Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassWord – 2nd December 2015

PassWord – 2nd December 2015

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker B: Hello and welcome to Password on Resonance FM with me, Peter Warren. The technology programme that digs into our digital world. In today’s show, we bring you an exclusive insight into the terrorist attacks in Paris and reveal that the French authorities were aware that an attack was imminent. And Michael Drury, the architect of the UK’s first surveillance legislation, cautions against knee-jerk reactions following the Paris outrage. In other news, the speed that the high-tech world is moving at. And why cybersecurity is now center stage. We bring you details of the world’s first robot iron mine controlled by NASA satellites. And the robots will soon be looking after their own. From the Berlin Global Cyber Leaders Conference, we bring you details of the intelligent robot security systems that are now sitting in company networks and looking for the criminals that soon might also be robots themselves. Themselves. It’s a high-tech world where everything is being turned upside down. According to the man tasked with protecting the Indian Stock Exchange, criminal gangs flush with looted cash are now headhunting for the high-tech talent that they need to take on the robots. It’s a world where we appear to be increasingly uncomfortable, a position underlined by the sad news revealed during an Oxford inquest that Jenny Fry, a young schoolgirl, committed suicide because she said she was being adversely affected by the signals given off by Wi-Fi routers. But first, Bruno Caruanton, the head of security from the Swiss Canton of Jura, tells us why the French government scrambled to try to get legislation onto the statute book immediately before the terrorist attacks. The Caruanton who is an honorary French consul, says the French had been monitoring but did not have enough evidence to take action on.

Speaker C: The problem was also before the attacks. In the UK, we had also the issue with the government trying to prevent encryption and trying to store more and more data for surveillance. The problem is that we see by experience that it doesn’t help a lot. Storing information Digital information of how citizens behave is maybe interesting for some people, but I guess for intelligence it’s not useful for two reasons. Because, well, criminals and terrorists know quite well that they can escape this by, well, using traditional means like seeing people in meetings, for example, without using phones or throwing them in the trash after. So it’s useless to collect everything. The second point is that when states are trying to store information to prevent criminals, they store a huge amount of information and they are not able yet to handle that. So it takes a lot of— a long time and money also to try to prevent breaches using that. And the best way is still human intelligence.

Speaker D: The human intelligence, it’s been revealed since the attacks, actually knew that these people were acting suspiciously. Why then couldn’t they have used that intelligence to prevent the attacks?

Speaker C: I guess France didn’t realize it would be possible to make those attacks like this way. The problem is that if you have human intelligence, they are able to do surveillance. They cannot act without strong evidence, and that maybe was the point.

Speaker D: So in that sense, the uses of surveillance might be limited.

Speaker C: Yes, I guess so. Surveillance, I guess, is not the solution.

Speaker D: And what’s your opinion of the new legislation that’s now being brought in in France?

Speaker C: I guess it was made too quickly because it was just, everything’s on fire, we have to act. And while new regulations about logging everything is not really something that we should have for the long term.

Speaker D: What do you think is the long-term solution?

Speaker C: Long term would be human intelligence again. That’s the best solution, I guess, because, well, when you know people, when you know the networks, social environment, that, that helps a lot. And also transparency for citizens.

Speaker B: Bruno Kerouanton on why the French authorities were rushing legislation through to deal with terrorism even before the coordinated killings in Paris. Now, Michael Drury of the law firm Burton Copeland and the former Director of Legal Affairs for GCHQ who drafted the Regulation of Investigatory Powers Act tells us why he thinks that we should be very careful about copying the French, and that if we are going to change the rules on surveillance, we should make sure that they work in everyone’s interests.

Speaker E: I think The answer is that in reality the position hasn’t changed. The requirements for surveillance, it seems to me, cannot be dictated by one terrible event or a lack of a terrible event. So the argument in a sense is, or rather should be, unaffected by that. Whether or not Harris could have been detected, we don’t know. Certainly There appears to have been lots of information available, but it’s too early to comment, and I’m sure that the French authorities will have a post-mortem on what has happened after the event. But does it change the arguments? No. Does it change the privacy arguments? No. And is there a danger that’s certain that it will be used in a way to justify what would otherwise be regarded as unjustifiable? There is that danger, although it’s interesting to see in the US the dynamic between John Brennan of the CIA saying that this justifies more powers and how the present capability has been affected by Snowden revelations, immediately met with a response from an editorial in The New York Times talking about the wrongness of that position and that the debate for privacy is separate and shouldn’t be affected by emotional events. And I think that in reality has to be right. Terrible these events are.

Speaker B: I mean, that’s the thing, isn’t it? Because inevitably people are going to focus in on the fact that it’s just emerged today, for example, that the Iraqi government and the Syrian government had both alerted the authorities to the fact that this was going to occur, that there seems to have been other information that was available from within France and within Brussels about this incident. So a lot of the people who are the critics of surveillance will say Hang on, you can’t actually do a decent job with the information you’ve got available, so why on earth do you need more information?

Speaker E: One would need to know, um, what the review of what was available and what was not available and how it could have been used, which I’m sure will happen maybe within the French system, possibly in the public domain, we don’t yet know, will reflect on that. Having said that, of course, the danger that one has in relation to the danger one has is that in the aftermath of an event like this, there is a blame culture such that I’m— such that it’s— one needs to be very careful in speculation. So, the answer is it doesn’t really bear upon me on the facts as they’ve happened. What is clear, that there is a growing threat from encrypted communications. What is clear is that those who would seek to do harm in the way we’ve seen in Paris are moving to communications which are more difficult to follow, and there does need to be a consideration of that. How far are we prepared to sacrifice the benefits of encryption? How far are we prepared to sacrifice the benefits of freedom to the web against that debate which will clearly take place in the context of the Investigatory Powers Bill in Britain, certainly.

Speaker B: Michael Drury of the lawyers Burton Copeland. Now, one of those truly remarkable stories that are milestones of development. In Brazil, the mining company Vale is about to charge up the world’s first robot mine to bring iron out of the ground via satellite control. It’s the stuff of science fiction, now turned into reality by the headlong rush of technology. Here’s Cesar Oliveira speaking to us in Berlin at the Global Cyber Leaders Conference on why he’s confident that the Brazilian company Veil will be in complete control of the system.

Speaker F: We are very, very excited with this project because we need to do, you know, the innovations to make our lives better. Actually to keep the people safer. We’re going to take a lot of people, you know, from the daily risks they face over the tracks. And so it’s, you know, getting better the whole process, which is one of our values, you know, to be innovative, to do innovations, do the things better every day.

Speaker D: Can you just talk me through how it will work, what the changes will be from mining with humans and trucks and to the new system?

Speaker F: We’re not using the trucks anymore, so we have moving machines, the conveyor belts. They will keep— we’ll have very complex machines that are going to move the conveyor belts as the machine The collector moves together. It’s a very innovative one, moving together. And then we use lots of them in order to take the iron ore out and store there in a place, you know, in order to go to the railways and go to the ships and then our customers.

Speaker D: And how would they be controlled?

Speaker F: They are controlled by satellites, very well complex systems, satellite systems, actually in the world, one of the most complex in the world, satellites, together with involvement with NASA as well, all the main actually vendors in the world in order to make this project to happen. Because that’s just one machine, you know, lots of machines being built. So that was— that’s the way we are very excited to, to start this project next year that we’re going to be very revolutionary.

Speaker B: Cesar Oliveira on the world’s first robot iron mine. And robots are now not only delving into the bowels of the earth, they have become entrenched in our communication networks in an attempt to hunt down the hackers that take over our computer systems to use them anything from Bitcoin mining to botnets. They’re the massive computer networks that can bring down servers by battering them with millions of simultaneous messages. The makers of Darktrace use a sophisticated intelligent system that takes huge amounts of data and uses that to learn what your network should be doing, and then alerts you when someone or something is behaving badly and shows you exactly what is happening and what is doing it. Here’s Dave Palmer, a mathematician and former intelligence agent, on how the system works and why we shouldn’t be scared of it.

Speaker D: It’s not very good at finding people that are entering fraudulent tax claims or tricking gambling systems. And really, to your use case, it’s a really different type of science that’s good at finding relationships where we superimpose what a bad guy or a fraudulent person or a tax avoider looks like, or indeed a terrorist. So no, quite a different family of science, and it’s much more— there are other companies out there investing in that sort of science, but not really us.

Speaker B: Okay, so, so you’re not looking for actual patterns of behavior, you’re just looking for a pattern of behavior that’s anomalous to the the way that somebody normally behaves. That’s right.

Speaker D: It really is about learning and then looking for differences. That’s the absolute crux of all of it. And what’s— what the tricky bit is, is finding the best learning approach for all the diverse things that we find in businesses, which is why we use such a big variety of the types of mathematics and then have to pick at the last possible moment which ones we think are the best.

Speaker B: OK. So is this a system that’s going to force conformity of movement?

Speaker D: I certainly think not. So I think this is about embracing that businesses are massively diverse, and to a large degree, job titles becoming meaningless. Pick 5 people in a modern digital organisation and see if they— each with the same job title— and see if they use their iPhone and their laptop exactly the same way. I don’t think so. I don’t think even near-identical robots on a factory floor are doing exactly the the same things as each other. Each of them has a unique contribution to make, and that’s why the learning part is so important. If we wanted conformity, we’d just say, hey, everyone is allowed to look at Facebook, BBC News, and Google Search, and no one’s to look at anything else. But businesses aren’t going to accept that stifling of creativity. It certainly isn’t consistent with the knowledge worker economy. No, we’ve got to embrace difference. We’ve got to accept that Everyone and everything is going to be pretty unique in our businesses, and we’ve got to be able to deal with that, and that’s what learning is all about.

Speaker B: So you’re even going to be able to pick up a malfunctioning robot on all of this, aren’t you?

Speaker D: Well, we’ve seen a bit of that, but one of my favourite stories is I’m pretty confident, having tried it in the past, that if I gave you my laptop now with all my passwords entered in, fully logged in, and walked off, that we’d be able to pick up that you were using my laptop in a way that is inconsistent with how I use it without having to do anything obvious like getting passwords wrong or trying to talk to systems that don’t exist.

Speaker B: How does that work then? How would you be able to know that I’m using your laptop?

Speaker D: So Darktrace wouldn’t know that it was you, Peter, touching my device, but what it would say is this doesn’t feel like Dave’s using his device anymore. We have an understanding of what information Dave uses and at what rate do I interact with that and all the different systems. And what happens in most organizations is people have much broader permissions to access stuff than they actually use, and maybe they have different preferences. So a great example would be I’m allowed to see the source code in our company of the software we develop, but you’d never catch me using my phone to look at the source code on its tiny screen. Life’s simply too short. And so if you grab my laptop and start using it, you need to use it in a way that is consistent with how I use it. Otherwise, we’d be able to spot that possibly there’s a problem there, and I’d expect perhaps a phone call from, from our security guys to say, Dave, we think you’re using your laptop unusually. Have you got it, or is it— have you perhaps left it somewhere, or is perhaps there’s some malicious software on it? So looking for those unknowns and they really can give you insight into attacks you otherwise wouldn’t have a way of being able to look for.

Speaker B: But interestingly, one of the things that we often see in films is that you will actually capture the loop of, say, a video of what’s going on and play that loop back. Couldn’t I then capture your behaviour and play a day in your life back through the system and then actually see a lot of the information that you routinely pull up and then therefore be able to extrapolate something from that.

Speaker D: If we get to a point where cyber attacks are diminished to all you can see is the information that a single person would routinely access within their working day, then I think we’ve achieved a massive victory. But you’re absolutely right, if there are cases where you will be able to just pretend to be someone and you will just be— your ability to do an attack will be limited to the normal aperture of information that that person has. But I would call that a victory. That isn’t stealing 4.5 million kids’ passwords and photos from their toys or 30 million credit card details from, you know, a major retailer or something.

Speaker B: Dave Palmer of the intelligent self-learning security system Darktrace. No, there’s no need to pinch yourself. This new technology world is now the new reality. And to quote from Shakespeare’s Macbeth, “Nothing is but what is not.” In this new topsy-turvy techno-future, the criminals laden with millions of pounds from their crimes are also determined not to be left behind. According to Narayan Nilakanthan, the head of IT risk and compliance at the Indian Stock Exchange, they are now responding to the computer skills shortage by headhunting for the people they want for a career in crime.

Speaker A: Of course it’s a big issue, it’s a huge issue. And with businesses going digital, the issue is just going to grow by leaps and bounds, and organizations are going to get hit all over the place if they are not going to get ready for tackling whatever is going to come at them.

Speaker B: I mean, it’s interesting, isn’t it? The UK government suddenly seems to have woken up to all of this, but it’s taken a long time, hasn’t it? I mean, it’s, you know, This has been going on at significant levels for well over 10 years.

Speaker A: Yes, I agree to that. But the fact is that probably governments have woken up a little late because I think in some form they were dealing with cybersecurity as part of defense, and probably it’s coming into mainstream lately. But I think BFSI or financial services sector was probably the first from a business standpoint to really look at it. And it’s only when customers or citizens started getting impacted is when probably governments woke up to it and are being more vocal about it to protect privacy and guard the citizens from getting impacted by cyber attacks. One other important thing that has happened is the advent of Internet of Things. So it has sort of bridged the gap between the virtual and the physical, and suddenly the governments have started getting concerned about citizens’ safety, which is a very important thing and needs to be addressed.

Speaker B: I mean, you know, you say people have been impacted by this. Every week now I see a hack come across my desk, and, you know, I mean, literally, as I came down this morning, it said 5 million people from a toy manufacturer, the records of that, the had been taken, records of small children. But nobody gets hurt by any of this, do they? I mean, all we see is we— records are lost, that’s it.

Speaker A: Yeah, but records are lost, uh, but the reality is where do these records go? So there’s a whole dark web down there, deep down, which is not accessible to the common person, where these records are up for sale at peanuts. And, uh, these, these records can be used to compromise so many other things, so that this can be just the first step.. And when the attackers get hold of this information, then they use it to further launch greater attacks and finally get hold of some kind of financial information of those citizens who have no clue what is happening. And suddenly they will get a message or they see that their bank account has been debited for whatever value is there. And then that is when things start falling into place. How did the whole thing happen? So probably record stealing should not be looked at in isolation. Look at the big picture and see eventually what it is going to lead to.

Speaker B: I see. So what you’re saying is that all of that information is taken out into the dark web and then it’s collated, and that’s essentially creating a soft underbelly that’s there to attack us at any point that somebody wants to.

Speaker A: Yes, it’s actually a soft underbelly, and you wouldn’t imagine, um, it sells for really peanuts, and it’s very organized. So it’s like an organized cybercrime. Out there, and people have got really good software which mines through all this information. So, you can actually have search engines on the dark web and search for information. Let us say you want credit cards of this much value in, let us say, in the UK or in Germany or in India or whatever, and you get really targeted information, and then you just make some payment and the number is yours.

Speaker B: Yeah, but I mean, these are just criminals, aren’t they? They can’t be as good as the people who are fighting against them? I mean, you’re the real professionals, aren’t you?

Speaker A: We are the real professionals, but I think the only big area we fail is in collaboration. Because as corporates, we have our own corporate boundaries which prevent us from sharing information with each other, which can help us be better prepared or leverage those attacks or those breaches which other organizations have faced, learn from them. And be more prepared. Whereas in the underworld, it’s all about collaboration, and that’s how it works so well. So you can be in Russia, you can be anywhere, and you just collaborate on the dark web, and it’s one big force against so many corporates, and still they keep winning.

Speaker B: And one of the things, just finally, I mean, people are suggesting here at this conference that this has been done in such an organized way that it’s actually a criminal business, and that people have actually got job vacancies. Is that so?

Speaker A: So just to relate to a think tank session that we had on the first day, which was very interesting, which talked about bounty hunters. So bounty hunters is a way of creating job vacancies to identify vulnerabilities in whatever systems we have. So there is a very fine line there between legit bounty hunters and bounty hunters with some kind of malified intentions. So yes, it’s creating a lot of jobs. And I would say it’s a very individual perspective on what the person really wants to do, whether he wants to side with the good or with the bad. But the options are open there.

Speaker B: So the criminals have job vacancies too? Of course. Narayan Neelakantan from the Indian Stock Exchange on the criminals looking for high-tech talent. Now, finally, to celebrate the fact that Resonance FM has now gone digital, and can be heard on the beach in Brighton and right across South East England, we bring you the sound of Brighton University’s innovative Digital Arts degree. It’s slow to all our new listeners, and goodbye for now. But you can find out more about technology in our society at our website, Future Intelligence. And I’ll be back next week with another edition of Password. Thanks for listening.

Speaker A: It’s This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00