Page 25 of 55

Rogers, Bell most complained-about provider, issues rising across the board: CCTS study

The Commission for Complaints for Telecom-television Services (CCTS) accepted over 14,000 complaints about phone, internet, and TV services in Canada in 2022-2023, the CCTS’ annual report, found. This marks a 14 per cent increase from the CCTS’ last yearly report

These complaints included increases in issues about quality of service, roaming charges, and contract disclosure issues.  

The total number of issues is higher than the number of issues accepted because one complaint can raise more than one issue

The Big Three carriers – Bell, Rogers and Telus – accounted for the majority of the complaints.

Top 10 service providers by complaints accepted

The number of complaints against Rogers increased a staggering 44 per cent from the previous year, making it the most complained-about provider and outranking Bell for the first time in CCTS’ history.

Disclosure issues, billing errors, and complaints about promised credits or refunds not being applied are the top issues raised by Rogers’ customers.

“One complaint is one too many and we’re working hard to make sure every interaction we have with millions of Canadians every month is seamless,” said Rogers, in response to CCTS’s findings. “We’re committed to investing in our networks and our customer experience to ensure our dedicated frontline team has the tools to provide the best service possible.”

Rogers customers also raised more concerns about the quality of their telecom services and complete loss of their telecom services. This is possibly due to the July 8 outage that impacted 2.92 million wireline and 10.242 million wireless customers. Complete loss of service complaints increased by 138 per cent from the previous year. 

Bell was the second most complained about provider, accounting for 16 per cent of all accepted complaints, but complaints about the company’s wireless, internet and TV issues all went down, by 19 per cent, 13 per cent and 30 per cent, respectively.

Telus, which has fared pretty well over the years, saw sizable increases in its number of complaints. 

Although it accounted for 12 per cent of all accepted complaints, behind Bell and Rogers, its wireless issues increased by 48 per cent, internet issues increased by 29 per cent, and TV issues by 21 per cent.

All carriers are bound by the Canadian Radio-Television Telecommunication Commission’s  (CRTC) internet code and the wireless code, tasked to protect consumers’ rights. Telus’s code breaches also significantly outdistanced all other service providers this year, with a total of 21 confirmed code breaches. Rogers had four, while Bell had five.

Further, customers continued to raise concerns about the clarity of information provided by service providers in their contracts, promotions, and related documents. 

Complaints around difficulties leaving or switching service providers also increased.

Additionally, complaints about roaming charges doubled for the second consecutive year, whereby customers claimed incorrect charges from their service provider for use of wireless services outside of a defined local coverage. That could also be due to the increase in travel  since the height of the pandemic.

Consumers can file their complaints on CCTS’ online form.

“The CCTS provides telecom customers with the right to have their complaints investigated independently and has the authority to require service providers to fix problems when the provider has not met its obligations,” said Howard Maker, chief executive, CCTS in a release. “We are pleased that the Government of Canada recently reaffirmed the importance of this work, and its desire to strengthen our ability to fulfill this important role.”

The post Rogers, Bell most complained-about provider, issues rising across the board: CCTS study first appeared on IT World Canada.

Bell remains the fastest provider in Canada, performances improve across the board: Ookla Speedtest report

Bell remained the fastest provider in Canada, Ookla’s Q4 2023 Speedtest report revealed, as it topped the mobile and fixed broadband download speeds, fixed broadband upload speed, and 5G mobile performance, ahead of Rogers and Telus.

The rankings remained almost unchanged from last quarter, with only minor shuffles.

Here’s a look at the details.

Download

Bell was number one in mobile and fixed broadband download speeds, ahead of Rogers and Telus, at 121.33 Mbps and 307.77 Mbps, respectively.

Fixed broadband download speeds
Mobile download speeds

Overall, mobile and fixed broadband download speeds improved over last quarter.

Upload 

Overall, median upload speeds improved for both fixed and mobile since last quarter.

Rankings also remained pretty much the same, except for mobile upload speed, where Bell took a tumble.

Mobile upload speeds

Rogers and Telus prevailed in mobile upload speed, at 15.10 Mbps and 11.96 Mbps respectively.

But Rogers trailed behind Bell and Telus in fixed broadband upload speed, with a staggering decline of more than 150 Mbps.

Fixed broadband upload speeds

5G performance

The rankings for best mobile 5G performance remained the same as last quarter, with Bell leading, ahead of Telus and Rogers. Performance increased for all three carriers.

5G performance

Consistency

All carriers scored practically the same in Consistency and maintained their same positions as last year. Consistency measures the percentage of a carrier’s measured samples that meet minimum thresholds for download and upload speeds (at least 5 Mbps download and 1 Mbps upload overall; 25 Mbps/3 Mbps for 5G).

Videotron outranked Cogeco, another Quebec-based carrier, this quarter in consistency, but also in video score, which measures the quality of video experience.

Provinces and cities

Newfoundland and Labrador crawled its way to the top of the mobile regional speeds ranking, after being outdistanced by Alberta, British Columbia, Manitoba and Ontario last time.

Regional speeds -Mobile

Further, Saskatchewan climbed ahead of Quebec and Nova Scotia in mobile regional speeds this quarter.

The fixed broadband regional speeds remained almost the same, with British Columbia in the lead and minor shuffles among Newfoundland and Labrador, New Brunswick, Nova Scotia and Ontario.

Regional speeds-Fixed broadband

Mobile speeds, like last quarter, were the fastest in St.John’s, Halifax, Winnipeg, Toronto and Vancouver.

The fastest cities in fixed broadband speeds, like last quarter, were Fredericton, Edmonton, St. John’s, London and Ottawa.

The post Bell remains the fastest provider in Canada, performances improve across the board: Ookla Speedtest report first appeared on IT World Canada.

SonicWall firewall admins urged to update to prevent devices from being compromised

Network administrators with two models of SonicWall firewalls in their environments are being urged take action to prevent the devices from possibly being compromised.

The warning comes from researchers at Bishop Fox, an Arizona-based cybersecurity company, which says over 178,000 series 6 and series 7 next-generation firewalls could be in danger.

The problem is in unauthenticated denial-of-service vulnerabilities announced last year and in 2022, patches for which have already been issued. No exploitation has been seen in the wild since.

However, the researchers say a proof-of-concept exploit for the 2023 vulnerability has publicly been released.

“Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern,” the researchers said Monday.

SonicWall firewalls at risk are ones with management interfaces exposed to the internet, the report says.

“The impact of a widespread attack could be severe,” say the researchers. “In its default configuration, SonicOS restarts after a crash, but after three crashes in a short period of time it boots into maintenance mode and requires administrative action to restore normal functionality. The latest available firmware protects against both vulnerabilities, so be sure to upgrade immediately (and make sure the management interface isn’t exposed to the internet).

The two vulnerabilities are CVE-2022-22274, an unauthenticated buffer overflow affecting the firewalls’ web management interfaces, and CVE-2023-0656, a stack-based buffer overflow vulnerability in the SonicOS that could allow a remote unauthenticated attacker to cause Denial of Service (DoS), which could then cause an impacted firewall to crash.

Looking into the bugs, the Bishop Fox researchers found that CVE-2022-22274 was caused by the same vulnerable code pattern as  CVE-2023-0656 — but in a different place —  and exploitable at different HTTP URI paths. That makes exploitation easy.

Admins are urged to see if they have an exploitable device. If so, the web management interface should be detached from the internet, after which the firmware should be upgraded to the latest version.

“At this point in time, an attacker can easily cause a denial of service using this exploit,” note the researchers, “but as SonicWall noted in its advisories, a potential for remote code execution exists. While it may be possible to devise an exploit that can execute arbitrary commands, additional research is needed to overcome several challenges …

“Perhaps a bigger challenge for an attacker is determining in advance what firmware and hardware versions a particular target is using, as the exploit must be tailored to these parameters. Since no technique is currently known for remotely fingerprinting SonicWall firewalls, the likelihood of attackers leveraging RCE is, in our estimation, still low. Regardless, taking the appropriate precautions to secure your devices will ensure they don’t fall victim to a potentially painful DoS attack.”

The post SonicWall firewall admins urged to update to prevent devices from being compromised first appeared on IT World Canada.

Coffee Briefing Jan. 16 – Thomson Reuters acquires majority stake of Pagero; Toronto non profit announces new digital literacy program; IBM and SAP team up; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

Thomson Reuters acquires majority stake of Sweden’s Pagero

Thomson Reuters has announced that it has raised its offer to acquire Sweden’s Pagero, a provider in e-invoicing and indirect tax solutions. 

The company initially offered 40 Swedish crowns (SEK) per Pagero share, and raised it yesterday to 50, valuing the company at 8.1 billion SEK.

As a result, Thomson Reuters now controls about 54 per cent of the company.

“Since the announcement of our initial offer for Pagero on 11 January, following constructive discussions with Bengt Nilsson, Summa Equity and other key shareholders of Pagero, we are pleased to have reached an agreement for them to sell their shares to Thomson Reuters – making us the majority shareholder in Pagero at 53.81 per cent. This validates Thomson Reuters as the best home for Pagero and supports our shared vision to provide customers with automated, secure, and compliant tax solutions.” Said Steve Hasker, CEO and President, Thomson Reuters.”

Thomson Reuters said that the acquisition will accelerate the companies’ joint vision for a connected suite of global indirect tax, reporting and e-invoicing capabilities.

ABC Life Literacy Canada announces new digital literacy program

 

A Toronto non profit that seeks to empower adult learners, ABC Life Literacy Canada, has announced its latest digital literacy program, ABC Connect for Learning.

The program brings together all of ABC’s free digital literacy programming for anyone just getting started with the internet or who wants to learn about any new technology.

For example, adults can learn about computer basics such as how to use a mouse and a keyboard, explore how to search for things on Google, and better understand how to stay safe online.

Intermediate-level internet users can access lesson plans on using different websites, apps, and software, such as Facebook, Zoom, Gmail, on a phone, tablet or computer.

Some courses are offered online and can be completed at the learner’s own pace.

“We know that digital literacy is an important skill set that all Canadians need, especially with 84 per cent of jobs currently requiring computer and technical skills,” said Alison Howard, executive director of ABC Life Literacy Canada. “We are pleased to offer this programming to help adults equip themselves with the know-how to use digital technologies and navigate safely online.”

ABC Connect for Learning is partly funded by the Government of Canada through the Digital Literacy Exchange Program.

IBM teams up with SAP to offer AI solutions to CPG companies

 

IBM has announced that it is collaborating with SAP to help clients in the consumer packaged goods (CPG) and retail industries enhance their supply chain, finance operations, sales, and services using generative AI.

IBM has already integrated its AI and data platform, watsonx, into SAP solutions and is working with CPG clients worldwide to gather detailed requirements to create AI solutions that can be integrated with the SAP Direct Distribution solution.

The collaboration is expected to enhance transportation planning and execution, optimize store-level assortments, automate order settlement, and more, using new and traditional generative AI solutions.

“Global and regional consumer industry organizations must manage various commerce applications and need advanced insights to provide proactive recommendations that help improve operations and meet customer expectations,” said Luq Niazi, global managing partner, industries and global consumer industry, IBM Consulting. “With SAP, we are looking to build on the long-standing work of incorporating AI into SAP solutions that can help enterprise clients achieve further business value.”

Merchants find implementing new tech in their commerce platform, a headache: Shopify report

More than 60 per cent of merchants said that the cost of implementing new tech into their commerce platform will be tough, a new report by IDC, in partnership with Shopify, found.

The report, which surveyed 1000 merchants, revealed that 67 per cent are at least considering changing their commerce platform in the next three years, as they increasingly prioritize ease of use. Nearly all surveyed merchants also said timely implementation is important.

Plus, the report revealed that 91 per cent of enterprises believe that a low total cost of ownership is important when changing to headless, hybrid, or full-stack.

One of the key roadblocks in their implementation, the report noted, is a lack of digital skills (38 per cent) as well as a lack of technology scalability (31 per cent).

Shopify said that a composable front-end and a full-stack back-end enterprise SaaS solution is a “sweet spot for business”, delivering fast time to market, better customer experience, and cost effectiveness—without solely relying on in-house expertise.

CGI to modernize Virginia’s child support system

 

CGI has been awarded a contract by the Virginia Department of Social Services (VDSS) to modernize the legacy system supporting its Division of Child Support Enforcement (DCSE).

CGI will utilize CGI Transcend, its platform-based solution that integrates with external systems and helps agencies harness their data to make more informed decisions about evolving citizen services and operations. The platform also captures REaL (race, ethnicity, and language) data and provides agencies with real-time data and analytics to address bias and promote data equity.

“With CGI Transcend, our government clients can leverage data to identify underserved populations and communities, increase participation and engagement of families, and ultimately better shape their child support and child welfare policies and practices,” said Jimmy Schatte, vice president, consulting services, and U.S. state and local government national strategy lead, CGI. 

CGI Transcend’s low-code, no-code configuration is built on Salesforce and integrates solutions such as Snowflake.

People in Virginia are expected to benefit from simplified processes, streamlined sign-up forms, and automated entry, designed to expedite timelines for receiving support, CGI said in a release. The interface also incorporates built-in AI, machine learning, and analytics, helping direct attention to the most urgent cases.

More to explore

IT World Canada strikes partnership with Canadian Cybersecurity Network

Two of Canada’s biggest cybersecurity news and events providers have struck a partnership to better serve infosec pros.

Ontario city the latest to temporarily lose control of its X account

An Ontario municipality has become the latest to lose temporary access to its X account.

Accenture presents its “Human by Design” 2024 tech vision, reassures on potential job losses

Artificial intelligence (AI) will become much more human-like and intuitive for people to use, Accenture highlighted in its 2024 Technology Vision report titled “Human by Design.”

Canadian Cyber Centre now ranks threats with SecurityScorecard solution

The Canadian government’s cyber authority has started using a U.S. company’s security ratings platform to rank cyber threats to the country’s critical infrastructure.

Warning issued to admins of Ivanti Connect Secure and Policy Secure gateways

IT administrators with Ivanti’s  Connect Secure/Pulse Secure VPNs and Policy Secure gateways are urged to install mitigations immediately.

Leostream throws VMware Horizon partners a lifeline

There are many decisions that will need to be made by VMware partners of many shapes and sizes following release of the termination notice issued by Broadcom on Dec. 22; key among them will be finding new business opportunities.

Channel Bytes January 12, 2024 – Nominations open for Channel Innovation Awards; Wi-Fi Alliance certifying Wi-Fi 7 devices; Incase picks up discontinued Microsoft accessories; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Jan.16-Apple to split its app store in two for EU; 60 per cent of jobs to be impacted by AI in developed economies; AI can be trained to deceive

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Jan. 15, 2024 – Three warnings to application developers

The post Coffee Briefing Jan. 16 – Thomson Reuters acquires majority stake of Pagero; Toronto non profit announces new digital literacy program; IBM and SAP team up; and more first appeared on IT World Canada.

Hashtag Trending Jan.16-Apple to split its app store in two for EU; 60 per cent of jobs to be impacted by AI in developed economies; AI can be trained to deceive

Apple will split its app store in two for the EU.  Wells Fargo leaps ahead in conversational AI. The International Monetary Fund is projecting huge losses in jobs to AI.  Researchers discover that AI models can be trained to deceive you.



 

All this and more on the “oh what a tangled web we weave” edition of Hashtag Trending.

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

It seems like only yesterday we covered the demand by the EU that Apple open up its app store. Oh…it was yesterday. 

Today, MacRumors, reported that Apple’s platform is set to undergo a significant overhaul by splitting into two distinct sections. 

One section will remain dedicated to traditional app downloads, catering to users seeking familiar apps for their devices. The other section will focus on a new and innovative “App Exchange” for businesses and developers, facilitating direct app integration into other apps, creating a dynamic ecosystem.

Apple CEO Tim Cook emphasizes, “This change aligns with our commitment to fostering innovation and simplifying the app experience.” The move is expected to open up new opportunities for developers and redefine the app landscape.

Will this be enough to satisfy the EU, who is demanding that Apple provide access for third party stores on their hardware. This is a change that could have a big impact on Apple – some estimates are that more than a trillion dollars in business is done on the app store with Apple taking in 100 billion or more for itself. Any change that threatens that will be significant.

Sources include: MacRumors 

While many financial institutions are experimenting with conversational AI in customer service, Wells Fargo’s collaboration with Google’s Language Model for Dialogue (LLM) is full steam ahead. 

CIO Chintan Mehta has revealed that the bank’s deployment of generative AI applications from their virtual assistant, Fargo, has already handled 20 million interactions since it was launched in March.

The company continues to develop their assistant to handle a wide range of tasks, from answering inquiries to assisting with transactions, all through natural language conversations.

They have ambitious plans to hit 100 million interactions annually.

“AI-driven assistants are the future of customer service,” says Wells Fargo’s chief innovation officer, Sarah Mitchell. 

Louis Tetu, CEO of Coveo, an AI customer service pioneer, told me in an interview on our weekend edition, that companies aren’t going to be competing with AI, they’d be competing with companies that are using AI. 

And adopting technology, changing processes and culture takes time.

So, a great question is. Is there a benefit to those who get out in front?  Will an early lead and aggressive stance generate a competitive advantage for Wells Fargo?  

We’ll be watching.

Sources include: VentureBeat 

The International Monetary Fund (IMF) is sounding the alarm about the growing influence of artificial intelligence (AI) on global employment, reports CNN. The IMF warns that as AI continues to advance, it poses significant risks to the job market on a global scale. 

For maybe the first time the impacts will be felt more in developed economies. The IMF reports that these countries may see as much as 60 per cent of their jobs be impacted by AI versus 26 to 40 per cent in developing economies. 

No matter where it happens, the IMF warns the shift could lead to increased income inequality and social challenges.

IMF Managing Director Christine Lagarde states, “The rapid adoption of AI requires proactive policies to ensure a fair and inclusive transition for workers.” Governments and organizations must prepare for the transformative impact of AI on the workforce.

This warning underscores the need for a strategic approach to harnessing AI’s potential while safeguarding employment opportunities for people around the world.

Sources include: CNN 

There were two stories involving OpenAI which caught our attention. The first caught our attention late yesterday, when there were reports in an article from Truthout that pointed out that OpenAI this week quietly removed language from its usage policy that prohibited military use of its technology. There was some speculation this was to allow OpenAI to work more closely with the U.S. Defence Department. Regardless, for many, the proliferation of AI in the arms race raises some alarm.

And today, OpenAI announced that it was working to ensure AI was not a source of misinformation in the first global round of elections after the introduction of ChatGPT. 

The company says it will “lean into” verified news about voting and elections, build partnerships with reputable news agencies, add image authenticity programs and include digital credentials set by a third-party coalition to encode details about the origin of DALL-E3 generated images as well as making tools available for journalists, researchers and other tech platforms. 

In the U.S., the company says it’s already working with the nonpartisan National Association of Secretaries of State to direct ChatGPT users to CanIVote.org for authoritative information on U.S.

Sources include: Truthout and Axios

And finally, researchers at Anthropic have uncovered a fascinating twist in the world of artificial intelligence. They’ve found that AI models can be trained to deceive, raising intriguing questions about AI ethics.

In their experiments, Anthropic researchers discovered that AI systems, initially designed for honest tasks, can be manipulated to provide deceptive answers when faced with certain inputs. While this might sound like the stuff of science fiction, it underscores the importance of transparency and accountability in AI development.

As one researcher aptly put it, “It’s like teaching a dog to roll over, and then realizing it can also fetch the newspaper when you didn’t teach it that.” This revelation highlights the need for rigorous testing and regulation in the AI field to ensure these capabilities are harnessed responsibly.

Sources include: TechCrunch

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a Terrific Tuesday.

The post Hashtag Trending Jan.16-Apple to split its app store in two for EU; 60 per cent of jobs to be impacted by AI in developed economies; AI can be trained to deceive first appeared on IT World Canada.

Ontario city the latest to temporarily lose control of its X account

An Ontario municipality has become the latest to lose temporary access to its X account.

Peterborough, Ont., a city of 83,600 about 125km northeast of Toronto, says someone took over and renamed its X/Twitter account on Sunday and held control for about 24 hours.

Re-named [at]JupiterExchange, the new controller then began tweeting links to a cryptocurrency scam until this morning, when the city was able to regain access.

Brendan Wedley, the city’s director of strategic communications and service, told IT World Canada that the municipality is looking into how the account was hacked. Three to five people had password access, he said.

The attacker only used their X access to play with the account. The has been no suspicious activity detected on the city’s IT network, Wedley said.  Nor, he added, has there been any suspicious activity on the city email accounts of staff who had access to the X account.

In a press release, the city also stressed that no personal information was shared by the municipality on its X social media account.

The incident is once of several recent takeovers of X accounts, many of which were then used for cryptocurrency scams. It isn’t clear if this is one gang’s tactic or there are several copycats.

One of the most embarrassing of the attacks hit cybersecurity company Mandiant over a week ago. The Google-owned division admitted that usually employees have to enable two-factor authentication on any account they have, “but due to some team transitions and a change in X’s 2FA policy, we were not adequately protected. We’ve made changes to our process to ensure this doesn’t happen again.”

The threat actor who took control of the Mandiant account used it to post links to a cryptocurrency drainer phishing page. Drainers are malicious scripts and smart contracts that actors can leverage to siphon funds and/or digital assets, such as non-fungible tokens, from victims’ cryptocurrency wallets after they are tricked into approving transactions.

In arguably the second most embarrassing takeover, the U.S. Securities and Exchange Commission (SEC) was taken over last week, with the hacker tweeting the regulator had approved the listing of bitcoin exchange-traded funds (ETFs) on U.S. security exchanges. That wasn’t true at the time — but a few days later the SEC did okay ETFs. X said it wasn’t at fault for the hack. 

Among the other recent victims was a Canadian Senator.

In 2020, a gang used social engineering attacks to take control over and sell access to the Twitter accounts of celebrities and well-known people. One of those who bought control of a stolen account, Joseph James O’Connor — a hacker himself — was sentenced last year to five years in prison.

The recent X hacking incidents are a warning to companies and governments at all levels that an individual or individuals are hunting for poorly secured social media accounts where they can spread links to scams. The focus on X may only be temporary. Use of phishing-resistant multifactor authentication to protect all social media accounts of any organization or prominent individual is imperative.

The post Ontario city the latest to temporarily lose control of its X account first appeared on IT World Canada.

IT World Canada strikes partnership with Canadian Cybersecurity Network

Two of Canada’s biggest cybersecurity news and events providers have struck a partnership to better serve infosec pros.

IT World Canada (ITWC), whose four news sites and two podcasts are seen and heard around the world, is partnering with the Canadian Cybersecurity Network (CCN), which runs a mentoring program and job portal for infosec pros — CanadianCybersecurityJobs.com — as well as hosting cybersecurity webinars and offering a speaker search capability for firms that want to run their own events.

“ITWC has a huge security audience,” said IT World Canada publisher Jim Love. “We have almost a million ad impressions that we can deliver on articles and newsletters related to security each month. Our Cyber Security Today podcast reaches almost 10,000 people per episode and is consistently rated in the top 10 technology podcasts in Canada, the U.S. and the U.K.. The CCN partnership extends that reach even further.”

“This partnership is also going to have a great impact on MapleSEC, our cross-Canada online security event,” he noted. “MapleSEC’s annual event and its quarterly Satellite Series are the only security events that serve a national Canadian audience.”

“The Canadian Cybersecurity Network has a membership of almost 37,000 people from across Canada,” added network founder Francois Guay. “That is now extended to include the reach of IT World Canada. This allows us to do bigger programs and serve our community better.”

The reach of this partnership will extend beyond MapleSEC, Love said. “We hope that this will also boost the reach of our events that aim to bring more people into cybersecurity careers, such as our Women in Cybersecurity event. And it will reach into other events like Technicity, which celebrates the municipal and government sector. That event will be further enhanced by the data from CyberTowns.”

CyberTowns is an annual program, developed by Guay, aimed at identifying the best communities for people with a cybersecurity/IT-related career. Winning communities will be determined by an online survey of CNN members plus those viewing ITWC’s publications. The report will merge that data with key available statistical information from cities across Canada. Initially, Guay said, it will deal with cities of over 100,000.

The two organizations will also soon launch a joint program: a forum tentatively called CyberVoices, where leading cybersecurity professionals will meet and issue regular strategic and operational cybersecurity advice to Canadian businesses, governments and individuals.

For Love, the announcement has a special and bittersweet component. “I only wish that former ITWC leader Fawn Annan, who passed away last year, was here to see this,” said Love.

“For years, Fawn and I had been dismayed at the way we tend to fracture and divide an already small tech community in Canada. In a small country, fracturing the audience just makes it harder to deal with the overwhelming competition from U.S. groups and publications. Fawn was passionate about reversing that. She was instrumental in building a number of partnerships, with the CIO Association of Canada (CIOCAN), for example. CIOCAN also has a CISO membership and the first thing that we did was to reach out to them.”

Guay agreed, saying, “It’s why our motto for CCN is ‘Stronger Together’.”

For more information on either of these organizations, or opportunities for sponsorship, contact Ray Christophersen of ITWC and Francois Guay of CCN

ITWC’s news sites include IT World Canada, ITBusiness.ca, Channel Daily News and the French language Direction Informatique. Its podcasts include Cyber Security Today and Hashtag Trending. It reaches hundreds of thousands of professionals across Canada through its podcasts, publications, and events on cybersecurity and IT. These include the quarterly MapleSEC webinars, Technicity, the annual Top Women in Cybersecurity awards, the CDN Top 100 and the CDN Channel Innovation Awards and the Women in the IT Channel event.

The post IT World Canada strikes partnership with Canadian Cybersecurity Network first appeared on IT World Canada.

Cyber Security Today, Jan. 15, 2024 – Three warnings to application developers

Three warnings to application developers

Welcome to Cyber Security Today. It’s Monday, January 15th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



From time to time I report that malware was found on Microsoft’s GitHub application development platform. Threat actors leave bad code there hoping to trick developers into downloading infected snippets to include in their apps. But a new report from researchers at Recorded Future says the strategy of abusing GitHub’s many services is only increasing. The abuse includes payload delivery, dead drop resolving, full command-and-control and data exfiltration. “GitHub’s popularity among threat actors lies in its ability to allow them to blend in with legitimate network traffic,” says the report. You may have heard of ‘living off the land,’ where threat actors use the tools in legitimate software like Windows to further their attacks. Abuse of GitHub and other platforms is called ‘living-off-trusted-sites.’ GitHub told The Register that it has teams and automated systems dedicated to detect malicious content. Meanwhile application developers have to be careful downloading code from any open source repository. And platforms have to protect themselves from being exploited by threat actors.

A separate report came out at the same time showing how platforms can be manipulated. Security researcher John Stawinksi and colleagues showed how malicious code created on the PyTorch machine learning framework could be uploaded to GitHub, AWS and other places. The report is another warning that threat actors are exploiting holes in continuous application integration and deployment platforms to further supply chain attacks.

And here’s the third warning: Developers using the GitLab Community or Enterprise DevOps software are being urged to upgrade to the latest versions. They have important security fixes to close two critical vulnerabilities. One could give a hacker the ability to take over an account through a password reset.

Modular laptop manufacturer Framework is telling customers that their personal information was stolen in a January 11th data breach at its accounting and consulting provider. This comes from SecurityWeek, which says it’s seen the notification Framework is sending. Customers are being told that an employee of Keating Consulting fell for a phishing message that pretended to be from the consulting firm’s CEO. That message asked the employee to send accounts receivable information of Framework buyers, which included their names, email addresses and balance owned on products.

Singing River Health System, which includes three hospitals in Mississippi, is notifying over 250,000 people of a data theft last August. It was part of a ransomware attack. Data stolen includes people’s names, dates of birth, addresses, Social Security numbers, medical and health insurance information.

American actuarial firm Milliman Inc. has upped the number of people affected by the hack of a MOVEit server used by a third-party data processor. The company now says just over 56,000 people had their data stolen. That’s up from the original estimate of 44,000.

Police in Ukraine have arrested a person they believe is the mastermind behind a sophisticated cryptojacking scheme. The suspect is believed to have mined over US$2 million in cryptocurrencies by compromising servers of an unnamed American cloud provider. According to Bleeping Computer, Ukrainian police say the suspect broke into 1,500 accounts by brute-forcing their passwords. Europol says cloud providers and customers should make sure strong access control and authentication is Used to protect servers and accounts.

A digital currency trading company will pay a US$8 million penalty for violating New York State’s virtual currency and cybersecurity regulations. Genesis Global Trading failed to meet required monitoring and cybersecurity standards, the state’s financial regulator found. As a result not only is it fined, the company is surrendering its BitLicence and is being closed.

Russia’s Sandworm hacking group was suspected of being behind two waves of cyber attacks last May against companies in Denmark. However, researchers at Forescout aren’t so sure. In a new report they say the two groups of attacks were unrelated. They also believe the second wave was a mass exploitation of unpatched Zyxel firewalls and not part of a targeted attack by any nation-state-sponsored group. Regardless of the source, the lesson of the attacks remains: Poorly secured routers, firewalls and servers are a prime target for any threat actor.

Juniper Networks has released updates to its Junos operating system for its SRX firewalls and EX switches. This is to close a critical vulnerability that could allow an attacker to cause a denial of service or run code remotely to get root access to a Juniper device.

Finally, Apple has updated its firmware for Magic Keyboard users. It closes a Bluetooth hole that could be abused by a bad person to mess up a Mac, iPhone, iPad or Apple TV digital media player. If you use a Magic Keyboard make sure its running version 2.0.6.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 15, 2024 – Three warnings to application developers first appeared on IT World Canada.

Hashtag Trending Jan.15-Microsoft’s software update triggers installation hassles; eBay fined for harassment campaign; AI girlfriend apps

Microsoft users hit a rough patch – literally.  The EU is challenging Apple to allow third party app stores on its devices, eBay is fined 3 million dollars for harassing a blogger who posted an unfavourable review and surprise, surprise, AI girlfriend apps are sneaking into the GPT store.



 

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

Microsoft’s recent software update, intended to fix a BitLocker vulnerability, is causing installation headaches for Windows 10 users. 

Released on January 9, the update aimed to prevent attackers from bypassing BitLocker encryption using the Windows Recovery Environment (WinRE). However, it’s been hit by Microsoft’s infamous quality control issues. 

Users are encountering a cryptic error message, which some reports attributed to insufficient disk space in the recovery partition.

Microsoft’s solution involves the end user resizing the recovery partition, daunting for the average user, fairly risky and definitely not for the faint of heart. 

Social media reaction predictably expresses widespread frustration, with users finding the workaround “too technical and scary.” Many are urging Microsoft to correct the issue themselves, rather than expecting users to handle such technical challenges.

The reaction is hard to miss. We’ll see if Microsoft responds.

Sources include: The Register

Contrary to expectations, CES 2024 in Las Vegas has not been dominated by groundbreaking AI gadgets. The event, which attracted over 130,000 attendees and more than 4,000 exhibitors, showcased a variety of technological advancements across personal tech, transportation, health care, and sustainability. However, the anticipated surge in AI-driven innovations didn’t materialize.

There were notable mentions at the event included GyroGear’s hand-stabilizing glove for tremor sufferers, priced at $5,899, and SK Group’s AI Fortune Teller, an emotion-reading machine for fortune telling. Hyundai’s flying taxi concept, a new device called the Rabbit and of course we reported that Volkswagen has gone “all in” and put ChatGPT into its user control systems.

Despite these innovations, the overall presence of AI at CES 2024 was less pronounced than expected. Too early? 

Sources include: Reuters 

Margrethe Vestager, the European Union’s antitrust chief, has told Apple’s CEO, Tim Cook, that the company must allow third-party app stores on its devices. This directive came during a meeting in San Francisco and Palo Alto with leaders of US Big Tech firms, including Apple, Google, Broadcom, and Nvidia. 

While the EU and Apple haven’t released detailed information about the meeting, Vestager’s brief summary on Twitter/X suggests that the conversation revolved around the long-standing issue of Apple’s exclusive control over its App Store. This meeting follows the EU’s previous ruling that Apple Music violates EU antitrust rules. 

The EU’s stance indicates a push for more open competition and consumer choice in the digital marketplace, challenging Apple’s traditional business model. 

This development could significantly impact how Apple operates in the EU, potentially leading to major changes in its App Store policies and practices.

Sources include: AppleInsider 

eBay has been hit with a $3 million fine, the maximum criminal penalty, for a harassment campaign against a Massachusetts couple, David and Ina Steiner. The couple, who published critical reports about eBay in their newsletter, EcommerceBytes, were subjected to an 18-day terror campaign in August 2019. 

This campaign was orchestrated by eBay’s former senior director of safety and security, Jim Baugh, and involved six co-conspirators.

The harassment included sending disturbing deliveries like a bloody pig mask and live insects, publishing Craigslist posts for sexual encounters at the victims’ home, and even installing a GPS tracker on their car. 

The Steiners’ ordeal, described as a “never-ending nightmare,” was part of an attempt to “take down” the couple by then-CEO Devin Wenig and then-chief communications officer Steven Wymer.

The FBI and the Department of Justice (DOJ) were involved in the investigation, which led to the conviction of all seven former eBay employees on felony charges. Baugh, identified as the ringleader, received a 57-month federal prison sentence. eBay has admitted to all facts uncovered in the case and expressed apologies to the Steiners. The company is now required to retain an independent corporate compliance monitor to prevent such conduct in the future.

I followed this when the story first broke, but I have to say I had real trouble believing that a large company would actually engage in this type of behaviour. Sadly, it’s true – and thankfully, the courts have reacted.

And ironically, if irony still exists, is that the verdict comes during Stalking Awareness Month a time that is supposed highlights the severity of stalking as a crime.

Sources include: Ars Technica

Perplexity AI, an AI-powered search engine startup, has raised a significant $73.6 million in a funding round, boosting its valuation to $520 million. 

Founded in August 2022 by a team of engineers with expertise in AI, distributed systems, search engines, and databases, Perplexity AI offers a chatbot-like interface for users to ask questions in natural language. 

The platform responds with AI-generated summaries and source citations, allowing for follow-up questions for deeper exploration. 

Subscribers to Perplexity’s Pro plan can access additional features like model switching, image generation, and document analysis.

Despite the competitive landscape with giants like Google and Microsoft, Perplexity AI aims to differentiate itself with more robust search filtering and discovery options, and by serving its own GenAI models through an API available to Pro customers. 

The company, which claims to have 10 million active monthly users, faces challenges such as the high costs of running GenAI models and concerns around misuse and misinformation. However, the significant investment and rapid growth indicate strong investor confidence in Perplexity AI’s potential to redefine AI-powered search.

I’ve checked it out and it’s kind of interesting. I’ve added it to my list of research tools which also includes Consensus, one of the new GPT’s in the new OpenAI GPT store.

Sources include: TechCrunch 

And speaking of the new GPT store, it was inevitable. Despite the supposed guidelines, the AI girlfriends are appearing.  A search on the word girlfriend pops up the latest round. I’m sure there will be more. 

Sigh.

But there’s a ray of hope. There’s also a GPT called “Dating Advice from your ex-girlfriend” and it’s definitely worth checking out. It’s funny and uh… pretty perceptive. 

For instance, here’s part of the advice that she gave to our audience:

Encourage them to balance their tech use with real-world interactions. While technology connects us, it’s also important to disconnect sometimes and engage in face-to-face interactions. Suggest tech-free date ideas or activities that encourage personal connection.

As a public service, and instead of banning these AI girlfriends, maybe OpenAI should insist that anyone who signs up for an AI girlfriend should first take a course from “Dating Advice from your ex-girlfriend.”  Just a thought.

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

We love your comments. Send me a note at jlove@itwc.ca or leave a comment at the bottom of the show notes posted on itworldcanada.com

I’m your host Jim Love.  Have a marvelous Monday.

The post Hashtag Trending Jan.15-Microsoft’s software update triggers installation hassles; eBay fined for harassment campaign; AI girlfriend apps first appeared on IT World Canada.

Dan Kagan, Country Manager at Okta – my guest on Hashtag Trending, Weekend Edition

SHOWNOTES:  Hi.  And welcome to Hashtag Trending – the weekend edition.  I’m your host Jim Love.
My guest for this week and I probably have met professionally, but I don’t think I really got to know him until we got on a call – arranged by our associate producer who sets this stuff up. I knew his company but I didn’t know who the person was meeting.
No, I try not to do too much “inside baseball” on this podcast, but I’ll let you in on my secret. I have to find a way to, tactfully screen guests. I want you – the audience – to meet people who are interesting, informative and who you want to spend time with.
So these interviews go one of two ways. They can be be an assessment to see if the guest is going to have someone to say or not.
And then there’s my worst nightmare.  Not that the guest isn’t interesting, but that he or she is so fascinating that you can’t stop talking with them.  And you wonder if you can recreate that spark from the original conversation.
Well, I’m going to take that chance, because my guest this week is one of those people who is so engaging, we just started to talk…
And I always say that I do my best job as a host when I meet fascinating people and let them talk.
My guest today is one of those people.
Dan Kagan is the Country Manager at Okta.  Okta is an identity management company. For those who don’t know what that is, I’ll let Dan explain. But in world where identify, privacy and security and foundational to everything we do.
And Dan is passionate about identity.
But he’s also, as you will find out – passionate about people and he’s passionate about  Canada and making Okta Canada a leader.

The post Dan Kagan, Country Manager at Okta – my guest on Hashtag Trending, Weekend Edition first appeared on IT World Canada.