Connect with us

Published

on

Ransomware has long been plaguing American municipalities. It appeared to be another typical ransomware attack that impacted the city of Columbus, Ohio, this past July. The city’s response to the hack, however, was not, and it has cybersecurity and legal experts across the country questioning its motives.

Connor Goodwolf (legal name is David Leroy Ross) is an IT consultant who plumbs the dark web as part of his job. “I track dark web-type crimes, criminal organizations, and stuff like what the Telegram CEO has been arrested for,” Goodwolf said.

So when word got out that the city of Columbus, his hometown, had been breached, Goodwolf did what he does: he poked around online. It didn’t take him long to discover what the hackers had in their possession.

“It wasn’t the biggest, but it was one of the most impactful breaches I have seen,” Goodwolf said.

In some ways, he described it as a routine breach, with personal identifiable information, protected health information, Social Security numbers and driver’s license photos exposed. However, because multiple databases were breached, it was more encompassing than other attacks. According to Goodwolf, the hackers had breached multiple databases from the city, the police, and the prosecutor’s office. There were arrest records and sensitive information about minors and domestic violence victims. Some of the breached databases, he says, went back to 1999. 

Goodwolf found over three terabytes of data that took over 8 hours to download.

“The first thing I see is the prosecutor’s database, and I’m like ‘holy sh-t’ these are domestic violence victims. When it comes to domestic violence victims, we need to protect them the most because they have already been victimized once, and now they are again by having their information exposed,” he said.

Goodwolf’s first action was to contact the city to let them know how serious the breach was, because what he saw contradicted official statements. At a press conference on August 13,  Columbus Mayor Andrew Ginther said: “The personal data that the threat actor published to the dark web was either encrypted or corrupted, so the majority of the data came by the threat actor is unusable.”

But what Goodwolf was finding didn’t support that view. “I tried to reach out to the city multiple times to multiple departments and was blown off,” he said.

Google-owned Mandiant, as well as many other top cybersecurity firms, have been tracking a continued increase in ransomware attacks, both in prevalence and severity, and the rise of the Rhysida Group behind the Columbus hack, which has come into prominence within the last year.

The Rhysida Group claimed responsibility for the hack. While not much is known about the cyber gang, Goodwolf and other security experts say they appear to be state-sponsored and based in Eastern Europe, possibly linked to Russia. Goodwolf says these ransomware gangs are “professional operations” with a staff, paid vacation, and PR people.

“They have ramped up the attacks and targets since last autumn,” he said.

The U.S. government’s Cybersecurity and Infrastructure Security Agency issued a bulletin about Rhysida last November.

Goodwolf said that because no one from the city responded to him he went to the local media and shared data with journalists to get the word out about the seriousness of the breach. And that is when he heard from the city of Columbus, in the form of a lawsuit and a temporary restraining order preventing him from disseminating additional information. 

The city defended its response in a statement to CNBC:

“The City initially moved to obtain this order, which was granted by the Court, to prevent the dissemination of sensitive and confidential information, potentially including the identities of undercover police officers, that threatens public safety and criminal investigations.”

The city’s temporary 14-day restraining order against Goodwolf has since expired, and now it has a preliminary injunction and an agreement with Goodwolf not to release more data.

“It should be noted that the Court order does not prohibit the defendant from discussing the data breach or even describing what kind of data was exposed,” the city’s statement added. “It simply prohibits the individual from disseminating the stolen data posted on the dark web. The City remains engaged with federal authorities and cyber security experts to respond to this cyber intrusion.”

Meanwhile, the mayor did have to perform a mea culpa at a subsequent press conference, saying his initial statements were based on the information he had at the time. “It was the best information we had at the time. Clearly, we discovered that that was inaccurate information and I have to accept responsibility for that.”

Realizing the exposure to residents was greater than first thought, the city is offering two years of free credit monitoring from Experian. This includes anyone who has had contact with the city of Columbus via an arrest or other business. Columbus is also working with Legal Aid to see what additional protections are needed for domestic violence victims who may have been compromised or need help with civil protection orders.

To date, the city has not paid the hackers, who were demanding $2 million in ransom.   

‘He’s Not Edward Snowden’

Those who study cybersecurity law and work within the realm expressed surprise at Columbus filing a civil lawsuit against the researcher.

“Lawsuits against data security researchers are rare,” said Raymond Ku, professor of law at Case Western Reserve University. On the rare occasion they do happen, he said, it is usually when the researcher is alleged to have disclosed how a flaw was or can be exploited, which would then allow others to take advantage of the flaw as well.

“He wasn’t Edward Snowden,” said Kyle Hanslovan, CEO of cybersecurity company Huntress, who described himself as troubled by the city of Columbus’s response and what it could mean for future breaches. Snowden was a government contract employee who leaked classified information and faced criminal charges, but considered himself a whistleblower. Goodwolf, Hanslovan says, is a Good Samaritan who independently found the breached data.

“In this case, it appears we have just silenced someone who, as far as I can tell, appears to be a security researcher who did the bare minimum and confirmed the official statements made were not true. This can’t possibly be an appropriate use of the courts,” Hanslovan said, predicting the case will be quickly overturned.

Columbus City Attorney Zach Klein said during a September press conference that the case was “not about freedom of speech or whistleblowing. This is about downloading and disclosure of stolen criminal investigatory records.”

Hanslovan worries about the ripple effect where cybersecurity consultants and researchers are afraid to do their jobs for fear of being sued. “The bigger story here is are we seeing the emergence of a new playbook” for hacking response in which individuals are silenced, and that should not be welcomed, he said. “Silencing any opinion, even for 14 days, could be enough to prevent something credible from coming to light, and that terrifies me,” Hanslovan said. “That voice needs to be heard. As we see bigger cybersecurity incidents come up, I am worried that folks will be more concerned bringing them to light.”

Scott Dylan, founder of United Kingdom-based venture capital firm NexaTech Ventures, also thinks the actions of the city of Columbus could induce a chilling effect on the field of cybersecurity.

“As the field of cyberlaw continues to mature, this case is likely to be referenced in future discussions about the role of researchers in the aftermath of data breaches,” Dylan said.

He says legal frameworks must evolve to keep pace with the sophistication of both cyberattacks and the ethical dilemmas they generate, and the approach taken by Columbus is a mistake.

Meanwhile, the legal process will grind on for Goodwolf. Despite Columbus and Goodwolf reaching an agreement last week on the dissemination of information, the city is still suing him for damages in a civil suit that could reach $25,000 or higher. Goodwolf is representing himself in his talks with the city, though says that he has a lawyer on standby, if needed.

Some residents have filed a class-action lawsuit against the city. Goodwolf says that 55% of the information breached has been sold onto the dark web, while 45% is available for anyone with the skills to access it.

Dylan thinks the city is taking a big risk, even if its actions may be legally defensible, by creating the appearance of an attempt to silence discourse rather than encourage transparency. “It’s a strategy that could backfire, both in terms of public trust and future litigation,” he said.

“I am hoping the city realizes the mistake of filing a civil suit and the implications not just on security,” Goodwolf said, noting that Intel is building a $1 billion facility in a Columbus suburb. In recent years, the city has been positioning itself as a new tech hub in the Midwest, and attacking white hats and cybersecurity researchers, he said, could cause some in the tech sector to rethink it as a location.

Continue Reading

Technology

YouTube announces AI features from Google DeepMind for Shorts creators

Published

on

By

YouTube announces AI features from Google DeepMind for Shorts creators

Veo in Dream Screen

YouTube

YouTube on Wednesday announced artificial-intelligence features for creators on its Shorts platform that tap into Google‘s DeepMind video-generation model.

The features, known as Veo, will allow creators to add AI-generated backgrounds to their videos as well as use written prompts to generate standalone, six-second video clips. YouTube CEO Neal Mohan said he hopes Veo will enable creators to produce more Shorts videos with the help of AI.

“Everything that we showed with AI was meant to really enhance the work that you do, make it faster, more efficient, to bring your creative ideas to life faster,” said Mohan, speaking at the Made on YouTube event in New York.

The Veo AI backgrounds are an upgrade over a similar AI-generation feature announced by YouTube in 2023 called Dream Screen. The company said its Veo AI background feature will roll out later this year while the six-second AI clips will become available in 2025.

Other announcements at the event included new features in the YouTube Studio app that will allow creators to use AI to generate titles, thumbnails and video ideas. Those features will roll out in late 2024, YouTube said.

Creators have been exploring various ways to leverage generative AI technology. Creators have used the new technology to insert clips in their videos or produce entirely AI-generated videos.

However, some creators expressed concerns that their videos on YouTube are used to train the AI models that built Veo.

“I don’t know how I feel about all this AI stuff,” said Thomas Simons, a comedian with more than 15 million subscribers on YouTube. “It doesn’t fill me with confidence and love.”

There has been criticism that other services like Facebook have become overrun by spammy, AI-generated content. There are also concerns that AI-generated content could violate intellectual property protections.

YouTube’s AI-generated content will be watermarked and will have a label indicating it was created by AI, the company said.

Generative AI places a new perspective on the creator economy, giving creators free access to tools utilized by large language models.

We “really sit at the nexus of that technology and creativity,” Mohan said. “Putting those two things together gives us this unique lens that everything we build is really about enhancing that human creativity.”

WATCH: How YouTube beat Netflix and Disney in the streaming wars

How YouTube beat Netflix and Disney in the streaming wars

Continue Reading

Technology

Elon Musk’s X ‘declined to send an appropriate witness’ to Senate hearing on election threats

Published

on

By

Elon Musk's X 'declined to send an appropriate witness' to Senate hearing on election threats

As the riots raged in the U.K., Elon Musk began making incendiary comments about the situation, including the statement: “Civil war is inevitable.” Musk is the owner of X, the social media platform formerly known as X.

Aytug Can Sencar | Anadolu | Getty Images

While top executives from Alphabet, Meta and Microsoft are headed to Capitol Hill on Wednesday for a hearing on election threats, Elon Musk’s X won’t be participating.

A representative for Sen. Mark R. Warner, the Democratic chair of the Senate Intelligence Committee, said in an emailed statement that X “declined to send an appropriate witness.” No further details were provided.

A spokesperson for X told CNBC that the company’s invited witness was Nick Pickles, who had been the head of global affairs but “resigned on September 6.” Warner’s office said X declined to send a replacement after Pickles’ departure.

The hearing is titled “Foreign Threats to Elections in 2024 — Roles and Responsibilities of U.S. Tech Providers.” Alphabet will be represented by Kent Walker, the president and chief legal officer, while Meta’s head of global affairs, Nick Clegg, will represent the social networking company. Microsoft President Brad Smith will represent the software giant.

The hearing, which is being led Warner (D-Va.) and committee Vice Chairman Marco Rubio (R-Fla.), is centered around lawmakers’ concerns over foreign entities that are attempting to influence the outcome of the presidential elections in November using the biggest tech platforms.

Alphabet and Microsoft recently published research into the efforts by Iranian and Russian hacking groups to influence or attack officials linked to President Joe Biden and former President Donald Trump. The hackers have utilized various tactics including spear phishing.

Earlier this month, the Biden administration said it’s targeting Russian government-sponsored attempts to affect U.S. public opinion.

“We will be relentlessly aggressive in countering and disrupting attempts by Russia, Iran, as well as China or any other foreign malign actor” attempting to “interfere in elections and undermine our members,” Attorney General Merrick Garland said in a statement at the time.

X’s absence from the Wednesday hearing follows a streak of divisive posts by Musk, the world’s richest person, on the app, formerly known as Twitter, which he acquired in 2022. Musk has close to 200 million listed followers.

After a second apparent assassination attempt against Republican former President Donald Trump over the weekend, Musk shared then deleted a post questioning why there weren’t more assassination threats made against President Biden and Vice President Kamala Harris, the Democratic nominee. Biden and Harris have both received assassination threats while in office.

European news agencies also reported this week that Musk has previously shared content on X that had been created by the Social Design Agency, which led a propaganda campaign at the Kremlin’s direction, according to the U.S. Department of the Treasury’s Office of Foreign Assets Control.

On Wednesday, Musk shared a false story on X that claimed explosives were found in a car near Trump’s planned rally in Long Island, New York. According to a statement from Nassau County police, a civilian near the site of the rally had falsely reported explosives being found.

In the early stages of the meeting Wednesday afternoon, Warner said “it’s a shame” that no one from X appeared. He said that, prior to Musk’s takeover, the company was a “collaborator.”

“Under X, they are absent and some of the most egregious activity has taken place” on the platform, Warner said.

WATCH: SpaceX will be filing suit against the FAA for regulatory overreach.

SpaceX will sue the FAA for regulatory overreach, Elon Musk posts on X

Continue Reading

Technology

The iPhone 16 Pro Max has better battery life and great cameras, but Apple Intelligence hasn’t arrived

Published

on

By

The iPhone 16 Pro Max has better battery life and great cameras, but Apple Intelligence hasn't arrived

iPhone 16 Pro

Apple Inc. 

Apple’s iPhone 16 family of phones will hit shelves on Friday. Ahead of their launch, I’ve spent the past five days been testing the high-end iPhone 16 Pro Max.

It’s a great phone with cool updates like a dedicated camera button, and it charges faster over MagSafe than earlier Pro models. The screens are also slightly larger than prior versions.

But this review is tricky, because one of the banner features Apple has been hyping — on stage and in its new ads — is Apple Intelligence. It’s Apple’s suite of AI features for the iPhone, and it’s not coming until later this year.

There are reasons to be excited. A few of the new AI features, like changes to Siri, photo editing, and the option to have AI rewrite text for you, will launch in beta in October. More additions, such as as Apple’s image and emoji generator, more personal Siri responses and integration with ChatGPT, will come later.

I was able to test some of the beta features for this review. Others weren’t available. Those limitations make it difficult to provide a comprehensive assessment of the new device or to suggest whether the upgrade is worthwhile.

Apple shares slid earlier in the week after analysts suggested lighter demand for the iPhone 16 Pro models this year. TF Securities analyst Ming-Chi Kuo said the problem is that Apple Intelligence isn’t out at launch. Barclays also feared it may be because the Chinese language version of Apple Intelligence won’t launch until 2025.

Here’s what you need to know about the new iPhone 16 Pro Max, as of now.

The changes to know about

iPhone 16 Pro.

Apple Inc.

The biggest change you’ll notice is the new camera button. I’m still getting used to it after a few days, but I’m already defaulting to just pulling the phone out of my pocket, tapping the button and taking a picture.

My wife rightly asked me why I don’t just hit the camera button on the lock screen like on earlier iPhones. I don’t have a good answer for that. It just feels more natural to push a camera button.

I enjoyed doing a half-press to get camera controls like the zoom during my son’s first soccer game, though I found it was easier to sometimes just pinch to zoom. The new 48-megapixel wide-angle lens offers sharper images in zoomed-out shots that can capture more scenery.

Videographers will likely enjoy the 4K 120fps recording offered on the iPhone 16 Pro Max. Still, I try to keep my clips in lower quality because I’m sharing them over text messages with family and friends.

The iPhone 16 Pro Max has the best battery life of any iPhone yet. Apple’s new A18 Pro processor paired with a larger battery offers up to 33 hours of video playback, up from 29 hours on last year’s iPhone 15 Pro Max. I was usually able to make it to about dinnertime before needing to charge the 15, and I can make it to bedtime — or beyond — with the new phone depending on how much I’m using it.

I love that Apple increased the speed of its MagSafe charging. I used MagSafe when it came out but ultimately switched back to regular cable charging because it was quicker. Now, MagSafe gives up to a 50% charge in 30 minutes if you’re using a 30-watt charger (not included.)

The screens are slightly larger on this year’s Pro models. The iPhone 16 Pro Max moved from 6.7 inches to 6.9 inches. I didn’t notice a difference and could only tell when I put the two phones next to each other. It’s still a fantastic screen with a high refresh rate, which means scrolling is smooth. It’s colorful and bright and I love the always-on display for seeing notifications without picking up my phone. It’s not new this year but still useful and limited to the Pro models.

Apple Intelligence

Apple Intelligence photos

Apple Inc. 

In the absence of Apple Intelligence at launch, I’m limited to testing a few beta features. They’re hit or miss, as to be expected in beta.

Apple Intelligence could help drive a new cycle of iPhone upgrades. Apple reported $39.3 billion in iPhone sales during the fiscal third quarter, about 46% of the company’s total revenue and down 1% from a year earlier. CEO Tim Cook said the segment grew on a constant currency basis.

I like email summaries provided by Apple Intelligence. They’re accurate and give you just a couple of lines that summarize what’s said or relayed in an email. This only works in Apple’s Mail app, though, so it won’t work if your company makes you use Outlook or if you prefer Gmail. Similarly, I found that Apple Intelligence accurately summarized long bits of text (including the introduction to this review) and returned an accurate snippet. 

In notifications, it’s just OK. Summaries of news alerts were correct. Summaries of text messages sometimes were unnecessary. In one text from my wife, for example, Apple Intelligence suggested I threw a dinosaur at my daughter and made her cry before I apologized. In reality, my son was the culprit. The original text would have been sufficient. 

In a daycare app notification that I use, Apple Intelligence did a good job summarizing that my daughter “took a nap, ate Cheerios, and is playing happily.” That would be a perfect amount of information to receive while driving.

Apple Intelligence photos

Apple Inc. 

Another Apple Intelligence feature can help you create movie memories, which are little snippets of photos and videos set to music. In a TV ad, Apple shows a young woman using it to create memories of a dead goldfish with the help of Siri.

I couldn’t use Siri to create movies like that. Instead, I opened the Photos app, tapped Memories and wrote in a prompt asking for a photo memory of my son “learning to fish at Skytop set to a fishing tune.” It correctly showed pictures of a family trip to the Poconos but didn’t include any pictures of my son fishing there. The music was called “Fishing Tune” by Jiang Jiaqiang but didn’t sound like fishing music to me. Another test, asking for a photo memory of my son “playing soccer,” worked better but also included a picture of him as a baby with a football in his hands.

There’s also the whole new Siri interface that glows along the edges of the screen. I like the look compared to the globe, and it’s easier to type to Siri by tapping the screen indicator at the bottom of the display. Siri doesn’t feel drastically changed to me right now, although I liked that I could ask iPhone-specific questions like “How do I use my iPhone to scan a document?” and “How do I take a screen recording?” Siri presents the answer in a simple step-by-step guide at the top of the screen.

You can speak to Siri with interruptions now, too. So, if you get stumped while you’re thinking and say “umm” or “hold on a second,” you can continue to ask questions in the same line of thought, like “How tall is the Eiffel Tower?” and then follow with, “And when was it built?” But it doesn’t always work. I tried “How far is Boston?” for example, followed by, “And what’s the weather there?” Siri gave me the weather for my current location. 

Apple Intelligence can be useful and I’m excited to see where it goes.

Apple iPhone 16

An attendee holds two iPhone 16s as Apple holds an event at the Steve Jobs Theater on its campus in Cupertino, California, on Sept. 9, 2024.

Manuel Orbegozo | Reuters

I focused this review on the iPhone 16 Pro Max. The iPhone 16 is slightly smaller and has a little less battery life but is otherwise identical. My colleague used the regular iPhone 16.

There are a few differences between the two. The iPhone 16 comes in more colors and is built out of aluminum instead of titanium like the higher-end Pro models. It also has the new camera button but lacks the higher refresh rate and the always-on features of the Pro model displays.

The iPhone 16 will support all of the Apple Intelligence features I’ve mentioned above, plus the ones that are still coming. Apple also upgraded the processor for faster performance and added a new macro camera mode for up-close pictures of objects, as well as support for capturing spatial images for the Apple Vision Pro headset. It offers up to 22 hours of video playback versus the 20 hours in last year’s iPhone 15.

Should you buy it?

Continue Reading

Trending