Category: News

Breaking news: Canadian privacy commissioners investigating TikTok

Canada’s federal privacy commissioner, along with three provincial privacy commissioners, has started an investigation into TikTok, examining how the video-streaming platform collects the personal data of Canadian users.

The investigation is beginning now because class action lawsuits in the United States and Canada have been settled, the commissioners said in a statement.

The three participating provincial commissioners are from Québec, Alberta, and British Columbia.

The four privacy regulators will examine whether the organization’s practices are in compliance with Canadian privacy legislation, the statement said, and in particular, whether valid and meaningful consent is being obtained for the collection, use, and disclosure of personal information. The investigation will also determine if the company is meeting its transparency obligations, particularly when collecting personal information from its users.

“An important proportion of TikTok users are younger users,” the commissioners said. “Given the importance of protecting children’s privacy, the joint investigation will have a particular focus on TikTok’s privacy practices as they relate to younger users, including whether the company obtained valid and meaningful consent from these users for the collection, use and disclosure of their personal information.”

The federal Office of the Privacy Commissioner (OPC) will investigate possible breaches of the Personal Information Protection and Electronic Documents Act (PIPEDA), Québec’s  Commission d’accès à l’information du Québec will investigate compliance with the Act Respecting the Protection of Personal Information in the Private Sector and the Act to Establish a Legal Framework for Information Technology in Québec, B.C.’s commissioner will investigate compliance with the provincial Personal Information Protection Act and Alberta’s information commissioner will investigate compliance with the  province’s Personal Information Protection Act.

This isn’t the first time several of the country’s privacy and information commissioners have partnered to perform a joint investigation. Last year, a group report was issued into the use by Tim Hortons of its mobile app for location tracking of users. The commissioners found the app violated federal and provincial privacy laws.

In 2021, a joint investigation found facial recognition provider Clearview AI violated federal and provincial privacy laws by scraping images from the internet without permission and using them in its commercial product.

While every province and territory has a privacy or information commissioner, the business sectors of most are covered by the PIPEDA. B.C., Alberta and Québec have their own private sector privacy laws.

According to a news report, the class action settlement in the U.S. meant American residents who created videos on the app before September 30, 2021 would receive payments between US$27.84 and US$167.04 following the US$92 million settlement of a data privacy class-action with the social media platform.

Last year, a Canadian court approved a deal to settle claims here. TikTok agreed to pay $2 million to resolve two class action lawsuits in British Columbia, both of which alleged it wrongly collected private information from minors and adults.

In both the U.S. and Canadian lawsuits, TikTok didn’t admit any wrongdoing.

The post Breaking news: Canadian privacy commissioners investigating TikTok first appeared on IT World Canada.

Research reveals career challenges faced by Black professionals in tech: Info-Tech

In a LinkedIn live event last week, research firm Info-Tech Research Group revealed the main career challenges that Black tech professionals face in 2023, and the responsibilities that companies have in ensuring a comfortable and inclusive work experience for everyone.

The event was a preview discussion of an online survey that garnered responses from 633 IT professionals, 25 per cent of which were from Black professionals. The survey results will be released by Info-Tech at the end of February.

Info-Tech’s research director, Allison Straker, and senior product manager Ugbad Farah said during the event that the key objective of the survey is to zero in specifically on the Black professional experience in tech, which can be very different from that of other ethnic groups.

The survey asked respondents not only how they saw themselves, but also how the world sees them, as this discrepancy can reveal much about the struggles and level of job satisfaction that Black tech professionals experience.

The survey revealed that only 23 per cent of all Black respondents said they were satisfied with their jobs. Job satisfaction in general, however, remains low, with only 34 per cent of respondents from other ethnic groups reporting being satisfied with their jobs.

However, Straker pointed out that it is difficult to determine causation and not just correlation between identity and level of satisfaction with just the results of the survey, but deeper conversations with some respondents suggested lower satisfaction among Black professionals.

Furthermore, the number of barriers to career advancement reported in the survey were higher for Black professionals. 

Farah explained that one of these barriers is microaggression, a statement or incident that sometimes unintentionally causes discrimination to a marginalized group.

Seemingly innocent questions like ‘why is your hair so different?’, or ‘can I touch it?’, ‘Where are you from? But no, where are you really from?’ are examples of those microaggressions that can accumulate and contribute to poor mental health among Black professionals.

When asked what’s important to them, Black professionals deemed safety and recognition as less important, in contrast to other ethnic groups. Basic needs like safety are key to achieving higher needs like self-esteem and self-actualization, hence, better mental health, Straker explained, referring to Maslow’s hierarchy – a classification system, depicted as a pyramid showing the core needs of an individual, with the lower tiers of needs being key to achieving the higher tiers.

Black tech professionals also consider their work relationships with their managers as less important. But Straker underlined the fact that Black professionals are not a monolith and everyone’s work relationships can be largely unique. Yet, “for many, they [safety, recognition or work relationship] are not as important because there are other issues that they need to address first.”

The research also showed that Black tech professionals (55 per cent) are more likely to report they have had no career advancement or promotions within their career.

“We kind of thought to ourselves–maybe they’re less experienced, that’s why they’re not getting those promotions and those advancements. But no, it turns out, even Black professionals with 20 years of experience are not advancing the same as their peers,” stated Farah.

Solutions, according to Farah and Straker:

More diversity in leadership can increase satisfaction among Black tech professionals
Mentorship and sponsorship programs to advance careers of Black tech professionals
Encourage conversations, especially difficult ones about goals, concerns, areas of improvement, etc. This can help Black professionals to be their authentic selves at work
ERGs (Employee Resource groups) are not a substitute for individual mentorship. ERGs are great for groups to come together and talk about things that they can all relate to but mentorship or a sponsorship can help one individual navigate a corporate environment with the support of a leader. “If you could do both–amazing. And if you can’t, ERGs is always a great place to start,” said Farah.
Remote work has helped with job satisfaction for many reasons, but it should not be a means to escape an office culture or a bad environment. Companies have a responsibility to work on their office culture, even if it is remote or hybrid.
Zero tolerance policies are sometimes necessary to allow a culture to change and ensure that it is accommodating and comfortable for people to come to, if acts of discrimination happen.
The post Research reveals career challenges faced by Black professionals in tech: Info-Tech first appeared on IT World Canada.

Hashtag Trending Feb.23rd- The job that AI cannot replace; potential court ruling that could reshape the internet; supercomputer capabilities added to cars

A job that Artificial Intelligence can’t replace.  A potential court ruling that could shake the foundations of the web as we know it.  And, how good is the mileage on your supercomputer?



 

Welcome to Hashtag Trending for Thursday, February 23rd.  

I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US – here’s today’s top tech news stories.

How many employees does it take to equal the salary of one CEO?

According to an article in the Register, HPE’s latest 10k filing shows that the answer is 271.  The value of CEO Antonio Neri’s compensation package was just over 17 million dollars in 2022 much of that in option awards.  The average salary of an HPE employee being about 64,000 dollars. gap

Neri, who replaced Meg Whitman took a pay cut from his 19 million dollar compensation in 2021. 

Tarek Robbiati, HPE’s CFO earned just over 8 million and Chief Operating Officer John Schulz was just shy of 8 million last year.  Chief People Officer Alan May made just under 5 million.

What did they do to earn that?  Well, HPE increased revenues 3 percent year-on-year to $28.5 billion which is up from previous years. Not as good as the 29 percent gains seen by AWS in calendar 2022 but significant.

Although HPE suffered somewhat from supply chain issues, it’s as-a-service offering Greenlake did achieve 17 percent growth to $936 million.  Not as strong as the 36 percent growth in the prior year but a healthy increase in an area that HPE hopes will compete with the other major cloud players. 

Source: The Register

Looking for a new job for when AI replaces you?  How about “prompt engineer.”  That’s what Sam Altman, CEO of ChatGPT recommended in an interview with Axios.

As everyone who has played with ChatGPT knows, the results you get vary measurably with the quality of the questions you ask.  

ChatGPT agrees and told us:  “A prompt engineer in the context of ChatGPT and generative AI would be someone who has expertise in crafting effective prompts to guide the output of a language model and achieve a desired outcome.”

Job’s are already being posted with prompt engineer as the function or as an important skill. There are number of platforms that are set up as “prompt search engines” such as Prompt Hero, Promptist and Krea. Remote course company Udemy is also offering classes.

Stephen Fragg the founder of chatbot-training business Prompt Yes!, told Axios, 

“It’s kind of like selling jeans during the gold rush. It’s not actually going out and digging up gold.” 

This is an allusion to the fact that overall, the merchants who supplied the gold miners in the Klondike Gold Rush made more money than the miners themselves. While some miners did strike it rich and found significant amounts of gold, the vast majority did not and struggled to make ends meet.

On the other hand, merchants like Levi Strauss who sold supplies to the miners, such as clothing, tools, and food, made significant profits.

How’d we know that?  Apparently, we might have a career as a prompt engineer.

Source: Axios 

Google’s lawyers have warned that a potential ruling by the US Supreme Court could “reshape the internet.”

The case, Gonzalez vs Google, was brought by the family of a terrorist victim.  They argue that YouTube violated the federal Anti-Terrorism Act because its algorithm recommended ISIS videos to users and helped spread the terrorist group’s message.

Google maintains that it is protected by Section 230 of the Communications Decency Act, which protects platforms from legal action over user-generated content.  It also protects them if they remove content. Section 230 has withstood court challenges more than 25 years since it was passed in 1996. 

But there are signals from the Court that the judges may be questioning this immunity from prosecution, echoing similar questions from the US Congress. Internet firms are, understandably, concerned about loss of that protection and the potential liability for the results of their algorithms.  

Experts argue that the issues raised are not simple and any decisions could have real repercussions which lawmakers and even Supreme Court judges may be highly unqualified to judge. This was made clear in an exchange between Google’s lawyer and Chief Justice John Roberts who asked. “Would Google collapse and the internet be destroyed if Google was prevented from posting what it knows is defamatory?” 

“Not Google,” answered Blatt, but other, smaller websites, yes. Blatt was referring to the fear that removing Section 230 provisions, if done as a way of reigning in an increasingly unpopular “big tech” could have inadvertently impact everything from a simple one person WordPress blog all the way up to sites like Reddit or the new open source Mastodon. 

In a digital economy, justice may be blind, but can it afford to be technologically illiterate?

Source: Deadline & Tech Republic

In a related story, Twitter CEO Elon Musk has promised to make Twitter’s algorithm Open Source by next week.  This isn’t a new idea, Musk has been advocating it for some time.  It might seem to be counter-intuitive for a company to make public what some regard as a company secret.  Google, for instance has strictly guarded the secret of its algorithm.  

It’s also strange, given recent claims that Musk has allegedly asked developers to adjust Twitter’s code to favour his tweets and claims that Musk has allegedly threatened to sue any Twitter employee who violates their NDA.

But as the Register article reported, the Brookings Institute has said that Open Source algorithms could be a “boon for tech sector competition, help define AI standards and, as Musk has implied, help fight algorithmic bias.”

And of course, Twitter is also facing a case similar to Google’s where it might be held responsible for the results of its algorithm.  Would it hurt their defence if they no longer controlled the algorithm? 

Source: The Register

How good is the mileage on your supercomputer? 

Auto giant Mercedes Benz has teamed up with Google to offer “supercomputer-like performance” in every car.  Benz is in a race to match and exceed the software powered features of its competitors, Tesla, the big 5 automakers and a fast growing and already large Chinese car manufacturing industry which is already dwarfing even Tesla, despite its early lead in this area.

Benz is also partnering with chip manufacturer Nvidia, investing heavily to bring down the cost of new semi-conductors and chips that will be needed in these cars. They’ve also enlisted Luminar Technologies, which Benz has a small investment and struck a multi-billion dollar deal with the company to provide it with sensors needed for its fleet of intelligent automobiles.

The Google partnership is not unique. Several auto manufacturers including GM and Nissan have included Google Maps, Google Assistant and other features.  Benz will add he ability to view You Tube in self driving mode on a cabin wide screen.

The move is not just a competitive race for features. Benz plans to offer some of the premium features at an additional cost.  The time-honoured tradition of upselling on options makes its way into the digital era. 

Source: Reuters

And that’s the top tech stories for today.  Hashtag Trending is produced by the ITWC podcast network and is heard Monday to Friday with a special weekend edition where we feature interviews on key subjects in technology.

Follow us on Apple Podcasts, Google, Spotify or wherever you get your podcasts.  You can even have us delivered to you daily on your your smart speaker.  If you follow stories about cybersecurity, why not check out our sister podcast CyberSecurityToday. 

You can find all our podcasts and the text versions –  as well as more in-depth coverage itworldcanada.com  and on technewsday.com in the US.

Let us know what you think – are we hitting the mark on the stories you want to hear? You can drop me a note on Linked In, Twitter or on our own Mastodon site at TechNews.Social  Or write me at jlove@itwc.ca

I’m Jim Love, have an awesome Thursday.

The post Hashtag Trending Feb.23rd- The job that AI cannot replace; potential court ruling that could reshape the internet; supercomputer capabilities added to cars first appeared on IT World Canada.

Gartner panel explores how citizen needs impact digital strategies

How digital should your organization be? It was a simple question posed to a group of senior government IT executives in a roundtable discussion held earlier this month at the Verity Club in downtown Toronto, but one in which the correct answer involves embarking on a series of incredibly complex steps.

The session was organized by Gartner Canada and led by Hung LeHong, a distinguished VP analyst with the research firm.

Digital leadership, Gartner noted, is the “duty of government executives and elected officials to optimize, evolve and transform the organizations they lead by serving as champions to increase digital capabilities and policy competencies in the public sector.

“Digital government offers opportunities to optimize existing citizen services and transform how the value of government is measured and delivered. Governments need digital leadership at every level of their organization and across related government silos.”

LeHong said in his opening comments that Gartner clients, both in the private and public sectors, are spending a “lot of money on becoming digital,” and that means they must be able to answer the question about how digital their organization should be, not with a response that is vague, such as ‘digital means different things to different people’, but something far more concrete.

“Your whole organization should understand what it means for you to be digital, and that’s what we are actually going to go through today.”

What digital should mean from a municipal perspective could be seen in a slide from the Department of Transport of the state of Victoria in Australia that he showed as an example of digital in action. In this case, the use of AI and image recognition have improved the speed with which the need for road repairs is recognized and catalogued, and ultimately performed.

“They used to drive around in a truck with clipboards and someone had to recognize that little arrow needs to be repainted, or this sign is broken,” said LeHong, adding that with a new digital initiative in place, tasks that once took weeks and months to complete can now be completed in days, and even in hours.

This is just one small example of what is happening in Victoria. The state’s digital strategy, a document that establishes the current government’s vision for a successful digital transformation, says that three key outcomes underpin it: better, fairer, more accessible services, a digital-ready public sector, a thriving digital economy.

“In delivering on these outcomes, we will improve the experience individuals, communities, businesses and the Victorian public sector have with government,” the document states.

LeHong, who, according to Gartner, “focuses on CEOs and other C-level executives to help them anticipate changes to business models and customer trends caused by digital business,” said much can be learned from what is happening in Victoria, in that going digital involves far more than simply adopting advanced technologies.

A municipality becoming more digital, he said, should revolve around conducting business operations in a more efficient manner.

“We call it digital business optimization, simply because it’s not that you are changing your products and services to whoever you are serving, you are not changing your business model – your public mandate, your mission remains the same, but boy, can you do things faster, cheaper and have a better customer experience with digital.”

Another example of digital business optimization, said LeHong, is taking place in Rio Grande do Sul, Brazil’s most southern state, which borders Argentina and Uruguay. Last year, the state’s 23 municipalities, he said, “integrated 20 databases representing the public safety ecosystem, including law enforcement, the prison system, courts, education, health, finance and traffic systems, supporting public safety and justice across the state.”

The result was a sharp reduction in violent crimes compared to 2021 and, in fact, the lowest number recorded since 2012.

“They all work together to catch the bad guys,” he said. “And the point is, they were not mandated to work together.”

Source: Gartner. © 2022 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. and its affiliates.

Throughout his presentation, there was discussion around one particular chart (see above) that had three components in different colours: In green was the Technology and Operating Model, in which modern technologies and approaches are used and form the base point of a digital transformation journey. Just above it to the left, and in orange lies Optimization; in which a municipality, having evolved their IT operating model conducts business more digitally, and right beside it in blue is the Transformation component, in which a whole new digital business model is created.

An assortment of Gartner benchmarks used during the 90-minute presentation revealed that not every municipality or every private enterprise will land on green, orange, and blue at the same time.

Dr. Peter Bak, chief information officer (CIO) at Humber River Hospital, said that all of LeHong’s insights and benchmarks were “extremely important, but the hard bit is how do you get the action going, and that would be a good follow-on topic to have.”

He said the way the “tech world is shifting does present an opportunity for us to rethink how healthcare is delivered, but that’s a very hard concept for people to grasp, because they believe you can’t change this – you treat people the way you treat them.

“It actually requires incredibly out-of-the-box thinking, which does not exist in healthcare. I don’t know how well it exists in other public sector environments, but I believe there are moments in time when opportunity presents itself to actually do a blue.”

In an interview with IT World Canada, Bak was asked if public service departments can learn from private enterprise when it comes to digital transformation, and his answer was “absolutely”. As proof, he referenced a recent executive hiring by the world famous Mayo Clinic, located in Rochester, Minn.

“(They) hired a chief digital officer who came from Best Buy, and it caught my attention. She had also worked in healthcare before, but I thought that was really fascinating. Why? Because they are trying to move to a much more online, engaged world with their patients, and healthcare is terrible at that because that’s not how healthcare functions.

“But which industry functions extremely well at that? It’s the consumer world, so why don’t we learn from them how they did it? It is not about the tech so much. It is about the engagement, change management, strategy, mindset, thinking. So yes, you can learn from other industries, and we should.”

The post Gartner panel explores how citizen needs impact digital strategies first appeared on IT World Canada.

Indigo admits cyber attack was ransomware, employee data accessed

Two weeks after suffering a cyber attack, Indigo Books and Music has acknowledged it was hit by ransomware and employee data was compromised.

“On February 8, 2023, Indigo experienced a ransomware attack,” the company says in an updated FAQ on its website. “Through our investigation we learned there is no reason to believe customer data has been improperly accessed, but that some employee data was.”

“We are notifying all affected employees,” the site says. “We have also notified and are co-operating with law enforcement.

“Since this incident, we have been working with third-party experts to strengthen our cybersecurity practices, enhance data security measures and review our existing controls.”

No ransomware group has taken responsibility for the attack as yet, according to a threat researcher for a cybersecurity company.

Also today, the company said it has been able to restore online sales of books — but not other items it sells.

“Books are back,” Indigo trumpeted on its website, saying thousands of titles are available. However, shoppers can only browse for lifestyle products. These will have to be bought in stores across the country.

Indigo is still in the process of remediation. The website says it is the “temporary online home,” suggesting that a new website is being built.

According to a report released today by Fortinet that looks at cyber incidents in the second half of 2022, ransomware volume around the world increased 16 per cent from the first half of last year.

Out of a total of 99 observed ransomware families, the top five families accounted for roughly 37 per cent of all ransomware activity during the second half of 2022, it said.

GandCrab, a ransomware-as-a-service malware that emerged in 2018, was at the top of the list. Although the criminals behind GandCrab announced that they were retiring after making over $2 billion in profits, the report says, there were many iterations of GandCrab during its active time. “It is possible that the long-tail legacy of this criminal group is still perpetuating, or the code has simply been built upon, changed, and re-released.”

In an IBM report, also released today, that looked at incidents the company was called on for help across all of 2022, researchers said incidents of ransomware dropped last year compared to 2021. However, deploying ransomware was the second most common action after a threat actor was able to breach security controls. Installing a back door was number one. Back doors lead to the distribution of malware, including ransomware, to further everything from credential theft through data theft and data destruction.

Alarmingly, IBM said there was a four per cent reduction in the average time for the deployment of ransomware attacks in 2022 compared to the previous year. To put that in perspective, what took attackers over two months in 2019 took just under four days in 2021.

The post Indigo admits cyber attack was ransomware, employee data accessed first appeared on IT World Canada.

CRTC launches consultation on enhancing reliability of Canada’s telecom; imposes interim directive on carriers

The new head of the Canadian Radio-television and Telecommunications Commission (CRTC) is wasting no time kickstarting efforts to improve the reliability and resiliency of Canada’s telecommunications networks.

“Canadians need reliable, high-quality telecommunications services,” said Vicky Eatrides, chairperson and chief executive officer of the CRTC, in a release. “We are taking action to lessen the disruptive impact of service outages on Canadians, reduce their occurrence and length, and ensure that essential services such as 911 and emergency alerts are always available.”

To that end, the CRTC today launched the first of several consultations, this one asking Canadians for their comments on proposed requirements for the reporting of major service outages.

In its call for comments, entitled Development of a regulatory framework to improve network reliability and resiliency – Mandatory notification and reporting about major telecommunications service outages, the CRTC noted that the scale and frequency of outages caused by extreme weather, cyber-attacks, and accidents have been increasing, citing factors such as climate change, the increased economic and social importance of telecommunications, and what it referred to as “technological evolution”.

“As the complexity of telecommunications networks and the importance of communication in Canadians’ daily lives increases, there is a need for additional measures to improve network reliability and resiliency and to mitigate the impact of service outages,” the call for comments explained. “Building on the work of Innovation, Science and Economic Development Canada (ISED) and the Canadian Security Telecommunications Advisory Committee (CSTAC), the Commission is taking action to develop a framework to improve the reliability and resiliency of telecommunications networks. This notice of consultation is the first stage in this process.”

Meanwhile, it said, “on an interim basis pending the outcome of this proceeding, the Commission directs all Canadian carriers to report major service outages (including outages affecting only 9-1-1 networks) to the Commission within two hours of when the carrier becomes aware of such an outage. Additionally, the Commission directs carriers to file a comprehensive report with the Commission within 14 days following the outage. This direction takes effect on 8 March 2023.”

In addition, it is hiring an independent firm to review the mitigations Rogers has put in place after its July 2022 outage, and will, in collaboration with ISED, commission a report on the measures employed by telecommunications regulators internationally to make networks more reliable and resilient against vulnerabilities and threats that may lead to a telecom service outage.

Comments on the Commission’s proposed reporting requirements for carriers, detailed in the call for comments, may be submitted online, mailed to Secretary General, CRTC, Ottawa, Ontario K1A 0N2, or faxed to 819-994-0218. Inputs will be accepted until Mar. 24.

The post CRTC launches consultation on enhancing reliability of Canada’s telecom; imposes interim directive on carriers first appeared on IT World Canada.

Government of Canada invests $94 million to provide high-speed internet access to homes and communities in Newfoundland and Labrador

Today, the governments of Canada and Newfoundland and Labrador announced an investment of up to C$94 million to provide high speed internet access to 36,000 homes and 350 rural, remote, and Indigenous communities across the eastern province. 

Bell and Xplore will be responsible for connecting these homes and communities by December 2025 and March 2026, respectively.

Today’s announcement is part of an existing historic agreement between the governments of Canada and Newfoundland and Labrador, announced in February 2022, to invest up to C$136 million to connect all remaining rural, remote, and Indigenous homes throughout the province to high-speed internet.

Since 2015, the government of Canada has invested over C$146 million in connectivity projects in Newfoundland and Labrador.

“We all know that internet is no longer a luxury in this day and age—it’s a necessity. That’s why our federal government made a historic commitment to connect 98 per cent of Newfoundlanders and Labradorians to high-speed Internet by 2026, and 100 per cent by 2030,” said Minister of Rural Economic Development Gudie Hutchings.

So far, 93.5 per cent of Canadian homes have access to high-speed Internet or are targeted to receive access through existing program commitments.

Residents can track the progress of the broadband project in their communities, see its estimated completion date, and more, through canada.ca/rural.

The post Government of Canada invests $94 million to provide high-speed internet access to homes and communities in Newfoundland and Labrador first appeared on IT World Canada.

Phishing still the leading way attackers breach security controls: IBM

IBM’s annual X-Force Threat Intelligence Index, an analysis of data gathered from network sensors and incident investigations, is filled with a dizzying array of numbers about breaches of security controls.

But arguably only one is the most important: The one that shows us how most successful attacks start. And the answer for 2022 — again — is phishing.

The report, released today, says phishing remained the leading infection vector last year, identified in 41 per cent of incidents. Of those phishing attacks, 62 per cent were spear-phishing.

The exploitation of public-facing applications — because, for example, they were unsecured or unpatched — accounted for 26 per cent of incidents.

Abuse of valid accounts was identified in 16 per cent of the observed incidents. These are cases where adversaries obtained and abused the credentials of existing accounts as a means of gaining access. These incidents included cloud accounts, default accounts, domain accounts, and local accounts.

The exploitation of remote services was the fourth most common attack vector, used in 12 per cent of successful attacks. Not every vulnerability exploited by threat actors results in a cyber incident, the report adds. The number of incidents resulting from vulnerability exploitation in 2022 decreased 19 per cent from 2021, after rising 34 per cent from 2020. IBM believes this swing was driven by the widespread Log4J vulnerability at the end of 2021.

Infections by malicious macros have fallen out of favor, adds the report, likely due to Microsoft’s decision to block macros by default. To compensate, attackers are increasingly using malicious ISO and LNK files as the primary tactic to deliver malware through spam.

Among other interesting numbers:

–- credit card information as a target in phishing kits dropped significantly. Last year only 29 per cent of phishing kits targeted credit cards. That suggests phishers are prioritizing personally identifiable information (PII), says the report;

— although ransomware’s share of incidents declined only slightly (4 percentage points) from 2021 to 2022, defenders were more successful in detecting and preventing ransomware. Despite this, attackers continued to innovate, with the report showing the average time to complete a ransomware attack dropped from two months down to less than four days;

— the deployment of backdoors after gaining access emerged as the top action by attackers last year. Twenty-one per cent of incidents involved the installation of backdoors. About 67 per cent of those backdoor cases were related to ransomware attempts where defenders were able to detect the backdoor before ransomware was deployed, says the report. The uptick in backdoor deployments can be partially attributed to their high market value, the report says. Threat actors last year sold existing backdoor access for as much as US$10,000, compared to stolen credit card data, which can sell for less than US$10 today;

— the second most common action after getting network access was deploying ransomware. One particularly damaging way ransomware operators distribute their payload across a network is by compromising domain controllers, the report notes;

— the most common impact from cyberattacks in 2022 was extortion, which was primarily achieved through ransomware or business email compromise attacks. Europe was the most targeted region for this method, representing 44 per cent of extortion cases observed, as threat actors sought to exploit geopolitical tensions. Data theft and credential harvesting were the second and third most common impacts;

— thread hijacking saw a significant rise in 2022, with attackers using compromised email accounts to reply within ongoing conversations, posing as the original participant;

— the proportion of known exploits relative to vulnerabilities declined 10 percentage points from 2018 to 2022, due to the fact that the number of vulnerabilities hit another record high in 2022. IBM concludes that legacy exploits enabled older malware infections such as WannaCry and Conficker to continue to exist and spread. On the other hand, the reduction of vulnerabilities with known exploits is evidence of the benefit of a well-maintained patch management process, the report says;

— don’t forget to close the door (or, more accurately, the ports) on USB-based attacks. In 2022, IBM saw the spread of the Raspberry Robin worm through employees plugging in infected USB devices. By early August, Raspberry Robin peaked at 17 per cent of infection attempts that X-Force observed;

— on the operational technology (OT) side, industrial control systems (ICS) vulnerabilities discovered in 2022 decreased for the first time in two years (457 in 2022 compared to 715 in 2021 and 472 in 2020). One explanation, says the report, may be found in ICS lifecycles and how they’re generally managed and patched. Attackers know that, with the demand for minimal downtime, long equipment lifecycles, and older, less-supported software, many ICS components and OT networks are still at risk from older vulnerabilities. Infrastructure is usually in place for many years longer than standard office workstations, which extends the lifespan of ICS-specific vulnerabilities beyond those that exploit IT.

Among the report’s recommendations for infosec leaders:

— organizations should develop incident response plans customized for their environment. Those plans should be regularly tested and modified as the organization changes, with a focus on improving response, remediation and recovery time;

— prioritizing the discovery of assets on the perimeter, understanding the organization’s exposure to phishing attacks, and reducing those attack surfaces further contribute to holistic security. Extend asset management programs to include source code, credentials, and other data that could already exist on the internet or dark web;

— have appropriate visibility into the data sources that would indicate an attacker’s presence.

The full report can be downloaded here. Registration required.

The post Phishing still the leading way attackers breach security controls: IBM first appeared on IT World Canada.

Hashtag Trending Feb.22nd-Four-day work week worth more than money; data centers used by Alibaba, Amazon, Apple breached; 60 countries including China agree to regulate military AI

Four-day work week worth more than money, hackers access data from Asian data center operators used by Alibaba, Amazon, Apple and more, and 60 countries, including China sign agreement to regulate military AI.



 

It’s Wednesday, February 22nd. These stories and more on Hashtag Trending–today’s top technology news stories. I’m your host, Jim Love.

92 per cent of companies involved in the massive four-day work week trial in the UK are sticking to it. 

The pilot for a four day work week that involved 3,000 employees across 61 British companies is now over and the results are worth thinking about, especially for companies struggling to attract and retain high value employees.

Of the 61 companies that participated, 56 will continue to offer a shorter week, although only 18 companies would commit to the policy becoming a permanent change.

Taking place over a period of six months from June to December last year, the trial did not require any employees’ salaries to be altered, nor were they asked to work extended hours.

The results of the trial consolidate the findings from previous research from 4 Day Week Global, which found that 63 per cent of businesses surveyed found it easier to attract and retain employees after switching to a four-day work week.

Other staffers who participated also suggested that the four-day work week could be more attractive than money. 15 per cent said “no amount of money” would induce them to accept a five-day schedule over the four-day week to which they were now accustomed.

Company revenue also stayed broadly the same over the trial period, rising by 1.4 percent on average, weighted by company size, across respondent organizations.

Plus, the trial concluded that a shorter work week led to more efficient meetings, increased productivity and morale by a whopping 40 per cent.

Source: The Register

Amazon employees take a huge pay cut as stock prices decline

Some Amazon corporate employees will be paid as much as 50 per cent less than previously expected in 2023 because of the company’s falling stock price, the Wall Street Journal reported on Monday.

Employees’ annual salaries are generally made up of cash compensation and awards of restricted stock units, but because of the 35 per cent decline in Amazon’s share this year, total compensation is set to drop sharply.

An Amazon spokesperson said to Insider that their compensation, is designed to encourage employees to “think like owners” but the model “comes with some year-to-year upside and some risk because the share price can fluctuate”

Amazon’s share price has fallen from around $150 per share in February 2022, to around $97 per share as of Tuesday, a drop of $53, or 35 per cent, Markets Insider data shows.

The company also recently announced plans to lay off 18,000 employees.

Source: Business Insider

Layoffs have indeed rattled the tech industry, but the outlook remains bright for developers, according to news site InfoWorld.

Career experts say hiring remains steady in transportation, manufacturing, healthcare, and other sectors and all are looking for developers with the skills to create innovative products and services.

Recruitment agency Robert Half maintained that hiring will increase early this year, stressing that the need to maintain or further develop organizational technology remains robust, despite the slowing economy.

Plus, the need for developers extends beyond the tech industry.

“Every company today is a tech company in some capacity, and that’s certainly true when it comes to software development,” says Nick Kolakowski, senior editor of Dice Insights at technology career marketplace Dice.

And these non-traditional technology companies, like in automotive, education, healthcare or food are now chasing the developers laid off from traditional tech companies.

Even though recent layoff news from big technology companies is making technology professionals feel less secure about their jobs, “job market prospects are still bright for software developers,” says Sinem Buber, lead economist with jobs site ZipRecruiter.

Still, 80 per cent of job postings are listed within the traditional tech sector. 

But developers can still look to join fast-growing fields like IoT and cybersecurity.

Plus, The U.S. Bureau of Labor Statistics (BLS) found that overall employment of software developers, quality assurance analysts, and testers is expected to grow 25 percent between 2021 and 2031, much faster than the average for all occupations.

According to Infoworld, “The future is bright, if you know where to look”

Source: InfoWorld

Asia’s largest data centres were hacked and with them, some of the world’s largest companies.

According to documents reviewed by Bloomberg, hackers have gotten hold of login credentials for data centers in Asia used by some of the world’s biggest businesses including Alibaba, Amazon, Apple, BMW, Goldman Sachs, Huawei, Microsoft and Walmart.

Shanghai-based GDS Holdings Ltd. and Singapore-based ST Telemedia Global Data Centres are the two impacted data centers that led to emails and passwords on customer-support websites being breached, affecting about 2,000 customers.

The hackers had access to the login credentials for more than a year before posting them for sale on the dark web last month, for $175,000, according to cybersecurity company Resecurity Inc. and a screenshot of the posting reviewed by Bloomberg.

Both data center operators said the rogue credentials didn’t pose a risk to clients’ IT systems or data but executives from four impacted US-based companies said the stolen credentials represented an unusual and serious danger, primarily because the customer-support websites control who is allowed to physically access the IT equipment housed in the data centers.

“The worst-case scenario for any data center operator is that attackers somehow get physical access to clients’ servers and install malicious code or additional equipment, said Michael Henry, former chief information officer for Digital Realty Trust Inc., one of the biggest US data center operators. “If they can achieve that, they can potentially disrupt communications and commerce on a massive scale.”

Among the companies affected, several declined to comment on the breach or claimed that the risk is minimal.

Source: Data Center Knowledge

Microsoft is preparing to launch a new version of Microsoft Teams, designed to deliver higher performance and use less resources on desktops.

The upgrade has involved moving from Angular to the React JavaScript framework, and switching from Electron, the cross-platform desktop app development framework, to Edge’s WebView2.

Performance improvements include reduced latency and page-load times, smoother scrolling and faster loading for the compose message box.

Source: ZDNET

Google also has some new updates for Chrome users aimed at relieving the resource and memory demands that have plagued the Chrome browser.

The giant is rolling out Energy Saver and Memory Saver, announced back in December, with the release of Chrome 110. The features will be turned on by default. 

Memory Saver will help users keep multiple tabs open at once, frees up memory from inactive tabs and ensures active websites run smoothly. In comparison, Battery Saver mode kicks in once a laptop’s battery level reaches 20 per cent, limiting background activity and visual effects on websites with animations and video.

Both modes can be disabled in settings.

Source: ZDNET

Your WhatsApp account can get inadvertently hijacked, who would’ve thought?

A reader, Eric, told news site The Register that this happened to his son, Ugo.

Upon changing his phone number, Ugo received a barrage of a stranger’s private WhatsApp messages and was even able to send messages to all of the person’s contacts.

The security hole stems from wireless carriers’ practice of recycling former customers’ phone numbers and giving them to new customers.

A WhatsApp spokesperson acknowledged that this can happen but it is extremely rare.

If a person no longer wants to use a WhatsApp account tied to a particular phone number, then they should transfer it to a new number or delete the account within the app, the spokesperson said. He added that two-step verification is strongly recommended for more security.

WhatsApp’s parent company Meta said that it has doesn’t have control over telecom providers who reissue phone numbers or with users having a phone number linked to their Facebook account that is no longer registered to them.

Regardless, the messaging company should take steps to mitigate the problem, Eric believes, like checking to ensure a user’s phone number is correct or provide a help page on how to transfer accounts.

Source: The Register

We have been talking in previous episodes the harms and absurdities that appeared with the recent viral developments in AI. But AI’s misuse in warfare could potentially be the gravest.

Sixty countries including China have signed an agreement at the first global Summit on Responsible Artificial Intelligence in the Military Domain (REAIM) to develop and use military AI in a responsible manner. They committed to abide by “international legal obligations and not compromise “international security, stability, and accountability,” with their use of AI.

All nations that attended the summit, except for Israel, signed the agreement. Russia was not invited to take part, while Ukraine did not attend.

The signatories sought to address the reliability of military AI, the unintended consequences of its use, escalation risks, and the way humans need to be involved in the decision-making process.

India’s push into AI-powered military systems potentially leading to a nuclear war with Pakistan is one of the predominant consequences that many fear.

However, some attendees did point out the benefits of using AI in conflict, especially in Ukraine where ML and other similar technology has been used to fend off a bigger aggressor.

“Imagine a missile hitting an apartment building,” said Dutch deputy prime minister Wopke Hoekstra. “In a split second, AI can detect its impact and indicate where survivors might be located. Even more impressively, AI could have intercepted the missile in the first place. 

Critics of the agreement however argue that it is not legally binding and fails to address many other concerns around military AI.

The summit was co-hosted by the Netherlands and South Korea last week at The Hague. 

Source: TechSpot

That’s the top tech news stories for today.

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in-depth coverage on itworldcanada.com or in the US on technewsday.com

If you’re trying to keep up on cybersecurity, you might want to follow our sister podcast, CyberSecurityToday.

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com

I’m Jim Love, have a great Wednesday.

The post Hashtag Trending Feb.22nd-Four-day work week worth more than money; data centers used by Alibaba, Amazon, Apple breached; 60 countries including China agree to regulate military AI first appeared on IT World Canada.

Coffee Briefing Feb. 21 – Government of Canada announces new Indigenous council, Zapier’s National No-Code Day contest returns; York University launches post-graduate certificate in CloudOps; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team!

Missed last week’s Coffee Briefing? We’ve got you covered.

What’s new this week

Government of Canada announces new Indigenous Council to lead clean energy projects in Indigenous and remote communities

The government of Canada has announced the selection of seven Indigenous leaders to make up a new Indigenous Council for Wah-ila-toos to help guide the transition to clean energy in Indigenous, rural, and remote communities.

The members, selected by an Indigenous consultant team, will serve on the council until the fall of 2024. The Indigenous Council is distinctions-based, with First Nation, Inuit and Métis representation, and reflects diverse communities, languages, geographies, and skills.

The announcement was made last week by the Minister of Natural Resources Jonathan Wilkinson; the Minister of Northern Affairs, PrairiesCan and CanNor Dan Vandal; and the Minister of Indigenous Services Patty Hajdu.

The Indigenous Council will support the government in the following ways:

provide guidance on program design and policy
help engage with Indigenous partners on accessing resources and funding that reduces diesel reliance
act as the jury for the Indigenous Off-Diesel Initiative’s (IODI) Second Cohort, aimed to support clean energy champions and their communities with training, access to expertise, and funding for projects that reduce diesel use for heat and power.

“I congratulate all of the members of Wah-ila-toos. The Government of Canada looks forward to your advice and guidance as we work toward reducing diesel reliance, advancing clean energy deployment, and creating economic opportunities and sustainable jobs with First Nations, Inuit and Métis,” said Wilkinson.

Zapier’s National No-Code Day contest returns for a second year

No-code automation platform Zapier is hosting its second annual No-Code Day Contest to recognize the most innovative employee/company using no-code technologies to make their work processes more streamlined and productive.

National No-Code Day, celebrated on March 11, was started by Zapier to create awareness among businesses and organizations to do more without code.

Applicants can submit to four categories:

No-code transforming businesses – how people or companies are using no-code tools to optimize their business tasks
No-code changing the world – how non-profits who are using no-code to further their missions
No-code empowering small businesses – how small businesses are using no-code to launch, scale or run their operations.
No-code featuring AI – how people or businesses are using AI to transform their work.

Zapier’s chief executive officer, Wade Foster, will be selecting a winner in each category to receive a cash prize of US$5,000.

The deadline for entries is Mar. 8. Finalists will be contacted prior to posting, and the winner of each category will be announced on Mar. 13.

Project management firm launches SaaS solution to accelerate construction projects

Contruent, an Illinois-based project management firm for large construction projects, has announced the launch of Contruent Enterprise, a software-as-a-service solution to empower owners and EPCs (Engineering, Procurement, Construction) companies to complete projects faster and more precisely.

“Construction projects show no signs of slowing down, particularly with President Biden’s US$1.2 trillion infrastructure initiative being deployed, and budget owners need the best tools to manage these opportunities,” said Ryan Kubacki, Contruent chief executive officer.

The announcement of the cloud-based software comes after the company rebranded from ARES PRISM to Contruent.

Users can perform scheduling and budget management for construction megaprojects with a customizable dashboard and other features such as contract management, engineering and field management. Furthermore, the software allows users to oversee project-critical tasks and enhance communication and collaboration across departments.

The company said that clients utilizing existing on-premise legacy systems will “continue to receive the same support with a stronger business foundation.”

ConnectPay weighs in on top e-commerce payments challenges in 2023

ConnectPay, a finance platform for online businesses that offers a broad range of payment solutions, has zeroed in on what it believes are the top ecommerce payments challenges that SMBs need to address to be successful in 2023. 

Here are the 2023 ecommerce challenges, according to ConnectPay:

Choosing a payment provider that offers multiple payment solutions in order to relieve SMEs of the burden of managing many vendors at once. 
Customers abandoning their shopping carts have been a key issue for many ecommerce SMBs. Additional delivery charges, multiple log-ins, and a complex payment process contribute to the high rate of losing sales.
Ensuring payment security and protecting client data. The fintech industry is implementing industry standards, such as PCI DSS 4.0 and 3DS 2.0, and integrating biometrics in payment processing to enhance user experience. This all adds an extra layer of security, however, it’s crucial to remain vigilant and keep the security standards up-to-date, considering how fast new methods of fraud pop up,” said Chief Business Officer at ConnectPay, Simas Simanauskas.
Keeping up with the rapid rise in contactless payments and digital wallets to lessen friction in the payment journey. Contactless payments can help SMBs increase sales, reduce costs, increase customer reach and competitiveness in the market.

York University launches full-time post-graduate certificate in CloudOps

 

York University School of Continuing Studies has announced a post-graduate certificate in CloudOps, the only full-time university-level cloud operations program to be offered in Canada, designed to prepare recent domestic and international university graduates for entry-level cloud computing jobs.

“People looking to enter this profession need the right mix of cloud competencies from organizational change management to data governance and flawless execution and deployment,” said Claude K. Sam-Foh, cloud computing expert and curriculum developer, instructor and program advisory member for the post-graduate certificate in CloudOps..

The curriculum includes the following:

Learn about cloud operations roles such as compliance, security, containers, microservices etc.
Work first-hand with a vast array of industry-standard tools, including Terraform, Git Merge, Ansible, Docker, and more. 
Become adept with prominent cloud platforms like AWS, Microsoft Azure, and Google Cloud.
Develop and present a business case for cloud adoption and digital transformation
Build effective automated pipelines and monitor systems and metrics for early detection of problems

Registration for the post-graduate certificate in CloudOps is now open, with classes beginning in September 2023.

More to explore

Unihertz Titan Slim review: the keyboard phone lives

BlackBerry fans who mourned the demise of the keyboard phone now have hope, thanks to a Shanghai-based vendor called Unihertz that has been developing phones, including several with keyboards, since 2017.

Veeam puts its money where its mouth is with ransomware warranty program

The big news from Veeam’s Software’s launch on Tuesday of what it simply called the new Veeam Data Platform was not the introduction of upwards of 500 new features, but the fact that the Premium Edition now includes a warranty program that covers data recovery in the event of a verified ransomware attack.

Record $117M funding for Scale AI supporting 15 AI projects

Montreal-based Scale AI announced recently that it has completed a $117 million financing round, its largest to date. This funding will support 15 AI projects that “demonstrate the acceleration of AI adoption in manufacturing, retail and agriculture, as well as in the development of innovative AI solutions for businesses”.

FBI detects, contains cyber attack on New York office: News reports

The U.S. federal law enforcement agency told the news organization that the incident involved an FBI computer system used in investigations of images of child sexual exploitation.

Indigo back online, but only for browsing

Canada’s biggest book chain is back online, but shoppers still can only buy products in stores.

Rogers-Shaw merger deadline extended again

The deadline to complete Rogers’ C$26 billion takeover of Shaw has been extended again.

IntegrityCounts: Finding fraud and waste all via the cloud

The term whistleblower, in the context of someone doing some good, has been in existence since the early 1970s, but for Shannon Walker, the sense of its significance came in the early 2000s with the onset of the Enron Corp. scandal.

Skyhigh’s new global partner program now officially in action

Skyhigh Security this month launched the Skyhigh Security Altitude Program, a global initiative the company said provides its partner community – value-added resellers, strategic integrators and managed service providers – with “incentives, tools and information designed to help them earn more.”

Rogers-Shaw merger closing date looms, critics go all out

The deadline to complete the biggest and most contentious merger in the history of Canadian telecom is nearing, and critics are pursuing their crusade against the deal.

Channel Bytes February 17, 2023 – Proofpoint launches simplified partner program; Exchange Server 2013 support ending; SASE market to hit US$60 billion by 2027; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Feb.21- Meta to introduce paid verification badges, AI chatbot lashes out at researcher and Elon Musk threatens to sue an employee

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Feb. 20, 2023 – A business email scam group is broken in Europe, GoDaddy’s IT system hit again and more

Listen to the latest episode of Hashtag Tendances

If you live in Québec, or prefer to consume the latest technology news in French, our sister publication Direction Informatique has you covered. Follow them on Twitter as well.

The post Coffee Briefing Feb. 21 – Government of Canada announces new Indigenous council, Zapier’s National No-Code Day contest returns; York University launches post-graduate certificate in CloudOps; and more first appeared on IT World Canada.