We Now Have Proof That Sobeys Was Pwned By Ransomware

Posted in Commentary on November 12, 2022 by itnerd

Earlier this week, I reported that there were rumours that Canadian grocery chain Sobeys was hit with a ransomware attack. At the time Sobeys simply said that there was an “IT problem” that they were dealing with. But from what I have heard, some of which was from Sobeys employees, I knew that they were hiding the truth. And now we have proof of that from a pair of reports.

On Thursday, this happened:

However, on Thursday, two provincial privacy watchdogs said they had received data breach reports from Sobeys.

Both Quebec’s access to information commission and Alberta’s privacy commission have both been notified by the grocer about a “confidentiality incident.”

Quebec’s access to information commission said confidentiality incidents occur when there is unauthorized access, use or loss of personal information or any other breach of the protection of this information.

That’s the first hint that this is not some “IT problem” and is indicative of Sobeys getting pwned and the threat actors having access to confidential data. Be it employee data, customer data, both, or even more than that. I say that because you only file a report like this if you’re the victim of some sort of data breach. Or in this case, you’ve been pwned by hackers. Since these are both public agencies that Sobeys reported this to, we’ll find out soon enough what was leaked and how.

The next day Bleeping Computer posted a story with proof that Sobeys was pwned in a ransomware attack:

Furthermore, based on ransom notes and negotiation chats BleepingComputer has seen, the attackers deployed Black Basta ransomware payloads to encrypt systems on Sobeys’ network.

BleepingComputer was told by multiple sources that the attack occurred late Friday/early Saturday morning.

Photographs shared by Sobeys employees online also show in-store computers displaying a Black Basta ransom note.

That’s right. They have screen shots, and Bleeping Computer has proof that Sobeys was in negotiations with the threat actors. Thus at this point, Sobeys really does need to just come clean and admit that they were pwned and what they are going to do to remediate the situation. The problem is that this is the worst kept secret in Canada at the moment, and Sobeys not only looks bad, but their silence really doesn’t create trust among their customer base. My wife for example has been freaking out as she walks a couple of blocks to the local Sobeys store anytime she need to grab something. And as a result of her shopping at Sobeys, she’s afraid her personal information has been exposed. I can’t answer that question. But I bet Sobeys can. But they’re too busy trying to hide this rather than taking steps to level with the public and describe what their next steps are to regain their trust. And to take this further, what if you’re an employee of Sobeys, I’m pretty sure that you’re scared that your personal info has been exposed. And to be frank, you should be. The fact is that Sobeys isn’t helping itself here, and that will only hurt Sobeys as a brand at the end of the day.

Cognitive Systems and MaxLinear partner to expand WiFi Sensing accessibility for ISPs

Posted in Commentary with tags , on November 11, 2022 by itnerd

Cognitive Systems Corp. announced today that its highly-accurate WiFi Motion™ detection software will be integrated intocMaxLinear’s cutting-edge broadband and access SoCs. Through this partnership, Cognitive Systems’ patented WiFi Motion technology will run on MaxLinear chips, enabling next-generation Wi-Fi Sensing applications such as home monitoring, wellness monitoring, and smart home automation.  

Since 2014, Cognitive Systems has designed, developed, and implemented the first and most sophisticated Wi-Fi-enabled motion sensing software in market, expanding how Wi-Fi networks are used. The breakthrough technology leverages connected IoT devices to transform the entire home into a motion-sensing network without any additional hardware. Cognitive Systems first launched a home monitoring solution, called Home Aware, and recently expanded its solutions by launching Caregiver Aware, a revolutionary solution for elder care. In addition to expanding its product portfolio, Cognitive Systems has optimized its rapid integration process. WiFi Motion is now available on most access points. Since 2020, WiFi Motion’s availability has grown to over 2.5M motion-capable devices and is offered by more than 100 service providers. 

Cognitive Systems’ WiFi Motion software is implemented as a function of MaxLinear’s suite of gateway and access platforms, including Wi-Fi, fiber, DOCSIS, and xDSL products. MaxLinear’s Wi-Fi solutions – including its latest generation Wi-Fi 7 product – deliver a fast, reliable, and responsive experience and are well-suited for next-gen Wi-Fi-enabled motion detection. Coupled with MaxLinear AnyWAN™ – the industry’s first single-chip SoC that targets Fiber-to-the-Home, Fixed Wireless Access, DOCSIS, and ethernet gateways and modems – services providers and home gateway designers have a set of highly-optimizable access solutions enhanced with leading functionalities such as Cognitive Systems’ motion sensing, which consumers are coming to expect.  

Through this partnership, Cognitive Systems’ WiFi Motion will be available on nearly every Wi-Fi access point.  

MaxLinear’s WiFi Motion-enhanced access point products will be available to Internet Service Providers in H1 2023.  

Cognitive Systems Corp. is on a mission to deliver the most advanced WiFi. Its core technology, WiFi Motion™, turns connected devices into motion sensors using WiFi signals. WiFi Motion harnesses artificial intelligence and predictive analytics to reliably identify and localize motion for endless application such as in the smart home, home monitoring, and wellness monitoring markets. This patented technology is layered onto existing WiFi networks without additional hardware to enhance service provider and router manufacturer offerings.  

MaxLinear, Inc. is a leading provider of radio frequency (RF), analog, digital and mixed-signal integrated circuits for access and connectivity, wired and wireless infrastructure, and industrial and multimarket applications. MaxLinear is headquartered in Carlsbad, California. For more information, please visit www.maxlinear.com.  

AppDynamics highlights a new class of post-pandemic agents of transformation

Posted in Commentary with tags on November 11, 2022 by itnerd

One of the terms often heard at development conferences is ‘change agents’. The term, which some trace back to 2018, refers to leaders in the technology sector who have been vital in transforming roles, organizations, technologies, etc. And while the last 4 years have been quite productive for the sector, many technologists today feel that being one is harder than ever.  

The insight comes from the study conducted by AppDynamics: ‘Agents of Transformation 2022: Innovating in the Experience Economy’ whose objective was to know the perception of IT professionals to determine how they saw the role of agents of transformation today.  

72% of Canadian technologists believe their experiences in recent years – particularly during the pandemic – have accelerated their careers, and 88% now consider themselves to be business leaders. Also, 82% say the skills and qualities that define an Agent of Transformation have evolved. 

The study revealed that in order to be considered a Transformation Agent, technologists need to be committed to leaving a positive legacy within their organizations and beyond, successfully driving business and digital transformation projects, and always doing things differently to shape a better future for all. On the other hand, they need to recognize the necessity to continually learn and develop their own skills, to reassure and educate those around them, and to collaborate to deliver maximum customer and business impact. 

Tips to make your drive safer and easier while getting to events this November: Plan your drive with Waze

Posted in Commentary with tags on November 11, 2022 by itnerd

t’s that time of year – when the hustle and bustle of the holiday season begins, and special events around the city take over our calendars!

For example, Katharine Harvey’s Light Up Downsview: A Drone Performance this Saturday (Nov 12) is at capacity, so attendees and residents in the area can expect the roads to be busy. The same will be true for other events happening this month including the Royal Agricultural Winter Fair (Nov 4 – 13); Santa Claus parades in Ontario throughout November and December; the One of a Kind 2022 Winter Show (Nov 24 – Dec 4); Cavalcade of Lights (Nov 26); and Glow Toronto – Christmas Light Festival & Market (Nov 30 – Dec 31).

Torontonians and visitors from out of town heading to any of these events can plan their routes ahead of time (especially when weather is unpredictable) and get real-time traffic alerts from fellow drivers and riders while en route with community-based navigation app Waze. Here are some tips for navigating to events like these safely while avoiding traffic – making your travel time less stressful and giving you more time for fun: 

Plan your drive ahead of time: Waze can help drivers choose the best route to their destination in advance, based on traffic patterns. It will even remind you when it’s time to leave.

Real-time reports: When using the app, users will see real-time reports of crashes, alternative routes, construction, weather hazards and traffic conditions — to help drivers make the best routing choice

Find parking: Need to find a parking lot near your scheduled drive? Once you’ve planned a drive, simply tap the three dots next to the drive and tap Find parking. This will bring up parking lots on the map close to your destination. Alternatively, after you have started a drive you can tap on the blue down arrow to pull up your drive details and select ‘P’ under “Add a stop.” This will pull up parking lot locations near your final destination as pins on the map, with details and the option to “Park here.”

Gas station feature: Get the most up-to-date gas location and pricing information. The Waze Gas Station feature notifies drivers of nearby gas stations, prompting users to update the price of gas at specific locations so other Waze users can search for the cheapest prices in their area.

Twitter Blue Is Gone As The Implosion Of Twitter Continues

Posted in Commentary with tags on November 11, 2022 by itnerd

It seems that Elon Musk finally figured out that Twitter Blue has become a train wreck next to a dumpster fire that he could not fix. I say that because The Verge is reporting that Twitter Blue appears to have been deep sixed:

Twitter users are reporting that the option to sign up for the company’s new $7.99 subscription service, Twitter Blue, has disappeared from the platform’s iOS app just days after the service launched.

You could previously subscribe to Twitter Blue from the sidebar in the iOS app (the service has yet to launch for Android users), but users this morning reported that the option has disappeared. For those for whom the link is still available, trying to sign up only returns an error message. “Thank you for your interest!” it reads. “Twitter Blue will be available in your country in the future. Please check back later.”

I can confirm that the option is gone for me as well. And reverse engineering expert Jane Manchun Wong seems to have further proof:

So clearly this has been pulled by Twitter and it’s not an accident or an outage.

If it wasn’t clear before, it should be clear now. Elon Musk has no clue what he’s doing. He’s trying random stuff hoping to hit a home run, and he’s ignoring the people around him who are trying to give him advice. Assuming that they have the courage to speak truth to power. As a result you’re seeing stuff like this Twitter Blue train wreck next to a dumpster fire. And since this is happening in public, it is likely sending advertisers to the exits along with the money that Twitter needs to survive. That’s creating a death spiral that will be hard to escape. I say that because while some predict that Twitter will be sold by Elon Musk so that he can find some way to save face and recoup the money he’s spent on it. I seriously doubt that Twitter will survive that long because Musk is doing everything he possibly can to kill the platform.

Twitter Is Imploding As Another Top Executive Leaves And More Chaos Ensues

Posted in Commentary with tags on November 10, 2022 by itnerd

Twitter is literally imploding in front of us. The latest person to go is this guy Yoel Roth as per this Tweet sent in by a reader:

This is bad. I am guessing that he’s had to walk the plank so to speak for the Twitter Blue gong show from yesterday….. More on that in a moment…… But it’s actually worse than that. According to the Washington Post, this has gotten the attention of the FTC:

The privacy departures prompted a rare warning from the Federal Trade Commission, which has emerged as the government’s top Silicon Valley watchdog. It marked the second time in two days that a federal official has expressed concern about the chaotic developments at the company, coming less than 24 hours after President Biden said Musk’s relationships with other countries deserved scrutiny. 

The agency said that it was “tracking the developments at Twitter with deep concern” and that it was prepared to take action to ensure the company was complying with a settlement known as a consent order, which requires Twitter to comply with certain privacy and security requirements because of allegations of past data misuse. Three of the resignations Thursday were by members of a data governance committee established in the FTC deal, according to a former employee who spoke on the condition of anonymity to discuss internal matters. 

Twitter was first put under a consent order in 2011, and it agreed to a new order earlier this year. If the FTC finds Twitter is not complying with that order, it could fine the company hundreds of millions of dollars, potentially damaging the company’s already precarious financial state.

“No CEO or company is above the law, and companies must follow our consent decrees,” said Douglas Farrar, the FTC’s director of public affairs. “Our revised consent order gives us new tools to ensure compliance, and we are prepared to use them.”

This validates this story from earlier today were I said that Musk messes with FTC at his own risk.

Oh, by the way, this is the list of people who have left the company today:

This is really bad. In my opinion, this literally means that Twitter is on life support as far as I am concerned. Because you literally cannot have this much talent leave and it not deeply hurt Twitter. Plus it also may mean that Musk is doing stuff that make people say “I don’t want to go to jail or lose my career over this. I’m outta here!” And remember, for every person that you hear about who has quits Twitter, there’s likely five more or ten more that you don’t. That’s not sustainable for Twitter.

But it is actually worse than that. Remember just yesterday people were impersonating major brands and people via Twitter Blue? Well, the fallout for Twitter is really starting to hit:

Thirty minutes later the REAL Eli Lilly Twitter account Tweeted this:

The problem with this if you’re Musk is that companies will not be on Twitter if the platform does nothing to protect the integrity of their brands. And at present Musk is doing nothing on that front. And advertisers are watching stuff like this situation with Eli Lilly and making their decisions accordingly. Until he changes course and proves he’s capable of providing value to advertisers on Twitter, he’s going to see his ad revenue shrink until it is zero. And then what does he do?

Let’s face it, everything that Musk has done publicly so far to Twitter seems like exactly what I’d do if I wanted to ensure the entire platform ran straight into the ground, and fast. His actions and words make it really hard to see how this isn’t actually his plan. Why he would have this plan I have no idea. But the only other reason for this that I can see is that Musk is incompetent and a horrible businessman. Which I suppose is possible too.

You might want to go sign up for that Mastodon account now. I suspect that you’re going to need it.

Elon Emails Twitter Staff…. He Kills Remote Work & Warns Of “Difficult Times Ahead”

Posted in Commentary with tags on November 10, 2022 by itnerd

It took Elon Musk a while, but he’s finally emailed the staff of Twitter on Wednesday. And the news that he shared was not good. The Verge has the details:

In the email sent to Twitter staff late Wednesday evening and obtained by The Verge, Musk warned that a weaker economic environment in the US would mean difficulties for the company’s ads business. “Frankly, the economic picture ahead is dire, especially for a company like ours that is so dependent on advertising in a challenging economic climate,” he wrote. “Moreover, 70% of our advertising is brand, rather than specific performance, which makes us doubly vulnerable!”

Musk said the company’s “top priority” is Twitter Blue, its revamped $8 a month subscription that adds a verified check mark to the user’s profile and unlocks additional features. “Without significant subscription revenue, there is a good chance Twitter will not survive the upcoming economic downturn,” he wrote. “We need roughly half of our revenue to be subscription.”

In a one-sentence follow-up email sent shortly after, simply titled “Top Priority,” Musk said, “Over the next few days, the absolute top priority is finding and suspending any verified bots/trolls/spam.”

He also told employees that, starting November 10th, they are expected to be in the office for a minimum of 40 hours a week and that he would only approve remote work on a case-by-case basis. “Obviously, if you are physically unable to travel to an office or have a critical personal obligation, then your absence is understandable,” he wrote.

I’m going to call it now. None of this is going to go over well with the remaining staff that are left at Twitter. In fact, this will likely send many to the exits. Assuming that everything else that is going on with Twitter hasn’t already sent the remaining staff to the exits. And what kills me about this email is that he’s taken two weeks or so to click send on it. If you’re looking to retain talent, communicating to employees should be job number one. But that’s clearly not how Musk rolls. And that will come back to haunt him.

All I have to say at this point is that anyone left in Twitter should assume the worst and make plans to be working someplace else when it happens. Because it will happen.

Threat Analyst Finds Cybercriminals Defrauding E-Commerce Vendors Around Holiday Season

Posted in Commentary with tags on November 10, 2022 by itnerd

Cybersixgill has published a new report analyzing how scammers commit refund fraud to steal from retailers on the heels of the RH-ISAC releasing its cyber threat trends, which highlights return fraud as a key area of concern that’s trending in the retail and hospitality industry during this holiday season. 

Threat Intelligence Researcher at Cybersixgill, Adi Bleih, examines refunding tactics increasingly growing in popularity on underground forums, where scammers share how they make cash by defrauding retailers, including a breakdown of the top 10 most mentioned brands on the dark web for retail fraud in 2022.

The report is worth your time to read. Especially if you’re selling online this holiday season.

Elon Musk’s Incompetence And Ego May Be Putting Twitter In The Crosshairs Of The FTC

Posted in Commentary with tags on November 10, 2022 by itnerd

A reader pointed me to this story on The Verge where it illustrates that the chaos within Twitter is worse than what we think it is. Let’s start with this:

Twitter’s privacy and security team is in turmoil after Elon Musk’s changes to the service bypassed the company’s standard data governance processes. The company’s chief privacy officer Damien Kieran, chief information security officer Lea Kissner, and chief compliance officer Marianne Fogarty have all resigned, according to two sources and an internal message seen by The Verge. Kissner confirmed their departure in a tweet.

In a note posted to Twitter’s Slack and viewable to all staff, an attorney on the company’s privacy team wrote that “Elon has shown that his only priority with Twitter users is how to monetize them. I do not believe he cares about the human rights activists. the dissidents, our users in un-monetizable regions, and all the other users who have made Twitter the global town square you have all spent so long building, and we all love.”

Well, I’ve been saying that for a while now. Thus it’s not a shock that this sentiment is starting to become more and more visible in the public sphere. But that’s not the worst of it. This is:

One of the main issues appears to be the FTC settlement Twitter agreed to in May after getting caught using personal user info to target ads. If Twitter doesn’t comply with that agreement, the FTC can issue fines reaching into the billions of dollars, according to the note. The note goes on to say that the writer has “heard Alex Spiro (current head of Legal) say that Elon is willing to take on a huge amount of risk in relation to this company and its users, because ‘Elon puts rockets into space, he’s not afraid of the FTC.’”

Musk’s new legal department is also apparently asking engineers to “self-certify” compliance with FTC rules and other privacy laws. “I anticipate that all of you will de pressured by management into pushing out changes that will likely lead to major incidents,” the lawyer wrote in the message to colleagues, which you can read below.

Here’s part of the internal Slack message sent by a leader on Twitter’s legal team:

Over the last two weeks. Elon has shown that he cares only about recouping the losses he’s incurring as a result of failing to get out of his binding obligation to buy Twitter. He chose to enter into that agreement! All of us are being put through this as a result of the choices he made. 

Elon has shown that his only priority with Twitter users is how to monetize them. I do not believe he cares about the human rights activists. the dissidents, our users in un-monetizable regions, and all the other users who have made Twitter the global town square you have all spent so long building, and we all love.

I have heard Alex Spiro (current head of Legal) say that Elon is willing to take on a huge amount of risk in relation to this company and its users, because “Elon puts rockets into space, he’s not afraid of the FTC.” I have heard another leader in the Legal department say that because of the tight SLA’s (of two weeks?!) between product inception > launch, Legal will “have to shift the burden to engineers” to self-certify compliance with FTC requirements and other laws. This will put huge amount of personal, professional and legal risk onto engineers: I anticipate that all of you will de pressured by management into pushing out changes that will likely lead to major incidents. 

All of this is extremely dangerous for our users. Also, given that the FTC can (and will!) fine Twitter BILLIONS of dollars pursuant to the FTC Consent Order, extremely detrimental to Twitter’s longevity as a platform. Our users deserve so much better than this.

If you feel uncomfortable about anything you’re being asked to do, you can call Twitter’s Ethics Hotline at (800) 275-4843 or submit a report at ethicshelpline.twitter.com. Please also note the FTC’s number is: 1-877-FTC-HELP. You may also remember that Mudge reached out to httos://whistlebloweraid.org

I wish you all luck. It’s been such an honor to work with all of you. And I’ll be taking a day of PTO today.

To be frank, this is far worse that I imagined as taking on the FTC is not a good idea as they have a great track record of winning against people who think that they are above the law. Musk thinks he’s above the law and will likely find out the hard way that he’s not. In the meantime Twitter users will lose and the platform will burn to the ground. And the person holding the matches and the the can of gas will be Elon Musk.

Walmart Canada and TELUS Health Join Forces To Provide Walmart Associates With Comprehensive Virtual Health And Wellbeing Services

Posted in Commentary with tags on November 10, 2022 by itnerd

Walmart Canada and TELUS Health announced today a new strategic initiative to bring TELUS Health’s full suite of total health and wellbeing solutions to all Walmart associates in Canada. This robust suite of health services will provide Walmart Canada associates and their families with confidential access to hundreds of health professionals from a variety of disciplines to support every step of their healthcare journey.

This enhanced offering will provide associates and their eligible dependents with a single source to access a full suite of services to improve their overall wellness, whether they need counseling on a variety of topics, including mental health, nutrition advice and more, a virtual consultation with a clinician, or want to improve their lifestyle habits through weight loss, more exercise or better eating. Programs include:

  • Virtual Care: associates and their family will have access to primary care from trusted clinicians, 24/7 and on-demand for text and video consultations. Drawing from diverse backgrounds, these healthcare professionals are trained to deliver inclusive care in a variety of languages, including occupational awareness, gender and sexual identity, ethnocultural diversity and faith, allowing associates to be matched with a compatible clinician.
  • Employee Enablement: This next generation platform transforms traditional Employee Assistance Programs (EAPs) into a single convenient and collaborative access point so that associates can more easily manage their physical and mental health, wellbeing, and work/life integration. Unique to this platform are dedicated care advocates who develop compassionate and guided care plans that support associates on their path towards improved health, mindfulness, performance and self-esteem. 
  • Wellbeing: associates in Canada will be able to embrace wellbeing and improve their overall health by engaging with like-minded communities and taking part in friendly challenges with colleagues to help build healthier habits, with the resources and goal-setting support they need to sustain newly-gleaned habits.

Associates can access the TELUS Health suite of solutions in French and English 24/7 via a single smartphone app or direct telephone number. associates will also be able to access the services in 220 other languages and dialects through specialized translation services, the first client to do so.

TELUS Health has more than a decade of experience in virtual care services delivering a national, employer-focused suite of programs that make health and wellness more accessible for associates and their families.