Friday, 28 September 2018

What's valid and what's not: Everything you need to know about today's Aadhaar verdict



The Supreme Court has upheld the Aadhaar scheme as constitutionally valid. However, the apex court's five-judge constitution bench also struck down several provisions in the Aadhaar Act.

Below are some of the highlights of the court verdict:

* The Supreme Court upheld the validity of Aadhaar saying sufficient security measures are taken to protect data and it is difficult to launch surveillance on citizens on the basis of Aadhaar. A five-judge bench led by CJI Dipak Misra asked the government to provide more security measures as well as reduce the period of storage of data.

* The SC asked the Centre to bring a robust law for data protection as soon as possible.

* The SC said Aadhaar cannot be made mandatory for openings of a bank account and for getting mobile connections.

* The SC said that Aadhaar must not be made compulsory for school admission and the administration cannot make it mandatory.

* The SC directed the government to ensure that illegal migrants are not issued Aadhaar to get benefits of social welfare schemes.

* Private companies can't ask for Aadhaar.

* Justice Sikri while reading out the verdict on the constitutional validity of Aadhaar said that there is a fundamental difference between Aadhaar card and identity. Once the bio-metric information is stored, it remains in the system, he said.

* The apex court struck down the provision in Aadhaar law allowing sharing of data on the ground of national security.

* The SC said there is a fundamental difference between Aadhaar and other identity proof as Aadhaar cannot be duplicated and it is a unique identification. It added that Aadhaar is to empower the marginalised sections of the society, and it gives them an identity.

* Aadhaar satisfies the doctrine of proportionality, said justice Sikri, adding, "It is better to be unique than to be best."


-GoITWay

Thursday, 27 September 2018

Every cyberattack is related to geopolitical conditions,' says CEO of cybersecurity company hired by Google


CNBC's Jim Cramer gets the latest on cybersecurity from FireEye CEO Kevin Mandia, whose company was hired by Google to defend against state-sponsored cyberattacks.
Mandia says that the "dead reality" is that every major cyberattack is somehow state-condoned.


In his more than 20 years responding to cyberbreaches, Kevin Mandia, the CEO of enterprise-facing cybersecurity company FireEye, has learned one key, overarching thing about cyberattacks.

"It took me too long, but here's the dead reality: every cyberattack's related to geopolitical conditions," he told CNBC on Tuesday in an interview with "Mad Money" host Jim Cramer.

"If you're in the United States and you hack a company, you're going to get caught, so you have to live in a safe harbor," Mandia said. "You almost have to be condoned, you have to be supported, and many of the attacks we respond to, there are, in fact, people in uniform conducting the attacks against our companies."


Mandia, whose company was hired by both Facebook and Google to help identify disinformation campaigns, said that while hackers still frequently target individuals, most hacks surveyed by FireEye in the last year had ties to foreign government entities.

"We responded to over 600 breaches last year," Mandia said. "I would say over 80 percent of them were state-sponsored or state-condoned, meaning the heads of the state or the heads of certain agencies of that state knew the attacks were ongoing, but there's no risk or repercussions to the attackers."

Mandia's statements come at a time when cyberattacks on both Wall Street and Main Street, with tech giants warning consumers about the billions of cyberattacks that happen every day and others fretting about how cyber-warfare could affect the 2018 midterm elections.


One of Mandia's top concerns was the lack of "segregation" between government, enterprise and individuals' networks, he said, cautioning that as the lines are blurred, hackers will likely go after more vulnerable targets and cause malware to "ripple" out through various systems.

"We're all blending together into this big mesh network and it could be the strategy of the adversaries to go after the softer targets," he warned. "If you hack every elementary school in a certain state, that means maybe employees aren't going to work that day, and then it ripples out from there."

And state-sponsored hacks from nations like Iran, with which U.S. representatives clashed at the United Nations General Assembly on Tuesday, are nowhere near quieting down, the FireEye chief said.

"We first responded to Iran in 2007, 2008, and they just looked like they had just gotten out of the classroom. They weren't very good in offensive cyber, but they've had 10 years now," he told Cramer.

"You know for a fact they had an agenda to get good at asymmetric warfare. Cyberattacks are, in fact, asymmetric," Mandia continued. "They're not going to meet us on a battlefield with a bunch of tanks, ... they're going to meet us in cyberspace. And from the attacks we're observing, I kind of dub 2017 the year of Iran."

-GoITWay

Google is making search engine more visual, intuitive; wants it to answer questions before being asked


Google unveiled changes Monday aimed at making the leading search engine more visual and intuitive to the point that it can answer questions before being asked.

Artificial intelligence and machine learning are core drivers of how Google will pursue its mission to organize the world's information and make it accessible to anyone, search vice president Ben Gomes said at an event in San Francisco.

The search engine focused strongly on mobile use and appeared to be growing more like Facebook, encouraging users to linger and explore topics, interests or stories with growing emphasis on photos and videos. Results will be increasingly personalised.

"Search is not perfect, and we are under no illusions it is," Gomes said.

"But, you have our commitment that we will make it better every day."

He described the latest changes as shifting from answers to journeys, providing ways to target queries without knowing what words to use and enhancing image-based searches.

Google Images was redesigned to weave in "Lens" technology that enables queries based on what is pointed out in pictures.

The Images overhaul includes carousels of online video clip highlights displayed with mobile search query results.

New Activity Cards will let users pick up searches where they left off, eliminating the need to retrace online steps.

The search engine will also let users create Collections of online content, and suggest related material that might be of interest.

A Google feed used by more than 800 million people monthly is getting a new name, Discover, and increased ability to offer people relevant information they are likely to want but haven't thought to ask for yet.

The feature was described as "Google search helping you discover new things without a query."


Google said it is also testing out an improvement to its job-related search results that will figure out what skills are needed for such posts and information about how to acquire them.

"Information and language are core to what we are as human beings," Gomes said.

"Our work here is never done."

Since being launched 20 years ago, Google has grown from simply a better way to explore the internet to an online tool so woven into daily life that its name has become a verb.

Early days of search were about software matching keywords or precise phrases to content on web pages, with typos or imprecise queries destined to fail.

Google has consistently refined its search algorithm, which it keeps secret, and uses AI to understand what people are looking for online and to tailor results based on what it knows about users individually and collectively.

Google's rise put it in the crosshairs of regulators, especially in Europe, due to concerns it may be abusing its domination of online search and advertising as well as Android smartphone operating software.


There have been concerns that parent company Alphabet is more interested in making money from people's data than in safeguarding their privacy.

Google was under fire anew from privacy advocates for a change that automatically signs users into Chrome browsers on desktop computers when they sign into any of the company's other services such as Gmail or search.

Chrome search data is not in sync with Google servers unless that function is enabled, the company said in an update to its policies.

Google is among the tech companies being called upon to better guard against the spread of misinformation - and has also been a target of US President Donald Trump, who added his voice to a chorus of Republicans who contend conservative viewpoints are downplayed in search results.

Google's anniversary also comes with the rising trend of people engaging with the internet through voice-commanded digital assistants, including one backed by the Silicon Valley giant.

Seattle-based Amazon last week sought to make its Alexa digital assistant and online services a bigger part of people's lives with an array of new products and partnerships.

Wednesday, 26 September 2018

WhatsApp says working with India's Reliance Jio to curb fake news menace

 WhatsApp is working closely with Reliance Jio to spread awareness of false messages, weeks after the Indian telecoms operator opened up the messaging service to tens of millions of customers using its cheap internet-enabled phone.

Jio this month gave its more than 25 million JioPhone customers, many of them first-time internet users, access to WhatsApp at a time when the messaging service is battling false and incendiary texts and videos circulating on its platform.

Reliance Chairman Mukesh Ambani, India's richest man, launched the JioPhone last year at a refundable deposit of 1,500 rupees ($20.60). The device is internet enabled but didn't initially allow the use of WhatsApp or have several popular smartphone features.

All new users of the JioPhone get educational material that tells them about spotting a forwarded WhatsApp message and encourages them to share messages thoughtfully, WhatsApp spokesman Carl Woog told Reuters.

"We are working closely with Jio to continue our education campaign for WhatsApp users," Woog said.

In India's smaller towns and villages, deep-seated prejudices, often based on caste and religion, and cut-price mobile data can aggravate the so-called fake news problem. Such regions are a key market for cheap devices such as the JioPhone.

More than 30 people have died this year in mob violence triggered by vitriolic messages on social media and WhatsApp, according to unofficial estimates, and police have previously told Reuters that minorities have been targeted in some remote and rural regions.

That has prompted New Delhi to call on WhatsApp to take immediate action to "end this menace".

WhatsApp has already taken some steps to quell the rise of fake news. It has launched print and radio ad campaigns to educate users and introduced new features on the app including limiting message forwards as well as the labelling of forwarded messages.

It has also partnered with Digital Empowerment Foundation (DEF), a New Delhi-based non-profit organisation, to spread digital literacy in India's towns and cities.

DEF will host a workshop in the eastern Indian city of Ranchi this week, WhatsApp's Woog said.

WhatsApp also plans to expand its outreach programme to existing JioPhone users.

Reliance Jio did not immediately respond to an email seeking comment.

GOITWAY

Top practices for corporate users to optimize email security

Fortinet reminds corporate users in India that email remains one of the most vulnerable vectors targeted by cybercriminals. The cyber-attacks are likely to happen to organizations that have yet to implement strong email security controls and best practices.

According to the Verizon Data Breach Investigations report, two-thirds of installed malware are actually delivered by email. To gain access into an organization’s network, cybercriminals often use phishing or social engineering techniques in emails, thus counting on human error or a lack of cybersecurity know-how to trick users into providing login credentials or initiating fraudulent transactions, as well as to unknowingly install malware, ransomware and other malicious payloads.

“Due to the ubiquity of email, it continues to be a common attack vector for cybercriminals seeking to steal login credentials, money, and sensitive data.” Said Rajesh Maurya, Regional Vice President, India & SAARC, Fortinet. “The top email-based cyberattacks carried out by cybercriminals today include phishing or spear-phishing, man-in-the-middle attacks and zero-day vulnerabilities. Companies must therefore ensure they have strong security controls in place to detect and prevent these e-mail attacks.”

To help ensure email security, Fortinet’s cybersecurity experts advised users to:
Filter Spam. Because most email scams begin with unsolicited commercial email, one should take measures to prevent spam from getting into the mailbox. Most email applications and web mail services include spam-filtering features, or ways in which email applications can be configured to filter spam.

Regard Unsolicited Email with Suspicion. Don’t automatically trust any email sent by an unknown individual or organization. Never open an attachment to unsolicited email. Most importantly, never click on an unknown link in an email. Cleverly crafted links can take users to forged web sites set up to trick them into divulging private information or downloading viruses, spyware, and other malicious software.

Treat Email Attachments with Caution. Email attachments are commonly used by online scammers to sneak a virus onto computers. These viruses can help the scammer steal important information from the computer, compromising the computer so that it is open to further attack and abuse, and convert a computer into a ‘bot’ for use in denial-of-service attacks and other online crimes. As noted above, a familiar “from” address is no guarantee of safety because some viruses spread by first searching for all email addresses on an infected computer and then sending itself to these addresses.

Install Antivirus Software. Users should install an antivirus program that has an automatic update feature. This will help ensure users to always have the most up-to-date protection possible against viruses.

Install a Personal Firewall and Keep it Up to Date. A firewall will not prevent scam email from making its way into users’ mailbox. However, it may help protect users should they inadvertently open a virus-bearing attachment or otherwise introduce malware to their computer. The firewall, among other things, will help prevent outbound traffic from a user’s computer to the attacker. When a personal firewall detects suspicious outbound communications from a user’s computer, it could be a sign that the user has inadvertently installed malicious programs on his computer.