Thursday, 18 March 2021

New story in Technology from Time: Facebook Is Building ‘Instagram Kids’ for Children Under 13



Facebook is building a version of the photo-sharing tool Instagram specifically for children under the age of 13, an effort to get its popular products into the hands of the next generation of internet users.

The new app was announced internally Thursday, but is not yet launched. Instagram currently requires that users must be at least 13 years old. BuzzFeed News previously reported on Instagram Kids.

Instagram, bought by Facebook almost a decade ago for $1 billion, has become one of its most popular products at a time when its main social networking property has failed to resonate with some younger users.

“Increasingly kids are asking their parents if they can join apps that help them keep up with their friends,” Joe Osborne, a Facebook spokesman, said in a statement. “Right now there aren’t many options for parents, so we’re working on building additional products — like we did with Messenger Kids — that are suitable for kids, managed by parents. We’re exploring bringing a parent-controlled experience to Instagram to help kids keep up with their friends, discover new hobbies and interests, and more.”

Messenger Kids is a version of Facebook’s messaging app for pre-teens. That app includes a number of parental controls, but a flaw previously allowed some kids to chat with people their parents had not approved. The incident sparked concern from regulators that it didn’t adequately protect children.

New story in Technology from Time: Digital NFT Art Is Booming—But at What Cost?



In central Washington State, electric utilities are watching for homes with oddly high power usage after a recent surge in cryptocurrency prices collided with a boom in NFTs, or “non-fungible tokens”—an emerging technology that uses crypto platforms to authenticate ownership of digital files. In an emerging hype cycle, such digital assets have sold at auction for millions of dollars, giving the buyer claim to an “original” version of a computer file, such as a piece of digital art or a sports highlight video.

During the last crypto boom, the region—home to some of the cheapest electricity in the U.S.—was beset by a new energy-hungry home industry: basements and sheds loaded with racks of computers churning through advanced mathematical calculations in order to “mine” valuable crypto coins like Bitcoin or Ethereum. Even those small mining operations can overload local grids, creating a problem for local utilities. Around the world, vastly larger cryptocurrency operations have sprung up from Texas to Iran to China’s Inner Mongoliaalmost anywhere miners can hook up to cheap electricity—filling air-conditioned, warehouse-sized spaces with endless rows of high powered computers running software to essentially convert energy into wealth.

While NFTs hold promise, critics say the mining that makes them possible is perhaps humanity’s most direct way of making money by polluting the planet–­Ethereum mining consumes about 26.5 terawatt-­hours of electricity a year, nearly as much as the entire country of Ireland and its almost 5 million residents. In theory, all mining energy could come from renewable sources, but right now, there is money to be made by essentially converting cheap fossil fuels into valuable cryptocurrencies. And for an asset with no physical presence or utility outside the digital realm, the process of producing the “coins” is tremendously inefficient–one 2018 study found that cryptocurrency mining consumes more energy for every dollar of value generated than extracting gold or copper.

“This is just heartbreaking in so many aspects,” says Camilo Mora, a professor of geography and environment at the University of Hawaii, Manoa. “Not only the environmental [toll], but the social and ethical.”

All this may come as a surprise to artists and others adopting NFTs, in part because they’re far removed from the technology’s environmental cost. If a digital artist wants to sell an NFT, they first have to “tokenize” their work on a blockchain, which is a kind of tamper-resistant digital public ledger; many use the Ethereum blockchain. To do that, they pay Ethereum miners a fee of up to a few hundred dollars to have their computers crank out the necessary calculations. But from the artist’s perspective, they’re just paying money on a website to get a token in return, masking the environmental cost. “If you are buying an artwork you don’t see those calculations going on,” says Alex de Vries, a financial economist and founder of Digiconomist, a site that explores the unforeseen consequences of technology trends. “You don’t see your money is going to a miner who’s going to pay for fossil fuel-based energy with it. That’s a real problem.”

This issue–an “externality,” in economist-speak–extends far beyond the digital art world. It’s long been a problem for Bitcoin, the largest and most mainstream cryptocurrency, and it only stands to become a bigger dilemma as other kinds of assets, like financial securities and real estate, also become tokenized. Some in the crypto world are working on solutions. The developers of Ethereum itself, for instance, promise to launch a new framework that would use orders of magnitude less energy than the current system by 2022. But cryptocurrencies like Ethereum have taken off in part because they’re decentralized, which attracts techno-libertarians and others intrigued by the idea of currencies and assets unmoored from a government or central bank. That decentralization means there’s no single leader or body that could force everyone using Ethereum to shift to a new, more efficient system. “It’s pretty much guaranteed that miners will continue to run Ethereum in its current form,” says de Vries, pointing to the millions of dollars that Ethereum miners have already poured into their setups.

For now, this year’s NFT craze appears destined to not only fuel coal-hungry server farms from the Texas plains to the Caucasus, but also to power a new wave of hype around cryptocurrencies more broadly, incentivizing the creation of yet more massive and wasteful mining operations. Still, the recent boom is raising fresh awareness of crypto’s environmental toll, and there’s a chance that activism could lead to real change–but many are skeptical that enough will be done in time. “This was a game,” says Mora. “It’s turning into a disaster.”

Monday, 15 March 2021

New story in Technology from Time: Exploring the Wild World of Weird Homes on Zillow Can Be a Cabin Fever Cure



If you’ve ever spent time surfing real estate sites like Zillow, Trulia or Redfin, then you’ve probably come across listings with design choices that left you scratching your head. But seeing an otherwise relatively normal house is different than stumbling upon something so eye-catchingly bizarre that it deserves to be shared with the rest of the world.

While browsing house hunting sites isn’t a new hobby, with many people spending the majority of the past year stuck inside their own homes, Zillow usage has soared. In November, the New York Times reported that online visitors to for-sale listings was up more than 50 percent year-over-year in the early months of the pandemic.

But many of these users aren’t actually looking to buy a house. As Times reporter Taylor Lorenz succinctly put it, “What many are contemplating when they browse Zillow…is not necessarily a purchase, but an alternate life. Zillow surfing has become a primary form of escapism for those who want to flee not just their homes but the reality of 2020.”

Part of the fun of whiling hours away on Zillow is that you can fantasize about living anywhere—from a luxurious penthouse to a cozy beachside bungalow—and hopefully shed some of the pandemic cabin fever.

But it’s also undoubtedly fun to tour homes that aren’t somewhere you’d necessarily want to live. Those houses, which run the gamut from wonderfully weird to “cursed,” are the listings that often go viral.

Social media accounts like Zillow Gone Wild, which exists on both Twitter and Instagram, round up the “best (worst)” Zillow findings sent in by nearly one million collective followers. Recent gems include a $119,000 one bedroom, one bathroom apartment filled with large safari animal statues—including a giraffe peering into the shower.

The comments on these posts say it all. “How do you get to this house? Just open up that Jumanji board game and you’re there,” one Instagram user said, prompting another to respond, “But can you get OUT is the real question!”

Another eye-opening listing is a $555,000 two bedroom, two bathroom house with, er, open-concept bathrooms.

Kacey Musgraves said what most of us were thinking about the bathtub sitting on the edge of a second-story ledge: “This is an ‘accidental’-forensic files-fall scenario if I’ve ever seen one.”

But sometimes, it’s the listings that Zillow surfers find and share on their own accounts that offer the best window into the wild world of weird real estate. In February, a $650,000 duplex in Lake Tahoe—notably listed to be sold “as-is”—earned the internet’s attention when viewers discovered that one of its units was filled with posed mannequins dressed in elaborate ballgowns.

“Please please please please look at this absolutely cursed Zillow listing my friend Ashley sent me,” Twitter user Rave Sashayed captioned her post about the home. “There is literally no way to anticipate or prepare for what reveals itself to you in this house.”

Of course, that’s not the only truly spectacular Zillow find of recent months. We must mention the infamous $2.2 million New Jersey mansion overflowing with Christmas decorations—including 81 wreaths, 30 trees, 20 nutcrackers, 38 Santa figurines, 14 nativity scenes, 115 religious statues, and 238 angels—that popped up on Zillow in November. And then there’s the $1.5 million seemingly Hard Rock Cafe-themed Omaha penthouse that Twitter account The Best of Zillow tweeted out in February.

If you go a little further back to May 2020, a Twitter user even unearthed the perfect Zillow listing to accompany accepting the harsh reality of being home for months on end: a $160,000 two-story converted Pittsburgh ranch complete with a “25th-century starship” dining room and an indoor beach bedroom. “A talking space alien greets you as you walk toward the floor-to-ceiling, outer space wall mural,” the listing adds.

“Each successive photo reveals another genre-themed room, with an increasing level of commitment,” @frazierapproves told Bored Panda of his viral discovery, which garnered nearly 130,000 likes on Twitter. “It’s like a miniature amusement park or a home-sized movie studio. It is simply the most amazing home I have ever seen.”

Whereas some browsers may have once turned their noses up at the intergalactic fun house, as one Twitter user said: “You have to admit, having your own beach in the basement would come in handy just about now.”

Then there are the homes where interior design quirks are the least of people’s focus. One striking example of this is the $350,000 former Missouri sheriff’s home outfitted with a hidden door leading to an old-fashioned jailhouse that made headlines last August.

While most people aren’t in the market for a home featuring nine fully functional jail cells, the listing realtor (this time on House of Brokers rather than Zillow) described the property as a “unique opportunity” where the “possibilities are amazing.”

Ultimately, the homes featured here barely scratch the surface of what Zillow has to offer in terms of “unique opportunity” real estate. Whether or not you’re in the market to purchase a home, virtually touring other people’s can provide ample distraction from the stresses of being stuck inside your own.

And be on the lookout for some exceptionally strange sights.

Sunday, 14 March 2021

New story in Technology from Time: Why Video Calls Leave Us Lonelier and More Stressed



A version of this article appeared in this week’s It’s Not Just You newsletter. SUBSCRIBE HERE to have an essay delivered to your inbox every Sunday.

My friend Haley called me the other day. She hadn’t texted me in advance to “find a time” to chat. Nor did we have a Zoom date “on the calendar.” She just up and called me unannounced.

It was thrilling, this unscheduled, spontaneous conversation without a purpose or the weight of a formal catch-up. This felt like wheeling over to someone in the office to hear a joke.

I was reminded of that larger orbit of friendships outside the inner core of those we still see in person, usually because we live with them.

<strong>Think about all those relationships once sustained by serendipity and proximity, now starved by a year of social distancing.</strong>

In what may be the world’s largest sociological experiment, many of us have had to rely almost completely on technology to tend these friendships. We now have a whole new cadre of Appointment Friendships.

And even with committed scheduling, it’s not really enough. A recent study from researchers at the University of Nevada, Las Vegas, confirms what we now know in our exhausted hearts: video calls, texts, social media, even phone calls are a great supplement to face-to-face interactions, but they aren’t a substitute.

Contrary to what you might expect, the more sophisticated the technology, the less it satisfies our need for connection.

Researchers reported that the humble phone call was associated with decreases in stress, loneliness, and relationship difficulties. Meanwhile, video chats were associated with increased stress, loneliness, and difficulties in maintaining relationships. I get it, we’re less self-conscious on the phone, and you can multitask and talk–maybe fold laundry or eat or both. With video, that uncanny valley of almost being there tends to make you long for the real thing.

Sign up to get an essay delivered to your inbox every Sunday.

The UNLV researchers also reported that social media posting, commenting, and sharing was the “modality most strongly associated with stress.”

No one is less surprised about all this than Sherry Turkle, a clinical psychologist at M.I.T. She’s been studying how technology affects our capacity for empathy and connection since the first Apple computer showed up with a smiley face, reporting her findings in two seminal books: “Reclaiming Conversation” and “Alone Together.”

When I spoke to her a few weeks ago, she’d just published her memoir, “The Empathy Diaries,” which is about becoming one of very few women at M.I.T. and one who was willing to challenge the enduring gospel of the engineering universe: that technology would solve the problems it caused.

<strong>In the crucible of enforced isolation, we explored the limits of where our screens can take us. As technology became our lifeline, we realized how much we missed the full embrace of the human.</strong>Turkle finished working on this book during pandemic shutdowns, which were akin to a real-world test of her life’s work. She writes:

The question now is whether we’ve gotten so used to the disconnect of screen communications, so seduced by the convenience and cost savings, that even when we can interact in person, there will be a net increase in the time we spend communicating via screens. Turkle urges us not to settle for a 2D life.

“The amazing thing about living through dramatic change is you are right there when something that once seemed odd begins to seem natural,” says Turkle. “The trick is to remember why it once seemed odd because that might be a reason worth remembering.”

The price for forgetting may be an increase in loneliness which was already epidemic before the pandemic. I “The first step is distancing ourselves from this new normal to reclaim our complex selves.”

It seems impossible now that we won’t remember how precious it is to communicate without texting or posting, or even talking. There’s so much beyond the clumsiness of words, like a hand on your arm at the right moment, or the gentle camaraderie of silence. 💌


If you’re new to It’s Not Just You, SUBSCRIBE HERE to get a weekly essay delivered to your inbox every Sunday for free. And write to me any time: Susanna@time.com.


In The Empathy Diaries,” Sherry Turkle’s story starts before her work as a clinical psychologist at M.I.T., where she holds an endowed chair. It’s a coming-of-age story about a girl who grew up in post-war Brooklyn and transformed feelings of being an outsider into a quest to understand others and to advocate for empathy and humanity in the face of massive technological transformations.


If you’re new to It’s Not Just You, SUBSCRIBE HERE to get a weekly dose delivered to your inbox every Sunday for free. And write to me any time: Susanna@time.com.


COPING KIT ⛱

What Daylight Savings Time Does to Your Brain Carl Johnson, a chronobiologist at Vanderbilt University says our bodies never really adjust to this annual leap into the future: “Our biologic, natural sun and social clocks have drifted apart.” So be easy on yourself.

If you haven’t listened to Mike Birbiglia’s “Working It Out Podcast,” in which he talks shop with other comedians, check out this episode with Taylor Tomlinson, who, at 27, already has a hit comedy special on Netflix, “Quarter-life Crisis.” The conversation gets very real and very funny about panic attacks, therapy, and parents.

Here’s to a glass half full: 48% of Americans now say they are “hopeful” — up from 20% who said they felt that way during the past year, according to a new Axios-Ipsos poll.

The world is indeed full of peril, and in it there are many dark places; but still there is much that is fair, and though in all lands love is now mingled with grief, it grows perhaps the greater.

J.R.R. Tolkien, The Fellowship of the Ring

 

This month, in honor of International Women’s Day, CARE is hosting a series of talks with fearless women who’ve shown leadership during the COVID-19 pandemic. See the lineup here. For a dose of inspiration, check out Chaka Khan and Idina Menzel‘s soaring remake of the anthem, #I’mEveryWoman, created for the occasion. And consider sending a Care Package to support women and girls in need around the world.

COMFORT CREATURES 🐕 🐈

Our weekly acknowledgment of the animals that help us make it through the storm.

Meet Cleo, comfort dog to my daughter Lily who is in her first year of medical school. Lily lives alone with Cleo. She caught Covid from a lab partner a few months ago. Cleo comforted Lily through her illness and is there with kisses at 5 a.m. when she gets up to study. Cleo also forces Lily to go out and play in the snow for much-needed breaks. And she gives comfort to Lily’s study buddies, too.

This lovely story shared by Nancy is a fine way to mark one year since the start of the pandemic:

SHARE this edition of It’s Not Just You on social. And you can send comfort creature photos and comments to: Susanna@time.com
Did someone forward you this newsletter? SUBSCRIBE to It’s Not Just You here.

Thursday, 11 March 2021

New story in Technology from Time: India’s New Internet Rules Are a Step Toward ‘Digital Authoritarianism,’ Activists Say. Here’s What They Will Mean



The Indian government must suspend sweeping new Internet regulations, 10 international NGOs said in an open letter Thursday.

The new rules, brought in by executive order in late February, give the Indian government an arsenal of muscular new powers that will force tech companies and news outlets to comply with government surveillance and censorship demands.

The rules increase the pressure on U.S. tech companies including Facebook, Twitter and WhatsApp to comply with what the letter’s authors say is an increasingly authoritarian Indian government—or risk losing access to India, their biggest market in the world, which many see as key to future growth.

The Indian government had been preparing the new rules for years, but published them amid an escalating protest movement by Indian farmers that has captured both national and international attention. In February, the Indian government clashed with Twitter over the company’s refusal of a government request to remove hundreds of posts by activists and politicians about the protests, with the company saying they constituted freedom of expression. After the Indian government threatened Twitter employees with jail time, Twitter eventually re-blocked most of the posts.

Read More: Why Twitter Blocked Accounts Linked to Farmers’ Protests in India

“Why the government brought this up now is deeply linked to the farmer protests,” says Raman Jit Singh Chima, the Asia-Pacific policy director at Access Now, one of the groups that signed the open letter criticizing the rules. “After the pushback they received from social media firms, who were contesting orders they were receiving, the government definitely wants to send a clear signal that ‘we are going to regulate you, and if you push back, it will result in more regulation overall.’”

Farmers cheer and wave flags near Kundli border in Haryana, India, as more tractors arrive from Punjab to participate in the ongoing farmers' protest at Singhu border to mark the 100th day of demonstrations against the farm laws on March 6
Anushree Fadnavis—ReutersFarmers cheer and wave flags near Kundli border in Haryana, India, as more tractors arrive from Punjab to participate in the ongoing farmers’ protest at Singhu border, to mark the 100th day of demonstrations on March 6.

India’s new rules come at a time when tech platforms are facing threats of regulation by Western governments over content including hate speech, misinformation, and incitement to violence. But the Indian rules are more worrying, the open letter says, because they are part of a wider push toward “digital authoritarianism,” including Internet shutdowns and arrests of journalists. Although the Indian rules also contain useful provisions like mandating transparency in cases when user content has been removed, they come with no clear mechanisms for tech companies to push back against potentially unlawful government demands.

“The rules change the fundamental Internet experience for any average user in India,” says Apar Gupta, executive director of India’s Internet Freedom Foundation. “Social media companies, streaming platforms and online news portals are now being brought under some level of direct government supervision,” he says. “These rules are a very stark illustration of a desire of the government to control the online conversation. They extend forms of regulation over areas that enrich any kind of democracy, and encourage self-censorship.”

What do the new rules say?

The rules force companies to remove content that the government says is illegal within three days of being notified, including content that threatens “the interests of the sovereignty and integrity of India,” public order, decency, morality, or incitement to an offense. The rules also state that platforms must hand over information about users to law enforcement upon request.

Encrypted messaging platforms like WhatsApp—which is owned by Facebook—will also be forced under the new rules to keep information on who the “first originator” of any message is, and provide it to the government upon demand. WhatsApp is already facing similar legislation in Brazil, its second-biggest market after India. And Western intelligence agencies have also pressured encrypted platforms to build “backdoors” into their messaging services.

WhatsApp did not respond to TIME’s request for comment, but its head Will Cathcart said the company was “still digesting them and understanding what they actually mean, or don’t mean,” in an interview on Big Technology, a podcast by journalist Alex Kantrowitz.

Cathcart suggested that WhatsApp may be prepared to bring legal cases in India if the rules meant breaking the end-to-end encryption that the chat service is based on. “If you’re talking about break[ing] encryption, it’s really hard for me to imagine being comfortable with it,” he said. “It’s hard for me to imagine even how you ask people to do that, I think it’s such a fundamental threat. So, we’ll stand and we’ll make our case, and we’ll argue.”

Facebook and Signal (an end-to-end encrypted messaging app that is growing in popularity in India) did not respond to TIME’s requests for comment.

Read More: The Inside Story of How Signal Became the Private Messaging App for an Age of Fear and Distrust

In a statement, Twitter said: “We are studying the updated guidelines, and we look forward to continued engagement with the Government of India to strike a balance between transparency, freedom of expression, and privacy … We believe that regulation is beneficial when it safeguards citizen’s fundamental rights and reinforces online freedom.”

India’s new rules also say that companies must appoint a resident Indian citizen to be a “chief compliance officer” who will be criminally liable for any failure to comply with the rules. “India’s worst-kept secret is that if you work in the Internet industry, you will face arrest threats and threats of prosecution on a regular basis,” Chima says. “They’re just trying to codify this in one place. The idea is that if you have one person, you can put them under so much pressure that it will force compliance.”

The open letter by the 10 activist groups called on tech companies to resist the new rules. “They should interpret and implement legal demands as narrowly as possible, to ensure the least possible restriction on expression, notify users, seek clarification or modification from authorities, and explore all legal options for challenge,” the letter said.

A child touches a TV screen displaying OTT streaming apps at his home in New Delhi, Feb. 25. India has rolled out new regulations for social media companies and digital streaming websites to make them more accountable for the online content shared on their platforms.
Altaf Qadri—APA child touches a TV screen displaying OTT streaming apps at his home in New Delhi, Feb. 25. India has rolled out new regulations for social media companies and digital streaming websites to make them more accountable for the online content shared on their platforms.

A chilling effect on the press

As well as social media and streaming platforms, the new rules also impose strict new limits on digital news platforms—where a small handful of Indian publications have managed to remain critical of the government. In March, India’s democracy rating was downgraded from “free” to “partly free” by the U.S.-based NGO Freedom House, which cited among other factors the government’s “rising intimidation of academics and journalists.”

Under the new rules, digital publications will be subject to oversight by government-run committees, with the power to block publication of stories, remove stories, or even shut down entire websites. One of the 10 signatories of the open letter on Thursday is Reporters Without Borders, an NGO that campaigns for press freedom worldwide.

“Digital media has been quite outspoken, and I see this clearly as a way to bring it to heel, to control it, and perhaps intimidate it,” says Sidharth Bhatia, a founding editor of The Wire, a leading online publication that regularly publishes content critical of the Indian government. “It is executive overreach of the worst kind.”

Read More: Press Watchdog Urges India to Drop Investigation Into Journalist Over COVID-19 Reporting

The new legislation could result in critical reporting being silenced, Bhatia says. “Let’s say we’re about to publish a story about somebody powerful,” he says. “In a normal journalistic way, we will probably send a message before publication saying we would like your point of view. That person could very well go and say ‘I fear they will publish a very damaging story against me, and it’s libelous, etc.’” If that were to happen, he says, the case would be escalated through two committees, that contain no representatives of the digital media, until it is heard by a senior bureaucrat in India’s Ministry of Information. “At that level, you’re not likely to want to go against the government,” Bhatia says.

The publisher of The Wire is challenging the government’s new rules in the Indian court system—a challenge that a Delhi high court judge upheld on Tuesday, with the case adjourned to April 16.

Bhatia says that if the new rules are allowed to stand, they will have a “terrible chilling effect” on Indian journalism. “There is already talk within the media of journalists self-censoring,” he says. “More and more will say it’s not worth the trouble.”

Monday, 8 March 2021

New story in Technology from Time: A Microsoft Server Hack Has Victims Scrambling to Stop Intruders



BOSTON — Victims of a massive global hack of Microsoft email server software — estimated in the tens of thousands by cybersecurity responders — hustled Monday to shore up infected systems and try to diminish chances that intruders might steal data or hobble their networks.

The White House has called the hack an “active threat” and said senior national security officials were addressing it.

The breach was discovered in early January and attributed to Chinese cyber spies targeting U.S. policy think tanks. Then in late February, five days before Microsoft issued a patch on March 2, there was an explosion of infiltrations by other intruders, piggybacking on the initial breach. Victims run the spectrum of organizations that run email servers, from mom-and-pop retailers to law firms, municipal governments, healthcare providers and manufacturers.

While the hack doesn’t pose the kind of national security threat as the more sophisticated SolarWinds campaign, which the Biden administration blames on Russian intelligence officers, it can be an existential threat for victims who didn’t install the patch in time and now have hackers lingering in their systems. The hack poses a new challenge for the White House, which even as it prepares to respond to the SolarWinds breach, must now grapple with a formidable and very different threat from China.

“I would say it’s a serious economic security threat because so many small companies out there can literally have their business destroyed through a targeted ransomware attack,” said Dmitri Alperovitch, former chief technical officer of the cybersecurity firm CrowdStrike.

He blames China for the global wave of infections that began Feb. 26, though other researchers say it’s too early to confidently attribute them. It’s a mystery how those hackers got wind of the initial breach because no one knew about this except a few researchers, Alperovitch said.

After the patch was released, a third wave of infections began, a piling on that typically occurs in such cases because Microsoft dominates the software market and offers a single point of attack.

Cybersecurity analysts trying to pull together a complete picture of the hack said their analyses concur with the figure of 30,000 U.S. victims published Friday by cybersecurity blogger Brian Krebs. Alperovitch said about 250,000 global victims has been estimated.

Microsoft has declined to say how many customers it believes are infected.

David Kennedy, CEO of cybersecurity firm TrustedSec, said hundreds of thousands of organizations could have been vulnerable to the hack.

“Anybody that had Exchange installed was potentially vulnerable,” he said. “It’s not every single one but it’s a large percentage of them.”

Katie Nickels, director of intelligence at the cybersecurity firm Red Canary, warned that installing patches won’t be enough to protect those already infected. “If you patch today that is going to protect you going forward but if the adversaries are already in your system then you need to take care of that,” she said.

A smaller number of organizations were targeted in the initial intrusion by hackers who grabbed data, stole credentials or explored inside networks and left backdoors at universities, defense contractors, law firms and infectious-disease research centers, researchers said. Among those Kennedy has been working with are manufacturers worried about intellectual property theft, hospitals, financial institutions and managed service providers who host multiple company networks.

“On the scale of one to 10, this is a 20,” Kennedy said. “It was essentially a skeleton key to open up any company that had this Microsoft product installed.”

Asked for comment, the Chinese embassy in Washington pointed to remarks last week from Foreign Ministry spokesperson saying that China “firmly opposes and combats cyber attacks and cyber theft in all forms” and cautioning that attribution of cyberattacks should be based on evidence and not “groundless accusations.”

The hack did not affect the cloud-based Microsoft 365 email and collaboration systems favored by Fortune 500 companies and other organizations that can afford quality security. That highlights what some in the industry lament as two computing classes — the security “haves” and “have-nots.”

Ben Read, director of analysis at Mandiant, said the cybersecurity firm has not seen anyone leverage the hack for financial gain, “but for folks out there who are affected time is of the essence in terms of of patching this issue.”

That is easier said than done for many victims. Many have skeleton IT staff and can’t afford an emergency cybersecurity response — not to mention the complications of the pandemic.

Fixing the problem isn’t as simple as clicking an update button on a computer screen. It requires upgrading an organization’s entire so-called “Active Directory,” which catalogues email users and their respective privileges.

“Taking down your e-mail server is not something you do lightly,” said Alperovitch, who chairs the nonprofit Silverado Policy Accelerator think tank.

Tony Cole of Attivo Networks said the huge number of potential victims creates a perfect “smokescreen” for nation-state hackers to hide a much smaller list of intended targets by tying up already overstretched cybersecurity officials. “There’s not enough incident response teams to handle all of this.”

Many experts were surprised and perplexed at how groups rushed to infect server installations just ahead of Microsoft’s patch release. Kennedy, of TrustedSec, said it took Microsoft too long to get a patch out, though he does not think it should have notified people about it before the patch was ready.

Steven Adair of the cybersecurity firm Volexity, which alerted Microsoft to the initial intrusion, described a “mass, indiscriminate exploitation” that began the weekend before the patch was released and included groups from “many different countries, (including) criminal actors.”

The Cybersecurity Infrastructure and Security Agency issued an urgent alert on the hack last Wednesday and National Security Advisor Jake Sullivan tweeted about it Thursday evening.

But the White House has yet to announce any specific initiative for responding.

___

Tucker reported from Washington and O’Brien reported from Providence, Rhode Island. AP writer Alan Suderman contributed from Richmond, Virginia.

Friday, 5 March 2021

New story in Technology from Time: Disinformation Is Among the Greatest Threats to Our Democracy. Here Are Three Key Ways to Fight It



In October 2019, the late Supreme Court Justice Ruth Bader Ginsberg was asked what she thought historians would see when they looked back on the Trump era in United States history. Justice Ginsberg, known for her colorful and often blistering legal opinions, replied tersely, “An aberration.”

As President Biden’s administration settles in, many feel an enormous sense of relief, an awareness that the United States dodged a proverbial bullet. But how do we ensure that Justice Ginsberg’s prediction becomes reality? This is not an academic question; Trump’s recent speech at CPAC all but announced his desire to return in 2024. Only by recognizing the underlying reason he succeeded in the first place and by making the structural changes necessary to prevent someone like him from succeeding again can we head off this eventuality.

First, to understand what we must do to prevent the return of someone like Trump or even Trump himself, we first need to define what Trumpism really is and how it came to be. The seeds of Trumpism in America have been analyzed to exhaustion, but something specific emerged in 2016 that holds the key to Trump’s rise to power: Online disinformation.

Modern online disinformation exploits the attention-driven business model that powers most of the internet as we currently know it. Platforms like Google and Facebook make staggering amounts of money grabbing and capturing our attention so they can show us paid advertisements. That attention is gamed using algorithms that measure what content we engage with and automatically show us more content like it.

The problem, of course, emerges when these algorithms automatically recommend and amplify our worst tendencies. As humans, we evolved to respond more strongly to negative stimuli than positive ones. These algorithms detect that and reinforce it, selecting content that sends us down increasingly negative rabbit holes. Resentful about losing your job? Here’s a video someone made about how immigrants stole that job from you! Hesitant about the COVID-19 vaccine? Here’s a post from another user stoking a baseless anti-vaccine conspiracy theory. Notice, of course, that truth is nowhere in this calculus—the only metric the algorithm rewards is engagement, and it turns out that disinformation and conspiracy theory make the perfect fodder for this algorithmic amplification.

This is also the perfect setup for someone like Trump to create further political turmoil in the future. People like him will say or do literally anything to grab attention as long as it benefits them. They lie outright solely to further their own immediate interests. Their disregard for truth is pathological. Their entire personas are fabrications designed to maximize ratings. Our modern information environment, which rewards engagement above all else, is perfect for someone like Trump to succeed unless we make fundamental changes to this system.

Read Now: Shoshana Zuboff on Building an Internet That Lets Democracy Flourish

Now is the time for strong tech reform. Disinformation is a product of a toxic internet business model, and Congress wields the power to change the conditions from which it emerged. This is not a “truth police.” I do not advocate regulating disinformation directly; so-called “anti fake news” laws passed in other countries are ripe for political exploitation to suppress free speech and antagonize dissidents, activists, and political rivals. Instead, by regulating the toxic business models underpinning our information environment, we will create a healthier ecosystem that stems the flow of disinformation, mitigates harm, and leads to a freer more productive conversation.

We need strong legislation in three areas. The first is privacy. Personal data has become the most valuable resource in the world, with companies that collect it en masse replacing even oil companies as the most central businesses in the global economy. How does this relate to disinformation? For starters, personal data is the fuel that powers this algorithmic distortion engine. But the connection goes deeper. As Dr. Johnny Ryan, Senior Fellow at the Irish Council for Civil Liberties and the Open Markets Institute, argues, targeted advertising has robbed traditional media outlets of their primary asset: Their audience. This effect has devastated publisher revenues and destroyed the business models that previously supported quality journalism, leaving a news vacuum that is being filled by disinformation. Strong federal privacy laws that go beyond those already in place in Europe and California would help stem the damage to the media business model and re-establish an environment where quality journalism could thrive once again.

The second area is antitrust. Right now, the digital ad tech market is dominated by two companies, Facebook and Google. Advertisers from around the world pay on average two thirds of their budget to just these two companies. This money is ultimately what pays for the internet we use so freely. This is also what disinformation peddlers seek to capture when they create salacious content to share on social media. By driving engagement and traffic to their sites, these malicious actors display ads and make money.

All of this creates a risky situation for advertisers, who are loath to have their ads appear alongside disinformation, say, extolling the recent riots at the U.S. Capitol or dissuading people from getting the COVID-19 vaccine. And yet, the advertisers have little to no say over where their ads are appearing. They pay Google or Facebook, and those companies use algorithms to choose where to place the ads. And when the advertisers complain—as many did last summer as part of the #StopHateForProfit campaign—these companies simply defy them. They have no competition and thus little incentive to better serve their customers, the advertisers, by blocking ads—and funding—to sites peddling disinformation and hate.

The final and most important area is content liability. Often referred to as “Section 230” reform, from Section 230 of the Telecommunications Decency Act of 1996, this is among the most difficult, but most critical areas of tech reform. Section 230 essentially makes internet platforms immune to legal liability for both the content that users post and the decisions they make to remove that content. Some call this law “the twenty six words that built the internet.”

Under Section 230, Facebook, for example, assumes no liability when they suggest people join white supremacist groups, as their own internal data shows they do a whopping 64% of the time. They bear no responsibility when those people become radicalized and commit hate crimes or attack public buildings, even though it was Facebook that originally set them down the path.

While there is widespread consensus that Section 230 needs to be reformed, it remains an open question how to do so in a way that adequately protects free speech. When the law was originally conceived, the popular analogy used at the time was that a platform was like a chalkboard in a town square—anyone could write anything on it, and the owner of the chalkboard was neither liable for what was written, nor what they chose to erase. It made sense in the early days of the internet when these platforms had far fewer users and weren’t dominated by algorithmically curated feeds.

Today, the chalkboard analogy no longer applies. Billions of users are effectively feeding these algorithms an infinite supply of content from which to populate our feeds. A better analogy for today’s algorithmically driven platform would be one of those ransom notes from the movies, where the kidnapper cuts out magazine letters to spell words. We don’t accuse the magazines of the kidnapping even though they printed the letters, and just because the kidnapper used letters from magazines to spell the words doesn’t mean they didn’t “write” the note. In the same way, it’s not the content that’s the problem on the modern social media platform. It’s the algorithms that are weaving that content into personalized toxic narratives in order to drive engagement at the cost of everything else.

This is what researchers mean when they compare freedom of speech to freedom of reach. We are all entitled to freedom of speech—though even that has limits in the face of imminent harm, and a clear link is emerging between online toxicity and offline harm—but algorithmic amplification, or “reach,” is the product of decisions made by private companies through the algorithms they program. Not only is there no intrinsic right to have those private companies show your posts to other users, but those companies should also be able to be held liable when they decide to do so via their algorithms if it ends up harming you or someone else. This is even truer when it comes to online advertising. Everyone has the right to say what they want on the web, but no one has a right to the money that advertisers pay into Google or Facebook to place ads next to that content. That should be entirely the choice of the advertisers footing the bill.

Given this model, a solution becomes clearer. Any time a platform makes a decision—or programs an algorithm to make a decision—to show content to a user, the platform should assume liability for that decision. If Facebook recommends a white supremacist group to a user, and that user joins the group, becomes radicalized, plans violence there, and harms someone, the victim should be able to hold Facebook accountable for recommending the group and facilitating the planning. Sure, Facebook didn’t solely cause the harm, but they were involved and thus bear some responsibility. Right now, under the blanket immunity provided by Section 230, the victim can’t even take Facebook to court to hash it out, let alone hold them accountable. That’s what needs to change.

Social media platforms have immensely affected the balance of power in media, giving space to voices that have historically been suppressed. But we need to update the rules that govern the manipulation of our information environment in order to prevent another nihilistic narcissist gaining power. The Global Disinformation Index, the nonprofit that I co-founded, has been working with the tech sector to stop the creation and spread of online disinformation. To date, we’ve partnered with tech companies, governments, and advocacy groups to disrupt these financial incentives to spread disinformation. Our industry-focused advocacy work is a start, but the world’s policymakers must now do their part. The EU is already leading the way with reforms through the Digital Services and Digital Markets Acts. These legislative initiatives, should they become law, seek to create platform liability and level the playing field in the ways that will make the web safer and more competitive. But since most of the companies affected are American, right now the most powerful levers to combat disinformation lay in the hands of Congress—it’s time to pull them and relegate Trumpism to the “aberration” Justice Ginsberg predicted it would be.

Ad 1