Are Smart Meters A Hacker Wonderland?

December 21, 2022

One reason to not upgrade your entire life to the digital cloud is an increased risk of hacking vulnerability. Interior and exterior security cameras, particularly baby monitors, are prone to hacking, but did you ever think smart meters for electricity and heating would be a target? Yahoo News reports that British households are being hacked by energy companies: “Switch By Stealth’: Alarming Rise In Homes With Smart Meters Being Cut Off Remotely.”

Smart meters are digital readers that monitor the amount of electricity a household uses, then sends the information back to the energy company. Smart meters provide energy companies with better information about energy consumption and billing. Smart meters also allow energy companies to remotely switch a customer’s payment method. The payment method is switched from debit payments to an expensive prepayment method.

What is worse is that when all the funds from the prepayment method are used up, the energy company will shut off the energy leaving a household without electricity and heating.

The British government is listening, but not acting quickly enough:

“It comes amid the worsening cost-of-living crisis, with the average yearly energy bill reaching £2,500 in October – a record high, and almost double the price it was last year. And energy bills are set to rise again in April, with estimates the average yearly bill could hit £3,500 per year. Campaigners are urging the government to honour their pledge to uprate benefits with inflation in the autumn statement next week, warning millions of low income households are already being forced into destitution without more support.”

It is understandable energy companies need to earn money to pay their employees, purchase energy, and keep the lights on, but why would they harm their customers? It would not be surprising if some bad actors wearing a white hat hack the smart meters and assist the people about to have their energy cut off.

Whitney Grace, December 21, 2022

Microsoft Software Quality: Word Might Stop Working. No Big Deal

December 20, 2022

I read a short item which underscores my doubts about Microsoft’s quality methods. l have questions about security issues in Microsoft’s enterprise and cloud products and services. But those are mostly “new” and the Big Hope for future revenues. Perhaps games will arrive to make the Softies buy Teslas and beef up their retirement accounts, just not yet.

Microsoft Confirms Taskbar Bugs, Broken File Explorer, and App Issues in Windows 10” reports:

If you use Windows 10, you might experience the following symptoms:

  • ?The Weather or News and Interests widget or icons flickers on the Windows taskbar
  • ?The Windows taskbar stops responding
  • ?Windows Explorer stops responding
  • ?Applications including Microsoft Word or Excel might stop responding if they are open when the issue occurs

The weather and news are no big loss in my opinion. Microsoft believes that Windows 10 users want weather and news despite the mobile phone revolution. (Remember Microsoft and its play to create a mobile phone? Yeah, that was spun as fail early and fail fast. I think of that initiative as a basic fail, not a fast or early fail. Plain old fail.)

The Taskbar and file manager are slightly more interesting. A number of routine functions go south for some lucky Windows 10 users.

But the zinger fail is that Microsoft Word or Excel die. Now that’s just what’s needed to make the day of a person who is working on a report at a so-so consulting firm like one of the blue-chip outfits in Manhattan, a newbie at a big law firm with former government officials waiting for the worker bees to deliver a document for the bushy eyebrow set to review, or a Wall Street type modifying a model to make his, her, thems partners lots of money.

These happy users are supposed to be able to handle stress and pressure.

I wonder if Microsoft executives have been in a consulting firm, law firm, or financial services company when a must have app stops responding. Probably not because these wizards are working on improving Microsoft’s quality control processes. Could Redmond’s approach to quality be blamed on an intern, a contractor, or a part time worker? My hunch is that getting blamed is not a component of the top dogs’ job description.

Stephen E Arnold, December 20, 2022

Want Clicks? Put War Videos on TikTok

December 20, 2022

Here is another story about the importance of click-throughs to social media companies, repercussions be damned. BBC News reports, “Russian Mercenary Videos ‘Top 1 Bn Views’ on TikTok.” The mercenary band in these videos, known as the Wagner Group, is helping Russia fight its war against Ukraine. Writer Alexandra Fouché cites a recent report from NewsGuard as she reveals:

“NewsGuard said it had identified 160 videos on the short-video platform that ‘allude to, show, or glorify acts of violence’ by the mercenary group, founded by Yevgeny Prigozhin, a close ally of President Vladimir Putin. Fourteen of those videos showed full or partial footage of the apparent killing of former Russian mercenary Yevgeny Nuzhin which saw high engagement within days of being uploaded last month, it said.”

That brutal murder, which was performed with a sledgehammer, was viewed over 900,000 times on TikTok before ByteDance took it down. Nuzhin was apparently killed because he switched sides and denounced the Wagner Group. Sadly but surely, there are many viewers who would seek out such footage; why blame TikTok for its spread? The article continues:

“NewsGuard found that TikTok’s algorithm appeared to push users towards violent Wagner Group content. When an analyst searched for the term ‘Wagner’, TikTok’s search bar suggested searches for ‘Wagner execution’ and ‘Wagner sledgehammer’. The same search in Russian resulted in the suggestions ‘Wagner PMC’, ‘Wagner sledgehammer’ and ‘Wagner orchestra’. Wagner refers to its fighters as ‘musicians’. NewsGuard also found that videos could be found on TikTok showing another Wagner murder involving an army deserter in Syria in 2017 and that they had reached millions of users.

The online analysis group said it had also identified other music videos on the platform that advocated violence against Ukrainians, including calls to kill Ukrainians claiming they were ‘Nazis’.

Funny, when I searched Google for “Wagner,” the first three results my filter bubble turned up were composer Richard Wagner’s Wikipedia page, Wagner paint sprayer’s home page, and Staten Island’s Wagner College. Some actual news articles about the Wagner Group followed, but nary a violence glorification video in sight. TikTok certainly knows how to generate clicks. But what about China’s “reeducation” camps? The Chinese company is not circulating videos of those, is it? It seems the platform can be somewhat selective, after all.

Cynthia Murrell, December 20, 2022

Who Can See Your Kiddies?

December 20, 2022

In an alarmingly hilarious situation, iCloud users are seeing photos of strangers on their devices. What sounds like a hacker’s gaff, actually proves to be a security risk. XDA Developers investigates what is going on with iCloud in, “iCloud For Windows Users Are Reportedly Seeing Random Family Photos From Strangers.”

People buy Apple products for its better security and privacy settings than PC devices. While Apple has an iCloud app for PC users, the app is not working as well as its fellow Apple products:

“Based on the reports, the corrupted files seemingly revolve around videos shot on iPhone 13 Pro and iPhone 14 Pro models. The footage in some cases is showing a black screen with scan lines. Though, what’s more worrisome is the random content that is showing up for some users. While it’s not confirmed yet, these photos of families, children, and other private moments could potentially belong to other people’s iCloud libraries. If this is the case, then Apple could get in some serious trouble. Unfortunately, deleting the iCloud for Windows app seemingly doesn’t solve this, as the issues are being reflected on the server.”

No one is certain what is causing the bug, but Apple needs to get on the problem. Apple will probably blame the issue on PCs being inept devices and the compatibility between Macs and PCs could be the reason. Apple is not infallible and here is a lesson in humility.

Whitney Grace, December 20, 2022

Transcription Services: Three Sort of New Ones

December 19, 2022

Update: 2 pm Eastern US time, December 19, 2022. One of the research team pointed out that the article we posted earlier today chopped out a pointer to a YouTube video transcription service. YouTube Transcript accepts a url and outputs a transcript. You can obtain more information at https://youtubetranscript.com/.

One of the Arnold IT research team spotted two new or newish online transcription services. If you want text of an audio file or the text of a video, maybe one of these services will be useful to you. We have not tested either; we are just passing along what appear to be interesting examples of useful semi smart software.

The first is called Deepgram. (The name echoes n-gram, grammar, and grandma.) Once a person signs up, the registrant gets 200 hours of free transcription. That approximately a month of Jason Calacanis podcasts. The documentation and information about the service’s SDK may be found at this link.

The second service is Equature. The idea is, according to Yahoo Finance:

a first-of-its-kind transcription and full-text search engine. Equature Transcription provides automated transcription of audio from 9-1-1 calls, radio transmissions, Equature Armor Body-worn Camera video, and any other form of media captured within the Equature recording system. Once transcribed, all written text is searchable within the system.

Equature’s service is tailored to public safety applications. You can get more information from the firm’s Web site.

Oh, we don’t listen to Mr. Calacanis, but we do scan the transcript and skip the name drops, Musk cheers, and quasi-academic pontification.

Stephen E Arnold, December 19, 2022

Over the Holidays Learn Algospeak

December 19, 2022

Internet content has evolved its own set of coded words and emojis called algospeak. Though often discernable from context, the meanings behind these terms and symbols can easily escape the uninitiated. Lifehacker supplies a list of such terms in, “All the Social Media ‘Algospeak’ You Don’t Understand.” But wait, you might ask, what is wrong with clarity and accurate wording? Writer Sarah Showfety explains:

“If you’ve ever created content for internet consumption, you know the number one rule: Don’t upset the algorithm. Modern-day social media algorithms are like the Wizard of Oz—cloaked, all-powerful puppeteers who can seemingly perform miracles for the right creators, instantly propelling their content in front of millions of eyeballs. But they are as fickle as they are promising, often trapping content in a dungeon of 53 views for no discernible reason. While the inner machinations of algorithms are largely unknown, being blackballed by one can suppress your content and seal your doom—and one of the quickest ways to do that is to use language that could be flagged as a violation of the platform’s content guidelines or terms of service. So internet content creators have developed a growing glossary of terms designed to circumvent automated brand safety filters. This evolving lexicon of euphemisms, abbreviations, deliberate misspellings, symbol insertions and emojis known as ‘algospeak’ is used to disguise sensitive and potentially problematic words having to do with polarizing political topics, controversial global events, cultural taboos, death, drugs, and just plain sex.”

Ah yes, the almighty algorithm. Readers may want to bookmark the post in case of future confusion. A few of the PG-rated euphemisms include “bink in lio” for “link in bio,” “swimmers” for vaccinated people, and the sunflower emoji to symbolize Ukraine. Showfety points out one entry is particularly unfortunate, at least for this charismatic kid who suddenly found himself famous for his love of maize: “Corn” is algospeak for “porn.” Really? We don’t make these choices, we just try to keep you informed, dear reader.

Cynthia Murrell, December 19, 2022

TikTok Explained without Mentioning Regulation and US Education Failings

December 19, 2022

I am not into TikTok. I enjoy reading analyses of TikTok by individuals who are not engaged in law enforcement, crime analysis, and intelligence work for the US and its allies. Most of these deep dives are entertaining because they miss the obvious: Hoovering data from users for strategic and tactical information weaponization and information operations. I assume that makes me a party pooper, particularly among those who are into the mobile experience. I recall laughing out loud when I listened to a podcast featuring a Silicon Valley news type explaining that TikTok was no big deal. Ho ho ho.

I read this morning (December 17, 2022, 530 am US Eastern) “TikTok’s Secret Sauce.” The write up explains insights gleaned from “a project studying algorithmic amplification and distortion.” Quotes from the write up are in italic to differentiate them from my comments.

I learned:

… the average ratio of hearts to views on TikTok is roughly 5%. People are just not that predictable.

Okay, people are not predictable. May I suggest spending some time with the publicly available information on the Recorded Future Web site? Google and In-Q-Tel were early supporters of this company. The firm’s predictive analytics rely, in part, that people are creatures of habits. Useful information emerges from these types of analyses. In fact, most intelware does, and this includes specialists in other countries, including some not allied with the US.

I learned:

Exploration explains why there are an unending variety of incredibly weird niches on TikTok: the app manages to connect those creators to their niche audiences.

Let’s think in terms of unarticulated needs and desires. TikTok makes it possible for that which is not stated to emerge from user behavior. Feedback ensures that skinny girls and diets that deliver thinness get in front of certain individuals. Feedback is good and finding content that reveals more of the user’s psychographic footprint useful. Why? Manipulation, identification of individuals with certain behavior fingerprints, and amplification of certain messaging. Yep, useful.

I learned:

More generally, in AI applications, the sophistication of the algorithm is rarely the limiting factor.

Interesting. Perhaps the function of TikTok is just obvious. It, in my opinion, so obvious that it is overlooked. In high school more than a half century ago, I recall our class having to read “The Purloined Letter” by that sporty writing Edgar Allan Poe. The main idea is that the obvious is overlooked.

In some countries — might TikTok’s home base be an example — certain actions are obvious and then ignored or misunderstood. TikTok is that type of product. Now, after years of availability, experts are asking questions and digging into the service.

The limiting factor is a failure to understand how online information and services can be weaponized, deliver directed harm, and be viewed as a harmless time waster. Is it too late? Maybe not, but I get a kick out of the reactions of experts to what is as clear and straightforward as driving a vehicle over a mostly clueless pedestrian or ordering spicy regional cuisine without understanding the concept of hot.

Stephen E Arnold, December 19, 2022

Need Holiday Cash? Some Gotchas Exist

December 19, 2022

Perhaps one’s mobile device is not the best place to turn when shopping for a loan. The Dailyhunt shares, “Nearly 300 Predatory Loan Apps Circulating on Google, Apple Stores: Report,” originally published at India.com. The brief write-up cites a recent report from Lookout, stating:

“Nearly 300 loan apps are circulating on Google Play and the Apple App Store that exhibit predatory behaviour, such as exfiltrating excessive user data from mobile devices and harassing borrowers for repayment, a new report has revealed. According to cloud security company Lookout, these loan apps exploit victims’ desire for quick cash to trap borrowers into predatory loan contracts and require them to grant access to sensitive information such as contacts and SMS messages. Some victims have reported that their loans were accompanied by hidden fees, high-interest rates, and repayment terms that were not as favourable as advertised. Lookout also found evidence that data exfiltrated from devices were sometimes used to pressure borrowers for repayment, which is a common threat tactic to disclose a borrower’s debt to their networks. Researchers at Lookout discovered 251 Android apps that had been downloaded over 15 million times. On the Apple App Store, the researchers discovered 35 apps that ranked among the top 100 finance apps in their regional stores.”

High interest rates, hidden fees, and bait-and-switch terms are problematic enough. Stealing personal information for more effective threats and harassment is next-level abuse brought to us by modern technology. It is not as if the companies are unaware there’s a problem. We learn Google recently removed over 2,000 personal loan apps from its Indian Play Store and ordered loan apps in Kenya to submit proof of licensing. It seems, though, more comprehensive measures may be required. Borrower beware.

Cynthia Murrell, December 19, 2022

The EU and the Tweeter Thing

December 16, 2022

Most of the folks who live in Harrod’s Creek, Kentucky, are not frequent tweeters. I am not certain if those in the city could name the countries wrapped in European Union goodness. The information in “Twitter Threatened with EU Sanctions over Journalists’ Ban” is of little interest. Some in the carpetland of Twitter may find the write up suggestive.

Here’s an illustrative statement from the BBC write up:

EU commissioner Vera Jourova warned that the EU’s Digital Services Act requires respect of media freedom. “Elon Musk should be aware of that. There are red lines. And sanctions, soon,” she tweeted. She said: “News about arbitrary suspension of journalists on Twitter is worrying. “[The] EU’s Digital Services Act requires respect of media freedom and fundamental rights. This is reinforced under our Media Freedom Act.”

One quick fix would be ban EU officials from Twitter. My hunch is that might poke the hornet’s nest stuffed full of well-fed and easily awakened officials.

There are several interesting shoes waiting to fall in one of the nice hotels in Brussels; for example:

  1. Ringing the Twitter cash register. Fines have a delayed effect. After months of legal wrangling, the targeted offenders pay something. That’s what I call the ka-ching factor.
  2. Creating more work for government officials in the US. The tweeter thing may not be pivotal to the economic well being of EU member states, but grousing about US regulatory laxness creates headaches for those who have to go to meetings, write memos, and keep interactions reasonably pleasant.
  3. Allowing certain information to flow; for example, data about the special action in Ukraine or information useful to law enforcement and certain intelligence agencies.

Excitement will ensue. I am waiting for certain Silicon Valley real news professionals to find themselves without a free info and opinion streaming service. The cries of the recently banned are, however, unlikely to distract the EU officials from their goal: Ka-ching.

Stephen E Arnold, December 16, 2022

Google to Microsoft: We Are Trying to Be Helpful

December 16, 2022

Ah, those fun loving alleged monopolies are in the news again. Microsoft — famous in some circles for its interesting approach to security issues — allegedly has an Internet Explorer security problem. Wait! I thought the whole wide world was using Microsoft Edge, the new and improved solution to Web access.

According to “CVE-2022-41128: Type Confusion in Internet Explorer’s JScript9 Engine,” Internet Explorer after decades of continuous improvement and its replacement has a security vulnerability. Are you still using Internet Explorer? The answer may be, “Sure you are.”

With Internet Explorer following Bob down the trail of Microsoft’s most impressive software, the Redmond crowd the Microsoft Office application uses bits and pieces of Internet Explorer. Thrilling, right?

Google explains the Microsoft issue this way:

The JIT compiler generates code that will perform a type check on the variable q at the entry of the boom function. The JIT compiler wrongly assumes the type will not change throughout the rest of the function. This assumption is broken when q is changed from d (an Int32Array) to e (an Object). When executing q[0] = 0x42424242, the compiled code still thinks it is dealing with the previous Int32Array and uses the corresponding offsets. In reality, it is writing to wherever e.e points to in the case of a 32-bit process or e.d in the case of a 64-bit process. Based on the patch, the bug seems to lie within a flawed check in GlobOpt::OptArraySrc, one of the optimization phases. GlobOpt::OptArraySrc calls ShouldExpectConventionalArrayIndexValue and based on its return value will (in some cases wrongly) skip some code.

Got that.

The main idea is that Google is calling attention to the future great online game company’s approach to software engineering. In a word or two, “Poor to poorer.”

My view of the helpful announcement is that Microsoft Certified Professionals will have to explain this problem. Google’s sales team will happily point out this and other flaws in the Microsoft approach to enterprise software.

If you can’t trust a Web browser or remove flawed code from a widely used app, what’s the fix?

Ready for the answer: “Helpful cyber security revelations that make the online ad giant look like a friendly, fluffy Googzilla. Being helpful is the optimal way to conduct business.

Stephen E Arnold, December 16, 2022

« Previous PageNext Page »

  • Archives

  • Recent Posts

  • Meta