Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 6th July 2016

PassW0rd – 6th July 2016

Play

Speaker A: Hello and welcome to Password on Resonance 104.4 FM with me, Peter Warren, the program that takes you into the workings of our high-tech world. In today’s show, we focus on one of the biggest issues that we now face. Because we are dependent on technology, we have become more and more dependent on a software world that is in a permanent state of change, and that has huge implications for us because most of us don’t know that the bedrock of the world that we access from our computers and the mobiles in our hands is reconfiguring itself all of the time. It’s a world where everyone is looking to access our devices, to update them, corrupt them, or to find out what we are doing. And the ramifications of that are huge, because soon even our cars will use over-the-air upgrades, and many of our devices are using software that could have weaknesses in it. It’s a world that is even worrying the police, because the highly controversial Data Regulation and Investigatory Powers Act, soon due to be debated in the Lords, confers huge new powers on them in this uncertain world, and they’re not sure that they want them. Earlier this month, Password attended an unprecedented meeting with the police at the National Crime Agency to discuss the issues. Due to reporting restrictions, we were unable to broadcast our recording of the meeting, so we interviewed Glyn Moody, contributing policy editor of the technology website Ars Technica UK, who was also present, about what was discussed.

Speaker B: Yeah, I think they’re a little bit worried actually, because it’s very striking that right at the beginning of the meeting, the top man there said, you know, we police by consent. If we lose that consent, the cornerstone of policing We can’t police without trust and confidence from the public. And I think what they’re worried about is that the powers in the new bill, the Investigatory Powers Bill, are so great, and I think they’re actually worried that they’ve been given sort of too many powers and they’re going to lose the public on this one.

Speaker C: You were quite vocal about this. One of the things that you were trying to point out was the incredible power. What is it that was worrying you?

Speaker B: I mean, there are several things that are concerning about this new bill. One is that all of our online activities, for example, every website we visit and every email we send will be stored for a year by our ISPs. Now one thing that the government likes to point out is that this is only, and they say only, metadata. In other words, they’re saying it’s not the content. It’s just the information about the content. But I think it’s pretty widely accepted by sort of people who know what they’re talking about that metadata is actually much more intrusive than content. Why? Well, because it’s digital. It’s not like content which has to be parsed and understood. You can just feed in a billion pieces of metadata to the computer and it will find all the connections between them. It’s already pre-sorted. Metadata actually is analyzed in terms of date, time, who you talk to. You can build up somebody’s entire life from that metadata. And the other aspect that’s very worrying are these bulk powers that are that are being given to the security forces, which lets them basically collect billions of pieces of information or break into huge numbers of machines. I mean, these are very worrying powers.

Speaker C: But the police were making the point, they pulled a slide up, they said, look, we just need to know what websites people went to. They were claiming that they couldn’t actually pull down very much more than that.

Speaker B: And the question is whether that’s proportionate. I mean, nobody wants to see the police struggling, but equally nobody wants the police to be giving your entire life on a plate.

Speaker C: They were talking about having the ability to hack into people’s computers.

Speaker B: Well, that’s right. I mean, the, the so-called interference powers, which obviously has been going on in the past without us really knowing about it, is being put on a firmer legal footing, which is good news. But this is really about giving the power to break into systems and indeed to plant malware there. So this really changes the whole relationship, I think, between the public and the police. And one issue that I raised that struck me as a possibility is that if it’s so easy for the police to get into your systems, then what’s to stop them from planting evidence? I mean, it just becomes very hard to trust the evidence that they claim to find on your computers.

Speaker C: That’s a real big issue, isn’t it? Because one of the things that they’ve done up till now with police investigations is image a hard drive. Now, how are they going to image a hard drive remotely? Sometimes that takes quite a long time. Somebody would be aware that that sort of interference was going on there. Assistance.

Speaker B: Well, that’s right. And they, and they may take shortcuts and they may just pull down the information that they want and then present it in court. But then I, I would expect that some of these things are going to be challenged, frankly, because it seems to be getting pretty tenuous. You know, as you know, you can just change things so easily and erase any sort of footprints that you leave that you’ve done it. So how can you trust evidence if you give police these powers?

Speaker C: And the other point that concerned you was this new software that the, the police were talking about developing, because you were pointing out that the government hasn’t exactly had the greatest record.

Speaker B: This is true. All these databases that the ISPs are setting up will be accessed by a single piece of software which, as you rightly say, the government will be commissioning and running. And so this will be an immensely powerful piece of software because basically they’ll be able to pull up anything from all these databases and consolidate that information. So again, it’s bringing together metadata.. And the big problem is not just the power that people will have, but the fact that the track record of the government, as you say, has been pretty poor for big projects. And the worry is that it’s going to be sort of badly done and that there will be big security holes which other countries and indeed criminals would be more than happy to exploit in order to access that very sensitive information.

Speaker C: And of course, going to that point that you were making about proportionality, The other thing that they were saying was that they will have the capability of being able to know who are in particular places at any one time. Now, that’s going to be very, very tempting for them to go on trolling exercises to find who are in places when a particular crime is being created.

Speaker B: Absolutely. I mean, this is the whole problem with this kind of power is that once you’ve got it, then the next stage is saying, well, since we’ve got it, why not use it?. And it’s this slippery slope that worries me, the fact that there are just no obstacles to tremendously intrusive spying of that nature. And so that’s why I was worried about those aspects because once these powers are in place, the police are bound to use them. I mean, it’s just human nature and they’ll say, well, look, surely you want us to stop the bad people. Why can you possibly be against that? But the problem is, as I say, it’s a slippery slope and it ends up becoming just a standard thing for the police to do.

Speaker C: And that seemed to be the point, didn’t it? Because what the police were trying to do was say, yes, in a new digital age, we have to be able to police that. However, they didn’t want to be perceived as a surveillance organization, did they? Exactly.

Speaker B: Well, it goes back to my initial point that they were saying that, you know, we police by consent. And I think they are aware of that tension, that they have these powers potentially that will destroy consent. And the big issue I think we as the public and society need to address is, you know, do we really want the police to have those powers? Would we perhaps rather have a police force that maybe doesn’t have all the powers but still has our support and consent to do its policing?

Speaker A: That was Glyn Moody of technology website Ars Technica UK on why the police are also feeling a little uncomfortable in the information age. And if you feel that you might be being pushed like the police into a new world that you may not be too comfortable with, the bad news is that in the short term it may not get any better because our cars are now caught in a technological revolution and are suffering a record number of recalls due to the tech being built into them. A problem that can only get worse when the robot cars start to roll out onto the road in numbers and join the electrical vehicles that are already there. Here’s Farzad Henara of Stericycle on research his company has carried out into the record number of auto recalls that have been occurring.

Speaker E: Blacksmith technologies is just increasing and increasing. But to just set expectation, at the moment about 10 to 20% of the recalls are related to software, where software basically needs an update. So those also, those types of issues fall under recall. And the rest is mechanical still, but that’s also because of the complexity of car. So an actual car is a very complex product, obviously. But about 80% is mechanical, and at the moment 10 to 20% is software-related. But it will continue with the uprise of the connected car and the autonomous car, obviously, which is just very near in the future.

Speaker A: Let’s return to that in a moment. Obviously there was the news recently that Mitsubishi had been hacked, or one of its cars’ ignition systems had been hacked. Is that one of the reasons for these software upgrades? Is it that you couldn’t possibly risk doing these software upgrades over the air, as it’s known, i.e., remotely? So the car’s got to go in to have them done?

Speaker E: Yeah, I mean, to be honest, over-the-air updates are already done, and I think the leader of that is Tesla. Tesla is already conducting over-the-air updates to its cars when there is a software issue. However, when you look at the connected car and you just mentioned obviously hacking, that is a big concern to the market and that’s why I think it’s one of the biggest holdups for the connected car to really accelerate through in being developed by manufacturers. But it’s just around the corner and just like with all of the other tech that we’re using around us, there will be a solution ultimately. However, over-the-air updates are already taking place. And I mean, we look at the market as a whole and we are in touch with a lot of developers behind these solutions. And it’s impressive to see how far we already are at this point for that to completely enter the market. And it’s interesting because you have to think about this. Over-the-air updates upgrades. It’s a very rapid solution, so it doesn’t require the vehicle owner to go back into the retailer to do the update. The manufacturer, in essence, is able to update the vehicle over the air through the wireless system of the car, through the connected car. And what it does, it obviously reduces the time that you’re driving around in an unsafe vehicle. So, I mean, there’s a big benefit to that as well.

Speaker A: Getting more, ever more complex, isn’t it, all of this? Because one of the problems, as you’ve said, is going to be autonomous vehicles. This degree of complexity that we’re seeing where you’re getting these machines updating themselves all of the time and cheerfully trusting ourselves to them is quite amazing. But do we have anything to be worried about?

Speaker E: I think it’s like with anything else, Peter. If you look at it, you know, the actual car from a mechanical standpoint, all of that is also driven by the way the car is set up. And when there’s an issue with the car, car, and we all know we all have issues with our car, we all need to service our cars, so it’s very important to keep servicing your cars because they are complex as it is. It obviously adds complexity with, however, with this software we’re also able to better monitor and track the performance of the car. So in essence, in a way, it allows us to monitor a potential upcoming risk. So if you can imagine technology becoming smarter and smarter, we’ll be able to predict potential failures as well with this new technology. So there’s this plus and there’s a downside.

Speaker A: Farzad Henreha of Stericycle on why being on the web is slowing down our cars. So why is this happening? Well, one of the things that we don’t realize about the software that is running our lives is that there are lots of bugs in it. In it. Bugs that are being fixed all of the time by the companies that make the software. And one of the issues is open source software. Free-to-use software that is made often out of love by programmers that can fulfill a particular task. But the companies that take advantage of it are not obliged to use the latest versions of the software. And often due to time, they simply load something that works even though it might be insecure. Only after it’s been released do they go back over it to check it and update it. Ever noticed those little alerts on your mobile? That’s what’s happening. Here’s Bob Cannaway, the Chief Marketing Officer of Black Duck Software, on a survey of the software in use that his company has just conducted.

Speaker F: So one of the things that we, we do as a company is we look at commercial software and the, the code that, that’s inside of that, typically because when another company wants to purchase them, they’re interested in what open source has been used. So we have some really good insight. And so the things that we’re seeing are all these companies are using more open source software than they think. So when they self-reported the open source components and software that were in their applications, we were finding that there was about 100% more, twice as much after we did a scan and looked into it.

Speaker A: Open source software, what is open source software? Everybody out there will be sort of thinking, they’ll be scratching their heads on that one.

Speaker F: Absolutely, so open source software is a license model for software. What it typically allows is the use of that software without any monetary compensation for the copyright holder, for the person who created the software.

Speaker A: So this is something like Linux or something like that?

Speaker F: Linux, Drupal, There’s OpenSSL, there’s a whole plethora of open source software. Millions of open source projects exist. About a million or so are actually being utilized and active in the marketplace.

Speaker A: So these are components of software that people have put together, they put into a library and they say, “There you go, you can use that, I’ve done that job for you.” That’s right.

Speaker F: That could be anything from running your website to something a developer might want to include in their application. Some sort of functionality that they don’t want to create themselves. And what open source allows is the use, reuse of that software, but what it also creates because it’s open, because the source code is available, it’s freely available, is that there’s a community of people, of experts writing the software because they have an investment in the project, whether that’s their company uses it or they just have a lot of passion for that software.

Speaker A: So essentially you’re taking a component that you might not know very much about and you’re having a bit of blind trust in that. So what does your software do then? Obviously you were interested in doing this study because you were interested in highlighting something that your software does.

Speaker F: Right, so what we do is we are able to look into a software application and see what open source components it is comprised of, right? And this software could be used for internal use within an organization or government. It could be used and sold from a software company. It could be used in an Internet of Things device or a medical device. One surprising thing is the firmware that runs these devices, the, you know, when you’re using your Nest thermostat, the controls are all software. It’s written in software. It’s It’s running inside of essentially a little computer like your mobile phones are now, and it’s able to execute that software code. And so software is everywhere. It’s in your car, it’s in all of the devices in the Internet of Things, in the smart home, in a hospital, etc. So it’s not just limited to what’s running on your MacBook.

Speaker A: So, and one of the things with this is time, isn’t it? Time’s an issue because companies want to get their products out there very, very quickly. How can they avoid that being a problem for them?

Speaker F: Yeah, so another one of the other things that we found through this study was that these companies, because they didn’t know about a lot of this open source, but also because when you manage all of these components, you have to go out and look for new versions, fresh versions, ones that address issues, because these open source developers are always releasing new versions of their product, and as best practices would have it, You should go to the most current one. Sometimes that’s difficult because we’re trying to get software out so quickly. If I have 100 components that make up my application or 150 components, every time I upgrade one of them, I have to go through a whole new cycle, which takes more time. And so what we see are that over two-thirds of these applications contain some known security vulnerability that has been reported and publicly disclosed. Disclosed in these open source components. And what we also found was really interesting was that they were on average a little over 5 years old. So that means that from the time that these were disclosed and fixed, the community is very fast at fixing them, 5 years had passed until we did our scan and were able to notify these companies that these issues existed.

Speaker A: And presumably these things are going to be, what, in the apps that people are using on their phone, they’re everywhere, aren’t they?

Speaker F: Right, so when you, when you see on your phone there’s a, there’s, there’s an update, right, you look at the, you know, the app store and you see that this is the number like 47 typically next to it, that means that you have 47 apps that have some kind of update coming. And a lot of those updates, they don’t let software companies don’t like to publicize that there might be a security vulnerability for obvious reasons, right? Why, why do we want to tip off a potential attacker that, that here’s an easy way in, and they do address the security vulnerabilities. That’s why you should always update the software on your phone as soon as possible.

Speaker A: That was Bob Cannaway of Black Duck Software on the ongoing battle to keep the software on the devices that run our world up to date. With such libraries of software out there with records of errors in them, it’s little wonder that the hackers And now it would appear the police are able to attack them so easily. It’s a world of impermanence though that is beginning to be rejected by many of us. Around 6 years ago, caught up in the hype, our mobiles used to have the life expectancy of butterflies and many of us changed them every 18 months. Not anymore according to the Green Alliance. We’re keeping our phones for longer and Dustin Benton head of energy and resources says that that is very good for the environment.

Speaker D: It’s changed enormously quickly. When we started looking at this, people were telling us mobile phones had a lifetime of 18 months at most. But what we found, and what’s really interesting from this bit of research that we’ve done, is that actually across the 8 million customers that we looked at, overall people are keeping their phones for something like 15% longer than they used to. I think the really interesting figures are SIM-only type contracts where people aren’t on on a sort of regular contract. Just in the last little while, people have decided to keep their phones for an average of 6 months longer. So now I think almost half the people on SIM-only have kept their phones for more than 3 years, and in some cases up to 6 years. So what it says to me is that the mobile phone industry is changing and people are saying, well, I’m actually quite happy with my phone as it is. I’m gonna hang on to it for much longer than people did in the past.

Speaker A: Is it that, or is it that people are tied into longer contracts that they don’t think they can get out of?

Speaker D: Well, actually, we looked at looking at the contract, and you’re right, contracts have extended from— for a while it was a year, then it was 18 months, and now it’s closer to 2 years normally. But what we find is that people who have a choice about upgrading early or going on to something like a SIM-only contract are keeping their phones for way longer. I mean, there are people who upgrade on that sort of 2-year cycle, but actually it’s the people who decide not to upgrade on the 2-year cycle, to keep their phone for longer and switch to SIM-only contract that are driving the increased longevity of phones.

Speaker A: Okay, so why are people doing this?

Speaker D: Well, we didn’t do a public opinion survey, so I can only really speculate. But I think what’s happened is that we saw a huge amount of change in mobile phones over the last couple of years. I mean, every new generation of phone was substantially better than the last. And what seems to be happening now is that mobile phones have got to the point where they’re good enough for most people. And there are a couple of reasons why I say this. First, we saw this with desktop computers and then with laptop computers where there was quick upgrades and then slowly the upgrade rate rate began to slow down. And also, I think that when you look at the new sorts of features that phones have, they’ve all got great screens, they’ve all got good or at least decent battery life. The pace has slowed and you can see that as people are seeing this pace slow, the number of sales of very premium-end phones are declining and people are picking up cheaper new phones and keeping the flagship phones that they might have bought for quite a bit longer than they used to. So I think what we’re seeing is basically a slowdown in innovation and people people saying, “Actually, this does everything I need it to.” What is the impact of keeping your phone for longer?

Speaker C: Is that good for the environment?

Speaker D: Yeah, it’s the best thing you can do really, and that’s because mobile phones, the majority of their impact happens at the point of manufacturing. So you build these things and they’re extraordinarily detailed and they’ve got semiconductors in them and there’s a huge amount of carbon and energy and really rare materials that go into making it. And then once you’ve made it, the amount of energy that that device uses for charging it and communicating with the network is pretty minimal actually. Over three quarters, something like 80% of the impact is in that first sort of manufacturing phase. So really keeping that in use for longer makes a huge difference. In fact, just keeping a mobile phone for 1 year longer cuts its footprint by up to half actually. And that’s well within what we think is certainly the technical lifetime and even the reasonable lifetime of most mobile devices. And I should say that you don’t necessarily need to keep your own phone. Phone for that period of time. If you sell it on to somebody who is also going to use it, that also cuts the impact if they are not buying a new phone because they have bought your secondhand phone.

Speaker A: Why keeping hold of your mobile phone for longer is good for your wallet and the planet. It’s also possible we might be doing it to make sure we control the data on it, because our mobile phones are now everything to us. And one of the biggest irritations that we face is when they are not available. When a mobile phone powers down, it induces panic in all of us. So, spare a thought then for people in developing countries like Africa who routinely tramp 20 miles to charge their devices. It’s something that Sudha Khetarpal, a top drummer with bands like the Spice Girls, Fearless, and Dido, has pondered over, and she’s come up with a device called Spark which aims to help a continent where only 1 in 3 houses has access to energy.

Speaker G: I spent many years on stage staring out at crowds, creating a lot of energy, and I always wondered whether that energy could be harnessed and used.

Speaker A: How does Spark work?

Speaker G: So Spark is a percussion shaker. It’s a bit like a maraca, so without the handle. And as you play it, so you kind of shake it in your hand, that energy generated from you playing gets converted into electricity and stored in a battery. And that battery can then lead you to generate light. Also, with the addition of a solar panel, it can charge a mobile phone as well.

Speaker A: Because that’s the point, isn’t it? Obviously, one of the things that people don’t really think about is that Africa’s not exactly the sort of place where there are plugs everywhere.

Speaker G: Absolutely. And Africa, as an emerging economy, has a huge reliance on mobile phones. So, for example, in Kenya, where we went to do our beta testing, 75% of people have a mobile phone, and 75% of people are actually without electricity. So it’s a no-brainer. People need to really charge up their phones, and Spark is definitely allowing them to do so. They also have very, very long distances to go and charge their phones. For example, in rural areas like Ghana, people would have to walk 15, 20 miles to the nearest village to charge up their phone. Also, in Kenya, the M-Pesa banking has revolutionized the banking system out there. Again, people need to be connected. They need to use mobile phones, and Spark obviously solves part of that problem.

Speaker A: That is the issue, isn’t it? Because a lot of people would say, why on earth? You’re in Africa. Why do you want a mobile phone? And what they don’t realize is that one of the things with the way that development has actually taken off in Africa is because they now have access to a huge range of internet services there, but that you can only get to them if you’ve got a mobile phone.

Speaker G: That’s right. And also, Africa has a target as well. So by 2030, one of the target lines is to have universal access for all within Africa. It’s a hugely growing— the economy is really growing. It’s a place of commercial enterprise, and obviously, you know, the mobile phone is just a very, very small part of that.

Speaker A: Could you generate enough power from just banging on this device or making a tune with it?

Speaker G: When you shake it, absolutely, you can generate— 12 minutes of shaking gives 1 hour of light. And what we didn’t want to do is pretend that, you know, you could shake for a certain amount of time to charge up your mobile phone. Like, the physics just simply doesn’t allow that. So that’s why we’ve added this smart power management system that allows us to draw from solar energy, so we have a dual harnessing system to really make it a practical tool for people who don’t have the electricity.

Speaker A: What would you like to see come from all of this?

Speaker G: I’d like to see SPARK really taken to scale throughout Africa, really to get the maximum impact so as many people as possible have access to it and can really make good use of it.

Speaker A: Right, so it’s not just about making yourself a millionaire, it’s to spread the light.

Speaker G: That’s right. If I wanted to be a millionaire, I’d have stuck to the music industry, I think.

Speaker A: Is this part of some bigger series of projects?

Speaker G: That’s right, yes. Currently we’re part of the Off the Grid Club. So essentially there is an events company in London called EnergyNac, and they approached us and said, we want to create this club to bring together new market-ready technologies such as Spark together with microfinances, regional heads, and business banks, etc., so we can really create this kind of club, this way to get these market-ready solutions out into Africa. They also saw the benefit of music. Music is a great universal connector. It brings us together, it pulls us together, and they could really see the advantage of this. So they’ve asked us to put on a launch which manifests itself as a gig, and what we’ve done is brought in some great London African celebrities. Fuse ODG is an example. He’s headline act. He’s a British Ghanaian rapper, 14 million views on Facebook and YouTube, so I think he’s really going to kind of pull a crowd. And this is going to trail into the first ever electricity festival or energy-related festival in Tanzania in December. So it’s really exciting to be a part of this initiative. It’s really exciting to bring music We’re looking for this whole thing to spread the word and to create a movement.

Speaker A: Suda Ketterpel, banging a drum to bring a bit more light to Africa. You are listening to Password with me, Peter Warren, and if you’ve just joined us, then I’m afraid you’ve missed it and will have to listen in next week or catch us on the listen again on the Resonance FM website. Password is brought to you by Future Intelligence and the Cyber Security Research Institute. To find out more about the issues we have been discussing please go to our websites on www.futureintelligence.co.uk and www.csri.info. Thanks for listening and goodbye.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00