Category: News

Quebec cybersecurity institute gets $1.3 million grant from Google

Google’s philanthropic arm is giving a $1.3 million grant to a Quebec agency for cybersecurity research.

The company said today the funds from Google.org are going to the Multidisciplinary Institute for Cybersecurity and Cyber Resilience (IMC2) to support research on the growing number of global cyber risks.

IMC2 is a partnership between Polytechnique Montréal, the initiator of the project, the University of Montreal, and HEC Montréal. Google.org says it supports nonprofits and social enterprises “whose work has the potential to produce meaningful change.”

Google Canada will also launch the Google Cybersecurity Certificate, an online course from Grow with Google that prepares learners for entry-level jobs in cybersecurity in less than six months, in French.

Google Canada will work with non-profit partners CyberQuebec, Hackfest, Cybereco, Canada Learning Code, and ComIT to provide scholarships to at-need communities and those in their networks to access the certificate for free.

Graduates from the Google Career Certificates program are connected to an employer consortium of companies including Bell, Shopify, Publicis Groupe and Unilever that consider students for relevant open roles. In Canada, over 19,000 people have graduated from the Google Career Certificate program, the company says.

“The grant from Google.org empowers IMC2 to drive cybersecurity initiatives which are essential for our vision of a cyber-resilient society,” Marc Gervais, the institute’s executive director, said in a statement. “The project focuses on four critical areas: fostering a cyber-aware and cyber-responsible society, implementing a secure platform for our researchers to share and leverage cybersecurity data, addressing the alignment between cyber initiatives and the creation of an environmentally friendly future, and driving economic growth and employment opportunities in Québec and Canada by supporting the entrepreneurial spirit in cybersecurity ventures.”

The post Quebec cybersecurity institute gets $1.3 million grant from Google first appeared on IT World Canada.

Bell and Québecor spar over MVNO access service agreements

Bell has accused Québecor of refusing to enter into necessary mobile virtual network operator (MVNO) access agreements.

This comes a month after Québecor accused Bell, in a Part 1 application to the Canadian Radio-television Telecommunications Commission (CRTC), of undue delays in granting access to its network for the launch of its MVNO service.

The CRTC set out an initial policy in 2021, allowing regional cell phone providers to compete as MVNOs across Canada. Under this policy, large cell phone companies must share their networks with competitors who are able to serve in areas that incumbent carriers do not operate.

The Commission then established a deadline for regional providers to negotiate MVNO access agreements with incumbent carriers. If they cannot come to an agreement, they can ask the CRTC to set the rate through a process known as final offer arbitration (FOA), wherein each company submits its proposed rate.

Québecor and Bell entered into FOA last year and, in October, the CRTC ended up siding with Bell for Québecor’s access to its wireless network,

Right after that, Québecor announced the launch date of Oct. 11 for its MVNO service, which it said Bell did not honour. Consequently, Québecor asked the CRTC to apply the rate retroactively to that date and impose a monetary penalty on Bell for the alleged inappropriate and anti-competitive delays.

Bell, instead contends that Québecor has refused to enter into the MVNO access service agreement that would then establish the start date for the launch of the service.

“Bell has consistently acted expeditiously and in accordance with its tariffs; Québecor is simply asking the Commission to grant it an unjustified windfall payment from Bell,” the company said in a reply to Québecor’s Part 1 application.

The telco added, “Québecor’s true motivation in its application has nothing to do with the launch of its MVNO service to consumers or with the contents of Bell’s proposed MVNO access agreement. It is simply to extract a windfall retroactive payment from Bell (and Telus) for its roaming usage on Bell and Telus’ networks.”

MVNO and roaming are two different services, and granting Québecor’s request would be imposing a roaming rate that was not determined in accordance with the Roaming Tariff or the Roaming Agreement, Bell argued.

Bell also noted that Québecor services had already launched on existing roaming agreements with Bell following the CRTC’s FOA decision in October.

Telus, which also provides MVNO service to regional carriers in its network area via an agreement with Bell, also intervened in the dispute between the two companies, asking the CRTC to deny Québecor’s retroactive rate adjustment request.

“Regardless of the existence of any Bell/Québecor MVNO service agreement, the Commission cannot force Telus to charge rates other than the domestic roaming rates for traffic,” affirmed Telus.

Québecor has until tomorrow to file its reply to Bell’s allegations.

The post Bell and Québecor spar over MVNO access service agreements first appeared on IT World Canada.

Data Privacy Week: Are you meeting the fundamentals?

Data Privacy Week is a period when organizations should reflect on whether they are at least doing the basics, says British Columbia’s privacy czar.

“The basic fundamentals” are what privacy pros need to be pondering this week, Michael McEvoy, B.C’s information and privacy commissioner, said in an interview. “Which,” he added, “you have to be thinking about all the time.

“When you are putting together a new product, or considering a new marketing tool, or anything of that kind, you need to be thinking about the personal information you’ll be collecting about patients, clients, customers, and how you’re going to protect it, how you’re going to use it and how you’re going to be transparent to your customers.

“People are far more aware of these issues than they were 10 years ago. They are far more sensitive about how their personal information can be used, and misused. And if you misuse it, you’re quickly going to lose the trust of those customers, clients and patients. So you have to think about these issues — and you have to think about them at the outset [of a project], not as an afterthought.”

This is a time when many innovative companies are pushing new technologies to corporate buyers, he said, such as facial recognition and artificial intelligence applications. But before organizations jump into new technologies, they have to ask whether they will serve their clients well and build trust with customers.

As an example, he cited a case his office handled of “a large retailer” in B.C. that used a facial recognition application to reduce shoplifting. It collected images of everyone who walked into stores and compared them to images of known shoplifters. As soon as management learned the privacy commissioner was investigating in November 2021, they pulled the systems and wiped the servers.

“Had they thought about some of these issues at the beginning, I don’t think they would have gone down that path,” McEvoy said.

He didn’t name the company, but it was a reference to four independently owned Canadian Tire affiliate stores. Last year McEvoy ruled the stores didn’t adequately notify customers and did not obtain consent for the collection of personal information using facial recognition technology.

Asked if companies just don’t think about some things they do, or deliberately want to test the limits of privacy law, he replied “My experience as commissioner is for the most part organizations want to do the right thing. And sometimes they will come to us, not sure if they are doing the right thing.” His office can’t give legal advice but does give guidance.

The best privacy action any organization can take is to create a privacy management program, he said. That doesn’t apply to just large firms, he added, because even small companies can collect a lot of personal information.

Related content: How to create a privacy management program

A privacy management program sets up a data privacy governance structure with processes employees have to follow — and includes measures to ensure they are being followed.

Senior management must actively champion the privacy program, according to guidance from three of the country’s privacy commissioners: “When senior management is committed to ensuring that the organization is compliant with privacy legislation, the program will have a better chance of success, and a culture of privacy will more likely be established.”

A data management program starts with the firm doing an inventory of all of the personal information it holds and categorizing it by sensitivity. When McEvoy’s office gets data breach reports, the first question asked is what information was breached. “You’d be surprised at the number of organizations that don’t have a good handle on exactly what they have,” he said.

A data inventory should lead to the creation of a data access policy, which restricts access to sensitive data to only those who need it.

Management also needs to decide why it is collecting, using, and disclosing data.

Then it has to develop internal policies to respect the principles in private-sector privacy legislation that the firm has to follow in each jurisdiction. That includes a policy on following data breach notification requirements to customers and/or a regulator.

Firms should conduct a privacy risk assessment of their data handling processes at least once a year.

Most of the incidents his office investigates could have been avoided, McEvoy said, had data been properly secured.

“That’s a hard lesson lots of organizations learn after the fact,” he said. Sometimes they didn’t want to spend the money. “But what is often not thought about is cost on the other side: what happens when things go wrong? What is the cost of that?”

Usually it’s far more worthwhile to spend on protecting data upfront than to pay for the costs of cleaning up after a privacy incident, he said. “Most cases are far more costly than any protection system you would have put in place”

The post Data Privacy Week: Are you meeting the fundamentals? first appeared on IT World Canada.

More work needed to blunt public’s AI privacy concerns: Report

Organizations aren’t making much progress in convincing the public their data is being used responsibly in artificial intelligence applications, a new survey suggests.

The report, Cisco Systems’ seventh annual data privacy benchmark study, was released Thursday in conjunction with Data Privacy Week.

It includes responses from 2,600 security and privacy professionals in Australia, Brazil, China, France, Germany, India, Italy, Japan, Mexico, Spain, United Kingdom, and the United States. The survey was conducted in the summer of 2023.

Among the findings, 91 per cent of respondents agreed they need to do more to reassure customers that their data was being used only for intended and legitimate purposes in AI.

“This is similar to last year’s levels,” Cisco said in a news release accompanying the report, “suggesting not much process has been achieved.”

Most respondents said their organizations were limiting the use of generative AI (GenAI) over data privacy and security issues. Twenty-seven per cent said their firm had banned its use, at least temporarily.

Customers increasingly want to buy from organizations they can trust with their data, the report says, with 94 percent of respondents agreeing their customers would not buy from them if they did not adequately protect customer data.

Many of the survey responses show organizations recognize privacy is a critical enabler of customer trust. Eighty per cent of respondents said their organizations were getting significant benefits in loyalty and trust from their privacy investment. That’s up from 75 per cent in the 2022 survey and 71 per cent from the 2021 survey.

Nearly all (98 per cent) of this year’s respondents said they report one or more privacy metrics to the board, and over half are reporting three or more. Many of the top privacy metrics tie very closely to issues of customer trust, says the report, including audit results (44 per cent), data breaches (43 per cent), data subject requests (31 per cent), and incident response (29 per cent).

However, only 17 per cent said they report progress to their boards on meeting an industry-standard privacy maturity model, and only 27 per cent report any privacy gaps that were found.

Respondents in this year’s report estimated the financial benefits of privacy remain higher than when Cisco started tracking them four years ago, but with a notable difference. On average, they estimated benefits in 2023 of US$2.9 million. This is lower than last year’s peak of US$3.4 million, with similar reductions in large and small organizations.

“The causes of this are unclear,” says the report, “since most of the other financial-oriented metrics, such as respondents saying privacy benefits exceed costs, respondents getting significant financial benefits from privacy investment, and ROI (return on investment) calculations, all point to more positive economics. We will continue to track
this in future research to identify if this is an aberration or a longer-term trend.”

One challenge facing organizations when it comes to building trust with data is that their
priorities may differ somewhat from those of their customers, says the report. Consumers surveyed said their top privacy priorities are getting clear information on exactly how their data is being used (37 per cent), and not having their data sold for marketing purposes (24 per cent). Privacy pros said their top priorities are complying with privacy laws (25 per cent) and avoiding data breaches (23 per cent).

“While these are all important objectives [for firms], it does suggest additional attention on transparency would be helpful to customers — especially with AI applications where it may be difficult to understand how the AI algorithms make their decisions,” says the report.

The report recommends organizations:

— be more transparent in how they apply, manage, and use personal data, because this will go a long way towards building and maintaining customer trust;
— establish protections, such as AI ethics management programs, involving humans in the
process, and work to remove any biases in the algorithms, when using AI for automated
decision-making involving customer data;
— apply appropriate control mechanisms and educate employees on the risks associated with generative AI applications;
— continue investing in privacy to realize the significant business and economic benefits.

The post More work needed to blunt public’s AI privacy concerns: Report first appeared on IT World Canada.

Why Canadian provinces, territories need to regulate AI

The use of artificial intelligence in Canada’s federal, provincial, territorial and municipal governments has to be regulated as much as its use in the private sector, a conference on AI in the public sector has been told.

However, Stephen Troupe, CEO of the Canadian Institute for Advanced Research (CIFAR), also warned that regulation here can’t be done in isolation from what other countries are doing.

“I am not convinced national level regulation will be enough, or even provincial regulation. And yet I think it’s going to be almost impossible to get global regulation,” he told the conference organized by Ontario’s Information and Privacy Commissioner on Wednesday.

CEOs of major companies are flying around the world calling for a “global compact around AI,” Troupe said, but that “is a cynical exercise, because it’s not likely to happen.”

Ontario AI panel. From the left Teressa Scassa, Colin Mckay, Chris Parsons, Stephen Troupe, Melissa Kittmer, moderator Mike Maddock and Ontario information and privacy commissioner Patricia Kosseim. Panel participant Jeni Tennison appeared by videoconference.

Instead he called for “regulatory coalitions” with other jurisdictions like the European Union to make our regulatory frameworks as compatible as possible with theirs “so we don’t have a regulatory reach for the bottom.”

At the same time, our public and private sector AI frameworks should be flexible so innovation isn’t stifled and creates barriers to Canada’s AI successes.

“That’s easier said than done,” he admitted, “It will be very complicated. But we will lose public trust [in the public and private sector use of AI] if we don’t do enough, and lose the potential for creativity and opportunity for Canada and Ontario if we don’t do it the right way.”

The conference was part of the Ontario privacy commissioner’s education efforts during Data Privacy Week.

The conference opened with Ontario Information and Privacy Commissioner Patricia Kosseim repeating her call for the province to have an AI framework with binding rules governing the use of AI in the public sector.

Melissa Kittmer, assistant deputy minister in Ontario’s Ministry of Public and Business Service Delivery, said the government has been working on a Trustworthy AI Framework since 2021.

It has three priorities: “AI that people can trust” (making clear the risks of using AI, putting in mitigation strategies to minimize harm to people); “AI that is responsible” (have mechanisms allowing residents to challenge decisions informed by AI); and “No AI in secret” (ensuring there is transparency and disclosure when AI has been used to inform government decisions).

The goal of the framework is to enable the responsible use of AI by civil servants, she said. It will include policies, products, guidance, and tools to ensure the provincial government is transparent, accountable and responsible in its use of AI.

She didn’t say when the framework will be released.

Meanwhile, she said, Ontario is already using AI for extracting large amounts of data, in chatbots and virtual assistants, and for predictive soil mapping.

There are several initiatives across the country to legislate and regulate AI. Parliament is in the middle of debating a proposed Artificial Intelligence and Data Act (AIDA). But it only covers federally regulated businesses, as well as firms in provinces and territories that don’t have their own AI legislation. As for the federal civil service, Ottawa issued a directive on the use of AI in 2019. A guide for the federal use of generative AI was issued last year.

Last month, the European Union Council and members of Parliament reached a provisional agreement over a proposed Artificial Intelligence Act covering both the private and public sectors of the 27 member nations. Supporters hope it will be passed before Parliament adjourns for this summer’s elections.

In her opening remarks, Kosseim said AI “ushers in tremendous opportunities, with real world impacts unfolding in real time” that could affect everything from jobs to people’s health.

She said governments could use AI to draft plain language summaries of reports to help political decision-makers, cut delays to residents trying to access government benefits and services, enhance healthcare diagnosis through AI assistants, interpret medical images to find things the human eye might miss, predict the length of hospital stays, and help screen job applicants. Currently AI is being used to translate for people accessing emergency 911 who don’t speak English, she said.

However, she added, around the world there are examples of AI algorithms failing to return accurate results or perpetuating bias and discrimination against historically marginalized groups. One example: An algorithm used by a hospital to predict which patients will require extensive medical care was “heavily skewed in favour of white patients over black patients.” In another case, an algorithm used to accelerate job recruitment turned out to be biased against women.

“These and other examples speak to the importance of ridding bias in data sources used to train algorithms in the first place, as well as the need for human supervision over the returning results,” Kosseim said.

Troupe, who also oversees CIFAR’s Pan-Canadian AI Strategy, spoke of a Canadian Black computer scientist working on a facial recognition system for the art world who realized the system — which was already in use around the world — didn’t recognize her face, and by extension the faces of Black women. “That tells you the teams creating these systems were utterly unrepresentative,” he said. “To help generate widespread public confidence [in AI] we have to address that [system] creation.”

Big companies know about AI’s challenges, said Chris Parsons, manager of technology policy and strategic initiatives at the Ontario privacy commissioner’s office. Many have built safety checks, but there still can be bias in the underlying data they use. Many less regulated systems, he added, are “the wild west” that do things like generating child porn.

Organizations waiting for federal or provincial law on the use of generative AI should in the meantime turn to guidance issued by the country’s privacy commissioners, he said.

There are other reasons why provinces and territories need their own AI laws. Teressa Scassa, Canada Research Chair in Information Law and Policy at the University of Ottawa, reminded the conference that provinces — not the federal government — have authority over broader public sector institutions like hospitals and local police departments.

There are other issues AI raises, Scassa added, that involve non-personal information but that may have an effect on people’s lives. For example, she said, a data marketing company called Environics Analytics has a demonstration website of how publicly-available data it collects can categorize a postal zone for its customers. One north Toronto (North York) zone was described as “white collar,” with older families and empty nesters and an average income of $173,000. Data like this puts people into ‘ad hoc groups,’ she said, that could affect the delivery of services. How, she asked, is that addressed in privacy and human rights legislation?

“We need to have an eye on the broad impact [of the use of technology], not just individual privacy,” agreed Jeni Tennison, executive director of Connected by Data, which advocates for open data governance. What are needed are “group rights” so people can “match the power of big AI companies or governments when they deploy AI.”

The post Why Canadian provinces, territories need to regulate AI first appeared on IT World Canada.

Booming data analytics and AI exacerbating tech talent shortage: Survey

Nearly 77 per cent of data professionals in Canada believe that the shortage of tech talent will continue throughout 2024, a new survey by Toronto-based IT consultancy firm Adastra found.

This is mainly because of the accelerated adoption of data analytics and AI.

Two specific areas are impacted by the widening talent gap, the survey revealed: frontline workers with the capacity to work with new analytic tools, strategies and programs, and senior data analysts/data scientists who can coordinate these activities and continue to discover business insights.

“We have certainly observed a spike in data analytics activity across all verticals, leading to a growing backlog of both talent and project demand within IT departments”, said Rahim Hajee, North American chief executive officer, Adastra, in a release. “Along with the shortage of qualified talent, the challenge in many companies is converting legacy mindsets and synergizing processes. 

This, he added, is a process of  “citizen enablement through re-training, allowing more members of an organization to participate through a no-code or low-code software environment.”

The survey, in fact, revealed that 90 per cent of respondents believe data optimization allows employers to redeploy staff to more meaningful and productive work.

Hajee added that the democratization of data within any organization allows more people to be involved in the day-to-day analytics taking place and helps to reduce the backlog that may exist in one’s IT/analytics department.

Close to 62 per cent of respondents are using, for instance, Retrieval Augmented Generation (RAG), which enables companies to use proprietary information to enhance the customer and employee experience via chatbot.

“Most organizations have realized the importance of data to their functionality and bottom-line successes”, said Dmitry Krass, academic co-director, Master of Management Analytics program at the University of Toronto’s Rotman School of Management. “It is not the number of trained people that is a problem, but rather the skills emphasized by the training. A data scientist without a strong focus on business and business processes cannot deliver value.”

The study shows that 76 per cent of Canadian respondents will be spending more on data analytics this year, notably as the push towards AI skyrockets. 

Accordingly, 87 per cent of respondents consider using data a competitive advantage, and as a result, 45 per cent believe more new jobs will be created in 2024.

Nick Kozlo, research director at Info-Tech Research Group, contended that IT leaders should remember that machines are not replacements for human talent, and conversely, humans should not be treated as machines.

He added, “The automation era demands a delicate balance in the workplace. IT leaders are increasingly required to integrate AI with human teams, balance remote and in-office work models, merge technical and soft skills, and ensure high productivity while maintaining employee wellbeing. Achieving this balance is crucial for both organizational success and team development.”

“As generative AI enters the workplace, organizations must not lose sight of its ultimate impact on the organization’s people and the skills that only people can bring to the workplace,” Info-Tech’s IT Talent Trends Report 2024 report highlighted.

The report also emphasized the need to optimize the new remote environment for human interactivity and collaboration. 

The post Booming data analytics and AI exacerbating tech talent shortage: Survey first appeared on IT World Canada.

Hashtag Trending Jan.25- New tool against vulnerabilities in open source AI models; AI behind doomsday?; 40th birthday of Macintosh

Researchers find huge vulnerabilities in open source AI models, a travel company sees a surge in popularity of the filter than allows you to choose which aircraft to avoid, scientists set the doomsday clock at 90 seconds to midnight naming AI as one of the causes, a professor demonstrates how easy it might be to hack a voting machine and we celebrate the 40th birthday of the Macintosh.



 

All this and more on this nostalgia edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

A recent study by Protect AI researchers uncovered a startling reality. Since August, they found 3,354 models that contained malicious code on Hugging Face, a popular AI model repository. 

Even more concerning, it’s reported that Hugging Face’s security scans failed to flag about a third of these as unsafe.

In response to this type of threat, the company Protect AI has launched a scanning tool designed to safeguard companies against the rising threat of malware in open source AI models.

Open source AI models are growing in popularity if only for the simple reason that few companies can afford the resources to develop and train an AI model from scratch. 

Platforms like Hugging Face are also growing in popularity as a way to share these models. But these repositories may lack comprehensive security measures, leaving the shared models vulnerable to hacker manipulation.

Founded in 2022, Protect AI’s new tool scans AI models for hidden malware before these models find their way into a company’s IT systems. 

Protect AI plans to use Huntr, an AI-focused bug bounty program it acquired, to help identify potential vulnerabilities.

Ian Swanson, CEO and co-founder of Protect AI, puts it plainly: “Companies are freely and blindly downloading these models, but they can contain things that can execute some pretty bad functions to steal data or take over systems.”

Sources include: Axios

Kayak, the online travel agent, has seen a huge increase in the use of a filter that allows travellers to filter by type of aircraft.  After an alarming incident involving an Alaska Airlines flight, where a piece of the fuselage fell off,

Initially launched in 2019, Kayak’s aircraft filter was rarely used. However, following the recent Alaska Airlines incident, usage of the filter spiked, leading to a 15-fold increase. This prompted Kayak to make the filter more prominent and user-friendly on their platform.

The revamped filter now allows users to distinguish between the 737 Max 8 and Max 9 models, particularly significant as the Max 9 has been grounded by the Federal Aviation Administration.

A Kayak spokesperson emphasized the goal of their filters: to empower travelers with information for smart decisions and confident travel. 

With this information being readily available, travelers are now actively avoiding certain aircraft models, a trend typically reserved only for seasoned travelers with specific preferences.

How much impact is this having on carriers? United Airlines, heavily invested in the affected Boeing models, issued a profit warning, indicating the significant financial and operational impacts of these safety concerns on airlines.

And as we are going to air, the Guardian has posted another story, which they attribute to the FAA, that says “a nose wheel fell off a Delta Air Lines Boeing 757 passenger jet and rolled away as the plane lined up for takeoff over the weekend from Atlanta’s international airport. 

Something tells me that filter usage will spike again.

Sources include: The Guardian

In a recent federal trial, a computer science professor from the University of Michigan, demonstrated the potential vulnerabilities of Georgia’s voting system. 

We are all familiar with the conspiracy theories that have been floating around that claim that there was massive fraud in the U.S. election.  None of these claims have ever been proven, in fact, in audits and court cases, they have been disproven.

But it doesn’t mean that the machines are not vulnerable. 

So in the courtroom, the professor, Alex Halderman, showed how easily a voting machine could be tampered with using simple tools like a pen, a fake voter card, or a USB device. His demonstration included altering the results of a hypothetical referendum and flipping the winner in a theoretical election.

This trial, presided over by U.S. District Judge Amy Totenberg, is trying to assess whether Georgia’s voting system is susceptible to manipulation or programming errors. Halderman’s testimony highlighted the ease of tampering with the machines, raising concerns about the security of the system.

Election officials, however, maintain that Georgia’s elections have never been hacked and that security measures in place effectively prevent interference. They argue that the vulnerabilities demonstrated are speculative and not indicative of real-world risks.

The trial also delves into the January 2021 breach in Coffee County, where election software was copied and distributed, raising questions about the overall security of the voting system. The plaintiffs, including Georgia voters and activists, are urging Judge Totenberg to prohibit the use of these touchscreens in the upcoming 2024 elections, advocating for hand-filled paper ballots instead.

The case, which includes testimonies from both sides, will be decided by Judge Totenberg, with the outcome potentially impacting the future of voting systems in Georgia and perhaps throughout the U.S. 

Sources include: AJC 

The Doomsday Clock, a symbol representing the likelihood of a man-made global catastrophe, remains set at 90 seconds to midnight, indicating a continued high risk of global peril. 

This year, artificial intelligence (AI) has been highlighted as one of the major threats contributing to this dire prediction. 

The Doomsday Clock was created by the scientists involved in the Manhattan Project, the U.S. group that developed the first atomic bomb as we saw in the movie Oppenheimer. 

It was first unveiled on the cover of a 1947 magazine called the Bulletin of Atomic Scientists and was initially set at seven minutes to midnight. It has moved 25 times in the past 77 years, mostly due to the potential of nuclear war. In recent years it has been set to 90 seconds to midnight but this time, not only because of global conflicts the potential for atomic war.

The Bulletin of Atomic Scientists, responsible for the Clock emphasized the risks posed by AI, including misinformation, military use, and its potential to exacerbate other threats.

The scientists were careful to point out AI’s dual nature. It poses significant risks, but it also offers great potential benefits if well managed. 

Rachel Bronson, President of the Bulletin, stressed the urgent need for global action as illustrated by the 90 seconds to midnight setting.  Bill Nye, who most of us remember as the “science guy” also participated in the announcement, maybe with the hope that the guy who taught our kids about science can teach us another lesson – for the good of humanity.

Sources include: Tom’s Guide

And yesterday was, I am told, the 40th birthday of Apple’s Macintosh computer. Amazingly, some of us were around when these amazing devices first made their way into our lives. 

Where we were all typing into a command line, the Macintosh had a graphical user interface and a mouse. All we could say was – wow!

Here’s a quote from Steve Jobs in Apple’s press release:

Macintosh easily fits on a desk, both in terms of its style of operation and its physical design. It takes up about the same amount of desk space as a piece of paper. With Macintosh, the computer is an aid to spontaneity and originality, not an obstacle. It allows ideas and relationships to be viewed in new ways. Macintosh enhances not just productivity, but also creativity.

Even back then, Jobs was selling an idea – never a product.

They were beautiful devices, but they never really took off in business. One reason? The pricing for the original Macintosh was far too high – about $2,500 USD, about $7,000 in today’s dollars. But it had to cost a lot. It had a whopping 8 MHZ processor, 128 kilobytes, yes, that’s kilobytes, not megabytes of RAM and 400 KB floppy drive for storage. 

But the Macintosh wouldn’t go away. It found a niche with graphic artists and those who needed its capabilities. 

It wasn’t til Jobs came back for a second run at running Apple that he really got to see his vision of “Think Different” working in the marketplace. 

Happy birthday old friend.

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition. 

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Thrilling Thursday.

 

The post Hashtag Trending Jan.25- New tool against vulnerabilities in open source AI models; AI behind doomsday?; 40th birthday of Macintosh first appeared on IT World Canada.

Global ransomware threat surely will rise with AI, U.K.’s NCSC warns

Artificial intelligence (AI) is expected to increase the global ransomware threat over the next two years, U.K. cyber chiefs have warned in a new report published today by the National Cyber Security Centre (NCSC).

The report, entitled The near-term impact of AI on the cyber threat, concludes that AI is already being used in malicious cyber activity and will almost certainly increase the volume and impact of cyber attacks – including ransomware – in the near term.

The NCSC is part of the Government Communications Headquarters (GCHQ), an intelligence security organization that focuses on identifying, analyzing and disrupting cyber threats in the U.K..

Among other conclusions, the report suggests that by “lowering the barrier of entry to novice cyber criminals, hackers-for-hire and hacktivists, AI enables relatively unskilled threat actors to carry out more effective access and information-gathering operations. This enhanced access, combined with the improved targeting of victims afforded by AI, will contribute to the global ransomware threat in the next two years.

“Ransomware continues to be the most acute cyber threat facing U.K. organizations and businesses, with cyber criminals adapting their business models to gain efficiencies and maximize profits.”

Commenting on the findings, NCSC chief executive officer (CEO) Lindy Cameron said, “we must ensure that we both harness AI technology for its vast potential and manage its risks – including its implications on the cyber threat. The emergent use of AI in cyber attacks is evolutionary not revolutionary, meaning that it enhances existing threats like ransomware but does not transform the risk landscape in the near term.

“As the NCSC does all it can to ensure AI systems are secure-by-design, we urge organizations and individuals to follow our ransomware and cyber security hygiene advice to strengthen their defences and boost their resilience to cyber attacks.”

A release from the organization notes that The Bletchley Declaration, which was agreed on at the U.K.-hosted AI Safety Summit at Bletchley Park in November, also announced a first-of-its-kind global effort to manage the risks of frontier AI and ensure its safe and responsible development.

It goes on to say that analysis from the U.K.’s National Crime Agency (NCA) suggests that “cyber criminals have already started to develop criminal Generative AI (GenAI) and to offer ‘GenAI-as-a-service’, making improved capability available to anyone willing to pay. Yet, as the NCSC’s new report makes clear, the effectiveness of GenAI models will be constrained by both the quantity and quality of data on which they are trained.”

According to the NCA, “it is unlikely that in 2024 another method of cybercrime will replace ransomware due to the financial rewards and its established business model.”

James Babbage, director general for threats at the agency, said, “ransomware continues to be a national security threat. As this report shows, the threat is likely to increase in the coming years due to advancements in AI and the exploitation of this technology by cyber criminals.

“AI services lower barriers to entry, increasing the number of cyber criminals, and will boost their capability by improving the scale, speed and effectiveness of existing attack methods. Fraud and child sexual abuse are also particularly likely to be affected.”

Meanwhile, authors of the NCSC report note that “while it is essential to focus on the risks posed by AI, we must also seize the substantial opportunities it presents to cyber defenders. For example, AI can improve the detection and triage of cyber attacks and identify malicious emails and phishing campaigns, ultimately making them easier to counteract.”

The post Global ransomware threat surely will rise with AI, U.K.’s NCSC warns first appeared on IT World Canada.

Cyber Security Today, Jan. 24, 2024 – The latest ransomware news and a controversy over alleged viruses in HP printer cartridges

The latest ransomware news and a controversy over alleged viruses in HP printer cartridges.

Welcome to Cyber Security Today. It’s Wednesday, January 24th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

There’s a lot of ransomware-related news today:

A company that provides water management services to 550 U.S. and Canadian municipalities was hit ransomware last week. Veolia North America says some of its software applications and IT systems were affected. Some customers faced delays in paying bills online because back-end systems were taken offline until they could be restored. However, the company says personal data of an unstated number of persons may also have been stolen.

Australia, the U.S. and the United Kingdom have sanctioned a Russian hacker they say is responsible for the 2022 ransomware attack against a major Australian health insurer. Data on 9.7 million current and former users of Medibank’s services was copied and then released on the dark web. Under the Australian sanctions it’s a criminal offence to provide financial assets to or handle assets of Alexander Ermakov. Under the American sanctions all property and interests in the property of Ermakov have to be blocked and reported to Washington.

A Canadian hospital is finally upgrading its digital records system after a ransomware attack last fall. Bluewater Health of Sarnia, Ont., announced this month it is switching to Oracle Cerner for its patient records. Its existing Meditech system was hacked in October. According to the Globe and Mail, the hospital committed 10 years ago to replacing Meditech. The hospital is one of five southwestern Ontario facilities that shares an IT services provider that was hacked. The others already use Oracle Cerner but the ransomware gang could only get into Bluewater Health’s Meditech platform.

Aercap Holdings, an Irish-based aviation leasing company, suffered a ransomware attack last week. In a filing with U.S. Securities and Exchange Commission the company says it now has full control over IT systems. It’s investigating how much if any data was stolen.

On Monday’s podcast I reported a data centre in Sweden had been attacked last week. The company that owns that facility now says this was a ransomware attack by someone deploying the Akira ransomware strain. Agence France Presse quoted a government spokesperson saying IT services of more than 120 government agencies were impacted. So were some retailers.

Palo Alto Networks has issued a background report on the BianLian ransomware gang. Defenders may be interested in the tactics and indicators of compromise listed in the report.

If you had any doubts, ransomware really did hit records last year. According to the year-end numbers compiled by the NCC Group, there were 4,667 ransomware attacks in 2023. Will the trend continue this year?

Splunk has patched several vulnerabilities in the Enterprise version of its network monitoring platform for Windows. One covers a deserialization of untrusted data issue.

HP has stirred controversy over its decision to brick its printers through a firmware update that prevents machines from using third-party ink cartridges. Last week CEO Enrique Lores told CNBC it’s because a virus can be embedded in a chip that cartridges use to communicate with its printers. However, experts interviewed by Ars Technica are skeptical malware could be planted this way. Could the claim have something to do with a proposed class action lawsuit HP might face? Read the article and make your own decision.

Apple has released security updates for all of its operating sytems and its Safari browser. According to the SANS Institute, the updates fix at least 16 security issues — some of which are being actively exploited. There’s also a new feature that — if a user enables it — helps protect against a person who steals an Apple device and then tries to log in with a password or PIN number they’ve seen the owner use.

Finally, although it’s only January scammers have started sending email and text messages impersonating the U.S. tax man. The messages supposedly from the Internal Revenue Service are about a tax refund or tax refund e-statement. The goal is to get victims to click on a link and get them to either download malware or fill out a form and steal personal information. The IRS won’t ask for personal information through an email or text.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 24, 2024 – The latest ransomware news and a controversy over alleged viruses in HP printer cartridges first appeared on IT World Canada.

Hashtag Trending Jan.24- Mother of all breaches leaks 26 billion user records; Gen Z more likely to fall for cyber scams; Humanoid robots make their way to BMW’s auto plants

The mother of all breaches has leaked 26 billion user records, Gen Z are more likely to fall for a phishing or other cyber scam, humanoid robots are making their way to BMW’s auto plants and maybe we haven’t learned much in decades about the risks of using technology in the justice system.



 

All this and more on this “isn’t this privacy week” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

Here is a 90 second summary for the podcast:

A massive data breach called the Mother of All Breaches has exposed an astounding 26 billion user records. Cybersecurity researchers discovered the 12 terabyte leak which contains personal information from past breaches of sites like LinkedIn, Twitter, and Tencent. While some records are likely duplicates, billions appear to be published for the first time. 

The compiled data could allow cyber criminals to launch damaging phishing campaigns, identity theft, and account takeovers. Records include names, passwords, phone numbers, addresses and other sensitive details from thousands of breached databases. Governments were also impacted.

Researchers aren’t sure who’s behind it but suspect a malicious actor given the huge scale. They warn consumers who reuse passwords to change them immediately. Other tips – use strong unique passwords, turn on two-factor authentication, watch for phishing attempts, and check if your information was exposed. With over 26 billion exposed identities, the consumer risk is massive.

If you are in the practice of not having unique complex passwords for each system you log into, with 26 billion records, chances are there is at least one occurrence of your favourite username and password.  

Best practice. Use a different password for each system. Longer is better. Make them difficult to guess. 

Two factor authentication wherever you can. 

Keep up on cybersecurity news by following our sister podcast Cybersecurity Today with Howard Solomon. You can find it on Google, Apple, Spotify – wherever you get your podcasts. Or at ITWorldCanada.com/podcasts.

Sources include: Cybernews.com

Contrary to expectations, Gen Z falls for online scams much more than older generations – 3 times more than baby boomers according to a recent survey by Deloitte. The first “digital native” generation uses the internet extensively across devices and platforms. But familiarity seems to breed complacency rather than caution.  

Gen Z reported higher rates than boomers of phishing scams, identity theft, romance fraud, and cyberbullying in Deloitte’s poll. The convenience of staying permanently logged into apps like Instagram makes security friction unappealing. But experts say reinforcing good habits needn’t limit internet use.

The types of scams target the behaviours of Gen Z whether online shopping, social media use or meeting people virtually. According to Social Catfish’s 2023 report, scam victims under age 20 lost an estimated $210 million last year compared to just $8.2 million in 2017 – as the generation processes life online, more exposure occasions more risk. Still, better design of platforms and privacy controls could reduce vulnerabilities.

Education focused on the incentives perpetuating scams may raise awareness effectively for youth. Rather than a choice between safety and convenience, a customized, empowering approach to online safety serves Gen Z best according to advocates.

Apologies to my Canadian listeners. I think this is one place where the Canadian Zed doesn’t work. 

Sources include: Vox

BMW is bringing in a new type of autoworker – humanoid robots from a company called Figure. These 5 foot 6 machines can walk, pick up objects with dexterous robot hands, and take breaks to recharge. 

It’s the first-time human-shaped robots will join auto manufacturing. While roles are still being defined, the robots’ mobility and flexibility are assets for automation. Industry analysts see it as a harbinger of increasing robotization to counter labour costs.

The deal has an initial phase identifying applications followed by deployment at BMW’s South Carolina plant. Further stages will explore how to integrate AI and other advances. Figure’s CEO says humanoids can handle most tasks people can within a few years.  

When auto manufacturers are asked how they will pay for the recent contract increases for auto workers, they are saying – more efficiency.

Certainly, BMW sees efficiency and productivity benefits from adding these humanoid robots. 

Warehouse robots are also emerging and some complex jobs like car production remain a stretch currently. Still robot capability is advancing. One day roles like equipment repair in risky areas may shift and even though mass replacement of humans is a long way off, these humanoid robots are a big first step.

Sources include: Axios

A false facial recognition match led to a devastating injustice for Harvey Murphy Junior. Macy’s, the U.S. department store’s security system incorrectly identified him as an armed robber – resulting in 10 days in jail.

Not only was he falsely accused, but he was sexually assaulted while being held in detention. 

The potential for these mistakes is known.  The technology’s accuracy depends heavily on image quality and database size. Despite police claims it’s only an investigative lead, this case shows the damage done once someone is identified as a criminal.

It adds to similar incidents where incomplete evidence paired with misplaced confidence in facial recognition tech, led officers to accuse innocent citizens like Murphy. While rare, the instances span race and gender. 

The FTC recently sanctioned RiteAid for enforcement practices stemming from their software’s mismatches. Still popularity grows among retailers like Macy’s seeking theft deterrence through instant screening of in-store cameras. 

Before we blame this all on a new technology, here’s another story that hit the air this week with  a similar theme. 

A software scandal has rocked Britain’s postal service. Bugs in a faulty accounting system helped convict over 900 postal workers of theft from 1999 to 2015. Innocent employees went to jail or paid to cover nonexistent shortfalls. 

The code defects were well known by the builder, Fujitsu, and postal authorities from the start. But this stayed hidden from courts and workers’ lawyers. 

93 verdicts have been overturned so far while victims await compensation. Fujitsu apologized this month for the injustice they enabled. Their executive admitted shameful, appalling concealment of exculpatory evidence from prosecutors. The fiasco fuels outrage at private prosecutions in the UK. Officials promise new laws to swiftly aid the falsely accused. But past harm haunts many victimized by rapid faith in flawed technology.

Police should be looking for corroborating proof before charges are laid, but critics say that everything is stacked against an accused person once they are brought under suspicion. 

And over the last 20 years, we still have issues that should be resolved before we let any algorithm or system be used without heavy scrutiny. 

The faith we seem to have in facial recognition and AI are just another reason to remember the phrase justice should be blind, doesn’t mean it should be blind to the risks of using technology.


Sources include: ArsTechnica and Washington Post

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition. 

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Wonderful Wednesday!

 

The post Hashtag Trending Jan.24- Mother of all breaches leaks 26 billion user records; Gen Z more likely to fall for cyber scams; Humanoid robots make their way to BMW’s auto plants first appeared on IT World Canada.