Friday, 18 December 2020

New story in Technology from Time: U.S. Blacklists More Than 60 Chinese Firms, Including Drone Giant DJI



The U.S. Commerce Department announced it’s blacklisting Semiconductor Manufacturing International Corp., drone maker SZ DJI Technology Co. and more than 60 other Chinese companies “to protect U.S. national security.”

“This action stems from China’s military-civil fusion doctrine and evidence of activities between SMIC and entities of concern in the Chinese military industrial complex,” the Commerce Department said in a statement.

Commerce Secretary Wilbur Ross confirmed the move in a Friday morning interview with Fox Business. It was reported first by Reuters overnight. Shares in SMIC, China’s top chipmaker, slid 5.2% Friday in Hong Kong on the news.

Other affected Chinese entities include those “that enable human rights abuses, entities that supported the militarization and unlawful maritime claims in the South China Sea, entities that acquired U.S.-origin items in support of the People’s Liberation Army’s programs, and entities and persons that engaged in the theft of U.S. trade secrets,” according to the U.S. government statement.

“There’s plenty in the open press about how DJI has been part of the surveillance state and overall suppression within China,” a senior Commerce official said.

The majority of the newly banned companies are Chinese and will join the likes of Huawei Technologies Co. on a list that denies them access to U.S. technology from software to circuitry.

Companies including Huawei and SMIC have been caught in the middle of worsening tensions between the world’s two largest economies, which have clashed on issues from trade to the pandemic.

President Donald Trump had been widely expected to level more sanctions against China’s national champions before Joe Biden formally took office.

Chinese Foreign Minister Wang Yi called the U.S.’s expansive use of sanctions against Chinese companies “unacceptable” in a video address to the Asia Society on Friday. He urged the U.S. to stop “over stretching the notion of national security,” and “the arbitrary suppression of Chinese companies.”

Shanghai-based SMIC, a supplier to Qualcomm Inc. and Broadcom Inc., lies at the heart of Beijing’s intention to build a world-class semiconductor industry and wean itself from reliance on American technology. Washington in turn views China’s ascendancy and its ambitions to dominate spheres of technology as a potential geopolitical threat. A blacklisting threatens to cripple SMIC’s longer-term ambitions by depriving it of crucial gear.

For U.S. companies exporting items to SMIC for making 10-nanometer or more advanced chips, their applications for a license will face “presumption of denial,” while items for producing chips more mature than 10-nanometer will be reviewed on a case by case basis, according to a senior Commerce official.

Companies exporting parts made outside of the U.S. to SMIC will face certain restrictions depending on how much of their technologies are U.S.-origin, and Washington is talking to “like-minded governments” about forming a unified approach to the Chinese chipmaker, senior Commerce officials said. They declined to give details on which governments the U.S. is talking to and potential implications on non-U.S. companies like ASMl Holding NV and Tokyo Electron Ltd. that also supply equipment for making advanced chips.

In response to the widening U.S. crackdown, China is planning to provide broad support for so-called third-generation semiconductors in its next five-year plan to increase domestic self-sufficiency in chip manufacturing, people with knowledge of the matter have said. SMIC, backed by the China Integrated Circuit Industry Investment Fund as well as Singapore’s sovereign fund GIC Pte and the Abu Dhabi Investment Authority, is expected to play a central role in that overall effort.

SMIC representatives didn’t respond to requests for comment. The company had already been laboring under similar, less severe curbs after the Commerce Department in September placed it on a separate export restrictions list, accusing SMIC of supplying the military. Those sanctions took a toll on shares of the company, whose co-CEO Liang Mong Song this week unexpectedly resigned, triggering another selloff.

—With assistance from Jing Li and Peter Martin.

Thursday, 17 December 2020

New story in Technology from Time: U.S. Nuclear Weapons Agency Hacked as Part of Massive Cyber-Attack



The U.S. nuclear weapons agency and at least three states were hacked as part of a suspected Russian cyber-attack that struck a number of federal government agencies, according to people with knowledge of the matter, indicating widening reach of one of the biggest cybersecurity breaches in recent memory.

Microsoft said that its systems were also exposed as part of the attack.

Hackers with ties to the Russian government are suspected to be behind a well coordinated attack that took advantage of weaknesses in the U.S. supply chain to penetrate several federal agencies, including departments of Homeland Security, Treasury, Commerce and State. While many details are still unclear, the hackers are believed to have gained access to networks by installing malicious code in a widely used software program from SolarWinds Corp., whose customers include government agencies and Fortune 500 companies, according to the company and cybersecurity experts.

“This is a patient, well-resourced, and focused adversary that has sustained long duration activity on victim networks,” the U.S. Cybersecurity and Infrastructure Security Agency said in a bulletin that signaled widening alarm over the the breach. The hackers posed a “grave risk” to federal, state and local governments, as well as critical infrastructure and the private sector, the bulletin said. The agency said the attackers demonstrated “sophistication and complex tradecraft.”

The Energy Department and its National Nuclear Security Administration, which maintains America’s nuclear stockpile, were targeted as part of the larger attack, according to a person familiar with the matter. An ongoing investigation has found the hack didn’t affect “mission-essential national security functions,” Shaylyn Hynes, a Department of Energy spokeswoman, said in a statement.

“At this point, the investigation has found that the malware has been isolated to business networks only,” Hynes said. The hack of the nuclear agency was reported earlier by Politico.

Microsoft spokesman Frank Shaw said the company had found malicious code “in our environment, which we isolated and removed.”

“We have not found evidence of access to production services or customer data,” he said in a tweet. “Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others.” Reuters had earlier reported that Microsoft was hacked and that its products were used to further the attacks.

In addition, two people familiar with the broader government investigation into the attack said three state governments were breached, though they wouldn’t identify the states. A third person familiar with the probe confirmed that state governments were hacked but didn’t provide a number.

Biden’s Pledge

While President Donald Trump has yet to publicly address the hack, President-elect Joe Biden issued a statement Thursday on “what appears to be a massive cybersecurity breach affecting potentially thousands of victims, including U.S. companies and federal government entities.”

“I want to be clear: My administration will make cybersecurity a top priority at every level of government — and we will make dealing with this breach a top priority from the moment we take office,” Biden said, pledging to impose “substantial costs on those responsible for such malicious attacks.”

Russia has denied any involvement in the attack.

Hynes, the Department of Energy spokeswoman, said that efforts were immediately taken to mitigate the risk from the hack, including disconnecting software “identified as being vulnerable to this attack.”

–With assistance from Ari Natter and Dina Bass.

New story in Technology from Time: Cyberpunk 2077 Is a Mess On Every Level



Cyberpunk 2077 and the constellation of controversy orbiting it—at nearly every level of its making—is almost laughable. The open-world shooter game, developed by Polish studio CD Projekt Red, was billed as the next big thing in video games, an experience that would impress both visually and narratively. From a huge city full of opportunities to an arsenal of upgradable elements for your customizable character, how could one not be enticed by the previews ahead of the Dec. 10 release? Hell, it’s even got Keanu Reeves in it, and a lot of him!

In hindsight, Cyberpunk 2077’s seven-year lead up didn’t do it any favors. After all, you can only rely on hype for so long.

Since release, players have experienced a broken, incomplete title pockmarked with bugs and errors so extensive many found themselves unable to make much progress, myself included. In the aftermath of its controversial launch, CD Projekt Red admitted to relying on the harmful practice of crunch—demanding longer hours from employees for weeks or months at a time—in order to finish development. The game’s available on last-gen consoles, but looks like garbage on them. Accessibility issues led people with epilepsy to have seizures during gameplay, an issue that’s since been addressed, but should never have been a problem in the first place. Facing intense disappointment from fans who long awaited the game, the studio announced Tuesday that unhappy players can get a refund, though some are having trouble getting their money back from outlets like GameStop and Sony’s PlayStation Store.

In short, Cyberpunk has a tough 2021 ahead before it can think about 2077.

In Cyberpunk 2077’s gritty reimagining of America, you play as “V,” your custom-made ne’er-do-well thrown into mercenary life after a fall from grace. Following a botched heist that puts a time limit on your lifespan, you go on a journey through the seedy underbelly of Night City to make deals with crooks, gangs, cops, and corporations in search of a cure for your terminal illness that manifests as a virtual hologram of a certain Night City celebrity.

Night City itself, as with the rest of Cyberpunk, is only “edgy” as defined by a 14-year-old in 2004. It’s replete with Blade Runner-esque neon lights and holograms complete with more than suggestive advertisements. Everyone and their grandma has a cybernetic enhancement. Dildos litter the street, and you can use them as components in the game’s crafting system. Transphobic ads mar an already garish world that lacks any sort of subtext or nuance. The environmental “jokes” don’t land, and offensive jabs are present throughout, giving me pause as to the game’s target audience.

Look, I get it. It’s cyberpunk! The gritty future, baby! Everything is chromed out, gaudy advertisements run amok, corporations run everything, and the line between law enforcement and lawlessness is as thin as the card full of eddies you pay your private security team (oh, and money is called “eddies” now). But that’s not enough to hold the fantasy together. Once you look a little deeper, or stand in the same spot for longer than four minutes, you start to notice the cracks.

It would be easier to praise the immersive world of Night City if it decided to stick around during gameplay. Cyberpunk’s open world is largely farcical, mostly an illusion meant to convey breadth without actually delivering. Whether or not you’ll see crowds milling about (as seen in various preview videos) is a crapshoot depending on where you’re standing and what your computer’s processing power can handle. My own playthrough left me befuddled after sprinting for a car that rounded a street corner only to disappear. Other players have found the world basically devoid of any advanced activity—people mill about aimlessly, cars are usually still, and cops you decide to help may randomly decide you’re the enemy should a single bullet go astray.

Patrick Austin

As you interact with Night City’s factions and gangs, you’ll quickly realize they’re disturbingly and stereotypically divided by race. As a Haitian-American, I took particular interest in the Haitian Voodoo Boys, one of the game’s many ethnically divided paint-by-numbers gangs. I can’t help but wonder what lack of imagination it took to put the primarily Haitian group—and the only black gang, full of the city’s most elite hackers—in the poorest part of town (V also makes a surprisingly racist comment in a Haitian doctor’s office, catching me off guard). It’s also confusing how much the gang relies on the exaggerated vodou aesthetic only to have the characters explicitly state they have abandoned the concept of god, “leaving them” on Haiti (despite the fact that Haiti is predominantly Roman Catholic). At least their Creole isn’t bad, I suppose.

This game is full of similar letdowns. It has intricate RPG elements, with a complex and tiered leveling system that gives you points for doing everything from helping the Night City Police Department (gross) to taking apart junk you find in the street. But there’s nothing new happening. If you’re familiar with open-world adventure games like Fallout or Grand Theft Auto, Cyberpunk 2077 will feel predictable—and all the bugs will make you realize how much fun those other games are by comparison.

On the right hardware, Cyberpunk 2077 is visually stunning—just be prepared to spend thousands of dollars for the best experience. Until then, your options are to play it on your PC and hope it runs properly, or stream it. There’s no “true” PlayStation 5 or Xbox Series S/X version of the game just yet, those are scheduled for release in 2021. You can still play it on the consoles, but they’ll be running the PS4 or Xbox One version of the title. Streaming options, like Nvidia’s GeForce Now and Google Stadia, can give you a pretty good approximation of playing on a high-end gaming PC, as long as your internet connection is quick and lag-free enough.

The game’s main storylines are pretty engaging, from the moment you meet Reeves’ character, Johnny Silverhand, to your last interaction with it. When the game’s set pieces work, they work quite well. Stealth elements are forgiving, letting you make risky and exciting dodges behind crates and cars. I felt a thrill concocting a plan using enemy-disabling “quickhacks” to take out four gangsters out without firing a single bullet, only to have it fall apart at the last second when a fifth suddenly appeared. Instead of blowing his head off, I opted to use more of V’s computer-based attacks, frying his brain before he could make a move.

But by the end of the game, I found myself relying on good old-fashioned bullets rather than those special abilities, akin to a wizard’s spells. Ironically, the unreliable hacking system sometimes worked only after repeated attempts. It makes you wonder if all the bugs in Cyberpunk add up to some sort of experiential art piece, where the glitches are a metaphor for the errors prevalent throughout Night City’s society.

Then there are the implications of the world Cyberpunk 2077 paints—a world where most people are cybernetically enhanced, be it with robotic limbs or synthetic organs. You must have a pretty good reason for removing your perfectly good legs or arms or face and replacing them with robotic prosthesis, right? Yet the game never really explains why everyone looks like they just crawled out of a Best Buy dumpster. The game opens with a very cool scene that puts you in the chair at your local “ripperdoc” office, where an automated tool tattoos a cybernetic attachment to your palm. Yet as you get even more invasive items installed, none of that attention to detail is present. There’s no mention of your natural limbs’ fate as they are removed without fanfare, and only sometimes reattached.

Cyberpunk 2077 left me both disappointed and frustrated. When it actually works, it’s somehow both enjoyable to play but incredibly difficult to stomach. But between the largely unplayable overall experience to its use of tried stereotypes of people of color and transphobic imagery in a misguided pursuit of “cool,” Cyberpunk is an undeniable mess. It’s a broken promise made to consumers who assumed it would look as advertised on their last-gen game consoles, complete with unforced errors and disingenuous apologies to both the studio’s own staff and to players who pre-ordered it sight unseen (The studio says Cyberpunk has already recouped its nearly decade-long marketing and developer costs from presales alone; it would likely have been a commercial flop in a world where people wait to read reviews before committing their money to new game.)

So let me be clear. If you still want to play Cyberbunk 2077 and own a next-gen console or a PC that exceeds the system requirements, you should avoid it for a few months while the issues are worked out and a dedicated version for those consoles is available. If you’ve got an Xbox One or PlayStation 4, you probably shouldn’t buy this game at all. If you’re mad about one of the most anticipated games of the decade turning out to be a hot mess, don’t worry. Everyone is.

Tuesday, 15 December 2020

New story in Technology from Time: European Union Announces Sweeping New Regulations Against Big Tech Companies



Big tech companies could face multibillion dollar fines in Europe and the threat of being broken up unless they comply with sweeping new regulations announced by the European Commission on Tuesday.

After years of wrangling in the U.S. over whether to hold tech companies accountable for data practices and anticompetitive behavior, the new rules in the E.U.—which has a total population of some 450 million across 27 countries —could force tech companies to change their practices globally.

The E.U. regulations come in the form of two new laws, one called the Digital Services Act and another called the Digital Markets Act. Both still need to undergo a consultation period and then be passed by European lawmakers, a process which could take years.

The Digital Services Act (DSA) would introduce new obligations on platforms to reveal information and data to regulators about how their algorithms work, how decisions are made to remove content, and how adverts are targeted at users. Many of its provisions only apply to platforms with more than 45 million users, a threshold surpassed by several services including Facebook, YouTube, Twitter and TikTok.

“With size comes responsibility,” said Margrethe Vestager, the European Commissioner for competition, on Tuesday.

Fines for failing to comply with the rules can be up to 6% of a company’s annual revenue—a sum which if levied at Facebook, for example, would amount to $4.2 billion.

Meanwhile on Tuesday, the U.K. government is also expected to announce a similar law that if passed would include fines of up to 10% of annual global turnover for platforms that fail to remove illegal content.

The other law announced by the European Commission on Tuesday, the Digital Markets Act (DMA), is closer to antitrust legislation. It aims to give smaller companies greater ability to compete with big tech platforms, which some European lawmakers have long thought of as monopolistic entities. Repeat violations of this law could lead to big tech companies being broken up, Vestager said. Fines for anti-competitive behavior could amount to up to 10% of a company’s annual turnover, and the E.U. will attempt to break up repeat offenders fined three times within five years.

Experts say the regulation could have consequences for tech companies beyond the borders of the E.U. “Europe increasingly sees itself as a trailblazer for what it sees as tech-savvy, human rights-proof tech regulations,” says Mathias Vermeulen, the public policy director at data rights consultancy AWO. “The mere fact that these companies will be forced to improve their content moderation and content distribution mechanisms—that is going to lead to a change in practices in the U.S., for instance. If you’re a global company, and you have to deal with new obligations in one very big and crucial market, then similar features could be taken up elsewhere even though there’s no hard requirement to do so.”

What is the Digital Services Act?

The DSA is aimed at improving what many European lawmakers see as the lack of oversight over large tech companies.

“The problem is that now tech companies can say they’ve been taking measures, but there’s absolutely no independent third party who can verify their figures,” Vermeulen says. “The idea with the Digital Services Act is to exercise more democratic control over how our rights are being affected by the products of these companies.”

The act obliges platforms with more than 45 million users in the E.U. to tell users in plain language the “main parameters” used in algorithms that rank content, and allow users to “select and modify their preferred option” for algorithms that determine the “relative order of information presented to them.” In a measure that appears tailored to allow users to opt out of having algorithms serve up content based on their past activity, it says platforms must offer users at least one option which is “not based on profiling,” according to a draft copy of the act seen by TIME.

When it comes to illegal content, the act upholds existing E.U. principles that—similarly to the U.S.— platforms should not be held accountable for illegal content posted by users. But it does state that if platforms do not act quickly to make that content inaccessible once they are made aware of it, they could be held liable.

The act does not expand the definition of illegal content. But it does lay out a list of content that is already illegal that the new regulations apply to, including illegal hate speech, terrorist content, images of child sexual abuse, non-consensual sharing of private images, stalking, counterfeit products, and copyright violations.

The act doesn’t spend much time discussing details of what content should be counted as illegal. Instead, it states that companies must carry out their own “risk assessments” about how their services could be used to spread illegal content or allow manipulation that has “an actual or foreseeable negative effect on the protection of public health, minors, civic discourse … electoral processes and public security.” It obliges platforms to then act to “mitigate” those risks.

“Before, the trend was to hold companies responsible for specific pieces of content that could still be found on their site,” says Vermeulen. “But this is more of a holistic vision, looking at what these companies are doing to address the risks their systems are posing.”

Amid pressure on social media companies for their role in amplifying political extremism across the globe, the act will give European regulators more power to demand information from tech companies about how both their moderation teams and their algorithms work at scale. The threat of large fines, officials hope, will force companies to roll out new institutional practices even before a single fine is imposed.

Alongside fines of 6% of turnover for failure to comply with the regulations, the DSA says that platforms must also allow regulators insight into how their systems work—with fines of up to 1% of annual revenue if platforms “supply incorrect, incomplete or misleading information” to regulators, or “refuse to submit to an on-site inspection,” according to a draft copy of the act seen by TIME.

The DSA says that those obligations will be accompanied by the ability to enforce changes to tech companies’ services, including “discontinuing advertising revenue for specific content, or other actions, such as improving the visibility of authoritative information sources,” according to the draft legislation.

In the Brexit referendum and 2016 U.S. election, so-called “dark ads” were common on social media platforms—adverts without any accompanying information about their funding or why they were targeted at users. The DSA introduces a legal requirement for platforms to maintain libraries of historical ads, and give people who see the ads more detailed information about the reasons they are being targeted. “Recipients of the service should have information on the main parameters used for determining that specific advertising is to be displayed to them, providing meaningful explanations of the logic used to that end, including when this is based on profiling,” the draft states. (Platforms including Facebook and Twitter have already introduced measures along these lines.)

What is the Digital Markets Act?

With the development of the technology sector, economic activity increasingly happens online—but in some cases “online” means within the bounds of specific services designed by big tech companies. Think buying an app through the Apple app store, or buying goods on Amazon.

Systems like that open the door to anticompetitive behavior, E.U. officials say. In November, the European Commission said it believed Amazon was acting anti-competitively by collecting data on independent sellers that use the Amazon platform, and using that data to benefit Amazon’s own competitior products.

Just as its sister legislation only targets companies with more than 45 million users, the Digital Markets Act only targets “gatekeeper” companies, or those defined–at some point in the future–as dictating the terms of a marketplace.

The act makes three main provisions: forcing “gatekeeper” companies to act fairly by not using competitors’ data to disadvantage them; by enforcing interoperability, allowing users to take their data elsewhere and still interact with their services; and by not treating their own services more favorably than competitors that use their platform.

“The business and political interests of a handful of companies should not dictate our future,” wrote Margrethe Vestager and Thierry Breton on Sunday, the two European commissioners leading on the regulations. “Europe has to set its own terms and conditions.”

Along with fines of up to 10% of global turnover for violations of antitrust law, the European Commission threatens that it could break up the businesses of repeat offenders—a step further than anything the incoming Biden Administration has pledged to do. “If a gatekeeper breaks the rules … several times repeatedly, we can also impose structural remedies, divestiture, that sort of thing,” Vestager said on Tuesday. (The E.U. has fined big tech companies for antitrust violations before — the most expensive instance being a $4.3 billion fine against Google in 2018.)

“The Digital Markets Act imposes new obligations on these so-called gatekeeper companies, which have enormous power to control the markets they are operating in,” says Vermeulen. “This is mainly geared at marketplaces, search engines, operating systems and cloud services. It would prohibit companies from giving preferential treatment to their own products and services in, for instance, search rankings.”

Monday, 14 December 2020

New story in Technology from Time: People Are Finally Downloading COVID-19 Exposure Notification Apps. Will They Make a Difference?



In the early weeks of the U.S. COVID-19 outbreak this spring, technologists pushed forward an idea to help bring the spread of the new virus under control: smartphones could notify users who had potentially been exposed to others with COVID-19, transforming millions of devices into the world’s most efficient army of public health contact tracers. Big tech got on board, with Apple and Google jointly releasing software in May that enabled state and national public health departments to build such “exposure notification” (EN) apps.

But as the pandemic burned through the country, slow development, sparse public outreach and suspicion of the new software from both states and users stymied the effort for months. Over the summer, only six states released apps using the software; just four more joined by October. Even in states that released EN apps, adoption was often agonizingly slow, with downloads far outpaced by similar efforts in countries like Ireland, where around a third of adults were using COVID-19-tracking apps as of November. In Alabama, only 3% of the state’s adult population had downloaded the state’s EN app by late October, more than two months after launch; by early December, that number was still just 4.6%. North Carolina and Pennsylvania, which both launched EN apps in late September, each managed to get around 6% of their adult populations on board as of early December.

But EN app adoption rates in some states are now skyrocketing by comparison, thanks in part to a new approach from Apple and Google. States using the new protocol, called Exposure Notifications Express (EN Express) and launched in September, can quickly and easily deploy a basic, pre-formatted version of the Apple/Google-enabled contact tracing apps, saving costs and development time. EN Express also lets states send push notifications encouraging residents to opt in, a feature that appears to be driving faster adoption.

Some states that recently launched apps with the updated approach have leapt ahead in sign ups, offering a glimmer of hope that smartphone-based exposure notification technology might finally start helping to mitigate the spread of COVID-19 in the U.S. Colorado, which launched EN Express in late October, signed up the equivalent of more than 28% of adults by the end of November. In Washington state, which launched EN Express on Nov. 30, nearly 17% of the state’s adults enabled the software in just four days. Adoption of Connecticut’s EN Express app topped 20% less than a week after it launched in mid-November. California’s state health department estimates that 13% of adults opted in within a day after it launched an EX Express app on Dec. 10. And in Nevada, where only 5% of adults were using an app published in late August, the launch of a complimentary EN Express service on Dec. 10 led to adoption of more than 9% in just four days.

Nowhere is the contrast between the old and new systems sharper than in Maryland and Virginia. Virginia launched the first U.S. Exposure Notifications app in August, and slowly accumulated users through aggressive outreach in what had been one of the country’s most successful adoption efforts so far; 13% of Virginia adults were signed up by December. Just across the border in Maryland, officials launched the state’s first exposure notification app, using EN Express, in mid-November. By month’s end, more than a quarter of the state’s adults had signed up, leapfrogging Virginia’s months-long effort in just weeks.

“Our delay was somewhat intentional,” says Kathleen Feldman, chief public health scientist at Maryland’s Department of Health. While Virginia was rushing to deploy a contact tracing app this summer, Maryland public health officials put their resources toward traditional contact tracing efforts while waiting to see how newer digital efforts worked out elsewhere, Feldman says. When Maryland’s program finally launched, they were able to take advantage of EN Express, which was not available when Virginia launched its app.

Colorado officials also intentionally waited to deploy an Exposure Notifications app. “When EN Express became an option, it was clear to us that the technology had matured,” says Sarah Tuneberg, leader of Colorado’s Coronavirus Innovation Response Team. Among the factors that helped spur adoption, Tuneberg cites the simpler user experience (on iPhones, for instance, users can turn on EN Express in their settings instead of downloading an app) as well as the fact that the state didn’t need to contract a private developer to build its app, and could devote those resources toward outreach instead.

“We know that states don’t have great adoption of apps you have to download from an app store,” says Tuneberg. “There was a service that didn’t require us to pay six, seven, eight figures…it just made it the right time for us.”

In Virginia, officials are planning to launch EN Express to supplement their contact tracing app (the two approaches are intercompatible, and both use the same underlying system). But other states, like North Carolina, Alabama and Delaware, which have released coronavirus-tracking apps but where adoption has been slower than that of many states using EN Express, still don’t have plans to use the newer tool. Representatives at Apple say they recommend all states adopt EN Express, even if they have already built their own app.

Still, even in states with high adoption rates, it’s difficult to tell how much difference the software is making in the fight against the pandemic. Health officials and technologists often argue that 15% adoption could reduce COVID-19 infections by 15% and deaths by 11%, a statistic based on modeling published by Oxford University and Google this fall. Either way, with EN Express substantially reducing the upfront investment for state governments, it seems likely that more states will get on board. “I think [EN Express] is helping,” says Tuneberg of Colorado. “The funny thing about a global pandemic is that you don’t have a control group, so we won’t ever know exactly how efficacious it was. But it’s not harming anything.”

Sunday, 13 December 2020

New story in Technology from Time: Hackers Break Into U.S. Treasury and Commerce Departments



(WASHINGTON) — Hackers broke into the networks of federal agencies including the Treasury and Commerce departments in attacks revealed just days after U.S. officials warned that cyber actors linked to the Russian government were exploiting vulnerabilities to target sensitive data.

The FBI and the Department of Homeland Security’s cybersecurity arm are investigating what experts and former officials said appeared to be a large-scale penetration of U.S. government agencies.

“This can turn into one of the most impactful espionage campaigns on record,” said cybersecurity expert Dmitri Alperovitch.

The hacks were revealed just days after a major cybersecurity firm disclosed that foreign government hackers had broken into its network and stolen the company’s own hacking tools. Many experts suspect Russia is responsible for the attack against FireEye, a major cybersecurity player whose customers include federal, state and local governments and top global corporations.

The apparent conduit for the Treasury and Commerce Department hacks — and the FireEye compromise — is a hugely popular piece of server software called SolarWinds. It is used by hundreds of thousands of organizations globally, including most Fortune 500 companies and multiple U.S. government agencies who will now be scrambling to patch up their networks, said Alperovitch, the former chief technical officer of the cybersecurity firm CrowdStrike.

The attacks were disclosed less than a week after a National Security Agency advisory warned that Russian government hackers were exploiting vulnerabilities in a system used by the federal government, “allowing the actors access to protected data.”

The U.S. government did not publicly identify Russia as the culprit behind the hacks, first reported by Reuters, and said little about who might be responsible.

National Security Council spokesperson John Ullyot said in a statement that the government was “taking all necessary steps to identify and remedy any possible issues related to this situation.”

The government’s Cybersecurity and Infrastructure Security Agency said separately that it has been working with other agencies “regarding recently discovered activity on government networks. CISA is providing technical assistance to affected entities as they work to identify and mitigate any potential compromises.”

President Donald Trump last month fired the director of CISA, Chris Krebs, after Krebs vouched for the integrity of the presidential election and disputed Trump’s claims of widespread electoral fraud.

In a tweet Sunday, Krebs said “hacks of this type take exceptional tradecraft and time” and raised the possibility that it had been underway for months.

“This thing is still early, I suspect,” Krebs wrote.

Federal government agencies have long been attractive targets for foreign hackers.

Hackers linked to Russia were able to break into the State Department’s email system in 2014, infecting it so thoroughly that it had to be cut off from the internet while experts worked to eliminate the infestation.

Reuters earlier reported that a group backed by a foreign government stole information from Treasury and a Commerce Department agency responsible for deciding internet and telecommunications policy.

The Treasury Department deferred comment to the National Security Council. A Commerce Department spokesperson confirmed a “breach in one of our bureaus” and said “we have asked CISA and the FBI to investigate.” The FBI had no immediate comment.

The Washington Post reported Sunday, citing three unnamed sources, that the two federal agencies and FireEye were all breached through the SolarWinds network management system.

Austin, Texas-based SolarWinds confirmed Sunday in an email to The Associated Press that it has a “potential vulnerability” related to updates released earlier this year to its Orion products, which help organizations monitor their online networks for problems or outages.

“We believe that this vulnerability is the result of a highly-sophisticated, targeted and manual supply chain attack by a nation state,” said SolarWinds CEO Kevin Thompson in a statement.

The comprise is critical because SolarWinds would give a hacker “God-mode” access to the network, making everything visible, said Alperovitch.

Last Tuesday, FireEye said that foreign government hackers with “world-class capabilities” broke into its network and stole offensive tools it uses to probe the defenses of its thousands of customers. Those customers include federal, state and local governments and top global corporations.

The hackers “primarily sought information related to certain government customers,” FireEye CEO Kevin Mandia said in a statement, without naming them. He said there was no indication they got customer information from the company’s consulting or breach-response businesses or threat-intelligence data it collects.

Former NSA hacker Jake Williams said it seemed clear that both the Treasury Department and FireEye were hacked using the same vulnerability.

“The timing of the release here is, I think, not at all a coincidence,” said Williams, the president of the cybersecurity firm Rendition Infosec.

He said FireEye surely told the FBI and other federal partners how it had been hacked and they determined that Treasury had been similarly compromised.

“I suspect that there’s a number of other (federal) agencies we’re going to hear from this week that have also been hit,” Williams added.

FireEye responded to the Sony and Equifax data breaches and helped Saudi Arabia thwart an oil industry cyberattack — and has played a key role in identifying Russia as the protagonist in numerous aggressions in the burgeoning netherworld of global digital conflict.

Neither Mandia nor a FireEye spokesperson said when the company detected the hack or who might be responsible. But many in the cybersecurity community suspect Russia.

___

Krisher reported from Detroit and Bajak reported from Boston. Associated Press writer Matt O’Brien contributed to this report from Providence, R.I.

Fox News Breaking News Alert

Fox News Breaking News Alert

White House confirms cyberattack on U.S. Treasury by foreign government.

12/13/20 2:24 PM

Ad 1