- The Strategist - https://www.aspistrategist.org.au -

Cyber wrap

Posted By on August 2, 2017 @ 13:02



It’s been a big week in cybersecurity. The twin giants of #infosec conferences, Black Hat and DEF CON, has just wrapped up in Las Vegas, and a DefCon Beijing beta event has been announced. The show-stealer was the open challenge, in which five different types of voting booths were left in a room for DEF CON attendees as a challenge. The first booth was hacked after 90 minutes, and the exercise demonstrated a number of poor security procedures, such as the default administrator passwords for the booths being unchanged and available online. They were not able to change votes, however. For a great write-up of the other keynote events and lectures, see here. In equally momentous news, yesterday marked the fourth anniversary of the launch of ASPI’s International Cyber Policy Center. Happy birthday, @ASPI_ICPC!

Russia has taken steps to pass a law that will ban the use of virtual private networks (VPNs) and other anonymisation technologies in the country. It will enter into force on 1 November 2017. Other legislation is set to come in early next year that will force messaging app companies to identify users by phone numbers by 1 January 2018. Edward Snowden, ex-NSA ‘whistleblower’ (and current Moscow resident), has publicly criticised the ban on VPNs, and noted it’s the second of such bans this week, with Apple reportedly removing VPN apps from its App Store in the Chinese market. While the exact cause of the removal was initially unclear, Apple has since released a relatively short statement taking responsibility for the removals, saying that the VPNs were not licensed under Chinese law. More than 60 VPNs have been affected so far.

Singapore’s privacy commission has proposed changes to the country’s personal data protection laws to provide mandatory data breach notification. Data breaches have remained topical elsewhere in the world, as Sweden’s nationwide motor registry data breach crisis has claimed the jobs of two Swedish ministers, Interior Minister Andres Ygeman and Infrastructure Minister Anna Johansson, and has saddled the prime minister with the possibility of facing a vote of no confidence. Data breaches have affected television as well. HBO’s internal databases were breached (again) and 1.5 terabytes of data exfiltrated. It’s not clear whether the data includes yet-unreleased episodes from season 7 of the hit TV show Game of Thrones, but written material from next week’s fourth episode has been released online.

Elon Musk and Mark Zuckerberg have had a public disagreement about whether we should welcome or fear our new artificial intelligence (AI) ‘overlords’. While Zuckerberg has described Musk’s concerns of an AI-led apocalypse as ‘irresponsible’, Musk has fired back that Zuckerberg’s understanding of the subject is ‘limited’. Commentators have suggested that it’s more about a difference of time scales, or a difference of branding, than a difference of opinion. In what might be a point for Musk, Facebook has gone back to the drawing board on one of its AI projects after two chatbots in the projects began communicating in their own language consisting of shorthand English strung together nonsensically, to humans at least.

A New York Times piece has outlined how China is aiming to become a leader in AI technology research and development by 2030, and how its spending billions of dollars to foster innovation. By contrast, the US has yet to create a national strategy for continued innovation in AI. There are programs and projects no doubt, like this week’s announcement that the US Air Force is looking at using AI to monitor Twitter and social media networks, but there’s an increasing risk that the US might find itself on the wrong side of the innovation offset.

Innovation remains high on the agenda for the Australian government. The Digital Transformation Agency and the Australian Public Service Commission are currently looking to find and place 250 cadets and apprentices in Australian government agencies to start off their brilliant careers in IT. On the senior side of the career spectrum, the Department of Defence’s chief information officer, Peter Lawrence, has come to the end of his five-year term after steering the department through a number of major programs and reforms. The Australian Communications and Media Authority will be conducting a review of the NBN and its 21 contractors and subcontractors by compelling all of the companies involved to provide data about why the NBN has been underperforming. And the South Australian government is allegedly introducing laws that would compel child exploitation website operators to provide their passwords so that law enforcement can access personal data held in their computers or personal clouds. The news has ignited some concern, though details remain scarce.

Adobe is killing off its Flash media player by 2020. Most have speculated that the reason for the closure is security, as Flash has been an infamous (and growing) source of many critical vulnerabilities. The move has been long predicted, as the functions that Flash provided have largely been replaced by the more secure and well-developed standards. Several major tech companies, including Microsoft, Facebook, Apple, Google and Mozilla have laid out roadmaps for how they’ll be moving on from Flash, and it looks like the change won’t be a big deal.

It’s been a good week for any ‘mooches’ looking for some free but good anti-virus software. Cybersecurity company ESET is offering a free 12-month subscription to its internet security service in partnership with PC Tech Authority Australia; it’s available here. Similarly, Kaspersky has begun offering a free version of its anti-virus software. In addition to improving the baseline security of users, one of the reasons the company is offering the software for free is that free installs of the software that encounter malware will provide more data points to improve Kaspersky’s threat-intelligence machine-learning systems.


Article printed from The Strategist: https://www.aspistrategist.org.au

URL to article: https://www.aspistrategist.org.au/cyber-wrap-175/

[1] #infosec: https://twitter.com/hashtag/infosec?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Ehashtag

[2] DefCon Beijing beta event: https://twitter.com/BreeJFowler/status/891828986254213120

[3] hacked after 90 minutes: https://www.usatoday.com/story/tech/2017/07/30/hackers-defcon-conference-exploit-vulnerabilities-voting-machines/523639001/

[4] see here: https://www.wired.com/story/best-black-hat-defcon-talks/

[5] @ASPI_ICPC: https://twitter.com/aspi_icpc?lang=en

[6] a law that will ban: http://www.zdnet.com/article/putin-bans-vpn-use-in-russia/

[7] force messaging app companies: https://www.engadget.com/2017/07/30/russian-censorship-law-bans-proxies-and-vpns/

[8] has publicly criticised the ban on VPNs: https://twitter.com/Snowden/status/891816123712372740

[9] Apple reportedly: https://www.engadget.com/2017/07/29/apple-pulls-vpn-apps-in-china/

[10] released a relatively short statement: https://techcrunch.com/2017/07/30/apple-issues-statement-regarding-removal-of-unlicensed-vpn-apps-in-china/

[11] More than 60 VPNs: http://www.bbc.com/news/technology-40772375

[12] commission has proposed changes: http://www.channelnewsasia.com/news/singapore/privacy-watchdog-proposes-mandatory-notification-for-certain-9068242

[13] claimed the jobs of two Swedish ministers: http://www.sbs.com.au/news/article/2017/07/27/swedens-data-breach-claims-ministers-pm-reshuffles-cabinet

[14] vote of no confidence: https://www.bloomberg.com/news/articles/2017-07-27/swedish-prime-minister-clings-on-to-power-as-cabinet-reshuffled

[15] 1.5 terabytes of data exfiltrated: http://ew.com/tv/2017/07/31/hbo-hacked-game-of-thrones/

[16] had a public disagreement: https://www.aspistrategist.org.au/aspi-suggests-52/

[17] overlords: https://www.youtube.com/watch?v=8lcUHQYhPTE

[18] time scales: https://arstechnica.com/gadgets/2017/07/elon-musk-mark-zuckerberg-artificial-intelligence/

[19] a difference of branding: https://www.theatlantic.com/technology/archive/2017/07/musk-vs-zuck/535077/

[20] gone back to the drawing board: http://www.ibtimes.co.uk/facebook-shuts-down-ai-experiment-after-chatbots-start-speaking-their-own-language-1632862

[21] communicating in their own language: https://code.facebook.com/posts/1686672014972296/deal-or-no-deal-training-ai-bots-to-negotiate/

[22] outlined how China is aiming: https://www.nytimes.com/2017/05/27/technology/china-us-ai-artificial-intelligence.html?_r=0

[23] by 2030: http://www.gov.cn/zhengce/content/2017-07/20/content_5211996.htm

[24] US has yet to create a national strategy: https://lawfareblog.com/dual-use-dilemma-chinas-new-ai-plan-leveraging-foreign-innovation-resources-and-military-civil

[25] using AI to monitor: http://www.ibtimes.co.uk/us-air-force-wants-ai-monitor-twitter-thats-pretty-exciting-technology-1632452

[26] wrong side of the innovation offset: https://www.aspistrategist.org.au/can-supercomputers-can-tell-us-third-offset/

[27] looking to find and place: https://www.itnews.com.au/news/dtas-plan-to-avoid-a-govt-it-brain-drain-469480

[28] come to the end of his five-year term: https://www.itnews.com.au/news/defence-cio-quits-469352

[29] why the NBN has been underperforming: https://www.itnews.com.au/news/govt-steps-in-to-stop-nbn-blame-game-469831

[30] allegedly introducing laws: https://tenplay.com.au/news/national/july-2017/Accused%20criminals%20to%20handover%20computer%20passwords%20or%20face%20jail

[31] ignited some concern: https://twitter.com/Asher_Wolf/status/890014961572864002

[32] the reason for the closure: https://www.darkreading.com/vulnerabilities---threats/adobes-move-to-kill-flash-is-good-for-security/d/d-id/1329472

[33] largely been replaced: https://blogs.adobe.com/conversations/2017/07/adobe-flash-update.html

[34] Microsoft: https://blogs.windows.com/msedgedev/2017/07/25/flash-on-windows-timeline/#oSoUy0Wbu5Gtaipg.97

[35] Facebook: https://developers.facebook.com/blog/post/2017/07/25/Games-Migration-to-Open-Web-Standards/

[36] Apple: https://webkit.org/blog/7839/adobe-announces-flash-distribution-and-updates-to-end/

[37] Google: https://www.blog.google/products/chrome/saying-goodbye-flash-chrome/

[38] Mozilla: https://developer.mozilla.org/en-US/docs/Plugins/Roadmap

[39] available here: https://www.eset.com/au/pc-tech-authority-offer/

[40] free version of its anti-virus software: https://eugene.kaspersky.com/2017/07/25/kl-av-for-free-secure-the-whole-world-will-be/

[41] provide more data points: https://eugene.kaspersky.com/2016/09/26/laziness-cybersecurity-and-machine-learning/