Hackers can read private AI assistant chats even though they’re encrypted

AI assistants have been widely available for a little more than a year, and they already have access to our most private thoughts and business secrets. People ask them about becoming pregnant or terminating or preventing pregnancy, consult them when considering a divorce, seek information about drug addiction, or ask for edits in emails containing proprietary trade secrets. The providers of these AI-powered chat services are keenly aware of the sensitivity of these discussions and take active steps—mainly in the form of encrypting them—to prevent potential snoops from reading other people’s interactions.

But now, researchers have devised an attack that deciphers AI assistant responses with surprising accuracy. The technique exploits a side channel present in all of the major AI assistants, with the exception of Google Gemini. It then refines the fairly raw results through large language models specially trained for the task. The result: Someone with a passive adversary-in-the-middle position—meaning an adversary who can monitor the data packets passing between an AI assistant and the user—can infer the specific topic of 55 percent of all captured responses, usually with high word accuracy. The attack can deduce responses with perfect word accuracy 29 percent of the time.

Keep reading

JPMorgan To Roll Out Controversial Biometric Payments

America’s largest bank and one of the largest in the world, J.P. Morgan, is preparing to launch biometric payments next year and is currently carrying out pilot projects.

J.P. Morgan has chosen PopID – which verifies a person’s identity via facial recognition, among other methods – as the backbone for the project.

The massive financial corporation is clearly unwilling to be left behind the likes of Mastercard or Visa, who are both implementing biometrics-powered payments.

According to the bank, one of the first events where this was trialed was the Formula 1 race in Miami, and that was also the first time this happened at a Formula 1 venue.

The ultimate goal is to expand authentication based on individuals’ fingerprints, palms, and faces to anyone interested, but with a focus on stores, restaurants, and various event venues.

J.P. Morgan says this will be a faster and safer, as well as “personalized” way for customers to pay, while those with things to sell are promised higher turnover and improved customer loyalty, but also a centralized place to access transactions and marketing data, say reports.

And what’s in it for the bank, other than potentially amassing large amounts of biometric data? Merchants will have the opportunity to buy J.P. Morgan Payments tablets, though this will not be obligatory, but support and transaction processing fees will be.

In a statement, the bank revealed that it is betting on biometric payments as the industry is forecast to grow to 3 billion users and $5.8 trillion worth of transactions over the next two years. And the giant expects digital commerce to eventually cover online, mobile, and in-store checkout.

Keep reading

Artificial Intelligence In The Classroom Can Only Offer Artificial Educations

Educators are grappling with how to approach ever-evolving generative artificial intelligence — the kind that can create language, images, and audio. Programs like ChatGPT, Gemini, and Copilot pose far different challenges from the AI of yesteryear that corrected spelling or grammar. Generative AI generates whatever content it’s asked to produce, whether it’s a lab report for a biology course, a cover letter for a particular job, or an op-ed for a newspaper.

This groundbreaking development leaves educators and parents asking: Should teachers teach with or against generative AI, and why? 

Technophiles may portray skeptics as Luddites — folks of the same ilk that resisted the emergence of the pen, the calculator, or the word processor — but this technology possesses the power to produce thought and language on someone’s behalf, so it’s drastically different. In the writing classroom, specifically, it’s especially problematic because the production of thought and language is the goal of the course, not to mention the top goals of any legitimate and comprehensive education. So count me among the educators who want to proceed with caution, and that’s coming from a writing professor who typically embraces educational technology. 

Keep reading

The Chinese company at the center of Biden’s crane concerns denies it’s a threat to U.S. national security

Chinese shipping cranes are fast becoming the latest item to get caught up in Washington and Beijing’s fractious relationship. U.S. officials have been talking about the security threat posed by Chinese-made cranes at U.S. ports for months. Then, last month, the U.S. announced an initiative to bolster cybersecurity at the country’s ports.

Now, the company at the heart of the controversy—China’s Shanghai Zhenhua Heavy Industries, also known as ZPMC—is denying that it poses a security threat. ZPMC said it “strictly adheres to laws and regulations of relevant countries and regions,” in a statement released on Sunday.

ZPMC accounts for over 70% of the global market in shipping cranes. There are over 200 Chinese-made cranes at U.S. ports, accounting for “nearly 80%” of the total, according to the U.S. Coast Guard.

These cranes help move goods through maritime ports. The cranes can often be controlled remotely, which U.S. officials fear could be an avenue for hackers to disrupt the economy. A recent congressional probe claimed to find over a dozen cellular modems on cranes that could be remotely accessed, the Wall Street Journal reports.

ZPMC, in Sunday’s statement, said that recent reports “can easily mislead the public without sufficient factual review.”

Keep reading

Suspicious tech found in Chinese-made cargo cranes, fueling spying worries: Congress probe

An investigation by the US Congress into Chinese-built cargo cranes has found suspicious technology that could potentially be used to disrupt or spy on American commercial activities, according to a report.

The House Homeland Security Committee said that it has discovered cellular modems that were installed in cranes and which can be remotely accessed by hostile powers, according to The Wall Street Journal.

The committee’s discovery has fueled concerns in the Biden administration that cranes built by a Chinese firm, Shanghai Zhenhua Heavy Industries (ZPMC), could potentially be used to spy on US ports.

More than 12 cellular modems were found in Chinese-made cranes that were relied upon in several US ports, according to the Journal.

While some of the modems were used for operational functions such as monitoring and tracking maintenance remotely, others were installed despite the fact that the ports in which they were being used hadn’t requested them.

China “is looking for every opportunity to collect valuable intelligence and position themselves to exploit vulnerabilities by systematically burrowing into America’s critical infrastructure, including in the maritime sector,” Rep. Mark Green (R-Tenn.), who chairs the House Homeland Security Committee, said.

Keep reading

Emotion-Tracking – AI on the job: Workers Fear Being Watched – and Misunderstood.

We have heard the warnings from Yuval Noah Harari, that if we don’t figure out how to regulate artificial intelligence (AI) human brains will be hacked soon,” a statement that arguably speaks to humanity’s worst fears about AI. This may be especially so, when hearing from Schwab’s advisor Harari that to “hack a human being is to get to know that person better than they know themselves,” which can enable those who own the technology to increasingly manipulate us.

We may believe this extreme threat to our privacy will occur some time in the future, but, the hacking Harari is describing is more proverbial than literal, and has already been occuring in environments like Facebook and YouTube where we are led to view content that the algorithms have deemed to be of interest to us. It now would appear that many have gradually become desensitised to it the “hacking” and manipulation allowing it to increase without too much protest.

But how would you feel if your workplace was tracking how you feel? asks Nazanin Andalibi who is Assistant Professor of Information at the University of Michigan. and in the article below dissuses emotion AI which is already being used in the workplace.

Keep reading

China wants to rid itself of Western tech by 2027 — outlines domestic alternatives in ‘Document 79’

The WSJ reports that China is on an extensive push to drive out Western tech companies from the country and replace them with domestic alternatives. China reportedly started its domestic expansion in 2022 with a highly secretive “Document 79,” an initiative focused on deleting Western tech companies from the country. Since then, China’s new plan has been in full effect — domestic alternatives have replaced most Western software providers.

When initiated two years ago, Document 79 was a super sensitive document that only high-ranking officials were purportedly shown. Security was so paramount that copies of the document were not allowed to be made. The initiative set out by Document 79 is to replace foreign software in China’s IT systems by 2027, with state-owned firms required to provide quarterly updates on their progress in replacing foreign software with domestic alternatives.

Two years later, the fruits of Document 79 are now apparent. Microsoft, HP Enterprise, and Cisco’s market share in China has fallen drastically in the past several years. In 2018,  HP Enterprise had a 14.1% market share in China, but in 2023, that has fallen to just 4%. Cisco’s market share has halved in the past five years down to just 8%. Microsoft’s Chinese sales today account for just 1.5% of the company’s overall sales.

Most government institutions in China are now buying domestic technology over Western solutions, even if the Western solutions are superior due to Document 79. This includes everything from software to hardware solutions. Chinese customers who were buying IBM-powered rack-mount servers five years ago are now requesting Chinese-made rack-mount servers utilizing Huawei chips.

Keep reading

NIST staffers revolt against expected appointment of ‘effective altruist’ AI researcher to US AI Safety Institute

The National Institute of Standards and Technology (NIST) is facing an internal crisis as staff members and scientists have threatened to resign over the anticipated appointment of Paul Christiano to a crucial, though non-political, position at the agency’s newly-formed US AI Safety Institute (AISI), according to at least two sources with direct knowledge of the situation, who asked to remain anonymous.

NIST is an agency of the US Department of Commerce whose mission is “to promote US innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life.” According to the agency’s website, its core competencies are “measurement science,” “rigorous traceability” and “development and use of standards.” NIST also develops cybersecurity standards, guidelines and best practices, and released an AI security framework in January 2023.

Christiano, who is known for his ties to the effective altruism (EA) movement and its offshoot, longtermism (a view that prioritizes the long-term future of humanity, popularized by philosopher William MacAskill), was allegedly rushed through the hiring process without anyone knowing until today, one of the sources said.

The appointment of Christiano, which was said to come directly from Secretary of Commerce Gina Raimondo, has sparked outrage among NIST employees who fear that Christiano’s association with EA and longtermism could compromise the institute’s objectivity and integrity.

However, Divyansh Kaushik, associate director for emerging technologies and national security at the Federation of American Scientists, told VentureBeat that President Biden’s AI Executive Order, introduced in November 2023, specifically asks NIST and the AISI to focus on certain tasks — including CBRN (chemical, biological, radiological and nuclear materials) — for which Paul Christiano is “extremely qualified.”

Many say EA — defined by the Center for Effective Altruism as an “intellectual project using evidence and reason to figure out how to benefit others as much as possible” — has turned into a cult-like group of highly influential and wealthy adherents (made famous by FTX founder and jailbird Sam Bankman-Fried) whose paramount concern revolves around preventing a future AI catastrophe from destroying humanity. Critics of the EA focus on this existential risk, or “x-risk,” say it is happening to the detriment of a necessary focus on current, measurable AI risks — including bias, misinformation, high-risk applications and traditional cybersecurity. 

Keep reading

Amazon’s Ring is the largest civilian surveillance network the US has ever seen

In a 2020 letter to management, Max Eliaser, an Amazon software engineer, said Ring is “simply not compatible with a free society”. We should take his claim seriously.

Ring video doorbells, Amazon’s signature home security product, pose a serious threat to a free and democratic society. Not only is Ring’s surveillance network spreading rapidly, it is extending the reach of law enforcement into private property and expanding the surveillance of everyday life. What’s more, once Ring users agree to release video content to law enforcement, there is no way to revoke access and few limitations on how that content can be used, stored, and with whom it can be shared.

Ring is effectively building the largest corporate-owned, civilian-installed surveillance network that the US has ever seen. An estimated 400,000 Ring devices were sold in December 2019 alone, and that was before the across-the-board boom in online retail sales during the pandemic. Amazon is cagey about how many Ring cameras are active at any one point in time, but estimates drawn from Amazon’s sales data place yearly sales in the hundreds of millions. The always-on video surveillance network extends even further when you consider the millions of users on Ring’s affiliated crime reporting app, Neighbors, which allows people to upload content from Ring and non-Ring devices.

Then there’s this: since Amazon bought Ring in 2018, it has brokered more than 1,800 partnerships with local law enforcement agencies, who can request recorded video content from Ring users without a warrant. That is, in as little as three years, Ring connected around one in 10 police departments across the US with the ability to access recorded content from millions of privately owned home security cameras. These partnerships are growing at an alarming rate.

Data I’ve collected from Ring’s quarterly reported numbers shows that in the past year through the end of April 2021, law enforcement have placed more than 22,000 individual requests to access content captured and recorded on Ring cameras. Ring’s cloud-based infrastructure (supported by Amazon Web Services) makes it convenient for law enforcement agencies to place mass requests for access to recordings without a warrant. Because Ring cameras are owned by civilians, law enforcement are given a backdoor entry into private video recordings of people in residential and public space that would otherwise be protected under the fourth amendment. By partnering with Amazon, law enforcement circumvents these constitutional and statutory protections, as noted by the attorney Yesenia Flores. In doing so, Ring blurs the line between police work and civilian surveillance and turns your neighbor’s home security system into an informant. Except, unlike an informant, it’s always watching.

Keep reading

Climate Change Committee’s Net Zero Plan Involves Pumping Compressed CO2 With Energy of 500 Hiroshima Bombs into Ground Every Year. Are They Mad?

In the last few weeks a number of serious errors have come to light in the Climate Change Committee’s (CCC) plan for Net Zero. The CCC plan was published mid-2019 in a document titled ‘Net Zero Technical Report’.

In summary, the CCCs plan for Net Zero is to shift transport and heating from using petrol, diesel and gas to using electricity and then to decarbonise the electricity grid.

To decarbonise the grid, it is assumed that electricity will be generated using nuclear and renewables. During periods when nuclear, wind and solar cannot meet demand, Carbon Capture and Storage (CCS) will be deployed to remove CO2 emissions as the electricity must be generated using gas.

Carbon Capture and Storage is a new and untested technology that has never been deployed at scale anywhere on earth. However, it is clear from the CCC’s report that CCS plays a major roll in achieving Net Zero. As I reported in a previous article, regardless of this being an untested technology, the U.K. only plans to build a quarter of the required capacity to hit Net Zero by 2050 (the plan requires the U.K. to capture and store 176Mt of CO2 annually).

Nevertheless, our Government envisages significant CCS capacity at 50Mt annually. Carbon Capture and Storage involves filtering CO2 from the exhaust produced from gas turbines used to generate electricity, then piping the captured CO2 to plants that compress the gas into a liquid before it is then injected into underground storage areas around the U.K.

Compressed CO2 is currently being commercialised as a way to store energy for use in periods when nuclear and renewables are unavailable. The company Energy Dome has developed a working 4MWh system in Sardinia, Italy. The company says its technology has an energy storage density 10-20 times higher than other compressed air energy storage (CAES) solutions and two-thirds that of liquid air energy storage (LAES).

The CCC’s plan requires vast quantities of CO2 to be compressed and stored under the U.K. Given this potential energy could be released at any time should something go wrong, it seems sensible to consider the safety implications of Carbon Capture and Storage.

Energy Dome has recently raised $11m and is building a larger 100MWh system. Its 100MWh store requires about 2,000 tonnes of CO2. This means the company is expecting to store 0.05MWh of energy per tonne of compressed CO2. Using this energy density, the CCC’s plan to store 176Mt per year will mean 8.8TWh of potential energy is being trapped beneath the U.K. annually. The bomb dropped on Hiroshima exploded with an energy of about 15 kilotons of TNT or 0.0174TWh. Therefore the energy we will be storing under our feet is equivalent to 505 Hiroshima bombs every year or the energy released by 16 magnitude seven earthquakes per year.

Keep reading