• Alphabet-owned jigsaw bought a Russian troll campaign as an experiment

    For more than two years, the notion of social media disinformation campaigns has conjured up images of Russia’s Internet Research Agency, an entire company housed on multiple floors of a corporate building in St. Petersburg, concocting propaganda at the Kremlin’s bidding. But a targeted troll campaign today can come much cheaper—as little as $250, says Andrew Gully, a research manager at Alphabet subsidiary Jigsaw. He knows because that’s the price Jigsaw paid for one last year. Andy Greenberg writes in Wired that as part of research into state-sponsored disinformation that it undertook in the spring of 2018, Jigsaw set out to test just how easily and cheaply social media disinformation campaigns, or “influence operations,” could be bought in the shadier corners of the Russian-speaking web. In March 2018, after negotiating with several underground disinformation vendors, Jigsaw analysts went so far as to hire one to carry out an actual disinformation operation, assigning the paid troll service to attack a political activism website Jigsaw had itself created as a target.

  • Lawmakers grapple with deepfake threat at hearing

    The House Intelligence Committee heard alarming testimony Thursday that deepfake videos could be weaponized by foreign adversaries to sow divisions in the United States. Olivia Beavers and Maggie Miller write in The Hill that Clint Watts, a former FBI special agent and senior fellow for Alliance for Securing Democracy at the German Marshall Fund, warned lawmakers that Russia and China will likely both work to develop “synthetic media capabilities” for use against the U.S. and other adversaries. “China’s artificial intelligence capabilities rival the U.S., are powered by enormous data troves to include vast amounts of information stolen from the U.S., and the country has already shown a propensity to employ synthetic media in television broadcast journalism,” he said.

  • A top voting-machine firm is finally taking security seriously

    Over the past 18 months, election-security advocates have been pushing for new legislation shoring up the nation’s election infrastructure. Election-security reform proposals enjoy significant support among Democrats—who control the House of Representatives—and have picked up some Republican cosponsors, too. Timothy B. Lee writes in Wired that such measures, however, have faced hostility from the White House and from the Republican leadership of the Senate. Legislation called the Secure Elections Act, cosponsored by senators James Lankford (R-Oklahoma) and Amy Klobuchar (D-Minnesota) last year, aimed to shore up the nation’s election security by providing states with new money to phase out paperless systems. But the Lankford-Klobuchar bill stalled in the face of opposition from the Trump administration and Senate Republicans. At this point, any election reform legislation looks unlikely to pass before the 2020 election.

  • Ahead of the 2020 election: National response to confront foreign interference

    Stanford University scholars outline a detailed strategy for how to protect the integrity of American elections – including recommendations such as requiring a paper trail of every vote cast and publishing information about a campaign’s connections with foreign nationals.

  • Eliminating infamous security threats

    Meltdown and Spectre are speculative side-channel attacks exploit a fundamental functionality in microprocessors to expose security vulnerabilities. No efficient protection against such attacks has been found. Until now.

  • Russian disinformation on YouTube draws ads, lacks warnings

    Fourteen Russia-backed YouTube channels spreading disinformation have been generating billions of views and millions of dollars in advertising revenue, according to researchers, and had not been labeled as state-sponsored, contrary to the world’s most popular streaming service’s policy. Reuters reports that the channels, including news outlets NTV and Russia-24, carried false reports ranging from a U.S. politician covering up a human organ harvesting ring to the economic collapse of Scandinavian countries. Despite such content, viewers have flocked to the channels and U.S. and European companies have bought ads that run alongside them.

  • Nuclear energy regulators need to bring on more cyber experts, watchdog says

    The Nuclear Regulatory Commission is facing a mass exodus of cybersecurity experts in the years ahead, which could limit its ability to ensure the nation’s nuclear power plants are safe from digital attacks, an internal watchdog found. Jack Corrigan writes in Defense One that Nearly one-third of NRC’s cybersecurity inspectors will be eligible for retirement by the end of fiscal 2020, and agency officials worry they aren’t training enough people to take their place, according to the NRC Inspector General. With nuclear power stations becoming increasingly popular targets for online adversaries, the shortage of cyber expertise could leave the agency struggling to do its job, auditors said.

  • Russia's 2016 Twitter campaign far broader, deeper, and incredibly successful: Symantec

    The archives of the Internet Research Agency, the St. Petersburg-based troll farm, show a broad, coordinated, and effective campaign which was, in the words of one report, “incredibly successful at pushing out and amplifying its messages.” The Internet Research Agency conducted a campaign on Twitter before the 2016 elections that was larger, more coordinated and more effective than previously known.

  • IS’s English-speaking fighters use Telegram to reinforce faith in the caliphate

    English-speaking Islamic State supporters are refusing to give up on the terror group’s ability to remain a force in Syria and Iraq. Even as the terror group was losing ground in Syria and Iraq to U.S.-backed forces, and even as IS leadership was encouraging followers to start looking to progress in IS provinces elsewhere, English-speaking supporters turned to Telegram to reinforce their faith in the caliphate.

  • Secure multiparty computation protecting privacy at the ballot box

    Shortly after the start of the new year, Americans around the nation will start returning to polling stations to vote in presidential primaries. How confident they feel in the voting process could depend on this thing called secure multiparty computation.

  • New computer attack mimics user's keystroke characteristics, evading detection

    Researchers have developed a new attack called “Malboard,” which evades several detection products that are intended to continuously verify the user’s identity based on personalized keystroke characteristics. 

  • The U.S. needs an industrial policy for cybersecurity

    Industrial policies are appropriate when market failures have led to the under-provision of a good or service. The cybersecurity industry’s growth has been held back for several reasons, including intractable labor shortages. Vinod K. Aggarwal and Andrew W. Reddie write in Defense One that both the United States and United Kingdom suffer from a documented shortage of skilled programmers and computer scientists working on cybersecurity issues, and the U.S. alone is projected to have a shortage of 1.2 million professionals by 2022, according to the Center for Strategic and International Studies. The market has also been hindered by so-called “information problems,” as firms are often not aware of their own vulnerabilities and avoid sharing information about data breaches given the reputation costs associated with disclosure. So what can the government do about it?

  • Many Americans say made-up news is a critical problem that needs to be fixed

    Many Americans say the creation and spread of made-up news and information is causing significant harm to the nation and needs to be stopped, according to a new Pew Research Center survey of 6,127 U.S. adults conducted between 19 February and 4 March 2019, on the Center’s American Trends Panel. Amy Mitchell, Jeffrey Gottfried, Sophia Fedeli, Galen Stocking and Mason Walker write for Pew Research Center that, indeed, more Americans view made-up news as a very big problem for the country than identify terrorism, illegal immigration, racism and sexism that way. Additionally, nearly seven-in-ten U.S. adults (68 percent) say made-up news and information greatly impacts Americans’ confidence in government institutions, and roughly half (54 percent) say it is having a major impact on our confidence in each other.

  • Hackers seek ransoms from Baltimore and communities across the U.S.

    The people of Baltimore are beginning their fifth week under an electronic siege that has prevented residents from obtaining building permits and business licenses – and even buying or selling homes. These types of attacks are becoming more frequent and gaining more media attention. Every user of technology must consider not only threats and vulnerabilities, but also operational processes, potential points of failure and how they use technology on a daily basis.

  • WhatsApp's loophole reveals role of private companies in cyber-surveillance

    Last month, WhatsApp’s latest security flaw was discovered, a flaw which allow governments to spy on dissidents, activists, and journalists. An Israeli cyber company is reportedly behind the loophole — and not for the first time.