Showing posts with label bad idea. Show all posts
Showing posts with label bad idea. Show all posts

Wednesday, March 4, 2026

New Zealand Navy grounding update

I posted about this 15 months ago. Midwest Chick has an update:

The New Zealand navy was so proud and happy to have a lesbian from Britain come on board that they gave her a $100M survey and dive vessel, which she crashed and sank.

The lesbian “diversity hire” captain of a Royal New Zealand Navy ship that ran aground and sank off Samoa has been charged with negligence along with two other officers over the loss of the vessel.

The $100 million HMNZS Manawanui, which was under the command of UK-born homosexual Yvonne Gray, crashed on the south side of Upolu on October 5, 2024, due to human error including failure to turn off autopilot, an inquiry found last year.

This is the official inquiry report which is leading to Commander Gray's Courts Martial.  Obviously the entirety of His Majesty's New Zealand Navy is a bunch of dirty misogynists ...

Midwest Chick adds this tidbit that I had missed:

This isn’t the first time that a NZ naval diversity hire damaged a ship. It happened in 2024 with a different female captain.

And that’s what happens when you choose diversity over competence. Wonder if the New Zealanders will actually learn from this??

Now maybe our own Navy could do something about our (multiple) female commanders who run into ships on the high seas. 

 

Thursday, February 19, 2026

Hallucinations come to Mass.gov

Okay, okay - Mass.gov has been hallucinating for years and years.  But now they're automating things:

Today, Governor Maura Healey announced the launch of the ChatGPT-powered Artificial Intelligence (AI) Assistant for the state’s workforce, with the goal of making government work better and faster for people.  

"Open the pod bay doors, HAL." 

Monday, December 15, 2025

Lawsuit over FedRAMP compliance

This is perhaps a niche security topic, but some of you are as niche as me:

The US is suing a former senior manager at Accenture for allegedly misleading the government about the security of an Army cloud platform.

Danielle Hillmer, 53, of Chantilly, Virginia, is accused of deceiving auditors over the capabilities of a service the government commissioned in 2017.

Although it is only referred to as Company A in the court documents, Hillmer claimed to work for Big Four consulting firm Accenture during the stated timeline, according to a now-deleted LinkedIn account.

The US alleges that between March 2020 and November 2021, Hillmer obstructed federal auditors and falsely represented the security of the company's cloud platform, which was used by other government customers beyond the Army.

Perhaps not security per se, but this raises the question of just how much do you trust the audit process?

Tuesday, December 9, 2025

Gartner Group recommends companies ban AI browsers

This is big news.  Gartner Group is the largest IT trend analysis firm, used by essentially all large corporations.  They just recommended blocking the installation and use of AI browsers:

Agentic browsers are too risky for most organizations to use, according to analyst firm Gartner.

The firm offered that advice last week in a new advisory titled “Cybersecurity Must Block AI Browsers for Now,” in which research VP Dennis Xu, senior director analyst Evgeny Mirolyubov, and VP analyst John Watts observe “Default AI browser settings prioritize user experience over security.”

I've posted about the risks of AI browsers.  Gartner's recommendations track mine:

Gartner’s fears about the agentic capabilities of AI browser relate to their susceptibility to “indirect prompt-injection-induced rogue agent actions, inaccurate reasoning-driven erroneous agent actions, and further loss and abuse of credentials if the AI browser is deceived into autonomously navigating to a phishing website.”

The authors also suggest that employees “might be tempted to use AI browsers and automate certain tasks that are mandatory, repetitive, and less interesting” and imagine some instructing an AI browser to complete their mandatory cybersecurity training sessions. [Highlighting mine - Borepatch]

The highlighted bit is a very clever way to get attention from IT departments.  Not only will it irritate the IT Security team but it will focus the Risk Management team on potential loss of SOC2 compliance.  This is a very Gartner way of getting eyeballs from the CISO and CIO.  Like I said, clever.

And yeah, I agree 100% with Gartner on this. 

 

 

Monday, December 1, 2025

Why can't the US Navy build ships?

First, they canceled the Little Crappy Shops (LCS) program as not fit for purpose.  Now it's the Constellation class Frigate program that gets the axe:

By 2024, the first ship of the class was 36 months behind schedule, with the second already considered two years behind before its keel was even laid. The plan, as I mentioned before, was to retain roughly 85% of the FREMM frigate design to expedite production, but by that point, the Constellation design retained only about 15% of its parent design. This caused a cascade of other issues, like the need to write new code for a reported 95% of the ship’s control system software due to deviations from the FREMM design it came from, and the incorporation of new equipment and systems.

The Constellation-class frigate seemed to suffer from a classic case of scope-creep, a term used to describe a program that keeps seeing new requirements tacked onto it as it develops, resulting in cost overruns and delays. As one lawmaker put it, the Navy kept chasing a 100% solution to the point where they ended up with 0% of the ship being delivered.

There's more here from the Tech Press, so this is getting attention. 

As Yogi Berra once said, if you don't know where you're going you'll end up somewhere else.  SECNAV should see to it that the Program Management Office finds itself somewhere else - preferably not working for the Navy.  Pour encourager les autres ...

Wednesday, November 5, 2025

Skynet has arrived

Um, I've seen this movie:

Nation-state goons and cybercrime rings are experimenting with Gemini to develop a "Thinking Robot" malware module that can rewrite its own code to avoid detection, and build an AI agent that tracks enemies' behavior, according to Google Threat Intelligence Group.

In its most recent AI Threat Tracker, published Wednesday, the Chocolate Factory says it observed a shift in adversarial behavior over the past year. 

Attackers are no longer just using Gemini for productivity gains - things like translating and tailoring phishing lures, looking up information about surveillance targets, using AI for tech support, and writing some software scripts. They are also trialing AI-enabled malware in their operations, we're told. 

It seems that the Bad Guys are using all the old malware tricks (obfuscation, hidden files, etc) plus some new ones (sending commands via LLM prompts, i.e. the malware queries (prompts) other LLMs to get commands.

The security model for AI/LLM is hopelessly broken, and the design is defective.  I mean heck - the designers didn't consider two decade old attack techniques.  I don't know if it's correct to label this broken as designed but it's not far off.  This is software engineering malpractice.

I can't wait to see what happens with this and one of Elon's humanoid robots ... 

Tuesday, October 28, 2025

AI Browsers considered unsafe

OK, that post title is more than a bit inflammatory, but who on earth would want to use something like this?

Several new AI browsers, including OpenAI's Atlas, offer the ability to take actions on the user's behalf, such as opening web pages or even shopping. But these added capabilities create new attack vectors, particularly prompt injection.

Prompt injection occurs when something causes text that the user didn't write to become commands for an AI bot. Direct prompt injection happens when unwanted text gets entered at the point of prompt input, while indirect injection happens when content, such as a web page or PDF that the bot has been asked to summarize, contains hidden commands that AI then follows as if the user had entered them.

This is unbelievably bad.  How bad?  This bad: 

Last week, researchers at Brave browser published a report detailing indirect prompt injection vulns they found in the Comet and Fellou browsers. For Comet, the testers added instructions as unreadable text inside an image on a web page, and for Fellou they simply wrote the instructions into the text of a web page.

When the browsers were asked to summarize these pages – something a user might do – they followed the instructions by opening Gmail, grabbing the subject line of the user's most recent email message, and then appending that data as the query string of another URL to a website that the researchers controlled. If the website were run by crims, they'd be able to collect user data with it.

Surely they must be exaggerating, I hear you say.  Nope - the author of the post at El Reg recreated the exploit his very own self, simply by creating a web page with the commands hidden in it.  FYI, that's 1996 technology right there.

Now look, I may be an old crabby security geezer (no comments, Glen Filthie!) but the problem of sanitizing user input is a really old one.  So old that it was old when XKCD did it's classic "Bobby Tables" cartoon:


There have been over 3000 XKCD cartoons; that one was number 327.  Yeah, that long ago. 

My opinion about anything regarding AI is that the hype is so fierce that the people developing the applications don't really focus much on security, because security is hard and it would slow down the release cadence.  And so exploits that wouldn't have surprised anyone back in 2010 keep popping up.

Le sigh.  Once again, security isn't an afterthought, it wasn't thought of at all.  My recommendation is not to touch these turkeys with a 100' pole.

Wednesday, August 13, 2025

UK.GOV to US Tech Companies: Put an encryption backdoor in your stuff

US.GOV to UK.GOV: Get lost, punk:

The Home Office's war on encryption – its most technically complex and controversial aspect of modern policymaking yet – is starting to look like battlefield failure after more than ten years of skirmishes.

First tabled by former prime minister David Cameron in 2015 following a terrorist shooting at the offices of French satirical magazine Charlie Hebdo, vague wording alluded to a potential ban in the Investigatory Powers Act 2016.

...

However, it seems Home Office staff are now coming to terms with the fact that the Trump administration will block any attempt to further strongarm Amercia's tech companies.


Insiders told the Financial Times, speaking on condition of anonymity, that the Trump administration's disapproval of the UK's plans, which the president has previously likened to Chinese-style policymaking, is the main obstacle in achieving its encryption-busting ambitions.

Being compared to Red China* has got to hurt.  But you know how not to get compared to Red China?  Don't act like Red China. 

Remember, Government mandated encryption backdoors are a bad idea.   Really.

* I only use the term to bother the Right Sort of people.

Friday, July 25, 2025

AI gets creepier every day

This starts out "yaknow, that sounds like a good idea" but gets creepier and creepier as you read more:

Ring doorbells and cameras are using AI to "learn the routines of your residence," via a new feature called Video Descriptions.

...

Once they do this, as Ring founder and Amazon VP of product Jamie Siminoff wrote in a blog today announcing Video Descriptions: 

Ring notifications will provide more meaningful information like, 'A person is walking up the steps with a black dog,' or 'Two people are peering into a white car in the driveway.'

The aim, according to Siminoff, is to shift more of the heavy lifting involved with home security to Ring's AI. This will also include "custom anomaly alerts," which are generated when "something happens on your property that is an anomaly to your property."

So far, so good.  Getting alerts only when something is unusual is generally considered A Good Thing when it comes to security.  But there's a downside:

And here's where it gets a little bit creepy: "It will learn the routines of your residence, get smarter, and deliver peace of mind by only notifying you when it is something out of the ordinary."

This gives us pause, as opposed to peace of mind, and sounds like super-charged snooping wrapped in an AI bow. If this kind of information is not properly secured, it could be a treasure trove for thieves, burglars, stalkers, and all other sorts of mischief-makers. In December 2022, a grand jury indictment charged two US men with breaking into Ring accounts to make fake emergency calls to police ("swatting"), then streaming the audio and video as the police arrived.

How long until AI will hack into your AI-enabled Ring account?  Asking for a friend.

Ring's response to The Register's reporter does not reassure:

The Register asked Ring where this information about users' home routines is stored, how it's secured, and under what circumstances it might be shared with law enforcement.

"We do not log the descriptions generated from Video Descriptions," a spokesperson emailed in response to our questions.

In the meantime, your humble vulture will continue to stick with dumb doorbells and barky dogs to deliver peace of mind about out-of-the-ordinary occurrences at home.

Endorsed.  Particularly the barky dog bit. 

Monday, May 19, 2025

Baseball and the steriod boys

Gerry leave a comment to ASM826's post about Pete Rose and Shoeless Joe Jackson becoming eligible for the Hall Of Fame:

So when will the Steroid boyz be allowed in?

Good question.  It brought to mind A-Rod, and a comment from Chris Lynch back in the day:

Every time A-Rod comes up to bat in Fenway, they should play Huey Lewis and the News "I want a new drug" ...

Well, okay then.  I dunno when he's be eligible, but if they induct him, this should be their bumper music.

Tuesday, May 6, 2025

Microsoft to end passwords for Windows

Well, Windows for consumers, at least:

The software giant announced the move Thursday, May 1, traditionally known as "World Password Day," with a declaration it had joined forces with the Fast Identity Online (FIDO) Alliance to re-name the pseudo-holiday "World Passkey Day."

Redmond’s not just playing with words as the Windows giant has also decided that all new Microsoft accounts will use passkeys by default. Passkeys, which involve the use of biometric identification like a fingerprint or face scan, PIN, and the like, will be the de facto new way to set up an account, and existing Microsoft users are being encouraged to visit their account settings page to delete their passwords and start using passkeys.

(Think of passkeys as a replacement of passwords.)

I'm of two minds here.  On the upside, passwords are generally an infinitely renewable source of insecurity.  This has been known  for decades:


On the downside, there is one negative that can simply never be fixed: you cannot change your biometrics if this somehow gets compromised.  You cannot revoke a fingerprint and issue a new one.

My take: hold off on this one.  Certainly Microsoft's commercial customers will never go here - password rotation is specifically required by essentially all industry security mandates (ISO 27000, SOC2, etc).

Color me unconvinced.  I'm not sure exactly what motivated Microsoft to do this.

Thursday, April 24, 2025

Blue Shield sent a boatload of member's health data to Google

This is pretty big:

US health insurance giant Blue Shield of California handed sensitive health information belonging to as many as 4.7 million members to Google's advertising empire, likely without these individuals' knowledge or consent.

The data shared may have included medical claim dates and providers used, which raises the specter of Google targeting ads based on the fact that you booked an appointment with a certain type of doctor - say, a cancer specialist, fertility clinic, or psychiatrist.

Other info potentially shared with Google ranged from patient names, insurance plan details, city of residence and zip code, gender, family size, and Blue Shield-assigned account identifiers, to financial responsibility info, and search queries and results for the "Find a Doctor" tool — including location, plan type, and provider details.

Other than that, Mrs. Lincoln - how did you like the play?

Blue Shield declined to answer The Register's questions, including how it discovered this years-long data leak, and what other third-party trackers (if any) are on its websites.
...

"This isn't just a technical misstep. It's a HIPAA compliance failure," Ensar Seker, CISO at threat intel firm SOCRadar, told The Register, referring to America's Health Insurance Portability and Accountability Act that safeguards medical data.

Bingo is his name-o.  Just to emphasize that: this wasn't just a "data breach", it was a criminal violation of US law.

 

Thursday, April 3, 2025

This. 1000x this.

When did the EU.gov get so, well, stupid?

The EU has issued its plans to keep the continent's denizens secure and among the pages of bureaucratese are a few worrying sections that indicate the political union wants to backdoor encryption by 2026, or even sooner.

While the superstate has made noises about backdooring encryption before the ProtectEU plan [PDF], launched on Monday at the European Parliament, says the European Commission wants to develop a roadmap to allow "lawful and effective access to data for law enforcement in 2025" and a technology roadmap to do so by the following year.

...

According to the document, the EC will set up a Security Research & Innovation Campus at its Joint Research Centre in 2026 to work out the technical details. Since it's impossible to backdoor encryption in a way that can't be exploited by others, it seems a very odd move to make if security's your goal.

China, Russia, and the US certainly would spend a huge amount of time and money to find the backdoor. Even American law enforcement has given up on the cause of backdooring, although the UK still seems to be wedded to the idea. [boldface by me - Borepatch]
Well, duh.

Now the cynical view of things is that the EU.gov is not being stupid at all, but just think that their adversary is not China and Russia and the USofA but rather their own populations.  

 

Monday, March 3, 2025

The (Security) lamps are going out all across Europe

We shall not see them relit in our lifetimes:

Signal CEO Meredith Whittaker says her company will withdraw from countries that force messaging providers to allow law enforcement officials to access encrypted user data, as Sweden continues to mull such plans.

Whittaker said Signal intends to exit Sweden should its government amend existing legislation essentially mandating the end of end-to-end encryption (E2EE), an identical position it took as the UK considered its Online Safety Bill, which ultimately did pass with a controversial encryption-breaking clause, although it can only be invoked where technically feasible.

Basically the Sweden.Gov is asking Signal to get pregnant, but only a little bit pregnant.  But vulnerabilities (and that's exactly what a government mandated encryption backdoor is) don't work that way.

And from the Department of Irony, the Swedish military oppose this:

The Swedish Armed Forces routinely use Signal and are opposing the bill, saying that a backdoor could introduce vulnerabilities that could be exploited by bad actors. 
I guess this is just Exhibit 14,543,928 that Europe is fundamentally unserious about their own defense.

This follows hard on the heels of Apple turning off encryption in the UK

Looking at what's going on over there, it makes me think that maybe we should just cut the whole of them loose, to sink or swim on their own.  Unwilling to defend themselves, increasingly despotic to their subjects at home, maybe JD Vance is right after all that we no longer have shared values.

 

 

Tuesday, February 25, 2025

Congress pushes back on UK snooping

Maybe there's something in the water in Washington D.C. these days, but this is clearly A Very Good Thing Indeed:

A bipartisan, bicameral pair of lawmakers urged newly confirmed Director of National Intelligence Tulsi Gabbard to reevaluate U.S. cybersecurity and intelligence-sharing relations with the United Kingdom in response to a report revealing that the UK secretly ordered Apple to build a backdoor into encrypted iCloud backups.

The Feb. 7 report from the Washington Post says that the order issued last month demands UK law enforcement and intelligence operatives be granted worldwide, unfettered access to users’ protected cloud data. Apple customers residing in the United States would be cast into that dragnet.

Sen. Ron Wyden, D-Ore., and Rep. Andy Biggs, R-Ariz., asked Gabbard in the Thursday missive if the Trump administration was made aware of the order by stakeholders and whether the White House has understanding of the CLOUD Act, which lets U.S. law enforcement get data stored by American tech companies, even if that data is on servers outside the U.S., by using warrants or subpoenas.

“If Apple is forced to build a backdoor in its products, that backdoor will end up in Americans’ phones, tablets, and computers, undermining the security of Americans’ data, as well as of the countless federal, state and local government agencies that entrust sensitive data to Apple products,” they wrote in their letter to Gabbard.

Remember, Encryption Backdoors are a Very Bad Idea.  It's not just me saying this, it's the former Director of the UK's GCHQ (their NSA equivalent).

And well done to Congresscritters from both parties in both the House and Senate for putting some pressure on the idiots in Blimey.

Thursday, January 16, 2025

Security wasn't an afterthought, it wasn't thought of at all

This keeps coming up over and over.  The latest example is GoDaddy:

GoDaddy has failed to protect its web-hosting platform with even basic infosec tools and practices since 2018, according to the FTC, but the internet giant won’t face any immediate consequences for its many alleged acts of omission.

As one of the world's largest web-hosting companies, and a registry and registrar with about 82 million domain names in its care, one would assume GoDaddy would be adept at applying software updates and monitoring security-related events in its hosting environment to protect its millions of customers and the visitors to their websites from online threats.

But according to a Wednesday statement from the FTC, “GoDaddy has failed to implement reasonable and appropriate security measures to protect and monitor its website-hosting environments for security threats, and misled customers about the extent of its data security protections on its website hosting services.”

So what triple-propellorhead security tech did they miss?  Basics like security log analysis tools, multi-factor authentication on login, missing security patches, and not maintaining an inventory of their systems.  This is all Security 101.  Actually, it may be Security Pre-K.

If you use GoDaddy's hosting you might want to consider an alternative.

 

Wednesday, December 4, 2024

New Zealand Navy ship lost due to series of human errors

They didn't turn off the autopilot:

A Court of Inquiry that was stood up following the grounding of the Royal New Zealand Navy dive and hydrographic ship HMNZS Manawanui in Samoa on October 5, 2024, determined that the incident was the result of human error.

"The direct cause of the grounding has been determined as a series of human errors which meant the ship’s autopilot was not disengaged when it should have been," said Rear Admiral Garin Golding, who stood up the Court of Inquiry in order to understand the facts of what occurred.

"The crew did not realise Manawanui remained in autopilot and, as a consequence, mistakenly believed its failure to respond to direction changes was the result of a thruster control failure."

And so the autopilot drove the ship onto the reef.  It seems that the manual on how to deal with this has "check that the autopilot is turned off" as step 1.

 

Thursday, November 14, 2024

AI failures in healthcare

Oh my word:

On Saturday, an Associated Press investigation revealed that OpenAI's Whisper transcription tool creates fabricated text in medical and business settings despite warnings against such use. The AP interviewed more than 12 software engineers, developers, and researchers who found the model regularly invents text that speakers never said, a phenomenon often called a "confabulation" or "hallucination" in the AI field.

Upon its release in 2022, OpenAI claimed that Whisper approached "human level robustness" in audio transcription accuracy. However, a University of Michigan researcher told the AP that Whisper created false text in 80 percent of public meeting transcripts examined. Another developer, unnamed in the AP report, claimed to have found invented content in almost all of his 26,000 test transcriptions.

Of course, they use it because it's cheaper than paying a human transcriber.  So riddle me this, Healthcare Administrator: what do you call yet another AI that lies all the time?  A day that ends in "-day".

And people have started noticing:

While the vast majority of people over 50 look for health information on the internet, a new poll shows 74% would have very little or no trust in such information if it were generated by artificial intelligence.

Meanwhile, 20% of older adults have little or no confidence that they could spot misinformation about a health topic if they came across it.

That percentage was even higher among older adults who say their mental health, physical health or memory is fair or poor, and among those who report having a disability that limits their activities. In other words, those who might need trustworthy health information the most were more likely to say they had little or no confidence they could spot false information.

People are smart enough to catch a whiff of marketing Bravo Sierra.

From now on I will start asking all of my healthcare providers if they do transcription, and if so whether they use AI for the transcription.  If they do I will demand to review the transcript.  If they won't, I'll get a different provider.

Friday, October 4, 2024

Meta fined for storing user passwords with no encryption

Holy cow, I've been in this industry for decades and can't remember a time when everyone knew that you encrypted the damn passwords*:

Officials in Ireland have fined Meta $101 million for storing hundreds of millions of user passwords in plaintext and making them broadly available to company employees.

Meta disclosed the lapse in early 2019. The company said that apps for connecting to various Meta-owned social networks had logged user passwords in plaintext and stored them in a database that had been searched by roughly 2,000 company engineers, who collectively queried the stash more than 9 million times.

This is such a rookie mistake that it makes you wonder what those 9 million queries were looking for.  Meta has such a horrible reputation for abusing its users privacy that the suspicion is that this was just one more wring on that rag.  That's only a suspicion, but Meta has certainly earned that suspicion over the years.

* Yeah, yeah I know - one-way hash.  I try not to use too much tech jargon.

Thursday, October 3, 2024

KIA cars can be hacked with a smartphone

I hope you don't drive a KIA.  This is actually a failure of post manufacturing security processes, not that it makes things any better:

Sam Curry, who previously demonstrated remote takeover vulnerabilities in a range of brands – from Toyota to Rolls Royce – found this vulnerability in vehicles as old as model year 2014. The mess means the cars can be geolocated, turned on or off, locked or unlocked, have their horns honked and lights activated, and even have their cameras accessed – all remotely.

...

The issue originated in one of the Kia web portals used by dealerships. Long story short and a hefty bit of API abuse later, Curry and his band of far-more-capable Kia Boyz managed to register a fake dealer account to get a valid access token, which they were then able to use to call any backend dealer API command they wanted.

"From the victim's side, there was no notification that their vehicle had been accessed nor their access permissions modified," Curry noted in his writeup. "An attacker could resolve someone's license plate, enter their VIN through the API, then track them passively and send active commands like unlock, start, or honk."

Security wags have long called this sort of architecture "broken by design" - it was intentionally set up to allow privileged access via a poorly authenticated system that has to scale through a big organization.  I don't have much confidence that KIA can fix this, or that they will likely want to.

And oh yeah - there's a smartphone app to help the Bad Guys.

All I can say is that 1968 Goat isn't vulnerable to this attack, and will never be.