Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.
Speaker B: Hello and welcome to Password on Resonance FM with me, Peter Peter Warren, the program that tells you all about the ins and outs of our new interconnected world. In today’s program, we look into an organized fraud that is costing the UK hundreds of millions of pounds and the world billions, why the UK needs to recruit more IT specialists, and how the internet is shaking up the high street, with the high street banks as the next possible victims. But first, phone fraud. Like much of the crime on the internet, Phone fraud is complex and almost banal unless you are the victim. By hacking the new software, switchboards, and devices used by UK businesses, organised cybercriminals are netting themselves fortunes. And it’s not only businesses that are being hit. Embarrassingly, Scotland Yard, that byword for UK police competence, has been among the victims, losing, it is claimed, nearly £1 million itself. Here, as part of a new series that looks behind the scenes at how cybercrime works and the part we all play in it, is Colin Duffy, who is doing an MSc in criminology at Oxford University. And he’s specialising in phone fraud. He’s uniquely qualified to know all about it. As the chief executive of the phone company VoIP Phone, he is on the front line of the fight against the criminals. Colin, what is VoIP Phone? Or what is VoIP, in fact? It sounds like just one another of these horrible acronyms that the technology industry spawns with such ease.
Speaker C: Oh, it’s not so bad. I mean, it just stands for Voice Over Internet Protocol. It just means you’re sending your voice over the internet just like you send email or music or whatever.
Speaker B: Essentially then, what we’re talking about is a service like Skype, are we?
Speaker C: Similar to Skype, but the only difference is— I mean, it’s a generic term, so it does cover what Skype does, but the telephony across the world is now all migrating to VoIP. Whereas telephony generally is an open standard, an international standard that everybody signed up to, Skype is a secret known only to Skype and Microsoft these days.
Speaker B: Okay. But what you’re saying is that essentially all of the telephone companies, whether it be BT or whether it be any of the other service providers and probably including the mobile phone companies, they’re all trying to use this voice over internet protocol.
Speaker C: Yeah. It’s the next set of technologies used by telephone companies to send telephone calls anywhere in the world. Every telephone company in the world is using it.
Speaker B: It would appear that every criminal in the world is now looking to abuse it as well. Why is it being targeted by criminals?
Speaker C: Well, there’s many reasons. I mean, it’s used by criminals because it can be used. They will use whatever the next technology is, and this is the next technology. Particularly in what we’re talking about. They can generate an awful lot of money by corrupting and abusing the systems. Because it’s so new, not everybody’s caught up with how to defend themselves against these kinds of attacks.
Speaker B: So what are the criminals doing? What they must be doing, they must be stealing phone calls.
Speaker C: Two generic approaches, if you like. One is to scan the world for equipment that is just hanging onto the internet and open. And one type of equipment is a PBX, the switchboard that most offices have to direct calls in between different extensions in the same building. These days they are all connected to the internet. And if you don’t know what you are doing, a criminal can spot it in Morocco very, very easily.
Speaker B: How quickly could they spot that?
Speaker C: A new server hanging on the internet anywhere in the world will be spotted within 24 hours and quite often within 30 minutes. They use tools that are open, free, they’re available out there, things like Shodan if you want to go look for it.
Speaker B: That’s a system that allows you to actually look at systems on the internet and see what they do, isn’t it?
Speaker C: Yeah, it’s a network scanner. So if you find using that tool or any other, there are any number of other tools. Find an open box out there. You can see almost immediately what services are available to you and you can use other tools to get inside the box. Things like SIPVicious. Once you’re in there, you use a brute-forcing piece of software to crack any passwords that might be protecting it and you’re away. You can make phone calls as though you owned that piece of equipment, which technically you do for the period of time that you’ve attacked it.
Speaker B: Okay, and SIPVicious, this tool that you’re mentioning, obviously named after the punk rock star. I am an antichrist. SIP, what is SIP? SIP is part of VoIP, isn’t it?
Speaker C: Yeah, Session Initiation Protocol. It’s the universal standard for VoIP. Telephony standard.
Speaker B: So it’s a component of this voice over IP system. So presumably that’s the thing that starts the phone call going.
Speaker C: Yeah, it starts it going. It manages the phone call and knows when the phone call’s ended and sends all the correct signalling to make sure that everybody gets billed properly and the call progresses properly.
Speaker B: You say that obviously you can detect a piece of equipment that’s been installed. What do you then do? What are the crimes that the criminals are doing?
Speaker C: Technically, the crime is getting into the equipment and stealing the phone calls. Technically, it’s a crime under the Communications Act 2003.
Speaker B: So you make phone calls from that server, yeah?
Speaker C: Yeah, you start making phone calls. They’re not just any old phone call. They’re not phoning the mother or the granny. What they’re doing is phoning then numbers that will generate revenue for them. And there are a number of services available to them to do that. They can sign up for services anonymously. And start sending phone calls to these premium rate services, as they’re called, quite often.
Speaker B: I mean, that’s one of the fascinating things, isn’t it? That it would appear that what is happening is that people are signing up to a premium rate line, then ringing that line, and they’re getting a percentage of the revenue back from that.
Speaker C: That’s correct. They get paid weekly on the nose in $200 blocks. So they’re still— they break an entry into a telephone system and start calling the numbers that they’ve previously hired and keep those numbers engaged for as long as they possibly can. And then they get a share of the revenue generated from those phone calls. Because you know, the premium rate numbers aren’t cheap. They’re generally over £1 a minute and quite often a lot more than that.
Speaker B: So you ring up on these numbers over the weekend and you just keep the line open. How much does that cost somebody? And are businesses in the UK being hit?
Speaker C: They’re being hit enormously. There’s no recorded, properly recorded analysis of all this, but you will find if you start looking through the archives that people are being done typically for about £20,000 to £50,000 over the weekend for an unprotected network. In the UK, the fraud, telephony fraud generally is just under £1 billion, £920,000,000,000, I think it is. Globally, it’s claimed to be about £46 billion. The industry actually thinks it’s going to be more than that because not all of it is reported. In fact, hell of a— almost none of it is.
Speaker B: £46 billion, but that’s obviously globally, nearly a billion in the UK. Who’s suffering because of that?
Speaker C: Two types of people. The first type is the businesses that are being hacked. They tend to be small businesses because they can’t afford the proper management and maintenance of the services. So they are at risk right from the very start. UK small businesses are being attacked all the time. Some bigger businesses go as well. And the other side of it is the service provider. Quite often the service provider themselves are attacked and they are losing out. And service providers these days don’t have to be mega corporations. They can be very small businesses themselves.
Speaker B: Obviously, you can’t get this money back. There is one school of thought that thinks that phone companies just generate the phone calls and it’s a very easy thing to do and that they must have the equipment to do it, but you’re saying that that isn’t the case.
Speaker C: No, no, they wouldn’t do that. It’s too easy to be caught out doing it. There’s just no point. There’s enough problems out there in the world. With people attacking you without you making problems for yourself.
Speaker B: So, but I mean, the point I was making is the conventional wisdom among people who may not be that wise is that if I make a phone call, it doesn’t actually really cost anything to the phone company until I make the phone call. So they can quite easily give me that back. What you’re saying is that if it’s a fraudulent call, then the person who’s made that fraudulent call can vanish off into the ether and leave you with the entire cost of that.
Speaker C: Oh yeah, leave it.
Speaker B: Could you give us an example of that?
Speaker C: They leave an enormous legacy behind. Them. It’s not true that it doesn’t cost people anything. If you take an example of a phone call that starts off in the UK and goes to Cuba, £2 a minute, let’s say, in order for the phone call to get to Cuba, it has to transit many operators. It will go from us, for example, Vodafone, into BT, it will go from BT into an international exchange, From there it will go to the next person in the line until it gets to Cuba. At the beginning of the call, Vodafone will charge its customer £2 a minute for that call, but it will hand over £1.99 of that to BT. Then BT will hand over a proportion of it to the next person on the line and so on until it gets to Cuba and Cuba gets a piece. So all along that chain, people have been paid for doing their work on the call., but only VoIP phone billed the customer. If that chain call turns out to be fraudulent, the bank will stop a payment and it will be VoIP phone’s payment that gets stopped. Whereas VoIP phone will still have to pay BT. BT will still have to pay whoever they sent the call on to next. So it’s the first provider in the chain that gets hurt and it’s a real amount of money in our case.
Speaker B: Well, that was Colin Duffy of VoIP Phone on the fraud that gives organised crime some £46 billion of seed capital that, according to the police, is being invested in terrorism and in other criminal enterprises such as drugs, gun running, people smuggling, prostitution, and online pornography. We did ask the Cabinet Office, which is responsible for cybercrime in the UK, for a comment on this, but they didn’t get back to us. So we decided to find out for ourselves why the criminals are able to get away with so much more online than they can on the real-world streets. And one of the reasons is that not enough of us know enough about it. Here’s Jason Gorman, an expert programmer and former advisor to the government on cyber training, to explain why, with computer programmers everywhere, we have a shortage.
Speaker D: There is a shortage of skills in the sense that there is a definite shortage of good software developers. They are hard to find. Having said that, there is no shortage of people calling themselves software developers and charging money to do it. If you stick an ad on a website like Jobsurf.com for a developer job that’s reasonably well paid, you will get hundreds of applicants of which maybe a few dozen will be worth looking at. Of those few dozen, maybe a handful will be genuinely any good. Because we’re a profession that doesn’t require any qualifications, we’re a profession that’s not organized in the way that medicine is or law is.. So we’re a bit of a wild frontier. So anybody who’s had a, you know, learned a bit of JavaScript, if they want to, they can call themselves a software developer. And there’s not a lot we can do about it. And particularly at times when there is this perception that we need lots of people, employers, because good developers are hard to find, they tend to lower the bar to let more people in. I saw this, I’m old enough to have been around for the first dot-com boom. As a software developer, and I saw how employers became so desperate for people that knew some basic web development skills, very basic, that the industry became flooded with people who weren’t software developers and didn’t really know what they were doing. And unfortunately, a lot of them are still around.
Speaker B: Well, that is a big problem, isn’t it? One of the biggest problems in all of this is this issue of certification. So why isn’t the British Computer Society doing something about it? Why isn’t Intellect doing something about it? Why aren’t they saying that we need to have qualifications like those, as you say, for lawyers or for accountants, etc., etc.?
Speaker D: Well, this is the thing. We do have them. Certification in software development is seen as a bit of a sort of a joke in the sense that you can work with developers who have been certified by whatever board or company it is. And it seems to have— it doesn’t indicate to any extent how good they are as software developers. We have a similar problem in academia. I have an apprentice who’s studying at Bristol at the moment computer science. And some of the advice he’s been getting on software development from some of the lecturers has been very worrying. And because there are a lot of lecturers, a lot of people teaching computers who’ve never done the job that I do, who don’t understand it, and are coming at it from either a purely theoretical or a purely academic standpoint. So a computer science degree is no indication that they’ll be any good as a software developer. An industry certification seems to be no indication that they’ll be any good as a software developer. And as it stands, the only way to know is to work with them and see how they they do their job, which is one of the services that I offer is sitting down with candidates for developer jobs and programming with them and seeing how they tackle problems. Unfortunately, that’s the best we’ve come up with.
Speaker B: But that’s terribly worrying, isn’t it? The whole area of computing is terribly worrying given that there is such reliance on this now from the whole world. There was a need for a software agency very, very similar to the Food and Drugs Agency because a lot of people roll out software that is untested and frankly dangerous. And bearing in mind some of the places where it is going to go, you know, that, that is— it shouldn’t happen. I mean, I’ve been told, um, by people of beta programs being run in nuclear power stations. Now that is frankly unacceptable. If it’s an untested piece of software is out there, then you shouldn’t really install it until you know what it can and can’t do.
Speaker D: I mean, I would completely agree. I think the problem in our industry, and this is probably a personality thing, I don’t want to tar all, you know, because I’m a software developer, so I’ll be tarring myself. I don’t want to tar all developers with this kind of Asperger’s brush and say that we’re difficult people, difficult personality types, but there is a tendency within the industry, I think, for us to be, we’re a very difficult social group to organize. It is a lot like herding cats.
Speaker B: So, according to Jason Gorman, we have a problem. This is Password with Peter Warren on Resonance FM, and after us you can hear Kitchen Magic Time. And if you are listening to the repeat, then it’s the organ presents the other rock show. Because we don’t know enough about computer programming ourselves, how can we know whether someone that we want to work with on the new high-tech business we’ve dreaming about can do what they say they can? Indeed, how can we check? According to Gorman, the problem could be even worse than that. The programmers we have employed may even be writing poor code that makes our online enterprise insecure and easy to hack. Unlike the builder who’s made some improvements in your home, you can’t You can’t even see with your eyes whether there are any imperfections, and even with builders, some of us would not be able to either. So how can we protect ourselves against the cowboy programmers, and what is the government doing? Here’s Ian Glover, president of the government-backed Crest programme, which aims to give qualifications to computer security staff and encourage more people to become involved, to plug the 1.5 million global shortage that has been identified by the research company Frost Sullivan. According to Glover, who runs Crest’s Inspired Careers programme, which aims to encourage more people into IT generally, we should all start considering a career in code.
Speaker E: So we have undoubtedly got a significant shortfall in terms of people working in IT in general and specifically in information assurance. What the number is is a very difficult thing to identify because obviously if we have more people, I think the industry will grow and our opportunity in the UK to export will increase. So if we increase the number of people, I think in many ways we increase the demand. But the people that we’re trying to identify at the moment tend to be very skilled people. So if you look at the job adverts, you look at the recruitment sites, they’re generally looking for experienced staff. And therefore, from my perspective, what we need to do is to invest below that to make sure that those younger people are actually encouraged into the industry. And that we provide an opportunity for them to become experienced. If we don’t do that, then I don’t believe we can grow the industry.
Speaker B: We’re talking about vacancies everywhere, aren’t we? We’re talking about vacancies in IT itself. We’re talking about particular vacancies in cybersecurity, which is quite a big issue.
Speaker E: It’s right the way across the board. It’s right the way across the board.
Speaker C: It’s—
Speaker E: and it’s not just industry. What we’re doing as an industry is competing with a number of other disciplines. If you look, I was speaking to some people at the University of West of England. They’ve had to close their entry in terms of hard engineering because of the demand for places on their courses. It’s quite incredible, and I think they’ve done a very good job in driving that forward. So I think if we just look in an insular way either at information technology or even information assurance or cybersecurity, then I think we’re missing the big picture. We have an aging population of hard engineers engineers and IT professionals, and a lot of those are retiring at a time when the industry is growing. But that’s the same for all the other industries as well. So what’s happening is everybody is competing for the very best young people, and the industry that is most organized and looks the best and has the most defined career paths and is most interesting, I think, will start to win. And what we as an industry, both in terms of IT and cyber, I think we need to take that message into young people to make sure we’re describing our industry as being the most exciting place in the world, which I absolutely believe it is.
Speaker B: But there is another issue here, isn’t there? We’ve interviewed a gentleman called Jason Gorman, and he says that the issue isn’t that there aren’t enough people. The problem is being able to find the right good people and being able to identify them.
Speaker C: That, he says, is an issue.
Speaker E: So in terms of trying to identify the right people, I completely agree. As you know, Crest, we carry out professional-level certifications of individuals, and that’s exactly what we’re trying to do. We’re trying to make sure that people are fit for purpose. If you go into a hospital or you go to a doctor’s, you understand the difference between a general practitioner and somebody who’s a specialist in heart surgery. You know, we— but you do that through their qualifications and through their certification and through their experience and training. What we’ve got to do as an industry is to be able to replicate that. Even in accounting, you understand that you leave university and then you have to go through a number of other training courses. You have to pass a set of increasingly difficult exams to be recognized within the industry. And I think within cyber, we are attempting to do that, particularly within cybersecurity in the technical area with organizations like CRASST. But I think we have to look at that in a more general way across the whole piece in terms cybersecurity, and I think the government is doing quite a good job with the CSG Certified Professional scheme, the CCP scheme, but we need to be able to have a scheme that’s recognized outside of government as well to make sure we understand what the individuals who are providing these services or developing our products actually look like and whether or not they’re qualified to do it. I think without that, as both an identifier in terms of the position you are in your career and how competent you are, then we can’t define a career structure. And again, I don’t think if we can’t define a career structure, we’re not going to get the very best people in the marketplace. They are going to go into finance, they are going to go into accountancy, or they are going to go into other disciplines where people understand the progression.
Speaker B: Well, that was Ian Glover, president of the government-backed computer security certification program Crest, talking about why the government wants more IT security professionals to be trained and rolled rolled out to more small businesses. But it’s not just small businesses that don’t seem to have grasped the fundamentals of the new internet world. Even organisations that you think would have their fingers on the pulse are struggling. And those villains of the 21st century, the bankers, seem to be in trouble too because of a process that luxuriates in the horrible name of disintermediation. And our new icons of financial probity Could be mobile phone companies. According to Michael Baxter, co-author of a new book, I Disrupted, who’s here in the studio, the banks themselves could be in danger of vanishing as we know them.
Speaker A: Hello and welcome, Michael.
Speaker B: Hello, good to be here. Well, the first question has to be, what on earth is disintermediation?
Speaker A: Well, it’s a horrible word, and it literally means cutting out the middleman. So in this internet age, when we have greater transparency, is much harder for a middleman, such as a bank sitting between a lender and a saver, to make its markup. But it also has a sort of a wider connotation. It just refers to disruption in general.
Speaker B: Okay, and so why are they vulnerable to this disintermediation? What is it that’s made banks vulnerable?
Speaker A: There are lots of reasons. First of all, you’ve got the rise of the challenger banks, which are helped partly because The current generation of banks are haunted by their IT legacy. It’s often cheaper to start from scratch than it is just to tweak it, so that gives an advantage to new entries to the market. You’ve also got much lower barriers to entry these days. The bank’s strength used to be their branch network. Well, that no longer counts. Then you’ve got sort of a wider technology impact. You’ve got things such as peer-to-peer lending. So that is a classic example. Now that, so in this respect, you’ve got cutting out the middleman. You’ve got lenders lending directly to borrowers, which is especially relevant when banks are struggling to make money because the rate of interest is so low. You’ve got regulators getting in the way, and for example, It’s harder for a bank to lend to Apple than it is to lend to Greece. Whereas if you’re a corporate and you want to make a loan, then the regulator is less of a hurdle. Then there are lots of other factors such as virtual currencies, peer-to-peer payments, crowdsource funding, the rise of the big tech giants such as Google and Apple. Facebook. There are all sorts of reasons why banks are under threat.
Speaker B: So what is legacy? When you say legacy, what is this legacy that the banks have?
Speaker A: So banks have developed their IT over decades at an absolutely massive cost. But these days, legacy IT is very different. We’re talking about the cloud. You’re talking about software products that are available for free across the internet, all of a sudden you can do your IT in a completely different way.
Speaker B: So in a sense, what you’re saying is that all of those ATM networks that they developed, all of their infrastructure was actually pre-internet, and the internet can knock that out just like that, in the same way that we can do transactions.
Speaker A: Exactly right.
Speaker B: Exactly right. Right.
Speaker A: And so peer-to-peer, what’s that then? So peer-to-peer is when an individual or a company can lend directly to another individual. So in the old days, the bank had that kind of, that sort of veil of secrecy. So people put their money in the bank and the bank would find people to lend it to and it would know things that nobody else sort of knows and it can go off and make its markups without anyone being any the wiser. Well, it’s different now. You don’t need a bank for that purpose. You can, if you’ve got money to lend and you’re fed up with receiving half a percent interest rate, you can go out and find people to lend the money to.
Speaker B: Right. Disintermediation sounds like it’s a good thing. But is trust an issue here? You know, apparently we feel a bit warmer to the telephone companies. Research has shown that people speed up and walk faster to past high street bank branches, or they used to when they were there. And, you know, is this going to happen with mobile phone companies?
Speaker A: Well, mobile phone companies, yes, and the big techs too. There’s something called the Millennial Disruption Index, and it found that 73% of the so-called millennial generation— that’s people born sort of in the late ’80s and the 1990s— would be more interested in a banking product from a big tech company such as Google, Apple, or PayPal than from a bank. Right, and why is that? Well, there’s a lot of research that suggests that the millennial generation have a slightly different way of looking at things. So a lot of people might say, well, why would I want to use a virtual currency? Why would I want to use Facebook for my banking when I’ve got a bank? And that’s a perfectly legitimate question. It’s just that the millennial generation have a a slightly different way of looking at that.
Speaker B: Okay. Now, there’s a move to make sure that all companies look after our personal data, and a lot better. We all know that banks have been sharing our data for a long time, but won’t any company that’s replacing the banks just morph into that same distrusted entity?
Speaker A: Well, there’s two answers to that. The sort of gut answer would be to say, well, if they were to do that, they’ll get disrupted too. But of course, there are certain companies out there that are rather powerful and rather large. And there are some companies out there who claim in their ethos to be holier than thou. But there are some people who would argue that they’re not quite as unevil as they claim to be. And so, yes, it is quite possible, if you like, that we will lose the devil that we know and have it replaced by a devil that we don’t know.
Speaker B: I can’t possibly think who you’re sort of meaning. Google has set up a banking system, hasn’t it? It’s got a bank as a junior partner.
Speaker A: Indeed. And Facebook recently has been in discussions with the Bank of Ireland to act as an e-money institution.
Speaker B: Now, very quickly, because we’re running out of time, it’s not just the retail parts of the banks that are under threat, is it? There are now all sorts of threats to their investment activity.
Speaker A: I think that’s disintermediation. I think that there’s an awful lot that the algorithm can do that investment bankers used to be able to do. Research from Oxford University looked at the different jobs that are going to be disrupted by technology, and investment banking was one of them.
Speaker B: Okay, well, that’s more bad news for the bankers. Michael Baxter, author of the book I Disrupted, thank you very much. You’re listening to Password on Resonance FM with me, Peter Warren, and I’m afraid If you’ve just tuned in, you’ve missed it because that’s all for this week. Password is brought to you by Future Intelligence. You can find more about the world of technology on our website, futureintelligence.co.uk. Password is an Angel Media production.
Speaker A: Goodbye. This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.
