Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassWord – 24th June 2015

PassWord – 24th June 2015

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker B: Hello and welcome to Password on Resonance FM with me, Peter Warren. The technology show that wrestles with the terrors and the trending in our ever more digital lives. In today’s show, the sound of one of the greatest dangers in our modern world. We have audio of a digital beast that is keeping politicians and scientists awake at night and could be turning many of us into unwitting criminals. The new network that some analysts are claiming is replacing the Silk Road, the notorious and now defunct criminal marketplace The company that is very deftly lifting your information from Facebook. And eScript, yet another new app, only this time it is one of those for those who want to see what students get up to. But first, you’re about to hear one of the most extraordinary sounds of the information age. Listen very carefully, because this is the sound of a digital soul in torment. An enslaved computer calling out to the master system that controls it as part of a criminal enterprise. This is the sound of what the cyber police call a zombie. A computer infected with malignant software that links it together with other computers to form a huge network called a botnet. A criminal development that is alarming politicians because these networks, sometimes made up of millions of computers, can be used to break the internet by sending huge amounts of targeted traffic to one particular place to overload the computer or website it is aimed at and bring it down. The computer giant Microsoft is one of many technology companies that are now hunting down botnets and trying to to cut their heads off. And as part of that process, they have sonified the activity that an infected computer makes when it calls out to the bot herders’ master computer so that they can home in on it. The problem for the hunters is that bot herders know that the hunters are after them, so they cycle the control through all of the infected computers they have in their herd. If you’ve not patched your computer and don’t run up-to-date computer security programs, you could be housing the master system on your home PC.

Speaker D: So Black Hope’s been in business for about 14 years, and essentially we do big data analysis for security. And today, that’s become incredibly important because the traditional security tools are waiting for the attacker to break in, when today the attackers are just logging in. They have stolen credentials, or they’ve phished credentials of some executive or some administrator. And so only through these, this type of anomaly detection algorithms can you actually detect them early in the lifecycle before the exfiltration or ransomware appears.

Speaker B: So Lancope have picked up an attempt to create a very, very large botnet, yes?

Speaker D: Well, yeah, the— I’m actually not sure who detected it. I got sent an article that I was requested to comment on, and it’s basically the, you know, the common type of thing where a bot herder on the internet is collecting resources, and they, you know, they either use it to farm Bitcoin or they use it for denial of service attacks. Attack. There’s multiple reasons for them to have a big or bigger botnet. What botnets are is an assembly, a massive assembly of compromised computers all being controlled by one master. And this master can make those computers do all kinds of things. They can get millions of computers to overload a target, and that target may be a commercial service, that target may be your business, and they will continue to deny you resources until you pay a ransom.

Speaker B: Well, that was TK Kearney of Lancope, and Tom Gaffney of F-Secure tells us what that can mean to you.

Speaker E: Yeah, it’s ransomware. We’ve seen some significant cases of that over the last 2 years. It’s a really growing attack mechanism for hackers. It’s relatively low money and they’re getting quite sophisticated about it. We had some cases, particularly you might remember the Zeus Trojan which hit last, or two years, been around for a few years. That would deploy some software which would lock the user’s device and then show them some sort of local police warning saying inappropriate content has been found, pay 50 quid or whatever it might be to get it unlocked. More recently that has morphed into they’d identify if the user was part of a company, and therefore the user would see a message that said, actually, it will cost you several thousand pounds to unlock this device. So the hackers have got smart enough to recognize what type of user’s been infected.

Speaker C: Right, so what, they will actually temper the amount of money that they demand according to how much they think that information is worth to them?

Speaker E: Yes, they would, and they’re also able to customize it for different nations. For example, if you were a UK-based user, you’d see a warning message that had a Metropolitan Police logo on it. In the US, it would be the FBI and so on.

Speaker C: That’s very clever. So they actually know geographically where the computer is?

Speaker E: Yes, they do. I mean, that information is obviously available through the user’s IP address.

Speaker C: Okay, so what was done to them? Um, how do you stop one of these, um, these botnets?

Speaker B: Don’t they— they don’t sound as though they’re that dangerous.

Speaker E: I guess on the one sense, if you’ve been, uh, affected by this and hit by some, by the crypto elements of it, then Yes, there’s a direct, immediate impact to you as a user because you’ve got to pay money to somebody and your money’s been compromised. Then yes, there is the sort of other question. Some people might say, why should I bother if my, for example, computer’s just being, the resources are being used, how does that directly affect me? But you know, in the sort of wider sense, you’re effectively part of a criminal network and that network is being used to hack governments, corporations, And we all pay in some respect for that.

Speaker B: Well, that was Tom Gaffney of F-Secure. There you go, in the wacky world of the internet, you could have a criminal mastermind sleeping in your bedroom and never even know about it. Now, while we’re on the subject of criminal masterminds, according to experts in the US, a new computer network has been built to replace the infamous Silk Road, an internet system that allowed anyone to sell anything that they wanted. From children to drugs and people, weapons such as attack helicopters, and contracts to kill people. The Silk Road, said the police, was a marketplace for anything that anyone thought had a value. I’ve been on the Silk Road, and I have to admit that the sheer scale of it stunned me. You could pull down pages that describe drugs in incredible detail and discuss them in the same way that we’re more used to seeing wine growers discussing their products. Drugs were grouped according to strength and quality and sold accordingly. The details of bank accounts stolen from zombie computers are bundled into packages of hundreds and sold in batches. You name it, it was there. But last month, Ross Ulbricht, the 31-year-old who was behind the Silk Road, was put behind bars for life. And according to Robert Gonzalez of Red Lambda, a big gap was created in the internet market, and it’s now been filled by I2P, a carefully concealed new system for those of a criminal disposition. Robert, hello and welcome to Password.

Speaker D: Greetings.

Speaker B: Now greetings. Now Robert, what is I2P? Is it just a website for criminals?

Speaker F: No, I2P at its core, let’s bring it down to basics. Think enhanced peer-to-peer, think emule, think VUSE clients running across all these different peer-to-peer connections, making a connection together and running encrypted traffic from place to place. Now once that peer is active, you can host a site on it.

Speaker B: I see. So it’s like the technology that sits underneath Skype, or did sit underneath Skype at the beginning, where you’re actually just engaging one computer directly to another. Is that how it works?

Speaker F: Exactly, but far more clever.

Speaker C: Right.

Speaker B: So if it’s far more clever, tell me how it’s clever.

Speaker F: Your encryption in I2P is solid. In order to actually enter an I2P site, I need to start my I2P router. And that’s a Java— it’s a Java-based router. So once the I2P router is started, my encryption fires up and I’m pretty much secure completely across the network.

Speaker B: So what you’re saying is it’s super anonymous then, is it?

Speaker F: Incredibly so.

Speaker C: So, and what sort of things are you now seeing on I2P then?

Speaker B: What is it? As just like Silk Road, is it like the Silk Road that I described at the beginning of this piece?

Speaker F: Yeah, very much so. But, um, let me go into a little more depth there. Um, with I2P, you basically— sites are not up all the time. You follow a careful trail of breadcrumbs to get to what you want. I will start, say, in an IRC channel that’s an I2P. I’ll start looking for different sites. There’s a search engine, but it’s woefully inadequate. I then find my way to the I2P site, usually by invitation or tons of research. A lot of them, if I may add, a lot of Russian sites, a huge amount.

Speaker B: And they are quite incredible, these, aren’t they? I mean, I’ve seen ones that are actually selling women, which is— and it describes their bodies in graphic detail. And it’s actually quite shocking, isn’t it, to actually see something described in that way?

Speaker F: Well, not only do you have selling of women, but you’ll have selling of guns. I found actually a site which, interestingly enough, sells algorithms cryptography and foreign-grade encryption. And if you’re in the US, so basically say if I want— basically say if I’m in the US and I want to use encryption in, say, a custom homebrew remedy for email that I’m using, and I want to really go hardcore, there is actually a site on there where you can buy it.

Speaker B: Right.

Speaker C: It is actually—

Speaker B: it’s very, very shocking. But surely you can’t just stumble on this, do you? I mean, obviously believe that the people who are behaving in this way are deeply criminal. So what do I do? Do I type criminal enterprises into Google or criminal career into a search engine and then off I go?

Speaker G: Well, it’s a—

Speaker F: I would border that on a 50-50 split. If I’m a criminal, this is what I’m going to do. I am going to first I’m going to surf around Tor a little. I’m going to see what’s out there. Then once I know I have a good place for my I2P router after I’ve done my reconnaissance, seeing what rooms, what chat rooms are available, because you need to know where to go. You just, it’s not like in the old days with Merck where you would just fire up your chat and just say, hey, let’s talk about buying credit cards. You need to do research. Once I’m on the I2P chat, once I’m there, then I’m gonna stick around for a while. I’m going to look and see what rooms I can go to, what I2P sites are available and at what time. In fact, there’s a Russian who likes to sell credit cards, but he’s only up from 1:00 AM to 3:00 AM Eastern Standard Time. Otherwise than that, you’re not gonna get to his room. And because it is so under the table, because it is so underground, It’s hard to get there. Now, conversely, if I’m a journalist, if I’m trying to— a whistleblower— I’m trying to hide something from the government, this is where I want to go.

Speaker B: Right. Now, I mean, all of this is a bit terrifying, isn’t it? I always have a deep sense of unease when I’m going on to these places. Is there the potential to get your computer infected or anything like that, or do they actually look after their clients?

Speaker F: No, no, no, no, no, very much— just like with Tor, just like with Tor, when you go to an I2P room, you need to be incredibly careful because remember, this is a Java-based client, so it can easily infect your machine. But here’s the little caveat that most people don’t get. If you fire up your peer-to-peer software on most things, say you’re going around just downloading music, You’re behind your firewall. You have your antivirus on. You know you’re safe. On an I2P network, in order to truly get everywhere, to see as many active peers as possible, that firewall has to come tumbling down. Otherwise, you’re not going to see everything. And that in itself is a huge security risk.

Speaker B: You’re telling me.

Speaker C: You see, but you said that the authorities don’t seem to be aware of this technology at all, or they don’t seem to be awake to its dangers.

Speaker F: The authorities have an inherent misunderstanding of this technology, and quite honestly, in my experience, they have an inherent misunderstanding in most technologies altogether. Then throw in a Java-based peer-to-peer network where I can launch sites, they get very, very confused. They don’t know how to handle it. Plus, they— it requires immense, immense research. Which it seems like they don’t want to do.

Speaker B: So what can be done about it then? What can we do to stop this? Or can we do anything?

Speaker F: You can do two things. You can do two things. First of all, at the corporate level, at the corporate level, you need to safeguard your security. I mean, it sounds like verbatim over and over again, safeguard your firewall, make sure you’re minding the store. But it’s true. If I’m going to go in and steal your data, I will put up something like an I2P website. I will bring in my thumb drive. I will launch a small I2P router because I’m already inside your organization. I can move that data off and you will have no idea. Why? Because your people don’t necessarily tend to your firewall— to the firewall. They don’t. They’re not vigilant. Always assume that your threat is going to be from within. And your regular home— your regular home user, don’t automatically believe that just because you have the latest virus updates that you’re safe. If you’re on an I2P network and you’re daring yourself to go across, you’re going to have to learn to read. Don’t click links. If I’m in an organization and say I spawn an I2P site, okay, I’m doing it within that organization so I can move data. If I got there already, chances are I spearfished my way in.

Speaker H: Mm-hmm.

Speaker C: Robert, isn’t this—

Speaker B: isn’t this the thing? It’s a bit like that famous whack-a-mole idea, isn’t it? You know, just like the botnets that we were discussing on the program earlier. As soon as you take them down, they’re just going to spring up again, aren’t they?

Speaker F: Exactly.

Speaker G: There’s a—

Speaker F: in fact, in that discussion you were having earlier, there’s different forms of Zeus formed Citadel. Citadel already has two variations out there that are running around in the wild that no one knows about. But because people take a lackadaisical approach to security, they, um, it, it is whack-a-mole because someone’s going to spawn it up and try to be more clever.

Speaker B: Right. Okay. Well, Robert Gonzalez, thank you very much. That was Robert Gonzalez, a computer security analyst from Red Lambda. This is Password with Peter Warren on Resonance FM, and after us you can hear Kitchen Magic Time. And if you are listening to the repeat, then it’s the Organ Presents the Other Rock Show. Now, even in the legal internet, there’s not too much that’s not for sale. And one of the things that computer companies prize most is our personal information, whether it’s our date of birth or a predisposition for pizza. People want to know about it. And now Facebook, that repository of all that we say and do, would appear that it wants to open that information up for analysis, but only in the best possible taste and in a way that won’t upset us. Here’s Tim Barker of Data Sif to tell us how that will be done.

Speaker G: Well, I think in terms of privacy, one of the challenges is that for any consumer, it’s a dull topic. For anyone in the media, it’s a dull topic. So increasingly, what you see, you know, from Facebook and others is providing more control and more proactive ways that individuals can control what their data on Facebook So I don’t see that with income being incompatible with creating insights around data, as long as you can ensure, as we’ve done with Facebook, that what you’re providing is aggregate and anonymized. So there’s no way to identify an audience from that data.

Speaker H: So that to me seems to be a wide open— That’s an interesting point, isn’t it? Because the conversation that I had this morning was with the representatives of some of 140 of the largest companies, countries in the world. And what they were talking about was new moves that they’re going to be involved with to protect everybody’s machines because it’s perceived that it is necessary in the wake of things like Snowden, in the wake of preoccupations about privacy to make machines like our mobile phones, like our computers loyal to us because at the moment there is a perception that they’re loyal in a different number of ways. You know, they’re loyal to the operating systems of Google or of Apple and that is the primary loyalty. Then there is a secondary loyalty that they appear to have to governments and we seem to be quite low in the pecking order of the loyalties in our systems. Quite often what we also see is that criminals are actually managing to take over some of our material as well. So what they were saying was that you actually do have to make these things look as though they are loyal to you, and that is going to be a preoccupation. And so that is why I was saying, do you think we need to have a more sophisticated idea of privacy?

Speaker G: There’s a general view inside privacy that it has to be a zero-sum game, meaning for someone to win, someone else has to lose. What we’re showing here, for example, with Facebook topic data is it doesn’t have to be that way. I’ll be very explicit about what I mean by that. The challenge that one of the things that we can provide here is because we are not including any identifiable information, we can start to add demographics around that data. So you can understand, you can’t understand who that audience or individuals are, but you can understand representative data about an audience as a group. That additional data could never ever be made visible at an individual level. You know, the demographic details that we entered inside Facebook are entered by us on our profile pages. And so I think as part of that, what we need to do is shift the conversation from somehow privacy being a net zero, so someone has to lose for someone else to win, into a net positive. Where companies that can create services that protect the identity and privacy of people can also provide insights that are valuable to business in a way that is a net positive to both parties.

Speaker H: Which is an interesting point, isn’t it? Because people have actually said that there will be the development of companies, and they’re calling this privacy as a service.

Speaker G: Yeah, and if you Google it, you’ll find for a number of years, and something that we’ve adopted here is the principle of privacy by design. So this is a framework that goes back probably 10, 15 years around an approach to big data and technologies that means that you can— you don’t have to compromise in order— consumer privacy in order to create valuable insights from that data. So I do think that, as you mentioned, a more sophisticated way we need to move the narrative on to privacy as a service or privacy by design because clearly as an industry it’s important to all of us as professionals and as consumers. We want to make sure that we are delivering services that have a net positive for both.

Speaker H: I mean, that’s going to be what, you know, that’s the important bit to move things on. And one of the Next stages in that is there is going to have to be transparency from a number of organizations to say what it is that they do. You know, for example, Google is not necessarily a search engine organization. Google has now become an identity verification system and Google sells identity verification to the US government, for example, and is probably selling identity identity verification to the UK government too. So in terms of what companies are doing, then evidently people are going to feel a little happier if they know what it is that they are doing.

Speaker G: Yeah, I couldn’t comment on Google. I’m not as familiar with it as you are. But clearly trust starts with transparency, doesn’t it? And that way, as a foundation, the most valuable currency we’ve all got in a business is trust. So clearly controls that help Providing control to help consumers feel, or stay in control of their own data and information and own it is kind of a fundamental part of that.

Speaker B: Right, that was Tim Barker of DataSift. Now, someone else who wants to make more information available is Joel Newman, one of the three young entrepreneurs behind eScript, yet another internet application that aims to make a living from our data. Only this time, it’s our old schoolbooks and college essays. Joel and his colleagues want to make some money from from all of our old trials and tribulations.

Speaker C: Okay, now Joe, eScript. What is eScript?

Speaker I: A very good question. I think eScript is, in essence, a platform, a new platform, a bit, in the simplest form, a little bit like eBay, but for students, past and present, to buy and sell their lecture notes, essays, dissertations to one another, naming their price. So we’re hoping, one, it’s going to reward students who have done the good work, and it’s also going to be an excellent resource for students who potentially haven’t.

Speaker C: But surely what people are inevitably going to say is this is going to be used for plagiarism, that someone’s going to say, yep, I want that essay on Twelfth Night, and oh look, there it is, I’ll buy it off there, and that guy got a good mark for it.

Speaker I: I think that’s a simplistic way of looking at it. We’re hoping, you know, that that’s not how the platform is going to be used. Of course people can plagiarise anything from books, so it’s not, you know, it’s no new concept that someone could take information from somewhere and re-edit it and put it out as their own. However, what we’re hoping to do is give people a deeper insight into whatever it is they’re studying, so they might be able to talk to someone who has studied or done work on their course a few years later down the line and therefore have access to notes that they might not be able to get. They might be able to get some innovative thought on something that they’re already studying, that someone else has researched and been able to accumulate information, and from that their own ideas. We’re hoping, you know, that will be the catalyst for that.

Speaker H: But isn’t it good?

Speaker C: I mean, obviously then the really important thing is how do you find that innovative thought? If you’ve got this great big haystack of material from all of the other past and present students, then how is that going to be ranked? How’s it going to be rated?

Speaker I: There’s a couple of ways. First Firstly, students are encouraged to put their grade on, and graded work is, we would imagine, a lot more likely to be downloaded. However, every student puts a synopsis of their work, and the first page of that work is available to view for anyone. So hopefully they can get an insight into the sort of style that is being written in, the quality, the level, and from that decide whether they think it will be of use or not.

Speaker C: So will this be an incentive then to students to produce work that is highly marketable?

Speaker I: Well, we’d like to think so. I mean, if it can change the way students go in and encourage them to get in there and take more concrete notes, then, you know, we applaud it. I think we want to reward people who are putting in the work, and we also want to help people who perhaps have a lot going on, have other jobs, have time, and they’re sensitive to that, and they need to get as much information as they can as quickly as possible.

Speaker C: So what inspired you to to do this?

Speaker B: What was the motivation behind it?

Speaker C: Why did you suddenly think, ah, this is a gap in the market that we must fill?

Speaker I: I think honestly it came from when we were all at uni. There’s 3 of us who started this business, and I think when we were all there, we, we often trod the same path that everyone before us had trod, and we often thought, hold on a minute, if someone’s gone in and done that work and read all these books and cited all these brilliant sources, do I need to do the same thing, or I can— can I pick up from a point where they’ve left left off and turn it into something perhaps better or more conclusive than they have.

Speaker C: A lot of college lecturers though, they would say it’s very important for people to turn up and do their lecture notes, it’s very important for them to go through that process of finding those things themselves and that it’s the actual gestation of all of that thought in their minds that then results in the essays. Aren’t you cutting that process out?

Speaker I: Well, I don’t I don’t think we’re encouraging people not to go to their lectures. I think we’re encouraging them to find more sources and more information. So if anything, it will be adding to what they already have for themselves. So hopefully a student can take some notes and sell their notes and potentially buy some notes from someone else, and then together collectively have a lot more information than they might have done.

Speaker C: So this is up and working now?

Speaker I: It’s up and working now, yeah. We have over 200 documents on there now. We’ve got about 600 students registered. And we haven’t done anything at all really to tell people about it. So we’re hoping that it’s something that’s going to snowball of its own accord.

Speaker C: So of those 200 documents, are people actually—

Speaker I: people are downloading them, they’re using them. Yeah, we’ve had some really great comments. Obviously there’s still areas that we’re not covered in. It’s funny, we’ve been picked up in Coventry and Birmingham weirdly by a lot of students down there, so it seems word of mouth has spread, and that’s where the people at the moment That’s where we’re getting the majority of our downloads. Been up and running for a few months now. We haven’t really told that many people, but already we’ve got 600 students registered, over 200 documents on there. Clearly, as we go, we’re going to fill up those spaces and gaps with courses that we perhaps haven’t touched on at the moment. But to kick things off, we’re really pleased. We’ve got, we’ve got subjects of, you know, all descriptions that you could think of on there.

Speaker C: So yeah, there must be some Are there some academics out there or some people who are highly prized? Are you going to go and approach them and see if you can get their notes?

Speaker B: Celebrities, for example.

Speaker I: Well, that’s a good idea. Not something we’ve really thought of, but you never know. I mean, I think the point is we want to provide a resource where there’s a wealth, far too much information that anyone could possibly need, and from that they can pick and choose and cherry-pick the best things for them. So, yes. It’s definitely on the agenda if it could be.

Speaker B: Right, that was Joel Newman of eScript. You’re listening to Password on Resonance FM with me, Peter Warren, and I’m afraid if you’ve just tuned in, you’ve missed it because that’s all for this week. Password is brought to you by Future Intelligence, and you can find out more about the world of technology on our website, www.futureintelligence.co.uk. Password is an Angel Media production.

Speaker A: This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00