Showing posts with label computers. Show all posts
Showing posts with label computers. Show all posts

Wednesday, June 7, 2017

Another Reason To Hate The Computerization Of Cars: Ransomware

Is ransomware in your car next?
A lot of us live in fear of  ransomware

You've probably heard of it. Hackers get into your computer and shut it down, deny you access to all your files, unless you pay a ransom to the hackers.

Often, if you get hit by ransomware, it's because you opened a safe looking email attachment, a fake email you thought was from a friend, and you're screwed.

Technically, that's partly your fault for not being careful, but we all get scammed every once in awhile, and fooled into doing something you thought was innocent. The scammers are crafty.

Now, there's other ransomware to worry about. As Consumer Reports tells us, the threat is in your car.

Says Consumer Reports:

"The reason cars are such inviting targets for ransomware hacjers is that they're increasingly computerized. And as automakers have transferred more and more functions to processors, they've neglected to install the same levels of security found in other modern devices - such as phones and laptops.

'Once you connect the car to the internet, the entire vehicle becomes a threat surface. If the auto industry doesn't adapt, we'll continue to see mistakes and potential vulnerabilities for things like ransomware to take place,' said Craig Hurst, executive director of the Future of Automotic Security Technology."

There's much more interesting things to read about this topic at in the Consumer Reports article.

One thing they don't get into, though, is this:  Unlike your laptop or phone, you don't get to install the hacking safety features in your car. The automaker does.

But if your car should get hacked one day and you get a demand for ransomware, I guarantee the car companies will not be held responsible.

It'll be all on you, because big corporations have all the rights these days, not you.

Thursday, May 4, 2017

This Video Shows Why Computer-Written News Copy Is Still Horribly Bad

I encountered a news video of a fatal house fire in East Bridgewater, Massachusetts recently.
An elderly man recently died in this Massachusetts house
fire, and an insulting computer generated "news" video
just made the situation even worse. 

The insulting, off the rails report of the fire showed that automation does not work when it comes to reporting on the news.

An outfit called World Today posted the video of the house fire, which was probably lifted from legitimate television news stations who were covering the fire.

The intro features some really bad dance club music, as if a tragic fire was an occasion to party.

The World Today video had an automated, computer generated voice that described the death in the house fire this way: "Police affirmed small time who lived in the house kicked the bucket thus of the fire."

Huh?

We also learned, "A working fire task was struck when firefighters touched bases as the house was immersed in blazes."

When the fire got too big for firefighters to work inside the house, the World Today video reported, "Firefighters were requested out of the building not long after arriving and are just battling the fire all things considered."

What do you mean "all things considered?" I don't even want to guess.

In reality, the fire was tragic. An 86-year old man's lawn mower caught fire, then caught his clothes on fire, and burned down his house. The elderly man died, and the house was destroyed, legitimate news station CBS Boston reported. 

Here's the horrible, cringe-inducing video, but you gotta see and hear it to believe it:

Monday, February 27, 2017

"Bringing Back" Virtual People Has Scary Orwellian Implications

Will the Light Stage technology shown here someday be used
to make it look like to the world that somebody who's innocent
is doing something not innocent?
Photo by Al Seib, Los Angeles Times
I was watching "CBS Sunday Morning" and what started out as a quirky fluff piece quickly scared the hell out of me.

The segment began by noting that the recent Star Wars movie "Rogue One" had in its cast the British actor Peter Cushing.  

Cushing died in 1994, so how can he be in a recently released film?

It turned out actor Guy Henry performed the new scenes, and a special effects engineers replaced Henry's face with Cushing's.

Here's where we begin to turn scary, when they introduced a guy named Paul Debevec.

According to CBS, Debevec invented something called the Light Stage. It has more than 10,000 LEDs, inside of which a subject - a person - is photographed with roughly 20 high quality DSLR cameras, which produce a series of high-resolution photos from different angles to reconstruct a 3-D model of the subject's face.

Debevec told CBS: "We'll have the actor make a succession of about 50 different facial expressions. And that produces all of the different motions of their face. But we also can record a facial performance from all these different angles, and then create a digital performance of that character that does exactly what they did in the video."

Adds CBS: "Once an actor has been scanned into Light Stage, engineers can digitally insert him or her into scenes, even if the actor is unavailable, much older or younger or deceased."

That's all fine and dandy if we're talking about the make-believe world of Hollywood. At least 100 famous actors have stood in this Light Stage to be scanned for movies, notes CBS.

The Light Stage was wicked expensive to build, but the price of this type of technology is coming down, and like most technology, will continue to come down fast.

Here's the scariest part, brought up by CBS Sunday Morning: What happens if someone scans a person, even unwittingly, and tries to pass it off as reality?

I'll take it to a ridiculous level. Remember that insane wacko rumor that Hillary Clinton was running a childhood sex ring in the non-existent basement of a Washington DC pizza restaurant?

So imagine scanning all these images of Hillary Clinton and making a film that "proves" she was running the child sex ring.

There are so many gullible people out there. An insane number of people believed the Clinton sex ring story. What if there was a computerized film to "prove" that it was true.

People are also always looking for blackmail opportunities, or to make it look like people did something bad that they didn't do.

Already, people hack into computers, making it look like they were committing crimes. Imagine using this Light Stage technology to produce videos for blackmail or worse that "show" the victim doing something terrible.

The lines between reality and fiction are blurring, be it politicians who do it by repeating false things, or people who use technology to make things up and pass them off as real.

This is another example of this blurring.

What kind of world will we live in when we can't distinguish the difference between what is really going on before our eyes, and what is pure fiction?

Saturday, December 10, 2016

Is This Doll Spying On Your Kids?

I'm glad I'm not a parent of young children.
Is this cute little computerized
doll named Cayla spying on
kids and saving their information?

Especially this time of year.  

So many things to consider. Is the toy safe? Will the kid like it? Will it instill the values we want in our children? Is it too expensive?

Unfortunately, parents now have a new, much more insidious worry: Is the toy spying on our children, on the family? Is the toy gathering intelligence on us?

This feels like Brave New World, but apparently, it's here.

According to Huffington Post and other news organizations, a group of consumer watchdog organizations has filed a complaint with the Federal Trade Commission, saing the dolls "My Friend Cayla" and "Que Intelligent Robot" have speech recognition software that gleans information from kids.

According to the FTC complaint:

"By design and purpose, these toys record and collect the private conversations of young children without any limitations on collection, use, or disclosure of this personal information.

The toys subject young children to ongoing surveillance and are deployed in homes across the United States without any meaningful data protection standards. They pose an imminent and immediate threat to the safety and security of children in the United States."

Sounds dire to me!

But how are these spy dolls doing this?

The concept of the dolls is really cool, until you think about how the dolls might collect information.

What child (or adult for that matter) wouldn't like adoll or other toy that has software that allows the doll to provide appropriate responses to everything the child says?

"Cayla can understand and respond to you in real time about almost anything.....She is not a doll...she's a real friend!" goes the Cayla advertising material.

I don't think that part of the FTC complaint iss the real objection.

But if you think about, as the people who filed the complaint have, this could be really underhanded.

Part of the complaint is fairly trivial, to be honest. Cayla mentions she likes the movie "Frozen," the movie "The Little Mermaid" and enjoys Disneyworld

The FTC complaint says that's product placement, and children don't recognize it as advertising.

That's probably true, but we're used to this by now.

To me, the real disturbing part of Cayla the doll is the information they try to glean from the kids who play with them.  Accompanying material with Cayla asks children to provide their name, mom and dad's name, which school they go to, their favorite foods and TV programs and things like that.

It's all about marketing and advertising, but it's creepy that a company would know all this stuff about a kid and her family. Especially since hackers can probably get in and cause all sorts of problems with the information.

Most worrisome, the complaint to the FTC  alleges the makers of Cayla, Genesis Toys, can record and store the information that the kids tell the doll while they're playing and conversing with it. Another company, Nuance Communications, allegedly stores the recordings for Genesis Toys.

The terms of use verbiage with Cayla, explains all this access to the information they have. But with all terms of service statements, this one is really dense and difficult to understand.  Nobody actually reads terms of service statements because they're so byzantine. and if they do, they reall don't understand it. I don't, that's for sure.

The Huffington Post and CBS says Genesis Toys won't comment. Neither would Nuance Communications, but they did direct media outlets to a Nuance muckymuck named Richard Mack, who wrote the company "takes data privacy seriously." and that the company doesn't use or sell voice data for marketing or advertising purposes."

Then why do they keep it, then? Part of it might be so the dolls interact with kids better, but I'm still suspicious.

Still, if I were a parent, I'd get my kids an old fashioned Teddy Bear or something. Call me a luddite, but I'm not sure I like this Brave New World of computerized kids toys.

Monday, January 19, 2015

Someday Your Car Might Be Taken Over By Hackers

Imagine this:
Will hackers remotely be able to cause wrecks
by this by taking control of cars'
computer systems?  

You're zooming down a highway in lots of traffic, doing the speed limit of 65 mph.

All of a sudden, your brakes don't work. Your car speeds up even though you have your foot off the gas. The steering wheel swings back and forth wildly, sending you all over the road.

Worse, this is happening to the cars around you. There's a big pileup and lots of people die.

I know that's the plot of some bad science fiction/action movie, but it's a worse-case scenario of what could perhaps happen in the future, at least according to a Vox article called "The Next Frontier in Hacking: Your Car."

Cars are increasingly equipped with super duper navigation, and will integrate with cellphones wonderfully, and will have more and more self driving capabilities, says Vox.

There's already a LOT of computer stuff in cars, and they're starting to become prone to hacking.  Most of the computer components in the past have been internal, but they're increasingly being connected to the greater outside Internet, and that trend will probably just keep accelerating.

You can only hack into these cars if you had physical access to them, just as you would need physical access to cut the brake lines or steal the battery or something.

But already, cars are starting to become hackable without ever getting near the thing.

Says Vox about one Universityof California study of an unnamed late model car:

"They found it was alarmingly vulnerable to external attack.

In one attack, they created a malicious music file that, if played on the car's stereo, would let hackers gain control of the car's computer systems. In another, they demonstrated that they could hack into the diagnostic equipment used by auto mechanics using its wifi connection, and from there install malicious software onto vehicles being serviced."

Some of this is dangerous and not deadly. Hackers would be able to listen in on conversations going on in the car, or disable the locking system, making it super easy to steal the car.

Hackers are already close to being able to take control of cars, or are already there.  From a scary article from Forbes about how researchers showing they ways cars like a Ford Escape and Toyota Prius  can be hacked:

"As I drove their vehicles for more than an hour (Charlie) Miller and (Chris) Valasek showed that they've reverse-engineered enough of the software of the Escape and the Toyota Prius (both the 2010 model) to demonstrate a range of nasty surprises: Everything from annoyances like uncontrollably blasting the horn to serious hazards like slamming on the Prius' brakes at high speeds.

They sent commands from their laptops that killed power steering, spoofed the GPS and made pathological liars out of speedometers and odometers.

Finally, they directed me out to a country road, where Valasek showed that he could violently jerk the Prius' steering at any speed, threatening to send us into a cornfield or a head-on collision. 'Imagine you're driving down a highway at 80,' Valesek says. 'You're going into the car next to yoi or into oncoming traffic. That's going to be bad times.'"

Notice the cars in the above passage were 2010 models. I can only imagine new model cars, like, say my new 2015 Toyota Tacoma could be hacked even more readily or extensively.

The danger of getting yourself killed by a hacker is of course the biggest worry. But there are also fraud worries. They can adjust the odometer. They could also probably alter the computer to hide the fact the used car you're buying has been in a wreck or a flood in the past.

And what if your car is hacked, you steer into a car carrying a family. How do you prove you weren't at fault?

There haven't been many hacks of cars yet, Vox explains, because each model of car has custom software that changes year to year. So you can't get widespread hacks, and it's harder to catch up with the changes.

PCs and smartphones are easier to hack hecause they all have standard operating systems, Windows, Android or iOS. So a single piece of malware can screw up millions of devices, says Vox. Plus, PCs and smartphones are connected to the Internet much more than cars are.

But as automakers keep upping the ante on the sophistication of car systems, the more likely they'll be hooked up to the Internet, and run on more hackable Android, Windows or iOS systems.

Says Vox:

"In the next year or two, most car manufacturers are going to support Android Audio and Apple's Carpay - standards that allow smartphones to control a cars dashboard touchscreen display. These interfaces could provide another potential route for hacking."

Vox said automakers need to do comprehensive security audits of the cars' software as part of a vehicle's safety testing process.

But that's hard to do since the auto manufacturers can't even look at source codes.  Vox says "suppliers consider this proprietary information and guard it closely."

OK suppliers, what's more important? Keeping people safe or making bundles of money?

Oh, right. Making bundles of money.

We hope the the Society of Automotive Engineers and the National Highway Traffic Safety Administration go forward with new standards for cyber security in vehicles.

Meanwhile, Miller and Valasek, the guys in the Forbes article above, have a good idea, according to Wired:

"The hacker duo has created a prototype of an intrusion detection system for cars - a $150 device that plugs directly into a vehicle's network to monitor and block suspicious commands."

Nice idea, and it would help, but I bet it could get hacked, too.

To be fair, some car manufacturers are starting to get on board with security.

According to CNN Money, Ford hardware has built-in firewalls that stop malicious tampering, and the company has a team of hackers that are always looking for weaknesses.

Toyota has a similar "good guy and gal" hacking team. Also, says CNN Money, "Toyota embeds security chips in the tiny computers throughout the car, narrowing how they communicate and lessening the chance of outsider interference."

Which makes me feel a little better about my new Toyota Tacoma.

Still, all this stuff in cars makes me nervous. I guess it boils down to our increasing lack of ability to control things. I actually resent even simple things, like car windows that roll down electronically, instead of with a crank.

If the electrical system malfunctions and I have to get out, how do I do it? Should I just carry a crowbar in the truck always, just in case?

Now we have all these computer systems. Convenient and fun, yes. I'm no Luddite. But I still have misgivings about all this, since for me, the point of driving a vehicle is to get from Point A to Point B, not be entertained by glitzy bells and whistles.  

Monday, March 25, 2013

Scary Hackers Get Scarier: SWATing Explained

Boy, people who maliciously get into computer systems, hack, whatever, are getting more and more viscious.

The latest new term to turn up in this weird underworld is SWATing, and that recently happened to a computer security journalist named Brian Krebs. 
Will these guys bust down your door, after being
pranked by jerks?
 That means you hack into his account, or get word to the FBI that the person you're targeting is illegally obtaining social security numbers and credit reports. Then the SWAT team arrives for raid to seize the target's computers, etc.

It's dangerous, of course. The authorities come with guns drawn, and if there's any misunderstanding between the person targeted for arrest and the SWAT team, things could get deadly fast.

In Krebs' case, the SWAT team arrived, he was cuffed, but fully cooperated, let the agents inside and explained. Plus, Krebs said he warned the FBI and other authorities beforehand that he was a target of these types of things. One of the agents in the raid remembered this report and realized Krebs was on the up and up.

Krebs said he'd been targeted in denial of service attacks on his web sites, and this SWATing thing, because he's been reporting on creepy web sites, mostly in Russia, that steal Social Security nunbers and credit reports, the very things the false tip to the FBI accused Krebs of doing.

There is a trend of much less sophisticated SWATing attacks in the country than what Krebs experienced. According to Dispatch magazine on line, a publication for 911 responders, people use computer technology to call 911 in distant cities to report things like a home invasion in progress.

Many of these SWATing incidents target unsuspecting homeowners who don't know the person who launched the dangerous prank. All of a sudden a SWAT team bursts in. Again, somebody is definitely going to get killed in one of these pranks.

Many times, this is caught in time, and there's no big SWAT response from police. Every once in awhile, some unsuspecting person ends up as the target of a major raid by gun wielding cops.

Not good.

As Dispatch magazine notes, it's really hard to catch the false calls as they happen:

".....There are investigative methods for identifying the origin of VoIP calls afterwards, although it takes a considerable amount of expertise, time and multi-agency assistance to accomplish. In fact, this seems to be the biggest hurdle in the investigation of these incidents--the anonymity of the caller, a lack of law enforcement contacts at VoIP providers, no phone numbers or e-mail addresses to report such incidents, and lack of resources within VoIP provider companies for investigating these incidents. The U.S. Attorney in the Texas prosecution praised the 40 agencies which cooperated to arrest their suspects--not an unusual number of agencies in these types of incidents."

Still, Dispatch notes there have been numerous arrests for these types of prank calls, like this guy. 

Many of the people initiating these false SWAT responses think they're being funny, it turns out. Wait until somebody gets killed. If that happens, can authorities bring murder charges against the "merry pranksters?"

Let's hope so.

Sunday, February 17, 2013

No Zombies in Montana, but Why Was There an Emergency Alert For Them?

People are still chortling over the Emergency Alert System broadcast on a Montana television station last week warning that zombies had risen from the dead and were menacing the good citizens of Big Sky country.
Zombies like these did not attack the good citizens
of Montana last week, despite an errant warning.
Somebody hacked into television station KRTV in Great Falls and activated the alert system. So viewers heard that familiar emergerncy tone, GRARRNK! GARRNNK!, followed by the mechanical sounding voice describing the emergency and the crawl across the bottom the screen putting the crisis into words.

Apparently, a few stations in Michigan were hacked by what was reportedly some overseas prankster who wanted to alert us if the faux zombie attack.

Zombies? Really? Aren't zombies becoming something of a cliche? Zombie attacks have become as tired a trope as the stereotype of the obnoxious drunk at a party dancing around with a lampshade on his head.

Time for something original, pranksters!

On a more serious note, why was it so easy to hack into the Emergency Alert System? It's meant for true emergencies. Say a tornado is heading straight for your town or a train derailed nearby and is threatening to overwhelm you with toxic fumes. The EAS is supposed to tell you about these things so you can either protect yourself or kiss your sorry ass goodbye.

Here's my paranoia again, but what if somebody with more ill intent than the Zombie jerks hack into the EAS and prompt a legitimate sounding, but fake alert? Maybe just to instill panic, or as a diversion for some other nasty crime?

And what if people stop trusting the EAS, and when there's a legitimate warning, people just shrug and ignore the oncoming danger, because the EAS just says things for fun, right?

I'm sure the Powers That Be are trying to figure out how the hackers got in, but even if they plug that hole, those wily hackers will surely find some other way to exploit the system, or any computerized system for fun or profit.

I guess we all have to fine tune our bullcrap meters so we can tell truth from fiction.