Week in Review: LinkedIn’s AI chicanery, AT&T FCC settlement, Craigslist defense network
Sep 20, 2024
auto_awesome
Mike Rosen, CISO at ZwillGen and advisor to NightDragon, dives into LinkedIn's controversial use of user posts for AI training without consent, raising vital privacy concerns. He discusses AT&T's minimal penalties for data breaches and the dire need for improved vendor management. The conversation highlights rising threats like credential theft and innovative community solutions for cybersecurity, including a new volunteer network to support small businesses. Additionally, Rosen shares his insights on Starlink's ability to detect stealth aircraft and its implications for privacy.
LinkedIn's controversial practice of harvesting user-generated content for AI training underscores the urgent need for clearer data ownership and ethical usage policies.
The $13 million AT&T settlement highlights critical concerns surrounding vendor oversight and the accountability of corporations for third-party data security practices.
Deep dives
LinkedIn's Data Harvesting Controversy
LinkedIn has faced backlash after it was revealed that the platform harvested user-generated posts for AI training without obtaining consent from its users. This practice, discussed during the episode, compels a consideration of data ownership, as many users may not fully understand the implications of sharing content on social media platforms. The update to LinkedIn's privacy policy raises questions about the ethics of user data usage, as the opt-out features may not be sufficient to inform users of their options effectively. Experts express concern that this scenario exemplifies a growing trend where user data is treated as a commodity, often without transparency from service providers.
Ransomware Groups Uphold Thieves' Honor
Recent ransomware incidents highlighted a grim reality where threat actors flourish by following through on their threats after organizations refuse to pay ransoms. The episode references specific cases involving the Port of Seattle and Kawasaki Motors Europe, where stolen data was publicly released as punishment for non-compliance. The discussion emphasizes the dilemmas faced by organizations, which must weigh the risks of paying ransoms against the potential for data recovery and future vulnerabilities. This has led to a growing narrative that many organizations might view ransom payments as a necessary cost of doing business in an increasingly hostile cyberspace.
Significant Vendor Management Failures at AT&T
AT&T has recently entered into a $13 million settlement with the FCC due to a data breach involving a third-party vendor that compromised customer data from around 9 million accounts. The breach arose from the vendor's failure to adhere to contractual obligations that required the destruction or return of sensitive data once their contract ended. The episode points to the larger issue of inadequate vendor oversight within corporations, as well as the significant financial and reputational consequences that can ensue from such negligence. Experts argue for a shift in accountability, indicating that larger corporations must take greater responsibility for the security practices of their vendors to prevent future breaches.
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Rosen, CISO, ZwillGen, advisor to NightDragon and Villager at Team8, whose favorite story of the week was Starlink’s ability to detect stealth aircraft. Check it out.
Thanks to our show sponsor, Conveyor
Why do teams choose Conveyor over the competition for customer security reviews?
A few reasons.
One. Market-leading AI accuracy for any format of security questionnaire with limited knowledge base maintenance.Two. Enterprise-grade trust center that automates every customer security request.Three. Conveyor’s sales team is actually fun to work with.
Learn why Conveyor is the security review platform your infosec friends love at www.conveyor.com
All links and the video of this episode can be found on CISO Series.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode