that compliant cameras from other sources were available. In fact, the GSA CIO agreed with the staff recommendation, even admitting the cameras ran afoul of the spirit of a Presidential executive order forbidding the purchase of Chinese equipment. But, the CIO said, based on what he was told by his staff there were no available comparable products. That wasn’t true. The staff told investigators that employees at the department wanting the gear preferred the non-compliant cameras.

The Inspector General recommends the cameras either be disposed of or returned and that appropriate action be taken against the digital infrastructure staff behind the misleading camera information. The head of the GSA thinks the security vulnerabilities in the remaining cameras in use can be mitigated.

There were a record 3,200 data breaches last year in the U.S. That’s according to the Identity Theft Resource Centre. By comparison there were 1,800 in the year before. Of those 3,200 incidents, the vast majority came from cyber attacks. But there were also 729 system and human errors that exposed data, 242 third-party supply chain attacks, and 53 physical data thefts. Data on 352 million American residents was stolen last year. Thirty-seven million came from a data breach at wireless carrier T-Mobile, and 35 million were from telecom provider Xfinity.

The Akira ransomware gang says it will soon start posting 33GB of data it says was stolen earlier this month from the Toronto Zoo. The zoo says personal information of current, former and retired employees dating back to 1989 was copied. The data included Social Insurance numbers, birthdates, telephone numbers and home addresses. The Zoo’s IT system is separate from the city’s.

A Chinese-aligned threat group has been delivering a backdoor by hijacking update requests from legitimate Chinese software undetected for years. That’s the finding of researchers at ESET. The targets were Chinese and Japanese companies as well as individuals in China, Japan and the U.K. who use applications from Tencent, WSOffice and others. Researchers can’t explain exactly how the software companies’ update mechanisms were compromised. But the report is a reminder to software firms to patch all internet connected devices to prevent them from being compromised, train staff to recognize suspicious email attachments and to regularly monitor their application update servers for compromise.

Finally, a Russian national has been sentenced by a U.S. judge to five years and four months in prison for his role in developing and deploying the Trickbot malware. Vladimir Dunaev [DOON-EV] had been extradited to the U.S. from South Korea in 2021. He pleaded guilty to several charges last November. One of his co-conspirators was sentenced to two years and eight months.

That’s it for now. But later today my Week in Review podcast will be available. Terry Cutler of Cyology Labs will discuss recommendations by the Network Resilience Coalition, a hack at Microsoft and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 26, 2024 – US government employees slammed for backing forbidden videocam purchases, and more first appeared on IT World Canada.

Hashtag Trending Jan.26-AI solves bus driver shortage; Impact of AI on quality of code; Apple’s privacy rules getting bypassed by Facebook, LinkedIn, Twitter and more

AI solves a bus driver shortage, a study is questioning the impact of AI on the quality of code – and researchers discover that your iPhone might be sending out a lot more data on you than anyone thought. 



 

All this and more on the final day of privacy week edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

In the face of nationwide bus driver shortages, school districts are turning to an innovative AI-powered tool for a solution. District 11 in Colorado Springs, serving around 22,000 students, has successfully implemented this technology, developed by child-transportation provider HopSkipDrive, to optimize bus routes and transportation options.

The AI tool, named “Strategic Routing,” analyzes student pickup needs and suggests efficient combinations of traditional buses and HopSkipDrive’s “CareDrivers.” This strategic approach has led to significant improvements for District 11. They’ve managed to reduce their bus routes from over 100 to 55, replacing some underutilized routes with HopSkipDrive rides. This change has not only increased on-time arrival rates from 85 per cent to 99 per cent but also projected savings of $8 million over a decade.

D11 superintendent Michael Gaal highlights the tool’s ability to provide predictive, rather than reactive, solutions. It offers a variety of options, including the use of smaller vehicles for less frequented routes, ensuring a more tailored approach to student transportation needs.

While some parents initially expressed skepticism about HopSkipDrive rides, they have come to appreciate the personalized transportation service. The tool’s flexibility allows for adjustments throughout the school year, ensuring optimal routing based on changing needs.

In the midst of concerns about job losses and hallucinations and all of that, we can easily lose sight of how AI can address worker shortages effectively, providing solutions that complement human efforts rather than replacing them.

Sources include: [Axios](https://www.axios.com/2024/01/25/ai-school-bus-driver-shortage-hopskipdrive)

A story I read today talked about how Google may finally come to market with something that will really challenge ChatGPT. 

Reportedly, in an upcoming release, Chrome will introduce an experimental AI-powered feature aimed at enhancing users’ writing experiences on the web. This includes a “Help me Write” feature, which can be accessed by right-clicking on any text box, prompting Google’s AI to assist in generating initial drafts for various writing tasks.

This integration could significantly reduce the reliance on external platforms like ChatGPT for drafting content, as users often work directly on the web for emails, articles, and presentations. Google CEO Sundar Pichai emphasized the ease these AI features bring to web tasks.

Google is not just focusing on text generation. It’s also advancing in multimodality with the introduction of Lumiere, a text-to-video diffusion model capable of synthesizing videos with realistic and coherent motion. 

The integration of AI and machine learning into Chrome is significant, considering Google’s dominance in online search and the widespread use of Chrome, which currently has 3.22 billion users compared to ChatGPT’s 100 million.

Google’s integration of AI into Chrome, coupled with advancements in multimodal AI capabilities, positions the company as a strong contender in the AI space, potentially challenging platforms like ChatGPT.

Over to you – OpenAI…

Sources include: Analytics India

Recent research by GitClear, a developer analytics company, suggests that the growing popularity of AI assistance in software development is leading to lower code quality. The study, analyzing 150 million changed lines of code from both private corporations and open-source projects, highlights issues like increased code churn (code added and then shortly deleted) and a higher proportion of repeated code.

GitHub’s Copilot, a prominent AI coding tool, boasts over 1 million developers with paid subscriptions. While it has been reported that developers complete tasks 55 per cent faster with Copilot, and 46 per cent of code in enabled files is completed by it, GitClear’s research focuses on the quality rather than the quantity of code. The study observes that AI assistants primarily suggest added code, but rarely advise on updating, moving, or deleting code. This trend leads to concerns about the conciseness and readability of the code.

The research identifies a rise in code churn, now at 7.1 per cent compared to 3.3 per cent in 2020, and a decrease in instances of code being moved, which could indicate less refactoring. The researchers criticize the increased use of copy/pasted code, calling it a major issue for long-term code maintainability.

While the reasons for these trends are speculative, the researchers link them to the growing use of AI coding techniques. They suggest that engineering leaders should monitor these trends and their implications for future product maintenance. The study concludes that AI coding assistants are not likely to replace human developers anytime soon, as current AI is too error-prone and far from being able to securely modify existing code.

This research may reassure developers concerned about being replaced by AI tools, emphasizing the current limitations of AI in coding contexts.

Sources include: The Register

Apple is set to allow alternative app stores on its iPhones in the European Union (EU) starting from March, marking a significant shift from its current policy where iPhone users can only download apps from Apple’s own App Store. This change is a response to the EU’s Digital Markets Act, aiming to regulate large companies and create a fairer market for both established and smaller firms.

The move could potentially enable iPhone users in Europe to access apps like Fortnite, which was withdrawn from the App Store in 2020 due to disagreements over Apple’s policies. However, the changes will not be applicable in the UK since it’s no longer part of the EU, but they have similar legislation being proposed called the UK’s Digital Markets Bill.

Apple has always maintained that its App Store rules are designed to protect users’ security. However, it has faced accusations of creating a monopoly and charging high commissions to developers. The introduction of alternative app stores is expected to address these concerns but comes with a warning from Apple about potential security risks, including increased exposure to malware, fraud, and scams.

Additionally, Apple announced it would open up browser choices for EU users, allowing them to opt out of using Safari from the first use. This development reflects the ongoing efforts to maintain open and competitive markets in the tech industry.

This has the potential to hit Apple’s bottom line and you can bet that Apple will do everything in its power to keep this from spreading to North America.

In its various stores some estimates say that Apple reportedly there are close to 100 billion dollars of purchases on in app purchases, subscriptions and premium apps.  A billion here, a billion there – soon you’re talking real money. 

Sources include: BBC and Statista 

And one more Apple story for today, this one with a theme to end privacy week.

Security researchers at Mysk Inc. have discovered that iPhone apps, including major ones like Facebook, LinkedIn, TikTok, and Twitter, are bypassing Apple’s privacy rules to collect user data through notifications. 

This method allows these apps to gather data even when users close them to prevent background data collection. The data collected, which is not necessary for processing notifications, appears to be used for analytics, advertising, and tracking users across different apps and devices.

The researchers were surprised to find that dismissing a notification could trigger the sending of detailed device information to remote servers. 

This practice is widespread in the iPhone ecosystem, not limited to a few apps. Meta (Facebook’s parent company) and LinkedIn have denied using the data for advertising or other inappropriate purposes, with LinkedIn stating that the data is only used to ensure notifications work properly and is in compliance with Apple’s guidelines.

This issue raises concerns about “fingerprinting,” a technique used to identify users based on various device details, which Apple explicitly forbids. The data collected includes IP addresses, phone memory space, and other details that can be combined to identify a person accurately. 

However, companies like Google, through apps like Gmail and YouTube, only collect data directly related to processing notifications, suggesting that the extensive data collection by other apps might have ulterior motives.

The upcoming changes to the iPhone operating system’s rules might improve the situation by requiring app developers to explain why and how they use certain APIs. However, it’s unclear how Apple will enforce these rules.

This revelation highlights the ongoing challenges in digital privacy and the complexities of managing user data collection in the ever-evolving tech landscape.

Well, that’s one way to end privacy week.

Sources include: Gizmodo

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.  This weekend we’ll be looking at how Vancouver is becoming a hub for the new breed of financial services companies. I hope you’ll catch the show.

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Fabulous Friday!

 

The post Hashtag Trending Jan.26-AI solves bus driver shortage; Impact of AI on quality of code; Apple’s privacy rules getting bypassed by Facebook, LinkedIn, Twitter and more first appeared on IT World Canada.