[{"content":"The Digt Analytics blog. Articles are organised by topic: electronic signature, digital signature, electronic workflow, information security, intelligent video surveillance, legislation and cases.\n","date":"26 August 2022","externalUrl":null,"permalink":"/posts/","section":"Blog","summary":"","title":"Blog","type":"posts"},{"content":"","date":"26 August 2022","externalUrl":null,"permalink":"/categories/cases/","section":"Categories","summary":"","title":"Cases","type":"categories"},{"content":"","date":"26 August 2022","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"Digt Analytics is an analytical blog by the DIGT group of companies. We publish reviews and analyses on electronic signatures, digital identity, cybersecurity and intelligent video surveillance.\n","date":"26 August 2022","externalUrl":null,"permalink":"/","section":"Digt Analytics","summary":"","title":"Digt Analytics","type":"page"},{"content":" European countries believe that blockchain is one of the key new technologies shaping its future. That is why the European Blockchain Partnership was established on April 10, 2018.\nIt considers that blockchain can help make interactions between citizens, businesses and public organizations more efficient. Let us speak about what the European Blockchain Partnership is, why it was created, and what it does, in this article.\nWhat is the European Blockchain Partnership\nThe European Blockchain Partnership (EBP) is an agreement between the EU countries on the development of blockchain technologies and the creation of a blockchain infrastructure for public services. It was signed on April 10, 2018 by 20 European Union member states, and now the partnership includes 30 countries, like EU member countries, Liechtenstein, Ukraine and Norway.\nThe partnership has started to create the European Blockchain Services Infrastructure (EBSI). It will enable the legal use of blockchain within the EU. Eventually, it should help to develop blockchain technology throughout Europe.\nEBSI is aimed to improve the ability of states to provide services across Europe in a secure, citizen-centric way. Subsequently, this should make it easier for residents and businesses in the region to live, work and do business.\nThe infrastructure is managed by the partnership and the European Commission. EBSI makes it possible to benefit from public blockchain by accelerating cross-border services for EU citizens and public administrations. The partnership also created the Early Adopters program, which began in July 2021. It launched an inter-university project with 18 universities in 15 EU countries. Its goal is to show how blockchain is used in the cross-border exchange of educational credentials.\nIn July 2022, Early Adopter was an incubator for blockchain-based projects using the EBSI environment. Participants of this program can connect their systems to the European blockchain, become part of the community, and collaborate with other entrants.\nWhy was EBP created?\nThe European Blockchain Partnership was created for the international integration of the blockchain system. This system will help Europe to become a world leader in the development and adoption of blockchain technologies.\nThe European Commission has already invested 80 million euros in blockchain projects supporting technological and social development. And over the next few years, the commission is going to spend another 300 million euros to develop the blockchain industry.\nWhat EBP is doing\nLet\u0026rsquo;s look at a few areas where EBP is going to or has already implemented blockchain technology.\nImproving public services for all Europeans. When the partnership finishes building EBSI\u0026rsquo;s blockchain infrastructure, all public services in Europe will use blockchain technology. And it will be easier for European citizens to access them.\nNotarization**. **Blockchain is used to notarize official documents. It comes in handy when documents need to be certified to be used in other European countries. Such assurances are already being used in the areas of digital audit and automated compliance checks.\nSharing digital credentials. Citizens get digital control over their credentials. It will, accordingly, take less time to verify them, trust in the authenticity of documents being increased. Initially, blockchain will be used for higher education and lifelong learning credentials, as well as for easier access to European social security services.\nSelf-identity. EBSI is helping to implement the Self-Sovereign Identity model in Europe. It enables users to create and control their own identity in all European countries. The model is developed in accordance with the eIDAS Digital Signature Regulation. eIDAS is an EU regulation on electronic identification and electronic transactions. In other words, it is a standard for electronic signatures that has legal force in Europe.\nReliable data exchange. Blockchain technology is used to securely exchange data between government agencies. Initially, it will be used in customs and tax authorities, as well as to manage asylum requests for refugees.\n**Skills support programs. **The European Commission gives European citizens digital skill training grants or provides free training. This includes blockchain training. And the European Union is creating special programs to replenish the blockchain talent pool. https://youtu.be/_VkzyMgjD4E\nBusiness Financing. The partnership is looking for ways to use blockchain technology for innovative financing models for small and medium-sized businesses.\nConclusion\nThe material figured out what the European Blockchain Partnership is. This is an agreement between the EU countries to develop a blockchain strategy and infrastructure for public services. It includes the EU countries, as well as Ukraine, Norway and Liechtenstein.\nIt is designed to internationally integrate the blockchain system and improve the ability of states to provide services across European borders in a secure manner. Subsequently, this should make life, work and business easier for citizens, residents and businesses in the region.\nSee also # St. Louis Prosecutor Quits after her eSignature Used on Court Docs while on Maternity Leave A Legal Case: The Plaintiff Failed to Prove the Authenticity of the Electronic Loan Agreement ","date":"26 August 2022","externalUrl":null,"permalink":"/posts/evropeyskiy-blokcheyn-konsortsium/","section":"Blog","summary":"European countries believe that blockchain is one of the key new technologies shaping its future. Let us speak about what the European Blockchain Partnership is.","title":"Why the European Blockchain Partnership is needed","type":"posts"},{"content":"","date":"23 March 2022","externalUrl":null,"permalink":"/categories/digital-signature/","section":"Categories","summary":"","title":"Digital Signature","type":"categories"},{"content":"","date":"23 March 2022","externalUrl":null,"permalink":"/categories/electronic-workflow/","section":"Categories","summary":"","title":"Electronic Workflow","type":"categories"},{"content":" Email was one of the first ways of online communication and perhaps the most successful one. The number of email users continues to grow steadily despite the appearance of other popular messaging applications such as WhatsApp or Signal.\nOne of the reasons for the popularity of email is its decentralized nature. You can send and receive emails from anyone, regardless of which email provider is being used. To communicate with anyone via WhatsApp or Signal, both users must have an account with the messaging provider. The user-friendliness created by email compatibility has made it an excellent means of communication. But one has to pay the cost by their privacy.\nEmail Tracking\nThe largest email providers are straightforward about tracking emails. For example, Yahoo\u0026rsquo;s Privacy Policy explicitly states their right to “analyze and store all communications content, including email content from incoming and outgoing mail, as well as incoming and outgoing messages to messaging apps.” And most of the other well-known mainstream and “free” email providers have similar provisions in their Privacy Policies.\n** Technical skills** To protect your email and privacy, you don\u0026rsquo;t need to be tech-savvy. All you have to do is create an email account with a trusted private email provider. In general, it is useful to understand the basics of email communications.\nLet\u0026rsquo;s use an example: you want to email someone. You create your email in your email client (on the website or through the app), add their email address, and click send. But how did your email reach the person? Your email client connects to the email service provider\u0026rsquo;s SMTP (Simple Mail Transfer Protocol) server, which will find and connect to the server of the person\u0026rsquo;s email service provider to deliver your message to their mailbox. These connections are most likely encrypted using TLS (Transport Layer Security), which means that the email is confidential between you, both of your email providers, and him or her.\nThe TLS protocol is used to prevent third parties from listening to your conversation by encrypting the message when it is transmitted between your providers. However, nothing prevents your email providers from accessing your emails. So, your email to other people and the information contained therein may be shared with others.\nNevertheless, it is quite possible to protect the letters in secret.\nSo, how can email be protected? # 1. Choose an email provider that respects the privacy and security of your data Using email generates a lot of data, and all this information is valuable to advertisers. \u0026ldquo;Free\u0026rdquo; email providers such as Google, Yahoo, and Microsoft show ads in users\u0026rsquo; mailboxes. These ads are based on your personal information and online behavior collected from various online sources. Follow the link https://policies.google.com/privacy to learn how and where Google collects your data. So \u0026ldquo;free\u0026rdquo; is not free - in this case, since you are paying these email providers with your personal information. By choosing an email provider that is secure and confidential, your data remains yours, and an additional bonus is no advertising!\nAlso, think about which country it works in, as the rules and regulations vary greatly. In the EU, the General Data Protection Regulation (GDPR) imposes many privacy protection rules on individuals, companies, and other organizations that process personal data, ensuring that the privacy of their users is protected by default.\n2. Encrypt your messages with PGP PGP encryption (Pretty good privacy) works with a pair of keys: a public and a private key. The public key is used to encrypt messages, and the private key is used to decrypt them. You should not disclose your private key to anyone. It is for your personal use only. On the other hand, your public key can and should be shared so that the messages sent to you can be encrypted. Similarly, you can encrypt messages you send to someone else using their public key. While this method may seem complicated, many privacy-conscious email providers have made it easy to use. PGP encrypts your messages from beginning to end with just one click, ensuring that only you and the intended recipient will see them. It is worth noting that PGP does not encrypt the subject line of your emails.\n3. Protect your PGP keys by replacing them regularly If your PGP private key gets stolen or falls into the wrong hands, it can be dangerous and could reveal all the information you tried to keep secret in the first place. To avoid this security breach, you should replace your keys regularly. Create a reminder to replace them in a few months or, if possible, set an expiration date for them. If one of your private keys is compromised, only messages encrypted with this key are at risk. The remaining encrypted messages remain unreadable.\n4. Protect the emails you send to people who don\u0026rsquo;t use PGP Not everyone has the time, money, or resources to assess the privacy risks associated with using email. Some services can encrypt your emails with a password. You can tell them the password via a secure channel or give them a hint that only they know. It is simple and effective, and it also raises privacy awareness.\n5. Use an alias to protect your email address from fraudsters/data leaks Countless services request your email address so that you can place an order or send a free ebook or coupon for online purchases. When you do, your email address may be sold or disclosed after a data leak. You can avoid these problems by using an alias - an alternative email address associated with your primary email address. The continued popularity of email means that protecting your email and your personal information is becoming more and more significant. Fortunately, it shouldn\u0026rsquo;t be difficult if you follow these five tips.\nThe original article can be found here. * * If you find our posts compelling, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Electronic signature for HR contracts in France An E-Signature: the Key to a Secure Document Workflow ","date":"23 March 2022","externalUrl":null,"permalink":"/posts/sovety-bezopasnost-email/","section":"Blog","summary":"Protect your email privacy with these tips and keep the untrusted providers, hackers and cyber criminals away from your email and your data.","title":"Email Safety Tips Every User Should Know to Keep It Confidential","type":"posts"},{"content":"","date":"16 March 2022","externalUrl":null,"permalink":"/categories/intelligent-video-surveillance/","section":"Categories","summary":"","title":"Intelligent Video Surveillance","type":"categories"},{"content":" Four wanted men were arrested by police using real-time facial recognition technology during operation over the weekend.\nThe suspects were detained on Saturday at various locations in Westminster, London by officers using the controversial technology. They include a 32-year-old man wanted for extradition for drug and violence offenses.\nThe vehicle-mounted scanning system uses cameras and biometric software to verify the identity of passers-by in real-time against a database of wanted individuals. Signs and notices are installed warning the public about the presence of cameras, and police officers proceed to arrest as soon as the system makes a match with its database.\nThe Metropolitan Police said the use of the technology was part of a wider operation to tackle serious and violent crime in parts of Westminster.\nAlong with the man arrested on an extradition warrant, a 31-year-old man was detained for being wanted for drug-related crimes, and a 40-year-old man was detained for traffic violations. A fourth man was arrested in connection with a charge of making death threats.\nCritics of real-time facial recognition technology say it raises serious human rights concerns about its ability to track people\u0026rsquo;s movements and invade privacy. Meantime, research in the US suggests the technology may be less reliable at identifying women and ethnic minorities.\nPolice claim that this is a valuable tool with high visibility for the suppression of criminal activity and state that all data of passers-by that does not match the database of wanted persons is instantly deleted.\nThe original news is here. *You can send us any comments to our *email; we will be elated to get feedback. If you find our articles fascinating, you can subscribe here.\nSee also # Video Surveillance Trends and Predictions in 2021 The Best Facial Recognition Algorithm Calling for a Ban on Facial Recognition: EU DPAs are Worried ","date":"16 March 2022","externalUrl":null,"permalink":"/posts/britanskaya-politsiya-raspoznavanie/","section":"Blog","summary":"British police will scan people’s faces to see if they’re criminals to disrupt criminal activity.","title":"UK police starts using facial recognition tech to catch criminals","type":"posts"},{"content":"","date":"16 February 2022","externalUrl":null,"permalink":"/categories/electronic-signature/","section":"Categories","summary":"","title":"Electronic Signature","type":"categories"},{"content":" Using electronic signature solutions represents an opportunity for new services and increases the efficiency of conventional business processes and implementation processes. Recently, customers and users have become more accustomed to managing interactions and transactions digitally. Providing them with a fast and easy-to-use electronic signature solution is a significant element if we want to offer customers a digital service that meets their expectations.\nThere are several types of electronic signatures, each of which has different characteristics. In this article, we will focus on a simple electronic signature. Except for simple electronic signatures, there are advanced and qualified electronic signatures. The last ones are characterized by additional complex elements that provide high guarantees before the law.\nNext, we will talk about what you can do with a simple electronic signature, from buying goods and services to signing typical documents of the personnel process.\nWhat is a simple electronic signature? A simple electronic signature (SES) is the least complex and well-defined type of electronic signature. While other electronic signature solutions must include legally defined elements, such as mandatory identification of the signatory, insurance protection, or, in the case of digital signatures, the use of cryptographic keys, a simple electronic signature does not require any of these. Instead, it meets the principle of technological neutrality. It means that SES solutions can take various forms and technical characteristics.\nSES is part of a more general definition of an electronic signature in the eIDAS regulation. According to the Regulation, an electronic signature is “a set of data in electronic form, which is attached or linked by logical association to other electronic data and used by the signer to sign.” In practice, a simple electronic signature in its basic form usually consists of a pair of username + password credentials, the same as those used to access an e-mail or personal account, and point \u0026amp; click solutions.\nCertain court decisions have confirmed that a message sent by e-mail can be considered assigned with a simple signature. For example, this was confirmed by ruling n. 858 of December 15, 2003, issued by the Court of Cuneo. Where can SES solutions be applied? SES solutions are easy for the user precisely because they are characterized by simple access. These solutions are easier to integrate with other systems already in use, making them suitable for integration into fully digital workflows, allowing you to implement effective digital technology implementation processes. The only thing that remains to be found out is which documents and contracts can be signed with a simple electronic signature.\nBuying goods and products online One of the activities that are becoming more and more common for all of us is going online to buy goods and goods of all kinds. An online purchase is a form of agreement between two parties, regardless of whether it is carried out in person or remotely. In most cases, in the presence of the client, this is an oral agreement that does not require the preparation of any written document and ends with the issuance of a receipt or invoice. In the case of online transactions, there is no need for advanced or qualified signatures since a simple signature is already pretty much enough.\nPurchase of a new supply of electricity or gas Another activity that has led to a reduction in queues at personal counters in favor of digital technologies is the purchase of new contracts for the supply of utilities and the subsequent management of all stages and related actions. Even in this case, the SES solution can be used effectively. This type of process is particularly well suited for electronic signatures. In addition to dematerializing contracts and subscriptions, it is also possible to create processes in which other interactions between the company and the client no longer take place behind the counter or over the phone, but in a digital format. With the right workflow and the necessary call to action, you can offer customers the opportunity to make an appointment with an operator or activate a new service with just a few mouse clicks. The necessary documents can be submitted for signature by e-mail or through a special web area, and it becomes possible to create an increasingly rich and personalized digital user experience.\nThe signing of personnel documents A simple electronic signature can also be used to dematerialize and optimize certain HR department reports and processes. For example, a simple electronic signature can be used when requesting vacations, vacations, training requests, or expense claims. In this regard, it is worth mentioning the recent clarification of the Revenue Agency, which is contained in response No. 740 of October 20, 2021, regarding the management of expense reports. The Agency\u0026rsquo;s response clarifies that digital expense reports do not require a qualified electronic signature or an extended employee signature, which makes it quite likely to use a simple electronic signature or single sign-on authentication (SSO) solutions.\nApproval of quotations and purchase orders Accepting an estimate or purchase order is another action that can be performed by attaching SES, thereby digitizing and increasing the efficiency of these types of transactions. Also, in this case, SES makes it possible to simplify processes that would otherwise require exchanging, printing, and scanning various documents to obtain a holographic signature, while these steps are significantly reduced, if not eliminated, with the adoption of a digital approach.\nThe signing of Privacy Notices You can sign the privacy policy using a simple electronic signature solution as soon as the signatory has the opportunity to properly view and read the document itself. This can also be implemented by email or using information available in a special web area that the signer accesses using a pair of credentials. A call to action for a signature in the form of a \u0026ldquo;point and click\u0026rdquo; decision (for example, a button that clearly expresses readiness to sign a document) can be placed at the end of the disclosure so that the signatory can view it correctly.\nHow to strengthen the SES solution? As we have already said, a simple electronic signature can have various characteristics that determine the degree of reliability. Since the value of a simple signature in the event of a dispute is assessed depending on its integrity, security, and immutability characteristics, it may be useful to take measures to increase the reliability of SES while maintaining its flexibility.\nThe easiest way to increase the value of SES is to use an OTP code (one-time password), which will be sent to the signatory via SMS, app, or email. Sending an OTP code to a device belonging to the signatory is their form of authentication and allows the person to additionally confirm their willingness to sign this particular document.\nThe source: 5 things you can do (and may not have known) with a simple electronic signature\nSee also # The EU law on Electronic Signatures The future of AI: regulation in Europe The Top 5 Myths about Cloud-Based Digital Signatures ","date":"16 February 2022","externalUrl":null,"permalink":"/posts/pyat-veshchey-prostoy-elektronnoy-podpisyu/","section":"Blog","summary":"SES are the broadest and simplest types of electronic signatures. In some cases, simple electronic signatures can be considered legally binding.","title":"Five Things You Can Do with a Simple E-Signature","type":"posts"},{"content":" Changes will be made to Jersey legislation by the Electronic Communications (Amendment No. 2) (Jersey) Law 202-, regulating electronic communications and related issues. These changes are necessary due to the development of new technologies, changes in business practices, and lessons learned from the accelerated transition to remote work as a result of COVID-19.\nThese additional amendments to the Electronic Communications (Jersey) Law 2000 will be introduced in the next few months. The Amendment Act No. 2 Law has been approved by the Jersey States Assembly and is awaiting the adoption of final ordinary measures for entry into force.\nThe benefits of these amendments will affect all areas of Jersey that rely on electronic paper flow. Enterprises and other organizations (especially those that are regulated) that issue documents in this way or plan to do so should consider developing new or updated policies and procedures for processing/verifying documents, taking into account upcoming changes in legislation.\nPrincipal changes\nIn summary, the principal changes relate to:\nRemote witnessing of signatures\nThe E-Comms Law does not currently specify how to electronically witness a person\u0026rsquo;s signature on a document.\nThe amendments will set out ways to electronically satisfy a requirement (whether under an enactment or otherwise) for a signature to be witnessed. This will be in addition to any other lawful means of witnessing that signature. It will apply to the electronic witnessing of both electronic and (to some extent) traditional signatures.\nUnder this new provision, such requirement for witnessing may be satisfied where:\nat the time the document is signed, the signatory and the witness are able to see one another by means of an audio-visual link; andeither (where the signatory is signing either a hard copy or electronic document): (i) by means of that (audio-visual) link the witness identifies the signatory and sees the signatory sign the document; (ii) the signatory sends an e-copy of the document to the witness; and (iii) the witness signs it, attesting to the signature of the signatory; or (where there is screen sharing and where both signatory and witness can see and manipulate the same electronic document): at the time the document is signed: (i) the signatory and the witness are also in communication by any other electronic means; (ii) the signatory and the witness can both see the document; (iii) the signatory makes his or her electronic signature on or in relation to the document; and (iv) the witness signs it, attesting to the signature of the signatory. Despite the requirements under the second bullet point above, the new provision permits a person, who has electronically witnessed the signature, at any time to make a declaration in writing attesting to the fact. This provision could be relied on where for example the relevant document could not be provided electronically to the witness for attestation.\nAuthority to attach electronic signature for another person\nThe E-Comms Law does not currently expressly deal with a person attaching an electronic signature for another person.\nA new Article will be added to the E-Comms Law that will apply where a person is required or authorised to sign a document. It permits a person to authorise another person to attach the first person\u0026rsquo;s electronic signature to the document on the first person\u0026rsquo;s behalf. It will apply despite any rule or presumption relating to agency or delegation.\nClarifying changes\nThere are further changes proposed to the E-Comms Law as well which are clarificatory in nature. These include:\nValidity of electronic signatures etc. generally\nCurrently the provision of the E-Comms Law that states that a signature, seal, attestation or notarisation is not to be denied legal effect, validity or enforceability only because it is in electronic form, is in Part 3 (Requirements under enactments) of that Law.\nThis provision will be moved to within Part 2 (General principles) to make it clear that it is of general application and does not only apply in circumstances where there is a requirement for a signature under an enactment, as implied by its current position in the E-Comms Law.\nIn the E-Comms Law as it stands this provision contains the only substantive references to a seal, attestation or notarisation, so it is important that it is in the right place.\nElectronic records within the definition of “electronic communication”\nAs its name suggests, most of the E-Comms Law applies to electronic communications, but the definition of “electronic communication” will be expanded to include electronic records - information which may not be communicated by electronic means. Electronic records includes information that may be generated, received or stored by electronic means (and that may also be – but not necessarily - communicated by such means).\n*The article was written by Peter German and Huw Thomas. To read the conclusion and recommendations for organizations working with electronic execution of documents, follow *the link.\nSee also # Vaccine Passports: Unlocking the EU Travel Advantages of a cloud-based qualified digital signature EFPE Conference 2021: Review ","date":"9 February 2022","externalUrl":null,"permalink":"/posts/zakonodatelstvo-dzhersi-ecomms/","section":"Blog","summary":"The Government of Jersey has approved further modernising amendments to the Electronic Communications (Jersey) Law 2000 (the EComms Law).","title":"The Jersey Legislation on E-Comms will be Updated Shortly","type":"posts"},{"content":" The Commission reports the first drop in investment in research and development in industry in ten years.\nThe level of investment has decreased due to the pandemic. However, Europe needs to invest more in new technologies to catch up with the US and China, which have increased research and development spending during the first year of the pandemic.\nAccording to data published in the issue of the European Commission Industrial R\u0026amp;D Industrial Scoreboard for 2021, the COVID-19 pandemic has dealt a significant blow to the growth of investment in research and development in the EU.\nThe rating of investments in industrial R\u0026amp;D of the EU, issued by the Joint Research Center (JCR), the service of the European Commission for Science and Knowledge, has been published annually since 2004.\nThe 2021 ranking includes 2,500 companies that invested enormous amounts in R\u0026amp;D in the world in 2020 based on data taken from their latest published reports.\nEach of these companies from 39 countries has invested at least 36.5 million euros in R\u0026amp;D, totaling 908.9 billion euros. The total amount of R\u0026amp;D is equivalent to about 90% of the world\u0026rsquo;s R\u0026amp;D funded by the private sector.\nThe sample includes 401 companies from the EU, which is 20.3% of the total R\u0026amp;D, 779 US companies (37.8%), 597 Chinese companies (15.5%), 293 Japanese companies (12.2%), and 430 from the rest of the world (14.2%).\nThe main goal of the Scoreboard is to compare the effectiveness of EU innovation industries with the central global counterparts and provide a database of R\u0026amp;D investments. Companies, investors, and politicians can use it to compare the results of individual companies with the best international competitors in their sectors.\nR\u0026amp;D investments by region and sector\nInvestment in R\u0026amp;D is primary for European industry to lead the environmental transition, succeed in the fast-growing ICT sector and lead a new wave of profound technological innovation. \u0026ldquo;The results table clearly shows where we need to step up our efforts, encouraging us to invest now in the future.\u0026rdquo; - said Maria Gabriel, Commissioner for Innovation, Research, Education, Culture and Youth.\nWorldwide, investments in industrial research and development have proved to be sustainable in the context of the crisis caused by the coronavirus. In 2020, it continued to grow by 6% for the 11th consecutive year. On the contrary, in 2020, there was a significant reduction in capital expenditures, net sales, and operating profit.\nConsistent R\u0026amp;D trends over the past ten years have significantly changed the specialization of R\u0026amp;D in the regions of the world: the EU maintains a stable mix of R\u0026amp;D investment sectors. They include a strong dependence on the Automotive sector while the US and China have increased their specialization in the ICT sectors, with the US also increasing its proportion in Healthcare.\nEU lags in R\u0026amp;D growth\nLooking at investment data by region and sector, the EU has yet to catch up with its main competitors in some spheres. For the first time in 10 years, the overall growth rate of R\u0026amp;D in 2020 in Europe turned out to be negative (-2.2%). The companies in the USA and China (9.1% and 18.1%, respectively) show the highest R\u0026amp;D growth rates.\nThe decline in the EU was mainly due to the weakening of R\u0026amp;D in the automotive, aerospace, and defense industries. Three German car manufacturers, Volkswagen, Daimler, and BMW, are among the top companies investing the most considerable sums in research and development worldwide in 2020.\nEach of the top 10 companies on the list invested more than 10 billion euros in 2020. Facebook (Johnson \u0026amp; Johnson), Volkswagen (Germany), Roche (Switzerland), Intel (USA) and Huawei (China), Microsoft (USA), Samsung (South Korea), Apple (USA), Facebook (USA), Alphabet, an American multinational technology holding company and the parent company of Google, are first on the list.\nTop 10 investors in R\u0026amp;D in 2021 vs 2016. Credit: The 2021 EU Industrial R\u0026amp;D Investment Scoreboard, European Commission, JRC/DG R\u0026amp;I.\n\u0026ldquo;International cooperation in research and science is very important to ensure the development of the most innovative products and services,\u0026rdquo; commented Tony Jin, Huawei\u0026rsquo;s chief representative in EU institutions.\nHuawei, a global telecommunications giant, climbed to the second place in 2020, compared to the previous year, when the company was ranked 3rd in the list. Most of the global research that Huawei conducts takes place in Europe. The company employs more than 2,400 researchers in 23 research centers across Europe. Through many partnerships with more than 150 European universities, Huawei is also integrated into the ICT research ecosystem in Europe.\nLessons learned for the EU\nCompanies have been asked in a parallel JRC survey about their expectations of where their R\u0026amp;D investments will take place. This study revealed no signs of erosion or offshoring to other regions by the EU\u0026rsquo;s leading R\u0026amp;D performers.\nAccording to the Commission, the EU remains one of the leaders in green high-value patents technology and for green patents in energy intensive industries, reflecting its transition to climate neutrality.\nJCR summarizes the following policy challenges for the EU:\nTo maintain leadership in the Automotive sector, which faces a dual-task: from the necessary transition to electric mobility and the growing integration of digital technologies. To restore a strong Healthcare sector by paying more attention to biotechnologies, which are increasingly at the heart of the development of new drugs. To make up for the lost time in ICT technologies by reversing the trends observed in the last decade, to extend the benefits of digital technologies to the entire economy, and, in particular, to use their enormous potential to solve environmental problems. To ensure strategic autonomy in key technology sectors, while maintaining its critical market segments to ensure the security of supply and stability of the essential supply chains. The sources: Global private sector R\u0026amp;D investments increased throughout pandemic and Commission reports first fall in industry R\u0026amp;D investment in ten years. If you find our posts engaging, you can subscribe here. If you have any questions or comments, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types ","date":"2 February 2022","externalUrl":null,"permalink":"/posts/evrope-investitsii-tehnologii/","section":"Blog","summary":"Companies in the EU and across the world have increased investment in research and development (R\u0026D) in the health and ICT services sector.","title":"Europe's Need to Invest More on New Technologies","type":"posts"},{"content":"","date":"2 February 2022","externalUrl":null,"permalink":"/categories/information-security/","section":"Categories","summary":"","title":"Information Security","type":"categories"},{"content":" We recently wrote about a new EU law regulating artificial intelligence.This article deals with the expert opinions about the regulation. In particular, they express their concerns about the imperfection of AI.\nAccording to scientists, super-powerful foundation models that adapt to various tasks can make all artificial intelligence systems unsafe, full of prejudice, and opaque. The proposed EU law on artificial intelligence may not be enough to mitigate this threat.\nSince the emergence of a super-powerful new type of AI has not been fully accounted for in the proposed EU law, this may mean that the law will quickly become obsolete. It is hard to predict how the technology will be implemented in the future. These can be new and unexpected ways.\nFoundation models are trained on enormous amounts of data by the largest technology companies in the world. Then they will be adapted to a wide range of tasks and will become the infrastructure on which other applications will be built.\nConsequently, any shortcomings in the foundation models will be inherited by the applications created on their basis. There is a concern that the underlying models will cause insufficient security and biases in AI.\nOne study showed that a model trained based on online texts reproduces the prejudices of the Internet, equating Islam with terrorism. This bias can unexpectedly manifest if the model is used, for example, in education.\nThus, if the base is erroneous, the subsequent use will be false.\nIn August, scientists from Stanford University have reported that there is no clear understanding of how the foundation models work, what will be in the error results, and what they are capable of at all. Even though some scientists are worried that foundation models will become widespread, some startups have already started to use models to create artificial intelligence tools and services. They include an automatically generated game \u0026ldquo;Dungeons and Dragons\u0026rdquo;, email assistants, and advertising copy.\nTraditional artificial intelligence systems are created for a specific purpose. For example, the diagnosis of X-rays is carried out after data collection, model construction, and deployment. Artificial intelligence can accurately determine whether a patient has pneumonia, spending much less time on it than a specialist.\nHowever, modern applications are isolated, and they cannot be used without human supervision because they do not have common sense knowledge.\nFoundation models are trained on a wide range of data, such as online text, images, or videos. They increasingly represent a combination of all three – and therefore, after some tweaking, can be applied to a wide range of different applications.\nFor example, GTP-3, a model created by the OpenAI Research Laboratory in San Francisco (but now licensed exclusively by Microsoft), is trained on 570 gigabytes of Internet text and can be configured to create, say, chatbots for all kinds of topics.\nBut the problem with training an artificial intelligence system all over the Internet is that it becomes much more difficult to understand why the foundation model gives a certain conclusion than when the data on which it is trained is precisely defined.\nAlthough AI can generate plausible answers to questions, foundation models do not have any deep understanding of the world. Their conclusions are not based on any truth; they are just based on statistical patterns that sound good together. In one test, the foundation model was deceived by claiming that the apple with the inscription \u0026ldquo;iPod\u0026rdquo; on it, is an iPod.\nIt may be good if an artificial intelligence system can offer creative ideas to the writer, but it is riskier if it is at the heart of a chatbot that should give accurate answers. Artificial intelligence does not have empathy. It collects a wide variety of data from the Internet, sometimes without any filter. It leads to the fact that chatbots\u0026rsquo; answers may sound unacceptably rude, touching on issues of gender, race, nationality, religion.\nMoreover, since these models extract publicly available data from the Internet, attackers can enter information online, tricking the artificial intelligence system into changing its output data. It is called \u0026ldquo;data poisoning.\u0026rdquo; It may lead it to think that, for example, the person who is being persecuted is a criminal or a terrorist.\nDig deeper\nCritics say that the problem with the EU\u0026rsquo;s proposed AI act is that it regulates or explicitly prohibits the specific use of AI, but does not delve into the foundation models underlying these applications. The act, for example, will ban artificial intelligence applications with \u0026ldquo;social scoring\u0026rdquo; or those that \u0026ldquo;exploit vulnerabilities of a certain group of people.\u0026rdquo;\nInstead, a general-purpose AI system will be covered by the act only if the “intended purpose” falls within its scope. Moreover, it means that the act will shift the burden of regulation from the major technology giants of the United States and China, which own foundation models, to European small and medium-sized enterprises and startups that use models to create artificial intelligence applications.\nAccording to experts, regulation should focus more on the general qualities of the entire artificial intelligence system, for example, whether it is biased or can tell the user that it is not sure of its answer.\nIf the foundation model has no idea of its own ”knowledge limitations”, it is OK for AI to recommend your next Netflix show. Still, it can be risky if it prescribes medications.\nHigh-risk systems\nLawmakers are likely to keep going back and changing the AI law in the future to ban or regulate new uses of AI subsequently, instead of making sure the underlying models are reliable in the first place. The foundation models should be classified in advance in the law as high-risk systems.\nOther artificial intelligence experts also agree that the act needs to be changed to consider the new challenges of the foundation models.\nA Commission spokesman confirmed that the AI act’s approach is to scrutinize the “intended use” rather than “the technology as such”. But if an AI system is classified as “high risk”, then “the underlying technology” will be “subject to stringent regulatory scrutiny.”\nThe list of what counts as “high risk” AI can also be “flexibly updated” if new and unexpected uses of AI “create legitimate concerns about the protection of health, safety, and fundamental human rights,” he said.\nThis article was rewritten and abridged to be published in our blog. The original article can be found here. * * If you find our posts compelling, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types ","date":"26 January 2022","externalUrl":null,"permalink":"/posts/ii-novyy-zakon-es/","section":"Blog","summary":"Academics warn ultra-powerful foundation models that can be adapted to a range of tasks risk infecting all AI systems with biases and security flaws.","title":"Expert Opinions: Artificial Intelligence and the New EU Law","type":"posts"},{"content":" In recent years some of the latest technologies, for example, IoT or SD-WAN, have become critical infrastructures for telecommunication companies and all surrounding industries. In this article, you will find a selection of technological trends in telecommunications for 2022.\nContinuing challenges in the telecommunications sector\nThere are more mobile phones than people in some parts of the world. Humanity has reached record levels, and in most developed countries, the total number of active mobile phones exceeds their population. However, despite the increase in the consumption of services, the sector\u0026rsquo;s performance in economic terms in some countries was negative. In reorienting the industry, operators must switch to digital transformation to be much faster and more flexible. If they want to return to previous levels, they need to identify methods that are more efficient, more flexible, and create fewer problems. Then, to achieve this, they have to integrate technology into their processes. It will simplify their organizational structures, processes, and systems. Internally, they need to use data to become more efficient and effective. Externally, it is essential to offer an innovative experience to customers and even develop new enterprises that have a significant impact.\nFive technological trends that will encourage innovation in telecommunications\n5G COMMUNICATION Today it is relevant to talk about the fifth generation of mobile networks. This new generation is very different from the first, as its primary application was exclusively voice communication. The first of the changes of this fifth generation will be the way to access the network and the benefits provided by WWWW (Worldwide Wireless Web). WWWW is designed for a mobile ecosystem where consumers will get seamless broadband connectivity, a rich ecosystem of mobile applications, and cloud services. 5G technology also promises data transfer speeds of up to 10 Gbps. It means that the speed will be 100 times faster than 4G.\nPractical application: the new 5G technology opens up new perspectives. The fifth generation of mobile telephony opens up significant commercial opportunities for the telecommunications industry. Its practical application extends to different services, such as transport, medicine, agriculture, public services, and others.\nWIFI 6 The WiFi organization (Wireless Fidelity) has launched a standard known as 802.11 ax, with the commercial name WiFi 6. Its main advantages are a large bandwidth for servicing devices, lower power consumption, and higher information acquisition speed. It means that one WiFi 6 access point can serve up to 500 devices simultaneously. Practical application: like 5G, WiFi 6 technology also has practical applications in entertainment, such as augmented reality or virtual reality. But it also has other applications in industry or sectors such as medicine: telemedicine, remote work, the Internet of Things, and smart city, which we will discuss in the next paragraph.\nSMART CITIES There are more and more Smart Cities in the world. Cities like Tokyo, New York, Singapore, and Barcelona are at the forefront of various Smart City-related activities. For example, environment, urban mobility, security, education, health, economy, and public administration. Smart Cities go beyond using technology to connect cities. Using the potential of innovation, we can solve problems related to life in cities to benefit citizens. For cities to continue to grow, it is necessary to introduce technologies such as 5G, WiFi 6, and others.\nPractical application: in general, smart city solutions can speed up emergency response, reduce travel time or reduce greenhouse gas emissions.\nEDGE COMPUTING Edge computing is one of the technologies that will define and revolutionize the way people and devices connect to the Internet. The growth in the number of Internet of Things devices leads to the appearance of an enormous amount of data to be calculated in data centers, which leads to limiting network bandwidth requirements. *Practical application: *the purpose of edge computing is to bring computing and data storage closer to the location where it is necessary to increase response time and save bandwidth.\nELECTRONIC SIGNATURE In the telecommunications sector, having the highest level of customer churn in the market, the signing of documents occurs constantly. During its life cycle, the customer must sign all kinds of documentation related to registration, such as a service provider agreement or obtaining a SIM card. Similarly, it is also necessary to sign a cancellation request and other relevant documents to make a legal cancellation. Telecom operators should implement technological tools to simplify these procedures and avoid problems with customers. Modern technologies would allow them to maintain dynamic and flexible relationships with their customers.\nPractical application: integration of electronic signature solutions helps speed up communication with customers: digital, agile, and paperless onboarding processes make this procedure an additional value for the client. In turn, digitization of signature processes increases the efficiency and productivity of internal business processes.\nIn 2022, an electronic signature using video identification will become one of the most popular innovative technologies in the telecommunications sector. In some countries, for example, in Spain, remote identification is already regulated as an acceptable method and guarantor. Its use will provide electronic signature processes with the speed and accessibility required by a digital client.\nThe original article can be found here. * * If you find our posts compelling, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # The EU law on Electronic Signatures The future of AI: regulation in Europe The Top 5 Myths about Cloud-Based Digital Signatures ","date":"19 January 2022","externalUrl":null,"permalink":"/posts/pyat-trendov-telekoma/","section":"Blog","summary":"The article deals with a selection of technological trends in telecommunications for 2022.","title":"Five technological trends driving innovation in telecommunications in 2022","type":"posts"},{"content":"","date":"12 January 2022","externalUrl":null,"permalink":"/categories/legislation/","section":"Categories","summary":"","title":"Legislation","type":"categories"},{"content":" The European Patent Office (EPO) started accepting qualified electronic signatures on licenses, registration of a transfer of rights, and other agreements.\nIn November, the EPO published the news that EPO now accepts assignments, licenses, and other recording agreements that have been executed using a qualified electronic signature.\nWhat is new?\nStarting from November 30, 2021, licenses, assignments, and other agreements executed via a qualified electronic signature will be accepted by EPO as evidence in support of registration of the transfer of rights or registration of a licence or other rights. A qualified electronic signature is considered to fulfil the legal requirement for a signature concerning data in electronic form in the same way that a handwritten signature does with respect to data on paper. According to the definition provided in Regulation (EU) No 910\\2014, a qualified electronic signature is an electronic signature that is:\n(a) uniquely linked to and capable of identifying the person signing;(b) created by means that the person signing can use with a high level of confidence and over which they have sole control;(c) associated with the electronic document to be authenticated in such a way that any subsequent change in the data is detectable;(d) created by a qualified electronic signature device; and(e) based on a qualified certificate. The requesters should establish that the electronically signed document meets the above requirements. They will generally be met if the parties use digital execution software. An individual needs a digital certificate to sign the document via such software. If the person does not have a digital certificate, one may need to get it from a Trust Service Provider. Previously, the EPO accepted only contracts, licenses, and other agreements that had been executed using wet-ink, handwritten signatures. Still, a scanned copy of such documents remains sufficient for registration.\nAdditional formalities for registering assignments, licenses, or other agreements in the EPO\nAll other formal requirements for assignments, licenses, and other agreements in EPO remain the same. Here are the three main things that need to be included:\n**European Patent Application Number: **EPO will not accept assignments, licenses, or other agreements that do not mention the EP number or (if applicable) the corresponding PCT application number. Signatures of all parties are significant to the relevant agreement/license. **Job titles: **The EPO still requires the signatories to be sufficiently senior (for example, these must be board-level positions, such as CEO, President, or Managing Director for UK companies or Company Secretary for US companies) and have proof that they are authorized to bind the relevant party; \u0026ldquo;Authorized Signatory\u0026rdquo; is usually insufficient without additional evidence. The possibility of using electronic signatures will ease the documentary burden for parties wishing to register assignments, licenses, or other agreements in EPO; it also brings EPO into line with UKIPO and EUIPO (UK Intellectual Property Office (UKIPO) and European Union Intellectual Property Office (EUIPO)).\nHowever, it is still significant to register changes or interests of third parties related to registered intellectual property rights with all relevant intellectual property offices. Many patent and trademark offices do not accept documents with an electronic signature. Therefore, although this change in EPO practice is very welcome, it does not mean that digital execution will always be the best solution.\nThe original aricle is here. The notice of the EPO from their Official Journal can be found here. *You can send us any comments to our *email; we will be elated to get feedback. If you find our articles fascinating, you can subscribe here.\nSee also # Vaccine Passports: Unlocking the EU Travel Advantages of a cloud-based qualified digital signature EFPE Conference 2021: Review ","date":"12 January 2022","externalUrl":null,"permalink":"/posts/kep-evropeyskoe-patentnoe/","section":"Blog","summary":"The European Patent Office (EPO) started accepting qualified electronic signatures on licenses, registration of a transfer of rights, and other documents.","title":"Qualified Electronic Signatures at the EPO","type":"posts"},{"content":" Enterprises and organizations frequently use electronic signatures to improve the efficiency of electronic workflow. In particular, for the execution of documents and their exchange. The increasingly ubiquitous spread of electronic signatures makes them open to fraud if they are not monitored and policed. Some time ago, in 2016, the Ontario Superior Court considered the issue in the case R. v. Pusey 1, where evidence of the use of an electronic signature was the basis for the court\u0026rsquo;s decision to convict the accused on fraud charges.\nEvidence\nThe defendant, Mr. Pusey, was a former staff director at the Fred Victor Center (the “Center\u0026quot;), a charitable organization based in Toronto. He was also the head of two companies (the \u0026ldquo;Companies\u0026rdquo;). These companies billed the Center for more than one hundred thousand dollars for work that was performed by other employees or subcontractors of the Center, in violation of the Center\u0026rsquo;s Code of Conduct regarding Conflicts of Interest.\nThe scheme was discovered when the Center’s employees questioned some invoices for payments made to the Companies following the cheque details signed by the accused. As a result, the Center paid out to the Companies various payments totaling more than $115,000 over 16 months. The accused testified that the arrangement was approved by the Center’s Executive Director. Allegedly, the scheme was that the Companies billed the Center for work done by subcontractors. Mr. Pusey then paid them in cash to get savings and tax benefits for the Center. The only documentary evidence presented by the accused were contracts allegedly signed by Mr. Pusey (on behalf of the Companies) and the Center’s Executive Director.\nUse of an Electronic Signature\nThe Center’s Executive Director testified that the contracts were fake, and refused to sign them. The Court examined evidence that the accused\u0026rsquo;s computer and flash drive contained electronic versions of the Executive Director\u0026rsquo;s signature, and also found that the accused would have had access to the signature.\nVersions of the electronic signatures on the accused\u0026rsquo;s hard drive were created and modified on the same day, which coincided with the first date when one of the Companies billed the Center.\nThe report of the Center of Forensic Sciences found that the electronic signature and the \u0026ldquo;contract\u0026rdquo; signature came from the same signature source “within the limits of practical certainty.\u0026quot;. The Judge declared that \u0026ldquo;the signature on the so-called contract and the electronic signature found on Mr. Pusey\u0026rsquo;s computer\u0026hellip; are identical.\u0026rdquo; The Court rejected Mr. Pusey\u0026rsquo;s explanations and alternative theories when finding him guilty of fraud.\nKey Findings\nThis case demonstrates the legal provability and security problem associated with electronic documents and signatures on negotiable instruments.\nIn most common law jurisdictions, including Ontario, legislation has been in place for many years making the use of electronic signatures legally provable.\nThus, almost all possible documents required by law to be executed in writing can be signed with an electronic signature, with some exceptions (such as wills and trusts).\nHowever, most legislative acts regulating the use of electronic signatures do not impose any specific standards for reliability or security. As a result, the person relying on the electronic signature or making a decision based on it determines its reliability or effectiveness.\nAttempts to fraudulently misrepresent or forge an electronic signature can be easily disclosed if, as in this case, there is competing objective evidence to reveal the fraud. In the absence of specific legislative procedures or security requirements for electronic signatures, this case demonstrates that organizations should consider whether their document management and security systems are sophisticated enough to track the use (and possible misuse) of electronic signatures for everyday transactions and documents.\nThe original aricle is here. *You can send us any comments to our *email; we will be elated to get feedback. If you find our articles fascinating, you can subscribe here.\nSee also # The EU law on Electronic Signatures The future of AI: regulation in Europe The Top 5 Myths about Cloud-Based Digital Signatures ","date":"6 December 2021","externalUrl":null,"permalink":"/posts/kejs-kanada-ukradennaya-podpis/","section":"Blog","summary":"Established case law demonstrates that electronic signatures are admissible in court. A stolen electronic signature helped to prove the defendant’s guilt.","title":"A Legal Case from Canada: a Stolen e-Signature was Used to Convict","type":"posts"},{"content":" Passwordless authentication that seamlessly combines security and user experience is crucial for better user protection in an enterprise. Still, most enterprises stick to password-based authentication, which is not that secure but quite risky. Some of the organizations tend to implement more secure systems.\nThere are various methods of sufficiently reliable authentication, for example, password managers, single sign-on technology, multi-factor authentication. Each of them has its methodology and a unique set of advantages. However, they also have their drawbacks.\nAlthough passwords are the most common authentication method, they are considered the most unreliable. The risks of this method are huge and exceed the imaginary convenience. According to Verizon\u0026rsquo;s 2021 Data Breach Investigation Report, 61% of breaches involve credentials. Despite this, passwords remain our default authentication method and often the only authentication method for enterprise systems and applications. The question is, why do we stick to an outdated authentication method that has disappointed users for a long time, and at the same time, it is beneficial to hackers?\nThree main authentication categories make up for the shortcomings of password authentication: password managers, single sign-on (SSO), and multi-factor authentication (MFA).\nPassword Managers Password managers generate, store and automatically fill in passwords for users who need to remember only one master password. This method solves the primary causes of human errors in authentication, including our tendency to short, weak, or template and recycled passwords. To this end, password managers can significantly improve password hygiene and simplify the login process.\nUnfortunately, password managers are not efficient authentication tools for extended user bases such as enterprises. The password managers control the generation and use of employee passwords, but they lack enforcement. Password managers can\u0026rsquo;t control how employees create and interact with each password; they only nudge them in the right direction if and when they choose one.\nThe misuse and enforcement of password managers also make it difficult for real visibility into the environment\u0026rsquo;s application inventory; as a result, gaps in accounts not protected by a password manager lead to an unknown number of missed detections. By contrast, using corporate password managers for personal accounts requires security analysts to analyze false alarms.\nMFA and Single Sign-On Security Assertion Markup Language (SAML) is a modern single sign-on solution for access control. It is particularly beneficial for securing the growing use of enterprise applications.\nThe solution allows users to log in to multiple accounts with a single set of credentials. Unfortunately, it is difficult for many enterprises to estimate the full potential of SSO. The identity providers often offer several IAM solutions for the prevalence of shadow accounts. It turns out they are significantly more expensive after accounting for the operational overhead of implementing single sign-on and licensing costs.\nLike single sign-on, MFA solutions cannot provide full enterprise coverage in practice. Even if the staff does not spend time on security issues after the MFA implementation, approximately the same time they will spend on maintaining their relevance.\nTo emphasize the importance of time, let\u0026rsquo;s consider businesses accepting an average of more than ten applications per month; while only onboarding four to single sign-on providers. It means that a significant backlog of almost ten applications remains without protection each month.\n**How to Reduce Risks ** Nowadays, it is difficult to avoid using passwords, and it is risky to believe that any password protection tool is better than nothing. In addition to the risk they create, they often annoy users. The authentication space is still waiting for alternative methods that can replace existing ones. Such methods should be effective and safe. Preferably, they should be implemented with minimal manual effort.\nThe inventory of applications is the first important step towards more advanced IAM solutions and the return of control over the security of enterprise passwords. Each account connected to a corporate environment poses a significant risk and should be treated as such; an application with one user login can be just as risky as another with hundreds.\nRisk classification in such circumstances can help understand how to best allocate time and resources for password protection. Data-based analysis can and should help predict the impact or likelihood of breach on these risk categories to make informed decisions.\nFinally, the cybersecurity industry must collectively find new and better ways to hold the line until we get to a better password-free place. We are in an era when business applications are increasingly self-service to maximize agile adoption. If it is impossible to eliminate all password vulnerabilities in user accounts, organizations should instead learn to change the paradigm of access to business applications towards self-management.\n*The article was originally written by Idan Fast and can be found *here. This article was rewritten and abridged to be published here. If you find our posts engaging, you can subscribe here. If you have any questions or comments, you may write to info@digt.com: we will be pleased to get feedback.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types ","date":"24 November 2021","externalUrl":null,"permalink":"/posts/besparolnoe-budushchee/","section":"Blog","summary":"Passwordless authentication that seamlessly combines security and user experience is crucial for better user protection in an enterprise.","title":"Waiting for the Passwordless Future: Reduce Risks, Secure Enterprise","type":"posts"},{"content":" Increasing demand for access to education data calls for more secure user authentication, as state and local educational agencies build robust education data systems to facilitate the management and sharing of student records. The article deals with the necessary steps to better user authentication in the educational sphere.\nSchool systems used to be of closed types, which simplified maintaining security a lot. However, the interconnectedness required by the Internet age made these systems open for interoperability. Unfortunately, it has exposed institutions to significant risks. Personal data can be compromised or shared and monetized by unscrupulous service providers.\nTo mitigate these risks, schools need an effective authentication system for students, staff, and teachers. It has to restrict access to institutional resources without compromising user data. There are many user authentication methods applied in education. Although, not all approaches are the same in terms of security and privacy.\nHere are some steps that schools can take to authenticate their students, staff, and teachers securely.\nUse Single Sign-On First of all, institutions should use Single sign-on Authentication (SSO) to verify users’ eligibility to access resources.\nPeople often use the same passwords, even though they are advised not to do so. When they have many accounts and are used to entering the same credentials on multiple systems, they entrust the data to numerous parties. Single sign-on provides access to many systems through one account and sign-in process. It reduces the number of parties to which credentials are passed.\nSingle sign-on is an excellent authentication method for several reasons. It lessens administrative burden in comparison with creating user accounts manually or through import.\nIt is less vulnerable to fraud than email authentication. It reduces password fatigue and provides a smoother user experience. Most importantly, with SSO, personal data is protected more than through any other authentication method. Anonymise User Data In addition to limiting the number of parties to whom data is transmitted, it is essential to ensure the anonymity of the transmitted data.\nInstitutions should use an opaque, immutable, unique identifier for each student, teacher, and employee who access resources. These identifiers must be different from any credentials known and used by the users themselves. Also, they should not contain any personal information such as names or email addresses.\nInstitutions should set default single sign-on policies to provide only the minimum set of anonymized data required. Many applications and services are designed with a default disclosure policy and will release this data to advertisers. Ensuring your institution’s default implementation is anonymized will prevent data leakage to external parties.\nImplement Multi-Factor Authentication Single sign-on verification can be even more secure when combined with multi-factor authentication (MFA). Users have to take additional actions to access the site, system, or platform when using MFA. It usually involves entering a code sent to the phone number or email address associated with the account being accessed. Requiring students, staff, and faculty to verify their identity when logging in this way can significantly increase data security.\nEven accounts with strong passwords can be compromised. Implementing an MFA with your institution\u0026rsquo;s identity provider can prevent unauthorized persons from hacking and using these accounts.\nChoose trusted partners The methods described so far are all measures that schools can take on their own to improve data security. But institutions need to consider more than just their systems and policies when it comes to protecting privacy. They should also take into account those of any external parties with which data is exchanged.\nAs you know, some service providers exchange user data and monetize it. Others may lack an adequate policy and guarantees for the protection of the data entrusted to them. With the growing number of cyber-attacks and strict privacy laws worldwide, colleges and universities need to check potential suppliers and partners for their ability to protect personal data.\nWhen evaluating the capabilities of a data security service provider, many factors must be taken into account. In particular, do they comply with data protection laws? Do they embed reliable security algorithms into their software products? Do they provide technical support? These factors should be evaluated before entrusting the implementation of authentication to third-party companies.\nThe original blog post can be found here. If you find our posts compelling, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types ","date":"10 November 2021","externalUrl":null,"permalink":"/posts/autentifikatsiya-obrazovanie/","section":"Blog","summary":"Increasing demand for access to education data calls for more secure user authentication. The article deals with the necessary steps.","title":"The Four Steps to Better User Authentication for Educational Institutions","type":"posts"},{"content":" When consumers create accounts to shop online, retailers can use their purchase history to offer a more personalized shopping experience. It increases the retail conversion rate to 15%. However, retailers have a hard time convincing people to sign up. Sometimes customers refuse to place an order just because they were asked to create an account.\nAuth0 surveyed more than 8,000 consumers in six global markets (UK, France, Germany, Australia, Singapore, and Japan) to research how they prefer to log in. They found widespread frustration with standard login methods with username/password (UP) and businesses that do not meet their expectations for ease of login.\nBelow are four authentication tools that can increase the conversion rate in retail by creating a more simplified and secure login that satisfies users.\n1. Multi-factor Authentication (MFA) MFA requires users to verify their identity in more than one way, which helps reduce the likelihood of unauthorized access to their data. For example, a user can enter a password and then confirm their additional account or device using a link sent to their email address or phone.\nConsumers want to know that companies are protecting their data. They want to be sure that companies they are dealing with have reliable security practices. MFA helps retailers provide consumers with greater confidence that their data is protected as it blocks 99.9% of attacks.\nAuth0 Survey: While 49% of surveyed consumers noted that they are more likely to sign up for an online account if a business offers an MFA, only 28% of the surveyed companies currently offer it as part of the login process. This discrepancy arises from the notion that a few steps in an MFA mean extra hassle for both users and the business.\nHowever, MFA is easy to implement; many companies quickly adopted it when COVID-19 forced them to switch to a remote workforce in 2020.\nA business use case: ecobee, the smart device retailer, wanted to protect consumers by using ecobee home monitoring products, so they outsourced the implementation of MFA. The team was thrilled that they were able to bring MFA to customers without starting from scratch. 2. Biometrics Measurable human traits, characteristics, or behaviors are used in biometrics to confirm user identity. Fingerprint scanning and facial recognition are the two most common forms of biometrics. However, the list of biometric parameters is growing. You can also recognize the voice, gait, iris, and even DNA.\nBiometric characteristics are harder for hackers to fake in comparison with usernames and passwords. These are more reliable authentication methods from a security point of view. Consumers also like it because it is faster than username/password authentication. Moreover, they do not have to struggle with remembering login credentials.\nAuth0: While 46% of the surveyed consumers said they would be more likely to log in if they could use biometrics, only 21% of the surveyed businesses currently offer it. Implementing biometrics will lead to improved customer service and higher retail conversion rates.\nNevertheless, it can be difficult for a business to develop biometric authentication within a company. To prevent the company\u0026rsquo;s resources from being diverted, some companies prefer to outsource the implementation to third-party vendors. Many providers specialize in identity management and already have experience with biometrics.\nA business use case: Consumers\u0026rsquo; use of Microsoft\u0026rsquo;s Windows Hello biometric authentication tool, which allows users to log in by scanning their face, iris, or fingerprints instead of a password, jumped from 69.4% to 84.7% in 2019 alone. Disney began experimenting with a facial recognition system at Walt Disney\u0026rsquo;s Magic Kingdom theme Park and used fingerprint scanning to prevent ticket fraud before COVID-19 appeared.\n3. Social Logins Social media login uses existing login information from a social media provider. It allows consumers to access a third-party website account without having to create another one. While the number of social providers continues to grow, the main networks are Facebook, Google, and Twitter.\nConsumers prefer social accounts to traditional UP authentication, as they usually allow them to create accounts and log in with a single click. As a result, social logins increase the conversion rate to 20%, although some companies report that it reaches 40%. Social logins also provide access to extensive user data, allowing you to use more personalized, targeted marketing with individual consumers.\nAuth0: Our survey found there was not an immense gap between consumers and companies using social logins: 37% of consumers said they were more likely to subscribe to it, and 31% of companies currently offer it.\nSocial logins are usually connected to larger companies with established data privacy measures, but security can be compromised if users reuse passwords. Consumers using social logins need to change their passwords on different platforms. You can improve the security of social logins by combining them with MFA.\nA business use case: WishPond: after the social network login option became more visible than UP authentication, the company increased conversions by 8.5%.\n4. Passwordless Authentication without a password is a confirmation of the consumer identity by something other than a password. In addition to biometrics, typical password-free options include magic links (the user is sent a link to login after submitting an email), one-time passcodes, and push notifications.\nSince an average consumer has about 100 passwords, passwordless authentication reduces the potential frustration of users logging in. The lack of traditional UP authentication also means increased data security. Verizon notes in its 2021 data breach investigation report that stolen login credentials are the primary way organizations are hacked.\nAuth0: Despite this, passwordless authentication ranked last in our survey both in terms of the probability of consumer registration (34%) and in terms of business use (20%). Traditionally, the IT infrastructure in large companies has been configured for authentication, so for businesses, implementing passwordless technologies on a large scale can be a complex process.\nA business use case: GrandVision, an optical retail chain, made \u0026ldquo;the checkout process as convenient as possible for customers” by providing a third-party vendor with the ability to authenticate without a password - accounts are created with a simple click of a button. As a result, GrandVision increased the conversion rate to 54%.\nAuthentication Technologies Improve User Experience By using one of the above authentication tools to provide consumers with an easy and secure way to log in, you can satisfy users and continue to strengthen their connections with your brand through personalized marketing, while increasing the retail conversion rate.\nThe whole article was originally written by Diego Poza and can be found here, with all the reference links to statistic numbers. This article was rewritten and abridged to be published here.\nIf you find our posts engaging, you can subscribe here. If you have any questions or comments, you may write to info@digt.com: we will be delighted to get feedback.* See also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types ","date":"3 November 2021","externalUrl":null,"permalink":"/posts/autentifikatsiya-riteyl/","section":"Blog","summary":"The article deals with advice on reducing the number of abandoned carts, increasing the simplicity and security of the user login process.","title":"Trustworthy Authentication Tools That Increase The Conversion Rate In Retail","type":"posts"},{"content":" Passwordless authentication is the process of verifying a software user\u0026rsquo;s identity using anything other than a password. The most common methods of such an authentication include verifying ownership of an additional device or user account or biometric characteristics.\nPasswordless authentication can reduce costs and security risks for any organization. That is why more and more businesses are switching to passwordless authentication and implementing it in their organizations.\nWhy Passwordless Authentication is Better than Passwords\nPasswordless authentication provides a smoother process than traditional username and password (U/P) authentication for both you and your users. It will not only save you money but may even lead to increased sales.\nReduced security risks According to Verizon\u0026rsquo;s 2021 Data Breach Investigation Report (DBIR), credential vulnerabilities account for more than 84% of all data breaches. Eliminating passwords reduces the risk of data leakage because it reduces the ability of an attacker to use them (and the insecure behavior that often exposes them) against you and your users.\nFor example, cybercriminals often use credential entry (using compromised user credentials from a breach to gain access to another organization) to hack into an organization because more than two-thirds of people reuse their passwords. Deleting passwords makes it impossible for cybercriminals to use credentials obtained elsewhere to access accounts on your system.\nPasswordless authentication reduces your organization\u0026rsquo;s vulnerability to phishing attacks (tricking users into downloading malware or providing confidential information with a malicious email).\n36% of all data breaches counts for phishing attacks stealing account information (usernames and passwords mostly). If you eliminate passwords, it means your users or employees will not accidentally provide attackers anything to access their accounts, even if users receive a phishing email.\n**Better user experience to reduce costs (and increase sales) **\nThe average person has to remember about 100 passwords and spends 12.6 minutes every week resetting them (often through a call to the support service). It ends up costing your organization more money in password reset and customer service time than you think.\nHowever, implementing passwordless authentication can reduce or eliminate these costs since your users will log in without a password. It also eliminates the need to store and maintain password databases.\nEliminating passwords may increase sales for some businesses, as many surveyed IT professionals reported that they did not manage to complete a personal transaction due to a forgotten password.\nFinally, user experience can be a competitive advantage for software companies (even at the enterprise level). Thus, reducing login friction can also encourage users to choose you over your competitors.\nTypes of authentication without a password\nTraditional username and password authentication require a user to enter something they know (a password) to confirm who they are. But passwordless authentication methods require the user to demonstrate that he has something (a possession factor) or that they are something (an inherence factor), both of which are harder to get around.\nThe following are the most common methods used to test both inheritance factors and possession factors:\n\u0026ldquo;Biometrics\u0026rdquo;: Many physical traits are more or less unique to each person. Biometric authentication uses these unique physical characteristics to verify whether a person is who they say they are without asking for a password. For example, the probability that two faces are the same is less than one in a trillion, so facial recognition is an effective way to verify identity. \u0026ldquo;Magic Links\u0026rdquo;:** **Instead of asking the user for a password, this form of passwordless authentication asks the user to enter their email address in the login box. They are then sent an email with a link that they can click to log in. This process is repeated every time the user logs in. \u0026ldquo;One-time Passwords/Codes\u0026rdquo;:** **One-time passwords (OTP) or one-time codes (OTC) are similar to magic links but require users to enter the code you send them (via email or to their mobile device via SMS) instead of simply clicking on the link. This process is repeated every time the user logs in. \u0026ldquo;Push Notifications\u0026rdquo;: Users receive a push notification on their mobile devices through a dedicated authenticator application (for example, Google Authenticator) and open the app with a push notification to confirm their identity. How to implement authentication without a password\nEncoding passwordless authentication is more complicated than simply telling your development team to change the login box. However, third-party vendors offer a faster and more secure implementation that is more secure and modern than anything that can be built in-house.\nA lot depends on the design of your existing Identification and Access Management (IAM) systems. But the point is that secure implementation is much more complicated and expensive than most realize and often requires dedicated resources for development over a long period (and then scaling and maintaining those systems after implementation).\nAs a result, many organizations prefer to work with a professional identity provider. In some cases, it can reduce the time to implement passwordless authentication for millions of users to several months. It also decreases many of the maintenance costs they would face in the future.\nThe referral links to statistics are in the original article is here. If you find our posts fascinating, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types ","date":"26 October 2021","externalUrl":null,"permalink":"/posts/besparolnaya-autentifikatsiya/","section":"Blog","summary":"Passwords have proven to be a weak form of security. Read how you can raise the level of enterprises’ data protection by passwordless authentication.","title":"Passwordless Authentication Reduces Security Risks and Costs","type":"posts"},{"content":" Many enterprises worldwide have faced the need to provide employees with the opportunity to work remotely. Here are 7 Things You Should Know Before Working from Home.\n62% of Wi-Fi security incidents occur in cafes and coffee shops ❌ Do not use public Wi-Fi. ✅Make sure your network is secured, even if it means working from home. If you need to work in a public place, use a VPN.\n74% of IT managers of global enterprises report that their organization has had a data leak due to problems with the security of mobile devices ❌ Do not use unauthorized personal devices to perform work-related tasks. ✅ Use the gadgets provided by the company. If you can, work with digital certificates to verify the authenticity of the devices accessing your systems.\n21% of files in the cloud contain confidential data ❌ Do not download applications or new software without getting permission from the IT department. ✅ Only use cloud services that have strong security policies. You may also choose those integrated with more comprehensive PKI-based security solutions.\nBy 2025, 90% of organizations that fail to control public clouds use will have improperly shared confidential data ❌ Do not share confidential information on any unknown platforms. They should always be checked or protected by your team. ✅Follow the IT policy regarding the use of the Internet and applications and participate in enterprise-wide security training. If you can, use certificates to encrypt and authenticate your email.\n80% of hacking-related violations are related to compromised and poorly protected credentials ❌ Do not lose your vigilance. ✅Always use two- or multi-factor authentication and strong passwords. A secure password management program is an excellent way to generate and store your credentials so that you don\u0026rsquo;t have to remember them right away.\nAt least 350,000 new malware are detected every day. ❌ Do not ignore antivirus expiration notifications. ✅Encourage your IT teams to invest in centralized antivirus management technologies. They let easily monitor and update software in the enterprise.\nEnterprises achieve a 70-80% increase in efficiency after eliminating manual processes having integrated digital technologies, such as electronic signature solutions ❌ Don\u0026rsquo;t waste time sending hand-signed documents between locations. ✅ Consider using digital signatures to sign fixed-term contracts, policies, and other legal documents.\n*These stunning pieces of advice are taken from the GlobalSign Infographic. * *You can send us any comments to our *email; we will be elated to get feedback. If you find our articles fascinating, you can subscribe here.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types ","date":"20 October 2021","externalUrl":null,"permalink":"/posts/7-veshchey-udalennaya-rabota/","section":"Blog","summary":"Remote work and security: how to ensure total protection of corporate information outside the office.","title":"7 Things You Should Know Before Working from Home","type":"posts"},{"content":" According to the FBI, as more and more people prefer remote or online working after 2020, the number of cyberattacks to disrupt online activities is also growing. It has been researched that a single successful cyber attack can impact an organization and its users increasingly for years.\nFor instance, between 2017 and 2020 the number of records exposed due to data leaks grew from 197 million up to 37 billion, though the total number of data leaks decreased. As IBM informs, only in the USA, between 2018 and 2020, the average cost of data leak for the companies that fell victim to cyberattacks grew from $ 7.91M to $ 8.64M.\nA number of methods used by cyber criminals are based on a human’s mistake, when even the smartest employees’ unconscious clicks can lead to malicious links. While other cyberattack methods take advantage of your data security gaps to get access to your confidential data.\nHere are 7 most common cyberattacks your organization can face in 2021 and ways to prevent the data leaking they can cause.\n1.Malicious software attacks\nMalware means numerous types of software aimed at infiltrating, spying on or creating a backdoor in an organization’s data system, including trojans, worms, ransomware, spyware and adware. According to experts’ reports, since the beginning of 2020 malware usage has grown up to 800%.\nMalware can cause serious data leakage and disrupt business operations. For example, Microsoft fell victim to ransomware when WannaCry made use of its operation weak points and plenty of banks, medical service providers and other companies all over the world got one and the same message on their displays:\nSource\nTo restore access to their computers and also to all the unbacked-up files, companies had to pay redemption to WannaCry creators in Bitcoin.\nMalware is usually downloaded unintentionally by clicking a malicious link when a user is made to think to be downloading something legal though it is not.\nHow to defend against malware attacks\nReduce the chance ofbeing infected by malicious software by teaching your employees how to detect suspicious links and pop up windows.\nUse extra means of protection against malware, such as antivirus software and operating system renewal to patch known security gaps. For instance, Equifax data leak could have been prevented should a proper be installed timely.\n2.Phishing attacks\nPhishing attacks are aimed at stealing users’ information or making them download malicious software by sending emails and text messages. It is a scam though looks like a real request. Verizon reports that phishing attacks are the most widely-spread reason for data leakage all over the world in 2021 and caused most prominent cases of cybercrime last decade. By breaching the AP News account the intruder falsely twitted that the White House fell victim to a targeted phishing attack (spear-phishing). So did the bad actors who breached the election campaign chairman’s confidential emails to Hillary Clinton before the 2016 election.\nHow to protect against phishing attacks\nThe best way to defend your company from phishing attacks is to educate your employees in identifying suspicious emails and text messages. CSO has made a list of sources that can assist you in teaching your teams how to detect phishing attacks. 3. DDoS attacks\nDDoS (Distributed denial of service) attacks violate the traffic of an application, website, service or a server by suppressing it with a flow of a compromised computer net (botnet ) trafic, that prevents real users from gaining access to it. The hardest DDoS attack in history took place in 2018 when GitHub received 1,35 terabits of traffic per second and was offline for about 20 minutes as a result.\nAccording to Kaspersky security company, DDoS attacks are a common thing and their number increased by 50% for only one year, the most significant surge occurring at the beginning of pandemic 2020.\nHow to protect yourself from Distributed denial of service attacks\nDDoS attacks are tricky to identify as they are hardly differentiated from legitimate traffic. Some ways of protection include blocking of all traffic for a while, traffic rate-limitation to a website, using a web application firewall to detect suspicious traffic patterns, or distributing traffic across a network of servers to cut the attack’s effect. 4. Man-in-the-middle attacks\nMan-in-the-middle (MtiM) attacks are made by bad actors who spy on you or intercept messages between you and your users or employees for stealing your personal or corporate information or for redirecting it to another place of destination or in espionage situations.\nMitM attacks is a relatively rare cyber attack type as most of its goals can be achieved with the help of malicious software. Though, being hard to reveal, they may be of great danger for organizations especially since more employees are working remotely after 2020.\nFor example, remote employees often work in cafés or coffee shops where fake WiFi networks can be easily deployed. Connecting to these networks and using them, unwillingly, people fall victim to criminals’ espionage. How to defend yourself from MitM attacks\nThe best way to protect yourself from MitM attacks is end-to-end encryption protocols such as Transport Layer Security (TLS). In addition to that, if your employees use VPN for corporate network access, any information shared during their session is guaranteed to remain private, no matter whether the network belongs to a malefactor or their coffee shop’s WiFi lacks security.\n5. Credential stuffing attacks\nFilling in credentials is a brute-force cyberattack method when intruders make use of once stolen usernames and passwords from one data leak to get access to another organization’s user account.\nAccording to statistics, 65% of all people use one and the same password for several accounts, so credential stuffing attacks are very likely to occur. That is why filling in credentials is one of the most common reasons for data leakage in the world.\nHow to protect yourself from credential stuffing attacks\nThe best ways of preventing credential stuffing attacks are passwordless authentication and multi-factor authentication (MFA). Passwordless authentication prevents malefactors from using stolen credentials by eliminating them completely while MFA demands identity verification in one or more ways in addition to the stolen credentials that the intruders use to log in.\n6. Password spraying attacks\nAnother type of brute-force attack is password spraying when intruders try to guess a user’s password from a list of mostly spread passwords such as “QWERTY”, “123456” or “password.”\nPassword spraying is as common as credential stuffing. So, according to Verizon’s 2020 Data Breach Report more than 80% of all hacking-related data leaks included brute-force methods like password spraying.\nHow to defend yourself against password spraying attacks\nPassword spraying attacks have much to do with credential stuffing attacks here, so using passwordless authentication or MFA, can prevent this type of cyber attack. Besides, following the NIST Password Guidelines can also be of great use, as they are considered the top password standards globally.\n7. Mobile device attacks\nMany organizations tend to elevate the mobility of their employees and, one the one hand, it improves operational efficiency and productivity. But on the other hand, cybercriminals, being aware of this fact, are focusing on mobile devices more and more often from year to year with various attacks mentioned above, which makes organizations more vulnerable to a data breach through more handheld devices than ever before.\nSo was Pegasus\u0026rsquo; attack on Apple’s iOS software. Phishing text messages asked iPhone holders receiving a text message to follow a link inside. Clicking the link started the installation of spyware capable of monitoring people through their camera and microphone. Should iPhone users be infected had their login credentials be stolen from Gmail, WhatsApp, and other susceptible communication applications.\nHow to defend against mobile device attacks\nBoth an excellent enterprise mobility management (EMM) program and mobile device management (MDM) tools will be of great help in protecting any company data that your employees may have on their personal or work devices. Unauthorized access to work applications containing sensitive information can also be prevented via multi-factor authentication and other identity and access tools.\nConclusion\nUse strict authentication protocols. They will help to minimize, eliminate or totally prevent damage from cyberattacks from the above-mentioned list.\nDo not forget about other protection tools. Start with sophisticated password policy and sound employee education. Multi-factor authentication or passwordless authentication together with brute force protection will add a new dimension of safety to your system.\nThe article has been based on the cybersecurity report \u0026lsquo;The 7 Most Common Types of Cybersecurity Attacks in 2021\u0026rsquo;.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions Work from Home: Securing Corporate Data outside the Office 7 Things You Should Know Before Working from Home ","date":"13 October 2021","externalUrl":null,"permalink":"/posts/kak-protivostoyat-kiberatakam/","section":"Blog","summary":"7 most spread recent cyber attack types. Learn which tools and methods will help you defend against common cyberattacks today.","title":"How to Fight against Most Spread Recent Cyberattack Types","type":"posts"},{"content":" The Provincial Court of Lleida, section 2, issued decision 74/2021, exempting the defendant from paying a loan provided by a company executed through a contract signed through a well-known commercial platform. The verdict in question is a decision rendered in the second instance, by which the provincial court decides on an appeal against the decision rendered by the court of the first instance.\nAt first, the decision of the court of first instance considered the claim filed by the company-lender of the loan against the alleged debtor, using as a basis an electronic contract signed through a commercial platform. To do this, the court of first instance considered that the defendant\u0026rsquo;s identity as a debtor should be proved not by the signature contained in the document itself but by a conclusion made based on a set of facts. For example, two days after the presumed date a deposit was made to an account co-owned by the defendant.\nThe Court of Appeal, when studying the system of the platform used, analyzed the quality of the electronic signature performed, specifying that the one who receives electronic documents through the platform does it by e-mail and signs them \u0026ldquo;manually\u0026rdquo; for the subsequent return. Without having \u0026quot;\u0026hellip; any evidence that the person who signed is the one who says they signed, and in [this] case it also appears in the certificate issued\u0026hellip; [platform]\u0026hellip; there is no account authentication\u0026hellip;\u0026quot;\nAfter this check, the Provincial Court determined that the only connection with the signatory that offers a signature made through this digital platform is the IP address from which the signed document was sent. The person who provided the loan and the loan recepient signed and sent the document from the same IP address. The coincidence of these data indicates that the same device was used for the signature of both parties. Or at least both devices were connected to the same Wi-Fi network. It was impossible to obtain any relevant evidence for the accreditation of the debtor\u0026rsquo;s identity.\nThe decision of the Provincial Court then declared that** the signature made through the specified commercial platform was not an electronic one based on a digital certificate issued by a legally authorized person. **\nAs a result of the above, it was assumed that there was no evidence since the identity of the person signing the loan agreement was not confirmed by a signature made using the digital platform used.\nThe court decision concluded that the document submitted as the basis for the claim for recovery (the loan agreement) is private. The signature did not have the characteristics of an electronic signature reliable enough to be a proof in the court. It was much less qualified and, at the same time, since it was not recognized by the alleged signatory, the burden of proving its authenticity fell entirely on the plaintiff-creditor company.\nThe evidentiary value of an electronic signature in a lawsuit directly depends on the type of signature used.\nEven though solutions for electronic signatures or some commercial platforms are legal, not all of them have evidential value in the court. The signatory may well try to ignore the signed document and not fulfill their obligations under the contract.\nQualified electronic signatures based on digital certificates issued by qualified trust service providers are the only ones that offer actual guarantees of authenticity, integrity, and non-repudiation. It prevents the possibility of denying their legal consequences.\nIt is crucial to note that the court record indicates that the plaintiff company required the company that provided the digital platform to provide evidence or elements, verifying the parties\u0026rsquo; signatures. No information was presented to help the applicant confirm the identity of the signatory.\nThe specific guarantees offered by the trust service provider are an essential element when choosing a reliable electronic signature solution.\nThe reliability of the provider and the guarantees that he offers us are essential. They have to be considered when evaluating the electronic signature solutions to be implemented in the business processes.\nWhen choosing a digital signature solution or platform, it is not enough to assess whether it is a multinational company or a well-known platform. We should pay special attention to reliability in the complex terms that it offers. For example, the additional services that the provider can offer, the assistance it provides in case of technical or legal incidents, such as a court decision, also the opportunity to consult in case of problems or additional requirements specifically adapted to the specific case of the client.\nThe qualified electronic signature facilitates the data verification contained in an electronic signature and confirmation of the signature authenticity. It can be presented in court together with the document to recognize all the favorable presumptions of law corresponding to them.\nThe court emphasizes that the plaintiff company did not conduct evidentiary activities in addition to presenting the signed document or expert practice on it, except that it was a signature executed through a commercial platform with little trust. Thus, this was not enough to prove its validity in court and, consequently, the document authenticity that gave consent to the credit operation.\nThus, tne of the advantages of using a qualified electronic signature in a document submitted to the court is that the burden of proof is lower or absent. As soon as it is confirmed that the signature has the status of a qualified electronic signature, the party who tries to ignore it will have to prove that they had not signed the document.\nThis court decision undoubtedly marks an important precedent in the electronic signature sector, not only in Spain but around the world.\nThe article was translated from Spanish, the original is here. You can send us any comments to our email, we will be elated to get feedback. If you find our articles fascinating, you can subscribe here.\nSee also # St. Louis Prosecutor Quits after her eSignature Used on Court Docs while on Maternity Leave Why the European Blockchain Partnership is needed ","date":"6 October 2021","externalUrl":null,"permalink":"/posts/kejs-elektronnyy-kreditnyy-dogovor/","section":"Blog","summary":"The Spanish justice acquits the defendant about the loan payment; it was not signed with a qualified electronic signature certificate.","title":"A Legal Case: The Plaintiff Failed to Prove the Authenticity of the Electronic Loan Agreement","type":"posts"},{"content":" *Baltimore recently prohibited several uses of “face surveillance” technology. Under the new law, companies cannot use systems that identify or verify individuals based on their faces. The law also prohibits saving information gathered from these systems. Getting an individual’s consent is not a way around the prohibition. Nor is promising not to connect information gathered with other personal information. *\nStill, there is an important exception that many companies will find helpful. Namely, the law permits facial recognition technologies that are used to give access to specific locations or devices. Some are concerned that the law is overly restrictive. The article has been written to offer several tips to try if you want to use facial recognition technology. The original article was written by David Oberly, an associate at Blank Rome*, *and can be found here.\nRapid advances have fueled a proliferation of facial recognition technology. It continues to spread to new areas of public and private life. In particular, today retailers and similar commercial organizations are increasingly relying on facial recognition for security and surveillance purposes.\nAt the same time, however, facial recognition is becoming an increasingly popular target for class-action litigation pursued under the Illinois Biometric Information Privacy Act (\u0026ldquo;BIPA\u0026rdquo;). Many states and Congress are trying to enact additional strict laws regulating facial recognition technology by commercial enterprises.\nAll organizations that use facial recognition technology today, especially those that use this technology for security and surveillance purposes, must ensure that they have appropriate biometric privacy practices. They have to take measures not to become the next target of a potentially game-changing biometric privacy class action lawsuit.\nLegal landscape\nCurrently, only three states have passed biometric privacy laws directly regulating the use of facial recognition technology.\nOf these laws, the BIPA of Illinois is considered the strictest. According to BIPA, an individual cannot collect or store data of a third party without prior notification, obtaining written consent, and disclosure of certain information.\nIn addition to Illinois, Texas and Washington have also passed biometric privacy laws regarding facial recognition technology. They establish similar requirements for notification, consent, and mandatory security measures.\nMany states are currently trying to pass their legislation on the privacy of biometric data. It will extend notification, consent, and security requirements similar to BIPA to additional parts of the country.\nThe scope of many of these bills goes far beyond BIPA and will include additional requirements. Pre-deployment testing and periodic training of employees will be mandatory requirements. As well as permission for testing this technology by third parties will be obligatory too.\nThe state has also included facial recognition as one of the main areas for countrywide regulation. Federal lawmakers will establish uniform requirements throughout the country regarding the use of technologies.\nAdditional problems and risks\nThe current (and future) problems associated with facial recognition technology are not limited to significant legal liability.\nFacial recognition has recently received a significant amount of negative media coverage. It concerned the potential accuracy and bias problems associated with this technology. Modern technologies are much less accurate in identifying people of color and women, thereby creating an increased risk of incorrect identification of people.\nThe new purpose of the class action lawsuit for the protection of biometric privacy\nRecently, the focus of BIPA class action lawsuits has been on employers. Many of them use biometric fingerprint readers to record working hours and attendance. However, not long ago, a new BIPA target has appeared on the radar of the plaintiff\u0026rsquo;s attorneys: companies using facial recognition for security and surveillance purposes.\nCompliance Tips\nDue to the rapidly increasing liability exposure associated with facial recognition technology, companies using this technology or planning to do so in the future should not wait for the adoption of new laws. Even if they are not currently subject to any regulations, they should take positive measures now to implement flexible, adaptable compliance programs. Thus, it can ensure continuous compliance with the rules of facial recognition.\nFortunately, there are several practical steps that companies can take to effectively use facial recognition technology in a way that meets their legal obligations. In particular, companies should consider the following:\n* Accuracy and bias testing: Since facial recognition software can produce biased results and harm certain ethnic and racial groups, it is necessary to complete preliminary testing to ensure its effectiveness and accuracy before using it in real-time situations.\nPrivacy Policy: Develop a publicly available, detailed privacy policy regarding facial recognition, which includes, at a minimum, an apparent notification that face template data is being collected, as well as additional information about the purposes for which face template data is used, as well as the company\u0026rsquo;s schedule and guidelines for preserving and destroying this data.\nWritten Notice: Provide a written notice — before any facial template data is collected. It has to inform individuals that the facial template data is collected, used, and(or) stored by the company; or how this data will be used and(or) transmitted, and the length of time the company will retain the data until it is destroyed.\nWritten Release: Obtain a signed written consent form from all individuals before any facial template data is being collected. It has to permit the company to collect or use biometric data and disclose the data to third parties for business purposes.\nOpt-out: Permit individuals to opt-out of collecting their face template data.\nData Security: Maintain data security measures to protect facial template data that meet reasonable standards of care applicable to the company\u0026rsquo;s industry and protect facial template data in the same or more secure manner than the manner the company protects other forms of confidential personal information.\n* Explicit prohibitions on using technology for discriminatory purposes:** **Adhere to a clear policy that strictly prohibits the use of facial recognition technology by employees, contractors, or suppliers to unlawfully discriminate against individuals or groups of individuals.\nConclusion Facial recognition technology has significantly improved the performance of enterprises in all industries in many different ways, including security/fraud prevention using personal data, access and authentication, and the availability of accounts and services.\nAt the same time, this technology is becoming an increasingly frequent target of class-action lawsuits for biometric privacy, exposing enterprises to tremendous potential legal liability. In the future, the scale of responsibility will only increase as additional states and Washington, DC, will seek to introduce stricter rules regarding the use of facial biometrics.\nConsequently, companies should take proactive measures to develop and implement biometrics compliance programs for facial recognition that cover the principles and methods described above.\nIf you find our posts riveting, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Video Surveillance Trends and Predictions in 2021 The Best Facial Recognition Algorithm Calling for a Ban on Facial Recognition: EU DPAs are Worried ","date":"29 September 2021","externalUrl":null,"permalink":"/posts/raspoznavanie-lits-bez-shtrafa/","section":"Blog","summary":"Baltimore recently prohibited several uses of “face surveillance” technology. Here are a few ways to keep it safe for your business.","title":"Using Facial Recognition for Security and Surveillance without Getting a Fine","type":"posts"},{"content":" A passport is one of the most reliable identity documents for authorities around the world. The basis for this trust is modern biometric chip-based technologies embedded in the documents. These technologies help protect and regulate international borders. They also ensure the security of travelers\u0026rsquo; data. With the accompanying set of global standards defined by the International Civil Aviation Organization (ICAO), a United Nations body, passports can be universally reliable and secure.\nHowever, the expectations of travelers and governments are changing as digital identities become more common and require the transfer of the same level of security and privacy in existing passports to these new digital documents.\nA modern passport The established trust and security in modern passports that meet the requirements of ICAO is a considerable achievement. A passport must be broadly interoperable. It also has to be impossible to disclose an individual\u0026rsquo;s personal information to unauthorized persons.\nCreating this necessary trust for governments and people requires that certain data is available for sharing, verifiable, and secure. The printed information in the passport is accompanied by digitally verifiable credentials containing additional information for personal identification, including biometric identifiers. Comparing all this information gives border guards guarantees that the data has not been tampered with and provides individuals with the highest available degree of trust and confidentiality. It is a process that is poles apart from simple since layered security and technological processes protect the privacy and reduce fraud. However, this was not always the case.\nDuring the early development of electronic passport standards, it was discovered that the chipped information in the passport could be read by intercepting radio signals between passports and passport readers from a distance of up to 30 feet. It was an obvious problem requiring additional protective measures to retain personal privacy and national security. Addressing the problem, governments have adopted technical specifications guaranteeing that passport chips will interact with readers only during specific authentication procedures. They are a combination of scanning printed information, accessing stored data, physical document access, encryption and decryption mechanisms, and the live document bearer who can present the document.\nThese problems allowed us to learn valuable lessons from passport security checks, and it helped set standards for the future use of electronic passports.\nAs passport identification capabilities expand into the digital realm with digital travel credentials, the same security is being thought through to ensure that e-passports remain as secure and reliable as their traditional satellites.\nGoing Digital Modern travelers who continue to demand more convenience and privacy; and governments increasingly concerned about security are the main trends contributing to the changes. Together, these trends stimulate the demand for new e-passport features.\nLeading the charge on digital passports is the aviation community – an industry located at the intersection of state regulation and the requirements of travelers.\nLong before the COVID-19 pandemic, aviation stakeholders were trying to find a way to digitize passports to provide contactless automated processes that would replace time-consuming manual checks. However, doing this while maintaining security, compatibility, and privacy is a difficult task.\nStandards and frameworks for digital travel identification cards (DTCs) are still in development, and significant issues, such as whether DTCs should be derived from the physical passport itself or generated by the issuer, are still being discussed by international standards bodies and governments.\nOnce a globally accepted framework is in place, technology providers will provide travelers with DTC codes. They will allow people to check in for flights and provide their information in advance for security and customs checks. An attractive offer for the authorities since early inspections give more time for reliable security checks.\nEarly submission of data and digital verification will significantly increase the efficiency of processes at airports, reduce processing time, and, consequently, the length of security lines at checkpoints. It may also allow travelers to bypass some touchpoints, such as check-in, and reduce or eliminate the exchange of physical documents.\nToday, some technologies would allow all checks at airports to be completely contactless, but it will take time for widespread implementation since it requires trust. Fortunately, passports have a solid foundation of trust and security, which bodes well for the future of DTCS.\nThe source of the article. If you find our posts fascinating, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Vaccine Passports: Unlocking the EU Travel Advantages of a cloud-based qualified digital signature EFPE Conference 2021: Review ","date":"22 September 2021","externalUrl":null,"permalink":"/posts/tsifrovoe-udostoverenie-kak-pasport/","section":"Blog","summary":"People rely on passports entirely. Is it possible to get the same level of trust with digital IDs? The article deals with the requirements for their security.","title":"Making Digital ID 'as Trusted as Passports' and What Enables Their Security","type":"posts"},{"content":" Unprecedented numbers of employees started working remotely in the past year. The article reflects an expert\u0026rsquo;s opinion of getting an appropriate level of protection for remote workers.\nA year and a half ago, the idea of remote work in the future, where we freely perform our work and cooperate with colleagues from anywhere, seemed engaging but an unlikely concept. And at one point, this future became the present.\nThe employees had to put up with a drastic change in their lifestyle. While the transition to remote work was a significant challenge for most organizations, it was also an opportunity to explore and accelerate the realization of plans, which were in the early stages of progress before the pandemic. It also allowed employees to experience a new way of working - remotely. For many people, the remote format provided an improved work-life balance and more time with their families.\nAs organizations and their employees begin, tentatively, to move to the post-covid stage of their lives, it remains unclear to what extent the changes and amendments of last year will remain in force.\nFor most, a complete return to office life from 9 to 5 seems extremely unlikely. But it is equally unlikely that the country\u0026rsquo;s office buildings will stand silent and empty for several months in a row.\nIt is essential to consider how we would secure remote work in the future. What processes, policies, and tools are necessary to protect personnel, devices, and – most importantly-data.\nHow will the work be different in the future? Work in the future will be different in how employees will access data and collaborate in the post-pandemic world.\nWhat does this mean for security tools and policies? Companies must have the same security policies wherever anyone works; two years ago, you could have gotten away with it. But now, any company must take care of data security in any format of its employees \u0026rsquo; work.\nMany companies had already taken some steps before Covid so that their organizations could work remotely to a certain extent. A classic example was VPN gateways, usually used for a small part of users, but which have now expanded and become the basis of the entire organization, where everyone works remotely.\nCloud services that bring users and applications together are especially relevant for remote work now. Cloud service gives its users the best experience and is at the center of the processes. It means that these connections do not have to pass through a central security stack at headquarters, as in the classic hub and spoke design created by VPN networks. Thus, users can have access to the cloud applications they need without additional delay.\nHas the large-scale transition to remote work increased the threat? The risk is higher when the employees work outside the office. In the office, an employer tends to have a lot of control over them. Now organizations need to consider all the networks employees connect as hostile. It\u0026rsquo;s time to stop thinking about connecting computers to networks and start thinking about connecting users to applications. Effective authentication and authorization are excellent for secure access.\nHow does the transition to the cloud affect security? As part of any digital transformation, you need to supervise the data you move to the cloud. And you should still be aware of how and where the organization provides its security. The company has to maintain the same level of data protection; wherever the worker does their duty: at or outside the office. If you don\u0026rsquo;t have such rules, criminals will figure out and target where you are weakest.\nWhat are the main threats or types of attacks currently facing organizations? Recently, due to the massive transition of employees to a remote work format, phishing attacks tremendously increased.\nThere have also been many ransomware attacks. Many of them related to how people got access to their network. Before Covid, the number of people connecting via VPN could be only 10% of the organization. But now the whole company uses VPNs – and since users are very poorly versed in passwords, and we often re-use them, there is an elevated risk of using hacked credentials against your VPN to check if they work. Then, as soon as they get into the network, they will have the opportunity to encrypt your data and demand a ransom. If you don\u0026rsquo;t want to pay it, they can hit you with an encryption replay attack, data disclosure, DDoS, as well as notifying your customers about the attack. All of this causes damage to the reputation.\nHow will security be adapted? The future of work fits very well into the edge model of the secure access service. It\u0026rsquo;s about security between users and applications; users no longer need to be present in the office; they can be anywhere, and applications can be anywhere, and the organization can still have the same level of security. The main aim is to secure the applications, leaving users and access managed by the cloud. Companies and organizations must also provide maximum technical safety while significantly increasing usability.\nThis article is based on an interview with an expert, Director of Security Technology and Strategy EMEA in Akamai, Richard Meeus. The original interview can be found here. If you find our posts compelling, you can subscribe here. If you have any questions, you may write to info@digt.com: we will be delighted to get feedback.\nSee also # Artificial Intelligence and Machine learning for the cloud-based solutions How to Fight against Most Spread Recent Cyberattack Types 7 Things You Should Know Before Working from Home ","date":"15 September 2021","externalUrl":null,"permalink":"/posts/udalennaya-rabota-zashchita/","section":"Blog","summary":"Unprecedented numbers of employees started working remotely in the past year. The article reflects an expert’s opinion on the approach.","title":"Work from Home: Securing Corporate Data outside the Office","type":"posts"},{"content":" According to reports, St. Louis lead homicide prosecutor resigned from her position in early July after her digital signature was discovered on several court documents after she had gone on maternity leave in May.\nProsecutor Kim Arshi reportedly began her maternity leave on May 10th. Yet her electronic signature appeared in more than 20 cases after the start of her leave in various court documents listed her as the lead prosecutor.\nOn July 20th, Arshi reportedly resigned but has not publicly commented on the matter, nor has St. Louis Circuit Attorney Kim Gardner’s office.\nOne of the cases in which Arshi was listed as the main prosecutor led to St. Louis District Judge Jason Senghizer dismissing the murder case against the defendant, identified as Brandon Campbell. At the time Arshi was on maternity leave.\nAccording to reports, the reason was that prosecutors from Gardner\u0026rsquo;s office did not show up at multiple hearings related to the case. In that case, Campbell was accused of fatally shooting Randy Moore in April 2020.\nSince the case was dismissed against Campbell, he was released from custody. Although Gardner\u0026rsquo;s office has reportedly re-opened a murder case against Campbell, he is currently at large.\nCircuit Attorney Kimberly Gardner stated Campbell\u0026rsquo;s release was due to her office\u0026rsquo;s inability to send prosecutors who had not been on leave to scheduled hearings. She blamed the incident on \u0026ldquo;internal policies and procedures regarding family medical leave\u0026rdquo; and that “corrective measures are needed to further prevent any future repeat occurrence of the incident in question.”\nCourt records show that Gardner\u0026rsquo;s office assigned Campbell\u0026rsquo;s case to Arshi on May 17th, a *week *after she was already on maternity leave.\nGardner says she is “accountable to the public for the actions of the office”. Nevertheless, she has yet to clarify what exact “internal policies and procedures” could result in an assistant prosecutor on leave having signed nearly 30 felony cases while she was not in the office. According to court documents, the cases included more than a dozen murders, a death penalty case, several assaults, and robberies.\nIt is an example of how the electronic signature of an official can be compromised and what consequences follow. In this case, the prosecutor resigned. Nevertheless, this is a good reminder that an electronic signature ensures the legal significance of electronic documents and an owner has to keep their private key confidential to avoid any possible legal ramifications.\nThe article has been based on the following news pieces:\nSt. Louis prosecutor quits after her signature used on court docs while she was on maternity leave. Assistant prosecutor in St. Louis was assigned nearly 30 felony cases while on leave. * If you find our articles fascinating, you can subscribe here; we will be elated to get feedback.*\nSee also # A Legal Case: The Plaintiff Failed to Prove the Authenticity of the Electronic Loan Agreement Why the European Blockchain Partnership is needed ","date":"8 September 2021","externalUrl":null,"permalink":"/posts/kejs-prokuror-st-luis/","section":"Blog","summary":"St. Louis lead homicide prosecutor resigned after her digital signature was discovered on several court documents.","title":"St. Louis Prosecutor Quits after her eSignature Used on Court Docs while on Maternity Leave","type":"posts"},{"content":" Why are electronic signatures the last barrier to a paperless office?\nElectronic signatures can provide additional efficiency of agreements, but their implementation remains slow. Hybrid work requires digital workflows for all processes. It can be video calls instead of meetings or live online documents for simultaneous collaboration. But signature commonly ends all the transactions and contracts, remaining the last step to leaving the analog office.\nEnterprises are increasingly moving from paper-based manual workflows to cloud-based ones. Digital technologies affected office life all over the world. Fast-growing startups hire and introduce new employees; banks acquire virtual clients; global pharmaceutical companies create networks of healthcare providers for a vaccination program. In each case, electronic signatures have become a significant factor.\nThe Pen matters\nSo far, the implementation of the electronic signature has been slow since the technology is much more complex than it may seem. Different legal requirements for diverse use cases mean that modern solutions are usually cumbersome and expensive. It often makes them the last step on the way to a fully digital office.\nAccording to IDC TechBrief 2020, only one in three companies uses electronic signatures. The pandemic and the forced shift to remote work have changed the situation since the paperwork has sharply decreased in parallel with the removal from the physical office. While it should have encouraged the use of electronic signatures, many businesses still rely on cumbersome solutions, such as signature cards with reader devices, printers, and scanners. They are still prevalent in our home offices.\nHowever, there is a better way – an integration of electronic signature functions into existing collaboration platforms is crucial to ensure that enterprises can work without resorting to complex manual approval chains and analog paper methods.\nThe content counts too\nFirst, let\u0026rsquo;s look at the importance of content for business. Simply put, content is an inherent value of the company. There are a lot of companies whose document content is highly confidential or of great importance. Content is the entire work of an organization, and it is unique for each company. Content is a database of its most valuable ideas.\nBut to effectively realize this value, organizations need to find a single place for their content. The separation of content between different repositories and applications creates friction that can prevent employees from accessing and sharing information, hindering innovation and productivity.\nThe ease of application integration with other technologies is quite essential in the modern content-oriented world. As a result, companies are turning to unified platforms where content can be safely stored and managed while meeting all compliance requirements and where all teams have the opportunity to collaborate on content both internally and externally.\nThe platforms with integrated e-signature capabilities help to avoid additional friction that interrupts the \u0026lsquo;content lifecycle\u0026rsquo;. For example, a contract bouncing through mailboxes can create many difficulties, starting with version control and editing and ending with signatures. The integration of electronic signatures into the platform will create a smoother workflow from start to finish, eliminating the possibility of errors or data loss.\nSecurity implications of integration\nIntegrated electronic signatures that are legally compatible and legally binding should be a fundamental element of the content cloud platforms. At the same time, these solutions should provide businesses with the opportunity to define a central, unified information security and management guide throughout the content distribution path. In this case, an electronic signature does not mean that mentioned solutions certified for security or compliance with the requirements are legally equivalent to advanced electronic signatures.\nWhen choosing an electronic signature solution for your company, it is important to look for a technology that is easy to use and meets the highest security standards. It should be simple and intuitive for your users but also very security-oriented to protect your content. As part of this focus on security, companies should define a single, consistent information security and management policy for the entire content distribution process, in which electronic signatures should fit.\nThe user interface should also be native and simple – there is no point in choosing a solution that requires more complex workflows and steps. Eliminating manual tasks is key, and omnichannel\u0026rsquo;s offerings (any device, any browser) will naturally work more smoothly. The solution must also support multiple document formats to ensure a consistent approach across the entire business.\nA complete content journey is crucial\nDisplaying electronic signatures directly in the cloud platform provides many advantages. Signatures can be executed in a legally secure way, even when remote employees or partners work together on documents, and the business increases ROI and efficiency by eliminating cumbersome and expensive solutions for qualified signatures.\nWhen choosing the right platform, it is important to ensure that the processes run as smoothly as possible. The most important points here are security, collaboration, productivity – and integration with other best-of-its-kind tools for communication and collaboration.\nThe original article Electronic signatures: please sign on the digital line was written by Sebastien Marotte. If you find our articles interesting, you can subscribe here; we will be pleased to get feedback.\nSee also # Electronic signature for HR contracts in France Email Safety Tips Every User Should Know to Keep It Confidential ","date":"25 August 2021","externalUrl":null,"permalink":"/posts/elektronnaya-podpis-dokumentooborot/","section":"Blog","summary":"E-signatures can ensure added efficiency to agreements, but uptake remains slow. The article deals with the key features of going digital.","title":"An E-Signature: the Key to a Secure Document Workflow","type":"posts"},{"content":" A controversial case with facial recognition in the Spanish supermarket chain Mercadona has been resolved. The supermarket company will pay a fine of 2.5 million euros to the Spanish Data Protection Agency (AEPD) because of a pilot project implemented in 48 stores. The Barcelona Provincial Court ruled that there was a \u0026ldquo;violation of privacy\u0026rdquo; in this project. It is a legal case that highlights the complexity of surveillance systems.\nThe Mercadona penalty as an alarm signal for systems of this type\nAs the company itself explains, the system “applied a technological filter and a second visual verification established that the identified person had a restraining order current of the establishment“.\nHowever, the AEPD concluded that the General Data Protection Rules were violated. In particular, Article 6 (Legality of the treatment) and Article 9 (Treatment of special categories of personal data). For this reason, a fine of two million euros is imposed, accompanied by other amounts for violations of other articles of the GDPR.\nThis sanction has been reduced by 20% because Mercadona voluntarily decided to make a payment, having taken into account the absence of recidivism or reiteration as a mitigating factor of particular importance. Mercadona explains that the company had judicial authorization from the very beginning. The company maintained close contact was with the corresponding authorities, and before the start of the tests, they shared all the procedures with the AEPD. Nevertheless, one of the grounds for applying sanctions is an incorrect evaluation of the impact.\nMercadona has completed a pilot project with a technology that is in the sights of Data Protection agencies. A test that was not carried out with the necessary rigor, as determined by the AEPD, resulted in a fine. A sanction that the Agency considers \u0026ldquo;proportional, effective and deterrent\u0026rdquo;. It will serve as a warning to other companies seeking to implement facial recognition systems. Mercadona states that \u0026ldquo;the most responsible and rigorous right now is to terminate this pilot test.\u0026rdquo; They decided to pay a fine and close the procedure before Data Protection.\nWhat aspects of the facial recognition project led to the sanction\nJorge Garcia Herrero, a lawyer specializing in Data Protection, is reviewing the Agency\u0026rsquo;s ruling. Among the proven facts, it is found that Mercadona launched the project in June 2020, only in May 2021, the project was discontinued in its forty establishments. So, these establishments used facial recognition technology at the entrance for about a year.\nHow did the Mercadona system distinguish between those who had received a court order? The company relied on its lawsuits against shoplifters and asked the judge to order this precise measure. The AEPD accuses them of having started before conducting an impact assessment. An impact report in which risks related to the company employees and vulnerable customers, such as minors, were not assessed, according to the AEPD. According to the Agency, biometric data is processed without sufficient basis nor are basic public interest requirements met.\nOne of the deep discussions about these facial recognition systems is the difference between using data for specific people and the rest. The AEPD understands that there is the legitimacy for the convicted, but not for the “not convicted”. Another aspect taken into account when using biometric data processing systems is the need for the measure. The AEPD explains that \u0026ldquo;utility\u0026rdquo; is confused with \u0026ldquo;necessity\u0026rdquo;. Although these facial recognition systems may be \u0026ldquo;useful\u0026rdquo;, they are not strictly necessary. Therefore consider that the Data Protection regulation prevents their use in cases such as Mercadona, where it is considered that the public interest is not being protected, but rather private, interests.\nThe news piece has been based on the article \u0026ldquo;Mercadona’s facial recognition ends in a fine of 2.5 million euros: what the Data Protection Agency says and what lessons can be learned\u0026rdquo;. If you find our articles riveting, you can subscribe here; we will be pleased to get feedback.\nSee also # Video Surveillance Trends and Predictions in 2021 The Best Facial Recognition Algorithm Calling for a Ban on Facial Recognition: EU DPAs are Worried ","date":"18 August 2021","externalUrl":null,"permalink":"/posts/kejs-ispaniya-shtraf-raspoznavanie/","section":"Blog","summary":"It is becoming increasingly popular for retailers to implement facial recognition technology for anti-theft purposes. But one case in Spain shows the consequences.","title":"A Spanish Supermarket Pays a Fine 2.5 Million Euros for Facial Recognition System","type":"posts"},{"content":" Fraud with electronic documents is not a common thing. As documents signed with a qualified electronic signature are normally protected from any forgery, it is a secure way to maintain the document workflow.\nIt is a fact that wet signatures can easily be forged and tampered with, while electronic signatures have many layers of security and authentication built into them, along with court-admissible proof of transaction.\nHowever, in legal practice, there are court decisions on illegal actions with documents in electronic format, which means that they may be of interest to all participants in electronic document management for protecting finances and business reputation.\nThe recent case of Marketlend Pty Ltd v. Blackburn [2020] NSWDC 358 (July 9, 2020) demonstrates what fraud looks like in the context of electronic documents execution and how the risk can be minimized.\nEvidence Marketlend lent the funds to a small company that runs a business selling mobile homes and residential vans, on the basis that the return will be guaranteed by its directors Matthew and Sarah. Matthew and Sarah were married but separated.\nMarketlend required that agreements be signed electronically using DocuSign. Both Sarah and Matthew had DocuSign accounts.\nMarketlend sent several emails using the DocuSign platform with the attachment of documents to the email address of Matthew\u0026rsquo;s company. Each document was purportedly signed by Sarah using DocuSign. Before that, Marketland had no contact with Sarah.\nThe company went into liquidation, and Matthew was declared bankrupt. Marketlend pursued Sarah for payment the remaining amount (more than $ 700,000).\nAfter analyzing the evidence, including DocuSign metadata and mobile phone location evidence, the court held that Matthew used Sarah\u0026rsquo;s account to sign the agreement without her knowledge or consent since she did not sign it when he asked her to do so. Sarah was not liable to pay the remaining amount in favor of Marketlend.\nLessons One of the advantages of using electronic signature platforms is the generation of a verifiable document execution trail. The case of Marketlend is a perfect example to prove that. But it is also a timely reminder to lenders of the importance of adopting reliable fraud prevention methods, even when signing documents with an electronic signature.\nThe case illustrates that the ability of lenders to claim against counterparty may be compromised if his signature platform account or the associated email address is compromised. For example, in this case, the judge found that:\nThe person using Sarah\u0026rsquo;s DocuSign account required access to emails sent to Sarah\u0026rsquo;s company email address. Both Matthew and Sarah had access to emails sent to Sarah\u0026rsquo;s corporate email account. Access to Sarah\u0026rsquo;s DocuSign account was not protected by a password or other authentication means, such as providing a confirmation code in a text message. The account holder was not notified that their DocuSign account had been accessed from a new device. Fraud prevention Below we provide some key lessons on fraud prevention. Most of them are equally applicable to documents signed traditionally (for example, in wet ink), and to documents signed electronically (for example, platforms for signing electronic documents).\nFor lenders:\nSend documents to be signed to each signatory directly, and not via another person. Separately engage with each party before signing if a guarantee is given by two or more individuals. Consider verifying the identity of each signatory. *For everyone: *\nIf you have a signature platform account, consider setting up multi-factor authentication. It is especially important if there is any concern as to the integrity of your email system. Make sure that all of your email accounts are secure and cannot be accessed by others.\nThe authentic article is here. If you find our articles fascinating, you can subscribe here; we will be elated to get feedback.\nSee also # The EU law on Electronic Signatures The future of AI: regulation in Europe The Top 5 Myths about Cloud-Based Digital Signatures ","date":"11 August 2021","externalUrl":null,"permalink":"/posts/kejs-moshennichestvo-podpis/","section":"Blog","summary":"The risk of fraud can largely be overcome with carefully considered practices and procedures. The article deals with the legal case.","title":"Electronic Signature Fraud: a Legal Case","type":"posts"},{"content":" The Hotel Management Association HOSBEC and Turisme Comunitat Valenciana are launching a pilot project of facial recognition in these establishments to take \u0026ldquo;another step\u0026rdquo; in their technological innovations. With a budget of 50,000 euros, technology companies were to submit proposals until July 15.\nIn this project, the starting point is to change the procedures that have been performed personally or manually so far. Hotels had to adapt by introducing technologies that meet the needs of \u0026ldquo;increasingly demanding\u0026rdquo; customers, the business organization emphasizes.\nThus, facial recognition is one of the technologies with which a hotel entrepreneur can get such advantages as simplifying the customer registration process, personalizing services, collecting data, reducing paper consumption, or reducing time.\nThis initiative joins the \u0026ldquo;big data\u0026rdquo; project called \u0026ldquo;BionTrend\u0026rdquo; as part of its commitment to technological innovation in this sector to increase competitiveness. Turisme CV cooperates with Generalitat within the framework of an annual agreement signed for advertising and innovation events.\nHOSBEC will invite a third-party company specializing in biometric systems for facial recognition as part of the public offering. They plan to sign a professional services agreement for the pilot phase of the project. It will also serve as the \u0026ldquo;customer registration\u0026rdquo; system through facial recognition in hotel establishments.\nThe systems will be installed from August 1 to December 31, 2021, in hotels associated with the Community Employers \u0026rsquo; Association. The budget of the pilot phase is 50,000 euros, although it may be increased in the future depending on the result.\nSee also # Video Surveillance Trends and Predictions in 2021 The Best Facial Recognition Algorithm Calling for a Ban on Facial Recognition: EU DPAs are Worried ","date":"4 August 2021","externalUrl":null,"permalink":"/posts/oteli-raspoznavanie-lits/","section":"Blog","summary":"Lost keys in hotels will soon be a thing of the past in Costa Blanca when facial recognition systems are implemented.","title":"Facial Recognition instead of Room Keys and Cards: Hotels in Spain go High-Tech","type":"posts"},{"content":" It has been five years since the application of Regulation (EU) no 910/2014 of the European Parliament and the Council of 23 July 2014, on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC, usually known as the eIDAS Regulation.\nOn February 19, 2020, the European Commission announced the revision of Regulation (EU) No. 910/2014 (eIDAS Regulation) to extend its benefits to the private sector and promote reliable digital identification data for all Europeans.\nThe coronavirus pandemic and the transition to the use of digital services showed that eIDAS Regulation has limitations that need to be urgently solved.\nFor the above reasons, the European Commission published a Proposal to amend the eIDAS Regulation on 3 June 2021 (“Proposal”). The proposed amendment is aimed at establishing a more consistent approach to digital identification in the internal market and cross-border transactions.\nNew in the Proposal in a nutshell\n1. European Digital Identity Wallet The Proposal introduces the concept of a \u0026ldquo;European Digital Identity Wallet\u0026rdquo;. It should be both a product and a service that, among other things, allows users to store identity data, credentials, and attributes linked to their identity. It will be used to:\na) provide them to the relevant parties upon request and to use them for authentication, online and offline, to receive services; and\nb) sign via qualified electronic signatures.\nThe use of the European Digital Identity Wallet should be free of charge for everyone and accessible to people with disabilities. Such a wallet can be used in many sectors, including the healthcare sector.\nThe European Digital Identity Wallet must be issued by a Member State (or under its mandate) or independently, but recognized by a Member state.\nMember States should provide validation mechanisms for European Digital Identity Wallet, namely:\na) to provide the possibility of verifying authenticity and validity;\nb) to allow the relevant parties to verify that the attestations of attributes (e.g. driving license, diplomas, bank account) are valid;\nc) allow the relevant parties and qualified trust service providers to verify the authenticity and validity of the attributed person\u0026rsquo;s identification data.\n2. Electronic Identification Schemes To make more electronic means of identification available for cross-border use, Member States should notify at least one “electronic identification scheme” that includes at least one means of identification.\nThe “electronic identification scheme \u0026quot; means an electronic identification system under which electronic identification means are issued to\nI. individuals or legal persons; or\nII. individuals representing legal entities.\n3. Unique Identification To guarantee the unique identification, Member States should include\nI. a minimum set of identification data required for the unambiguous and persistent representation of an individual or legal person; and\nII. a unique and permanent identifier following the legislation of the Union for identifying the user at their request in cases where user identification is required by law.\nThis is important in cases where identification is required by law, for example, in the field of healthcare, finance to fulfill anti-money laundering obligations or for judicial use.\n4. Cross-border recognition of European Digital Identity Wallets\nThe electronic identification means issued in another Member State should be recognized in the first Member State for cross-border authentication for that online service, provided that some conditions are met. This is necessary in cases where authentication is required under national legislation or administrative practice to access an online service provided by a public sector authority in a Member State.\n5. Qualified preservation service for qualified electronic signatures and qualified electronic archiving service for electronic documents\nThe services may only be provided by the standards, adopted by the Commission, by a qualified trust service provider that uses procedures and technologies capable of extending the trustworthiness of a qualified electronic signature beyond the technological validity period.\n6. Electronic attestation of attributes The current eIDAS framework does not cover the provision of electronic attributes, such as medical certificates or professional qualifications, which makes it difficult to ensure the pan-European legal recognition of such credentials in electronic form.\nFor this reason, the electronic attestation of attributes is introduced in the Proposal.\nAccording to the Proposal, the electronic attestation of attributes should not be denied legal force and admissibility as evidence in court proceedings solely because it is performed in electronic form.\nThe attestation of the above attributes must have the same legal force as legally issued attestations in paper form.\n7. New qualified trust services In addition to the qualified electronic archiving service for electronic documents (as described above), the Proposal introduces other new qualified trust services, namely:\na.* Remote qualified signature creation device*\nThe “remote qualified signature creation device” means a device for creating a qualified electronic signature in which a qualified trust service provider generates, manages, or duplicates data for creating an electronic signature on behalf of the signatory.\nManagement of the devices as a qualified service can only be carried out by a qualified trust service provider that meets the conditions set out in the Proposal.\nb. Electronic Ledgers\nAn Electronic ledger is a tamper-proof electronic record of data, providing authenticity and integrity of the data it contains, the accuracy of its date and time, and its chronological ordering. An electronic ledger should not be denied legal effect and admissibility as evidence in legal proceedings solely because it is in an electronic form or that it does not meet the requirements for qualified electronic ledgers. A qualified electronic ledger should enjoy the presumption of the uniqueness and authenticity of the data it contains, the accuracy of its date and time, and its sequential chronological ordering within the ledger.\nThis masterly written article was created by Gian Marco Rinaldi and Marta Breschi. You can find the original article here. If you find our articles interesting, you may subscribe here.\nSee also # EU Approves Deal on Data Flows in the UK Despite Opposition ","date":"28 July 2021","externalUrl":null,"permalink":"/posts/eidas-peresmotr/","section":"Blog","summary":"The eIDAS-Regulation has been fully in force for five years now and is facing a revision, which will provide a more successful application of electronic identification.","title":"The eIDAS Has Been Revisioned after 5 Years since the Application","type":"posts"},{"content":" The European Commission sealed a deal on data flows with the United Kingdom for billions of euros in digital trade.\nThe approval by the EU executive came just a few days before the adoption of an interim decision to continue data transmission over the channel after the end of Brexit.\nThe adequacy decision, as the data flow deal is called, will allow the transfer of personal data from the EU to the UK, avoiding a no-deal scenario that could have cost the British economy £1.6 billion.\nUK Secretary of State for Digital, Oliver Dowden, said that the formal recognition by the European Union of the UK\u0026rsquo;s high standards of data protection is right. He added that this is welcome news to business, it also supports cooperation between the UK and the EU and will help law enforcement authorities to ensure the safety of people.\nThe EU\u0026rsquo;s decision requires that both sides renegotiate the agreement within four years. It means that the EU can pull the deal if the UK diverges too much from the EU\u0026rsquo;s privacy rules. That could have a significant impact on the UK since three-quarters of its international data flow is coming from the EU. London has said it wants to review its privacy standards to get more economic benefits from data.\n“After months of careful assessments, today we can give EU citizens certainty that their personal data will be protected when it is transferred to the UK. This is an essential component of our new relationship with the UK. It is important for smooth trade and the effective fight against crime,\u0026quot; EU justice chief Didier Reynders said in a statement.\nDespite the announcement, the decision has faced heavy criticism from European lawmakers, regulators, and privacy activists, who argue that the UK\u0026rsquo;s surveillance rules and exemptions for immigrants deserve further scrutiny from Brussels. Responding to concerns, Commission vice-president Věra Jourová said that Brussels had provided precautionary measures that will allow it to intervene if the UK diverges too far from EU data protection standards.\nThe approval completed a complex process. The European Commission ran out of time to approve the deal before the Brexit transition period ended in January 2021, so it was necessary to develop a temporary six-month solution as part of the trade deal to continue the data transfer.\nSince then, the EU\u0026rsquo;s decision to approve the data regime in the UK, first proposed in February 2021, has been heavily criticized by the European network of privacy regulators, the EDPB, as well as MEPs who recently called on the European Commission to postpone the approval of data standards in the UK.\nTheir criticism is based on the British government\u0026rsquo;s plan to diverge from EU data protection standards, which is a prerequisite for getting the deal, as well as on court decisions in Europe and London that have questioned the legality of British privacy standards and the country\u0026rsquo;s surveillance regime.\nUK adequacy is likely to come under scrutiny in the coming months and years. Several campaigners are preparing legal actions against this decision, inspired by judicial precedents regarding similar data flow deals in the United States.\n*The news piece has been based on the article **\u0026ldquo;EU approves UK data flows deal\u0026rdquo; *by Vincent Manancourt. If you find our articles interesting, you can subscribe here; we will be pleased to get feedback.\nSee also # The eIDAS Has Been Revisioned after 5 Years since the Application ","date":"26 July 2021","externalUrl":null,"permalink":"/posts/es-soglashenie-potoki-dannyh-uk/","section":"Blog","summary":"The EU approves the UK’s data protection rules, even as London thinks over revising them. Opposition to the deal is running high.","title":"EU Approves Deal on Data Flows in the UK Despite Opposition","type":"posts"},{"content":" The European Commission wants to develop an application that would contain a digital version of your ID.\nThe European Commission unveiled plans to introduce a bloc-wide digital identity card.\nIf approved, the plan would allow people to use the app to verify their identity online. Whether to confirm their age or to check their driver\u0026rsquo;s license, it would come in very handy.\nThe EU plans to start testing the application, which it calls a \u0026ldquo;wallet,\u0026rdquo; in October 2022, when it hopes it will form the basis of an agreement between member countries. But how will this wallet affect people? Will it be the end of their anonymity on the Internet?\nWhat is the ID required for?\nThe Commission says it needs a new identification system because it wants EU residents to retain control over their data, rather than sharing it with tech giants such as Google and Facebook.\nThe Commission also hopes that digital identity cards will help to fight online fraud, encourage people to feel safer when using online services, and will be able to improve the economic situation. One study by the McKinsey Global Institute claims that countries with a digital identity card system will be able to increase their gross domestic product by 3 to 13 percent by 2030.\nSome EU countries have already implemented their own national digital identity cards, but they have a mixed track record. According to the Commission, 19 eID schemes are used by 14 EU countries, but \u0026ldquo;the coverage is small, their use is cumbersome, and business cases are limited.\u0026rdquo;\nThe goal is to emit a national identification card, which citizens would link to the application placed on their phones.\nIf a person is from an EU country that already has a digital identification system, one will not have to register again or apply for a new digital identity card. The proposed application is designed to develop these existing systems and allow people to use this digital identification in a wide range of situations.\nIf a person does not want to have such an ID, it will not be necessary to have such an identifier.\nBut EU countries will have to offer their residents a digital identity card system. Similarly, public and private services will have to accept the new ID, but still, they cannot make it mandatory for users.\nThomas Loninger, vice president of the digital rights group EDRi, is concerned that the Commission has not taken into account people who do not want to have a digital identity card, leaving them at a disadvantage if companies or governments start encouraging people to use it.\nThe EU plans to start testing this scheme only in October next year and has not yet set an exact date when it will be available to all EU residents.\nIt\u0026rsquo;s unclear what the apps might look like, and each country will have to decide how to offer them to its residents. “You will probably be able to download it in standard app stores or on government websites,” a Commission representative told reporters.\nPeople can expect to be able to use the \u0026ldquo;wallet\u0026rdquo; to verify their identity using public and private online services within the bloc, including access to their bank account, filing tax returns, verifying they came of age and renting a car. The regulation also includes the right to make transactions under a pseudonym, if anyone wants to conceal their private data. Digital rights activists like Loninger fear that the proposal could allow the private sector to access government-certified information. He said he had little faith in EU data protection rules to make the system secure, and he didn\u0026rsquo;t like that countries were responsible for complying with the proposal. The Commission said that with the participation of EU countries, it will develop rules and standards that will ensure \u0026ldquo;the highest level of security.\u0026rdquo;\nThe digital ID may look like the passport of the vaccine 2.0. The Commission\u0026rsquo;s digital vaccine passports-called COVID digital certificates-probably paved the way for the EU proposal. “This is the impressive side of this pandemic,\u0026quot; said one of the Commission\u0026rsquo;s officials, stressing that digital projects have received priority in responding to the health crisis.\n“This is a path of no return, \u0026quot; the official added.\nThe source for this piece of news is here. If you find our articles engaging, you can subscribe here; we will be pleased to get feedback.\nSee also # Vaccine Passports: Unlocking the EU Travel Advantages of a cloud-based qualified digital signature EFPE Conference 2021: Review ","date":"19 July 2021","externalUrl":null,"permalink":"/posts/es-tsifrovaya-identichnost/","section":"Blog","summary":"The European Commission shared its plans for a new ID app for citizens, residents and businesses last month.","title":"A EU Digital Identity Framework: Plans and a Scheme","type":"posts"},{"content":" EU Data Protection Authorities called for a general ban on any use of artificial intelligence technologies to recognize human features in public places in June.\nThese two authorities include the European Data Protection Supervisor, which is responsible for ensuring that EU institutions comply with EU data protection rules, and the European Data Protection Board, the bloc\u0026rsquo;s network of national privacy regulators.\nAndrea Jelinek, EDPB chairman and European data protection supervisor Wojciech Wiewiórowski said in a joint statement that the deployment of remote biometric identification in publicly accessible places means the end of anonymity in these places. Applications such as live face recognition violate fundamental rights and freedoms to the extent that they can call into question the essence of these rights and freedoms.\nThe statement is in response to the Commission\u0026rsquo;s bill on Artificial Intelligence, which imposes restrictions on the use of live facial recognition by law enforcement agencies in public places but does not explicitly prohibit it.\n\u0026ldquo;A general ban on the use of facial recognition in public areas is a necessary starting point if we want to preserve our freedoms and create a human-centered legal framework for AI,\u0026rdquo; the statement said.\nThis statement is not binding on the Commission, but regulators are responsible for complying with the EU\u0026rsquo;s strict data protection rules, known as GDPR.\nAlongside faces, gait, fingerprints, DNA, voice, keystrokes, and other biometric data should also not be recorded, regulators said. They called for a ban on Artificial Intelligence systems that use biometric data to recognize ethnicity, gender, political or sexual orientation. The regulators have also called for a ban on AI technologies that claim to recognize emotions and any social scoring, which is prohibited for public authorities, but not private firms under the current bill. The source of this article is here. If you find our articles fascinating, you can subscribe here; we will be elated to get feedback.\nSee also # Video Surveillance Trends and Predictions in 2021 The Best Facial Recognition Algorithm Facial Recognition instead of Room Keys and Cards: Hotels in Spain go High-Tech ","date":"6 July 2021","externalUrl":null,"permalink":"/posts/zapret-raspoznavaniya-lits/","section":"Blog","summary":"Faces, gait, fingerprints, DNA, voice, keystrokes, and other biometric data should not be recorded, regulators said.","title":"Calling for a Ban on Facial Recognition: EU DPAs are Worried","type":"posts"},{"content":" The European Forum on Electronic Signature and Trust Services (EFPE) is the largest international conference in Europe. It is dedicated to electronic trust services, including electronic signature, PKI, electronic identification, and digital security. For two decades, EFPE has been bringing together experts and professionals in the field of law, technology, and the application of electronic trust services.\nThe conference included discussions between experts in the field of law, business, and new technologies. The discussions focused on:\nthe undeniable impact of digitization processes on both maintaining business continuity on economic recovery after the COVID-19 pandemic on global economic development in the coming years. Trust and identity services were evaluated through the prism of practical application. The most attractive examples of digital transformation in organizations operating in the European market were also presented. Developing the Ecosystem of Digital Future with eIDAS2.0\nThis year, discussions during the 21st European Forum of Electronic Signatures and Trust Services dominated the recently published proposal by the European Commission to revise the regulation of eIDAS. It presents several new solutions, such as the European Digital Identity Portfolio, which offers the creation of eID for individuals and legal entities and expands opportunities for international cooperation. How did the experts evaluate the proposals for amendments to the Regulations on Electronic Identification and Trust Services? From the point of view of digital identity, it is good that these changes are taking place because they allow state bodies, businesses, and citizens to use modern solutions more widely. There are many new trusted services. We are also moving towards standardization. There are a lot of digital processes going on now, \u0026quot; EFPE Director Tomas Litarovich said at the conference. In turn, Andrey Doperala, president of Asseco Data System, recalled that the pandemic is a time when the world is becoming more digital. - We are living in a period of huge, unprecedented changes associated with technological innovations that affect both our personal and professional lives and change the behavior and ways of human interaction. The pandemic has caused an urgent need for universal digitization in society. The past year has been a period of intensive development of technological solutions that allow you to interact and trade without direct contact with a person. Remote identification of the participants in the process and remote confirmation of their decisions were key to increasing the use of electronic documents, which was the only way to avoid or minimize interpersonal interaction, \u0026quot; said Andrey Doperala.\nElectronic identification and trust services are the tools that make digital transformation possible. During the first debate within the framework of the EFPE, experts agreed that there are many problems ahead for the EU and individual member countries. The fact that the EC takes, in the form of an eIDAS resolution, a significant part of them does not mean that the topic is exhausted. \u0026ldquo;The rules and their changes should be focused not only on national but also on European dimensions to fully harmonize the legal framework and reveal the full potential of digital services,\u0026rdquo; said Tomasz Chomiatski, Business Development Director at Samsung Electronics Poland. - We should look at it more broadly because these are elements of a global economy based on trust.\nWe must remember that digital transformation will require a digital identity. He acknowledged that the rules focused on electronic identification are very important. New products that appear on the market allow us to accelerate the digital transformation of business and public administration. At the same time, they also raise questions about security, regional and global compatibility, the attractiveness of their use, and popularization on the side of business and citizens.\nTo address digital identity as widely as possible, the EFPE is divided into three thematic blocks. The first one concerned market changes in Poland and Europe. The second was devoted to the introduction of trust services in individual organizations. Third, the future of the digital economy is an attempt to find answers to questions about the changes in eIDAS proposed by the EC about whether they are going in the right direction, at least in the context of international cooperation and building a global digital economy.\nThe EU has defined a model for regulating electronic signatures, which has been adopted as a standard in many countries. The revision, which focuses on the EU market, will affect other countries, not only Switzerland or Norway but also those outside of Europe, \u0026quot; said Andrea Valle, president of the Cloud Signatures consortium. From the provisions of the amendments, eIDAS pointed to Article 14, which implies mutual legal recognition of trust services established in third countries. - Until now, this issue has been neglected, which did not allow us to cooperate, for example, with the dynamically developing Indian market, - said Valle. He also stressed that in the field of identification and identity verification, the amended Article 24 would be extremely important. - It harmonizes the principles of remote identification on the EU trend. Until now, its absence has been the main obstacle to the development of joint trust services by the EU, he added.\nTomasz Khomiatski noted that cybersecurity is essential if we think about the further development of electronic identification services. \u0026ldquo;This is the point when we should stop for a moment and reflect on the new rules, like eIDAS 2.0, and emphasize that new services should be deployed in such a way that is more and more secure. Today we see the growing importance of AI, cloud computing, e-commerce, but it is also worth noting that hackers are also participating in this race, \u0026quot; he said.\nIn turn, Andrey Doperov from Asseco Data Systems admitted that eIDAS 2.0 is the next stage for digital transformation. - Updating eIDAS will lead to the fact that the systems will interact with each other. It is not only an electronic signature but also a certificate confirming that I am an expert. I have a higher education diploma - if it matters for a particular situation-it will become part of my digital identity. The possibilities are immeasurable. Maybe we still don\u0026rsquo;t see them today, \u0026quot; he said. He also stressed that \u0026quot; companies such as Asseco Data Systems and most certification authorities are prepared for the new rules and recommendations that follow from the eIDAS update.\u0026rdquo; \u0026ldquo;I am convinced that these changes will happen quickly, and I see opportunities for such entities as ours,\u0026rdquo; he added.\nIn the context of the further development of digital services and the subsequent stages of transformation, the EU will allocate significant funds within the framework of a multi-year financial structure and the Reconstruction Fund. It was stated at the EFPE by Michal Kanowiec, President of the Union of Digital Technologies of Poland. - The EC has prepared a program for the next generation of the EU- a financial plan for 750 billion euros. Each country had to prepare its recovery plan, and 20 percent. Funds should be allocated for digital transformation. In addition, from 2021, more than 130 billion euros will be allocated for digitization in the common market within the framework of the EU budget, he recalled. As he noted, Europe should prepare and invest in digitalization to be a real partner in economic relations.\nThis is the first part of the article. The original article in Polish can be found here. If you find our posts compelling, you can subscribe here; we will be delighted to get feedback.\nSee also # Vaccine Passports: Unlocking the EU Travel Advantages of a cloud-based qualified digital signature A EU Digital Identity Framework: Plans and a Scheme ","date":"30 June 2021","externalUrl":null,"permalink":"/posts/konferentsiya-efpe-2021/","section":"Blog","summary":"Electronic identification and trust services – the future of the digital market. How do experts see the prospects of trust services?","title":"EFPE Conference 2021: Review","type":"posts"},{"content":" NtechLab won the competition for facial recognition algorithms. The Face Recognition Vendor Test (FRVT) was conducted by the U.S. National Institute of Standards and Technology (NIST). Their algorithm demonstrated the highest accuracy of biometric matching.\nMore than one hundred algorithms were submitted for the NIST benchmark from developers around the world. The main criteria were the speed and accuracy of the search. The NtechLab algorithm, FindFace, showed the best result for the entire time of the competition. Also, the program was among the top three leaders in facial recognition in masks.\nThis competition is a recognized global competition of facial recognition algorithms. The test plays out scenarios when you need to confirm the identity of a person in a photo. For example, when one crosses the border or passes face checks in various payment systems. The algorithm from NtechLab scored the lowest error rate in the Visa Photos, Visa Border, and Border Photos categories, and second for the Mugshot Photos database.\nSeveral years ago, NtechLab already won this competition. The company has also won another similar competition conducted by the Defense Advanced Research Projects Agency. The algorithm is currently used in smart city systems in several countries.\n“In the last few years, the competition in the field has increased, as well as the accuracy and the of the competitor algorithms,” states NtechLab Co-founder and Head of its Neural Network Research Lab Artem Kukharenko. “Today we can say with certainty that the NtechLab intelligent video-analytics platform is the best worldwide judging by a whole range of criteria. To achieve this result NtechLab engineers used the most innovative methods for neural network training and new algorithms for data processing and preparation for machine learning. The results of these developments are already implemented in NtechLab products and will serve to improve the safety and comfort of smart cities’ population across the world.”\nThe original news is here.\nSee also # Video Surveillance Trends and Predictions in 2021 Calling for a Ban on Facial Recognition: EU DPAs are Worried Facial Recognition instead of Room Keys and Cards: Hotels in Spain go High-Tech ","date":"24 June 2021","externalUrl":null,"permalink":"/posts/luchshiy-algoritm-raspoznavaniya/","section":"Blog","summary":"The facial recognition algorithm FindFace has been acknowledged as the top-performing facial recognition software.","title":"The Best Facial Recognition Algorithm","type":"posts"},{"content":" An electronic signature and a digital signature are often used interchangeably, but the two concepts are different. The main difference between the two is that a digital signature is primarily used to protect documents and is certified by certification authorities, while an electronic signature is often associated with a contract that the signer agrees to. More information about the difference between the two concepts can be found below.\nMain features of the digital signature\nA digital signature is a unique characteristic in digital form, something like a fingerprint embedded in a document. The signer must have a digital certificate to be associated with the document. The certification authority issues the digital signature. It is comparable to a driver\u0026rsquo;s license or passport. A digital certificate helps to verify the document\u0026rsquo;s authenticity to determine if it has been tampered with. It plays a primary role in identity verification.\nAnother significant feature of a digital signature is that it is used for protecting digital documents. Fraudsters can forge documents to submit online using an electronic signature, but with a digital signature, it is nearly impossible. The electronic document is protected; only an authorized person can view it to make changes or edits.\nWhen a digital signature is applied to a specific document, the digital certificate is bound to the signed data in a single, unique fingerprint. These two components of a digital signature are unique, and it makes them more practical than wet signatures because it is possible to authenticate their origin. This cryptographic operation helps to perform the following actions:\nProving the authenticity of the document and its source Ensuring that there were no changes in the document after signing Confirming the identity of the signer. Main features of an electronic signature\nUnder US law, an electronic signature is any electronic symbol, process, or sound associated with a record or contract that the interested party intends to sign. Thus, the main feature of an electronic signature is the intention to sign a document or agreement. Another noteworthy aspect that distinguishes an electronic signature from a digital signature is that an electronic signature can be oral, a simple mouse click, or any electronic authorization.\nThe main characteristic of an electronic signature is that it reveals the signer\u0026rsquo;s intent to sign the document. It usually complies with contracts or other agreements that are entered into by two parties. As mentioned earlier, there are different types of electronic signatures. They are legally binding once all parties have demonstrated their commitment and intention to enter into a particular contract.\nAnother aspect of an electronic signature is that it helps to verify the authenticity of the document. Once it has been signed, the parties involved should be able to be identified. However, an electronic document can be hard to verify because there is no digital certificate, making the process secure.\nAnother notable feature of an electronic signature is that it is used to execute an agreement. For example, in a contract, two people usually agree to perform certain obligations. This agreement becomes legally binding if both parties sign it. In this case, you can use an electronic signature. In addition, electronic signatures are often used in contracts because they are easy to use.\nTable Showing Differences between Digital Signature and Electronic Signature\nThus, although both electronic and digital signatures are legally binding, it is preferable to use the latter because they are more secure than the former.\nConclusion Digital signatures and electronic signatures are different in some very significant ways. We have tried to give a brief overview of the types, having highlighted their main differences. Knowing what types of signatures an organization needs to collect impacts the technology and processes you need to implement. The original resource used for this article can be foundhere. If you find our posts compelling, you can subscribehere; we will be delighted to get feedback.\nSee also # The EU law on Electronic Signatures The future of AI: regulation in Europe The Top 5 Myths about Cloud-Based Digital Signatures ","date":"10 June 2021","externalUrl":null,"permalink":"/posts/raznitsa-tsifrovoy-i-elektronnoy-podpisi/","section":"Blog","summary":"The terms “digital signature” and “electronic signature” are often used interchangeably. Digital signatures are a type of electronic signature.","title":"Difference between a Digital Signature and an Electronic Signature","type":"posts"},{"content":" Hanwha Techwin has outlined five key trends for the video surveillance industry in 2021. These include AI-based edge solutions, open platform, cloud, cybersecurity, data protection, and privacy issues.\n**Growth of AI-based edge solutions **with unlimited application potential\nThe significant advantage of edge devices is that they can run specialized software applications onboard. It increases resource efficiency, saves processing time, and minimizes network bandwidth requirements. With advanced functionality now included in edge-based Deep Learning AI solutions, there is likely to be a significant increase in the number of deployed devices that can process data at the edge.\nThe expanded open platform will facilitate the development of a more extended range of customized solutions for the vertical market and end-users\nBecause end users want to get the most out of their video solutions, software development cannot continue as an isolated process led by one company\u0026rsquo;s own software development team.\nThe Open Security \u0026amp; Safety Alliance (OSSA) is an initiative that brings together like-minded organizations to define specifications for a common platform for security and security solutions. The business will work with other OSSA members in 2021 to create a standardized and accessible framework that provides the flexibility to develop end-to-end solutions tailored to regional or user requirements.\nOSSA members intend to further improve the compatibility and interoperability of their products with the open platform within the video surveillance ecosystem.\nThe Сloud will be more extensive as a business intelligence tool\nThe Сloud is now widely used as a way to update product features, as well as install security patches. However, the increase in the number of edge devices deployed means that the Cloud also plays a significant role in securely managing devices and processing large amounts of data to provide business intelligence.\nLeading companies plan to implement cloud-based solutions that will allow users to manage network products and monitor their status in real-time. Equally important, the solutions will generate reports that provide greater situational awareness and business intelligence.\nCybersecurity will become even more significant with the increased use of edge devices\nAs data is increasingly collected, stored, and protected at the edge as part of a smart factory, smart office, smart retail store, or, more broadly, a smart city solution, the need to protect against cyberattacks has become an even more essential requirement. However, cybersecurity will continue to be a considerable concern for an application, regardless of its size or complexity.\nRespect for data protection and privacy\nThe GDPR in Europe and the CCPA in the US have highlighted the need for companies that collect personal data to have proper data processing procedures in place.\nIn the video surveillance industry, protecting personal identification information based on video data is vital. It is necessary to have a balanced approach that enforces privacy rules while making the best use of the latest advances in technology and the data it helps to collect.\n\u0026ldquo;Independently produced market research reports and customer feedback give weight to these forecasts,\u0026rdquo; said Jeff (Chae Won) Lee, Managing Director of Hanwha Techwin Europe. “In this regard, our product roadmap and sales strategy take into account that whether system integrators are involved in complex, mission-critical, or highly secure video surveillance projects, or simply provide security for a small office, factory, or retail applications, these trends and topics are likely to have a significant impact over the next 12 months and beyond.”\nThe original article and a report on trends may be found here.\nSee also # The Best Facial Recognition Algorithm Calling for a Ban on Facial Recognition: EU DPAs are Worried Facial Recognition instead of Room Keys and Cards: Hotels in Spain go High-Tech ","date":"9 June 2021","externalUrl":null,"permalink":"/posts/trendy-videonablyudeniya-2021/","section":"Blog","summary":"The article deals with the five key trends for the video surveillance industry in 2021 for businesses to be safe and secure.","title":"Video Surveillance Trends and Predictions in 2021","type":"posts"},{"content":" Any commercial process between two countries should include cross-border authentication and mutual recognition of electronic signatures and documents. The article deals with the legal aspect of the use of electronic signatures.\nOnline operations are getting increasingly common in developed and developing countries. People often purchase goods or sign contracts in a digital environment or exchange documents related to commercial transactions. Taking part in the transactions between the countries raises the question of the cross-border legality of electronic signatures in commercial processes and contract agreements in a digital environment. In this article, we will try to eliminate the most common doubts about this issue.\nDigitization of document workflow in commercial operations Document exchange in commercial transactions takes place either in public administrations to exchange tax and customs information or in the private sector for business transactions. People often share information, such as personal data, bank information, contracts, invoices, delivery notes, or statements, among other documents. Increasingly, their document flow is carried out in a digitally automated format, optimizing the entire process.\nOf course, when considering the exchange of documents in digital formats, such as offers, contracts, invoices, or any other documents related to commercial transactions, the use of electronic signatures should inevitably be considered. In most cases, they require authenticity, traceability, integrity, and an expression of willingness to accept or approve the content of the documentation.\nHowever, what happens when these commercial transactions are carried out between people or companies located in two or more countries?\nThere are various legal aspects or specific features of electronic services. Does the electronically signed documentation have legal force in a country other than the country where the signatory companies or individuals are located? Will it be legal? In all the countries? Who can provide us with these services? These are just some of the challenges that arise when digitizing processes or digitally managing our business and contractual relationships beyond our borders. Is an electronic signature legal in all countries? Agreements are generally governed by the principles of autonomy of the will of the parties and contractual freedom of choice, which recognize the right of the parties to independently regulate the contractual terms, including how consent is given or presented.\nThe above means that, regardless of whether the parties are located in the same country or two different countries, their willingness to accept the use of an electronic signature is sufficient to create legal consequences in the contract or any other related document.\nThus, if internationally recognized commercial practice in the sector or industry in which the contracting parties operate accepts the use of an electronic signature as a valid contractual document and the parties do not declare otherwise, no additional recognition is required.\nOne has to check that it is allowed to sign documents digitally in all the countries involved to ensure that the electronic signature is legal. And it should be recognized as a valid means of proof to represent will or acceptance. This point can usually be easily verified by checking whether there is an electronic signature regulation in these countries.\nIn the European Union States, the eIDAS Regulation uniformly regulates the European Digital Single Market. It also regards the implementation of trustworthy electronic services such as electronic signatures. So, the use of electronic signatures is fully recognized in any other member state within the EU.\nIn this sense, people and companies established in the Member States of the European Union can use electronic signature solutions without restrictions to conclude contracts and exchange documentation in digital format for commercial transactions and of any kind, unless a legal prohibition applies.\nThus, a citizen or company located in a country such as Spain can use an electronic signature to sign a contract with a person located in Belgium, Germany, Portugal, or any other member State of the European Union. It will have full legal consequences; these signatures are legal evidence following the general regulatory framework. Qualified Trust Service Providers: Providers of signature solutions in international transactions\nThe legal value of electronic signatures is determined not by the geographical location but by the elements associated with the signature itself. Among the main features that we need to consider when evaluating is a unique connection with the signer, established through a secure issuing process. It should be linked to the data so that any subsequent change in the data can be detectable.\nThe article includes data previously presented in here.\nSee also # The EU law on Electronic Signatures The future of AI: regulation in Europe The Top 5 Myths about Cloud-Based Digital Signatures ","date":"28 May 2021","externalUrl":null,"permalink":"/posts/transgranichnaya-elektronnaya-podpis/","section":"Blog","summary":"Any commercial process between two countries should include cross-border authentication and mutual recognition of electronic signatures.","title":"Legality of an Electronic Signature in Cross-border Operations","type":"posts"},{"content":" What is a cloud-based digital certificate? # A digital certificate is an electronic document emitted for natural or legal personalities. It associates their identity with a pair of keys: a private key that is kept secret by the certificate owner, and a public key that is shared with any recipient. This pair of keys is generated on a cryptographic device. As for a cloud-based digital certificate, the cryptographic operations are carried out in a secure HSM server. It is supervised by a qualified Trust Service Provider. It is as legal as a token-based process of signing. Moreover, it can be far more convenient. So, what is the future of cloud-based technologies in the sphere of a document workflow?\nThe COVID-19 pandemic has made adjustments to the imminent process of global digitalization: corporate, industrial, educational, and government organizations are affected. It revealed the shortcomings of digital infrastructures. Applications for holding meetings, working in document management systems, making remote transactions, and signing contracts - all of them have shown inconsistent performance and some technical errors. Enterprises and institutions had to switch to a remote work format, following the directions of authorities; most of them faced financial meltdown.\nHowever, any crisis is often the starting point of progress: many traditional activities will be transferred online and never return to their previous format.\nAs for the document workflow, the cloud-based digital signature is becoming quite popular. Presumably, almost all elements of office processes related to documents will be transferred to the remote work and storage format. Even now, many companies exchange documents in the \u0026ldquo;clouds.\u0026rdquo; Workers can create, store, and jointly edit texts and other files hosted on a remote server. As for a legally significant document workflow, it must comply with the requirements of the law for confirmation of the originality and legitimacy of the document. Many public authorities have accepted files signed by digital signatures. What are the advantages of using \u0026ldquo;cloud-based\u0026rdquo; digital signatures?\nAdvantages of a cloud-based electronic signature # The most apparent advantage is signers\u0026rsquo; mobility: a person does not have to sit at his desktop to sign and encrypt the document. It means that the user will sign any reports, acts, protocols, contracts, cover letters using various devices - smartphones, tablets, laptops, home computers, at any time. It is particularly convenient for those managers and executives who have to be absent from the workplace due to multiple business trips. Often employees have to wait for their chiefs because they do not have the legal right to sign and send the report.\nData security is one of the priority issues of concern for business owners of any size or heads of public authorities. Losing the key is a problem if you need to sign a document urgently. If the key is stolen, it can be used by fraudsters. However, if you store the signature key on a remote server of the certification authority, these fears are groundless. Despite the myth about the vulnerability of clouds, the keys are stored in a safe place. It is the certification center that is responsible for the safety of the keys. This security is provided by the HSM (hardware and software cryptographic module).\nThe absence of a token is one of the absolute advantages. The USB token or smart card can be lost or broken, or even stolen. It will not happen with the keys in the cloud. If you notify the Certification Center about the loss of the cryptographic key at once, there will be no serious consequences. However, even if illegal transactions are conducted, you can dispute them in court. But any legal process inevitably leads to time and financial costs.\nCost-effectiveness of cloud-based solutions: to take advantage of new opportunities, there is no need to purchase specialized software (for example, a license for the CSP, since the signing of documents is performed on the side of the certification center). In particular, you do not need a driver with a digital certificate - a token or a smart card.\nThe next advantage is that the cloud service significantly simplifies the deployment of a document management system with support for digital signatures. All operations go through the API. Moreover, cloud services are often scalable. High scalability means that no additional configuration or integration is required. Unlike traditional implementation, cloud solutions do not require extra equipment and software configuration.\nOn the whole, the prospects for cloud-based electronic documents and electronic document management are attractive. It is the case when the benefits outweigh the drawbacks.\nSee also # Vaccine Passports: Unlocking the EU Travel EFPE Conference 2021: Review A EU Digital Identity Framework: Plans and a Scheme ","date":"21 May 2021","externalUrl":null,"permalink":"/posts/oblachnaya-kvalifitsirovannaya-podpis/","section":"Blog","summary":"The concept of moving processing to the cloud makes the workflow faster and even more secure than before.","title":"Advantages of a cloud-based qualified digital signature","type":"posts"},{"content":" Last year, cloud solutions became one of the main elements of modern business. They managed to cover the needs caused by the pandemic and, in particular, to support the remote and hybrid working policies. Those companies that successfully implemented cloud-based solutions using artificial intelligence and ML programs have reported successful process optimization, faster time to profit, and increased customer satisfaction as the main benefits. Companies spend an average of $1.06 million a year on AI and ML initiatives. These costs are distributed throughout the organization on ongoing and planned projects to increase revenue, drive innovation, increase productivity, and improve the user experience. However, the pace of implementation was rapid, and therefore success is not guaranteed. Moreover, the data of analysts on project implementation does not look impressive. Gartner predicts that by 2022, less than half of modern data analytics and ML initiatives will be successfully deployed into production. So it\u0026rsquo;s no surprise that more than half of IT professionals in Australia, for example, are still learning how to implement and operate AI and ML models. When more than a third of them also report that R\u0026amp;D has been tested and abandoned or failed. For companies investing millions, failing to understand the complexities of creating and running AI and ML programs can be pretty costly. A common pain point for IT teams is balancing the potential benefits of AI and ML with the challenges associated with running these programs. While some early adopters have already seen the advantages of these technologies, others are still struggling to cope with a lack of in-house knowledge, outdated technology stacks, poor data quality, or an inability to measure ROI. Given the many challenges associated with implementing AI and ML to optimize cloud technologies, many may wonder how to make this integration successful, especially if the company is beginning to transform its technological processes. Here are three essential steps that entrepreneurs and IT decision-makers can take today.\n1. Fill in all the skill gaps\nWhether upgrading legacy technology infrastructures, opening up new opportunities by developing custom AI and ML algorithms for your data or creating a project module management system (pipeline) in the enterprise cloud for AI and ML operations - it all depends on the business needs. However, not all enterprises have the required resources, technical skills, and established business processes to implement AI and ML solutions. They may not have expertise in math, algorithm design, or data science and engineering. Or the data may not be available in a unified data lake infrastructure for ready access. These circumstances create challenges for any business seeking to advance in the market and benefit fr om AI and ML. Before starting the program, business owners need to evaluate their internal skills and determine whether it is necessary to re-skill their team or whether there is a need to enlist an experienced provider.\n2. Address data quality\nAt the heart of any AI and ML program is the desire to act on the available data. However, data quality and data management issues have historically plagued businesses, and these same issues often stand in the way of AI and ML adoption. These barriers are mainly related to the categories of data hygiene, governance, and processes. Enterprises that engage in AI and ML initiatives without plans to complete the necessary data cleanup and data management optimization and management work are often doomed to failure. AI and ML can help companies leverage data for innovative new use cases, but they cannot inherently clean up data or realign data collection and management policies. The AI and ML programs require clean and integrated data. One of the first steps in a successful AI and ML implementation program is the cleaning of enterprise data and information processes. It includes setting clear definitions, eliminating data silos, developing a management strategy, and coordinating business processes.\n3. Strategy first\nIn most companies, IT and operations are the leading areas wh ere they plan on adding AI and ML capabilities. However, AI and ML have potential in a variety of business units. Organizational challenges in implementing AI and ML often extend beyond the IT department, and other obstacles, such as executive involvement, can also affect the process. Strategic challenges, such as identifying use cases and defining the business case, confirm the importance of starting with a clear plan when launching AI and ML programs. To determine the right AI strategy, prepare data, incorporate AI and ML frameworks into the development of applications and data platforms, and maintain and optimize the environment, requires dedicated planning, AI and ML engineering expertise, and automated operations. Most importantly, however, the strategy can help you succeed in areas where the AI and ML program implementation could be unsuccessful due to their complexity. Without a solid destination and organizational buy-in, an AI and ML journey could waste a lot of money and resources and never become production-ready. You have to start by reaching agreements with key stakeholders, presenting a compelling business case, and achieving a consensus on results, milestones, and deadlines to keep the project running. Across industries, businesses are looking for ways to expand their product offerings, improve business performance, and predict customer behavior. What\u0026rsquo;s more, successful AI and ML initiatives tie together a complex ecosystem of data, business processes, and new skill sets to drive business value.\nReference: Three tips to successfully leverage AI and machine learning for your cloud solutions\nSee also # Work from Home: Securing Corporate Data outside the Office How to Fight against Most Spread Recent Cyberattack Types 7 Things You Should Know Before Working from Home ","date":"18 May 2021","externalUrl":null,"permalink":"/posts/ii-ml-oblachnye-resheniya/","section":"Blog","summary":"In a highly competitive environment, every business must adapt to succeed, and AI and ML initiatives help with that.","title":"Artificial Intelligence and Machine learning for the cloud-based solutions","type":"posts"},{"content":" A lot of people do business on the Internet via smartphones and tablets. They often have to manage documents that are part of high-value, high-risk, or strictly regulated business processes. Cloud-based technologies for mobile devices are the best choice for a fast and seamless workflow. Therefore, entrepreneurs need simple and secure ways to protect and manage documents in the cloud. Cloud-based digital signature complies with the strictest requirements of the eIDAS, the Regulation comprising types of electronic signatures and trusted services. It also allows signing documents with the highest level of reliability.\nHowever, for most people, cloud-based solutions do not seem to be a secure option. They still prefer to store signing keys using USB tokens. There are several myths about cloud-based digital signatures. Let\u0026rsquo;s take a closer look at some of them.\nMyth 01: Cloud-based digital signatures are not secure enough because there is a risk of cloud hacking # Special hardware provides a high degree of protection. The certificate keystore should be securely protected by tamper detection sensors, a trusted operating system, and secure audit mechanisms and connection control. User keys are stored encrypted. Believe it; nothing will happen to your digital signature and keys in the cloud.\nMyth 02. A digital signature does not give documents any legal status # Electronic signatures are legally valid and evidence-based in industrialized countries around the world. Although the requirements may differ depending on the region, industry, and business process.\nIn most cases, for electronic signing, a simple verification of the identity is sufficient - by email, confirmation with a one-time password, etc.\nThough, sometimes a more secure and advanced level of assurance is required. In this case, you need to use a digital signature.\nDigital signatures are the most secure type of signatures. In the European Union, such signatures get the legal status of a handwritten signature. Since signing in the cloud is similar to a common signing process using a token, a cloud-based digital signature has the same level of legal significance.\nMyth 03. Cloud-based signatures are unreliable because the server can crash at any time # The hardware used for remote operations with electronic signatures and for storing keys is highly fault-tolerant. If any component of the system fails, it is automatically replaced by a backup one, without interruptions in operation or the participation of maintenance personnel. For load balancing a server software is used. It evenly distributes requests across multiple servers.\nMyth 4. Cloud signing is inconvenient because you need a constant Internet connection # That is partially true. However, the cloud-based digital signature has a lot of advantages over the digital signatures stored on tokens. USB tokens can be lost or broken. One needs a desktop computer to use them. Whereas you can sign remotely in the cloud using the digital signature. You can even sign a document from your phone, as long as there is the Internet.\nMyth 05: Cloud storage is expensive # Not at all. A cloud-based qualified digital signature will cost less than a hardware token containing a digital signature certificate since there is no need to purchase a USB token driver. In addition, you can issue a conditionally unlimited number of keys and certificates while using cloud storage. If the company needs to organize an electronic workflow and provide each employee a USB token for the digital signature certificate, cloud-based service is the best option.\nSee also # The EU law on Electronic Signatures The future of AI: regulation in Europe Legality of an Electronic Signature in Cross-border Operations ","date":"14 May 2021","externalUrl":null,"permalink":"/posts/the-top-5-myths-about-cloud-based-digital-signatures/","section":"Blog","summary":"A lot of people do business on the Internet via smartphones and tablets. They often have to manage documents that are part of high-value, high-risk, or strictly regulated business processes.","title":"The Top 5 Myths about Cloud-Based Digital Signatures","type":"posts"},{"content":" In European countries, electronic and digital signatures are used for the exchange of electronic documents. What are the differences, what are the conditions for their application? This article outlines:\nThe EU law on electronic signatures The three types of electronic signature recognised by EU law and their characteristics. Electronic signature in Europe, the Law # In Europe, legislative work with electronic signatures has been carried out for a long time. In 2011, the European Commission presented the Single Market Act. It set out 12 strategic initiatives designed to boost growth and strengthen the economy of Europe. They also included an overhauled Directive on Electronic Signatures (the Directive on Electronic Signatures (1999/93/EC)). This Directive gave the participating countries free rein to apply the provisions, but this only resulted in fragmented and inconsistent laws that failed to achieve the cross-border application of electronic signatures. Moreover, the Directive did not keep up with the development of technology at the time of its drafting; there were no mobile and cloud-based signature tools that changed our understanding of electronic document management.\nThe law* regulating Electronic Identification and Trust Services came into force on 1 July 2016. *(The EU Regulation on Electronic Identification and Trust Services in the Internal Market (910/2014/EU), hereafter referred to as the Regulation, or eIDAS in short) At the moment, this is the main regulatory document regulating the use of electronic signatures and their verification. It also covers some other trust services, including electronic seals and timestamps in the European domestic market. The aim is to help businesses, consumers, and public sector bodies to carry out convenient and secure electronic transactions across the EU. The Regulation involves not only the electronic signature but also other trust services: electronic stamps (similar to electronic signatures, but used by legal entities); timestamps; rules for conducting transactions and authentication. Besides, in many countries, previously created acts concerning electronic signatures retain their influence. When deciding to interact in the legislative field with the Europeans, it will always be necessary to specify which electronic signature will be valid for a particular document. For example, in Germany, where the law requires a contract to be in the written form, Article 126 of the German Civil Code provides that this requirement can be fulfilled electronically, but only a qualified electronic signature. And in the UK, there is no such requirement for contracts, and in general, the QES is less used when conducting business. Nevertheless, the Regulation applies equally all over the European Union. It ensures relative cross-border compatibility simplifying international transactions conduct and the conclusion of various types of contracts in the domestic market of Europe.\nTherefore, the use of a particular type of signature in industries will differ depending on the country. The Regulation provides information in the field of categorization of electronic signatures.\nTypes of signatures according to eIDAS. # The Regulation defines three types of electronic signature: electronic, advanced and qualified. Let\u0026rsquo;s take a closer look at each of the signature types.\nElectronic signature # \u0026lsquo;Any data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.\u0026rsquo;(Article 3(10), the Regulation) Standard electronic signature means \u0026lsquo;any data in electronic form attached to or logically associated with other data in the electronic form used by the signatory.\u0026rsquo; In other words, this type of signature is the electronic equivalent of a handwritten signature. This signature can range from a printed name in an email to confirmation of consent by providing your biometric data.\nAn electronic signature platform typically allows the signatory to write his signature directly on the document (with a stylus or mouse). Also, one can select a computer-generated signature from a variety of fonts and styles. These types of signatures usually do not involve any independent third party to verify the signatory\u0026rsquo;s identity. At the same time, they meet the requirements for an electronic signature of the eIDAS regulation.\nPossible applications of standard electronic signatures include standard forms of hospitals, schools, insurance companies, some bank forms, documents submitted to the public sector, contracts for the provision of services to small businesses, contracts with freelancers and consultants.\nAdvanced electronic signature # An advanced electronic signature is a more sophisticated and secure form of signature. It is a digital signature created with public key cryptography (PKI) and inserted into the code of an electronic document. The legal requirements for an AES are laid out in Article 26 of the Regulation (see box \u0026lsquo;Requirements for an advanced electronic signature\u0026rsquo;).\nThe Regulation itself is technology-neutral and does not prescribe how these requirements should be met. However, even before the repeal of the Directive, a working paper of the Forum of European Supervisory Authorities for Trust Service Providers (FESA) prescribed that the advanced electronic signature is the result of PKI technology.\nThe trust provider issues and signs a digital certificate that confirms the signatory\u0026rsquo;s identity and contains its public key. A digital certificate is associated with an electronic document as a result of signing with a digital signature.\nThe recipient of the document may be sure that the signer is the one who was supposed to sign the file, and he uses the public key of the signer to verify the digital signature.\n*Requirements for an advanced electronic signatureArticle 26 of the Regulation on Electronic Identification and Trust Services in the Internal Market (910/2014/EU) states that an advanced electronic signature must be: **• Uniquely linked to the signatory. **• Capable of identifying the signatory. • Created using electronic signature creation data (that is, a private encryption key) that the signatory can, with a high level of confidence, use under his sole control. *• Linked to the signed data in such a way that any subsequent change in the data is detectable.\nQualified electronic signature # The third type is the qualified electronic signature. It is also a digital signature created by a qualified electronic signature creation device. It provides the highest level of admissibility in the EU courts and has the equivalent legal effect of a handwritten signature (Article 25(2), the Regulation).\nIn addition to meeting the requirements for the AES, the European QES must be supported by a qualified certificate issued by a qualified trust service provider (QTSP), whose credentials have been recorded in a trusted list published by a member state (Article 22, eIDAS Regulation). This list includes information related to a qualified trust service provider supervised by the EU member state. It also contains a scope of the trusted services it provides. The qualified trust service provider will only be qualified if it appears on a trusted list.\nAn interactive map*** ***showing the current status of the trusted list of qualified trusted service providers in Europe.\nthe \u0026ldquo;Signature Generation \u0026amp; Sealing Service\u0026rdquo; (SigS) - signature and seal generation services, the \u0026quot; Validation Service \u0026ldquo;(ValS) - verification services, the \u0026quot; Preservation Service \u0026ldquo;(PresS) - storage services, the \u0026quot; Electronic Delivery Service \u0026ldquo;(EDS) - electronic delivery services, the \u0026quot; Time Stamp Authority” (TSA) - centres authorized to issue timestamps, the ”Certification Authority \u0026quot; (CA) - the certification authority.\nSources: Key Contractual Issues by Richard Oliphant\nSee also # The future of AI: regulation in Europe The Top 5 Myths about Cloud-Based Digital Signatures Legality of an Electronic Signature in Cross-border Operations ","date":"26 April 2021","externalUrl":null,"permalink":"/posts/the-eu-law-on-electronic-signatures/","section":"Blog","summary":"In European countries, electronic and digital signatures are used for the exchange of electronic documents.","title":"The EU law on Electronic Signatures","type":"posts"},{"content":" On March 17, 2021, the head of the European Commission, Ursula von der Leyen, announced the introduction of “Digital Green Certificates” before the tourist season. Holders of these certificates, who are vaccinated against Covid-19 or have other evidence of their safety for others, will be able to move and travel around the region freely, without restrictions and without the need to maintain the mandatory quarantine. What does the Сertificate look like? # The Сertificate will have a QR code; it can be presented in paper or electronic format and will be issued free of charge. It will not only allow free entry to European countries, but it will also be possible to present it in public places: on public transport, restaurants, theatres, and cinemas. This document will allow you to prove that a person is immune: one was vaccinated, recently cured of Covid-19, and has antibodies or received negative results of a PCR test.\nThe project has already been approved by the European Medicines Agency (EMA), provided that vaccines presented in the Сertificate are among those that are allowed in Europe (at the moment, four have been approved: BioNTech and Pfizer, AstraZeneca, Moderna, Johnson \u0026amp; Johnson).\nHow does the Digital Green Certificate work across the EU? # The Digital Green Certificate contains a QR code with a digital signature to protect it against tampering. When the certificate is verified, the QR code is scanned and the signature is validated. Each authority (e.g. a hospital, a test laboratory, a health authority) that has the right to issue certificates has its own digital signature key. All of them are stored in secure databases in each country. The European Commission plans to create a registration database with a gateway. Through this gateway, all certificate signatures can be verified throughout the EU. The personal data of the certificate holder do not pass through the gateway, as these are not necessary to verify the electronic signature. The European Commission will also provide open source implementations to support member states in developing software that authorities can use to scan and verify the QR codes.\nSee also # Advantages of a cloud-based qualified digital signature EFPE Conference 2021: Review A EU Digital Identity Framework: Plans and a Scheme ","date":"26 April 2021","externalUrl":null,"permalink":"/posts/vaccine-passports-unlocking-the-eu-travel/","section":"Blog","summary":"On March 17, 2021, the head of the European Commission, Ursula von der Leyen, announced the introduction of “Digital Green Certificates” before the tourist season.","title":"Vaccine Passports: Unlocking the EU Travel","type":"posts"},{"content":" Signing employment contracts in electronic form is an opportunity for the HR department to translate the personnel files into digital format and meet the increasing expectations of employees and managers who regularly require HR managers to improve productivity.\nThus, if the HR department plans to develop strategically, it is appropriate to say that an electronic signature can help optimize the signing of employment contracts in electronic form.\nWhat is an electronic signature? # An electronic signature is a term for any type of signature in electronic format. As defined by the EU regulations on e-signatures (eIDAS), an electronic signature refers to “data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.”\nAn electronic certificate is required to verify the signer’s identity. It includes the signer’s personal information, as well as the private key required for the signature. The certificate can be stored in two ways: on a physical device or in the сloud.\nBesides, an electronic signature has legal significance. It is based on the eIDAS (Electronic Identity And Trust Services) regulation, which came into force on July 1, 2016. It regulates various types of signatures and their use. An advanced electronic signature (an AES) is recognized legally if the following requirements are met.\nAn AES must be: • Uniquely linked to the signatory • Capable of identifying the signatory • Created using electronic signature creation data (that is, a private encryption key) that the signatory can, with a high level of confidence, use under his sole control • Linked to the signed data in such a way that any subsequent change in the data is detectable.\nThe eIDAS defines three types of electronic signature: electronic, advanced, and qualified. Standard electronic signature: is used for documents with limited risk(examples: invoices, estimates); the document integrity is guaranteed after signing. The signatory’s identity is confirmed too. Advanced electronic signature: is used for financial transactions or legal documents, such as an employment contract. The security level of an AES is higher. Qualified electronic signature: is used for documents with a high risk of liability, such as legal documents in the judicial system. It is the most secure type of signature since the signatory\u0026rsquo;s identity is verified in his physical presence.\nBenefits of signing an employment contract with an electronic signature for HR departments Electronic signatures are advantageous not only to HR departments but to businesses too.\nIllustration of the process of signing an employment contract in electronic format # An employment contract is one of the personnel documents that require the signature of two parties. The established practice of signing an employment contract in paper format is still quite widespread. Nevertheless, the personnel document flow is evolving following modern trends, and more and more software manufacturers allow dematerializing an employment contract and signing it electronically.\nThe dematerialisation of contracts is the process of digitizing documents or creating, signing, and archiving contractual documents online using specific electronic signature programs and electronic document storage systems, such as DocaPost, DocuSign, or PeopleDoc. There are different electronic signature tools: some are intended only for the electronic signing of documents. These tools are often used more widely, not only for personnel document management but also for the procurement process, accounting (for example, to sign client contracts, invoices), etc. There are also electronic signature tools that offer more extensive functions for the HR department. These tools may initially offer other HR modules that are interconnected or integrated into HR solutions. In both cases, the use of an electronic signature improves the efficiency of the recruitment process. A contract can easily be generated with a few clicks, and prospective employees can access their employment contract shortly after receiving a job confirmation.\nThe seamless process of signing documents makes a favorable impression on candidates. It also speaks about the right choice of the employer.\nHow do I sign an employment contract with an electronic signature? # To dematerialize the process of drawing up and signing an employment contract, you need to complete five steps in the diagram below:\nThere are a few things that you should pay attention to before you translate employment contracts in your company into an electronic format :\nThe cost can be very high. Therefore, it is vital to check the proposed price by checking the competing suppliers. The implementation time varies depending on the existing IT structure within the company. It also depends on the software provider that will implement this integration. It is also significant to make sure that you are signing the document with the appropriate electronic signature certificate.\nFinally, the choice of an electronic signature tool should match the overall IT structure of the company.\nSwitching to electronic HR workflow will help your company achieve its performance goals and shift from traditional HR transactions to engaging, end-to-end experiences, using intelligent technology to make each interaction less complicated and more meaningful. An original article is here.\nSee also # An E-Signature: the Key to a Secure Document Workflow Email Safety Tips Every User Should Know to Keep It Confidential ","date":"24 April 2021","externalUrl":null,"permalink":"/posts/electronic-signature-for-hr-contracts-in-france/","section":"Blog","summary":"Signing employment contracts in electronic form is an opportunity for the HR department to translate the personnel files into digital format and meet the increasing expectations of employees and manag…","title":"Electronic signature for HR contracts in France","type":"posts"},{"content":" On 21 April 2021, the European Commission unveiled its long-awaited proposal for a regulation setting out harmonized rules on artificial intelligence and amending some of the union legislation. The proposal is the result of several years of preparatory work by the commission and its advisers, including the publication of the \u0026ldquo;White Paper on Artificial Intelligence.\u0026rdquo; This proposal is a key element of the commission\u0026rsquo;s European Strategy for data.\nThis provision applies to (1) providers that place on the market or put into service AI systems, irrespective of whether these providers are established in the European Union or in a third country; (2) users of AI systems in the EU; and (3) providers and users of AI systems that are located in a third country where the products produced by the system are used in the EU.\nThe term “AI system\u0026quot; is broadly defined as “software that is developed with one or more of the techniques and approaches listed in Annex I and can, for a given set of human-defined objectives, generate outputs such as content, predictions, recommendations, or decisions influencing environments they interact with.” The commission takes a risk-based but generally cautious approach to AI and recognizes the potential of AI and the many benefits it presents, but at the same time is acutely aware of the dangers these new technologies present to European values and fundamental rights and principles.\nThis explains why the sentence begins by listing the four types of artificial intelligence techniques that are prohibited:\nPlacing on the market, putting into service or using an AI system that deploys subliminal techniques beyond a person’s consciousness to materially distort a person’s behavior in a manner that causes that person or another person physical or psychological harm. Placing on the market, putting into service or using an AI system that exploits vulnerabilities of a specific group of persons due to their age, physical or mental disability to materially distort the behavior of a person pertaining to the group in a manner that causes that person or another person physical or psychological harm. Placing on the market, putting into service or using an AI system by public authorities or on their behalf for the evaluation or classification of the trustworthiness of natural persons with the social score leading to detrimental or unfavorable treatment that is either unrelated to the contexts in which the data was originally generated or unjustified or disproportionate. Use of “real-time” remote biometric identification (read: facial recognition) systems in publicly accessible spaces for law enforcement purposes, subject however to broad exemptions that, in turn, are subject to additional requirements, including prior authorization for each individual use to be granted by a judicial authority or an independent administrative body in the member state where the system is used. The bulk of the offer focuses on high-risk AI systems. High-risk AI systems should be thoroughly tested before they are placed on the market or put into service and throughout their life cycle, including through a mandatory risk management system, strict data and data governance requirements, technical documentation and record-keeping requirements, and post-market monitoring and reporting incident requirements.\nA conformity assessment by a third party or the provider itself and, for stand-alone AI systems, registration in a central database set up and maintained by the commission. Different procedures apply depending on the type of system and whether the system is already covered by existing product safety legislation.\nThe obligations under the proposal affect all parties involved: the provider, importer, distributor, and user. There are special provisions relating to transparency to ensure people know that they are dealing with an artificial intelligence system but also allow users to interpret the results of the system and use it appropriately.\nArticle 14 of the proposal emphasizes that AI systems shall be designed and developed in such a way that human oversight is guaranteed while in use.\nIn an effort to demonstrate that the commission is aware of the opportunities presented by AI technology, the proposal also contains several provisions in Title V that outline measures in support of innovation. They include regulatory sandboxing schemes and an obligation on member states to provide certain services and facilities for small-scale providers and users.\nIn line with positions taken in other data-related legislative initiatives, it is up to the member states to ensure compliance with the AI rules. The regulation foresees steep administrative fines for various types of violations ranging for companies from 2% to 6% of total annual global turnover. The proposal foresees the creation of a European AI Board with various tasks, including assisting the national supervisory authorities and commission to ensure the consistent application of the regulation, issue opinions and recommendations, or collect and share best practices among member states.\nThe regulation, once adopted, will come into force 20 days after its publication in the Official Journal. It will apply 24 months after that date, but some provisions will apply sooner. This long \u0026ldquo;grace period\u0026rdquo; increases the risk that, despite the commission\u0026rsquo;s efforts to make the regulation future-proof, some of its provisions will be overtaken by technological developments before they are even apply.\nThe proposal now goes to the European Parliament and Council for further consideration and debate. Given the controversial nature of AI, large number of stakeholders and interests involved, it seems fair to assume the road to adoption will be bumpy and long. There will likely be many amendments in the European Parliament and discussions with member states. The source is here.\nSee also # The EU law on Electronic Signatures The Top 5 Myths about Cloud-Based Digital Signatures Legality of an Electronic Signature in Cross-border Operations ","date":"16 March 2021","externalUrl":null,"permalink":"/posts/the-future-of-ai-regulation-in-europe/","section":"Blog","summary":"On 21 April 2021, the European Commission unveiled its long-awaited proposal for a regulation setting out harmonized rules on artificial intelligence and amending some of the union legislationhttps://…","title":"The future of AI: regulation in Europe","type":"posts"},{"content":"DIGT is a group of companies investing in IT projects. We have many years of experience in developing software solutions in the following areas:\nDevelopment of solutions for authorization, authentication, user operation record Development of systems of identification and managing access to information resources Development of complex solutions for secured electronic legal work-flow Development and supply of software for cryptographic protection of information Integration of cryptographic algorithms in application programs and business applications Development of solutions for user authentication and data encryption Development of intelligent video surveillance systems Creating artificial neural networks of our own architecture Creation of complex solutions using machine learning technologies Source: digt.com.\n","externalUrl":null,"permalink":"/about/","section":"About","summary":"","title":"About","type":"about"},{"content":"","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"}]