Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassWord – 10th February 2016

PassWord – 10th February 2016

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker B: Hello and welcome to Password on Resonance FM in the station’s fundraising month. Over the next couple of programs, we’re going to be offering up a range of goodies, books, and experiences from the world of the high tech as part of an auction to help support the station that The Independent called a glorious experiment that everyone in the country deserves to hear. And of course they can, because Resonance FM is available via the web and via DAB. But all of that costs money, which is why we are appealing to you to dig deep into your pockets to fund the station that The Telegraph says puts the BBC and its vast budgets to shame. Now, in this week’s show On the 2nd of Feb, the EU and the US signed an agreement that has created the Digital Shield, an attempt to deal with the fallout from the Edward Snowden affair. And, still on the topic of Snowden, the powerful parliamentary Select Committee on Science and Technology has come out against the controversial Data Retention and Investigatory Powers Act, brought in to legitimise UK government surveillance, exposed by Snowden. Snowden just will not go away. We also find out about a new program to make the EU the privacy centre of the world. And how counterintuitive is this? European hackers want to be paid to fix our computer security problems. For me, it makes perfect sense, but to many in the technology community, it’s the equivalent of asking the criminals to make the prisons. We speak to a head hacker. Finally, a little relief. The Danish company that is looking to combat the dark side of the fashion industry by letting its clothes tell their story. First, the Digital Shield. Not the latest Star Wars film, but the name given to the new agreement hammered out on February 2nd by the US and Europe so that data can still flow between the two economic zones to replace the Safe Harbor agreement that collapsed in the wake of the Snowden whistleblower revelations about NSA and UK GCHQ spying. Stuart Room is the lawyer who heads up accountancy giant PwC’s privacy department. I asked him what has changed with this announcement.

Speaker C: What we’re seeing is an announcement of the EU-US Privacy Shield. So that’s the label. So Safe Harbor is now the Privacy Shield. So we’ve got a title for it. It’s simply saying that political agreement has been reached between the EU and the US about 3 elements. There will be strong obligations being placed on entities handling European data while it’s in the US. So US are going to have— US entities will have more obligations with robust enforcement. There’s going to be safeguards and transparency obligations about how the US government accesses data, and European citizens will have better rights of redress in the US. So, you know, very, very, very, very high level. It plays to, in a headline sense, the concerns of the European Court of Justice. But the next thing that will have to happen is this privacy shield will have to be substantiated and fleshed out. So the detail will have to be created. It will have to be put into a European Commission decision. If Europe then decides that this is good enough, then it will come into force and that will replace Safe Harbor, the privacy shield. So I don’t perceive there to be an urgent enforcement or litigation risk.

Speaker D: So it’s given us— well, it’s given the clarity and it’s given that stability that essentially business is looking for.

Speaker C: The press release certainly points in the right direction, and then we’ll need to see the detail because presumably what will happen once the Commission decision has been drafted, we’ve not seen the paperwork yet, is it will then be dissected by everyone who’s interested in it from privacy advocates through to politicians to lawmakers, and there’ll be an array of criticism or support. So, on the headlines, it plays to the issues. So, I think that we— entities will not be panicking tonight. I hope they won’t. And I certainly hope that professional organizations who are seeking clarity in the economy will be pleased with this outcome.

Speaker D: Some observers in the US are actually saying that the European Commission should change its data protection regulations and replace the adequacy standard with the duty of care provision. What does that mean?

Speaker C: My interpretation of the law is that this creates a duty of care. So, it always has. The data protection regime creates a duty of care. So, I think potentially that there is— it might be a distinction without a difference between the two points. If you’re looking at what it’s really going at in a functional sense, I think it’s this operational adequacy idea. The duty of care would say, prove that you are good. Don’t judge me by the country I am in. So, if there is a difference between those two points, the adequacy decision issue says, is America or another country good from a European law perspective, whereas a duty of care would be saying, ‘Oh, don’t really worry about the country I’m in, worry about me.’ And that’s what I’m saying is the most important thing, is the entity, can the entity prove that this is good?

Speaker D: One of the points that has been made is that the big problem with the way that businesses view cybersecurity, for example, or view the protection of people’s data, is that they see it as a risk issue. They see it as what will it cost me if I lose this information, and that duty of care view of people’s data is the one that really we should be pushing. And that’s what people are saying now, is that businesses should have it imposed upon them to take much, much more care. In a sense, that’s perhaps why the European Union has put in place the changes to data protection rules to say that, okay, if you want to make it a risk issue, then we’ll say 4% of global turnover and €100 million, fine.

Speaker C: My position is that the law says that the duty of care exists, and if the duty of care is broken, then there is legal risk. The difficulty is about how people gain access to justice to enable them to pursue their remedies, if they have any. Judicial redress is very, very expensive. It’s a hard thing to get, and it’s certainly much more complicated when you’re dealing with this on an international stage.

Speaker B: Stuart Room, head of PwC’s privacy section. You could say the room at the top. Now DRIPA, the bill brought in by David Cameron that lets the intelligence agencies store all of our digital exchanges so that they can home in on any particular conversation to find out who it was between and when, even if it is on social media. It is also the legislation that is seeking to control the use of encryption. But it has run into a lot of trouble. The EU courts are currently considering whether it is lawful, and now the Science and Technology Select Committee has said that it will cripple the UK technology industry. I asked Andrew Kernaghan, a spokesman for the Internet Service Providers Association, what the problem is for the technology industry.

Speaker A: It does need more openness and transparency. I think people need to be aware of exactly what powers are brought in and what they actually mean in practice. The bill goes some way in addressing that. It does talk of greater safeguards and a new investigatory powers commissioner, but we think it needs to go further. I think privacy is nowadays, as you mentioned, it’s a priority for people. It’s a business competitive issue. People want to be clear that their data isn’t being misused. So that have been echoed throughout Europe, although it’s fair to say perhaps in the UK, culturally speaking, these issues aren’t, whilst they’re front page news, they’re not exactly the biggest political issues of the day as perhaps they are in other European countries.

Speaker D: [Speaker:DAVID] They aren’t yet, but I mean yesterday I interviewed somebody who’s part of a European initiative. And that EU initiative is to create a privacy and security safe haven in Europe. And these are the sorts of measures that go particularly, well, almost counter to that. If you want to encourage businesses to come to Europe because you can offer to protect their their data, then obviously it’s working against that if you know that there is a security establishment which is basically running roughshod through data.

Speaker A: Yeah, and that’s why it’s important the points about encryption which are in the legislation, that the removal of electronic protection are actually properly scrutinized and the government is clear on what it’s asking industry to do because as you know there was a big discussion around ending end-to-end encryption. Obviously we’re not 100% accurate at the time and the legislation has sort of borne that out. But it’s still unclear exactly what’s going to be asked of industry. And we just want to make sure that it’s clear that the legislative framework works for members and is understood by Parliament and also the general population so that they do have trust in online services, which is effectively what the online economy is based on.

Speaker D: Tina, do you not think that there are also two other issues here? One of these issues appears to be that the legislators don’t really understand technology. Do you think that that needs to be changed?

Speaker A: Yeah, and actually I think it perceives itself as trying to improve the level of debate around some of these issues so that technology is better understood, which is why we welcome the Science and Tech Committee’s report, because it will also be looking at the technology aspects of what this could mean for the industry and whether it’s technically feasible, rather than the bigger questions around proportionality, which the Joint Committee will be looking at in a week or so’s time. So yeah, absolutely, I think we need more experts, we need more people like like yourselves and, you know, academics to make sure that Parliament is being held to account, that the debate is being improved. I think we’re starting to see an improvement, but there’s an awful long way to go, and I would very much agree with you on that.

Speaker D: Do you think— another point is that one of the issues— I interviewed Michael Drury, who is the former Director of Legal Affairs for GCHQ. He said the real problem that they’re having is being able to future-proof. Against technological developments? Because, for example, when the first Regulation of Investigatory Powers Act was put down, there was no social media. So to actually try to put something together which does future-proof actually creates a dragnet that, you know, creates a huge issue in its own right. Do you think that that’s a problem?

Speaker A: Our evidence to the committee is that the rush to future-proof this— and I understand why they want to do that, to make these powers effective going forward so they don’t have to go back to Parliament year upon year. It has meant that we’ve got these overbroad terms that could include any sort of telecommunication service, any sort of internet service. As things stand, that’s not necessarily helpful or proportionate. So I think what we see our job to do now is to make sure these definitions are put down more clearly, even in the legislation itself or in the accompanying codes of practice, so that if a if a hotel or Wi-Fi provider is covered. They have the certainty around that. I mean, we actually had a telephone call from a member of a government department asking about these proposals and whether they were going to affect the communications network they run on their own department because they’re just not entirely sure. They’ve heard about it. They’ve done some reading. And the lack of clarity, the lack of certainty about it is even leading some government departments to not knowing if and when they’re going to be subject to these powers and what they need to do about it. So there’s an awful long way to go, I think, for the government to clarify these issues and to give confidence to, as the committee itself says, an incredibly important growth sector for the UK.

Speaker B: Andrew Kernaghan of the Internet Service Providers Association. Now, work in the technology world for long enough and you find everything is yin and yang. At the moment, we have the world of big data and transparency being touted as the future of the world. At exactly the same time as companies and individuals bay for the encryption and privacy that they want to protect their identities and data. So it’s no surprise that at the same time as the EU is pushing for data flows to restart across the Atlantic, that it is also championing the creation of a new industry in the EU to protect personal data. As with all technology, it has to be wrapped up in an awful acronym. PASS, Privacy as a Service. I asked Seamus Galvin of Espion, one of the researchers on the European project, what the aim was.

Speaker E: The aim overall really, I think, was to showcase and promote innovative companies in Europe in the area of privacy and cybersecurity, and also to support those innovators in a number of ways. So the core of the project was to develop a set of innovation framework, a set of innovation guidelines to help smaller companies in particular to understand the different processes, methodologies, ways in which they can consider improving how they bring privacy and cybersecurity services to market.

Speaker F: Okay.

Speaker D: So why did the EU want to do this? I mean, surely, you know, these companies must exist already. Why did the EU pick cybersecurity and privacy?

Speaker E: I think the EU, the R&D structure in Europe is split into different subsections and a big question for them was to understand within all the different realms of science and technology, because we’re funding this specific area of research, how can we actually understand how to innovate more effectively in this area? And is it different to other areas of technology or innovation or is it similar? That was something that they were interested in understanding. Understanding from the outset. So I suppose the motivation for them was that, you know, it’s their money, it’s their funding, they’re representing taxpayers, and they wanted to understand, well, are there initiatives that they can do to promote privacy and security innovation in Europe?

Speaker D: Were they doing this because there’s a perception that Europe’s a bit weaker in this area? Were they doing this because there was a perception that this is an opportunity for Europe to develop something that could mean that a lot of countries or a lot of companies will want to do business in Europe because we are a safe place to house data. What was behind it in that sense?

Speaker E: I think the number of the things you said there are applicable. I think there is a perception out there that, you know, maybe Europe is a laggard. And if you look at some of the the spend on security, it’s about a quarter of the global market at the moment, somewhere around €26 million, I believe one survey said. But a lot of that is actually net imports. So a lot of the products and services that are consumed in Europe are coming from other regions. So they’re saying, well, how can we, rather than having this import trend of privacy and cybersecurity products and services, how can we have more people in Europe actually using indigenous products and services built in the area. So that was one aspect that they were concerned about.

Speaker D: So unlike sort of America or Israel, for example, who have used defense funding to build this sector, what you’re saying is that Europe’s suddenly saying, hang on a minute, there’s a big sector here, and Europe’s got some very, very good reasons for developing this and a very good reputation.

Speaker E: Yeah, and I suppose that was the second point, Peter, as well, was that there are a lot of very, very good cybersecurity companies across Europe and a lot of very good emerging clusters. And in the research, we identify at least 14 or 15 very good clusters across Europe in the area of privacy and cybersecurity. In the UK, as you know, there’s lots of innovative companies. The Hague Delta in Holland is another example. So I think what Commission are looking for is how can we support those really good companies to move from maybe their own local market in Europe to actually scaling up to being global players, you know, alongside maybe some of the other international players that we know very well. And it’s not that that isn’t happening, it’s just that, you know, to optimize the conditions where that can happen more often than maybe it’s been perceived to be happening to date.

Speaker B: The EU project that wants to give us our privacy and data security back. Someone else who wants to give us our data security back is Thomas Alex of Bounty Factory. They’ve started up yet another EU initiative, this time Europe’s first bug bounty exercise. The idea is simple: you have some code and you want to make sure that it works properly and is safe. So you submit it to Bounty Factory and they see if they can find anything wrong with it by letting hackers attack it., and if they do, you pay them for bringing it to your attention. You get good code, and the hackers get to try out their skills and get paid on results. I asked Thomas Alex about it.

Speaker G: The bug bounty program is a crowdsourcing initiative for cybersecurity. A company or a project proposes some kind of its code. It may be a website, a mobile app, or whatever. People will look through the code for weaknesses and vulnerabilities, and the first to get a validated bug will get a reward. It’s usually money, financial, but it may be some goodies as well.

Speaker B: So what you’re saying is that somebody sort of says, I want my code checked, and so they ask a lot of hackers to check it and see whether there’s any holes that they can pull in it.

Speaker G: Yes, that’s exactly the point.

Speaker B: This has been happening for a while in the US, isn’t it? Why is it taking so long to get to Europe? You’re the first people to try this out in Europe.

Speaker G: Well, I don’t know, maybe cybersecurity sector in Europe is very institutionalized. There is a lot of restrictions by law. For instance, I mean, I think you may refer to some platforms in US, but maybe American people are more likely to recruit hackers because they understood more quickly that they need them.

Speaker B: So I mean, yeah, it’s one of those things that is noticeable about the US. I mean, the US Army does employ hackers, and it even employs ones who’ve been to prison. Um, so, but so what is it that you’re doing that is so different from this institutionalized or bureaucratic sort of cybersecurity world that you’re mentioning? What, what, what do you do that’s different?

Speaker G: This profession, uh, emerged from the community, the hacking and hacker community underground. People who are working at their desk at home at night and finding bugs or doing research on cybersecurity systems. A lot of them are working in their day-to-day life in cybersecurity. But you can see it’s the same people. So why should we get a service with a big company, like a big consultancy? Company because it’s the same guy out there in the community, you know.

Speaker B: So is it what— it’s what you’re saying then, that the, you know, the, the hackers are the people who are fixing these problems? And yes, in a sense nobody wants them to be fixed because the, um, the, the more institutionalized companies want to, want to basically say, ah, you’ve got a problem, and, and, and they want to leave those problems there because it keeps them in work.

Speaker G: Yes, of course. It’s a really big market. Big companies are doing big money with cybersecurity because when they are providing services by rebonds, they can sell other services like organization cybersecurity or stuff like this, you know. Yeah, but they are quite very expensive.

Speaker B: As well. Okay, but I mean, a lot of people will say, hang on though, I mean, many of the companies who offer these services are large accountancy companies, they’re very creditable organizations, and people like to trust those, those sorts of organizations rather than trust a load of hackers. And so why, why should they trust the, the, the hackers who you, you are encouraging to, to sort of come and do this work?

Speaker G: Yeah, but why shouldn’t we? Like I said, it’s the same people. I’m doing research in social sciences— in social science, sorry— on that subject exactly, and I can tell you it’s strictly the same people.

Speaker B: One of the problems with all of this, the biggest problem in cybersecurity recruitment, is actually finding people who know what they’re doing. So does your service sort of qualify or quantify people so that people can say, yes, that person knows what he’s doing?

Speaker G: Yes, it’s one of our innovations because the platform in US don’t work like this, but we have another platform which is called jobs.csreact.com, which is interconnected, interrelated. For instance, a company through bug bounty program and people will get through their code, right? But then the first to get the most critical vulnerability will get a reward and will also get points. Then we’ll make a ranking of all the people, and in an interconnected way with the job board, if they want to, I mean, they can make proof of their skills.

Speaker B: Thomas Alex, one of the hackers hoping to make our data more secure. Now, a feel-good story. Think of the fashion industry and you undoubtedly think of pretty faces, striking poses, and catwalks. But behind the compelling images is a very ugly face. The fashion industry’s drive for profits has made it one of the most polluting industries in the world because of its use of water and chemicals. And its drive to create an incessant churn of clothes as we buy to stay trendy and discard the outdated before it’s even been worn out. But a Danish company is hoping to change that by creating leather jackets that last forever and can say where they’ve been via technology on the internet. I asked Reimer Ivang of Better World Fashion how big a problem clothes are for the environment.

Speaker F: Just producing a pair of jeans costs 20,000 liters of water, of fresh water. That’s one example. When I talk about leather, I’m talking about if you have 1 ton of skin, you would use 500 kilos of chemicals. So that means that for 1 kilogram of leather, you would use 2 kilograms of very, very toxic chemicals. And of course, when you then talk about that the leather industry is around 6-8 billion tonnes of leather, then you can also talk about how much chemicals, how much water, how much contamination there’s built into this.

Speaker D: So what you want to do is recycle clothes, is almost stop people from buying new clothes by saying, hang on a minute, we want to take your old clothes and we want to remake them into new clothes.

Speaker F: Is that the idea? Yeah, well, it is not a coincidence that we have looked at leather. It comes better from using it, and on the other side, it is one of the most polluting processes within the second most polluting industry. So when we looked at textiles, we immediately looked at leather because it simply makes no sense that we throw away leather because the design of our jacket that we are just annoyed with it that we want to get a new one. So what we do is that we collect used leather in NGO organizations. We cut them up. Okay.

Speaker D: Now, the internet is essential to this, isn’t it? Because the concept that you have, you basically want people to one, buy via the internet, but also keep track of where their clothes are, and you want them to actually bring them back to you.

Speaker F: Exactly. So there’s this buyback opportunity. So it is built into the whole concept that we want these jackets back so that they can recirculate. It is inspired from the sharing economy, and the sharing economy has a huge platform that’s called the internet where it sort of rests on, because you can’t— it is not efficient to share if you don’t have that backbone. Bone that sort of helps you coordinate. Secondly, we have a storytelling mechanism built into each jacket. That’s why we want to have the interaction with each individual consumer. The reason for that is of course that when I buy vintage clothes, I always think about who has worn this clothes before me, where has it been, has it been in Paris. So what has happened? Why does it look as it look? There’s a stitch here. What story has that stitch? And we actually building in an Instagram-looking mechanism on each piece of clothes so that each consumer that wears our jackets has the opportunity to tag and fill in information on each piece of jacket. And that will then follow each jacket we cut them up into new jackets, that also means that the stories will spread and thereby there’ll be an individual story to each individual jacket.

Speaker D: I mean, it’s an interesting idea, isn’t it? Because in a sense then, some jackets will actually, uh, develop a, a value because of the person who’s worn them. So for example, if somebody has worn them who then goes on to become a celebrity or something like that, then in the same way that people buy memorabilia from celebrities, then they’re obviously going to be looking to buy a particular jacket because somebody else wore it.

Speaker F: Exactly, exactly. So we’re using reused leather. That means that each individual leather jacket by production is individual. It’s one of a kind. But then we build onto the individualism or make it even more individual by saying that each jacket has its own unique history.. And that means that if it got scars or something like that, that also originates back to something that has happened with this unique jacket. And in that way, you will really hear when you purchase a jacket, you will get the only jacket of its kind in the whole world. You will build on the story, you will narrate, you will write the story, and when you are done with the jacket, you will hand it over to others. And then they will continue the story of this individual jacket.

Speaker B: Raimund Aiwanger of Better World Fashion. You’re listening to Password on Resonance FM. And if you’ve just joined us, I’m afraid you’ve missed it. But we’ll be here again next week when we bring— Raimund Aiwanger of Better World Fashion. You’re listening to Password on Resonance FM. And if you’ve just joined us, I’m afraid you’ve missed it, but we’ll be here again next week when we’ll be bringing you more news about Resonance FM’s fundraising spectacular, when you will be able to bid for an incredible range of items ranging from records and art to tech that reflect the sheer diversity of the shows that Resonance FM brings to you. Password is a joint production between Future Intelligence and the Cyber Security Research Institute. Institute. And if you want to find out more about what we do, then log on to our website at www.futureintelligence.co.uk. Password is produced by Tim Smith. Thanks for listening and goodbye.

Speaker A: This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00