Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassWord – 18th November 2015

PassWord – 18th November 2015

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker B: Hello and welcome to Password on Resonance FM with me, Peter Warren. The show that takes you behind the headlines of our high-tech world. In today’s programme, 3 leading experts provide the background to Chancellor George Osborne’s announcement of a doubling of the cyber security budget. Why blockchain, the technology behind Bitcoin, is leaving the banks behind, caught in a muddle of old technology. And the emergence of the broadband van, high-speed connectivity on 4-wheelers wheels that can outstrip that icon of the phone age, the white van man. But first, this week the Chancellor has announced that the cybersecurity budget will leap to £1.9 billion in what he says is a response to the threat from Islamic cyber terrorists to our critical national infrastructure. That’s the computer-controlled systems that keep our world running: power stations, transport networks, gas and electricity and the communication companies. The Chancellor has said that the extra funding will be used to create a new cybersecurity centre at GCHQ, the UK surveillance headquarters at Cheltenham, fund another 1,900 intelligence posts and help to head off cyber attacks that have risen from 100 a month last year to 200 a month in 2015. Commodore Patrick Tyrrell, the first man in the UK Department of Defence to warn about the risks of cyber attacks in 1996 and an intelligence expert expert gives us his take on the situation.

Speaker C: There is no doubt that it has been technically shown that you can take, you know, if you want to, you can take charge of cars, you can take charge of other systems. You could certainly take charge of signaling systems on a railway or perhaps even in air traffic control. But it hasn’t happened yet. That’s not to say it won’t happen at some point.

Speaker D: Right. Now, I mean, is the other thing that has to be done here to actually attack cybercrime? Because cybercrime appears to be providing this wonderfully rich base for all of these bad things to occur, doesn’t it?

Speaker C: Oh, well, that’s always the way, somebody cybercrime becomes the objet du jour. It’s the thing which, in looking for defense dollars, GCHQ knows it’s on to a winner because it can frighten ministers quite considerably. And it holds up the sort of prize of intelligence and rapid intelligence to understand what’s going on in the criminal mind.

Speaker D: But cybercrime does allow the terrorists something. It allows them to potentially get in there and use it as an opportunity to raise money. It also potentially provides them with talent. They could actually go and, according to the government, there is the potential to hire hackers or to buy malware that can be used in an attack. Is that something that you would worry about?

Speaker C: Oh yes. I mean, I think the longer we get the technically easier it becomes because it becomes routine technology, if you like. There are a lot more people coming up and getting involved in these things and becoming skilled at it. And whether they go on the dark side or stay on the right side depends upon what’s on offer. Now, ISIS has huge a cash pile that it can spend on encouraging people to make use of these technologies. I mean, at the moment, technologies are mainly used by the big criminal gangs. They’re the ones who are doing this, the hacking, taking the results of big hacks, paying the people who’ve done the hacking, and then using them for financial scamming. But at some point ISIS or others like it will start using that for their own ends. I mean, it’s inevitable, I think.

Speaker D: And is one of the other things that they would be looking to do to actually radicalize people who were working, say, within the IT or the cybersecurity sector within the UK, to find and identify people who may have an empathy with them and their ideals?

Speaker C: Well, yes. I mean, I think that there are two ways, several ways you can do it. The first one is to radicalize people who can be used for hacking. The second thing is to pay them lots of money, and they will use all of these activities to try to persuade people to do what they want to do.

Speaker D: I mean, it has been said that paying them a lot of money, that they would have to pay them a significantly large amount of money because obviously the intelligence agencies will not look very favorably at all on anybody who is helping an organization like ISIS and could perhaps terminate you with extreme prejudice for having done so.

Speaker C: Well, the laborer is worth their hire, as it were. People are going to set their own levels of remuneration. The thing about ISIS is they’ve got lots of money and they don’t have to justify to anyone how they use it.

Speaker B: Commodore Patrick Tyrrell on the capability of ISIS to wage a cyber war. And apparently, if we are to prevent this, we will need to train a huge amount of new people in this new boom sector of the internet. Something that, according to Charles White, head of the leading computer security company IRM, we should really have started working on a while ago.

Speaker E: Skill shortage is, I mean, acute. I mean, it really is acute. I, you know, the government, to be fair, has— well, no, it’s not fair. The government simply has not put the money, time, and effort behind getting suitably skilled people into the cybersecurity industry. Representing IRM, one of the larger or largest consultancies out there, I know that salary costs are extremely high for well-skilled and talented people, and the shortage of skilled talent is acute. And that makes it very, very hard for us to deal with the ever-ending people knocking at the door that want us to go and help them because there is only so much bandwidth that we have. So that has to be addressed. And so, you know, I welcome more money into cyber and welcome the fact that that is going into bringing talent into this place and this market. But putting another n number of 100 million into creating more university courses or more apprenticeship courses is fine, but it will not deal with the acute problem that we have today. And the problem that we have exists today. The time for putting time and money into students coming out of the education system in 3 years’ time is sort of been gone and over. We need the people now.

Speaker B: Okay, so what are the ramifications of that, Charlie?

Speaker D: Does that mean that the average small and medium-sized business, the average person on the street, that they’re not being protected by the government.

Speaker B: Surely, surely they should be protected by GCHQ.

Speaker E: No, I don’t think they should. That’s not the purpose of GCHQ. GCHQ is there as part of our intelligence services to look after the well-being of the population of the UK. It is absolutely the responsibility of the small to medium-sized enterprise to understand the value of its data and determine, you know, how much risk it’s prepared to put that data out and then pay the consequences in the event that that data is stolen or lost. It is not, I’m afraid, in my opinion, the job of the intelligence services to come to the rescue of the corporate when it’s lost all the data. TalkTalk being a great example. At what point did it ever become GCHQ’s problem that TalkTalk spent very little when it came to protecting their information assets and the data that their customers gave them on trust. They couldn’t be bothered to look after it, and so the net result is, ah, there. It shouldn’t be anybody else. It certainly shouldn’t be the taxpayers.

Speaker D: So does that mean then that you think that everybody’s on their own, that it’s up to them to start protecting themselves?

Speaker E: I think that has always been the case, but I think, again, government has done a lot by talking to a number of the FTSE chairman and chief executives, talking to non-executives of big corporates and getting them to understand that they need to take cyber seriously. The government has asked non-executives of big corporates to sort of give a state of the nation on, within your organization, do you have the following basic cybersecurity hygiene things going on. They’ve taken the results from that, aggregated them, and sent them out as a report to senior executives of corporates to say, look, this is where UK PLC is, and it’s not necessarily good enough. You need to take this more seriously. You need to ask the following questions of your people within your organization, and you need to treat cybersecurity more seriously. So I think there’s been an education piece with the big corporates to get them to understand they have to step up to the plate more. I think, however, for many big corporates, they don’t necessarily see the issue until, of course, they have to look at the unedifying sight of a fellow chief exec struggling to communicate why they didn’t invest in cybersecurity when they’re splattered across the BBC.

Speaker B: Charles Wyatt of the Computer Security IRM speaking to us from Cheltenham on why cybersecurity is now everyone’s business. Now, still on the theme of George Osborne’s announcement in the wake of the Paris terrorist outrage, we ask Professor Andrew Jones, author of Global Information Warfare, an expert on computer forensics and the Middle East, about the threat and how viable the Chancellor’s claims are that we can hunt down the perpetrators and bring them to book.

Speaker F: There’s two options. You can take aggressive online action, or you can take aggressive other action. I would imagine it’s the other action that he’s talking about.

Speaker D: And when you say other action, what does that mean?

Speaker F: Well, it’s, you know, the physical pursuit of them, the finding them and dealing with them.

Speaker D: Right. So would that be online or would that, that be trying to sort of find out who it is physically and then administer some sort of retribution?

Speaker F: I can only imagine it’s the physical locating them and following due process.

Speaker D: Right. Because I mean, one of the problems that has been sort of mentioned so many times in this area of cyber is to actually find out who did something is very, very difficult.

Speaker F: Yes, we’ve seen it time and time again. You know, it’s, it’s not necessarily the obvious. And if they’re any good, it certainly won’t be. But, you know, taking them offline briefly is all, all you’re going to achieve. In the sort of electronic environment.

Speaker D: Okay, now just to go on to very briefly, um, capability. Uh, obviously you know ever such a lot about the area of the Middle East. You, you’ve actually been out there and, and you, you have sort of, uh, you know a lot of the people who are involved in, um, cyber security in the area. Does ISIS have capability?

Speaker F: It’s— they’ve shown that they have good understanding of how the systems work through their use of the internet for publicity, you know, using it to push their story and put their message out. But beyond that, we haven’t seen a lot of evidence of their capability elsewhere.

Speaker D: So insofar as an attack on the critical national infrastructure, we have not as yet seen that.

Speaker F: Not to my knowledge, no. We see plenty of attempts on the critical national infrastructure, but most of those are being attributed to other nation states, shall we say.

Speaker D: Right now, how likely is it that there would be an association between those other nation states and an organization like ISIS?

Speaker F: I can only think of a couple that may wish to associate or be interested in associating that have any sort of capability.

Speaker A: Right.

Speaker D: So, I mean, cyberterrorism, it’s one of those terms that has been bandied around a lot in the last 3 years. There hasn’t actually been a lot of evidence to suggest that it’s been going on, bar, as you’ve mentioned, for the recruitment and radicalization of people via extremist websites.

Speaker F: Yeah, you know, cyberterrorism is a lovely journalistic term. Do terrorists use the internet? Absolutely. For all sorts of things. Have they mounted any significant attacks? Not that I’m aware of.

Speaker D: Okay, so, but the announcement by the Chancellor, it’s good news if they’re targeting cybercrime because the cybercrime itself is the element of instability, isn’t it? This is the area that could be used by ISIS if they wanted to. It’s the area where they could get involved in fundraising. It’s the area where they might be able to find guns for hire.

Speaker F: Yeah, absolutely. I mean, this is not the use of the internet for terrorism, but use by the internet of terrorists.

Speaker D: So that would tend to be a little more likely at the moment. Although that said, the internet does allow people to quite rapidly upskill to use one of those horrible industry terms, you can actually learn quite quickly how to do things.

Speaker F: Yeah, and no denying that. But what you come to is, you know, can you mount a sustained attack? And that takes resource and infrastructure.

Speaker D: Although, I mean, one of the things that everybody has mentioned about ISIS is that they do have quite considerable resources.

Speaker F: They certainly aren’t short of funding, but whether they can achieve a concerted cyberattack— and I’m not talking about it— undoubtedly they could raise a short-term attack. Could they do significant damage to the critical infrastructure? I don’t think they could at the moment.

Speaker B: Okay.

Speaker D: But Perhaps one of the other risks—

Speaker G: the banks have got an issue with legacy software. What is that issue?

Speaker H: The problem with legacy is that you can’t surely do it with open-source software. Many banks might think of IT in the 1960s, ’70s, or even as late as the 1980s using custom-designed solutions. And as time went by, Very few banks, probably none, actually replaced these core systems in order to update them. Their approach was simply to build extra layers of software on top of the existing systems.

Speaker G: And they also got very, very worried about their data.

Speaker H: Absolutely data retention is freaking essential for a bank. They have a tendency to be extremely conservative anyway. Data loss for a bank is completely and utterly disastrous. So from their point of view, it makes more sense, or has made more sense, to remain running on these legacy systems simply because they’re stable and not present the possibility of data loss.

Speaker G: And that’s given them a big problem, hasn’t it? I mean, that’s given them a big problem in the past. We saw with the NatWest example, actually, of, you know, a bank collapsing because of its systems and the fact that they were a bit old. That’s hampering them now, isn’t it? Because they want to be a lot more footloose and they can’t because of these old systems.

Speaker H: Yes, they’re basically working with one hand tied behind their back. They want to try and take that into the future, but the amount of work that’s involved in simply scrapping a legacy system and starting something new is going to be huge. And much of the knowledge to actually work with the older layers of these systems, for example, the code that dates back from the ’60s or ’70s, much of that knowledge is gone. Documentation was patchy in the first place. And the people who actually knew and understand these systems have all retired by now.

Speaker G: So how does blockchain then? I mean, blockchain’s been held up as this ultimate panacea to everything. How does that work? How’s that gonna make everything better?

Speaker H: I’m not sure if the blockchain is the ultimate panacea for everything, but it is certainly a way to simplify a lot of things. You can look at blockchain technology as allowing you to create a complete ledger system that is completely secure, completely stable, and does not rely on placing trust in any third party. I mean, Bitcoin is at the moment the most well-known blockchain technology, but what banks can actually do is to transfer some of their systems or some of their currency onto the blockchain gradually and build up the blockchain systems from there, taking over from the legacy systems. So you’ll have two systems running roughly at the same time. But the blockchain allows a much flatter architecture than the current legacy systems. You have one layer of software running instead of 4, 5, 6, or 7. Right.

Speaker G: So that’s, that’s the, that’s the main advantage then of NXT.

Speaker H: NXT, what do you do?

Speaker G: What are you? Are you just somebody who has this blockchain technology and you’re rolling it out, or?

Speaker H: You can see NXT as being an evolution of the Bitcoin core technology. Bitcoin is really the beta system for blockchain technology, the very first pioneer. They’ve been running for approximately 7 years now. Nexxt was set up 2 years ago in order to evolve cryptocurrency and digital currencies beyond the simple functionality of Bitcoin. Bitcoin allows you basically to create, store, and transfer electronic tokens. The market or whoever can then assign a value to these tokens. Nxt has built on this basic storage, transfer, and creation functionality to allow you to include extra data inside the blockchain, to, for example, write contracts to the blockchain, to provide information attached to a currency transfer that moves across the blockchain.

Speaker G: So very quickly then, Dave, does this mean that the bank is dead? I mean, it seems as though you can put all of this information in there, you can get the single user profile, um, you know, the banks have been wanting to do that for a long time. They could vanish, couldn’t they? Could evaporate.

Speaker H: Yes, there are two ways this scenario could go, and there are two major viewpoints within the cryptocurrency digital currency world. Either there’s going to be a massive revolution which will allow people to have complete control over their entire financial life from behind their own computer using the blockchain, and in that case banks will effectively disappear. Or the second scenario is that banks move into using blockchain technology, adapt, move with the times, and and build on blockchain technology to provide services to their customers.

Speaker B: The blockchain technology that could be putting the banks’ heads on the block, and Dave Pearce of NXT, one of its pioneers, who points out that even those irritating items like the banker’s letter become much, much cheaper with the blockchain. Now, a slight chink of light in the glowering technological clouds: the broadband van. In a bid to get over the problems caused by poor bandwidth, Fujitsu, which took over ICL, the former flagship British computer company, has created what could only be a perfectly British anachronistic solution to a problem that shouldn’t be there. They’ve come up with the superfast broadband van, a recognition of the fact that you have to have bandwidth now wherever you are, from an inner-city building site to a civil engineering project over a river. Their van’s got broadband, RFID, and can even control its driver. What more can you want? Here’s Graham Wright of Fujitsu on the thinking behind the van. Graham Wright on the ultimate van. He knows where it is, he knows where it’s going, he knows what’s in it, and you can put it in contact with whoever you want. You’re listening to Password on Resonance FM, and if you’ve just joined us, then I’m afraid you’ve missed it, but we’ll be back next week. Password is brought to you by Future Intelligence. And if you want to find out more about the stories in today’s program, log on to the website at www.futureintelligence.co.uk. Password is an Angel Media production. Thanks for listening. Goodbye.

Speaker A: This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00