Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassWord – 18th February 2015

PassWord – 18th February 2015

Play

Speaker A: PayPal and checks.

Speaker B: Welcome to Password with me, Peter Warren. In today’s show, the biggest ever theft of money by cybercriminals, just as a new film about hackers hits the cinema. Fears for freedom of information as the Commissioner’s budget is cut. Again. We preview, preview the biggest ever virtual reality show this weekend. First, security company Kaspersky Lab has revealed that hackers have stolen up to $1 billion by infiltrating the computers of over 100 banks. They inserted malware that enabled them to copy the actions of employees making genuine transactions and then move the money to dummy accounts where it could be withdrawn in cash. Kaspersky says most of the money was stolen in Russia, but European, American, and Japanese banks are also affected. We’re joined now on the line by David Eames of Kaspersky Lab. David, welcome to Password.

Speaker C: Thank you very much.

Speaker B: Now, what can you tell us about who’s behind this massive bank robbery, David?

Speaker C: Well, we know it’s a diverse group made up of a whole bunch of people in different countries, actually, including Russia and China and Ukraine, a couple of other places as well. So it’s sort of a wide diverse group.

Speaker B: Okay, and when you say it’s a wide diverse group, is it just that the software has been shared between this wide diverse group or that they’re all working on it together?

Speaker C: Well, it seems like they’re all working together. This is part of a concerted campaign as opposed to individuals using off-the-shelf software.

Speaker B: Well, that’s rather a new development, isn’t it? I mean, up to now we’ve seen software being developed by particular organizations who might be renting it out to other groups, but the development of it tends to be within one group.

Speaker C: Yeah, I mean, we certainly, we have seen obviously targeted attack campaigns before. What’s new about this, I think, is that in the past where people have gone after money from banks, it’s typically been by going through individual bank customers who may not be technically aware and therefore can fall victim more easily to attacks. This attack, on the other hand, is specifically going after the bank systems rather than going through individual online bankers.

Speaker B: So presumably in that case then, what they’ve done is they’ve targeted, or they’ve aimed in on a particular software that is the thing that they are exploiting.

Speaker C: Yeah, they are. They are going after individuals as many targeted attacks at other organizations do by using spear phishing. So sending phishing emails specifically aimed at a particular person designed to try and trick them into launching some code in the first place. And this code is then basically recording what it around it, so it’s pulling in keystrokes that people type. It’s basically trying to track what the individual who’s been infected is doing so that its subsequent actions when they try to move money around look as though they’re just part of the normal everyday activity of that person at the bank.

Speaker B: Okay, so how were they able to continue hacking for 2 years since 2013 without being detected then?

Speaker C: Well, they haven’t gone after a single individual bank and sort of been there for 2 years. What they’ve done is actually gone after anything up to 100 banks. And in each particular case, the operation maybe has spread sort of 2, 3, or 4 months. So they’ve been going in at a relatively short time per bank. And they’ve obviously aimed to keep their heads very, very low. And so it’s not really been until they’ve initiated some action to move money about that there would have been anything untoward detected, typically speaking. And even at that point, as I say, because they’re mimicking some individual at the bank, they effectively have an insider in their pocket, albeit an unwitting insider.

Speaker B: Okay. So does this organization go by any name? I mean, it’s one of the things that the computer security industry love to do is to give some sort of glamorous name to these things.

Speaker C: Well, we’ve given the name Carb Bank. Carbanak to this. This is the name given to the group behind these attacks, these breaches.

Speaker B: Any particular reason for that?

Speaker C: Well, I think it’s a sort of nod in the direction of a piece of banking software called CarBurp, and we think that’s because there are some links to that of the people who developed that banking Trojan, even though that Trojan is aimed at individual bank customers rather than banks itself.

Speaker B: Okay, now in future, what should the banks do to prevent all of this? I mean, in America we’ve seen within the last couple of weeks Obama’s been calling for people to share information. Would that have helped them?

Speaker C: Well, I think sharing information is a great idea. There’s no question of that because it’s one great way in which people can be tipped off about potential problems, much like a neighborhood watch works. I think one thing for me anyway that this points out is how crucial it is for organizations and banks included to make sure that staff who are not necessarily technical at least have some basic level about malware, because time and again we see quite sophisticated targeted attack campaigns begin by trying to trick people into doing something that jeopardizes wider security.. So making sure that people understand how they can become an unwitting target is really, really important, I think.

Speaker B: Okay. Now, very quickly and finally, Kaspersky Lab are in the news again because of the Equation Group. What is the Equation Group? This seems to be another piece of software that seems to be part of an intelligence agency, doesn’t it?

Speaker C: Yeah. This is one more of those sort of groups really aimed at cyber espionage, in other words using malicious code in order to get information out of a targeted organization. This particular one, extremely sophisticated. Probably, I mean one of the things that stands out in terms of level of sophistication is the fact that it’s, the people behind it have been able to get their code into the firmware of the hard drive in computers which has allowed them to do two things. One, to resurrect themselves so that even if that hard drive is formatted because they are in the firmware rather than on the drive itself, they can resurrect from that. And the second is it gives them the opportunity to carve out a slice of that hard drive to store information that they are stealing prior to delivering sending it to their servers outside of the targeted organization. And I mean, we know some of this code goes back to 2001. There are indications actually that this group has been developing stuff for a lot longer than that, maybe as long as 2 decades.

Speaker B: Now the Washington Post is saying it’s the NSA. Any comment on that?

Speaker C: Well, attribution is notoriously difficult. I mean, often it’s impossible. So I mean, we’re not in a position position to say that. We just know that this is a determined group of people intent on gathering information, actually.

Speaker B: And it seems to be based on Stuxnet, which a lot of people said, including the New York Times, was—

Speaker C: I think that’s the link a lot of people are making, yeah. Certainly these people, their activities predate the development of a lot of the Stuxnet stuff, but certainly some of the exploits that Stuxnet used were developed prior to that by the Equation Group.

Speaker B: Good. Okay, well, David Emmes of Kaspersky Lab, thank you for joining us.

Speaker C: Thanks. My pleasure.

Speaker B: Now, of course, this is all very worrying for anyone who has a bank account or even a computer, in fact, and that means all of us. But the security industry is always on the case, finding new ways to authenticate genuine users and block out hackers or thieves. Indeed, the news just broke today that NatWest and RBS are going to be taking fingerprints off your phones as a mechanism to enable enable you to access your bank account. The latest technique, though, is a sort of whole-body fingerprint, a complicated set of gestures and mannerisms that only you can make when you’re using your smartphone, tablet, or computer. BehaviourSec’s Neil Costigan, whose company has developed this, joins us now. Neil, welcome to the Password Studio.

Speaker D: Thank you very much.

Speaker B: Now tell me, how do you log and measure all of those gestures?

Speaker D: What we do is offer some small code to typically a bank, when we speak of bank accounts, that they embed in their mobile app or on their website. And it’s very, very light. It just captures the events, the kind of XY position of where you are and the millisecond times and that. And in the backend, as you move through your pages and you do continuously through your login pages, account transfers, et cetera, we’re just calculating, you know, is this the person who they say they are by comparing this to their previous behavior.

Speaker B: Okay, but in the case of this massive bank robbery, could BehaviourSec have prevented the criminals from gaining access?

Speaker D: I believe it could have been a tool to help. You know, it’s not just what the people are typing and how they’re logging in, but it’s how they do it, the rhythm of how they type. So it’s an extra layer, adds extra complexity. So there’s no silver bullet to this security stuff, and the anti-fraud people and security officers have to take every tool in their arsenal and just layer them on top of each other.. And we seem to be an intriguing new effective layer that catches it earlier, and costs are saved if you catch it early.

Speaker B: Now, I mean, obviously you’re doing this off the keyboard, aren’t you?

Speaker D: Keyboard, mouse, touchscreen. The mobile device itself is a fabulous tool with the amount of sensors— gyroscope, the angle, the pressure on the screen, even XY spots. So your gesture, your depth of touch, is a big part.

Speaker B: So presumably, though, that’s then been reconciled to a memory or some stored data that they have about you. Isn’t that the sort of Achilles heel? Because then, you know, somebody could capture that data and maybe mitigate it in some way.

Speaker D: Yeah, the profile is not so much what you’ve been doing, it’s a kind of statistical map of it, and it’s very hard to take one of those then and reproduce it as a human to do it. That’s part of the premise in security.

Speaker E: Okay.

Speaker B: Now, you’re a new company, so the technology’s yet to prove itself in the market. How’s it going? I mean, this is a big up-and-coming area, isn’t it? I predict that biometrics is going to be a big thing at the Mobile World Congress in a bit later on.

Speaker D: We hope so. We’re newish. We’re a university spin-out. We’ve been doing this about 6 years now. We’re Scandinavian, and we’ve been very successful in the Nordic market. So pretty much every internet user, bank, and mobile in Sweden, Denmark, and Norway have our technology. We have like 10 million users, 500 million transactions last year. So we’ve proven it in a market that’s kind of a bellwether for the industry. The Scandinavians are not trendsetting, but they tend to be the first to do some stuff. And so we’ve done it. We’ve proven it at scale. About a year or two ago, people were intrigued and said, this is curious, this is interesting. But now that we’re doing millions and millions, it’s kind of accepted as a, you know, this is a technology that works.

Speaker B: And is this something that we’re all going to have to get used to? Because a lot of people would say, I know there’s something a bit creepy about this. My mobile phone will know exactly who I am. And then when that’s reconciled to the mobile phone knowing exactly where I am, et cetera, et cetera, people will see it not just as an ID-proving device, but as a know where you are device.

Speaker D: Yeah, I would like to think of it as consumer-friendly. There’s kind of Big Brother biometrics, the physical ones, kind of do people creep out, but we’re kind of just doing the rhythm of what you do. It’s really verifying you are who you say you are rather than trying to figure out who you are and that kind of thing. So yeah, it’s a tool hopefully used positively. The banks are doing it to help you not be attacked and would see it, at least in Scandinavia, the announcement is, we’re doing every technology we can find to prevent—

Speaker B: you know, you losing money, basically. Well, it’s interesting though, isn’t it? Because the ID card scheme in the UK has— because the Liberal Democrats shot it down, that’s gone the way of what’s considered to be bad ideas. But this is almost an ID card by default, isn’t it?

Speaker D: Yeah. In Scandinavia, the banks operate together. They join together instead of each of them figuring out the security. They join together and made this kind of digital identity, and this is one of the tools they use to verify it. And they license that on to the tax authorities and the government. So it’s an electronic form of identity.

Speaker B: Good. Well, Neil Costigan, thanks very much for joining us on Password. Thanks very much for getting here to us, and I know you’ve got to go jump on a plane. Thank you very much for having me. Now, here’s another financial technology expert, and he’s hoping to transfer his success in preventing money laundering to a new role in the National Health Service. Freddie McMullen at Anomaly 42 says new apps and sensors can make us all healthier and save the cash-strapped NHS money by reducing the number of nurses, doctors, and hospital beds. He’s surprised that the political parties are producing what he calls analog plans that don’t include the latest applications and systems. Freddie’s been explaining to our producer Jane Wyatt.

Speaker E: Now, I’ve already talked to companies that have been experimenting with with coating tablets that are— the coating actually has sensors that when the tablet reaches the stomach, it automatically sends a signal to an app with the details of the tablet, the date and time of when it’s actually taken, etc. There’s already new Internet of Things that are now starting to emerge in the market whereby sensors are printed onto bandages and those sensors are picking up data as well. So the rate of innovation is going so fast that by 2020, if we start to think about the blueprint in terms of manifesto today, that blueprint could actually be changing so much in terms of healthcare moving from more reactive to preventative in so many different ways. It could change by being more open-minded and thinking about the pervasive use of technology. It could be changing the way waiting queues are hurting the NHS in the A&E or at doctor’s surgeries, etc. The move towards self-service, self-sufficiency. Yes, I do believe that the manifestos really don’t have the blueprint for where we should be as a society in 2020. I can see that all those innovations are really exciting and that they would empower patients and free up medical experts such as nurses and doctors from a lot of unnecessary paperwork because the data will be connected and transmitted automatically. But surely smart pills and bandages that can do a blood count for you, they’re obviously going to be more expensive than standard pills and standard bandages, aren’t they? How is it going to save the cash-strapped NHS money? Well, this is why I believe one has to be careful of where to spend where to start, and the lessons we’ve learned in financial services is start where you can make big cost savings in relatively short spaces of time, and then reusing the savings from that to actually reinvest in new capabilities. If one’s smart about it, then— Sorry to be devil’s advocate here, but if you’re reusing the savings,— they’re not savings, are they? You’re still spending the same amount of money. Yes, but— yes, that’s absolutely true. Maybe I’m not using the right word, but for sure, if one can actually do far more with the same budget— so if we were able to keep healthcare expenditure to around 9% of GDP, but do 2 to 3 or 4 times better and that the healthcare of the whole society improves and that the pioneering capabilities from the UK are actually also shared with other countries around the world, which I believe they could do, then yes, for the same amount of budget one could be doing so much more better.

Speaker B: Well, that’s Anomaly 42’s Freddie McMahon with his vision for the future of the health service. Whatever happens to our public Public Services, we’re more likely to get informed decision-making if whistleblowers are protected and ordinary people have the right to demand information. In fact, the NHS have just been talking about how they can actually protect the role of whistleblowers. Now, it’s been 10 years since the Freedom of Information Act was passed, but here in the UK, our Information Commissioner, Graham— Christopher Graham, fears that his office may go the same way as the Australian Information Commissioner, who’s currently on extended leave and whose role is described in an official the statement by his deputy as in limbo. Australia’s new government has decided it doesn’t need an Information Commission. So could it happen here? His funding’s been cut again and again, and Christopher Graham believes freedom of information is not a priority for the government, which is very worrying given the assaults on privacy that have been occurring.

Speaker F: I suppose everybody says that. You won’t find a public official who won’t say he’d like a bigger budget, but I’ve been Information Commissioner for 5 years, and every year the granting aid I get from the Ministry of Justice for Freedom of Information has been reduced. I would like to break out of this. I think the Freedom of Information regime would be better administered if the Information Commissioner was recognised as an officer of Parliament and we drew our funding direct from the Treasury. I’m not pretending that would be easy. I’m sure they’re very difficult to deal with, but at the moment I’m at the bottom of the pecking order. Obviously prisons, the court service, the probation service— those are the priorities the Ministry of Justice quite rightly has, and funding the little old Information Commissioner is neither here nor there.

Speaker B: But we—

Speaker F: I think the system would work better, and I think we could save a whole pile of public money if more public authorities had, had the benefit of the work which the ICO, the Information Commissioner’s Office, does on the data protection side of of the business where we are adequately funded through notification fees, where we can do a lot of proactive good practice advice and guidance. You don’t get that in Freedom of Information. It’s a much more formal reactive process.

Speaker A: So what effect is this reducing budget having?

Speaker F: At the moment, the impact has not been too serious. Over the last 5 years, we’ve actually caught up with ourselves and eliminated a huge backlog, which was very worrying because I think the public authorities were thinking, well, let’s just say no because he’ll take some time to get to us. And that was the case. We’re now able to turn around most, most cases within 3 months, some of the more difficult ones 6 months, everyone getting a, a, at least an acknowledgement within within a month. That’s fine, but if my budget is cut back and cut back and cut back, you’ll begin to see those queues lengthening, and that’s when I think the system will become less effective, when public authorities get back to their old ways.

Speaker A: We’ve seen in Australia the new government coming in and just sweeping away the Office of Information Commissioner.

Speaker F: Is that a fear lurking in your mind, or Well, I just want to make sure that if it happens, everyone is alerted and can make a hell of a row. What happened in Australia was a coup, and before anyone realised what was happening, it had happened. I have no evidence to believe that anyone in the UK plans that, but I think it’s a well-known fact that governments regard the Freedom of Information process as a bit of a pain. Although, to be fair, this government is very very enthusiastic about open data and the proactive publication of more information, and that’s going pretty well. But I’m sure that the mandarins would like to have the process rather more under the thumb of the Cabinet Office, and I don’t intend to allow that to happen.

Speaker B: Well, let’s hope not. This is Password with Peter Warren on Resonance FM, and after this on Wednesday, you can hear Kitchen Magic. Time. The Organ presents the other rock show after our Friday edition. Now, the latest unemployment statistics show the number of people in jobs is at an all-time high, but if you work in technology, chances are that you’re male. Stats from the BIPB big data company show that 45% of the British workforce is female, yet in computer-based jobs, only 23% are women, and that’s down from 27% in 2013. The gender gap is getting wider. Does it matter? Well, it does to Anne-Marie Inmarfidion. She’s founded the STEMettes to get more girls into tech.

Speaker G: You need to change the perception. You also need to change their influences. So some of the women that have come to us that are role models that have now gone into industry come back and they say, yeah, when I was younger, I told my mom I wanted to study biochemistry and she said to me, what are you going to do with that? Or, you know, when I was younger, I had this person that said that and I trusted them and they said, no, no, no, if you do, that’s going to be really difficult. You’re going to get your hands dirty. So I just didn’t. I didn’t choose to do it. So it’s those kind of things where if you understand, knowledge is power. If you actually understand what it is, what’s involved, you choose a different path. I mean, the last one that we see a lot of is girls that are like, yeah, I want to be in STEM, I want to be in medicine, I want to be a doctor. And it’s like, okay, great, fantastic. You know, we need doctors. Why do you want to be a doctor? Because I want to help people. Okay, any other, you know, what I know is just I want to help people and I was good at science, so Miss said I should, I should go and do medicine. So okay, but in being good at science, if you want to help people, you could become an engineer, right? So we’ve got, um, just talking about them last week actually, 14, 4 14-year-olds in Nigeria who’ve turned a liter of urine into 6 hours of electricity. I know, right? And it’s like, how many people are you going to help by turning urine into electricity? Capacity, let alone, you know, being a doctor that treats one person at a time. And that’s not at all to belittle what doctors do, but if you’ve got the capacity to do that, if you knew— and some of them are like, God, you know, the same way you’re like, wow, they’re like, wow, forget being a doctor, I want to become an engineer. It’s like, of course you do, but did you know that’s what engineers did? No. So why would that be something that you want to try and do? So that’s the— those are the things that we often see with the girls when they come up.

Speaker A: What about the technology industry? How is that responding? All those men, how are they responding to the STEM-ettes?

Speaker G: So, technology industry has been pretty supportive of us. I mean, we’re going 2 years now with people coming to us that are interested in what we’re doing. Not to pick on Mark Zuckerberg, but you know, that you all look a bit like Mark Zuckerberg, you all look a bit the same, you know. What is it? Why is it that— do you have to be a Zuckerberg to do this, to do well, to get the computer science? You know, there’s something not quite up there. We’ve got more diverse judges and leaders and all these kind of things. And yet, you know, in, in, in the Valley, let’s say, or with the venture capitalists, you’re all guys. You know, there’s something up there.

Speaker A: There’s not something not quite right. And do you think it might be to do with the fact that a lot of these jobs are very highly paid, or entrepreneurs can, you know, they can go to all the venture capitalists in Silicon Valley and get millions and millions of dollars, millions of pounds, and people aren’t used to seeing women in those kind of really highly paid positions?

Speaker G: So I’m not sure if it’s about the pay necessarily. Um, yeah, I’m not sure it’s about the pay. I do think that it is easier for people of a certain— that look a certain way and that are from a certain background to walk up to a VC and say, you should give me the money for this reason, um, or you should just give me the money. Um, so I do think, I do think there’s a lot of that at at play. But I think it’s also about being lazy, you know, and just following what you’ve seen has been successful previously and just following that and kind of just going with the sure bet rather than being like, you know what, you know, we’re not— we’ve not seen many women around here before. You’re here. What are you doing? I mean, take your idea on face value and I mean, that’s what you’ve got is a great idea. We’re going to— we’re going to run with it. And so I think it’s— I think it’s a little bit— it’s a little bit of that.

Speaker A: Yeah, it’s an unconscious bias. And what’s next on the agenda for STEM-Eds?

Speaker G: So we’ve—

Speaker B: this—

Speaker G: we’re 2 in a month’s time, actually. Um, we’ve done workshops, we’ve done public events, we’ve done hacks, we’ve gone, we’ve traveled around, we’ve seen so many girls. Now what we’re finding is, as we’ve gone around and we’ve met these girls, there are some who are not sure, some who are on the fence, and there are others who have won big prizes. So others who’ve won Big Bang, who have been recognized, we’ve got Some 3 Irish girls that won Google Science Fair last year. You know, got all these girls who are superstars. I call them X-Men. They’re like X-Men, right? All around the UK. They are the only girl in their school, in their friendship groups, in their town, in their wherever that is super on it. Like, they’ve got it. They’ve been building. One girl has been running a music blog, and she’s under— she was 15, I think, when we saw her, so she was under 18. And in the music blog, in reviewing music on the internet, no one knows you’re a dog. So she’d been invited to all these concerts and all these gigs at over-18 venues, and it’s like, no, the person behind this website is actually a 15-year-old girl, believe it or not. And so girls like this who have gone over and above, either with an idea or with a skill set. And so what we’ve done is we’ve kind of rounded them up, and we’re going to have all the X-Men in one house under one roof over the summer holidays. And we’re going to have them spending time with entrepreneurs and spending time with STEM entrepreneurs with STEM-ettes as well, and have them building products, ideating together, working together, knowing each other, but also learning about what their options are for what comes next. And that’s not necessarily in an employment sense, but in a, you know, if you’ve got a great idea, if you’ve discovered a new bacteria, if you’ve done something like that, what’s— what are your IP options? What are your business model options? What do you want to be doing on marketing? Do you know how to set yourself to put it up online, if you’re going to code it yourself, you know, all these different things that there are to know, giving them that information, but also giving them that environment to think and to network with other girls and kind of understand what it is. And it’s come from the fact that we actually met one of the Irish girls before she won the Google Award.

Speaker B: Well, that was Ann-Marie in Mafidon, and the STEMettes are hacking this week in their half-term holidays at the Stephen Lawrence Centre in Deptford. Ann-Marie’s girl hackers, or what we call white hats—people who break into computer systems for fun, to improve them, or to point out flaws in code or security. Black hats are the opposite—criminal or terrorist hackers out to steal and destroy. And that’s what you’ll see in the film Black Hat, out this week in the UK, and by all accounts a well-researched, technically accurate rendition of a cyberattack on a nuclear power plant. We’ll let you know what we think of it next week. Visions of underwater worlds, fantasy game scapes, and 360-degree films will be materialising at the Bristol Science Centre this weekend at the world’s biggest ever virtual reality festival. Dan Page is the organiser, and he joins us on the line from Bristol.

Speaker C: Dan, what gave you the ideas for this event? Hi there, I’m having problems hearing you unfortunately.

Speaker B: Dan, hi, sorry about that. We were having a few technical difficulties here.

Speaker C: Can you hear me now? Dan?

Speaker B: Sorry, hello, can you repeat that please?

Speaker C: Hi, yeah, Dan, what gave you the idea for this event? Basically, I haven’t really seen anything sort of approach a virtual reality conference in the same sort of way. I haven’t seen anybody else kind of quite do doing something on the same kind of scale that we’re attempting to do. Basically, just the timing just seemed right. There’s quite a lot of different companies that are putting a lot of money into virtual reality at the moment, and it just seemed like something that we should do, really.

Speaker B: Okay, Dan, unfortunately, because of various different issues, we’re beginning to run out of time. What we’re going to aim to do is to get you onto the program next week and we’ll solve all of this. I apologize for this. Sure, no worries. Okay, all right then. Well, thank you very much. We will tell everybody about virtual reality next week. This is a virtual preview. Okay, all right. This is Password with Peter Warren on Resonance FM. And if you’ve just joined us, you’ve missed it, but you can find out more about technology and society at our website, Future Intelligence, and sign up for our regular newsletter. Password is

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00