Google Search

Showing posts with label Australian. Show all posts
Showing posts with label Australian. Show all posts

Thursday, February 7, 2013

Would you like spam with that? McDonald's pinged for spamming by Australian regulator

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Macca's archesMcDonald's Australia has been told off by the Australian Communications and Media Authority (ACMA), which polices the Spam Act across all Australian jurisdictions.

The world-famous burger joint restaurant chain was deemed to have been spamming when it implemented a 'send to friends' feature on one of its websites.

You probably know the sort of thing I mean.

There's a web page you're enjoying; it contains a button labelled something like Tell A Chum; you click the button because it seems harmless enough.

You type in your friend's email address and, pretty soon, he or she receives some marketing blurb that mentions your name.

On the surface, it seems very similar to Liking something on Facebook, retweeting something, or emailing a funny YouTube link around.

Technically, however, these click-a-button email services work very differently.

Known as friend get friend marketing, this technique works by generating personal-sounding email, and it sounds as though it ought to be very effective for exactly that reason.

But it is spam, however you hold it up to the light. You give my email address to X, and X takes this as permission to email me. And that's an inference too far, at least for ACMA.

Indeed, as ACMA points out in an opinion piece written to coincide with the formal warning it issued to McDonald's, inferring consent in this way probably isn't going to have the net positive outcome you were hoping for:

One of the most common types of complaint we deal with comes from people who’ve received a marketing message from a business they've never heard of. They’re wondering how that business came to have their personal email address—and they're not happy! It often turns out that the complainant's email address was given to the marketer by a 'friend'.

This kind of practice is called friend get friend marketing — when your customers or website users promote your business to people they know.

[This sort of] marketing is a risky business. Not only does the Spam Act dictate that you must be sure that a recipient has given consent to receive your marketing messages, there's a strong chance you'll upset or annoy people with unwanted messages.

According to ACMA, "McDonald's has since removed the 'send to friends' facility from the Happy Meal website, and has given assurances about its future e-marketing activities."

In other words, the restaurant chain has stopped doing what it wasn't supposed to be doing anyway, and says it won't do it again.

In legalistic terms, at least, McDonald's certainly got off lightly.

(There's a small but separate backlash from some observers, lamenting what they see not only as spamming, but marketing to children to boot, since the 'send to friends' button was on the Happy Meal website - content specifically aimed at kids.)

Intriguingly, the ACMA article is attracting questions from electronic marketers, such as Rachel, who asks:

No one ever wants to send illegal email but the guidelines are so vague it is next to impossible to know if your process is valid or not. For example how would it be possible to gain consent from a friend of a friend without emailing them?

I don't think Rachel intended that to be a rhetorical question, but it certainly sounds like one to me.

It isn't possible to get consent from a friend of a friend without asking them, and one of the big ideas behind the Spam Act is to stop you emailing them to find out if they would like to receive emails from you!

So the bottom line is really simple: if you use email auto-generation tools, you must comply with the law.

And you might as well comply with common decency, because customers and prospects get cheesed off when you don't.

By the way, it's pretty easy to report spam (including SMS spam) to ACMA. For email, simply forward the message to the Spam Intelligence Database at report@submit.spam.acma.gov.au.

You may as well. There might not be a lot ACMA can do to reduce spam and improve behaviour, but without evidence they can't do anything at all.

Follow @duckblog


View the original article here

Thursday, January 24, 2013

Australian Defence Force Academy in stinkingly bad password breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Australian Defence Force Academy (ADFA) is the latest high-profile organisation to become embroiled in a data breach.

Students at the Academy apply both to the Defence Force and to the University of New South Wales (UNSW), which runs the academic side of ADFA's operations in Canberra.

It turns out that a hacker calling himself Darwinare breached the UNSW's servers about a month ago and sucked down a heap of SQL database records, including those of ADFA students.

He then uploaded the data to an anonymous dump site, where interested members of the public can acquire it at will.

Fast-forward four weeks to today, and the breach is starting to attract attention, no doubt because of the connection of UNSW Canberra with the Defence Force Academy.

Darwinare brag-art

It's certainly a bad look for both the University and the Academy.

It's not the end of the world, fortunately. No juicy Defence secrets such as troop movements, aircraft plans, coastal patrol schedules, or weapons purchases have been revealed.

And UNSW did the right thing, candidly explaining the breach to those affected the day after it was reported. The breach included student ID, full name, email address and date of birth; similar data about staff was dumped, too.

Nevertheless, it shouldn't have happened, and there can be no excuses.

Worst of all, the data dump reveals that UNSW was storing usernames and passwords for at least one of its computer systems in plaintext.

To be fair, these passwords were meant just for initial login, and were therefore expected to have a short life. But passwords should never be weak or guessable, or, for that matter, stored in plaintext. And the algorithm for generating the passwords in the dump is like a timewarp back into the 1970s.

They are all just seven or eight lower-case letters long. Many are repeated. All are meant to be pronounceable - surely an unnecessary step for a password that is intended to be typed in once and then changed - which leads to a conspicuous lack of randomness. Only a small set of digraphs (two-letter pairs) is used.

That produces some comic results. One percent of the passwords, for example, end in -poo, making them rather sadly self-descriptive.

Make sure this doesn't happen to you.

Harden your web services! Bring your password handling into the 1990s, if not actually the twenty-first century! Do it today!

Thanks for listening.

Follow @duckblog

Do you run a web server at home, perhaps for friends and family, or even just for fun? How well protected are you?

Why not try our free Sophos UTM Home Edition?

You get a web application firewall, web and email filtering, IPS, VPN and more for up to 50 IP addresses.

Turn that spare PC into a full-on network security appliance!


View the original article here

Wednesday, August 24, 2011

Australian bomb hoax suspect tracked across internet and arrested in Kentucky, USA

Facebook logoOver 30,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest internet and Facebook security threats. X

Twitter logoHi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats. X

For the last two weeks, the media in Sydney, Australia, have been fascinated with a police investigation into a most peculiar crime committed in one of Sydney's most prestigious suburbs.

If you've heard the name of the victim, Madeleine Pulver, you've probably heard the story behind the crime.

Imagine the scene.

Pulver is a final-year school student who will sit her school-leaving exams at the end of the year. She's studying at her parents' home in top-of-the-market Mosman in Sydney's Lower North Shore on the afternoon of 03 August.

A man clad in a balaclava and carrying a baseball bat bursts into her room and chains a plastic box to her neck. He puts a lanyard round her neck with some printed documentation and a USB key attached to it. Then he vanishes.

Pulver looks at the printout. She reads these words: "Powerful new technology plastic explosives are located inside the small black combination case delivered to you. The case is booby trapped. It can ONLY be opened safely, if you follow the instructions and comply with its terms and conditions."

The printout continues by saying, "You will be provided with detailed Remittance Instructions to transfer a Defined Sum once you acknowledge and confirm receipt of this message." A Gmail address is provided for future communications.

In the curious grammar used these days by New South Wales (NSW) Police on charge sheets, a whole battery of crimes have just taken place: aggravated break and enter with intent to commit a serious indictable offence; demand property by force with intent to steal; kidnap.

Hats off to the NSW cops. They've put in the investigative work on this one, identified a suspect, tracked him to Kentucky, and had him arrested in the USA. Now they'll apply to have him extradicted back to their jurisdiction.

The investigation makes a great story, too, and you can read it online thanks to documents tendered in court to prepare for the suspect's arrest in Kentucky.

Here's the brief version of what's claimed so far.

* Trace the PC used to create the Gmail account mentioned in the extortion message to Chicago airport.

* Trace all subsequent uses of that email account to a small town on the NSW Central Coast. Get CCTV footage from the vicinity.

* Identify a Range Rover of an identifiable vintage arriving and leaving at the right time. Check NSW vehicle registrations for vehicles which fit the age and the location.

* Cross-check the name of the closest registered owner againt recent border control records.

'Ello, 'ello! The owner of the perfectly-placed Range Rover flew to Chicago shortly after the crime. Then he flew to Kentucky.

* Move on to credit card records. The owner of the Range Rover also made purchases at an office supply store and a sports shop on the Central Coast about a month before the crime.

* Check with the shops to see what he bought in those transactions. Hmmm. A USB key. A baseball bat. [Note: baseball is a minority sport in Australia, like cricket in the USA.]

* Check whom he'd remitted money to in recent years. Ha! A woman with the same surname living in La Grange, Kentucky. Find that house up for sale.

* Get the Kentucky cops to drive by. Spot a bloke hanging out behind the house looking at least somewhat similar to the guy who boarded that Chicago flight, owned the Range Rover on the Central Coast, and bought the baseball bat.

And that was enough for the Kentucky court. The suspect was arrested and taken into custody.

In today's society, most of us leave digital breadcrumbs wherever we go. When the cops can use this information appropriately, as they have done in this case, most us us agree that this amounts to a good result.

But there are three important issues this brings to the fore:

* This isn't a cybercrime case. It's a case of person-on-person crime involving intimidation, extortion and a bomb threat. Yet much of the investigation has required cyberskills by the investigators.

So when you read that the cops are being given more money "for cybercrime", don't expect them to start busting pure-play cybercrooks such as spammers and scammers immediately. Almost every modern crime has a cyber-element.

CSI* This didn't play out like it does on CSI or Hawaii-Five-O. There, the cops get results in seconds, where satellites orbiting directly overhead can mysteriously get clear images of vehicle registration plates from low angles, and where warrants magically appear at all hours of day and night.

There are many hoops which the cops have to jump through to be able to pursue an enquiry of this sort - a due process which means they can't always and immediately get access to anything they want.

And that is exactly as it should be. Most of us are law-abiding, and our privacy and security is too important to be eroded merely to make the Orwellian nonsense of Hawaii-Five-O into a reality.

* Pure-play cybercrooks don't play by the rules. They don't have to show due cause to retrieve information from immigration. They don't bother with a warrant before they install surveillance software on your PC. And they don't leave an obvious trail like the apparently inept suspect in the Pulver case.

Of course, there's a fourth matter, too:

* All the evidence so far is circumstantial, and the suspect is innocent until proved guilty beyond reasonable doubt.

In a case which is as perplexing, and which has provoked as much media commentary and as much speculation as this one, it's important to keep that in mind.

Now you've heard the story, stop and think how much this suspect gave away without intending to.

Think about how much you give away - for example on social networking sites - entirely willingly.

Having just the tiniest amount less fun online can make you enormously more secure.

Follow @duckblog

Tags: arrest, bom hoax, Cybercrime, kentucky, law enforcement, madeleine pulver, mosman, nsw, pulver, sydney, usb


View the original article here