Unsupervised Learning No. 241

News & Analysis

STANDARD EDITION | EP. 241 | August 10, 2020

State Department Russian Media, Clean Network Plan, Cap One Fine, NSA Tracking Warning, YouTube Account Ban, Amazon Malls, No More Pixel 4, Audio RPGs, Technology News, Human News, Ideas Trends & Analysis, Discovery, Recommendations, and the Weekly Aphorism…

SECURITY NEWS

The State Department's Global Engagement Center is a group that tracks foreign intelligence efforts, and they have released a new report that shows multiple Russian media groups collaborated to magnify the reach of various articles and narratives related to COVID-19. The articles promoted misinformation and conspiracy theories, such as the idea that the US attacked China with a biological weapon. More

The US has announced a new "Clean Network Plan", which has three pushes: 1) Clean Network, which is about cloud services and such, 2) Clean Store, which is about removing malicious apps from app stores, and 3) Clean Apps, which is about stopping dangerous apps from being pre-installed on manufacturers' equipment. It appears that the US government has in fact had enough of China's crap, which I think is positive, but I'm not sure this level of anti-China aggression is the right answer. More

Capital One was fined $80 million for its 2019 data breach. More

The NSA says you should worry about location tracking on your mobile phone, but I'm quite confused about their threat model. Who are they worried about getting access to this information? Malicious app developers and/or governments who wrote those apps? Mobile phone providers themselves, like AT&T and Verizon? Or maybe they worry governments have access to those providers and can steal said data? I think something like this advisory would be far more useful if it were paired with a realistic threat model for various user types. Regular people, journalists, security researchers, etc. Describe who might want to get your data as members of those groups, and what you can do to stop it. Their advice to "turn the stuff off" is not good enough. More

YouTube has banned thousands of Chinese accounts due to "Coordinated Influence Operations". Most of the content these accounts were posting was just spam, but there was some percentage that was misinformation around topics like COVID-19. I think it's important to call out that much of what we've seen from China hasn't been of the Russian type—which is basically Information Warfare trying to cause discord in the US. The Chinese version of misinformation has been more like pro-China (and anti-US) marketing, basically saying things like, "No, this wasn't China's fault, it's the fault of the US's incompetence." That's far more benign than what Russia is doing, in my opinion. More

A talk at Blackhat last week did a deep dive on how a group of Chinese hackers penetrated the Taiwanese microchip industry and stole source code, SDKs, chip designs, and other content. More

The US is offering a reward of $10 million for information around election security tampering. More

Incidents:

  • 20 gigabytes of Intel's intellectual property was dropped on the internet, mostly consisting of documentation on products, including many under development or that have not yet been released. More 

  • Tens of Reddit channels have been defaced to show pro-Trump reelection messaging. More

  • US Carlson Wagonlit pays $4.5 million in ransom. More

  • Canon got hit with ransomware that hit their email, Microsoft Teams, their US website, and other internal applications. More

Companies:

  • Cyemptive is a company that tries to address the problem of ransomware-compromised backups. More

  • Censys has raised $15.5 million to map the internet. More

  • Silverfort just raised $30 million to add stronger authentication to remote workers. More

TECHNOLOGY NEWS

One of the largest mall owners in the US is talking to Amazon about using abandoned malls as Amazon fulfillment centers. More

Google has discontinued its flagship Pixel 4 and Pixel 4XL phones, which they launched less than a year ago. I am continuously stunned at how bad they are at creating and launching consumer products. They have so much technical talent, and they make such great stuff, but they can't figure out how to create stuff people want and then release that product with quality and consistency. I don't know how their management allows them to continue own-goaling themselves. More

Chinese companies have AI-based telemarketing technology that can make 3,000 calls a day. I feel like this has already been unleashed on the US. I don't know if it's AI or just regular automation, but most spam calls I get these days are in Mandarin. More

HUMAN NEWS

One-third of Americans say they won't get a COVID-19 vaccination when it comes out. More

A study has shown that diluting the blood plasma of older mice improves their age-related health problems. The current theory is that there are inflammatory agents in older blood, and that removal of some of them lead to improvement. They're working on human trials. More

Amazon is doing some really interesting stuff with an audio-only RPG series that you can "play" on Alexa. You simply ask it to "play the Starfinder game", and it takes you into RPG episodes that let you interact with the outcomes like a real RPG. More of this, please, Amazon. More

Debt collectors are doing quite well right now because people are stuck at home with stimulus money. More

A fascinating new study found that Dark Triad traits (Machiavellianism, Narcissism, and Psychopathy) predicted both White Identitarianism (WI) and Political Correctness Authoritarianism (PCA). They had a great possible explanation, which is that Dark Triad traits don't indicate left or right, but rather what people are willing to do to further their goals regardless of beliefs. More

Companies:

  • Ginger is an on-demand mental health provider, and they just raised $50 million. They're evidently one of 55 mental health startups that saw major funding raises in Q2 2020. More

IDEAS, TRENDS, & ANALYSIS

Many are predicting that COVID will get worse in the winter, not for any strange virus reasons, but simply because cold weather will force many together indoors. More

An argument that we're living in The Most Counterintuitive Recession Ever, with an intense crash followed by a faster recovery than we've ever seen. More

There was a 1200% increase in Americans giving up their citizenship in the first 6 months of 2020. Compared to the previous 6 months, the numbers went from 444 to 5,816. That's crazy growth, but the numbers are still pretty small. More

The Truth is Paywalled, But the Lies Are Free More

UPDATES

Here's the video of my talk, Mechanizing the Methodology, at DEFCON's Red Team Village this past weekend. Video

The story above about Dark Triad traits has made me want to take a test. I found one. More

I find myself writing an awful lot about China and Russia, and I'm not super pleased about that. I'm quite interested in m/disinformation, and in Information Warfare, but I'm not interested in having a show about two threat actors. It just so happens that they are the most active in this space right now, and the world is a bit crazy at the moment. If you're finding yourself annoyed at how much I talk about China and Russia, I can't promise it'll get better in the short term, but I can promise you that I notice, and that I'm not happy about it either.

DISCOVERY

My friend Clint Gibler does a weekly newsletter called TL;DR Sec, and it's the only pure security newsletter that I read. Highly recommended. More

Jumping Fox Design just released two more colors of their high-end notebooks, which we bought for ourselves. If you're into quality writing accouterments, they're worth checking out. More
 
Awesome Concepts — A collection of laws, principles, mental models, and cognitive biases. More

DEFCON 2020 Live Notes on various talks. More

Your calendar should be an allow list, not a block list. More

Volunteers have built a nationwide database of police records. More

Paul Graham's recommended booklist. More

A Dark Triad traits personality test. More

The Workforce is About to Change Dramatically More

DEFCON was last weekend, and MultiTwitch is a really interesting way to watch remote conferences. I'll be using this more for future conferences. More

RECOMMENDATIONS

Check out my recent talk at DEFCON's Red Team Village. Video

APHORISMS

“Power corrupts the few, while weakness corrupts the many.”

~ Eric Hoffer