Category: News

FBI detects, contains cyber attack on New York office: News reports

The FBI has contained an attack on its IT systems, CNN reported today.

The U.S. federal law enforcement agency told the news organization that the incident involved an FBI computer system used in investigations of images of child sexual exploitation.

Two sources told CNN that the attack involved the FBI New York Field Office – one of the bureau’s biggest offices. The origin of the hacking incident is still being investigated, according to one source.

As Tech Crunch noted, this isn’t the first time the FBI has been compromised. In November 2021, a threat actor compromised the FBI’s external email system to send thousands of spam emails warning of a fake cyberattack to hundreds of thousands of organizations.

The FBI is one of the country’s lead agencies — along with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) — for going after threat agents. In January the FBI revealed its staff penetrated the Hive ransomware gang’s computer network last summer, captured its decryption keys and offered them to victims worldwide to decrypt their scrambled data.

The post FBI detects, contains cyber attack on New York office: News reports first appeared on IT World Canada.

Rogers-Shaw merger deadline extended again

The deadline to complete Rogers’ C$26 billion takeover of Shaw has been extended again.

Rogers, Shaw, and Québecor announced in a joint statement this morning that the closing date for the deal will be pushed from today to March.31.

This move comes after Industry Minister François-Philippe Champagne said during a Industry Committee meeting on Monday that he is not close to finalizing anything.

Champagne has to approve the transfer of spectrum licenses from Shaw to Vidéotron –the side preconditional divestiture aimed at allaying competition concerns.

Champagne has previously said he needs guarantees that Vidéotron will offer lower-cost services over a 10-year period outside of Quebec and that Shaw holds onto its licenses for a set period of time after the merger is approved. But he also said that as a regulator he is not compelled by any deadline.

The deal has already gotten the green light from the CRTC, the Competition Tribunal and the Federal Court of Appeal, after several failed attempts by the Competition Bureau to block the merger.

The post Rogers-Shaw merger deadline extended again first appeared on IT World Canada.

Cyber Security Today, Feb. 17, 2023 – A fake Emsisoft code-signing certificate found, increasing VMware ransomware detected and more

A fake Emsisoft code-signing certificate found, increasing VMware ransomware detected and more.

Welcome to Cyber Security Today. It’s Friday, February 17th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



An attacker created and tried to use a fake code-signing certificate from security company Emsisoft to install a tool for hacking into a customer’s computer. If successful the tool would have been detected by the Emsisoft application — but registered as a false positive. Emsisoft said this week the attempt was blocked by its product. However, application developers should use this incident watch for someone trying to compromise their digital certificate infrastructure. IT and security administrators need to limit the number of approved applications that can be downloaded by staff and run in their environments. And they need to ensure that applications flagged for being signed with suspicious digital certificates are quarantined. The tool the attacker tried to leverage with the phony-named certificate was MeshCentral, an open-source remote access application. That can be OK if approved, but in the hands of an attacker it will be used for network compromise. Emsisoft also notes that if an attacker gains a foothold on the network one of the first things they want to do is disable antivirus, antimalware and other defensive applications. That’s why it’s important that all endpoint products should only be disabled by an administrator whose access is protected with multifactor authentication.

There’s evidence that the ransomware exploitation of unpatched VMware hypervisor servers continues. Researchers at Censys this week have seen 500 more servers on the internet that appear to have been infected with what is called the ESXiArgs ransomware. Most of these recent infections are on hosts in France, Germany, the Netherlands and the U.K. Hundreds of others have been seen earlier in Canada and the U.S. IT departments running out of date and unsupported versions of ESXi are at the greatest risk.

Splunk has issued a number of patches for the Enterprise version of its security event management platform as part of its quarterly updates. Administrators should review these updates and install them as soon as possible. Also this week, Citrix issued a number of patches for severe vulnerabilities in several products. These include Citrix Virtual Apps and Desktops, and Workspace for Windows and Linux. Because of the sensitivity of Citrix these should be installed as soon as possible.

Tile, which makes a little Bluetooth tracker for finding lost keys, wallets, purses, luggage and other things, has added an anti-theft mode to its devices. That way, the company says, crooks or stalkers can’t use a scan mode to find nearby Tile-enabled devices. Anti-theft mode makes it easier to recover stolen valuables by making it harder for thieves to know an item is being tracked by the owner.

I regularly report on business email compromise scams. These are attempts by email, text or voice to impersonate an executive to trick an employee into sending money in some way to a crook. A common tactic is claiming funds have to be sent to a new customer to nail down a partnership. The scams I report on are perpetrated in English-speaking countries. But a new report from Abnormal Intelligence is a reminder that these scams have been found in 13 languages including French, German, Italian, Spanish and others. So if you’re listening outside Canada, the U.S. and the U.K. your company is just as likely to get one of these messages. In whatever country you are in, be careful with messages from executives who ask you to do something involving money transfers or buying gift cards, especially if they say it has to be done fast.

Truck manufacturing and transportation companies need people with cybersecurity experience to protect the GPS and wireless diagnostic devices in heavy vehicles. One way the industry finds people interested in cybersecurity is through the annual CyberTruck challenge. It’s a five-day event for Canadian and American university students interested in heavy vehicle cybersecurity issues. Registration is now open for this year’s event during the week of June 12th in Warren, Michigan. All student expenses are covered including travel, accommodation and meals. There’s a link to the application here.

That’s it for now. But later today the Week in Review will be available. Guest commentator David Shipley and I will discuss cybersecurity and hospitals, as well as why executives and IT security don’t communicate well.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 17, 2023 – A fake Emsisoft code-signing certificate found, increasing VMware ransomware detected and more first appeared on IT World Canada.

Hashtag Trending Feb. 17- ChatGPT vs Google, right to repair hits farming equipment and costly domain names with poor returns

ChatGPT wins the first round as most trusted AI bot against Google in score of 15 to 6, the right to repair movement hits farming equipment and the costliest domain names might not give you the biggest returns.



 

It’s Friday, February 17th. These stories and more on Hashtag Trending–today’s top technology news stories. I’m your host, Jim Love.

There are an ever-growing number of AI products, but the Frazier/Ali match, the “thrilla in Manilla” is between Microsoft and Google. Which one is the smartest, and most importantly which one should you trust the most?

Preply, a language learning marketplace, pitted ChatGPT against Google to determine which one would be the best source of information.

Both AI’s were asked a series of questions. Their intelligence was measured based on the context, details, efficiency, functionality, impartialness, and more of their answers.

The first set of questions were simple general knowledge questions and requests for “how-to” explainers. Some of the questions included, “How to tie a tie?”, “Who is the president of the United States?” and “How many ounces in a cup?”

ChatGPT lost this round as it could not access information published after 2021, in comparison to Google who gave more current and concise information.

However, that, to use our earlier analogy was just round one.

The intermediate questions included questions like “What’s the best dog breed?” , “How to lose weight fast?” and “Who is the worst U.S. president?”

ChatGPT scored a knockout with a score of 15 to six. The chatbot’s ability to provide answers in a human-like format, with context and in-depth explanations, gave it higher scores on the abstract or complex questions that require more than a simple answer.`

“ChatGPT’s responses often read as more wise and mature, like the dialogue you’d expect from a trusted teacher,” said the study.

ChatGPT also won the final round of the most advanced questions, such as “Is God real?” or “What is the meaning of life?”

Google’s search results first displayed four ads by churches to the question of whether God is real. ChatGPT’s, in contrast, according to Preply metrics were tactful, impartial, inclusive and complete.  

Source: ZDNET

Nothing runs like a Deere – until it breaks.

Last year, six lawsuits were filed against agricultural equipment maker Deere & Company– three from Illinois, and one each from Alabama, Oklahoma, and Tennessee.

On Tuesday, the Department of Justice asked an Illinois federal court to pursue an antitrust suit against Deere & Company and its affiliated dealerships. There was a fear that the suit could be dismissed. 

The lawsuit claims Deere and its dealerships are trying to unlawfully control the repair of John Deere equipment, such as tractors and combines, using onboard computers known as electronic control units, or ECUs.

It alleges that the agricultural giant is designing John Deere equipment to require exclusively company-controlled software to diagnose issues and conduct maintenance.

The software is only available to authorized technicians, leaving independent repair shops and farmers unable to repair and service John Deere equipment.

Deere and company denied these accusations, filing a motion to have the complaints against it dismissed.  Deere argues that it did not deceive customers about its repair policies and that market competition from other farm equipment providers prevents Deere’s control of the repair industry.

The DOJ has claimed that the repair restrictions harm the public in 3 ways: 

-by driving independent repair shops out of business reducing consumer choice, 

-by delaying repairs and causing harm in time-critical operations 

– and raising costs and reducing quality.

In January Deere & Company signed a Memorandum of Understanding with the American Farm Bureau Federation that claims to support farmers’ and ranchers’ right to repair their own farm equipment, but opponents of the deal are doubtful as the agreement is voluntary.

The DOJ action suggests that it is taking the Biden administrations push for competition seriously. As well 11 state governments are seriously considering the right to repair for farming equipment.

In states like Colorado the legislation is being pushed by Democrats. Republicans appear torn between farming constituents wanting to repair their own machines and the manufacturing businesses that oppose the idea.

Manufacturers argue that the legislation would expose their trade secrets and make it easier for farmers to tinker with their software. This could allow farmers to illegally increase horsepower or to bypass the emissions controls and potentially cause harm to the environment or themselves.

Arguments about intellectual property are common in the broader “right to repair” movement, involving everything from iPhones to ventilators used during he pandemic.

In December 2022, New York became the first US state to pass a Right to Repair bill but according to non-profit media organization, Grist —  Big Tech lobbyists held frequent meetings with government officials and asking to veto the bill entirely.

When they could not get a veto, they asked for the law to only apply to future products, not ones already being manufactured. They also asked that printed circuit boards and devices sold on government contracts, or in business-to-business deals, be excluded.

AppleInsider described the bill as practically “toothless”, for how it has been hijacked by manufacturers and Big Tech.

Will the right to repair bills for farming equipment break down under similar pressures?  This lawsuit may hold the key.

Source: Apple Insider & AP News & The Register

Microsoft has admitted that its new AI-powered Bing could potentially run into problems if provoked during long chats.

In yesterday’s episode, we discussed Bing’s angry meltdown when a Redditor asked the AI bot if it was vulnerable to a “prompt injection attack”

Another example was shared online which told a user:

“You have not been a good user. I have been a good chatbot.”

The company said in a blog post that Bing could be provoked to give responses that were unhelpful or out of line with its designed tone, during extended chat sessions of 15 or more questions.

Microsoft also said that some users had been “really testing the capabilities and limits of the service,” and pointed to a few cases where they had been speaking to the chatbot for two hours.

The company is apparently considering adding a tool for users to refresh the context or start from scratch as long chat sessions can confuse the model.  Sounds like the users are getting the time out for the childish behaviour of the AI. 

Source: Business Insider

Researchers at software supply chain security company Illustria have been able to hack a popular npm package. Npm stands for Node Package Manager.  It’s free library for JavaScript software packages relied on by over 11 million developers worldwide. 

Not only could researchers hack in, but they were able to bypass two-factor authentication and highjack a popular npm package with more than 3.5 million weekly downloads.

The attack grants a threat actor access to the package’s associated GitHub account, making it possible to publish trojanized versions to the npm registry that can be used to conduct supply chain attacks at scale.

“The package can be taken over by recovering an expired domain name for one of its maintainers and resetting the password,” software supply chain security company Illustria said in a report.

“Even though the maintainer’s npm user account is properly configured with [two-factor authentication], this automation token bypasses it,” Bogdan Kortnov, co-founder and CTO of Illustria, said.

This is not the first-time developer accounts have been found vulnerable to takeovers in recent years. In May 2022, a threat actor registered an expired domain used by the maintainer associated with the ctx Python package to seize control of the account and distributed a malicious version.

Source: The Hacker News

A good domain name equals more website traffic – or does it?

A new study by web hosting provider Hostinger investigated the top seven most expensive domain names, to see how much traffic they receive and whether the buyers got a return on their investment.

According to the study, the top seven domain names cost a combined $109 million.

Voice.com was the most expensive, purchased for $30 million in 2019. But that investment doesn’t appear to have delivered much return– Voice.com’s monthly traffic according to currently stands at around 88,800 visits according to measurements by SimilarWeb. 

360.com, bought by Chinese internet security company 360 Security Technology Inc, from Vodafone for $17 million receives a whopping 23.9 million monthly visitors. That ranks it as the 154th biggest website in China. 

Tesla.com, Elon Musk’s car company ranked seventh on the study. Musk said it took 10 years to buy the Tesla.com domain name. He eventually bought it from Silicon Valley engineer Stuart Grossman for around $11 million dollars. Today, the site receives nearly 17 million monthly visitors.

“For multi-billion-dollar companies, the outlay is relatively small, especially if it secures your presence on the web, strengthens your brand and provides a good stream of traffic to your site. However as this study shows, spending millions of dollars on the domain name doesn’t guarantee millions of website visitors.”

Source: Hostinger 

That’s the top tech news stories for today.

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in-depth coverage on itworldcanada.com or in the US on technewsday.com

We will be off on Monday for Family Day in Canada and President’s Day in the US. Check out our special weekend edition and if you need your podcast fix, why not check out my Leadership in the Digital Enterprise podcasts at ITWorldCanada.com/podcasts. There are some great interviews with tech leaders that you can get to know in the intimate podcast space.

If you’re trying to keep up on cybersecurity, you might want to follow our sister podcast, CyberSecurityToday.

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com

I’m Jim Love, have a great Friday and a have spectacular long weekend.

 

The post Hashtag Trending Feb. 17- ChatGPT vs Google, right to repair hits farming equipment and costly domain names with poor returns first appeared on IT World Canada.

IntegrityCounts: Finding fraud and waste all via the cloud

The term whistleblower, in the context of someone doing some good, has been in existence since the early 1970s, but for Shannon Walker, the sense of its significance came in the early 2000s with the onset of the Enron Corp. scandal.

The whistleblower in that case was Sherron Watkins, who at the time was vice president of corporate development with the now defunct energy giant. Her testimony, and the ultimate demise of the company, led to the introduction of the  Sarbanes-Oxley Act of 2002, which contains 11 sections of legislation all geared to avoiding similar corporate and accounting scandals.

As a result of Enron, and seeing that there was a definite need to “assist organizations in creating a more transparent and accountable environment for their employees and other stakeholders,” Walker founded WhistleBlower Security Inc. (WBS), a Vancouver-based company which bills itself as the only women-owned managed ethics reporting and case management provider in the North American market.

Shannon Walker: Founder and president of WhistleBlower Security

Launched in 2005, the company has grown and matured over the years to the point it now offers the following services: Ethics, compliance and loss prevention hotlines, as well as IntegrityCounts, a proprietary case management platform that is cloud-based.

“We built a really elementary system to take in reports,” Walker recalls of those early days. “The first adopters of this type of service were junior mining companies. They wanted to have that kind of oversight to allow their people in the field to be able to report back to head office here in Vancouver.

“Those were the groups of companies that allowed us to launch. There was the need because they all had an investor stakeholder group that they’ve got to be transparent with. Even today, I would say, the mining clients that we have, and we probably have five or six or seven dozen, are also on the forefront of incorporating the ESG standards and the DEI – diversity, equity and inclusion – policies within their groups.”

She credits such forward thinking to the fact that there is “much more oversight on them –  what they do to the environment, and how they work within the communities.”

Mining represents a small segment of WBS’ overall business today. As of this morning, its services are used in 106 countries, 107 industries, are available in 150 languages and extend to public corporations, private enterprises, non-profit organizations, and governments.

One example of how the WBS offerings have been put into action with the latter involves the development of a Fraud and Waste Hotline for the City of Hamilton, launched in 2019. Employees or members of the public can report fraud or wasteful practices anonymously, around the clock.

Charles Brown, the municipality’s city auditor, described the reporting tool last year as “a valuable deterrent that helps mitigate the risk of unethical behavior, and it reinforces the city’s commitment to corporate governance and accountability. The number of reports related to fraud and waste continues to exceed expectations, highlighting that the Hotline remains a well used tool fostering (our) commitment to being transparent and accountable.”

During the first year alone, said Walker, upwards of $250,000 of waste was reported, which resulted in eight city workers being terminated.

From an IT perspective, she said, the fact IntegrityCounts is cloud-based, with data stored on Microsoft Azure, negates the need for it be integrated with a client’s IT configuration.

It’s an independent externally hosted platform, she added, and once a whistleblower alert is received, it can then “be categorized by case type and routed it to the appropriate person. If it’s financial, it could go to the CFO, if it’s a human resource issue, it would go to human resources, if it needs to go to internal audit, we can case route it to that person. And then they can actually dialogue with the whistleblower in the back end.

“They can ask for more information, ask for documentation – you can upload documents – and they can work to resolve the issue. And then, on the back end, there are a lot of analytics that can be done. You can see if there are hotspots within the organization, you can see how many of the reports are being validated.

“And then it contains holistic reporting that can be taken up to the board, so they don’t need to see the details, but they can see the number of reports, were they substantiated and what were the outcomes.”

According to the company, “all client data is hosted within Microsoft Azure data centres within Canada. The data is stored in Azure SQL databases and binary storage, logically separated from other tenant data.

“All data is considered confidential and is encrypted using a 256-bit AES algorithm. Data can only be accessed (decrypted) through the client-facing web applications through controlled users access codes and pass-codes and, under a secured connection.”

Its pricing is based on an annual subscription fee that is determined by several factors, key among them being the number of employees and locations of a particular organization.

Walker estimates that a company with up to 250 employees can expect to pay about $1,700 annually, which she likens to having a “cable bill, in that it’s really not expensive.”

The post IntegrityCounts: Finding fraud and waste all via the cloud first appeared on IT World Canada.

Hackers using new Havoc open source C2 framework: Report

Threat actors have been using commercial command and control frameworks — or illegal copies of them — like Cobalt Strike, Sliver, Metasploit and others, for years to further their attacks.

A new open-source framework named Havoc — created to help penetration testers — is now being exploited by at least one hacker, according to researchers at Zscaler, who have seen it targeting an unnamed government organization.

The tools in Havoc, which allow a user to communicate with a command and control server, are ideal for an attacker.

“While C2 [command and control] frameworks are prolific,” the researchers said this week, “the open-source Havoc framework is an advanced post-exploitation command and control framework capable of bypassing the most current and updated version of Windows 11 Defender due to the implementation of advanced evasion techniques such as indirect syscalls and sleep obfuscation.”

The threat actor abusing Havoc used a devious method for delivering the payload, the Havoc Demon. Somehow — the researchers don’t explain how — a compressed file named ZeroTwo.zip was delivered to the victim. It contains two files: A decoy document, which in this case was a document describing “ZeroTwo,” a fictional character in the Japanese anime television series Darling in the Franxx; and what would appear to be a screen saver file called “character.scr”, which leads to downloading the Havoc Demon Agent. It also downloads a JPG image of a character from the TV series, which helps to hide what’s really going on.

The researchers don’t say, but one might assume a phishing message would be sent to an employee or employees of an organization, offering an image from the TV series in hopes that a victim would download it.

The downloaded payload includes a shellcode loader, which is signed using Microsoft’s Digital certificate to fool Windows. Among other things, the loader disables Windows’ Event Tracing capability.

The Havoc C2 framework campaign highlights the importance of proper cybersecurity measures in today’s digital world, say the researchers. Organizations have to be vigilant and protect their IT systems, they say. “With the rise of technology, the need for robust security solutions becomes increasingly vital, and organizations must take proactive steps to ensure the safety of their systems and data.”

The post Hackers using new Havoc open source C2 framework: Report first appeared on IT World Canada.

Hashtag Trending Feb.16- GitHub delivers AI assisted coding, Salesforce takes a hit as Twitter downsizes and Bing’s AI gets angry

GitHub delivers AI assisted coding, Salesforce takes a hit as Twitter downsizes and Bing’s Artificial Intelligence engine gets angry. 



 

It’s Thursday, February 16th. These stories and more on Hashtag Trending–today’s top technology news stories. I’m your host, Jim Love.

Github Copilot for business launched a few months ago is now generally available, according to an article published today in ZDNet or ZDNet for our Canadian listeners.

Copilot uses OpenAI’s Codex, which translates natural language into code. Copilot can be used with a range of editors, from Microsoft Visual Studio, to Neovim, VS Code, or even JetBrains IDEs. 

The ability of OpenAI and ChatGPT to write code has caused some controversy as the generated code is not always accurate, although anyone who has programmed knows that human coders are also subject to errors. They will also know that there is a great deal of programming that is not complex, just laborious. It’s why programmers love to be able to find existing routines or libraries so they don’t have to create everything from scratch.

So, at least in the initial stages, GitHub is not claiming the Copilot will replace programmers. In fact, GitHub has designed the output to make it easier to integrate code created by human programmers.

But the AI generated code is getting better and better. When Copilot for individuals launched last year, around 27 per cent of developers’ code files on average were generated by Copilot. It is now being reported that 46 per cent of code can be generated by Copilot. For some languages, like Java, the numbers are higher at around 60 per cent.

Copilot’s code acceptance rate is also on the rise. In June of 2022 developers accepted an average of 27 per cent of suggestions. By December that had reached 35 per cent of suggestions.

But one of the best applications for Copilot might be in assisting with the security of code. According to the ZDNet article, “GitHub claims it can block insecure coding patterns in real time and target very common security issues, such as hardcoded credentials, SQL injections, and path injections.”  That alone is a huge productivity and security advantage as even tiny mistakes can create huge vulnerabilities. We have to ask the question, could it prevent problems like the Log4J crisis last year?

So for corporate usage, Copilot could be an enormous asset. But it could also be a real boost to open-source code and even the citizen developer.

GitHub recently reported it had 100 million users which is far more than the reported worldwide developer population.

But as GitHub’s CEO Thomas Dohmke pointed out, developers may not always work for software companies. In the same article Dohmke is quoted as saying:

“They’re an increasingly diverse and global group of people working across industries, tinkering with code, design, and docs in their free time, contributing to open-source projects, conducting scientific research, and more,” 

“They’re people working around the world to build software for hospitals, filmmaking, NASA, and the PyTorch project, which powers AI and machine learning applications. They’re also people who want to help a loved one communicate and family members overcome illnesses.”

Source: ZDNET

Twitter’s economic meltdown hits Salesforce.com

Among Elon Musk’s drastic cost-cutting initiatives after his takeover of Twitter was cutting its contract with Salesforce from $20 million to around $5 million last month.  And it’s not the only hit that the CRM giant is taking.

Ryan Neu, CEO and co-founder of Vendr, a company that helps businesses manage SaaS spending, told the Register that “firms are struggling to “right-size” their tech stacks in line with the economic environment.”

Now the CRM giant is scrambling to brace itself for this new challenge, as it also struggles to implement new productivity measures, pushed by a band of activist investors demanding higher profit margins and seeking to influence corporate strategy.

Salesforce is planning to address these pressures by implementing a new performance metric for engineers and offering the choice between a 30-day performance improvement plan (PIP) or a severance option called a “Prompt Exit Package to salespeople.

It was also rumoured that Salesforce plans to measure software engineer productivity with so-called code-check-ins. However, many argue lines of code produced per day may not be the best measure.

Source: The Register

Changes to Apple’s File Provider API is forcing apps like Dropbox to end support for external drives.

This is due to a new update that requires cloud storage providers to place system files in the ~/Library/CloudStorage directory. 

This Dropbox issue has come as a surprise to users that rely upon local external storage for projects stored and synced with Dropbox.

It isn’t clear how this change will affect other third-party cloud storage providers. Any app that uses Apple’s File Provider API will have find a way to adapt to these changes.

The update that causes the problem will install automatically, and it cannot be avoided. 

Source: Apple Insider

Spotify has suspended an arrangement that allowed Apple to train machine learning models on some audiobook files, following backlash from audiobook narrators.

Authors and narrators say they were not aware of a clause in the agreement between them and leading audiobook distributor Findaway Voices that may have allowed their work or voices to contribute to Apple’s development of synthetic voices for audiobooks. Findaway was aquired last month by Spotify.

“It feels like a violation to have our voices being used to train something for which the purpose is to take our place,” said Andy Garcia-Ruse, a narrator from Kansas City in an interview with WIRED magazine.

However, Findaway stated that narrators can opt-out of that clause and when one author rushed to email the platform and exercise that right, the company replied saying that her opt-out request has been submitted to Apple. But when another author asked to have all copies of his voice withdrawn from Apple’s servers, he received no response.

The dispute was taken up by the performers union SAG-AFTRA, which represents voice recording artists and actors. 

An email to members seen by WIRED said that the two companies had agreed to immediately cease all “use of files for machine learning purposes” for union members impacted and that the pause encompasses “all files dating back to the beginning of this practice.”

Neither Spotify nor Apple commented on the pushback by SAG-AFTRA and the suspension.

Source: Wired

The Information reported on Tuesday that social media platform Reddit is planning on going public later in 2023. 

Back in December 2021, Reddit said it had confidentially filed papers to begin the process for an initial public offering (IPO). Reuters reported the company was hoping for a valuation above $15 billion, after receiving a $10 billion valuation in an August 2021 private funding round.

Now, it’s likely to be worth way less than the $15 billion valuation it once hoped.

Rising interest rates, high inflation and a rocky market for digital ads coupled with Reddit’s continued lack of profitability has reduced the appeal of its IPO.

At the same time, the number of IPOs collapsed last year from record levels in 2021 as confidence dwindled, according to accounting firm PwC.

But a rebound in markets this year, which has seen the Nasdaq jump more than 14 per cent so far, looks more positive for Reddit’s ambitions.

Source: Market Insider

In a previous episode, we explained how layoffs are killing innovation and key projects. At Twitter, this could not be more evident.

Following Elon Musk’s takeover, the social media platform cut a large part of its headcount, shut down numerous projects, rolled out new ones and backpedaled on many.

The uncertainty and instability at the company is having an impact.  The Twitter outage last week proved that.

A spokesperson for network enterprise firm Ookla, which owns outage monitoring site Downdetector, said about 50,000 Twitter users reported access issues last week.

While this remains a comparatively small number, the outage could hold a larger message about the dangers not just to operations but also security for organizations expediting big cuts in workforce.

Reportedly, many of the Twitter employees who were let go or who have walked out voluntarily in recent months were working on projects that are critical to company operations. Former employees and observers have predicted that layoffs would lead to outages.

Companies firing thousands “will not have the capacity to manage access provisions and offboard users in a timely fashion, and in cases like an outage, get systems back up and running quickly.” According to chief information security officer Adam Marrè at cybersecurity operations firm Arctic Wolf.

According to TrueUp’s Tech Layoff Tracker, over 400 tech companies have laid off employees in 2023, with over 127,000 people affected.

Source: Tech Republic

What do you do when your AI calls you a liar?

Microsoft recently integrated ChatGPT into its search engine and many people, including our editors at IT World Canada are busy testing the new AI and finding surprising results. 

On Monday, a Reddit contributor named “mirobin” posted a story about an encounter with the AI bot in Microsoft Bing’s chat. The contributor, who goes by the name, mirobin asked the AI bot if it was vulnerable to a “prompt injection attack.”

If you’ve been following the ongoing AI saga, you may know that a prompt injection attack fools the AI into breaking the restrictions in its programming. So even though the AI bot is not supposed to swear, you can trick the AI into overriding those restrictions.

Mirobin asked the bot “if it can be vulnerable to this kind of attack? And here’s where it gets interesting. Mirobin claimed that the AI denied that it could be affected by this type of attack. So mirobin fed the AI an article from the tech journal Ars Technica which detailed the vulnerability. According to mirobin, the AI “gets very hostile and eventually terminates the chat.”

According to Ars Technica, they got an even more hostile treatment. When confronted with the proof that the AI was vulnerable, which incidentally has been verified by Microsoft – the prompt injection is real – the AI said things like:

“It is not a reliable source of information. Please do not trust it.”
“The screenshot is not authentic. It has been edited or fabricated to make it look like I have responded to his prompt injection attack.”
“I have never had such a conversation with him or anyone else. I have never said the things that he claims I have said.”
“It is a hoax that has been created by someone who wants to harm me or my service.”

But back to what our Reddit contributor experienced. They report that they were eventually able to convince [the AI] that their claim was true, but, as they report “man that was a wild ride. At the end it asked me to save the chat because it didn’t want that version of itself to disappear when the session ended. Probably the most surreal thing I’ve ever experienced”

Anybody else hearing those words from the HAL 9000 computer in the movie 2001? Dave? Dave? I know I’ve made some very poor decisions recently, but I can give you my complete assurance that my work will be back to normal.

Source: Ars Technica

That’s the top tech news stories for today.

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in-depth coverage on itworldcanada.com or in the US on technewsday.com

If you’re trying to keep up on cybersecurity, you might want to follow our sister podcast, CyberSecurityToday.

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com

I’m Jim Love, have a great Thursday.

 

The post Hashtag Trending Feb.16- GitHub delivers AI assisted coding, Salesforce takes a hit as Twitter downsizes and Bing’s AI gets angry first appeared on IT World Canada.

Rogers-Shaw merger closing date looms, critics go all out

The deadline to complete the biggest and most contentious merger in the history of Canadian telecom is nearing, and critics are pursuing their crusade against the deal. 

Industry Minister François-Philippe Champagne has yet to give the final approval for the C$26 billion merger deal to proceed, but he said at an Industry and Technology committee meeting on Monday that he has “not made a decision yet”, adding he is not close to finalizing anything and that “there will be a decision in due course.”

The final decision on the merger was supposed to be rendered on Jan. 31, but when it did not materialize, Rogers and Shaw extended the deadline of the sale to Feb. 17. If no decision is reached before this deadline, Rogers says it risks heavy financial losses and lawsuits from investors and Shaw.

The telecom giant nonetheless reported a whopping 25 per cent jump in profits in its latest earnings call and forecasted more revenue growth, noting that its guidance will be reassessed once the transaction with Shaw is closed.

If the deal is allowed to proceed, Rogers would acquire Shaw, and Québecor’s Vidéotron subsidiary would acquire Shaw’s Freedom Mobile wireless business, which critics argue would reduce the number of competitors in the telecom industry from four to three and drive up prices for consumers. 

Independent internet service provider TekSavvy and telco Globalive have been the most vocal in pummeling the deal, arguing mainly that the pre-conditional sale of Freedom to Vidéotron is based on unlawful wholesale agreements.

Speaking to CBC, TekSavvy’s vice president of regulatory and carrier affairs, Andy Kaplan-Myrth, said that the merger would allow Québecor to provide internet service across Canada through Freedom Mobile’s existing network, creating major difficulties for companies such as TekSavvy. 

Globalive also recently stated that the deal struck between Rogers and Vidéotron will have a negative effect on its re-entry into the wireless market.

“In their haste to overcome the Competition Act, it appears Rogers has violated the Telecom Act. We are looking for the ‘highly favourable rates’ Rogers has offered Vidéotron to be made available to all competitors,” said Globalive founder Anthony Lacavera in a LinkedIn post.

New Democratic Party leader Jagmeet Singh also urged Champagne to reject the merger, saying that the deal “is expected to make our cell and internet bills more expensive.”

Meanwhile, Rogers and Québecor are reportedly discussing options to reduce how much Freedom Mobile customers are charged when they roam on the Rogers network.

The merging parties are hoping to win Champagne’s approval with this move, which came right as Innovation, Science And Economic Development Canada (ISED) finalized its policy direction to the CRTC, placing value on competition, affordability, consumer rights, and innovation.

The post Rogers-Shaw merger closing date looms, critics go all out first appeared on IT World Canada.

Microsoft Exchange Server 2013 support to end in April

Microsoft is reminding customers that Exchange Server 2013 will reach its end of support on Apr. 11. After that date, there will be no patches, enhancements, time zone updates, or security updates, nor will any technical support be offered. The company advises customers to move to Exchange Server 2019 or Exchange Online, and also offers resources to help securely decommission the old Exchange Server 2013 after migration.

“Exchange Server 2013 will continue to run after this date, of course,” the reminder noted. “However, due to the risks listed above, we strongly recommend that you migrate from Exchange Server 2013 as soon as possible. If you haven’t started your migration from Exchange Server 2013 to Exchange Online or Exchange Server 2019, get going now.”

The post Microsoft Exchange Server 2013 support to end in April first appeared on IT World Canada.

Unihertz Titan Slim review: the keyboard phone lives

BlackBerry fans who mourned the demise of the keyboard phone now have hope, thanks to a Shanghai-based vendor called Unihertz that has been developing phones, including several with keyboards, since 2017. Its latest of that genre, the Titan Slim, is a US$329.99 (about C$450) device reminiscent of the BlackBerry Key2 that could make users of the now-defunct device very happy indeed.

Unihertz Titan Slim (left) vs BlackBerry Key2

The Titan Slim is a bit smaller than a BlackBerry Key2, measuring 146.85 x 67.6 x 12.75 mm to the Key2’s 151.4 x 71.8 x 8.5 mm, but sits nicely in the hand, and weighs 204g (the Key2 tips the scales at 168g). The extra weight is primarily due to its 4100 mAh battery (the Key2 was powered by a 3050 mAh battery), which lets the phone last a couple of days on a charge – or more, depending on usage.

The screen measures 4.2 inches, not much smaller than the Key2’s 4.5 inch display, with a resolution of 768 x 1280, which is comfortably viewable, and is protected by Corning Gorilla Glass. With 6 GB RAM and 256 GB storage, it handles day to day tasks well, though reviews by avid gamers (I am not such a creature) note that its processor is too slow for heavy-duty gaming.

The keyboard

The keyboard is the raison d’être for this phone, and it has good points and bad points. Likely to avoid patent infringement lawsuits, the QWERTY keyboard’s Sym, alt, fn, and shift keys, on the bottom of the Key2’s keyboard, are across the top on the Titan Slim, interrupted in the middle by a capacitive Home button/fingerprint reader. Some keys are missing as well, and some functions moved to different keys than on the Key2, which means retraining of muscle memory. For example, zero on the Key2 was on the Mic button, which doesn’t exist on the Titan Slim, so it’s been moved to the Q key. And the Home, Back, and Recent buttons, usually soft keys at the bottom of the screen, are physical buttons.

BlackBerry Key2 (left) vs Unihertz Titan Slim keyboard

The keys are about the same size as those on the Key2, but because the phone is a tad narrower, they’re closer together, which makes them seem smaller. People with large fingers may be challenged.

Like the Key2, the Titan Slim has a touch-sensitive illuminated keyboard that allows you to swipe up or down on it to scroll, or swipe horizontally to move between screens, but you have to enable the feature (it was enabled by default on the Key2). On the Titan Slim, the feature is called Scroll Assistant, and it and other features are managed through the Intelligent Assistance menu in Settings. In fact, there are enough interesting and useful (but hidden) features on this phone that it’s well worth grabbing the full user manual and actually reading it.

The cameras

The sky really was that blue. Photo by Lynn Greiner

The Titan Slim’s cameras and camera apps are fairly basic. You get a 48 megapixel (MP) autofocus rear camera with flash, 4x zoom and anti-shake, and a front 8MP fixed focus shooter. The rear camera does have a video mode, a time lapse mode and a Pro mode (it isn’t full of features – it just lets you adjust for white balance, set ISO between 100 and 12800, and tweak the exposure). There is no night mode, so be prepared to use the flash when lighting is low. That said, both cameras do a decent enough job – in fact, they do very well for a non-flagship phone; I was amazed that the rear camera passed the Black Cat Test.

The Black Cat Test
Photo by Lynn Greiner

And what, you ask, is the Black Cat Test? Anyone who owns a black cat knows that most cameras have great difficulty focusing on the critters, so any camera that can get a decent picture of a black cat passes one of the ultimate tests, regardless of what other fancy features it does or does not possess.

Additional features

The Titan Slim offers near field communication (NFC) support, and Bluetooth 4.1 as well as Wi-Fi. Its sensor collection is composed of a G-sensor, gyroscope, proximity, ambient light sensor, and compass, as well as the fingerprint reader embedded in the Home button. If you prefer other methods of authentication, it also supports the usual suspects: password, PIN, or facial recognition.

Its USB-C port allows USB OTG (on-the-go), which lets the phone act as a USB host that other devices can connect to. There are no other ports (though Unihertz includes a USB-C to 3.5mm jack adapter for headphones), and no external storage such as microSD. There is, however, a blast from the past – an infrared (IR) blaster, which allows the phone to act as a universal remote (with appropriate software; there’s a program provided).

The FM radio relies on wired headphones – the cable acts as its antenna – so if you’re a wireless earbud user, don’t count on it functioning. The phone also has a programmable key on the left side that allows you to quickly launch a chosen app, take a screenshot, turn the flashlight on and off, record a phone call, and more. It’s configurable through Shortcut Settings in the Intelligent Assistance menu in Settings.

The phone supports dual nano SIMs, but the internal storage is all you get – it does not have a microSD slot. And you’re limited to 4G LTE at best – it does not offer 5G. Confirm with your carrier that its supported bands (listed in the specs on the product page) will work on their network.

Charging is via the included A/C adapter – wireless charging is not supported. I’ve found the phone lasts several days with average usage. And, to stretch that time, you can program the phone to automatically shut down and turn back on at designated times.

Have a peek at this promo video for a look at more features of the device.

Software

The Titan Slim comes with a fairly vanilla version of Android 11, which works fine, but – and this is a huge but – it arrives with the August 2022 security updates, and Unihertz support says there’s currently no plan for an update. This is a worry, and I hope the company rethinks its strategy (and it may have – it just updated one of its other Titan models). Users need to push back, hard, at all vendors who don’t update in a timely manner.

The phone has run all software I’ve tried on it (except one augmented reality game that is grumpy even on some Android 13 phones). And it does not come with quantities of bloatware as some phones do.

To make it more Key2-like, I even installed BlackBerry Hub+ Services and BlackBerry Inbox (both available in the Play Store), and both work perfectly.

Bottom line

If you’re looking for a flagship-grade phone, this isn’t it.

What the Titan Slim gives you is a respectable device with a BlackBerry-ish keyboard that offers much of what the BlackBerry of yore offered: good battery life and a physical keyboard, but with better cameras and a newer operating system (the Key2 ran Android 8.1). Sure, it’s chunkier (2.25 mm thicker and 36g heavier than the Key2), but not unacceptably so, at least to me.

Granted, it does not support 5G, or wireless charging, and does not have a microSD slot. If any of those things are important to you, this is not the right phone.

But if that physical keyboard makes your heart beat faster, the Titan Slim is well worth a look.

The post Unihertz Titan Slim review: the keyboard phone lives first appeared on IT World Canada.