Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, November 03, 2017

Security, the Internet of Things and The Future of Humanity

I don't know about you, but security issues with digital devices, websites and apps both worry me and render me feeling a bit lost and as if we're always going to be fighting a losing battle with hackers and fraudsters. There are stories in the news every day about a data hack with consumer data being stolen, being locked out of personal accounts, having our laptops being held to ransom and more. It's very worrying as to how vulnerable we can be. And this isn't necessarily through any fault of our own.

As a consumer, we have little control over what happens on the server of the service we're accessing. So even if we're taking care with out passwords and login details, if the server is hacked, we're still vulnerable. Add to that the plethora of connected devices on the market such as routers, health trackers, Amazon Fire Stick, Google Home, Smart Meters and you see the problem is even bigger than just dealing our phones, tablets and laptops. Much of or town and city infrastructure is also connected such as the Oyster Card system on London's Underground, connect street lighting and traffic lights, CCTV cameras, speed cameras and much more besides. This part of the technology industry is only going to get bigger.

Fortunately, there are some very smart people working very hard indeed to help keep us and our digital lives safe. One of those people is David Rogers, my go to guy on all things mobile security. He writes in a post he's written today,
"We know that regular software updates, whilst a pain to establish and maintain are one of the best preventative and protective measures we can take against attackers, shutting the door on potential avenues for exploitation whilst closing down the window of exposure time to a point where it is worthless for an attacker to even begin the research process of creating an attack." 
That makes me feel marginally better about the tedium of seemingly endless updates to apps and software. It also shows us how important it is to keep these things up to date.

But keeping these things up to date, secure and safe is not a trivial task. It's complex and you're likely dealing with a supply chain rather than a single company. I imagine it could be quite daunting for a start-up or a small company.

If you're a developer of software or hardware or commission software or hardware or are generally interested in these things, especially in relation to the Internet of Things, then you would do well to have a gander at David's post, 'The Future of Humanity Depends on Us Getting Security Right with Internet of Things' and check his list of resources and further reading. He really is expert in this area. And I don't think he's underplaying it when he says that the future of humanity depends on it. With all the connected equipment in hospitals, schools, banks, energy companies, airports, transport networks and more, these are all vital and largely invisible parts of our lives. It's only when they don't work that we feel it and the impact can be truly dreadful, and indeed, life threatening.

I, for one, am reassured that there are lots of people in different areas of the business looking at this, not in silos, but together to come up with the right solutions and to keep coming up with solutions as this area evolves and grow. And if you're a youngster thinking about what career you might go into, I'd say that you'd be fairly sure of a solid and lucrative career by specialising in cyber security.

(Day 3/30 NaBloPoMo done.)



Wednesday, October 26, 2016

IOT, Connected Devices and You

I thought the Internet of Things was supposed to make life easier and simpler? Just ask Alexa (Amazon Echo) to turn on your music, add things to your shopping list and order them for and even tell you a joke. There are adverts on TV suggesting we turn our homes into smart homes so we can monitor our energy usage. We're encouraged to monitor our fitness with Fitbit devices and Apple Smart Watches. There's everything from a connected toothbrush to make sure you're brushing your teeth properly to a connected babygro that monitor your baby's heart rate and other vital stats.

Turns out we're just making it more complicated than ever - security being the thing about all this stuff that feels the most complex to me.

You've probably already heard that the DDOS attack that put out a whole bunch of websites last week was caused by security weaknesses in connected devices or 'internet of things' allowing a massive botnet to be created.You may say, oh, that's not me. I wouldn't be affected by something like that! I don't have an Amazon Echo or a Nest thermostat or anything like that.

Except, you could be affected. It's not these fancy, high-falluting new gadgets that aided the attackers. The list of devices that were used to propagate the Mirai virus includes printers, routers and TV receivers. How many of us have those in our homes and offices and don't think twice about it? Hmm.

As Benedict Evans said in his newsletter last week where I picked up on this story (you can sign up for it here), "A network designed to withstand nuclear attack, brought down by toasters". He's not far off the mark there. 

I hope someone is working on a solution to help normal people get their heads round this stuff to make it easy to manage our digital lives. I'm already boggled by the amount of passwords, settings, app updates and other online admin I need to manage. I don't want more of this stuff. I want less. How about you?

And how do we raise the profile of security issues like these to make them accessible to the general public and to make it a no-brainer to set-up and manage and lessen the admin burden?

More on the DDOS attack here and here.

Thursday, December 17, 2015

The Spy Who Scored Me - social media, gamification, data mining & Big Brother

A friend shared this video on Facebook earlier today and it raises (again) many concerns that I've had over the last year or two regarding social media scoring, gamification and how our data is used.


Games, gamification and addiction

I've thought for some time that the flashing lights on our mobile screens are as addictive as slot machines. There are many games that require little or no skill whatsoever but just requires you to push your finger around a screen and in return you get the dopamine rush of a virtual reward. Whether that's a reward in game points, being told you're a winner, it amounts to the same thing - a bit of your screen lit up, and in turn, parts of your brain lit up. A cursory search on Google brings up many articles and research studies about this addiction.

And this addiction is starting at a very young age - children are playing digital games from being toddlers and the addictive nature of these games is apparent when you see how a child behaves when they're told to stop playing or their device is taken away.

At the same time, games can be great fun and are a way for many people to relax. So it's not all bad, as long as we're aware of when it may be getting out of hand.

Social scoring

And then we come on to social scoring. There are several companies like Klout, PeerIndex and their ilk who score people base on their activities on social media platforms such as Facebook, Twitter and LinkedIn. I've never been much bothered about my score but these are the social media equivalent of our credit ratings which brands and agencies can use to target for 'blogger outreach' or product promotions. Indeed, I'm sure these scores now feed into our credit rating as well and also feed into job applications and more. I guess that's a feature of living in the modern world and I can't say it's something I'm particularly happy about, nor do I feel I can do much about it either.

Sesame Credit

China takes these two concepts to the next level. Sesame Credit, the brainchild of Alibaba and Tencent, is a combination of social scoring, credit scoring, gamification (or the addictive nature of gaming) to promote and encourage 'good citizenship'. In China, that means compliance, falling in line and not criticising the government or those in power. The video above explains it very well and the BBC covered it a couple of months ago. The Chinese seem to have taken to the system like a duck to water and freely share their current score. Although it's not currently compulsory to participate, according to the video and the BBC, it will be compulsory by 2020.

What about the UK?

Well, I don't foresee that there will be a compulsory system imposed here, but the UK government has been spying on us via our telephone and internet activity for the last 15 years and keeping records on millions of British citizens according to El Reg. I'm sure every government is doing something similar.

Oh, and don't forget that the advertising industry is busy watching us too. Check out The Secret Life of Your Mobile Phone video below and catch the stage show if you can. It's brilliant. There's an audio available of their show at The Hay Festival (£1 to download).

See also You are Your Phone on how the pattern of smartphone use is the pattern of the self.



Big Brother Is Watching You? You betcha. Merry Christmas!


Wednesday, November 28, 2012

I know what you did five minutes ago

Friend and fellow mobilist, Terence Eden, has just published a really interesting post ‘The Future is Now but not Everyone Knows it’. Well worth a read. This resonates with me on the privacy issues front in particular. I’ve been sort of aware of security issues around identity fraud, having your credit card cloned, about having your site or email hacked into. But it has never really felt real. It has always felt to me that these things happen to someone else, they’re things you read about on the news or memes that travel on twitter. And I sincerely hope none of them happen to me. But I fear that some of this stuff could become as commonplace as shoplifting or pickpocketing.

The reality is, that you usually give yourself a split second to decide on the convenience of clicking on something right now to get to a site or buy something or not and so we usually click. Who reads privacy policies, terms and conditions and what not? How do you verify a site is real and not fake? Convenience or immediate gratification usually wins out.

I’m afraid I don’t have the answers when it comes to data privacy and online security issues. But I do know that the mobile environment is dealing with similar issues around malware that the desktop world experienced ten years ago. Growth of mobile malware is huge and ‘it is now fully functional and mature’ to quote this article. There are holes in our smartphone operating systems that means smart, and probably not so smart, hackers can worm their way in to take control over a device or install a key-logging operation and from there, everything can unravel pretty quickly. The holes are often to do with the access rights that we actively give to app developers and also down to the access rights the handset manufacturer and network operator sets when they add on the 70 or so apps we have no control over to make our devices work.

And even if you don’t succumb to mobile malware, if you’re not careful with how you manage passwords, pin codes and privacy settings, you can still be vulnerable, as this wonderful video by Tom Scott demonstrates.

 

Wednesday, April 22, 2009

The Mobile Phone Security Challenge

Today sees the launch of a national search for designers to develop new ways of securing mobile phones against thieves and fraudsters, as research shows that 80% of phones contain data which can be used by criminals to access bank accounts, steal identity, or sell on personal data.

The Mobile Phone Security Challenge is offering a total of £400,000 to designers and technology experts to come up with new ways of securing handsets, the data they contain, and their future use as electronic ‘wallets’ when m-commerce technology is introduced in the UK.

The Challenge is part of Design out Crime, an initiative from the Home Office Design & Technology Alliance Against Crime and the Design Council.  The Mobile Phone Security Challenge is supported by the Technology Strategy Board.

Applicants will submit a tender outlining how they will approach the challenge and identifying any relevant experience they may have. Once selected by a panel of experts, the teams will be allocated money for research and development from the £400,000 fund, and spend six months developing designs and working prototypes in one or more of three key areas:

· Making mobile phone handsets harder or less desirable to steal

· Making the data stored on mobile phones harder or less desirable to steal

· Making future m-commerce transactions secure and fraud proof

They will produce market-ready applications which may include hardware and software for handsets, new services and other innovations, which will be showcased and promoted by early 2010, with a view to their widespread and rapid take-up by the market.

A recent survey found that 80% of people carry information on their mobile phone handsets that could be used by criminals to commit fraud - and 16% keep their bank details saved on their phone, yet only 4 in 10 people currently lock their mobiles using a PIN. Such data includes website passwords, bookmarks, emails, personal security data and locations/addresses on map applications.

The deadline for applications is Friday 22nd May. Short-listed applicants will present to the expert panel on Friday 27th June, and the four finalists will be announced on Monday 29th June. The teams will develop prototypes over six months involving a process of review and advice from the expert panel. Four prototypes will be showcased in early 2010. More details of the Challenge can be found at www.designcouncil.org.uk/crime.

Sebastian Conran, chair of the Design & Technology Alliance Against Crime said: “This challenge is the result of work undertaken last year when we engaged young victims of crime, police, mobile industry experts and designers to understand current and future issues regarding mobile phone crime.  The Alliance has prioritised five areas and is working hard to deliver insights that the UK’s design and technology sector can use to deliver innovative solutions to reduce the instances of crime and antisocial behaviour.  This is one of the early results of our work – there’s more to come.”

Previous advances in technology have led to unexpected new forms of crime; email heralded the phenomenon of ‘phishing’, ATMs precipitated the new crime of ‘card catching’ and online banking gave rise to ‘key logging’, used by fraudsters to track the input of secret passwords and account numbers. However, there are also many examples of technology being applied successfully to reduce crime – for example, British Crime Survey figures show theft of vehicles has reduced by 51% since 1997 as a result of improved security being designed into the vehicle, and an evaluation of houses built to the ACPO Secured By Design (SBD) standards showed that these experience 26% less crime than non SBD houses, and residents fear of crime is lower.

The Mobile Phone Security Challenge will be steered by a group of leading specialists:

· CHAIR: Simon Waterfall, Co-founder, POKE

· Steve Babbage, Security Technologies Manager & Group Chief Cryptographer, Vodafone Group R&D

· Mark Delaney, Director, Connect Design, Nokia

· Josh Dhaliwal, Co-founder, Mobile Youth

· Richard Martin, Business Security Consultant, APACS

· Joe McGeehan, Managing Director, Toshiba Research Lab and Professor of Communications and Engineering at the University of Bristol

· Dr Walter Tuttlebee, Executive Director, Mobile VCE

So that’s not bad then, a prize fund of £400k and will be supported to get to prototype and production stage. If this is your area of expertise, then I’d say it could be worth a shot.

I would like to see a woman in the steering group though. My hunch is that women have a very different response to security concerns than men do. I also believe that women and men respond differently to technology and that should be accounted for in the design process, but that’s one for another day.

Tuesday, July 31, 2007

Tuesday linkage 31 July 2007

I'm having a clearout of all the tabs I have open on firefox so here are a few links for you

Keep stuff secure with your eyes (and your mobile)
Oki Japan has developed software that brings iris recognition security to existing mobile phones. Of course the focus described is security and that's *great*. Can you imagine, no more pin number or password traumas. But I wonder if it could also be used for iridology, either now, or at some point in the future when the resolution improves?

Mobile and fashion
Or perhaps we're better off with a mobile 'colour me beautiful' type service, courtesy of the folks over at HP. It's still in prototype mode but I can see it taking off and is a nice takeaway if you've gone through the whole Colour Me Beautiful (or similar) process. Maybe this is what the fashion industry needs to help get them more mobile. I can't help thinking though that lighting is going to play an important factor as to whether or not this will be successful. In certain lights, it's very difficult to tell what colours clothes are exactly and I'm wondering if the camera can get round this or not.

Get the message right
ICSTIS is investigating anonymous text message services as they seem to be used for bullying and rather insidious messages which is not what they were designed for. There's a public consultation under way, so get in there quick to add your point of view. You can download the pdf http://www.icstis.org.uk/pdfs_consult/anonymous_sms.pdf here and the deadline is 7th September.

Meanwhile, Darla Mack, wishes SMS a happy birthday this week. It's 15 years old. Can you believe it?! I only started texting in 2000 so as much as I like to think I'm an early adopter for some things, maybe I wasn't an early adopter when it came to SMS!

Social media continues apace
Online social networking isn't going away. Via Twitter, I'm finding friends are unhappy about being facebook-less today (it's undergoing maintenance right now - but only affecting *some* accounts, including mine). But never fear, there's always somewhere else to go play and connect with folks like you. So if you're a teenager (I'm not) and you're into anime, avatars and the like, then join 8.5m other teens like you at Gaia. Ok, it's not mobile, but it's big and we need to be keeping an eye on this social media type stuff.

Monday, July 23, 2007

Monday musings

  • Bill Thompson discusses security risks in the new i-phone and the wider implications of a networked customer base and how the corporates need to adapt to our needs and not the other way round. I think he has a point but it's a challenge.
  • Any phone can be a credit card as the clever folks at Masabi has come up with a new way to manage secure transactions using your mobile phone using just 3kb of handset memory.
  • Desperate for the loo? Don't know where your nearest one is? Then help is at hand with Mizpee. Trouble is it only works in the US and I find it hard to believe they have every single loo in the US on their database. But hey, maybe they have. Anyone tried it?
  • User generated content, social media and how to make money from it. Well these were the topics tackled by the w2forum last week. Unfortunately, no-one had any definitive answers as it's still too early to know how best to monetise this area.
"Roy Vella, Head of Mobile Payments at PayPal, summed up the feeling in the room when he pointed out that none of the best-known social networking sites on the web, such as MySpace and FaceBook, were initially about monetisation, and that “the monetisation stuff” is only happening because there are so many eyeballs.
“You want to know how do big companies make money out of all those eyeballs” said Vella. “The answer is, I don’t think we know yet.”

Vella also warned brands that they would need to exercise caution if they were going to try to establish a presence on social networking sites, mobile or otherwise. “If you threw a party and a corporation showed up, how would you feel about it?” he asked. “It’s a new space, and we all have to tread carefully. The way to succeed is the way it has always been – to delight customers.”