Talking Tasmanian goverment hack on ABC 936 Hobart

Yesterday the Tasmanian government was hit by a hacker.

Sp1d3r from the hacking crew S4t4n1c_s0uls got into a Debian Linux box and inserted his graphic into an email sent to state’s media.

I reported this for CSO Online.

S4t4n1c_s0uls has claimed responsibility for almost 100 website defacements this month, including sites in Brazil, Jamaica, China, India and the Philippines. Five Chinese government websites were hit, and one in the Philippines.

I spoke about the hack with Louise Saunders on ABC 936 Hobart, and here’s the audio.

The audio is ©2011 Australian Broadcasting Corporation, but it hasn’t been posted on their website so here it is. In return, I reckon you might choose to listen to Louise Saunders’ drive program some time soon.

R18+ computer games, finally, but little on cybercrime

Australia’s Standing Committee of Attorneys-General has been meeting in Adelaide these past two days. They’ve finally agreed to allow an R18+ classification for computer games. But I’m surprised to see they’ve said almost nothing about online crime.

In their Communiqué and Summary of Decisions [25kb PDF] they say:

R 18+ Classification for Computer Games

Ministers made a decision in principle, to introduce an R 18+ category for computer games. NSW abstained.

Ministers:

(a) agreed to take the Guidelines for the Classification of Computer games, as amended at the meeting, to their respective Cabinets

(b) agreed in principle, with the exception of the NSW Attorney General who abstained, that the Commonwealth introduce the proposed amendments to the National Classification Code to support the introduction of an R 18+ category

(c) agreed, with the exception of the NSW Attorney General who abstained, to commence drafting amendments to their enforcement legislation to reflect the introduction of an R 18 + category for computer games

(d) agreed that it would be desirable for classifications of existing games to be reviewed in light of the new classification Guidelines.

This leads to the interesting possibility that the federal government could legislate to create the R18+ category, but NSW could choose not to implement matching laws. The result would be that the games would be legal to sell everywhere in Australia except NSW.

A similar situation already exists for X-rated movies. The federal government passed the laws, but the states changed their minds later. So X-rated material is available in the ACT.

But as I say, there was precious little on cybercrime.

Continue reading “R18+ computer games, finally, but little on cybercrime”

Privacy rights for Australia, maybe, but where’s speech?

Early this morning, Australia’s Minister for Privacy Brendan O’Connor announced that the government will start a public consultation into whether Australia should have a statutory right to privacy.

The media release was emailed at 6.26am AEST, a clear sign that it was a calm, reasoned decision made as part of a long-term government strategy. Sorry? No? Read the release?

“The News of the World scandal and other recent mass breaches of privacy, both at home and abroad, have put the spotlight on whether there should be such a right.”

The Australian Law Reform Commission’s recommendation for such a law has been sitting on the table for three years now. But hey, something in the news cycle triggers a potential “announceable” and… disco!

Right then.

I’ve already written straight news stories today for CSO Online, Australia to consider right-to-privacy law and Watchdogs welcome Australia’s right-to-privacy move. I’ll be writing about the timing thing tomorrow for ABC’s The Drum.

Right now, though, I have one question. It’s a question I’ve asked before, but I was reminded by something Mark Newton said earlier this evening.

How come we don’t see such sudden action, ever, when is comes to giving Australians a statutory right to freedom of speech?

LulzSec vs Murdoch: the lessons, and what’s next?

LulzSec’s hack of The Sun and other UK websites belonging to Rupert Murdoch’s News International yesterday was one of the highest-profile infosec breaches in history. But will it mean anything beyond today’s news cycle? I suspect not.

(If you’re not up to speed on this, please read my initial summary for CSO Online or a shorter but fresher story for Crikey.)

As I thought about this overnight, and after chatting with Paul Ducklin from information security vendor Sophos, I came to the conclusion that despite all the media coverage yesterday nothing will change.

I wrote that up as an op-ed for CSO Online, Four lessons from LulzSec vs Murdoch.

We’ve seen hack after hack after hack, but civilisation has stubbornly refused to crumble. We’ve cried wolf a few hundred times too often. We’re experiencing what Paul Ducklin from Sophos calls “hack fatigue”.

We only hear about successful hacks, from LulzSec or anyone else, Ducklin told CSO Online. “They can crow about every time they have a success,” he said, “but you never hear about the sites they never broke into.”

And the idea that LulzSEc’s high-profile hacks will suddenly focus attention on organisation’s information security vulnerabilities? Bah. We’ve been flooded with media reports of high-profile hacks for the last few years, from NATO to Paris Hilton, Google to prime minister Gillard.

After all those stories we held urgent meetings, changed our ways, and put infosec at the top of the business agenda, right?

Yeah right.

So now what? I’ll put my money on LulzSec being forgotten until their next high-profile attack, or their arrest.

[Picture: Early this morning Australian time, LulzSec tweeted: “The Sun taken care of… now what about the moon…”, linking to that image (source unknown). Is it a hint? Or a meaningless distraction?]

Talking hacker arrests on ABC’s “The World Today”

While I was busy writing an op-ed on the LulzSec vs Murdoch saga this morning — and I’ll post more about that momentarily — I got a phone call from ABC Radio’s lunchtime current affairs program The World Today to comment on the FBI’s arrest of alleged Anonymous-connected hackers overnight.

The story is TransAtlantic arrests target hackers, and if you click through you’ll get both transcript and audio. You’ll hear me, as well as Patrick Gray, presenter of the Risky Business podcast on information security. The reporter is Sarah Dingle.

I’d be interested to know what you think of these arrests.

Patrick reckons they arrested nobodies.

This current batch of arrests will “bring to justice” a bunch of people who made no attempt to conceal their actions because they’re either technically useless or just didn’t care.

They’re “low hanging anons”.

But that won’t stop the mainstream media from portraying this as the establishment striking back at online troublemakers.

I reckon that while that may or may not be true, the computers the FBI has just seized will be handy evidence when it comes to tracking down other culprits. After all, their operational security has hardly been world class.

Talking LulzSec vs Murdoch on ABC 774 Melbourne

I knew as soon as I posted my CSO Online and Crikey stories about the hack of the News International websites including The Sun this morning that I’d be asked to do some radio spots.

If you missed the story, this morning I posted a screenshot of the fake story posted on The Sun.

Sure enough, this afternoon I chatted with Lindy Burns on ABC 774 Melbourne. And here’s the audio.

The audio is ©2011 Australian Broadcasting Corporation, but it hasn’t been posted on their website so here it is. In return, I reckon you might choose to listen to Lindy Burns’ drive program some time soon.

I also spoke with Bernadette Young on ABC Gold Coast, but my phone kept dropping out. I did record the audio, but it covered much the same territory. Would you like me to post it?