Amazon claims AWS Rekognition can now detect fear


Bobby Hellard

14 Aug, 2019

Amazon Web Services has revealed an update to its facial recognition software, Rekognition, that can detect a person’s fear.

This update was announced on Monday along with improvements to accuracy and functionality of its facial analysis feature that can identify gender, emotions and age range.

The company claims the software can already accurately read seven ‘emotions’, but it has now added an eighth – the ability to spot fear.

However, some experts have pointed out that while there is scientific evidence that suggests there are correlations between facial expressions and emotions, the way they’re communicated across cultures and situations can vary dramatically.

«Today, we are launching accuracy and functionality improvements to our face analysis features,» the tech giant said. «Face analysis generates metadata about detected faces in the form of gender, age range, emotions, attributes such as ‘Smile’, face pose, face image quality and face landmarks.

«With this release, we have further improved the accuracy of gender identification. In addition, we have improved accuracy for emotion detection (for all 7 emotions: ‘Happy’, ‘Sad’, ‘Angry’, ‘Surprised’, ‘Disgusted’, ‘Calm’ and ‘Confused’) and added a new emotion: ‘Fear'»

The ethical use of facial recognition, and its accuracy, particularly when deployed on a crowd, has caused concern throughout the world. From the London Met Police’s use that resulted in zero arrests and a 98% failure rate, to San Francisco’s outright ban of the technology, it’s now more famous for its problems than its benefits.

The UK’s Information Commissioner (ICO) has announced an investigation into the privacy aspect of facial recognition, which came to light this week after the owner of a development site in King’s Cross confirmed the technology was being used.

Amazon’s own Rekognition has also been a source of controversy after it was revealed that US law enforcement used the technology. There was even reports that AWS tried to offer the software to the Immigration and Customs Enforcement organisation, which sparked protests from Amazon staff.

Why a holistic approach to cloud transformation is key to success

As applications increasingly move to the cloud, businesses often voice concerns about soaring WAN costs as well as latency issues when accessing apps. The much-anticipated benefits of a cloud transformation, including greater efficiency and agility, risk being eroded when the user experience is unsatisfactory and costs spin out of control.

How, then, can organisations successfully tackle their transformation projects to avoid these pitfalls and fully realise the benefits of the cloud? This is a contentious issue, even for companies that have already begun their cloud journeys.

According to our own recent independent survey, which included 400 decision-makers in four European countries, fewer than one in 10 companies (nine percent) in Germany, England, France, and the Benelux region are employing a holistic transformation approach, which includes taking application, network, and security aspects into account at the same time.

Furthermore, 21 percent of companies reported starting their journey with applications; 26 percent used the network as the starting point, and one-third (33 percent) began by transforming security. In 11 percent of the companies surveyed, decision-makers actually considered the transformation of applications together with that of the network. The results demonstrate that there is no consistent way to approach a transformation project.

Network topologies for the cloud?

Businesses are advised to take holistic considerations into account during an application transformation as early as the planning phase. This means that the decisions for a cloud project should not be started in isolation from a single business unit, because such siloed thinking leads to negative performance and spiralling costs. If an application is pushed into the cloud without the network and security teams being involved in the planning stage, problems are inevitable.

A traditional network topology is not designed to meet the needs of the cloud. Users are not directly connected to applications in the cloud when using a classic hub-and-spoke network. Whether at the headquarters, at a branch office, or from another remote location, users must always take a detour via the data centre, which creates latency as this connection to the internet is never the shortest or most time-saving path.

This detour can also help explain the skyrocketing costs. The traffic from remote users goes through the MPLS lines several times through this detour. In addition, the increase of internet-bound traffic must be taken into account. Office 365, the most popular cloud-based application suite and the one that launches many companies’ journey to the cloud, can increase traffic substantially. For good reason, the recommendation in the Microsoft Design Guide is to rely on direct internet connections at each location to give employees the shortest path to applications in the cloud.

Security for the cloud, from the cloud

Businesses must understand that a cloud-ready network should be built before deploying a cloud-based application. Part of the building process involves changes to the security infrastructure. If applications are to leave the network and a mobile user wants to access data in the cloud, security hardware at the perimeter becomes a bottleneck for this traffic. Here the second silo opens up. The security team must be invited to the table when a transformation project is planned. The specific security requirements of cloud-based projects have to be considered.

If only the network team is consulted, but not the security expert, the following aspects are often overlooked in the planning phase:

  • Is the existing proxy designed to cope with increasing network traffic?
  • Is the appliance capable of scanning traffic for the rising volume of malware that hides behind SSL encryption?
  • Is the firewall also keeping up with the new data volume and parallel connections, which are required for the Office 365 example?

In short, not only is there more data traffic, but there are also new requirements for the security infrastructure as applications move to the cloud. If companies anticipate the move and provide local internet breakouts, the security infrastructure must also be maintained locally because the traditional security infrastructure around the centralised data centre would, in turn, be associated with a detour.

The solution cannot be to install stacks of appliances at each site, as cost and administrative overhead bar such a move. To secure local breakouts, the solution is a security stack in the cloud with all the necessary security modules, from the next-generation firewall to cloud sandboxing and data loss prevention.

Cloud-delivered security as a service reduces the administrative burden through a high degree of integration and therefore a short path to log correlation. And security from the cloud scales easily with increased data volume and ensures the correct path for business-critical applications through bandwidth management. Application, network, and security transformation must go hand in hand

According to our research, a third of decision-makers are already adapting security requirements as part of their transformation. Building on this progress, the network topology should also be cloud-ready to intercept bottlenecks as applications move to the cloud. That means that the one-quarter of companies that said they want to start with application transformation should reconsider their strategy. All in all, transformation efforts in all three areas must go hand in hand and be planned jointly by all departments from the start. In such a scenario, companies will benefit from their cloud transformation right from the outset.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Slack hands more power to large company admins


Bobby Hellard

14 Aug, 2019

Slack has revealed a set of features for admins that make it easier to manage organisations with large employee counts and busy channels.

The biggest change is that admins can now assign posting permissions more widely than a few select channels, and there is also a new set of APIs to automate the creation of workspaces with names, domains and descriptions.

«We believe this should be easier and today we’re introducing a couple of new features to do just that,» the company said in a blog post.

It comes a week after the company introduced more robust security measures for admins, including the ability to enforce data sharing limits and content blocks on certain devices, as well as a greater variety of two-factor authentication checks.

To start with, the announcement channels will create a single destination for the key information, so teams no longer have to decide what gets shared via email instead of what gets shared via Slack.

«We’ve long encouraged teams to send announcements in channels, where your employees are already working,» the company said. «To broadcast those updates clearly and without distraction, admins have always been able to limit posting permissions in the default ‘general’ channel. Now, for teams on our Plus or Enterprise Grid plans, we’re allowing users to set posting permissions for any channel.»

These come in the form of ‘granular’ controls which limit who can post in a channel and keep chatter to a minimum, leaving the space clear for the most important updates.

As for the new admin APIs, there will be a feature to invite thousands of members at a time, without the need to join the workspace themselves. Invite guest accounts to specific channels (including private ones), set a guest expiration date and customise a welcome message, delegate admin responsibilities to a specific member and automatically trigger the events above based on information collected via web forms.

«All these APIs work towards templated workspace creation and setup,» the company said. «In the future, admins can script the creation of new workspaces that will automatically be configured with their desired settings, content, apps and more.»

Microsoft and Reliance Jio team up in 10-year cloud deal to ‘transform Indian economy and society’

Indian network operator Reliance Jio has announced a 10-year partnership with Microsoft to utilise and promote Azure and ‘accelerate the digital transformation of the Indian economy and society.’

The alliance will comprise a variety of initiatives. Jio will move its non-network applications to Azure, as well as set up data centres across India with Azure housed there. The telco’s internal workforce will be supplied with the Microsoft 365 collaboration suite, while Jio’s connectivity infrastructure will promote the adoption of Azure as part of the company’s cloud-first strategy.

The move will extend beyond Jio internally to its customer base; startups will have greater access to cloud infrastructure, while Indian SMBs will have access to a range of cloud-based productivity apps. For larger organisations, the companies state that new Jio solutions can be leveraged which work with Microsoft offerings already in use.

“In combining efforts, Jio and Microsoft aim to enhance the adoption of leading technologies like data analytics, AI, cognitive services, blockchain, Internet of Things and edge computing among small and medium enterprises to make them ready to compete and grow, while helping accelerate technology-led GDP growth in India and driving adoption of next-gen technology solutions at scale,” the companies said in a statement.

India’s role in the cloud computing ecosystem is an interesting one. The country’s potential is unmistakable; a report last November argued more than one million cloud jobs will be created in India by 2022 while figures in April suggested the overall cloud computing market will break $7 billion by the same year.

Yet glaring weaknesses remain. The most recent report from the Asia Cloud Computing Association (ACCA) last April ranked India only above China and Vietnam in its 14-nation ranking of best cloud nations within Asia Pacific. Many of India’s problems are similar to China’s – the country’s vast expanse means that while certain areas are prosperous, the overall score for connectivity, sustainability and data centre risk are low.

The ACCA report noted at the time that one of the key areas where India could gain leverage is through its tech-literate workforce to improve its attractiveness as a data centre hub. It is however a slow process. “Cloud infrastructure is the weakness that is weighing India down,” the report noted. “Lack of access to quality broadband and sustainable power remain serious issues throughout India, making it difficult for even the most polished security and governance frameworks to drive cloud adoption.”

Figures from Synergy Research last June showed that across APAC, AWS remained the leading public cloud provider, with Alibaba breaking the Microsoft stranglehold on second place – primarily down to Chinese dominance. Satyajit Sinha, an analyst at Counterpoint, told the Economic Times that the Jio and Microsoft team up would require AWS and Google to come up with ‘new, perhaps cheaper’ pricing models for the Indian market.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

How public cloud will become the driving force for connected cars

Opinion The cars we drive today are very different to the first models introduced in the late 1800s. Every aspect of the driving experience has evolved, innovating to meet customer needs, industry standards and to ensure passenger safety. Our new cars now offer voice assistants, can be fuelled by electric power, and typically include satellite navigation and collision detection as standard.

It’s time for the next stage of innovation, which will make the cars of the future very different to the ones we have today. this phase includes the introduction of autonomous and connected cars, which are integrated with the public cloud.

As we embark on this period of cloud-based automotive development, data security and privacy must be at the heart of everything we do. Car manufacturers will collect more and more data about us through cloud applications, just as the mobile phone providers do, the question will be: who controls that data? More to the point, who has access to that data? After all, our cars could tell a hacker where we live, where we work, the route we take and when and where we shop…

Consumers, governments and businesses alike are all waking up to the importance of secure, private data usage, so car manufacturers have an opportunity to build compliance in from the get-go.

Key challenges for automotive manufacturers creating connected cars are extracting the huge amount of data from the multitude of sensors on modern-day vehicles, augmenting that data for additional value, anonymising it for GDPR compliance, storing it and presenting it in a format that data scientists can analyse. Public cloud is an ideal solution, providing flexibility, scale, agility and security.

Data-driven cars

As the now-famous quote says, “data is the new oil.” It’s valuable, but if unrefined it cannot be used –the autonomous vehicle must be fed by structured data.

So what if all this data that is now collectable from our connected cars? Off-car analysis for the manufacturer’s gain is one thing, but how could this be put to good use to input into an intelligent city transport system, for example?  Will Audi, BMW, Mercedes, Lexus, VW, JLR all share the data from their connected cars for the greater good of a more intelligent public-use transport system? Only time will tell.

It’s an exciting time for the automotive industry. The basic design of a car hasn’t changed for decades, but it’s now time for the industry to evolve at speed. Of course, there will always be concerns over privacy risks. It’s vital that the industry takes these concerns seriously and puts security at the heart of evolution.

There’s a real opportunity for all vehicle manufacturers to improve their customer experiences through data-driven cars. Not only can these cars help travel experiences through integrated car and traffic management solutions, but they can additionally benefit society through reduced pollution.

The first car models from the 1800s seem basic to modern consumers, and it’s exciting to think that today’s electric, voice-assisted vehicles may spur the same reaction in the future. 

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Analysing Microsoft Azure Dedicated Host and licensing changes: Risk, rage, and reward

Microsoft is modifying some of its Azure licensing terms for dedicated hosted cloud services, with a knock-on effect of making services more expensive for customers of Amazon Web Services (AWS), Google and Alibaba Cloud.

The move coincides with Microsoft launching Azure Dedicated Host, a service that enables users to run Linux and Windows VMs on single-tenant physical servers.

The overall rationale for the service was outlined by the Azure team in a blog post. “The emergence of dedicated hosted cloud services has blurred the line between traditional outsourcing and cloud services, and has led to the use of on-premises licenses on cloud services,” a post read. “Dedicated hosted cloud services by major public cloud providers typically offer global elastic scale, on-demand provisioning and a pay-as-you-go model, similar to multi-tenant cloud services.

“As a result, we’re updating the outsourcing terms for Microsoft on-premises licenses to clarify the distinction between on-premises/traditional outsourcing and cloud services and create more consistent licensing terms across multi-tenant and dedicated hosted cloud services.”

Starting from October, customers who buy on-premises licenses without ‘software assurance and mobility rights’ cannot be deployed with dedicated hosted cloud services offered by the three big competitors, including VMware Cloud on AWS. Microsoft added these changes did not apply to other providers.

Owen Rogers, research vice president for digital economics at 451 Research, noted an example of the potential change. “Back when Azure didn’t offer dedicated hosts, some AWS customers installed Windows Server Datacenter on an AWS dedicated host – as a result, all virtualised operating systems on the host were licensed to run Windows Server, from the single host license, which aided migrations and license management plus lowered costs,” Rogers told CloudTech.

“Now Microsoft is saying you won’t be able to install Windows Server on a dedicated host at all, unless you use Azure.”

It is safe to say that AWS responded to the news with claws out. Writing on LinkedIn Sandy Carter, AWS vice president, argued the announcements “certainly seem like they’ve been taken from the old guard software vendor playbook.” Amazon CTO Werner Vogels was similarly dismissive, writing on Twitter.

Carter cited eMarketer as an example of a customer which had begun its digital transformation journey on Azure but had moved to the other side. “The cloud enables your company’s agility and innovation. Do you really want to bring along the licensing baggage of the old world, especially if those rights continue to change?” wrote Carter. “At AWS, our goal is to provide our customers with choice.”

Choice at what cost, however? This statement may raise the odd eyebrow for those who have been monitoring the recent rumbles around open source and big cloud providers. MongoDB, Confluent and Redis Labs were three companies who had modified their licensing because of major cloud providers who ‘take the open source code, bake it into [their] cloud offering and put all their own investments into differentiated proprietary offerings’, as Confluent co-founder Jay Kreps put it last year.

Redis CEO Ofer Bengal told this publication in February that, aside from AWS, ‘the mood [was] trying to change’, inferring that partnerships between open source cos and big clouds were on the horizon. Lo and behold, less than two months later, Google Cloud announced partnerships with seven open source vendors – including all of the above.

“[The move] is controversial because Azure is restricting freedom of choice regarding where its software can be hosted, and is using its software to undercut its competition,” added Rogers. “Many will say this is just good business sense – Microsoft has invested billions in its software and services over the years, why shouldn’t it use its assets to capitalise on the opportunity? Others will say that some enterprises will have to pay more as a result without getting more value in return.

“The risk is that this move doesn’t encourage customers to move to Azure, but rather encourages customers to migrate to Microsoft’s competitors’ services,” added Rogers.

Ultimately, both sides appear to be looking out for number one – an understandable position given the long-standing supersonic growth from the hyperscale clouds appears to be on the wane. As Synergy Research puts it, this is more the ‘law of large numbers’ taking its inevitable effect – but perhaps the well-known proverb around stones and glass houses may also apply.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Microsoft slammed over changes to cloud licensing


Bobby Hellard

9 Aug, 2019

Senior executives from AWS and Google Cloud have hit out at Microsoft for changing how it charges customers using its software on other public clouds.

Some are even accusing Microsoft of trying to lock customers into a single vendor with a complex pricing structure.

From 1 October, Microsoft customers will have to pay additional fees if they want to run its software on AWS, Google or Alibaba cloud environments due to a change to its on-prem licences.

AWS CTO Werner Vogels took to Twitter to slam the change, saying: «Yet another bait+switch by $MSFT, eliminating license benefits to force MS use. 1st, MS took away BYOL SQL Server on RDS, now no Windows upgrades w/BYOL on#AWS. Hard to trust a co. who raises prices, eliminates benefits, + restricts freedom of choice.»

Google Cloud’s president, Robert Enslin, posted a tweet that suggested Microsoft was harking back to its old ways.

«Shelf-ware. Complex pricing. And now vendor lock-in. Microsoft is taking its greatest hits from the ’90s to the cloud,» he wrote.

AWS VP Sandy Carter said in a post that Microsoft was ‘awkwardly’ trying to force customers into Azure with the license change.

Carter said that Microsoft seemed to be taking from the «old guard software vendor playbook». Firstly, by trying to put an end to Bring Your Own License (BYOL) for Windows Server purchased after October 1, 2019. She said that it would restrict customers ability to bring their own purchased licenses to their preferred cloud when using licenses purchased after the change comes into force.

She also accused Microsoft of trying to limit choice around SQL Server.

«If you are running SQL Server on the AWS cloud with Dedicated Host without software Assurance (SA) (which is allowed today) and want to upgrade to a newer version after October 1, you would be required to purchase a new SQL Server license with SA,» she explained.

Until now, Microsoft customers were allowed to use the same licence if they wanted to move a workload from an on-premise environment to a single-tenanted public cloud server.

«The emergence of dedicated hosted cloud services has blurred the line between traditional outsourcing and cloud services and has led to the use of on-premise licences on cloud services,» it said in a blog.

«As a result, we’re updating the outsourcing terms for Microsoft on-premise licences to clarify the distinction between on-premise/traditional outsourcing and cloud services and create more consistent licensing terms across multi-tenant and dedicated hosted cloud services.»

Customers now wanting to run Microsoft software on single-tenant cloud servers of AWS, Alibaba, Microsoft and Google will have to pay additional fees on top of the standard licensing.

Alastair Pooley, CIO at Snow Software, argues that the changes will almost certainly bring added complexity for customers.

«Microsoft’s recent change to licensing rules impacts the ability to «bring your own license» to dedicated cloud environments. If you are using the more common shared compute instances this will not affect you. Higher security or performance needs have led some companies to choose to be the only tenant on a physical machine and for those customers this will likely increase their costs and add complexity to their Microsoft licensing.

IT Pro has contacted Microsoft for comment

Why it’s time to make continuous cloud security part of your developer journey

Cloud computing hasn’t always been synonymous with great security. However, despite early fears that it was less secure than data centres, the cloud is now considered a useful – and secure – solution for most critical business functions. While some of its earliest adopters could afford to be somewhat blasé about security, that’s no longer the case. The latest generation of cloud entrants mainly operate in finance and government sectors, meaning that security and compliance are at the very top of their agendas.

This emphasis on cloud security has also been sped up by the series of significant data breaches which have affected consumers in recent years. Security has been thrown into the legal spotlight more than ever before too, particularly after GDPR was introduced in Europe, giving strict regulation for businesses to either comply with or face direct consequences.

But while the development and operations departments of businesses have largely embraced the dynamic world of the cloud, for the security team it presents a whole new set of challenges. They no longer work with controlled environments that they can carefully assess and manage as they did before. Instead, with cloud platforms and application code so tightly integrated, development teams must now incorporate security requirements into their code itself to enforce in the platform.  

As cloud platforms often change daily, the potential risk of a misconfiguration is significant. According to Gartner analysis, by 2020, 80 percent of cloud breaches will be due to customer misconfiguration, mismanaged credentials, or insider theft – not cloud provider vulnerabilities. 

Solutions do now exist that can help the security team with these challenges. These solutions allow them to define their policies (PCI-DSS, CIS, NIST, HIPAA) against the cloud environments and, then, to present them to the development team in a concise way.

Reducing the unnecessary overheads incurred in maintaining security policies can aid an organisation enormously. It lowers the risk of misinterpretation, narrows the margin for human error, and allows the development team to work safely within the guardrails established by the security team. This means that they do not constantly need to be aware of the latest changes on the cloud platform and how they correspond to the written security policies. Free from their security role, they can code without wading through pages of policy.

At my organisation, we faced this exact challenge. We found that the existing tools for multi-cloud environments were poor and that any remediations were lacking. In order to address these gaps, we created a solution named Cloud Security Guardian (CSG) and, now, our workflow follows a clearly-defined pattern:

  • Deployment: Stand up a new Azure subscription or AWS account 
  • Permission: Create the IAM controls and give them to security teams to allow them to configure CSG in order to inspect the new environment
  • Definition: The security team can create or apply the compliance policies that they require the cloud solutions to meet. This can be easily changed as the environment expands or as the compliance requirements evolve
  • Building: The development team can now start making their cloud deployments into the environments. For these initial ones, the developers can focus on function as this will be evaluated in real time. 
  • Consumption: Query CSG via the API and find out exactly where that new deployment fails to match the security policy. If the deployment matches it perfectly, then you now have the report to prove it.
  • Remediation: If there is at least one thing to remediate, the violations can be fixed with another quick call. The corrected template can then be pulled back into the repo or the API can provide the JSON to integrate independently. (Those who like GUIs can review the alerts and remediate from the GUI instead)
  • Report: As the project progresses, the reports can be shared with stakeholders. These can prove invaluable when performing risk analysis and will assist with sprint planning because they show which areas should be focused on

For developers, this process provides information throughout the entire integration cycle. It can point out the risks in smoke, make quick remediations in UAT, or provide validation in staging. Once in production, this could then be handed over to the operations team to monitor for manual changes or for configuration drift.

Of course, the security team can use this tool too. It allows them to have an immediate overview of the security of all cloud environments and to keep an eye on short-lived environments in order to assess the risk they may have presented as well. Once the security team can view the system’s entire infrastructure, they can easily see how its components interconnect and identify its weak points. 

When it comes to carrying out company-wide reviews of security practice, it allows the security team to quickly make a report on compliance status at any given point in time. It also provides them with a full audit trail. Every change made to the system can be monitored in real time and alerts can be sent to Slack, Sumo Logic, or email whenever something falls out of compliance. 

Making continuous security part of the cloud lifecycle can benefit a company’s security and development teams in equal proportion. It allows them to operate the cloud environments and to manage their compliance requirements as one joined entity using the methods that best suit each team.  

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

How AWS certifications are increasing tech salaries by up to $12k per year

  • AWS and Google certifications are among the most lucrative in North America, paying average salaries of $129,868 and $147,357 respectively
  • Cross-certifying on AWS is providing a $12K salary bump to IT professionals who already have Citrix and Red Hat/Linux certifications today
  • Globally, four of the five top-paying certifications are in cloud computing

These and many other insights of which certifications provide the highest salaries by region of the world are from the recently published Global Knowledge 2019 IT Skills and Salary ReportThe report is downloadable here (27 pp., PDF, free, opt-in). The methodology is based on 12,271 interviews across non-management IT staffs (29% of interviews), mid-level professionals including managers and team leads (43%), and senior-level and executive roles (28%) across four global regions. For additional details regarding the study’s methodology, please see page 24 of the report.

Key insights from the report include the following:

Cross-certifying on AWS is providing a $12K salary bump to IT professionals who already have Citrix and Red Hat/Linux certifications

Citrix certifications pay an average salary of $109,546 and those earning an AWS certification see a $12,339 salary bump on average. Red Hat/Linux certification-based jobs pay an average of $113,165 and are seeing an average salary bump of $12,553.  Cisco-certified IT professionals who gain AWS certification increase their salaries on average from $101,533 to $111,869, gaining a 10.2% increase. The following chart compares the salary bump AWS certifications are providing to IT professionals with seven of the more popular certifications (please click on the graphic to expand for easier reading).

AWS and Google certifications are among the most lucrative in North America, paying average salaries of $129,868 and $147,357 while the most popular are cybersecurity, governance, compliance, and policy

27% of all respondents to Global Knowledge’s survey have at least one certification in this category. Nearly 18% are ITIL certified. In North American, the most popular certification categories beyond cybersecurity are CompTIA, Microsoft, and Cisco. The following table from the report provides an overview of salary by certification category (please click on the graphic to expand for easier reading).

AWS Certified Solutions Architect – Associate is the most popular AWS certification today, with 72% of respondents having achieved its requirements

Certified Solutions Architect – Associate leads the top five most commonly held AWS certifications today according to the survey. AWS Certified Developer – Associate (33%), AWS Certified SysOps Administrator – Associate (24%), AWS Certified Solutions Architect – Professional (16%) and AWS Certified Cloud Practitioner round out the top five most common AWS certifications across the 12,271 global respondents to the Global Knowledge survey.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Microsoft contractors listen to Skype Translator recordings


Bobby Hellard

8 Aug, 2019

Contractors working for Microsoft are reportedly listening to personal Skype calls made using the app’s translation function. 

The video calling platform’s website does say that the company may analyse audio of translated phone calls in order to improve the service but it doesn’t state that this will be done by humans. However, through obtaining some Skype audio recordings and accounts of the human listening situation from unnamed Microsoft workers, Motherboard reported that the contractors are allegedly listening to personal conversations made through Skype. 

It is also reported that these contractors are reviewing recordings of voice commands made to Microsoft’s Cortana, which is currently a controversial trend with tech companies. Both Amazon and Google came under fire recently for reports that revealed workers were reviewing Alexa and Google Assistant recordings – Amazon later introduced a setting for users to disable human reviews.

The issue with it, however, isn’t that humans are listening to the device, but that it isn’t made clear in the terms and conditions. Skype Translator Ts&Cs state: «When you use Skype’s translation features, Skype collects and uses your conversation to help improve Microsoft products and services. To help the translation and speech recognition technology learn and grow, sentences and automatic transcripts are analysed and any corrections are entered into our system, to build more performant services.»

While it does state that it collects recordings to improve the service, it doesn’t explicitly say that these recordings are reviewed by humans contractors. Likewise, Microsoft’s own privacy statement also fails to make this crystal clear.

In July, after an unnamed Google worker leaked details to a Belgian public broadcaster about how the company reviews recordings made on its smart speaker, the tech giant responded in a blog post defending the practice.

As GDPR expert lawyer Frank Jennings told IT Pro at the time, speech recognition has progressed so far that we don’t expect humans to be involved at all, but there is still an obligation to be clear on the matter.

«While asking humans to assist with language recognition and booking fulfilment is a ‘legitimate purpose’ under GDPR, the real question is whether Google is doing so in a ‘transparent manner’ and for ‘specified and explicit purposes’,» said Jennings. 

While home speakers like Alexa and Google Assistant raise questions over privacy in the home, the reports of Skype Translator recordings present a potential worry for businesses.

«We strive to be transparent about our collection and use of voice data to ensure customers can make informed choices about when and how their voice data is used,» a Microsoft spokesperson said to IT Pro in an email. «Microsoft gets customers permission before collecting and using their voice data. We also put in place several procedures designed to prioritise users privacy before sharing this data with our vendors, including de-identifying data, requiring non-disclosure agreements with vendors and their employees, and requiring that vendors meet the high privacy standards set out in European law. We continue to review the way we handle voice data to ensure we make options as clear as possible to customers and provide strong privacy protections.» 

Which, again, still doesn’t explicitly say ‘humans’ are involved in this process.