Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

20 July 2011

Beyond RIPA, privacy and hacking: the ramifications of the hacking enquiry by the UK Culture, Media and Sport Select Committee

Yesterday was the day eagerly awaited by all of us following the News Inc phone hacking scandal.
The UK Culture, Media and Sport Select Committee ('the Select Committee') had the difficult task of conducting an inquiry in a case that is still under police investigation. This can, of course, close certain avenues for questioning but could still have been an important forum to ask the key figures caught into the recent phone hacking scandal the key questions. Disappointingly apart from the very good lines of questioning by Tom Watson and Louise Mensch, the rest of the Select Committee failed to pin down the evasive, long-winded answers and the non-answers. But this was perhaps to be expected in many ways. The forthcoming judge-led inquiry and current police investigation will shed more light on the ins and outs of the scandal and whether the current state of affairs is merely the tip of the iceberg or as bad as it will get.


As a lawyer, I am, of course very interested to find out the legal ramifications of any breaches of RIPA 2000 and privacy which will be uncovered in the coming months.  Incidentally, the Guardian provides a quick guide to the RIPA regulatory framework on hacking. Additionally, the evidence given by the Murdochs reveals a wider issue of corporate governance at News International as many crucial actions (e.g. payments of large sums of money, payment of the legal fees of Mulcaire, alleged hacking) fell under the radar of those who are at the very top of the company. To what extent can such vague answers such as 'payments were not within my remit' (a la Rebekah Brooks) or 'I was not aware of this' (in Murdoch senior`s softer tone) or 'this is an interesting question but...' (a la James Murdoch) show that the senior executives at News International exercised the proper level of care required? As much as this scandal has revealed the inextricable links between the various institutions invovled, it has also highlighted that the phone hacking scandal goes much further than RIPA, privacy and Jude Law.

23 June 2009

A new blog is born: FBHive!!

CyberPanda is loving the new blog FBHive which deals with all things related to Facebook: the news, the rumours, and the controversies!! And this new blog has started with a bang as it has disclosed a major security flaw which enables any user to access the basic information of other users even when such information has been protected by its owner (via privacy settings). Amazingly, the blog reports that it took Facebook 15 days to deal with this issue!!!

The flaw has now been fixed but you can still see how it could have been done in the past by checking out the FBHive blog. Amazing footage!!! As a security expert from Sophos has noted, what is worrying is that such a flaw existed and that users` data have been at risk for an unknown period until the flaw was fixed. In addition, users do not whether their data have been 'hacked' into by any other user in this manner. So many privacy issues are raised by this latest Facebook related issue.

11 August 2008

Worms, Trojans and Malwares: A Bad Case of Indigestion

Sophos has recently reported that Facebook is under attack by a new malware which targets the all famous Facebook 'Wall.' The post by the hacker (who impersonates a friend of a friend) on the 'Wall' invites Facebook users to click on a link. This leads the user to a webpage which appears to be hosted by Google. In reality, the user is directed to a downloaded trojan.

The head of security at Facebook, Max Kelly, has re-assured users that the company is currently working on a fix for this worm. He goes, as far as saying that the company has 'identified and blocked the ability to link to the malicious websites from anywhere on Facebook.' However, he does not explain how this has been achieved.

Without further explanation, it is difficult to understand how the malware will be effectively blocked. In particular, given that the malware can navigate Facebook in the same way as the user can, detection is very much a tricky business, even for security experts. Currently, Facebook does a number of things to protect its users. Most of its measures are reactive (educating users by posting security notices) and part of the solution could be a more pro-active stance.

Jennifer Legio has made a number of sensible suggestions on how users can be educated to prevent such situations from arising. Some of her suggestions include using instances of compromise of the network as an opportunity to educate users effectively and developing “Secure Social Network Consortium” to increase user awareness.

Increasing user awareness is no doubt a good move but it will not completely answer the issue of hacking on social networks. The response to this should be an organic one: educational, technological and also, perhaps more importantly, regulatory (identification of the hackers, sanctions against the hackers). Effective sanctions include withdrawal of access to internet, withdrawal of access to social networking sites and a strike system (e.g. one strike you are included on a list available to similar websites, two strikes you are out). It will be interesting to see whether the response in this case will be solely technological or a more organic one.