Category: News

Hashtag Trending Dec.8- Meta’s Purple Llama for cybersecurity; Memory vulnerabilities in C/C++ languages; McDonald’s to integrate AI in its operations

Purple Llama combines the red and blue team for AI. C+ gets an F in security because of memory vulnerabilities. Missing files in Google? Here’s a fix – but don’t ask questions. Apple launches some free machine learning tools and “would you like AI with that?” McDonalds is diving big into AI as fast food is moving into AI.



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Meta has launched “Purple Llama,” a set of cybersecurity benchmarks for large language models (LLMs), aiming to bolster AI safety. This move aligns with the White House’s call for enhanced AI security, as outlined in its AI Executive Order. LLMs, like Meta’s Llama 2, can be exploited for accessing sensitive information or generating harmful content. Purple Llama introduces CyberSec Eval, a benchmark for evaluating LLM cybersecurity, and Llama Guard, a pre-trained model to prevent the generation of risky outputs. Joseph Spisak, Meta’s director of product management for generative AI, emphasizes the need for community collaboration in standardizing these safety measures. Purple Llama, named after a blend of red (attack) and blue (defense) teams, is part of an AI Alliance including major tech players like Microsoft and Google Cloud. Critics, however, have questioned the effectiveness of Meta’s open-source model management in real-world applications.

Sources include: Axios

Meta has announced that all Facebook and Messenger chats will now be automatically encrypted, ensuring that messages and calls can only be read by the sender and recipient. This shift to end-to-end encryption (E2EE) as the default setting has sparked criticism from the UK government and police, who argue it will hinder efforts to detect child sexual abuse on Messenger. Home Secretary James Cleverly expressed disappointment, seeing it as a step back in online child safety. Despite these concerns, Meta insists on the importance of privacy and safety, working with experts to balance these aspects. The company plans to extend default encryption to Instagram messages in the new year. While encryption protects user privacy, it has become a contentious issue, with law enforcement and children’s charities opposing its expansion due to concerns over child safety. Meta, however, is committed to using tools like artificial intelligence to detect malicious behavior without scanning private messages.

Sources include: BBC News Article

The US Cybersecurity and Infrastructure Agency (CISA), along with cybersecurity authorities from the Five Eyes nations, is urging business and technical leaders to prioritize memory safety in software development. In a paper titled “The Case for Memory Safety Roadmaps,” CISA highlights the significant damage caused by memory safety errors like buffer overflows and type confusion.

These vulnerabilities can lead to system takeovers and data theft. The agency’s guidance, part of its Secure By Design recommendations, calls for a shift towards memory safe languages (MSLs) and the creation of roadmaps to eliminate these vulnerabilities in products. This initiative follows a year of criticism of C/C++ languages, known for memory safety bugs, and praise for memory safe languages like Rust. Microsoft, acknowledging that about 70 per cent of its bugs are memory safety vulnerabilities, has committed $10 million to Rust tooling development. CISA advises developers to transition to memory safe languages like C#, Go, Java, Python, Rust, and Swift to reduce these vulnerabilities.

Sources include: The Register

Google has addressed a recent issue with missing files in Google Drive for desktop users on Windows and macOS. The solution involves installing the latest version of the Drive for desktop app (version 85.0.13.0 or newer) and following a simple recovery process.

Users are instructed to open the app, access the settings while holding the Shift key, and select “Recover from backups.” This process will recover files and folders into a new folder named “Google Drive Recovery” on the desktop, separate from the locally synced Google Drive space. Google encourages users facing any recovery issues to provide feedback through the Drive desktop app with the hashtag #DFD84 and include diagnostic logs.

For those seeking more control over file recovery, Google also provides command line instructions. However, users who have disconnected their account or removed their local Drive cache as a DIY fix are limited to restoring from Windows backups or macOS Time Machine. The issue, which began affecting users in late November, was linked to Google Drive versions 84.0.0.0 to 84.0.4.0 and involved local files not yet synced to Drive. Google’s release notes for version 85 don’t clarify the cause of the problem, and further details are awaited.

Sources include: The Register

The race to deploy 5G networks by major US carriers like Verizon, AT&T, and T-Mobile has reached a pivotal point where the focus shifts from expansion to managing the financial aftermath. Initially, 5G was touted as a revolutionary technology for autonomous vehicles, remote surgery, and augmented reality. However, the actual applications have been more mundane, such as improved streaming capabilities and home internet options.

Verizon, having spent $45.5 billion on new spectrum licenses, is now under investor scrutiny for returns on this massive investment. The company’s approach includes selling private networks for industrial and manufacturing businesses, but progress has been slow due to the complexity of tailoring services to specific industries.

The most successful 5G application so far has been fixed wireless access (FWA), providing an alternative for home broadband. However, this falls short of the transformative benefits initially promised. Network slicing, a feature that prioritizes certain types of network traffic, shows potential but requires a standalone 5G network, which is still under development.

The rapid deployment of 5G has led to significant debt for these companies, prompting them to seek new revenue streams, often resulting in higher costs for consumers. The consolidation of wireless carriers, with T-Mobile’s acquisition of Sprint, has further limited competition in the market. The long-term benefits of 5G may still materialize, but for now, the technology’s impact is more incremental than revolutionary.

Sources include:  The Verge

Apple has quietly released Apple MLX, a new set of open-source machine learning tools optimized for Apple Silicon. Aimed at simplifying AI development, MLX is accessible via platforms like PyPI and GitHub. It’s designed to be efficient and user-friendly, supporting various AI tasks such as language processing and image generation. This move highlights Apple’s strategy to integrate advanced AI capabilities into its products, leveraging its powerful in-house silicon technology. While less publicized than its competitors, and dwarfed by Google’s Gemini, Apple’s MLX launch signals a significant step in its AI innovation journey, catering to both researchers and developers.

Sources include: ITPro Article

McDonald’s is set to collaborate with Google in 2024 to integrate generative AI into its operations. This partnership will involve hardware and software upgrades in thousands of McDonald’s stores, enhancing various systems including ordering kiosks and the mobile app. The goal is to utilize AI for optimizing operations, with a promise of delivering “hotter, fresher food” to customers.

While specific applications of AI in McDonald’s operations are not detailed, the upgrades will run both in-store and through Google Cloud services. These improvements aim to help managers quickly identify and solve operational issues, potentially reducing complexity for store staff and creating new experiences for customers and crew.

This move towards AI-driven automation aligns with trends in the fast-food industry, as seen with Wendy’s AI ordering tests. However, McDonald’s has not explicitly addressed the potential impact on human employment, focusing instead on enhancing operational efficiency and customer experience. The integration of AI in McDonald’s operations is part of a broader shift towards digital transformation in the fast-food sector, with potential implications for service quality and efficiency.

Sources include: The Verge 

And that’s what’s trending today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts

I’m your host Jim Love. Have a Fabulous Friday!

The post Hashtag Trending Dec.8- Meta’s Purple Llama for cybersecurity; Memory vulnerabilities in C/C++ languages; McDonald’s to integrate AI in its operations first appeared on IT World Canada.

Canadian privacy czars release principles for responsible development of AI

On the heels of cybersecurity guidance for generative AI systems issued by the federal government, Canada’s federal, provincial, and territorial privacy regulators have issued their own set of privacy-related principles to be followed.

Announced Thursday, the principles are aimed at advancing the responsible, trustworthy and privacy-protective development and use of generative artificial intelligence (AI) technologies in this country.

While Parliament is debating the proposed Artificial Intelligence and Data Act (AIDA), which would put mandatory rules around high-risk AI systems, the law likely won’t come into effect for several years. Governments and regulators hope in the meantime the guidelines will give application developers, businesses, and government departments some idea of how far they should — or shouldn’t — go.

And though laws regulating AI aren’t on the books yet, the regulators note that organizations developing, providing, or using generative AI have to follow existing privacy laws and regulations in Canada.

Also on Thursday, the government announced that eight more companies have signed on to its voluntary AI Code of Conduct. They include AltaML, which helps firms with AI solutions; BlueDot, which uses AI to track infectious diseases; solutions provider CGI, Kama.ai, which uses AI for building marketing and customer relationship applications; IBM, Protexxa, which offers a SaaS cybersecurity platform; Resemble Ai, which lets organizations create human-like voices for answering queries in call centres; and Scale Ai, which helps firms create AI models. The voluntary code identifies measures that organizations are encouraged to apply to their operations when they are developing and managing advanced generative AI systems.

Federal Privacy Commissioner Philippe Dufresne announced the new principles document today at the beginning of an international Privacy and Generative AI Symposium organized by his office.

The document lays out how key privacy principles apply when developing, providing, or using generative AI models, tools, products and services. These include:

establishing legal authority for collecting and using personal information used in AI systems, and when relying on consent, ensuring that it is valid and meaningful;
being open and transparent about the way information is used by AI systems and the privacy risks involved;
making AI tools explainable to users;
developing safeguards for privacy rights; and
limiting the sharing of personal, sensitive or confidential information.

Developers are also urged to take into consideration the unique impact that these tools could have on vulnerable groups, including children.

The document provides examples of best practices, including implementing “privacy by design” into the development of the tools, and labeling content created by generative AI.

The post Canadian privacy czars release principles for responsible development of AI first appeared on IT World Canada.

Analytics Unleashed keynoter Scheibenreif examines how ‘we shape AI, AI shapes us’

In a presentation at IT World Canada’s Analytics Unleashed on Tuesday, Gartner Distinguished VP analyst Don Scheibenreif discussed what organizations need to do in order to handle the generative artificial intelligence (GenAi) juggernaut and artificial intelligence (AI) in general.

The content he delivered was originally seen by a packed house of upwards of 8,000 chief information officers (CIOs) and other senior IT executives attending an opening day keynote address at the Gartner IT Symposium/Xpo 2023 in Orlando in mid-October.

Scheibenreif and fellow Gartner Distinguished VP Analyst Mary Mesaglio were on stage to discuss the year’s hottest topic – generative AI (GenAI) – and how best to “stay out in front in this new era of human-machine relationships.” The title of their address was The Next Era – We Shape AI, AI Shapes Us.

“The truth is that we are at the beginning of a new era where AI is going to infuse everything that we do,” he told Analytics Unleashed attendees. “The last technology this huge was back in 2007 with the introduction of the iPhone, and before that it was 1993 with the arrival of the worldwide web.

“One of the things that we wanted to communicate in this year’s keynote is to get people to think about their relationship with machines, not just as tools, but how they can affect all parts of our lives, both at work and at home.”

There were, said Scheibenreif, four primary takeaways, starting with the fact the human-machine relationship  is fundamental to understanding AI. “We have to be very mindful about our relationship with machines, because they’re changing. They are moving from not just being our tools to actually becoming our teammates.

“This is part of an evolution that’s been taking place for a long time, and AI is not new, but GenAI and the associated tools have certainly sparked a lot of conversations about the role of machines in our lives. And it’s asking us to think about not what machines can do for us, but what machines can be for us. Machines as teammates, but also machine as a friend, as a consultant, machine as a customer, even.”

At a corporate level, the focus is squarely going to be on senior IT executives, he added, to deliver value, as judged by “our research that tells us about 51 per cent of CEOs expect the CIO or other tech leaders to really help the organization get the most value from investments in generative AI and AI in general. So, CIOs not only have a role, they actually have the role, at least for now.”

The second takeaway revolved around what Gartner defines as Everyday AI and Game Changing AI. The former, says Gartner, is focused on productivity: “The machine is a productivity partner. It enables workers to do what they already do, faster and more efficiently. Currently, 77 per cent of CIOs and technology leaders worldwide are focused on the opportunities of everyday AI.”

In Orlando, Mesaglio warned that “it is important to note that everyday AI will go from dazzling to ordinary with outrageous speed. Everyone will have access to the same tools, and it will not provide a sustainable competitive advantage.”

She described game-changing AI as being focused primarily on creativity. “It doesn’t just make us faster or better. Either it creates new results, via AI-enabled products and services, or it creates new ways to create new results, such as with AI-enabled new core capabilities. With game-changing AI, machines will disrupt business models and entire industries.”

In his address this week, Scheibenreif said the third takeaway revolved around every organization needing to define its own AI ambition and be governed by what Gartner calls Lighthouse principles. “This is very, very important. We’ve seen recently in the news how the lack of governance can impact organizations – i.e. OpenAI. We want to make sure that you as clients, and as organizations that are engaged in AI, can actually follow some of these Lighthouse principles to be able to govern your own use of the technology.

“In reality, most organizations really have to think about their opportunities for AI. How will you use this technology? What won’t you use the technology for? These are all important questions you’ll have to consider when thinking about AI in your organization.”

Lighthouse principles, he said, help “light the way when things are murky or unclear.”

The fourth and final takeaway is this: If your data is not ready for AI, then you are not ready for AI. Gartner analysis recently revealed that 96 per cent of organizations’ data is not ready for AI, and only four per cent is, which is, said Scheibenreif, “a problem, because if your data is not ready, then your ability to tap into some of the of the opportunities that AI offers will be limited.

“What is AI-ready data is one of the main things we talked about in the keynote. It is secure, obviously, it is enriched, it is fair, it is accurate, and it is governed by Lighthouse principles that you will have developed for your organization.

“Now, the other thing about data is that we’ve all been taught to believe that our mountains of data are actually mountains of gold. But in truth, it’s actually fool’s gold. Not all of it matters. We instead are encouraging organizations to focus on making that data essential to your AI ambition, ready for AI. And that includes your algorithms, your formulas, your blueprints, your schematics, and any type of data that’s really proprietary to your organization. That is the real goal – you don’t have to make all of your data ready for AI, just that which serves your AI ambition.”

Gartner, said Scheibenreif, believes that the CIO can be the guide “for the executive team when it comes to AI, and also be part of the team that helps govern its use. We also believe that you have to choose your AI ambition. What do you want to use this technology for? What will it do for you? And what won’t it do for you?”

The post Analytics Unleashed keynoter Scheibenreif examines how ‘we shape AI, AI shapes us’ first appeared on IT World Canada.

Nova Scotia privacy commissioner investigating provincial MOVEit hack

Why were thousands of organizations seemingly defenceless against the zero-day vulnerability in Progress Software’s MOVEit file transfer service, a hole that so far has seen the personal data of tens of millions of people copied by the Clop/Cl0p ransomware gang?

That question may be at least partly answered by an investigation announced today by Nova Scotia Information and Privacy Commissioner Tricia Ralph into the theft of data from the provincial healthcare sector.

The purpose of the investigation is to review the adequacy of the security practices and incident response of the province’s health department, and of IWK Health Centre, a major pediatric hospital and trauma centre in Halifax.

Nova Scotia and the hospital have to comply with regulations under the Privacy Review Officer Act, the Freedom of Information and Protection of Privacy Act and the Personal Health Information Act.

The province uses MOVEit for transferring payroll information. Data of at least 100,000 public servants and hospital staff was stolen, including Social Insurance numbers, addresses and banking information.

Ralph promised a “comprehensive investigation,” the results of which will be publicly released.

This may be the first publicly announced investigation by a privacy commissioner of a MOVEit hack in Canada or the U.S. In October, Progress Software said it is co-operating with several inquiries from U.S. and foreign data privacy regulators, as well as inquiries from several U.S. state attorneys general. The company said in a regulatory filing that the U.S. Securities and Exchange Commission has also started a fact-finding inquiry.

Related content: Sony Playstation division hit by MOVEit hack

Security experts say a zero-day vulnerability in an application is hard to defend against because there are no known patches. However, that doesn’t necessarily mean protections such as firewalls, data encryption, network intrusion and detection, employee awareness training, and other tools can’t blunt an attack — for both the software companies that created the vulnerable applications as well as their customers.

According to an article in last month’s Cyber Defence Magazine by Jack Viljoen, head of Prodinity Cyber Solutions, the attacks were allegedly “driven by poor cyber security practices related to vendor access vetting and monitoring of company systems.” Weak password practices served as another entry point for attackers, he added.

Related content: Data on 3.4 million mothers, children stolen from Ontario registry

The MOVEit Transfer vulnerability (CVE-2023-35708) is a SQL injection exploitation. According to security firm Malwarebytes, it allows an attacker to drop a webshell in the wwwroot folder of the MOVEit install directory. This allows the attacker to obtain a list of all folders, files, and users within MOVEit, download any file within MOVEit, and insert an administrative backdoor. This last is crucial: It gives attackers an active session to allow credential bypass.

File transfer servers can be a golden repository for data if it’s just sitting there before or after being copied. The Clop/Cl0p gang is known for having found vulnerabilities in other file transfer applications such as GoAnywhere MFT and Accellion File Transfer Appliance (FTA). While many of the MOVEit hacks occurred in the last days of May, investigators at Kroll LLC believe the gang was likely experimenting with ways to exploit this particular vulnerability as far back as 2021.

Researchers at Emsisoft have so far identified 2,662 organizations around the world whose data was stolen through MOVEit Transfer, involving the personal information of over 83 million people.

The post Nova Scotia privacy commissioner investigating provincial MOVEit hack first appeared on IT World Canada.

Memorial today for Softimage founder and partner to be broadcast online; two charged in their murder

Police in Dominica have charged two American men, Jonathan Scott Lehrer and Robert Snyder Jr., with the murders of Softimage founder Daniel Langlois and his partner, Dominique Marchand, whose bodies were found in a burned-out car on Friday.

Lehrer and Snyder are alleged to have murdered Langlois and Marchand at Lehrer’s chocolate plantation, Bois Cotlette Estate, sometime between Nov. 29 and Dec. 2. They were remanded into custody pending a preliminary inquiry on Mar. 15, 2024, when the court will determine whether there is sufficient evidence to proceed to trial.

Langlois and Marchand had been reported missing last week, and the remains of two individuals were discovered on Friday in a vehicle which matched the description of their car. The bodies were burned beyond recognition, so police had to rely on circumstantial evidence for identification.

Langlois and Lehrer had been involved in a long-standing legal dispute over the use of Morne Rouge Public Road, which passed through Lehrer’s property on the way to the eco-resort and hotel owned by Langlois and Marchand. Lehrer had obstructed the road to prevent access, prompting Langlois to take legal action. The courts ruled in his favour, and Lehrer was ordered to unblock the road. In 2019, Dominica’s High Court affirmed the ruling that it was a public road.

A memorial ceremony will be held today (Dec. 7) on the island of Dominica for Langlois and Marchand, at 4 pm ET; it will be broadcast live on YouTube and Facebook. More than 15 local organizations will take part.

A release said, “Divers, fishermen, ecologists: all forces of the Dominican society are showing up for the deceased. They will come together at the Soufriere Bay, both offshore and on the jetty. At sunset, Dominicans will paddle out and form a circle ‘a symbol of the community and of the resilience of this exceptional couple,’ explains Simon Walsh, of the REZDM Foundation (Resilient Dominica Project).

“A minute of silence will be observed at 4:34 pm as flowers will be thrown in the middle of the circle at sea and traditional chants will arise, sung a cappella by the Sisserou Singers gathered on the jetty in a candlelight vigil.”

The post Memorial today for Softimage founder and partner to be broadcast online; two charged in their murder first appeared on IT World Canada.

Small Canadian energy producer reports cybersecurity incident

A Calgary oil and gas producer says it has suffered a cybersecurity incident that impacted certain aspects of its business.

Clearview Resources Ltd. made the statement in a news release issued late Wednesday that gave no details of how the attack affected operations.

“Upon learning of the incident, Clearview took steps to secure its systems and mitigate the impact to the company’s data and operations,” the statement said. “Independent cybersecurity experts have been retained to assist the company in dealing with the matter in accordance with industry best practices.

“Clearview is in the process of assessing the impact to the company’s operations. At this time, we are not aware of any evidence that customer, supplier or employee data has been compromised or misused as a result of the situation.”

Clearview is a small player in the oil patch. Its third quarter oil and natural gas sales totaled C$5.7 million, compared to C$9.2 million in the same period in 2022. For the quarter it recorded a net loss of C$1.6 million.

For the nine months ending Sept. 30, oil and gas production was down 21 per cent compared to the same period in 2022, in part due to the disposition of non-core properties at the beginning of the year and production downtime due to wildfires and overland flooding in the second quarter.

Energy companies — producers and distributors — are considered part of any nation’s critical infrastructure. Without energy, a country’s economy stops, which is why the sector is a target for threat actors who hope firms will pay to get back access to stolen data, or control over operations. Nation states are also known to probe energy companies for espionage purposes.

In June, one of the country’s largest energy producers, Suncor, suffered a cyber attack affecting its ability to process credit and debit cards. Earlier this year, Prime Minister Justin Trudeau acknowledged a cyber attack on a Canadian energy firm, although, he said there was no physical damage to any energy infrastructure.

One of the biggest known attacks in North America was the 2021 ransomware attack on Colonial Pipeline in the U.S., which forced the company to shut down the operation of one of the largest gasoline, diesel, and jet fuel pipelines in the U.S.. Flights had to be re-routed, there was panic gasoline buying, and briefly, the price of gas shot up.

According to numbers compiled by Statista, energy firms were the fourth most popular targeted industry in 2022 (10.7 per cent of attacks around the world, behind manufacturing (24.8 per cent), finance and insurance (18.8 per cent) and professional services (14.6 per cent).

Attacks aren’t always direct. In a report released this week, SecurityScorecard said 90 per cent of the world’s leading energy companies reported having experienced a third-party data breach in the past 12 months.

In June, the Canadian Centre for Cyber Security issued a report on cyber threats to Canada’s oil and gas sector. Oil and gas organizations tend to have a broad attack surface of connected digital systems, it notes.

Financially motivated crooks are the main cyber threat against this country’s energy sector, the report says in part. But it is also targeted by state-sponsored threat actors looking for trade secrets, research, and business and production plans.

The post Small Canadian energy producer reports cybersecurity incident first appeared on IT World Canada.

Hashtag Trending Dec.7- Google’s Gemini to outperform OpenAI? AMD takes on Nvidia with new GPU accelerators; Are we closer to understanding Altman’s ouster?

Google announces that its new Gemini AI will outperform its rival OpenAI.  AMD’s new chips are claimed to outperform its rival NVIDIA (at least for now) and we might be closer to understanding why the board of OpenAI fired Sam Altman so he could return and be more powerful than his rivals.

 



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Google has announced its new advanced large language model (LLM) called Gemini, is now powering Google Bard and other AI-enabled products and includes a mobile version for Google’s Pixel 8 Pro. 

Google is also touting several industry-standard benchmarks which it claims shows Gemini outperforms ChatGPT 3.5.

Google unveiled Gemini in three sizes: Ultra, Pro, and Nano. Gemini Pro has been integrated into Bard, enhancing its capabilities in reasoning, planning, and understanding. 

Gemini’s design is multimodal, capable of recognizing and interacting with various formats like video, images, text, and voice. 

Gemini Ultra is currently undergoing additional safety and testing, but Gemini Pro is accessible to developers and enterprise customers through Google AI Studio or Google Cloud Vertex AI. 

Google also plans to introduce Bard Advanced, powered by Gemini Ultra, offering enhanced capabilities.

Gemini AI is also appearing in a mobile version on the Google Pixel 8 Pro. The phone now features Gemini Nano, a version of the AI model tailored for mobile devices. 

In practical terms, it will be used in the Smart Reply in Gboard and the auto summarize feature in the Recorder app. 

But Google is saying this is just the beginning of Gemini’s potential impact on Android devices, and will be a significant shift in how users interact with their smartphones.

Sources include:

ZDNet on Bard’s Upgrade 

Axios on Google’s AI Race

ZDNet on Gemini’s Impact on Pixel 8 Pro 

In the high-octane world of datacenter GPUs, a new champion has emerged: AMD, with its “Antares” Instinct MI300 family of GPUs that has positioned AMD as the performance leader in the datacenter GPU arena, at least for the moment.

AMD’s new GPU accelerators, designed to directly challenge Nvidia in the generative AI market. The demand for these chips has skyrocketed, particularly in the generative AI space, where supply can barely keep up with the voracious demand.

Nvidia, long a dominant player in this field, finds itself in a fortunate position where the overwhelming demand for AI training and heavy inference accelerators outstrips the supply. So even head-to-head competition between AMD and Nvidia is unlikely to lead to price reductions.  

At some point, the AI hardware market may normalize, and bring things back to a more traditional competitive landscape, but that’s not expected in the short term.

As the market evolves, both Nvidia and AMD will continue to push each other and the boundaries of technology. The upcoming Nvidia “Blackwell” datacenter GPUs are expected to reclaim the performance crown, albeit temporarily, as AMD is already working on the next iteration, the MI400.

If you really want to geek out on this, there’s a great and very detailed article in the Next Platform. There’s a link on the show notes at itworldcanada.com/podcasts

Sources include: The Next Platform

Microsoft is extending a lifeline to Windows 10 users and  offering three additional years of security updates beyond the October 14, 2025, end-of-support date. 

This program, similar to what was offered for Windows 7, is aimed at those who need or want to stay on Windows 10. 

But it comes at a cost.

The ESU program will provide monthly security updates and technical support, paid for annually. While pricing details are yet to be announced, it’s expected to follow the pattern of the Windows 7 ESU program, where costs increased each year to encourage upgrading to a newer Windows version. The cost is also per-seat, meaning it varies based on the number of PCs requiring updates.

A notable difference this time is that Microsoft plans to offer Windows 10 ESU updates to individuals, not just businesses and institutions. 

This program will not include any additional features for Windows 10.

For businesses, educational institutions, and governments, the ESU program provides extra time to adapt to new Windows features, educate users, and test for compatibility issues. 

With Windows 11’s new system requirements, not all Windows 10 PCs support the latest version, so staying with Windows 10 can avoid hardware replacement.

For individuals, that decision to stick with an older operating system could be to avoid hardware upgrades or just personal preference. The ESU program could offer a solution for those who prefer Windows 10 over Windows 11, depending on its cost and availability for different Windows editions.

Sources include: Ars Technica 

A recent in-depth piece in The New Yorker by Charles Duhigg, who spent months embedded inside OpenAI, sheds light on the tensions within the board that led to the decision to fire Sam Altman..

The report suggests that some board members found Altman to be manipulative but in particular the story talks about his efforts to have fellow board member Helen Toner removed. 

Toner, the director of strategy and foundational research grants at Georgetown University’s Center for Security and Emerging Technology, co-wrote a paper that criticized OpenAI’s approach to AI safety compared to Anthropic’s more cautious stance. This apparently didn’t sit well with Altman.

Altman’s politicking to have Toner removed was perceived as manipulative by some, while others saw it as a clumsy attempt to address the issue.

The board’s attempt to hold Altman accountable could be seen as a personality conflict gone wild or a much loftier goal of trying to ensure that AI benefits all of humanity – I always say, never look for a complex reason or conspiracy when simple human nature could be the cause.  

But whatever it was, it ultimately backfired, solidifying Altman’s position as a powerful figure in Silicon Valley.

Sources include: Ars Technica 

And that’s what’s trending today.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host Jim Love.  Have a Thrilling Thursday. 

The post Hashtag Trending Dec.7- Google’s Gemini to outperform OpenAI? AMD takes on Nvidia with new GPU accelerators; Are we closer to understanding Altman’s ouster? first appeared on IT World Canada.

MPs to investigate allegations “spyware” used against federal employees

A parliamentary committee voted unanimously on Wednesday to investigate allegations that the government has used what some call “spyware” against federal employees.

The House of Commons ethics and privacy committee voted to hear the heads of several federal departments and Treasury Board head Anita Anand next month on the use of digital data recovery and investigative tools, as well as whether departments followed rules for doing a privacy impact review before implementing them.

Treasury Board is responsible for setting policies and procedures all government departments and employees have to follow.

The allegations stem from a November 30th report by Radio-Canada that “spyware normally associated with the intelligence world is being used by 13 federal departments and agencies.”

None of the departments did application privacy impact assessments on the tools as required by government policy, the news story says.

MP Mona Fortier, former Treasury Board president, who sits on the committee, said the government “is not here to spy on people and departments.”

“I know there are protocols and what I find concerning is that departments didn’t follow protocols” for doing application privacy assessments. Another Liberal MP denied the government uses “spyware.” But it does have digital tools for investigating allegations against government employees for fraud and other wrongdoing, she said.

Radio-Canada said the tools come from Cellebrite, an Israeli maker of tools for getting into mobile devices, and Waterloo, Ont.-based Magnet Forensics, which makes digital investigation solutions for governments and law enforcement agencies.

While several federal departments obtained some of the tools, Radio-Canada says it was told they are no longer used.

Speaking at the committee meeting in support of a study, Calgary Conservative MP Stephanie Kusie said she found the allegation the government could have captured texts, internet search histories, photos and more of federal public servants “very concerning.”

It amounts to a “normalization of surveillance,” she said. “It is terrifying.”

Kusie said she received no response when she asked Anand in writing to confirm the departments haven’t done privacy impact statements on the applications.

Liberals on the committee agreed to call witnesses on the allegations. But Hamilton MP Lisa Hepfner, parliamentary secretary to the Minister for Women and Gender Equality and Youth, denied the government uses “spyware” and urged opposition members to watch their “rhetoric.”

She described the applications as “specialized software for digital forensics” used for cyber incident response, and in internal investigations of civil servants when, for example, there is suspicion of fraud or workplace harassment.

“And it’s always done in accordance with internal protocols that govern the collection and storage of personal information to ensure its protection,” she said.

“I agree it’s concerning departments are not following the [policy for doing] privacy impact assessments. It’s a really important process and departments should be following that. Maybe the directive needs to be strengthened.”

But, she added, “spyware is not something that the Government of Canada uses. Spyware is illegal.” Nor, she said, does the government use malware or malicious code against employees.

The study will start Jan. 29, 2024. Also to be called as witnesses are Jennifer Carr, president of the Professional Institute of the Public Service of Canada, which represents more than 70,000 federal employees, and Chris Alyward, national president of the Public Service Alliance of Canada, which represents 230,000 federal staff.

The post MPs to investigate allegations “spyware” used against federal employees first appeared on IT World Canada.

Generative AI increasingly used for threats to Canadian democracy: Report

Generative AI systems are increasingly being used by threat actors to influence elections around the world, including in Canada, says the latest report by Canada’s electronic spy agency on threats to this country’s democratic process.

“We assess that AI synthetic content generation related to national elections will almost certainly increase in the next two years, as this technology becomes more widely available.” says the biannual report of the Communications Security Establishment (CSE).

“As synthetic content generation increases and becomes more widespread, it will almost certainly become more difficult to detect, making it harder for Canadians to trust online information about politicians or elections.”

Cyber threat activity targeting democratic processes are likely viewed by adversaries as “an obscure and risk-averse way of impacting Canada’s policy outcomes,” the report says.

The report comes just over a month before the start of a national public inquiry into foreign interference in Canadian elections and democratic institutions. The Foreign Interference Commission’s website is here.

Related content: Federal budget includes millions for fighting foreign interference

Since the 2021 version of the report, the CSE says there has been an increase in the amount of synthetic content — such as deepfake images, videos and news — relating to elections.

This is almost certainly because of the increased accessibility of technologies to create synthetic content.

“On the other hand, the use of synthetic content for disinformation about elections remains relatively low,” the report adds.

Disinformation about the next Canadian federal election will almost certainly be found online, the report says, and foreign adversaries will likely use generative AI to target Canada’s federal election in the next two years.

“Cyber incidents are also more likely to happen in Canada’s next federal election than they have been in the past,” the report adds.

Related content: Parliamentary hearing continues into foreign use of social media

The CSE, part of the Defence Department, has the responsibility for protecting federal IT networks, including intercepting and breaking foreign codes and creating secure codes for government employees.

About 85 per cent of cyber threat activity targeting national elections last year couldn’t be attributed to a state-sponsored cyber threat actor, the report says, a tribute to the techniques they use — either because the attackers obfuscate their origins, or because they outsource attacks to third parties. Sometimes these third parties are commercial public relations or marketing firms.

Of the 15 per cent of activity that can be identified, most is linked to Russia and China.

This includes attempted distributed denial of service attacks, attacks against election authority websites, accessing voter personal information or information relating to the election, and vulnerability scanning of online election systems. In Canadian federal elections, the report notes, residents only vote by paper ballots.

However, some municipalities here have allowed online voting.  Almost half of Ontario’s 444 municipalities, and 42 of Nova Scotia’s 49 municipalities (86 per cent) used online voting in at least one of their past elections, the report notes.

Generally, threat actors targeting elections favour manipulating the information environment over attempts to directly impact the voting process, the report adds.

Russia and China will continue to be responsible for most of the attributed cyber threat activity targeting foreign elections, the report says, and will focus on targeting countries of strategic significance to them.

It notes that upcoming European elections in 2023 and 2024 “could be a significant target for Russia due to the military and economic importance of Europe’s support to Ukraine.”

The CSE’s outward-facing department, the Canadian Centre for Cyber Security, has published a Cyber Security Guide for Campaign Teams and Cyber Security Advice for Political Candidates.

The post Generative AI increasingly used for threats to Canadian democracy: Report first appeared on IT World Canada.

New AI Alliance to advance open source AI convenes IBM, Meta, AMD, excludes Microsoft, Google, AWS, Nvidia

IBM and Meta have partnered to form a new group, the AI Alliance, bringing together more than 50 organizations to promote open source development and innovation in artificial intelligence (AI).

But many of the world’s biggest AI players, including Microsoft, Microsoft-backed OpenAI, Google, and Amazon Web Services (AWS ), all long-standing defenders of closed source AI models and the proprietary, licensed approach, are absent from the alliance.

Intriguingly, however, Partnership on AI (PAI), a nonprofit coalition announced in 2016 by founding members Amazon, Facebook, Google, DeepMind, and Microsoft, has also joined the alliance.

The coalition, which is committed to the responsible use of AI, said it will continue to work with its 90+ partners and the alliance members to ensure that “open science and innovation contribute to safe and responsible AI.”

While open source AI has been riding the wave of growth, Microsoft has only sluggishly embraced the movement, partnering, for instance, with Meta’s Llama 2 and Databricks to bring open-source AI models to its Azure cloud platform. Google, AWS and OpenAI have moved slowly with their open source AI projects.

On the other hand, Meta’s entry in the AI arms race, largely dominated by heavy hitters like OpenAI, Google, and Microsoft, was marked by its commitment to market open source models, notably with the release of Llama 2, one of the most used foundation models.

IBM also recently released an open source foundation AI model, in collaboration with NASA, also a member of the alliance, designed to help scientists analyze satellite imagery.

“We believe it’s better when AI is developed openly – more people can access the benefits, build innovative products and work on safety,” said Nick Clegg, president, global affairs, Meta. “The AI Alliance brings together researchers, developers and companies to share tools and knowledge that can help us all make progress whether models are shared openly or not.”

IBM and Meta bring different capabilities to their partnership headlining the alliance, said Brian Jackson, principal research director at Info-Tech Research Group.

Jackson noted that IBM brings its credibility in professional services and experience in taking open source software – most notably with its 2019 Red Hat acquisition – and translating it into a solutions and services business model. Meta, in contrast, brings its AI talent and leading researchers to the alliance.

This focus on open source through the alliance, however, will likely be more advantageous to Meta than to IBM, he said.

“For Meta, its open-source models are already available on Microsoft’s Azure platform. Its models will find enterprise users so long as there are professionals willing to support them. That takes some wind out of the sails of IBM, who can’t claim any sort of competitive advantage by hosting Meta’s models. At best, it can claim that it has more support services built up around them.”

Chief product officer (CPO) of information management giant OpenText, Muhi Majzoub, acknowledged that IBM and Meta coming together to form the AI Alliance leaves a lot of question marks for the enterprise.

“Any CIO will tell you, ‘I’m not putting my data in a publicly trained, open source LLM’. Business leaders are looking for AI solutions where their company’s data is secure and protected.”

But while AI researchers worry that cybercriminals will download and use these open-source models to further illicit business models, that’s not necessarily a risk for organizations using open source models from the AI alliance today, contended Jackson.

He added, “But in the future, if governments apply more restrictions to the release of LLMs, then it could become an issue.”

Notable presences in the newly formed Alliance are Hugging Face, Oracle, ServiceNow, Dell, Linux Foundation, Stability AI, Red Hat, and several startups, leading universities, governments and more.

Interestingly, the Alliance also includes chip giants including AMD, Intel, and Cerebras, who, since the AI boom, have been steamrolled by competitor Nvidia, currently occupying a near monopoly in AI-enabled GPUs and selling to the biggest cloud providers like AWS, Azure and Google.

AMD’s chief executive Lisa Su said, “The history of our industry highlights how open, standards-based development leveraging the capabilities of the entire industry both accelerate innovation and ensure technology advances have the largest positive impact.”

What will the Alliance do?

IBM said that the AI alliance will begin with the following projects:

Develop and deploy benchmarks and evaluation resources that enable the responsible development and use of AI systems
Responsibly advance the ecosystem of open foundation models with diverse modalities to address society-wide challenges
Foster a vibrant AI hardware accelerator ecosystem
Engage the academic community to support global AI skills building and exploratory research 
Develop educational resources to inform the public discourse and policymakers on AI regulation
Host events to explore AI use cases and showcase how Alliance members are using open technology in AI responsibly.

The AI alliance, IBM said, will begin its work with the formation of member-driven working groups across the areas listed above. It will also establish a governing board and technical oversight committee tasked to advance the key project areas and establish project standards and guidelines.

Further, the alliance plans to partner with existing AI initiatives from governments, non-profit and civil society organizations.

The post New AI Alliance to advance open source AI convenes IBM, Meta, AMD, excludes Microsoft, Google, AWS, Nvidia first appeared on IT World Canada.