Supplier Report: 11/30/2018

The haze of Thanksgiving and Black Friday is wearing off and several companies have found themselves with security issues.

Amazon, Venmo (Paypal) the United States Postal Service, and Microsoft have all been dealing with potential bugs and vulnerabilities (at various levels of severity).

Facebook continues to have exposure to social vulnerabilities – and things are getting tense: Sheryl Sandburg is rumored to be fearing for her job, but Mark Zuckerberg says she isn’t going anywhere (for now).

Artificial Intelligence

  • Lab-Grown Mini-Brains Spontaneously Produced ‘Human-Like’ Brain Waves for the First Time

    After the brain organoids had been growing in petri dishes for about six months, the researchers noticed that the electrical activity they were measuring was occuring at a higher rate than had ever been documented before in lab-grown organoids. Even more surprising, however, was that this electrical activity didn’t resemble the synchronized activity seen in mature human brains. Instead, the electrical patterns were chaotic, a hallmark of a developing brain.

    When Muotri and his colleagues compared the organoids’ electrical activity to that seen in premature babies, they found that it was strikingly similar to the patterns seen in babies born 25-39 weeks after conception.

    https://motherboard.vice.com/en_us/article/a3meza/lab-grown-mini-brains-spontaneously-produced-human-like-brain-waves-for-the-first-time

Cloud

  • Google’s cloud business under Greene was plagued by internal clashes, missed acquisitions, insiders say

    Google’s lack of big deals has puzzled analysts given how aggressive the major software vendors have been at opening their wallets to win in the cloud. In two of the year’s biggest deals — IBM’s $34 billion purchase of Red Hat and Microsoft’s $7.5 billion acquisition of GitHub — Google was involved in talks but ultimately came up short, according to people familiar with the matter.

    Greene wanted to buy GitHub but Pichai was less enthusiastic, unclear why Google would spend big money to get into the market for developer tools, said a person close to the business. Google’s bid for GitHub, whose cloud software lets programmers collaborate and share code, came in at just under $6 billion, and it declined to raise the price after being told of Microsoft’s offer, the person said.

    https://www.cnbc.com/2018/11/21/google-cloud-plagued-by-internal-clashes-in-its-effort-to-catch-amazon.html

Security

  • Venmo Caught Off Guard by Fraudsters

    In the first three months of 2018, the digital money-transfer service owned by PayPal Holdings Inc. PYPL -1.48% recorded an operating loss of about $40 million—nearly 40% larger than the loss for which the company had budgeted, according to internal documents reviewed by The Wall Street Journal.

    Expenses related to fraudulent transactions were a big factor. The so-called transaction loss rate, which includes losses related to fraudulent charges, rose from about 0.25% of overall Venmo volume in January to 0.40% in March. The company had been shooting for a rate of roughly 0.24% in those periods, according to the documents.

    https://www.wsj.com/articles/venmo-caught-off-guard-by-fraudsters-1543068120?ns=prod/accounts-wsj

  • USPS took a year to fix a vulnerability that exposed all 60 million users’ data

    The vulnerability included all 60 million user accounts on the website. It was caused by an authentication weakness in the site’s application programming interface (API) that allowed anyone to access a USPS database offered to businesses and advertisers to track user data and packages. The API should have verified whether an account had permissions to read user data but USPS didn’t have such controls in place.

    Users’ personal data including emails, phone numbers, mailing campaign data were all exposed to anyone who was logged into the site. Additionally, any user could request account changes for another user, so they could potentially change another account’s email address and phone number, although USPS does at least send a confirmation email to confirm the changes.

    https://www.theverge.com/2018/11/22/18107945/usps-postal-service-data-vulnerability-security-patch-60-million-users

  • Amazon leaks users’ names and emails in ‘technical error’

    When contacted for comment, Amazon said that neither its website nor any of its systems had been breached and that it has “fixed the issue and informed customers who may have been impacted.” It did not reveal the number of accounts affected or which countries the users are located in. Twitter users across Europe and the United States have reported receiving the email, and forum posts suggest that the error affected consumer rather than business accounts on the platform.

    Characterizing this as a “technical error” means that the incident is unlikely to be related to reports of Amazon firing employees for sharing customer emails with third-party sellers, but the lack of information makes it difficult to establish exactly what happened. We have reached out to the UK’s Information Commissioner’s Office, which Amazon would have needed to inform in the event of a breach, for comment.

    https://www.theverge.com/2018/11/21/18106306/amazon-email-address-leak-technical-error-phishing

  • Hackers May Exploit Microsoft PowerPoint For Malware Attacks

    As explained, the malicious file involved in this attack method appears to have a blank page, but secretly connects to a malicious link. Ramilli analyzed the slide structure and noticed an external OLEobject. Upon further analysis, he found the target device already infected by the file downloaded on the system, that is, wraeop.sct. After this step, stage 3 of the attack begins that utilises an internal image to execute additional code leading to stage 4 – the payload execution.

    The researcher suspects the malware to be AzoRult after performing traffic analysis and considering the C&C admin.

    https://latesthackingnews.com/2018/11/18/hackers-may-exploit-microsoft-powerpoint-for-malware-attacks/

Software/SaaS

  • Red Hat to be ‘Switzerland’ within IBM

    According to Marco Bill-Peter, Red Hat senior vice president of customer experience and engagement, Red Hat will function as an independent, distinct unit within IBM’s Hybrid Cloud team and maintain its commitment to open source principles.

    https://www.computerworld.com.au/article/649888/red-hat-switzerland-within-ibm/
    Red Hat Says IBM Acquisition Won’t Change Its Culture — But Can It Change Theirs?

    “There is a commitment from them and a commitment from us as well: we stay true to open source. The other one is [Red Hat will] operate as an independent distinct unit and preserve our unique culture.”

    Significantly changing its culture could cause many of Red Hat’s 13,000 employees to leave, Bill-Peter said. It could also scare off long time partners like Amazon and Google from collaborating on “the next open hybrid cloud”. But Bill-Peter has little doubt IBM is committed to their independence.

    https://which-50.com/red-hat-says-ibm-acquisition-wont-change-its-culture-but-can-it-change-theirs/

Datacenter/Hardware

  • America’s nuclear arsenal relies on this brand-new supercomputer

    In an expansive white-tiled room in Livermore, California sits Sierra, the world’s second most powerful supercomputer. Sierra looks like an unassuming server farm, but is actually a massive connected hive of 190,000 processing cores. It was completed earlier this year, and has been on a shakedown cruise since then: researchers at the Lawrence Livermore National Laboratory ran astrophysics, climate, and precision medicine simulations on Sierra while ferreting out bad components and other technical hiccups.

    But early next year, Sierra’s real work will begin. The system will be “air gapped,” meaning that it will be disconnected from any external network to prevent unauthorized access. Once that happens, it can begin the calculations it was purpose-built to carry out: simulations of nuclear weapons launches and detonations.

    https://www.theverge.com/science/2018/11/20/18097534/nuclear-weapons-supercomputer-sierra-california-classified-stockpile-simulations

Other

  • With Facebook at ‘War,’ Zuckerberg Adopts More Aggressive Style

    Mr. Zuckerberg, who previously set annual goals such as to learn Mandarin and read 25 books, said this year he would focus on fixing Facebook. He believes this tougher management style is necessary to tackle challenges being raised both internally and externally, according to a person familiar with his thinking.

    Mr. Zuckerberg’s new posture could trouble those who feel his “move fast, break things” mantra from Facebook’s early days contributed to many of the company’s current problems. It also has led to confrontations with some of his top reports, including Ms. Sandberg, who has long had considerable autonomy over the Facebook teams that control communications and policy.

    https://www.wsj.com/articles/with-facebook-at-war-zuckerberg-adopts-more-aggressive-style-1542577980
    Zuckerberg says stepping down at Facebook is ‘not the plan’

    Otherwise, he seemed unwilling to change his role or step down as leader of the company, and of COO Sandberg said “I hope we work together for decades more to come.” Separately, tonight TechCrunch reports that an internal memo showed outgoing policy head Eliot Schrager take responsibility for the company hiring Definers, a PR firm that spread negative publicity about competitors and pushed angles linking George Soros to critics. In the memo Schrage said Facebook did ask them to do work relating to Soros and that Definers reached out to members of the press showing that he funded some people who were critical of the company.

    https://www.engadget.com/2018/11/20/zuckerberg-says-stepping-down-at-facebook-is-not-the-plan/

Photo: Almos Bechtold

News You Can Use: 11/28/2018

  • Managers, consider these things before you give someone a promotion

    Moving into a managerial role is usually considered a high point in one’s career. It’s a sign that the company recognizes your leadership potential. In actuality, being a good employee doesn’t automatically translate to being a good leader. That transition requires learning a lot of new skills, sometimes from scratch.

    When new managers struggle, so do their teams. The likelihood of losing employees under a struggling manager is high. And that gets costly when you look at all that goes into replacing employees. Statistics on the cost of replacing a new hire run from tens of thousands of dollars to 1.5 to two times the employee’s annual salary.

    https://www.fastcompany.com/90268727/managers-consider-these-things-before-give-you-give-someone-a-promotion

  • You Didn’t Get the Promotion: Now What? 3 Options For Moving On When You Can’t Move Up

    Forget society’s formula. Ask yourself what you want. Do you really want to sink more hours into a job that may or may not have anything to do with your passions and beliefs? Is managing a small chain of stores specializing in Halloween costumes for pets worth the extra twenty-plus hours of your existence you’ll put in? If it is, great – but don’t buy into the notion that you need to constantly curb-stomp your fellow man to chase something you never wanted to begin with.

    https://www.primermagazine.com/2018/earn/didnt-get-promotion

  • The connection paradox: Why are workplaces more isolating than ever? | Dan Schawbel
  • How to Be Wrong Without Losing Face

    When JFK went on national television and took full responsibility for the Bay of Pigs disaster, the nation didn’t throw up their hands in collective horror and ask themselves how they could have possible elected such a moron to high office. The opposite was true. His popularity rose. Far from losing the trust of the citizenry, he gained even more of it. There’s something inspiring about a leader who can come right out and confess their faults.

    The reasons for this aren’t hard to discern. For one, you become relatable, because there isn’t a single person on the planet who hasn’t been in your shoes. Secondly, letting down your guard, showing vulnerability, is attractive and inspiring. Instead of locking the door to your soul, you let folks in.

    https://www.entrepreneur.com/article/321911

  • Half of Jobs at Amazon’s Two New Headquarters Won’t Be Tech Positions

    New York City officials said during a presentation Tuesday night that of the at least 25,000 jobs that the online retailer plans to bring to a new headquarters in Long Island City, Queens, 12,500 will be in tech.

    The other half will be “administrative jobs, custodial staff, HR, all those things,” said Eleni Bourinaris-Suarez, vice president of government and community relations at the city’s Economic Development Corporation, which helped broker the Queens deal with Amazon.

    Virginia officials said they expect the same job breakdown for Amazon’s new headquarters in Northern Virginia. The company has also promised to bring at least 25,000 jobs to that site.

    https://www.wsj.com/articles/half-of-queens-amazon-jobs-wont-be-tech-positions-1542829226

Photo by Caleb Frith on Unsplash

Supplier Report: 11/23/2018

Amazon executed a master maneuver via the split HQ2 announcement. The company is moving into 3 locations (NYC, Virginia, and Nashville) and gained invaluable access and data about cities across the east coast.

While some are unhappy about the news (including the places that won), the company set a precedent with local governments about how to frame a RFP to get maximum shareholder value. The question is… will there be backlash?

Meanwhile Facebook continues to fail in their attempts to regain the public’s and government’s trust.

Acquisitions

  • Microsoft acquires AI and bot development house XOXCO

    Microsoft is acquiring conversational AI and bot development software vendor XOXCO Inc. for an undisclosed amount. Microsoft announced its acquisition plans on November 14, the same day it is going public with a number of other AI product and service announcements.

    Among its products are Howdy.ai, which Microsoft describes as “the first commercially available bot for Slack that helps schedule meetings.” Howdy assists with the creation of custom bots, including bots for work chat, bots for customer support and bots for marketing. XOXCO also sells Botkit, a collection of development tools for those working on GitHub. Microsoft has partnered with XOXCO for a number of years.

    https://www.zdnet.com/article/microsoft-acquires-ai-and-bot-development-house-xoxco/

  • Oracle buys SD-WAN company Talari Networks

    Financial terms of the deal were not disclosed.

    Talari’s main product is its Failsafe technology, which is an SD-WAN platform used to connect enterprise networks such as branch offices and data centers over large geographic distances. WAN connections traditionally required special proprietary hardware, but the SD-WAN movement does away with this by moving network control into the cloud using a software approach.

    https://siliconangle.com/2018/11/15/oracle-buys-sd-wan-company-talari-networks/

  • Analysts weighing in on $8B SAP-Qualtrics deal don’t see a game changer

    Tony Byrne, founder and principal analyst at Real Story Group, says he likes what Qualtrics brings to SAP, but he is not sure it’s quite as big a deal as McDermott suggests. “Qualtrics enables you to do more sophisticated forms of research which marketers certainly want, but the double benefit is that — unlike SurveyMonkey and others — Qualtrics has experience on the digital workplace side, which could complement some of SAP’s HR tooling.” But he adds that it’s not really the central CEM piece, and that his company’s research has found that SAP still has holes, particularly when it comes to marketing tools and technologies (MarTech).

    https://techcrunch.com/2018/11/12/analysts-weighing-in-on-8b-sap-qualtrics-deal-dont-see-a-game-changer/

  • Kofax to buy Nuance’s imaging division for $400M in cash

    The acquisition is a notable move for Kofax — itself acquired by Thoma Bravo last year in a $1.5 billion deal — as it continues to build up its business in Robotic Process Automation (RPA), the area of enterprise IT services that uses machine learning, computer vision and other AI-based tools to bring automation to repetitive or mundane back-office tasks that would have in the past been done by humans. (The idea is that this frees up the humans to make more sophisticated assessments in specific cases, or focus on entirely different tasks.)

    https://techcrunch.com/2018/11/12/kofax-to-buy-nuances-imaging-division-for-400m-in-cash/

Artificial Intelligence

  • Amazon Says It Has Over 10,000 Employees Working on Alexa, Echo

    Amazon announced its decision Tuesday on those two locations, after its yearlong review of possible cities to establish a second headquarters. Mr. Limp said Amazon picked them because of the availability of talent.

    “The tie went to where we could recruit and where people would want to live,” Mr. Limp said.

    Amazon said in September 2017 it had 5,000 employees working on Alexa and Echo. The company’s total workforce has grown 13% to more than 600,000 over the past year.

    https://www.wsj.com/articles/amazon-says-it-has-over-10-000-employees-working-on-alexa-echo-1542138284

  • Did IBM overhype Watson Health’s AI promise?

    In July, the healthcare news publication Stat published a report claiming “internal IBM documents” showed the Watson supercomputer often spit out erroneous cancer treatment advice and that company medical specialists and customers identified “multiple examples of unsafe and incorrect treatment recommendations,” even as IBM was promoting its AI technology.

    Stat cited several slide decks it had obtained from a presentation made by IBM Watson Health’s deputy chief health officer in 2016. The slides mostly blamed problems on the training of Watson by IBM engineers and staff at the Memorial Sloan Kettering Cancer Center (MSKCC).

    https://www.computerworld.com/article/3321138/healthcare-it/did-ibm-put-too-much-stock-in-watson-health-too-soon.html

Cloud

  • Former Oracle exec Thomas Kurian to replace Diane Greene as head of Google Cloud

    The company had a disparate set of cloud services when she took over, and one of the first things Greene did was to put them all under a single Google Cloud umbrella. “We’ve built a strong business together — set up by integrating sales, marketing, Google Cloud Platform (GCP), and Google Apps/G Suite into what is now called Google Cloud,” she wrote in the blog post.

    As for Kurian, he stepped down as president of product development at Oracle at the end of September. He had announced a leave of absence earlier in the month before making the exit permanent. Like Greene before him, he brings a level of enterprise street cred, which the company needs as it continues to try to grow its cloud business.

    https://techcrunch.com/2018/11/16/former-oracle-exec-thomas-kurian-to-replace-diane-greene-as-head-of-google-cloud/
    Google’s Cloud-Computing Boss, Diane Greene, to Step Down

    Google’s hiring of Mr. Kurian could suggest the company will consider making a bid for Red Hat Inc., the software-and-services company that International Business Machines agreed to acquire last month for $33 billion, Mr. Reback said. Red Hat would provide Google with the sales and support muscle, as well as credibility with corporate tech buyers, that it lacks, Mr. Reback said.

    https://www.wsj.com/articles/googles-cloud-computing-boss-diane-greene-to-step-down-1542396164?ns=prod/accounts-wsj

  • Oracle’s JEDI protest denied

    GAO denied Oracle’s protest and said that a single award strategy did not violate federal laws and procurement regulations — one of Oracle’s key arguments.

    “The Defense Department’s decision to pursue a single-award approach to obtain these cloud services is consistent with applicable statutes (and regulations) because the agency reasonably determined that a single-award approach is in the government’s best interests for various reasons, including national security concerns, as the statute allows,” GAO said in a statement announcing its ruling.

    https://washingtontechnology.com/blogs/editors-notebook/2018/11/oracle-lost-jedi-protest.aspx

Software/SaaS

  • Zuckerberg Defends Company in Friday Meeting With Employees

    Some Facebook employees indicated that they believe The Times and other news outlets are unfairly targeting the company because of its outsize influence — a sentiment shared in the session on Friday when employees asked executives what would happen to employees who leak information to the press.

    Mr. Zuckerberg made it clear that Facebook would not hesitate to fire employees who spoke to The New York Times or other publications. But after an employee asked whether the company should issue a report about how many leakers Facebook had found and fired, Mr. Zuckerberg played down the idea.

    Leaks, he said, are usually caused by “issues with morale.”

    https://www.nytimes.com/2018/11/17/technology/facebook-mark-zuckerberg.html

  • Facebook Fallout Ruptures Democrats’ Longtime Alliance With Silicon Valley

    Facebook previously signaled that it was ready to work with Mr. Warner and others in Congress on new regulation. Yet at the same time, Facebook turned to a conservative opposition research firm that sought to undermine detractors by publicizing financial links to Mr. Soros, a harsh critic of both Facebook and Google.

    The revelations angered Democrats, who accused Facebook of tapping into anti-Semitic conspiracy theories about Mr. Soros — the very kind of propaganda the company has claimed to be battling. Facebook has denied that the effort was anti-Semitic.

    https://www.nytimes.com/2018/11/17/technology/facebook-democrats-congress.html

Other

  • Amazon, Google Poised for Race to Hire High-Tech Talent

    Amazon will bring more than 25,000 jobs to New York and another 25,000 to Northern Virginia, it announced Tuesday. Google, meanwhile, plans to double its workforce in New York City to more than 14,000 workers over the next ten years, its chief financial officer said Monday at The Wall Street Journal’s WSJ Tech D.Live conference.

    The competition for talent will be stiff, recruiters say. But the two companies each have some distinct requirements that set them apart from other employers—and from each other, according to an analysis that labor-analytics firm Burning Glass Technologies conducted for the Journal. For example, the companies favor different coding languages and technical approaches for software projects.

    https://www.wsj.com/articles/amazon-google-chase-software-developersbut-not-the-same-ones-1542133719
    New York politicians push back on Amazon HQ2 plans

    “Amazon is a billion-dollar company,” Ocasio-Cortez wrote. “The idea that it will receive hundreds of millions of dollars in tax breaks at a time when our subway is crumbling and our communities need MORE investment, not less, is extremely concerning to residents here.”

    https://techcrunch.com/2018/11/14/new-york-politicians-push-back-on-amazon-hq2-plans/

    What Is Amazon Getting From New York City and Virginia?

    Incentives from New York state: $1.525 billion, including:

    • $1.2 billion in refundable tax credits from state’s Excelsior Program over 10 years, based on the creation of 25,000 jobs that pay an average of $150,000.
    • $325 million from Empire State Development based on how much space Amazon takes over the next decade.

    Incentives from New York City:

    • Amazon said it would apply for a New York City subsidy program that would provide it property-tax abatements for up to 25 years.
    • The company also is to seek incentives under a city program that could provide $3,000 in tax credits per eligible employee over 12 years, implying a $900 million benefit if all 25,000 workers are eligible. Amazon may also be eligible for other tax credits.

    https://www.wsj.com/articles/what-is-amazon-getting-from-new-york-city-and-virginia-1542127124

Photo by Mael BALLAND on Unsplash