TechLetters #179 DEFEND Open Internet Governance. Polyfill compromise. Backdooring AI/ML models in various ways. EU opens a Digital Markets Act probe about Apple
Internet, a great civilizational achievement, is under potential threat by the push for centralized control, as highlighted by the ongoing Global Digital Compact (GDC) negotiations which propose shifting from the traditional multistakeholder model to state-centric governance. This poses risks to the established, open framework that fosters global connectivity and free expression. Maintaining the processes that underscore the internet's significance is crucial. I am one of the 36 people involved in internet architecture and governance who have issued a letter advocating for the preservation of the internet’s principles
Security
Very popular library polyfill.js compromised. Potentially huge supply-chain risk. "taken over by a foreign actor identified as a Chinese-originated company, embedding malicious code in JavaScript assets". 100,000 websites impacted. Best solution: remove the library. It’s no longer needed in 2024.
Hacking AI/Machine Learning model the right way. Model targeting. Possibility to backdoor the model, or tamper with inference output. It can act as a logic bomb. „only use models from trusted organizations and rely on safer file formats”
Backdooring AI/LLM systems in undetectable ways. Banks and firms relying on AI must TRUST the AI/LLM model suppliers. AI security is based on trust.
Privacy
Technology Policy
European Commission is opening a first DMA case. A DMA case against Apple. "Breach of the Digital Markets Act". It is unclear of web browser issues are also formally included the case. There’s also a case against Microsoft for bundling Teams for Office users. Compliance with Digital Markets Act is tough because it's a new, not understood regulation (& more complex than GDPR). The safety rule of thumb for the moment: gatekeepers can't introduce new features for existing users. Sounds a bit absurd? Never mind about that. It’s as simple as “gatekeepers should better get a good advice”. My presentation at Brussels Academy for Global Privacy Law 2024 is Wednesday 3.07. I shed light on the DMA process.
EU Commission is probing Microsoft-OpenAI collaboration. Through the lens of competition practices and law. "Under the terms of Microsoft’s arrangement with OpenAI, Microsoft’s Azure is the exclusive cloud provider for OpenAI"
In case you feel it's worth it to forward this content further:
Subscribed
If you’d like to share: