Speaker A: Welcome to Password on Resonance FM with me, Peter Warren. Today we look forward to a roller coaster inside your head as neurosis comes to South London. It’s the first fairground ride that’s powered by your own brainwaves. We review the West End play set in a future where sad old paedophiles act out their fantasies in totally lifelike virtual reality. And we talk to two top cybersecurity experts about the latest threats. Now, we’re raising money to keep Resonance FM independent and free from advertising, and we’ve got a very special smartphone to auction. It’s a Fairphone made using some conflict-free materials and in a factory with proper workers’ rights. Fairphones have been selling so well there are only a few left with the resellers. The Phone Co-op has kindly donated a handset and a pay-as-you-go SIM card, and it’s a dual SIM phone, so you can just insert your own, and there’s no need to break any contract with your existing phone provider. The Fairphone’s recommended retail price is £265, and you can start the bidding at £50. Just search on eBay for Resonance FM Fairphone, or to find out more about it, go to fairphone.com. Now we’re off to Barcelona, where the world’s mobile phone companies are holding their annual expo. Will Findlater from Stuff magazine joins us on the line to talk about the latest in handheld and wearable devices.
Speaker B: Will. Hello.
Speaker A: Hi.
Speaker B: How are you?
Speaker A: Yeah, very good. How are you?
Speaker B: I’m very well, thank you.
Speaker A: So Mobile World Congress, what is it?
Speaker B: It’s, uh, It’s the biggest expo set of mobile technology that happens each year. It always happens in Barcelona at the Fira Gran Via, which is a beautiful city to have it in, but you tend to spend all of your time inside just sort of checking out the booths and finding out what’s going to be big in mobile technology this year. Sort of the huge companies are there, and they will showcase their flagship devices for the next 12 months. And if you’re involved in mobile technology in some way, it’s a place you really have to be. So, yeah, it’s a pretty interesting show. It’s always got a few very sort of fascinating products each year.
Speaker A: All right, so you can be gadgeted to hell and back. So anyway, at any of these shows, a theme emerges, doesn’t it? So what was it for this year?
Speaker B: I think the— well, in addition to the themes around the general sort of move towards creating smartphones that are even more lifestyle-oriented, even more prettier and more jewel-like, the big thing for me I think is a big push behind mobile payments. We saw last year Apple was talking about Apple Pay. Apple Pay, which allows you to use your mobile phone, NFC technology built into an iPhone 6 or iPhone 6 Plus, to make payments on any NFC-enabled teller machines. So the idea is that you can just tap your phone to the PIN reader, and because you’ve got a fingerprint scanner built into the home button, it can verify that you are you and it will take the payment. Now we saw two other platforms emerge in Mobile World Congress. First was Samsung Pay, which uses some interesting technology that can also not just work with machines with NFC readers built in, these contactless ones, but theoretically at least any any machine that can read the magnetic strip in a credit card. It actually spoofs the magnetic identity of the credit card by some built-in hardware in Samsung Galaxy S6 and S6 Edge phones. So in theory it works with far more machines and far more shops. And also in addition to that, there was— Google announced its Android Pay system, which is much the same as Apple Pay. Not quite as interesting and different as Samsung Pay, but uses, again, standard NFC to make payments. So however you cut it, it looks like Apple, all of the big mobile tech manufacturers in the world are getting behind using mobile phones as sort of physical payment devices in some capacity, which is interesting. It’s putting even more importance into payments for, into sort of single mobile devices and what they can do for us.
Speaker A: It’s a bit of a sign of the times, isn’t it? I mean, basically our mobile phones are going to become credit cards. And the other really interesting thing is that they could also become jewelry, couldn’t they? There’s a trend towards them becoming absolute designer objects.
Speaker B: Absolutely. As you say, the last bastion of the big smartphone manufacturers that haven’t gone down really adopting high-end design and expensive feeling materials was Samsung. And it was always berated by the tech press for its devices feeling like they were worth less than they cost. Because the engineering was always absolutely solid, always high-end components in these devices, like the Samsung Galaxy S5, but the materials they used tended to be polycarbonate plastics. So you just didn’t have the premium feel compared to an iPhone, for example. This year with the Galaxy S6, they ended up putting glass, Gorilla Glass, on the front and back of this device. It’s got a machined aluminum frame which is very sort of watch-like in the quality of its manufacture. So they’ve realized that this is what consumers want from devices. Not only do they want high-end engineering, but they want something that feels expensive too.
Speaker A: But there’s also always going to be a battle, isn’t there? And that battle is form against function. I mean, the big issue that there always is is battery life, isn’t there? You know, the phone’s no good without a signal in it.
Speaker C: No, you’re not.
Speaker B: And that’s interesting because in the past, and this was something that Samsung executives were very keen to play up at their keynote where they announced the Samsung S6 and S6 Edge, was that in the past they’ve really been a very engineering-focused company. And they’ve never scrimped on functionality. They’ve always had devices where you could remove the back, replace the battery if you need to. They always have really big batteries as well compared to a lot of the competition. And they’ve had expandable memory. And actually, they’ve foregone all of that. They’ve, with the S6 Edge, it’s a unibody design. There’s no SD slot. The batteries aren’t removable. The batteries are also a little bit smaller because they’ve been so keen to make something that is an object of desire. Now, Samsung says that there’s absolutely no compromise to the battery life. This is for the device that’s going to run and run and run through various optimization technologies. But there’s no getting away from the fact that if the previous device had some functionality this one doesn’t in that removable battery, that means that not only could you, if you run out, you could theoretically replace it and keep on going again, But also, if the battery for some reason died permanently, then you could put a new one in there. Now, that’s not going to be the case anymore with the S6 and S6 Edge, and that’s very much through design considerations.
Speaker A: Well, Will Finlayter of Stuff magazine, thanks for joining us, and thanks for that glimpse of the future. Jewelry that will be powered up forever. Now, Jane Wyatt has the latest news from the cybersecurity front.
Speaker D: Europol’s broken up a botnet affecting 3.2 million computers. The police force worked with cybersecurity companies Symantec, Microsoft, and Anubis to dismantle the Ramnit network. A botnet is a collection of computers assembled by criminals who use their computational power for their crimes without the knowledge of the computers’ owners. Ramnit is the second botnet to be dismantled by Europol in the past few months. Months. So, Pete, that’s quite a triumph, isn’t it?
Speaker A: Yeah, I mean, botnets are a— they’re one of the biggest problems. It’s almost the anonymous part of the internet. Essentially what you’re seeing is lots and lots of computers that have a bit of malware, is the term that’s used, which is, you know, nasty software that is used to bombard websites and servers and take them down. And the amount of sophistication in these things is quite incredible. You can actually target huge amounts of traffic at the the computer or the server, all at the same time, and the poor old computer just collapses and says, “I give up.” Mm, yeah.
Speaker D: And in other news, the phone and broadband provider TalkTalk has revealed that hackers have stolen customers’ account numbers and phone numbers, and they’ve used the numbers to create hoax calls in an attempt to scam the customers into paying them money. Mark Zuckerberg, the founder of Facebook, has launched a new online application in his keynote address at the Mobile World Congress in Barcelona. Internet.org promises to make mobile internet access affordable in parts of the world that don’t already have good connectivity, such as Africa. A university researcher has found that 91% of Americans searching online for information about medical problems have details of those searches passed on to third parties such as insurance and marketing companies. Timothy Liebert at the University of Pennsylvania shows how this information can be used to deny people services if it’s suspected that they have an illness, and to work out their identity using fuzzy matching. That’s when companies overlay different sets of personal information to build up a complete profile of an individual. And Britain’s spy centre GCHQ is recruiting new cyber experts. They’re offering computer science students a 3-week summer school in Scarborough or Cheltenham and £2,500. Back to you, Pete.
Speaker A: Thanks, Jane. And now we’re joined very aptly by the security evangelist Martin McKay from Akamai, a company based in Cambridge, Massachusetts, although he works in Surrey. Martin, welcome.
Speaker E: Thank you. And obviously, as you can tell, I’m not exactly British in origin. I come from the US myself.
Speaker A: I’d noticed. We’ve just heard how police and security companies have brought down a botnet. How can we protect against botnets? What does it take to get rid of them?
Speaker E: To get rid of them is going to be very, very difficult. You’ve got to remember we’re looking at computers that have anything from the latest patch level that is available today to having— not having been patched, not having had their vulnerabilities taken care of for years. This is a common problem. We know that throughout Asia that it’s very low connectivity. We know that many of the people who own computers just don’t know how to even patch them. So there are going to be vulnerabilities that are years old that are going to persist, and that’s part of how botnets get into the systems, how they get into people’s computers, how they get into servers as well.
Speaker A: [Speaker:GUY_CLAPPERTON] And your company’s just joined the UK CISP, one of these other horrible acronyms that the technology industry so loves. It’s a body that reports and collates all the information about security breaches in the UK. How does that work?
Speaker E: Basically, it’s a public-private partnership. The companies that are dealing with CISP are actually providing some of the information, saying, here’s what we’re seeing. This is not giving whole database dumps of all the traffic we’re seeing, but actually the professionals talking to each other. So I will go on in the morning and look and see what sort of activity other companies are seeing and see how that relates to what I’ve seen, to see— to some of the security issues that I’ve seen., and I will provide feedback. If I have an answer to some of their questions, I will answer it. If they have answers to my questions, they’ll answer it. It also is a way for people who would not normally meet face-to-face to start building up an idea of who are their peers in other companies within the government, and it’s basically a way of us establishing credentials between security professionals without ever meeting, and it’s also a way for the government to give us feedback, give us information that they’re getting from sources we wouldn’t necessarily have access to at any other time.
Speaker A: It’s interesting, isn’t it? In a sense, the internet’s a bit like a great big sea, and you’ve all got these sensors in it, and you’re trying to pick up the sounds that are going on and seeing how dissonant it is.
Speaker E: There is a lot of that. There’s a lot of, “This is what I’m hearing over here. Is anyone else hearing the same thing?” And you can compare the patterns. You can compare some of the traffic, but also you compare what people have done, not just a signature, but the intelligence behind it. If I see something and I’ve figured it out, I can share that with other people who are in the same profession.
Speaker A: Now, Akamai, it’s one of those names, isn’t it? Everybody sort of thinks that they’ve heard of it. I mean, it’s been involved for ages in the movement of creative content around the web. What’s its special expertise in the realm of cybersecurity?
Speaker E: Well, we started looking at cybersecurity from the very start. We looked at what we do. We deliver about a third of the internet’s web traffic. So when you’re having that much traffic flow across your network, you have to have security as one of your core concerns. And we had always looked at security in this way, you know, as something that we had to do. And then we started seeing that we were helping defend companies from the attacks that were coming against them. You’re talking about the botnets. We can go back and talk about Anonymous. There’s been no problems finding people that are trying to attack companies around the world. When we looked at that, we realized that we were already being a security company. It was just a matter of making it official and starting moving the whole company in that direction. Last year we bought another company called Prolexic that basically was a security company from the very start, and between the security chops they had and what we already had, we’ve added a lot of the expertise and knowledge to make it so that we can actually protect people around the globe.
Speaker A: Now, let’s just very quickly pick up this thing on botnet. Distributed denial of service, yet another technology mouthful, but it’s been developing, hasn’t it? That’s a distributed denial of service attack is what botnets are very good at.
Speaker E: So this is where, as you said earlier, this is where you’re sending traffic to a site that may or may not be prepared to handle it, or you may be sending what’s called malformed traffic. In other words, taking and adding or subtracting things to the traffic that should be there and confuse the network if it’s not. And we’re seeing this just continue to grow and grow and grow. It’s up to, I think, about 320 gigabytes per second. I don’t know if I can put that in terms that an average person can understand, but Maybe about—
Speaker A: might possibly help. A gigabyte is a pile of A4 documents the size of Canary Wharf. So if you imagine that floating around, that’s a lot of mess.
Speaker E: I like to think of it in terms of the Library of Congress personally, but that makes sense too.
Speaker A: Right. And the thing about these sophisticated denial of service attacks now is that they’re actually not aiming to take things down. They’re aiming to degrade the service, aren’t they?
Speaker E: And to do that, they don’t necessarily have to be huge. They can do it with actually very small packets and not necessarily a lot of traffic because there are things they can do to make the servers on the backend work harder. So a lot of that’s aimed at confusing the systems, confusing the people who are defending them, and often it’s about hiding what’s really going on. So you may have a denial of service attack going on, but at the same time there’s fraud going against your backend and things like that where because the security team, because the fraud team are tied up with the DDoS, they don’t realize until it’s too late that the other activity is happening.
Speaker A: And that’s the other thing that you’ve been looking at, isn’t it? Because in a sense, the work that you’ve been doing on man-in-the-middle attacks, that’s the potential growth of a botnet onto a smartphone, and it’s also fraud, etc., etc. Tell us very quickly about that.
Speaker E: So when you’re talking about man-in-the-middle, you’re actually talking about either a proxy on the internet, or more often, something where they’ve installed software on your phone or on your computer that’s actually intercepting all that traffic that you’re sending out and doing whatever it wants. They could be taking that traffic and adding something to it or collecting your username and password for sale, or they could just be catching all of your banking credentials from those systems, or they could be using you as part of a botnet as well.
Speaker A: Well, Martin McKay of Akamai, thank you very much. Thank you for coming in. And we also have Matt here from CyberArk, the Israeli security company. Matt Middleton-Lale. Now, how is CyberArk different from Akamai? Hi.
Speaker F: So I guess, you know, CyberArk’s whole ethos is that we recognize that organizations are going to get breached. And then what we say is, okay, we know you’re going to get breached. What controls can we put in place to ensure that when you do get breached, we minimize the damage and disruption inside your organization. We effectively secure the most important assets and make sure they can’t be stolen.
Speaker C: Okay.
Speaker A: The latest research into the technology business puts Tel Aviv in the top 3 cities of the world for startups and innovation, and Israel is now one of the D5 top 5 digital nations. What’s driving this passion for new technology in Israel?
Speaker F: I think, you know, if you look at the culture in Israel, that they’ve always been very forward-thinking. I think it just fits in perfectly with their kind of whole ethos mentality, the way the culture has grown up through the— without going into anything political here, which we don’t want to do, you know, if you look at the kind of conditions they live in, shall we say, security is at the heart of the nation and it’s very important to them.
Speaker A: I see. So presumably they’re also one of these nations that is quite keen on listening to people as well. Where does CyberArk see the real threats to security in 2015?
Speaker F: So the threats aren’t changing. You know, what’s possibly changing is that the bad guys having access, easier access to tools and techniques to actually breach organizations. The reality is that we haven’t really moved on. So if you actually analyze the most high-profile breaches in recent times, they’re actually using quite basic techniques to carry out the breaches. You know, there’s lots of talk around zero-day threats, you know, things that can just be done which have never been heard of before. But actually, when you do the analysis, people have been using very old techniques to get into organizations. And typically the biggest threat is your staff. And that’s where you really need to put some focus quickly.
Speaker A: I mean, that’s a really interesting thing because as you say, the biggest threats, well, RSA apparently attacked by the Iranians. That was a human error. And as you say, A lot of the old techniques are just coming round and round and round again, aren’t they?
Speaker F: Yeah, absolutely. I mean, still to this day, phishing is one of the biggest, you know, one of the biggest threats out there. You can’t believe that your staff are clicking on malicious links. You know, look at a picture of a celebrity or whatever it may be, you know, that takes their fancy and they’re still clicking them in your organization. And the second they’ve clicked on it, the bad guys are inside.
Speaker A: Just a quick thing on that. When you say those malicious links, my producer’s much taken with the idea of steganography. Steganography. Is that what you’re talking about, a little bit of code buried in a picture that people don’t know is there?
Speaker F: It’s either that, exactly that, or it’s taking them to a malicious website. It may be taking them to something they believe to be an internal website, or it may be taking them to what they believe is their bank account, or whatever it may be. But it is ultimately just tricking them into going somewhere they weren’t intending to go.
Speaker A: And phishing, I mean, phishing is sending somebody an email that’s got some sort of thing that they might be interested in, or some sort of silly little catchline about it that you think is interesting, saying that somebody’s caught in some compromising position, something like that.
Speaker F: Yeah, there’s some pretty embarrassing ones which people have clicked on which, you know, I don’t think they want to get out into the public.
Speaker A: And obviously we’re not going to be given an example of that. Thank you very much, Matt. Also here in the studio, we have Professor Brendan Walker, who has a wearable headset that can literally transport you to another world. Created in the Thrill Factory, also known as Aerial’s design studio in Bethnal Green, the Neurosis headset offers a new kind of experience. Brendan, welcome to Password.
Speaker F: Hey, hello, good afternoon.
Speaker A: Now you’re going to explain how Neurosis works in words.
Speaker C: Well, Neurosis is actually a new fairground ride. The headset, the monitor, is only just part of that. So we can actually monitor people’s brain activity And also they’ll be wearing an immersive virtual reality headset, and they’ll be sitting on top of a motion platform which is being designed and created specially for the ride. And essentially we can monitor people’s brain activity, and we can create an immersive virtual world, we can create amazing music, and people will be transported and able to ride the very inner workings of their own brain patterns.
Speaker A: Do you— this is with a headset. I mean, I’ve actually done one of these things quite a long time ago, actually, when it was the computer company responsible for doing a lot of the special effects for Hollywood, where I actually flew through the Blade Runner thing. It was quite mind-blowing, and the chair was a big part of it.
Speaker C: Yes, now that the technology is becoming more ubiquitous, so the Emotiv headset we’re using is now only $300 or $400. And many universities, many home gamers are actually buying these headsets and experimenting for themselves. And the idea of Neurosis is to experiment when we marry traditional fairground language, traditional fairground rides with this kind of input device. What is the new breed of future fairground rides that can actually be realized with this technology?
Speaker A: So my brain reacts to what I’m seeing and hearing. The headset controls what I’m going to hear and see next.
Speaker C: Is that right? Absolutely. So I’ve been working with a sound artist, the mighty Jungulator. I’ve been working with a computer vision artist, and we’re creating a world which is quite abstract. It’s almost like a stained glass window. It’s like the Rose Window at York Minster, but imagine that in 3 dimensions and you’re flying through this. So I see it as a kind of cathedral to brain monitoring.
Speaker A: But does that mean everybody who plays on Neurosis gets the same experience, or does it differ?
Speaker C: There’s a certain set trajectory. It’s a 3-minute ride, very similar to a fairground ride, but the brain patterns of everybody creates a uniquely different experience. So part of the allure for riders is that if they’re not very excited, that the ride will become much more extreme, and hopefully we can push people to the very limits of what they’re able to or would like to experience.
Speaker A: So what about the after-effects of this? One of the problems with virtual reality has been that when people are wearing these virtual reality headsets, headsets, they feel a little disorientated. They can also suffer from this condition, which is that we always look up to see danger at a certain amount of times. It’s hardwired into us, and that gets cut off by these headsets, doesn’t it?
Speaker C: Absolutely, yes. And the technology, the Oculus Rift, which we’re actually playing with on this ride, does actually, can elicit a sense of vertigo or even nausea. And in fact, one of my research interests currently is vertigo and actually this disconnect between the visual, auditory, vestibular inputs and how we can actually play with that. And it’s actually quite an interesting challenge for theme park industries, which I work for Alton Towers and occasionally as a consultant and other theme parks. And as we move into this world where we’re creating mixed reality rides, mixtures of physical experience and virtual experiences. And I think these disconnects are kind of interesting to play with. And also they can kind of be useful if you can understand the disconnects and actually play with people’s sense of nausea. I think it’s actually— people quite like to experience unusual effects, whatever they might be.
Speaker A: Oh, well, I mean, that doesn’t mean, though, to say that you’re going to get the authentic feel of the fairground when you get made so dizzy that you actually are physically sick. No. Mike, so how did you get the idea for Neurosis?
Speaker C: So I’ve been working with, with theme park designers for about 10 years now, and the, the idea of the motion platform actually came from an idea I had for Thorpe Park for a hotel there where we’re going to develop a motion platform where when you sleep we could detect REM sleep. When I was going to replay very subtly the theme park ride you’ve been on during the day, so you’d actually be able to re-dream them during the night. But actually, the motion platform idea— Middlesex University decided that they would actually partner with me and actually make this motion platform. Another interest I have with horror films and looking at the effect of horror films on the brain— so all these different themes kind of crystallized around my invitation to take part in Future Fest, which is this future festival which is being put on by Nesta, which is going to be over the weekend of the 14th and 15th of March, when people can actually come down and experience Neuroasis for themselves.
Speaker A: Okay, is it just for fun or any serious applications of this technology? I used some of this very strange technology once in a research center which will go nameless, and that night I woke up with my leg straight up in the air, so it obviously had some impact on me.
Speaker C: Yeah, there are serious implications. I mean, there’s no denying that the Fairground has a tradition of presenting emerging technology so the, the modern population can actually actually ride the technological advancements of their era. But actually, the motion platform that I’m developing is going to be made open source and available to secondary schools to be able to build their own. The data gathering and manipulation I’m developing with the University of Nottingham is going to be available to other creative artists to be able to use data, medical data, in their own creative practice. So there are many repercussions that are going to come out of NeuroRacers.
Speaker A: Where can we try it out?
Speaker C: Everybody’s fascinated now. Well, if you go to futurefest.org, you’ll see the festival website. It’s actually in Vinopolis in London over the 14th and 15th of March. I’m going to be one of many people there. There’s George Clinton, there’s Vivienne Westwood, and, you know, there’s just a massive lineup. It’s a proper festival looking at the future of democracy, of money, of entertainment. So if you have an interest in technology and the future, then come to Future Fest.
Speaker A: Right, well, Professor Brennan-Walker, we will walk along. Thank you very much. Thanks for joining us. Thank you. Now, there’s a very different way to get transported to another world via new technology at the Duke of York’s Theatre. It’s a play set in the future where the internet is called The Nether, and that’s the title of the play. In The Nether, everyone can reenact their darkest fantasies without any consequences in the real world. One of the characters is a pedophile and claims he is saving the real world’s children by offering virtual victims to men who might might otherwise groom, seduce, and murder little girls and boys. It’s a chilling idea, and although the play is rather thin and poorly written, the notion that the digital world could offer new freedoms is very powerful. Libertarians started the internet, and there are still many passionate defenders of all kinds of filth, racism, homophobia online, because censorship is seen as the greatest of all evils. This is worth debating, and we’d love to hear your views. Later this week, I’ll be interviewing the director of The Nether. You can send your questions and points of view. Tweet @peterwarren with the hashtag #thenether, or if you prefer, you can email pwonthearadio@gmail.com. Perhaps you’ve been to see The Nether. We’d love to know what you thought of it as a play, as well as a philosophical concept. This is Password. With Peter Warren on Resonance 104.4 FM. And if you’ve just joined us, you’ve missed it, but we’ll be back next week. And you can find out more about technology and society at our website, Future Intelligence, and sign up for our regular newsletter. Password is made by Angel Media Productions CIC. Thanks for listening. Goodbye.
