With help from Eric Geller, Martin Matishak, Melissa Heikkil, Cristiano Lima and Daniel Lippman
Editors Note: Morning Cybersecurity is a free version of POLITICO Pro Cybersecuritys morning newsletter, which is delivered to our subscribers each morning at 6 a.m. The POLITICO Pro platform combines the news you need with tools you can use to take action on the days biggest stories. Act on the news with POLITICO Pro.
Advertisement
A coronavirus contact-tracing initiative from Apple and Google has some privacy and security landmines to navigate.
An advocacy group urged the Federal Energy Regulatory Commission to move ahead with cybersecurity standards despite calls to move back the timing.
A top U.N. official called for a digital cease-fire as the world contends with coronavirus, especially because of the need to safeguard health care organizations and employees.
HAPPY MONDAY and welcome to Morning Cybersecurity! So relatable. If a hacker gets a hold of a Zoom, what can they tell? Send your thoughts, feedback and especially tips to [emailprotected]. Be sure to follow @POLITICOPro and @MorningCybersec. Full team info below.
POLITICO Pro is here to help you navigate these unprecedented times. Check out our new Covid-19 Coverage Roundup, which provides a daily summary of top Covid-19 news coverage from across all 16 federal policy verticals as well as premium content, such as DataPoint graphics. Please sign up at our settings page to receive this unique roundup sent directly to your inbox every weekday afternoon.
Sign up for POLITICO Nightly: Coronavirus Special Edition, your daily update on how the illness is affecting politics, markets, public health and more.
TRACKING DOWNSIDES A joint Apple-Google project to track coronavirus exposure risks announced last week has sparked privacy and security fears even as some lawmakers are willing to give the tech giants some leeway. Tech companies new feature to contact trace coronavirus cases has positive potential, but we must ensure privacy concerns are considered, tweeted House Energy and Commerce Chairman Frank Pallone (D-N.J.). Ill be following this closely to ensure consumer privacy is protected. Rep. Jan Schakowsky (D-Ill.), who chairs E&Cs consumer protection subcommittee, echoed the sentiment.
Some security experts said that although the plan features safeguards, they arent adequate given the nature of the information at play. Phone data has NEVER been proven secure and the chance of release is above 0%, observed Sergio Caltagirone, vice president of threat intelligence for Dragos. In fact, this is so juicy I'd argue there will be lots of baddie[s] who are interested in finding ways to leak this. Matt Tait, a cyber fellow at the University of Texas at Austin, spelled out a slew of other potential problems.
Jennifer Granick, surveillance and cybersecurity council for the ACLU, credited the two companies for steps to mitigate risk but said there was room for improvement. These systems also cant be effective if people dont trust them, she said. People will only trust these systems if they protect privacy, remain voluntary, and store data on an individual's device, not a centralized repository.
Former Vice President Joe Biden, the presumptive Democratic nominee, broadly touched on the issue in his newly released proposal to safely reopen America. In a New York Times op-ed outlining his plan, Biden calls for a contact tracing strategy that protects privacy. And Apple and Google reportedly will work with the U.K., too.
NOT SO SLOW The coronavirus pandemic isnt a reason to significantly delay supply chain cybersecurity standards for electric grid utilities, the grid resilience advocacy group Protect Our Power told FERC late last week. The North American Electric Reliability Corp. wants FERC to delay the deadline for complying with the cyber rule and other new regulations, saying compliance could disrupt operations at a critical time. But in comments filed Thursday with FERC, Protect Our Power said NERCs requested three-month delay may not be justified or necessarily be in the public interest. Instead, it asked FERC to only grant a 30-day extension. This approach would acknowledge the time lost by utilities due to the coronavirus pandemic, the group said, but otherwise require the industry to continue to treat the supply chain security issue with the importance and seriousness it deserves.
In requesting a 90-day delay, NERC argued that the extra time would allow entities to recover from coronavirus-related strains, but Protect Our Power said such a long recovery window likely wasnt necessary. Given that FERC issued the supply chain standard 15 months ago, the group said, many or most utilities may already be prepared to comply with it by the current July 1 deadline. A shorter delay, it said, would also prevent us from having one crisis, the pandemic, unnecessarily cause us to lose focus and a sense of urgency about another crisis, supply chain risk.
CYBER CEASE-FIRE The United Nations undersecretary-general on Friday published an op-ed calling for a worldwide digital cease-fire during the coronavirus pandemic. When launched successfully, digital attacks are catastrophic and can lead to loss of life, wrote Fabrizio Hochschild. In particular, health care workers and hospitals battling Covid-19 shouldnt have to question whether their data and medical equipment is secure or worry about it being shut down. We must commit to an immediate digital cease-fire, and governments, civil society groups, and the private sector must set the tone. Without this step, our global response to the pandemic will be weakened, according to Hochschild.
ALL I WANNA DO IS ZOOM-A-ZOOM-ZOOM-ZOOM The top Republican on the House Oversight panel on Friday called for majority Democrats to abandon usage of the Zoom video conferencing service, citing security issues. Given the concerns surrounding Zooms security, it is clear Zoom is not an appropriate platform for Committee business, which may be particularly sensitive during the COVID-19 pandemic, wrote Rep. Jim Jordan (R-Ohio). Please immediately suspend any current or future use of Zoom systems for official committee activities and take immediate steps to evaluate the Committees internal cybersecurity preparedness to prevent hackers from accessing sensitive committee information through the Zoom platform.
Jordan cited the Senate sergeant at arms warning last week for offices to stop using it, broader hacking and malware concerns, and Zoom work done by employees in China as causes to suspend use. Jordan said House Oversight Democrats had been Zoom-bombed, something Democrats denied.
Rep. Jordans office was consulted directly and repeatedly about using Zoom and never raised any concerns, so its unfortunate that he is now putting out inaccurate information in this public letter, said Chairwoman Carolyn Maloney (D-N.Y.). Had his office consulted with us first, we could have clarified their misunderstandings and provided more information about the steps the Committee has already taken to address any potential issues. She said the committee would continue to use a number of different technologies to fulfill its responsibilities. The House was already reevaluating whether the chamber should switch to a government-specific form of Zoom.
EDGAR RIGHT The SEC announced last week that it has settled charges with two traders accused of profiting by exploiting sensitive corporate earnings information hacked from its EDGAR system. David Kwon of California settled for $165,474 that represented the profits from his alleged illegal trades, and $16,254 in interest; Igor Sabodakha of Ukraine settled for $148,804 in profits, prejudgment interest of $20,945 and a civil penalty of $148,804, plus the SEC said it would dismiss charges against his wife, Victoria Vorochek, whose accounts he allegedly used to conduct trades.
The EDGAR hack generated considerable interest from Congress when the SEC disclosed it in 2017, with some lawmakers pointing to their prior concerns about SEC vulnerabilities. The SEC charges against seven individuals and two entities filed in 2019 were accompanied by criminal charges against two other men.
CRITICAL SAFETY AND PRIVACY FLAWS IN CONNECTED CARS Drivers beware: Your rides are vulnerable to digital saboteurs. Some of Europes most popular connected car models have crucial security flaws that allow intruders to access personal data such as passwords and location history as well as components that control key functions such as collision-warning systems and tire air pressure, according to an investigation by British consumer group Which?.
By lifting the Volkswagen badge on the front of the car, researchers say they were able to access the vehicles front radar module, which controls its collision-warning system, according to our friends at POLITICO Europes Cyber Insights. Using a cheap laptop and a 25 gadget bought from online marketplace Amazon, the researchers also hacked into the Ford Focus system monitoring air pressure in tires. The investigators also got access to personal data such as Wi-Fi passwords, phone contacts and location history.
TWEET OF THE WEEKEND And then Zoom keeps doing stuff like this.
Kevin Zerrusen is now a managing director at EY where he works on cybersecurity and advisory services. He most recently was senior adviser to the chairman for cybersecurity policy at the SEC and is also a Goldman Sachs alum and served in the CIA for 30 years.
POLITICO: Small business loan effort might be less generous than advertised.
The Wall Street Journal: After Congress allowed surveillance tools to lapse, DOJ hasnt been able to obtain wiretaps or request business records between five and 10 times.
The Wall Street Journal: The FBI made errors in two FISA application filings last year.
Forbes: Cryptocurrency scammer revenue is down during the pandemic.
CyberScoop: Cyber criminal forums are also offering discounts during the pandemic.
Register: Cyber criminals leaked sensitive documents from contractors for Boeing, SpaceX, Tesla and other major companies in retaliation for an unpaid ransomware demand.
The Wall Street Journal: Travelex paid a $2.3 million ransom to hackers.
Bleeping Computer: San Francisco International Airport had a data breach.
gCaptain: Mediterranean Shipping Company may have suffered a cyberattack.
ZDNet: Online betting company SBTech will have to place $30 million in escrow as insurance for covering the fallout from a suspected ransomware infection.
Inside Cybersecurity: Two industry groups want more details from the Pentagon on its cybersecurity standards for contractors.
Forbes: Big data firm Palantir got some coronavirus emergency relief funds.
The New York Times: Burning Cell Towers, Out of Baseless Fear They Spread the Virus.
Thats all for today.
Stay in touch with the whole team: Eric Geller ([emailprotected], @ericgeller); Bob King ([emailprotected], @bkingdc); Martin Matishak ([emailprotected], @martinmatishak); and Tim Starks ([emailprotected], @timstarks).
See more here:
The security issues with the Apple/Google virus tracking project - Politico
- Is Google Advertising Revenue 70%, 80%, Or 90% Of Alphabets Total Revenue? - Forbes [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Google My Business Photos Being Added To Google Posts Without Option To Delete - Search Engine Roundtable [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Even amid the affluence of tech capital in Silicon Valley, local news struggles - CNBC [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Where in the world was Santa? It depended on which online tracker you were following - The Boston Globe [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Huawei, Facebook, and Oracle Put Pressure on Google - Market Realist [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Huawei and Google Diverge in Their Treatment of ToTok - Market Realist [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Google Maps: Aftermath of plane crash in Somalia discovered - what happened? - Express [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Why Apple, Google, and other big tech companies create their own fonts - Mashable [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- ProBeat: Google only updated Android distribution data once in 2019 - VentureBeat [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- 10 things to try with your new Google Nest smart speaker - VentureBeat [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Google workers exposed to chemical that causes birth defects - City A.M. [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- The most popular products of 2019, according to Google - TODAY [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Google Chromes five security features that every user should know - Hindustan Times [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Googles YouTube Goes To War With Bitcoin And Crypto [Updated] - Forbes [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Google is poised to make another blitz at CES 2020 - CNET [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- These Were The Top Google Searches And Trends Of 2019 - Forbes [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Google Search now lets you add movies and shows to a 'Watchlist' - Engadget [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- 31-year-old Google executive says reading this one book has had a huge influence on her career - CNBC [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Obama praises book that slams his White House for its Google relationship - Mashable [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Why Google was the most important brand marketer of the 2010s - Fast Company [Last Updated On: December 30th, 2019] [Originally Added On: December 30th, 2019]
- Amazon and Facebook Are the Most 'Evil' Tech Companies, According to Experts. Google Isn't Far Behind - Inc. [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Google Rich Results testing tool now reports on unloadable embedded resources - Search Engine Land [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Google Assistant routines haven't worked on Android Auto for over a year, still no fix in sight (Update: Google acknowledges) - Android Police [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Jussie Smollett is probably toast now that Google is handing his data to the special prosecutor - Washington Examiner [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Americans trust Amazon and Google more than the police or the government - MarketWatch [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Using Google Authenticator? Here's why you should get rid of it - ZDNet [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Googles hidden AR tool will blow your mind - Creative Bloq [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Kids, Want to Win a $30,000 Scholarship and Show Your Art to Billions? Googles Annual Doodle Contest Is Now Open - artnet News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- 1 Reason 2020 Will Be a Big Year for Google and Facebook - The Motley Fool [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Google Health Exec Defends Controversial Partnership With Ascension: Were Super Proud Of It - Forbes [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Labs arrive in Google app to let you experiment with features like pinch-to-zoom - 9to5Google [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Sorry, Alexa and Siri, but only Google Home can do these 5 things - CNET [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Kittle photobombed by The Rock in roster Google search - NBCSports.com [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- This Is How Your iPhone Is A Cool New Way To Access Google - Forbes [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Googles Takeover of Fitbit Faces Another Regulatory Hurdle - Motley Fool [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Google Health VP on Ascension partnership: 'The press has made this into something it's not' - Healthcare IT News [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Google Maps keeps a detailed record of everywhere you go here's how to stop it - CNBC [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Will Googles more-efficient Reformer mitigate or accelerate the arms race in AI? - ZDNet [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Rachel Bovard: Congress has a role to play in regulating Google - Home - WSFX [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Why Google added little logos next to search results this week - CNBC [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Report: Google wants to bring the Steam game store to Chrome OS? - Ars Technica [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- BT partners with Google to bundle free Stadia with broadband deals in the UK - The Verge [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Google Play [Last Updated On: January 18th, 2020] [Originally Added On: January 18th, 2020]
- Google Photos app for Android will soon phase out the hamburger menu - GSMArena.com news - GSMArena.com [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- What Is Google Coral And Do You Need It? - Lifehacker Australia [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google and Amazon limit employees travel because of coronavirus fears - The Verge [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google, Toyota Tsusho invest in WhereIsMyTransport to map transport in emerging cities - TechCrunch [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- This Is Huaweis Alarming New Surprise For Google: Heres Why You Should Be Concerned - Forbes [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google and Microsoft offer free teleconferencing tools to combat coronavirus - TechRadar [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google bans on-site job interviews for the foreseeable future due to coronavirus - The Verge [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- AWS to double sales droids as Google, Microsoft's growing clouds threaten to gobble larger slices of Bezos' pie - The Register [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google's Exposure To Travel Will Impact Revenue, BofA Says - Benzinga [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google Cloud goes after the telco business with Anthos for Telecom and its Global Mobile Edge Cloud - TechCrunch [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Apple, Microsoft, Google look to move production away from China. That's not going to be easy - CNBC [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google will lose its John Legend Google Assistant voice on March 23rd - The Verge [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google and Microsoft are giving away enterprise conferencing tools due to coronavirus - The Verge [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Google Stadia now supports 4K streaming on the web - The Verge [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Star Engineer Who Crossed Google Is Ordered to Pay $179 Million to Company - The New York Times [Last Updated On: March 5th, 2020] [Originally Added On: March 5th, 2020]
- Why companies like Microsoft and Google are betting big on Africa - CNBC [Last Updated On: March 8th, 2020] [Originally Added On: March 8th, 2020]
- Google Announces A Coronavirus Incentive For G SuiteAnd Other Small Business Tech News - Forbes [Last Updated On: March 8th, 2020] [Originally Added On: March 8th, 2020]
- Microsoft, Google, and Twitter Are Telling Employees to Work From Home Because of Coronavirus. Should You? - Inc. [Last Updated On: March 8th, 2020] [Originally Added On: March 8th, 2020]
- Facebook, Google among those kicking some cash over to Silicon Valley communities affected by coronavirus cancellations - CNBC [Last Updated On: March 8th, 2020] [Originally Added On: March 8th, 2020]
- Google now giving away three months of Stadia access to Chromecast owners - The Verge [Last Updated On: March 8th, 2020] [Originally Added On: March 8th, 2020]
- Google location data turned a random biker into a burglary suspect - The Verge [Last Updated On: March 8th, 2020] [Originally Added On: March 8th, 2020]
- Apple, Google and others partner with Ad Council and US govt to expand coronavirus messaging - The Drum [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Google Has No Plans To Postpone Killing Third-Party Cookies In Chrome - AdExchanger [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Why Zoom is winning so much hype over Microsoft and Google - Business Insider [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Logged On From the Laundry Room: How the C.E.O.s of Google, Pfizer and Slack Work From Home - The New York Times [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Google cancels its infamous April Fools jokes this year - The Verge [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Google Tests Audience Buying In ADH, A Big Step From Analytics To Activation - AdExchanger [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Googles new Pixel Buds could hit spring release date, as they may have just hit the FCC - The Verge [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Google Removes Infowars Android App From Online Store Over Coronavirus Misinformation - Variety [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Cruising Through South Central Los Angeles With Google Street View : The Picture Show - NPR [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Google ups Duo group calling limit from eight to twelve - The Verge [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Outside China, Android isnt Android without Google - The Verge [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Google has banned the Infowars Android app over false coronavirus claims - The Verge [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- My top 3 Google Home pet peeves and how to fix them - CNET [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Google Unveiled a Massive Stimulus Program of Its Own - Inc. [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Facebook, Google and Twitter Struggle to Handle Novembers Election - The New York Times [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]
- Test and trace with Apple and Google - TechCrunch [Last Updated On: March 30th, 2020] [Originally Added On: March 30th, 2020]