Podcasts

News, analysis and commentary

UNCUT: AFP says Facebook putting "lives at risk"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

The following is a longer, uncut version of a story that appeared on the front pages of The Age and Sydney Morning Herald yesterday.

Facebook's woeful relationship with law enforcement bodies is hampering police investigations and putting lives at risk, the Australian Federal Police says.

AFP assistant commissioner and head of high tech crime operations Neil Gaughan will fly to Washington DC today for a high level meeting convened by the US Department of Justice in which senior law enforcement officials from around the world will discuss their concerns with the social networking website.

Both state and federal police have told The Age the company has been unwilling to provide police with the intelligence they need for investigations. They want Facebook to appoint a dedicated law enforcement liaison in Australia who can match user accounts suspected of criminal activity to physical Internet addresses, for example.

''This [current] situation could lead to loss of life, there's no doubt about that at all,'' Mr. Gaughan told The Age. ''It's just a matter of time.''

However Facebook doused expectations of such a hire in a statement issued to The Age. ''Facebook does not put [law enforcement] people in every country where Facebook has users; it's just not the way companies scale,'' the statement said.

A senior investigator with a state police service said Facebook was prepared to assist officers when someone's life was in danger, but otherwise ''they give you the bird,'' he said.

''They only comply to subpoenas issued by a US court,'' said the investigator, who did not wish to be identified.

Police services have also demanded Facebook's law enforcement guidelines document be brought into line with Australian law and legal terminology. Mr Gaughan said that in one case Facebook had ignored an Australian warrant because it was issued by a judicial officer rather than a court as its current guidelines require.

''Information was not provided and it slowed down our ability to... obtain a search warrant for a premises,'' Mr. Gaughan said. ''In this instance we still got the result but much slower than should have been the case.''

Facebook has recently faced criticism over the vandalism of tribute pages set up to honour the victims of crime. Pages dedicated to slain teenagers Elliot Fletcher, Michele Morrissey and murdered child Trinity Bates among others were defaced.

On Monday night Senator Stephen Conroy lambasted the site over its ''complete disregard'' for its members privacy during a senate estimates hearing, and the company is facing intense media scrutiny following the death of Sydney teenager Nona Belomesoff two weeks ago, who met her alleged killer, a man posing as a wildlife carer, via Facebook.

The trial of Melbourne man Ron Felicite, who killed his wife over her involvement with a man she met via the social networking site, has also made headlines and the company is weathering a grassroots backlash over controversial changes to its privacy policy.

''It's not only Australia where we're having these issues with Facebook,'' Mr. Gaughan says. ''I know it's a significant problem in the UK... what I'm hearing from my US and Canadian counterparts is this is also issue for them.''

Senior law enforcement representatives from the UK, USA and Canada will also attend the meeting in Washington on Thursday, which will be chaired by the US Department of Justice National Coordinator for Child Protection and Interdiction Ms. Francey Hakes.

Facebook's rival social networking site MySpace did have a dedicated law enforcement liaison in Australia, Mr. David Batch. He was made redundant last year following the site's decline in market share.

Mr. Batch, a former AFP agent, said he had worked closely with police. ''The only service I could provide was an intelligence service... but that was enough to keep law enforcement on side and happy,'' he says.

''Nine times out of 10, intelligence would be enough to get [investigations] over the line.''

Police can use such intelligence to locate suspected offenders and then to apply for search warrants to gain access to the suspect's computer, for example. But such intelligence cannot be used as evidence in a trial -- only evidence collected via the Mutual Assistance in Criminal Matters Act of 1987 can be used in court.

Under the complicated mutual assistance regime police requests for correctly formatted, admissible evidence are funnelled between the Attorneys General in each country.

Mr. Batch says a typical request via the mutual assistance act typically takes 6-18 months to be returned.

In a written statement Facebook said it works closely with the Attorney General's Department and the AFP to make ''our law enforcement requests as efficient and helpful as possible''. The company said it dedicated ''significant resource to Australian law enforcement relationship building and information processing''.

RB2: AusCERT presentation: Tor's battle against censorship

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this presentation you'll hear Tor project leader Roger Dingledine talking all about Tor. Who uses it? Why? What's it good for?

For those who don't know what it is, Tor is a free-software anonymizing network that helps people around the world use the Internet in safety, the official blurb says.

Tor's 1600 volunteer relays carry traffic for several hundred thousand users including ordinary citizens who want protection from identity theft and prying corporations, corporations who want to look at a competitor's website in private, and soldiers and aid workers in the Middle East who need to contact their home servers without fear of physical harm.

So if you're based in Iran or China and don't want the government being able to identify your source IP, it's a pretty handy tool.

But governments are cottoning on to Tor and making efforts to block their citizens from using the Tor network. Roger discusses the changes the Tor project has made to combat these government restrictions. It's a good talk and I hope you enjoy it!

RB2: AusCERT presentation: Tor's battle against censorship
0:00 / 55:44

RB2: AusCERT presentation: Cisco VP and CSO John Stewart predicts the future

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this presentation, Cisco's Vice President and Chief Security Officer John Stewart tries to pin down where we're going to be in 2012. More devices doing more things! Malware embedded in video streams! All sorts of funky stuff!

RB2: AusCERT presentation: Cisco VP and CSO John Stewart predicts the future
0:00 / 46:02

RB2: AusCERT interview: Google drops the ball

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this podcast you'll hear an interview I did with ZScaler's Michael Sutton. In it he expresses frustration that criminals are able to so easily manipulate Google's search results for trending topics.

Sutton claims that malicious pages linked to trending topics are rising through Google's rankings almost immediately. In other words, the bad guys have gotten good at SEO.

But if Sutton and his colleagues can identify these pages from outside Google, why can't Google detect them? It's not exactly short on resources or cash.

RB2: AusCERT interview: Google drops the ball
0:00 / 17:06

RB2: SPONSOR PODCAST: Microsoft's Steve Adegbite on avoiding a computing nanny state

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In the following interview, Microsoft's Steve Adegbite joins me for this interview about the potential for a nanny state operating system.

With all this rogue AV stuff floating about, the Microsofties are encountering a few fairly significant dilemmas on how to deal with this stuff. Should the OS only accept certain, known brands of AV? Well, then they're acting as a gateway and telling people what they can and can't run. Can't do that. What about a warning system like they did with device drivers? Well, that wasn't much good in the end because people just ignored the warnings.

So what can Microsoft do about this rogue AV problem?

RB2: SPONSOR PODCAST: Microsoft's Steve Adegbite on avoiding a computing nanny state
0:00 / 9:41

RB2: AusCERT podcast: Speed debate

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

What you're about to hear is the speed debating panel from AusCERT's 2010 conference.

A highlight of the conference, this year's panel was hosted by Australian media personality guy Adam Spencer. Panelists were: Max Kilger, Scott McIntyre, Marcus J. Ranum, Roger Dingledine, Alastair MacGibbon, Paul Gampe and Tim Redhead.

RB2: AusCERT podcast: Speed debate
0:00 / 62:15

AusCERT interveiw: Ben Mosse on vulnerability mitigations

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this interview you'll hear me having a quick chat to Stratsec's Ben Mosse about vulnerability mitigation in Windows. Cutting a long story short, he reckons measures like DEP and ASLR work quite well, and it's only a matter of time before more, similar protections are introduced.

AusCERT interveiw: Ben Mosse on vulnerability mitigations
0:00 / 6:44

IBM distributes malware-infested freebies at AusCERT

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Risky.Biz has confirmed IBM staff distributed malware-infected USB drives at the AusCERT security conference this week.

In a highly embarrassing admission, the company has sent a broadcast e-mail to all AusCERT attendees warning them of the security lapse.

"At the AusCERT conference this week, you may have collected a complimentary USB key from the IBM booth," the message reads. "Unfortunately we have discovered that some of these USB keys contained malware and we suspect that all USB keys may be affected."

IBM is not the first company to distribute malware at AusCERT -- Australian telco Telstra did exactly the same thing in 2008.

Risky.Biz confirmed the authenticity of the e-mail message with IBM.

For all Risky.Biz coverage of AusCERT, click here.

For Risky.Biz podcast feeds click here.

RB2: AusCERT presentation: Michael Sutton on next generation offline Web applications

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

The following is a recording of a presentation by Zscaler's Michael Sutton. The topic is Security risks in the next generation of offline Web applications. Basically the talk looks at persistent client side storage, as brought on by stuff like Google Gears and the Database Storage functionality included in HTML5.

It was one of the better talks.

RB2: AusCERT presentation: Michael Sutton on next generation offline Web applications
0:00 / 53:00

RB2: AusCERT presentation: Scott McIntyre says "get a grip"

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this presentation you'll hear Scott McIntyre talking about maintaining proportionality when dealing with matters of digital security.

Scott's the Chief Security Officer for Dutch ISP XS4all and serves on the board of directors for the Forum of Incident Response and Security Teams, or FIRST.

In this talk Scott argues that all the FUD out there is leading to over regulation. He also argues that CSIRT teams and incident handlers actually cause some security failures and that understanding the far reaching consequences to our actions is critical if we're ever going to have a safe Internet experience for the masses.

RB2: AusCERT presentation: Scott McIntyre says "get a grip"
0:00 / 31:33