Autonomous AI Cyber Weapons Inevitable Says Security Research Expert
Speaking at a recent CloudSec event in London, Trend Micro’s vice-president of security research, Rik Ferguson said that AI cyberattacks operated autonomously are an inevitable threat that security professionals must adapt to tackling.
If Leveraged By Cybercriminals
Mr Ferguson said that when cybercriminals manage to leverage the power of AI, organisations may find themselves experiencing attacks that happen very quickly, contain malicious code, and can even adapt themselves to target specific people in an organisation e.g. impersonating senior company personnel in order to get payments authorised, pretending to be a penetration testing tool, or finding ways to motivate targeted persons to fall victim to a phishing scam.
AI Vs AI
Mr Ferguson suggested that the inevitability of cybercriminals developing autonomous AI-driven attack weapons means that it may be time to be thinking in a world of AI versus AI.
Example of Attack
One close example given by Ferguson is the Emojet Trojan. This malware, which obtains financial information by injecting computer code into the networking stack of an infected Microsoft Windows computer, was introduced 5 years ago but has managed to adapt and cover its tracks even though it is not even AI-driven.
AI Launching Own Attacks Without Human Intervention
Theresa Payton, who was the first women to be a White House CIO (under president George W Bush) and is now CEO of security consultancy Fortalice, has been reported as saying that the advent of genuine AI has posed serious questions, that the cybersecurity industry is falling behind, and that we may even be facing a situation where AI will be able to launch its own attacks without human intervention.
Challenge
One challenge to responding effectively to AI cyber-attacks is likely to be that cybersecurity and law enforcement agencies must move at the speed of law, particularly where procedures must be followed to request help from and arrange coordination between foreign agencies. The speed of the law, unfortunately, is likely to be much slower than the speed of an AI-powered attack.
What Does This Mean For Your Business?
It is a good thing for all businesses that the cybersecurity industry recognises the inevitability of AI-powered attacks, and although it fears that it risks falling behind, it is talking about the issue, taking it seriously, and looking at ways in which it needs to change in order to respond.
Adopting AI Vs AI thinking now may be a sensible way to help security professionals, and those in charge of national security to focus thinking and resources on finding ways to innovate and create their own AI-based detection and defensive systems and tools, and the necessary strategies and alliances in readiness for a new kind of attack.
Tech Tip – Canva
If you’d like a free, graphic design app that can help you to improve your business and social media communications then Canva may be the app for you.
Canva is a versatile graphic design app: full editor, Instagram story maker, video maker, video editor, logo maker and poster maker, enabling you to easily stay on brand and create some very professional logo and poster designs with your photos and videos.
Canva also provides a great way to design your Instagram Highlight cover and create a logo and banner for social networks (Facebook, Pinterest and Twitter).
You can get Canva on the Google Play Store and Apple’s App Store
Tech Tip – ExpressVPN App
If you’d prefer to keep your communications from your mobile device as secure as possible you may like to try a secure VPN app such as ExpressVPN.
The Express VPN app is straightforward to use, offers both a virtual private network and a number of advanced features such as the choice of connecting to 100+ servers around the world. ExpressVPN, which hides your IP address and encrypts your network data offers apps for every device you own on a single subscription: Windows, Android, iOS, Linux, routers, and more.
The app is available from the Google Play store and Apple’s App Store / iTunes.
Revenue Risk To UK Companies Too Slow To Adopt AI
Research from the McKinsey Global Institute shows that UK companies could lose 20% of their cash flow if they are too slow to invest in and adopt Artificial Intelligence (AI) tools.
Could Miss Out
Even though the report highlighted the UK’s higher than average AI-readiness, the country could miss out on a potential 22% boost to the economy and a 120% growth for individual businesses if organisations do not start investing now in AI tools that could help them gain considerable competitive advantages.
Investment Pockets
The research noted that the UK currently only has pockets of innovation for AI e.g. Google’s DeepMind AI division, and that in order to replicate this kind of innovation for growth, businesses need to be in a position where they can offer AI at scale, invest in the necessary talent and find ways to use the findings of the latest research to help achieve commercial success.
IT Skills Shortage
The UK already has an IT skills shortage and is experiencing a “brain drain” from UK university talent to US companies, a further brain drain pressure caused by Brexit fears, and the pull of attractive higher salaries and advanced tech sector careers in tech firms overseas.
Oxford University – Massive Donation For AI
One way of combatting an AI brain-drain and helping to grow UK AI talent which could help UK businesses with AI is to have an AI centre in the UK. Oxford University has just received the largest single donation to a UK university of £150m from US private equity billionaire and Republican political adviser Stephen Schwarzman for the purpose of building an institute to study the ethics of AI. Mr Schwarzman is reported as saying that artificial intelligence is the major issue of our age. He has also given £279m to the Massachusetts Institute of Technology (MIT) to establish a centre for computing and artificial intelligence.
What Does This Mean For Your Business?
Both this research, and some Nesta research from last year have highlighted how UK businesses may be facing added competitive challenges and missing out on revenue in the not-too-distant future due to an ongoing skills shortage that has been amplified and exacerbated by Brexit uncertainty, and by late investment in and adoption of AI.
McKinsey’s latest research builds on its research from last year where it attempted to simulate the effects of AI on the global economy. The results showed that AI could deliver additional global economic activity of around $13 trillion by 2030, or about 16 per cent higher cumulative GDP compared with today. This, of course, would be good for businesses that have invested in AI, and where many of the potential challenges are adequately tackled e.g. the UK’s IT skills shortage. It should also be accepted that the productivity growth that AI could help fuel is likely to be affected by a host of different factors in different parts of the world e.g. labour automation, innovation, the pace of adoption of AI, and the global connectedness or labour-market structure of any given country.
It is also worth noting that AI can deliver threats as well as opportunities, in the form of AI-based cyber-attacks which are a developing risk to whole nations and economies as well as individual businesses. This is certainly one area where nations such as the UK must invest in its own AI defence structures and tools.
ICO’s Own Website Fails GDPR Compliance Test
Irony and embarrassment are the order of the day as the Information Commissioner’s Office, which is responsible for ensuring GDPR compliance in the websites of businesses and organisations has been forced to admit that its own website is not GDPR compliant.
Cookie Consent Notice
The problem, as pointed out to the ICO by Adam Rose, a lawyer at Mishcon de Reya, is that the ICO’s website currently uses implied consent to place cookies on mobile devices, which is prohibited under the Electronic Communications Regulations (PECR) 2003. These Regulations operate alongside GDPR, and as highlighted on the ICO’s own website, consent needs to be clearly given for cookies (e.g. by a tick box) and where they are set, the website needs to give users, mobile or otherwise, a clear explanation of what the cookies do and why.
Article 6
It has been reported that Mr Rose argued that the ICO’s own website’s cookie consent tools were at odds with Article 6 of PECR.
ICO’s Own Guide
For example, in the ICO’s own online guide, in terms of getting marketing consent, it states that “some form of very clear positive action” is needed, “for example, ticking a box, clicking an icon, or sending an email – and the person must fully understand that they are giving you consent”.
Cookies Admission
Under “Cookies” in the guide, and in admission of not being fully compliant itself at the moment, the ICO now states that “We use a cookies tool on our website which relies on implied consent of users. In recognition of the fact that the implementation date for the revised e-Privacy Regulation remains unknown, we are taking reasonable steps now to align our use of cookies the standard of consent required by GDPR. This means that we are in the process of updating the tool (Civic Cookie Tool) which, by default, requires explicit opt-in action by users of our website.”
This means that the ICO has yet to upgrade to the version of the Civic Cookie Tool which includes explicit opt-in, and therefore, the ICO isn’t currently compliant with the laws that it is supposed to help implement and uphold.
Why?
Even though the ICO announced back in May last year that it would be upgrading to the new version of the Civic Cookie Tool, this has not yet happened. This appears to indicate a possible failure on the ICO’s part in the planning and implementation aspects of this particular tool on its website.
Also, as some tech and security commentators have pointed out, there is still a lack of clear legal rules on cookie compliance, and this has even led to confusion on some points among data protection experts.
It could also be argued that a lack of regulatory enforcement against cookie compliance breaches may mean that most website operators can still put consent rules to the bottom of the list of business priorities with no fear of consequence. It’s also unclear if the regulator would or would not be able to carry out some kind of enforcement of the law against itself.
What Does This Mean For Your Business?
Many businesses may be thinking that, aside from the obvious irony of the regulator not being totally compliant, what hope do the rest of us have of getting it right if the ICO can’t?
This story could also act as a reminder to businesses that consent is a complicated area in data protection, and that it may be worth revisiting what cookie consent tools are in place on their websites and whether they are up to date and compliant. For example, as the ICO has discovered, if you’re responsible for implementing the updated version of tools relating to your GDPR compliance, the planning and implementation needs to be managed in order to avoid unwittingly leaving the organisation open to possible infringements of current regulations.
Samsung’s Advice To Virus-Check TVs Causes Customer Concern
Samsung’s recent release of a how-to virus check video coupled with the advice to complete the check “every few weeks” has caused confusion and concern among customers.
Video
At the heart of Samsung’s virus-checking information release was a 19-second video guide that Samsung said had been posted simply to educate and inform customers. The video guide, which was watched more than 200,000 times, was presented to customers via a tweet which it is reported, has since been deleted.
The video showed Samsung TV owners how to access the sub-menu and go to the System Manager to conduct their own “Smart Security Scan”.
Although this feature is already built-in to Samsung TVs, it was the fact that the tweeted video contained the advice that customers would need to carry out the scan themselves every few weeks to prevent malicious software attacks that caused concern that there were known attack attempts or that their QLED TVs were vulnerable in some way.
Misunderstanding
Samsung is since reported to have said that the video was simply for information and was a proactive way to remind and educate customers that the feature existed and how to operate it as a preventative measure and that the video was not sent as a reaction to a specific current threat.
What Are The Risks?
A smart TV is essentially an IoT device, and as such, faces similar potential risks to other IoT devices, although Samsung TVs don’t appear to be at any more of risk than other devices. In fact, back in 2017, after claims that many zero-day vulnerabilities had been found in Samsung’s smart TV operating system, the company reminded users that its TVs already contained features that allowed them to detect malicious code at platform and application levels.
That said, Samsung’s Smart TVs are likely to have a built-in microphone, an Internet connection with streaming apps, and customers may enter credit card details for buying on-demand video content. All this means that the potential privacy and security risks exist.
What Does This Mean For Your Business?
It appears that security and privacy are very sensitive subjects for consumers and that an attempt to remind customers about a security feature ended up highlighting one of the risks of owning a smart TV, leading to concern and an unnecessary PR gaffe.
In the light of the tweet and video, some security commentators have criticised Samsung for making security checks the responsibility of the customer rather than the company sending out automatic security updates. Also, the company may be expecting too much of some of its customers to ask them to delve into the perhaps complicated sub-menu to find the virus scan feature, and to do so on a regular basis.