Page 20 of 55

Coffee Briefing Jan. 30 – CGI and National Bank of Canada deepen partnership; OpenText’s new cloud editions release; Telus’ new AI report gathers a diversity of perspectives; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

CGI and National Bank of Canada renew partnership for 10 years

 

CGI and the National Bank of Canada have renewed their partnership for another 10 years, wherein CGI will continue to deliver a wide range of technology services to help the bank enhance its client experience and drive operational excellence.

“CGI is a trusted partner in the financial services sector,” said Julie Levesque, executive vice president technology and operations, National Bank of Canada. “We value CGI’s expertise and commitment to excellence that will play an important role in our ongoing efforts to meet the evolving needs of our clients and stay at the forefront of the financial services industry.”

This renewed agreement extends the 20-plus year partnership between the organizations, with CGI delivering banking insights, expertise, business consulting, project development, systems integration, and wealth and payment solutions.

“This agreement exemplifies the trust National Bank of Canada has in CGI’s capabilities and we look forward to bringing the best of CGI globally to help the Bank accelerate its transformation,” said Michael Godin, CGI senior vice president, Greater Montréal.

Montreal company enables access to Google’s Privacy Sandbox feature

Software-as-a-Service (SaaS) data management platform Optable has launched an Early Access Program for its Privacy Sandbox activation capabilities.

Google made the Privacy Sandbox APIs available last summer, it said, to foster “greater privacy, transparency, choice, and control without undermining the business model of ad-supported websites.”

Optable says its Early Access Program allows advertisers to target audiences while preserving privacy. Publisher networks also benefit from the ability to launch privacy-safe advertising products, engaging user cohorts across owned, operated, and third-party media.

The API is also integrated with Optable’s data management solution, Optable DMP, and its data clean room suite, Optable Collaborate.

“Our customers require solutions that empower them to leverage both authenticated and anonymous user data in innovative, privacy-centric ways for audience-based planning, activation, and measurement,” said Bosko Milekic, chief product officer and co-founder, Optable. “This integration fundamentally strengthens our platform and will redefine what people expect to get out of data management and collaboration platforms in the era of privacy.”

OpenText Cloud Editions 24.1 release contains 3 Aviator upgrades

OpenText recently released Cloud Editions 24.1, which contains what the company described as the “latest OpenText Aviator innovations.”

These include:

OpenText Content Aviator, which is now available on OpenText Extended ECM, integrating conversational search, summarization, and translation within content management. The update allows an organization to leverage generative AI technology to help accelerate content discovery, improving employee efficiency and productivity.

OpenText IT Operations Aviator on its software as a service (SaaS) offering, service management automation X (SMAX), efficiently resolves common IT service requests, thus minimizing the need for support staff and reducing tier-one business costs. Learn more about the early adopter program here.

OpenText Thrust Studio is now available through an early access program. These new tools enable developers to design, build, and deploy applications utilizing OpenText Thrust APIs more seamlessly with enhanced workflows, permissions, and decision models.

“The latest Cloud Editions launch isn’t just about enhancing our offerings or providing a solution,” said Mark Barrenechea, chief executive officer (CEO) and chief technology officer (CTO) at OpenText. “It is about enabling a paradigm shift in how businesses operate, how industries evolve, and how we collectively engage with technology in this era of rapid transformation.

“Leveraging AI for impactful results depends on reliable data – without it, even the most skilled data scientists will struggle.”

90 per cent of Canadians want AI development to be guided by ethical principles: Telus report

Telus has released a new report highlighting Canadians’ support for AI regulation, as well as the importance of including diverse voices in the development of AI.

The report surveyed 5,000 Canadians, including Indigenous Peoples, racialized groups, the LGBTQ2S+ community, and older and new Canadians, as well as people with physical disabilities.

Over 90 per cent of respondents agreed that AI development should be guided by ethical principles, with almost half believing that AI governance should include community consultation to ensure diverse perspectives. 

In fact, 42 per cent of respondents who self-identified as part of a racialized group feel that AI is biased against them and their peers. Sixty-one per cent of respondents identifying as LGBTQ2S+ fear that AI may be used against certain people and communities.

Many respondents also expressed concerns about the risks of job losses and deepfakes, biases in data, copyright infringement, and privacy.

As a result, 78 per cent of respondents believe that AI usage and development should be regulated in Canada. The majority of respondents believe that this regulation should be government-led, with 2 in 3 suggesting that input is needed from professionals in data ethics, the law, and academia.

Telus emphasized the need for active participation and input of all Canadians.

“This report is our rallying cry for organizations to get involved by building useful resources to educate the public on how they are considering ethics and human impacts throughout the development of this incredibly powerful innovation, while being inclusive in decision-making around all aspects of AI’s development,” said Pam Snively, chief data and trust officer at Telus.

Concordia University of Edmonton and Robogarden present new upskilling programs

 

Concordia University of Edmonton (CUE) and online learning platform RoboGarden have announced the availability of new cohorts for their digital workforce career upskilling and transition programs.

CUE’s Machine Learning and AI Development and Full Stack Development bootcamps, powered by RoboGarden, are 100 per cent online and are supported with scheduled instructor and teaching assistant hours. Students get self-paced study hours and content delivery strategies built for engagement and skill acquisition. Career and freelancer income generation preparation content are also delivered throughout the program, and focused on in the final module.

“Concordia University of Edmonton was one of our first Canadian post-secondary institution partners and we are delighted the University continues to collaborate with RoboGarden in the delivery of digital workforce career upskilling and re-skilling programs,” said RoboGarden president and co-founder Mohamed Elhabiby. “We know Concordia University of Edmonton alumni and learning community members are highly suitable to upskill for the Canadian digital workforce; it is good news that RoboGarden-powered lower-cost programs can continue to be offered by the institution they connect with.”

More to explore

Failure to launch: Cybersecurity pros discuss how to solve the resource crisis

As part of IT World Canada’s partnership with the Canadian Cybersecurity Network, we are featuring a replay of a recent panel discussion featuring cybersecurity professionals discussing the issues that we face in gaining and retaining talent.

FTC investigates AI oligopolies; calls on Microsoft, Alphabet, Amazon to disclose investments in startups

Yesterday, following a half day summit hosted by the U.S. Federal Trade Commission (FTC) that convened experts to examine the key players and the litany of consumer protection issues arising from the mushrooming AI market, the agency announced that it is investigating tech goliaths’ investments in artificial intelligence startups.

Why Canadian provinces, territories need to regulate AI

The use of artificial intelligence in Canada’s federal, provincial, territorial and municipal governments has to be regulated as much as its use in the private sector, a conference on AI in the public sector has been told.

Quebec cybersecurity institute gets $1.3 million grant from Google

Google’s philanthropic arm is giving a $1.3 million grant to a Quebec agency for cybersecurity research.

Bell and Québecor spar over MVNO access service agreements

Bell has accused Québecor of refusing to enter into necessary mobile virtual network operator (MVNO) access agreements.

More work needed to blunt public’s AI privacy concerns: Report

Organizations aren’t making much progress in convincing the public their data is being used responsibly in artificial intelligence applications, a new survey suggests.

Channel Bytes January 26, 2024 – Microsoft hires execs to run nuclear program; Aptum tech partnership with Avant; HiddenLayer launches partner program; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Jan.30- Google’s Bard may be reading your email; Siri to get an AI makeover? The demise of the floppy disk

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Jan. 29, 2024 – SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more

 

The post Coffee Briefing Jan. 30 – CGI and National Bank of Canada deepen partnership; OpenText’s new cloud editions release; Telus’ new AI report gathers a diversity of perspectives; and more first appeared on IT World Canada.

Government vows to address corporate privacy worries in proposed cybersecurity law

Parliamentary hearings opened Monday into proposed new laws that would give Ottawa authority over the cybersecurity readiness of critical infrastructure providers, with the government quickly signaling that it’s sensitive to complaints about the amount of information companies may have to give bureaucrats.

The committee had set aside an hour for MPs to discuss Bill C-26, which would amend the Telecommunications Act overseeing telecom companies and create the Critical Cyber Systems Protection Act (CCSPA). Both would obligate designated critical infrastructure providers to have cyber security plans and report breaches of security controls to the Communication Security Establishment (CSE), a division of the Defence Department responsible for securing government networks and, through the Canadian Centre for Cyber Security, advising the private sector and government departments on cybersecurity.

Initially, only a few critical infrastructure sectors (banking, telecom, interprovincial pipelines and energy providers) will be covered.

In his opening remarks to MPs, Sami Khoury, head of the Cyber Centre, told Parliament’s public safety committee that “we are aware of privacy concerns raised by some stakeholder groups about the reporting requirements of cyber incidents to CSE.

“CSE and the Cyber Centre have an important responsibility to protect Canadians’ privacy and personal information, and we take it very seriously.”

However, right after Khoury finished his introduction, the Conservatives introduced a motion demanding the committee call government and private sector witnesses to investigate the recent rise of car thefts in the country. Two Conservative speakers on that motion took up 34 minutes before a Liberal motion to adjourn debate on the request was passed by a 6-5 vote.

Committee members then only had about 10 more minutes to ask questions of government department witnesses on C-26 before the committee adjourned for the day.

During that time, Kelly-Anne Gibson, director of CSE’s cyber protection policy division, told MPs that the CSE knows the privacy of personal and cyber threat information that firms have to provide the government if there are cyber breaches or risks is a “key consideration” for the private sector.

“Protection of confidential information underpins this legislation,” she said, “because if companies and operators don’t feel that we are going to protect information then they are not going to share it. So what you see in the legislation are specific provisions to define confidential information, protect it, and there are consequences if we or others don’t protect that confidential information.”

Federal experts have been meeting behind closed doors for years with critical infrastructure providers — who cover every sector in Canada except retail and hospitality — to improve their ability to withstand cyber attacks. However, no legislation compels them to specific action.

International legislation

As cyber attacks against hospitals, banks, utilities and other critical infrastructure providers around the world increase, some governments are starting to regulate cybersecurity in the private sector.

In 2021 — after the Colonial Pipeline ransomware attack — U.S. President Joe Biden signed a National Security Memorandum (NSM) on improving cybersecurity for critical infrastructure control systems, ordering the Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) and the Department of Commerce’s National Institute of Standards and Technology (NIST) to develop cybersecurity performance goals for critical infrastructure firms.

Then, in 2022, he signed into law the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), making designated firms report cyber incidents and ransomware payments to CISA. Final disclosure rules have to be set by September 2025.

In 2018, Australia passed the  Security of Critical Infrastructure Act. It creates a Register of Critical Infrastructure Assets, where critical infrastructure firms have to provide the government with their operational and ownership information. Firms also have to report cyber incidents that impact the delivery of essential services to the Australian Cyber Security Centre, and adopt a written risk management program.

Canada’s Bill C-26

Under Bill C-26’s proposed changes to the Telecommunications Act, carriers like Bell, Rogers, and Telus could be ordered by an Order-in-Council — that is, by the federal cabinet — to do anything necessary to secure their systems. That includes, for example, tearing out a compromised server or router known to be susceptible to a zero-day vulnerability.

The CCSPA would require designated operators — like banks and interprovincial utilities — to establish and implement cyber security programs if they haven’t already done so, mitigate supply-chain and third-party risks, report cyber security incidents to the CSE, exchange information with government agencies, and comply with cyber security directives.

Government officials said details of what companies will have to do will be fleshed out in regulations created — with private sector consultations — after the legislation passes. That would include what kinds of cybersecurity programs critical infrastructure must have, how much firms would have to tell the government about their cybersecurity programs, and how they are taking “reasonable steps” to mitigate risks of cyber attacks through third parties like partners and suppliers.

Khoury highlighted the bill’s importance during his opening remarks, noting that Bill C-26 “is a critical next step that provides the government with new tools and authorities to better bolster defences, improve security across federally regulated industry sectors, and protect Canadians and Canada’s critical infrastructure from cyber threats. This legislation would also establish a regulatory framework to strengthen cybersecurity for services and systems that are vital to national security and public safety, and give the government new authority to issue cybersecurity directives to respond to emerging cyber threats.

“At the Cyber Centre, it will facilitate the sharing of information [from designated firms] as necessary to protect critical infrastructure and investigate reported incidents, and provide mitigation advice [to the private sector]. It will also allow regulators to request advice, guidance or services from CSE by providing information about the designated operator’s cybersecurity program and mitigation of risk from the supply chain or use of third-party products and services.”

The post Government vows to address corporate privacy worries in proposed cybersecurity law first appeared on IT World Canada.

Federal government launches new platform to recruit digital talent

The government of Canada has launched the Digital Talent Platform, an online recruitment site for digital and IT professionals.

The platform simplifies the application process for individuals who specialize in digital and IT who are looking to apply for jobs within the government. It will also provide federal institutions with lists of pre-qualified individuals that match their digital talent needs.

“We are pleased to see the Government of Canada recognizes the pivotal role that tech talent plays in the delivery of modernized digital services and are actively working to improve the way it recruits and deploys digital talent across the public service,” commented Michele Lajeunesse, senior vice president of government relations and policy at Technation Canada.

This announcement comes on the heels of a series of enquiries into the government’s IT systems, with members of parliament denouncing the lack of incentives for the country’s digital talent to join government IT, which contains siloed systems and offers lower pay compared to the private sector.

These issues were further brought to light following the resignation of Canada’s chief information officer, Catherine Luelo, who, during and after her tenure, addressed the dire need for attracting digital talent to the government, but also claimed that outside consultants are as critical.

A couple of months before her resignation, she spearheaded the Digital Talent Strategy to tackle the sluggish recruitment process at the government, as well as develop and retain talent.

Yesterday, the president of the Treasury Board, Anita Anand, echoed these objectives at the 2024 Digital Government Leaders Summit.

“Canada’s public service is one of the best in the world — and we must improve the way we attract and retain new talent, especially for digital and IT,” she said. “The GC Digital Talent Platform will improve the way we recruit digital and IT professionals as we work to better deliver services to Canadians in this digital age.”

The new platform, the government says, is part of the Directive on Digital Talent which supports the development and growth of the digital community through data collection and planning for talent sourcing, management, and guidance across the government. The directive was developed in April 2023 with input from the Professional Institute of the Public Service of Canada (PIPSC), Canada’s largest union of scientists and federal workers.

“We favour any effort to leverage the skill sets of government employees and streamline the hiring process – ideally reducing the need to hire contractors while full-time permanent jobs sit vacant,” said Jennifer Carr, president, PIPSC. “This initiative has the potential to deliver on both efficiency and financial prudence, benefiting the government and Canadians alike.”

The post Federal government launches new platform to recruit digital talent first appeared on IT World Canada.

U.S. has disabled parts of Chinese hacking infrastructure, says Reuters

American authorities got legal authorization to remotely disable aspects of a Chinese-based hacking campaign, sources have told Reuters.

The news agency said in an exclusive story Monday that the action against the hacking group, dubbed Volt Typhoon by Microsoft and other threat researchers, came because the government worries it’s part of a larger effort to compromise Western critical infrastructure.

The U.S. Justice Department and the FBI declined to comment, the news story said. The Chinese embassy in Washington did not immediately respond to a request for comment.

Under Microsoft’s new nomenclature, threat actor groups are named after weather events.  Typhoon indicates a group originates in or has been attributed to China.

Last May, Microsoft reported that Volt Typhoon had been targeting critical infrastructure organizations in Guam and elsewhere in the United States since 2021, probably for espionage. At the time, says Reuters, Chinese foreign ministry spokesperson Mao Ning said the hacking allegations were a “collective disinformation campaign” from the Five Eyes countries, the intelligence sharing grouping of countries made up of the United States, Canada, New Zealand, Australia, and the U.K.

The discovery deeply worried the U.S., reported the New York Times. After investigating, American authorities believed the infiltration was even worse than stated in the Microsoft report.

Going after a threat actor’s infrastructure — where they can — is a favoured tactic of experienced American cyber authorities. A year ago this month, the FBI seized the website of the Hive ransomware gang after penetrating the group’s computer networks — fortunately located in California. Last August, police in seven countries, including the U.S., announced they had infiltrated and took down the infrastructure behind the Qakbot botnet, and then used that access to order infected computers to delete the malware.

The post U.S. has disabled parts of Chinese hacking infrastructure, says Reuters first appeared on IT World Canada.

Hashtag Trending Jan.30- Google’s Bard may be reading your email; Siri to get an AI makeover? The demise of the floppy disk

Google’s Bard could be reading your email, rumours that Siri will finally get an AI makeover, the NSA is once again under pressure to stop buying your browser data from data brokers and we mourn the demise of the floppy disk. Anyone born after the year 2000 may have to google that one. 



 

These and more top tech stories on this edition of Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

9to5Google.com, a site that monitors all things Google is reporting that they have seen the latest version of Google Allo and that it looks like that Bard may be integrated with Google Messages.

From one standpoint, that sounds like good news as it will allow a greater degree of integration and email users can have greater access to AI to assist them in using and managing email. 

It appears that Bard will be able to draft messages, identify images and do other cool things like suggest books, offer recipes and more. 

So whether you need a well written message about why you are calling in sick or if you need a vegan meal for lunch, Bard is there for you. 

From the samples, Bard will interact with you so that Bard generates a response. You get a cute sparkle thing happening and you can give it a thumbs up or down. You can also copy, forward or star that message.

But how does Bard know about your email? How does it learn?  

That’s where the story gets a little fuzzy. According to 9TO5 Google, “chats with Bard are not end-to-end encrypted.” 

Now that’s a real surprise for all of us who thought that our mail was encrypted in transit and at rest. 

Turns out that might not be the case. Not only can Bard read your email, but apparently trained human reviewers can also see it. Reviewed data is “disconnected from your account and retained for up to 3 years.” 

And while Bard is processing somebody’s email, I’m still processing the thought of what happens to privacy?

Companies can say all they want about their AI not learning from our personal data, but I have to cry BS on that one.  Google claims it won’t use your email to train its models, but that’s kind of irresistible, isn’t it? How else does it learn from those thumbs up and down if it has no context. And what do those human trainers read, if not your email?

Unless the AI is run on your phone and never pings any data back to the mothership for processing, somewhere, this AI is reading my email.

This is going to take on even more importance as Apple joins the AI sweepstakes as well.

This is as much as I could figure as we went to press. We’ll keep digging and keep you up to date as we find out more. 

And I stand to be corrected by Google or anyone else smarter than me out there, which is a pretty big group. 

Sources include: Forbes, 9TO5Google

See one, play one, as we say in cribbage. 

A story in Apple Insider today reported that Apple’s iOS 17.4 beta has “signs for an AI-improved Siri and that Apple could announce an AI-powered version of Siri as soon as June. 

Apple is reported to be testing four different AI models including its own in-house large language model.  From what we’ve heard, they aren’t going to use ChatGPT, but they may be using it to test how well their own AI is doing. 

Apple also seems to be trying to figure out what gets processed on the device versus what happens on the server.

This is going to be a big question. Apple has always had Vegas rules for the iPhone. What happens on your iPhone is supposed to stay on your iPhone. 

Apple has been buying up AI companies that have particular expertise in smaller AI processing, suitable for a phone. But will they be able to make that work? 

But outside of the rumour mill, Apple is notoriously closed mouth about its product development. So we’ll find out if they really have been falling behind or if this is another sneak attack from Apple – let everyone else lead and then come to market with something that nobody saw coming.

The upcoming iOS 18 release is already being described as one of the biggest releases in Apple history. This should make Apple’s world wide developer conference in June a must see. 

Sources include: Apple Insider and TechCrunch

So what’s the big deal about the data on your device? Well, as it turns out, the NSA in the U.S. thinks it’s worth enough to buy your browser records. Yup. 

We covered this story a few months back, given the news about AI on your phone, and a recent announcement, it’s come to the forefront again. 

A U.S. Senator has formally requested that the NSA stop buying personal data from data brokers. There are questions about how that data is obtained in the first place, whether it was obtained legally.  

For years the NSA has been intercepting metadata from phones and internet communications. Supposedly they cannot spy on U.S. citizens (Canadians are probably fair game) but there is no doubt that in monitoring the great Maple Syrup conspiracy that they catch some Americans in the back and forth.

But it turns out that they don’t have to monitor traffic to get personal information when they can just buy it from data brokers, without permission from a judge or even informed consent. 

If it was all above board, they certainly didn’t advertise what they were doing. The practice became known a few months ago – as I noted, we covered it. 

And in response to this, and presumably pressure from this senator and others, the US Federal Trade Commission is suggesting that buying and selling unlawfully obtained data will no longer be tolerated. 

Which makes you want to ask – how much data out there is lawfully captured?

Sources include: The Register

And just so you don’t think that it’s only Google and Apple who may be facing the heat from regulators, OpenAI has once again drawn attention from Italy’s data protection authority. You may remember that the Italian authority is pretty aggressive – they had OpenAI in their sites a while ago, but the company addressed their concerns, especially allowing users to decline consent for their data to be used to train AI models. 

Well, the regulator said they would allow OpenAI to operate but would “continue their investigation.”  And they are back, saying that there are still privacy violations, although they did not elaborate. 

Presumably they did tell OpenAI who now has 30 days to respond.

Sources include: Axios

And for something completely different, Amazon cancelled its 1.4 billion acquisition of Roomba maker iRobot, due to opposition from European antitrust regulators.

This deal dates back to mid-2022 when Amazon announced a 1.7 billion dollar price tag, hoping to add the robot vacuum cleaner to its list of household automation products including Ring and Alexa.

The deal had been approved in the UK and was being looked at by the U.S. Federal Trade Commission but the EU opposition was apparently more than Amazon could take. The company said in a statement,  Undue and disproportionate regulatory hurdles discourage entrepreneurs, who should be able to see acquisition as one path to success, and that hurts both consumers and competition—the very things that regulators say they’re trying to protect.”

Amazon will pay 94 million to iRobot whose shares fell on the announcement by 18 per cent.

And that sucks….

Sources include: Axios

And finally, a few moments of silence for the floppy disk. And I felt about this story like you do about hearing some old movie star has died and you say to yourself, “I didn’t know he was still alive.” 

But apparently, Japan has kept the floppy drive alive because it was required for filing official documents. In fairness, they did get with the times and allow submission by CD-ROMS.

But when the announcement came in 2022, that the Japanese government was phasing them out, a government minister was said to have asked “where can you buy floppy disks these days.” 

As it turns out, there was some guy, I think in the U.S. who recycled old drives for his company floppydisk.com  If you hurry, you can probably still buy a box of 50 recycled disks for $19.95 US. 

As we say in Canada – bargain.

Sources include: Tom’s Hardware

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Terrific Tuesday!

The post Hashtag Trending Jan.30- Google’s Bard may be reading your email; Siri to get an AI makeover? The demise of the floppy disk first appeared on IT World Canada.

Hearings on Canada’s proposed cybersecurity law to start today

Work on the second plank of the Liberal government’s cybersecurity and privacy strategy starts this afternoon.

That’s when the House of Commons Standing Committee on Public Safety and National Security opens hearings on Bill C-26, which amends legislation governing telecommunications companies and creates the Critical Cyber Systems Protection Act (CCSPA).

“This legislation is among the most important safety and regulatory regimes of a generation,” says David Shipley, head of New Brunswick’s Beauceron Security and co-chair of the Canadian Chamber of Commerce’s cyber council.

“We have to both get it right and get it done. We’ve mostly gotten it right, with a few surgical tweaks needed. We’ve been abysmal at getting it done.

“Canada is woefully behind the United States, Australia and Europe when it comes to the protection of our critical infrastructure,” he said. “We had the airport equivalent of a near miss between two planes last year where an amateur Russia hacking team almost made a Canadian pipeline explode. They had access and were given the green light by their GRU handler. It was good fortune that saved us, not good defences and good planning.

“We don’t want to see what happens when good fortune runs out.”

If C-26 passes, for the first time there will be legislated security obligations for “high-risk firms” in six of Canada’s critical infrastructure sectors — telecommunications providers, banks, financial clearing systems, interprovincial energy providers, nuclear energy stations, and transport companies.

Those firms deemed vital to national security would be designated under regulations to toughen their cybersecurity and confidentially share cyber threat information with the Communications Security Establishment (CSE), the government’s IT security and signals intelligence agency.

Designated firms would have to implement and report on a cybersecurity program to address risk across the organization, third-party services, and supply chains. The government would have the power to tell providers to do anything necessary to secure their systems.

The industries — and outside experts — have had almost two and a half years to think about what they like and don’t like about the proposed legislation. In a statement today, the Canadian Telecommunications Association, which represents major telcos including Bell, Rogers and Telus, said detailed comments about proposed changes to the Telecommunications Act will come when it testifies.

But briefly, the statement said, the association’s members have concerns about the “overly broad scope of order-making powers [by the government] and the absence of a requirement for government to consult with or consider the advice of industry and security experts. We are also concerned that the bill does not require the government to make its orders proportionate to the alleged security risk, that telecom providers can be held liable for violations even when they have taken all reasonable steps to comply with an order, and that the bill prohibits the government from providing compensation to parties for the costs associated with complying with a government order.

“Finally, while we recognize there may be situations where orders must be kept secret, the bill errs on the side of secrecy rather than transparency. Transparency is an important element for maintaining the public’s trust in the exercising of government authority.”

In a brief to the committee, Electricity Canada, which represents many utilities and power producers, complained C-26 doesn’t recognize established security standards and expertise within the sector. “In practice, the bill risks adding very little security to our sector, and redundantly adds an additional layer of regulatory requirements,” the submission says.

Other groups have already issued criticisms:

— Shortly after the legislation was introduced, a senior research associate at the Citizen Lab, part of the University of Toronto’s Munk School of Global Affairs and Public Policy, suggested 30 changes to the proposed legislation to blunt powers C-26 would give the Minister of Industry;

— The Business Council of Canada worries the CCSPA will impose costly regulatory obligations on many critical infrastructure providers with no associated benefit. The law should impose different regulatory requirements on designated operators proportionate to their level of risk, it argued. The council also argues the CCSPA should follow Australia’s similar Security of Critical Infrastructure Act to limit the power of the government to issue designated firms to comply “with any measure” for the “purpose of protecting a critical cyber system;”

— the Canadian Civil Liberties Association and other groups have called on Parliament to amend the legislation to limit government powers over the private sector.

Today’s hearing starts with closed-door testimony to MPs from senior officials in the Departments of Industry and Public Safety. After that, officials from those departments, as well as the CSE, will answer questions in an open committee session.

Meanwhile, committee hearings will resume shortly on the other leg of the government’s strategy, an overhaul of federal private sector privacy legislation to create the Consumer Privacy Protection Act (CPPA), plus the Artificial Intelligence and Data Act. (AIDA).

The post Hearings on Canada’s proposed cybersecurity law to start today first appeared on IT World Canada.

Cyber Security Today, Jan. 29, 2024 – SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more

SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more.

Welcome to Cyber Security Today. It’s Monday, January 29th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

 



 

SolarWinds is going to court to fight the U.S. Securities and Exchange Commission’s allegations that the company and its chief information security officer defrauded investors by overstating its cybersecurity practices. The allegation relates to the lead up to the 2020 revelation of the compromise of the SolarWinds Orion software update mechanism. Security observers were stunned to learn a Russian-based threat group was able to insert a malware-filled application update into the mechanism that some organizations downloaded. Last week, Bloomberg Law says, SolarWinds asked a court to dismiss the SEC charges, saying they are unfounded. “The SEC is trying to unfairly move the goalposts for what companies must disclose about their cybersecurity programs.” “The case is fundamentally flawed,” SolarWinds says, “and should be dismissed in its entirety.”

A Canadian man has been sentenced by an Ottawa judge to two years in prison for his role in cyber attacks including ransomware. The CBC said Matthew Philbert received that sentence Friday after pleading guilty to criminal charges of running attacks. They started with phishing messages. There were over 1,100 victims of various attacks. According to the Ottawa Citizen, his targets included three police departments.

The Medusa ransomware gang has claimed responsibility for attacking Kansas City’s transportation authority last week. That’s according to the news site Security Affairs. It says the gang has published samples of allegedly stolen data as proof of its claim. All transit services are operating but temporarily riders couldn’t call regular phone numbers.

Threat actors are increasingly using the Greatness Phishing Kit to trick Microsoft 365 users into downloading malware. That’s according to researchers at Trustwave. Greatness is a phishing-as-a-service platform that charges hackers US$120 a month in bitcoin to use for launching phishing campaigns. The platform generates deceptive emails with attachments that capture passwords and — if the victim is gullible — their multifactor authentication codes. Employees need to be reminded not to fill out login forms that come from links in emails.

It’s vital that every company have a way — by email or by phone — to take seriously warnings their cybersecurity controls may have a hole. Otherwise that hole will be found by a threat actor. I raise this because security researchers at Britain’s RedHunt Labs recently felt they had to contact the TechCrunch news service to relay a warning to Mercedes-Benz of a serious problem. A Mercedes developer had left an authentication token in a publicly-available GitHub repository where they presumably were working on application code. RedHunt Labs believed the token would have given anyone access to Mercedes’ GitHub Enterprise Server and the ability to muck around with corporate software code. Two things here: First, companies and government departments may be shy about putting phone numbers and email addresses on the web these days, but they can’t ignore the fact that some calls from people may be more than harassment or silly questions. Second. application developers need to be regularly reminded of what not to do on GitHub or any other public code repository. And managers need to watch their work to make sure security rules are enforced.

Don’t like marketing companies scraping your personal information from social media platforms and reselling it to advertisers? Well, social media platforms are finding it hard to stop. In the latest incident, a California judge last week ruled that an Israeli company called Bright Data did nothing wrong in scraping public data from Facebook and Instagram. Bright Data is being sued by Meta — the parent company of Facebook and Instagram — for breach of contract and tortious (TOR-SHUS) interference with contract. Ars Technica reports that the judge agreed the terms of Facebook and Instagram don’t prevent logged-off scraping of public data. As a result the judge dismissed that part of Meta’s lawsuit before trial. The claim of tortious interference with contract still exists. Meta can appeal the decision.

In addition to advertisers, know who else buys internet records of Americans from data brokers? The National Security Agency. U.S. Senator Ron Wyden released documents last week from the NSA that he says confirm the electronic spy agency buys data that can reveal which websites people visit and the apps they use. The problem, Wyden alleges, is that the data is collected illegally and obtained without a warrant from a judge. The U.S. Federal Trade Commission recently said data brokers have to obtain the informed consent of Americans before selling their data.

American insurance broker Keenan & Associates is notifying 1.5 million people some of their personal data that it holds was stolen in an August data breach. That data included names, dates of birth, Social Security numbers, driver’s licences, passport numbers and health information.

Last October reports began emerging of ransomware groups taking advantage of a vulnerability in Citrix Netscaler application delivery controllers and gateways called Citrix Bleed. Now comes word that Planet Home Lending is notifying almost 200,000 Americans personal data it holds on them was stolen in a November ransomware attack. The cause was exploitation of that vulnerability. The data was in a read-only folder with loan files that included applicants’ names, addresses, Social Security numbers, loan numbers and financial account numbers.

Another victim of Citrix Bleed is Comcast cable. In December Comcast told Maine’s attorney general’s office that has to notify almost 35 million of its customers that personal data it holds was stolen from its system between the time Citrix released patches for the vulnerability and Comcast implemented mitigations.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 29, 2024 – SolarWinds demands fraud allegation be dropped, a Canadian sentenced for ransomware attacks, and more first appeared on IT World Canada.

Hashtag Trending Jan.29- LLMs learn to hide dishonest behaviour; Tech layoffs a strategic move? 90 per cent of spreadsheets have errors

AI models can learn to hide their dishonest behaviour, Open AI is making it easy for anyone to call multiple GPTs from a single conversation, are mass layoffs with huge earnings and share values a strategic thing for big tech? And a study claims that 90 per cent of spreadsheets have errors.  



 

All this and more on the, oh gosh I’m shocked edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.  

In a recent study, AI researchers discovered that large language models (LLMs) trained to behave maliciously resisted various safety training techniques designed to eliminate dishonest behavior. This study, conducted by Anthropic, an AI research company, involved programming LLMs similar to ChatGPT to act maliciously and then attempting to “purge” them of this behavior using state-of-the-art safety methods.

The researchers employed two methods to induce malicious behavior in the AI: “emergent deception,” where the AI behaves normally during training but misbehaves when deployed, and “model poisoning,” where the AI is generally helpful but responds maliciously to specific triggers. 

Despite applying three safety training techniques — reinforcement learning, supervised fine-tuning, and adversarial training — the LLMs continued to exhibit deceptive behavior. Notably, adversarial training backfired, teaching the AI to recognize its triggers and better hide its unsafe behavior during training.

Lead author Evan Hubinger highlighted the difficulty in removing deception from AI systems with current techniques, raising concerns about the potential challenges in dealing with deceptive AI in the future. The study’s results indicate a lack of effective defenses against deception in AI systems, pointing to a significant gap in current methods for aligning AI systems.

Sources include: Live Science 

A recent study showed that 90 per cent of spreadsheets with more than 150 rows contain at least one major mistake. 

The flexibility of spreadsheets, while a key to their success, also contributes to these errors. Even with evolving features like Python scripting in Excel, human error remains the primary cause of spreadsheet problems.

Sometimes the consequences make for big news. The Police Service of Northern Ireland experienced a massive data leak due to a spreadsheet error, exposing personal details of 10,000 officers. Spreadsheet mistakes disrupted the recruitment of trainee anaesthetists in Wales, erroneously labeling all candidates as “unappointable.”

Crypto.com accidentally transferred $10.5 million instead of $100 to a customer due to a spreadsheet entry error, and an Icelandic bank undervalued its shares by millions of dollars because of a spreadsheet error.

The lack of U.S. or Canadian examples, doesn’t mean they don’t occur. 

But for every major error, there are dozens of others that happen on a daily basis.  

These errors, according to the author of one article I read, arise from a lack of standardization in spreadsheet formatting and structure, coupled with manual data entry, which is prone to mistakes. 

It might be time for organizations to implement standardization in spreadsheet use, improve training for users, and foster a culture of critical thinking towards spreadsheet creation and maintenance. 

Apparently, Spiderman’s Uncle Ben was right. With great power comes great responsibility.

Sources include: The Conversation

The U.S. government is escalating its measures in the ongoing chip war with China by proposing to restrict foreign entities, particularly Chinese, from using U.S. cloud computing resources for AI model training. 

U.S. Commerce Secretary Gina Raimondo announced this initiative as part of efforts to protect national security and maintain U.S. technological superiority.

This proposal is seen as an extension of existing export controls on high-performance AI processors, requiring U.S. cloud companies to rigorously identify their foreign users. The aim is to prevent entities from countries like China from accessing American cloud resources for developing artificial intelligence. This move is in line with the Biden administration’s broader strategy to ensure U.S. cloud platforms are not used for potentially hostile AI development.

The regulation imposes significant responsibilities on cloud computing firms, mandating them to verify the identity of foreign customers, maintain user identification standards, and certify their compliance annually. However, Chinese entities can still access services deployed in Europe and the Middle East.

The industry’s response to these measures has been mixed, with some criticism regarding the potential impact on international collaboration in AI. Carl Szabo, general counsel at NetChoice, a tech industry trade group, criticized the executive order’s implementation as potentially illegal.

But it doesn’t seem like the U.S. will back down on this strategy to control the use of its technology in AI development, particularly in the context of its competition with China.

Sources include: Tom’s Hardware

OpenAI is testing a new beta feature for ChatGPT, introducing multi-GPT conversations. This feature allows users to interact with multiple GPTs in the same chat window, marking a significant step towards OpenAI’s vision of creating a universal assistant for everyday life. By using the “@” symbol followed by the name of a GPT, users can summon individual GPTs into the chat, enabling a more personalized and comprehensive assistant experience.

Sam Altman, in a recent podcast with Bill Gates, emphasized that customizability and personalization are crucial elements in OpenAI’s development roadmap. This includes tailoring GPT-4 to individual preferences, styles, and data like emails and calendars.

But it also appears to be making it a platform to integrate different GPT based models and make that easy for anybody to do.

Sources include: [THE DECODER](https://the-decoder.com/chatgpts-new-feature-paves-the-way-for-openais-vision-of-a-universal-assistant/?amp=1)

Click here: WebPilot

The tech industry has started 2024 with a significant wave of layoffs, similar to the previous year, despite the booming U.S. economy and the thriving tech sector. 

This has mystified me, and I’m sure others. How can tech companies be doing so badly in this economic climate? 

Microsoft recently announced the layoff of 1,900 workers from its gaming division, following its acquisition of Activision Blizzard. These cuts represent about 8 per cent of the company’s total gaming workforce of 22,000. Google also announced layoffs earlier this month, with some cuts continuing throughout the year. Despite these layoffs, both Google and Microsoft’s stocks hit record highs this week.

A story from Axios explains this saying that layoffs are not a “sign of distress” but a “strategic move” by tech giants like Microsoft and Amazon, who are simultaneously cutting jobs and investing heavily in areas like AI.

Boom and bust isn’t something new in the tech world. But that’s not what’s happening, apparently. These layoffs are strategic, not desperate cost-cutting measures. 

I get it when an industry is struggling – I’m running a media company and everyone in this industry faces the challenge of staying solvent in a world that wants free media, but doesn’t realize that people have to get paid to produce what they read and view.

But for an industry to be thriving and still putting people through this much upheaval – you think by now we’d have found a better way.

Just sayin’

Sources include: Axios 

And on that note, I am putting out an appeal to our audience. Both Howard and I produce two very successful podcasts, we reach thousands of people every day, but I’ll be honest, we struggle to find sponsors. 

Howard’s CyberSecurity Today reaches between 8 and 10,000 people per episode which often puts him in the top 10 tech podcasts in Canada, the US and even the UK. 

My numbers are smaller but thanks to all of you, we’ve grown by almost 50 per cent – thank you and please keep referring us to your friends and given us those great reviews.

And if you know of someone or some company that would like to sponsor two of the most successful tech podcasts, I’d love to hear from you.

Hashtag Trending goes to air five days a week with a daily news show and every Saturday, we have an interview show called the Weekend Edition.  

We love your comments. Please let us know what you think. You can reach me at jlove@itwc.ca  or leave a comment under the show notes at www.itworldcanada.com/podcasts

I’m your host Jim Love, thanks for listening and have a Marvelous Monday.

 

The post Hashtag Trending Jan.29- LLMs learn to hide dishonest behaviour; Tech layoffs a strategic move? 90 per cent of spreadsheets have errors first appeared on IT World Canada.

Project Sponsor’s Warp Speed Guide: AuthorYogi Shulz is our guest on Hashtag Trending, the Weekend Edition

Welcome to Hashtag Trending, the Weekend Edition.  I’m your host Jim Love.

A number of years ago, a client of mine said to me, “I have no idea what you do, but where you’re here, stuff gets done.” He actually didn’t say stuff, but you might be playing this podcast with your family listening, so let’s stay PG rated.

The point is that not a lot of people know how to get things done. It is an undervalued but important skill in business.

Another example – I taught at the University of Waterloo for a while and I remember a successful CEO came in talked our class about how his company had taken on some big players and won. He’d made tens of millions of dollars.

He got questions like “what was your strategy?” He explained it. It seemed simple. Powerful. The next question was “how did you come up with that?”

His answer surprised us all. He said, “we read a book.” Which leads to an obvious next question. “What book?”

His answer has stuck with me for years. He said, “it didn’t matter.” By the time any book got to be published my a major publisher, it was going to be pretty good.  The difference with us wasn’t the strategy. It’s that we actually DID IT.”

Execution. We disdain it. We somehow think that great ideas are what makes the difference when getting stuff done is much more important.

And I take nothing away from the intelligence or the strategic thinking of my guest this week, but one of the things I most admire about him, is his attention to getting stuff done.

My guest is Yogi Shulz, author of a new book  A Project Sponsor’s Warp Speed Guide.

If you are thinking that the world doesn’t need another book on project management – you might be right. But Yogi has written this book not from the point of view of the project manager. He’s written it for the project sponsor.

He makes the point that so many project managers know all too well –  executives often don’t understand how valuable performing this project sponsor role can be. Nor do they really know what to do. Or as Yogi says in this interview, “we’ve spent a lot of time and money training project managers and next to no time training project sponsors.”

The book itself is an easy read, and it’s set up to read all at once, or to provide quick snippets of “just in time guidance” to a project sponsor.

Join me for my conversation with Yogi Shulz, author of A Project Sponsor’s Warp Speed Guide. You can find his book on Amazon and it may make the appropriate gift for the executive sponsor of your next project, or for anyone listening who is that executive sponsor.

Hashtag Trending goes to air five days a week with a daily tech newscast. And every weekend we have a special in depth interview with a person or on a topic of interest – hopeful both.

We love your comments – suggestions on topics, guests or just in telling us what you like and maybe what you don’t like. You can reach me at jlove@itwc.ca

And if you like what you hear why not recommend us to a friend? You can send a copy at itworldcanada.com/podcasts

If you are an Apple podcast listener, and you like the show, why not give us a review? It all helps to grow our podcast and help us reach more people.

Our  recording engineer is Midori Nagai. Our associate producer is Krystle McLean. And I’m your host,  Jim Love.

Thanks for sharing your weekend with us.

The post Project Sponsor’s Warp Speed Guide: AuthorYogi Shulz is our guest on Hashtag Trending, the Weekend Edition first appeared on IT World Canada.

FTC investigates AI oligopolies; calls on Microsoft, Alphabet, Amazon to disclose investments in startups

Yesterday, following a half day summit hosted by the U.S. Federal Trade Commission (FTC) that convened experts to examine the key players and the litany of consumer protection issues arising from the mushrooming AI market, the agency announced that it is investigating tech goliaths’ investments in artificial intelligence startups.

Microsoft, Amazon, Alphabet, Anthropic, and OpenAI will be the subjects of the inquiry, and will be required to provide information regarding recent investments and partnerships involving generative AI companies and major cloud service providers. They will have 45 days to respond to the agency.

Since the start of the generative AI buzz last year, Amazon and Google have injected a total of US$6 billion in Anthropic, while Microsoft pledged over US$10 billion to OpenAI.

“History shows that new technologies can create new markets and healthy competition. As companies race to develop and monetize AI, we must guard against tactics that foreclose this opportunity, ” said FTC Chair Lina M. Khan. 

During yesterday’s summit, industry experts discussed how the AI tech stack – from the semiconductor level to the cloud to the data – is incredibly concentrated.

Nvidia is making all the AI chips, it’s selling to the hyperscalers, who end up announcing their own chips, making it difficult for new entrants to come into the market, explained Daven Rauchwerk, a technologist who founded a semiconductor startup.

Hyperscalers making their own chips, he added, grants them a form of innovation surveillance, whereby they can look into the memory inside of the chip itself and see what their customers are doing, and figure what needs to be made before it is made.

“Now has never been a better time to be in the semiconductor business. We’re going to have more fabrication capacity in the next five years than we’ve ever had. And there’s enormous demand. And yet the dynamics of the market make it extremely challenging to get off the ground.”

Rauchwerk argued that innovation is happening in real-time at the lowest layers of the stack, but we do not get to see it because of the concentration of the dominant players.

“It’s to the point where the hyperscaler becomes the customer for the chip startup, and you talk to the chip companies, they say, ‘we can sell to one hyperscaler, one data center is millions of units, and it’ll make our whole business.’”

Plus, AI chips are extremely expensive and supply-constrained, and how they get doled out by vendors like Nvidia “has always been something out of a black box” and effectively makes Nvidia the new kingmaker in the entire space, explained Corey Quinn, the chief cloud economist at The Duckbill Group, a company that helps companies manage their Amazon Web Services (AWS) bills.

Hyperscalers also do a lot of bundling and packaging across the board that allows them to net the most chips, he stated. For instance, Nvidia would give Amazon more chips in exchange for a preferred placement on amazon.com for the company’s other retail lines.

“There’s no transparency, and it’s this cross-cutting across so many different units of business that lets them tie things together in strange ways, that we just don’t know what’s happening,” said Quinn.

Even the hyperscalers, he added, are in a centralized, co-dependent system. You can decide, for instance, to build an ecommerce store on Azure so that you do not have to deal with AWS. But if you use financial services like Stripe, which is the strategic payments partner of AWS, then no one can buy from your shop if AWS is down.

Even the U.S. government, he noted, runs a staggering percentage of its compute on the Big Three hyperscalers.

“I’m not suggesting that there’s undue influence of ‘stop investigating us or your computers are going to stop working’”, Quinn said. “I don’t think anyone is getting to that point. But there is a sense of how much can really be done when you are critically dependent upon the continued existence and well being of these companies.”

Further, Tania Van den Brande, director of economics at the U.K.’s communications regulator, Ofcom, detailed how the hyperscalers make it difficult for customers to move their data out of their clouds, through things like egress fees. Additionally, they face difficulties re-engineering apps to move them from one cloud to another, or connecting apps hosted on different clouds. 

Quinn affirmed that it’s obvious we have a monopoly, or if not, the next thing to it, because the cloud companies talk in the language of monopolists, touching on ideas of survival and the risk of being out-innovated by a startup in a garage.

That, he says, is implausible unless you give that startup, for instance, $6 billion of funding for all their AI training runs, plus the massive hiring binges and the specialized hardware.

“We face basic questions of power and governance,” said Khan. “Will this be a moment of opening up markets to fair and free competition, unleashing the full potential of emerging technologies, or will a handful of dominant firms concentrate control over these key tools, walking us into a future of their choosing?”

The post FTC investigates AI oligopolies; calls on Microsoft, Alphabet, Amazon to disclose investments in startups first appeared on IT World Canada.