Page 9 of 55

Cyber Security Today, March 1, 2024 – Warnings to GitHub users and Ivanti gateway administrators, and more

Warnings to GitHub users and Ivanti gateway administrators, and more.

Welcome to Cyber Security Today. It’s Friday, March 1st, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Developers who download code from the open-source GitHub repository always have to be careful they don’t get tricked by malicious packages. This is vital more than ever because since November a threat actor launched an automated campaign of uploading bad code into the repository. They hope this code will find its way into commercial or open-source applications, compromising millions of computers. According to researchers at Apiiro over 100,000 infected packages have recently been poured into GitHub. The threat actor behind this campaign clones existing packages, infects them and then re-loads them into GitHub. Then these bad packages are promoted to unsuspecting developers in forums. They collect login credentials of developers and anyone who uses an application the developer puts the bad code in. An estimated 99 per cent of bad packages have been removed by GitHub. But that still leaves thousands on the platform. And the campaign continues.

I’ve reported previously about the need for administrators of Ivanti Connect Secure and Policy Secure gateways to reset and patch those devices. Well, that isn’t enough. Cybersecurity agencies of the Five Eyes intelligence-sharing countries warned Thursday that threat actors can get around mitigations. In particular they can deceive Ivanti’s integrity Checker Tool to continue compromising these devices through three vulnerabilities. Administrators should consider dropping these devices, the agency say.

After years of company reminders and media reports about following safe cybersecurity practices some people still don’t get it. That’s a takeaway from a phishing report this week by Proofpoint. The company’s annual State-of-the-Phish report includes a survey of over 7,000 working adults in 15 countries. About a quarter admit they do risky things like use a work device for personal activities, reuse or share passwords and connect without using a VPN in a public place like a mall or airport. Some of these activities could be legitimate — there’s nothing wrong with sharing a password with a family member so they can access your personal email in an emergency. Or using an office computer to go to a website if its OK with management, like sites about your hobbies or to research a vacation. But the numbers suggest that some people do risky things because the security message isn’t getting through. A quarter of the respondents said they took risky action to meet an urgent deadline. Others did it to save time or money. Eleven per cent said they did it to meet a revenue target; 10 per cent did it to meet a performance objective. Here’s another factoid from the report: While 99 per cent of security pros surveyed said their organization has a security awareness program, only slightly more than half say they train everyone in the organization.

Speaking of phishing, Pepco Group, a European discount retailer, has acknowledged its division in Hungary recently lost the equivalent of US$16 million. How? Staff fell for a phishing lure.

Finally, a Malwarebytes researcher stumbled across a crook running an apartment reservation scam while trying to book a vacation in Amsterdam on Airbnb. The person who posted the apartment asked him to switch to communicating by email because Airbnb’s platform was allegedly having some problems. If interested, the owner said, they would send the traveler a link to Tripadvisor to complete the reservation. Well, the link went to a fake Tripadvisor website. The goal of this scam: To get an unsuspecting victim to click on a booking button on the fake Tripadvisor site and enter credit or debit card details. Two lessons: If someone asks you to switch communicating from one site to a different one or email when making any kind of purchase, be suspicious. And when you buy anything, do it on a full-screen computer or laptop, not a smartphone, so you can see the full email address of who you’re dealing with or the full website address of where you’re going.

That’s it for now. But later today the Week in Review podcast will be out. Guest Terry Cutler of Cyology Labs will join me to discuss how hard it is for law enforcement to put ransomware gangs out of business and Canada’s proposed law to make social media platforms take down child porn images fast.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening. I’m Howard Solomon

The post Cyber Security Today, March 1, 2024 – Warnings to GitHub users and Ivanti gateway administrators, and more first appeared on IT World Canada.

Hashtag Trending Mar.1- HP debacle; Humanoid robots closer to hitting our workplaces; Apple blew $10 billion on the electric car before pulling the plug

If rumours are true and this one should be, I started it, we have a special edition of the Weekend show where we talk about the evolution of the role of the CIO with two incredible CIOs as the CIO Association of Canada turns 20. Don’t miss it. 

MUSIC UP

Can HP make you love them again? Humanoid robots with AI might be closer than we think. Researchers find that talking like a character from Star Trek can improve your AI results. And how many iPhones would it take to make up the money Apple blew before it killed its self-driving electric car?



 

All this and more on the “you can’t make this stuff up” edition of Hashtag Trending. I’m your host, Jim Love, CIO of IT World Canada and TechNewsDay in the US.

HP is trying to make you love them again. 

We love the price of these printers, but who among you has not gone to buy ink for that new purchase then asked yourself if it wouldn’t just be cheaper to buy a new printer again?

We always knew that the ink jet printers were a lot like shaving razors. They’ll give you the printer to get you hooked, and then you have to buy the ink.

Which generated a whole industry of refilling cartridges and then third party or no-name ink. 

So printer manufacturers, HP being the most well-known, started making their printers so they wouldn’t allow cheaper third party ink. They said it was for our own good – because these knock off cartridges could harm our printer. 

That didn’t go over well. People felt they bought the printer, and then they had the right to do whatever they wanted.

So HP tried – ink on subscription. But people who didn’t use up their limit on printers were complaining that they shouldn’t have to pay for more ink than they used.

So HP is trying another tactic. 

Their All-In-One plan lets you rent the printer, starting at a low price of $6.99 US per month.

You get the printer. You get the ink. You get a guarantee that subscribers to the HP All-In Plan will receive a new printer and all the ink they need, along with access to HP’s “24/7 Pro Live support.” If a subscriber encounters a problem that HP cannot fix remotely, the company promises to replace the faulty printer the next business day for free.

They eliminate the “never-ending struggle” of printer ownership by providing a hassle-free printing solution.

Will this make you love HP again? Will this stop the criticism and class action suits?

It might – until you read the fine print. Yes, it’s $6.99 per month but you can only print 20 pages each month. After that, you pay more, depending on the number of pages. You can pay between $8.99 up to $60.99

I predict that the next Reddit post will be about someone who bought this All In One package and got a much bigger bill than they thought. 

Sources include:  [PCMag](https://www.pcmag.com/news/hp-targets-the-haters-with-printer-rental-subscription-plan).

How long do you think it’s going to be before humanoid robots hit the workforce.

And will they be able to fix the printer?

Hint: There’s some of them working now in companies ranging from BMW to even Canadian Tire.

And don’t be surprised if they can do some incredibly intricate things.

A new humanoid robot startup Figure has attracted significant attention and investment, with a “who’s who” of Silicon Valley ponying up enough to give the company a valuation of $2.6 billion. 

Figure is at the forefront of integrating bipedal robots with dexterous hands into the labour force, and there’s a lot of other companies trying to get in on the action.

So guess who is working with this robot manufacturer Figure? You don’t need an AI to figure out that OpenAI’s is working to bring capabilities in processing and reasoning from language to humanoid robots

But do not worry. We have assurances from robotics companies that these robots are not here to take our jobs. They will at first undertake tasks that are too dangerous or repetitive for humans. And they emphasize “upskilling” as a strategy to retrain displaced workers for more fulfilling roles within the same field.

Then they’ll replace us. 

But that’s a long way off. Right? Nope. Silicon Valley’s Brett Adcock, the “flying taxi” pioneer, thinks we’ll see robots move into the workforce in about 2 years. 

And I put some links to videos in the show notes. It’ll make you wonder.

As the late Jimmy Buffet said, “my occupational hazard is being…my occupation’s just not around.” 

Sources include: Axios

Robot  moving a crate to a conveyor belt

Robot making coffee

Tesla’s Robot Optimus taking a stroll 

Sanctuary’s Phoenix taking your blood pressure.

Forget all those prompt management course on YouTube. 

A new study has revealed that AI chatbots perform better at solving grade-school-level math problems when prompted to respond as if they are a Star Trek character. 

Two researchers from VMware in California conducted a study, which was initially reported by New Scientist and published on arXiv on February 9, 2024. 

Their investigation aimed to explore the impact of “positive thinking” prompts on AI performance, a concept that has gained attention among those working to optimize chatbot outputs. 

I’ve read stuff like this before where emotional prompts appear to work better. One study said that if you put emotion into your prompt, it would work. I started saying that I would be fired if the answers were wrong. 

I don’t know if it worked, but it’s like chicken soup. “Can’t hoit.”  

It just points out how little we really know about how these incredible algorithms can display behaviours that we don’t understand.

These researchers thought “positive thinking” should not influence a computer system’s performance, but they may have found evidence suggesting otherwise.

The study involved feeding three Large Language Models (LLM) — Mistral-7B5, Llama2-13B6, and Llama2-70B7 — with 60 human-written prompts designed to encourage the AIs. These prompts varied from motivational statements like “This will be fun!” to affirmations of the AI’s capabilities. The models were then tasked with solving the GSM8K, a dataset of grade-school-level math problems, to determine the effectiveness of each prompt.

So what were the best-performing prompts for the Llama2-70B model?  

Talk like Star Trek. 

Their prompt specifically requested the AI to navigate through turbulence and locate the source of an anomaly, using phrases reminiscent of a Starfleet commander’s log. This Star Trek-themed prompt significantly improved the model’s math-solving abilities, a result that both surprised and puzzled the researchers.

The study underscores the unpredictable nature of AI systems and the intricate factors that can influence their performance. While the exact reasons behind the Star Trek prompt’s effectiveness remain unclear, it suggests that the way questions are framed can dramatically impact AI output quality. 

Catherine Flick, a researcher at Staffordshire University, UK, commented on the findings, emphasizing that AI models do not truly understand the context of the prompts but rather access different sets of weights and probabilities based on the input.

This research shows how little we know about AI behaviour. So add that to your list of ways to optimize AI performance through carefully crafted inputs. 

Is this guy really telling me my prompts will be better if I talk like a Star Trek character. I know what you are thinking. 

Captain, I can’t believe my ears.  

I canno believe your ears either, Mr. Spock.

Sources include: Business Insider

And speaking of costing more than you thought possible….

We covered the story about the demise of Apple’s self driving electric vehicle called “Project Titan.”  

Apparently, Apple blew a cool $10 billion on that project before they pulled the plug. (I will never tire of that pun – tire – get it?) 

And it turns out that this might have been Dodgy from the beginning (Dodgy?) 

Some employees called the project “the Titanic disaster,” reflecting doubts about its feasibility. Okay, I can’t outdo that one. Titan – Titanic. They were asking for that.

It seems the only smart move Apple made was not buying Tesla.  They were in discussions with Elon Musk but Apple ultimately decided it would be too hard to integrate Tesla into its “ecosystem.”

Yeah. But they put the brakes on that deal (gotta love it) and missed the bonus of having Elon associated in some way with the Apple brand. 

But you know something? Apple still has hundreds of millions in cash and plans to leverage the knowledge and innovations gained from working on the car, including AI-powered AirPods with cameras, robot assistants, and augmented reality technologies.

So all of that IP will have a new lease on life. 

Couldn’t resist.

Sources include: Mac Rumors

And that’s our show for today. And what a strange day it was. 

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition. 

Love your comments. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Fantastic Friday.

 

The post Hashtag Trending Mar.1- HP debacle; Humanoid robots closer to hitting our workplaces; Apple blew $10 billion on the electric car before pulling the plug first appeared on IT World Canada.

MWC Barcelona 2024 news roundup: Telecom, AI, security and more

MWC Barcelona 2024 comes to a close today. Here’s a look at some of the announcements that the event brought to light, from industry leaders like Cisco, Google, Intel and others, spanning artificial intelligence, telecom, security and sustainability.

Telecom

Cisco has partnered with Telus to launch new 5G capabilities for IoT use cases across industry verticals, notably connected cars. Car original equipment manufacturers (OEMs) will be able to offer new on-board applications and advanced driver assistance system (ADAS) services while pursuing other revenue diversification goals, said Cisco.

Further, U.S.-based data infrastructure semiconductor solutions provider Marvell Technology, announced that it is collaborating with Dell, Fujitsu and Wind River to deliver Open RAN solutions for Japanese mobile phone operator NTT Docomo and other carriers.

ORAN is a nonproprietary version of the Radio Access Network (RAN) system that allows interoperation between various pieces of cellular network equipment provided by different vendors, including the radio unit (RU), the distributed unit (DU) and the centralized unit (CU).

A big focus for numerous other companies at MWC, ORAN expected to account for 20-30 per cent of worldwide RAN revenues by 2028, according to the Dell’Oro Group.

Singapore-based SynaXG, for instance, announced a strategic collaboration with Wind River and Ampere. The partnership integrates SynaXG’s virtualized distributed unit (vDU) card with StarlingX, a cloud-native, Kubernetes, open-source infrastructure project supported by Wind River and Ampere’s multicore processors to redefine 5G network infrastructure.

The collaboration sets new industry standards for power efficiency, ease of integration, and cloud-based network management for Open RAN, said SynaXG.

Germany-based ng-voice launched Hyperscale IMS, a cloud-native instant messaging system solution to empower telecom operators to reduce voice production costs, optimize network management and service delivery with AI and deploy new voice services for additional income streams.

AI

Telematics company Geotab, attending MWC as part of Ontario’s delegation, introduced Geotab Ace, a generative AI assistant for connected transportation.

The tool has access to an expansive array of insights, the company said, including predictive safety analytics, predictive maintenance, trip data, zone activity, electric vehicle statistics, exception events, GPS tracking, and more. It’s built on privacy-by-design principles, and never shares customer telematics data with any Large Language Model (LLM), said Geotab.

Further, Arizona-based telecom equipment supplier Viavi announced additional capabilities of a joint Testbed as a Service (TBaaS) with VMware (recently acquired by Broadcom) to advance digital twin environments.

The digital twin modeling, based on AI and enabling new predictive capabilities, will be leveraged for the evaluation and performance benchmarking of applications.

In other AI news, users now have access to Google’s generative AI assistant, Gemini, in Gmail, Docs, Slides, Sheets and Meet (formerly Duet AI), with a Google One AI Premium plan. The tech giant highlighted that no personal or business Workspace data will be used to train underlying LLMs, without permission.

The Google One AI Premium plan costs US$19.99 per user per month after a no-cost two month trial.

Finally, American messaging platform, Gupshup announced that it is integrating AI chatbots, powered by Google’s Vertex AI, to rich communication services (RCS) conversations. That, the company said, “will enable businesses to deliver more precise and human-like interactions with speed and scale and offer a more personalized and responsive experience.”

Security

Palo Alto Networks announced end-to-end private 5G security solutions and services, in partnership with Celona, Druid, Ataya, NETSCOUT, Nvidia and NTT DATA.

Specifically, Palo Alto Networks’ enterprise-grade 5G Security, along with the partner integrations, seek to enable organizations to easily deploy, manage, and secure networks throughout their entire 5G journey.

Furthermore, endpoint security solutions provider, BUFFERZONE introduced the NoCloud AI anti-phishing detection solution, which runs on Intel’s processors. The company said it uses multiple deep-learning engines that work together to uncover malicious behavior, enabled by the Intel technology.

NoCloud AI has been added to BUFFERZONE’s Safe Workspace platform and integrated as a Chrome or Edge browser extension.

Meanwhile, Viavi announced the addition of traffic analysis capabilities to Observer Sentry, its Software-as-a-Service-based threat exposure management solution. The new capabilities will allow Observer Sentry to go beyond identifying unintended and dangerous exposures, and help SecOps, DevOps and cloud architects determine whether a vulnerability has been exploited.

Sustainability

Orange Business signed a Memorandum of Understanding (MoU) with Cisco for a joint action plan to help reduce their greenhouse gas (GHG) emissions. Further, the collaboration will allow Orange Business to provide their customers with an estimate of the GHG emissions from their products and solutions based on Cisco technology.

Secondly, GSMA, unveiled a network equipment commerce platform, in partnership with Shields Environmental Group, to help the telecom industry achieve its financial and environmental sustainability goals.

The platform will be available to more than 1000 mobile operators and equipment manufacturers globally.

Finally, NTT Data and Schneider Electric announced a partnership combining NTT DATA’s Edge as a Service, which includes fully managed edge to cloud, private 5G, and IoT capabilities, with Schneider Electric’s EcoStruxure, a modular data center. The partnership seeks to enable companies to maximize energy efficiency while meeting the demands of compute-intensive tasks such as machine vision, predictive maintenance, and other AI inferencing applications at the edge.

Discover in detail all MWC Barcelona announcements here.

The post MWC Barcelona 2024 news roundup: Telecom, AI, security and more first appeared on IT World Canada.

MWC 2024: A wild Journey to the Future in Hall 6

The future and all that is possible was on full display this week at MWC Barcelona 2024 in Hall Six of Gran Via, the site of an innovation zone that featured hands-on and immersive demos of things ranging from devices that enhance the growing of fruit to what has been described as the “world’s first flying car.”

Called Journey to the Future, the venue was described by show organizer GSMA as the place “where we pay homage to technology’s transformational impact on tomorrow’s industries, communities and citizens.” It focused on five key areas:

Sustainability:  On display was Agerpix’s precision agriculture quad, which uses computer vision, artificial intelligence (AI) and data mining advances to gather and generate global data on fruit production. According to a release, “integrated with intelligent sensors capable of detecting the amount of fruit on a tree with a 95 per cent accuracy rate, the quad is helping to achieve smarter and more sustainable harvests in the fresh fruit industry.”

Hovering Solutions demonstrated its autonomous flying drones, which it said are being used to create 3D models of GPS-denied infrastructure, leading to safer, faster and more accurate maintenance of difficult-to-reach areas. “Mapping cities’ most underground inaccessible areas in a safe and efficient way, our robots are able to fly fully autonomously from one location to another through sewage tunnels, providing geolocated data of the interior of the infrastructure, such as panoramic high-resolution images and georeferenced 3D point clouds,” the company says.

“Our patented technology enables navigation in complex environments with no light, no pilot or any communication, generating georeferenced point-clouds and high resolution geolocated images.”

Health: The “Next Healthcare” space hosted exhibitors that the GSMA said are “revolutionizing the way medical practitioners diagnose and treat patients, as well as those disrupting the health tech space with new and emerging technologies.”

Among them, was ISDIN, which showcased its latest UV camera offering, which provided a “real-time demonstration of the protective barrier sunscreen creates against UV light – paving the way for more effective detection of skin diseases.”

Attendees were also able to discover Cortical Labs’ biological intelligence offerings. The company says it “harnesses the energy and information sampling efficiency of biological intelligence for computing devices. We do this by growing stem-cell derived neurons into silicon chips and program them to perform intelligence tasks in a simulation that they are embedded in.”

Artificial Intelligence: The zone’s dedicated AI track included an exhibition from the Catalonian Police Force, the Mossos d’Esquadra.

The Mossos, a release stated, uses AI-enabled offerings to “support operations in a number of areas, and its stand will spotlight some of the technology’s many applications in law enforcement – featuring a fixed-wing drone integrated with AI systems that enable automated data capture, allowing the service to detect, classify and track moving targets.”

Mobility: Prior to the conference, the GSMA in a release said, “pop culture has led many of us to picture hoverboards and flying cars when we think of the future and, as part of its attendance at Journey to the Future, Alef Aeronautics will bring part of this vision to life – hosting the first real flying car at its booth for all visitors to see.

“The Model A is a two-seat, all-electric vehicle designed to both drive on the street and take off vertically when needed and fly above traffic – with a flight range of 110 miles. The vehicle uses proprietary technology that elevates the vehicle without the need for runways thanks to eight propellers housed within its body, providing attendees with a glimpse into the faster and easier commutes of the future.”

Retail: This track featured a self-driving Coffee Vehicle from Rhea. According to a fact sheet, “powered by renewable energy sources, the barista vehicle allows users to order their coffee through an app which will then be delivered by the unmanned vehicle – transforming the traditional go-to-shop model and giving an insight into the industry’s convenience-led and sustainable future. “

The four-day conference, which concluded today, drew an estimated 93,000 delegates.

The post MWC 2024: A wild Journey to the Future in Hall 6 first appeared on IT World Canada.

Pornhub operator broke Canadian privacy law, watchdog rules

The company behind Pornhub and other popular pornographic sites broke Canadian privacy law by allowing intimate images to be shared on its websites without the direct knowledge or consent of everyone depicted, the federal privacy commissioner has ruled.

The Office of the Privacy Commissioner’s (OPC) investigation into Aylo (formerly MindGeek), one of the world’s largest operators of pornographic sites, was launched in 2020 after a woman discovered that her ex-boyfriend had uploaded an intimate video and other images of her to Aylo websites without her consent.

Under its normal practice at the time, MindGeek didn’t seek the complainant’s consent to collect, use, and disclose her intimate images, the report says. Instead, the company relied exclusively on her ex-boyfriend to attest that she had consented to the video being distributed on MindGeek’s websites.

The investigation found that Aylo had a legal obligation under the Personal Information Protection and Electronic Documents Act (PIPEDA) to obtain the complainant’s consent, and had failed to do so.

The OPC made a number of recommendations that Aylo should follow to improve its processes for dealing with uploaded content. However, so far Aylo has not committed to implementing any of the recommendations.

“While Aylo made changes to its consent practices in recent years,” the commission said in a statement, “the company has not provided the OPC with evidence that it is obtaining meaningful consent directly from everyone appearing in images and videos that are posted on its websites.”

The OPC report was ready to be released last May. However, Aylo went to court and tried to block its release. It lost the challenge, which is why the report was released today.

“In its response to our preliminary report, MindGeek expressly disagreed with our findings,” the final report says, and the OPC agreed to add new facts and legal arguments from MindGeek. But, the final report says, “ultimately, MindGeek did not accept responsibility and take the necessary corrective measures to redress the significant privacy harms that we uncovered in our investigation, and has yet to offer any commitments in response to our recommendations.”

The investigation uncovered significant problems that allowed highly sensitive and intimate content to be posted online without individuals’ knowledge or permission. This has led to severe impacts on victims, including social stigmatization, psychological damage, financial loss, and even attempted suicide, the OPC says.

“The inadequate privacy protection measures on Pornhub and other Aylo sites have led to devastating consequences for the complainant and other victims of non-consensual disclosure of intimate images,” said Privacy Commissioner Philippe Dufresne.

MindGeek was founded in Montreal, and still has about 1,000 employees there. In March, 2023 it was bought by Ethical Capital Partners, a Canadian private equity firm. The company’s name changed to Aylo six months later.

The incident is an example of why Canadian law needs to be updated. While MindGeek did take down the images after the woman complained, however, says the report, the content, which could be easily downloaded by users at the click of a button, continued to be re-uploaded, both on MindGeek and on other websites (including sites unrelated to pornography). Various strangers from around the world, who had seen the video online, contacted her on Facebook using information contained in the video’s title and tags, such as her name, mother’s maiden name, university and sorority, the report says.

Ultimately, the woman had to hire a professional takedown service, which led to the removal of more than 700 instances of her intimate images on more than 80 websites. The material continued to resurface on several websites until at least 2020, and is likely still available online.

The permanent loss of control over her intimate images has had a devastating effect on the complainant, says the report, who alleged that it caused her to withdraw from her social life, lose an employment opportunity, and live in a constant state of fear and anxiety.

The government this week announced a proposed Online Harms Act that would give a Digital Safety Commission the power to order such images be removed from designated web sites within 24 hours or face large financial penalties.

Parliament is also in the middle of debating an overhaul of PIPEDA called the Consumer Privacy Protection Act (CPPA, also known as Bill C-27) that would give the OPC broader powers.

The OPC recommended:

— Aylo stop allowing the upload of intimate content without first obtaining meaningful consent directly from each individual appearing in that content;

— delete all content that it previously collected without obtaining such consent;

— implement a privacy management program to ensure that it is accountable for information under its control.

— and recommended that Aylo agree to enter into a compliance agreement with the OPC and to be subject to oversight by an independent third-party reporting to the office for five years.

MORE TO COME

The post Pornhub operator broke Canadian privacy law, watchdog rules first appeared on IT World Canada.

Are federal IT systems supporting the targeted service outcomes? Deloitte examines the future role of the government

In an interview with IT World Canada, consulting giant Deloitte highlighted the importance of an ecosystem-based approach to tackle issues around digital equity in Canada and service delivery challenges in the public sector.

“Our strong view is that the people of Canada benefit when there’s effective collaboration between public and private organizations, including on critical government programs and services,” said Jaimie Boyd, Canada’s national digital government leader, Deloitte. “When we collaborate effectively, it allows us to mobilize the experience, the expertise, the contextual knowledge, leading practices globally.”

The government’s IT systems recently came under scrutiny at the House of Commons for the barrage of modernization challenges it currently faces. At the same time, members of parliament questioned the big contracts given to third party contractors.

“I do definitely recognize we are the largest professional services firm in Canada,” said Boyd, when asked about the concerns of the MPs. “And with that comes a responsibility that we are proud to carry. We’re proud to serve the people of Canada and perform our work in strict accordance with professional standards. And we’re absolutely committed to upholding the utmost standards of trust.”

She also acknowledged that there are “really high expectations” around digital service delivery and “significant barriers”, adding, “I would just really advocate for anything that we can do as a community to build these ecosystem-based approaches, build that collaboration and tackle some of these thorny issues together.”

A top priority in the government right now, she noted, is whether the investments are in alignment with service imperatives, and whether they are making lives better for Canadians.

“A relentless focus on human impact and elevating the human experience is the thing I am the most concerned about,” she added. 

The company, in fact, today released the first installment of Deloitte Canada’s Future Role of Government article series that aims to rethink government response in tackling issues around digital equity in Canada. The article provides the following recommendations:

Align federal, provincial and territorial governments’ approaches to digital skills development and measurement
Enforce cross-jurisdictional regulation and enforcement of competition in Canada to foster a stronger tech sector and provide more digital choice for citizens. Currently, competition policy is only within federal jurisdiction, which limits Canada’s ability to regulate anti-competitive behaviour
Continue to expand connectivity to close the gap in underserved populations
Ensure equitable access to technology such as smartphones and computers — they’re needed today for work, education, or essential online activities. The Minister of Finance, for instance, could introduce a targeted tax credit for internet-enabled devices for underserved groups, similar to the pandemic-era remote-work tax deduction for devices needed for work or education.
Protect Canadians from online harms; adopt an approach of ongoing public consultation to position Canada as a global leader in privacy protections; update online safety laws to balance protection from harm with respecting freedom of expression; invest further in research initiatives for cybersecurity and in digital infrastructure to protect citizens; implement an accessible and user-friendly reporting mechanism; legislative obligations should also be flexible so that they are not quickly outdated.
Shift the approach to digital policymaking to one that is agile, experimental, and closely aligned with the development and risks of new technologies. Examples are policy labs, regulatory sandboxes, and greater collaboration between regulators and innovators, the EU Policy Lab, the U.K. government’s Policy Lab, and Denmark’s MindLab.
Carry out a coordinated effort by federal and provincial governments to establish a digital credential ecosystem and build trust through public consultations.

Boyd also warned against rushing to get new technologies out, and being transparent about that process, especially when taxpayers resources are involved.

“People have traditionally talked about technology cultures, and they say, ‘Oh, you have to, you know, move fast and break things.’ And I would say quite the opposite in a public sector context. You need to move slowly and thoughtfully to build things. You need to build empowering experiences that do right by Canadians.”

In the following weeks, Deloitte Canada will be unveiling the remaining installments of the Future Role of the Government series that will span topics like reskilling, natural resources security, international relations, supply chain, health and social equity, indigenous sovereignty and more.

The post Are federal IT systems supporting the targeted service outcomes? Deloitte examines the future role of the government first appeared on IT World Canada.

Hashtag Trending Feb.29- Google’s troubles with AI; New U.S. executive order to regulate data broker industry; Lockbit announces return

Sponsor:

Hashtag Trending is sponsored by Dalikoo.com (Spell). The founder is a big supporter of our podcast and is not only a sponsor but he has offered to provide $20,000 in Azure credits for two to three of our listeners who have a unique idea for an Azure based project. The credits can be applied to existing subscriptions as well. 

That’s Dalikoo.com – and there’s a link in the show notes. 

MUSIC UP

Google’s recent troubles in AI may not be that easy to fix, the U.S. government buys data instead of spying on its citizens and realizes that other governments can do the same thing and two gangs of cybercrooks that law enforcement thought they had disrupted are back with a vengeance. 



 

All this and more on the “some days you just can’t win” edition of Hashtag Trending. I’m your host, Jim Love, CIO of IT World Canada and TechNewsDay in the US.

Google’s artificial intelligence (AI) tool, Gemini, has been taking a lot of criticism online and seems to have been caught in the culture wars. 

After a couple of false starts with errors and accusations of altering a video to exaggerate its AI, Google had been counting on Gemini to put it back into a leadership position in AI. Gemini came to market with technical achievements like its ability to a much larger prompt than its rival ChatGPT, but one of its key advantages was supposed to be its superiority in multi-modal work – audio, video and image generation and analysis from simple text prompts. 

They even came to market with a solution that had plagued image creation – the bias in the data. 

AI tools are trained on vast amounts of data from the internet, which contains inherent biases. Google’s attempt to correct these biases with Gemini has led to responses that many find absurd due to the lack of nuance that humans instinctively understand but AI systems do not.

For instance, Gemini created an image of the US Founding Fathers that inaccurately included a black man. It depicted German soldiers from World War Two featuring a black man and an Asian woman. 

In response, Google prevented its AI from showing pictures of people. This was a huge embarrassment.

But it turns out the problems were not restricted to images. 

There was controversy about Gemini’s text responses, such as stating there was “no right or wrong answer” to a question comparing Elon Musk’s meme posting on X (formerly Twitter) to Hitler’s actions during World War Two. 

Google’s CEO, Sundar Pichai, has acknowledged that some of Gemini’s responses have offended users and shown bias, which he deemed “completely unacceptable.” His embarrassment showed in an internal leaked memo where he talked about the need to work day and night to fix this problem. 

Pichai’s frustration is understandable. Google’s AI development problems have resulted in many embarrassing moments. In the launch of Gemini’s predecessor, Bard, the AI made a simple and obvious mistake during the launch, one that was caught by everyone – except the embarrassed Google team and its AI.

A subsequent video demo which supposedly showed how the AI could interpret and create images from even unclear instructions or drawings was found to have been altered to speed it up and make the results look more appealing than they did in real life. Once again, this was caught and publicized heavily.

Google was a pioneer in AI development, and it largely invented the transformer architecture that gave us generative AI. But after ChatGPT took the public attention, Google seems unable to launch a successful AI offering. 

No matter what they do in terms of technical advancement, they seem to always make a significant mistake.

So it’s no wonder that Pichai wants this fixed, quickly. But according to some experts, it may not be easy to do. 

Many believe that there is no easy fix for these issues, as correcting bias in AI outputs is a complex task that has been a focus of the AI ethics community for years. 

So, do they go back to biased data or do they persevere and take the delays? There are times when you are damned If you do and damned if you don’t.

Sources include: BBC

We’ve covered stories in the past about how the U.S. government doesn’t have to conduct surveillance to get information about its citizens – they can simply buy information from data brokers. There are real debates about whether this is appropriate and there will undoubtedly be guidelines restricting some of this activity by the U.S. government.

But what about other governments who don’t play by the rules? It turns out that instead of spying on U.S. citizens they can simply buy the data as well – unless a new government restriction is put in place.

President Joe Biden is reported to be set to issue an executive order aimed at limiting the mass sale of Americans’ personal data to “countries of concern,” including Russia and China. 

This executive order specifically targets the bulk sale of geolocation, genomic, financial, biometric, health, and other personally identifying information. A senior administration official highlighted that the sale of such data to these countries poses a national security risk, pointing out that buying data through data brokers is currently legal in the United States. 

The executive order will prohibit data brokers and other companies from selling large troves of Americans’ personal information to countries or entities in Russia, China, Iran, North Korea, Cuba, and Venezuela, either directly or indirectly. This includes additional restrictions on companies’ ability to sell data as part of cloud service contracts, investment agreements, and employment agreements.

While the White House has described this step as “the most significant executive action any President has ever taken to protect Americans’ data security,” the specifics of how the new policies will be enforced within the Justice Department remain unclear. A Department of Justice (DoJ) official mentioned that the executive order would require data brokers to perform due diligence to vet their clients, similar to how companies adhere to US sanctions.

This executive order represents a significant move to regulate the largely unregulated multibillion-dollar data broker industry, which has been warned by researchers and privacy advocates as posing national security risks. 

However, once again, this may be easier said than done as the order does not address the bulk sale of Americans’ data to countries or companies not deemed to be a security risk. The White House has urged Congress to pass comprehensive bipartisan privacy legislation, especially to protect children’s safety.

Sources include: Engadget 

Cybercriminals are increasingly targeting the manufacturing industry with ransomware attacks, according to a report by operational technology security firm Dragos. 

In its 2023 year-in-review report, Dragos found that 70 percent of all industrial organization ransomware infections affected manufacturing companies, impacting 638 entities across 33 unique manufacturing subsectors.

The report suggests that the manufacturing sector’s early adoption of digital transformation, including IoT and connected machines, without parallel investments in security, has made it a relatively easy target for cybercriminals. 

Manufacturing organizations’ systems are richer targets due to their significant role in revenue generation. When these systems are hit, the impact on the company’s bottom line prompts faster and more substantial ransom payments.

Dragos CEO Robert Lee highlighted that manufacturing’s struggle with network segmentation. This lack of effective network defenses allows intruders to move across systems and environments more freely.

The report also touches on the broader issue of supply-chain attacks, where exploiting vulnerabilities in commonly used software or equipment can enable mass targeting of organizations for ransomware infections—or worse. 

The report underscores the need for enhanced security measures in the manufacturing sector to protect against these growing cyber threats.

Sources include: The Register

Lockbit, a notorious cybercrime gang known for its use of ransomware to extort victims, has announced its return online after being targeted by an international law enforcement operation. The operation, described as unprecedented, led to the arrest and indictment of its members. Despite these efforts, Lockbit claims to have restored its servers and is back in business.

The gang’s darkweb site, used for leaking data stolen from its victims, was reportedly hacked by law enforcement using a vulnerability in the PHP programming language. Lockbit’s statement, posted in English and Russian on a new version of its darkweb site, asserts that servers with backup blogs not using PHP remain unaffected and will continue to release data from attacked companies.

The National Crime Agency (NCA) of Britain, which spearheaded the international effort to dismantle Lockbit’s operations, stated that the group “remains completely compromised.” The NCA acknowledged the possibility of Lockbit attempting to regroup and rebuild their systems but emphasized that a significant amount of intelligence about the gang and its associates had been gathered. The agency remains committed to targeting and disrupting Lockbit’s activities.

The new Lockbit darkweb site features a gallery of company names, each accompanied by a countdown clock indicating the deadline for the required ransom payment. 

Sources include: The Register 

Despite the FBI’s efforts in December to disrupt BlackCat’s operations by taking down its Tor negotiation and leak sites, the gang has managed to “unseize” their sites and continue their criminal activities. This resilience underscores the challenges faced by law enforcement in permanently dismantling such cybercrime networks.

FBI, CISA, and the Department of Health and Human Services (HHS) have issued a warning to U.S. healthcare organizations about targeted ransomware attacks by the ALPHV/Blackcat group. 

The gang had been linked to over 60 breaches and had reportedly accumulated at least $300 million in ransoms from more than 1,000 victims by September 2023, and apparently, the group has shown resilience and adaptability in the face of law enforcement actions.

The recent surge in attacks against the healthcare sector, with nearly 70 leaked victims since mid-December 2023, appears to be a direct response to an operational action against the group and its infrastructure in early December 2023. The ALPHV Blackcat administrator’s encouragement for affiliates to target hospitals highlights a deliberate and malicious focus on exploiting vulnerabilities within critical healthcare infrastructure.

The U.S. State Department’s offer of rewards for information leading to the identification or location of BlackCat gang leaders, as well as tips on individuals linked to the group’s ransomware attacks, shows how seriously they are taking the pursuit of this group.  

Remember those horror movies where at the very end the villain comes back from the dead or reaches up from the grave? 

Listeners who want even more cybersecurity stories may want to subscribe to our sister podcast CyberSecurity today. You can find it anywhere you get your podcasts. 

Sources include: Bleeping Computer

And that’s our show for today.

Hashtag Trending goes to air five days a week with daily newscast and a weekend interview show that we creatively called – the weekend edition. 

Remember if any of you want to connect with Dalikoo, remember to mention us. We need sponsors to pay for the work it takes to produce this show. www.dalikoo.com

Love your comments. 

Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending. 

Thanks for listening and have a Thrilling Thursday.

 

The post Hashtag Trending Feb.29- Google’s troubles with AI; New U.S. executive order to regulate data broker industry; Lockbit announces return first appeared on IT World Canada.

MWC 2024: 5G momentum on a roll with 1.6 billion connections worldwide

New figures from GSMA Intelligence (GSMAi) released today at MWC Barcelona 2024 reveal that 5G connections are expected to represent over half (51 per cent) of mobile connections by 2029.

Authors of the report note that 5G has been the fastest mobile generation rollout to date, surpassing one billion connections by the end of 2022, rising to 1.6 billion connections at the end of 2023 and projected to reach 5.5 billion by 2030.

Findings showed that, as of last month, 261 operators in 101 countries had launched commercial 5G services, and more than 90 operators from 64 markets have committed to rollouts.

Of the 261 commercial 5G services available, 47 are provided on 5G Standalone (SA) networks, with a further 89 planned deployments near-term that will take advantage of network slicing, ultra-reliable low-latency communications support, and the simplified 5G SA network architecture.

Peter Jarich, the head of GSMAi, said, “the early success of 5G was driven by enhanced mobile broadband (EMBB) and EMBB-related network traffic requirements. Yet, while consumer requirements will continue their trajectory, we are now seeing use cases beyond that.

“Opportunities are now appearing in areas including API monetization and 5G RedCap for enterprise IoT – all supported by 5G-Advanced and 5G SA networks. 5G SA brings home 5G’s early promise, particularly where slicing, low-latency and massive IoT capabilities tied to enterprise service needs can be met. 5G-Advanced will only extend that further.”

A release issued by the GSMAi indicates that the growth of available 5G Standalone (SA) networks, and improved support for private and dedicated networks, will support a massive number of connected devices and help to realize the global IoT vision for the enterprise.

GSMAi data shows the enterprise segment now counts 10.7 billion IoT connections (versus 10.5 billion consumer connections) and this momentum is expected to continue, with enterprise connections more than doubling to 38.5 billion by 2030 and smart buildings and smart manufacturing accounting for 34 per cent and 16 per cent of total enterprise connections respectively.”

The release states that beyond 5G SA, “the availability of 5G-Advanced with 3GPP Release 18 will be another key 5G milestone in IoT delivery, providing the catalyst for new 5G investment throughout 2024 and into 2025. GSMAi data shows over half of operators expect to begin deploying 5G-Advanced within a year after commercial availability of 5G-Advanced solutions, driven by priority use cases such as 5G multicast services and low-cost IoT support.”

GSMAi predicts a fourfold rise in mobile data traffic between now and 2030 with expansions in 5G coverage and capacity playing a prominent role, showcasing the importance of continued infrastructure investments. It is predicted that monthly global mobile data traffic per connection will grow from 12.8 GB in 2023 to 47.9 GB in 2030.

The increasing use of Generative AI (GenAI) – 56 per cent of operators are currently testing applications – will also likely fuel this growth, the release said. This will be driven by applications including the use of GenAI-enabled chatbots for customer service efforts and the continued growth of AI-generated video and music content, it added.

Authors of the report say that 5G is expected to “benefit all economic sectors of the global economy, although some industries will benefit more than others due to their ability to incorporate 5G use cases in their business. Over the next seven years, 36 per cent of benefits are expected to originate from the manufacturing sector, 15 per cent from public administration and 10 per cent from services, driven by applications in smart factories, smart cities and smart grids.”

The post MWC 2024: 5G momentum on a roll with 1.6 billion connections worldwide first appeared on IT World Canada.

MWC 2024: Intel adds AI processors, launches the new vPro platform

Intel yesterday launched its commercial line of Intel Core Ultra processors featuring NPUs (neural processing units) to accelerate artificial intelligence (AI) at MWC Barcelona 2024. The processors, whose consumer versions were announced in December, include the new Intel vPro platform that the company said, offers productivity gains as well as enhanced security and new manageability features.

This year, Intel said in a release, partners including Acer, ASUS, Dell Technologies, Dynabook, Fujitsu, HP, Lenovo, LG, Microsoft Surface, NEC, Panasonic, Samsung and VAIO will deliver more than 100 notebook, 2-in-1, entry, and workstation designs using the technology.

Compared to a three-year-old PC, users can expect up to 47 per cent better productivity with office applications, noted Jen Larsen, general manager, commercial segments at Intel, during a briefing, up to 36 per cent processor power reduction vs the previous generation for video conferencing, and up to 2.2 times AI performance, gen over gen, for video editing.

Intel has been working with the application software ecosystem to optimize performance even more, added Carla Rodriguez, vice president and general manager, client software ecosystem.

“On the productivity side, we’ll work with players like Teams, Zoom, etc. so that there’s a better collaboration experience – many things that we take for granted today [like background blur and noise cancellation],” she said. “But the reality is, that’s only possible through the unlocking of that hardware benefit with software applications.”

On the security front, Intel has designed its threat detection technology to take advantage of the NPU to improve performance while freeing the CPU for other tasks and reducing power consumption. A new Intel Silicon Security Engine, for example, authenticates system firmware. Larsen said that Intel has enabled some ISVs (independent software vendors) to make use of the NPU, but not in isolation.

“We have this xPU strategy; we have a CPU, a GPU and an NPU, and they’re able to leverage all of them, depending on what the workload looks like.”

Manageability is a key feature of vPro and, the company said in a release, it has added more to the platform to help IT departments manage their fleets. These include:

Intel Device Discovery – a new way for cloud-based tools to receive the information they need to take appropriate actions on a given PC.

Intel Device Health with VMware and Eclypsium – helps IT organizations gain visibility into fleet patching requirements and deliver end-to-end device management.

Intel noted that it also “continues to invest in hardware-based remote management, both for on-premises solutions leveraging endpoint management technology and cloud-native (offerings) like VMware Workspace ONE.”

The post MWC 2024: Intel adds AI processors, launches the new vPro platform first appeared on IT World Canada.

MWC 2024: Ontario startup collaborates with Intel to advance Open RAN solutions

Bluewaves Mobility Innovation (BMI), a North York-based startup that specializes in ORAN (open radio access networks) solutions, this week announced a partnership with Intel at MWC 2024 in Barcelona.

ORAN is a nonproprietary version of the Radio Access Network (RAN) system that allows interoperation between various pieces of cellular network equipment provided by different vendors, including the radio unit (RU), the distributed unit (DU) and the centralized unit (CU).

BMI builds Open RAN RUs, where the radio frequency signals in a network are transmitted, received, amplified and digitized.

The company is embedding Intel’s Agilex FPGA (field-programmable gate array) products in its radio designs for accelerated performance and increased power efficiency. An FPGA is a reprogrammable chip that can be customized to accelerate key workloads.

“The telecom industry is at a tipping point. ORAN is creating a multitude of new opportunities as leading mobile operators seek to disaggregate their networks and reap the benefits of ORAN” said Darron Enright, director of business development at BMI. “With Intel’s Agilex silicon components embedded, BMI ORUs will assist operators to meet their ORAN objectives in reducing the overall TCO of their networks as well as those for environmental sustainability.”

Enright added that BMI has set up its radio manufacturing in the greater Toronto area, and is acquiring partners like Intel to create a robust, resilient and secure North American ORAN supply chain.

The post MWC 2024: Ontario startup collaborates with Intel to advance Open RAN solutions first appeared on IT World Canada.