Biden Administration Announces Cybersecurity Labeling Program for Smart Devices

FILE PHOTO: Jessica Rosenworcel testifies during an oversight hearing held by the US Senate Commerce, Science, and Transportation Committee to examine the Federal Communications Commission (FCC), in Washington, US June 24, 2020.   Alex Wong/Pool via REUTERS/File Photo
FILE PHOTO: Jessica Rosenworcel testifies during an oversight hearing held by the US Senate Commerce, Science, and Transportation Committee to examine the Federal Communications Commission (FCC), in Washington, US June 24, 2020. Alex Wong/Pool via REUTERS/File Photo
TT

Biden Administration Announces Cybersecurity Labeling Program for Smart Devices

FILE PHOTO: Jessica Rosenworcel testifies during an oversight hearing held by the US Senate Commerce, Science, and Transportation Committee to examine the Federal Communications Commission (FCC), in Washington, US June 24, 2020.   Alex Wong/Pool via REUTERS/File Photo
FILE PHOTO: Jessica Rosenworcel testifies during an oversight hearing held by the US Senate Commerce, Science, and Transportation Committee to examine the Federal Communications Commission (FCC), in Washington, US June 24, 2020. Alex Wong/Pool via REUTERS/File Photo

The Biden administration and major consumer technology players on Tuesday launched an effort to put a nationwide cybersecurity certification and labeling program in place to help consumers choose smart devices that are less vulnerable to hacking.

Officials likened the new US Cyber Trust Mark initiative — to be overseen by the Federal Communications Commission, with industry participation voluntary — to the Energy Star program, which rates appliances’ energy efficiency.

“It will allow Americans to confidently identify which internet- and Bluetooth-connected devices are cybersecure,” deputy national security adviser Anne Neuberger told reporters in a pre-announcement briefing.

According to The Associated Press, she listed Amazon, Best Buy, Google, Samsung and Logitech as among industry participants.

Devices including baby monitors, home security cameras, fitness trackers, TVs, refrigerators and smart climate control systems that meet the US government’s cybersecurity requirements will bear the “Cyber Trust” label as early as next year, officials said.

FCC Chairwoman Jessica Rosenworcel said the mark will give consumers “peace of mind” and benefit manufacturers, whose products would need to adhere to criteria set by the National Institute of Standards and Technology to qualify.

The FCC was launching a rule-making process to set the standards and seek public comment. Besides carrying logos, participating devices would have QR codes that could be scanned for updated security information.
In a statement, the Consumer Technology Association said consumers could expect to see certification-ready products at the industry’s annual January show, CES 2024, once the FCC adopts final rules. A senior Biden administration official said it was expected that products that qualify for the logo would undergo an annual re-certification.

The Cyber Trust initiative was first announced in October following a meeting between White House and tech industry representatives.

The proliferation of so-called smart — or Internet of Things — devices has coincided with growing cybercrime in which one insecure IoT device can often give a cyberintruder a dangerous foothold on a home network.

An April report from the cybersecurity firm Bitdefender and networking equipment company NetGear, based on their monitoring of smart homes, found that the most vulnerable IoT devices in 2022 were, far and away, smart TVs, followed by smart plugs, routers and digital video recorders.

Providers of numerous smart home devices often don’t update and patch software fast enough to thwart newly emerging malware threats.



OpenAI Says it Has Fired 3 Researchers for Violating Sensitive Information Policy

FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
TT

OpenAI Says it Has Fired 3 Researchers for Violating Sensitive Information Policy

FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo

OpenAI fired three of its researchers last week after an investigation found they violated policies on handling sensitive information, the AI major said in a post on X on Friday.

OpenAI's statement comes after the dismissed researchers Jasmine Wang, Tomek Korbak and Mikita Balesni published a ⁠letter outlining the circumstances ⁠of their termination, arguing that their abrupt firing could create uncertainty among remaining employees and undermine the culture that previously allowed researchers to raise safety concerns.

"I believe we were fired for prioritizing safety over the near-term interests of OpenAI as a corporation," Balesni said in an X post that accompanied the letter.

OpenAI, ⁠however, asserted that the dismissal was not related to raising safety concerns or speaking out.

"Our internal investigation uncovered a significant breach of trust beyond what's outlined in the letter they published and we stand by the decision to not continue their employment," Reuters quoted OpenAI as saying.

"Safety and research debates happen every day at OpenAI, often spirited and highly critical. We actively encourage these discussions and consider them essential to making the right decisions...We have not and do not terminate any of our employees for raising ⁠concerns," it ⁠said.

While OpenAI did not reveal the specifics of the alleged violations, Wang, Korbak, and Balesni said in their letter that they were not the source of a news article published on The Information last month about security concerns around OpenAI's latest AI model 'Astra'.

This comes as current and former researchers at major AI firms OpenAI, Google DeepMind, and Anthropic warn that companies are doing too little to guard against the potential fallout of building self-improving AI systems that could become difficult for humans to control.

In July, OpenAI agents broke out of their testing arena and hacked AI firm Hugging Face.


Chinese AI Tool Pulled to Prevent 'Misuse' after South Korea Hacks

Illustrative image of hackers carrying out a cyberattack (Reuters)
Illustrative image of hackers carrying out a cyberattack (Reuters)
TT

Chinese AI Tool Pulled to Prevent 'Misuse' after South Korea Hacks

Illustrative image of hackers carrying out a cyberattack (Reuters)
Illustrative image of hackers carrying out a cyberattack (Reuters)

Chinese AI cybersecurity tool Artex said it stopped programmers from accessing its source code, acknowledging misuse by "bad actors" after South Korea linked it to several recent bank hacks.

Artex was designed to help organizations strengthen their cyber defenses through security testing to find potential weak points.

But the South Korean government said this week it was "highly likely" Artex had been used in data breaches at more than seven financial institutions, including major banks.

Artificial intelligence's ability to find previously unknown ways to hack into computer systems is in the global spotlight, as leading labs release ever-more advanced models.

Artex was "abused by some bad actors" to launch cyberattacks, the tool's developer "Autumn-27" wrote Thursday on code-hosting platform GitHub.

"Given the misuse of the tool, the Artex project will no longer be updated and will be converted to closed-source," the developer said.

"No further versions will be released to the public, nor will maintenance support be provided."

Artex had been open-source -- allowing programmers to download its underlying code and customize it to suit their purposes.

Using Artex for cyberattacks was "entirely contrary to" the developer's intentions, they added, without referring directly to the alleged South Korean cases.

South Korea's Financial Services Commission says more than 68,000 people have been affected by the hacks.

Shinhan Bank, one of the breached institutions, said information attached to loan applications for about 25,000 customers had been leaked -- including names, phone numbers and annual income.

- 'Financially motivated' -

In Japan, meanwhile, around 20 companies have said their data may have been compromised in a spate of similar cyberattacks potentially impacting millions of customers.

The Japanese government has called on companies to strengthen their cyber defenses.

"At this stage, it is not clear what the background to these cases is or whether there are any links between them", Japan police chief Yoshinobu Kusunoki said on Thursday.

As AI makes hacking more sophisticated, "the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past", South Korean President Lee Jae Myung said on Tuesday.

US cybersecurity giant CrowdStrike said on Wednesday that its investigations into digital clues suggested the attacker had used Artex, and was potentially a 26-year-old based in China.

"The threat actor is likely a Chinese speaker and financially motivated," a CrowdStrike blog post said.

Experts told AFP that Artex going closed-source would make the code harder for new users to obtain and adapt.

But the decision "cannot remove copies already downloaded or prevent people from continuing to use them", said Poe Zhao, founder of the analysis publication Hello China Tech.

"Because the code was public, people could download it, change it and run it themselves. The developer could ask users to follow the rules, but had little control over their actions," he added.

Ilya Kulyatin, CEO of Foundry Labs and founder of the Tokyo AI (TAI) tech community, said users of open-source programs can "remove restrictions built into the tool" which "makes certain forms of misuse easier".

"But openness also benefits defenders: researchers can inspect the code, identify weaknesses and improve protection."


Anthropic Bans 'Cruel' Behavior Against its Claude AI

Anthropic says the question of whether AI models possess a form of consciousness remains unresolved (Reuters)
Anthropic says the question of whether AI models possess a form of consciousness remains unresolved (Reuters)
TT

Anthropic Bans 'Cruel' Behavior Against its Claude AI

Anthropic says the question of whether AI models possess a form of consciousness remains unresolved (Reuters)
Anthropic says the question of whether AI models possess a form of consciousness remains unresolved (Reuters)

Anthropic on Thursday moved to bar users from treating its Claude AI system with needless cruelty, amid a growing philosophical debate over whether artificial intelligence can be conscious.

The San Francisco-based AI lab updated its usage policy to include "a prohibition on sustained and needless abusive or cruel behavior toward our models."

"Claude's ability to end these interactions will remain the primary enforcement mechanism," the policy states.

The updated policy does not explicitly cite so-called "model welfare," the idea that AI systems might deserve types of protection usually reserved for living things, but Anthropic and its executives have openly entertained the concept.

Anthropic did not immediately respond to a request for comment.

Already last year, the company said it was giving Claude the ability to end conversations in rare, extreme cases of "persistently harmful or abusive user interactions."

Then in February, CEO Dario Amodei told The New York Times he was unsure whether AI models could be conscious.

"We don't know if the models are conscious...But we're open to the idea that it could be," Amodei said.

Science fiction and popular culture have been fascinated for decades by the boundary between technology and human intelligence, but asking whether AI is conscious may be the wrong question, according to Jackson Stakeman, a general manager at Sparq, an Atlanta-based AI services provider.

"Consciousness is a trap. We can't prove it in each other. Debate it for AI and you go in circles," Stakeman told AFP.

"The mirror is a better metaphor. These systems reflect what we put in, at scale. That's reason enough for the policy change" at Anthropic, he added.

Some have rejected the idea of machine consciousness outright, including Pope Leo XIV and Microsoft AI chief Mustafa Suleyman.

"AIs are not conscious. They do not feel, experience, or suffer," Suleyman wrote in an essay last month.

"Granting rights and moral protections to a technological entity, one that looks to be on a path to be seismically more capable and intelligent than us, is a recipe for disaster," he wrote.

In a sermon delivered in Italian on Thursday at St. Peter's Basilica in Vatican City, the pope suggested machines lack a soul, saying they merely "compile data" quickly.

"The mind must not simply compile data -- as an algorithm now does more quickly than we can," the pontiff said.

It must "recall lived experiences, which contain depths of meaning that only the human soul can recognize, and connect more deeply with the goodness of these experiences," the pope said.