Page 23 of 55

Responding to challenges of new tech, children’s rights among federal privacy czar’s priorities

Promoting Canadians’ fundamental right to privacy, addressing the privacy impacts of new technologies like artificial intelligence, and championing children’s privacy rights will be the priorities of the federal Office of the Privacy Commissioner (OPC) for the next three years.

Commissioner Philippe Dufresne revealed the strategic plan Monday at the start of the annual observance of Data Privacy Week.

“This plan offers a high-level overview of the kinds of initiatives that we are undertaking, the areas where we will focus our efforts, and the outcomes that we intend to achieve,” Dufresne said in a statement. “It will drive our responsiveness and our proactivity and help us make choices about where to focus our resources. It requires us to consistently equip and continue to develop our talented team and recruit new employees to address the complexities in the field and the changes ahead.”

The plan in part relies on Parliament passing a new privacy law covering federally-regulated industries and businesses in provinces and territories that don’t have their own private sector privacy legislation.

That proposed law, C-27, which includes the Consumer Privacy Protection Act (CPPA) and the Artificial Intelligence Data Act (AIDA), is still before the House of Commons industry and technology committee.

Innovation Minister François-Philippe Champagne has said the proposed act will be amended before a final vote to make it clear Canadians have a right to privacy.

As part of the CPPA, the privacy commissioner would get new powers, including the ability to recommend fines for violating the act.

To ensure children’s privacy is protected, the privacy commissioner will work for laws that acknowledge children’s rights, and compel organizations to embed privacy in their products and services.

“Our commitment to this issue stems from the belief that children deserve to be children, even in the digital realm, free from deceptive practices and with the freedom to navigate online spaces securely,” the strategic plan says.

The strategic plan is an outline of priorities, and not a detailed list of what the Office of the Privacy Commissioner intends to accomplish.

For example, to achieve the goal of addressing the privacy impacts of technological advances, the OPC intends to establish privacy standards for emerging tech, issue guidance to businesses, and form partnerships “that complement and recognize the breadth of our areas of involvement and our technological capacity.”

Dufresne became privacy commissioner in the summer of 2022. He signaled his direction when he testified last October before the House of Commons Standing Committee on Access to Information, Privacy and Ethics. At that time, he said that “it is critical that government and organizations take action to ensure that young people can benefit from technology and be active online without the risk of being targeted, manipulated, or harmed as a result.”

Several weeks earlier, when presenting the OPC’s annual report to Parliament, Dufresne said the impact of emerging technologies on personal privacy was also one of his priorities. 

The post Responding to challenges of new tech, children’s rights among federal privacy czar’s priorities first appeared on IT World Canada.

Most enterprises still at beginning of their AI journeys: Report

Talk about the endless possibilities and impact of artificial intelligence is rampant, yet a new report by Everest Group shows that the majority of enterprises (83 per cent) are currently only testing the capabilities of AI through pilot programs, or have adopted generative AI for one or more production-grade use cases.

“Our research clearly documents that most organizations are in what we call ‘Wave 1’ or the pilot phase of Gen AI adoption; however, in 2024 and 2025 we fully expect more organizations to advance to the ‘Wave 2’ phase of production-grade deployments,” said Abhishek Singh, partner at Everest Group.

Wave 2 of generative AI adoption, the report says, is when we’ll see enterprises move from small-scale pilot projects and experiments to enterprise-wide scaled pilots, and increased focus on optimizing performance of generative AI models, as well as the initial adoption of enterprise AI platforms.

As part of this study, more than 50 chief information officers were jointly interviewed for their perspectives on current adoption maturity and key strategies and challenges, as well as future investment plans in Gen AI.

Over 60 per cent of feel that the fast-evolving and confusing technology landscape is one of the top challenges for them when scaling their generative AI initiatives.

Canadian C-suite members echo the same sentiment. A recent Global Leadership Monitor survey by Russell Reynolds Associates (RRA) showed that one in three leaders in Canada say that they are uncomfortable with implementing generative AI.

Globally, 55 per cent of leaders say that knowledge and expertise are top barriers to implementing generative AI, and 72 per cent agree that a strong understanding of generative AI will be required for future C-suite members, the same report affirmed.

CIOs also cite things like a lack of clarity on success metrics, budget constraints, talent shortage, and data security and privacy concerns as top barriers to scaling AI, the Everest study indicated.

As we look ahead to 2024, leaders need to get on board, RRA said. They need to come to terms with the fact that generative AI is here to stay, and will impact the way we do business and which companies will stay ahead of the game.

The three generative AI areas that have gained substantial adoption, according to Everest, are:

Content creation and preparation – creative writing, email generation, language translation, etc.
Knowledge management – context-aware search, summarization, conversational employee interface
Software development – automatically generating code snippets, scripts, or even entire programs based on natural language descriptions or high-level requirements

All these use cases have converged and taken over areas such as customer service delivery and management. A report by Zendesk reveals that 70 percent of customer experience (CX) leaders are reimagining their customer journeys using tools like generative AI, and a staggering 83 per cent report positive ROI.

Everest also highlighted other generative AI use cases that are in the exploration stage. Financial institutions, for instance, are exploring things like financial bots, use of synthetic data for risk simulation, claims processing and more. The healthcare industry is looking to use AI for medical report generation and drug research and discovery, while the media and entertainment industry is testing AI for game development, AI avatars, as well as AI-generated media posts.

The “Wave 3” of AI adoption, slated for 2026 and beyond, the report claimed, will see enterprises innovate and create custom-built generative AI solutions to meet specific business needs.

Navigating this journey, CIOs will have to pay attention to the following four key considerations, Everest affirmed:

Generative AI is an expensive technology, so it is imperative that leaders establish and translate the right business objectives into the right value equation to create a successful Gen AI strategy.
Assess their digital maturity to lay out the right AI adoption strategy – They need to firstly prime their data foundation, making sure it’s fine-tuned to the context of the enterprise. Additionally, enterprises need to ensure their talent is AI-ready. Employees need to understand the technology, its implications and applications.
The countless risks of generative AI, from cyber threats, data privacy violations, to AI hallucinations, biases, and risks to intellectual property require enterprises to implement a well-structured, enterprise-wide risk and governance strategy. They need to ensure, for instance, that there are guardrails for handling and storing sensitive data used in training and inference, there is transparency embedded in their AI systems, that they stay abreast of the evolving regulatory environment and conduct regular compliance audits.
Enterprise leaders need to select the best foundation model vendor for their generative AI strategies. That entails careful assessment of the vendor’s expertise, particularly evaluating the model’s performance on relevant benchmarks, adaptability, data security, and privacy policies, as well as ensuring alignment with regulatory requirements.

The full Everest report is available for purchase here.

The post Most enterprises still at beginning of their AI journeys: Report first appeared on IT World Canada.

Data Privacy Week: Get ready for tougher regulation

In 2023, regulators around the world stiffened or vowed to tighten their data privacy and cybersecurity laws. Expect more of that in 2024.

With Data Privacy Week starting today, it’s a development that should worry data privacy officers, CISOs, and CIOs who aren’t prepared.

In the U.S., the WilmerHale law firm noted, the Federal Trade Commission (FTC) last year expanded its definition of the “unfairness” doctrine under Section 5 of the FTC Act in the privacy context, asserting that an alleged data privacy violation goes beyond just being deceptive to the consumer; it is outright unfair.

Separately, this month the FTC proposed sanctioning a data broker for selling precision location data of mobile users without their consent.

Meanwhile 10 states have consumer privacy legislation in various stages before their legislatures.

In Canada, Parliament is debating a new Consumer Privacy Protection Act (CPPA), which would expand the powers of the federal Privacy Commissioner.

This means that, more than ever, Data Privacy Week is a period when public and private sector leaders should be re-examining their data privacy and protection controls — or start planning to create those policies.

It’s one thing to have a cybersecurity policy to prevent and respond to cyber attacks. It’s another to have a policy on what your organization collects, how it processes that data, how transparent it is to customers and partners about the sale or distribution of that data to third parties, and how long data is kept.

Here’s a small reminder of the pitfalls: In 2019, Canadian financial services provider Desjardins Group learned an employee had copied data on 9.7 million current and former customers. Of that number, half were customers whose banking or credit card accounts had expired and whose information didn’t necessarily have to be kept.

If being squeezed by governments isn’t enough, privacy pros worry about not getting support from the C-Suite. In a just-released report, ISACA (formerly known as the Information Systems Audit and Control Association) says a global survey of 1,300 professionals who work in data privacy roles found nearly half of respondents (43 percent) say their privacy budget is underfunded. Only 24 percent expect to get a budget increase this year.

They said the biggest privacy failures in their organizations were lack of or poor employee training (49 per cent), not practicing privacy by design (44 per cent), and data breaches (42 per cent).

“Unfortunately,” said Quaiser Habib, director of engineering and Toronto site lead at Snowflake, a Montana-based cloud compute and storage platform, data privacy “is one of those missions where you hear about it only when something goes wrong.”

“Things like Data Privacy Week are an important reminder to reassess, to make sure everything is working as expected,” he said in an interview.

During this week, he said, data privacy pros should be asking if the electronic data held by their organization is safe, if the organization follows legal and regulatory requirements, if the right data access controls have been implemented, if data has been properly classified for storage and protection, and if staff is properly trained to meet data privacy requirements.

“Data privacy week is an important reminder to organizations, individuals, and businesses alike to safeguard their data and maintain compliance,” said Greg Clark, director of product management at OpenText Cybersecurity. “It is also an opportune time to take privacy to the next level.”

Given the vast amounts of data organizations have—which will grow exponentially with AI, machine learning (ML) and generative AI—using disparate methods to collect, process and manage data will no longer be enough, he said.

In today’s increasingly digitized world, a modern data privacy program needs to unify data discovery and protection to improve privacy and security posture, he noted. By modernizing and taking data privacy to the next level, organizations can remediate risk and ensure compliance and the responsible use of data while reducing their power consumption and carbon footprints from managing data. Most importantly, he added, gaining control over data creates an opportunity to strengthen trust with investors, boards, business partners and customers in the face of increasingly stringent regulations and a complex security landscape.

“Up levelling data privacy should not be overlooked,” Clark said. “Organizations should take control this data privacy week to safeguard their data.”

He said that best practices privacy leaders should be implementing in their data privacy programs include:

Understanding your data: Most organizations don’t understand how much sensitive or high-value data they have, nor where it is located. Understanding is key to reducing your data footprint and threat landscape. Data discovery tools, especially those that go beyond data mapping or metadata scans, are essential for privacy programs as they help find data, understand risk, and set priorities with internal stakeholders and business owners to mitigate compliance and financial risks;

Putting in place privacy-enhancing technologies (PET) to help preserve privacy while data is in use by the business. These include anonymization or de-identification of personal data.This is increasingly important for protecting unstructured data before it hits AI in large language models;

Wrapping your data privacy strategy in your Zero Trust approach to data access control and cybersecurity;

Cleaning up your house. The risks presented by over-retention, global privacy regulations, and cyber threats are huge, not to mention the resources required to maintain data estates. Data minimization can help keep data and application sprawl in check.

The post Data Privacy Week: Get ready for tougher regulation first appeared on IT World Canada.

Cyber Security Today, Jan. 22, 2024 – LockBit ransomware gang hits the Subway fast food chain, and Data Privacy Week starts

The LockBit ransomware gang hit the Subway fast food chain, and this is the start of Data Privacy Week

Welcome to Cyber Security Today. It’s Monday, January 22nd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



The LockBit ransomware gang says it compromised the Subway fast food chain. It’s threatening to leak hundreds of gigabytes of stolen data on February 2nd. According to the news site SecurtyAffairs.com, that data allegedly includes employee salaries, franchise royalty payments, master franchise commission payments, numbers on restaurant turnovers and more.

A data centre provider in Sweden called Tietoevry says one of its facilities was partially hit by a ransomware attack Friday night. Service to some customers has been affected.

A Russian state-sponsored group used a password spray attack last November to get into a Microsoft legacy non-production test account and then pivot to steal corporate emails. The attack, by a group Microsoft used to call Nobelium and now it calls Midnight Blizzard, was only detected earlier this month. The group used their initial access to get into the email accounts and stole attachments of a “very small percentage” of executives and employees in the cybersecurity, legal and other departments. Microsoft said the attack was not the result of a vulnerability in its products or services.

Last October VMware patched an out-of-bounds write vulnerability in its vCenter Server. However, researchers at Mandiant now say a Chinese-based threat group was exploiting that unknown hole for a year and a half before the patch was released. The discovery comes from Mandiant’s continued research into the group it calls UNC3886, which goes after VMware and Windows virtualized hosts. IT administrators with VMware systems that experienced unexplained crashes since 2021 should look for backdoors and signs of compromise — and, if they haven’t already done, so update to the latest version of vCenter.

The operator of the BreachForums marketplace for hacked and stolen data has been sentenced to 20 years of supervised release. Conor Brian Fitzpatrick received that sentence last week from a Virginia judge after pleading guilty to conspiracy to commit access device fraud, possession of child porn and other charges. According to Cyberscoop.com the 20-year-old will serve the first two years of the sentence as home confinement, won’t have access to a computer for a year and will have to register with state sex offender registries.

The maker of the MOVEit file transfer service hasn’t lost many customers despite the exploitation of a vulnerability last year that saw the personal information of over 90 million people stolen from over 2,000 firms using the application. Progress Software said last week customer retention levels remained steady in the second half of 2023. One cybersecurity analyst told Cybersecurity Dive customers may be sticking with the product because the vulnerability was a zero-day, so they don’t see the developer as negligent.

Finally, today starts Data Privacy Week, when IT, data privacy and organization leaders should think about their data collection and protection policies. They may want to consider a just-released study by Consumer Reports. It says Facebook is a great receiver of personal information from firms that collect individuals’ shopping information. These include big brands (like Amazon), retailers (like Home Depot, Walmart and Macy’s), data brokers and political service firms. This is how Facebook targets ads to its users. One finding: more than 2,000 companies had data on a group of over 2,000 volunteer Facebook users in the study group — but many of those people didn’t directly interact with all those firms. Is all this data collection and selling bad for your business’s reputation? The report says many consumers will be concerned about the extent to which their activity is tracked by Facebook and other companies. It suggests governments demand firms only collect data they need, and that governments improve the ability of consumers to opt out of data collection from several companies at once through automation.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 22, 2024 – LockBit ransomware gang hits the Subway fast food chain, and Data Privacy Week starts first appeared on IT World Canada.

Hashtag Trending Jan.22-Zuckerberg commits to developing AGI; CIOs worried about Broadcom’s changes to VMware; Apple’s Vision Pro fails to sell out on launch day

Mark Zuckerberg causes a storm with his commitment to developing Artificial General Intelligence, CIOs are sounding worried about Broadcom’s changes to VMWare, tax changes in the U.S. are having an impact on startups and – in what can only be described as a sign of the apocalypse, a new Apple product failed to sell out on its first day. 



 

Welcome to the end of the world as we know in this edition of Hashtag Trending.  I’m your host, Jim Love, CIO of IT World Canada and TechNewsDay in the US. 

Mark Zuckerberg, CEO of Meta, has stirred controversy with his commitment to developing an Artificial General Intelligence (AGI) system, potentially on par with human intelligence. This ambitious project, which he also suggested might be made open source, has raised alarms among experts and academics.

Zuckerberg envisions this next-generation technology as a key driver for tech services, even though the concept of AGI still remains largely theoretical. Even Sam Altman – although he has talked about huge advancements in the upcoming version 5 of ChatGPT – is not yet ready to announce AGI has been achieved.

AGI refers to an AI system capable of performing a wide range of tasks at human-level intelligence or beyond. The prospect of achieving such a breakthrough, and more so, making it publicly accessible, has sparked fears about its potential to escape human control and pose significant threats.

Dame Wendy Hall, a prominent computer science professor and member of the UN’s AI advisory body, labeled the idea of open source AGI as “really very scary” and criticized Zuckerberg’s approach as irresponsible. She emphasized the urgent need for regulatory frameworks to ensure public safety in the face of such powerful technologies.

Meta’s previous decision to open source its Llama 2 AI model was met with criticism, drawing parallels to “giving people a template to build a nuclear bomb.” The debate extends beyond Meta, with other tech giants like OpenAI and Google’s DeepMind also pursuing AGI, each with their own definitions and timelines.

Sources include: The Guardian

Broadcom’s recent acquisition of VMware, a virtualization pioneer, for $69 billion has led to significant changes in VMware’s product and pricing strategies, drawing the attention of chief information officers (CIOs) across various industries.

Since the acquisition’s completion in November, Broadcom has streamlined VMware’s product offerings from nearly 1,000 to just two bundles and shifted from perpetual license sales to a full subscription payment model. This move aligns with Broadcom’s history of acquiring companies and leveraging pricing power but has raised concerns among VMware’s customers. Additionally, Broadcom has laid off hundreds of VMware workers, although the company declined to comment on these layoffs.

With around 330,000 customers, VMware’s changes under Broadcom are closely monitored by CIOs, who are considering alternatives due to potential price increases and concerns about support levels.

CIOs like Todd Florence of Estes Express Lines and Suvajit Basu of Goya Foods express apprehension about their future with VMware, especially given Broadcom’s strategy of focusing on a core base of around 600 business customers. This approach, while successful in Broadcom’s chip business, is less common in software and raises questions about support and pricing for the broader customer base.

Analysts from Forrester Research note that moving away from VMware could be costly and time-consuming for customers, but also see potential benefits in the changes, such as simplified product portfolios and more focused customer engagement.

This overhaul by Broadcom signifies a pivotal shift in VMware’s strategy, impacting the broader IT and cloud computing landscape, with CIOs and companies reevaluating their reliance on VMware’s virtualization services.

Sources include: The Wall Street Journal

American legislators are rushing to clean up a mess created in a 2017 revision to the U.S. tax laws.

Previously, a company with $1.5 million in revenue and $1 million in R&D expenses would pay taxes on $500,000 profit. Now, the same company can only deduct one-fifth of its R&D expenses annually, resulting in a higher taxable profit. This shift is causing some startups to face unsustainable tax bills.

The impact is particularly felt among bootstrapped companies that are being penalized for generating profits sooner. Venture-backed startups, typically pre-revenue, are less affected for now. But even those companies are changing their planning, with some slowing down hiring due to budget constraints.

This taxation change also affects large corporations, especially those with overseas R&D activities. In late 2022, CFOs from major companies like Ford and Netflix appealed to Congress for a repeal of this change.

Currently, there’s bipartisan support to address this issue. The Tax Relief for American Families and Workers Act of 2024 proposes to delay the change to Section 174 until January 1, 2026, and apply it retroactively. However, it’s still early in the legislative process, and the outcome remains uncertain.

Meanwhile the Canadian government is moving to…. Just kidding. They’ve got bigger things to do that worry about technical innovation and its impact on the Canadian economy.

Sources include: Axios

 

Apple continues to take a beating from the EU and has proposed to allow third-party mobile wallet and payment providers to access the iPhone’s NFC (Near Field Communication) capabilities. 

This move is a response to a European Commission antitrust investigation, which has been ongoing for nearly four years. The investigation accused Apple of using its iOS policies to unfairly restrict competition in the mobile payments market, benefiting its own solution, Apple Pay.

Previously, while third-party developers could use the iPhone’s NFC features for reading electronic tags, they were restricted from making NFC payments, which was exclusively reserved for Apple Pay. Apple’s new commitment, if accepted, would enable users in the European Economic Area (EEA) to make NFC contactless payments from within third-party iOS apps, separate from Apple Pay and Apple Wallet.

This change marks a shift in Apple’s tightly controlled ecosystem. The proposed commitments would last for 10 years and could lead to a fine of up to 10 per cent of Apple’s worldwide annual turnover if not honored. 

The decision to open up NFC payments to third-party developers could have significant implications for the mobile payments market, particularly in the EU.

Sources include: The Verge

And this wouldn’t be news for any other company, but  Apple’s Vision Pro did not sell out on its launch day, despite limited initial availability estimated between 60,000 and 80,000 units. 

The Vision Pro, priced at $3,500 to $3,899 U.S. depending on storage capacity, saw its 256GB model quickly backordered, but the 512GB and 1TB models remained available for in-store pickup the day after launch. 

For Apple, that’s amazing given its reputation for creating hype around new products and typically seeing rapid sell-outs. 

The Vision Pro, marketed as a device ushering in the “era of spatial computing,” seems to have encountered challenges in gaining immediate traction, similar to competing AR and VR headsets.

Concerns have been raised about the Vision Pro’s weight, comparable to a 12.9-inch iPad Pro, and the limited number of spatialized apps available at launch. Apple developed only 15 stock apps for the device, and major third-party platforms like Netflix, YouTube, and Spotify have no immediate plans to create spatialized versions of their apps for it.

This situation suggests that even with Apple’s brand and marketing strength, success in the AR and VR market may not be guaranteed.

Sources include: Notebook 

And finally, two bits of news from OpenAI from last week. Open AI announced its first partnership with a university.  Arizona State University is going to use OpenAI’s Enterprise offering for its coursework and to build a personalized AI tutor for students.  

Enterprise offers a secure environment that will supposedly protect the university and student  data.

It also means that students will no longer have usage caps. Given that the course on AI prompts is one of the most popular courses on the university’s calendar, this could be a bonus in student recruitment. As well as the fact that presumably, there’s no penalty for using AI to assist in your assignments. 

And a second OpenAI story has been circulating on YouTube. Last month one YouTuber showed how he had gotten access to the main prompt for ChatGPT. I didn’t try it, but it looked credible. Now, with the advent of the store, there is at least one more video making the rounds showing how easy it is to expose the prompt that drives any custom GPT.  That one I can tell does work. 

We are moving exceptionally quickly into this new world – but sometimes it makes you wonder if at the speeds we are moving, if we are doing this in the safest and smartest way possible.

And that’s Hashtag Trending for today.  

I’d like to once again thank all of you who are new listeners and all of you that have helped us grow by sending this to a friend or by giving us a great review on the Apple store. While the listener base grew by 20 per cent thanks to you – and I’m keeping to my goal to double our listeners this year, with your help.  So please, invite a friend to join our Hashtag Trending family.

I’m your host, Jim Love, thanks for listening and have a Marvelous Monday.

The post Hashtag Trending Jan.22-Zuckerberg commits to developing AGI; CIOs worried about Broadcom’s changes to VMware; Apple’s Vision Pro fails to sell out on launch day first appeared on IT World Canada.

Samsung launches AI-powered Galaxy S24 series

For the first half hour of Samsung’s Galaxy Unpacked event Wednesday, one could be forgiven for thinking that it was a software launch, as speaker after speaker touted Galaxy AI, the company’s new set of artificial intelligence (AI) tools driving the Galaxy S24 series of devices.

“Artificial intelligence will bring about great change in the mobile industry, and in the way we live,” noted TM Roh, president and head of mobile experience (MX) business at Samsung, during his keynote address. “We believe Samsung Galaxy will democratize this change. Samsung Galaxy AI is the spark that ignites new possibilities.”

Circle to Search
Credit: Samsung Electronics

Samsung-developed AI features include simultaneous on-device two-way voice and text translation for calls on the new Galaxy S24 series devices (with a ton of fine print saying accuracy is not guaranteed). Partnerships with companies such as Google are providing cloud-based functionality like Circle to Search with Google, a new feature that allows users to circle, tap, or scribble on something on the screen, such as a piece of clothing or a landmark, and get search results about it without having to leave the app they’re viewing it in.

Image editing tools are all AI assisted – but Samsung adds a watermark and info in the metadata when a photo has been manipulated, as in the example it showed transforming a mundane basketball jump shot to a spectacular one, by shifting the player’s position in the photo.

Original image. Credit: Samsung Electronics
Edited image. Note the watermark at bottom left. Credit: Samsung Electronics

 

There will also be AI enhancements to Lens, but Samsung said they will not be available in Canada.

The AI goodies appear impressive – we’ll know better how they work after trying the devices. However, there is a caveat in the fine print, which says: “Galaxy AI features will be provided for free until the end of 2025 on supported Samsung Galaxy devices. Different terms may apply for AI features provided by third parties.”

Now for the phones. As in previous years, the Galaxy S24 phones come in three flavours: the Galaxy S24, Galaxy S24+, and Galaxy S24 Ultra. All three models feature the new Qualcomm Snapdragon 8 Gen 3 chip, with its AI engine that handles on-device AI processing.

The Galaxy S24 and Galaxy S24+ are pretty much the same, save screen size (6.2 inches vs 6.7 inches) and battery size (4000 mAh vs 4900 mAh). The Galaxy S24+ also comes with 12 GB of memory, vs the Galaxy S24’s 8 GB.

The Galaxy S24 Ultra is where Samsung pulled out all the stops, and it was the device featured during all of the demos at Unpacked. Its display is 6.8 inches, it has a 5000 mAh battery, 12 GB of memory and up to 1 TB of storage, two wide and two telephoto cameras on the rear, and has a titanium frame rather than the aluminum of the other models. The display uses Corning Gorilla Armor, a new, tougher glass that Corning said is also anti-reflective, where the other models offer Gorilla Glass Victus 2. And it comes with an S Pen.

All three devices are available for pre-order now, with availability in retail outlets and from carriers on Jan. 31. The Galaxy S24 starts at C$1,099.99, the Galaxy S24+ at C$1,399.99, and the Galaxy S24 Ultra is priced starting from C$1,799.99, topping out at C$2,279.99 for a model with 1 TB of storage.

The post Samsung launches AI-powered Galaxy S24 series first appeared on IT World Canada.

Cyber Security Today, Week in Review for the week ending Friday, Jan. 19, 2024

Welcome to Cyber Security Today. From Toronto this is the Week in Review for the week ending Friday, January 19th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

In a few minutes David Shipley, head of Beauceron Security, will be here to discuss recent news. But first a recap of some of the news from the past seven days:

Cryptocurrency scammers this month have been hacking the X accounts of companies or of well-known people. One of the latest was the city of Peterborough, Ont. David and I will discuss this trend.

We’ll also talk about the arrest in Ukraine of a resident for using hacked cloud accounts to create 1 million virtual servers for mining cryptocurrency.

We’ll discuss how an accounting firm employee falling for a phishing scam led to disclosure of the names of some customers of an American laptop maker.

And while it happened earlier this month, David will have thoughts about the genetic testing service 23andMe blaming some poor users’ password practices for a huge data breach.

Also in the news this week, Atlassian, Ivanti, Citrix, SonicWall and Juniper Networks were among companies that issued security updates to fix major vulnerabilities in their applications.

The ‘Have I Been Pwned’ website, where you can check if your credentials have been stolen, has added millions of unique email addresses to its data store. This is from a huge credentials-stuffing database called Naz.API that someone has been pedaling on the dark web. Not all of the stolen credentials on this list are new. But researcher Troy Hunt, who maintains the site, said about one-third of the email addresses are new to the millions of stolen credentials he has collected so far from other sources.

American home loan provider Academy Mortgage Corp. said it is notifying over 248,000 people that some of their personal data was stolen last March. An attacker accessed and disabled some IT systems, the company says. Information stolen included names, dates of birth and Social Security numbers stored for payroll and organizational purposes.

Google has updated its explanation of what the Chrome browser’s Incognito mode does and doesn’t protect users from. This comes as Google reportedly has reached a settlement on a class action lawsuit over alleged tracking of users’ activity in Incognito mode. According to the website MSPowerUser, the disclaimer now clearly states Incognito doesn’t change how data is collected by websites users visit, including Google.

The Governor of New Jersey this week signed data privacy and breach notification legislation. Starting next January companies doing business in the state can only collect personal data that is necessary for the business. And they’ll have to tell consumers what collected data is being used for.

Consumer Reports says nine of 10 American health-related websites it recently studied raised at least one data privacy concern, including sharing consumer data with a long list of third parties. Two websites that claimed they don’t sell or share covered data appeared to allow third party marketing cookies, which might legally constitute a data sale. Despite new health privacy protections in state laws, the report says, many health-related sites shared data with third parties.

Finally, a cybercrime syndicate has been creating a huge botnet by compromising smart TVs and set-top boxes running the Android and eCos operating systems for the last eight years. That’s according to researchers at a Chinese cybersecurity company called XLab. They call the bot Bigpanzi. Not only can it launch distributed denial of service attacks, it can also substitute content on victim’s TVs. One way homeowners can avoid being victims is by refusing to download apps that promise access to pirated movies and TV shows. Those apps are likely infected.

(The following is an edited transcript of part of the discussion. To hear the full conversation play the podcast)

Howard: There have been several high-profile hacks of prominent accounts on the X social media platforms, with many of the attackers renaming accounts and promoting links to cryptocurrency scams before the real owners regain control. One victim this week was the city of Peterborough, Ont. Recent victims have included security firm Mandiant and the U.S. Securities and Exchange Commission. The group that hacked the SEC account claimed the regulator had announced a change in policy for bitcoin exchange-traded funds. We’re not sure if this is one group or several copycats. David, what’s going on?

David Shipley: Thankfully, for the most part it looks like it’s just the usual crypto scammers. I’ll speak up about the SEC separately because I think there’s some unique twists about it. But for the other ones, for Mandiant the the city of Peterborough this could have been so much worse. If it was someone doing it for the lulls, as the hacker kids like to say, imagine one of those accounts pumping out deep fake intimate images and you can get a sense of how off the rails this could have gone. Or, on the other side, hacking the Mandiant account to hit key folks who follow it like security professionals, researchers, CISOs and hitting them with malicious links or malware. That could have been far more damaging than promoting crypto scams. So I think we dodged a bullet on this one.

The X/ Twitter hack — I just can’t get over calling it Twitter — is fascinating because it did move the market for a short time, particularly for bitcoin, and that could have made somebody millions of dollars. On top of that a few days later the actual announcement did come out that the SEC authorized bitcoin ETFs. I’ve often thought about how hacks and social media takeovers could be used to move entire industries or markets in a way that would be hard for authorities to trace manipulation of stocks or commodities …

Howard: One thing these X takeovers have in common is weak security — easily guessed passwords or a security weakness or an account user is falling for a trick and giving up their password. This last is the allegation by X itself in the hack of the SEC’s account. X tweeted that the cause was a hacker getting control over a phone number associated with the SEC account through what they said was a third party. It sounds like either a wireless carrier or an outside support company was tricked into giving an attacker control over an employee’s phone and that employee uses that phone tor the SEC tweets.

David: It screams SIM swap attack. One of the questions I had is was the SIM swap tied to bypassing MFA? Because, ironically, phone-based SMS-based multifactor authentication is a premium feature if you pay for X/Twitter. Was that how they bypassed MFA? Which makes me wonder if they [the attackers] used an old feature where you could send an SMS text and it would create a tweet for you. If you are planning a market-moving event and if you were going to poke the SEC, using burner phones would probably not be a bad idea: Get a burner phone, SIM swap it, do the tweet and ditch the phone. That could make investigating it even harder.

Howard: In the case of the Mandiant hack, the company said employees are supposed to have two-factor authentication enabled on any account that they use for logins. However, it said in this case due to some team transmission transitions one person’s account was open and it fell to a brute-force password attack.

David: For all the technological tools we have to secure accounts things like MFA and conditional access et cetra, it always always comes down to people and processes. So the interesting question for enterprises is how do you monitor compliance for third-party SaaS platforms like X and others when it comes to making sure accounts have turned on MFA? At my firm every single quarter we have to do a full review of all the applications that we use as part of our ISO 27001 process. We have to provide evidence of not only who has access and what access they have, but are appropriate controls in place as dictated by the risk impact [assessment] — even for a 40-person company. That’s a lot of work. We estimate that that we probably spend about $5,000 to $6,000 a year in staff time [on that]. That’s just a direct cost. That’s not the productivity cost to review around a hundred applications quarterly. Imagine a large enterprise that has tens of thousands of applications: How do they stay on top of these things? The only thing I would say is that we’re learning from this experience. I think it’s good to have a learning attitude from this [the X account takeovers]: How could we avoid something like this?

Howard: What are the lessons learned from these recent hacks of X?

David: There are a couple of different pieces: First, we need a standard way for SaaS [software-as-a-service] customers to automatically be able to query [accounts] for compliance with basic hacking mitigations and controls like multifactor authentication. You should be able to just plug into your SaaS provider with some kind of a trusted feed setup so that it can send alerts to other security tools when there’s a rogue account created or an account that doesn’t have basic control like MFA. This standard needs to be mandated by regulators for platforms once they reach a certain size, whether that’s revenue or user base. And you should prohibit vendors from selling this specific set of functionality as a premium — ie. an extra cost service. This API access should allow for systems to query for access compliance and should send alerts in a standard format when accounts don’t have the proper control set up now. That’s the technology side. Ironically, that’s not that hard to do, but making it happen is going to require policy and regulation –and a mindshift miracle.

Part two, regulators should mandate mandatory multifactor authentication for platforms of certain size and scale — like big tech social media firms, major cloud providers. At the same time industry best practices standards and certifications — I’m looking at you SOC 2, ISO 27001 — should require companies provide this to their customers as well. Maybe we can see that before 2030.

Part 3 is the importance of measuring security culture, not just compliance. I mentioned earlier how my firm measures compliance and how we’d see a higher cost for unclear gains. Maybe if we did it more often. But if folks believe in the importance of doing what’s right and being secure as part of their job and as part of the right thing to do, that could potentially make all the difference in the world. Getting people to that point takes more than Cyber Security Awareness Month and a platform. But it can have huge ROI, and that’s what building a security culture can do.

The post Cyber Security Today, Week in Review for the week ending Friday, Jan. 19, 2024 first appeared on IT World Canada.

Lock down TeamViewer or pay a price

IT administrators allow remote access software like Zoho Assist, TeamViewer VNC Connect, Windows RDP and AnyDesk to help employees do their work away from the office.

Unfortunately, those products can also be useful to hackers, who try to leverage poorly-secured applications like these on computers to also get (unapproved) access into enterprise networks. Which is why these utilities have to be locked down.

The latest example of failing to do that comes in a report from researchers at Huntress, who recently discovered that two endpoints at unnamed organizations had been encrypted with ransomware through compromised TeamViewer software.

Logs suggest the attacker in each case was the same, Huntress staff said in a blog. On both endpoints, the initial ransomware deployment started with a DOS batch file run from the hacked user’s desktop.

Fortunately, security software on one computer limited the number of files that were encrypted. And in neither instance was there any indication the threat actor conducted reconnaissance beyond the impacted endpoint, nor attempted to move laterally to other endpoints within the infrastructure.

There have been several reports of attackers using TeamViewer and other remote access tools to their advantage. In December, Microsoft disabled Windows App Installer because threat actors were using it to trick people trying to download legitimate versions of TeamView, AnyDesk and other utilities.

Last summer, cybersecurity agencies from seven countries warned that the LockBit ransomware gang either leveraged existing installations of TeamViewer and other tools or added them to compromised IT systems.

“Threat actors look for any available means of access to individual endpoints to wreak havoc and possibly extend their reach further into the infrastructure,” Huntress warned, which is why IT administrators need a thorough inventory of software under their control so they can apply security policies.

The post Lock down TeamViewer or pay a price first appeared on IT World Canada.

Toronto to integrate IT systems after ransomware attacks on zoo, public library

After suffering serious ransomware attacks on its zoo and public library system, the city Toronto has decided to integrate its IT systems for better cybersecurity, the Toronto Star reports.

“The city of Toronto’s main system is one of the most secure in North America, second to New York,” the news agency quotes Mayor Olivia Chow saying at a press conference. Bringing all the city-linked organizations under the city’s umbrella would make them “far more secure,” she said.

City agencies like the library, zoo, and the Toronto Transit Commission (TTC), have their own IT systems.

The decision to merge systems comes after the Toronto Zoo was hit earlier this month and the Toronto Public Library was hit in October. The library attackers stole information on current and former staff, including their names, social insurance numbers, date of birth, and home address. Copies of government-issued identification documents provided to the library by staff were also likely taken.

The library still hasn’t fully restored its systems. In an update today, it said the home page of its website will be restored by the end of the month. However, online access to the full catalogue and users accounts won’t be restored until February.

“We recently restored network connectivity to more than 3,000 staff computers,” the statement says. “This needed to happen before reconnecting our 2,000 public computers to the network.”

Use of public computers in branches for connecting to the internet will return early in February. However, a date for restoring the ability of users to print documents from public computers hasn’t been set.

The post Toronto to integrate IT systems after ransomware attacks on zoo, public library first appeared on IT World Canada.

Cyber Security Today, Jan. 19, 2024 – Vulnerabilities found in server firmware, a warning to Docker administrators, and more

Vulnerabilities found in server firmware, a warning to Docker administrators, and more.

Welcome to Cyber Security Today. It’s Friday, January 19th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Nine vulnerabilities have been found in an open-source reference implementation of a protocol that allows enterprise computers and data centre servers to boot across a network. If exploited these holes could lead to data theft, denial of service attacks and other ugly things. Researchers at Quarkslab say the problems are in TCP/IP stack specification maintained by Tianocore TEE-AN-O-CoRE, a community of developers from software vendors including Microsoft, ARM, American Megatrends, Phoenix Technologies and others that use the project for their firmware implementations. Carnegie Mellon University’s Computer Emergency Response Team (CERT) says IT leaders should look for and install firmware updates from their equipment manufacturers. They should also consider disabling a capability called PXE boot, sometimes called Pixie boot.

Separately, the Carnegie CERT issued a warning that general-purpose graphic processors from AMD, Apple and Qualcomm have a memory leak vulnerability. The hole, discovered by researchers at Trail of Bits, means at attacker with access to a GPU programmable interface can dump local memory. IT managers should watch for security updates from their hardware makers.

Button up your Docker containers. That’s the advice from researchers at Cado Security. Their honeypot recently attracted a piece of malware hunting for vulnerable Docker services. It installs a cryptominer as well as an application called 9hits that threat actors can use to run their attacks from the compromised container. It isn’t clear how this Docker malware is being spread. But the report makes it clear that exposed Docker hosts are a risk to organizations that use them.

American cybersecurity authorities have issued an advisory to help defenders fight the Androxgh0st malware. A threat group has used this malware to create a botnet to steal login credentials for Amazon Web Services, Microsoft Office 365, SendGrid, Twilio and more. Targets also include websites that use the Laravel LARA-VEL web application framework and web servers running certain versions of Apache HTTP Server. The advisory includes indicators of compromise defenders should watch for.

The pressure on IT security leaders in the financial services sector won’t let up this year. That’s according to researchers at Abnormal Security. They note in a report this week that firms in this sector get about 200 advanced phishing attacks per 1,000 mailboxes each week. One of the most common tactics used by threat actors is impersonating a business provider, like a supplier or a software company, and demanding payment for an invoice. Last year that type of attack went up 137 per cent compared to 2022.

Finally, Middle Eastern affairs experts at universities and think tanks should be careful replying to emails. According to Microsoft, they’re being targeted by an Iranian-based threat group it calls Mint Sandstorm. Typically the gang uses custom phishing lures to trick targets into downloading malicious files and gain access to their computers through a backdoor.

Later today the Week in Review podcast will be available. On this show guest commentator David Shipley and I will discuss the recent takeovers of poorly secured accounts on the X platform, and more.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 19, 2024 – Vulnerabilities found in server firmware, a warning to Docker administrators, and more first appeared on IT World Canada.