Author: azeeadmin

18 Feb 2019

Australia’s government and political parties hit by cyber attack from ‘sophisticated state actor’

The Australia government suffered a cyber attack that it suspects is the work of a “sophisticated state actor,” according to the country’s Prime Minister.

PM Scott Morrison said today the computer network of the country’s parliament, and those belonging to Liberal, Labor and Nationals parties, were targeted by an attack which took place a few weeks ago, The Sydney Morning Herald reports. Australia is months away federal elections which will take place in May.

Morrison said there is “no evidence of any electoral interference.”

“We have put in place a number of measures to ensure the integrity of our electoral system,” he said, adding that security services “acted decisively to confront it.”

There is apparently no indication that data was accessed following the attack.

Where exactly it originated from remains unclear.

Sources told SMH that the sophistication of the attack was “unprecedented,” but nobody in the government is naming suspects. Reportedly, the incident sports “the digital fingerprints of China” but there remains the possibility that the attack was framed to look like it originated from China.

The incident recalls the hacking of the Democrat Party around the U.S. Presidential election in 2016. The attackers, who are widely suspected to be linked to the Russian government, accessed are to have accessed 19,252 emails and 8,034 attachments from DNC email accounts, John Podesta, who was the campaign chairman for Hillary Clinton.

Australia itself has a history of parliamentary hacks. The national government was attacked in 2015 by a “foreign government” (later named as China) that reportedly used computers at the Bureau of Meteorology as its entry point. The incident is said to have given China the records of 14 million federal employees.

18 Feb 2019

Alan raises another $45 million for its health insurance product

Paris-based startup Alan has raised a Series B round of funding of $45 million (€40 million). Index Ventures is once again leading the round, with partners of DST Global also participating. The company had raised a $28 million funding round only ten months ago.

Alan is a software-as-a-service startup tackling a very specific industry — the health insurance market in France — and soon across Europe. The company wants to create a well-designed insurance product with transparent pricing and policies to make healthcare more accessible. And it isn’t just a marketplace — the startup has obtained an official health insurance license and is the first new health insurance company in France in 30 years.

In France, every employee is covered by the national healthcare system for basic reimbursements as well as a private insurance company for more expensive treatments. In addition to that, legacy insurance companies have neglected those products as they usually don’t generate a lot of margins on that segment. It creates a huge market opportunity for Alan.

With today’s funding announcement, the startup has shared some numbers. In 2018 alone, the company grew from 5,000 insured people to 27,000, and revenue jumped from $4 million to $25 million (€3.5 million to €22 million). Alan has been focused on freelancers as well as small and medium companies, such as My Little Paris, Le Slip Français, Ledger and Converteo.

More interestingly, Alan is close to break-even right now with 64 employees. That gives you an idea of Alan’s margins.

Following today’s funding round, the company is going to hire a lot more people. There should be around 175 people working for Alan by the end of the year.

On the product front, the company is always looking at ways to make the experience as seamless as possible. “We’re trying to make the insurance process instantaneous, from quotes to coverage and reimbursements” co-founder and CEO Jean-Charles Samuelian told me.

But Alan has always been about healthcare at large, not just insurance products. So let’s see how they can use this influx of funding to simplify healthcare in general.

18 Feb 2019

Razer is closing its game store after less than a year

Razer is one of the dominant brands in gaming when it comes to buying equipment to play, but one of its biggest efforts to own a larger slice of digital spending hasn’t gone according to plan. After less than a year, the company announced that it will close its digital game store at the end of this month “as part of realignment plans.”

The Razer Game Store launched worldwide in April 2018 with the aim of taking a slice of a game sales business that is dominated by Steam. Razer’s offering tied into its gamer credit (virtual currency) strategy to incentivize its customers to buy hardware and digital content with the promise of discounts. The company didn’t comment on why the store is closing, but you’d imagine that it didn’t go as well as Razer had hoped.

It sure takes a lot to bite into digital game sales, but the rewards are potentially lucrative.

Steam made $4.7 billion in 2017 (we don’t yet know its total for 2018) and Epic Games, buoyed by the runaway success of Fortnite, banked a $3 billion profit last year across its entire business, sources previously told TechCrunch.

Amazon-owned Twitch — which dominates the live-streaming space — has its own store, while Epic launched a very competitive offering at end of 2018. The Epic Games Store, though, is fairly sparsely populated at this point. It is a long-term project, but the fact that even a company of the size and influence of Epic needs time goes to show the struggle that any new entrant will face.

The Razer Game Store will close down on February 28

The Razer Game Store will close its doors at 1am PST February 28. All purchased games will continue to work and pre-ordered titles will ship as planned, according to Razer. Discount vouchers must be used before that date, however.

In a Q&A accompanying the announcement, Razer said it would “continue bringing games to gamers via other services.”

“We will be investing in other ways to deliver great content and introduce game promotions through Razer Gold, our virtual credits system,” the company said, perhaps hinting at tie-ins with other game stores in the future.

Razer went public with an IPO in Hong Kong in 2017.

18 Feb 2019

China tells teachers to quit assigning homework through WeChat

China’s education authorities are about to take some burden off parents with school-aged children. A proposal posted last week by the Department of Education in China’s eastern province of Zhejiang said teachers should be banned from using WeChat, QQ or other mobile apps to assign homework or ask parents to grade students’ assignments.

As mobile internet booms in China, phones have become an extension of daily activities, including school practices. Instead of announcing homework in class or handing out notices to students in person, teachers are now dumping assignments into WeChat groups designed to interact with parents. Many teachers are keen to exercise their power through these digital channels, asking parents to help students with problem sets and even grade their homework.

The regional call to action follows a set of national guidelines released by the Ministry of Education in October directing teachers and schools to take more responsibilities rather than shift the load onto parents. “Teachers should be accountable for their job, treat teaching seriously, correct homework with prudence and help students with care.”

Not all schools abuse digital platforms to such an extent. A Shenzhen-based parent told TechCrunch that her second-grader who attends a local public school still does much of her homework in written form and parents’ involvement is moderate.

“Different schools treat technology differently and I’m not opposed to the use of it. It’s helpful, for example, to use a digital device to learn English because much of the process involves audios and videos,” the parent said. “I think sometimes media are painting teachers and schools in such a negative light just to get attention.”

Other recommendations in the national notice include limiting the amount of online homework to reduce nearsightedness, which has become a source of concerns for parents and society at large.

The new directives also come as Beijing tries to rein in what and how private technology services are infiltrating students’ lives. In one far-reaching move, the government ordered video-game publishers to cap children’s playing time, sending shares of industry leaders Tencent and NetEase tumbling. More recently, the Ministry of Education asked schools and universities to audit apps used by teachers and students on campus in accordance with guidelines set by the regulator.

Despite the government’s intent to ease stress and unplug devices for students, education apps have flourished in China. Those that help students outperform their peers have done particularly well. Yuanfudao, a startup that offers live courses, exam prep and homework help, gained a $3 billion valuation in its latest $300 million funding round in December. Its rivals Zuoyebang and Yiqi Zuoye have similarly attracted big-name investors and sizable funds to help their young users get ahead.

18 Feb 2019

GoCardless raises $75M Series E for its recurring payments network and heads to America

Compared to startups born into the frothy London fintech space as it exists today, 2011-founded GoCardless could well be considered a slow burner. However, in more recent years, the nearly 300 person company — headed up by co-founder and CEO Hiroki Takeuchi — has undoubtedly stepped on the gas in a bid to become the one stop shop globally for businesses that want to let customers pay via recurring bank payments.

A little over a year ago, GoCardless announced that it had raised $22.5 million in further funding, off the back of record annual growth in the U.K. and strong early traction in new markets. And today the fintech is disclosing another fresh injection of capital: $75 million in Series E funding, in part to fund new offices across EMEA, APAC and North America. In addition to its London HQ, the company already has sites in France, Australia and Germany, from which it says it processes transactions for 40,000 businesses worldwide.

Leading the round are new investors Adams Street Partners, Google Ventures and Salesforce Ventures. Previous backers Accel Partners, Balderton Capital, Notion Capital and Passion Capital have also followed on.

In a call with Takeuchi late last week, he picked up on a familiar a theme, describing the collection of recurring payments for many business as “broken”. Accessing the various bank to bank payments schemes has traditionally been difficult from a commercial, compliance and technical point of view. Instead, businesses have typically relied on payment methods, such as card payments or cheques, which aren’t up to the job of recurring payments.

That’s because these payment options are designed for one-off transactions (cards, for example, expire, breaking the payment flow). Meanwhile, there’s been a rise in subscription business models and an expanding B2B market in which contractors and partners need to make regular variable payments. According to Takeuchi, this means an international recurring payments network like the one GoCardless is building is needed more than ever.

“A global network for bank debit is an absolute necessity in allowing businesses to easily collect recurring payments anywhere, in any currency,” he says. “Thanks to the support of our investors we can now open up our global network and payments platform to more businesses across the world, delivering on our mission to take the pain out of getting paid, so that businesses can focus on what they do best”.

Takeuchi also tells me GoCardless is investing heavily in its product, with a product team of around 100 members. He declined to go into much detail with regards to GoCardless’ immediate or more long term roadmap, although currency conversion is one area the company is developing new products for. It’s not clear if that will be via an FX partner, such as London neighbour TransferWise, or a more home grown solution, although the former seems more likely. Takeuchi wouldn’t be drawn on any specifics.

Other areas of development include products to help businesses boost cash flow via “instant settlement,” and smarter payment features to increase transaction success rates. The latter could include using open banking to check if funds are available before trying to process a bank debit, or to automatically set the most appropriate payment date.

18 Feb 2019

Etsy error resulted in large amounts being withdrawn from some sellers’ bank accounts and credit cards

An Etsy bill payment error resulted in large amounts of money being withdrawn from several sellers’ bank accounts and credit cards on Friday morning. While the company says the issue has been resolved and was not the result of fraud, the headache isn’t over for affected sellers because Monday is a federal holiday in the United States, and many financial institutions are closed.

Etsy sellers are required to have a valid credit or debit card on file with Etsy in order to have a payment account. Boing Boing reports that complaints first began emerging in Etsy’s Community Forums and Twitter on Friday morning, when sellers began noticing amounts ranging from hundreds to tens of thousands of dollars had ben withdrawn or charged to those accounts.

An Etsy representative posted with a brief message in its forum stating that the company was “aware of a bill payment error affecting a small group of sellers which resulted in some cards being incorrectly charged.” Then on Sunday afternoon, Etsy sent a longer explanation to sellers. The company said it has already refunded all incorrectly charged cards and will be sending deposits on Tuesday.

“An update on recent issues affecting payment accounts

On Friday, February 15, a bill payment error affected a small group of sellers which resulted in some cards being incorrectly charged. Sellers who were affected have been notified by email, or by Etsy Conversations, and the issue that caused this has since been resolved.

As part of fixing this issue, all incorrectly charged cards have been refunded. It may take several business days for the refunded amounts to clear and settle in card accounts.  Also related to fixing the root problem, some sellers saw their scheduled deposit of funds returned to Etsy on Friday, February 15, and those deposits will now be sent on Tuesday, February 19.

For affected sellers, we are very sorry for the trouble or concern this may have caused. Our first priority has been to correct the issue. This was not a fraud issue, but instead an error related to a site change which affects a small group of sellers and is unrelated to buyers’ purchases.

This is an issue we do not take lightly. We’ve assembled a Payments task force, including senior executives across Etsy, to address any concerns or troubles resulting from this error. We will refund any undue fees associated with this incorrect charge and change in deposit schedule. We don’t expect this error to impact additional sellers going forward.”

The explanation was not enough for many sellers, who said hourly updates should have been posted for a problem of this magnitude, and that Etsy had not addressed how it will compensate them for overdraft or late fees, or if the returned deposits will appear on their 1099s. TechCrunch has contacted Etsy for comment.

18 Feb 2019

Stop saying, “We take your privacy and security seriously”

In my years covering cybersecurity, there’s one variation of the same lie that floats above the rest. “We take your privacy and security seriously.”

You might have heard the phrase here and there. It’s a common trope used by companies in the wake of a data breach — either in a “mea culpa” email to their customers or a statement on their website to tell you that they care about your data, even though in the next sentence they all too often admit to misusing or losing it.

The truth is, most companies don’t care about the privacy or security of your data. They care about having to explain to their customers that their data was stolen.

I’ve never understood exactly what it means when a company says it values my privacy. If that were the case, data hungry companies like Google and Facebook, which sell data about you to advertisers, wouldn’t even exist.

I was curious how often this go-to one liner was used. I scraped every reported notification to the California attorney general, a requirement under state law in the event of a breach or security lapse, stitched them together, and converted it into machine-readable text.

About one-third of all 285 data breach notifications had some variation of the line.

It doesn’t show that companies care about your data. It shows that they don’t know what to do next.

A perfect example of a company not caring: Last week, we reported several OkCupid users had complained their accounts were hacked. More likely than not, the accounts were hit by credential stuffing, where hackers take lists of usernames and passwords and try to brute-force their way into people’s accounts. Other companies have learned from such attacks and took the time to improve account security, like rolling out two-factor authentication.

Instead, OkCupid’s response was to deflect, defend, and deny, a common way for companies to get ahead of a negative story. It looked like this:

  • Deflect: “All websites constantly experience account takeover attempts,” the company said.
  • Defend: “There’s no story here,” the company later told another publication.
  • Deny: “No further comment,” when asked what the company will do about it.

It would’ve been great to hear OkCupid say it cared about the matter and what it was going to do about it.

Every industry has long neglected security. Most of the breaches today are the result of shoddy security over years or sometimes decades, coming back to haunt them. Nowadays, every company has to be a security company, whether it’s a bank, a toymaker, or a single app developer.

Companies can start off small: tell people how to reach contact them with security flaws, roll out a bug bounty to encourage bug submissions, and grant good-faith researchers safe harbor by promising not to sue. Startup founders can also fill their executive suite with a chief security officer from the very beginning. They’d be better off than 95 percent of the world’s richest companies that haven’t even bothered.

But this isn’t what happens. Instead, companies would rather just pay the fines.

Target paid $18.5 million for a data breach that ensnared 41 million credit cards, compared to full-year revenues of $72 billion. Anthem paid $115 million in fines after a data breach put 79 million insurance holders’ data at risk, on revenues that year of $79 billion. And, remember Equifax? The biggest breach of 2017 led to all talk but no action.

With no incentive to change, companies will continue to parrot their usual hollow remarks. Instead, they should do something about it.

18 Feb 2019

UK parliament calls for antitrust, data abuse probe of Facebook

A final report by a British parliamentary committee which spent months last year investigating online political disinformation makes very uncomfortable reading for Facebook — with the company singled out for “disingenuous” and “bad faith” responses to democratic concerns about the misuse of people’s data.

In the report, published today, the committee has also called for Facebook’s use of user data to be investigated by the UK’s data watchdog.

In an evidence session to the committee late last year, the Information Commissioner’s Office (ICO) suggested Facebook needs to change its business model — warning the company risks burning user trust for good.

Last summer the ICO also called for an ethical pause of social media ads for election campaigning, warning of the risk of developing “a system of voter surveillance by default”.

Interrogating the distribution of ‘fake news’

The UK parliamentary enquiry looked into both Facebook’s own use of personal data to further its business interests, such as by providing access to user data to developers and advertisers in order to increase revenue and/or usage; and examined what Facebook claimed as ‘abuse’ of its platform by the disgraced (and now defunct) political data company Cambridge Analytica — which in 2014 paid a developer with access to Facebook’s developer platform to extract information on millions of Facebook users in build voter profiles to try to influence elections.

The committee’s conclusion about Facebook’s business is a damning one with the company accused of operating a business model that’s predicated on selling abusive access to people’s data.

Far from Facebook acting against “sketchy” or “abusive” apps, of which action it has produced no evidence at all, it, in fact, worked with such apps as an intrinsic part of its business model,” the committee argues. This explains why it recruited the people who created them, such as Joseph Chancellor [the co-founder of GSR, the developer which sold Facebook user data to Cambridge Analytica]. Nothing in Facebook’s actions supports the statements of Mark Zuckerberg who, we believe, lapsed into “PR crisis mode”, when its real business model was exposed.

“This is just one example of the bad faith which we believe justifies governments holding a business such as Facebook at arms’ length. It seems clear to us that Facebook acts only when serious breaches become public. This is what happened in 2015 and 2018.”

“We consider that data transfer for value is Facebook’s business model and that Mark Zuckerberg’s statement that ‘we’ve never sold anyone’s data” is simply untrue’,” the committee also concludes.

We’ve reached out to Facebook for comment on the committee’s report.

Last fall the company was issued the maximum possible fine under relevant UK data protection law for failing to safeguard user data from Cambridge Analytica saga. Although Facebook is appealing the ICO’s penalty, claiming there’s no evidence UK users’ data got misused.

During the course of a multi-month enquiry last year investigating disinformation and fake news, the Digital, Culture, Media and Sport (DCMS) committee heard from 73 witnesses in 23 oral evidence sessions, as well as taking in 170 written submissions. In all the committee says it posed more than 4,350 questions.

Its wide-ranging, 110-page report makes detailed observations on a number of technologies and business practices across the social media, adtech and strategic communications space, and culminates in a long list of recommendations for policymakers and regulators — reiterating its call for tech platforms to be made legally liable for content.

Among the report’s main recommendations are:

  • clear legal liabilities for tech companies to act against “harmful or illegal content”, with the committee calling for a compulsory Code of Ethics overseen by a independent regulatory with statutory powers to obtain information from companies; instigate legal proceedings and issue (“large”) fines for non-compliance
  • privacy law protections to cover inferred data so that models used to make inferences about individuals are clearly regulated under UK data protection rules
  • a levy on tech companies operating in the UK to support enhanced regulation of such platforms
  • a call for the ICO to investigate Facebook’s platform practices and use of user data
  • a call for the Competition Markets Authority to comprehensively “audit” the online advertising ecosystem, and also to investigate whether Facebook specifically has engaged in anti-competitive practices
  • changes to UK election law to take account of digital campaigning, including “absolute transparency of online political campaigning” — including “full disclosure of the targeting used” — and more powers for the Electoral Commission
  • a call for a government review of covert digital influence campaigns by foreign actors (plus a review of legislation in the area to consider if it’s adequate) — including the committee urging the government to launch independent investigations of recent past elections to examine “foreign influence, disinformation, funding, voter manipulation, and the sharing of data, so that appropriate changes to the law can be made and lessons can be learnt for future elections and referenda”
  • a requirement on social media platforms to develop tools to distinguish between “quality journalism” and low quality content sources, and/or work with existing providers to make such services available to users

Among the areas the committee’s report covers off with detailed commentary are data use and targeting; advertising and political campaigning — including foreign influence; and digital literacy.

It argues that regulation is urgently needed to restore democratic accountability and “make sure the people stay in charge of the machines”.

Ministers are due to produce a White Paper on social media safety regulation this winter and the committee writes that it hopes its recommendations will inform government thinking.

“Much has been said about the coarsening of public debate, but when these factors are brought to bear directly in election campaigns then the very fabric of our democracy is threatened,” the committee writes. “This situation is unlikely to change. What does need to change is the enforcement of greater transparency in the digital sphere, to ensure that we know the source of what we are reading, who has paid for it and why the information has been sent to us. We need to understand how the big tech companies work and what happens to our data.”

The report calls for tech companies to be regulated as a new category “not necessarily either a ‘platform’ or a ‘publisher”, but which legally tightens their liability for harmful content published on their platforms.

Last month another UK parliamentary committee also urged the government to place a legal ‘duty of care’ on platforms to protect users under the age of 18 — and the government said then that it has not ruled out doing so.

“Digital gangsters”

Competition concerns are also raised several times by the committee.

“Companies like Facebook should not be allowed to behave like ‘digital gangsters’ in the online world, considering themselves to be ahead of and beyond the law,” the DCMS committee writes, going on to urge the government to investigate whether Facebook specifically has been involved in any anti-competitive practices and conduct a review of its business practices towards other developers “to decide whether Facebook is unfairly using its dominant market position in social media to decide which businesses should succeed or fail”. 

“The big tech companies must not be allowed to expand exponentially, without constraint or proper regulatory oversight,” it adds.

The committee suggests existing legal tools are up to the task of reining in platform power, citing privacy laws, data protection legislation, antitrust and competition law — and calling for a “comprehensive audit” of the social media advertising market by the UK’s Competition and Markets Authority, and a specific antitrust probe of Facebook’s business practices.

“If companies become monopolies they can be broken up, in whatever sector,” the committee points out. “Facebook’s handling of personal data, and its use for political campaigns, are prime and legitimate areas for inspection by regulators, and it should not be able to evade all editorial responsibility for the content shared by its users across its platforms.”

The social networking giant was the recipient of many awkward queries during the course of the committee’s enquiry but it refused repeated requests for its founder Mark Zuckerberg to testify — sending a number of lesser staffers in his stead.

That decision continues to be seized upon by the committee as evidence of a lack of democratic accountability. It also accuses Facebook of having an intentionally “opaque management structure”.

“By choosing not to appear before the Committee and by choosing not to respond personally to any of our invitations, Mark Zuckerberg has shown contempt towards both the UK Parliament and the ‘International Grand Committee’, involving members from nine legislatures from around the world,” the committee writes.

“The management structure of Facebook is opaque to those outside the business and this seemed to be designed to conceal knowledge of and responsibility for specific decisions. Facebook used the strategy of sending witnesses who they said were the most appropriate representatives, yet had not been properly briefed on crucial issues, and could not or chose not to answer many of our questions. They then promised to follow up with letters, which—unsurprisingly—failed to address all of our questions. We are left in no doubt that this strategy was deliberate.”

It doubles down on the accusation that Facebook sought to deliberately mislead its enquiry — pointing to incorrect and/or inadequate responses from staffers who did testify.

“We are left with the impression that either [policy VP] Simon Milner and [CTO] Mike Schroepfer deliberately misled the Committee or they were deliberately not briefed by senior executives at Facebook about the extent of Russian interference in foreign elections,” it suggests.

In an unusual move late last year the committee used rare parliamentary powers to seize a cache of documents related to an active US lawsuit against Facebook filed by a developer called Six4Three.

The cache of documents is referenced extensively in the final report, and appears to have fuelled antitrust concerns, with the committee arguing that the evidence obtained from the internal company documents “indicates that Facebook was willing to override its users’ privacy settings in order to transfer data to some app developers, to charge high prices in advertising to some developers, for the exchange of that data, and to starve some developers… of that data, thereby causing them to lose their business”.

“It seems clear that Facebook was, at the very least, in violation of its Federal Trade Commission [privacy] settlement,” the committee also argues, citing evidence from the former chief technologist of the FTC, Ashkan Soltani .

On Soltani’s evidence, it writes:

Ashkan Soltani rejected [Facebook’s] claim, saying that up until 2012, platform controls did not exist, and privacy controls did not apply to apps. So even if a user set their profile to private, installed apps would still be able to access information. After 2012, Facebook added platform controls and made privacy controls applicable to apps. However, there were ‘whitelisted’ apps that could still access user data without permission and which, according to Ashkan Soltani, could access friends’ data for nearly a decade before that time. Apps were able to circumvent users’ privacy of platform settings and access friends’ information, even when the user disabled the Platform. This was an example of Facebook’s business model driving privacy violations.

While Facebook is singled out for the most eviscerating criticism in the report (and targeted for specific investigations), the committee’s long list of recommendations are addressed at social media businesses and online advertisers generally.

It also calls for far more transparency from platforms, writing that: “Social media companies need to be more transparent about their own sites, and how they work. Rather than hiding behind complex agreements, they should be informing users of how their sites work, including curation functions and the way in which algorithms are used to prioritise certain stories, news and videos, depending on each user’s profile. The more people know how the sites work, and how the sites use individuals’ data, the more informed we shall all be, which in turn will make choices about the use and privacy of sites easier to make.”

The committee also urges a raft of updates to UK election law — branding it “not fit for purpose” in the digital era.

Its interim report, published last summer, made many of the same recommendations.

Russian interest

But despite pressing the government for urgent action there was only a cool response from ministers then, with the government remaining tied up trying to shape a response to the 2016 Brexit vote which split the country (with social media’s election-law-deforming help). Instead it opted for a ‘wait and see‘ approach.

The government accepted just three of the preliminary report’s forty-two recommendations outright, and fully rejected four.

Nonetheless, the committee has doubled down on its preliminary conclusions, reiterating earlier recommendations and pushing the government once again to act.

It cites fresh evidence, including from additional testimony, as well as pointing to other reports (such as the recently published Cairncross Review) which it argues back up some of the conclusions reached. 

“Our inquiry over the last year has identified three big threats to our society. The challenge for the year ahead is to start to fix them; we cannot delay any longer,” writes Damian Collins MP and chair of the DCMS Committee, in a statement. “Democracy is at risk from the malicious and relentless targeting of citizens with disinformation and personalised ‘dark adverts’ from unidentifiable sources, delivered through the major social media platforms we use every day. Much of this is directed from agencies working in foreign countries, including Russia.

“The big tech companies are failing in the duty of care they owe to their users to act against harmful content, and to respect their data privacy rights. Companies like Facebook exercise massive market power which enables them to make money by bullying the smaller technology companies and developers who rely on this platform to reach their customers.”

“These are issues that the major tech companies are well aware of, yet continually fail to address. The guiding principle of the ‘move fast and break things’ culture often seems to be that it is better to apologise than ask permission. We need a radical shift in the balance of power between the platforms and the people,” he added.

“The age of inadequate self-regulation must come to an end. The rights of the citizen need to be established in statute, by requiring the tech companies to adhere to a code of conduct written into law by Parliament, and overseen by an independent regulator.”

The committee says it expects the government to respond to its recommendations within two months — noting rather dryly: “We hope that this will be much more comprehensive, practical, and constructive than their response to the Interim Report, published in October 2018. Several of our recommendations were not substantively answered and there is now an urgent need for the Government to respond to them.”

It also makes a point of including an analysis of Internet traffic to the government’s own response to its preliminary report last year — in which it highlights a “high proportion” of online visitors hailing from Russian cities including Moscow and Saint Petersburg…

Source: Web and publications unit, House of Commons

“This itself demonstrates the very clear interest from Russia in what we have had to say about their activities in overseas political campaigns,” the committee remarks, criticizing the government response to its preliminary report for claiming there’s no evidence of “successful” Russian interference in UK elections and democratic processes.

“It is surely a sufficient matter of concern that the Government has acknowledged that interference has occurred, irrespective of the lack of evidence of impact. The Government should be conducting analysis to understand the extent of Russian targeting of voters during elections,” it adds.

Three senior managers knew

Another interesting tidbit from the report is confirmation that the ICO has shared the names of three “senior managers” at Facebook who knew about the Cambridge Analytica data breach prior to the first press report in December 2015 — which is the date Facebook has repeatedly told the committee was when it first learnt of the breach, contradicting what the ICO found via its own investigations.

The committee’s report does not disclose the names of the three senior managers — saying the ICO has asked the names to remain confidential (we’ve reached out to the ICO to ask why it is not making this information public) — and implies the execs did not relay the information to Zuckerberg.

The committee dubs this as an example of “a profound failure” of internal governance, and also branding it evidence of “fundamental weakness” in how Facebook manages its responsibilities to users.

Here’s the committee’s account of that detail:

We were keen to know when and which people working at Facebook first knew about the GSR/Cambridge Analytica breach. The ICO confirmed, in correspondence with the Committee, that three “senior managers” were involved in email exchanges earlier in 2015 concerning the GSR breach before December 2015, when it was first reported by The Guardian. At the request of the ICO, we have agreed to keep the names confidential, but it would seem that this important information was not shared with the most senior executives at Facebook, leading us to ask why this was the case.

The scale and importance of the GSR/Cambridge Analytica breach was such that its occurrence should have been referred to Mark Zuckerberg as its CEO immediately. The fact that it was not is evidence that Facebook did not treat the breach with the seriousness it merited. It was a profound failure of governance within Facebook that its CEO did not know what was going on, the company now maintains, until the issue became public to us all in 2018. The incident displays the fundamental weakness of Facebook in managing its responsibilities to the people whose data is used for its own commercial interests.

17 Feb 2019

What business leaders can learn from Jeff Bezos’ leaked texts

The ‘below the belt selfie’ media circus surrounding Jeff Bezos has made encrypted communications top of mind among nervous executive handlers. Their assumption is that a product with serious cryptography like Wickr – where I work – or Signal could have helped help Mr. Bezos and Amazon avoid this drama.

It’s a good assumption, but a troubling conclusion.

I worry that moments like these will drag serious cryptography down to the level of the National Enquirer. I’m concerned that this media cycle may lead people to view privacy and cryptography as a safety net for billionaires rather than a transformative solution for data minimization and privacy.

We live in the chapter of computing when data is mostly unprotected because of corporate indifference. The leaders of our new economy – like the vast majority of society – value convenience and short-term gratification over the security and privacy of consumer, employee and corporate data.  

We cannot let this media cycle pass without recognizing that when corporate executives take a laissez-faire approach to digital privacy, their employees and organizations will follow suit.

Two recent examples illustrate the privacy indifference of our leaders…

  • The most powerful executive in the world is either indifferent to, or unaware that, unencrypted online flirtations would be accessed by nation states and competitors.
  • 2016 presidential campaigns were either indifferent to, or unaware that, unencrypted online communications detailing “off-the-record” correspondence with media and payments to adult actor(s) would be accessed by nation states and competitors.

If our leaders do not respect and understand online security and privacy, then their organizations will not make data protection a priority. It’s no surprise that we see a constant stream of large corporations and federal agencies breached by nation states and competitors.  Who then can we look to for leadership?

GDPR is an early attempt by regulators to lead. The European Union enacted GDPR to ensure individuals own their data and enforce penalties on companies who do not protect personal data.  It applies to all data processors, but the EU is clearly focused on sending a message to the large US based data processors – Amazon, Facebook, Google, Microsoft, etc. In January, France’s National Data Protection Commission sent a message by fining Google $57 million for breaching GDPR rules. It was an unprecedented fine that garnered international attention. However, we must remember that in 2018 Google’s revenues were greater than $300 million … per day!  GPDR is, at best, an annoying speed-bump in the monetization strategy of large data processors.

It is through this lens that Senator Ron Wyden’s (Oregon) idealistic call for billions of dollars in corporate fines and jail time for executives who enable privacy breaches can be seen as reasonable.  When record financial penalties are inconsequential it is logical to pursue other avenues to protect our data.

Real change will come when our leaders understand that data privacy and security can increase profitability and reliability.  For example, the Compliance, Governance and Oversight Council reports that an enterprise will spend as much as $50 million to protect 10 petabytes of data, and that $34.5 million of this is spent on protecting data that should be deleted. Serious efficiencies are waiting to be realized and serious cryptography can help.  

So, thank you Mr. Bezos for igniting corporate interest in secure communications. Let’s hope this news cycle convinces our corporate leaders and elected officials to embrace data privacy, protection and minimization because it responsible, profitable and efficient. We need leaders and elected officials to set an example and respect their own data and privacy if we have any hope of their organizations to protect ours.

17 Feb 2019

SeaBubbles shows off its ‘flying’ all-electric boat in Miami

We were promised flying cars but, as it turns out, flying boats were easier to build.

SeaBubbles, a “flying” boat startup that uses electric power instead of gas, hit Miami this weekend to show off one of its five prototype boats — or six, if you count an early, windowless white boat they’ve lovingly dubbed the “soapdish.” This innovative boat design combines technology from nautical industries, aviation, and intelligent software to raise the hull of the boat out of the water using foils, which helps it to consume less energy by allowing it to travel on rougher waters with reduced drag, while also keeping the passenger cabin relatively comfortable.

When raised, the boat is “flying” above the water, so to speak.

Founded only three years ago in Paris, the idea for SeaBubbles was dreamed up by Alain Thébault, a sailor who previously designed and piloted the Hydroptère, an experimental hydrofoil trimaran, using a similar system that lifts the boat up in order to reduce drag. That boat went on to break the world record for sailing speed twice, at 50.17 knots. Meanwhile, SeaBubbles co-founder, Anders Bringdal, is a four-times windsurf world champion, who also set a windsurfing world record, at 51.45 knots.

Together, the two have envisioned SeaBubbles as a way for cities to reduce traffic congestion and help the environment by taking advantage of the area’s waterways to move people around in fast water taxis.

“The cities today have one thing in common: pollution and congestion,” explains Bringdal. “Every city has waterways — ones that are fairly unused. Think about having a giant freeway that goes straight down the center of the city, and no one uses it… why is that?,” Bringdal continues.

“You could do this with a normal boat,” he admits. “But with a normal boat with a normal combustion engine, the fuel price you’re paying is between $70 and $130 per hour. With us, it’s $2 dollars,” he says.

The cost savings come from an all-electric design, which means the boat charges at a power station — preferably one that’s solar charged, of course, instead of guzzling gas.

The company has experimented with all sorts of designs and models before settling on its first-to-market SeaBubbles water taxi: a smaller, 4.5-meter version that seats four in addition to the pilot. However, the technology itself is scalable to larger boats or even ferries.

According to SeaBubbles’ U.S. partner, Daniel Berrebi, whose company Baja Ferries has made a “small” investment in SeaBubbles, even larger boats like his could eventually benefit from the technology.

Beyond his obvious business interest on that front, Berrebi is also working with SeaBubbles to help the company make its first U.S. sales. He says he’s sold four boats to private individuals in the area — yes, sold as in “checks in hand, and signed on the dotted line.” These buyers don’t want to be named, but may include well-known names in music and sports. (Of course one has to wonder how much anonymity they will really have when tooling about Miami waterways in one of only a handful of these flying boats currently in existence?)

SeaBubbles has been able to come to market with its technology so soon because it’s not building everything in-house.

The boats’ engines are from Torqeedo, for example, while the fly-by-wire software to control the boat comes from foiling and flight control systems engineer Ricardo Bencatel’s company, 4DC Tech. His software solution also powered America’s Cup teams’ boats, like those from Artemis Racing and Oracle. But the version running on SeaBubbles has customized components to control the boat’s unique features.

“The [SeaBubbles] boat has three main sensors — it has two high altitude sensors to measure the height of the water, then it has a gyroscope — like the one in cell phones,” explains Bencatel.

“The computer combines those measurements from the sensors, then it knows the angles of the boat, the height and the speed,” he says. The software then uses this information to control the flaps on the boat to make adjustments. “For example, the lift — if you want to go higher,” Bencatel says. “Or if it’s rolling to one of the sides, it uses the flaps to turn it to the other side. Or if it’s pitching — bow down or bow up — it uses the front or the rear flaps,” he adds.

And all of these adjusts are being made automatically, by way of software, meaning the boat operator only really has to turn the wheel and drive. They don’t have to think about when to raise or lower the boat — it just happens when the boat reaches a certain speed. Under six knots, the boat is experiencing 100 percent drag, while above eight knots, the boat is ‘flying’ and the drag is reduced to 60 percent. This makes the ride less bumpy, too.

The lithium-ion batteries used by SeaBubbles are IP67 waterproof, and, over time, the boat could make up for its high sticker price — $200,000 at its suggested retail price — with savings on gasoline and reduced maintenance costs.

The prototype version of the SeaBubbles boat has only 1.5 hours autonomy and a five hour battery recharge to show off the technology. But the company claims the versions going into production have 2.5 hours autonomy and a 35 minute recharge. These are the ones they expect to ship this summer to the first purchasers.

In addition to Miami, SeaBubbles also has customers in Russia — a luxury hotel in Moscow and a deal in St. Petersburg — as well as in Rotterdam and Amsterdam. It plans to start building boats for these markets, and hopes to reach Paris by this summer or the next. In Paris, the prototype boats run slower — takeoff speed is six knots, and cruising speed tops out at 15 knots. The production version is faster due to bigger engines, with an average cruising speed of 16 knots and a top speed of 20 knots.

The company is in Miami this week to show off its boat to more buyers, and take meeting with local officials.

Bringdal admits that some of the company’s earlier statements may have been overly ambitious — like having boats in 50 cities by 2024. ”I think, in reality, it’s step by step,” he says  “We’re very happy to be seeing something here in the U.S.”

SeaBubbles, which has seven staff full-time and 25 people including contractors, has raised $14 million to date from investors including the founder of drone maker Parrot, Henri Seydoux; Partech Ventures; the French government-backed BPI fund; MAIF, a French insurance group; as well as friends, family and other angels.

The company is preparing to raise a Series A.

(Photo credits: Alain Thébault and Sarah Perez)