IA, Franco Pizzetti: ‘Con il Regolamento l’Ue vuole sviluppare una tecnologia umanocentrica”

“L’Europa in questa fase è guidata da una grande ambizione politica volta a recuperare il tempo perso e riconquistare la capacità di competere a livello globale sulle opportunità dell’Intelligenza artificiale. L’Unione Europea, con l’adozione del Regolamento, affronta per prima la sfida. Non di rinunciare alla tecnologia, ma di sviluppare una tecnologia umanocentrica”.

Lo ha dichiarato Franco Pizzetti Università LUISS-Guido Carli, nel corso dell’intervista realizzata da Key4biz su «L’intelligenza Artificiale e il Regolamento Europeo. Regole, Opportunità e Rischi».

“Non solo una competizione economica, ha aggiunto Pizzetti.” C’è bisogno che l’uomo non rinunci all’intelligenza artificiale, ma allo stesso tempo non diventi prigionieri delle stesse conquiste”.

Rivedi la videointervista a Franco Pizzetti

[embedded content]

https://www.key4biz.it/lia-e-il-regolamento-europeo-regole-opportunita-e-rischi-oggi-alle-15-videointervista-live-a-franco-pizzetti/357975/




Google Data Protection Case to be Heard in UK Supreme Court

Google on Wednesday began a legal bid at Britain’s highest court to try to block a class action alleging that it illegally tracked millions of iPhone users.

The hearing at the Supreme Court will hear arguments for two days before judges decide whether the claim against the internet search giant should proceed.

The “Google You Owe Us” association, which is led by the former head of consumer rights group Which?, Richard Lloyd, is seeking at least £1 billion ($1.4 billion, 1.1 billion euros) to compensate four million users in England and Wales.

In October 2018, the High Court dismissed the case but the Court of Appeal overturned the decision in October 2019, allowing it to proceed. Google has appealed against the decision, hoping to get the case dismissed on the grounds the claimants have shown insufficient evidence users were adversely affected.

The association accuses Google of circumventing iPhone security options and collecting personal data between August 2011 and February 2012 using the Safari browser.

Information about users’ social or ethnic origin, health, political views, sexual preferences or shopping habits was collected, according to the complaint, which alleges the information was then compiled and offered to advertisers.

“Google illegally misused the data of millions of iPhone users without consent and we want to hold them to account,” Lloyd said in a statement before the hearing.

Google has said the events that happened 10 years ago were responded to at the time.

“Google You Owe Us” has said the door was opened to its complaint following the confidential settlement of a similar case in 2015 which was brought by three individuals.

view counter

© AFP 2020

Previous Columns by AFP:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/PIZHGNzAkDc/google-data-protection-case-be-heard-uk-supreme-court




Green pass e obbligo vaccinale, Cerrina Feroni: “Da modificare. Il Governo consulti il Garante Privacy”

Il Governo non ha consultato l’Autorità Garante per la protezione dei dati sui due decreti leggi con cui ha introdotto il green pass e l’obbligo vaccinale per i sanitari. Ma l’esecutivo è obbligato dal GDPR a coinvolgere il Garante Privacy. Su questa violazione di legge del Governo e sui rischi privacy non considerati dal Consiglio dei ministri sul certificato verde e vaccini obbligatori per medici e operatori sanitari in prima linea nella battaglia contro il Covid, abbiamo intervistato Ginevra Cerrina Feroni, vicepresidente Autorità Garante per la protezione dei dati personali.

Key4biz. Professoressa Cerrina Feroni, vi siete lamentati del mancato coinvolgimento da parte del Governo su norme di grande importanza come quelle sui certificati verdi e gli obblighi vaccinali. Che succede?

<!-- LARGE RECTANGLE POST - CORPO TESTO

-->

Ginevra Cerrina Feroni. Nessuna ragione di necessità e di urgenza può mai giungere ad estromettere gli interessi fondamentali al cui presidio è posta l’azione del Garante per la protezione dei dati personali. Interessi che assumono rango quanto meno equiordinato rispetto a quelli, pur legittimamente, posti a fondamento delle misure del Governo. Ilmancato coinvolgimento del Garante non è tanto, o solo, un problema di natura formale e di fluidità dei rapporti tra istituzioni, di cui peraltro agli italiani può interessare ben poco, ma sostanziale. 

Riguarda, per l’appunto, i loro diritti e libertà costituzionali fondamentali. E questo, invece, interessa molto. Entrambi idecreti legge adottati dal Governo – certificati verdi per spostarsi tra Regioni e obbligo vaccinale per sanitari – presentano gravi violazioni sotto il profilo della protezione dati.

Key4bizPer quali motivi?

Ginevra Cerrina Feroni. In relazione ai certificati verdi per spostarsi tra Regioni abbiamo adottato un formale provvedimento di “avvertimento” al Governo, evidenziando che il “decreto riaperture” è privo di una valutazione dei possibili rischi su larga scala. Non sono definite le finalità per il trattamento dei dati, non è indicato il titolare del trattamento, non è rispettato il principio di minimizzazione, non sono contemplati i tempi di conservazione, non sono previste misure per garantire la loro integrità e riservatezza. 

Key4bizE sull’obbligo vaccinale per i sanitari?

Ginevra Cerrina Feroni. Quanto all’obbligo vaccinale la situazione è pure più grave. Non è stabilito, ad esempio, quali siano le categorie obbligate, i tempi di conservazione dei dati, le modalità con cui gli ordini professionali e i datori di lavoro debbano comunicare alle ASL gli elenchi degli interessati, le misure a garanzia degli interessati. Non sono definite neppure le misure a tutela della privacy di coloro che non possono vaccinarsi e i cui dati, per ovvie ragioni, sono ancora più sensibili. All’Autorità in tre settimane sono arrivati più di 1.500 reclami o segnalazioni. 

Key4biz. Il Governo è obbligato a chiedere il parere del Garante Privacy, perché non lo fa? 

Ginevra Cerrina Feroni. Corretto parlare di obbligatorietà. Eppure, evidentemente, manca ancora questa consapevolezza. Il coinvolgimento dell’Autorità su tutti i provvedimenti normativi che coinvolgono dati personali in via preventiva, cioè nel momento di costruzione della norma, non è un mero “accessorio”, ma un obbligo di legge. Lo stabilisce il Regolamento europeo entrato in vigore nel maggio 2018 che contiene norme direttamente applicabili nel nostro Paese e che prevalgono sempre e comunque sulle leggi dello Stato nazionale. In ben due disposizioni, l’art. 36 e l’art. 57, si prevede l’intervento della Autorità “durante l’elaborazione” di un atto legislativo o regolamentare che incida sul trattamento dei dati personali. Il mancato coinvolgimento del Garante nella fase prodromica alla adozione di misure normative di così grande impatto sui dati personali pone problemi seri. Per prima cosa priva il Governo dell’apporto tecnico della Autorità indipendente che, ex lege, è chiamata a garantire la legittimità del trattamento dei dati personali. In secondo luogo si pone in aperto contrasto con norme specifiche e puntuali del diritto dell’Unione, potendosi arrivare alla disapplicazione in via giudiziaria della norma nazionale contrastante. In terzo luogo contrasta con i principi di cd. “better regulation”, che esigono il confronto e la interlocuzione preventiva. Infine, elimina per i cittadini un presidio forte di garanzia su un diritto costituzionale fondamentale. Se la legge nasce gravemente viziata in punto di tutela della protezione dati non si rimedia con l’intervento del Garante in un momento successivo, ad esempio in fase di attuazione in via amministrativa.

Key4biz. C’è una mancanza di cultura della protezione dati a tutti i livelli, dunque…Stiamo scontando un ritardo rispetto ad altri Paesi europei?

Ginevra Cerrina Feroni. Vorrei dire prima entrerà nel “dna collettivo” che la protezione dati è parte essenziale del rilancio del Paese, a partire dalla definizione del PNRR, meglio sarà per tutti. E tutti ne guadagneremo. Semplificazione amministrativa, digitalizzazione, giustizia, fascicolo sanitario, ma anche previdenza, fisco, didattica a distanza, telelavoro ecc… Tutto passa dalla regolazione dei dati, non solo di quelli personali. I dati sono il fulcro del nuovo mondo e della nuova civiltà. Ad esempio – e lo abbiamo segnalato al Governo – il successo o l’insuccesso delle politiche pubbliche e private basate sull’intelligenza artificiale dipenderà in larghissima misura dalle regole che governeranno la progettazione, lo sviluppo e l’uso degli algoritmi e dall’attività di regolamentazione, vigilanza e promozione della circolazione dei dati pubblici e privati, personali e non personali. 

Key4biz. Occorre governare il futuro, ma anche proteggere i nostri dati

Ginevra Cerrina Feroni. Certo. Scegliere se e quanto investire nella regolamentazione, vigilanza e promozione di queste materie significa, in buona misura, decidere quale “comunità di destino” – per usare una nota citazione – vogliamo essere nei prossimi vent’anni.  Prospettiva usurata, ma soprattutto, contraddetta dai fatti, continuare a ghettizzare la privacy nell’abito stretto del “diritto ad essere lasciati soli”. Poco lungimirante pensare poi alla privacycome ad un intralcio, addirittura un ostacolo, all’efficiente azione di Governo. Nelle imprese più strutturate, ad esempio, sta già nascendo la consapevolezza che la tutela dei dati è anzitutto valore. E il valore lo misuri in termini di tutela dei clienti e di competitività nei mercati. 

Key4biz. L’Autorità ha risorse adeguate per svolgere i suoi compiti?

Ginevra Cerrina Feroni. L’Autorità Garante, anche a seguito dell’entrata in vigore del Regolamento europeo, ha assunto un ruolo strategico nel Paese cui però non è seguito un adeguamento conseguente sotto il profilo delle risorse umane, finanziarie e strumentali. L’indipendenza di una istituzione la si garantisce anche dotandola delle risorse necessarie per svolgere i suoi compiti. E le nostre sono assolutamente inadeguate. Pensi che il Garante italiano può contare, ai sensi della normativa vigente, su una dotazione organica di 162 persone di cui allo stato 134 in servizio. A parità di compiti in Francia ne hanno 215, nel Regno Unito 680, in Germania addirittura 887. Solo nel 2020 noi abbiamo ricevuto oltre 12.000 richieste di intervento, che significa avere aperto 12.000 nuovi fascicoli. Anche il Parlamento europeo nella recentissima Risoluzione del 25 marzo 2021 ha espresso preoccupazione e richiamato l’urgenza di dotare le autorità privacy delle risorse necessarie per adempiere efficacemente i loro compiti ed esercitare i loro poteri enormemente aumentati. Si sta lavorando da mesi con una pressione fortissima per non rallentare provvedimenti utili al Paese. La nostra disponibilità non è mai mancata. Ma per collaborare bisogna essere in due. Ci auguriamo che questo messaggio venga recepito dal Governo. 

Key4biz. A proposito di Europa. Sul green pass annunciato da Bruxelles qual è la posizione del Garante? 

Ginevra Cerrina Feroni. Le due proposte di Regolamento UE, recentemente varate, mirano ad istituire un quadro comune per il rilascio di certificati comuni relativi alla vaccinazione, ai test e alla guarigione dal COVID-19, in tal modo facilitando l’esercizio del diritto di libera circolazione all’interno dell’UE. L’obiettivo è permettere al viaggiatore di fornire una prova documentale, universalmente riconosciuta (nel territorio dell’Unione), volta a consentire il superamento delle misure restrittive foggiate dagli Stati membri in funzione del contenimento della pandemia da Covid-19. Anche il diritto dell’Unione, quindi – ma sul punto si è espressa altresì l’Assemblea del Consiglio d’Europa – non contempla in alcun modo l’obbligo della vaccinazione. La somministrazione del siero anti-Covid non costituisce, pertanto, la condicio indefettibile per l’esercizio di libertà fondamentali, quale quella di circolazione; alle persone non vaccinate, per le più disparate ragioni, potranno solo richiedersi oneri particolari, quali la effettuazione di tamponi ovvero, eventualmente, periodi di quarantena. Il carattere assai sensibile dei dati trattati, e la dimensione “europea” del trattamento,  dovrebbero indurre alla adozione di un sistema che contempli il più ampio numero di garanzie. In ossequio al principio di “minimizzazione” e di “proporzionalità”, dovrebbero essere circoscritti in modo puntale l’ambito e gli scopi dei trattamenti, ridotte allo stretto indispensabile le categorie di dati ed informazioni richieste, precludendo altresì l’accesso ai dati contenuti nei certificati una volta cessata la emergenza pandemica. Lo stesso certificato dovrebbe essere “neutro”, e cioè non indicare la specifica ragione giustificativa del rilascio.

Key4biz. Come è possibile far crescere la consapevolezza delle persone riguardo al valore dei propri dati?

Ginevra Cerrina Feroni. Si sta scrivendo, causa pandemia, forse la più importante pagina della storia italiana di trattamento di dati sensibili. Eppure siamo qui a fare questa intervista per spiegare perché è un ossimoro che il Garante privacy non sia stato coinvolto. È evidente che dobbiamo fare ancora molta strada in questo Paese sulla cultura della protezione e del valore dei nostri dati. Da parte nostra, saremo presenti mediaticamente e nel pubblico quanto più possibile. Ci appoggeremo ad iniziative prestigiose del terzo settore, anche internazionali, per svolgere la nostra missione a contatto con gli operatori, i gruppi d’interesse ed i cittadini del mondo digitale. Il Collegio si è insediato da pochi mesi. Il nostro progetto è di lungo corso e la sfida è appena iniziata.  

https://www.key4biz.it/green-pass-e-obbligo-vaccinale-cerrina-feroni-da-modificare-il-governo-consulti-il-garante-della-privacy/357831/




Apple’s iPhone Privacy Clampdown Arrives After 7-Month Delay

Apple is following through on its pledge to crack down on Facebook and other snoopy apps that secretly shadow people on their iPhones in order to target more advertising at users.

The new privacy feature, dubbed “App Tracking Transparency,” rolled out Monday as part of an update to the operating system powering the iPhone and iPad. The anti-tracking shield included in iOS 14.5 arrives after a seven-month delay during which Apple and Facebook attacked each other’s business models and motives for decisions that affect billions of people around the world.

“What this feud demonstrates more than anything is that Facebook and Apple have tremendous gatekeeping powers over the market,” said Elizabeth Renieris, founding director of the Technology Ethics Lab at the University of Notre Dame.

But Apple says it is just looking out for the best interests of the more than 1 billion people currently using iPhones.

“Now is a good time to bring this out, both because of because of the increasing amount of data they have on their devices, and their sensitivity (about the privacy risks) is increasing, too,” Erik Neuenschwander, Apple’s chief privacy engineer, told The Associated Press in an interview.

Once the software update is installed — something most iPhone users do — even existing apps already on the device will be required to ask and receive consent to track online activities. That’s a shift Facebook fiercely resisted, most prominently in a series of full-page newspaper ads blasting Apple.

Until now, Facebook and other apps have been able to automatically conduct their surveillance on iPhones unless users took the time and trouble to go into their settings to prevent it — a process that few people bother to navigate.

“This is an important step toward consumers getting the transparency and the controls they have clearly been looking for,” said Daniel Barber, CEO of DataGrail, a firm that helps companies manage personal privacy.

In its attacks on Apple’s anti-tracking controls, Facebook blasted the move as an abuse of power designed to force more apps to charge for their services instead of relying on ads. Apple takes a 15% to 30% cut on most payments processed through an iPhone app.

Online tracking has long helped Facebook and thousands of other apps accumulate information about their user’s interests and habits so they can show customized ads. Although Facebook executives initially acknowledged Apple’s changes would probably reduce its revenue by billions of dollars annually, the social networking company has framed most of its public criticism as a defense of small businesses that rely on online ads to stay alive.

Apple, in turn, has pilloried Facebook and other apps for prying so deeply into people’s lives that it has created a societal crisis.

In a speech given a few weeks after the Jan. 6 attacks on the U.S. Capitol, Apple CEO Tim Cook pointed out how personal information collected through tracking by Facebook and other social media can sometimes push people toward more misinformation and hate speech as part of the efforts to show more ads.

“What are the consequences of not just tolerating but rewarding content that undermines public trust in life-saving vaccinations?” Cook asked. “What are the consequences of seeing thousands of users join extremist groups and then perpetuating an algorithm that recommends more?”

It’s part of Apple’s attempt to use the privacy issue to its competitive advantage, Barber said, a tactic he now expects more major brands to embrace if the new anti-tracking controls prove popular among most consumers.

In a change of tone, Facebook CEO Mark Zuckerberg recently suggested that Apple’s new privacy controls could actually help his company in the long run. His rationale: The inability to automatically track iPhone users may prod more companies to sell their products directly on Facebook and affiliated services such as Instagram if they can’t collect enough personal information to effectively target ads within their own apps.

“It’s possible that we may even be in a stronger position if Apple’s changes encourage more businesses to conduct more commerce on our platforms by making it harder for them to use their data in order to find the customers that would want to use their products outside of our platforms,” Zuckerberg said last month during a discussion held on the audio chat app Clubhouse.

In the same interview, Zuckerberg also asserted most people realize that advertising is a “time-tested model” that enables them to get more services for free or at extremely low prices.

“People get for the most part that if they are going to see ads, they want them to be relevant ads,” Zuckerberg said. He didn’t say whether he believes most iPhone users will consent to tracking in exchange for ads tailored to their interests.

Google also depends on personal information to fuel a digital ad network even bigger than Facebook’s, but it has said it would be able to adjust to the iPhone’s new privacy controls. Unlike Facebook, Google has close business ties with Apple. Google pays Apple an estimated $9 billion to $12 billion annually to be the preferred search engine on iPhone and iPad. That arrangement is currently one element of an antitrust case filed last year by the U.S. Justice Department.

Facebook is also defending itself against a federal antitrust lawsuit seeking to break the company apart. Meanwhile, Apple is being scrutinized by lawmakers and regulators around the world for the commissions it collects on purchases made through iPhone apps and its ability to shake up markets through new rules that are turning it into a de facto regulator.

“Even if Apple’s business model and side in this battle is more rights protective and better for consumer privacy, there is still a question of whether we want a large corporation like Apple effectively ‘legislating’ through the app store,” Renieris said.

RelatedApple iOS 14.5 Patches 50 Security Vulnerabilities

Related: Apple Ships Emergency Fixes for Under-Attack iOS Zero-Day

view counter

Previous Columns by Associated Press:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/X886Qqs_2bc/apple%E2%80%99s-iphone-privacy-clampdown-arrives-after-7-month-delay




Apple releases iOS 14.5, the biggest update since iOS 14 first launched

Apple's 2020 iPad Air.
Enlarge / Apple’s 2020 iPad Air.
Samuel Axon

Today is the day: Apple has finally released iOS 14.5 and iPadOS 14.5 worldwide after a longer-than-usual beta period. If you’re using a supported device, you should be able to find the update on the software update page in the iPhone, iPad, or iPod touch’s Settings app.

This is arguably the biggest update of the iOS 14 cycle that began with iOS 14.0 and iPadOS 14.0 on September 16 of last year. The most consequential change for many is App Tracking Transparency, a new policy whereby app developers are required to get user opt-in to track users between apps.

But iOS 14 and iPadOS 14.5 also introduce a long-needed workaround for using Face ID when wearing a mask, support for the new AirTag accessory, several changes aimed at making experiences within the software more inclusive for a diverse user base, new Siri features and voices, and changes to the Reminders, News, Music, and Podcasts apps, among other things.

Here’s what you can expect to see when you install the new software.

App Tracking Transparency

Apple’s long-debated, long-awaited App Tracking Transparency feature and policy will now be fully enforced starting with today’s release of iOS 14.5 and iPadOS 14.5 (as well as tvOS 14.5, which we wrote about earlier today).

A large portion of the apps in the App Store for these devices utilizes a tracking technique called ID for Advertisers (IDFA) to track users’ activity between multiple apps published by multiple companies, to inform ad targeting and other monetization and data collection techniques.

Last year, Apple announced that it would begin requiring all apps to ask for users’ permission in advance to do this on an app-by-app basis. Anticipating that many users would opt out and that the change would therefore significantly impact revenue, various app developers and ad networks have criticized the move, saying it will hurt big and small businesses alike.

Those critics are not making that up: the move is likely to have a significant impact on the bottomline for many types of apps that rely on advertising for revenue. But Apple maintains that users’ control over how they are tracked and how their data is used and accessed is the most important concern at hand.

Apple initially delayed the move (which was originally planned for the first iOS 14 release) so developers and advertisers could have more time to prepare. Today’s launch of iOS and iPadOS 14.5 is the point of no return; the requirement will now be enforced. (Some apps already implemented it before today’s release.)

A COVID-mask Face ID workaround: Use your Apple Watch

Face ID seemed like an overall win over Touch ID after it was first introduced in 2017, but as we all know, the COVID-19 pandemic in 2020 put Face ID phones in a tough spot.

With people all around the world wearing masks to protect themselves and others from the virus, Face ID phones are unable to use their main method of authentication for getting past the lock screen or using features like Apple Pay.

Now, users who update their iPhones to iOS 14.5 and their Apple Watches to the also-just-released watchOS 7.4 can unlock their said phones with said watches.

When you’re wearing an Apple Watch and that watch is unlocked and close to your iPhone, you should now be able to just glance at the iPhone screen and see it unlocked via the watch’s own authentication. The watch will give you haptic feedback to let you know the iPhone has been unlocked.

This works on all Face ID iPhones paired with an Apple Watch Series 3 or later, provided both devices are running the latest software.

Diversity and inclusion

Apple has made a few small but meaningful changes to better represent iPhone users in a couple of parts of the iPhone and iPad experience.

First off, Siri has two new voices in the United States modeled after Black American English. You’ll find these in the Siri page for voices within the Settings app. Select “American” under variety and, in addition to the two existing American accents, you’ll find two more voices: a Black female voice, and a Black male voice.

Further, Siri no longer has a single voice that’s treated as the default. Users select from multiple options when first setting up their phones now.

Apple has also introduced new emojis meant to allow users to express themselves better. In addition to various new heart and face emojis, Apple has added a woman with a beard emoji in various skin colors, as well as the ability to independently select the skin color for each of the two people in the emojis of couples hugging and the like.

New Siri and Maps capabilities

Siri can now be used to initiate FaceTime calls with groups of people; you just need to ask it to call any already existing Messages group.

Also, iOS and iPadOS 14.5 give Siri the ability to announce incoming calls through connected AirPods or Beats headphones. They also support “calling emergency contacts if the iPhone owner needs assistance and is unable to make a call,” Apple says.

When driving, users can tell Siri about hazards on the road so other drivers can be warned, for example by saying, “Hey Siri, there’s a crash up ahead.” Users can also tell Siri when a previously reported incident has been resolved.

And while we’re on the subject of cars and maps, we’ll use this opportunity to mention that Maps users can now share their ETA with contacts when traveling with walking or cycling directions. That’s a feature that people have been requesting for a while now. Additionally, CarPlay users can use Share ETA with Siri.

Apple app updates

Apple has introduced a few new features and design changes to some of the iOS apps it has made itself. For example, Podcasts now has a redesigned show page, plus top charts section and new categories and curated collections in the search tab. Users can also save and download episodes individually and see them added to the library automatically.

Apple News likewise has a redesigned Apple News+ tab with a prominent place to manage and download magazine and newspaper issues. It also has some improvements to search, with a category-based results page.

Apple Fitness+ within the Fitness app can stream audio and video to any AirPlay 2-enabled TV or device, potentially expanding the places the service can be conveniently used in the home or other setting.

Apple Music now offers users the option to share individual lyrics segments via Messages, Facebook, or Instagram Stories. It also has city-specific playlists for several large urban centers like Los Angeles, Chicago, Dublin, Berlin, Jakarta, Istanbul, Tokyo, Seoul, and Dubai, among many others.

Reminders has new sort options within reminder lists; users can now sort by title, priority, due date, or creation date. They can also print reminder lists with an easily accessible widget within the app.

Grab bag

There are a few other features that don’t neatly fit into the buckets above. They include:

  • Support for AirTags, Apple’s new geolocation devices.
  • Dual SIM support that “enables 5G connectivity on the line that’s using cellular data on iPhone 12 models”
  • The ability to tweak playback speed in the Translation app by long-pressing the play button
  • Support for the PlayStation 5’s DualSense controller and Xbox Series X|S controllers via Bluetooth
  • Several bug fixes, which are listed in the full update notes below

https://arstechnica.com/?p=1760177




EU lawmakers propose strict curbs on use of facial recognition

EU lawmakers propose strict curbs on use of facial recognition

EU regulators have proposed strict curbs on the use of facial recognition in public spaces, limiting the controversial technology to a small number of public-interest scenarios, according to new draft legislation seen by the Financial Times.

In a confidential 138-page document, officials said facial recognition systems infringed on individuals’ civil rights and therefore should only be used in scenarios in which they were deemed essential, for instance in the search for missing children and the policing of terrorist events.

The draft legislation added that “real-time” facial recognition—which uses live tracking rather than past footage or photographs—in public spaces by the authorities should only ever be used for limited periods of time, and it should be subject to prior consent by a judge or a national authority.

The document comes as privacy advocates, politicians, and European citizens have become increasingly vocal about regulating the use of live facial recognition. At present, there are no clear rules around how and where the technology can be used on the general public, so the proposed legislation would be the first to codify these limitations into law.

The introduction of tougher curbs on the use of facial recognition technology would likely reignite debate over whether the practice should be banned altogether, as experts warn that it is still fraught with risks.

In a landmark ruling last August, the UK Court of Appeal said that the use of facial recognition technology by South Wales Police was unlawful and found that it breached privacy rights, data protection laws, and equality laws.

The EU’s draft legislation also addressed a range of related issues such as algorithmic bias, arguing that technology used in contexts such as recruitment and finance should be developed so as not to replicate “historical patterns of discrimination” against minority groups.

EU regulators proposed hefty fines of up to 6 percent of a company’s global turnover if it is found to have abused artificial intelligence in this way or fails to detect biases when hiring workers or providing services.

They added that so-called social-scoring practices, which assess a person’s trustworthiness from behavioral data gathered about them, should also be banned. In China, for instance, a system is being developed that calculates a person’s credit score using information about their online habits.

“The social score obtained… may lead to the detrimental or unfavorable treatment of [people or groups]… which are unrelated to the context in which the data was originally generated,” the leak said.

The proposals, which will be presented on Wednesday in Brussels, will now be debated by the European Parliament and member states until at least 2023 before becoming law.

© 2021 The Financial Times Ltd. All rights reserved Not to be redistributed, copied, or modified in any way.

https://arstechnica.com/?p=1758740




Commissione Ue pronta a vietare l’utilizzo dell’IA per la sorveglianza indiscriminata dei cittadini

L’intelligenza artificiale (IA) è considerata a ragione una tecnologia strategica per la crescita economica, l’innovazione industriale e il raggiungimento dei più alti livelli di competitività delle imprese sui mercati globali. Prova ne è la crescente spesa, a livello europeo e globale, in questo tipo di soluzioni.

L’Europa vuole un posto di leadership nel settore, ma deve prima trovare un approccio comune di tutti i suoi Stati all’implementazione dell’IA ad ogni livello, con norme e limiti di ordine etico, regolatorio e finanziario, ma anche culturale e relativi a privacy e sicurezza.

<!-- LARGE RECTANGLE POST - CORPO TESTO

-->

Approccio etico dell’Europa all’IA

A riguardo, la Commissione europea proporrà entro l’anno in corso un pacchetto di regole per l’intelligenza artificiale, mirato a salvaguardare i valori etici e i diritti fondamentali dell’essere umano, quindi teso a stabilire i requisiti di sicurezza ed affidabilità di questa tecnologia.

Nella bozza di documento “European approach for artificial intelligence”, visionato in anteprima da euractive.com, si manifesta la volontà della Commissione di vietare l’utilizzo di sistemi IA per le operazioni di sorveglianza indiscriminata dei cittadini.

Entro la prossima settimana, si legge sul sito, saranno proposti nuovi criteri e parametri per l’utilizzo dell’IA in questo tipo di operazioni. Tra i diversi metodi di sorveglianza sono citati quelli che includono il monitoraggio e il tracciamento delle persone fisiche, sia in ambiti tradizionali, sia digitali, ma anche l’aggregazione e l’analisi automatizzate di dati personali provenienti da varie fonti.

Divieti e sanzioni, le deroghe per la sicurezza nazionale

Ulteriori divieti saranno proposti per ogni uso dell’intelligenza artificiale che violi i valori di base dell’Unione e i diritti umani più in generale.

Si pensa di estendere il divieto di utilizzo dell’IA anche a quel tipo di sorveglianza tesa a manipolare, controllare o limitare il comportamento e la libertà di spostamento degli esseri umani, soprattutto a vantaggio di terzi.

In termini di sanzioni, potrebbero essere previste multe fino al 4% del fatturato annuo globale di un’azienda che non rispetti tali divieti.

Nel documento è però precisato che in caso di motivi di sicurezza nazionale tali divieti non varranno per i Governi e le Autorità pubbliche che impiegheranno l’IA anche nei modi sopra descritti.

Questo significa che gli Stati europei potrebbero in futuro impiegare l’intelligenza artificiale anche per la sorveglianza di massa o il tracciamento dei nostri dati, se per comprovati motivi di sicurezza interna.

Applicazioni IA ad alto rischio

Altre applicazioni IA ad alto rischio sono l’identificazione biometrica remota di ignari cittadini in spazi accessibili al pubblico, tra cui il riconoscimento facciale, l’integrazione nelle infrastrutture pubbliche strategiche, come quelle relative ai trasporti, alla fornitura di acqua ed energia, la Difesa.

Per tutti questi motivi, la Commissione propone l’istituzione di un Board europeo per l’intelligenza artificiale, composto da 27 rappresentanti degli Stati membri, dal Garante europeo per la protezione dei dati e da un rappresentate della Commissione europea.

La proposta, infine, dovrebbe essere presentata ufficialmente dal Vice Presidente esecutivo per il digitale della Commissione europea, Margrethe Vestager, il prossimo 21 aprile. Seguirà il parere del Consiglio e il voto del Parlamento europeo.

https://www.key4biz.it/commissione-ue-pronta-a-vietare-lutilizzo-dellia-per-la-sorveglianza-indiscriminata-dei-cittadini/355745/




Euro digitale: ok di cittadini e imprese alla Bce, ma prioritario tutelare la privacy

Pubblicati oggi i risultati della consultazione pubblica della Banca centrale europea (Bce) sull’euro digitale. Dal documento potrebbero emergere secondo gli esperti indicazioni rilevanti per le attività di analisi e sperimentazione della Bce.

La consultazione

Suggerimenti utili anche per la prossima decisione del Consiglio direttivo sull’opportunità di avviare una fase di indagine formale per l’eventuale emissione di una valuta digitale per la metà dell’anno in corso.

<!-- LARGE RECTANGLE POST - CORPO TESTO

-->

Al centro delle preoccupazioni degli europei riguardo l’euro digitale sembrerebbero trovarsi la tutela dei dati personali e la sicurezza delle transazioni.

Un euro digitale può avere successo soltanto se risponde alle esigenze dei cittadini europei”, ha dichiarato in una nota Fabio Panetta, membro del Comitato esecutivo della BCE: “Faremo del nostro meglio per assicurare che un euro digitale sia in linea con le aspettative dei cittadini che sono emerse dalla consultazione pubblica”.

Principali indicazioni sull’euro digitale

Si confermano così le prime osservazioni già raccolte dalla Bce: innanzitutto una più decisa tutela della privacy per il 43% dei partecipanti, seguita dalla sicurezza (18%), dalla possibilità di utilizzarla in tutta l’area dell’euro (11%), senza costi aggiuntivi (9%) e offline (8%).

Il mondo delle imprese e più nello specifico i commercianti chiedono ulteriori requisiti volti a prevenire attività illecite, mentre meno di un cittadino su dieci è favorevole al completo anonimato.

L’euro digitale è inoltre visto come valido strumento per rendere i pagamenti transfrontalieri più rapidi e meno costosi.

Quasi la metà dei partecipanti ha menzionato la necessità di stabilire limiti all’ammontare detenuto, ma si delinea una certa preferenza per l’integrazione di un euro digitale negli attuali sistemi bancari e di pagamento.

Da un punto di vista tecnologico, infine, sono considerate preferibili le soluzioni con carta (o smartcard) o con un sistema sicuro nello smartphone per gli utenti finali.

La consultazione pubblica ha ricevuto più di 8.200 risposte, provenienti perlopiù dalla Germania (47%), dall’Italia (15%) e dalla Francia (11%).

https://www.key4biz.it/euro-digitale-ok-di-cittadini-e-imprese-ma-prioritario-tutelare-la-privacy/355613/




No password required: Mobile carrier exposes data for millions of accounts

No password required: Mobile carrier exposes data for millions of accounts
Getty Images

Q Link Wireless, a provider of low-cost mobile phone and data services to 2 million US-based customers, has been making sensitive account data available to anyone who knows a valid phone number on the carrier’s network, an analysis of the company’s account management app shows.

Dania, Florida-based Q Link Wireless is what’s known as a Mobile Virtual Network Operator, meaning it doesn’t operate its own wireless network but rather buys services in bulk from other carriers and resells them. It provides government-subsidized phones and service to low-income consumers through the FCC’s Lifeline Program. It also offers a range of low-cost service plans through its Hello Mobile brand. In 2019, Q Link Wireless said it had 2 million customers.

The carrier offers an app called My Mobile Account (for both iOS and Android) that customers can use to monitor text and minutes histories, data and minute usage, or to buy additional minutes or data. The app also displays the customer’s:

  • First and last name
  • Home address
  • Phone call history (from/to)
  • Text message history (from/to)
  • Phone carrier account number needed for porting
  • Email address
  • Last four digits of the associated payment card

Screenshots from the iOS version look like this:

No password required . . . what?

Since at least December and possibly much earlier, My Mobile Account has been displaying this information for every customer account whenever it is presented with a valid Q Link Wireless phone number. That’s right—no password or anything else required.

When I first saw a Reddit thread discussing the app, I thought for sure there was some kind of mistake. So I installed the app, got the permission from another thread reader, and entered his phone number. I was immediately viewing his personal information, as the redacted images above demonstrate.

The person who started the Reddit thread said in an email that he first reported this glaring insecurity to Q Link Wireless sometime last year. Emails he provided show that he notified support twice again this year, first in February and again this month.

Feedback left in reviews for both the iOS and Android offerings also reported this issue, in several cases with a response from a Q Link Wireless representative thanking the person for the feedback.

Downright negligence

The data exposure is serious because phone numbers are so easy to come by. We give them to prospective employers, car mechanics, and other strangers. And of course, phone numbers are easily obtained by private detectives, abusive spouses, stalkers, and other people who have an interest in a particular person. Q Link Wireless making customer data freely available to anyone who knows a customer’s phone number is an act of downright negligence.

I began emailing the carrier about the insecurity on Wednesday and followed up with almost a dozen more messages. Q Link Wireless CEO and founder Issa Asad didn’t respond despite my noting that every hour he allowed the data exposure to continue compounded the risk to his customers.

Then late on Thursday, My Mobile Account stopped connecting to customers’ accounts. When presented with the number of a Q Link Wireless customer, the app responds with a message saying, “Phone number doesn’t match any account.” The iOS and Android versions of the app were last updated in February, suggesting that the fix is the result of a change Q Link Wireless made to a server.

While My Mobile Account displayed customers’ personal information, it didn’t provide a means to change that data. The app also didn’t display passwords. That means a person couldn’t exploit this leak to perform a SIM swap or lock users out of their accounts, although the exposure might make it easier for a would-be SIM swapper to social engineer a Q Link Wireless employee into porting a number to a new phone.

There are no indications one way or the other that this leakage was actively exploited. Researchers from security firm Intel471 found no discussions in criminal forums about the available data, but there’s no way to know if it was abused on a smaller scale, say by someone a Q Link Wireless customer knows or has interacted with.

As phone users seeking low-cost, no-frills mobile service, Q Link Customers are a part of a population that may be least able to afford data breach services and other privacy services. The carrier has yet to notify customers of the data exposure. People using the service should consider any data displayed by the app to be available to anyone who has their phone number.

https://arstechnica.com/?p=1755853




Cost of Sandboxing Prompts Shift to Memory-Safe Languages. A Little Too Late?

NEWS ANALYSIS: Google’s decision to promote Rust for low-level Android programming is another sign that the shelf-life for memory corruption mitigations are no match for the speed of in-the-wild exploit development.

Just 13 years after Google introduced the sandbox in Chrome touting “a new approach in browser security,” the company is now blaming the limitations — and high processing cost — of sandboxing for a new decision to promote Rust as the low-level programming language of choice for the Android operating system.

The decision to promote Rust over C and C++ isn’t exactly a surprise but the language used in Google’s announcement signals a sad end to the sandbox as an effective anti-exploit mitigation for a vexing problem haunting software engineering since the mid-1990s.

“Sandboxing is expensive,” says Jeff Vander Stoep, a member of Google’s Android team. “Sandboxing doesn’t eliminate vulnerabilities from the code and its efficacy is reduced by high bug density, allowing attackers to chain multiple vulnerabilities together,” he added.

He said Google is turning to memory-safe languages like Rust to help overcome these “limitations” by lowering the density of bugs in the Android code and increasing the effectiveness of the existing sandbox.

More importantly, Vander Stoep says the move reduces Google’s sandboxing needs entirely and enables the creation and introduction of new software features that are both safer and lighter on resources.

HIGH SEVERITY 

He said memory safety problems in C and C++ continue to be the “most-difficult-to-address” issue in modern software engineering and noted that the Android team — like the rest of the tech industry — spent heavily to mitigate a class of vulnerabilities without much success.

“In spite of these efforts [to detect, fix and mitigate these issues], memory safety bugs continue to be a top contributor of stability issues, and consistently represent more than 70 percent  of Android’s high severity security vulnerabilities,” Vander Stoep added.

The problem isn’t limited to Android.  Published data from Google Project Zero shows that the majority of in-the-wild zero-day attacks over the last few years are dominated by buffer overflows and use-after-free memory corruption issues.

Ever since the mid-1990s, the brightest minds in cybersecurity have attempted to find approaches to solve memory corruption issues.  These long-term, cross-industry efforts produced many exciting mitigations and effectively raised the cost for attackers.

However, these mitigations came with heavy costs and the shelf-life for things like sandboxing has gotten shorter and shorter as attackers quickly found ways to bypass these roadblocks.

CAT AND MOUSE

“It’s a cat-and-mouse we can’t win,” says an ex-Google software engineer who requested anonymity. “We spend a lot on these mitigations. We spend a lot to address CPU performance hits, we spend a ton more on software development costs and, poof, someone comes up with a bypass and it feels like we’re back to square one.”

“Should we really have spent so much on sandboxing?  Should we really have spent so much all the control-flow integrity mitigations that didn’t really move the bar?  I’m not sure this was money and resources well spent,” he said in exasperation.

Despite these frustrations, the sandbox has been an effective mitigation that made it very difficult to exploit software programs.  Prior to the popularity of sandboxing, attackers could simply exploit a single buffer overflow vulnerability to achieve remote code execution, the holy grail of attacks.

Once sandboxes became a key feature in browsers and desktop apps, the cost of a remote code execution exploit was raised. Where a single bug won the Pwn2Own contest 10 years ago, attackers today must chain exploits for multiple vulnerabilities and include an expensive “sandbox escape” to achieve full code execution.

Now, there’s a shift to using memory-safe languages to effectively eliminate memory corruption as a bug class. For example, on the Android OS, managed languages like Java and Kotlin have become the go-to choice for app development because of ease of use, portability, and safety.  In addition, the Android Runtime (ART) manages memory on behalf of the developer.

The Android OS uses Java extensively, effectively protecting large portions of the Android platform from memory corruption bugs. However, Java and Kotlin are not options for lower layers of the operating system, as Google explains here:

Lower levels of the OS require systems programming languages like C, C++, and Rust. These languages are designed with control and predictability as goals. They provide access to low level system resources and hardware. They are light on resources and have more predictable performance characteristics.

For C and C++, the developer is responsible for managing memory lifetime. Unfortunately, it’s easy to make mistakes when doing this, especially in complex and multithreaded codebases.

Rust provides memory safety guarantees by using a combination of compile-time checks to enforce object lifetime/ownership and runtime checks to ensure that memory accesses are valid. This safety is achieved while providing equivalent performance to C and C++.

Google describes the addition of a new language to the Android platform is a large undertaking and warned that there are toolchains and dependencies that need to be maintained, test infrastructure and tooling that must be updated, and developers that need to be trained. “Scaling this to more of the OS is a multi-year project,” the company said.

NO SILVER BULLET

Still, security experts warn that moving to Rust isn’t going to solve all memory lifetime issues.

“Certain patterns just turn them into application logic bugs vs. RCE. An improvement, but no silver bullet,” says Halvar Flake, a security industry pioneer who has worked on memory corruption mitigations.

On a recent podcast interview, head of privacy and security at Lyft Nico Waisman also discussed the shift to memory-safe languages and predicted a future of app logic bugs and a continued dependence on C and C++ code in legacy software products.

Memory safety issues will continue to haunt the security landscape for decades to come but there is optimism that a combination of new technology — especially around memory tagging — and the adoption of safer programming languages will point to a brighter future.

But, as history has shown, mitigations have a shelf-life and novel techniques and bypasses are always just a Black Hat presentation away.  The sandbox was effective and it made life more difficult for attackers but, as Google’s decision shows, there’s a hefty price tag and no signs that sandbox-bypass exploits are going away.

The sandbox had a good run but it’s time to acknowledge this mitigation has seen its time in the sun.

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/w3Q6T2GCDbU/cost-sandboxing-prompts-shift-memory-safe-languages-little-too-late