Unsupervised Learning: No. 187
Unsupervised Learning22 Heinä 2019

Unsupervised Learning: No. 187

Lots of people in the security community went silly over the FaceApp application last week, basically saying that you shouldn't be using the application because they'll steal your face and then be able to impersonate you. Oh, and then it turned out to be a Russian company who put out the application, and that made it 100x worse. The problem here is the lack of Threat Model Thinking. When it comes to election security, propaganda discussions, etc., I am quite concerned about Putin's willingness and ability to harm our country's cohesion through memes and social media. But that does not extend to some random company stealing faces. Why? Because before you can get legitimately concerned about something, you have to be able to describe a threat scenario in which that thing becomes dangerous. As I talked about in this piece, pictures of your face are not the same as your face when it comes to biometric authentication. There's a reason companies need a specific device, combined with their custom algorithm, in order to enroll you in a facial identification system. They scan you in a very specific way and then store your data (which is just a representation, not your actual face) in a very specific way. Then they need to use that same exact system to scan you again, so they can compare the two representations to each other. That isn't happening with random apps that have pictures of you. And even if that were the case, they could just get your face off your social media, where those same people who are worried are more than happy to take selfies, put their pictures on profile pictures, and make sure as many people see them as possible. There are actual negative things that can be done with images (like making Deepfakes of you), and that will get easier over time, but the defense for that is to have zero pictures of you…anywhere. And once again you have to ask who would be doing that to you, and why. Bottom line: authentication systems take special effort to try to ensure that the input given is the same as the enrollment item, e.g., (face, fingerprint, etc.), so it will not be easy any time soon to go from a random picture to something that can full a face scanner or fingerprint reader at the airport. People reading this probably already know this, but spread the word: threat modeling is one of our best tools for removing emotion from risk management.

A contractor named SyTech that does work with Russian FSB has been breached, resulting in the release of 7.5TB of data on the FSB's various projects. This is obviously embarrassing for SyTech and the FSB, but the leaked projects focused on de-anonymization, spying on Russian businesses, and the project to break Russia away from the Internet, which are all known and expected efforts. So there don't seem to be any big reveals as a result of the leak. More

Someone discovered that a bunch of browser extensions were reading things they shouldn't be, and sending them out to places they shouldn't be. This is not surprising to me. Chrome extensions are like Android apps, which should tell you all you need to know about installing random ones that seem interesting. My policy on browser extensions is extremely strict for this reason. People need to understand how insane the entire idea of the modern web is. We're visiting URLs that are executing code on our machines. And not just code from that website, but code from thousands of other websites in an average browsing session. It's a garbage fire. And the only defense really is to question how much you trust your browser, your operating system, and the original site you're visiting. But even then you're still exposing yourself to significant and continuously-evolving risk when you run around clicking things online. And the worst possible thing you can do in this situation is install more functionality, which gives more parties, more access, to that giant stack of assumptions you're making just by using a web browser. The best possible stance is to have as few people possible with access to your particular dumpster. And that means installing as few highly-vetted add-ons as possible. More

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Jaksot(532)

UL NO. 447: Sam Curry on Bug Bounty Careers, Slack Data Exfil, The Work Lie

UL NO. 447: Sam Curry on Bug Bounty Careers, Slack Data Exfil, The Work Lie

Stopping Chinese AI/Robot imports, Substrate for political platforms, sun vs. smoking, and more... Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

31 Elo 202432min

Don’t Judge Yourself Based On What Companies Think of Your Skills

Don’t Judge Yourself Based On What Companies Think of Your Skills

I watched a number of videos last night about people losing their jobs, starting a YouTube channel, and just generally struggling. People are hurting because they’re feeling the ground shifting under their feet and it’s not clear if it’s their fault, what’s going on, or what to do about it. Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

29 Elo 20244min

Microsoft Fires DEI Team & The Correct Approach To Diversity

Microsoft Fires DEI Team & The Correct Approach To Diversity

Microsoft Lays Off DEI Team — Microsoft laid off its diversity, equity, and inclusion team, saying DEI is "no longer business critical." MORE Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

27 Elo 20242min

UL NO. 446: AI Ecosystem Components, MS 0-Days, Iranian Campaign Hacks…

UL NO. 446: AI Ecosystem Components, MS 0-Days, Iranian Campaign Hacks…

Political deepfakes are here, Grok2 is insane, weakness vs. evil, and more…  Check out ThreatLocker to secure your data: threatlocker.com/ul Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!   Discussed in this episode: Intro (00:00:00)Migration to Go (00:01:45)Aphorisms and AI Models (00:03:09)Peter Thiel and Joe Rogan Discussion (00:04:12)Thiel's Intellectual Approach (00:05:15)Thiel's Complexity (00:07:25)Community Libraries (00:11:13)AI Model Ecosystems (00:12:12)Microsoft Security Flaws (00:13:15)Russian Cyber Campaign (00:13:45)Taiwan Strait Drone Strategy (00:14:24)Offensive AI Research (00:14:45)Cyber Attacks on Iranian Banks (00:15:21)Trump's Fake Image Controversy (00:15:21)Deepfakes and Misinformation (00:16:16)Potential for Crisis from Misinformation (00:18:24)Iranian Hacking Campaigns (00:19:31)China's Cyber Spies (00:20:22)AI Image Generation Chaos (00:20:22)AI in Comedy (00:21:28)Deepfake Comedy Integration (00:22:40)Future of Deepfake Comedy (00:23:28)San Francisco's Software Ban (00:23:28)China's Manufacturing Crisis (00:24:25)Venture Capital Trends (00:25:30)Gen Z Unemployment Trends (00:28:24)Impact of Technology on Childhood (00:29:28)Dopamine Levels and Boredom (00:32:22)Privilege of Stable Households (00:34:23)Market for Content Authenticity (00:35:24)Weakness vs. Evil (00:35:24)Fabric Integration with Raycast (00:36:25)Eric Schmidt's Honest Interview (00:37:59)AI as Augmentation Technology (00:38:63)Live Coding Demonstration (00:39:57)The Importance of AI Awareness (00:41:08)Aphorism of the Week (00:41:29)Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

22 Elo 202442min

Introducing Substrate—An Open-source Framework for Human Understanding, Meaning, and Progress

Introducing Substrate—An Open-source Framework for Human Understanding, Meaning, and Progress

This episode introduces Substrate—An Open-source Framework for Human Understanding, Meaning, and Progress.  Substrate is a crowdsourced project designed to enhance understanding, communication, and action in order to move humanity forward. Read the Article:📃 https://danielmiessler.com/p/introducing-substrate TOPICS:Introduction to Substrate (00:00:00)Components of Substrate (00:01:18)GitHub Repository Overview (00:02:33)Purpose of Substrate (00:04:36)Argument Visualization Example (00:05:32)Graphical Representation of Arguments (00:07:55)Trust in Sources (00:09:56)Strengthening Discussions (00:10:57)Real-World Use Cases (00:11:54)Describing Yourself with Substrate (00:12:55)Learning About Others (00:14:54)Visualizing Arguments and Claims (00:15:51)Transparency in Evaluating Claims (00:17:59)The Tiny Teapot Claim (00:18:54)Substrate Plus AI (00:20:04)Automating Science Workflows (00:21:16)Monitoring Crime and Corruption (00:24:21)Leadership Accountability (00:29:49)Companies as Graphs of Algorithms (00:31:56)Future State Optimization (00:35:47)Understanding Security Assessment (00:36:41)Optimizing Processes with AI (00:37:46)The Purpose of Substrate (00:38:49)AI's Role in Substrate (00:39:56)Want to Be Involved? (00:39:56) REFERENCED RESOURCES: My 9,000-word Illustrated Essay on Where I Think AI is Heading🔥 https://danielmiessler.com/p/ai-predictable-path-7-components-2024 The Substrate Project:⚙️ https://github.com/human-substrate Follow on X:🆇 https://x.com/danielmiessler Subscribe to the newsletter at: ✉️ https://danielmiessler.com/subscribe Join the UL community at:🤝🏻https://danielmiessler.com/upgradeBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

9 Elo 202441min

UL NO. 444: Pizza Meter Intelligence, China Bypasses Bans, Securing AWS Secrets…

UL NO. 444: Pizza Meter Intelligence, China Bypasses Bans, Securing AWS Secrets…

What to expect at Blackhat/DEFCON, Identifying Explosives, OpenAI's new models, Llama 4 Timeline, and more…  ➡ Check out Vanta and get $1000 off:vanta.com/unsupervised Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Discussed in this episode:Intro (00:00:00)OSINT and the Pizza Index (00:01:08)Agent Framework Development (00:02:12)State of Cybersecurity (00:04:08)Critical Security Vulnerabilities (00:05:27)Ransomware Trends (00:06:25)Data Breach Costs (00:07:29)AI Developments (00:08:40)California AI Regulation (00:09:42)OpenAI's GPT-4 Launch (00:11:01)Tech Company Updates (00:12:03)Shifts in Workforce Dynamics (00:13:07)Prisoner Swap News (00:17:06)Shark AI Model (00:18:03)Dementia Prevention Insights (00:19:03)Genetics of Self-Control (00:20:12)Name and Appearance Study (00:20:12)Alzheimer's Disease Research (00:20:12)Dungeons and Dragons Rulebooks (00:20:12)Novelists Writing Bug Reports (00:21:22)Recent UBI Study Analysis (00:21:22)Free-Range Kids Initiative (00:21:22)Discovery Farm Bot (00:22:13)Super Memory AI (00:22:13)Avi Shipman's AI Pendant (00:22:13)Installing Fabric (00:22:13)Fleet Open Source Tool (00:22:13)SOC2 Policy Templates (00:22:13)Clutch Security Platform (00:22:13)Black Hat Reminder (00:23:48)Aphorism of the Week (00:23:48)Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

9 Elo 202424min

Scaling Misinformation With AI

Scaling Misinformation With AI

Daniel Miessler discusses how AI can grow the number of elite propagandists and hackers employed by foreign intelligence agencies. Discussed in this video: AI-Enhanced Software and Disinformation (00:00:00)Russia utilizes AI software, Millio Radar, to create sophisticated fake personas for disinformation. Concerns About AI Sophistication (00:01:12)The increasing capabilities of AI could enable enemies to manipulate information on a massive scale. Shift from Block List to Allow List (00:02:30)The internet may need to transition to an allow list system to combat overwhelming disinformation. Risks for Ordinary Individuals (00:03:44)Regular users, especially the less tech-savvy, are at high risk of falling victim to manipulation online. Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

7 Elo 20245min

UL NO. 443: North Korean Co-workers, UBI Failure?, AI-Groupthink, GPS Spoofing…

UL NO. 443: North Korean Co-workers, UBI Failure?, AI-Groupthink, GPS Spoofing…

Switzerland goes open source, Google keeps cookies, DJI not cancelled, Alzheimer's spray, and more… ➡ Check out Vanta and get $1000 off:vanta.com/unsupervised Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at:https://danielmiessler.com/upgrade Follow on X:https://twitter.com/danielmiessler Follow on LinkedIn:https://www.linkedin.com/in/danielmiessler See you in the next one!Discussed in this episode: Intro (00:00:00)Job Loss and Career Change (00:01:42)Self-Worth in the Job Market (00:02:55)The Need for Kindness (00:03:54)North Korean Cybersecurity Threat (00:04:57)GPS Spoofing Risks (00:07:11)Malicious Acts Disrupting Transportation (00:08:10)Google's Cookie Policy Change (00:09:19)AI's Impact on the Job Market (00:10:30)Generative AI and Creativity (00:11:32)Concerns Over AI Influence (00:12:50)Switzerland's Open Source Law (00:15:08)Waymo vs. Tesla in Self-Driving (00:16:07)Hiring Practices in Tech Companies (00:17:07)Declining U.S. Birthrate (00:18:11)Universal Basic Income (00:18:11)Building a Star Team (00:19:48)Overcoming Disadvantages (00:23:06)Distribution of Talent (00:24:07)Southwest Airlines Policy Change (00:25:16)Economic Stress in America (00:26:32)Breakthroughs in Medicine (00:27:45)Conspiracy Theories in Politics (00:28:32)Humanizing Political Differences (00:30:00)Lessons from "The Righteous Mind" (00:31:16)The Importance of Empathy (00:32:17)  Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

5 Elo 202433min