Saturday, July 29, 2023

Poco Pods announced with 12mm drivers, up to 30-hour playback

Xiaomi's Poco has announced its entry into the AIoT space in India with the launch of Poco Pods TWS earphones in the Asian country. The Poco Pods are budget wireless earphones that pack a 12mm driver in each bud and have an IPX4 rating. The Poco Pods have Bluetooth 5.3 connectivity, support Google Fast Pair, and are advertised with a latency of up to 60ms. The earphones come with Environmental Noise Cancellation (ENC) and only support SBC audio codec. The Poco Pods also support touch controls, allowing users to control their calls and music playback. You can answer the call and...



from GSMArena.com - Latest articles https://ift.tt/pc29I1H

Samsung to start production of its rumored Galaxy Ring next month

There's been a rumor doing rounds for the past year or so that Samsung is preparing a new smart wearable - a ring, possibly called Galaxy Ring. It's a fairly untapped smart wearable market, so it makes sense for Samsung to explore it. According to The Elec, the company has already finished the development process and will likely kickstart production next month. The Korean tech giant has reportedly secured its sourcing of the needed hardware and it just needs to decide when to start mass production. Although production is near, the release won't happen until 2024. Aside from the...



from GSMArena.com - Latest articles https://ift.tt/km9SriP

CISA’s security-by-design initiative is at risk: Here’s a path forward

The Biden administration’s 2023 National Cybersecurity Strategy identified structural shortcomings in the state of cybersecurity, calling out the failure of market forces to adequately distribute responsibility for the security of data and digital systems. Most prominently, the strategy seeks to “rebalance responsibility [for security] to those best positioned.”

Shortly after the strategy’s launch in March of this year, the Cybersecurity and Infrastructure Security Agency (CISA) kicked off an effort to “shift the balance of cybersecurity risk” by pushing firms to adopt security-by-design (SbD) practices, improving the safety and security of their products at the design phase and throughout their life cycle.

CISA director Jen Easterly’s announcement of these efforts appears to put CISA at the forefront of this rebalancing, addressing technology vendors’ incentives to underinvest in security through changes in how those firms design and deploy the products they sell. As the first substantive proposal from President Biden’s administration to effectuate this rebalancing since the launch of the strategy, the success or failure of the SbD initiative could be a bellwether for one of the strategy’s two fundamental ideas.

Success with SbD is at risk, however, both from the political challenges of implementing SbD practices and the threat of unrealistic expectations. This piece addresses both and highlights a path forward.

Political and structural headwinds

The politics of SbD implementation — which implicitly require a capacity to compel change in vendor practices, as well as the insight to design them — are treacherous ground for CISA, as the fast-growing agency is not a regulator. In time, it might become one, but current and past leadership insist that such responsibilities would be at odds with agency culture and its operational responsibilities.

The agency’s ability to support, build capacity, train, coordinate, and plan together with state, local, tribal and territorial entities, and industry stakeholders is rooted in its disposition as a trusted partner and neutral convener.

This means CISA should be only one of several federal agencies working to implement SbD, with cooperation from regulators like the Federal Trade Commission (FTC), a sharp and pointy complement to CISA’s open-handed approach. Otherwise, the SbD initiative could place CISA in a bind, trying to fix entrenched market incentive problems but without the ability to compel companies to act differently. CISA efforts to create accountability might undermine its attempts to generate goodwill.

Developing and defining a set of SbD practices that vendors can attest to, and that the U.S. government and other parties can verify or enforce, is a tremendous undertaking in and of itself. CISA must build SbD practices alongside an architecture for enforcement that sets clear roles for entities like the FTC, the Department of Defense, the Securities and Exchange Commission, and the General Services Administration.

The White House has responsibility here, too, and specifically the Office of the National Cyber Director, to guide this multi-agency effort within a strategy to manage the industry politics of shifting the incentives in this market — precisely what the office was designed, staffed, and organized to do. CISA’s focus must remain on enumerating and updating the essential SbD practices.

Just one piece of the puzzle

As we have argued before, “no strategy can address all sources of risk at once, but . . . silver bullets often trade rhetorical clarity for crippling internal compromises.” The SbD program could achieve deep, meaningful changes in how some of the largest technology vendors build services and products. Those changes would have material benefits for the security of every technology user.

However, cajoling all firms toward a comprehensive and uniform set of best practices is a fundamentally incompletable task.

Malicious actors perpetually seek new means of exploit; different sectors and system classes face different and unique challenges; and new technologies are prone to modes of failure, both new and unforeseen. Adopting certain new processes, rigorously enforcing them, and fixing existing incentives would still be a much-needed improvement over the current status quo.

However, adopting memory-safe languages or pushing large actors toward better risk management would not necessarily have prevented many significant vulnerabilities in recent memory, such as Log4Shell. To succeed, CISA will also need to understand how large technology companies build products and services — current industry practice is far from complete or perfect, but it is the baseline from which SbD hopes to drive change. Understanding that baseline is critical.

There is danger when rhetoric around shifting responsibility in cyberspace suggests that cybersecurity problems and challenges exist only because technology vendors cut corners or that all cybersecurity risk can be avoided by following a simple set of straightforward practices. The increasingly interconnected, dependent nature of software systems, as well as the variety of organizations and systems they connect to, creates risks all its own.

SbD is an important piece of managing this — the status quo of responsibility deferred to the user is broken — but describing SbD as a panacea risks creating backlash when insecurity inevitably persists.

It is clear CISA recognizes that success in SbD could be one of the most impactful policy interventions in cybersecurity in the last decade. It is also clear that the program, even in its most successful incarnation, will leave some problems unsolved. Specificity about the scope and goals of the program will help prevent its inevitable critics from distorting the debate into all-or-nothing terms.

Risk and opportunity

SbD — the first policy manifestation of the National Cybersecurity Strategy’s effort to shift responsibility — will not come about by sheer goodwill alone. CISA is not a regulator, and it must define a path for federal agencies that are regulators so that the implementation of SbD leverages the broader standards setting, enforcement, and regulatory powers of the federal government.

Shying away from direct government enforcement of these security practices risks consigning the effort to history, alongside many other “voluntary” and “industry-led” programs.

The growing and talented team at CISA have 18 months until January 2025, which will bring either the paralyzing tumult of transition or the still-chaotic maturation of a first-term administration into a second. The largest vendors that would participate in this program are not going anywhere and can afford to wait.

In this sense, CISA and the wider U.S. government’s cyber policy apparatus is on the clock. CISA must focus on the essential elements of SbD and organize, build, and engage with a clear deadline in mind. The clock is ticking.



from TechCrunch https://ift.tt/bZmJH05

Sony Xperia I V starts shipping in the US

The Sony Xperia I V, which was unveiled in May and was up for pre-orders in the US until now, is finally shipping in the States. It's priced at $1,400 in the US and comes in a single 12GB/256GB configuration. You can purchase it from Sony's official website or Amazon. The Sony Xperia I V is built around a 6.5" 120Hz OLED having 3,840x1,644-pixel resolution and Gorilla Glass Victus 2 protection. It's powered by the Snapdragon 8 Gen 2 SoC and runs Android 13 out of the box. Sony Xperia I V The Xperia I V features four cameras - 48MP primary (with OIS), 12MP telephoto (with OIS),...



from GSMArena.com - Latest articles https://ift.tt/Ytz0cFC

AMD announces Radeon RX 7900 GRE in China

AMD today announced the Radeon RX 7900 GRE desktop graphics. Although announced first in China, it seems the card will also be available globally. The RX 7900 GRE (which stands for Golden Rabbit Edition) is a cut-down version of the RX 7900 XT with some minor reductions to the GPU and significant reductions to the memory. Compared to the 7900 XT's 84 compute units, the 7900 GRE has 80. The game clock drops from 2000MHz to 1880MHz. The 20GB 20Gbps 320-bit memory drops down to 16GB 18Gbps 256-bit, which causes the memory bandwidth to drop from 800GB/s to 576GB/s. The Infinity...



from GSMArena.com - Latest articles https://ift.tt/CGa6Jf2

Friday, July 28, 2023

HerMD opening new women’s health clinics following $18M extension

Women’s healthcare got another capital infusion today in HerMD, which announced $18 million in additional Series A funding, showing that this area continues to be of interest to investors.

My colleague Dominic-Madori Davis reported earlier this year that women’s health companies raised about $1.16 billion in 2022. Though down from $1.41 billion in 2021, this is still a vast improvement over the $496 million raised in 2020, according to PitchBook data.

Somi Javaid, HerMD

Dr. Somi Javaid, founder and chief medical officer of HerMD. Image Credits: HerMD

HerMD is among a group of companies (for example, Herself Health, Tia Health, Vira Health and Adyn) providing care options specifically for women, at all stages of their lives, and attracting venture capital for their approaches.

Founder and chief medical officer Dr. Somi Javaid opened the first HerMD location in 2015 in Cincinnati to help change the notion that less than 20% of OBGYNs are trained in menopause and sexual health care. She later brought on Kathy McAleer as CEO in 2022.

The company offers comprehensive women’s healthcare, either in-person or virtual, and one of its differentiators is that the average appointment is between 20 and 60 minutes. All medical services are insurance- and Medicare-based. In addition, HerMD provides aesthetic services, including facial injectables and body treatments.

To address the lack of training, the company created the HerMD University that centers around proprietary algorithms of care to take providers from classroom to clinic. Providers are able to attend health conferences around menopause and sexual health and participate in monthly meetings.

“The first thing we had to fix was the educational component,” Javaid told TechCrunch. “Some providers have told us that they get more education in the first couple of weeks at HerMD University than they have in their entire career. Then we had to give our providers and patients more time.”

HerMD has around 20 providers between its clinics in Cincinnati, Franklin, Tennessee and Carmel, Indiana and is consistently seeing a waitlist of approximately 500 patients leading up to a clinic opening.

One of the areas that Javaid also focuses on is provider experience, explaining that many providers have become burned out in recent years amid the failings of the existing U.S. healthcare system.

“We’re in this era where we may lose 47% of our workforce by 2025 because of burnout from COVID, because of lack of mission-driven work and because female providers feel like they can’t climb the ladder as well and there’s a pay gap,” Javaid said. “We don’t have any of that at HerMD — it’s equal opportunity. You want to climb the ladder, you climb a ladder. And we give work-life balance, so we have almost zero turnover.”

Meanwhile, the Series A extension was led by existing investor JAZZ with participation from Amboy Street Ventures and B-Flexion. The new investment brings HerMD’s total funding to nearly $30 million.

With the funding, the company will expand its brick-and-mortar locations, including the first in the New York City area and a second Nashville-area clinic. HerMD will also continue developing its virtual services and HerMD University and grow its team — Javaid said there are 100 providers eager to join. The company will also launch mental health services and invest in the latest technologies around sexual health and menopause.

“We will also be introducing e-commerce and physician-curated products,” Javaid said. “Hospital-based systems, and relationships like that, is another thing that we would love to do. We rely on hospitals for imaging, primary care and obstetric and oncology care, but a lot of hospital systems say they struggle because their providers aren’t trained in menopause and sexual health. They need a partner like us, and I see HerMD having over 200 clinics in the future.”



from TechCrunch https://ift.tt/jOyhHMd

Cyber insurance audit: Painful necessity, or a valuable opportunity?

Not that long ago, few companies even considered purchasing insurance to mitigate their financial exposure from a cyber incident, and for those that did, obtaining a policy was as easy as filling out an application and writing a check. Those days are now squarely in the rearview mirror. Today, companies everywhere are rushing to get cyber insurance — the value of the global cyber insurance market reached $13.33 billion in 2022 and is projected to soar to $84.62 billion by 2030.

However, the increased number of policies combined with the sharp uptick in costly attacks led to higher costs for cybersecurity insurance providers. To stem their losses, insurance companies now often require proof that an organization has implemented a variety of security measures in order to be eligible to purchase a policy.

Rather than resisting or resenting risk assessments from potential cyber insurance vendors, IT leaders should regard them as an opportunity to strengthen their organization’s security posture.

Cyber insurance involves risk assessment

Across the insurance industry, policy requirements and premiums vary according to risk assessment. For instance, installing an anti-theft system might reduce the cost of insuring an expensive sports car. A person living in a flood plain can expect to pay more for a homeowner’s policy than someone with a similar house on higher ground — or they might not be able to purchase a policy at all, as homeowners in states like Florida are discovering.

It is the same for cyber insurance. An insurance provider may impose more security demands on a company that hosts large volumes of personally identifiable information (PII) than it does for a company of similar size with far less PII. And organizations that lack sufficient security controls to bring risk down to a level acceptable to an insurance provider might not be eligible for any policy at any price.

What cyber insurance actually covers

The main focus of cyber insurance is obviously on covering the financial risks of an incident. Typically, you can expect the insurance to cover the firsthand costs to the business that are the direct result of the cyber event, such as:

  • Forensic analysis and incident response. Some insurers require that you engage specific managed incident response services.
  • Recovery of data and systems caused by actual loss and destruction.
  • Cost of the downtime due to the cyber event.
  • Costs incurred from sensitive data breaches, such as handling PR activities, notifying impacted clients, or even providing credit monitoring services to customers.
  • Legal services and certain types of liability for regulated data, including covering the costs of the civil lawsuits.

It is important to note that insurance rarely or never covers some of the longer-lasting impacts of the event, such as any future profit loss due to theft of intellectual property or the need to invest in cybersecurity program improvements after the event.

There is no consensus on reimbursement for paying a ransom. Not all insurers cover this type of expense. Some experts argue that it can encourage further attacks and fund criminal activities. In some jurisdictions, the discussion is going back and forth on whether paying ransom should be banned altogether.

As with any insurance policy, you can expect extra clauses. These may include the top amount they cover, the requirement to go through a due process with the law enforcement agencies, or involvement in professional ransom-negotiation services.

The must-have security measures for cyber insurance

A recent Netwrix study reveals useful details about the process of qualifying for cyber insurance today. It found that 50% of organizations with cyber insurance implemented additional security measures either to meet the requirements of the policy they selected or to simply be eligible for a policy at all. The figure below shows the specific requirements they reported having to meet:

Image Credits: Netwrix/Netwrix Hybrid Trends Security Report 2023

Don’t take this list as comprehensive or authoritative. For instance, implementing MFA does not necessarily mean requiring MFA for all users; an insurer might require additional authentication only for users with privileged access to sensitive data and systems. In addition, remember that these controls are interrelated. For example, in order to require MFA for access to particular types of data, you need to know where sensitive and regulated data resides and have control over user and administrative privileges.



from TechCrunch https://ift.tt/ZpIjadS