Page 8 of 55

Coffee Briefing Mar. 5 – High speed internet access for 150 NWT households; Canadian small business owners slow in generative AI uptake; Mistral AI open source model now available on IBM’s watsonx; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team! 

Missed the last Coffee Briefing? We’ve got you covered.

Government of Canada invests over $2 million to connect 150 Northwest Territories households

The federal government has announced an investment of over C$1.9 million to connect 152 Indigenous households in Whatì, a community in the Northwest Territories (NWT).

The investment will go to Northwestel, which will be undertaking the project. Owned by Bell, Northwestel is an incumbent local exchange carrier (ILEC) and long-distance carrier in the territories of Yukon, the Northwest Territories, Nunavut, and part of Northern British Columbia.

Another C$480,000 went to SSI Micro, a Yellowknife-based telco that provides cellular access to a repositionable communications shelter, located in hunting and fishing grounds near Fort Providence.

“Connectivity is an essential tool to access education and health care and to grow a business,” said Gudie Hutchings, minister of rural economic development. “It also improves safety and provides peace of mind. Your government is on track to exceed its historic commitment to connect 98 per cent of Canadians to high-speed Internet by 2026.”

The investments are provided through the Universal Broadband Fund, which seeks to ensure that Canadians in rural, remote, and Indigenous communities have access to reliable internet and mobile connectivity.

GoDaddy launches AI tool to help Canadian small business owners increase productivity

Web hosting company GoDaddy announced that it has launched GoDaddy Airo, an AI-powered solution designed to help small business owners save time and attract new customers, in Canada and the U.S..

The tool will, for instance, recommend catchy domain name options, generate logo designs, create a fully built website, a professional email account, product descriptions, email marketing campaigns, a social media calendar and more.

This announcement comes as GoDaddy released a survey of 500 Canadian small business owners revealing that only one in five of them used generative AI for business-related tasks, despite expectations that AI will reduce costs and hours worked.

The average Canadian small business owner, in fact, estimates that generative AI tools could save them $2,600 and around 260 hours per year, while one in four believes the technology can reduce their workload by 500 hours or more annually.

However, half of the surveyed respondents admit they don’t know how to start using generative AI.

“That’s about to change,” asserted Young Lee, head of GoDaddy Canada.

eCampus Ontario launches AI-enabled tool to address skills gaps

eCampus Ontario, a Toronto-based non profit organization that aims to strengthen Ontario’s post secondary education system through online learning, has launched SkillsFinder.ai, a custom GPT, powered by OpenAI to to help learners better understand their skills gaps and find a micro-credential to fill these gaps.

The tool seeks to complement the Ontario Micro-credential Portal, a platform of record launched in 2021 to help learners across Ontario to find short courses to learn the in-demand skills employers need.

Additionally, SkillsFinder.ai adds a smart conversational interface that allows visitor interaction and increases their engagement with the platform.

“The new generative AI tool also helps our member Indigenous institutes, colleges and universities realize efficiencies and save money in reaching learners while helping to increase incremental revenue through new program registrations,” said Robert Luke, chief executive officer of eCampusOntario.

Over the next month, eCampusOntario will be testing the new proof of principle interface as part of experimenting with AI tools to empower learners.

SkillsFinder.ai requires a ChatGPT account to use.

Mistral AI open source model now available on IBM’s watsonx

IBM has announced the availability of Mixtral-8x7B large language model (LLM), developed by Mistral AI, on its watsonx AI and data platform.

“Clients are asking for choice and flexibility to deploy models that best suit their unique use cases and business requirements,” said Kareem Yusuf, Ph.D, senior vice president, product management and growth, IBM Software. “By offering Mixtral-8x7B and other models on watsonx, we’re not only giving them optionality in how they deploy AI — we’re empowering a robust ecosystem of AI builders and business leaders with tools and technologies to drive innovation across diverse industries and domains.”

The Mixtral-8x7B model is widely known for its ability to rapidly process and analyze vast amounts of data to provide context-relevant insights. But IBM says it offers an optimized version of the model, which in internal testing was able to increase throughput (the amount of data that can be processed in a given period of time) by 50 per cent, promising reduced latency. 

This week, IBM also announced the availability of ELYZA-japanese-Llama-2-7b, a Japanese LLM model open-sourced by ELYZA Corporation, on watsonx. More third party models are to come on watsonx in the next months, said IBM.

GSMA and European Space Agency partner to advance new satellite and terrestrial networks technologies

Last week at MWC Barcelona 2024, the European Space Agency (ESA) and GSMA Foundry announced a series of initiatives to help the mobile and satellite industries collaborate on developing new, innovative satellite and terrestrial networks technologies.

“ESA is proud to partner with the GSMA on a variety of impactful initiatives in our commitment to advance connectivity solutions, through the integration of satellite and terrestrial networks,” said  Antonio Franchi, ESA’s head of the 5G/6G Non-Terrestrial Network (NTN) Programme Office. “One of ESA’s aims is to connect everyone, everywhere and at any time, and this powerful collaboration with GSMA is a significant step in advancing the mobile and satellite communications industries.”

The initiatives include:

up to €15 million (around C$22 million) in ESA funding opportunities, to help stimulate innovation and project development.
Expansion of lab network access for Foundry participants who want to collaborate at ESA’s 5G/6G Hub in Harwell, UK and 5G/6G Telecom Lab in Noordwijk, Netherlands.
Launch of a new GSMA advance training course to grow knowledge about, and support collaboration between, terrestrial and non-terrestrial networks.
Launch of the Non-Terrestrial Network (TN-NTN) Community to develop new projects and plot a roadmap for future initiatives and activities.
Ecosystem unification. The GSMA Foundry and ESA will work with and invite the wider industry to unify efforts towards seamless TN and NTN interworking.

More to explore

Is the BlackCat/AlphV ransomware gang self-destructing?

The ongoing saga of the BlackCat/AlphV ransomware gang continues, with a news report that the crew has shut down its servers after a controversial hack of an American healthcare services provider.

Fab wars: Intel, Tata Group, CG Power all launch foundry plans

With competition heating up in the foundry business – India this week approved three new semiconductor plants involving Tata Group and CG Power,, and is looking to achieve dominance in the industry – existing foundries have to up their game.

Canadian police need a search warrant to get your IP address: Supreme Court

How private is your internet address? Very, says the Supreme Court of Canada.

AI usage the highest among Quebec employees: KPMG

In a new report, KPMG has broken down the provincial adoption rate of generative AI across Canada, and found that Quebec led with 26 per cent, ahead of Alberta (23 per cent), British Columbia (22 per cent) and Ontario (20.5 per cent), which nearly tied with Saskatchewan and Manitoba. Atlantic Canada saw the lowest adoption rate.

MWC 2024: A wild Journey to the Future in Hall 6

The future and all that is possible was on full display this week at MWC Barcelona 2024 in Hall Six of Gran Via, the site of an innovation zone that featured hands-on and immersive demos of things ranging from devices that enhance the growing of fruit to what has been described as the “world’s first flying car.”

Love, Collins discuss what it takes to succeed in the channel

A webinar held last week took a deep dive into what it takes to build a successful channel program in Canada.

Channel Bytes March 1, 2024 – Today is the deadline for Top 100 Solution Provider nominations; WLAN market contracting: Dell’Oro; ASCII Group launches AI committee; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Mar. 5- Apple Music fined for market dominance; LockBit back from the dead; OpenAI kills ChatGPT plugins

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, March 4, 2024 – A hacker is trying to trick the U.S. telecom regulator, WhatsApp gets to see Pegasus code and more

 

The post Coffee Briefing Mar. 5 – High speed internet access for 150 NWT households; Canadian small business owners slow in generative AI uptake; Mistral AI open source model now available on IBM’s watsonx; and more first appeared on IT World Canada.

Hamilton confirms ransomware is behind cyber attack

Ransomware is behind the cyber attack on the city of Hamilton, Ont., the municipality’s city manager says.

Marnie Cluckie told reporters Monday afternoon that the attack, which was detected the evening of Sunday, Feb. 25, was the result of ransomware.

She wouldn’t say what strain of the malware the city has been hit with, how long it will take to restore full services, or whether the city has received a demand for money. Some information has to remain confidential, she explained.

Asked if the city is considering a ransom payment, Cluckie replied, “I can assure you we’re going to do what’s best for the city.”

“It’s impossible to know when we will be able to get fully up and running again. I can tell you that we will only restore systems when we are confident we can do so safely and securely,” she said. “As of this moment, we do not believe personal data has been accessed.”

The municipality has cyber insurance, she said, but wouldn’t give details.

The city has already said critical services such as transit, water and wastewater treatment, and emergency services are operational. However some phone systems are offline.

Authorities are still giving out parking tickets. In some cases, systems in facilities such as buses and swimming pools aren’t working, and in those instances residents don’t have to pay.

Automatic payment of property taxes has been disrupted. Cluckie couldn’t say how payments will be handled once the payment capability has been restored.

Nor could she estimate when full services will be restored. A reporter noted it’s taken the city of Toronto’s public library system four months to almost fully return to business.

Every cyber attack is different, Cluckie replied. “We are doing what we can to get things up and running as soon as possible.. can’t give a timeline… want to be careful and diligent so we restore systems safely and securely.”

Hamilton is a city of about 780,00 at the western edge of Lake Ontario.

According to CHCH-TV, city council has been meeting behind closed doors to discuss the attack. Regular council meetings have been temporarily suspended. Mayor Andrea Horwath told reporters that’s partly because municipal staff’s priority is dealing with the cyber attack, so meetings can’t be staffed as needed. It also happens that there’s little on council’s agenda this week and next because of spring break, she added.

“Council and I recognize very clearly how disruptive things have been, and what a challenging time it has been for the people of our city,” Horwath said. City staff have been “working around the clock” to restore services, she added.

“As soon as our staff discovered the breach, the team right away began to respond. They acted immediately. Their most important priorities, as you can imagine, have been to protect the community and protect the service delivery staff, as well as to minimize any impact people might experience.” That included hiring an outside firm with expertise in incident response, and notifying insurers and Hamilton police.

“Once we have gone to a place where we have fully restored our systems,” the mayor added, “our city manager Cluckie and her team have committed to conduct a full review to understand how this breach was able to happen. Based on their findings, they have committed to me and the council that they will ensure the city puts in place appropriate systems and protocols to try to avoid something like this happening again.”

The post Hamilton confirms ransomware is behind cyber attack first appeared on IT World Canada.

Meta and other sites down across North America this morning

Meta and its associated sites were reportedly taken down this morning. Cyberint (Cyberint.com) reported that three threat actor groups – Skynet, Godzilla, and Anonymous Sudan – claimed that they had shut down Facebook, Instagram and Threads.

Although reports surfaced as early as 10 am Eastern Time, Ookla’s Downdector site showed a massive spike in outages reported at approximately 11 a.m. ET.

Source: downdetector.com

The outages were sporadic, with Canadian users in Ottawa and Toronto reporting outages, but other were unaffected.

Source: downdetector.com

While the focus of the attack was clearly the Meta sites, a quick review showed that a vast number of sites reported a spike in service interruption at the same time, although to a far lesser degree than the Meta sites, which were the main sites affected. For example, Facebook Canada showed a reported 125,000 outages and Facebook U.S. a reported 560,000 outages.  But even sites like YouTube showed a spike in outages, although at much lower level.

This is a breaking story. We will update this as further information becomes available.

The post Meta and other sites down across North America this morning first appeared on IT World Canada.

Hashtag Trending Mar.5- Apple Music fined for market dominance; LockBit back from the dead; OpenAI kills ChatGPT plugins

Apple Music gives a whole new meaning to the phrase the hits just keep on coming.  It’s not the opposing candidates, it’s public AI systems that are spreading election disinformation, and LockBit, the cybercriminal gang may be back from the dead and saying so long to the ChatGPT plugins, which went from innovation to legacy in only a few months.



 

All this and more on the “they were so 2023” edition of Hashtag Trending. I’m your host, Jim Love, CIO of IT World Canada and TechNewsDay in the US.

The European Commission has imposed a fine of about a billion dollars US on Apple for what it claims is Apple’s abuse of its dominant market position in the distribution of music streaming apps through its App Store. 

The Commission found that Apple had implemented restrictions on app developers, preventing them from informing iOS users about alternative and more affordable music subscription services available outside the app, known as “anti-steering provisions.” Such actions are deemed illegal under EU antitrust rules.

This latest action from the European commission was initiated by a complaint from Swedish music streaming service Spotify.

Margrethe Vestage, the executive vice president in charge of competition policy, said, “For a decade, Apple abused its dominant position in the market for the distribution of music streaming apps through the App Store. They did so by restricting developers from informing consumers about alternative, cheaper music services available outside of the Apple ecosystem. This is illegal under EU antitrust rules, so today we have fined Apple over €1.8 billion.” 

Apple, being the sole provider of an App Store for iOS users across the European Economic Area (EEA), controls every aspect of the iOS user experience, including the terms and conditions developers must comply with to reach iOS users. 

The Commission’s investigation highlighted that Apple’s anti-steering provisions banned developers from:

Informing iOS users within their apps about subscription offers available on the internet outside of the app.
Informing iOS users within their apps about the price differences between in-app subscriptions sold through Apple’s in-app purchase mechanism and those available elsewhere.
Including links in their apps that lead iOS users to the app developer’s website where alternative subscriptions can be purchased. Additionally, app developers were restricted from contacting their newly acquired users, for instance, by email, to inform them about alternative pricing options after setting up an account.

Apple has taken a series of hits from the European Commission, on its app store and now on its music service. It faces class action lawsuits about its closed system that forces users to pay for iCloud backups, this last action happening in the U.S.. But clearly Apple’s closed system, the thing that has made them a multi-trillion dollar company, is under attack.

Apple has said it will appeal the order and maintains that consumers were not harmed by their actions and that Spotify had also not suffered any harm as they sell their subscriptions from the Spotify website and don’t have to pay Apple anything.

Source include: 

A recent study has revealed that public AI chatbots have been spreading false and misleading information about the 2024 election. 

This came from research conducted by the AI Democracy Projects and Proof News, underscoring the critical need for regulatory oversight as AI increasingly influences political discourse.

The study tested various AI models, including OpenAI’s ChatGPT-4, Meta’s Llama 2, Anthropic’s Claude, Google’s Gemini, and Mistral’s Mixtral, and found them all guilty of giving voters incorrect polling locations, illegal voting methods, and false registration deadlines. 

For example, Llama 2 incorrectly claimed that California voters could vote via text message, an illegal method in the United States. Additionally, none of the AI models tested could accurately identify the prohibition of campaign logo attire at Texas polling stations, such as MAGA hats.

This spread of misinformation has prompted responses from the AI developers. Anthropic plans to release an updated version of its AI tool with accurate election information. OpenAI has expressed intentions to refine its approach. However, Meta dismissed the findings as “meaningless” and that has sparked controversy and raised questions about their commitment to curbing misinformation.

That attitude from Meta could come at a cost as it may place pressure on the government to increase regulations on AI systems – although that may not be considered a bad thing by election officials – or the public.

Sources include: 

The Federal Bureau of Investigation (FBI) and the UK’s National Crime Agency, along with agencies from ten countries, collaborated in Operation Cronos to target the LockBit ransomware gang, one of the world’s most successful ransomware groups. This operation, which began on February 20, led to the takedown of over 30 servers, acquisition of source code, decryption keys, affiliate details, chat logs, and more, effectively disrupting LockBit’s operations.

The agencies involved in the operation added a twist of humour to their takedown by altering the traditional “Game over” message seen by users trying to connect to the seized sites. They included a loading animation featuring the flags of the agency consortium and embedded images with jokey file names. Additionally, they replicated LockBit’s countdown timer, which typically indicated the time left for victims to pay up, to count down to the unmasking of LockBit’s leader, known as LockBitSupp.

LockBit, which emerged in 2019, had become the most successful ransomware gang by adopting a business-oriented model. It provided tools and managed negotiations with victims in exchange for a 20 percent cut from its affiliates, who conducted the actual hacking. The gang’s professional online presence and marketing strategies were notable, even running bug bounty programs to improve its operations and security.

But it may turn out that Lockbit may have the last laugh on this one.

Despite the initial success of Operation Cronos, LockBit and LockBitSupp resurfaced online just five days later, with LockBitSupp mocking the federal agencies’ efforts.

 The FBI and its partners had anticipated this comeback, emphasizing that they had obtained keys to assist thousands of victims. The future rounds of this ongoing battle between law enforcement and the LockBit gang will determine the ultimate victor.

But it may have turned out that LockBit may have had a better recovery plan than most of its victims.

Sources include: 

BBC News has launched a new “content credentials” feature, designed to prove the authenticity of images and videos used in their journalism. 

This feature, part of BBC Verify, allows users to see a button labeled “how we verified this” beneath images and videos on the BBC News site. Clicking on this button reveals the verification processes undertaken by BBC journalists, such as cross-referencing content with other sources, examining metadata, comparing locations, and checking for the correct casting of shadows, among other methods.

This initiative aims to counter the spread of disinformation, AI-generated deepfakes, and other forms of manipulated content. It also seeks to help audiences distinguish between real and fake BBC content when encountered on external sites. 

Deborah Turness, CEO of BBC News, emphasized the importance of earning trust by showing audiences not just what the BBC knows, but how it knows it, highlighting the significance of transparency in today’s environment of deep fakes and misinformation.

The “content credentials” feature incorporates a new technical standard that embeds information about the origins of media, including how it has been edited, functioning like an audit trail. This standard, developed by the Coalition for Content Provenance and Authenticity (C2PA) co-founded by BBC Research & Development, Adobe, and Microsoft, is freely available and has seen participation from major organizations like Google, Facebook, and OpenAI.

Initially, content credentials will be available on select content published by the BBC Verify team on the BBC News site and app. 

Future plans include working with external publishers and social media networks to ensure these credentials are displayed wherever news is consumed, aiding in the quick identification of genuine BBC content.

Sources include:  BBC 

And finally, OpenAI is doing away with its plugins. These functions, added by third party developers, extended the functionality of OpenAI. The first, and in my mind, still the best way of linking ChatGPT to the internet is via a plug-in.

What will replace the plug-ins? Apparently, ChatGPT wants to use its GPT’s – the feature that they introduced recently that allows anyone to write their own mini-GPT model that can also now be called from another chat session.

That has a couple of problems. One, the plug-ins were created and tested to perform their functions and while there are a lot of them, they also had some kind of quality control.

GPTs, on the other hand, might be a great idea, but were launched with no quality control and the number of them – one estimate was more than three million – makes it difficult to even conceive of how to sort through the mess and replace some of the plugins that users have come to count on.

A lesson to all of us – these public AI models are evolving rapidly and they may not feel an obligation to support any legacy functions. And in the world of AI, a “legacy function” could be measured in months, giving little time to react.  


That’s our show for today.

Love your comments. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Terrific Tuesday.

 

The post Hashtag Trending Mar.5- Apple Music fined for market dominance; LockBit back from the dead; OpenAI kills ChatGPT plugins first appeared on IT World Canada.

Is the BlackCat/AlphV ransomware gang self-destructing?

The ongoing saga of the BlackCat/AlphV ransomware gang continues, with a news report that the crew has shut down its servers after a controversial hack of an American healthcare services provider.

Bleeping Computer says the gang’s data leak blog shut on Friday and the sites it uses to negotiate ransom payments closed today.

This comes after

— a gang affiliate last month was allegedly paid US$22 million after its data theft and ransomware attack disrupted the services of Change Healthcare, which provides a range of services to hospitals and clinics including processing pharmacy prescriptions and healthcare payments;

— on the heels of that incident, the BlackCat/AlphV operators reportedly plucked that payment back from the affiliate’s digital wallet before shutting down operations.

Got it?

Bleeping Computer says it’s unclear whether the closure is an exit scam or an attempt to rebrand the gang under a different name. BlackCat, the news service points out, is a rebrand of the DarkSide ransomware operation.

All this comes after American cyber authorities in December seized several of the group’s data leak and communications sites and published a decrypter that victim organizations can use to get access back to scrambled data.

It isn’t unknown why BlackCat/AlphV operators struck at one of its partners. Because of the December hit, the gang said it removed all of its rules forbidding affiliates allowed to use its ransomware to attack critical infrastructure like the healthcare sector.

In fact, the attack on Change Healthcare appeared to be a sign that BlackCat/AlphV had bounced back from the December blow.

Rick Pollack, CEO of the American Hospitals Association, called it “the most serious incident of its kind levelled against an U.S. healthcare organization.” According to Change Healthcare, he noted, the company processes 15 billion healthcare transactions annually and touches one in every three American patient records.

The incident is serious enough that, according to Politico, the White House’s National Security Council started looking into ways to provide short-term financial relief to U.S. hospitals. Arguably, attention from the White House is not what a ransomware gang wants.

The post Is the BlackCat/AlphV ransomware gang self-destructing? first appeared on IT World Canada.

Cyber Security Today, March 4, 2024 – A hacker is trying to trick the U.S. telecom regulator, WhatsApp gets to see Pegasus code and more

A hacker is trying to trick the U.S. telecom regulator, WhatsApp gets to see Pegasus code and more.

Welcome to Cyber Security Today. It’s Monday, March 4th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Threat actors have been impersonating IT support staff to sucker people for years. According to researchers at Lookout, the latest version of this scam is aimed at employees of the U.S. Federal Communications Commission and at the cryptocurrency exchanges Binance and Coinbase. The goal is to trick staff into giving up their login credentials. It works like this: An employee would get a phone call or text supposedly from the company IT support staff saying their email account had been hacked. The employee would then be sent a text to their smartphone with a link that’s supposed to help them regain access to their account. What the employees would see is a fake login page created by a newly-discovered phishing kit that impersonates the single-sign-on services of Gmail, iCloud, Okta, Outlook, Twitter, Yahoo and AOL.

Employees need to be reminded of the dangers of taking for granted phone calls, texts or emails claiming to be from IT support — especially if they get links to supposed company login pages sent to their smartphones. Smartphones don’t always show the full address of a link, which makes it harder for users to spot something suspicious. Staff need to be reminded that just because part of a link includes a company’s name doesn’t mean its legit.

A Washington State radiology clinic is notifying over 235,000 people of a data theft. Yakima Valley Radiology says it learned in August of a theft of data from its systems including names and social security numbers.

Two American insurance companies are warning over 28,000 people of a theft of data from its third-party information processor. Fidelity Life Insurance and Empire Fidelity Investments Life Insurance are sending letters to people about the incident. The data was stolen last fall from Infosys McCamish Systems, which processes services for deferred compensation plans. Last month Infosys McCamish notified over 57,000 people of the data breach, including people with the Bank of America.

An Asian telecom manufacturer that routes millions of SMS text messages a day — including multifactor authentication codes — left a database with that sensitive information open for anyone who knew how to find it. According to TechCrunch, a security researcher found the database and needed the news service’s help to find the company that owned it. Public access to the database belonging to YX International has now been blocked.

WhatsApp and its parent Meta may get a look into the innards of the Pegasus commercial spyware, which has been sold to and abused by some government and law enforcement agencies around the world. WhatsApp is suing Pegasus developer NSO Group, alleging the spyware was used against 1,400 WhatsApp users for two weeks in 2019. A judge has ordered the company to hand over versions of Pegasus that would have been running in and around 2019. Commercial spyware works by exploiting vulnerabilities that application developers don’t know about.

To meet the shortage of IT workers with cybersecurity expertise colleges and universities are increasingly offering courses for students. But what should be in a course? The U.S. Cybersecurity and Infrastructure Security Agency has advice. It’s contained in a new publication called a Resource Guide for Cybersecurity Clinics. It has links to agency resources like its guidance for small businesses, how to create cybersecurity performance goals, how to create incident plans and more. The guide could also be useful to companies that want to create a cybersecurity training course — and IT leaders who don’t know how to create a cybersecurity strategy.

Finally, if you’re looking for a wireless doorbell camera to improve home security, buy one that can’t be hacked. Consumer Reports says many retailers like Walmart and Sears, and online marketplaces like Amazon, Shein and Temu, may be selling camera doorbells that could allow someone to know when you’re not home, or let them harass or threaten you. They can do it by capturing the WiFi video stream. The publication warns about devices with brand names of Eken, Fishbot, Rakeblue and Tuck. Any so-called smart devices that connects to your home internet network with a smartphone app — especially if it has a camera or a microphone — must have protection against being hacked. Do your research before buying.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, March 4, 2024 – A hacker is trying to trick the U.S. telecom regulator, WhatsApp gets to see Pegasus code and more first appeared on IT World Canada.

Hashtag Trending Mar.4- Canadian police need a search warrant to access IP address; Musk sues OpenAI; World Server Throwing Competition too violent?

In Canada, your IP address has the right to remain silent. Elon Musk is suing OpenAI for not being Open. Apple faces a class action not allowing competitive access to backup services and the World Server Throwing Competition in March 2024 is accused of being too violent towards servers.  



 

All this and more on the “no servers were harmed in the making of this podcast ” edition of Hashtag Trending. I’m your host, Jim Love, CIO of IT World Canada and TechNewsDay in the US.

The Supreme Court of Canada has ruled that Canadian police must obtain a search warrant to access an individual’s IP address. This decision, passed with a 5-4 majority, underscores that an IP address, which serves as a critical link between an internet user and their online activity, carries a reasonable expectation of privacy under section 8 of the Charter, which protects against unreasonable search and seizure.

The ruling came from a 2017 case where Calgary police, investigating fraudulent online purchases, demanded a credit card processor to hand over IP addresses associated with certain transactions. This led to the arrest and conviction of an individual for 14 offenses after further obtaining subscriber information and search warrants. However, the Supreme Court has now clarified that obtaining IP addresses without judicial authorization constitutes an unlawful search.

This decision builds on a 2014 Supreme Court ruling that internet providers cannot turn over subscriber information to police without a search warrant. The court’s majority emphasized that the private nature of the information potentially revealed by an IP address warrants protection over governmental law enforcement interests. They highlighted how the internet has transformed privacy dynamics, concentrating vast amounts of personal data with third parties and enhancing the state’s informational capacity.

The ruling has sparked concerns among law enforcement, particularly in internet child exploitation units, about the potential for slowing down investigations. RCMP Sgt. Kerry Shima expressed worries that the decision could hinder the ability to act swiftly in cases, potentially putting children at risk and offering offenders greater opportunities to evade detection.

Our U.S. listeners may need a special note that in Canada, there is no distinction made in the press about which government regime appointed which judge so all we really know is that it was a 5-4 decision. 

Sources include: ITWorld Canada

Elon Musk has filed a lawsuit against OpenAI, a company he co-founded, and its CEO Sam Altman. Musk accuses OpenAI of shifting its focus towards profit rather than humanity’s benefit.  

Musk’s contention centers around OpenAI’s partnership with Microsoft, which he claims contradicts the organization’s original mission by making it a “closed-source de facto subsidiary” of Microsoft. 

Microsoft, under CEO Satya Nadella, has significantly invested in OpenAI and exclusively licenses the technology behind GPT-4, OpenAI’s advanced AI model. 

The lawsuit is posted on a number of sites, we’ll put a link in the notes. But while it’s provocative, it’s more than a little confusing. Musk notes in his lawsuit that Microsoft’s investment does not entitle it to any “ownership” in Automated General Intelligence. Interestingly, the suit also reveals that the board of OpenAI has the sole right to declare when AGI has been achieved. 

Musk presumably is complaining because he thinks that OpenAI has already achieved AGI in some form and is not sharing it with the world. 

But if OpenAI was an open source company, everyone would have access including Microsoft.

The lawsuit has sparked reactions among Silicon Valley’s elite, with venture capitalist and OpenAI investor Vinod Khosla and others exchanging criticisms on social media platforms. 

But this isn’t the only feud that Musk has going. He’s supposedly planning to create a Gmail competitor in response to Google’s AI biases and a challenge to humanoid robot startup Figure, backed by Jeff Bezos and others, as Musk develops his own robot at Tesla.

To anyone who has followed the extensive political lawsuits in the U.S. recently, Musk’s legal battle could expose a wealth of information about Musk, OpenAI, and a lot more companies and people, potentially affecting reputations and the operations of AI companies.

And as tantalizing as it might be to get some dirt on Musk, Google’s Larry Page, Sam Altman, Satya Nadella, Mark Zuckerberg and others, it really underscores the fact that a handful of billionaires and their whims and feuds control what might be the greatest scientific breakthrough since the invention of the digital computer or if you even partially believe the idea that AI could possibly, in the wrong hands, lead to the extinction of humanity, you have to ask yourself if these guys are the “right hands” to hold the future of humanity.

Sources include: Axios and The Verge has the text of the suit

Apple is facing a newly proposed class action lawsuit that accuses the company of unfairly monopolizing the cloud storage market for its devices by restricting device backups and other storage needs exclusively to its iCloud service. The lawsuit, reported first by Bloomberg Law, alleges that Apple has “marked up its iCloud prices to the point where the service is generating almost pure profit,” by rigging the competitive playing field.

The core of the complaint (pun not intended) is that Apple provides only 5GB of free iCloud storage, a limit that has remained unchanged since its introduction by Steve Jobs announced it in 2011. The plaintiffs argue that this amount of storage is insufficient for most users’ needs, compelling them to purchase additional iCloud storage plans.

The lawsuit focuses on the fact that iPhone users have no alternative but to use iCloud for full device backups. While users can choose other cloud-based storage providers, the lawsuit claims that Apple’s restrictions prevent rival platforms from offering a comprehensive cloud solution that can effectively compete with iCloud.

By making iCloud the only option for backing up Restricted Files and limiting the free storage to 5GB, Apple effectively forces device owners to use iCloud and pay for additional storage, the lawsuit alleges. It argues that there is no technological or security justification for this requirement, suggesting that Apple imposes it solely to limit competition and favour its iCloud service.

The lead plaintiff in the case is represented by Hagens Berman law firm, known for handling various class action lawsuits against Apple, including the notable $560 million Apple Books price-fixing lawsuit.

Individuals who have purchased iCloud storage and are interested in potentially joining the lawsuit are encouraged to do so via a form on the Hagens Berman website. 

Sources include: 9to5 Mac

The 2024 World Server Throwing Championship is set to take place at the annual CloudFest conference on March 19th. 

This unique competition, which began in Holland about a decade ago, has been described as an “intense underground sport” criticized for being “needlessly brutal to servers.” 

Emerging from its data-center basement origins, the WSTC as it is called is now stepping onto the world stage, inviting athletes to showcase their strength and skill in server throwing.

The event will be held outdoors in front of a live audience, welcoming up to 40 server-throwing athletes from all genders and ability levels. Participants will be given two attempts to throw a server as far as possible, with the top three performers winning prizes. While the sport’s nature is inherently brutal, safety measures such as wearing gloves are recommended due to some servers having very sharp edges.

The Dutch have established a strong presence in the sport, with the winner of a national championship event in 2022 managing to throw a server weighing over 10kg (22 pounds) a distance of 12.23 meters (over 40 feet).

CloudFest 2024 will be held in Rust, Germany. (I do not make this stuff up)

The event is described as essential for anyone working in the cloud industry, featuring keynotes, panel discussions, masterclasses, networking events, and more. Only paying attendees will have the opportunity to participate in the server-throwing competition, with tickets starting at 499 euros.

A shout out to Tom’s Hardware that did the groundbreaking journalism on this story.

Sources include: Tom’s Hardware

And that’s our show for today. 

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition. 

xxx

Love your comments. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Magnificent Monday.

 

The post Hashtag Trending Mar.4- Canadian police need a search warrant to access IP address; Musk sues OpenAI; World Server Throwing Competition too violent? first appeared on IT World Canada.

Canadian police need a search warrant to get your IP address: Supreme Court

How private is your internet address? Very, says the Supreme Court of Canada.

Police can’t just walk into a company and demand a suspect’s IP address by saying a Canadian resident doesn’t have an expectation of privacy of that information, the court ruled today. An IP address is vital enough that every resident expects it to be private, and it can’t be handed to police without a court order, the nation’s top court concluded.

“If s. 8 of the Charter [which says everyone has the right to be secure against unreasonable search and seizure] is to meaningfully protect the online privacy of Canadians in today’s overwhelmingly digital world, it must protect their IP addresses,” the court ruled in a 5-4 decision. “An IP address is the crucial link between an internet user and their online activity. Viewed normatively, it is the key to unlocking a user’s internet activity and, ultimately, their identity. Thus, an IP address attracts a reasonable expectation of privacy.”

Here’s the background: In 2017, Calgary police investigating fraudulent online purchases at a liquor store demanded a credit card processor hand over IP addresses for certain transactions. With the two IP addresses, police then got a production order from a judge compelling Telus to disclose the name and address of its customers at each IP address. Using this subscriber information, police got search warrants which led to a person being arrested and ultimately convicted of 14 offences.

The accused was convicted at trial, a decision upheld by the Alberta Court of Appeal. Both courts rejected his argument that his rights had been violated.

The case went to the Supreme Court to answer a question: Was obtaining the IP addresses a lawful search? No, said the majority.

Requiring that police obtain prior judicial authorization before obtaining an IP address “is not an onerous investigative step,” the court ruled. “Where the IP address, or the subscriber information, is sufficiently linked to the commission of a crime, judicial authorization is readily available.”

The court ordered the accused to face a new trial.

This isn’t the first time the Supreme Court has dealt with companies handing over internet-related data. In a 2014 decision, it unanimously ruled that Canadian internet providers can’t turn over basic subscriber information to police without a search warrant.

The minority in this case argued an IP address alone doesn’t have private information. “Without more, all an IP address reveals to the police is a user’s ISP [internet service provider] — hardly a particularly private matter, let alone core biographical information,” the minority judges wrote. The accused had little control over his IP addresses, which an ISP can change at will and without notice, the judges said. And, they noted, the search wasn’t carried out at the accused’s home, but at the credit card company.

That wasn’t persuasive to the majority. “In the informational privacy context, the claimant’s control over the subject matter [the IP address] is not determinative,” they wrote. “The internet requires that users reveal subscriber information to their ISP to participate in this new public square, and Canadians are not required to become digital recluses in order to maintain some semblance of privacy in their lives.”

“Defining a reasonable expectation of privacy is an exercise in balance,” said the majority. “In this case, the balance weighs in favour of extending a reasonable expectation of privacy to IP addresses.

“The intensely private nature of the information an IP address may betray strongly suggests that the public’s interest in being left alone should prevail over the government’s interest in advancing its law enforcement goals. The internet has exponentially increased both the quality and quantity of information stored about internet users, spanning the most public and the most private human behaviour. The internet has not only allowed private corporations to track their users, but also to build profiles of their users filled with information the users never knew they were revealing.

“By concentrating this mass of information with private third parties and granting them the tools to aggregate and dissect that data, the internet has essentially altered the topography of privacy under the Charter. It has added a third party to the constitutional ecosystem, making the horizontal relationship between the individual and the state tripartite. Though third parties are not themselves subject to s. 8, they mediate a relationship which is directly governed by the Charter — that between defendant and police. This shift has enhanced the state’s informational capacity.”

RCMP Sgt. Kerry Shima, acting officer in charge of Alert ICE, the internet child exploitation unit for Alberta, told CBC News that the ruling will slow down the unit’s investigations.

“This definitely throws a wrench into the machine. It’s going to put a lot of children at risk,” he said.

Shima said the ruling means police will not be able to act swiftly to tackle most of their cases in an “efficient manner.”

“It gives a wide berth for offenders on the internet and it gives an opportunity for people to hide even better and avoid detection,” Shima said.

The post Canadian police need a search warrant to get your IP address: Supreme Court first appeared on IT World Canada.

Fab wars: Intel, Tata Group, CG Power all launch foundry plans

With competition heating up in the foundry business – India this week approved three new semiconductor plants involving Tata Group and CG Power,, and is looking to achieve dominance in the industry – existing foundries have to up their game. Chief among them is Intel, which has been trying to recover from historical missteps that put it behind competitors such as TSMC and Samsung.

At its Intel Foundry Direct Connect event last week, it unveiled Intel Foundry, which will build not only its own chips, but products for anyone looking for fab services. It also announced a new organizational model.

“We’re not fixing one company, we’re establishing two vibrant new organizations,” said Intel chief executive officer Pat Gelsinger during his keynote. “Intel Foundry, to serve internal and external customers at scale, to manage supply chains, to assure capacity corridors, and Intel Products, our client, data centre and networking products. Two distinct and separate organizations.

“That begins today.”

AI, he said, will be incorporated everywhere, from data centre to cloud to network to edge to client, and it’s generating new excitement.

He noted, “When I showed up, it was like ‘This is boring. Here, let’s add a few more cores on the chip. Let’s make PCIe a little bit faster. Let’s increment the DDR. Boring.’ And then AI happened. End of boring. This is transforming everything about computing.”

And Intel plans to take advantage of this explosion of technology.

“Through our foundry, I want to manufacture every AI chip in the industry,” Gelsinger said. “Those internal that are being done by the cloud service providers, those merchant providers, the technology providers. We’re engaging in 100 per cent of the AI TAM [total addressable market]. And with that, we need a new model of what the foundry requirements are for that industry. And that’s, simply put, what we call the systems foundry for the AI era.”

Intel CEO Pat Gelsinger: “This is what we call a family photo mode. So, kids, come to papa, here we go – five nodes in four years.” Credit: Intel Corporation

He said that the company’s goal is to become the world’s number two foundry by 2030, and it will be the “world’s most sustainable foundry, committing to net-zero Scope 1 and Scope 2 GHG emissions by 2040, and net-zero upstream Scope 3 emissions by 2050.” It will also, he asserted, be the most resilient.

In 1990, 80 per cent of the semiconductors were built in US and Europe, Gelsinger noted. Today, 80 per cent are manufactured in a small concentrated area in Asia.

“We’ve seen this long, steady decline in terms of our supply chains for the world,” he said. “Nothing should be reliant on a single port to a single country, a single place in the world. We need resilience – resilient access to supply chains and capacity in the right regions at the right time. And thus the opportunity to drive systemic change, and where and how we drive the most important aspect of our future where the technology supply chains are. And as I’ve liked to say, the moonshot is 80/20 to 50/50 in a decade, rebalancing the supply chains of the world.”

Roadmap

Gelsinger also highlighted the company’s progress on its foundry process roadmap, announcing 14A, which he said is “venturing deeply into the Angstrom era,” as well as revealing extensions to existing nodes. And, he and Microsoft CEO Satya Nadella jointly announced that Microsoft has chosen Intel Foundry to build its own chip, based on the Intel 18A process.

Stuart Pann, senior vice president and general manager of Intel Foundry services, then took the stage to elaborate on the foundry’s activities.

“In this systems era, you can not only have to have open standards between devices, you have to have standards on the device.,” he pointed out, describing Intel as “a systems company turning into a foundry, not the other way around.”

But, he stressed, Intel can’t do it alone. Partners are key, and Intel has more than 30 ecosystem partners, including, he announced, Arm.

“This morning, we’re announcing a new partnership with Arm, an emerging business initiative. How do we take advantage of all the programs that Arm has to offer to bring design capability, design education out to all their customers. We’re doing this with Arm; we will make co-investments, will do joint programs, will provide shuttles at scale, Arm will provide IP at scale. And this is how we’re going to fuel this next wave of innovation.”

While Canada may not be in line for a fab (a semiconductor fabrication plant), at least not at the moment, Denis Gaudreault, Intel Canada country manager, said in an interview that this country is contributing in other ways.

Intel is now working with Markham-based ventureLAB, whose Hardware Catalyst Initiative supports the development of semiconductors, and has an R&D lab of its own on site. In fact, almost 90 per cent of Intel Canada’s employees in all locations work in engineering or development. And, he said, he’s continually looking for more ways that Canada can contribute.

The post Fab wars: Intel, Tata Group, CG Power all launch foundry plans first appeared on IT World Canada.

Healthcare sector “stretched thin” in fight against cyber attacks warns CSO of Health-ISAC

Healthcare organizations need more support from boards and governments to defend against the rising number of cyber attacks, particularly ransomware, says the chief security officer of a U.S.-based information sharing and analysis centre for the sector.

“Organizations are stretched thin, they just don’t have the people, budget to support the basic types of [cybersecurity] programs,” Errol Weiss, CSO of the Health-ISAC said in a recent interview.

“We need more resources for cybersecurity, everything including budget and appropriately trained and experienced staff to set up cybersecurity systems and to make sure they are being monitored and anomalies are being addressed quickly and mitigating controls are being put in place rapidily to close those holes.”

Two recent reports show what the sector is facing. Health-ISAC’s Q4 report for last year highlighted that ransomware attacks against the healthcare sector rose steadily throughout 2023.

Globally, 459 of 5,559 ransomware attacks hit the healthcare sector last year. The vast majority of them (379) were in the Americas (315 in the U.S. and 17 in Canada).

While initial compromises were often through poorly secured implementations of Windows RDP (remote desktop protocol) and compromised credentials, towards the end of the year many networks were penetrated by exploiting a vulnerability in devices running Cisco Systems’ IOS XE operating system (CVE-2023-20198).

The latest examples of the crisis: In the past seven days, the BlackCat/AlphV ransomware gang took credit for an attack on Change Healthcare, which processes pharmaceutical scripts for many hospitals, and the Rhysida gang said it was behind the attack on Chicago’s Lurie Children’s Hospital.

Health-ISAC also participated with the American Hospital Association in a just-released report for CISOs on the current and emerging healthcare cyber threats.

The number of healthcare-related data thefts globally averaged more than 86,000 records a day for the past 13 years, it found. “What’s even more troubling,” the report adds, “is that the number of incidents reported is increasing at an alarming rate.”

Although headquartered in Orlando, Fla., the Health-ISAC has 835 members in 100 countries, including 10 in Canada. Members include hospitals, clinics, insurance companies, pharmaceutical companies, medical device manufacturers, and electronic health software providers.

Health-ISAC charges membership fees based on revenue. For example, organizations that have under US$100 million revenue pay US$2,400 a year for access to threat intelligence.

Last year, it provided 39 targeted alerts to specific Health-ISAC member organizations to help teams mitigate potentially exploited vulnerabilities. It also delivered eight targeted alerts to member organizations where threat actors had already installed an implant using the Cisco IOS XE vulnerability.

Hospitals and clinics hold sensitive data of patients, which may put pressure on them to cave to ransom demands. And for-profit hospitals might seem to be logical targets in particular, because they would be seen as able to pay to get access back to encrypted and stolen data.

However, Weiss believes most ransomware attacks are opportunistic: Attackers exploit any opening at any organization they find. “I call it a shotgun method: They’re not aiming at anyone, they’re just casting a wide net.”

“They don’t even realize, when they obtain access to a victim’s network, what they have a foothold in,” he said.

However, once inside and when they realize what the victim organization is, gangs don’t hold back on their pressure tactics. “We have seen threats to release information including psychiatric care notes, even images of cancer patients, before and after pictures of surgeries — really horrific stuff,” Weiss said.

Asked why cybersecurity isn’t more of a priority in the sector, Weiss said that in the past several years, the rapid rise of ransomware is causing organizations to act. “We’re starting to see more discussion around what represents good minimum cyber hygiene, for example, when it comes to securing environments.”

Historically in the U.S., he said, healthcare institutions were focused on being compliant with privacy regulations. That has left “a large gaping security hole that an adversary could take advantage of.”

One recent aid: In January, the U.S. Department of Health and Human Services published Cybersecurity Performance Goals for the public health sector to follow.

The biggest mistakes organizations make are: not backing up data regularly, not patching vulnerabilities fast enough, and not implementing multifactor authentication to protect logins, Weiss said.

Asked why healthcare organizations aren’t doing those basics, he said it comes back to a lack of financial and human resources.

To move in the right direction, organizations sometimes have to decide between buying medical or IT equipment, he said. But they also have to realize that cybersecurity risks are “huge.”

“There’s going to have to be some hard decisions made when it comes to budgets,” he said. Government tax breaks for purchases and training IT staff will help, he added.

If things continue as they are, “we’ll continue to read about organizations becoming victims of the next cybercriminal organization,” he said. “The malware we’re getting is getting more sophisticated. Bad guys are constantly evolving their tactics to beat the system, and if organizations aren’t addressing that, there will be an impact.”

The post Healthcare sector “stretched thin” in fight against cyber attacks warns CSO of Health-ISAC first appeared on IT World Canada.