Showing posts with label personal data security. Show all posts
Showing posts with label personal data security. Show all posts

Tuesday, October 29, 2019

SECURITY - Ransomware Hunting League Hero




"The Ransomware Superhero of Normal, Illinois" by Renee Dudley, ProPublica 10/28/2019

Thanks to Michael Gillespie, an obscure programmer at a Nerds on Call repair store, hundreds of thousands of ransomware victims have recovered their files for free.

This story was co-published with the Chicago Sun-Times and The Pantagraph.

ProPublica is a nonprofit newsroom that investigates abuses of power.  Sign up for ProPublica’s Big Story newsletter to receive stories like this one in your inbox as soon as they are published.


About 10 years ago, Michael Gillespie and several classmates at Pekin Community High School in central Illinois were clicking on links on the school’s website when they discovered a weakness that exposed sensitive information such as students’ Social Security numbers.  They quickly alerted their computer repair and networking teacher, Eric McCann.

“It was a vulnerability that nobody even knew about,” McCann said.  “They did a quick search on passwords and student accounts, and lo and behold, that file is sitting out there.”

A shy, skinny teenager whose hand-me-down clothes didn’t fit him, and who was often ridiculed by schoolmates, Gillespie was already working after school as a computer technician.  “He was full of information all the time,” McCann said.  “We’d bounce ideas off each other.  You could tell his passion for technology, for computers, for figuring out things.  That definitely made him stand out.”

Without crediting the students, school administrators closed the breach and changed everyone’s passwords.  Gillespie’s anonymous protection of the school’s cyberdefenses was a harbinger of his future.  Like a real-life version of Clark Kent or Peter Parker, the self-effacing Gillespie morphs in his spare time into a crime-foiling superhero.  A cancer survivor who works at a Nerds on Call computer repair shop and has been overwhelmed by debt — he and his wife had a car repossessed and their home nearly foreclosed on — the 27-year-old Gillespie has become, with little fanfare or reward, one of the world’s leading conquerors of an especially common and virulent cybercrime: ransomware.  Asked what motivates him, he replied, “I guess it’s just the affinity for challenge and feeling like I am contributing to beating the bad guys.”

Each year, millions of ransomware attacks paralyze computer systems of individuals, businesses, hospitals and medical offices, government agencies, and even police departments.  Often, files cannot be decrypted without paying a ransom, and victims who haven’t saved backup copies and want to retrieve the information have little choice but to pony up.  But those who have recovered their data without enriching criminals frequently owe their escapes to Gillespie.

The FBI and local law enforcement agencies have had little success in curbing ransomware.  Local departments lack the resources to solve cybercrime, and the ransoms demanded have often been below the threshold that triggers federal investigations.  Security researchers like Gillespie have done their best to fill the gap.  There are almost 800 known types of ransomware, and Gillespie, mostly by himself but sometimes collaborating with other ransomware hunters, has cracked more than 100 of them.  Hundreds of thousands of victims have downloaded his decryption tools for free, potentially saving them from paying hundreds of millions of dollars in ransom.

“He took that deep dive into the technical stuff, and he just thrives on it,” said Lawrence Abrams, founder of a ransomware assistance website called BleepingComputer.com.  “Every time a new ransomware comes out, he checks it out.  ‘Can it be decrypted?  Yes, it can be decrypted.  OK, I’ll make the decryptor.’  And it’s just nonstop.  He just keeps pumping them out.”

Gillespie downplays his accomplishments.  “IT [Internet Technology] moves so fast, there’s always something to learn, and there’s always someone better than you,” he said.

Gillespie’s tools are available on BleepingComputer.com, and they can be accessed through a site he created and operates, called ID Ransomware.  There, victims submit about 2,000 ransomware-stricken files every day to find out which strain has hit them and to obtain an antidote, if one exists.

As hackers and their corporate enablers, including cyber insurance providers and data recovery firms whose business models are based on paying ransoms, profit directly or indirectly from cybercrime, one of ransomware’s greatest foes lives paycheck-to-paycheck.  Under his internet alias, demonslay335, Gillespie tackles ransomware either in his downtime at Nerds on Call or at night in the two-story bungalow he shares with his wife, Morgan, and their dog, rabbit and eight cats.  Surrounded by pets, he lies on his living room couch, decoding ransomware on his laptop and corresponding with victims desperate for his help.

Although the FBI honored him in 2017 with an award for his website, it doesn’t systematically recommend ID Ransomware — meaning that some victims may never learn of a resource that could help them avoid paying a ransom.  Many of his friends, relatives and colleagues don’t know the extent of his war on ransomware.  “They do not have a clue because of Michael’s modesty,” said his wife’s grandmother, Rita Blanch.  “Honestly, I don’t think anyone in the family knows what he does for free.  I barely know.”  When he got the FBI award, she added, “I sent out a family text, and they’re like: ‘What?  What?  Our Michael?’”

McCann wasn’t aware of Gillespie’s accomplishments either.  “It kind of gives me goosebumps,” the teacher said.  “He’s sitting here doing all this for free.  That’s incredible.”

On a humid morning in July, Gillespie sat on his covered front porch.  His hair was pulled back into a low ponytail, and he sported scraggly facial hair and a V-neck striped shirt.  Brown leaves left over from the previous autumn and birdseed from a feeder were scattered on the ground.  Gillespie said hello to a cardinal — the Illinois state bird, he pointed out — and a squirrel with a “wonky eye.”  He said a family of groundhogs resides under the porch and eats from the front-yard mulberry tree, but they didn’t make an appearance.

He opened his Twitter account.  “Like right now, I have 58 PMs and 120 notifications,” he said.  Most were pleas for help from victims of a ransomware strain, STOP Djvu, which he can sometimes decrypt.

Gillespie’s love of computers and electronics started early.  His paternal grandmother, a video gamer, introduced him to online role-playing games such as RuneScape.  He played Donkey Kong Country on a used Super Nintendo that his uncle gave him.  As emergency services volunteers, his parents communicated with tornado spotters via ham radios.  His father, a land surveyor, taught him how to repair electronics by soldering the radios.

Gillespie gleaned from his mother’s father, a police lieutenant in Florida, the importance of protecting the public.  Reinforcing the message, his parents went out of their way on family trips to pass through Metropolis, Illinois, which proclaims itself to be Superman’s hometown, and pay their respects at the Man of Steel’s bronze statue.  Gillespie was also fascinated by cryptography.  He liked the idea of having secret codes that no one else could figure out — and cracking other people’s.

Struggling financially, his family sometimes had to move in with friends or relatives.  When he was in high school, his parents filed for bankruptcy in the Central District of Illinois, court documents show.

At Pekin High, he helped protect not only the website but also his classmates’ belongings.  One day, noticing that other students were pre-setting codes to the combination locks on their lockers for convenience, he pulled down on every lock in his aisle.  About a quarter of the lockers opened.  He left a Post-it note in each one, admonishing the user to be more careful.

By then, he and Morgan Blanch were becoming close.  They lived down the street from each other but didn’t become friends until their freshman year at Pekin.  They began hanging out at each other’s houses and messaging on Myspace.  They were both in the school show choir and eventually sang in a national competition on the Grand Ole Opry stage in Nashville, Tennessee.

Both sometimes felt like outcasts.  She was overweight.  Gillespie, she said, was “that one kid at school that everybody knows who they are because they’re weird or they’re the butt of people’s jokes.”

But they could rely on each other.  “We’d get annoyed because our other friends were more flighty,” she said.  “They weren’t dependable, whereas if Michael and I made a plan, we stuck to it.  And we liked that about each other.” They started dating during Christmas break of their junior year.

When he graduated in 2010, Gillespie was named a Prairie State Scholar and an Illinois State Scholar, based on his standardized test scores and class rank.  Instead of going to college, he began working full time at the Nerds on Call store in Normal, Illinois.  Even with financial aid, he said, college would have been too expensive, and he already had everything he wanted.  “I got a job, got a car, got a girlfriend.  Boom.  Life together,” he said.

“He just felt that he could learn better on his own than in a classroom setting,” Morgan Gillespie said.  “He doesn’t really like to be restrained by protocol or by doing the ‘typical’ route of things.  He likes to get in there and figure it out and do whatever it is he feels like he wants to do.”

She enrolled at Millikin University in Decatur, Illinois, but missed Gillespie and dropped out after two months.  They moved into a new apartment close to his job and were married in October 2012, with Rita Blanch officiating.  For the bachelor party, Gillespie and his Nerds on Call friends went to a nearby farm and shot up old computers with his father’s firearms.  “Nobody who was too tipsy got to hold the rifles, but we put a few rounds through some old monitors,” said his best man, former co-worker David Jacobs, who organized the party.

The couple honeymooned in Peoria, Illinois.  The next year, with a Federal Housing Administration loan for lower-income borrowers, they purchased their $116,000 bungalow in a working-class neighborhood in Bloomington, Illinois.  There they could hear Amtrak’s Lincoln Service roar by on its way to Chicago.

At Nerds on Call, Gillespie was known as the Swiss Army Knife for his versatility.  So when a client was hit by TeslaCrypt ransomware in 2015, Gillespie was assigned to recover the files.

He embraced the task.  Not only was it an opportunity to expand his skills, but he also objected to the very idea of paying a ransom.  “I say hell no,” he said.  “There’s all the stuff about how it’s funding terrorism, funding bad stuff.  But more so, it’s just encouraging [criminals] to keep going.”

Gillespie “lives so heavily in the tech world, I think having bad actors involved just bothers him,” Jacobs said.  “Sometimes it’s also a little bit of competition.  ‘It’s me versus the bad guys and I want to win.  I want to be able to outdo their schemes.’”

Gillespie immediately consulted BleepingComputer.com.  Established in 2004 by Abrams to provide free advice for any computer problem through tutorials and forums, it had become the go-to site for ransomware assistance.

Sure enough, a BleepingComputer member known as BloodDolly had figured out how to crack TeslaCrypt.  But Gillespie still had to create a key for the client, which required running complex software for hours or days at a time.  “I wanted to post a success story for one of my customer’s systems that was hit this week,” he proudly announced on the forum in August 2015.  “I’ve just successfully decoded a few sample files at home.  … My customer is going to be thrilled we can get her photos back.”

Gillespie realized that Abrams, BloodDolly and other ransomware researchers were overwhelmed with requests for help.  He soaked up everything they could teach him.  Soon he was running software from both his home computer and computers under his desk at work, generating customized keys for scores of TeslaCrypt victims who had posted on BleepingComputer or on social media.

“It was huge, it was insane,” Abrams recalled.  “We were cracking keys left and right.  And Michael got the bug from that.  He came to the site, started cracking keys, starting helping.”

Gillespie also began exchanging private messages on BleepingComputer with U.K.-based ransomware expert Fabian Wosar.  Wosar, now the chief technology officer of antivirus provider Emsisoft, was working to break other strains of ransomware, and he referred TeslaCrypt victims to Gillespie.  Wosar, too, shared his knowledge with Gillespie.

“Sometimes, when people seem genuinely interested, I just ask them if they want to come along,” Wosar said.  “I just open a screen share, and they can watch what I’m doing.  And I explain to them what I am doing and why, and what all this different stuff means.”

Wosar, Gillespie, Abrams and a handful of other volunteers worldwide began communicating over the messaging platform Slack, forming a group they dubbed the Ransomware Hunting Team.  Abrams would hear about a new type of ransomware through users’ posts on his website and send a sample to his teammates.  If they could solve it, they would.

Gillespie creates 90% of the decryptors available on BleepingComputer, Abrams said.  Since May, when Abrams began tracking statistics, decryptors on the site have been downloaded more than 320,000 times.

While BleepingComputer makes money from advertisers, members of the hunting team from time to time have discussed charging for their services.  Each time, “it left a sour taste,” Abrams said.  He recalled a mother who contacted him to say she’d lost photos of her son, a fallen Army veteran, to ransomware.  Abrams helped to decrypt her files.  “I couldn’t charge for that,” he said.

Wosar and Gillespie have each created more free, public decryptors than anybody else in the world.  The two have much in common: neither went to college and both consider themselves autodidacts, learning mostly from internet research.  Both found a home and friendships on BleepingComputer.  And both, Wosar said, suffer from imposter syndrome — feelings of inadequacy that persist despite their success.

“I think we’re all kind of misfits,” Wosar said, referring to members of the team.  “We all have weird quirks that isolate us from the normal world but come in handy when it comes to tracking ransomware and helping people.  That’s why and how we work so well together.  You don’t need credentials, as long as you have the passion and the drive to teach yourself the skills required.  And Michael clearly has it, right?”

As ransomware became increasingly prevalent, the Ransomware Hunting Team had trouble staying abreast of new variants.  “It just got to the point where we just couldn’t keep track any more,” Abrams said.

Gillespie quietly began working on a solution.  “I’m a programmer,” he said.  “What do I do?  I automate.”

At night, on his couch, Gillespie developed a site where victims could upload a ransomware-encrypted file and automatically learn what type it was, whether a decryptor existed and, if so, how to get it.  In March 2016, he launched ID Ransomware with an announcement on Twitter and on BleepingComputer.  “All too often after a ransomware attack, the first question is, ‘what encrypted my files?’, followed by ‘can I decrypt my data?’” he wrote.  “This web service aims to help answer those questions, and guide a victim to the correct information relating to their infection.”

The site took off immediately.  Victims, ransomware recovery firms and other researchers sent encrypted files for analysis.  When they submitted files infected by an unidentified type of ransomware, Gillespie added it to his database.  As before, he and other members of the team worked to create decryptors for newly discovered strains.  ID Ransomware currently can detect more than 780 strains, of which almost 40% have free decryptors, most of them developed by Gillespie or Wosar, and others by cybersecurity firms such as Kaspersky, Avast and Bitdefender.

He’s developed other free applications for victims, which are available on BleepingComputer.  RansomNoteCleaner removes ransom notes left behind after an infection — eliminating the time-consuming task of removing them manually — and CryptoSearch locates encrypted files and makes it easier to back them up, in the hope that a solution may someday be discovered.  ID Ransomware also cross-references the submitter’s IP address with Shodan, a site that can show a computer’s vulnerabilities.  If it detects an open port, which could have allowed the hackers in, ID Ransomware flags the vulnerability — and, like the notes Gillespie stuck in the high school lockers, suggests fixing it.

Gillespie worked nonstop.  “I felt like I never saw him,” his wife said.  “We would be hanging out in the evening, and he would be like, ‘Oh my gosh, I have to go do this.’ And he would just disappear for hours.”

Volunteers around the world have translated ID Ransomware into two dozen languages, from Swedish to Nepali.  Only 26% of submissions to the site have come from the U.S.  “He collects amazing data because so many people use it,” Abrams said.  “He has tons of information.  You can see statistics, trends, what kinds of attacks are happening and when.  Everyone uses it.”

Those users include law enforcement, on both sides of the Atlantic.  Europol and Netherlands police flattered ID Ransomware by imitation, launching a similar but less comprehensive site.  An FBI agent from the Springfield, Illinois, field office asked to meet Gillespie, and they got together with another agent at a local Panera restaurant.

“The first meeting was nerve-wracking for me because, you know, why does the FBI want to talk to me?” Gillespie recalled.  “I was so awkward at that meeting.  I wasn’t thinking, ‘Am I gonna get arrested.’  But I did have in the back of my mind, ‘Am I gonna say something stupid?’”

The FBI needed help.  Victims often don’t report attacks to the bureau because they don’t want investors or the public to learn of their security lapses.  In 2018, the FBI received only 1,493 reports of ransomware — compared with the 2,000 queries daily to Gillespie’s site from about 750 different IP addresses worldwide.

At first, the agents sought information about the origins of a specific ransomware attack, something Gillespie does not investigate.  Then they began requesting lists of IP addresses that had uploaded files to ID Ransomware, which could help identify victims, as well as ransom notes and other material.  Gillespie, who discloses on the ID Ransomware homepage that email or bitcoin addresses uploaded to the site may be shared with “trusted third parties or law enforcement,” complied.

His assistance appears to have paid off.  Gillespie said agents indicated to him that his information may have been instrumental in last year’s indictment of two Iranian hackers wanted in connection with SamSam ransomware, which paralyzed computer networks across North America and the U.K. between 2015 and 2018.  Although the suspects have not been arrested, it was the U.S. government’s first indictment of cyberattackers for deploying a ransomware scheme.

Gillespie continues to meet regularly with FBI agents.  He tips them off, for instance, when a ransom note or extension on a file uploaded to the site identifies the targeted business.  Cooperation from such victims could help law enforcement learn more about the source of the ransomware, he said.

Some other ransomware hunters are warier of the FBI.  Abrams expressed concern that, despite the ID Ransomware acknowledgment, there could be “repercussions” from victims who might be upset that Gillespie identified them to the bureau.  Gillespie “is a little too trusting” of law enforcement, Abrams said.  “I do think that he’s not very worldly and that he sees things a little more black and white than with a lot of shades of gray.  And I think in that case he could be easily manipulated and taken advantage of.”

In 2017, the FBI awarded Gillespie a Community Leadership Award for his “public service, devotion and assistance to victims of ransomware in the United States and Internationally.”  Gillespie prominently displays the award in his home.  In April 2018, he and his wife flew to Washington for the award ceremony, accompanied by his boss at Nerds on Call.  The joke around the office was that the boss “went with him to try to nerf anybody trying to recruit him,” said Gillespie’s former co-worker, Jacobs.  “He would be very difficult to replace.”

Philosophically opposed to charging victims, Gillespie keeps ID Ransomware free.  He put up a link for donations to help cover the costs of running the site, but he didn’t bother to register it as a nonprofit, which would have enabled donors to deduct gifts from their taxes.  Contributions were scarce.  One $3,000 donation through PayPal proved to be a scam — Gillespie speculated that it may have been revenge by hackers whose ransomware he disabled — and PayPal demanded the money back.  He couldn’t repay it and switched to another service.

Gillespie “doesn’t chase money,” Jacobs said.  “If he were chasing money, he would have been living on the East or West Coast by now and doing something for some company that we’d all heard of instead of a little service provider in the Midwest.  But he’s one of those guys, he operates very heavily on principle.”

To make ends meet, Gillespie supplemented his Nerds on Call salary with a 2 a.m. paper route, delivering the local newspaper on his bike.  While he had enjoyed having a paper route in junior high, the job now depressed him.  But the family bills were mounting, especially for health care.  Morgan Gillespie struggled with diabetes and other medical issues.  Over the years, Michael Gillespie noticed blood in his urine, and in the fall of 2017, his wife finally made him see a doctor.  The physician removed a tumor and diagnosed bladder cancer, which rarely affects young adults.  Gillespie took one day off for surgery and one to recover before returning to work.  He underwent immunotherapy treatment weekly for two months, and the cancer has been in remission since.  Although he was insured through Nerds on Call, the costs for his care still added up.

The couple reached a financial breaking point.  They racked up credit card debt and fell behind on payments on Morgan Gillespie’s Nissan.  They rotated which utility bills they would pay; one month their electricity would be turned off, and the next month it would be gas.  They surrendered the car to the bank, which sold it at a loss at auction and forced them to make up the difference.  Last year, around the time his wife lost her job as a nanny, they missed four mortgage payments on their house and began to receive foreclosure notices, Michael Gillespie said.

Gillespie said he’s considering charging other security researchers for the statistics he gathers on the site, but he will always keep the tools free for victims.  Friends and family members nagged Gillespie to collect fees from ID Ransomware users.  Even his wife’s grandmother, whom Gillespie calls “grammy,” brought it up.  “I try to not interfere in that area,” Rita Blanch said.  “Unless, being silly at times, when I would say to him, ‘Babe, you need to charge, you could, like, be rich.’”

Other relatives “have been like: ‘Why isn’t he charging?  Why isn’t he making money off of this?’” said his wife, who recently found a part-time job as a babysitter.  “They think it’s almost dumb, the fact that he does what he does.  But that was just never what the deal was for us.  He just doesn’t want to take advantage of people who are already being taken advantage of.”

Instead, his fellow ransomware hunters stepped in.  Abrams covered the $400 cost of obtaining a certificate that lets users know they’re downloading from a trustworthy site.  Wosar began donating to ID Ransomware, and his employer, Emsisoft, hired Gillespie part-time this year to create Emsisoft-branded decryptors.  The money enabled the Gillespies to catch up on mortgage payments.

“He’s doing so much, how do you not support him if you can?” Abrams said.

After dinner one summer evening, Gillespie took a visitor to the Normal office of Nerds on Call, one of the company’s three locations in central Illinois, nestled in a strip mall between a check-cashing store and a Great Clips hair salon.  Gillespie, who has worked for Nerds on Call for 11 years, has keys, so he was able to open the office and disable the alarm system.  In the back, behind the retail area, is his desk, adorned with framed photos of his cats.

As his wife’s relatives often remind him, he could earn three times as much somewhere else.  But he’s happy at Nerds on Call, which gives him the freedom to work on ransomware in his downtime.  This year, he figured out fixes for the STOP Djvu ransomware, which was infecting files through pirated software.  Victims — who were unlikely to seek law enforcement assistance since they were committing a crime themselves — continue to press Michael for help unceasingly.  “It’s borderline harassment,” he said.

His frustration with the deluge of entreaties occasionally boiled over in his tweets.  “Everything you could possibly need to know is IN THE FUCKING FAQ, and its in BIG BOLD RED LETTERS,” he once responded.  “I’m losing sleep, losing time at my job, losing fucking sanity at this point.”

Some STOP Djvu victims thanked Gillespie.  Adam Hegedus of Szolnok, Hungary, was surfing the internet on his girlfriend's laptop in August when he disabled the anti-virus and firewall protections.  Ransomware crippled the computer, and a text file demanded $1,000 to restore access.  Hegedus' girlfriend is a teacher, and her lesson plans, thesis and other important documents were encrypted.  Hegedus felt so guilty that he couldn't sleep, and he sought assistance from several forums, including BleepingComputer.com.  This month, Gillespie replied with some good news; he had a decryption key.  Hegedus called his girlfriend, who rushed home and was delighted to be able to use her files again.

"You cannot imagine how grateful I am," Hegedus wrote to Gillespie.  "Everything has been decrypted and this is only because of your hard work." Hegedus offered a donation, but Gillespie declined.

Gillespie hopes that someday his services will no longer be needed, because businesses and people will have learned proper cybersecurity.  “If the world had backups, then we wouldn’t have ransomware,” he said.

In the meantime, he said, he plans to keep plugging away, even as hackers and their enablers pile up profits.  “There’s a time in every IT person’s career where they think, ‘I’m on the wrong side,’” he said.  “You start seeing the dollar amounts that are involved.  But nah, I can’t say that I ever have.  I just don’t care to go that way.”

ProPublica research reporter Doris Burke contributed to this article.

Monday, July 22, 2019

PRIVACY - The Face Off

Yah.....lets trust software from a hostile nation that has been hacking and trolling America for years, and still trying to influence our political process.  NO WAY!

"How FaceApp highlights a gap in U.S. privacy protections" PBS NewsHour 7/18/2019

Excerpt

SUMMARY:  The growing popularity of FaceApp, a photo filter app that allows users to transform their features by adding or removing wrinkles, is sounding alarm bells among privacy advocates and lawmakers.  There are questions about how the images of people's faces could be used, especially as the app's company is based in Russia.  Amna Nawaz talks to the Center for Democracy & Technology’s Joseph Jerome.

Monday, January 21, 2019

SOCIAL MEDIA - The Threat of Intelligent Machines

"How to keep AI from turning into the Terminator" by Mark Surman, CNN Opinion 1/15/2019

On GPS: The threat of intelligent machines (video link)

Editor's Note: Mark Surman is the executive director of the Mozilla Foundation, a global community devoted to keeping the internet open and free.  The views expressed in this commentary are his own.  View more opinion on CNN.

Artificial intelligence (AI) has long occupied an outsized role in our collective imagination, in everything from pulp science fiction novels to James Cameron blockbusters.  When AI is the antagonist, it is corporeal and impossible to overlook, like the Terminator.  Even in the real world, discussions about rogue technology tend to focus on the overt and dramatic, such as Elon Musk's exhortations on Twitter that the dangers of AI rival the dangers of nuclear weapons.

Perhaps humankind is moving toward an oppressive artificial superintelligence.  In the meantime, artificial intelligence is already woven into our everyday lives.  It provides us with things we love and need, from productivity advice to movie recommendations.  Yet, when we don't carefully consider its impact on our democracies, our justice systems and our well-being, we open ourselves up to real risks.

The AI of today is invisible to most of us, yet ubiquitous.  One example we interact with frequently is recommendation engines on the internet -- the code recommending that next video on YouTube or a post on Facebook.  These algorithms pull together vast amounts of our personal data to learn about us and curate our experience online.  In this case, AI is simply your personal data mixed with the data of people with similar interests -- and then pointed back at you.

The result can be serendipitous and delightful.  It can also be dangerous.  Last year, Silicon Valley moguls opened up to New York Magazine about how today's social media is designed to addict users.  Using our data to manipulate us to stay on a site may or may not be pernicious in its own right.

But even if you don't worry about it for yourself, there is growing evidence that these systems tend to radicalize and polarize.  Last year, University of North Carolina at Chapel Hill researcher Zeynep Tufekci dubbed YouTube "the Great Radicalizer": view one anti-vaccination video, and YouTube will suggest a second; watch one factually incorrect political video, and YouTube will recommend a sequel.

Further, these algorithms can be gamed by humans to sow even more discord.  Data for Democracy researcher and Mozilla fellow Renee DiResta uncovered how anti-vaccine activists exploit Google's algorithm to spread dangerous disinformation.  How?  By publishing reams of misleading articles peppered with popular keywords and search terms.  She also recently testified before Congress about how Russian operatives manipulated Facebook's AI to influence American voters by posing as American news outlets and American voters.  (Note: Mozilla, a nonprofit, is the creator of the open-source Firefox browser, a competitor of Google's Chrome browser.)

Of course, the problem isn't technology, per se -- AI isn't inherently malicious.  But it does replicate and amplify human bias.  Computer programs are made by humans who bake in certain design goals and draw on certain data sets.  Inside all of this are the normal contradictions of humanity: generosity and greed; inclusion and bias; good and evil.

Think about it: If the goals and incentives of a set of programmers are to increase advertising revenue, it's not surprising that the content recommendation algorithms they create keep people watching videos for as long as possible.  And, since these algorithms learn and adapt to get better at their goals, it's not surprising that apps like Facebook, YouTube, and Instagram are becoming what Professor Ronald J. Deibert, who has hosted past Mozilla fellows, dubbed "addiction machines" in a recent paper titled, "Three Painful Truths About Social Media."

Further, this technology is developed by a small handful of companies -- names like Facebook that you know and others, like Palantir, that you probably don't -- with little transparency.  Public officials, investigative journalists, and civic-minded citizens can't peer at the code to uncover problems.  Put simply: "The public doesn't have the tools to hold algorithms accountable."

The question we really need to be asking is: how do we make AI responsibly and ethically?  Fortunately, there is a growing cadre of people and companies asking this question.

Researchers like Tufekci and DiResta are vital voices.  Groups like the Center for Humane Technology are examining how the "addiction economy" works.  Organizations like New York University's AI Now Institute are examining the ways AI impacts essential liberties.  Even established players like Microsoft and startups like Element AI are calling for regulation.

Others are stressing the need for more engineers and product designers who consider responsibility and ethics when building AI.  Imagine a social app designer who asks: How do I both grow profits and keep users safe?  People who create drugs and automobiles ask these questions; why not developers?  With this in mind, Mozilla (my company), Omidyar Network, Schmidt Futures, and Craig Newmark Philanthropies are leading the Responsible Computer Science Challenge, a $3.5 million initiative to integrate ethics into undergraduate computer science curricula.

Finally, it is worth noting that a handful of governments are starting to step up, too.  In 2018, the New York City mayor's office announced an AI watchdog panel.  More recently, the governments of Canada and France announced a joint initiative to examine the intersection of AI and ethics.  And, in Finland, the government is training 1% of the population in AI basics, such as when it is deployed and the definitions of terms like "machine learning" and "neural networks."

As artificial intelligence becomes more pervasive, it's critical to foster a better public understanding of its impact on society.  Hulking robots make for good cinema but aren't accurate representations of how AI can and does do harm today.  We need to focus on real solutions, like planning for ethical and responsible technology at the drawing board, not after the fact.

Bottom line: We need to anticipate and eliminate bias in AI before it reaches millions of people.

Monday, December 10, 2018

FACEBOOK - Oversharing?

"In the hunt for revenue, did Facebook share more data than it disclosed?" PBS NewsHour 12/5/2018

Excerpt

SUMMARY:  In April, Facebook CEO Mark Zuckerberg told Congress that his platform doesn’t “sell any data to anyone.”  But now, documents released by a British Parliament committee suggest the social media giant was trading access to user data in exchange for advertising dollars.  Nick Schifrin speaks with the Washington Post’s Elizabeth Dwoskin for specifics on the accusations and Facebook's response.

Monday, December 03, 2018

PERSONAL DATA SECURITY - Are Companies Doing Enough? No

"Why companies are still failing to protect our personal data" PBS NewsHour 11/30/2018

Excerpt

SUMMARY:  A newly announced breach into the Marriott hotel chain’s reservation database is one of the biggest hacks in history, affecting half a billion customers in all.  Amna Nawaz speaks with David Kennedy, co-founder of security firm TrustedSec, to understand what's unusual about this breach, whether companies are doing enough to safeguard data, and how individuals can protect their own information.

Monday, April 09, 2018

FACEBOOK - The Storm

"New Facebook revelations over user privacy deepen crisis and invite scrutiny" PBS NewsHour 4/5/2018

Excerpt

SUMMARY:  Social media giant Facebook says it now believes that up to 87 million people had their data improperly shared with Cambridge Analytica, the political consulting firm that worked for the Trump campaign, and that public profiles for most of the platform's 2 billion users were likely accessed by outsiders without explicit permission.  John Yang reports.




"Sheryl Sandberg: Facebook ‘made big mistakes’ on protecting user data" PBS NewsHour 4/5/2018

Excerpt

SUMMARY:  Facebook Chief Operating Officer Sheryl Sandberg apologized Thursday for the social media giant’s data breach and admitted the company failed to do enough to protect the data of tens of millions of its users.

Yet she said the company does not know whether political consulting firm Cambridge Analytica, which used Facebook data to target voters in the run-up to the 2016 elections, still possesses user data from the company, and if so, what the data is.

“We were given assurances by them years ago that they deleted the data.  We should’ve followed up.  That’s on us.  We are trying to do a forensic audit to find out what they have,” Sandberg said.

Cambridge Analytica’s misuse of Facebook data, which may have affected up to 87 million users, according to a blog post from the company this week, has sparked widespread anger at the company and its founder, Mark Zuckerberg, who will testify before Congress about how his company protects user data next week.

In an interview with the PBS NewsHour’s Judy Woodruff, Sandberg acknowledged the company “under-invested” in the safety and security of user data.  Sandberg said Facebook is now working to rectify that.

“We were very focused for the last 10 years on building on social experiences [but] we were not focused enough on the possible misuses of data,” Sandberg said.  “What we are doing now is looking much more holistically at all the ways Facebook data is used and making a lot of proactive changes.”

Monday, October 31, 2016

CYBER WARS - Protecting Consumer Data

Also a Greed File

"FCC chief outlines new plans to protect consumer data online" PBS NewsHour 10/27/2016

Excerpt

SUMMARY:  There are new rules for broadband providers when it comes to collecting and sharing consumer data.  On Thursday, the Federal Communications Commission voted for the first time to create protections on the transmission of personal information for broadband providers.  Hari Sreenivasan speaks with Tom Wheeler, chairman of the FCC.

HARI SREENIVASAN (NewsHour):  New rules for broadband providers when it comes to collecting and sharing customer data.

The Federal Communications Commission voted for the first time today to create protections on the transmission of personal information from broadband providers.

Tom Wheeler is the chairman of the FCC.  And he joins me now.

What is a provider going to have to do under these new rules?

TOM WHEELER, Chairman, Federal Communications Commission:  Well, the key thing is that it is the consumers' information.  It's not the network's information.

And the consumer now has the choice to say how they want that information to be used and if they want it to be used.  So, there are really three key things.  One, there has to be transparency, that the consumers have to be told, here's what we're doing with your information.  Two, they have to have choice.  So, do you want to opt in or opt out of this kind of service?

And, three, that data, when it's stored someplace, has to be stored securely and consumers have to know if there is some kind of data breach.

HARI SREENIVASAN:  So, you have also expanded the definition of what is sensitive data.  And some businesses have pushed back, saying, the browsing history, the app usage, Internet companies like Facebook and Google, they already have all that, and you're placing undue burdens on companies like Verizon, AT&T, et cetera.

TOM WHEELER:  But what we're talking about is not the fact that you may go to a dozen sites that each will get a little bit of information.

We're talking about the network that takes you to every site and knows everything you're doing.  And that's the big difference.  You hire the network to deliver you to those sites.  You don't hire the network to take your information without your permission and turn around and resell it.

Monday, August 24, 2015

INTERNET - Not Private, Not Safe

IMHO:  As a computer specialist and IT Technician (retired) I can tell you that ANYTHING on the Internet is never safe and therefore not private.  Pay attention to the hacking going on world-wide.  Governments are hacked, military sites are hacked, businesses are hacked, and more.  Being on the Internet and expecting privacy is like holding a conversation in Central Park (New York) and expecting that no-one will overhear you.

"Is the trail of secrets we leave online ever safe?" PBS NewsHour 8/21/2015

Excerpt

SUMMARY:  Hackers dumped troves of personal information stolen from the adultery website Ashley Madison this week.  Millions of names, email addresses and partial credit card numbers were released, raising alarms about how much privacy any of us enjoy online.  Hari Sreenivasan discusses the fallout with Neil Richards of Washington University and Julia Angwin of ProPublica.

JUDY WOODRUFF (NewsHour):  Internet hackers dumped troves of personal information this week stolen from an adultery Web site, raising new questions about online privacy and the ability of Web sites to protect it.

Hari Sreenivasan has our look.

HARI SREENIVASAN (NewsHour):  The hackers said the attack on Ashley Madison was motivated by the failure of its parent company to deliver on a service that promised to erase users’ information for a fee.  Millions of names, e-mail addresses and partial credit card numbers were released, a public outing that has raised questions about how much privacy any of us enjoy online.

Joining me to discuss this are Neil Richards, a professor of law at Washington University in Saint Louis, where he studies privacy and the Internet.  His recent book is “Intellectual Privacy:  Rethinking Civil Liberties in the Digital Age.”  And Julia Angwin, who covers privacy for ProPublica, her most recent book is called “Dragnet Nation:  A Quest for Privacy, Security, and Freedom in a World of Relentless Surveillance.”

All right, so, Neil, I want to start with you first.

We have had the Sony Pictures hack, where thousands of employees of a corporation had their communication and their information released.  We have had the Office of Personnel Management hacked, 22 million employees of the federal government, right?

We have also had celebrity hacks before, where unsuspecting celebrities had their photos from iPhones or iClouds released.  What makes this different?

NEIL RICHARDS, Washington University:  Well, it’s certainly different because it’s more salacious.  Right?  It involves sex and betrayal.

I think the magnitude of the hack and the sensitivity of the information that is being exposed.  I think it’s important that we think about these questions, because this is a little more juicy in terms of — maybe like tabloid news, than some of the other hacks, but it’s important to draw attention to what is an increasingly enormous problem.

HARI SREENIVASAN:  So, Julia, I want to ask.  There is this notion that your information, especially on a sensitive site like this, sits in a lockbox.  And to credit this site, this digital set of locks that they had was actually better than average.

But is there such a thing as true security?  As soon as you type something, is it out there forever?

JULIA ANGWIN, ProPublica:  Sadly, what we’re learning is that there doesn’t seem to be a lot of true security out there in the real world.

Monday, July 13, 2015

NATIONAL SECURITY - OPM Hack

"OPM hack affecting more than 21 million includes sensitive data" PBS NewsHour 7/9/2015

Excerpt

SUMMARY:  More than 21 million Americans had personal data stolen from files held by the Office of Personnel Management.  Anyone who went through background checks to apply for a government position since 2000 has been affected, according to the OPM.  That makes the data breach six times larger than was originally disclosed.  Gwen Ifill learns more from Josh Lederman of the Associated Press.

GWEN IFILL (NewsHour):  More than 21 million Americans had personal information stolen from government files in a data breach that was six times as large as originally disclosed.  The information was hacked from the Office of Personnel Management, or OPM, which said today it is highly likely that anyone who went through background checks to apply for a government position since 2000 was affected.

Joining us to fill in the blanks is Josh Lederman of the Associated Press, who has been covering the story.

In terms of scope, we know this is huge, but how is it different from the earlier hacks we have heard about, Josh?

JOSH LEDERMAN, Associated Press:  Well, what we’re finding out now, Gwen, is not only were many more Americans affected than we previously knew, but just what kinds of data.

We’re talking about very personal data that most people would be very uncomfortable knowing is out there.  We’re talking about health histories, their criminal histories, their educational and residency backgrounds, as well as interviews that they conducted with members of OPM, Office of Personnel Management, or other people conducting background checks in the process of applications to get a security clearance.

Wednesday, August 27, 2014

SURVEILLANCE - NSA's Secret 'Google'

"The Surveillance Engine:  How the NSA Built Its Own Secret Google" by Ryan Gallagher, The Intercept 8/25/2014

Excerpt

The National Security Agency is secretly providing data to nearly two dozen U.S. government agencies with a “Google-like” search engine built to share more than 850 billion records about phone calls, emails, cellphone locations, and internet chats, according to classified documents obtained by The Intercept.

The documents provide the first definitive evidence that the NSA has for years made massive amounts of surveillance data directly accessible to domestic law enforcement agencies.  Planning documents for ICREACH, as the search engine is called, cite the Federal Bureau of Investigation and the Drug Enforcement Administration as key participants.

ICREACH contains information on the private communications of foreigners and, it appears, millions of records on American citizens who have not been accused of any wrongdoing.  Details about its existence are contained in the archive of materials provided to The Intercept by NSA whistleblower Edward Snowden.

Earlier revelations sourced to the Snowden documents have exposed a multitude of NSA programs for collecting large volumes of communications.  The NSA has acknowledged that it shares some of its collected data with domestic agencies like the FBI, but details about the method and scope of its sharing have remained shrouded in secrecy.

ICREACH has been accessible to more than 1,000 analysts at 23 U.S. government agencies that perform intelligence work, according to a 2010 memo.  A planning document from 2007 lists the DEA, FBI, Central Intelligence Agency, and the Defense Intelligence Agency as core members.  Information shared through ICREACH can be used to track people’s movements, map out their networks of associates, help predict future actions, and potentially reveal religious affiliations or political beliefs.

The creation of ICREACH represented a landmark moment in the history of classified U.S. government surveillance, according to the NSA documents.

“The ICREACH team delivered the first-ever wholesale sharing of communications metadata within the U.S. Intelligence Community,” noted a top-secret memo dated December 2007.  “This team began over two years ago with a basic concept compelled by the IC’s increasing need for communications metadata and NSA’s ability to collect, process and store vast amounts of communications metadata related to worldwide intelligence targets.”

The search tool was designed to be the largest system for internally sharing secret surveillance records in the United States, capable of handling two to five billion new records every day, including more than 30 different kinds of metadata on emails, phone calls, faxes, internet chats, and text messages, as well as location information collected from cellphones.  Metadata reveals information about a communication — such as the “to” and “from” parts of an email, and the time and date it was sent, or the phone numbers someone called and when they called — but not the content of the message or audio of the call.

Monday, July 07, 2014

PERSONAL SECURITY - The Real Threat are Data Brokers, Not Government

"What do data brokers really know about us?" PBS NewsHour 7/6/2014

Excerpts

HARI SREENIVASAN (NewsHour):  Post Edward Snowdwn has the conversation changed, are more people aware now in the last year of not just NSA and the data that they’re gathering, but all the data of them that exists?

JULIA ANGWIN:  Yeah, I think people are more aware.  Although it still surprises me how much people are not aware.

It’s not just the NSA.  All these companies or even when you go to a shopping mall they might be setting up all these kind of WiFi sniffers that kind of ping your phone to see who is walking by, right?

The ubiquity of surveillance is really hard for people to grasp.
----
HARI SREENIVASAN:  Do we as consumers have rights to look at the data that a commercial company might have on us and then dispute that, if that’s wrong?

JULIA ANGWIN:  No, we don’t have that right.  So we’re one of the only Western nations that doesn’t have a law that allows us to see the data, that commercial data gatherers have.

So must countries don’t let you see the data that intelligence agencies have, obviously.  But commercial data gatherers in most countries and Canada, and Europe, and the UK.  You can go to them and say, show me the information.  And if it’s wrong you can correct it, or ask for correction, and there’s sort of a dispute process.  But we don’t have that here.

So I tried to find where my data was.  I identified two hundred data brokers, and I was only able to see my files at 13 of them.

HARI SREENIVASAN:  Of those 13, were they all accurate?

JULIA ANGWIN:  No, so that’s the other thing.  Of the 13 there were probably about 5 or 6 that were very accurate.

Monday, June 30, 2014

HEALTH - Hospitals Using Data Brokers

"Hospitals turning to data brokers for patient information" PBS NewsHour 6/29/2014

Excerpt

HARI SREENIVASAN (NewsHour):  A story published a few days ago caught our attention.  It described how hospitals buy information about you to determine how likely you are to get sick and what it would cost to treat you.  For more we’re joined by one of the co-authors, Shannon Pettypiece of Bloomberg News.  So what are they buying and who are they buying it from?

SHANNON PETTYPIECE, Bloomberg News:  Well they are buying the same type of data that retailers have been using for years to target products at you and what we’re talking about here is that information that’s collected by companies called data brokers, which can track every transaction a consumer can make, every purchase they make, with a drug store or a grocery store loyalty card.

They can find out how much your home is worth, what type of car you own.  Even things like your interests, whether you like hiking or rock climbing based off of public databases or even your web browsing history.  And for years, retailers have used this to send you a coupon or to figure out who might want to subscribe to their certain list or product.

Now hospitals are saying, can we use this data this information to try to predict who’s going to get sick and who is going to end up at the emergency room.

HARI SREENIVASAN:  So why are hospitals interested in having this kind of information?

SHANNON PETTYPIECE:  Well under Obamacare they have an increased incentive to keep patients healthy because the law changes the way they are paid.

So under the law, hospitals now get penalized if you come back to the emergency room too frequently and if a hospital isn’t meeting certain patient quality and health outcomes and insurers are following the same mold too.

Insurers no longer want to pay for hospitals who are just doing more and more test and procedures over and over again and they want to be paying for quality so hospitals are going to be held accountable if patients are too sick if patients are coming to the emergency room too frequently.

Monday, June 02, 2014

PRIVACY - Warning, Big Data Brokers

"FTC report warns consumers about big data brokers" PBS NewsHour 5/31/2014

Excerpt

HARI SREENIVASAN (NewsHour):  Earlier this week, the Federal Trade Commission issued a report that contained consumer protection recommendations concerning what’s referred to as “big data” – the companies that collect and sell billions of bits of information about all aspects of our online lives.  Information that includes purchases, income, political affiliations – even religion. As FTC Chairwoman Edith Ramirez put it:

“It’s time to bring transparency and accountability to bear on this industry on behalf of consumers, many of whom are unaware that data brokers even exist.”

For some insight, we turn to Amy Schatz who covers tech policy issues for Re/code.

So, what were the things that this report uncovered that might surprise consumers?

AMY SCHATZ, Re/code:  I think most of the things in the report would surprise consumers, although this isn’t necessarily a new issue – this has been going around for a couple of years – but most people don’t know that there are a bunch of data collectors out there who are collecting data about you.  Whether it’s who you voted for or your political beliefs.  Whether it’s your zip code or what you purchased at the store last week or what you’re lookeingat online.  There are these profiles that are being created online of most Americans now and that information is being traded and shared in a way that a lot of consumers might find a little troubling.

Friday, January 31, 2014

PERSONAL SECURITY - Opting Out from Data Brokers

Maybe it's time to HAVE a law to allow us to opt-out from Data Brokers, one without having to expose more personal information.

My 'We the People' Petition

"Privacy Tools:  Opting Out from Data Brokers" by Julia Angwin, ProPublica 1/30/2014

In the course of writing my book, Dragnet Nation, I tried various strategies to protect my privacy.  In this series of blog posts, I try to distill the lessons from my privacy experiments into a series of useful tips for readers.

Data brokers have been around forever, selling mailing lists to companies that send junk mail.  But in today’s data-saturated economy, data brokers know more information than ever about us, with sometimes disturbing results.

Earlier this month, OfficeMax sent a letter to a grieving father addressed to “daughter killed in car crash.”  And in December, privacy expert Pam Dixon testified in Congress that she had found data brokers selling lists with titles such as “Rape Sufferers” and “Erectile Dysfunction sufferers.”  And retailers are increasingly using this type of data to make from decisions about what credit card to offer people or how much to charge individuals for a stapler.

During my book research, I sought to obtain the data that brokers held about me.  At first, I was excited to be reminded of the address of my dorm room and my old phone numbers.  But thrill quickly wore off as the reports rolled in.  I was equally irked by the reports that were wrong — data brokers who thought I was a single mother with no education — as I was by the ones that were correct — is it necessary for someone to track that I recently bought underwear online?  So I decided to opt out from the commercial data brokers.

It wasn’t easy.  There is no law requiring data brokers to offer opt-outs.  Of the 212 data brokers that I managed to identify, less than half — 92 — accepted opt-outs.  Of those, a majority — 65 — required me to submit some form of identification, such as a driver’s license to opt out.  Twenty-four sites required the opt-out forms to be sent by mail or fax.  In some cases, I decided not to opt-out because the service seemed so sketchy that I didn’t want to send in any additional information.

Still, I achieve some minor successes:  A search for my name on some of the largest people-search websites, such as Intelius and Spokeo, yields no relevant results.

So, for those who want to try my strategy, here are the two spreadsheets I put together with the names of companies that track your information, links to their privacy pages, and instructions on how to opt out, in the cases where they offered them.

The first spreadsheet below is a list of data brokers who will give you copies of your data (you can download your own copy).  The second is the list of data brokers from whom I sought to opt-out, with the ones that allowed opt-outs highlighted (download this one here).

Good luck!

The spreadsheet links above, they have names and links to help you opt-out, you will have to have Microsoft Office or similar software installed to view.  If you do not, just use the article link.