Page 18 of 55

Critical infrastructure cyber law needed ‘more than ever,’ Parliament told

The Canadian government’s proposed law forcing critical infrastructure providers to toughen their cybersecurity is “needed now more than ever,” an expert told a parliamentary committee on Monday.

“We are far behind our allies” in protecting critical infrastructure firms, David Shipley, CEO of New Brunswick’s Beauceron Security and co-chair of the Canadian Chamber of Commerce’s cyber committee, told the House of Commons national security committee.

“And,” he added, “we are risking the safety and prosperity of Canadians every day we delay.”

However, again delaying and reducing the amount of time witnesses could testify on Bill C-26, which would create the Critical Cyber Systems Protection Act (CCSPA), is exactly what MPs on the committee did.

For the second meeting in a row, MPs bickered about allowing a Conservative motion to have sessions examining current and former cabinet ministers, to justify invoking the Emergency Act a year ago to break up protests in Ottawa. It was the third meeting on C-26 that a proposed Conservative motion on a different topic interrupted witness testimony. In contrast, an industry committee meeting Monday dealt with a Conservative motion at the end of the session, so witness time wasn’t cut.

At least 30 minutes of the two hours set aside Monday to hear witnesses testify on the  proposed cybersecurity law Monday was chewed up as Conservative Glen Motz — in the middle of the experts’ testimony — tried to continue debate on his motion last week calling for witnesses and government legal documents justifying use of the Emergency Act. Later, he interrupted testimony by introducing a second, slightly different, motion to do the same thing.

Motz thought he had a “gentleman’s agreement” to introduce that motion last week. But under protests for the length of time he was taking — and the fact that witnesses had flown to Ottawa to testify at the taxpayer’s expense — he agreed to adjourn his motion for Monday’s committee meeting.

Eventually things got testy, with Liberal Jennifer O’Connell verbally fencing with meeting chair Conservative Doug Shipley [no relation to David Shipley]. Shipley told her to stop interrupting him, then abruptly adjourned the meeting.

Bill C-26 has two parts: One would amend the Telecommunications Act to give the federal cabinet and the Minister of Industry the power to order designated telecom providers to do “anything” to secure their systems against a range of threats. The other part, creating the CCSPA, would apply to other critical infrastructure providers. Initially, these would be limited to banking, financial clearing firms, interprovincial transport and energy companies, and nuclear power operators. Similar to the Telecommunications Act changes, it would create a cyber security compliance regime for designated federally regulated firms. Included would be a requirement to report cyber incidents “immediately” to the Canadian Security Establishment (CSE), the branch of the Defence Department responsible for government cybersecurity.

Related content: What C-26 requires of companies

In his opening remarks, David Shipley of Beauceron Security — a regular guest on IT World Canada’s Cyber Security Today Week in Review podcast — said C-26 needs some “fine-tuning,” including the following:

— companies should be allowed to raise the defence of “due diligence” (essentially, ‘We did our best’) if faced with administrative fines under C-26 for not keeping their IT networks secure;

— MPs should remove C-26’s ability to hold employees, directors, and officers to be held personally liable for committing or directing violations of the act. That puts “a target on their heads” and will discourage people from choosing a career in IT, Shipley said;

— the government should ensure in C-26 that regulators who will have to enforce the CCSPA have the cybersecurity skills to do it.

— and MPs should change the bill to limit the amount of sensitive data regulators can collect about cybersecurity defences of critical infrastructure firms. That information would be a “one-stop shop” for cyber crooks looking for ways to cripple those firms, Shipley said.

In their presentations Monday, the Canadian Chamber of Commerce and IBM said C-26 should be changed to allow designated firms up to 72 hours to report cyber events to regulators. They also called on MPs to clarify in the proposed law details such as what has to be reported, and not leave it up to the government to declare those details in regulations after the law passes.

Todd Warnell, chief information security officer at Bruce Power, an Ontario nuclear power generator, said C-26 “is of vital importance.”

The post Critical infrastructure cyber law needed ‘more than ever,’ Parliament told first appeared on IT World Canada.

Pass Canadian AI law as soon as possible, expert tells Parliament

A Canadian who is one of the world’s leading thinkers on artificial intelligence says Canada’s proposed AI law needs to be passed as soon as possible.

“We urgently need agile AI legislation, and I think this law is moving in right direction,” Yoshua Bengio, scientific director of Mila, Quebec’s Artificial Intelligence Institute, told the House of Commons industry committee studying the proposed Artificial Intelligence and Data Act (AIDA) on Monday.

While other experts have told the committee that AIDA should be withdrawn for a complete redrafting or until more public consultation has been held, Bengio urged Parliament to pass AIDA soon — although with some amendments.

“An imperfect law with regulations to be adopted later is better than no law, or postponing it,” he said.

In fact, Bengio added, it’s so critical to oversee AI that some rules should come into effect as soon as AIDA is signed, rather than wait the expected two years or so while regulations with details about how some things in the bill will work are being written by the government.

For example, he said, as soon as the bill is signed into law, businesses would have to list AI systems above a set capacity, showing information about the system’s safety, security measures, and security assessments. The AI regulator — at the moment proposed to be an official of the Innovation ministry — would be able to use that information to create best-in-class requirements for future permits to continue developing and deploying advanced systems.

“This would put burden of demonstrating safety on developers with the billions required to build these advanced systems, rather than taxpayers,” Bengio said.

Computing systems that are as smart as humans (what he called “superhuman AI”) with the capacity for what experts call artificial general intelligence (AGI) may be online within two decades and “possibly in the next few years,” he said. But, he added, society isn’t ready.

“The current AI trajectory poses serious risk of major societal harms even before AGI is reached,” he said.

RELATED CONTENT: Government updates proposed AI, privacy laws

While progress in AI has opened what he called “exciting opportunities for numerous beneficial applications,” he noted, “it is urgent to establish the necessary guardrails to foster innovation while mitigating risks and harms.”

Briefly, AIDA would oversee classes of “high-impact” AI systems — such as those covering employment, providing services to an individual, processing biometric information for identification, moderating content on a search engine or social media platform, or being used by police. It would be illegal to deploy an AI system likely to cause serious physical, psychological or economic harm to an individual. Persons responsible for high-impact systems would have to establish measures to identify, assess and mitigate the risks of harm or biased output that could result from the use of the AI system.

In addition to amending the legislation so the registry would come into immediate effect, before regulations are set, Bengio also said there should be two other additions:

— the definition of a high-impact AI system should include “national security risks and societal threats,”

— and an AI developer should be required to show its safety and security before the system is fully trained and deployed. “We need to identify risks early in an AI lifecycle,” he explained.

The post Pass Canadian AI law as soon as possible, expert tells Parliament first appeared on IT World Canada.

Global tablet market ends tough 2023 with 11% decline in Q4: Canalys

According to the latest data from Canalys released today, global tablet shipments experienced a drop of 11 per cent year-on-year in Q4 2023, to a total of 37.8 million units. The findings resulted in a full-year 2023 figure of 135.3 million tablets shipped, a 10 per cent decrease from 2022.

“The latest holiday season saw a significant surge in tablet promotions and bundled offers, but this was not enough to reverse the market’s fortunes, “said Himani Mukka, research manager at Canalys.

Mukka added, “with healthier inventory levels and further scope for government and commercial deployments, tablet sell-in is expected to rebound in 2024. New models announced by TCL and Lenovo at CES 2024 and anticipated updates to Apple’s iPad portfolio early this year will help provide a boost to the tablet refresh opportunity.”

Kieran Jessop, an analyst with the firm, said that a key element that tablet vendors need to pay attention to is the “innovation gap between tablets and other personal computing devices.

“Plans around on-device AI integration in tablets trail behind those in PCs and smartphones. Bringing this functionality across devices will be crucial for vendors aiming to deliver a unified and seamless experience on ecosystems. Elsewhere, this year will see a greater focus on foldable tablet form factors. Although shipment volumes will likely remain restricted due to the premium pricing of these models, they will provide an opportunity for vendors to showcase user-experience benefits for content consumption, learning and productivity.”

Apple maintained its leading position in shipments despite a 24 per cent year-on-year decline, shipping 14.8 million iPads in the quarter, while Samsung secured second spot with 6.8 million units shipped, posting an 11 per cent annual decrease.

Huawei landed in third, with 2.8 million units shipped following healthy growth, and Lenovo, Canalys said, “dropped to fourth place but posted healthy shipment growth of 15 per cent, gaining over two points of market share year-on-year. Amazon rounded out the top five, with a 44 per cent annual decline and two million tablets shipped globally.”

The news is much brighter when it comes to PC shipments. Canalys is predicting that full-year 2024 shipments will hit 267 million units, an eight per cent rise from 2023, helped, it said, by “tailwinds including the Windows refresh cycle and emergence of AI-capable and Arm-based devices.”

In a forecast released late last year, Canalys analyst Ben Yeh said the global PC market is on a recovery path, and set to return to 2019 shipment levels in 2024: “The impact of AI on the PC industry will be profound, with leading players across OEMs, processor manufacturers, and operating system providers focused on delivering new AI-capable models in 2024. These initiatives will bolster refresh demand, particularly in the commercial sector,” he said.

The total shipment share of AI-capable PCs, he added, “is expected to be about 19 per cent in 2024. This accounts for all M-series Mac products alongside the nascent offerings expected in the Windows ecosystem. However, as more compelling use-cases emerge and AI functionality becomes an expected feature, Canalys anticipates a fast ramp up in the development and adoption of AI-capable PCs.”

The post Global tablet market ends tough 2023 with 11% decline in Q4: Canalys first appeared on IT World Canada.

Cyber Security Today, Feb. 5, 2024 – Warnings to AnyDesk and Mastodon administrators, a lesson from a Cloudflare breach, and more

Warnings to AnyDesk and Mastodon administrators, a lesson from a Cloudflare breach, and more.

Welcome to Cyber Security Today. It’s Monday, February 5th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



IT administrators allowing the use of the AnyDesk remote desktop connection software should immediately force users to change their passwords. This is because the developer realized hackers recently got into the company’s production systems. In addition to changing passwords, IT must mandate the use of multifactor authentication as an additional login step if it hasn’t already done so. AnyDesk revealed the compromise on Friday. On Saturday researchers at Resecurity said at least two crooks are already offering to sell 18,000 credentials apparently stolen from AnyDesk customers. The cost of buying those 18,000 passwords? US$15,000 in cryptocurrency. Resecurity has warned that particular group of users that their credentials are at risk. Compromising an AnyDesk installation could lead to compromise of the IT system.

Employees need to be warned that threat actors often try to trick people into installing AnyDesk so they can remotely access computers. Scams include emails or phone calls pretending to be from Microsoft or another company saying they need to install AnyDesk to clean their Windows computer. Another scam is a communication claiming to be from AnyDesk support saying they need remote access to the person’s computer or their Android or Apple smartphone.

Administrators overseeing instances of the Mastodon social networking platform need to update their servers. Due to a vulnerability attackers can impersonate and take over any remote account. All versions of Mastodon are vulnerable.

The consequences to some companies of the compromise last October of identity and access management provider Okta continue to emerge. Last week security provider Cloudflare said a threat actor accessed the Atlassian servers that run its internal source code management system, its corporate wiki and its bug database. How did the attacker do it? By using one access token and three Cloudflare service account credentials that were among credentials stolen from Okta in October. Cloudflare’s mistake? Most, but not all of its credentials were rotated after being told of that attack. Why not rotate them all? Because staff thought those particular accounts weren’t used. The lesson: Don’t assume anything when password credentials have to be revoked, rotated, reset or whatever you call it.

Four vulnerabilities have been found that could allow an attacker to escape the confines of a Docker or Kubernetes container, whose goal is, as the name suggests, to contain nasty people. The discovery by researchers at Snyk means that developers using containers and container build tools need to update those applications as soon as patches are released by their vendors.

Another U.S. company has reported the high cost of a cyberattack. Cleaning products manufacturer Clorox said in a regulatory filing that so far the August cyberattack has cost it US$49 million in IT recovery and related costs. That included having to take systems off line, which resulted in disruption of business operations for weeks. Clorox may get some insurance coverage for some expenses.

A U.S. regulator says the “shoddy” cybersecurity and data retention practices of an American company called Blackbaud caused a huge data theft and ransomware attack in 2020. Blackbaud provides data services to nonprofits, schools, healthcare providers and businesses. Among the victims were universities and charities in the U.S., Canada and the U.K. The U.S. Federal Trade Commission said last week that Blackbaud didn’t monitor attempts by hackers to break into its networks, didn’t segment data for security, didn’t ensure sensitive data that wasn’t needed was deleted or adequately implement multifactor authentication. The attacker was in its system for three months. Blackbaud paid a ransom of about US$250,000, but never verified the attacker actually deleted stolen data. And it waited nearly two months do notify customers about the theft of their data. As part of a proposed settlement with the FTC Blackbaud will have to develop a comprehensive IT security program, and delete personal data it doesn’t have to hold.

News is now coming from Interpol that law enforcement agencies from 50 countries including the U.S., Canada and China participated last fall in the seizure of servers behind phishing, malware and ransomware attacks. So far Operation Synergia has seen 31 people arrested or detained.

Finally, a former CIA software developer has been sentenced to 40 years in prison for sending classified agency documents to the WikiLeaks website and possession of child pornography. Joshua Schulte wasn’t a model employee. In 2016 he was transferred from his work at the time to another branch because of a dispute with another developer. In his new post his administrator privileges were soon revoked. However, he kept secret server adminin privileges which allowed him to steal documents in the largest data breach in CIA history and send them to WikiLeaks from his home computer. While investigating the theft of those documents from the home computer the FBI cam across the child porn.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 5, 2024 – Warnings to AnyDesk and Mastodon administrators, a lesson from a Cloudflare breach, and more first appeared on IT World Canada.

Scientists create functioning brain cells using 3D printing: Hashtag Trending, Monday February 5th, 2024

Canada moves closer to the EU on addressing issues of digital technology. IBM demonstrates how deep fakes can be a new risk area, in what seems like a scene out of Die Hard, researchers show how a digital highjacking could happen and scientists use 3D printing to create functioning brain cells.

All this and more on the, “Master, I’ve got the brain” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Listeners will probably notice that we cover a lot of stories about the EU and its legislation, partly because in key areas, the EU seems to be in the lead with its approach to regulating both AI and big tech – as opposed to the theatre that we see in the US government.

In a recent announcement, it appears that the government of Canada agrees with our assessment.

The Minister of Innovation, Science and Industry, the Honourable François-Philippe Champagne, and the European Union (EU) Commissioner for Internal Market, Thierry Breton announced the implementation of a Canada-EU Digital Partnership, which was concluded at the Canada–European Union Summit 2023 held in Canada in November.

They issued this joint statement following their virtual meeting:

“The Digital Partnership will help the EU and Canada address new challenges in digital transformation that impact research, industry, society and the broader economy.

“It aims to focus on increasing cooperation on artificial intelligence (AI), quantum science and semiconductors; public policy related to online platforms; secure international connectivity; and cyber security. These priorities will be discussed at the officials’ level through a Digital Dialogue in February.

“On semiconductors, the EU and Canada intend to cooperate to address future disruptions in the semiconductor supply chain by exploring monitoring and early warning mechanisms. They intend to exchange information on public support to the sector.

“On AI, the EU and Canada intend to set up regular channels of communication and exchange information through workshops, including on AI governance and international standards.

“On quantum science, the EU and Canada will expand mutually beneficial collaboration to accelerate research, development and innovation while promoting jobs and the utilization of quantum technologies in the broader economy.

“On online platforms, the EU and Canada intend to continue to cooperate and exchange information on measures to ensure transparency, fairness and accountability and to make the Internet a safer and more inclusive place for users.

“On secure and resilient connectivity, the EU and Canada intend to exchange information to encourage the development of secure and high-quality connectivity. The partners will also explore actions to develop secure and high quality connectivity between Europe, North America and Asia, for example, potential routes in the Arctic or North Atlantic.

“On cyber security, the EU and Canada intend to collaborate on the implementation of cyber security regulatory frameworks, including in the areas of critical infrastructure protection and cyber security of products.

“On digital identity, digital credentials and trust services, both sides intend to promote interoperability through pilot projects.

It’s a lot to take in but this marks a big move for Canada to become a partner with the EU. There’s a link to the full announcement in the show notes.

Sources include: Cision (link to full announcement)

Just to show the contrast, here’s a story from over the weekend on US regulations.

In an unprecedented surge, AI-related lobbying efforts have skyrocketed by 185% in 2023, with over 450 organizations now actively participating in shaping the future of artificial intelligence regulation.

This significant increase, analyzed by OpenSecrets for CNBC, highlights the tech industry’s urgency in influencing policy amidst the Biden administration’s push for regulatory frameworks. Companies such as ByteDance, Tesla, and Nvidia, along with entities spanning sectors from Big Tech and startups to finance and academia, have joined the lobbying frenzy. This diverse coalition aims to ensure that forthcoming AI regulations foster innovation while addressing ethical and societal concerns.

The landscape of AI lobbying has evolved dramatically, from a handful of organizations before 2017 to a broad spectrum of industries now advocating for their interests. The collective lobbying expenditure topped $957 million in 2023, covering AI among other issues.

The U.S. government has responded with initiatives like President Biden’s executive order on AI, setting the stage for developing standards and assessments aimed at safe and equitable AI deployment. As the industry and policymakers navigate these complex discussions, the focus remains on balancing technological advancement with ethical considerations and societal impact.

Sources include: CNBC

IBM researchers have uncovered a new method for hijacking voice calls using generative AI, a development that could have significant implications for financial institutions and others who manage sensitive data. This technique, known as “audio-jacking,” allows cybercriminals to manipulate ongoing conversations by cloning voices and intervening in real-time discussions.

By exploiting low-cost AI tools, scammers can easily impersonate individuals, swapping out spoken content with fabricated responses. For example, during a conversation about bank accounts, an AI chatbot could substitute a victim’s bank account number with that of the attacker, diverting funds to the wrong destination.

The process begins with malware installation on the victim’s phone or compromising a voice-calling service, after which the chatbot scans for specific keywords to trigger the voice swap. Despite the potential for misuse, IBM’s experiment also revealed some hurdles, including delays in the cloned voice’s response and the varying quality of voice mimicry.

Cybersecurity experts caution that generative AI is making voice scams more believable, with some attacks requiring as little as three seconds of someone’s voice to create a convincing clone. However, the effectiveness of these scams can be mitigated by vigilance and simple verification techniques during suspicious calls.

Source include: Axios

In a scenario reminiscent of a movie plot, researchers have shown how criminals could remotely manipulate data in aviation apps, potentially affecting aircraft takeoff and landing procedures. This vulnerability, discovered in an app used by Airbus pilots, highlights the growing concern over cybersecurity in aviation. While the actual risk of exploitation is considered low due to specific conditions required for an attack, the study underscores the importance of securing digital flight systems against potential threats. Airbus has since addressed the issue, reinforcing the continuous effort to safeguard flight operations from cyber vulnerabilities.

Sources include: The Register.

In a groundbreaking development, researchers have successfully created the first functional 3D-printed brain tissue, paving the way for revolutionary advances in the study of the brain’s function and neurological disorders. This innovative work was conducted by experts at the University of Wisconsin-Madison, where they developed printed tissue capable of growing and functioning akin to typical brain tissue. The primary aim of this 3D-printed brain model is to facilitate research into neurological and neurodevelopmental disorders, including Alzheimer’s and Parkinson’s disease.

Researchers highlighted the potential of this model as a powerful tool in understanding the communication between brain cells and various parts of the human brain.

The printed tissue, designed to be thin to ensure optimal nutrient and oxygen intake, allowed cells to form networks mirroring those in human brains. These networks facilitate active communication through neurotransmitters, enabling neurons to send signals to one another. Remarkably, the tissue incorporated different brain cells, such as those from the cerebral cortex and the striatum, which could interact in specific ways despite their distinct origins.

This breakthrough not only offers new insights into the complex communication and network development within human brain tissue but also stands to revolutionize stem cell biology, neuroscience, and our understanding of various neurological and psychiatric disorders. The precision of this 3D printing approach allows for control over cell types and their arrangement, a feature not present in brain organoids, which are miniature lab-grown organs used for brain research.

Source include: Interesting Engineering,

I’m not scared about this. Are you? I mean, what could go wrong?

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts.

I’m your host Jim Love, thanks for listening and have a Marvelous Monday.

 

 

 

 

 

 

 

 

The post Scientists create functioning brain cells using 3D printing: Hashtag Trending, Monday February 5th, 2024 first appeared on IT World Canada.

Apple’s New Vision Pro: The Best of YouTube

I watch far too many YouTube videos – so you don’t have to.

I’ve read a lot about the Vision Pro from Apple but these crazy guys give a really good and objective view of the Vision Pro. It’s far better than the fanboy raves or the corporate blah-blah. If you are interested in finding our what Apple’s Vision Pro is but like me, aren’t going to spend thousands of dollars to find out – check this out.

Here’s what they the talk about in the video. It’s rough notes but it’s what I remember. It’s a mixture of points and quotes from the video. Of course, check it out for yourself. This is just a guide:

The battery in the Vision Pro is heavier and bigger than expected, with an M2 Chip and R1 chip putting out 78 Watts.

The quality looks insane, like looking at a 4K display or maybe better than a 4K 32in display.

“I got my phone out and it is all blurry just like with most cameras. You have a Minal focusing distance so right over here. It’s sharp but it’s still fuzzy to read the text.”  (This came as a surprise to me)

The speed of controlling stuff with my eyes on the Vision Pro is way faster than a mouse, it’s insane! (This is really cool – how you can select things with your eyes. This had me thinking about real uses for this. Also watch for how you select things with gestures. We are seeing what the next interface with out computers will be like, maybe not today, but sometime very soon.)

The app downloaded and installed almost instantly, making it so easy to spend money on this. (They are talking about how easy it is to buy apps using the Vision Pro. There aren’t a lot of them yet – I covered that disappointment in my daily podcast. But when they are there, this is going to be how Apple will make billions from you, a few dollars at a time. They already pull in close to 100 billion dollars in purchase in their app stores.)

Connecting the Vision Pro to a Mac and screen mirroring to another laptop for screen recording is really impressive, it looks better than expected and legit looks like 4K quality.

The processing is being done four times speed on my Mac, and it actually is really quick and as far as the quality being able to read everything it looks really good. (They talk a lot about the speed of how this delivers, which is absolutely critical and it seems to be working. I wonder what it would be like in my satellite internet world.)

Wearing the Vision Pro for 3 hours was comfortable, with minimal pressure and no issues with the weight on the face. (I can’t imagine keeping that thing on for three hours. But apparently, Apple has pulled it off and it’s comfortable enough for long sessions.)

That’s my “best of YouTube” for the Apple Vision Pro.  Let me know if these are helpful or useful. I’ll try to give you only the videos that I find appear to be honest, factual and informative.

 

 

 

The post Apple’s New Vision Pro: The Best of YouTube first appeared on IT World Canada.

Cyber Security Today, Week in Review for the week ending Feb. 2, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, February 2nd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In a few minutes David Shipley of Beauceron Security will be here to discuss recent news.

That includes more revelations from 23andMe and from Microsoft about their recent data breaches; the Canadian government investigating a hack at Global Affairs, this country’s foreign service; the FBI’s testimony before Congress on the cyber threat from China; Canada’s proposed cybersecurity law for critical infrastructure providers and the $27 million cost to Johnson Controls of a ransomware attack.

Also in the news in the past seven days, administrators of Ivanti Connect Secure VPN and Policy Secure gateways were told of the discovery of two new vulnerabilities they have to take action on.

A cyberattack against Fulton County, which includes the city of Atlanta, forced the temporary closing of some government IT systems. That included phone lines, the ability to file documents online with the court system, paying property taxes, accessing property records used for buying and selling land, the ability to pay water bills online and more. The county continues to work on restoring services.

Meanwhile one or more students at an innovation academy accessed the school district’s IT system without authorization. This is unconnected to the attack on the county.

Three Americans were charged with stealing more than US$400 million in a 2022 SIM-swapping attack. Security reporter Brian Krebs believes the funds were stolen from the now-defunct FTX cryptocurrency exchange.

Linux administrators and application developers were warned to make sure they’re running the latest version of the operating system. That’s because researchers at Qualys discovered four vulnerabilities.

The AlphV/BlackCat ransomware gang is trying to stay alive after the FBI took its infrastructure down in December. It may now be lying about successful attacks to get headlines — and possibly to trick victims into paying. That’s according to a researcher at RedSense. He told the news site Dark Reading this week that while AlphV claimed an attack on a defence contractor, but other than a few screen shots there’s no evidence the company was compromised.

And Juniper Networks released updates to fix high-severity vulnerabilities in its SRX and EX series firewalls.

(The following is an edited transcript of the first of the discussion topics. To hear the full conversation play the podcast)

Howard: Topic one: Timing is everything: The genetic testing service 23andMe gave new details about its huge data breach last week, and the Canadian government admitted the IT network of its foreign affairs department was hacked.

What do these incidents have in common? It took a while for them to be detected. In the case of 23andMe, hackers were in its system for five months. In the case of Global Affairs, the attacker was in the system for a month before detection. David, what does this say?

David Shipley: First, this kind of presence for that length of time is to the right of the median dwell time for cyber attacks, as measured in reports by Mandiant. Dwell time is the time criminals are in a network before either attacking with things like ransomware or being discovered by defenders. Dwell times have generally been trending down from 21 days in 2021 to eight to 10 days in 2022. Keep in mind median is one measurement. It’s not necessarily average. Average can be skewed by folks to the left or right of the median, so it’s really interesting. These attacks should have been caught sooner. I suspect if attacks were using normal tools in the 23andMe case that are regularly present in the IT environment — what we regularly call living-off-the-land — it’s going to be hard to spot unless the company has a very, very good monitoring program. And again, in the case of 23andMe, given that this was using a multitude of breached user accounts unless they were watching for logins from geographies outside of the private country of the user they’d likely have no clue what was happening — other than potentially looking for failed login attack patterns.

In the case of Global Affairs, I am deeply, deeply interested in learning more about what the VPN tool the government referenced as being an integral part of the breach. Was this a zero-day vulnerability or was it a more routine misconfiguration? Was this a known vulnerability? If so, why wasn’t it patched? I can’t imagine December 20th [when the hack reportedly started] was a great time for the IT team there [at Shared Services Canada] to be doing anything. I really hope we get more transparency from the federal government on what happened, how it happened and lessons learned. If they were using a commercial vendor product, this could be beneficial for many other organizations to learn from.

Howard: I thought that detection is one of the prime parts of a cyber security strategy.

David: It is, but it’s certainly not the only part of of a strategy. And you know, people’s perception of what detection actually is capable of doing, what catching something that’s abnormal when it looks and walks and talks everything that’s normal because you know … Stop and step back for second. Global Affairs will have logins from countries around the world. That’s where staff are. That’s where their embassies are, working remotely from internet service networks associated with those various countries. So a lot of the easy ways that people might detect things get a lot harder. It’s tough, but they do have some really really good tooling. So what I’m hoping is that we learn more about who the attackers were.

Howard: Well, 23andMe didn’t know about the incident until the hackers advertised that they had stolen data.

David: This wins the award for the worst possible way you can learn about a breach.

Howard; This was the second hack at Canada’s Department of Global Affairs in two years. Does that say something about government security?

David: I’ll use a hockey analogy: First shots on goal on the federal government are astronomical, Everybody’s trying to get into the net, so they’re never going to be perfect defenders. They’re too big of a target for too many players who have the money and patience to keep taking shots until they score. Second, we really need the government to come out and give us a sense of whether this was regular cybercrime, which would be disappointing to see get past its defenses, or another nation-state which frankly is much more understandable. It’s what we do to other countries. This is exactly the kind of target our intelligence agencies would be going for. It’s part of the great game and frankly, it’s fair game in spying This is what I would expect but I would like to understand the context.

Howard: Well, the Canadian government hasn’t given details about how Global Affairs was hacked two years ago. You know, silence isn’t golden.

David: It’s incredibly frustrating. We need the federal government to follow the leadership that some of the provinces like Nova Scotia have displayed. They did a great job being transparent and accountable during the MoveIT breach. And we need the federal government to lead by example, particularly in a time when they’re going to be passing legislation that will force others to provide it with information about their cyber incidents. It should do the same as a measure of good faith.

…… ….

Howard: Topic 6: American cyber leaders rip China.

In testimony on Wednesday before Congress, FBI director Christopher Wray complained China is attempting to preposition malware on the IT systems of U.S. critical infrastructure providers to strike whenever it wants. He also said the FBI had, with a court order, disrupted a [Chinese] botnet of hijacked American routers whose goal was to spread malware. That botnet was created by the group that security researchers call Volt Typhoon. The congressional committee also heard complaints about China from the Director of the Department of Homeland Security, the Cyber Security and Infrastructure Security Agency and the commander of U.S. Cyber Command. How likely is it that this saber-rattling will affect China’s cyber strategy?

David: I don’t think it’s going to affect it a whit. I think we also need to recognize the Americans are doing this to China, they were doing it to Russia. You’d be insane as a modern country to not be trying to get a foothold in these things as part of a holistic conflict strategy that might involve a proportional response. You know — you get hacked, the power grid goes down in Cincinnati and maybe you turn power off in Shanghai as a proportional response, versus let’s go straight to World War III. This is the Great Game. I find the timing fascinating, and the reason I say that is I was reading CNN earlier this week and we had President Biden and President Xi saying China’s agreed not to do election interference.

By the way, President Biden, free advice: Canada signed a nonaggression treaty with China back in the day under Prime Minister Trudeau about cyber after they raided our cookie jar and they didn’t keep their end of the bargain. So keep your election non-interference receipt with a big grain of salt.

Howard: This bot was composed of home office routers from Cisco Systems and Netgear that are no longer able to get or qualify for security updates. Once again old equipment is a security risk.

David: This goes back to something we were talking about in 2023 which had to do with internet of things regulation in security, reasonable lifespans for equipment and reasonable expectations for customers to keep them secure. Maybe we have to get to the point of saying, ‘As a responsible maker of technologies that can have a dual purpose — that is, they can be a great home router but also can become part of a zombie bot army used by the Chinese to shut down the power in Cincinnati — you have to keep these things patched and updated for 10 years. These patches have to flow through, ideally by default, automatically. Two things: People who are busy moving their regular lives aren’t trying to be cyber security network engineers at home. And that at the end of an equipment’s life you actually have to make it stop working when when there’s a reasonable notice period. ‘This thing is going to be out of security in 12 months and we’ve notified you and at the end of that 12 months it’s not going to be able to connect to the internet anymore.’ Maybe that’s the solution for home internet routers so they can’t be a threat to national security.

The post Cyber Security Today, Week in Review for the week ending Feb. 2, 2024 first appeared on IT World Canada.

Tories again cause testimony on proposed cybersecurity bill to be shortened

For the second meeting in a row, Conservative MPs shortened witnesses’ testimony at committee meetings looking into proposed cybersecurity legislation for overseeing critical infrastructure providers. They did it by bringing forward and forcing debate on other business.

What’s before the public safety and national security committee is Bill C-26, which would do two things: Amend the Telecommunications Act, and create a new Critical Cyber Systems Protection Act (CCSPA). Both would impose new cybersecurity obligations on critical infrastructure providers like telecom companies, banks, and energy companies

On Monday — when long-awaited hearings on Bill C-26 first started — the Conservatives cut into the time Industry and Defence Department witnesses could be questioned on the legislation by bringing forward a motion to start looking into the increase of carjacking in Canada. [See our coverage of Monday’s session here]. When a motion is tabled, committee work stops until it is voted on.

On Thursday, shortly after two witnesses gave their five minute opening statements, the Conservatives again stopped the hearing by raising a motion to start looking into the Liberal cabinet’s use of the Emergency Act during last year’s Ottawa protests over COVID restrictions. This even though another Parliamentary committee is already looking into that incident.

Liberal, NDP and Bloc Quebecois MPs on the committee protested that this was the second time this week the agenda of the committee had been — properly according to committee rules — diverted. Their protests were determined enough that the Conservatives were forced to agree to suspend debate on the second motion to another time, so hearing the witnesses could continue.

However, so much time was eaten up — almost an hour — that MPs didn’t get a chance to question Trevor Neiman of the Business Council of Canada and Byron Holland, CEO of the Canadian Internet Registry Authority (CIRA) after the pair had each given five-minute introductory statements. Instead, they left and the committee heard from other witnesses scheduled for the second hour of the session.

The legislation would allow the government to designate services and systems that are vital to national security or public safety.

The government could also designate the operators, or classes of operators, responsible for their protection. Firms would have to show the government they have a cybersecurity program, and report certain cyber incidents.

Among the controversial parts: the Minister of Industry would have the power to order telecom providers to do “anything” necessary to secure the Canadian telecommunications system. Under the CCSPA, the cabinet would have a similar power over designated critical infrastructure providers. Civil rights groups worry that “anything” gives the government unchecked power. The Telecommunications Act, though, includes examples of orders the minister can give, such as the removal of a product from a provider’s network.

While critical infrastructure providers include manufacturers, food producers and processors, interprovincial transport, pipeline and energy companies, banks and internet operators, the government has said initially the legislation would only apply to high-risk companies.

Neiman, the Business Council’s vice-president of policy, said the group is asking for “targeted amendments” to the CCSPA in several areas including:

— “fair and reasonable limitations” on the federal cabinet’s power to issue cybersecurity orders to critical infrastructure firms. Otherwise, Neiman said, the cabinet could give an order regardless of whether it would be effective or reduce risk to a critical cybersecurity system. As the wording stands now, he said, there would be no obligation for the cabinet to consider the costs to companies of complying with an order, if there are reasonable alternatives to an order, or to consider the possible effects on competition or customers;

— putting a risk-based methodology into the legislation that would put fewer and less onerous obligations on low-risk firms with well-established cybersecurity programs.

Holland suggested three changes to C-26:

—  any cabinet orders issued to firms under the CCSPA should be first examined by the Clerk of the Privy Council — the head of the civil service — and the Deputy Minister of Justice, who is usually a career civil servant;

— the CCSPA should limit the ability of the government to use cybersecurity data collected from companies for only cybersecurity and information assurance purposes;

— and the government should have to report annually to Parliament on how many orders it has given companies under the act.

After Neiman and Holland left — without being questioned by MPs because time had run out for their session — the committee heard from Aaron Shull, managing director of the Centre for International Governance Innovation, a Waterloo, Ont.-based think tank, and Sharon Polsky, president of the Privacy and Access Council of Canada, who made a joint submission with several civil rights groups including the National Council of Canadian Muslims.

“I think the bill is pretty good as it stands,” Shull said. However, he added, it should include a tax incentive to encourage small and medium-sized businesses to invest in cybersecurity.

Polsky complained the bill could allow the government to force companies to create backdoors, break encryption, “or go on a fishing expedition to find whatever information the government wants, including what’s in your emails and your texts, your cellphone and vehicle locations, purchasing information, donor details, so that it can make an order — and the order will be secret until the target realizes something’s up.

“With a nod to Eastern European regimes a hundred years ago, this bill lets the [Industry] minister compel any person, under threat of punitive fines, to provide any information within any time, subject to any conditions that might be specified, or authorize anyone to enter and seize any information in [IT systems], but without the checks and balances that are the mainstay of democracy.”

In short, the bill makes it impossible for organizations to comply with privacy laws, she said. Nor is there an obligation for the government to consult with the federal Privacy Commissioner to ensure personal information handed over is adequately safeguarded.

The joint submission says the CCSPA should be amended in several ways. One is to make it clear that the Industry Minister can’t issue an action order unless there are reasonable grounds to believe it is necessary. Before issuing an order, the Industry Minster should have to consult with the Minister of Public Safety and a body of industry experts.

The law should also make it clear that the cabinet can only ask a firm to comply with an order to protect a critical cyber system only “against a material threat.”

The post Tories again cause testimony on proposed cybersecurity bill to be shortened first appeared on IT World Canada.

Cyber Security Today, Feb. 2, 2024 – AI fakes are making trouble for facial recognition logins, and more

AI fakes are making trouble for facial recognition logins, and more.

Welcome to Cyber Security Today. It’s Friday, February 2nd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

US



 AI-generated fake biometric images are so good that in two years many firms won’t accept facial recognition alone for identity verification and authentication. That’s the conclusion of researchers at Gartner. Some organizations allow facial scanning for logging into applications. But deepfake images are becoming so good that by 2026 30 per cent of firms will insist on a second factor or more for those wanting to log in through facial recognition. Current security technologies aren’t good enough to spot good fake images. Gartner says CISOs should choose identity authentication vendors that show they can handle these new types of attacks.

The recent discovery of vulnerabilities in Ivanti Connect Secure and Policy Secure gateways is so serious that American government agencies have been told to disconnect the devices from their networks by midnight tonight. To bring those devices back online a complete reset is required as well as upgrading to the latest device software. After that the admin and user passwords and API keys have to be reset. Departments must also assume the domain account associated with the devices has been compromised and take action by March 1st. In addition, government agencies have to continue hunting for compromises on any IT systems that were recently connected to Invanti devices.

Researchers at Cado Security have discovered another threat group going after poorly-protected Docker containers. The Commando Cat cryptojacking campaign leverages compromised Docker instances as an initial vector. Then the service is used to run a number of payloads that steal credentials for cloud services like Amazon AWS and Microsoft Azure, and install a cryptocurrency miner. The report says the attacker targets exposed Docker API endpoints, so administrators have to make sure these parts of containers are well protected.

Finally, poor digital hygiene of key IT and network employees is putting carriers and companies in Europe, Asia, Africa and Latin America at risk. That’s the conclusion of researchers at Resecurity. Several threat actors on the dark web are selling over 1,500 login credentials of telecom network administrators and engineers from a number of providers, the researchers say. Probably these are hackers who picked up on the recent successful hack of the internet registry login credentials of an employee of Spain’s Orange Espagne. That apparently prompted hackers to look for other telecom employees who don’t have multifactor authentication on their internet registry login accounts. A threat actor with internet registry control over a telecom provider can do nasty things. IT leaders be warned: Staff who have login privileges to their organization’s internet registry account must enable multifactor authentication or risk losing access to the account.

Later today the Week in Review podcast will be out. David Shipley of Beaceron Security and I will discuss the FBI warnings on China’s cyber threat, hacks at 23andMe and Microsoft, an attack on a Canadian government email system and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 2, 2024 – AI fakes are making trouble for facial recognition logins, and more first appeared on IT World Canada.

Google gets its mojo working and threatens Open AI’s dominance: Hashtag Trending for Friday February 2nd, 2024

Gemini Pro looks poised to give OpenAI some real competition for a change, TikTok loses access to a huge amount of popular music, there is finally a fix for the Pixel phone storage bug (but you’re probably not going to like it), and the US Senate hearings on social media are like social media itself, high on emotion, light on accuracy, and big on theatrics…

All this and more in this anti-social edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

The competition between Google and OpenAI intensifies with the global rollout of Gemini Pro on Bard.

Some reports are saying that this new Gemini Pro release potentially surpasses OpenAI’s GPT-4.

Gemini Pro, now integrated into Bard, will be accessible in over 40 languages across more than 230 countries. And unless I’m severely mistaken, Canada still appears to be left off the list. Although you can reach it with a VPN, I can only access it this way.

The Gemini upgrade introduces a text-to-image generation feature powered by the Imagen-2 model, which is touted to outperform OpenAI’s Dall.E2. In my brief test before we went to air, it was impressive and fast. But in an equally quick test of the writing ability of Bard versus OpenAI, ChatGPT is still ahead of Bard in terms of the flow of its prose. And it might just be me, but Bard seems to always give a great description and a bit of an overstatement of its own abilities. I did an earlier test of Bard versus ChatGPT, and Bard rated itself as superior on a task it didn’t complete. I’ll be testing on the weekend and I’ll update you all on Monday.

To ensure ethical use and distinguish AI-generated images from human-created art, Bard will use SynthID to embed digitally recognizable watermarks in the images it generates.

Bard’s Gemini Pro upgrade includes features that directly compete with ChatGPT Pro’s integration of GPTs. Google’s strategic releases, including the ‘Help me Write’ feature in Google Chrome and the integration of Gemini capabilities in Samsung’s new Galaxy AI smartphones, highlight its aggressive push in the generative AI domain.

Additionally, Google’s Lumiere, a text-to-video generation model, may have an edge over OpenAI, which has yet to release a similar offering.

Google seems to have gotten their mojo back and are actually releasing generative AI features and not just doing videos and announcements. Bard recently secured the second position on the HuggingFace Chat Bot Arena Leaderboard surpassing GPT-4.

All of this makes OpenAI’s response, potentially with the release of GPT-5, eagerly awaited as the competition heats up.

Google’s new offering positions it as a formidable contender in the generative AI space. But something tells me that OpenAI will not simply just roll over and play dead.

Sources include: Analytics India and Bard.Google.com

TikTok users are facing the loss of access to songs from popular artists like Taylor Swift, Jon Batiste, and boygenius, all part of the Universal Music Group (UMG) roster.

This development follows the collapse of contract negotiations between TikTok and UMG. As a result, TikTok has started muting videos featuring songs from these artists.

The dispute centers around compensation and rights issues. UMG accuses TikTok of not compensating artists and songwriters adequately, not protecting human artists from the harmful effects of AI, and failing to address online safety issues. UMG’s stance is that TikTok’s compensation accounts for only a small fraction of total revenue, despite music being a core part of the TikTok experience.

UMG also raised concerns about AI-generated recordings flooding the platform, which they believe dilutes the royalty pool for artists. Additionally, UMG pointed out issues with problematic content on TikTok, including sexualized images of artists like Billie Eilish.

TikTok, on the other hand, has criticized UMG for putting “greed above the interests of their artists and songwriters.” The platform argues that it has reached artist-first agreements with other labels and publishers, and that UMG’s actions are not in the best interests of artists, songwriters, and fans.

This situation has led to shock and disappointment among TikTok users, particularly fans of the affected artists. Some users have even joked about moving to Instagram Reels as an alternative. The dispute highlights the ongoing challenges in the digital music industry, particularly around rights, compensation, and the use of AI-generated content.

Sources include: Devdiscourse

Google has released a fix for a major storage bug affecting Pixel phones, but the solution is far from user-friendly. The issue, which emerged after the January 2024 Google Play system update, locked some Pixel owners out of their phone’s local storage, rendering the devices nearly useless. Google’s response, posted on the Pixel Community Forums, requires users to manually intervene using developer tools and a command-line interface.

The process to fix the bug involves several technical steps: enabling Android’s Developer Options, downloading Google’s “SDK Platform-Tools” zip file, connecting the phone in the correct mode, and executing specific commands through a terminal. The commands involve uninstalling certain media components using the Android Debug Bridge (ADB), a tool typically used by developers for testing and debugging.

While this method promises no data loss for those who haven’t already wiped their devices, it poses a significant challenge for average users. The instructions are complex and require a level of technical expertise that many may not possess. Additionally, issues with ADB driver installation on Windows can further complicate the process, leading to errors and difficulties in running the necessary commands.

This situation highlights the challenges of addressing software issues in consumer electronics, where solutions may require technical skills beyond the average user’s capabilities. It also raises questions about the effectiveness of automatic updates and the need for more accessible solutions for resolving such critical issues.

Sources include: ArsTechnica

I have no idea what to report about the recent US Senate hearings that brought the leaders of social media companies in for what can only be described as theatre.

Don’t get me wrong, I’m not a Zuckerberg fan by any stretch of the imagination, but I have no idea what was gained by senators accusing him of being responsible for the suicides of children and pointing to the grieving parents.

Zuckerberg, caught off guard, was forced to apologize – but aside from humiliating him, there was theatre – no substantive discussion.

Robert F. Kennedy Junior attempted to be “cool” with a specific phrase that he’d picked up, which one of the CEOs had never heard.

One senator, Tom Cotton, repeatedly asked TikTok’s CEO Shou Zi Chew if he’d ever been a member of the Chinese communist party, and Chew had to tell him multiple times that Chew is Singaporean, not Chinese.

Short of saying, “you all look alike,” it’s hard to imagine how a senior US legislator could be any more racist or rude – you can take your pick which one.

And as for substantive discussions about deep fakes or real proposals about what can actually be done? I heard nothing.

If I missed it, I’ll stand corrected but once again, but I thinkit was Seth Myers who gave the best analysis – these guys didn’t look like they could operate their garage door opener.

Which makes for a good line, but the fact is that there are real issues in social media that require if not legislation, then at least some agreement or regulation.

But nothing will happen if it’s all political theatre, with a bunch of legislators who aren’t willing to engage in substantive discussions.

Sources include: MSNBC, YouTube highlights and several stories including Axios and one in The Register

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca or leave a comment under the show notes at www.itworldcanada.com/podcasts.

I’m your host Jim Love, thanks for listening and have a thrilling Thursday.

The post Google gets its mojo working and threatens Open AI’s dominance: Hashtag Trending for Friday February 2nd, 2024 first appeared on IT World Canada.