No inherent legal duty to be good at cybersecurity

Colonial operates a large oil pipeline and had a very bad ransomware attack in 2021 that shut down the pipeline for five days.

Some individuals that purchased gas and paid higher prices as a result of the shutdown sued Colonial for negligence (among other things) under Georgia law.

The District Court for the Northern District of Georgia has now dismissed that lawsuit:

Plaintiffs provide no Georgia statutory or common law authority for the proposition that industry standards impose a duty of care to protect against cyberattacks generally, nor do they provide support that the particular industry standards they allege have been recognized by Georgia courts.

June 17, 2022 Order Granting Motion to Dismiss at 11-12 [N.D. GA, Case 1:21-cv-02098-MHC]

And because plaintiffs could not allege exposure of personal data or any other violation of statute or legal duty, the complaint was dismissed.

Now if Colonial had said it was good at cybersecurity, and then events suggested they were not in fact good at cybersecurity, they would definitely have drawn a few shareholder derivative suits and maybe even an SEC investigation. See Matt Levine (“everything is securities fraud”).

But there is no inherent duty to be good at cybersecurity. (Yet.)

Frustration with GDPR bottleneck in Ireland

VINCENT MANANCOURT writing for Politico:

So far, officials at the EU level have put up a dogged defense of what has become one of their best-known rulebooks, including by publicly pushing back against calls to punish Ireland for what activists say is a failure to bring Big Tech’s data-hungry practices to heel.

Now, one of the European Union’s key voices on data protection regulation is breaking the Brussels taboo of questioning the bloc’s flagship law’s performance so far.

“I think there are parts of the GDPR that definitely have to be adjusted to the future reality,” European Data Protection Supervisor Wojciech Wiewiórowski told POLITICO in an interview earlier this month.

What’s wrong with the GDPR?

The main complaint appears to be that the Irish Data Protection Commission (which handles most big-tech privacy complaints) is overworked and slow.

Otherwise there appears to be a sense that things haven’t quite worked out as hoped, whatever that means.

The Privacy “Duty of Loyalty”

The draft American Data Privacy and Protection Act has a section called “duty of loyalty.” What the heck is that?

In the draft it’s a collection of specific requirements to minimize data collection and prohibit the use and transfer of social security numbers, precise geolocation, etc. See Sections 101, 102, 103 in the Discussion Draft.

But the “duty of loyalty” as a data privacy concept is broader. It means that data collectors must use data in a way that benefits users and places their interests above the interests of making a profit, much like a duty of loyalty (or a fiduciary duty) that a lawyer must have to their client.

Neil M. Richards and Woodrow Hartzog explain the concept in a 2021 paper:

Put simply, under our approach, loyalty would manifest itself primarily as a prohibition on designing digital tools and processing data in a way that conflicts with a trusting party’s best interests. Data collectors bound by such a duty of loyalty would be obligated to act in the best interests of the people exposing their data and engaging in online experiences, but only to the extent of their exposure. 

A Duty of Loyalty for Privacy Law at 966.

Richards and Hartzog suggest that a broad duty of loyalty combined with specific prohibitions against especially troubling practices would work like other areas of regulation (e.g., “unfair and deceptive trade practices”).

But although the American Data Privacy and Protection Act refers to this concept, the broad duty of loyalty is not (yet) part of the draft.

Blowing past the Turing Test

Nitasha Tiku for the Washington Post:

“I know a person when I talk to it,” said Lemoine, who can swing from sentimental to insistent about the AI. “It doesn’t matter whether they have a brain made of meat in their head. Or if they have a billion lines of code. I talk to them. And I hear what they have to say, and that is how I decide what is and isn’t a person.” He concluded LaMDA was a person in his capacity as a priest, not a scientist, and then tried to conduct experiments to prove it, he said.

The Google engineer who thinks the company’s AI has come to life

The actual Turing Test has been met for quite some time, though it didn’t lead to a pronouncement of artificial sentience in the way envisioned by Alan Turing himself.

But maybe we are now at the uncanny valley of sentience: it looks similar enough to make you feel uneasy.

Physical neural networks are very fast

CHARLES Q. CHOI writing for IEEE Spectrum:

In a new study, researchers have developed a photonic deep neural network that can directly analyze images without the need for a clock, sensor, or large memory modules. It can classify an image in less than 570 picoseconds, which is comparable with a single clock cycle in state-of-the-art microchips.

“It can classify nearly 2 billion images per second,” says study senior author Firooz Aflatouni, an electrical engineer at the University of Pennsylvania, in Philadelphia.

Photonic Chip Performs Image Recognition at the Speed of Light

There appears to be an increasing amount of research activity in the field of physical neural networks.

And it’s not just optics. Researchers are using vibrations, voltages, lasers, etc.

A future for “prompt engineers”?

Two Minute Papers highlights the incredible achievements of OpenAI’s DALL-E 2 in a video that includes a “photograph of Darth Vader as a robot ant”:

Crafting the right prompt can yield remarkable results:

Two Minute Papers points out this could be a new field of “prompt engineering”:

This is an AI where a vast body of knowledge lies within, but it only emerges if we can bring it out with properly written prompts. It almost feels like a new kind of programming that is open to everyone, even people without any programming or technical knowledge. This is prompt engineering if you will. Perhaps a new kind of job that is just coming into existence.

OpenAI’s DALL-E 2: Even More Beautiful Results! 🤯 at 5:50

New York passes “right to repair” law, including electronics

Russell Brandom writing for The Verge:

The New York state legislature has passed the United States’ first “right to repair” bill covering electronics. Called the Fair Repair Act, the measure would require all manufacturers who sell “digital electronic products” within state borders to make tools, parts, and instructions for repair available to both consumers and independent shops.

New York state passes first-ever ‘right to repair’ law for electronics

Makers of “digital electronic equipment” sold in New York must make available (on fair terms) “documentation, parts, and tools” required for “diagnosis, maintenance, or repair.”

“Digital electronic equipment” is defined as any product with a value over $10 that depends for its functioning on “digital electronics.”

If an electronic lock prevents the repair, makers need to allow the device to be unlocked.

And there are a bunch of limitations:

  • no need to reveal trade secrets;
  • no need to provide for “modification” purposes;
  • no need to provide for home appliances with embedded digital electronic products such as refrigerators, ovens, etc.;
  • does not apply to motor vehicles, medical devices, off-road equipment.

You can read the full law here.

AI-enhanced enzyme eats plastic bottles even faster

KATRINA KRÄMER for Chemistry World:

A team around Hal Alper from the University of Texas at Austin in the US has created a PETase that can degrade 51 different PET products, including whole plastic containers and bottles.

A neural network helped the team decide how to modify the protein scaffold. The algorithm was first trained on 19,000 proteins of similar size, though of very different functionalities. For each of PETase’s 290 amino acids, the program checked whether it fits well within its immediate structural environment compared with other proteins.

AI-engineered enzyme eats entire plastic containers

This is good news since apparently plastic is not really recyclable.

We’re going to have to innovate our way out of this climate mess, and AI will play a central role.

Privacy Policies are Long, redux

Geoffrey A. Fowler for the Washington Post:

Facebook . . . last week rewrote its infamous privacy policy to a secondary-school reading level — but also tripled its length to 12,000 words. The deeper I dug into them, the clearer it became that understandability isn’t our biggest privacy problem. Being overwhelmed is.

We the users shouldn’t be expected to read and consent to privacy policies. Instead, let’s use the law and technology to give us real privacy choices. And there are some very good ideas for how that could happen.

I tried to read all my app privacy policies. It was 1 million words.

Proposed solution is something like a privacy nutrition label. Or maybe machine readable privacy disclosures that enable automated decision making by a user’s client (e.g., phone or browser).