Archive for June 8, 2023

Apollo To Shut Down As Of June 30th Because Of Reddit’s API Changes

Posted in Commentary with tags on June 8, 2023 by itnerd

I recently told you about the fact that Reddit was going to start charging for access to its API, and that had many upset enough to plan to black out Reddit on June 12th. Related to this, it now seems that Apollo which is the most popular third party Reddit client is going to shut down on June 30th:

Eight years ago, I posted in the Apple subreddit about a Reddit app I was looking for beta testers for, and my life completely changed that day. I just finished university and an internship at Apple, and wanted to build a Reddit client of my own: a premier, customizable, well-designed Reddit app for iPhone. This fortunately resonated with people immediately, and it’s been my full time job ever since.

Today’s a much sadder post than that initial one eight years ago. June 30th will be Apollo’s last day.

I’ve talked to a lot of people, and come to terms with this over the last weeks as talks with Reddit have deteriorated to an ugly point, and in the interest of transparency with the community, I wanted to talk about how I arrived at this decision, and if you have any questions at the end, I’m more than happy to answer. This post will be long as I have a lot of topics to cover.

Please note that I recorded all my calls with Reddit, so my statements are not based on memory, but the recorded statements by Reddit over the course of the year. One-party consent recording is legal in my country of Canada. Also I won’t be naming names, that’s not important and I don’t want to doxx people.

I encourage you to read the full post, but to be honest, this post does not paint Reddit in the best light as you can make an argument that Reddit is simply using charing for access to their API as cover to kill third party clients. That makes Reddit a way less appealing place to be. Much like Twitter. Minus the Twitter levels of hate, bigotry and everything else. This is sure to generate a lot of negativity towards Reddit, and you have to wonder if this will force Reddit to course correct. Or they simply don’t care and are going to push ahead with this ill conceived idea to kill third party clients.

Barracuda Is Telling ESG Customers To Physically Replace Their Hardware To Address An Actively Exploited Vulnerability… WTF?

Posted in Commentary with tags on June 8, 2023 by itnerd

I recently told you about an extremely serious vulnerability with Barracuda’s Email Security Gateway Appliance (ESG) that has alarm bells ringing all over Hell’s half acre.

Barracuda has a full description of the incident so far in their advisory, including extensive indicators of compromise, additional vulnerability details, and information on the backdoored module for Barracuda’s SMTP daemon. Now this I give Barracuda credit for as there’s a lot of detail here so that if you have one of these ESG Appliances, you can in theory address any vulnerabilities quickly and effectively. But at the same time that document says this right at the top of it:

ACTION NOTICE: Impacted ESG appliances must be immediately replaced regardless of patch version level. If you have not replaced your appliance after receiving notice in your UI, contact support now (support@barracuda.com).  

Barracuda’s remediation recommendation at this time is full replacement of the impacted ESG. 

That’s right. You need to replace your ESG Appliance to address this actively exploited vulnerability. Even if you’ve patched it. I’ve been in this space for over 25 years and I have never, ever seen a recommendation like this before. The only reason that I can come up with for this recommendation is that whatever threat actor did this has managed to gain persistence on the device. Or put into layman’s terms, they’ve pitched the tent, started the campfire, and built a very high wall around the campsite along with a moat that would make it next to impossible to get them out. That’s the holy grail for any threat actor and that’s really, really, bad if you have an ESG Appliance.

Here’s the problem with that, replacing devices wholesale isn’t something that can be scaled to a level that Barracuda customers can work with as we are not talking about a consumer router that can be reconfigured in an hour or less. We’re talking about an email gateway that is actively scanning for email based threats, and in today’s world not only can’t be out of service for a lengthy period, but these sorts of appliances are often tied into a much larger security setup that company have. And you have to wonder if Barracuda can scale to meet the demands of customers who are going to email them with requests to replace this gear quickly. As in next day or same day replacements in some cases. This is a very bad situation and I am sure this is going to cost Barracuda some customers. Because even though there are exploits out there that threaten everyone, this is above and beyond anything that I have ever seen before. And that will make some of Barracuda’s customers wonder if the company was asleep at the switch when it came to the security of their devices.

FBI Issues Warning About Sextortion Schemes

Posted in Commentary with tags on June 8, 2023 by itnerd

Earlier this week, the FBI issued a warning about an uptick in malicious actors using “deepfakes” (the manipulation of benign photographs or videos) to target victims in a new wave of sextortion schemes:

The FBI is warning the public of malicious actors creating synthetic content (commonly referred to as “deepfakes”) by manipulating benign photographs or videos to target victims. Technology advancements are continuously improving the quality, customizability, and accessibility of artificial intelligence (AI)-enabled content creation. The FBI continues to receive reports from victims, including minor children and non-consenting adults, whose photos or videos were altered into explicit content. The photos or videos are then publicly circulated on social media or pornographic websites, for the purpose of harassing victims or sextortion schemes.

John Wilson, senior fellow of threat research at cybersecurity company Fortra had this to say about this FBI warning:

“Because everything can be spoofed, from websites and emails to phone numbers and caller IDs, it’s easy for trusting teens and even adults to be duped into believing they’re interacting with someone they know, or someone they admire and would like to know. And social media, email, games, chat rooms and cell phones give scammers plenty of ways to reach and extort individuals once they make a connection and establish trust. 

Aside from deepfakes, there’s another type of sextortion scheme that doesn’t involve the exchange of explicit photos. A scammer will send an email or direct social media message telling the child they’ve got access to their computer and webcam and have been recording them and the explicit sites they visit. The scammer threatens to tell the victim’s family and friends if they don’t send money. In actuality, the scammer doesn’t have access and is just hoping the victim is scared enough to pay up.”

Not everything and everyone is a threat, but kids and teens need a healthy level of suspicion in their interactions with unknown people and sites. Parental controls can only do so much. John stresses the importance of having the “other” talk to help educate young people about how to navigate the internet safely, offering these tips:

  • Keep the lines of communication open. Your kids need to feel safe coming to you even if they’re in an awkward or embarrassing situation. If possible, start talking with them before they really get active online. Let them know you’ll figure out problems together.
  • Think carefully about photos. Reinforce that once a photo is shared, it cannot be controlled. Any image could wind up on a forum for all to see, including a Snapchat exchange captured as a screenshot. Remove location information from photos by updating the exchangeable image file (EXIF) data. And it might sound obvious, but ensure your kids know never to send nude photos. It could even be a felony if they’re underage. 
  • Think before you post. Remind kids that what’s shared on the internet is permanent. That unseemly party pic they get tagged in at 17 could cost them a job five years later when a prospective employer does social media due diligence.
  • Don’t respond directly to inbound requests. The rule is if it’s inbound and unexpected, don’t give out any information. Hang up and verify contact information via a secondary channel before responding. Click on the sender’s name in the email header to view the actual domain. Many times, the sender isn’t who you think it is.
  • Practice what you preach. Parents also need to be careful of how much information they post online about their families. Sharing the location of soccer practice and friends’ names is valuable intel for scammers to use in befriending kids with accurate details that build trust. Also review your social media account privacy settings and lock down access to your profile and posts so only trusted contacts can see them.

This is really good advice from Mr. Wilson that everyone should follow. Because deepfakes are popping up everywhere, and you need to do everything that you can to make sure that you’re not a victim.

New Research Reveals Marketers’ Adoption of Generative AI & Salesforce’s Latest Innovations from Connections 2023

Posted in Commentary with tags on June 8, 2023 by itnerd

According to new Salesforce research released this week at Connections 2023, 51% of marketers are already tapping into the power of generative AI, and an additional 22% are actively planning to adopt this technology in the very near future. By embracing generative AI, companies are accelerating their productivity and achieving remarkable efficiencies, all while delivering exceptional value to their customers.

Key highlights from the global research:

  • 60% of marketers say generative AI will transform their role, while
  • 71% believe it will enable them to focus on more strategic work.
  • However, “accuracy and quality” is the number one concern for those surveyed, and 63% say trusted customer data is critical in successfully using generative AI.

This underpins the business value of Salesforce’s latest AI and automation innovation updates for the marketing and commerce industry announced during Connections:

  • Marketing GPT & Commerce GPT: Salesforce’s new Einstein-powered generative AI offerings that combine trusted, real-time data and generative AI to transform how companies connect with their customers.
  • WhatsApp for Service: Powered by AI and data, organizations are empowered to efficiently connect with customers through personalized and proactive experiences across marketing, commerce, and service touch points.
  • Google Cloud Expanded Partnership: Includes new integrations between Data Cloud, Google Vertex AI, and Google BigQuery that provide secure, real-time data sharing with improved AI capabilities, and enhancements to Salesforce’s integration with Google Ads and Google Analytics 4.

The Apple Silicon Version Of The Mac Pro Is D.O.A.

Posted in Commentary with tags on June 8, 2023 by itnerd

I don’t know what Apple is thinking here, but after seeing Apple launch the Mac Pro with the M2 Ultra chip alongside the Mac Studio with an option for an M2 Ultra chip, I don’t see any reason why anyone would want to buy a Mac Pro. Why do I think this is the case? Let me list the reasons why:

  • There’s a $3K USD difference between the Mac Studio with the M2 Ultra and the Mac Pro: Keep in mind that they come with exactly the same M2 Ultra chip. So logic suggests that even though the Mac Pro might have a bit more thermal headroom because of the bigger chassis, which means that sustained workflows in theory should perform better on the Mac Pro, the performance differences likely won’t be huge. Thus, who would buy the Mac Pro if you would get almost the same performance from the Mac Studio for way less money? I wouldn’t.
  • The Mac Pro isn’t as expandable as you think It Is – Part 1: Sure the Mac Pro comes with PCI-E slots. But you really can’t do much with them. For example, there are no options for GPUs. That’s going to be a #fail for a lot of people. And whatever PCI-E cards you can use in this new Mac Pro are likely to be for rather unique use cases. For example, you need more internal high speed storage, or some sort of specialized PCI-E card for some highly specialized workflow. Thus this reduces the appeal of the Mac Pro.
  • The Mac Pro isn’t as expandable as you think It Is – Part 2: Just like every other Apple Silicon computer, you can’t expand the RAM after you buy it. Which means that you may be forced to max the machine out from the start. But it’s actually worse than that. If you have a workload that requires more than the 192GB of RAM that the Mac Pro can be configured from the factory, you’re out of luck.
  • The Mac Pro isn’t as expandable as you think It Is – Part 3: While there are disk upgrade options available from Apple for the Mac Pro that you can install after purchase, those upgrade options are insanely expensive. And while the Mac Pro does come with two SATA connectors inside the case for say an internal SSD or two, most people will not use them as that will be a drop in speed versus the on board storage. Which means that many may choose external storage options instead. And that may push many to buy the Mac Studio as opposed to the Mac Pro.
  • More Thunderbolt 4 Ports Mean Nothing For Most: For some, having two extra Thunderbolt four ports in the Mac Pro (8 as opposed to 6 in the Mac Studio) may be important to their workflow as it allows them to connect more Thunderbolt 3/4 devices. I don’t know who those people are. Perhaps they’re the people who need additional storage as I highlighted in my previous point. If you’re one of those people who needs 8 Thunderbolt 4 ports, please enlighten me as to why this is important to you by leaving me a comment below. But for most 8 Thunderbolt 4 ports is a non-factor.

Based on the above, I don’t expect the Mac Pro to sell well except for those who have very specific use cases that require what the Mac Pro has to offer over the Mac Studio. I also think that those who are current owners of the Intel version of the Mac Pro who have been waiting for an Apple Silicon version to come out will likely go to the Mac Studio instead of buying the Mac Pro. I say that because for many of those owners, this Mac Pro really seems like a bigger and More expensive Mac Studio with PCI-E slots, but the same inability to expand the RAM and use GPUs. So there’s no point for them to upgrade to anything other than the Mac Studio. The Mac Pro leaves me with the impression that Apple put this out there simply to kill the Intel Mac Pro and declare the transition to Apple Silicon complete. If that’s the case, then Apple really has disappointed a lot of people who expected better. Because the Mac Pro is basically dead on arrival.

Coming To Toronto Soon Is Uber Carshare

Posted in Commentary with tags on June 8, 2023 by itnerd

This morning, Uber is hosting Go Get Zero, their first-ever sustainability product event introducing new products and features to support their march to zero-emissions. One of the products is coming to Toronto later this year—Uber Carshare—the newest way to rent affordable cars from people right in your neighborhood. 

With Uber Carshare, getting behind the wheel will be:  

  • Convenient: You can find cars right around the corner to instantly unlock and drive.
  • Flexible: Enjoy hourly options so you only pay for the time you need.
  • Affordable: Browse a wide variety of quality cars to find the best fit for your needs and budget.

If residents are interested in being one of the first borrowers or owners with Uber Carshare, they can sign up today to be notified of launch details at this link

Just because you need a car sometimes, doesn’t mean you need to own one. Uber believes that car sharing is one of the most affordable and sustainable ways to access a car. Uber Carshare allows customers to pick up a nearby car and drive it themselves. Together with Rides, public transportation, riding a bike and walking, this means that you no longer need to own a car to get where you want, how you want. 

Most cars sit idle and are unused the majority of the time, so by putting them into shared use – optimizing utilization of existing vehicles on the road – it means fewer cars are needed to move more people. Research shows that carsharing can support car-free or car-lite lifestyles and even lead active users to reduce or “shed” the number of cars they owned before.

Since recently acquiring Car Next Door in Australia – and rebranding to Uber Carshare – Uber has seen the platform grow significantly, which has given them the confidence to launch this product in Toronto and Boston later this year. Uber Carshare is a perfect example of how we’re continuing to identify, innovate and scale the products that are meaningful to consumers and our business.

This is part of their sustainability commitment to provide sustainable, shared alternatives to the personal car. Other innovations that empower Canadians throughout the country to choose green include: 

  • Uber Comfort Electric: It’s as simple as tapping a button and getting a ride in a premium EV. This is now available in Toronto, Vancouver and Montreal. 
  • Uber Green: The most widely available on-demand mobility solution in the world for no- or low-emission rides.
  • Transit: We’re partnering with local transit agencies around the world to add real-time transit information and ticket purchase directly in the Uber app.
  • Bikes and scooters: We’ve integrated Lime bikes and scooters into the Uber app across 55+ cities globally, with plans to expand micromobility options.

Rezilion 2023 Half-Year Critical Vulnerabilities Report Reveals Significance Of Maintaining Software Security 

Posted in Commentary with tags on June 8, 2023 by itnerd

Rezilion, an automated software supply chain security platform, today announced its new research, “2023 First-Half Critical Vulnerabilities Report: Key Software Applications Under Fire.” The report identifies and analyzes the most significant vulnerabilities in numerous widely utilized software applications and open-source projects during the first half of 2023 while offering practical remediation and mitigation strategies.

Cybersecurity leaders and teams must stay abreast of the latest vulnerabilities, regardless of their origins, to ensure that necessary security measures are implemented. While some vulnerabilities may present severe implications for organizations, others might prove less impactful than initially perceived. The report highlights vulnerabilities in critical software applications integral to organizations, which enable vital capabilities such as data analytics, visualization, AI, web development, and cybersecurity. 

Among the vulnerabilities identified and thoroughly analyzed are those found in JsonWebToken (CVE-2022-23529), ChatGPT (CVE-2023-28858), Apache Superset (CVE-2023-27524), PaperCut NG/MF (CVE-2023-27350), Fortinet FortiOS (CVE-2022-41328), and Adobe ColdFusion (CVE-2023-26360).

Particularly notable was the JsonWebToken vulnerability, initially rated with a high CVSS score of 9.8. However, after a detailed examination, the severity of this vulnerability was reassessed and ultimately retracted, underscoring the importance of rigorous analysis and robust community feedback in ensuring accurate assessments and mitigations. 

Rezilion also drew attention to a low severity but significant vulnerability in OpenAI’s ChatGPT service. While the CVSS score was only 3.7, the vulnerability is noteworthy due to the increasing reliance on AI services across industries, serving as a stark reminder that security must remain paramount as AI technology continues to evolve. Additionally, Apache Superset is a critical vulnerability caused by the application’s default SECRET_KEY configuration, highlighting the importance of unique, secure keys to safe application access.

Moreover, the report explores the vulnerabilities in PaperCut, Fortinet FortiOS, and Adobe ColdFusion. These involve an access control issue that permits remote code execution, a zero-day vulnerability exploited in the wild, leading to substantial data loss and operating system corruption, and a zero-day vulnerability exploited in limited attacks enabling remote code execution, respectively.

Cybercriminals exploit software vulnerabilities to launch attacks against organizations, customers, and entire supply chains; threat actors leverage weaknesses in software code to launch attacks like ransomware. Rezilion’s comprehensive analysis and detailed insights aim to assist cybersecurity teams in understanding and addressing these vulnerabilities effectively.

In the face of increasing cybersecurity threats, it is crucial to maintain vigilance and adopt proactive remediation strategies, which include regularly updating all software and systems to their latest versions, as these often contain patches for known vulnerabilities. Equally important is implementing robust security practices such as secure configurations, rigorous input/output sanitization, and continuous threat monitoring. Open-source and AI technologies should be used with heightened attention to maintain user data integrity.

To download the full report, please visit: https://info.rezilion.com/the-most-important-vulnerabilities-discovered-in-2023

Latest Phishing Attack Spoofs a German Broadband and Media Conference to Steal Personal Credentials

Posted in Commentary with tags on June 8, 2023 by itnerd

Rresearchers at Avanan, a Check Point Software company, have put out a report where they discuss how hackers are sending spoofed emails and creating spoofed webpages to make it appear as it comes from Anga Com, a popular conference based in Germany for broadband and media distributors attracting over 22,000 participants from 470 companies from across the world.

In this attack, users get an email from what appears to be coming from Anga Com notifying them that visitors expressed interest in their exhibit during the conference. The email continues by encouraging end-users to click on the link and sign into the portal where they are able to interact with the person who initially expressed their interest. The entire ploy was created to ultimately steal user credentials.

You can read the report here.

TELUS launches fourth #StandWithOwners contest

Posted in Commentary with tags on June 8, 2023 by itnerd

TELUS’ #StandWithOwners program is back for its fourth consecutive year, championing business owners, leaders and teams who are doing things differently and making an impact in their local communities. With small businesses employing 10 million Canadians, representing 69 per cent of private sector employment growth in Canada year-over-year, TELUS is recognizing the critical role business owners play in fueling innovation, propelling economic growth and driving social change. 

Starting today until September 6, 2023, businesses can apply at telus.com/StandWithOwners for a chance to win one of five grand prize packages, valued at over $125,000 each, including $50,000 in cash, $50,000 in advertising, over $25,000 in technology and business services from TELUS and their partners, a round-trip package to Vancouver to celebrate their achievement, as well as access to customized mentorship through the TELUS advisory council. In addition, 15 finalists will each receive $20,000 in funding, technology and additional prizing. Throughout the summer, applicants will also be randomly selected as part of the “50 Days of Hustle” to win further prizes. 

Applicants will demonstrate how their business is changing the game, solving the problems of today and tomorrow and using technology to grow and differentiate their business. Winners will be selected by a judging panel that includes Roi Ross, Vice-president of Marketing at TELUS Business; Anjali Kapal, Vice-president, Product Management & Customer Experience at Canada Post; Penny Hicks, Managing Director, Client Partnerships at The Globe and Mail; and Mark Hickman, Managing Director at Sage Canada.

The panel of judges also features Lourdes Juan, Founder of Leftovers Foundation and 2021 #StandWithOwners winner. As an award-winning entrepreneur who has founded a diverse array of organizations, Juan knows firsthand the importance of being recognized as a growing business and having the support of other business leaders in the community.

TELUS is a proud supporter of Canadian business. Since 2020, TELUS has committed $3.5 million to #StandWithOwners, providing funding, advertising and technology to help businesses thrive in a digital world. As part of TELUS’ greater commitment to the growth of Canadian business, over $300 million has been invested to support entrepreneurs, start-ups and leaders of tomorrow through the TELUS Pollinator Fund for Good and TELUS Ventures.

To learn more about the program and how to apply, visit telus.com/StandWithOwners.

Veridas Expands Its Age Verification Solution

Posted in Commentary with tags on June 8, 2023 by itnerd

Veridas, a leading global provider of AI-driven identity verification solutions, is proud to announce the expansion of its groundbreaking Age Verification product. Designed to help businesses meet stringent age verification regulations, this cutting-edge solution combines biometric verification and artificial intelligence to deliver accurate and efficient age verification services.

Veridas’ existing Age Verification solution now comes equipped with Age Validation capabilities, which only require a simple selfie. This new component will allow our customers to drive age verification processes that respect their users’ privacy by not requiring them to show or send any personal data, such as identity documents.

In an era of tightening regulatory restrictions, businesses face increasing pressure to comply with age verification laws or face severe penalties, including fines and legal actions. Veridas’ Age Verification product offers a seamless and reliable solution, empowering businesses to verify customer ages quickly and confidently.

A growing regulatory context for greater child protection

Regulatory bodies worldwide are increasingly focused on implementing measures to safeguard children in the digital era. Stricter age verification requirements are enforced for online platforms, including gambling, social media, adult sites and marketplaces. Failure to comply with these regulations can lead to significant penalties and legal consequences.

In the United Kingdom, regulations such as the Gambling Commission’s License Conditions and Codes of Practice and the recently introduced “Age Assurance” provision of the Children’s Code emphasize age verification to prevent underage access to online platforms and protect children from age-inappropriate content. In the United States, individual states are taking proactive measures to address age verification and child protection online. Examples include Louisiana’s law requiring age verification on pornography websites and Arkansas’ Social Media Safety Act. Federal proposals, such as the Mature Act and the Kids Online Safety Act (KOSA), seek to introduce national regulations and age verification standards for online platforms.

These UK and US regulations highlight the ongoing efforts to establish comprehensive age verification mechanisms and ensure enhanced child protection measures in the digital landscape.

Veridas Age Verification for Businesses: Swift, Reliable, and Secure Solution

Veridas offers an advanced Age Verification solution designed to benefit businesses and enhance customer experiences with:

  • Swift and Reliable Verification:
    Our biometrics-based solution ensures quick age verification, mitigating fines and reputational damage while delivering fast and frictionless customer access experiences.
  • Increased Customer Acquisition:
    Streamlined age verification processes enhance user experiences, reducing friction and boosting customer acquisition with a quick selfie backed by our Real-Identity Platform.
  • Protected Reputation:
    Veridas’ advanced technology safeguards businesses from compliance breaches, protecting their brand reputation and ensuring trust by meeting age-related regulatory requirements.
  • Simplified Compliance:
    Veridas’ solution prioritizes customer privacy, aligning with evolving data protection regulations and providing an extra layer of trust while simplifying compliance.

Veridas Age Validation: The New Addition to Our Orchestrated Solutions for Tailored Age Verification

Veridas takes a comprehensive approach to Age Verification, combining cutting-edge AI technology, robust anti-spoofing measures and meticulous document checks. As of today, the highlight of Veridas’ offerings is the new Facial Age Validation service, which leverages advanced facial biometrics to determine an individual’s age within milliseconds. This innovative solution can be used independently or orchestrated with other Veridas Age Verification suite components, providing businesses with a guided experience and real-time feedback.

Veridas’ Facial Age Validation service revolutionizes age verification by utilizing facial biometrics. Lightning-fast processing accurately determines whether an individual is above or below the target age. Businesses can seamlessly integrate this service into their verification process, ensuring a guided experience for customers and real-time feedback on age validation.

However, Veridas’ suite of Age Verification solutions goes beyond Facial Age Validation. It includes automated ID document verification, facial biometric checks, liveness detection, database, and government checks. These solutions enhance the overall verification process, ensuring the authenticity of documents, precise identity verification, prevention of fraud through deepfakes or presentation attacks, real-time validation of IDs and selfies, and cross-referencing against official government databases.

Veridas, with its extensive experience in these sectors, has been at the forefront of verifying ages for organizations such as BBVA, Cabify, Renfe, Codere, Sportium, and Alkomprar, among others. By partnering with industry leaders like OneSpan, LexisNexis, and TransUnion, Veridas has demonstrated its commitment to delivering top-notch identity verification solutions.

To learn more about Veridas’ Age Verification Solution and its AI-driven identity verification products suite, visit veridas.com.