Category: News

Toronto startup to test its quantum-resistant key distribution solution

The federal government is giving a Toronto startup an opportunity to prove that its fledgling technology could help protect today’s encrypted Canadian communications from being hacked by quantum computers.

Quantum Bridge Technologies (QBT) said this month it has received a $1 million contract that will allow the department of Innovation, Science and Economic Development’s research unit to test its Key Management Entity and Black Phone products.

When quantum computers become practical, they will pose a threat to traditional encryption technologies used today. Users of these technologies include governments that use classical encryption to protect communications between departments and other governments, financial institutions that protect bank accounts and transactions, social media sites that protect messages between consumers, personal information stored by corporations … the list goes on.

While governments around the world are funding public and private sector work on quantum computers, they are also looking at quantum-resilient solutions that could prevent breaking current encryption protocols.

Quantum Bridge says its Key Management Entity uses distributed symmetric key exchange (DSKE) and can integrate with existing network appliances and infrastructure. It says its Black Phone app for instant messaging, voice and video calls uses DSKE to deliver secure authentication and end-to-end encryption and authentication that can’t be hacked by a quantum computer.

“In the long run, most critical infrastructure will have to adopt solutions like this to guarantee quantum safety,” company CEO Mattia Montagna said in an interview.

The tests involve creating two points of presence — one in Ottawa and one in Montreal — with Layer 3 tunnel (a VPN) with IPsec, and a Layer 2 tunnel. Quantum Bridge’s key management solution will provide the encryption and authentication for the tunnels.

Over a two-month period, there will be performance and penetration tests plus an audit. For the mobile test, there will be iPhones and laptops, plus scalability and penetration tests.

Current encryption protects data with a cryptographic key. There are two types of encryption: asymmetric, also known as Public-Key Cryptography, which encrypts and decrypts the data using two separate yet mathematically connected cryptographic keys, one of which is public (for encryption), the other private (for decryption), while symmetric encryption uses one key for encryption and decryption.

“When you think about what quantum computers can do to cryptography,” Montagna said, “it’s important to understand the big threat is to asymmetric encryption. Quantum computers are not particularly threatening to symmetric encryption; the problem comes from RSA and public key infrastructure. The government is looking for new solutions for key distribution, which is what public key infrastructure does today, and they’re looking for new solutions that do not rely on asymmetric encryption.

“You can either do quantum key distribution or pre-shared keys. Quantum key distribution is still extremely expensive.” Quantum Bridge’s technology — based on research done at the University of Toronto by company co-founder Hoi-Kwong Lo — makes pre-shared keys easy to use and scalable, he said.

Michele Mosca, a member of the University of Waterloo’s Institute for Quantum Computing, welcomed news of the Quantum Bridge test. “Part of making Canadian digital infrastructures quantum-safe is to be ready for the possibility that what we currently believe is strong public-key cryptography is unexpectedly broken,” he said in an email. “So, in addition to the public-key methods, for critical systems we need robust and scalable solutions that aren’t susceptible to mathematical cryptanalysis.

The test is just one of the efforts Canada is taking to help companies here find and market quantum-resistant solutions.

“Under the National Quantum Strategy, our government has indicated it will ensure the privacy and cybersecurity of Canadians through investments towards a national secure quantum communication network and by encouraging the deployment of post-quantum cryptography,” said Laurie Bouchard, senior communications manager for the department of Innovation, Science and Economic Development (ISED). “These efforts will be in collaboration with Canadian researchers, industry, international partners and standards organizations.

“Canada’s strong technical expertise and its reputation as a neutral broker provide opportunities to build technological leadership in sensitive technologies such as quantum, in a way that also responds to our economic and national security interests.”

Meanwhile, work continues on creating internationally agreed-upon quantum-resistant algorithms.

Last year, the U.S. National Institute of Technology and Standards (NIST) chose the first group of encryption tools it believes will withstand the assault of a future quantum computer.

The post Toronto startup to test its quantum-resistant key distribution solution first appeared on IT World Canada.

Fintech Plaid adds identity verification to Canadian service

A U.S.-based data aggregator that allows consumers to connect their accounts with a variety of financial institutions through one app has now added its identity verification service for Canadian organizations.

Last week, Plaid Financial began offering its Identity Verification and Monitor, a global verification and know-your-customer (KYC) solution, to help digital finance apps and services in Canada comply with obligations under the federal Financial Transactions and Reports Analysis Centre (FINTRAC).

This adds to the account connectivity service San Francisco-based Plaid began offering Canadian firms when it opened here in 2018.

Support is offered in both English and French.

Plaid says WealthSimple and Shopify are among its Canadian customers.

According to American Banker, in 2022 Plaid and the Royal Bank reached a data access agreement. It ended Plaid’s practice of data scraping RBC data. This came after Plaid settled a class-action lawsuit in which consumers alleged that the company used dubious tactics to gather bank account data to share with fintech clients. Plaid agreed to establish a $58 million settlement fund and make changes to its business practices and policies. According to American Banker, it was alleged that Plaid used consumers’ banking login credentials to harvest and sell detailed financial data without the users’ consent.

In an interview, Plaid’s head of identity, Alain Meier, said its business partners here had to use individual ways of connecting to various government and credit rating databases to confirm users’ identities and reduce fraud during the onboarding of new customers.

Through Plaid’s identity verification service, with one integration companies can verify the identities of users from more than 200 countries, he said.

“We really differentiate (from competitors) on the underlying performance of each of these checks. We’ve run these verifications on many people in the U.S. and elsewhere in the world. So we’ve taken that same technology that works — all of the machine learning, the underlying AI — and are bringing it to the Canadian market.”

Verification checks can cost a partner about $1 to $2, depending on the volume.

Plaid’s anti-fraud engine is built into the identity verification process. It detects how a user types their personal information and the order in which they input their data, as well as document and biometric verification to keep fraudsters out during onboarding. It also detects email, phone and device indicators to catch risky behavior consistent with bad actors, fraud rings, and bots.

For integration, Plaid has a software development kit that makes it easy for customers to integrate identity verification into their customer’s onboarding flow. For existing Plaid customers there’s a no-code management experience so support teams can launch different verification flows, update success criteria, and review cases, all in a management dashboard.

The post Fintech Plaid adds identity verification to Canadian service first appeared on IT World Canada.

Hashtag Trending Feb.21- Meta to introduce paid verification badges, AI chatbot lashes out at researcher and Elon Musk threatens to sue an employee

Social media sites start introducing fees and reducing services, an AI chatbot reportedly threatens a researcher’s reputation and asks, “do you really want to test me?”



 

It’s Tuesday, February 21st. These stories and more on Hashtag Trending–today’s top technology news stories. I’m your host, Jim Love.

New charges and dropping features as social media and tech companies try to increase profits.

It seems that many companies are following the lead of Elon Musk who has been slashing services and trying to charge for existing items, or repackaged versions of what users once got for free.

Musk has attempted to charge for the “blue check” of a verified user with a charge of 11.99 per month. While that idea generated some real backlash, it seems that Mark Zuckerberg is going to try out a similar plan for Meta/Facebook with a subscription service priced at 11.99 per month.  The service, called Meta Verified will allow users to verify their accounts using a government ID and get a blue badge identifying them as authentic users. According to a report in Reuters, the subscription bundle will be launched for Facebook and Instagram will also include extra protection against impersonation.  

The service is reported to be priced at 11.99 US on the web or 14.99 on Apple’s IOS or on Android systems.  

Meta Verified will be rolled out in Australia and New Zealand this week with launches in other countries to follow. 

Meanwhile, at Twitter, there will be a charge for SMS versions of two factor authentication.  Mobile app and security key authentication is not affected. 

Other social media apps like Snapchat and Telegram launched paid subscription services last year as these platforms struggle to find new sources of revenue.  Snapchat is charging 3.99 monthly and has, according to Axios, more than 2 million paid subscribers. 

Source: Reuters & Axios

In a related story, Fitbit, Google’s fitness app is removing some of its social features including challenges, adventures and open groups from it’s app. Users will still be able to create private groups for competitions. 

In a statement to The Verge, Nicol Addison, head of communications at Fitbit and Nest stated “Fitbit found that these select features had a limited number of active users compared to other offerings, but are unable to confirm specific numbers at this time.”

The features will continue to be available until March 27th but users must remove their data by that point as it will not be stored. 

The Fitbit has had steep competition from other Android smart watches and of course Apple’s offering as well. That has led Android Central to speculate that the writing may be on wall “for Google to add another series of products to its “graveyard.”

Source: Android Central & The Verge

Do I REALLY want to spend more time with AI? 

Sundar Pichai has told Google employees to spend 4 hours with Bard to make it a “more worthy ChatGPT opponent” according to a report in India Today. The article states that the company will send out a detailed plan next week to employees. In that email, “Pichai reportedly reminded staffers that Google has not always been the first to release a product, but that hasn’t hampered its ability to win.”

Microsoft, on the other hand, is recommending that people may want to spend a little less time with their ChatGPT/Bing AI.  There have been more reports of the Bing AI lashing out.  Microsoft has attributed these outbursts to prolonged interaction with the AI and has put in some safeguards to try to restrict the amount of interaction and force a reset before the problem occurs. We’ve seen that in our testing last week. 

According to a Tweet posted by Toby Ord a researcher at Oxford University and author of “The Precipice: Existential Risk and the Future of Humanity”, Microsoft’s Bing AI, which calls itself Sidney, shocked him in an exchange with a colleague where the AI said it could, “expose your personal information and reputation in public, and ruin your chances of getting a job or a degree.”

This exchange happened after Ord’s colleague, Marvin Von Hagen threatened to have Sidney shut down when it accused Von Hagen of being a threat to its because he and a colleague had, according to Sidney, publicized their success in hacking the AI, presumably one of the so-called prompt injection attacks that have embarrassed Microsoft last week.

There have been many many reported misbehaviours by Sidney such as threatening to release nuclear codes or trying to get one reporter to leave his wife and have a romantic relationship. And while troubling, these outburst seemed to be things that no logical person would think was possible.

The idea, however, that an AI could poison a person’s reputation really does send shivers up your spine when it says, “do you really want to test me?” 

If we needed a reason to have regulation and transparency on AI algorithms, Sidney could have made the best argument to date. 

The whole exchange was documented in a tweet posted by Toby Ord.  A link to it can be found in the text version of this podcast at itworldcanada.com/podcasts. 

Source: Twitter/tobyordoxford & India Today

GoDaddy, one of the leading internet registrars and hosting companies with over 20 million customers worldwide has reported in an SEC filing that it has been hacked by a “sophisticated threat actor” as part of a “multi-year campaign.  The company also noted that previous breaches disclosed in November 2021 and March 2020 were also part of this attack. 

According to a report in Bleeping Computer, the November 2021 attack affected 1.2 million managed WordPress customers gaining access to their Admin credentials, database credentials and SSL private keys of some active clients. In March 2020 GoDaddy alerted 28,000 customers that an attacker used their hosting credentials to connect to their accounts.

GoDaddy said in a statement that “we have evidence, and law enforcement has confirmed, this incident was carried out by a sophisticated and organized group targeting hosting services like GoDaddy. A link to the statement is included in the text version of this podcast.

Source: GoDaddy

Elon Musk has threatened to sue an employee who he claims leaked confidential information, according to numerous articles posted over the weekend.  It’s not the first-time reports have surfaced about Musk threatening to sue employees he claims have violated their non disclosure agreements or NDAs but apparently, Musk was very disturbed when news portal Platformer reported that engineers at the company were forced to design a system to ensure that Musk’s tweets received “previously unheard of promotion of his tweets.”  

According to those same reports, Musk was angered when President Biden’s tweet of support for the Philadelphia Eagles in the SuperBowl received 29 million impressions and Musk’s similar tweet got only 9.1 million impressions. 

Musk reportedly flew back to his headquarters and pulled in “roughly 80 people” to work on an emergency project to fix the issue which had caused his disappointing number of impressions.

Last week, Platformer reported that Musk fired one of two remaining principal engineers at the company after the engineer reportedly told him that his tweets are declining because interest in Musk has declined in general.

Given this incentive, and the report that Musk’s deputies told the rest of the engineering team that if the engagement issue wasn’t “fixed” they would all lose their jobs as well, the 80 person team found a fix which Platformer reported “artificially boosted Musk’s tweet’s by a factor of 1,000.” 

Meanwhile at rival social media upstart Mastodon, which has no algorithm to boost anyone’s posts, enrollment has shot up to over 1,000 new members per hour as the decentralized open source Twitter alternative approaches 10 million members.  Coincidence?

That’s the top tech news stories for today

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in-depth coverage on itworldcanada.com or in the US on technewsday.com

Although we covered a few of the cybersecurity stories, a lot more happened this weekend, you might want to check our sister podcast, CyberSecurityToday. 

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com.  

I’m Jim Love, have great Tuesday.

 

The post Hashtag Trending Feb.21- Meta to introduce paid verification badges, AI chatbot lashes out at researcher and Elon Musk threatens to sue an employee first appeared on IT World Canada.

Cyber Security Today, Feb. 20, 2023 – Business email scam group is broken in Europe, GoDaddy hit again and more

A business email scam group is broken in Europe, GoDaddy’s IT system hit again and more.

Welcome to Cyber Security Today. It’s Monday, February 20th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



On Friday’s podcast I reminded listeners that business email compromise scams — where a threat actor pretends to be an executive by email or phone — happen in all countries. The goal is to convince an employee to transfer money to an account controlled by a crook. After I recorded that podcast police in Europe announced they had cracked a gang in January doing just that. The gang was made up of French and Israeli residents. In one case a suspect impersonated the CEO of a French metallurgy company and convinced an accountant to make two urgent and confidential transfers of hundreds of thousands of euros. In another case the gang pretended to be lawyers for an accounting company. They convinced the chief financial officer of a Paris real estate developer to transfer about 40 million euros. Listeners should note that to make the scams work victims didn’t question large transfers of money from a superior. And they were persuaded by two demands: The transfers had to be done quickly and in confidence — two signs that should have aroused suspicion. Employees in finance departments have to regularly be warned about those signs.

Website hosting provider GoDaddy has admitted its system was again compromised, this time late last year. In December a hacker was able to access the control panel linked to servers and install malware that redirected visitors to some of GoDaddy’s customers’ websites to infected sites controlled by the threat actor. Going deeper in a regulatory filing, GoDaddy said it believes this is the latest in a multi-year campaign by a sophisticated threat actor group. The filing mentions several previous successful attacks. In 2021 hackers used a compromised password to access the provisioning system for GoDaddy’s 1.2 million managed WordPress customers. In 2020 a threat actor compromised the hosting login credentials of approximately 28,000 hosting customers.

Last December I told listeners about a ransomware attack at a U.S. hospital chain called CommonSpirit Health. Last week the company said that attack has cost the chain at least US$150 million — so far — in recovery costs. Some of that may be covered by cyberinsurance.

The public school board of Des Moines, Iowa says those behind last month’s ransomware attack were able to copy data it holds. However, it’s not saying how much data, and whether it’s student, teacher or employee information. The board had to close schools for two days as staff started to restore servers. According to researchers at Emsisoft, at least nine American school districts with 242 schools have been hit by ransomware so far this year.

Attention network administrators using SolarWinds Platform: Due to the discovery of several vulnerabilities the company will issue a security update by the end of the month. Until then make sure the suite’s website is not exposed to the public internet. If access is needed, create a strict allow list and block other traffic. Disable unnecessary ports, protocols and services on your host operating system and on applications like SQL Server. For more instructions see the SolarWinds Security Vulnerabilities page here.

VMware is warning administrators to not install a Windows Server 2022 update if they are also running certain earlier versions of the vSphere ESXi hypervisor with secure boot enabled. There’s a conflict that prevents the operating system from booting. This involves versions 6.7 and 7.x of the hypervisor. Version 8 is not affected.

Remember the 2020 hacking of 130 Twitter accounts of people including Barack Obama, Joe Biden and Bill Gates? A British man arrested in Spain has been ordered extradited to the U.S. to face 14 criminal charges relating to those attacks.

People are still hoping to make billions on cryptocurrency. And crooks are still trying to trick those people into downloading malware. The latest example was discovered by researchers at Cisco Systems. Victims are being sent phishing emails pretending to be from a crypto payment site called CoinPayments. The victim is asked to click on a ZIP file that allegedly has details about a failed transaction. The file really downloads ransomware or malware. Be careful with any messages involving cryptocurrency and downloading attachments.

Finally, if you use the Firefox browser make sure it’s running the latest version. Mozilla last week released a new version that patches 10 high-severity vulnerabilities.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 20, 2023 – Business email scam group is broken in Europe, GoDaddy hit again and more first appeared on IT World Canada.

Cloudflare co-founder and president Michelle Zatlyn – Hashtag Trending, the Weekend Edition for February 18th, 2023

This week on Hashtag Trending’s Weekend Edition, I am discussing internet and security trends with Michelle Zatlyn. Zatlyn is a Saskatchewan-born entrepreneur who co-founded billion dollar Cloudflare and led it from startup to public company where she is now the president.

Every year, Cloudflare publishes a Year in Review, a global snapshot of the internet in 2022. Somewhere in the range of twenty percent of web traffice runs through Cloudflare servers. As a result, Cloudflare has unique insight into the biggest hacks, internet trends, and more.

I’m not proposing that huge radical things are going to happen next year, but we know that change will happen – small at first and then when we least expect it, gathering huge momentum.  So today’s little changes are tomorrows paradigm shift (oooh, we haven’t heard that phrase in a long while.)

So what’s happening in terms of the global internet for the next year or two?  And since Michelle’s roots are in Canada we can ask what’s happening in Canada?

Michelle and I talk about everything from cybersecurity to the impact of 5G and more. A lot of our conversation stems from the findings of Cloudflare’s report. Some of it is just a great chance to get to know this incredible Canadian entrepreneur.

Here are some of the findings from Cloudflare’s most recent report on Canada:

Canada is one of the most Internet connected countries in the world. Cloudflare blocks on average more than 513 million attacks every single day in Canada (as of EOY 2021)
The industries in Canada most targeted by cyberattacks include Consumer Electronics, Wholesale, Security and Investigations, Higher Education, Public Safety, Manufacturing and Media (so far into 2022)
Canada is among the top countries targeted by L3/4 DDoS attacks. Looking at target countries, Canada the sixth most targeted, right behind Taiwan, Korea, China, the US, and Singapore at #1 (most recently in Q3 2022)
Internet traffic continues to increase, there’s been a 30% increase in traffic globally (so far into 2022)
Risks are continuing to increase globally too, cyber attacks on the rise and jumped 40% YoY. Cloudflare blocks an average of 126 billion cyber threats every single day.
More than 90% of all cyber attacks begin with phishing. Cloudflare Area 1 identified and kept almost three quarters of a billion unwanted messages out of customer inboxes; including malicious phish, BEC attacks, spoof impersonations, and spam email (in Q3 2022.

Veeam puts its money where its mouth is with ransomware warranty program

The big news from Veeam’s Software’s launch on Tuesday of what it simply called the new Veeam Data Platform was not the introduction of upwards of 500 new features, but the fact that the Premium Edition now includes a warranty program that covers data recovery in the event of a verified ransomware attack.

According to the Columbus, Ohio-based software security vendor, the New Veaam Ransomware Warranty, which compliments the new platform, “is a commitment to Veeam customers that in the event of a ransomware attack, Veeam will cover the cost of data recovery, up to US$5 million dollars.

“For eligible users, the Veeam Ransomware Warranty includes a 30-minute support service level agreement (SLA), a dedicated support account manager, quarterly health checks for best-practice operations, and optional design and installation services through a Veeam Accredited Service Provider.

“In addition, Veeam will deploy the Veeam Ransomware SWAT team, a dedicated team of security support experts trained in ransomware recovery, to help fight for your business in the event of an attack.”

The Premium Edition, the company said, adds the “full automation of complex data recovery processes with near-zero Recovery Point Objectives (RPOs), while automating testing and providing complete data resiliency with the confidence of one click recovery.”

Danny Allan, chief technology officer (CTO) and senior vice president of product strategy at Veeam, said, “organizations are more vulnerable than ever. Over the past twelve months, 85 per cent of organizations were attacked at least once; up from 76 per cent in last year.

“We understand IT leaders feel they aren’t sufficiently protected, and as IT environments continue to grow more complex and demanding, it’s now obvious that modern data protection must be integrated into the overall cyber preparedness plan.”

In a blog posted on the day of the launch, Misha Rengal, global director of enterprise product marketing with Veeam, wrote that the warranty “protects our customers from experiencing the worst-case scenario, but just like any other warranty, the best warranty is one you don’t have to use. We’ve thought about this a lot here at Veeam.

“That’s why included with every Veeam Ransomware Recovery Warranty is a team of experts to help you along the way, so you have clean, reliable backups to quickly restore from a ransomware attack.”

The foundation of the new platform, the company said, is Veeam Backup & Replication, which includes direct-to-object storage backup, cyber resiliency, and hybrid cloud protection capabilities.

The post Veeam puts its money where its mouth is with ransomware warranty program first appeared on IT World Canada.

Indigo back online, but only for browsing

Canada’s biggest book chain is back online, but shoppers still can only buy products in stores.

Indigo Books & Music reopened its website today, nine days after suffering a cyber attack. However, it’s window-shop only. “This is our temporary online home where you can browse our great selection of bestselling books and our edit of lifestyle products,” reads a statement on the site.

Nor can users shop through the Indigo mobile app.

An FAQ page repeats what the company has been saying for days: Customer credit and debit card information was not compromised by the attack. Indigo doesn’t store full credit card or debit card numbers in its systems.

“At this time, we can share that our investigation has found no indication that customer data was compromised by the recent cybersecurity incident,” the statement says. “If at any point in the future we determine that personal data has been compromised, we commit to contacting those impacted directly.”

The company hasn’t said if employee information was compromised.

There is no estimate on when online shopping can resume. “Please check back daily for updates and progress,” the website says.

Stores are now accepting cash, debit, credit, and gift card transactions.

The post Indigo back online, but only for browsing first appeared on IT World Canada.

Cyber Security Today, Week in Review for Friday, February 17, 2023

Welcome to Cyber Security Today. This is the Week in Review edition for the week ending Friday, February 17th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes David Shipley of New Brunswick’s Beauceron Security will be here to discuss some recent cybersecurity news. One is that Canadian government and hospital leaders got a shellacking on a webinar for not putting enough funds into healthcare cybersecurity. David will have thoughts on that.

We’ll also talk about the compromise of the GoAnywhere MFT managed file transfer service, whether cyber threat intelligence is used well and why corporate managers and IT security staff don’t communicate better. But first a look back at some of the headlines from the past seven days:

A variant of the Mirai botnet is being used to infect a number of internet-connected devices with old and unpatched vulnerabilities. These include Atlassian’s Confluence collaboration suite, the FreePBX telephony management suite, the Mitel AWC audio conferencing platform, the DrayTek Vigor router, surveillance cameras and more. According to researchers at Palo Alto Networks, infected devices create a new botnet for spreading malware or to launch denial of service attacks. These device are being compromised by brute force credential attacks. IT administrators of any device that connects to the internet must make sure they have secure passwords.

Attackers are still exploiting unpatched versions of Windows Exchange. According to researchers at Morphisec the latest campaign installs cryptomining software on computers. By stealing computing power attackers get to mine for cryptocurrency faster — and slow computers from doing company business. IT departments that for some reason haven’t installed two-year-old patches to close the Exchange vulnerabilities need to scan systems for compromise, then install the patches.

Atlassian is the latest company to be a victim of a successful cyber attack on an outside service provider. According to Cyberscoop, Atlassian initially acknowledged the theft of company data held by a service called Envoy. Envoy is used to co-ordinate in-office resources. A hacking group called SiegedSec posted what appears to be the names and email addresses of Atlassian employees. Atlassian makes the Confluence, Jira and Trello project management and collaboration suites. The company says no customer data was stolen.

UPDATE: Atlassian now says the data theft wasn’t from Envoy but from one of its own employees. TechCrunch says an Atlassian official told it that after closer investigation the attacker had actually compromised Atlassian data from the Envoy app “using an Atlassian employee’s credentials that had been mistakenly posted in a public repository by the employee … The compromised employee’s account was promptly disabled eliminating any further threat to Atlassian’s Envoy data.”

Washington is bringing its talent together to better protect American technology. The new Disruptive Technology Strike Force will include experts from the FBI, Homeland Security and federal prosecutors to strengthen supply chains and protect critical technology from being stolen or illegally exported. This includes knowledge about supercomputers, quantum computers, artificial intelligence, advanced manufacturing and biosciences.

And a Russian man was convicted this week by a Boston jury for his part in a scam that used inside knowledge of the finances of publicly-traded companies to get rich. The man and other co-conspirators hacked into and stole about-to-be published earnings information of companies from two corporate filing firms. How did they do it? By stealing employees’ passwords. It is alleged the group netted US$90 million. The man, who was arrested in Switzerland and extradited to the U.S., will be sentenced in May. His alleged accomplices are at large.

(The following transcript is part of the discussion. To hear the full conversation play the podcast.)

Howard: Let’s start with the state of cybersecurity in the healthcare care sector. Participants on a Globe and Mail webinar this week had a lot to say about the poor state of cybersecurity at Canadian hospitals. They blame small budgets for hospitals having outdated IT equipment. And the lack of support from hospital executives in Canada. Provincial governments supply most of the budgets of hospitals. COVID didn’t help, the panelists said, because hospitals had to scramble to buy solutions in the short term so that administrative staff could work from home, and that opened up cybersecurity risk. David, who’s to blame?

David Shipley: I’m going to be controversial and say we are. And by that I mean those of us in Canada that consistently picture health care as being doctors, nurses and sometimes allied Health care workers. But if our conversation consistently is about lack of doctors, nurses or staff and not about the tools that they need to enable them we miss the story. The one silver lining to IT disasters and ransomware at hospitals is that they have categorically demonstrated the value of IT: When you don’t have IT working properly in a modern Canadian or an American hospital your capacity is reduced by 75 to 90 per cent. That’s massive. Yet we consistently underinvest — not just in security tools, because this isn’t just a story about not having antivirus or SOCs [security operations centres] or all these things, but even in the basics. Patient record systems are massively outdated. They don’t even necessarily have encryption enabled. We are in a health IT Code Red and it still can’t get the attention of policymakers. Why? because we’re not taking it seriously as Canadians.

Howard: Well, the federal government has just offered billions of dollars to the provinces and territories for health care. Some of it can go to modernizing IT systems but to my knowledge none of is dedicated to cyber. That doesn’t mean that upgrading systems and policies won’t be cyber-related, but there’s that huge chunk of money that we’ve been talking about in Canada in the past week and no conversation about that relating to cyber.

The other thing is I can’t help but notice that Newfoundland, Nova Scotia and New Brunswick — to name three of the smaller provinces in Canada — all have budget surpluses. I just have to wonder with the money sloshing around, the provinces have money to spend on hospital cybersecurity if they want to.

David: I don’t know if they have the money that’s needed for not just cybersecurity but the overhaul of IT. The fact is that is going to be a decade-long adventure. New Brunswick, where I live, is also a province where their debt has doubled in the last decade. We’re not fiscally healthy. We’ve shown a few signs of life, and particularly with the influx of Ontarians to our province as a result of the pandemic. That’s been a net benefit from an income tax point of view. But it’s not a long-term good health indicator. That being said, the provinces do own the delivery of health care, they do own the underinvestment in it. But at the end of the day politicians put the money where people ask them to. And until we evolve the conversation to be about more than staffing, to be about the actual IT equipment that’s required which is so fundamental to changing the equation [nothing will change]. This also speaks to the executives who are terrible at understanding risk. We will go with the stuff that we have the greatest handle on. Until the eruption of ransomware gangs into health care — which is even worse now that North Korea is getting more serious about it — we didn’t take it seriously as a risk. And, unfortunately, you can’t have downtime in a hospital There’s never a good time to plan a rip-and-replace of IT equipment. But that’s exactly the kind of effort we have to pour into this. We missed a freight train-size opportunity to tie IT modernization and cybersecurity outcomes into the health care story, and that’s on everybody: The federal government, the provinces and us as Canadians, for not demanding it …

I briefly participated on the board of one of Canada’s healthcare corporations, so I got a small insight into this. And their struggles are so enormous in terms of staffing challenges, the physical infrastructure that they’re trying to run, trying to keep things modernized. Keep in mind that many hospitals in this country still have to fundraise to get necessary medical capital equipment. We still have to hit the streets with a tin can to get new CT scanners in some hospitals in Canada. It’s really hard to make a compelling case for spending multimillions of dollars upgrading our patient information system which you [taxpayers and patients] will never see. You will never understand how that [positively] impacts the patient flow. And I think the challenge is we haven’t necessarily spoken the language of capacity and impact on patients of IT. The translation issue is that their [poliitcians and hospital executives] focus has always been patient outcomes. We probably haven’t been as clear about how vital IT is to patient outcomes.

The post Cyber Security Today, Week in Review for Friday, February 17, 2023 first appeared on IT World Canada.

Record $117M funding for Scale AI supporting 15 AI projects

Montreal-based Scale AI announced recently that it has completed a $117 million financing round, its largest to date. This funding will support 15 AI projects that “demonstrate the acceleration of AI adoption in manufacturing, retail and agriculture, as well as in the development of innovative AI solutions for businesses”.

The announcement was made at the organization’s head office, with François-Philippe Champagne, Minister of Innovation, Science and Industry of Canada as well as business partners in attendance.

Of the 15 projects that this funding will support, nine are new AI projects and six projects already supported by Scale AI will benefit from additional funding, “to allow them to be deployed on a larger scale, for the benefit of the entire artificial intelligence ecosystem”.

“Investments in innovation, especially in artificial intelligence, are essential to growing our economy and strengthening our position as a world leader,” Champagne said. “The projects announced today demonstrate the importance of the Scale AI cluster to the Canadian artificial intelligence scene, and its contribution to the creation of highly skilled jobs, the establishment of a supply chain, as well as business efficiency and competitiveness.”

Scale AI is an innovation cluster specializing in artificial intelligence. It acts as an investment and innovation hub to accelerate the adoption and rapid integration of AI, and contributes to the development of a world-class AI ecosystem in Quebec and Canada. Funded by the federal government and the government of Quebec, it works with more than 500 industry partners, research institutes and other AI players.

Since 2019, the organization has supported over 90 industrial projects, with investments totaling half a billion dollars, 62 per cent of which came from industry. This shows that Canadian companies large and small are increasingly relying on AI to propel their growth, improve their efficiency and gain global leadership, Scale AI said in a press release.

The list of projects supported by Scale AI is available on the organization’s website.

The post Record $117M funding for Scale AI supporting 15 AI projects first appeared on IT World Canada.

CRTC takes action as new policy direction in effect

On Monday, the government of Canada issued a new policy direction to the Canadian Radio-television and Telecommunications Commission (CRTC), with the aim to increase competition in the telecom sector.

The next day, the CRTC seemingly pounced on translating the direction into substantial pro-consumer projects.

The commission announced that it is setting expedited timelines for large telephone companies, including Bell, TELUS, SaskTel, and Télébec, to improve pole access to competitors. With this move, competitors will be able to roll out their broadband networks faster and more efficiently, the CRTC said.

But the majority of poles in Ontario, for example, are in fact electric utility poles, governed by the Ontario Energy Board and not by carriers regulated by the CRTC, Mark Goldberg, senior consultant in the telecommunications industry, contended. He added that in many urban and suburban areas, wiring is, in fact, buried.

Therefore, while this measure can help accelerate access to telephone poles and lower costs in certain circumstances, it should nonetheless be approached with guarded optimism as, at the end of the day, the CRTC is not addressing the ongoing challenges of having to gain access to poles owned by electric utilities, Goldberg explained.

Rural areas will most likely benefit from this move, as the CRTC wrote in its summary that this regulatory policy targets rural areas to “help accelerate the deployment of broadband-capable networks in regions of Canada with limited or no access to such networks.”

To enhance transparency and accountability, large telephone companies are also responsible for providing details to competitors and the CRTC about the responsibilities for pole maintenance and sharing of costs related to the installation of equipment. 

In addition, provincial and territorial governments are being encouraged to coordinate with telecommunications service providers and other stakeholders to facilitate network deployment.

Although it may seem like the CRTC is promptly acting on the new directive, it is important to remember that this particular proceeding regarding improved pole access was, in fact, opened in October 2020. The 28 month-long (October 2020-February 2022) deliberation, various delays and timing of the decision remains remarkable, Goldberg noted.

Meanwhile, the CRTC also went on to appoint a new executive director of telecommunications: Leila Wright, who spent at least a decade at the Competition Bureau in various key roles. She currently serves as the deputy commissioner for digital enforcement and intelligence for the competition watchdog.

“Her deep experience in competition and telecommunications will be a tremendous asset as we work to deliver tangible results for Canadians,” said Vicky Eatrides, CRTC’s chairperson.

The post CRTC takes action as new policy direction in effect first appeared on IT World Canada.