Mine: The startup that can track down your data


Bobby Hellard

GDPR defines personal data as an ‘asset’, yet despite this modern valuation, most of us have unwittingly – or unthinkingly –  given it away in exchange for online services. As such, the average digital footprint is spread far and wide.

If you can remember all the companies that have bits of your digital info, you can begin approaching each one individually and demand they delete it – but you may be surprised at the quantity of organisations that really is. While the mind may immediately leap to Facebook, Google and the other tech giants, it’s also lots of obscure entities. That time you brought a hat at Disneyland, for example, the shop collected more than just a payment. 

How do you start tracing companies you don’t remember engaging with? The answer is in your inbox and involves a little AI knowhow. This is the basic premise of Mine, an Israeli startup that uses machine learning to make the GDPR’s ‘right to be forgotten’ serviceable.

Gold Mine

Mine was founded by CEO Gal Ringel and CTO Gal Golan, who met in the cyber security unit of the Israeli army, and CPO Kobi Nissan, who previously worked for CandyCrush developer King. While many businesses saw GDPR as a hindrance when it came into force in 2018, for Mine it was an integral part of its inception.

“When we started to research the right to be forgotten, we quickly realised that we couldn’t find one tool that makes the GDPR accessible for the average person,” Ringel tells IT Pro. “Regulations are complex and difficult for the average user to understand. With that goal in mind, we quickly realised that we needed to come up with a really simple app that uncovers what companies have your personal data, to make your digital footprint tangible, for the first time, so you can almost touch it.” 

Ringel estimates that around 350 companies are waiting to be found in the average person’s email. For work accounts, it’s almost half of that falling somewhere between 80 to 100. A staggering 90% of the companies that have your data can be found in your inbox, spam filter or even your trash folder. What’s more, the key to finding out who has your personal details isn’t in the email itself, but rather the subject line.

With Google Cloud’s AI platform, Mine has built machine learning models divided into two datasets. The first is trained on emails that have been tagged as different types of interactions – specifically learning about subject lines. This process has been repeated in 12 different languages so that the service works for users in other parts of the world, not just Israel, and can also spot traces of companies from Germany, France, Italy, Israel, Spain and many more. 

“We search for these traces and then reflect it back to you,” Ringel explains. “So basically the AI understands what the interaction you had with a company was just based on the email’s subject. So for example, ‘Welcome to Air BnB’, that interaction is a sign up, and ‘Your purchase from Amazon’, means you’ve bought something. 

“We worked really hard for almost a year to develop machine learning that is non-intrusive, but basically scans your inbox by only looking at the email subject. So it never actually reads the context of the email, because we don’t want to see the process of how they collect the personal data and we also don’t want to be collecting any email data.”

How Mine understands what data you’ve given to that company is down to the second dataset, which has been trained on thousands of privacy policies. Under the rules of the GDPR, companies have to be transparent with the ‘what’ and ‘why’ of data collection. So for example, Airbnb collects your data for two reasons: Signing up to its service and then for payments. So it will have your name, address, email, mobile phone number, a copy of your passport, plus payment details if you’ve ever used its service. 

Sign up

Naturally, to find all this out, you need to sign up to one more service: Mine’s. It requires your email address to perform its basic function and your first and last name so that it can contact each company on your behalf. Upon registering your email, the company says, the machine learning models get to work and within 30 seconds you’ll be presented with 40 or so companies that have your data – this expands to hundreds after roughly 48 hours and repeatedly notifies you as and when you sign up to more. 

All the usual suspects will be there – Netflix, LinkedIn, Amazon – along with an assortment of unknown and forgettable one time services. Underneath each will be the data you signed up and a button to take action. Click on this and Mine sends a request on your behalf. Some companies, however, will be listed as “action unavailable”. 

“The reason you see action unavailable can be for two reasons,” Ringel explains. “First, these are companies that we still haven’t got round to analysing their privacy policies and learned their data structure. And the second could be that we didn’t find any contact information within their privacy policy. So we don’t know who to approach. When you want to reclaim from a company, we automatically shoot an email to its data protection officer or its privacy officer.” 

As a company turning the GDPR into a service, Mine will come under more scrutiny than most when it comes to compliance. The company’s own privacy policy has no margin for error.  

«The only data we do store is your email address, which you signed up with, and a list of the companies’ names we identified in your footprint,” Ringel confirms. “You can easily request a copy of the data we hold about you to see exactly what we keep. We are fully transparent on everything we are doing and, of course, in line with GDPR regulations.»

Main image copyright: Mine.

HSBC agrees multi-year cloud partnership with AWS


Bobby Hellard

15 Jul, 2020

HSBC Holdings has selected Amazon Web Services (AWS) as its long-term cloud provider for its planned digital transformation

The multi-year agreement will make AWS technology available across the company’s business, starting with customer-facing applications and modernisation of its Global Wealth & Personal Banking arm.

HSBC Holdings, the parent company of HSBC, is headquartered in London and serves customers around the world out of offices in 64 countries across Europe, Asia, North America, Latin America, and the Middle East and North Africa. 

With the migration, HSBC will have access to AWS’s extensive portfolio of cloud services, including compute, containers, storage, database, analytics, machine learning, and security to develop new digital products and support security and compliance standards for millions of its personal banking customers around the worldwide. 

The bank plans to use AWS serverless and analytics services, including Amazon Kinesis, to create a more personalised and customer-centric banking experience, it said. 

«Our work with AWS is an example of how HSBC continues to invest in secure and advanced technologies to make our digital banking experience even better for customers,» said Dinesh Keswani, CTO and CIO for digital at HSBC. 

«Our ambition is to make it easy, safe, and reliable for customers to bank with us, whenever and wherever they are. HSBC’s collaboration with AWS helps us to deliver innovative banking solutions to customers at a faster rate, starting with our Wealth & Personal Banking business.»

According to AWS, HSBC is continuing to expand its use of its cloud services to deliver innovative financial services that help customers grow their wealth in «new and more personalised ways».

«We look forward to our continued collaboration with HSBC as they leverage AWS’s proven capabilities, reliability, and security to drive efficiency across their business and become a more agile organisation in the cloud,»  said Frank Fallon, VP of financial services at AWS. 

Microsoft and Citrix expand partnership for the new normal


Bobby Hellard

14 Jul, 2020

Microsoft and Citrix have announced an expansion of their partnership to help organisations deal with the move to remote and agile business models.

The multi-year deal between Citrix and Microsoft aims to help businesses accelerate the move to the cloud and speed up adoption of digital workspaces and virtual desktops.

Citrix and its workspace portal will become Microsoft’s «preferred» digital workspace, while Citrix has chosen Azure as its preferred cloud platform.

The thinking behind the deal is to help businesses address the «workplace of the future» with the pandemic drastically changing the way companies operate. Citrix believes that more organisations will make remote work a permanent part of their cost and workforce management strategies, which will mean that office structures will change. 

Virtual desktops has been an area of heavy investment from Microsoft, with the pandemic forcing many businesses to shift to working from home. As a result, Windows Virtual Desktop usage has almost trebled in recent months and the company’s CEO, Satya Nadella, has prioritised work on both Microsoft Teams and Windows Virtual Desktops.
 
The two companies will provide joint tools and services to simplify and speed the transition of on-premises Citrix customers to Azure. They will also devise a connected roadmap to enable a consistent and optimal flexible work experience that will include joint services comprised of Citrix Workspace, Citrix SD-WAN, Microsoft Azure and Microsoft 365.

«The COVID-19 pandemic has forced businesses around the world to change the way that employees work, while still meeting the speed and security requirements that today’s uncertain business environment demands,» said David Henshall, president and CEO of Citrix.

«Looking forward, hybrid-work models will become the standard for many customers, requiring a flexible infrastructure to support, secure and empower their teams.
 
«Together, Citrix and Microsoft can deliver a powerful digital workspace in a trusted and secure public cloud where employees can access everything they need to engage and be productive whether they are at home, in the office or on the road.»

Google launches Confidential VMs for sensitive data processing


Dale Walker

14 Jul, 2020

Confidential VMs will be the first product in Google Cloud’s new confidential computing portfolio, the company has revealed, allowing companies to process sensitive data while keeping it encrypted in memory.

The announcement aims to capitalise on a growing interest in confidential computing, a field that promises to revolutionise cloud computing by providing what is in effect permanent uptime on data encryption.

Until now, like many cloud providers, Google offered encryption on data at rest and while in transit, requiring that data to be decrypted before it could be processed. Through Confidential VMs, Google customers encrypt data while it is being processed inside a virtual machine.

Google’s new feature is an evolution of its Shielded VMs, a tool launched in 2018 that companies could deploy to strip out most of the potentially vulnerable startup processes that trigger when attempting to create a new environment. This is in addition to a few layers of extra protection against external attacks, and monitoring systems that check for unexpected changes to data.

These added layers of security were required given that data is normally decrypted in order to be processed inside the VM – something that not only creates added risk from external attacks, but also forces companies to deploy strict access controls to ensure only the right employees handle the data.

The Confidential VMs feature, available as a beta today, attempts to solve these issues by allowing customers to encrypt their data in memory, meaning encryption can be maintained while it is being used, indexed, queried, or trained on.

This promises to have profound implications for those industries that process highly sensitive or heavily regulated data, such as those in finance and health, or government agencies. Companies in these sectors, which are usually forced to keep most of their data processing in their own private networks, now have a public cloud option, Google claims.

“These companies want to adopt the latest cloud technologies, but strict requirements for data privacy or compliance are often barriers,” Sunil Potti, general manager and VP of Security at Google Cloud. “Confidential VMs… will help us better serve customers in these industries, so they can securely take advantage of the innovation of the cloud while also simplifying security operations.”

Providing confidential computing is largely a question of hardware, something that many vendors have grappled with over the past few years. In this case, Google has turned to AMD and its second-generation EPYC CPUs – these now support a ‘Secure Encrypted Virtualisation (SEV)’ feature, which allows a VM to run with encrypted memory using a unique, non-exportable, key.

“Our deep partnership with Google Cloud on its Confidential VMs solution helps ensure that customers can secure their data and achieve performance when adopting this transformational technology,” said Dan McNamara, senior vice president and general manager of AMD’s Server Business Unit.

“Confidential VMs offer high performance for the most demanding computational tasks all while keeping VM memory encrypted with a dedicated per-VM instance key that is generated and managed by our hardware.”

The company has also confirmed that any customers already running workloads in a VM on Google Cloud Platform will be able to shift these over to a Confidential VM using a checkbox.

Google has also said that VM memory encryption will not interfere with workload output, promising that the performance of Confidential VMs will be on-par with that of non-confidential VMs.

BigQuery Omni pulls Google, AWS, and Azure analytics into one UI


Dale Walker

14 Jul, 2020

Google has launched an early version of BigQuery Omni, its new analytics tool that lets users access and view data across Google Cloud and Amazon Web Services without leaving the Big Query UI.

Powered by Google Anthos, its vendor-neutral app development platform, users will be able to use SQL and the standard BigQuery APIs to manipulate data silos sourced from multiple platforms, without having to manage the underlying infrastructure.

Although the initial alpha launch of the service is restricted to Google Cloud and AWS, Google has also confirmed that Microsoft Azure will eventually be supported.

The tool has been designed to target those customers who rely on multiple cloud service providers and are forced to juggle and consolidate a number of analytics tools in order to get a view of their data.

This is made possible by the decoupling of storage and compute, according to the firm. The compute side has always been regarded as ‘stateless’ but, until now, BigQuery required data to be stored in Google Cloud – this restriction has now been scrapped, allowing customers to store their data in any supported public cloud.

This single view means that customers can use BigQuery Omni to run SQL queries on clusters in whichever region the data resides. For example, it will be possible to query Google Analytics 360 Ads data stored in Google Cloud while simultaneously querying logs data from any apps stored in AWS S3. This can then be used to build a dashboard to get a complete view of audience behaviour alongside ad spend.

This means customers can avoid any costs associated with moving or copying data between cloud platforms in order to get a full view, Google claims.

“85% of respondents to 451 Research’s Voice of the Enterprise Data & Analytics, Data Platforms 1H20 survey agreed that the ability to run the same database on multiple cloud/data centre environments is an important consideration when selecting a new data platform,” said Matt Aslett, research director, Data, AI and Analytics, 451 Research.

“As hybrid and multi-cloud adoption has become the norm, enterprises are increasingly looking for data products that provide a consistent experience and lower complexity of using multiple clouds, while enabling the ongoing use of existing infrastructure investments,» he added.

The new system is built using Anthos, an app development platform launched last year to appease customers that wanted a single programming model that allowed for data to be moved between their various cloud providers without charge or requiring changes.

The underlying infrastructure is run entirely by Google, including any communication between cloud providers, on the familiar BigQuery UI, so there will be little operational change from the customers’ perspective, the company claims.

BigQuery Omni’s engine will run on Anthos clusters inside the BigQuery managed service, and will source data from the various data silos across a customer’s public cloud services, provided they have provided authorisation. In order to run queries, data is temporarily moved from the cloud provider’s data storage to the BigQuery cluster running on Anthos.

For now, BigQuery Omni is only available in private alpha, so customers will need to apply to Google to use it if they’re interested. It’s also only available for AWS S3 for now, with Azure support coming soon.

There is currently no general release date available.

SAP patches critical flaw that lets hackers seize control of servers


Keumars Afifi-Sabet

14 Jul, 2020

Software company SAP has patched a critical vulnerability that can be exploited by an unauthenticated hacker to take control of systems and applications.

The flaw, assigned CVE-2020-6287, affects the LM Configuration Wizard element of the NetWeaver Application Server (AS) Java platform, and affects potentially 40,000 customers, according to Onapsis, which discovered the vulnerability.

Alarmingly, the flaw has been rated 10 out of 10 on the CVSS scale and has spurred the United States Computer Emergency Readiness Team (US-CERT) into issuing an alert encouraging organisations to patch their systems immediately.

«Due to the criticality of this vulnerability, the attack surface this vulnerability represents, and the importance of SAP’s business applications, the Cybersecurity and Infrastructure Security Agency (CISA) strongly recommends organizations immediately apply patches,» the alert said. 

«CISA recommends organizations prioritize patching internet-facing systems, and then internal systems.»

Those unable to patch their systems should mitigate the vulnerability by disabling the LM Configuration Wizard service. Should this step be impossible, or take more than 24 hours to complete, CISA has recommended closely monitoring SAP NetWeaver AS for any suspicious or anomalous activity. 

The flaw is a result of the lack of authentication in a web component of the SAP NetWeaver AS for Java which allows for several high-privileged activities on the SAP system. 

Successful exploitation involves a remote hacker obtaining unrestricted access to SAP systems by creating high-privileged users and executing arbitrary OS commands with high privileges. Hackers would retain unrestricted access to the SAP database and can perform application maintenance activities. 

The flaw, in essence, entirely undermines confidentiality, integrity and availability of data and processes hosted by the SAP application. 

The vulnerability is present by default in SAP applications running over SAP NetWeaver AS Java 7.3, and any newer versions up to SAP NetWeaver 7.5, affecting a handful of applications. These include SAP Enterprise Resource Planning (ERP), SAP Product Lifecycle Management, SAP Customer Relationship Management (CRM), and around a dozen more.

Flaws rated 10/10 on the CVSS scale are barely encountered, and ordinarily mean the vulnerability is highly exploitable, easy to trigger, and require little or no additional privileges and user interaction. Nevertheless, the SAP flaw is the second 10-rated vulnerability discovered within a couple of weeks, after Palo Alto patched a flaw in its networking services based around its SAML-based authentication mechanism.

Both the SAP and Palo Alto flaws were highlighted by official US law enforcement agencies, the former flagged by US-CERT and the latter by US Cyber Command.

What is serverless computing?


Steve Cassidy

14 Jul, 2020

If you’re looking to move away from hybrid cloud and pack up your on-premises servers all together, but are worried about how your applications will run in the cloud, serverless computing could be the right strategy for you.

Serverless computing? As in running everything on desktops?

Ah, no – serverless computing means building your server functions in the cloud, rather than on a local, physical machine. In this way, they can benefit from demand-driven management, spinning up as required then closing down again when, for example, the entire human race decides to stay at home for several months. Ideally, functions should be fully portable, eschewing platform-specific services and tricks, so they’ll run in any data centre.

So we can go serverless and retire our old servers?

It’s unlikely that you’d be able to do a straightforward lift-and-shift of your old, badly behaved suite of IT resources up into the cloud. Any function that depends on some older technology (say, for example, a Windows dialog box) will have to be rebuilt with modern tools that embrace scalability and movability. Indeed, even once you’ve moved, it might make sense to keep your older servers running in parallel for some time, as a fallback in case of unforeseen hiccups. 

Could we at least streamline our local admin team?

If that’s your plan, make sure they’re ready to come back on a consultancy basis: you’re going to need their knowledge more than ever while the development is in progress, and likely for some time afterwards. Only the very simplest of businesses can make a consequence-free shift, and they’re still likely to need some techie oversight to ensure everything is scaling and behaving like it should.

Surely moving our everyday line-of-business functions off-site is going to slow things down?

If you have a big on-site compute load then it might, but for outward-facing services – that is, ones used by your customers rather than your employees – moving to a scalable architecture could speed things up. What’s more, a serverless approach easily allows for multiple instances so you can, for example, create different versions of your site for different users and markets.

Is it wise to put our critical functions in the hands of a third party?

Part of the beauty of the serverless model is that you’re not tied to any single provider. If there’s a problem with one host, you can just pop a serverless image onto a flash drive and fire it up somewhere else. Running instances here and there might not be cheap, but it’s a much more resilient position than one where yanking out a 13A lead will scuttle your whole operation.

Are there other benefits?

Most popular business apps are now very old: histories stretching back 20 years or more are not uncommon. That means you’re working with two decades of accumulated bug fixes, function changes and bloat. The process of moving to a serverless model gives you a chance to take stock, assess which parts of your code portfolio could work better in the cloud, and to re-engineer any broken or backward functions. 

So when will our everyday apps go serverless?

Basic, network-shared apps aren’t going to magically transform into serverless versions: the cost of moving outweighs the advantages. However, it may be that service providers (like your card payment processor) migrate you to serverless because you’re only using one specific part of their offering, so it makes sense for them to only fire up the code you’re using. That move will probably be entirely invisible to you, though – which is just as it should be. 

IBM job ad calls for 12-years of experience with six-year-old Kubernetes


Bobby Hellard

13 Jul, 2020

IBM has put out a job advert calling for a candidate with over 12-years of experience with Kubernetes administration and management. 

It looks like a fairly straight forward ad, except for the fact that Kubernetes has only been a thing for the last six years.

The advertisement, which is still live, calls for a «minimum» of 12 years experience in Kubernetes, including «hands-on» experience setting up Kubernetes platforms, deploying microservices and other web applications and managing secure secrets along with container orchestration.

It requires someone to have earned at least six years experience before the first GitHub post about the project was made on 7 June 2014.

As the Twitter account ‘Really Bad Job Ads‘ shows, it’s very common to make typos or strange syntactical errors in job ads, but nothing on its feed comes close to a giant tech company getting in a muddle over new technology.

In this regard, IBM is not alone, as developer Sebastián Ramírez pointed out on Twitter. He applied for a role that asked for over four years of experience using FastAPIs, but Ramírez knew all too well at the time that no one could have more than one and a half years experience of it because he created it. 

This also goes the other way with job seekers sometimes getting it wrong. Replying to Ramírez, researcher Lynn Boyden recalled an applicant in 2012 that said they had over 17-years of experience with web design.

«We interviewed a 28-year-old designer in 2012 who told us he had 17-years experience designing websites. I said, ‘Tim Berners-Lee doesn’t have 17 years experience designing websites’. ‘Who’s Tim Berners-Lee?’ he asked. So yeah.»

Again, this goes the other way as further down the replies, App designer Jens Ravens explained that he was once told he didn’t have enough experience with a certain iOS library during an interview, despite the fact he developed it.

Nokia begins major data centre networking gambit


Keumars Afifi-Sabet

10 Jul, 2020

Nokia has launched a set of tools, equipment and an operating system for data centre networking to help large companies manage growing traffic in light of increased 5G and machine learning adoption.

Working in collaboration with Apple to build the technology, Nokia has launched a data centre Network Operating System (NOS) as a toolkit to allow for intent-based automation and operations in data centres. This is in addition to new routers and switches.

The company’s data centre venture is based on the idea that the data centre will overlap with cloud and telecoms networks, with technologies like 5G and the Internet of Things (IoT) causing demand for data movements to rise.

All together, Nokia’s foray will allow what it describes as ‘cloud builders’ – webscale firms, service providers and large enterprises – to scale-up and adapt their data centre environments in light of the surging traffic.

“With decades of experience serving the world’s telecom operators, we understand the engineering challenges of building and operating business and mission-critical IP networks on a global scale,” said Nokia’s president of IP and optical networks, Basil Alwan.

“However, today’s massive data centers have their own unique operational challenges. The SR Linux project was the proverbial ’clean-sheet’ rethink, drawing from our partnership with Apple and others. The resulting design is impressive in its depth and strikes the needed balance for the future.”

Nokia describes its Service Router Linux as the first fully modern microservices-based network operating system. It’s built on technology used in more than a million IP network routers, and runs standard Linux. This can be combined with the Nokia Service Router Linux NetOps development kit, which allows customers to take advantage of a rich set of programming capabilities.

Majority of UK firms say cyber threats are outpacing cloud security


Sabina Weston

10 Jul, 2020

New research into cloud security management has found that 83% of UK organisations believe threats to cloud systems are outpacing their ability to effectively deploy countermeasures.

This places the UK behind the global average, at 71%. By contrast, only 53% of German enterprises believe the same.

Cyber security company Palo Alto Networks has published its findings about the practices, tools, and technologies that companies around the world use to manage security for cloud-native architecture, interviewing 3,000 professionals in cloud architecture, information security, DevOps, and application development located across the UK, Germany, USA, Singapore, and Australia.

The State of Cloud Native Security report shows that UK organisations today host 42% of their workloads in the cloud and expect this to increase to 65% in the next two years.

A significant majority (93%) of UK businesses admitted to using more than one cloud platform, while one in two (57%) said they use between two and five. The trend was reflected on a global scale, with 94% and 60% of global organisations admitting to the same respectively.

However, the report has found that the growing reliance on cloud infrastructure has not translated into increased confidence in cloud security. In fact, 84% of UK respondents admitted that their organisation struggles to draw a clear line between their own responsibility for cloud security and their cloud service providers responsibility for security.

Low confidence in cloud security, and undefined responsibility for it, coincides with a surge in the number of attacks on cloud accounts, up by 630% between January and April of this year, according to McAfee. A majority of these external attacks were large-scale attempts to access cloud accounts with stolen credentials and usually targeted collaboration services like Microsoft 365.

The research also found that, while overall enterprise use of cloud services increased by 50%, access to the cloud using unmanaged, personal devices doubled, contributing to the risk of company data being stolen.