Page 11 of 55

Proposed Canadian law puts burden on large internet providers to police child porn, hate

Designated social media providers, live-streaming services and adult sites that allow users to upload content will have to scrutinize and delete objectionable messages, images, and videos if the Liberal government’s proposed Online Harms Act, which includes the creation of a Digital Safety Commission to hear complaints, is passed.

The act, Bill C-63, which was introduced today, says designated services must remove within 24 hours two categories of content: Material that sexually victimizes a child or re-victimizes a survivor; and intimate content posted without the consent of an individual.

The 24-hour deadline would be subject to oversight and review.

The law would also make it clear anyone who provides an internet service — including social media platforms — has to report to a designated law enforcement agency if child porn is posted on their service. To enhance that reporting, service providers will have to hold user content for one year — up from the current 21 days — to ensure content is available for criminal investigation.

Designated providers would have to put child safety first when designing products and features including offer parental controls, content warning labels for children and set rules around targeted content or ads directed at children.

In addition, the government plans to amend the Criminal Code to fight hate by creating a new hate crime offence punishable by up to life imprisonment, and by raising the maximum penalties for the existing four hate propaganda offenses.

The Canadian Human Rights Act would be amended to specify that posting hate speech online is discrimination, and allow the Human Rights Tribunal to handle hate speech complaints, including granting them the power to order the removal of such content.

Amendments would also make it clear anyone who provides an internet service — including social media platforms — has to report to police if child porn is posted on their service.

Only online services that have a big enough number of users would be covered under the Online Harms Act. The size would be covered in yet-to-be announced regulations.

The proposed law would cover seven categories of harmful content:

— content that sexually victimizes a child or re-victimizes a survivor;

— content that could be used to bully a child;

— content that induces a child to harm themselves;

— content that incites violence;

— content that foments hatred;

— intimate content communicated without consent, including deepfaked audio, images and videos.

The Digital Safety Commission would be composed of five people appointed by the government, with the power to order providers to remove content that sexually victimizes a child. It would also have the responsibility of setting norms in online safety.

The proposed legislation would also create a Digital Safety Ombudsperson, also appointed by the government.

The goals, the government says, are to reduce the exposure of harmful content to Canadians, give special protections for children and stronger reporting of child pornography; give public oversight of and accountability from online services and “improved safety over time.”

The legislation will allow people to request the quick removal of child porn, submit complaints to the Digital Safety Commission, allow people to contact the Digital Safety Ombudsperson to receive support and be directed to the right help resource and to file complaints with the Human Rights Commission when facing online hate.

The bill makes it clear it doesn’t cover private communications such as email and text messages or service such as WhatsApp. But it does apply to social media platforms such as Facebook and others where a poster can invite many people into a group.

More to come…

The post Proposed Canadian law puts burden on large internet providers to police child porn, hate first appeared on IT World Canada.

Cyber attack on Hamilton knocks out municipal phone, email

One of Ontario’s biggest cities is in the second day of dealing with a cyber attack.

Hamilton, a municipality of about 570,000 on the shore of Lake Ontario, said Sunday it had suffered a city-wide phone and email “disruption” to municipal and public library services, which included the Bus Check Info Line and the HSRNow transit planning app.

Today, the city’s description of the problem changed from a disruption to a cyber incident.

Buses started as scheduled Monday, and transit schedules are available on the city’s website.

“At this time experts are actively responding to the incident to determine the cause and potential impacts,” the city said in a news release Monday on its website. “Our priority is to safeguard the integrity of our systems and protect any sensitive or private information.

“While the investigation is ongoing, we want to assure the community that we are taking this matter seriously and are collaborating closely with cybersecurity experts and relevant authorities to address the issue as quickly and effectively as possible.

“We understand the importance of transparency and will provide updates as new information becomes available. We apologize for any inconvenience caused by this incident.

“The City remains committed to protecting the privacy and security of our community while managing impacts to City service levels.”

Threat actors may target provincial, state, and local governments for several reasons: Generally their IT departments are less well-funded than national governments and may be less well defended. Threat actors may also believe local governments are susceptible to paying ransoms for access to stolen data because they are responsible to taxpayers.

Experts also say some attacks are just opportunistic — that is, a hacker finds an IT system vulnerable to an attack and takes advantage of the opening.

A report last year by cybersecurity awareness training supplier KnowBe4 on the economic impact of cyber attacks on U.S. municipalities noted getting into the network in the first place is often done with low-tech phishing emails.

The City of Toronto’s public library system is only now in the final stages of recovering from a ransomware attack last October. It has been forced to rebuild its network. The names, Social Insurance numbers and other information of employees going back to 1998 was copied by the attacker.

The post Cyber attack on Hamilton knocks out municipal phone, email first appeared on IT World Canada.

Hashtag Trending Feb.26-Cybersecurity firm selling your data? AT&T outage; Microsoft’s updates may no longer force you to reboot your computer

A cybersecurity firm selling your data? AT&T says a flawed network update caused last week’s major outage. Self checkout may be watching you more closely using AI. And Microsoft has announced that updates may no longer force you to reboot your computer. 



 

All this and more on the “ah, come on, Reboot? I’m late for the meeting,” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US. 

In a striking turn of events, Avast, a well-known cybersecurity software company, has been fined $16.5 million by the Federal Trade Commission (FTC) for engaging in practices that starkly contradict its user privacy promises. 

For years, Avast harvested sensitive user data through its antivirus software and browser extensions, collecting information on individuals’ religious beliefs, health concerns, political views, and financial status, only to store this data indefinitely and sell it to over a hundred third parties without user consent.

This revelation not only sheds light on the deceptive practices of a trusted antivirus provider but also underscores the broader issue of digital privacy in the tech industry. The FTC’s crackdown reveals a disturbing trend of companies exploiting user data under the guise of providing security and privacy enhancements. Avast’s claim that it anonymized user data before selling it was debunked by the FTC, which found that the data sold included unique identifiers, making it possible to trace back to individual users.

Moreover, Avast’s actions of tracking users while promising to eliminate web tracking highlight a significant breach of trust, prompting the FTC to impose not just a hefty fine but also stringent restrictions on Avast’s future operations. This includes a ban on selling or licensing browsing data for advertising purposes and an order to delete all web browsing data obtained through its Jumpshot division.

Sources include: The Verge

AT&T has admitted that last week’s major network disruption, which affected an enormous number of its mobile users, was the result of an “incorrect process used as we were expanding our network,” not a cyberattack .

The outage saw over 70,000 problem reports lodged on DownDetector, a website that tracks service interruptions. By midday, AT&T reported that three-quarters of its network had been restored, with full service resuming by the afternoon.

The Federal Communications Commission (FCC) has taken notice, launching an investigation into the outage, emphasizing the critical nature of reliable communication services, especially in emergencies. This situation also affected FirstNet users, a nationwide public safety network built by AT&T, underscoring the potential risks to public safety and homeland security.

And in a related story, AT&T has reportedly offered a five-dollar rebate to each affected customer. The same reports have some customers calling this “insulting.” 

Sources include: ArsTechnica

Microsoft has announced a significant update to Windows 11 that will allow the operating system to update without the need for a reboot. Dubbed “hot patches,” this new mechanism is currently being tested in the latest Windows 11 update distributed in the developer channel. 

The concept of “hot patches” is described by Microsoft as “updating the code of a process running in memory without restarting the process.” This approach not only enhances convenience but also ensures that security updates are implemented more efficiently, reducing the system’s vulnerability window. While the system will still require a reboot every few months to apply certain updates, the frequency and disruption caused by these reboots will be significantly reduced.

Now what will we blame for being late for virtual meetings?

Sources include: Gadget Tendency

Sam Walton, founder of Walmart reportedly once said that the reason he had a greeter in the store was that if you shook someone’s hand and looked them in the eye, they wouldn’t steal from you. 

I’m sure this won’t affect any of our listeners, but apparently, when it’s not a person, but a scanner and a self-checkout, customers are more likely to make mistakes that are, shall we say, in their favour.  Some estimates are that when self-checkout is in place, losses may increase by as much as 30 per cent.

Stores have noticed. 

One way that they may be fighting back is with the use of AI.  

A company named Diebold Nixdorf introduces an AI-powered software suite named ‘Vynamic Smart Vision | Shrink Reduction’. 

This technology aims to address what are called “inventory discrepancies caused by unintentional or deliberate actions by customers”, such as missed scans or manipulation of barcodes. It sounds so much nicer than stealing.

The AI system will self-checkout stations in real-time, alerting staff members to potential discrepancies through a tablet or phone. It includes applications for automatically verifying the age of alcohol purchasers, recognizing fruits and vegetables, and detecting irregular checkout behaviours. The software promises reducing shrinkage, which is the retail term for uh…stealing. In fairness it covers errors as well.

There are some questions about privacy and the customer experience. While it aims to streamline operations and reduce losses, the increased surveillance at self-checkout stations might not sit well with all customers. 

Whether this approach will lead to a significant reduction in losses without alienating customers remains to be seen.

Sources include: ZDNet

And Air Canada has the dubious distinction of being the first company in Canada to have a threatened legal action because of an error from its chatbot. 

The stories in the media are saying that an AI chatbot promised a  bereavement discount to a customer, a commitment the company was then obliged to honour. 

And we’ll check this out, to the best we can, but before we all go down the rabbit hole of blaming AI, let’s be certain that the AI, if it really was AI, was fed the right information. Most large companies are still using structured chatbots which read information given to them. Not many are using ChatGPT or generative AI solutions like ChatGPT. And some that are, use a new approach called Retrieval Augmented Generation which reduces so called hallucinations. 

And if it is an AI error, we’d like to know. But nobody is served by lumping this incident with stories of hallucinations or of lawyers who had used what they thought were case precedents only to find out that these were fictional documents written by ChatGPT. None of these are relevant to this story. 

There will be errors attributable to the use of generative AI. Just like there are errors in standard computer algorithms and human errors.

And yes, generative AI is capable of creating erroneous answers – or in plain, it can make stuff up. So do humans. Neither of those is of any help to us working to responsibly use and implement AI, something we should do from knowledge, not fear. 

We hope that Air Canada will be very transparent about how the errors occurred. Let’s get the facts. That will do a service to all of us.

Sources include: The Register

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition. 

I got comments on my story yesterday on the growth in C level titles. Thanks. I am really interested in what you think about AI and your reaction to the story today. 

I like to keep it real and knowing what you think is a big help. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Marvelous Monday.

 

The post Hashtag Trending Feb.26-Cybersecurity firm selling your data? AT&T outage; Microsoft’s updates may no longer force you to reboot your computer first appeared on IT World Canada.

LockBit claims it’s back, blames failure to patch vulnerability for police attack

The LockBit ransomware gang says it’s back in business, with a person posting a message admitting his “personal negligence and irresponsibility” for not updating an application was likely used by law enforcement last week to dismantle much of the operation’s IT infrastructure.

This explanation is included in an English and Russian message on the gang’s new TOR site. The full text has been posted on X by vx-underground.

The sometimes rambling message, titled, “What happened,” is dated Feb. 24 and  gives an account of the Feb. 19 attack, claims without evidence that the FBI attacked now because the gang or an affiliate had stolen documents related to a Georgia investigation into allegations Donald Trump and others tried to interfere with the results of the 2020 presidential election in the state that LockBit was about to release, claims the gang has not been put out of business and vows there will be retaliatory attacks on U.S. .gov domains.

The new LockBit site lists several new victims as well as Fulton County, Ga. According to the news site Databreaches.net, LockBit claimed to have hit the county before the Feb. 19 takedown of its infrastructure.

In the Feb. 24 message, the author writes that on Feb. 19 he detected “penetration testing” on two of his servers. An error was detected, but nothing apparently changed. “I didn’t pay much attention to it, because for 5 years of swimming in money I became very lazy, and continued to ride on my yacht with titsy girls.”

However, 14 hours later, after a new server error popped up, he said he couldn’t log in. “As it turned out later, all the information on the disks was erased.”

The problem, he believes, is that he hadn’t updated the servers’ PHP, an open-source general-purpose scripting language used for web development. He believes the attackers accessed two LockBit servers through this or another zero-day vulnerability.

“The new servers are now running the latest version of PHP,” the letter adds. “I noticed the PHP problem by accident and I’m the only one with a decentralized infrastructure with different servers, so I was able to quickly figure out how the attack happened. If I didn’t have backup servers that didn’t have PHP on them, I probably wouldn’t have figured out how the hack happened.”

“The fact that LockBit has relaunched its website isn’t particularly surprising, and doesn’t mean the disruption effort was unsuccessful,” Brett Callow, Canadian-based threat analyst with Emsisoft, told IT World Canada. “On the contrary, law enforcement likely obtained valuable information that will enable them to identify and take action against LockBit’s past and present affiliates as well as others involved in the ransomware supply chain.

“Realistically, this is likely the end of the LockBit brand. Other cybercriminals will not be willing to risk working with an operation that was so thoroughly compromised. It’d simply be too risky.”

The U.K.’s National Cybercrime Agency says it obtained “the LockBit platform’s source code and a vast amount of intelligence from their systems about their activities and those who have worked with them and used their services to harm organizations throughout the world.” Working with the FBI and law enforcement agencies from nine other countries, they seized a LockBit data exfiltration tool, known as Stealbit, 28 servers belonging to LockBit affiliates and over 1,000 data decryption keys.

The LockBit author says the FBI got “a database, web panel sources, locker stubs that are not source as they claim and a small portion of unprotected decryptors.”

“Yes it’s bad,” the author says of the loss of the decryptors, “but it’s not fatal.” He claims there were over 20,000 more decryptors that were protected and can’t be used by victims to unscramble their data.

The seized database, he says, has “generated nicknames” and not real nicknames of LockBit partners. But, he admits law enforcement did get cryptocurrency wallets. But he says people will be arrested and accused of being partners, which, he says, they aren’t.

As for police getting the source code of the panel, what remains of the panel will be divided into many servers for verified partners, the LockBit author says, with each partner getting their own copy. to reduce the chance of a future hack.

Police said several alleged LockBit gang members were arrested, but LockBit believes these were only people who laundered cryptocurrency.

“The FBI decided to hack now for one reason only,” the LockBit author claims — because they didn’t want to see a leak of information from Fulton County, Ga., where former U.S. President Donald Trump and others are being investigated for allegedly trying to change the outcome of the 2020 election in the state.

If it wasn’t for the FBI attack, the author claims, the documents would have been released on Feb. 19. “because the negotiations stalled, right after the partner posted the press release to the [LockBit] blog … Had it not been for the election situation the FBI would have continued to sit on my server waiting for any leads to arrest me and my associates, but all you need to do to not get caught is just quality cryptocurrency laundering.”

“Even after the FBI hack, the stolen data will be published on the blog, there is no chance of destroying the stolen data without payment,” the message says. “And after introducing maximum protection on every build of locker, there will be no chance of free decryption, even for 2.5 per cent of attacked companies.”

“New affiliates can work in my affiliate program if they have a reputation on the forum, can prove they are pentesters with post-pay-payment, or by making a deposit of 2 bitcoins, the deposit increase is due to proof and beautiful advertising from the FBI, which is that my affiliates and I earn together hundreds of millions of dollars, and that no FBI with their assistants can scare me and stop me, the stability of the service is guaranteed by years of continuous work.”

According to researchers at Switzerland-based Prodaft, LockBit has seven affiliates that use its ransomware-as-a-service, some of which have ties to other threat actors such as FIN7, Wizard Spider, and EvilCorp. One focuses almost exclusively on GIT and Jenkins Servers, another relies on compromised Microsoft RDP server information from certain initial access brokers, while a third primarily focuses on vulnerable Fortigate and Citrix platforms. Some train other affiliate gangs.

The post LockBit claims it’s back, blames failure to patch vulnerability for police attack first appeared on IT World Canada.

Cyber Security Today, Week in Review for week ending Friday, Feb. 23, 2024

Welcome to Cyber Security Today. From Toronto this is the Week in Review edition of the podcast for the week ending Friday, Feb. 23rd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes Terry Cutler of Cyology Labs will be here to discuss recent news. But first a review of headlines from the past seven days:

Law enforcement agencies from 10 countries hit the Lockbit ransomware gang where it hurts: They seized control of its website, 28 servers and more. This will be Topic 1 in the discussion, which will also include reports of organizations still seeing no alternative but to pay ransomware gangs.

We’ll also look at a report that the department of a U.S. state was compromised through a former employee’s credentials, the ending of a Canadian program to help small companies modernize their IT and why companies hit by data breaches don’t notify victims faster.

Also in the news this week, researchers at Cisco Systems said threat actors are increasingly taking advantage of the Google Cloud Run service in phishing attacks. Google Cloud Run enables developers to build and deploy web services on Google Cloud. But its also an inexpensive way to deploy malware distribution infrastructure that probably isn’t blacklisted by many security applications. The Cisco report includes URLs, IPs and domains to be blocked.

Hackers are increasingly getting hold of and exploiting valid account credentials as an initial way of breaking into IT networks. That’s according to a new IBM report that — again — emphasizes the need for IT departments to implement identity and access management controls.

Developers of the Anasta trojan that hides in malcious Android apps are more active. This malware steals the bank login credentials of victims foolish enough to download the bad apps. Researchers at ThreatFabric say the latest version has added more financial institutions to their target list. Researchers also say the latest version targets Samsung smartphones. Banks need to watch for suspicious withdrawals from mobile devices.

And two more malicious packages have been found on the open-source PyPI library for Python. Researchers at ReversingLabs say the pair of packages use DLL sideloading to launch malware. As with many phony packages, their names were close approximations of legitimate packages. The discovery is another reminder to developers to be cautious when taking code from open-source libraries.

(The following is an edited transcript of the first of five topics discussed )

Howard: Joining me now from Montreal is Terry Cutler of Cyology Labs.  The LockBit ransomware gang suffered a major blow this week when law enforcement agencies led by the U.K. and the U.S. seized at least one of the gang’s websites, 28 servers, source code and possibly more. Question: How big a blow was it?

Terry Cutler: I think it was significant because law enforcement has disrupted a significant financial stream for the gang. It also highlights the capability of international collaboration. As you mentioned. the FBI worked with the U.K. and other countries to collect and share information to bring this gang down. For those of you who don’t know, this ransomware gang has earned about US$120 million from over 2,000 victims worldwide.

When they [police] got access to the server they also got access to sensitive internal workings of the gang — how the servers are configured — and they were also able to pull out over a thousand decryption keys. This way they’re able to go out and help victims decrypt their data without having them pay.

But the challenge that we’re seeing is that as a ransomware-as-a-service gang there’s potential for rebranding of the gang. We suspect that a lot of the members will just regroup.

Howard: Ransomware gangs have been known to rise from the dead in one way or another, either by resuscitating their infrastructure or by forming a new gang. How long do you think it’ll it’ll take LockBit to recover — or will it?

Terry: It’s going to come down to how fast they can Innovate. We’ll call this a hiccup.It gives the gang a chance to evaluate what went wrong, how did law enforcement get access to their information, what can they do better. Once they’ve had that little pause they’re going to regroup and rebuild, but during that time there’s probably going to be a little less ransoware attacks.

Howard: We recorded this podcast on Thursday, which is also when researchers at Trend Micro released a fascinating analysis of the Lockbit gang and its recent technical and operational troubles. The researchers also came across what looks like a new variant of the LockBit ransomware code the gang was probably working on. This would be the fourth generation of its code. Exposure of this code is going to hurt the gang and any plans that it had um to make use of it in the future.

Terry: What’s interesting is that in an October 2021 report [a researcher] interviewed LockBit, and they always felt there was a risk of them being hacked … Law enforcement is getting very savvy on collecting evidence properly and and going after these groups.

Howard: In late 2022 a Canadian member of the gang was arrested here. He pleaded guilty earlier this month to multiple charges and will be sentenced soon — and then he’s also wanted for extradition to the U.S. This is speculation, but could he have said anything that helped the LockBit takedown this week, or did the things that led to his arrest and that police seized from his house then set in in motion the events that we’ve seen this week?

Terry: When they arrested him they got access to his computer’s hard drives. I think it revealed a ton of juicy information to law enforcement. Not only that, because of his arrest the gang halted for a step, so they had to reevaluate their capabilities and during that time there was a bit of a slowdown with the ransomware.

Howard: Will other ransomware gangs be intimidated by the action taken this week against LockBit?

Terry: Yes and no. I think it’s going to hurt others in the short term because when high profile takedowns occur they want to know how did law enforcement infiltrate them [LockBit]? … What will happen is other ransomware gangs are going to share information with other ransomware groups.

(To hear the rest of the discussion play the podcast)

The post Cyber Security Today, Week in Review for week ending Friday, Feb. 23, 2024 first appeared on IT World Canada.

Breaking news: RCMP facing ‘alarming’ cyber attack

The RCMP is facing a serious cyber attack from an unspecified threat actor.

The Mounties told CBC News today that a “breach of this magnitude is alarming.”

“The situation is evolving quickly but at this time, there is no impact on RCMP operations and no known threat to the safety and security of Canadians,” a spokesperson for the RCMP said in a statement issued to CBC News.

“The quick work and mitigation strategies put in place demonstrate the significant steps the RCMP has taken to detect and prevent these types of threats,” CBC News was told.

So far the RCMP’s web sites don’t appear to be affected.

It could be a coincidence, but this week, Canada’s Communications Security Establishment — the government’s cybersecurity and electronic spy agency — urged IT departments to be vigilant for attacks, because Saturday is the second anniversary of Russia’s invasion of Ukraine. The worry is that Russian government threat actors or groups affiliated or sympathetic to Russia will mark the time by launching cyber attacks against nations supporting Ukraine.

The CSE said possible activity ranges from defacing websites and denial of service attacks to more serious activities.

The post Breaking news: RCMP facing ‘alarming’ cyber attack first appeared on IT World Canada.

Making AI explainable to bridge trust gaps: Forrester weighs in

Artificial intelligence has invaded industries and companies of all sizes, but the backstory of what makes these tools powerful and erratic alike remains somewhat obscure.

Understanding how and why AI systems arrive at their outputs, Forrester explained in a new report, is a critical transparency mechanism, called explainable AI. And that is key for enterprises to minimize the trust gap in AI systems across all stakeholders.

Companies that have attained a higher level of AI maturity wherein they start to leverage opaque methods like neural networks for additional predictive power are the most concerned with explainability challenges, the report explained.

These neural networks are the only way to analyze text, images, and video at scale, so industries with use cases involving unstructured data will be more inclined to invest in explainability. At the same time, these companies will have even more regulatory exposure.

However, with the explosion of generative AI-enabled natural language interactions, eventually all companies will need to invest in explainability, the report noted.

Regulatory compliance is one factor, but explainability can also help companies unlock the business value of their AI algorithms. For example, in a use case like credit determination, explainability can inform future credit risk models. Customer insights is another big one that enterprises are eyeing in order to drive business value.

Furthermore, explainability can drive trust among employees who use AI systems to perform daily functions. AI adoption suffers significantly when employees do not at least have a minimum understanding of how the system produces results. Forrester’s 2023 Data and Analytics survey, in fact, showed that 25 per cent of data and analytics decision makers say that lack of trust in AI systems is a major concern in using AI.

To achieve these outcomes with explainability, researchers have developed interpretability techniques like SHAP and LIME, which are open source and which are widely used by data scientists. Many larger machine learning platform vendors also offer explainable AI capabilities on top of their existing model development functionality. These vendors also serve other responsible AI needs like model interpretability, bias detection, model lineage and more.

But data scientists are not the only ones who will need explainability. AI governance teams need model intelligence platforms that provide responsible AI assessments to oversee an enterprise’s use of AI.

Business users can also use these model intelligence platforms, or they can use machine learning engines with explainable AI techniques, especially for high-risk or highly regulated use cases such as credit determination and hiring.

Forrester recommends enterprises seeking explainability to do the following:

Look at the different AI use cases, classify risk accordingly, and then define explainability requirements for each tier. Companies, for instance, have been borrowing from the EU’s AI Act that classifies AI systems into four categories — unacceptable risk, high risk, medium risk, and low risk. As a result, high-risk use cases, for example, may require complete transparency, while interpretability may suffice for moderate risk use cases.
Demand explainability from AI vendors and beware of the black box, as you may be held accountable for any vulnerabilities or flaws. 
Ensure that explainability goes beyond individual models and covers how the entire system works — the interoperability of all the pieces — and measure business outcomes and customer satisfaction as well as model performance to ensure the system is delivering as expected.

The full Forrester report is available for purchase here.

The post Making AI explainable to bridge trust gaps: Forrester weighs in first appeared on IT World Canada.

Hashtag Trending Feb.23- Companies losing top talent with long hiring processes; Intel – the “foundry for the world?”; AT&T outage

(PRE MUSIC ANNOUNCEMENT)

If you know me, you know I’m passionate about three things – music, books and data. My interview on the weekend edition hits two of those passions. I read a book called Winning with Data Science, and it blew me away. So, I reached out and managed to get one of the authors, Howard Friedman in for an interview. Check it out on the Weekend Edition. 

(GAP)

Companies are hiring for IT jobs in Canada but long hiring processes may have them losing top talent. Intel is set to split into two companies to become the “foundry for the world” A US nation-wide outage affects AT&T and other carriers and a blog post about the benefits of job hopping goes viral on LinkedIn.



 

All this and more on the “can you hear me now?” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US. 

A recent study by Robert Half reveals that over 50% of Canadian technology managers are set to continue hiring in the first half of 2024, despite facing significant challenges in finding skilled talent. 

This is driven by factors such as anticipated company growth, increased turnover, and a notable skills gap among current employees. 

The opportunity to capitalize on talent laid off from other companies is a key strategy for many.

The study, which surveyed executives, senior managers, and workers across small, medium, and large businesses in Canada, highlights a strategic shift towards hiring more contract professionals, especially in burgeoning fields like AI, machine learning, cloud architecture, and software development. 

This move is to advance projects that were previously put on hold in 2023.

But recruiting the right talent isn’t easy. Nearly half of the managers surveyed acknowledged skill gaps within their teams were affecting the quality of work and project completion. The greatest challenges lie in securing talent proficient in AI and machine learning, security, privacy and compliance, and cloud architecture and operations.

The report advises recruiters to act swiftly to fill these gaps, noting that the hiring process has become more prolonged than in previous years, with 64% of managers reporting longer hiring times. 

To combat this, companies are encouraged to streamline their interview processes and offer competitive compensation and benefits packages to attract and retain top talent.

Interestingly, the study also sheds light on the priorities of workers seeking new opportunities, with higher salaries, advancement opportunities, benefits, perks, and flexible work options topping the list. The challenge for recruiters is to meet these expectations while navigating the higher salary demands and preferences for flexibility that lead to losing skilled candidates to competitors.

Despite the hurdles, this study indicates that the Canadian tech sector remains resilient, with a clear focus on growth and innovation. As companies adapt to these challenges, the landscape for hiring and employment in technology continues to evolve.

Sources include: ITBusiness.ca

In a strategic pivot aimed at reshaping its future, Intel is splitting into two distinct entities. This move is not just about restructuring; Intel is trying to become the world’s second-largest chip manufacturer by 2030. 

Speaking at Intel’s Foundry Direct Connect event in San Jose, California Intel CEO Pat Gelsinger said “We want to be the foundry for the world. If we’re going to be the Western foundry at scale, we can’t be discriminating in who’s participating in that,” 

By dividing its operations, Intel is hoping to win business from rivals traditionally viewed as competitors.

The split creates two independent organizations under the Intel umbrella: Intel Foundry Services (IFS) and Intel’s Product division. IFS will now encompass technology development, supply chains, fabrication, and packaging services, marking a significant expansion of its capabilities. 

The Product division will concentrate on developing and licensing client, desktop, and networking equipment, operating similarly to a fabless chipmaker.

The two divisions will have separate staff, processes, and even sales forces. This allows Intel to engage in arm’s length transactions between its foundry and product groups.

Intel’s strategy also involves deepening its collaboration with Arm, aiming to make Arm’s intellectual property available on Intel’s process nodes. This partnership, described as “strange bedfellows” by Arm CEO Rene Haas, underscores the unconventional yet promising alliances Intel is forging to fill its fabs and push the boundaries of technology.

With this focus on chip manufacturing Intel is also hoping to take a substantial of the 39 billion dollars of subsidies for chip fabrication in the US and EU CHIPS Act.

But Gelsinger is not yet ready to spin off the foundry business entirely, taking a cautious approach to fully separating Intel’s manufacturing capabilities from its product innovation arm. 

But the move towards creating legally distinct entities hints at a future where Intel could move depending on the success of this initial split.

Sources include: The Register

In a significant disruption that unfolded across the United States, thousands found themselves without cell service as AT&T, alongside other providers, faced network outages. 

This widespread service interruption left many unable to make calls, send texts, or access the internet on their mobile devices, raising concerns over public safety and the ability to reach emergency services.

AT&T was the most affected carrier. Reports of service disruptions peaked early Thursday, with Downdetector noting over 73,000 complaints shortly after 8:30 a.m. ET. 

Customers reported a complete loss of signal, rendering their mobile phones unusable. 

The outages predominantly affected major cities including Houston, Atlanta, and Chicago. 

AT&T responded with advisories for customers to rely on Wi-Fi calling while efforts were underway to restore full service. By later in the day, the company announced that three-quarters of the network had been reinstated, with ongoing work to reach full restoration.

Verizon and T-Mobile users also encountered service issues, albeit on a smaller scale compared to AT&T’s challenges. Verizon assured that their network was “operating normally,” suggesting some difficulties arose from attempts to connect with users on the impacted AT&T network. T-Mobile’s stance mirrored this, attributing Downdetector’s outage reports to similar cross-network connection attempts rather than an internal failure.

The outages extended were more than an inconvenience. 

Authorities, including the San Francisco Fire Department and police departments in Irving, Texas, and Prince William County, Virginia, were affected.

The incident serves as a stark reminder of our dependency on digital connectivity and there will no doubt be investigations to determine the cause of the outage.

Sources include: Axios

A couple of updates our our Reddit stories of the past few day. It turns out that Google was the AI company that was willing to pay Reddit 60 million dollars a year for access to their data. 

And another Reddit tid-bit. As the company goes public it is planning to offer the opportunity to buy shares to its most loyal supporters. Forum moderators and those with over 2,000 karma points, the mark of a Reddit contributor will get preferential treatment, something that is usually reserved for large corporate investors. 

Sources: Various

In a candid LinkedIn post that has since gone viral, Seattle-based software engineer Alex Nguyen shares his view on job hopping, challenging the traditional notion of company loyalty. 

Having moved between Amazon, Microsoft, and Google within a span of three years, Nguyen’s career sparked a spirited conversation about employer-employee loyalty in the modern workforce.

Nguyen pointed out the financial benefits of job-hopping. He netted a 20% salary increase by moving from Amazon to Microsoft for a role with identical responsibilities. He noted that It’s a lot easier to ace a job interview than to get promoted.

Nguyen’s post sparked a spirited debate and some downright nasty comments. Some argued that a resume filled with short stints may deter potential employers, while supporters applauded the opportunity for growth, connections and passion over job stability.

But is raises a couple of questions. If companies can axe jobs to meet profit objectives, why should employees not move to enhance their earnings? But in a world where we all essentially become glorified contractors or “guns for hire” how do you build a unique company culture? Isn’t a company’s competitive advantage it’s team? 

And can you have customer loyalty if you don’t have employee loyalty? 

Sources include: GeekWire

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition. 

I got comments on my story yesterday on the growth in C level titles. Thanks. I am really interested in what you think about AI and your reaction to the story today. 

I like to keep it real and knowing what you think is a big help. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Fabulous Friday.

 

The post Hashtag Trending Feb.23- Companies losing top talent with long hiring processes; Intel – the “foundry for the world?”; AT&T outage first appeared on IT World Canada.

Cyber Security Today, Feb. 23, 2024 – A cyber warning on the second anniversary of Russia’s invasion of Ukraine, and more LockBit news

A cyber warning on the second anniversary of Russia’s invasion of Ukraine, and more LockBit news

Welcome to Cyber Security Today. It’s Friday, February 23rd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

 



 

Saturday will mark the second anniversary of Russia’s invasion of Ukraine. Russia may mark the day in several ways, one of which may be by launching or approving the launching of cyber attacks against countries that support Ukraine. So Canada’s Communications Security Establishment — the government’s cybersecurity and electronic spy agency — is urging IT departments to be vigilant. That’s especially true for critical infrastructure providers. Possible activity ranges from defacing websites and denial of service attacks to doing really nasty things. Now’s the time to make sure the cybersecurity basics are in place like making sure essential systems aren’t open to the internet and being prepared for denial of service attacks.

Following on this week’s international disruption of the LockBit ransomware gang, the U.S. State Department is offering up to US$15 million for information leading to the arrest and/or conviction of gang leaders and affiliates. Some 200 cryptocurrency accounts linked to the gang have been frozen as well as 14,000 accounts on email and file hosting providers. According to one report, law enforcement was able to infiltrate LockBit’s IT infrastructure by exploiting an unpatched vulnerability.

Earlier this week ConnectWise warned users of its ScreenConnect application to apply an update immediately. Some weren’t fast enough. Researchers at Sophos say some organizations have been hacked this week through ScreenConnect and suffered malware attacks including the installation of LockBit ransomware — possibly by gang affiliates.

Later today my Week in Review podcast will be out. Among other things guest commentator Terry Cutler of Cyology Labs will talk about how badly LockBit has been hurt.

The U.S. Cybersecurity and Infrastructure Security Agency has issued advice on how to secure water utilities. This comes after reports last December that an Iran-linked hacking group was targeting and compromising water and wastewater processing plants through vulnerabilities in a programmable logic controller. The CISA report recommends eight actions for utilities that come under cybersecurity 101. They include conducting a thorough inventory of all IT and OT assets; limiting the exposure IT or OT systems to the internet like controllers and remote terminal units; changing the default passwords of any hardware and software; and conducting regular cybersecurity assessments.

Finally, the U.S. Federal Trade Commission will order software provider Avast to pay US$16.5 million and forbid the company from selling or licencing web browsing data for advertising to settle allegations the company sold data to third parties after promising its products would protect consumers from online tracking. The FTC says Avast collected consumer data through its antivirus software and browser extensions and sold it without adequate notice or consumer consent.

A reminder to watch for the Week in Review podcast later today with lively commentary on some of the week’s news.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 23, 2024 – A cyber warning on the second anniversary of Russia’s invasion of Ukraine, and more LockBit news first appeared on IT World Canada.

Charting Canada’s AI future: Firms must move quick, innovate, panel says

A recent Empire Club of Canada luncheon panel explored what Canadian organizations must do to keep up with the rest of the world when it comes to developing artificial intelligence (AI) advances, and, equally important, what the fallout will be if they do not.

Sal Rabbani, chair of the organization, kicked off the presentation, entitled Charting Canada’s AI Future: How to Build a Resilient Framework for Investment, Adoption, and Economic Prosperity, by saying there is much to consider when it comes to AI – “from government and investment to the state of adoption to the unimaginable way it will impact our economy, our workplaces and our lives.”

Prior to the panel discussion, there were opening remarks from Angus Lockhart, senior policy advisor at  the Dais, a public policy think tank at Toronto Metropolitan University (TMU), whose subject areas include the impact emerging technologies such as AI are having, or will have, on Canada and its economy.

“When we talk about commercialization of AI at the Dais, why do we care?” he asked. “Well, we care because – and this is a problem Canada has been facing for decades – there is declining productivity growth. Back in 2022, (federal finance minister) Chrystia Freeland acknowledged that we’re falling behind when it comes to economic practice productivity, and called it both a well known Canadian problem and an insidious one.

“This has been an ongoing problem for the last two decades, and to us, AI represents a path to challenging this – it is an opportunity to fight labour shortages, while increasing productivity and bolstering Canada’s competitiveness. That is assuming that we can adapt AI successfully in businesses, and that is a big assumption.”

The challenges and opportunities Canada faces were left to the panel, moderated by Jordan Jacobs, co-founder and managing partner of Radical Ventures, a venture capital firm that focuses on AI and deep tech, and co-founder of the Vector Institute, a not-for-profit organization dedicated to AI research.

Joining him were Martin Kon, president and chief operating officer (COO) of Cohere, a Canadian tech firm that specializes in large language models (LLMs), Chris Walker, the chief executive officer (CEO) of Toronto-based chip manufacturer Untether AI, Mara Lederman, the co-founder and COO of Signal 1, an AI company that focuses on the healthcare sector, and Tony Gaffney, president and CEO of the Vector Institute.

Asked by Jacobs to describe the potential market opportunity for AI, Kon described it as the “biggest transformation and disruption to everything that the world is doing since the Mosaic browser came out in 1993, which was when the internet started to become mainstream.

“If you look at how much the world changed between 1995 and 2005, every single enterprise fundamentally changed everything they did, and those that did not, do not exist anymore. Those that did it well were extremely successful.

“The same will happen now in terms of enterprises that embrace AI, that are quick and innovate, versus those that do not.”

Lederman, formerly a professor at the University of Toronto’s Rotman School of Management, said that it is “probably uncontroversial to say three things about AI and healthcare: one: it is probably the biggest opportunity for AI – all types of AI, not just what we’re doing – two: almost no industry is as behind as healthcare in adopting AI, and three: we all believe we’ll get there, but none of us know exactly how.

“And that’s the problem we’re trying to solve. We’re trying to build the technology system, both the actual AI applications and the underlying platform that manages those applications.”

AI, said Lederman, can be used to get people admitted into a hospital sooner or determine who should or should not walk into an emergency ward. “The opportunity for AI in healthcare is not that it is massive, it’s entirely essential.”

There is, she said, a “huge mismatch of supply and demand” when it comes to healthcare and the Canadian population, and it can not be fixed by building more hospitals and “shuffling” medical staff from one place to another. “The only answer is technology, not just AI. But AI in particular is incredibly well suited for expanding our capacity and to deliver health care to a growing number of people.”

Without the right silicon, said Walker, there is no AI, for it is the silicon that runs the AI models and is how they get deployed.

“One way that we help AI become real in the world is being able to process it faster so, for example, a street corner can be safer. Agriculture technology, you don’t think about AI, but if you can have an autonomous tractor that, instead of using pesticides, is using a laser to zap weeds. AI is necessary to do that at speed and at a pace to make it productive.

“What’s also transformative is in the generative and language model space, it has the opportunity to take small businesses and let them compete like big businesses. And this is something as important as when the internet opened the world to people. The generative tools, the things people are going to do to build and use code to build up their applications, it’s going to make them appear and compete on the world stage at a much larger scale as a startup.”

Another key angle relating to silicon revolves around what Jacobs described as “governments – the U.K. France, Germany, Japan, Saudi Arabia and the UAE – literally buying up chips, which has never happened before.” He asked Gaffney what the federal government can do to ensure that Canada has an adequate supply of compute resources.

Governments around the world, replied Gaffney, need chips to build a national compute infrastructure that supports AI over the near to medium and long term, and also to work with research organizations, startups, and industry to ensure they can secure an adequate supply now.

“I would say that there’s no need for government in Canada to wonder what it should do, for best practices have emerged,” he said. “Other countries are acting for us and, if you think about it, it’s a national supply chain risk if we can’t get the compute we need.”

The first two questions computer science students and faculty contemplating coming to Canada now ask, he said, are “’what compute can you provide me with, and what data is going to be available to me to do my work?’

“What is at risk here is not just supply chain for what we built. The research work that we continue to lead and the talent pool that we have here is top of mind for them.”

Without adequate computing resources, said Gaffney, “people won’t come, and that’s really bad. People who are here will consider their options, and that’s really bad. And the startup community that’s flourishing around them will also consider their options as to where else they can go.

“I don’t have to continue the story. Investors have come here because of the talent pool. We just cannot let (an exodus) to happen.”

The post Charting Canada’s AI future: Firms must move quick, innovate, panel says first appeared on IT World Canada.