Blog

  • Italian regulator fines Facebook £8.9m for misleading users

    Italian regulator fines Facebook £8.9m for misleading users, company criticised over data misuse and ordered to issue an apology on its website and app

    Facebook has been fined €10m (£8.9m) by Italian authorities for misleading users over its data practices.

    The two fines issued by Italy’s competition watchdog are some of the largest levied against the social media company for data misuse, dwarfing the £500,000 fine levied by the British Information Commissioner’s Office in September – the maximum that body was able to issue.

    The Italian regulator found that Facebook had breached articles 21, 22, 24 and 25 of the country’s consumer code by:

    The company was specifically criticised for the default setting of the Facebook Platform services, which in the words of the regulator, “prepares the transmission of user data to individual websites/apps without express consent” from users.

    Although users can disable the platform, the regulator found that its opt-out nature did not provide a fully free choice.

    As an additional penalty, the authority has directed Facebook to publish an apology to users on its website and on its app.

    In a statement, a Facebook spokesperson said: “We are reviewing the Authority’s decision and hope to work with them to resolve their concerns. This year we made our terms and policies clearer to help people understand how we use data and how our business works. We also made our privacy settings easier to find and use, and we’re continuing to improve them. You own and control your personal information on Facebook.”

    Italy’s antitrust authorities have pressed hard against Facebook for data misuse. In 2017, the same authority issued a €3m fine against the company for “inducing” users of its WhatsApp messaging service to share data with the main Facebook app.

    In that ruling, the regulator criticised WhatsApp for misleadingly implying that users could continue to use the service only if they agreed to the data transfer.

    The fine issued on Friday is only Facebook’s second since the Cambridge Analytica scandal brought the company’s data protection practices to wider attention in March this year. But other regulators, including those in Ireland and California and the US Federal Trade Commission, have expressed interest in the company’s practices.

    In Ireland, an investigation into a data breach affecting 50m accounts could result in a fine of up to $1.6bn (£1.25bn) under the new regime established by the General Data Protection Regulation, which came in to force in May. However, Rowenna Fielding, a senior data protection lead at Protecture, warned that this sum was “a ceiling, not a stipulation”.

    News Source: https://www.theguardian.com

  • IoT Could Expand Cyberattack Surface by Bringing Offline Legacy

    IoT Could Expand Cyberattack Surface by Bringing Offline Legacy Infrastructure Online. Digital transformation is the latest jargon in the industry and there is probably no process across the globe that is not integrating new age technologies in their way of functioning.

    Nevertheless, while technologies like artificial intelligence (AI), Internet of Things (IoT), machine learning (ML) and big data analytics are doing a world of good, cybersecurity is a major concern when talking of these technologies as well. In an exclusive interview with DataQuest, Mr Ashish Sharma, Partner, Deloitte India, shares his views on the impact the above mentioned technologies have had on cybersecurity, some of the initiatives taken by the government, and the challenges faced by the cybersecurity industry in the current scenario.

    Impact of New Age Technologies on Cybersecurity Scenario

    New age technologies viz. Artificial Intelligence (AI), Blockchain, Internet of Things (IOT), 3D printing, Robotics, etc. have the potential of revolutionising the industries. While the results of these technologies are path-breaking, the cybersecurity vulnerabilities are also on the rise. One may owe this to the inadequate research for securing emerging technologies, absence of industry guidelines/frameworks, unclear responses from regulators on the adoption of technology or security guidelines, increase in attack surface or inability of the legacy infrastructure to secure new age technology riding on it, etc.

    For example, adopting IoT introduces a vast number of devices to an organisation’s network. The chances of exposure increases since IoT massively expands the attack surface by bringing the previously offline legacy infrastructure to the internet. Similarly, AI technologies are helping to solve today’s toughest business problems. However, the risk of an algorithm changing its course due to unauthorized interventions has been concerning to the industry.

    Preparedness of Current Indian IT Industry in Handling Technological Advancements like Blockchain, IoT, and Artificial Intelligence in terms of Cybersecurity

    Focus on Cybersecurity has been critical for both the Government and the Industry. Regular global cyber hacks have ensured that Cybersecurity is a topic in the Senior Government circles and amongst the Board of Directors in various companies.

    The adoption of the latest technological advancements such as AI, IoT etc. is not only driven by organizations in India but are also being the focus areas of the Indian government. For instance, the Government of India has proposed a multi-dimensional approach in its draft IoT policy to develop the IoT market in India by 2020.  Similarly, recognising AI’s potential to transform economies and the need for India to strategize its approach, Hon’ble Finance Minister, in his budget speech for 2018 – 2019, mandated NITI Aayog to establish the National Program on AI with a view to guiding the research and development in new and emerging technologies. The discussion paper on National Strategy for Artificial Intelligence (June 2018) suggests establishing data protection frameworks and sectorial regulatory frameworks, and promotion of adoption of international security standards.

    Importance of Data Breach Prevention

    Data breach prevention should be planned in two ways; by design and by operation. Organisations should develop a mind-set that has privacy at the forefront of the design, built and deployment of new technologies. Organizations have traditionally focused their investments on becoming secure. However, this approach is no longer adequate in the face of the rapidly changing threat landscape. Put simply, organizations should consider building cyber risk management programmes to achieve three essential capabilities namely: the ability to be secure, vigilant and resilient.

    A good understanding of known threats and controls, industry standards and regulations can guide organizations to secure their systems and data through the design and implementation of preventative, risk intelligent controls. Based on leading practices, organizations can build a ‘defence-in-depth’ approach to address known and emerging threats. This involves a number of mutually reinforcing security layers both to provide redundancy and potentially slow down the progression of attacks in progress, if not prevent them.

    The Reskilling Challenge Faced by Cybersecurity Industry

    Skilled workforce plays a vital role in cybersecurity as they impact an organization’s ability to protect its data, systems and operations. Getting a trained/experienced cybersecurity workforce remains a significant challenge for organizations. According to the 2017 Global Information Security Workforce, there is expected to be a shortage of 1.8 million workers in cybersecurity by 2022. With the rapid adoption of new technologies by organizations, the requirements for security experts in these fields have also risen. Whether it’s in the domain of cyber-security for AI, Blockchain or IoT, innovative employees who know how to protect digital information and can translate that knowledge into solving real-world security problems are in demand by both the private and public organizations. And that demand will continue to increase. Conventional education and policies may not adequately meet such demands.

    Upskilling and reskilling should be a constant effort in modern information security programs within every organization. Organizations should allocate sufficient budget specifically for training and certifications of their information security workforce and annual training calendars should be drafted for the wider organization.

  • What do the cloud wars mean for enterprises in 2019?

    What do the cloud wars mean for enterprises in 2019? In reviewing a year of heated and varied competition, there are two key themes that have emerged as central to 2018’s cloud wars, and which help set the stage for 2019.

    The market for public cloud services is on the upswing.

    According to Gartner, it’s projected to be worth over $200 billion in 2019. Of the market segments that comprise public cloud, Infrastructure as a Service (IaaS) is the fastest-growing, with expected growth of more than 27 percent next year.

    This market growth prompts the question: Which monolithic corporation will lay claim to the largest share? The answer is that it’s an ongoing race. But as three corporate giants contend for cloud dominance — and niche players give them a run for their money — what are the implications of the cloud wars for enterprise customers, both in 2019 and beyond?

    Cloud wars: A brief rundown

    Over the past few years, there’s been a battle for control of the cloud among three market leaders: Amazon, Microsoft and Google. And while Amazon could have laid claim to the title back in 2015 — with a 30 percent IaaS market share at the time — the race has become much tighter in the years since, both due to the acceleration of Microsoft and Google’s offerings and the evolution of new and growing cloud providers.

    In 2017, Microsoft posted a cloud revenue of $18.6 billion, surpassing Amazon. As former Oracle Chief Communications Officer Bob Evans pointed out in a 2017 piece for Forbes, one reason Microsoft edged out Amazon is because of the breadth of its offerings: Whereas Amazon’s product has largely focused on IaaS, Microsoft has taken a more holistic approach to building out its Azure Stack, focusing on Platform as a Service (PaaS) and Software as a Service (SaaS) offerings.

    But it’s not just the expected enterprises that are fuelling the cloud wars; once-small players like IBM, Oracle and Alibaba are helping to expand the competitive landscape. Oracle in particular has made significant strides in its cloud marketplace. In its 2018 Q3 earnings summary, Oracle reported that IaaS revenue growth was up 28 percent year-over-year. The upward trajectory of traditionally niche players like Oracle coupled with heated competition among the big three has made 2018 a transformative year for the cloud.

    Key cloud war takeaways heading into 2019

    In reviewing a year of heated and varied competition, there are two key themes that have emerged as central to 2018’s cloud wars, and which help set the stage for 2019:

    Moving into 2019, Oracle’s focus on the database will likely pay off with a bigger market share. For enterprise IT leaders in particular — who are often very discerning in terms of identifying a solution that aligns with and augments their overall strategy — Oracle’s focus on its database, enterprise applications and features will be a differentiator. Oracle’s enterprise focus, coupled with the relative newness of its offering, places it in a unique position to take a potentially significant market share from The Big Three in the new year.

    How enterprise customers can maximise the cloud wars

    As the cloud wars rage into 2019, what does this mean for enterprise customers? Can businesses looking to leverage a cost-effective, features-rich and scalable cloud platform use the cloud wars to their advantage?

    The answer is yes — but only if enterprises pursue IT spending and cloud computing strategically. Here are some important cloud computing considerations enterprises should bear in mind as they prepare for the new year:

    By working strategically to build a multi-cloud strategy — and proactively working to manage it — enterprises can take advantage of the cloud wars’ stiff competition, channelling competing solutions into a hybrid architecture that meets the needs of their business.

  • Half of business leaders unaware of BPC cyber attacks

    Half of the business leaders are unaware of BPC cyber attacks. Half of the management teams polled in 12 countries, including the UK, are unaware of business process compromise (BPC) attacks.

    Despite 43% of organizations surveyed in 12 countries admitting they have been affected by a business process compromise business process compromise (BPC) attack, they are not on the radar of 50% of management teams.

    Half of the management teams polled did not know what these attacks are or how their business would be affected if they were targeted, according to a survey commissioned by cybersecurity firm Trend Micro.

    The study carried out by Opinium surveyed more than 1,000 IT decision-makers responsible for cybersecurity across the UK, US, Germany, Spain, Italy, Sweden, Finland, France, Netherlands, Poland, Belgium, and the Czech Republic.

    In a BPC attack, cybercriminals typically look for loopholes in business processes, vulnerable systems, and susceptible practices. Once a weakness has been identified, a part of the process is altered to benefit the attacker, without the enterprise or its client detecting the change.

    According to Trend Micro, 85% of organizations targeted by BPC attacks would be prevented from offering at least one of their business lines.

    “We’re seeing more cybercriminals playing the long game for greater reward,” said Rik Ferguson, vice-president of security research for Trend Micro.

    “In a BPC attack, they could be lurking in a company’s infrastructure for months or years, monitoring processes and building up a detailed picture of how it operates.”

    Once the cybercriminals have a foothold and have built a detailed picture of the target organization’s operations, Ferguson said they can insert themselves into critical processes, undetected and without human interaction.

    “For example, they might re-route valuable goods to a new address, or change printer settings to steal confidential information – as was the case in the well-known Bangladeshi Bank heist,” he said.

    In this attack, cybercriminals showed that they had a strong grasp of how the Swift financial platform works and had knowledge of weaknesses in partner banks that use it. By compromising the Bangladesh Central Bank’s computer network, cybercriminals were able to trace how transfers were done and seize the bank’s credentials to conduct unauthorized transactions.

    The survey revealed, however, that although half of the management teams are unaware of BPC attacks, security teams are not ignoring this risk, with 72% of respondents stating that BPC is a priority when developing and implementing their organization’s cybersecurity strategy.

    But the study report warns that the lack of management awareness around this problem creates a cybersecurity knowledge gap that could leave organizations vulnerable to attack as businesses strive to transform and automate core processes to increase efficiency and competitiveness.

    The most common way for cybercriminals to infiltrate corporate networks is through a business email compromise (BEC). This is a type of scam that targets email accounts of high-level employees related to finance or involved with wire transfer payments, either spoofing or compromising them through keyloggers or phishing attacks.

    In Trend Micro’s survey, 61% of organizations said they could not afford to lose money from a BEC attack. However, according to the FBI, global losses due to BEC attacks have continued to rise since December 2016, reaching $12bn earlier this year.

    “To protect against all forms of BPC attacks, business and IT leaders must work together to put cybersecurity first and avoid potentially devastating losses,” said Ferguson.

    “Companies need protection beyond perimeter controls, extending to detect unusual activity within processes if attackers breach the network. This includes locking down access to mission-critical systems, file integrity monitoring, and intrusion prevention to stop lateral movement within a network.”

    According to Trend Micro, there are three main types of BPC attacks: diversion, piggybacking, and financial manipulation.

    Diversion attacks refer to those where attackers exploit security gaps in the organization’s cash flow system. Threat actors are then able to transfer money to supposedly legitimate channels.

    In piggybacking attacks, criminals take advantage of key business processes, such as the transportation of illegal goods and the transfer of malicious software, which translates to big financial gains for the attackers.

    Financial manipulation attacks include those that aim to influence financial outcomes and important business decisions such as acquisitions. Attackers do this by introducing malicious variables into a key business system or process.

    To defend against BPC attacks, Trend Micro recommends that organizations:

  • Microsoft is embracing Chromium bringing Edge to Windows 7 and others

    Microsoft is embracing Chromium, bringing Edge to Windows 7, Windows 8, and macOS.  Microsoft yesterday embraced Google’s Chromium open source project for Edge development on the desktop. The company also announced it is decoupling the browser updates from Windows 10 updates, and that Edge is coming to all supported versions of Windows and to macOS.

    Microsoft launched Edge in July 2015 as the default browser for, and exclusive to, Windows 10. But it never saw much adoption. Sure, Microsoft claimed Edge had 330 million active devices back in September 2017, but it never did reveal an active user figure beyond “hundreds of millions” (Google said Chrome passed 1 billion active users in May 2015). Edge has 4.34 percent market share today, according to the latest figures from Net Applications.

    So Microsoft wants to make some big changes, which it says will happen “over the next year or so.” The first preview builds of the Chromium-powered Edge will arrive in early 2019, according to Microsoft.

    Chromium-based Microsoft Edge

    Adopting the Chromium project means a lot more for Microsoft. The Edge rendering engine EdgeHTML will be swapped out for the Blink rendering engine. The Chakra JavaScript engine will be swapped out for V8. Microsoft will even take some of the UI stack, for use on non-Windows 10 platforms.

    Also worth noting: Microsoft is not forking Chromium.

    Microsoft hopes moving to Chromium will “create better web compatibility for our customers” and “less fragmentation of the web for all web developers.” The former is certainly true, as the Edge web platform will thus become aligned with web standards and other Chromium-based browsers. The latter is not true in the short term (plenty of testing will be needed to accommodate the switch) but it is likely in the long term, as developers will have one fewer browser to explicitly test against.

    No longer wasting resources on building Edge’s backend will likely turn out to be a big win for Microsoft. It is a lot of work to constantly update a browser engine to be standards-compliant and compatible with the actual web. Microsoft has decided to let the open source community do that instead, which it will participate in, so it can focus on improving the browser itself.

    Again, Edge isn’t changing significantly. This is an “under the hood” transformation, and most Edge users won’t notice anything significantly different — save for some sites working as expected.

    The future of EdgeHTML and Chakra

    Edge uses Blink/Chromium on Android and WebKit/WKWebView on iOS. Thus, when Edge on desktop moves to Blink and V8, the main use case for EdgeHTML and Chakra will disappear overnight.

    Windows 10 apps that use EdgeHTML and/or Chakra will be able to keep using them, according to Microsoft. But, Microsoft will also eventually let app developers leverage the Chromium-based solution that Edge will use. This will likely impact regular apps that render web content but also Progressive Web Apps (PWAs), which are essentially mobile websites that mimic native apps.

    App developers will thus be able to choose to keep using the legacy option or switch to Chromium. Microsoft says it has no plans to stop maintaining EdgeHTML and Chakra, although if usage were to decline, developers could expect them to hit end of support eventually.

    Chrome extensions

    In addition to better web compatibility, Edge users stand to benefit from support for Chrome extensions. Microsoft expects that it will be very easy for developers to bring their Chrome extensions to Edge. It might even be the case that it requires no work at all in most cases, but it’s too early for the company to say so definitively.

    Microsoft’s intention is to support existing Chrome extensions in Edge, but how exactly this will work remains to be seen. Keep in mind that for years now, Google has been locking down the Chrome Web Store and Chrome extensionsin general — Microsoft will have to be careful with its solution.

    All supported versions of Windows

    So far, all this largely makes sense, but Microsoft also wants to port Edge to all supported versions of Windows. Edge is no longer going to be a Windows 10-only affair.

    That means Edge is coming to Windows 7 SP1 and Windows 8.1. For Windows 10, this means the Chromium-based Edge and future updates is coming to Windows 10 version 1607, version 1703, version 1709, version 1803, and version 1809. Those are all supported versions of Windows, so they’ll be getting the latest version of Edge until Microsoft ends support.

    Microsoft also currently supports Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server version 1709, Windows Server version 1803, Windows Server version 1809, and Windows Server 2019. The company hasn’t yet said if the latest version of Edge is coming there too.

    This is a massive undertaking that one can only justify through a corporate lens. It’s about letting IT departments offer a heterogeneous browser environment. Microsoft wants everyone on the latest version of Windows, but for those that cannot, or refuse to, upgrade, it has decided to bring the latest Edge to them. That means bringing Edge to older versions of Windows, including older versions of Windows 10. Within major organizations, there are computers running all sorts of Windows versions, and right now only a single one can get the latest version of Edge.

    macOS

    If you thought supporting old Windows versions was nuts, your jaw will drop when you hear Microsoft also wants to bring Edge to macOS. This is bizarre for several reasons, not even including that Microsoft ceased development of Internet Explorer for Mac in June 2003 and Apple killed Safari for Windows in July 2012. But the same heterogenous environment thinking applies: Microsoft wants all devices in an organization using the latest Edge, and that requires getting Macs onboard.

    Indeed, Microsoft doesn’t expect to get a lot of Mac users switching to Edge, the company said. Instead, the company simply wants to make it easier for more developers, many of whom use Macs, to test against Edge. Bringing Edge to macOS is about developers, not market share.

    More frequent updates

    Edge is updated every six months. Chrome and Firefox, meanwhile, are updated every six weeks.

    Even if you do have the latest Windows 10 version, Edge updates today are tied to Windows 10 updates, and half a year is a long time on the web. It’s a long time to wait for compatibility fixes, performance improvements, and new features.

    Could Edge get more frequent updates than Chrome and Firefox? I’m not holding my breath. But Microsoft does say that agility will be a focus going forward and does expect “a more frequent cadence” than the current six-month wait.

    Chrome updates hit Windows, Mac, and Linux all on the same day, while Firefox updates hit Windows, Mac, Linux, and Android on the same day. Microsoft wants the version of Edge on Windows and Mac to be the same, but we’re hearing it’s too early to commit to same-day updates across all supported versions of Windows and macOS.

    Chromium contributions

    Microsoft says it intends to become a “significant contributor” to the Chromium project. The company will try to improve Chromium not just for Edge, but for other browsers as well, and not just for PCs, but for other devices too.

    The priority will, however, be web platform enhancements to make Chromium-based browsers better on Windows devices. Microsoft stands to benefit if the web works well on Windows, as the impact trickles down to its customers, partners, and the overall business.

    Last month, Microsoft was spotted making contributions to the Chromium project for ARM-based Windows devices. The thought at the time was that Chrome was being ported to Windows 10 on ARM, but now we know Microsoft was thinking bigger. (Chromium-based browsers are 32-bit only, meaning they run emulated and negatively impact battery life. Microsoft wants to fix for all Chromium-based browsers, including Chrome and Edge.)

    Microsoft intends to continue work on ARM64 support, but it also hopes to improve Chromium’s web accessibility and take advantage of other hardware features like touch support. Indeed, Edge is the only major browser with a 100 percent HTML5Accessbility score and is known for having solid touch scrolling performance.

    In fact, Microsoft doesn’t want to switch to Chromium until some of that functionality has been contributed to the project. That way, Edge won’t lose features when the switch happens next year.

  • Amazon Web Services Customers Can Hack AWS Cloud And Steal Data

    Amazon Web Services Customers Can Hack AWS Cloud And Steal Data, Says Oracle CTO Larry Ellison.

    (Note: After an award-winning career in the media business covering the tech industry, Bob Evans was VP of Strategic Communications at SAP in 2011, and Chief Communications Officer at Oracle from 2012 to 2016. He now runs his own firm, Evans Strategic Communications LLC.)

    CLOUD WARS — Oracle founder Larry Ellison this week said businesses using arch-rival Amazon’s AWS cloud have become major cybersecurity threats because the AWS cloud architecture allows them to see and steal data belonging to other customers using the AWS cloud.

    Ellison made the remarks in a keynote at Oracle’s annual OpenWorld conference on Monday while extolling the advantages of Oracle’s new Generation 2 Cloud versus traditional cloud architecture such as what he said Amazon currently uses.

    The comments were striking because while cybersecurity has unquestionably become one of the major issues for business leaders in our increasingly digital economy, the blame for cyberattacks and cybercrime has rarely been put on customers—instead, organized teams of cybercriminals and/or nation-states looking to exploit digital weaknesses in other countries have almost always been named as the culprits.

    But Ellison on multiple occasions cited AWS “customers” as the agents or potential agents of data manipulation, data exfiltration and data theft—and I’ll offer verbatim examples from his keynote in just a moment.

    Before getting to those verbatim comments, I want to offer a few thoughts that help provide some context for Ellison’s remarks—because while cybersecurity and cyberattacks have been a major theme in some of Ellison’s recent public presentations, he has never, as far as I can discover, cited “customers” as the bad guys.

    So let’s take a look at Ellison’s verbatim comments about customers as cyber threats and cybercriminals, which I transcribed from the video archive of his keynote address:

    Those are very strong words about the business customer that are using the enterprise cloud. I asked the Oracle spokesperson if she could share any data that supports what Ellison was saying—for example, does Oracle consider that 10 percent of customers engage in cybercrime in the way Ellison described, or is it 25 percent, or something higher?—but Oracle did not offer any such facts. Here’s the statement I received from Oracle:

    “The point is that  bad actor can pose as customers on any public cloud, so from the perspective of an actual customer, a bad actor is a “customer.”

    “You can have bad actors using cloud instances for distributing unlawful content or performing otherwise forbidden tasks (crypt mining) while paying for their cloud instances with stolen credit cards. You can also deal with sophisticated attackers who will attempt to make use of malicious code and known vulnerabilities in an attempt to break multi-tenant separation (recent highly publicized vulnerabilities come to mind). So…Yes. Bad actors posing as customers in the cloud are potential cyber threats. We prevent bad actors from committing nefarious acts. Bad actors posing as customers are to clouds, what insider threats are to traditional on-premises environments…

    “There is nothing stopping operatives from a rogue nation, for instance, from posing as a business of some kind, and opening an account with any public cloud vendor. From that standpoint, they are a customer – but they are also a bad actor who, once set up inside Microsoft or Amazon or Google cloud, to name a few, can start using malicious code to either mess with the infrastructure’s control code or attempt to move sideways to steal data from other (legitimate) customers.

    “From the standpoint of a legitimate customer, using such a less-secure-than-Oracle cloud vendor, that bad actor LOOKS LIKE A CUSTOMER.

    Since public cloud vendors aren’t the FBI or other law enforcement, they can’t be in the business of vetting the legitimacy of customer x or customer y.

    Thus, bad actors posing as “customers” are a potential threat agent that Oracle can protect its other customers from by, among other security measures, isolating control code from software that manages the virtual machines or bare metal servers used by other customers.” (End of Oracle response.)

    To be sure, those are all very reasonable thoughts. But Larry Ellison’s a very reasonable guy—so why didn’t he at least allude to a couple of these points during his hour-long keynote?

    So Oracle’s just unveiled a sophisticated new “Generation 2 Cloud” to help customers avoid becoming victims of cyberattacks in the cloud, and Oracle’s also warning its good customers to watch out for its bad customers and/or truly bad guys posing as customers.

    All in all, more proof that life’s never dull in the Cloud Wars.

    I’ve analyzed and written about the enterprise-tech business for more than 20 years from the media side as an editor-in-chief and chief content officer, and more recently as Chief Communications Officer at Oracle from 2012-2016. I’ve written thousands of articles and columns…MORE

    As businesses jump to the cloud to accelerate innovation and engage more intimately with customers, my Cloud Wars series analyze the major cloud vendors from the perspective of business customers.

  • Microsoft overtakes Amazon as second most valuable U.S. company

    Microsoft overtakes Amazon as second most valuable U.S. company. Microsoft Corp (MSFT.O) regained its spot as the second most valuable U.S. company on Friday after a disappointing quarterly report from Amazon.com (AMZN.O) wiped $65 billion off the online retailer’s market capitalization.

    Apple Inc (AAPL.O) tops the list at over $1 trillion after crossing that threshold in September. Microsoft’s market capitalization was Wall Street’s highest in late 1998 through early 2000 before the dot-com bubble burst.

    Amazon’s shares dropped 7 percent, the most in nearly three years after its holiday season sales outlook missed targets, fanning concerns that Wall Street’s tech darlings are finally starting to face stronger competition.

    Microsoft fell a more modest 1.1 percent in a broad technology sell-off that was also driven by a weaker-than-expected report from Google-parent Alphabet Inc (GOOGL.O), leaving the Nasdaq composite index .IXIC down 1.9 percent late Friday afternoon.

    (Graphic: Market cap – Apple, Amazon and Microsoft – tmsnrt.rs/2ORT0Yq)

    Shares of Microsoft remain up nearly 4 percent from Wednesday, when the four-decade-old software company beat quarterly profit expectations, driven by its cloud computing business that competes with Amazon’s.

    Its stock market value on Friday stood at $823 billion, on track to close above Amazon’s for the first time since April, when it gave up its spot as second largest company by market capitalization.

    Amazon was worth $805 billion on Friday, after falling below Microsoft’s in extended trade on Thursday. The drop was equivalent to the combined values of Target Corp (TGT.N) and Corning Inc (GLW.N).

    Amazon’s tumble left it up around 40 percent year to date, while Microsoft has gained about 25 percent in 2018. On Wednesday, Amazon’s stock traded at the equivalent of 70 times expected earnings, its lowest level since 2011.

    The average analyst price target for Microsoft puts its market cap at $963 billion, while the average price target for Amazon values it at $1.068 trillion.

  • Phishing attacks: Why is email still such an easy target for hackers?

    Phishing attacks: Why is email still such an easy target for hackers? The majority of cyber attacks begin with one simple phishing email. So will it ever be possible to close this door to hackers, once and for all?

    Email is incredibly useful, which is why we all still use it. But chief among its downsides (along with getting caught in a group-cc’d message hell) is that email remains one of the most common routes for hackers to attack businesses.

    Around one in every hundred messages sent is a malicious hacking attempt. That might not seem like a large figure, but when millions of messages are sent every day, it adds up — especially when it just takes one employee to fall victim to a phishing message and potentially lead to a whole organisation being compromised.

    For example, the cyber attack against the Democratic National Committee that led to thousands of private emails being exposed in the run up to the US Presidential election started with just one successful phishing email, while countless espionage and malware campaigns have also gained entry to organisations via an email-based attack.

    But if email leaves us so vulnerable to attempts at hacking, why do we stick with it?

    “Email is still the main way that two entities who may not have a relationship get together and communicate. Whether it’s a law firm communicating with a business or a candidate applying for a job, email is still the bridge to getting these entities communicating. It’s not going away,” says Aaron Higbee, co-founder and CTO at anti-phishing company Cofense.

    As long as email is here, phishing will also remain a problem — and while some phishing campaigns are really sophisticated and based around cyber criminals performing deep reconnaissance on targets, other email-based attacks aren’t so sophisticated — and yet are still worryingly successful.

    Locky ransomware was often delivered to targets in blank phishing messages containing just an attachment. In the vast majority of cases, people didn’t open this, but given how Locky was successful, it’s evident that a number of people did. Why did they click the attachment in a blank message?

    “At the end of the day, we’re people and sometimes we make mistakes. Even careful and aware people could and would click on malicious attachments. Why is that? Because education isn’t enough; people will continue to click on things that look suspicious,” said Liron Barak, CEO and co-founder at security company Bitdam.

    “We can definitely see there’s been a rise in email attacks in the last year. And something that I believe is that attackers are becoming more and more sophisticated — attacks are bypassing Microsoft, Gmail and other channels,” she adds.

    Many phishing and spam messages do get blocked by mail providers but there are those that continue to sneak through — especially into consumer mailboxes, despite the efforts of email providers.

    While enterprises might not think too seriously about the actions their employees take using their personal inboxes, it could have serious consequences; not only is it likely that employees will examine their own emails at the office, many people use their personal email addresses to conduct business activity — and that’s a security risk.

    “One of the lessons that comes up very regularly is that one thing people often do wrong is when they conduct official business out of a consumer mailbox as they often don’t understand there’s no defence there,” says Matthew Gardiner, director of product at email security company Mimecast.

    “The lesson is to have good security defences on your business email and then use your business email for business, not your consumer email. Because once they’re into your personal account, they could be loading malware onto the machine you use for both,” he says.

    So, when this provides a potential risk to businesses, why is the security of some consumer mailboxes still so relatively poor compared with their enterprise cousins?

    “One of the sadder situations is here we are protecting the enterprise and they’re getting the full focus and top knowledge to protect them — but then when you go down to consumers and even small businesses, they’re not really looked after by the security industry,” says Ken Bagnall VP of email security at FireEye.

    There’s also the fundamental problem around email that it’s relatively simple to spoof names and addresses, allowing attackers to claim to be anyone — perhaps celebrities offering prizes or your boss asking you to look at a document or to make a transfer.

    “There’s really no embedded security in the basic internet for email. So you can claim to be anyone and send an email and the average person will probably trust that,” says Gardiner.

    Add to that how the make-up of phishing messages is changing all the time and you have an evolving problem.

    “While we continually evaluate and improve our automated screening protocols to help protect users, spam is an industry-wide ongoing challenge. Bad actors and opportunistic promoters quickly alter their approaches, which makes it difficult for any vendor to address 100 percent of spam,” says Jeff Jones, senior director at Microsoft.

    There’s even whole underground marketplaces dedicated to conducting phishing attacks, with professional hackers offering their services to crack specific inboxes.

    “Trying to guess what the next step of the attackers will be will always leave us behind, because there’s someone else controlling the landscape and trying to evade us and thinking strategically about bypassing security,” says Bitdam’s Barak.

    Much of the issue lies with the fundamental way in which email works and how this method of communication has become so pervasive in our everyday lives.

    “For email based phishing to really go away, we’re going to have to come together as a world and say this email protocol that was designed decades ago, it just isn’t working anymore,” says Higbee.

    There is one system that could help and it’s called DMARC — short for “Domain-based Message Authentication, Reporting & Conformance. It’s an email authentication protocol that enables users to determine what a legitimate email is and what’s spam, complete with a reporting function for ongoing improvement and protection.

    Many have argued that it would massively release spam, but it still isn’t widely used in industry as it can be tricky to implement, actually blocking all messages if set up incorrectly.

    Another solution to this could be a reputation score system — something that Dr Ian Levy, technical director at the UK’s National Cyber Security Agency (NCSC) wants to encourage the industry to pick up. He argues that it could make differentiating between trusted sources and malicious sources much easier for users — therefore reducing the risk of phishing attacks.

    “We’re trying to get the industry to do a reputation score,” he says. For example, if an email address has been in use for years, has never sent a bad message that’s one thing; an email address registered today via a Tor node sending its first email may be something that should be treated with a little more caution, he argues.

    “We want to give people that reputation information about email accounts so they can make decisions.”

    But for now, this is just an idea and phishing attacks against email users are as successful as they ever were — and some are resigned to this continuing to be a problem for a long time to come.

    “I saw my first phishing email professionally in 1998 — and if I thought I’d still be working on this phishing problem in 2018, it would’ve seemed unimaginable,” says Cofense’s Higbee. “It’s such a huge challenge that in five or ten years from now, the email phishing problem will be the same as it is today.”

  • Tim Cook says tech’s dark side is real

    Tim Cook says tech’s dark side is real and is hurting people and strong regulations are needed to protect user privacy, Apple said in a speech in Brussels on Wednesday.

    Details: As promised, Cook praised Europe for passing its GDPR protections. He also called on the U.S. to enact “a comprehensive federal privacy law” consisting of at least 4 key planks:

    Cook also took aim at the companies that are profiting off the collection of user information, calling it a “data industrial complex.” He warned of the privacy implications of mass data collection, and criticized tech and government leaders who downplay tech’s negative impact on society.

    Key quotes:

    “Our own information, from the everyday to the deeply personal, is being weaponized against us with military efficiency. … Taken to its extreme, this process creates an enduring digital profile that lets companies know you better than you may know yourself.”

    “Rogue actors and even governments have taken advantage of user trust to deepen divisions, incite violence, and even undermine our shared sense of what is true and what is false. This crisis is real. It is not imagined, or exaggerated, or ‘crazy.'”

    “If we get this wrong, the dangers are profound. … We can achieve both great artificial intelligence and great privacy standards. It’s not only a possibility, it is a responsibility. In the pursuit of artificial intelligence, we should not sacrifice the humanity, creativity, and ingenuity that define our human intelligence.”

    Yes, but: The “data industrial complex” Cook refers to pays for much of the modern internet, helping Google, Facebook, and many other companies target ads and keep their services free.

    The bottom line: Supporters of meaningful privacy regulations can count on Apple’s backing, as the company continues to try to stand apart from other tech giants, particularly Google and Facebook.

  • Facebook to Pay $67.5 Million in Fees in Suit Over Shares

    Facebook to Pay $67.5 Million in Fees in Suit Over Shares. Facebook Inc. agreed to pay $67.5 million in legal fees so co-founder Mark Zuckerberg won’t have to explain in court why he dropped a plan to create non-voting shares to further his charitable efforts.

    Lawyers for a group of Facebook investors, who sought $129 million in fees for challenging the new share class, agreed to cut their demand by about half to resolve the case, according to a Delaware Chancery Court filing. The settlement may be paid by the company’s insurers, the filing shows.

    Zuckerberg was criticized for asking directors to create a class of non-voting shares so he could sell most of his Facebook stake to fund charitable works while still keeping control of the world’s largest social-media company. The board approved the new stock and a majority of all the company’s shareholders had backed the move before Zuckerberg decided to drop the effort last year.

    Zuckerberg was scheduled testify next month in Delaware about his reasons for dropping the plan to help a judge decide the value of investors’ efforts in fending off the move. Vanessa Chan, a spokeswoman for Facebook, declined to comment Wednesday on the accord over the fees.

    Investors’ Interests

    Objecting investors claimed victory after Zuckerberg nixed the proposal. They said they “challenged the reclassification in this hard-fought litigation’’ and deserved to be rewarded for achieving “the outcome they were seeking at trial.’’ Stuart Grant, one of the investors’ lawyers, declined to comment on the fee settlement.

    Earlier this year, a pension fund sued Facebook directors for being too accommodating to Zuckerberg’s non-voting share gambit and not working diligently enough to protect other Facebook investors’ interests.

    According to that suit, Zuckerberg, during a meeting with a special board committee considering the proposal, got real-time texts from director Marc Andreessen giving him a heads up on which of his arguments were gaining traction.

    “This line of argument is not helping,’’ Andreessen warned in one text. “The committee wants to do this. You don’t need to question that.’’ In another, the venture capitalist noted “NOW WE’RE COOKING WITH GAS.’’

    Those kinds of actions by supposedly neutral directors made the committee’s evaluation of the proposal “a charade that was designed to appease’’ Zuckerberg, the fund’s lawyers said in the suit against directors.

    The fee dispute was In re Facebook Inc. Class C Reclassification Litigation No. 12286, Delaware Chancery Court (Wilmington). The new investor case is United Food and Commercial Workers Union and Participating Employers Tri-State Pension Fund v. Zuckerberg, 2018-0671, Delaware Chancery Court (Wilmington).