Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Wednesday, August 11, 2021

Computer security firm Norton buys Avast for over $8 billion

LONDON - US cybersecurity giant NortonLifeLock is to buy Czech rival Avast for over $8 billion to create a leading consumer business, the pair announced Wednesday after the pandemic fuelled online activity.

The deal, equivalent to more than 6.7 billion euros, "is a huge step forward for consumer cyber safety and will ultimately enable us to achieve our vision to protect and empower people to live their digital lives safely", Norton chief executive Vincent Pilette said in a joint statement.

Ondrej Vlcek, chief executive of London-listed Avast, said that amid increasing global cyber threats, the tie-up would allow for "enhanced solutions and services, with improved capabilities".

More than 500 million users will benefit from the new group's safety offerings, the statement added.

Pilette was set to become chief executive of the expanded group, while Vlcek is to join NortonLifeLock as president and become a member of the NortonLifeLock board.

The combined company, to be listed on the Nasdaq, will be dual headquartered in Prague and Tempe, Arizona.

Businesses worldwide are at threat from an increasingly lucrative form of digital hostage-taking, or ransomware attacks, that typically see hackers encrypting victims' data and then demanding money for restored access. 

A massive ransomware attack on US tech firm Kaseya in July affected businesses from pharmacies to gas stations in at least 17 countries. 

While Kaseya was little known to the public, analysts say it was a ripe target as its software is used by around 40,000 businesses, allowing the hackers to paralyse many companies with a single blow.

"At a time when global cyber threats are growing, yet cyber safety penetration remains very low, together with NortonLifeLock, we will be able to accelerate our shared vision of providing holistic cyber protection for consumers around the globe," Vlcek added Wednesday.

US cybersecurity officials last week announced that Amazon, Google and Microsoft had enlisted to help them fight ransomware and defend cloud computing systems from hackers.

The tech giants are among firms signed on to be part of a Joint Cyber Defense Collaborative intended to combine government and private skills and resources to fight hackers, according to the Cybersecurity and Infrastructure Security Agency (CISA).

Agence France-Presse  

Wednesday, March 10, 2021

Hackers breach cameras at banks, jails, Tesla and more

SAN FRANCISCO, United States - A US hacker collective on Tuesday claimed to have tapped into footage from 150,000 security cameras at banks, jails, schools, carmaker Tesla and other sites to expose "the surveillance state."

Images captured from hacked surveillance video were posted on Twitter with an #OperationPanopticon hashtag.

"What if we just absolutely ended surveillance capitalism in two days?" a purported member of a group called APT-69420 Arson Cats asked amid a string of tweeted images.

"This is the tip of the tip of the tip of the iceberg."

The hacker group claimed to have ferreted out credentials of a high level administrator account at Silicon Valley firm Verkada, which runs a platform operating security systems online.

"We have disabled all internal administrator accounts to prevent any unauthorized access," a Verkada spokesperson said in response to an AFP inquiry.

"Our internal security team and external security firm are investigating the scale and scope of this issue, and we have notified law enforcement."

Verkada added that it has notified companies that rely on its platform.

Surveillance camera imagery posted on Twitter included a jail cell block and a man wearing a fake beard dancing in a bank storage room.

The Verkada breach shows the risk of outsourcing security surveillance to companies in the internet cloud, according to Rick Holland, chief information security officer at Digital Shadows, a risk protection firm.

"Verkada positions itself as a 'more secure, scalable' alternative to on-premises network video recorders," Holland said.

"You don't always get more secure when you outsource your security to a third party."

He said he expected the breach to trigger investigations by privacy regulators in the US and Europe.

Agence France-Presse

Friday, July 3, 2020

Google-backed groups criticize Apple's new warnings on user tracking


SAN FRANCISCO, United State - A group of European digital advertising associations on Friday criticized Apple Inc's plans to require apps to seek additional permission from users before tracking them across other apps and websites.

Apple last week disclosed features in its forthcoming operating system for iPhones and iPads that will require apps to show a pop-up screen before they enable a form of tracking commonly needed to show personalized ads.

Sixteen marketing associations, some of which are backed by Facebook Inc and Alphabet Inc's Google, faulted Apple for not adhering to an ad-industry system for seeking user consent under European privacy rules. Apps will now need to ask for permission twice, increasing the risk users will refuse, the associations argued.

Facebook and Google are the largest among thousands of companies that track online consumers to pick up on their habits and interests and serve them relevant ads.

Apple said the new feature was aimed at giving users greater transparency over how their information is being used. In training sessions at a developer conference last week, Apple showed that developers can present any number of additional screens beforehand to explain why permission is needed before triggering its pop-up.

The pop-up says an app "would like permission to track you across apps and websites owned by other companies" and gives the app developer several lines below the main text to explain why the permission is sought. It is not required until an app seeks access to a numeric identifier that can be used for tracking, and apps only need to secure permission once.

The group of European marketing firms said the pop-up warning and the limited ability to customize it still carries "a high risk of user refusal."

Apple engineers also said last week the company will bolster a free Apple-made tool that uses anonymous, aggregated data to measure whether advertising campaigns are working and that will not trigger the pop-up.

"Because it's engineered to not track users, there's no need to request permission to track," Brandon Van Ryswyk, an Apple privacy engineer, said in a video session explaining the measurement tool to developers.

-reuters-

Thursday, May 28, 2020

PLDT says hacked Twitter account 'recovered, ready to serve'


MANILA -- PLDT Inc said Thursday it recovered its verified customer service account on Twitter shortly after it was hacked with a post from a group that identified itself as Anonymous.

"Our @PLDT_Cares Twitter account has been recovered and is now ready to serve," PLDT Inc said in a statement.

PLDT assured the public that the "security issue" was limited to the said Twitter account and that its network and services were unaffected.

Despite restrictions imposed to contain the spread of COVID-19, PLDT continuously invested in its fiber and LTE network rollout to meet demand, it said. 

The unauthorized post, which was removed, read: "As the pandemic arises, Filipinos need fast internet to communicate with their loved ones. Do your job."

"The corrupt fear us, the honest support us, the heroic join us. We are Anonymous. We are Legion. We do not forgive. We do not forget . Expect us," it said.

news.abs-cbn.com

Tuesday, January 21, 2020

Alphabet CEO backs temporary ban on facial-recognition, Microsoft disagrees


BRUSSELS -- The EU's proposal for a temporary ban on facial-recognition technology won backing from Alphabet Chief Executive Sundar Pichai on Monday but got a cool response from Microsoft President Brad Smith.

While Pichai cited the possibility that the technology could be used for nefarious purposes as a reason for a moratorium, Smith said a ban was akin to using a meat cleaver instead of a scalpel to solve potential problems.

"I think it is important that governments and regulations tackle it sooner rather than later and give a framework for it," Pichai told a conference in Brussels organised by think-tank Bruegel.

"It can be immediate but maybe there's a waiting period before we really think about how it's being used," he said. "It's up to governments to chart the course" for the use of such technology.

Smith, who is also Microsoft's chief legal officer, however cited the benefits of facial recognition technology in some instances such as NGOs using it to find missing children.

"I'm really reluctant to say let's stop people from using technology in a way that will reunite families when it can help them do it," Smith said.

"The second thing I would say is you don't ban it if you actually believe there is a reasonable alternative that will enable us to, say, address this problem with a scalpel instead of a meat cleaver," he said.

Smith said it was important to first identify problems and then craft rules to ensure that the technology would not be used for mass surveillance.

"There is only one way at the end of the day to make technology better and that is to use it," he said.

The European Commission is taking a tougher line on artificial intelligence (AI) than the United States that would strengthen existing regulations on privacy and data rights, according to a proposal paper seen by Reuters.

Part of this includes a moratorium of up to five years on using facial recognition technology in public areas, to give the EU time to work out how to prevent abuses, the paper said.

Pichai urged regulators to take a "proportionate approach" when drafting rules, days before the Commission is due to publish proposals on the issue.

Regulators are grappling with ways to govern AI, encouraging innovation while trying to curb potential misuse, as companies and law enforcement agencies increasingly adopt the technology.

There was no question AI needs to be regulated, Pichai said, but rulemakers should tread carefully.

"Sensible regulation must also take a proportionate approach, balancing potential harms with social opportunities. This is especially true in areas that are high risk and high value," he said.

Regulators should tailor rules according to different sectors, Pichai said, citing medical devices and self-driving cars as examples that require different rules. He said governments should align their rules and agree on core values.

Earlier this month, the US government published regulatory guidelines on AI aimed at limiting authorities' overreach, and urged Europe to avoid an aggressive approach.

Pichai said it was important to be clear-eyed about what could go wrong with AI, and while it promised huge benefits there were real concerns about potential negative consequences.

One area of concern is so-called "deep fakes" - video or audio clips that have been manipulated using AI. Pichai said Google had released open data sets to help the research community build better tools to detect such fakes.

The world's most popular internet search engine said last month that Google Cloud was not offering general-purpose facial-recognition application programming interfaces (APIs) while it establishes policy and technical safeguards.

source: news.abs-cbn.com

Monday, December 16, 2019

Somebody’s watching: Hackers breach home security cameras in US


Ashley LeMay and Dylan Blakeley recently installed a Ring security camera in the bedroom of their 3 daughters, giving the Mississippi parents an extra set of eyes — but not the ones that they had bargained for.

Four days after mounting the camera to the wall, a built-in speaker started piping the song “Tiptoe Through the Tulips” into the empty bedroom, footage from the device showed.

When the couple’s 8-year-old daughter, Alyssa, checked on the music and turned on the lights, a man started speaking to her, repeatedly calling her a racial slur and saying he was Santa Claus. She screamed for her mother.

The family’s Ring security system had been hacked, the family said. The intrusion was part of a recent spate of breaches involving Ring, which is owned by Amazon.

There have been at least 3 similar cases reported this month — the others were in Connecticut, Florida and Georgia. Other breaches, involving Google’s Nest and Taococo, a baby monitor sold on Amazon, have also drawn scrutiny and prompted concerns about privacy.

LeMay, 27, said the Dec. 4 episode unnerved her family, particularly her daughter Alyssa.

“She won’t even sleep in her room,” LeMay said Saturday. “She actually spent the night with a friend the other night because she didn’t want to be here.”

LeMay said that she and her husband, who unplugged the camera, immediately reported the episode to Ring and later to the police in Southaven, Mississippi. Since the episode, she said, her family had been contacted by the FBI and by Ring’s chief operating officer, Jon Irwin.

But she criticized the company’s response, saying it had provided scant information and deflected responsibility for the breaches onto customers.

A Ring spokeswoman said in a statement Saturday that the company took the security of its devices seriously and attributed the recent episodes to hackers gaining users’ login credentials.

“Our security team has investigated this incident and we have no evidence of an unauthorized intrusion or compromise of Ring’s systems or network,” the statement said. “Recently, we were made aware of an incident where malicious actors obtained some Ring users’ account credentials (e.g., username and password) from a separate, external, non-Ring service and reused them to log in to some Ring accounts.”

Ring users can monitor the cameras on the company’s smartphone app and speak to people inside their home and at their front door using a two-way audio feature. But cybersecurity experts say all it takes is a username and password for hackers to gain access to the devices.

Ring said it began sending emails this weekend to its millions of customers, reminding them to use multifactor authentication, which requires users to verify their identity by entering a code that they receive as a text message or by using an authentication application, in addition to their password.

“Unfortunately, when the same username and password is reused on multiple services, it’s possible for bad actors to gain access to many accounts,” the statement said.

A spokesman for the Jackson, Mississippi, field office of the FBI said he could not confirm or deny that the episode was being investigated. The Southaven police chief, Macon Moore, said Monday that the case was under investigation but would not comment further because the investigation was active. He also said that police had not received other reports.

Cybersecurity experts said it’s not that difficult for hackers to gain access to “internet of things” devices, which include Ring security cameras and voice assistants, such as Alexa and Google Home.

“Unfortunately, we’re so reliant on passwords at this point, but passwords are absolutely the weakest link,” said Tim Weber, security services director for ADNET Technologies in Farmington, Connecticut.

Weber, who is a certified ethical hacker, said he had not seen any evidence that Ring’s operating platform had been breached. He recommended that people avoid reusing old passwords because they could have already been compromised as part of a previous data breach without users even knowing it.

“People are honestly struggling right now because they have so many passwords to maintain,” he said.

In Waterbury, Connecticut, Ed Slaughter told NBC Connecticut last week that he felt “violated” after a hacker started yelling obscenities and woke up his mother-in-law, who had been sleeping in the basement where he had installed a Ring camera. Efforts to reach Slaughter were unsuccessful.

In Cape Coral, Florida, Josefine Brown told NBC 2 that she was frightened by an episode in which a hacker could be heard in footage from a Ring security camera provided to the station asking the interracial couple if their son was a “baboon.”

In an email Sunday, Brown said: “We are very concerned about our safety and privacy because we thought having a security camera will keep us safe. We don’t know how long someone has been watching us. It is very scary.”

She said that after listening to the voices on videos in the other Ring cases, she was convinced it was the same person who hacked her device.

A Georgia woman told WSB-TV 2 that she was terrified when a man started talking to her through her Ring camera while she was in bed. The station did not name the woman.

Kelli Burgin, chairwoman of the cybersecurity department at Montreat College in North Carolina, said there are inherent risks with new smart devices.

“Nothing is 100 percent secure,” she said. “It takes a lot of layers of defense to make things more secure and to lower the risk. I understand the convenience of getting these devices, but I would also hate to see children exploited. We don’t know how long someone may be monitoring those cameras.”

In addition to multi-factor authentication, she recommended using passphrases instead of passwords, because they are harder for hackers and computers to guess.

LeMay, who works the overnight shift as a laboratory scientist at a hospital, said she thought she had been getting peace of mind with the Ring camera, as one of her daughters suffers from seizures.

Now, she said, the family is on edge.

“I’m definitely very paranoid,” she said. “Yesterday, I told my husband, ‘I really want to get away from here for a bit.’”


2019 The New York Times Company

source: news.abs-cbn.com

Wednesday, December 11, 2019

America’s Top Foundations Bankroll Attack on Big Tech


WASHINGTON — Critics of big tech companies are eager to keep up their momentum — and some of the country’s wealthiest foundations are providing the financial firepower.

Major nonprofits, including the Ford and Hewlett Foundations, have pledged millions of dollars in total toward taking on the power of the country’s corporate giants like Facebook and Amazon. Other supporters include groups run by George Soros, the billionaire financier, and Pierre Omidyar, an eBay founder.

The foundations regularly fund critical looks at capitalism. The Ford Foundation, for example, supports many organizations that study and fight inequality. The Hewlett Foundation, whose lineage goes back to a founder of Hewlett-Packard and has a $10 billion endowment, has put a slice of its money toward organizations re-examining the free market economic policies that dominate Washington.

But the financial support is reaching new heights, and it could help the activists keep pressure on Silicon Valley by building the sort of political might that has powered liberal policy victories on issues like civil rights and net neutrality. Activists recently announced a coalition to take on Amazon, for example, that includes organizers around the country.

One of the groups receiving foundation money is led by Chris Hughes, a Facebook co-founder who now publicly argues for breaking up the social media giant. His group, the Economic Security Project, is pooling some of the money and then distributing it to projects focused on antitrust and concentration concerns. Hughes, wealthy from his time at Facebook, has contributed some of the money himself.

The Economic Security Project plans to give antitrust activists $10 million over the next 18 months. On Tuesday, the organization will announce how it plans to spend the first $3 million, putting the money toward grassroots organizers, researchers at several Washington think tanks and a group that recruits artists to make graphics that “expose how our economy really works.”

The coming years will test whether the efforts of the advocates can harness the skepticism about large corporations and the wealthy that is animating the Democratic presidential primary race. Federal and state officials have already announced investigations into Amazon, Facebook, Google and Apple. Ultimately, these advocates hope to address corporate concentration in numerous businesses, including drugs and farm products, and combat rising economic inequality.

They have their work cut out for them. Tech companies spend tens of millions of dollars on lobbying every year. And antitrust issues hinge on dense questions of law and economics that don’t fit on a bumper sticker.

“It’s not just about trends and corporate accountability,” said Maria Torres-Springer, vice president for US programs at the Ford Foundation, which has a $12 billion endowment. “It’s about creating and sustaining a movement that rebuilds political and economic power for everyday Americans.”

A leading beneficiary of the money is the Open Markets Institute, a research group whose focus on antitrust issues has been pivotal in making corporate concentration a matter of public debate. It expects to bring in more than $3 million in 2020, according to an internal document from the first half of this year. In 2016, before the group split off from a bigger organization, New America, its revenue topped out at just over $900,000.

This year, the Knight Foundation, which focuses on journalism, awarded Open Markets $2 million to study the impact that concentration among technology platforms has on the media. In September, the Ford Foundation gave it $200,000 to examine how tech monopolies affect workers. A public campaign it has led to break up Facebook will expand to include Google next year, according to Sarah Miller, the organization’s deputy director.

Hughes’ Economic Security Project is contributing to that campaign. It is also paying for Open Markets to conduct public opinion polling.

“Our view is you need an ecosystem,” Hughes said. “You need a community of people who generally share the same values but who, among themselves, may even have different approaches to the issues.”

Another progressive group, Jobs With Justice, plans to hold sessions next year explaining to people the antitrust case against tech companies in simple terms. In the draft script of the training, the session’s leader seizes on a simple metaphor, asking attendees to consider two lemonade stands.

The first stand belongs to someone whose family owns the local grocery store, so it gets its lemons free. The family’s neighbors, who opened a competing stand, aren’t so lucky. Over time, the first stand is able to slash its prices to undercut the second stand.

The session leader asks for a volunteer to play the person running the stand that can’t use a family connection to get free fruit. The volunteer has to decide whether to engage in a price war with the more powerful competitor while an organizer charts the volunteer’s dire financial situation on butcher paper.

Each situation ends with the volunteer’s lemonade stand closing and a revelation: Amazon, the session leader will tell participants, has used this tactic against its competitors.

“What we wanted to do was create some field materials, some training materials, just to even explain what a monopoly meant for people,” said Erica Smiley, Jobs With Justice’s executive director. “Outside of people maybe playing the board game, it’s kind of an old idea that maybe they learned in their fourth grade civics class but haven’t necessarily re-upped on.”

Smiley’s group is one participant in Athena, the new coalition organizing opposition to Amazon over antitrust, privacy and other concerns. The coalition says it wants to raise $15 million in its first 3 years.

Athena will receive money from Hughes’ fund, along with other groups trying to rally the grassroots to the cause.

Civil rights group Color of Change plans to use its funding from the project to pay for new hires to lead public campaigns around antitrust issues, while the Action Center on Race and the Economy will run “corporate campaigns designed to influence the public narrative on corporate concentration and win real victories for communities of color around the country.”

Other projects, like the artists’ group, are focused on finding new ways to explore the antitrust issue. Hughes’ group paid for a New York event in November — held by a project called the Museum of Capitalism — where people could play versions of the board game Monopoly that are meant to call out inequities in the economy.

Hughes will also finance some groups doing academic research on corporate concentration and intends to support more researchers in the future.

“If you’re going to see real change, you need a community of scholars who are in dialogue with one another,” he said.

Money is already flowing to campuses. In November, the Knight Foundation allocated $3.5 million to researchers to examine questions about digital platforms, including competition issues.

The foundation, along with Omidyar’s philanthropic network, has also provided the money to introduce an antitrust-focused initiative at Yale’s business school. In an interview, Sam Gill, a Knight executive, said the foundation had not yet taken a position on whether there should be an anti-monopoly movement but felt it was important to finance inquiries into the questions posed by major tech companies.

In recent years, more potential solutions to corporate concentration have emerged. While some believe in aggressive approaches like breaking up companies, others prefer new regulations or other measures.

At a conference at the University of Utah this fall, Dan Crane, a conservative law professor, challenged a group of participants including Tim Wu, a legal scholar and New York Times contributing opinion writer who is a leading voice calling for more aggressive antitrust enforcement. Crane pushed them to be more specific about the changes they would like to see in how antitrust laws are interpreted and enforced.

Over box lunches, the group wrote a statement, later published by Wu, listing legal precedents the group hopes will be overturned and policies it hopes will be enacted.

“Those who believe in a strong revival of antitrust, and a return to its anti-monopoly roots, have a duty to specify what, exactly, they mean, in concrete, legal detail,” the statement said.

Wu said that, among other purposes, the statement could be a test for judicial nominees. It’s a focus reminiscent of the playbook that helped build the conservative legal movement — which in turn shaped the antitrust laws Wu and his compatriots criticize today.

“Over a 30-year period, they won almost every one of those battles,” Wu said. “They just sort of said, ‘Here’s what it should be,’ and it happened.”


2019 The New York Times Company

source: news.abs-cbn.com

Thursday, December 5, 2019

Who’s hacking your Spotify?


Connor Ball, the 23-year-old bassist of British pop band the Vamps, was in the shower when he realized something was up. The song he was listening to on Spotify, by American singer Lauv, had suddenly stopped.

“That’s a shame,” Ball remembered thinking. (He couldn’t start it again; he was still showering.) Then another song started playing. The music was odd, like nothing he would choose to play for himself.

“It was atmospheric, almost like massage music,” he said.

He soon realized that he had been hacked. The music was playing on Google Chrome, a web browser that Ball does not use. Weeks later, he has not yet changed his password, he said, because of “laziness.” So he has continued to endure his hackers’ strange taste.

Asked how he pictured the person choosing the songs, he said, “I’m imagining a 70-year-old bald man in a rocking chair.”

Accounts get compromised. It’s the way of things. (Spotify said in a statement that it takes “all fraudulent activity on our service extremely seriously” and recommended that its users protect themselves by refraining from using the same user names and passwords across various accounts.) These digital incursions can be unsettling (when not outright upsetting), but they’re often impersonal. Usually, one doesn’t think about one’s hacker too often.

That seems to be less true when it comes to music. When a Spotify account gets hacked, the hackee is able to see the music the hacker has chosen (either on the hacker’s device, or sometimes, presumably by accident, on the hackee’s). A portrait of the hacker often emerges.

“I assumed it was like some sad teenager going through a breakup, listening to bad music,” said Charlene Coughlin of her hacker.

Coughlin, 36 and an advertising executive in Cleveland, was hacked last Saturday. She was in the car listening to either Christmas music or Taylor Swift (she couldn’t recall which), when there was an interruption. When she got home, she looked on her laptop and found her hacker was listening to a playlist of “sad trap music” on a device named Sophia’s iPhone.

Despite the imagined breakup, Coughlin did not feel sorry for this alleged Sophia. “I was mostly a little irritated that someone had broken into my account,” she said.

While Coughlin turned to Spotify and Ball to apathy, other victims of hacking have come up with ingenious ways to drive their hackers out. Margaret Harris, a 23-year-old Toronto resident, realized she had been hacked over the summer when she found a playlist of EDM with song titles in what looked like Cyrillic characters.

She deleted the playlist, but every couple of days it would come back. And her hacker — whom she imagined as “some Russian guy in his car,” though he listened through a web browser and nothing explicitly indicated that he was a man — got more aggressive.

The two of them started fighting over the account as if they were grappling for sole authority over the remote control.

“We were actively having this Spotify battle,” she said. “His music would start. I would just keep hitting pause and playing mine.”

After seeing that the hacker was playing music from Firefox, she had a “eureka” moment. Harris is a metal fan and she wracked her brain for a particularly intense song. She settled on “Bleed,” by Swedish metal band Meshuggah. (Opening lyrics: “Beams of fire sweep through my head / Thrusts of pain increasingly engaged.”)

“I would skip to the middle of the song where it’s most hard-core, and I would crank my Spotify and play it through his computer,” she said. She did this several times.

Though the hacker fought back at first, eventually the interruptions ceased, she said. She had driven the intruder out. “Which is great,” she said.

Some hacks do not seem altogether human. Anneke Schuurman, a high schooler who lives on Vancouver Island in Canada, likes to listen to soft indie music as she falls asleep. (Like Ball, she enjoys Lauv.)

“Over the night it changes what it’s playing,” she said. “I wake up in the morning and it’ll be some weird genre I don’t listen to.”

She suspects that a bot is responsible for the “relaxing music” playlists that started to flood her library.

“Obviously people can listen to relaxing music, but it was too often. Like that was the only thing that they’re listening to,” she said.

A similar idea occurred to Chris Pantin, a 19-year-old sociology student in California, when he was hacked in March. His hacker played an album by Los Angeles rapper YG on repeat. (The first time it happened, the music started playing out of his laptop in the middle of a chemistry class.)

“It almost makes me feel like there’s some weird hack to try to get streams,” Pantin said.

Recently, he has been hacked again. This hacker he imagines to be a human — “probably a skinny white boy who’s short,” he said. The hacker likes what appears to Pantin to be Eastern European club music, music the student thinks is actually pretty decent. And what’s more, this hacker has shown some social grace, unlike the previous one.

“They would be trying to listen to music while I was listening to music so they cut me off. Always with the YG album,” Pantin said. “Whoever’s doing it now just stops listening to the music when I start playing mine. So I’ve just let it happen because it’s not bothering me as much.”

source: news.abs-cbn.com

Wednesday, December 4, 2019

TikTok sued in US over alleged China data transfer


SAN FRANCISCO, United States - A university student in California has filed a class-action lawsuit against video app TikTok, which she accuses of harvesting large amounts of user data and storing it in China.

"TikTok clandestinely has vacuumed up and transferred to servers in China vast quantities of private and personally-identifiable user data," the court filing said.

Misty Hong, a student in Palo Alto, California, filed the suit against the Chinese-based app in California federal court last week, according to a report in The Daily Beast on Monday.

The video platform, which is hugely popular with teenagers around the world, was launched by Chinese company ByteDance in September 2017.

"TikTok also has surreptitiously taken user content, such as draft videos never intended for publication, without user knowledge or consent," the lawsuit alleges.

"In short, TikTok's lighthearted fun comes at a heavy cost," it said.

The suit marks the latest legal battle for the app. In early November, the US government opened a national security investigation into TikTok, according to the New York Times, potentially looking into whether the app was sending data to China.

Hong alleges that the app retrieved her data without permission -- including videos that she had created but not shared online -- and transferred them to servers run by companies that cooperate with the Chinese government.

She filed the suit on behalf of the approximately 110 million US residents who have downloaded the app.

TikTok did not immediately reply to AFP's request for response.

In November, it said it could not comment on a possible US investigation but emphasized that the respect of US users and regulators was its highest priority.

TikTok has distanced itself from Chinese authorities, maintaining that its servers are located outside of the country and that its data is therefore not subject to Chinese law.

In November, the app hit 1.5 billion downloads worldwide, outperforming Instagram.

source: news.abs-cbn.com

Monday, December 2, 2019

Huawei plans to shift research center to Canada from US


Huawei Technologies Co Ltd plans to shift its research center to Canada from the United States, Ren Zhengfei, the founder of the Chinese telecoms equipment maker, said in an interview with Canada's Globe and Mail.

Ren's remarks came as Reuters reported on Friday that the United States is weighing expanding its power to stop more foreign shipments of products with US technology to Huawei. The US Commerce Department in May placed Huawei on a trade blacklist, citing national security concerns.

Huawei's "center for research and development will be moved out of the United States, and that will be relocated to Canada," Ren told the Globe and Mail, adding that the company will also manufacture some mobile network equipment outside China.

The Huawei founder wants to build new factory capacity in Europe to make fifth-generation (5G) networking equipment there, hoping to assuage fears stemming from US allegations that its product could be used by China for spying, the Globe and Mail reported.

Huawei was not immediately available to comment on Ren's interview when contacted by Reuters. The firm has previously denied it is a risk to US national security.

The company spent $510 million on the operations of its US research arm last year, according to the Globe and Mail report, which added that it has now trimmed the arm's work force by 600 to about 250.

Separately, Ren's daughter and Huawei Chief Financial Officer Meng Wanzhou, who was arrested by Canadian police on a US warrant late last year, is fighting extradition to the United States on charges of violating sanctions against Iran. She is currently out on bail.

Huawei has denied the charges and China has urged Canada to release her.

Commenting on her case, Ren said that it is an example of "obvious political interference from the US."

source: news.abs-cbn.com

Thursday, November 21, 2019

Stop! Don’t charge your smartphone this way


A dead or dying phone or laptop is enough to send anybody on a mad dash to find a way to charge the device, but you might want to think twice before using that random cable found at an airport charging station or docking into that hotel USB port — hackers could be waiting.

As the busy holiday season approaches, the Los Angeles County District Attorney’s Office is warning travelers about a USB charger scam, or “juice jacking.”

“A free charge could end up draining your bank account,” Luke Sisak, a deputy district attorney, said in a video posted online this month.

Juice jacking happens when unsuspecting users plug their electronic devices into USB ports or use USB cables that have been loaded with malware.

The malware then infects the devices, giving hackers a way in. They can then read and export your data, including your passwords, and even lock up the gadgets, making them unusable.

Juice jacking exploits the fact that somebody doesn’t have a full battery, said Liviu Arsene, a cybersecurity expert at BitDefender, a Romanian cybersecurity and anti-virus software company.

Arsene cautioned against using USB cables found already plugged into charging stations or even given away as promotional gifts.

“You can easily brand these things so you can make it look like any other cable,” he said, adding, “When people see it, they don’t really think or expect it to be malicious in any way.”

Other ways to protect yourself include carrying your own charging wires, only charging directly from an electrical outlet and using portable batteries that were bought from known vendors, Arsene said.

“Don’t believe everything you see, and don’t believe everything you get your hands on,” he said, noting that starting with Black Friday, if it looks too good to be true, it probably is.

But it isn’t just cables that pose a risk for tech consumers; it’s the ports, too.

Like scammers who steal debit card numbers by putting illegal card-reading devices, or skimmers, on ATMs, hackers can easily rip out USB ports and replace them with their own malicious hardware, said Vyas Sekar, a professor at CyLab, a security and privacy research institute at Carnegie Mellon University.

“It’s easy to modify the outlet if the attacker has physical access,” Sekar said.

Though Arsene and Sekar said they were unsure of how often hacking attacks like these happened, the growing ubiquity of USB charging ports in places like hotels, airports and public transportation has translated into an increased risk of falling victim to such scams.

“People want the convenience of charging their phones and tablets wherever they go,” Sekar said, adding, “Obviously I would like it too, but there is a risk.”

Sekar said consumers could also use attachable protective devices on USB cables known as “USB condoms.”

“What they do is a very simple trick,” he said. “They essentially disable the data pin on the USB charger.”

This means that the device will charge, but the cable will be unable to send or receive data.

“For less than 5 bucks you can buy it,” he said, “and that can actually save you.”

The Los Angeles County district attorney’s office echoed cybersecurity experts in its tips for consumers, including using a power outlet and not a USB charging station, carrying your own AC and car chargers and keeping a portable charger for emergencies.

2019 The New York Times Company

source: news.abs-cbn.com

Tuesday, November 19, 2019

EXPLAINER: End-to-end encryption and chat privacy


SAN FRANCISCO — A Justice Department official hinted on Monday that a years-long fight over encrypted communications could become part of a sweeping investigation of big tech companies.

While a department spokesman declined to discuss specifics, a speech Monday by the deputy attorney general, Jeffrey A. Rosen, pointed toward heightened interest in technology called end-to-end encryption, which makes it nearly impossible for law enforcement and spy agencies to access people’s digital communications.

Law enforcement and technologists have been arguing over encryption controls for more than two decades. On one side are privacy advocates and tech bosses like Apple’s chief executive, Tim Cook, who believe people should be able to have online communications free of snooping. On the other side are law enforcement and some lawmakers, who believe tough encryption makes it impossible to track child predators, terrorists and other criminals.

Attorney General William P. Barr, joined by his British and Australian counterparts, recently pressed Facebook’s chief executive, Mark Zuckerberg, to abandon plans to embed end-to-end encryption in services like Messenger and Instagram. WhatsApp, which is owned by Facebook, already provides that tougher encryption.

“Companies should not deliberately design their systems to preclude any form of access to content even for preventing or investigating the most serious crimes,” Barr wrote in a letter last month.

Here is an explanation of the technology and the stakes.

HOW DOES THE ENCRYPTION WORK?

End-to-end encryption scrambles messages in such a way that they can be deciphered only by the sender and the intended recipient. As the label implies, end-to-end encryption takes place on either end of a communication. A message is encrypted on a sender’s device, sent to the recipient’s device in an unreadable format, then decoded for the recipient.

There are several ways to do this, but the most popular works like this: A program on your device mathematically generates two cryptographic keys — a public key and a private key.

The public key can be shared with anyone who wants to encrypt a message to you. The private key, or secret key, decrypts messages sent to you and never leaves your device. Think of it like a locked mailbox. Anyone with a public key can put something in your box and lock it, but only you have the private key to unlock it.

HOW IS IT DIFFERENT FROM OTHER FORMS OF ENCRYPTION?

A more common form of encryption, known as transport layer encryption, relies on a third party, like a tech company, to encrypt messages as they move across the web.

With this type of encryption, law enforcement and intelligence agencies can get access to encrypted messages by presenting technology companies with a warrant or national security letter. The sender and recipient would not have to know about it.

End-to-end encryption ensures that no one can eavesdrop on the contents of a message while it is in transit. It forces spies or snoops to go directly to the sender or recipient to read the content of the encrypted message. Or they must hack directly into the sender’s or recipient’s device, something that can be harder to do “at scale” and makes mass surveillance much more difficult.

Privacy activists, libertarians, security experts and human rights activists argue that end-to-end encryption steers governments away from mass surveillance and toward a more targeted, constitutional form of intelligence gathering. But intelligence and law enforcement agencies argue that end-to-end encryption makes it much harder to track terrorists, pedophiles and human traffickers.

When Zuckerberg announced in March that Facebook would move all three of its messaging services to end-to-end encryption, he acknowledged the risk it presented for “truly terrible things like child exploitation.”

“Encryption is a powerful tool for privacy, but that includes the privacy of people doing bad things,” he said.

HASN'T THIS DEBATE BEEN AROUND FOR DECADES?

The debate over end-to-end encryption has had several iterations, beginning in the 1990s with the spread of Pretty Good Privacy, or PGP, software, an end-to-end encryption scheme designed by a programmer named Phil Zimmermann. As a result, the Clinton administration proposed a “Clipper Chip,” a back door for law enforcement and security agencies.

But the Clipper Chip provoked a backlash from a coalition of unlikely bedfellows, including the American Civil Liberties Union; televangelist Pat Robertson; and Sens. John Kerry, (Democrat, Massachusetts), and John Ashcroft, (Republican, Montana). The White House backed down in 1996.

End-to-end encryption gained more traction in 2013, after data leaked by former National Security Agency contractor Edward J. Snowden appeared to show the extent to which the NSA and other intelligence and law enforcement agencies were gaining access to users’ communications through companies like Yahoo, Microsoft, Google and Facebook without their knowledge.

Encrypted messaging apps like Signal and Wicker gained in popularity, and tech giants like Apple and Facebook started wrapping user data in end-to-end encryption.

Google, which pledged to add an end-to-end encryption option for Gmail users several years ago, has not made this the default option for email. But the company does offer a video-calling app, Duo, that is end-to-end encrypted.

As more communications moved to these end-to-end encrypted services, law enforcement and intelligence services around the world started to complain about data’s “going dark.”

WHAT ARE GOVERNMENTS DOING?

Government agencies have tried to force technology companies to roll back end-to-end encryption, or build back doors, like the Clipper Chip of the 1990s, into their encrypted products to facilitate government surveillance.

In the most aggressive of these efforts, the FBI tried in 2016 to compel Apple in federal court to unlock the iPhone of one of the attackers in the 2015 mass shooting in San Bernardino, California.

Cook of Apple called the FBI’s effort “the software equivalent of cancer.” He said complying with the request would open the door to more invasive government interception down the road.

“Maybe it’s an operating system for surveillance, maybe the ability for the law enforcement to turn on the camera,” Cook told ABC News. “I don’t know where it stops.”

Privacy activists and security experts noted that any back door created for US law enforcement agencies would inevitably become a target for foreign adversaries, cybercriminals and terrorists.

Alex Stamos, chief security officer of Yahoo at the time, likened the creation of an encryption back door to “drilling a hole in the windshield.” By trying to provide an entry point for one government, you end up cracking the structural integrity of the entire encryption shield.

The FBI eventually backed down. Instead of forcing Apple to create a back door, the agency said it had paid an outside party to hack into the phone of the San Bernardino gunman.

SO WHAT NOW?

Governments have stepped up their calls for an encryption back door.

Last year, Australian lawmakers passed a bill requiring technology companies to provide law enforcement and security agencies with access to encrypted communications. The bill gave the government the ability to get a court order allowing it to secretly order technology companies and technologists to re-engineer software and hardware so that it can be used to spy on users.

Australia’s law is based on Britain’s 2016 Investigatory Powers Act, which compels British companies to hand over the keys to unscramble encrypted data to law enforcement agencies. The Australian law could apply to overseas companies like Facebook and Apple.

Australia’s new law applies to network administrators, developers and other tech employees, forcing them to comply with secret government demands without notifying their employers.

Other governments are also considering new encryption laws. In India, Facebook’s biggest market, officials told the country’s Supreme Court in October that Indian law requires Facebook to decrypt messages and supply them to law enforcement upon request.

“They can’t come into the country and say, ‘We will establish a non-decryptable system,’” India’s attorney general, K.K. Venugopal, told the court, referring to Facebook and other big tech platforms. India’s Supreme Court has said it will reconvene on the issue in January.


2019 The New York Times Company

source: news.abs-cbn.com

Monday, November 18, 2019

How not to plot secret foreign policy: On a cellphone and WhatsApp


Rudy Giuliani, the former New York mayor at the center of the impeachment investigation into the conduct of Ukraine policy, makes a living selling cybersecurity advice through his companies. President Donald Trump even named him the administration’s first informal “cybersecurity adviser.”

But inside the National Security Council, officials expressed wonderment that Giuliani was running his “irregular channel” of Ukraine diplomacy over open cell lines and communications apps in Ukraine that the Russians have deeply penetrated.

In his testimony to the House impeachment inquiry, Tim Morrison, who is leaving as the National Security Council’s head of Europe and Russia, recalled expressing astonishment to William B. Taylor Jr., who was sitting in as the chief US diplomat in Ukraine, that the leaders of the “irregular channel” seemed to have little concern about revealing their conversations to Moscow.

“He and I discussed a lack of, shall we say, OPSEC, that much of Rudy’s discussions were happening over an unclassified cellphone or, perhaps as bad, WhatsApp messages, and therefore you can only imagine who else knew about them,” Morrison testified. OPSEC is the government’s shorthand for operational security.

He added: “I remember being focused on the fact that there were text messages, the fact that Rudy was having all of these phone calls over unclassified media,” he added. “And I found that to be highly problematic and indicative of someone who didn’t really understand how national security processes are run.”

Giuliani’s partner, Gordon D. Sondland, the US ambassador to the European Union, held an open cellphone conversation with Trump from a restaurant in Ukraine, apparently loud enough for his table mates to overhear. And Trump’s own cellphone use has led US intelligence officials to conclude that the Chinese — with whom he is negotiating a huge trade deal, among other sensitive topics — are doubtless privy to the president’s conversations.

But Ukraine is a particularly acute case. It is the country where the Russians have so deeply compromised the communications network that in 2014 they posted on the internet conversations between a top Obama administration diplomat, Victoria Nuland, and the US ambassador to Ukraine at the time, Geoffrey R. Pyatt. Their intent was to portray the Americans — not entirely inaccurately — as trying to manage the ouster of a corrupt, pro-Russian president of Ukraine.

The incident made Nuland, who left the State Department soon after Trump’s election, “Patient Zero” in the Russian information-warfare campaign against the United States, before Moscow’s interference in the US presidential election.

But it also served as a warning that if you go to Ukraine, stay off communications networks that Moscow wired.

That advice would seem to apply especially to Giuliani, who speaks around the world on cybersecurity issues. Ukraine was the petri dish for President Vladimir Putin of Russia, the place where he practiced the art of trying to change vote counts, initiating information warfare and, in two celebrated incidents, turning out the lights in parts of the country.

Giuliani, impeachment investigators were told, was Trump’s interlocutor with the new Ukrainian government about opening investigations into the president’s political opponents. The simultaneous suspension of $391 million in military aid to Ukraine, which some have testified was on Trump’s orders, fulfilled Moscow’s deepest wish at a moment of ground war in eastern Ukraine and a daily, grinding cyberwar in the capital.

It remains unknown why the Russians have not made any of these conversations public, assuming they possess them. But inside the intelligence agencies, the motives of Russian intelligence officers is a subject of heated speculation.

A former senior US intelligence official speculated that one explanation is that Giuliani and Sondland were essentially doing the Russians’ work for them. Holding up military aid — for whatever reason — assists the Russian “gray war” in eastern Ukraine and sows doubts in Kyiv that the United States is wholly supportive of Ukraine, a fear that many State Department and National Security Council officials have expressed in testimony.

But Giuliani also was stoking an unsubstantiated conspiracy theory that Putin has engaged in, suggesting that someone besides Russia — in this telling, Ukrainian hackers who now supposedly possess a server that once belonged to the Democratic National Committee — was responsible for the hacking that ran from 2015 to 2016.

Trump raised this possibility in his July 25 phone call with the new Ukrainian president, Volodymyr Zelenskiy. It was not the first time he had cast doubt on Russia’s involvement: In a call to a New York Times reporter moments after meeting Putin for the first time in Hamburg, Germany, in 2017, Trump endorsed Putin’s view that Russia is so good at cyberoperations that it would have never been caught. “That makes sense, doesn’t it?” he asked.

He expressed doubts again in 2018, in a news conference with Putin in Helsinki, Finland. That was only days after the Justice Department indicted a dozen Russian intelligence officers for their role in the hack; the administration will not say if it now believes that indictment was flawed because there is evidence that Ukranians were responsible.

Whether or not he believes Ukraine was involved, Giuliani certainly understood the risks of talking on open lines, particularly in a country with an active cyberwar.

As a former prosecutor, he knows what the United States and its adversaries can intercept. In more recent years, he has spoken around the world on cybersecurity challenges. And as the president’s lawyer, he was a clear target.

Giuliani said in a phone interview Monday that nothing he talked about on the phone or in texts was classified. “All of my conversations, I can say uniformly, were on an unclassified basis,” he said.

His findings about what happened in Ukraine were “generated from my own investigations” and had nothing to do with the US government, he said, until he was asked to talk with Kurt D. Volker, then the special envoy for Ukraine, in a conversation that is now part of the impeachment investigation. Volker will testify in public Tuesday.

Giuliani said that he never “conducted a shadow foreign policy, I conducted a defense of my client,” Trump. “The State Department apparatchiks are all upset that I intervened at all,” he said, adding that he was the victim of “wild accusations.”

Sondland is almost as complex a case. While he is new to diplomacy, he is the owner of a boutique set of hotels and certainly is not unaware of cybersecurity threats because the hotel industry is a major target, as Marriott learned a year ago.

But Sondland held a conversation with Trump last summer in a busy restaurant in Kyiv, surrounded by other US officials. Testimony indicates Trump’s voice was loud enough for others at the table to hear.

But the Russians most likely did not need a reservation because Ukraine’s phone system is deeply compromised. After the Nuland-Pyatt interception — which was held on an open line — embassy personnel have been told to assume that whatever they say routes back through Russian intelligence.


2019 The New York Times Company

source: news.abs-cbn.com

Tuesday, November 5, 2019

Web giants' wield 'irresistible power,' whistleblower Snowden warns


LISBON -- Technology has given internet giants "irresistible power" when they work in concert with governments, Ed Snowden told the Web Summit that opened in Lisbon on Monday.

"When we see government and corporations working in concert... they become the left and right hands of the same body. What we see is the concentration of power," he told the European celebration of startups and new technologies gathering high-tech entrepreneurs and investors.

"If you create an irresistible power... how do you police the expression of that power when it is used against the public rather than for it?" he asked, speaking by video link from Russia where he has lived since 2013.

The US government last month urged tech giants to allow police to read encrypted messages, saying access was essential to prevent serious crime despite privacy concerns.

Snowden has just published a book that lays out his reasons for passing tens of thousands of secret documents to major news organisations in 2013.

The files were compiled while he worked for the US National Security Agency and revealed a dense network of communications and internet scrutiny by the NSA and partner agencies around the world.

Snowden recognized that public awareness is growing over the abuses he has denounced, and he lauded efforts to protect privacy, especially in Europe.

But he told the gathering of some 70,000: "The problem is not data protection, it's data collection" and the blind faith that internet users must have in the internet's masters.

'HYPER-POLITICAL'

The four-day summit is expected to focus on politics and tax issues, as well as new mobilities, medical applications, robotics and crypto currencies, organizers said.

"Tech has become hyper-political," said Paddy Cosgrave, the Irish founder and boss of Europe's biggest tech gathering.

"Increasingly, the front page of newspapers around the world are dominated by issues relating to technology," he told AFP.

Among the main events are discussions on the future of money, cars, medicine, housing, advertising, medias and humans' presence in outer space.

But what has emerged as the leading topic is how high tech has become a crucial factor in the Chinese-US trade war, the monetary power of sovereign governments and the radicalization of social media.

As sector giants continue to face calls for fair taxation or even dismantlement, regulators such as the EU Commission's vice president and competition chief, Margrethe Vestager, are expected to draw a crowd.

Vestager is to close the summit on Thursday, speaking just after Michael Kratsios, who is being sent from the White House to present the US viewpoint on internet taxation and regulation.

Vestager has spearheaded European efforts to get companies like Amazon, Apple, Facebook and Google to pay more in taxes in countries where they earn large amounts of their profits.

In addition to her post as EU competition chief, the Dane has also now been tasked with overseeing digital activities across the 28-member bloc.

Vestager "is incredibly popular... because she's trying to create a level playing field for innovators in particular in Europe," Cosgrave told AFP.

CAMBRIDGE ANALYTICA

At another event, former Cambridge Analytica executive Brittany Kaiser is expected to outline risks to personal data in the run-up to the 2020 US presidential election.

The now defunct data consultancy allegedly hijacked personal data on Facebook users ahead of the 2016 US vote. 

Huawei's rotating chairman Guo Ping is another headliner.

He is likely to call for support from the tech community after the Chinese phone giant was banned from the United States owing to suspicion its systems could be used to collect data for Beijing.

A scheduled address almost certain to raise the issue of internet taxation is by Pascal Saint-Amans, head of the OECD's Centre for Tax Policy and Administration.

The Organisation for Economic Co-operation and Development is drafting a "unified approach" to a digital tax on internet giants and multinational groups to be presented by June next year.

source: news.abs-cbn.com

Monday, September 23, 2019

China’s Big Brother targets business


BEIJING — China is funnelling vast amounts of public and private data into huge databases aimed at tightening its control over its nearly 1.4 billion people.

But the business world has become its biggest target.

Beijing is increasingly amassing information now divided among various government agencies and industry associations — including court decisions, payroll data, environmental records, copyright violations, even how many employees are members of the Communist Party — and using it to grade businesses and the people who run them, according to state media, government documents and experts.

Companies that get low grades can be banned from borrowing money or doing other essential tasks. Their owners or executives could have their bank accounts frozen or be forbidden from traveling.

It isn’t just aimed at Chinese businesses. In letters sent to the companies, officials have threatened to give United Airlines, American Airlines and Delta Air Lines black marks on their records if they don’t bend to Beijing’s wishes. FedEx could face a similar punishment.

China calls it the social credit system. By next year, Chinese leaders had hoped to start an ambitious nationwide program focused on punishing or rewarding individuals. It was aimed at replicating the credit scoring system common in the United States and other places, as well as taming behavior in a country where laws are inconsistently enforced.

Civil libertarians warned that it would create a digital Big Brother that would intrude into everyday Chinese life. But the system has yet to materialize for individuals on a mass scale.

For many businesses, however, social credit has become a fact of life. In September, China’s central economic planning agency announced that it had completed a first evaluation of 33 million businesses, giving them ratings from 1 for excellent to 4 for poor. China hopes it will someday become a nationwide regulatory tool, harnessing the country’s growing skills in big data and automation, to help the Communist Party keep the business world in line.

“It’s supposed to affect the decision-making of businesses to conform to what the party wants,” said Samantha Hoffman, a fellow at the Australian Strategic Policy Institute, a think tank.

Loren Fei, the 30-year-old-daughter of a silk factory owner, has been added to a blacklist of businesses and their owners. Because her father couldn’t pay his bills, she said, her bank accounts have been frozen and she lost her job and her ability to travel.

“My family really wants to pay back the money, and the system is making it impossible,” Fei said.

Authorities are testing the system as a tool to bend foreign companies to the Communist Party’s political views.

United, Delta and American received letters last year from Chinese aviation officials saying their social credit score could be hit unless their websites labeled Macao, Hong Kong and Taiwan as part of China. Lower scores would lead to investigations, the possibility of frozen bank accounts, limitations on local employees’ movement and other punishments, according to a letter sent to United and seen by The New York Times.

Representatives of United, Delta and American Airlines confirmed changing their websites but declined to comment specifically on the matter.

Social credit is one aspect of the Communist Party’s efforts under Xi Jinping, its top leader, to strengthen its hold over the country. Authorities are installing separate facial-recognition technology and other monitoring systems to quell dissent as well as stop crime. They have taken a tougher line on media and worked to give the party a greater role in offices and classrooms.

Applied to businesses, the social credit system could bring real benefits to China. Despite Beijing’s authoritarian grip on power, it has long struggled to get businesses to follow the law. Competing, inefficient government ministries hinder enforcement. Local governments shelter powerful businesses. The result has been widespread pollution, rampant violations of labor laws and other problems.

For instance, Fei said that for years her family’s silk factory had been given dispensation to break environmental rules by local government authorities eager for economic growth. It was finally shut down for environmental reasons.

But companies have little recourse if the data is inaccurate or punishments disproportionately disruptive, experts said.

“The unified rewards and punishment system significantly increases the potential for one violation to snowball across your operations until you have this avalanche of penalties that make it impossible to operate until you solve that one thing,” said Kendra Schaefer, head of digital research at Trivium China, a consulting firm that recently published a report on social credit.

Foreign companies have expressed concern about how they could be affected by their business partners. The German chemical company BASF, for example, is responsible for ensuring that its Chinese partners stay environmentally compliant.

“They put pressure on us in the supply chain to sort out the environmental challenges,” said Jörg Wuttke, president of the European Union Chamber of Commerce in China, who is also the chief representative of BASF in China. “That’s a definite shift that puts a lot of pressure on us.”

Foreign businesses also worry that social credit could become a weapon in the trade war between China and the United States. In a report last month, the European Union Chamber of Commerce cited the example of FedEx, the US package carrier, which has been caught in the middle of the trade fight. The Chinese government has threatened to place FedEx on a list of foreign companies and people it considers unreliable, alleging that it broke the law by withholding the shipment of Huawei products. The language used was similar to social credit.

Chinese officials have not released the list or said what it would do, but they have said they will treat all companies equally.

China began to detail its ambitions for the social credit system 6 years ago, saying it could be a reality by 2020. While some critics saw it as a form of total social control, it was primarily envisioned as a tool for a country where people often break the law in big and little ways without consequences. Chinese authorities typically exert social control through police, who are setting up separate, more draconian systems that include biometric data, like face scans and DNA records.

In any case, social credit has proved difficult to use on individuals. China’s central bank canceled plans to include data from popular electronic payment systems run by Alibaba and Tencent, two Chinese internet giants. Pilot programs have been started in only a few places.

Even there, the programs have had little impact. During a visit to Rongcheng, a social credit pilot city in eastern China, officials said that a good score would get you a speedier check-in at the hospital and easier access to loans. But hospital workers and teachers said social credit had not affected how they do their jobs. Many residents said they were unaware it existed.

“I might have heard about it somewhere but I think it’s none of my business and not relevant to our lives in the village,” said Liang Xiaoli, a store owner. Besides, she added, “I don’t really care. I mean, why should I?”

Residents were rewarded based on factors like whether they helped to keep the city clean. Officials with clipboards collected data and handed out self-assessment forms. They posted photos of citizens with top scores on bulletin boards. In many cases the standouts were related to local Communist Party leaders. Liang Huaying, a Rongcheng official, said they got points because they most often showed up at official events.

The system has proved more adaptable to ensuring good conduct for business.

The social credit system brings together various blacklists long run by different ministries and local governments, allowing authorities to broadly and consistently punish wrongdoers. But while China is assembling a nationwide social credit system, it still has dozens of city-level systems that use different scoring methods.

Fei, the daughter of the silk factory owner, found out she was in the system during a work trip in late 2017, when she could not buy a train ticket home. Then her bank accounts were frozen. She was eventually fired from her job as a financial analyst.

Fei had signed for a loan on her father’s behalf. Fei’s mother, who is retired, is also on the blacklist because she is a shareholder. Her monthly pension payments have been frozen. The family is in debt for hundreds of thousands of dollars. Fei, who now sells goods on the internet, said she makes one-tenth of what she did before.

She found a community of people online with situations like hers. One man told her he used to be a civil servant until he was forced to quit his job after being blacklisted.

Fei said this was unfair. “No one wants to be a dishonest person,” she said.


2019 The New York Times Company

source: news.abs-cbn.com