Transcript: Hacking and irrational actors in Redfern

Back in February I spoke at the “Freedom of Information? panel held in Redfern by Recordkeeping Roundtable. I’ve previously posted the audio of my contribution. Here’s a transcript.

Recordkeeping Roundtable’s website has the raw transcript as supplied, but I’ve decided to edit it up a little to make it more readable. Enjoy.

Continue reading “Transcript: Hacking and irrational actors in Redfern”

Talking AusCERT 2012 and cyberwar on ABC Local Radio

My full output from the AusCERT 2012 information security conference has yet to appear. Stand by. But last night I did a half-hour conference wrap with Dom Knight on ABC Local Radio.

We spoke about the conference atmosphere itself, cybercrime, cyberwar, the risk of Cybergeddon (yes, I know), and the claim by Eugene Kaspersky that Apple is ten years behind Microsoft when it comes to security.

Not that Mr Kaspersky would ever, like, troll the entire planet.

What we didn’t talk about, really, was the two stories that have been published so far:

The audio is of course ©2012 Australian Broadcasting Corporation, but as usual I’m posting it here as an archive.

AusCERT 2012: What’s changed since 2011?

I’m currently on the train down from the Blue Mountains to Sydney, en route to the AusCERT 2012 information security conference on the Gold Coast, and I’m thinking about what stories might emerge.

Here’s what I wrote last year when, just like this year, I was on the ZDNet Australia team:

The feeling I get from scanning those headlines is that there’s always a lot of scaremongering but the threats often don’t materialise. Are the threats over-stated? Does pointing out the threats trigger an effort to counter them, thus defeating them? Is it all just a bit too screechy?

And over the last year there’s been so much talk of imminent cyberwar. Is that just this year’s fashionable scary thing on a stick? I intend to ask a few questions. And I’ll plug it again: Thomas Rid says we shouldn’t believe the hype.

I haven’t yet looked in detail at the conference program but will do so over the next few hours. What do you reckon I should be investigating?

[Update 16 May 2012, 0625 AEST: Changed second paragraph to emphasise that I am covering the event for ZDNet Australia this year as well as last.]

Why tweeting my movements isn’t a safety risk

[Update 2.25pm: Comments on Twitter have persuaded me to emphasise that the question here is specifically about “personal safety” only, not lame and replaceable possessions, and my personal safety at that. As the second-last paragraph says, the risk profile might not be the same for everyone. These are the choices I’ve made with open eyes.]

“How do you think that tweeting your day plans affects your personal safety?” asked Ravneel Chand a short time ago. Overall, I reckon it actually increases my safety. Here’s why.

Background first. Here’s today’s “daily plan” tweet which, like those on pretty much every other day, is tweeted shortly before I settle down to work.

Thu plan: Bump out Waratah Cottage; 1032 train to Sydney; lunch (where?); errand Newtown/Enmore; write something; evening TBA.

Later in the morning I mentioned that I’d be catching a later train. And then, just as I left the house:

Mobile: Cab, shortly, to Wentworth Falls; 1132 train to Sydney Central; train to Town Hall station; 1335 walk to SEKRIT hotel and check in.

Clearly the fear being expressed is that by knowing my movements some bad person could more easily do me harm. But let’s do a proper risk assessment. You start one of those by enumerating the risks, and then you look at how this additional information might change those risks.

Continue reading “Why tweeting my movements isn’t a safety risk”

So how should I cover Budget 2012?

I’ve commented on the Budget for Crikey every May since Labor took power in 2007. This year will be no exception. But what will I say?

In 2008 I criticised Rudd’s slow digital revolution.

Dig into Budget Paper No. 2 and there’s a frustrating lack of detail and commitment.

Of $4.7b promised for the National Broadband Network [this was the original 12Mbps fibre to the node policy], only 0.16% has been committed: $2.1m this financial year and $5.2m next for “establishment and implementation”. The remaining 99.84% — you know, actually building the thing — is all “nfp”. Not for publication. We’ll get back to you…

The rest? All. Too. Slow. And. Vague.

In 2009 I complained that the machinery of Australian government is as outdated as the steam locomotive and the electric telegraph in The Budget? How quaint! They’re just made-up, you know.

Here we imagine that once a year we can produce a Big List of Numbers that’ll cover everything our “modern” nation-state will need to deal with for the next 365 days.

We proclaim it Good or Bad for this or that self-interested sector of the community on the basis of a quick glance, a gut reaction, and the need to create a narrative that’ll attract an audience or justify a pre-existing political zealotry.

We pretend to believe numbers like “$20 million over four years” when only a tiny part of that might be committed in the coming financial year and the rest, still to be confirmed in the next Budget, is therefore nothing but wishful thinking.

The reality, of course, is that the world moves faster than this. We experience a sudden global financial crisis, and must immediately tighten our belts by … um … giving away $900 cash to everyone.

In 2010 I complained of More NBN vagueness, border control and cyber-safety re-allocation. It’s not a bad read, but I’ll leave you to click through to that one.

And by 2011 I was clearly over the whole thing, writing Ritual shenanigans, but hey, this is government.

Riddle me this. What is the actual point of the federal budget process and all the lock-up shenanigans that go with it when the biggest bucket of money related to the technology sector by far, that National Broadband Network thing, isn’t even on the books?

What is the point when the way that NBN money is being spent – and is it $26 billion or $36 billion or $43 billion or that $50 billion scare-number that Malcolm Turnbull pulled out of some random orifice and keeps repeating unchallenged? – it is all SEKRIT thanks to those magic words “commercial confidentiality”…

What is the point of this annual ritual – built on the assumption that we can publish a set of numbers in May that will, in this complex and rapidly changing world, still be meaningful six months down the track – when the government has to respond to changing circumstances? Such as urgently building a fibre-to-the-premises network? Or responding to a global financial crisis? Or starting a land war in Asia? Or handing to every taxpayer $900 because, um, oh, shut up stop asking questions and buy a new TV.

I went on about “$20 million in suck-up-to-Tasmania funding” and “Labor’s half-arsed internet ‘filtering’ policy” and “loud-mouthed entrepreneur Ruslan Kogan” and noted:

Just be aware that all of this could be changed in an instant, budget process or not, if a minister gets on a plane with the Ranga-in-Chief with a few numbers scribbled on the back of an envelope.

So, what the fuck will I end up writing once the budget papers drop onto government websites tonight? Especially given that my shoulder is “out” and I won’t be able to get it fixed until tomorrow afternoon — my birthday! — and I’m scoffing codeine? Suggestions please!