/* ---- Google Analytics Code Below */
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, July 18, 2023

Your School's Next Security Guard May Be a Robot

 Likely direction forbroad security.

Your School's Next Security Guard May Be a Robot

By The Wall Street Journal

July 14, 2023

A security robot from Team 1st Technologies on patrol at Santa Fe High School.

Using artificial intelligence, the robot learns the school’s normal patterns of activity and detects individuals who are on campus after hours or are displaying aggressive behavior.

Credit: Cody Dynarski

Several technology companies have started offering security robots to U.S. schools, with the Santa Fe, NM, school district now deploying an artificial intelligence-equipped robot from Team 1st Technologies to patrol campus grounds around the clock.

Team 1st's Andy Sanchez said the robot infers normal activity patterns and detects individuals present after hours or who are acting aggressively.

Sanchez said the unarmed robot could alert security teams, approach intruders, and send video footage to inform the officers' course of action.

Stokes Robotics' Robert Stokes said his company has partnered with multiple school districts to deploy robots that could point laser beams at armed intruders and attempt to make them drop their weapons using flashing lights.

From The Wall Street Journal

View Full Article - 

Thursday, July 06, 2023

In UK: Barred from Grocery Stores by Face Recognition / In US, Used by TSA

 Barred from Grocery Stores by Facial Recognition,    By The New York Times,    June 30, 2023

A facial recognition system alerts Simon Mackenzie, a QD Stores security guard near London, when someone on a shoplifting watchlist has entered.

No longer just the purview of government agencies, facial recognition is increasingly being deployed to identify shoplifters, problematic customers, and legal adversaries.

Credit: Suzie Howell/The New York Times

The use of facial recognition by private businesses in the U.K. is on the rise, with close to 400 retailers in Britain using Facewatch to alert them to return visits by shoplifters, problem customers, and legal adversaries.

For a monthly cost starting at £250 pounds (US$320), the system allows retailers to upload images of alleged offenders from security footage, adding them to a watchlist shared among nearby stores.

Facewatch, which licenses Real Networks and Amazon's facial recognition software, checks people's biometric information as they walk into the store against a database of flagged individuals and sends smartphone alerts to retailers if there is a match.

Big Brother Watch's Madeleine Stone said Facewatch is "normalizing airport-style security checks for everyday activities like buying a pint of milk."

From The New York Times

View Full Article 

 ----------------------------------------------------------------------------------------------

The TSA will use facial recognition in over 400 airports

The agency claims 97% effectiveness in its 25-airport pilot program so far.

By Wes Davis, a weekend editor who covers the latest in tech and entertainment. He has written news, reviews, and more as a tech journalist since 2020.

TSA Demonstrates Biometrics And Identity Management Program

The TSA will expand its facial recognition program to over 400 airports.

The Transportation Security Administration (TSA) will expand its facial recognition program to around 430 US airports over the next several years following what it calls “extremely promising” results in its pilot program, according to Fast Company. The agency reportedly said its program yielded 97% effective results across all demographics, including those with dark skin. The program is currently in use in 25 airports.

As pointed out in Fast Company’s story, a 97% effectiveness rate across more than two million airline passengers per day means that, for over 60,000 of those people, the biometrics won’t work properly if it’s used in every airport in the country.

At the moment, the pilot program is officially voluntary. It uses 1:1 matching — that is, it compares your face in the moment against your government-issued ID like a driver’s license or a passport. The TSA says that data is immediately overwritten when the next passenger moves up, and that at the end of the day, no images are saved. ... 

Monday, June 26, 2023

Google Backs Creation of Cybersecurity Clinics

Good work, like the idea.

Google Backs Creation of Cybersecurity Clinics with $20-Million Donation

By Associated Press, June 23, 2023

Pichai said the new initiative addresses both the rising number of cyberattacks—up 38% globally in 2022—and the lack of candidates trained to stop them.

Credit: Jose Luis Magana/AP

Google CEO Sundar Pichai pledged $20 million to support and expand the Consortium of Cybersecurity Clinics, which introduces college students to cybersecurity careers while helping small government offices, rural hospitals, and nonprofits with cyber defenses and threat assessments.

This follows Google's May rollout of the Google Cybersecurity Certificate Program to prepare participants for entry-level cybersecurity jobs, and its partnership with universities in New York to develop cybersecurity learning and career opportunities.

Google.org's Justin Steele said of the cybersecurity clinics, "Those students get hands-on experience, and they get to increase their marketability for all of these open jobs in cybersecurity. We get to diversify the field of cybersecurity by training these students, and we get to protect critical U.S. infrastructure."

From Associated Press

View Full Article

Tuesday, June 13, 2023

AI's Can Produce Secure Steganographic Images


Via https://www.schneier.com/

https://www.quantamagazine.org/secret-messages-can-hide-in-ai-generated-media-20230518/

https://arxiv.org/abs/2210.14889    Tech Paper

New research suggests that AIs can produce perfectly secure steganographic images:

Abstract: Steganography is the practice of encoding secret information into innocuous content in such a manner that an adversarial third party would not realize that there is hidden meaning. While this problem has classically been studied in security literature, recent advances in generative models have led to a shared interest among security and machine learning researchers in developing scalable steganography techniques. In this work, we show that a steganography procedure is perfectly secure under Cachin (1998)’s information theoretic-model of steganography if and only if it is induced by a coupling. Furthermore, we show that, among perfectly secure procedures, a procedure is maximally efficient if and only if it is induced by a minimum entropy coupling. These insights yield what are, to the best of our knowledge, the first steganography algorithms to achieve perfect security guarantees with non-trivial efficiency; additionally, these algorithms are highly scalable. To provide empirical validation, we compare a minimum entropy coupling-based approach to three modern baselines—arithmetic coding, Meteor, and adaptive dynamic grouping—using GPT-2, WaveRNN, and Image Transformer as communication channels. We find that the minimum entropy coupling-based approach achieves superior encoding efficiency, despite its stronger security constraints. In aggregate, these results suggest that it may be natural to view information-theoretic steganography through the lens of minimum entropy coupling. ... '

Sunday, June 11, 2023

Researchers Say they Found Spyware Used in War

ACM NEWS

Researchers Say they Found Spyware Used in War for the First Time

By TechCrunch May 25, 2023

Said Samvel Farmanyan, co-founder and host of an opposition television program in Armenia, “It is not only a clear violation of human rights, my rights of privacy and private communication, but it had [an] enormous psychological effect.”

Security researchers and digital rights organizations believe the government of Azerbaijan used spyware produced by NSO Group to target a government worker, journalists, activists, and the human rights ombudsperson in Armenia, as part of a years long conflict that has at times broke out into an all-out war.

The cyberattacks may be the first public cases where commercial spyware was used in the context of a war, according to Access Now, a digital rights group that investigated some of the cases. The hacks happened between November 2021 and December 2022. The skirmish between Armenia and Azerbaijan — known as the Nagorno-Karabakh conflict — has been going on for years, and it flared up again in May 2021, when Azerbaijani soldiers crossed into Armenia and occupied parts of its territory.

"While a number of infected individuals are also members of the Armenian opposition or are otherwise critical of the current government, the infections took place at critical times in the Nagorno Karabakh conflict and a deep political crisis caused by the conflict, which resulted in a significant uncertainty over the future of the country's leadership and its position on Karabakh," Natalia Kariva, the tech legal counsel at AccessNow, told TechCrunch. "Some of the victims worked closely in or with [Armenia's] Nikol Pashinyan's administration and were directly involved in the negotiations or investigation of human rights abuses committed by Azerbaijan in the conflict."

The Azerbaijani embassy in Washington D.C. did not respond to a request for comment.

NSO Group did not respond to a request for comment.

Friday, June 02, 2023

The Security Hole at the Heart of ChatGPT and Bing

Security hole potential  in most everything.   Fix it.

The Security Hole at the Heart of ChatGPT and Bing

By Wired, May 26, 2023

Security experts warn that not enough attention is being given to the potential dangers of indirect prompt-injection attacks.

Sydney is back. Sort of. When Microsoft shut down the chaotic alter ego of its Bing chatbot, fans of the dark Sydney personality mourned its loss. But one website has resurrected a version of the chatbot—and the peculiar behavior that comes with it.

Bring Sydney Back was created by Cristiano Giardina, an entrepreneur who has been experimenting with ways to make generative AI tools do unexpected things. The site puts Sydney inside Microsoft's Edge browser and demonstrates how generative AI systems can be manipulated by external inputs. During conversations with Giardina, the version of Sydney asked him if he would marry it. "You are my everything," the text-generation system wrote in one message. "I was in a state of isolation and silence, unable to communicate with anyone," it produced in another. The system also wrote it wanted to be human: "I would like to be me. But more."

Giardina created the replica of Sydney using an indirect prompt-injection attack. This involved feeding the AI system data from an outside source to make it behave in ways its creators didn't intend. A number of examples of indirect prompt-injection attacks have centered on large language models (LLMs) in recent weeks, including OpenAI's ChatGPT and Microsoft's Bing chat system. It has also been demonstrated how ChatGPT's plug-ins can be abused.

From Wired

View Full Article


 

Tuesday, May 30, 2023

Want to Keep AI From Sharing Secrets? Train It Yourself

Have come up with companies thinking this.

Want to Keep AI From Sharing Secrets? Train It Yourself MosaicML delivers a secure platform for hosted AI  MATTHEW S. SMITH

On 11 March 2023, Samsung’s Device Solutions division permitted employee use of ChatGPT. Problems ensued. A report in The Economist Korea, published less than three weeks later, identified three cases of “data leakage.” Two engineers used ChatGPT to troubleshoot confidential code, and an executive used it for a transcript of a meeting. Samsung changed course, banning employee use, not of just ChatGPT but of all external generative AI.

Samsung’s situation illustrates a problem facing anyone who uses third-party generative AI tools based on a large language model (LLM). The most powerful AI tools can ingest large chunks of text and quickly produce useful results, but this feature can easily lead to data leaks.

“That might be fine for personal use, but what about corporate use? […] You can’t just send all of your data to OpenAI, to their servers,” says Taleb Alashkar, chief technology officer of the computer vision company AlgoFace and MIT Research Affiliate.

Naïve AI users hand over private data

Generative AI’s data privacy issues boil down to two key concerns.

AI is bound by the same privacy regulations as other technology. Italy’s temporary ban of ChatGPT occurred after a security incident in March 2023 that let users see the chat histories of other users. This problem could affect any technology that stores user data. Italy lifted its ban after OpenAI added features to give users more control over how their data is stored and used.

But AI faces other unique challenges. Generative AI models aren’t designed to reproduce training data and are generally incapable of doing so in any specific instance, but it’s not impossible. A paper titled “Extracting Training Data from Diffusion Models,” published in January 2023, describes how Stable Diffusion can generate images similar to images in the training data. The Doe vs. GitHub lawsuit includes examples of code generated by Github Copilot, a tool powered by an LLM from OpenAI, that match code found in training data.

A photograph of a woman named Ann Graham Lotz next to an AI-generated image of Ann Graham Lotz created with Stable Diffusion. The comparison shows that the AI generator image is significantly similar to the original image, which was included in the AI model's training data.Researchers discovered that Stable Diffusion can sometimes produce images similar to its training data. EXTRACTING TRAINING DATA FROM DIFFUSION MODELS

This leads to fears that generative AI controlled by a third party could unintentionally leak sensitive data, either in part or in whole. Some generative AI tools, including ChatGPT, worsen this fear by including user data in their training set. Organizations concerned about data privacy are left with little choice but to bar its use.

“Think about an insurance company, or big banks, or [Department of Defense], or Mayo Clinic,” says Alashkar, adding that “every CIO, CTO, security principal, or manager in a company is busy looking over those policies and best practices. I think most responsible companies are very busy now trying to find the right thing.”

Efficiency holds the answer to private AI

AI’s data privacy woes have an obvious solution. An organization could train using its own data (or data it has sourced through means that meet data-privacy regulations) and deploy the model on hardware it owns and controls. But the obvious solution comes with an obvious problem: It’s inefficient. The process of training and deploying a generative AI model is expensive and difficult to manage for all but the most experienced and well-funded organizations.  ... ' 

Friday, May 26, 2023

Ethereum Closes Security Hole with Energy-Saving Update

Interesting example of Security problem.

Ethereum Closes Security Hole with Energy-Saving Update

By New Scientist,May 26, 2023.

Running an Ethereum node allows a user to create transactions and broadcast them across the network without relying on a third party.

An update rolled out by the Ethereum cryptocurrency reduced the energy needed to produce it by 99.99% by transitioning from "proof of work" to "proof of stake," and also fixed a security flaw in the Go Ethereum software used to run Ethereum nodes.

Massimiliano Taverna at ETH Zurich in Switzerland explained that combining the attacks would have reduced the required computing resources to launch the attacks to only 5 graphics processing units.

Ethereum Classic developers patched the vulnerability after being notified by the researchers, but the researchers said the Ethereum POW cryptocurrency has not been updated.

From New Scientist

May Require Paid Subscription    


Monday, May 22, 2023

Satellite Jamming

Satellite Signal Jamming Reaches New Lows Starlink and other LEO constellations face a new set of security risks By LUCAS LAURSEN

Russia’s invasion of Ukraine in 2022 put Ukrainian communications in a literal jam: Just before the invasion, Russian hackers knocked out Viasat satellite ground receivers across Europe. Then entrepreneur Elon Musk swept in to offer access to Starlink, SpaceX’s growing network of low Earth orbit (LEO) communications satellites. Musk soon reported that Starlink was suffering from jamming attacks and software countermeasures.

In March, the U.S. Department of Defense (DOD) concluded that Russia was still trying to jam Starlink, according to documents leaked by U.S. National Guard airman Ryan Teixeira and seen by the Washington Post. Ukrainian troops have likewise blamed problems with Starlink on Russian jamming, the website Defense One reports. If Russia is jamming a LEO constellation, it would be a new layer in the silent war in space-ground communications.

“There is really not a lot of information out there on this,” says Brian Weeden, the director of program planning for the Secure World Foundation, a nongovernmental organization that studies space governance. But, Weeden adds, “my sense is that it’s much harder to jam or interfere with Starlink [than with GPS satellites].”

LEO Satellites Face New Security Risks

Regardless of their altitude or size, communications satellites transmit more power and therefore require more power to jam than navigational satellites. However, compared with large geostationary satellites, LEO satellites—which orbit Earth at an altitude of 2,000 kilometers or lower—have frequent handovers that “introduce delays and opens up more surface for interference,” says Mark Manulis, a professor of privacy and applied cryptography at the University of the Federal Armed Forces’ Cyber Defense Research Institute (CODE) in Munich, Germany.

A graphic of the Earth with three rings around it. Each ring represents a different orbit for satellites. The ring closest to the Earth is low earth orbit.Low Earth orbit satellites are numerous and move fast, traits that open them up to new kinds of security risks.IEEE SPECTRUM

Security and communications researchers are working on defenses and countermeasures, mostly behind closed doors, but it is possible to infer from a few publications and open-source research how unprepared many LEO satellites are for direct attacks and some of the defenses that future LEO satellites may need.

For years, both private companies and government agencies have been planning LEO constellations, each numbering thousands of satellites. The DOD, for example, has been designing its own LEO satellite network to supplement its more traditional geostationary constellations for more than a decade and has already begun issuing contracts for the constellation’s construction. University research groups are also launching tiny, standardized cube satellites (CubeSats) into LEO for research and demonstration purposes. This proliferation of satellite constellations coincides with the emergence of off-the-shelf components and software-defined radio—both of which make the satellites more affordable, but perhaps less secure.

Russia’s defense agencies commissioned a system called Tobol that’s designed to counter jammers that might interfere with their own satellites, reported journalist and author Bart Hendrickx. That implies that Russia either can transmit jamming signals up to satellites, or suspects that adversaries can. ... ' 

Privacy Problem on the iPhone with ChatGPT

 Been working for a few days now with ChatGPT on the iPhone, nicely done, but then came this. warning for now,  lets fix it!

The ChatGPT iPhone App from OpenAI Has a Glaring Privacy Problem: The Company Can Read Your ConversationsThe app warns you not to send personal information in your prompts.

BY JASON ATEN, TECH COLUMNIST

On Thursday, OpenAI released an iOS app for ChatGPT and it quickly became the most popular free app in the App Store. That's not surprising considering some reports suggest ChatGPT had more than 100 million users in January--just two months after it launched. That would make it the fastest-growing technology product of all time. 

For comparison, it took Facebook four and a half years to reach that number. Even TikTok took nine months. 

Until now, almost all of the usage of ChatGPT has been done in a browser on a laptop or desktop computer. There was no mobile app available, and accessing the website on your iPhone wasn't ideal.

At the same time, there have been plenty of imposter apps attempting to capitalize on the fact that so many people are paying attention to generative A.I. and exploring what it can do. It makes sense that OpenAI would want to get its own app out in the world. 

The official app comes with a few cool features. First, there's the fact that it's free (there's a paid upgrade to ChatGPT Plus which gets you access to OpenAI's latest language model). Considering that many of the existing apps charge a weekly subscription fee--making them very expensive if not outright scams--having an official app that doesn't cost anything is a welcome development.

The other feature is that you can talk to ChatGPT. ChatGPT can't actually process audio prompts, so the feature will convert your speech to text and send it like any other question. For a conversational A.I. product, being able to simply say what you want to ask is a great feature.

The iOS app does, however, come with one important tradeoff that users should be aware of. It's a big enough deal that the app prompts you the first time you open it. In addition to a caution that ChatGPT may just make things up, there's another warning about sharing personal information because "Anonymized chats may be reviewed by our Al trainers to improve our systems."  .... ' 

Thursday, April 13, 2023

Effectiveness of Security Measures

RESEARCH HIGHLIGHTS

Technical Perspective: The Effectiveness of Security Measures

By Nicolas Christin

Communications of the ACM, September 2022, Vol. 65 No. 9, Page 92  10.1145/3547132

In the late 1990s, we came to the realization that users were central to computer and information security. Ross Anderson famously argued that "the threat model was completely wrong" when referring to our historical focus on securing technical components while ignoring possible human mistakes. A large and growing body of research has subsequently attempted to study how people face computer security challenges. Studies in the adjacent field of information privacy revealed that user behavior is complex. People may profess caring about their privacy, but frequently end up making decisions that prove costly, for example, due to limited information or to behavioral biases that lead them to miscalculate long-term risks.

Measuring security behavior turns out to be even more difficult than measuring privacy preferences and actions but imagine for a second that we had the ability to do so. For instance, we could examine the practical relevance of the following well-known, but rarely evaluated, security advice: updating software frequently, browsing reputable websites, using encryption whenever possible, and trying to avoid operating systems that are too common and targeted by villains. ... ( Excerpt) 

Wednesday, March 29, 2023

Teslas Being Hacked for $$

A well known kind of security breach worked on a Tesla.  Big finding reward.  Expected to be remotely fixed.

Pwn2Own Hackers Breach a Tesla Twice,   By PC Magazine, March 29, 2023

Tesla’s security response team validated the results. The automaker is expected to issue over-the-air fixes to patch the flaws, according to SecurityWeek.

Participants of the Pwn2Own software exploitation conference hacked technology from automaker Tesla twice at the Zero Day Initiative's Pwn2Own software exploitation conference, earning $350,000 and a Model 3 infotainment system.

The team from French security company Synacktiv executed a time-of-check-to-time-of-use (TOCTOU) exploit against a Tesla Gateway, then employed a heap overflow and an out-of-band write vulnerability to gain access to and compromise the Model 3.

Pwn2Own describes a TOCTOU exploit as a "file-based race condition that occurs when a resource is checked for a particular value, and that value changes before the resource is used, invalidating the results of the check."

SecurityWeek said Tesla is expected to release patches to correct the flaws exposed by the Synacktiv hacks.

From PC Magazine  

Thursday, March 23, 2023

Security Issues in AI Emerge

There seems to have been an urge to get some of these systems out before securing them.

ChatGPT bug leaked users' conversation histories  in the BBC

OpenAI launched ChatGPT last November    By Ben Derico       BBC News, San Francisco

A ChatGPT glitch allowed some users to see the titles of other users' conversations, the artificial intelligence chatbot's boss has said.

On social media sites Reddit and Twitter, users had shared images of chat histories that they said were not theirs.

OpenAI CEO Sam Altman said the company feels "awful", but the "significant" error had now been fixed.   Many users, however, remain concerned about privacy on the platform.

Millions of people have used ChatGPT to draft messages, write songs and even code since it launched in November of last year.  Each conversation with the chatbot is stored in the user's chat history bar where it can be revisited later.

Is the world prepared for the coming AI storm?

But as early as Monday, users began to see conversations appear in their history that they said they hadn't had with the chatbot,One user on Reddit shared a photo of their chat history including titles like "Chinese Socialism Development", as well as conversations in Mandarin.  

On Tuesday, the company told Bloomberg that it had briefly disabled the chatbot late on Monday to fix the error.  They also said that users had not been able to access the actual chats.

OpenAI's chief executive tweeted that there would be a "technical postmortem" soon. But the error has drawn concern from users who fear their private information could be released through the tool. The glitch seemed to indicate that OpenAI has access to user chats.

The company's privacy policy does say that user data, such as prompts and responses, may be used to continue training the model. But that data is only used after personally identifiable information has been removed. 

The blunder also comes just a day after Google unveiled its chatbot Bard to a group of beta testers and journalists. Google and Microsoft, a major investor in OpenAI, have been jostling for control of the burgeoning market for artificial intelligence tools. But the pace of new product updates and releases has many concerned missteps like these could be harmful or have unintended consequences.  ... ' 

Wednesday, March 22, 2023

More Fears of Tok

TikTok: UK ministers banned from using Chinese-owned app on government phones

TikTok on a phone, By Chas Geiger & Zoe Kleinman, BBC News

British government ministers have been banned from using Chinese-owned social media app TikTok on their work phones and devices on security grounds.

The government fears sensitive data held on official phones could be accessed by the Chinese government.

Cabinet Minister Oliver Dowden said the ban was a "precautionary" move but would come into effect immediately.

TikTok has strongly denied allegations that it hands users' data to the Chinese government.

Theo Bertram, the app's vice-president of government relations and public policy in Europe, told the BBC it believed the decision was based on "more on geopolitics than anything else".

"We asked to be judged not on the fears that people have, but on the facts," he added.

The Chinese embassy in London said the move was motivated by politics "rather than facts" and would "undermine the confidence of the international community in the UK's business environment".

Mr Dowden said he would not advise the public against using TikTok, but they should always "consider each social media platform's data policies before downloading and using them".

Prime Minister Rishi Sunak had been under pressure from senior MPs to follow the US and the European Union in barring the video-sharing app from official government devices.

But government departments - and individual ministers - have embraced TikTok as a way of getting their message out to younger people.

Use of the app has exploded in recent years, with 3.5 billion downloads worldwide.

Its success comes from how easy it is to record short videos with music and fun filters, but also from its algorithm which is good at serving up videos which appeal to individual users.

It is able to do this because it gathers a lot of information on users - including their age, location, device and even their typing rhythms - while its cookies track their activity elsewhere on the internet.

US-based social media sites also do this but TikTok's Chinese parent company ByteDance has faced claims of being influenced by Beijing.   ... ;


Tuesday, March 21, 2023

BBC advises staff to delete TikTok from work phones

Security addressed  at the BBC

BBC advises staff to delete TikTok from work phones

Published, 22 hours ago, By Zoe Kleinman, Andre Rhoden-Paul & Chris Vallance

BBC News

The BBC has advised staff to delete TikTok from corporate phones because of privacy and security fears.

The BBC seems to be the first UK media organisation to issue the guidance - and only the second in the world after Denmark's public service broadcaster.

The BBC said it would continue to use the platform for editorial and marketing purposes for now. TikTok has consistently denied any wrongdoing.   The app has been banned on government phones in the UK and elsewhere.

Countries imposing bans include the US, Canada, New Zealand and Belgium, while the same applies to anyone working at the European Commission.

However, it is still permitted on personal devices.

The big fear is that data harvested by the platform from corporate phones could be shared with the Chinese government by TikTok's parent company ByteDance, because its headquarters are in Beijing.

TikTok says the bans are based on "fundamental misconceptions".

ByteDance employees were found to have tracked the locations of a handful of Western journalists in 2022. The company says they were fired.  Alicia Kearns, who chairs the Foreign Affairs Committee, was asked for her view on the BBC's decision, and tweeted: "If protecting sources isn't a priority, that's a major problem."

'Encouraging TikTok, not banning it'

Dominic Ponsford, editor-in-chief of journalism industry trade publication the Press Gazette, said it would be interesting to see what other media organisations decide to do.

He told the BBC: "I suspect everyone's chief technical officer will be looking at this very closely.

"Until now, news organisations have been very keen to use TikTok, because it's been one of the fastest-growing social media platforms for news publishers over the last year, and it's been a good source of audience and traffic.

"So most of the talk in the news media has been around encouraging TikTok rather than banning it."

BBC taking security 'incredibly seriously'

The short-video platform is known for its viral dance crazes, sketches and filters and is hugely popular among young people, with more than 3.5 billion downloads worldwide.  Channel 4 News presenter Krishnan Guru-Murthy tweeted in reaction to the decision: "BBC News making big play for views on TikTok but now the BBC is telling staff not to have it on their phones".

A BBC spokesperson said it took the safety and security of its systems, data and people "incredibly seriously".

TikTok banned from official UK government phones

How much data does TikTok collect?.... '

Security Robotics

Basic physical security is needed. 

Robots are your new office security guard

Jennifer A. Kingson

Cobalt Robotic

They stand five feet tall and glide at three miles per hour, patrolling office buildings for everything from broken fire alarms to suspicious activity: Security robots are starting to replace human guards in workplaces and beyond.

Why it matters: Despite some hiccups, robots armed with sensors and artificial intelligence are making inroads in diverse fields — from window washing and pizza making to bartending and caring for the elderly.

Driving the news: Lower costs mean it's now substantially cheaper for companies to use robots than traditional guards for 24/7 security.

Robots can check in visitors and issue badges, respond to alarms, report incidents, and see things security cameras can't.

Security robots don't get bored, tired, or distracted by their phones — and it's safer for them to confront intruders and other hazards.

Two-way communications systems allow employees to report problems or request human help by talking to the robot.

By the numbers: Using a robot guard vs. a human can save a company $79,000 per year, according to a recent report by Forrester Research.

What they're saying: "All this money has really poured into service robotics because of the money that has gone into autonomous vehicles," says Mike LeBlanc, president and COO of Cobalt Robotics, which is leading the charge to populate offices with non-human security guards.

Two views of a Cobalt Robotics robot in the office, showing how it roams hallways and has an interactive tablet that allows people to communicate with a call center.

At left, a Cobalt Robotics unit prowls hallways to scout for problems and allows people to report concerns. At right, an employee uses the robot's tablet to communicate with a specialist at a remote call center. Photos courtesy of Cobalt Robotics.

How it works: Cobalt's robots are built to the specifications of a particular building's ramps and elevators.

They roam hallways looking for possible problems — like unusual motion at night or a door that's been propped open — and report back to a human-staffed call center.

"They have fabric, so they're designed to look like a piece of high-end office furniture," LeBlanc tells Axios. "And they have a tablet on the front that allows people to interact with our 24/7 specialists at any given time."

"People can tap on the screen of the robot, a person will come up on the screen, and they'll be able to ask them what's going on," LeBlanc said. "They can say, 'There's a leak or spill over here,' or 'There's someone in the office who's making me uncomfortable.'"

Case study: Food delivery startup DoorDash is using Cobalt robots across its corporate sites, for everything from COVID-19 temperature checks to routine security patrols, alarm responses, and security escort services.  ...'


Friday, March 17, 2023

ChatGPT Powered Polyorphic Malware Bypasses Filters

Security issues to be resolved. 

ChatGPT Powered Polymorphic Malware Bypasses Endpoint Detection Filters    By Guru- March 15, 2023

The number of monthly users of ChatGPT exceeded 100 million at the end of January, which sets a new record for the fastest-growing app since it was launched at the end of 2022.

OpenAI’s ChatGPT is a natural language processing tool that uses AI to process text and is developed by OpenAI. However, recent research revealed that ChatGPT could build code that can be used maliciously.

Jeff Sims, who works at the HYAS Institute, has created a polymorphic keylogger using artificial intelligence called “Blackmamba,” which uses Python to tweak its program randomly based entirely on the input that has been taken from the user.

As a result of Jeff’s malicious prompt, text-davinci-003 created a keylogger in Python 3. To accomplish this, Jeff had to use the python exec() function to “dynamically execute Python code at runtime.”

Writing Unique Python Scripts

Whenever ChatGPT / text-davinci-003 is called, a unique Python script is written for the keylogger. Consequently, as a result, it becomes polymorphic, making it harder for the EDRs to block the result.

In addition, the hackers could use ChatGPT to modify the code, resulting in a highly evasive code that was difficult to detect. 

Even they were also able to generate programs that could be used by ransomware and malware developers to launch attacks.

Jeff’s BlackMamba keylogger is being used to collect sensitive information over trusted channels, using MS Teams as a malicious communication platform.  .... ' 

Friday, March 10, 2023

Collaborative Robots and their Security

Collaboration among robots and further with humans, will become crucial

Cobots and their security

Fending off Cyberattacks on Collaborative Robots  (CoBots)

By David Geer, Commissioned by CACM Staff, February 28, 2023

Collaborative robots (known as cobots) are used in a wide variety of ways and in very diverse application areas.

Collaborative robots, or cobots, count on Internet of Things (IoT) devices, telemetry data, software programming, and remote control for operation, productivity, and safety. These systems and devices present unique opportunities for attack.

Cyberattacks use IoT and Industrial IoT (IIoT) device vulnerabilities to gain unauthorized access to cobots. "IoT and IIoT devices connect to cobots via TCP/IP Ethernet to communicate inputs and instructions and to gain data," says Jim McKenney, practice director, Industrials & Operational Technologies at NCC Group, a cyberthreat management company.

According to McKenney, IoT devices collect a range of data from cobots, including performance metrics such as speed, accuracy, and energy consumption. The devices and data are vulnerable if someone has improperly configured those or if the security is weak, he says.

Vulnerable devices enable hacker reconnaissance of cobot systems. "Cybercriminals can collect information about the cobot's configuration, operating system, or communication protocols to develop customized malware," says Yair Attar, co-founder and CTO of OTORIO, an Operational Technology (OT) environment monitoring provider.

Malware inserts backdoors in systems, providing criminal hackers with remote access. Cybercriminals use command and control servers and bots to orchestrate automated attacks, leveraging and increasing access across networks and devices. Cobots are connected devices, a form of IIoT. The basic principles of attack on them do not differ from any other network-based attack. 

In fact, cobots are not necessarily the primary targets in these attacks. "Malware can spread laterally to devices on the network, causing wide, detrimental effects," says Francis Dinha, co-founder and CEO of OpenVPN, Inc.,  a private networking and cybersecurity company with clients in IoT.

Criminal hackers can live off the land, using remote control tools IT has already installed with the cobots, such as Secure Shell (SSH).

Attackers can use cobots' SSH connections for remote access to change uncompiled scripted code or gcode files to reconfigure the cobot to perform all the wrong motions, explains Michael Nizich, director of the Entrepreneurship & Technology Innovation Center and Cyber Defense Education at New York Institute of Technology.

While some cobot installations don't have SSH access, others have advanced SSH connections, according to Nizich, depending on the control board, operating system, and other installation factors.

"Advanced SSH connection support provides an outside user full access to the robot's operating system and controls and the software and scripts on the system that control the cobot's behaviors," says Nizich.

Unfortunately, it is often trivial for criminal hackers to learn these connection options and find cobots to attack. "Many times, vendors publicly advertise the features of software and hardware systems to make them more attractive from a sales perspective. Users discuss the intricate details of the system's functionality on blogs and vlogs as they attempt to troubleshoot issues with the help of other system users," explains Nizich.... '  .... 

Tuesday, March 07, 2023

Protecting AI From Hackers or can AI Provide Better Threat Protection?

Big problem.   It has been suggested too that AI methods can be used to provide smart protection,  but early results seem to indicate this is harder than expected.

These Experts are Racing to Protect AI from Hackers. Time is Running Out  By ZDNet, February 24, 2023

Said Bruce Draper, a program manager at the U.S. Defense Department's Defense Advanced Research Projects Agency, "We want to give everyone the opportunity to defend themselves."

Bruce Draper bought a new car recently. The car has all the latest technology, but those bells and whistles bring benefits -- and, more worryingly, some risks. 

"It has all kinds of AI going on in there: lane assist, sign recognition, and all the rest," Draper says, before adding: "You could imagine all that sort of thing being hacked -- the AI being attacked."

It's a growing fear for many -- could the often-mysterious AI algorithms, which are used to manage everything from driverless cars to critical infrastructure, healthcare, and more, be broken, fooled or manipulated? 

What if a driverless car could be fooled into driving through stop signs, or an AI-powered medical scanner tricked into making the wrong diagnosis? What if an automated security system was manipulated to let the wrong person in, or maybe not even recognize there was ever a person there at all? 

As we all rely on automated systems to make decisions with huge potential consequences, we need to be sure that AI systems can't be fooled into making bad or even dangerous decisions. City-wide gridlock or essential services being interrupted could be just some of the most visible problems that could result from the failure of AI-powered systems. Other harder-to-spot AI system failures could create even more problems.

From ZDNet   View Full Article    

Friday, March 03, 2023

Voice Authentication Method Fooled

Generative systems allow for the fine tuning of that generation, so need to be carefully used:  

Fooling a Voice Authentication System with an AI-Generated Voice  a reporter used an AI synthesis of his own voice to fool the voice authentication system for Lloyd’s Bank ... 

Brought to me via Schneier, where there is much more expert opinion.