whoisjoe.com

What I’m Thinking About May

 Safety, Security, and Privacy 

May 5, 2018

Home About Projects Blog LinkedIn ReThink Security

Safety, Security, and Privacy

Safety, Security, and Privacy continue to be merged together as IoT increases its reach into new devices. IoT devices are being develope with little security in mind, these devices continue to be attacked successfully. I attended a talk at ZonCon by (Senrio) in which their VP of Research outlined the many, many issues they’ve discovered in connected medical devices. Microsoft released Azure Sphere which aims to help their customers build more secure IoT devices with easy Azure connectedness and a standard Linux based platform.

Privacy & GDPR

Facebook has been raked over the coals time and time again over their treatment of shared data. Meanwhile GDPR is ramping up in the EU to help protect customers privacy and how their usage data is used. At least one company, https://www.streetlend.com, has shuttered their doors under the pressure of GDPR and privacy concerns. Facebook https://www.facebook.com/zuck/posts/10104899855107881 is rolling out a clear history feature to combat these concerns as well.

Blockchain

Blockchain and Smart-Contracts technologies continue to be interesting to our customers, especially in financial services. A number of companies are researching ways to use this technology (not directly related to Bitcoin or other cryptocurrencies) to solve novel problems.

Security Innovation Launched blockchain CTF, training, and services

We released our Blockchain CTF a couple weeks ago, with good adoption. We also have a could really cool training options and services to help secure your smart contract.

  • Blockchain Services
  • Smart Contract CTF
  • Launch of Security Innovation Blockchain CTF

AI/ML

Mixing AI/ML and other expert systems with a human can be a powerful marriage. DARPA is researching this with a program called CHESS. DARPA Wants to Merge Human and Computer Cyber Defenders - Defense One. We’re getting to the point of AI/ML where we’re throwing a ton of data at an expert systems and asking it to infer meaning. This can be powerful and good, especially in domains like medical diagnosis, but it can be dangerous when applied to other domains like the legal system. The system’s predictions are only as good as the data it ingests. In diagnosis expert systems have been out performing doctors since early systems (1960’s I believe). In the legal system predictors are acting as a proxy for racism and oppression.

  • AI found better than doctors at diagnosing, treating patients
  • AI Outperforms Doctors in Reading Heart Scans | Asharq AL-awsat
  • The minority report: Chicago’s new police computer predicts crimes, but is it racist?
  • Rise of the racist robots – how AI is learning all our worst impulses | Inequality | The Guardian

Posted By: Joe Basirico

  • 81 More Posts
  • So, You're a Manager Now
  • A Mixtape in 2022
  • The Middle Path of Planning and Reflection
  • Micromanagement and Trust
  • On Giving Advice
  • Emergency Preparedness During Coronavirus Frenzy
  • Mind Map Your Life
  • Start With the Hard Part
  • Delight in the Details
  • Introducing ReThink Security
  • Newsletter & Recommendations
  • Take a Moment
  • Triage Decision Making
  • Show Your Work
  • Getting Back Up
  • Max Out vs. Continuous Development
  • Mental Diet and Exercise
  • Asking for Help Part 2 - Alerting
  • High Water Mark
  • Who Do You Want to Be
  • Presentation Tips
  • Asking for Help
  • China Hijacking the Internet
  • Recording Audio with AirPods in Imovie
  • Active Decisions
  • Create/Publish Scripts
  • Specialize or Do Not Specialize
  • Exactis Breach
  • Optimizing Images
  • What I Track
  • What I’m Thinking About May
  • What I’m Thinking About March
  • What I’m Thinking About January
  • Building a Collaborative & Social Application Security Program
  • Lazy Days in the Cloud
  • Delegate Then Do
  • So you want to be a better programmer
  • Project Success
  • Don't Short Circuit a Lesson
  • Scale Your Solution to the Problem
  • Digital Currencies
  • Fortnightly
  • Why You Should Have Trust Issues with Pokemon Go, and Every Other App on Your Phone
  • In Defense of Reverse Engineering and Responsible Disclosure
  • Ruby open allows command injection if user controlled
  • New Mac Install Guide
  • Understanding Customer Needs and Helping Them Mature
  • My Experiences with IOS8 and Yosemite so far
  • The Importance of Vulnerability Disclosure Programs and Bug Bounties
  • My New Record Player and Beck - Morning Phase (The Vinyl Experience)
  • An Hour of Code with Code.org
  • Gmail Changes to Displays Images by Default
  • Why I Donated to Help Jailbreak iOS7 & You Should Too
  • Email Strategy
  • Shutdown
  • Anatomy of a Distributed Denial of Service (DDoS) Attack
  • NASA Forced to Suspend All Public Outreach & Education Programs
  • Joe_CMS Open Source!
  • Mobile Application Security Testing FAQs: Post #1
  • How Much Security Does Obfuscation Get You?
  • Why Privacy Matters Even if You Have 'Nothing to Hide'
  • What LinkedIn Should Have Done with Your Passwords
  • Constant Vigilance
  • Boeing Paying Hackers to Break into Their Systems
  • My Reading Cycle
  • Developing Tools for Professional Hackers
  • Finding Your Inner Evildoer (4/4): An Evil Streak
  • Finding Your Inner Evildoer (3/4): A Good Imagination
  • When to Rebuild Your Process from Scratch
  • Finding Your Inner Evildoer (2/4): Complete Knowledge of the System
  • Continuous Incremental, Personal Improvement
  • Finding Your Inner Evildoer: Part 1
  • CISCO Password Revealer
  • Battling with Word and Excel
  • Which is More Secure: Windows or Linux?
  • The High Cost of an Application Security Data Breach
  • Using the ConfigurationManager to Access your ConnecitonStrings in the Web.Config
  • New WikiRater Features
  • When is it OK to Build up Technical Debt
  • Time Management with the Pomodoro Technique
  • Manage Energy Not Time
  • Goals, Results and Activities - defining your productivity
© 2022 whoisjoe.com