Hillary’s mangoes, no NSA involved

[I was in a bit of a mood on Thursday, so when The Guardian broke the news that the NSA has been collecting the phone records of American citizens, my tolerance for political arsehattery was nonexistent. Calls for street protests? Bah! My countermove was to tweet a bunch of nonsense, which is posted here as prose.]

Mangoes by umstwitMaybe if we all run around like headless chooks, Mr Obama will say “Oh, sorry” and disband the NSA. And then Mr Obama will mount his trusty cyberpig and fly to the Moon, leaving behind a chemtrail of glitter and Bitcoins.

But look, headless chooks are the important bit. The more rushing around and screeching you can manage, the sooner the cyberpig lifts off. And quite frankly, Obama’s first term was a big disappointment as far as glitter showers go.

By comparison, I imagine that on weekends Hillary Clinton pumps out a steady stream of glitter. Like a Queen Ant, kinda.

Nyan Cat was DARPA’s prototype for that. DARPA’s main challenge was making it come out as glitter. When Hillary gets steam up, there’s no telling what it’ll be. Hummus, sometimes. Whipped cream.

One day it was just mangoes. Whole mangoes. Three a second, hour after hour. Secret Service guys took the whole weekend to clear the mess.

Then they had to figure out a cover story. Why were there mangoes smeared all the way down Pennsylvania Avenue? Eventually they decided just to tell everyone it was Madeleine Albright’s fault, so the press corps obviously bought that.

There’s a reason trams never took off in Washington.

[Photo: Mangoes by Flickr user umstwit, used under a Creative Commons Attribution 2.0 Generic license.]

Talking ASIO hack on BBC World Service

BBC World Service logoMonday night’s Four Corners episode claimed, amongst other thing, that Chinese hackers had stolen the plans to the new headquarters of the Australian Security and Intelligence Organisation (ASIO). It made global news, and as a result, I ended up being interviewed on the BBC World Service program World Have Your Say.

The 15-minute live panel discussion also included Four Corners journalist Andrew Fowler, one of the BBC’s journalists based in China, and a journalist from The New York Times.

I quite enjoyed the chat, but it also showed how new all this stuff is to a mainstream audience.

Here’s the audio of the full 30-minute program. It starts off with a discussion of the current situation in Syria, and then we start at about the 14-minute mark.

The audio is of course ©2013 British Broadcasting Corporation. The audio player is linked directly to the BBC’s copy of the MP3 file. If that ever breaks, let me know and I’ll post my copy.

Talking NBN on Radio Adelaide

Radio Adelaide logoThe National Broadband Network (NBN) has been a thing in the news for years. It’s less that four months until another federal election where the NBN will be a critical policy issue. And yet I still find myself explaining some of the basic concepts in the media.

Tuesday morning saw another such session, on Radio Adelaide‘s breakfast program with presenter Angus Randall.

I wonder how well we managed to explain the differences between the Labor and Coalition policies. In interviews like these, I try to present both policies fairly. While I have my own views on what I think Australia should do in terms of its broadband policies, it’d be completely unprofessional to turn such an interview into an opportunity to push my own agenda.

Here’s the full audio.

[Update 4 June 2013: The interview has been posted at the Radio Adelaide website, and at their request I’ve linked to that instead of embedding the audio here. Due to a quirk of how they’ve set up their site, I am unable to make that part of the iTunes-compatible feed on this website.]

The audio is ©2013 Radio Adelaide, of course, but as usual I’m archiving it here because I don’t believe it’s archived anywhere else.

Infosec at AusCERT 2013: the media coverage

AusCERT 2013 conference banner: click for conference websiteHere’s a list of the news stories I’ve found this morning that have been written about the AusCERT 2013 information security conference.

The theme for this year’s conference was “This time it’s personal”:

[The theme reflects] the growth in attacks and unauthorised disclosures of online personal information. Motivated by illicit financial gain, cyber criminals obtain unauthorised access to personal information, but more and more, we are seeing data disclosures being posted publicly by attackers for political motives, rather than financial gain.

Hence the theme will resonate within the information security community and remind us that the online environment provides opportunities galore to capture personal information; of the impact these breaches can have on the lives of individuals; and the importance of information security to prevent these attacks. AusCERT2013 will explore these issues and bring experts from Australia and around the world to provide insight and solutions to deal with these challenges.

Items are arranged alphabetically by masthead and then chronologically. If I’ve missed anything, please let me know. Indeed, I daresay that some more articles will be published on Monday or Tuesday, so if that happens I’ll update this post appropriately.

There’s a lot here for me to read, so if I’m going to write a reaction piece some time then it’ll be… later.

Continue reading “Infosec at AusCERT 2013: the media coverage”

AusCERT 2012 and the militarisation of cyberspace

AusCERT 2012 logo: click for conference websiteI didn’t make it to information security conference AusCERT 2013 this year. I’m about to read what’s been written and compile a list — but first, a reflection on what happened in 2012.

When I look back two years to what I wrote from AusCERT 2011, I’m reminded that we were just getting our head around the implications of the Stuxnet worm. Not only was malware being written by organised criminals, and we were facing an explosion of anti-banking malware and mobile malware, and looking ahead to when an angry child might deploy malware against their neighbours — we were now made well aware that malware was also being written by nation states with budgets in the millions of dollars and beyond.

But looking through the list (below) for AusCERT 2012, what jumps out is the emphasis on the militarisation of information security, as well as the emphasis in the scale of criminal activities. I won’t expand on that, because the conversation with AusCERT general manager Graham Ingram speaks for itself.

Articles from AusCERT 2012

Podcasts from AusCERT 2012

  • Patch Monday episode 139, “War talk dominates AusCERT 2012”, the first of two episodes based on material recorded at the information security conference. The overall theme is that infosec is becoming militarised. We no longer talk about “information assurance” but “defensive cyber operations”. Click through for the full list of speakers.
  • Patch Monday episode 140, “Cybercrime: it’s just too easy”, the second of two episodes based on material recorded at the AusCERT 2012 information security conference. AusCERT general manager Graham Ingram explains why cybercrime is here to stay, and F-Secure chief research officer Mikko Hypponen details a complex transnational criminal operation that saw goods bought fraudulently in Denmark being resold in Moscow, as well giving his views on hacktivism and the level to which antivirus companies should cooperate with governments.

Bonus Extra Video

After the conference, my flight back to Sydney was delayed. With the need to kill some time, this video was the result.

My compilation of reports from AusCERT 2013 will be posted later today. My compilation of reports from AusCERT 2013 is now online.

Australia’s Budget 2013 keeps us stuck in the past

[As it turns out, my planned Budget commentary for Crikey didn’t happen. I got up early in San Jose, read the budget papers and made notes, but then my as-yet-unwritten article got spiked. This is a quick and somewhat belated post based on my notes, not as polished as it might have been if written for Crikey.]

Photo of Budget 2013-2014 papers: click for official government budget websiteThe problem with Australia’s Labor government is that after having had One Big Idea for a bold new future in the National Broadband Network (NBN), they’ve come up with almost nothing anywhere else. This year’s federal budget was a dull plod. Again.

There was even one move which struck me as remarkably dumb: capping the available tax deductions for self-education expenses at just $2000 a year. Apparently that saves $500 million, and that’ll go to the schools — and schools are good for the kiddies, of course — but that’s half a billion dollars less for people to be able to keep up with a rapidly-changing work environment.

This strikes me as particularly stupid when so many of the people servicing the computers, networks and other technology that powers small business are often freelancers, as are so many web developers and designers.

Two grand a year doesn’t go far when it costs nearly half that just to attend the annual user conference for just one of your core software toolsets — more if you have to add airfares and accommodation — and the rest would soon be burnt up on a handful of reference books.

Back when I used to work in various management and staff development roles, I was told that any organisation that wants to advance its knowledge base should be spending at least 5% of its time on staff development. In a technology field, in my opinion, that should be at least 10%. That’s four hours a week, or a week or so every three months.

That still doesn’t sound very much, but it’d cost at least four times that capped amount. And that’s still not compensating freelancers for the loss of billable hours.

“Business and training groups have already said capping the expenses will stop employers from being able to offer staff new training initiatives. There were reports [the week before the budget that] the government would end up reversing the move, but the budget papers now state the change is locked-in,” wrote Patrick Stafford at SmartCompany.

“The announcement is sure to raise the ire of small business groups. Many business owners also use these deductions for short courses and industry-based training sessions.”

There’s two particularly galling lines in the budget papers themselves. First, the tax deductions are now only available…

…where these expenses are incurred in the production of the taxpayer’s current assessable income.

So you’re discouraged from educating yourself for the jobs that will become available even in the very near future. Why?

The potential for uncapped claims for a wide range of expenses provides an opportunity for some people to enjoy significant private benefits at taxpayers’ expense.

Orly? That’s a bit rich, given that vast sums already given to private schools. Or the “baby bonus” that people on quite significant household incomes still get for extruding another brat. That simply reeks of hypocrisy.

Continue reading “Australia’s Budget 2013 keeps us stuck in the past”