Google Search

Showing posts with label World. Show all posts
Showing posts with label World. Show all posts

Tuesday, May 20, 2014

Keeping secrets in a world of spies and mistrust

Revelations of the extent of government surveillance have thrown a spotlight on the security -- or lack thereof -- of our digital communications. Even today's encrypted data is vulnerable to technological progress. What privacy is ultimately possible? In the 27 March issue of Nature, the weekly international journal of science, researchers Artur Ekert and Renato Renner review what physics tells us about keeping our secrets secret.

In the history of secret communication, the most brilliant efforts of code-makers have been matched time and again by the ingenuity of code-breakers. Sometimes we can even see it coming. We already know that one of today's most widely used encryption systems, RSA, will become insecure once a quantum computer is built.

But that story need not go on forever. "Recent developments in quantum cryptography show that privacy is possible under stunningly weak assumptions about the freedom of action we have and the trustworthiness of the devices we use," says Ekert, Professor of Quantum Physics at the University of Oxford, UK, and Director of the Centre for Quantum Technologies at the National University of Singapore. He is also the Lee Kong Chian Centennial Professor at the National University of Singapore.

Over 20 years ago, Ekert and others independently proposed a way to use the quantum properties of particles of light to share a secret key for secure communication. The key is a random sequence of 1s and 0s, derived by making random choices about how to measure the particles (and some other steps), that is used to encrypt the message. In the Nature Perspective, he and Renner describe how quantum cryptography has since progressed to commercial prospect and into new theoretical territory.

Even though privacy is about randomness and trust, the most surprising recent finding is that we can communicate secretly even if we have very little trust in our cryptographic devices -- imagine that you buy them from your enemy -- and in our own abilities to make free choices -- imagine that your enemy is also manipulating you. Given access to certain types of correlations, be they of quantum origin or otherwise, and having a little bit of free will, we can protect ourselves. What's more, we can even protect ourselves against adversaries with superior technology that is unknown to us.

"As long as some of our choices are not completely predictable and therefore beyond the powers that be, we can keep our secrets secret," says Renner, Professor of Theoretical Physics at ETH Zurich, Switzerland. This arises from a mathematical discovery by Renner and his collaborator about 'randomness amplification': they found that a quantum trick can turn some types of slightly-random numbers into completely random numbers. Applied in cryptography, such methods can reinstate our abilities to make perfectly random choices and guarantee security even if we are partially manipulated.

"As well as there being exciting scientific developments in the past few years, the topic of cryptography has very much come out of the shadows. It's not just spooks talking about this stuff now," says Ekert, who has worked with and advised several companies and government agencies.

The semi-popular essay cites 68 works, from the writings of Edgar Allen Poe on cryptography in 1841, through the founding papers of quantum cryptography in 1984 and 1991, right up to a slew of results from 2013.

The authors conclude that "The days we stop worrying about untrustworthy or incompetent providers of cryptographic services may not be that far away."

Journal Reference:

Artur Ekert, Renato Renner. The ultimate physical limits of privacy. Nature, 2014; 507 (7493): 443 DOI: 10.1038/nature13132

View the original article here

Monday, October 28, 2013

Hacking the World Economy with a 3-D Printer

NEW YORK (MainStreet)—It's called a printer but really is a manufacturing plant in a box. 3-D printers can build an object, layer upon layer, from plastic, metal, glass, ceramics – even chocolate. By now, we have seen that these amazing desktop devices can create guns, human tissue, DNA -- and drugs. As with most emerging technologies, for years 3-D printers were institutional and educational devices priced far beyond the reach of the typical consumer. Now you can buy one on Amazon. Creating your own plastic toy is one thing, but as the technology evolves, the world economy might face a physical hack from the same particle print-on-demand technology.

Also see: 'Curbed' and Enthusiasm: Lockhart Steele on What's wURKEN?

As cyber security expert Marc Goodman said in his presentation of "A Vision of Crimes in the Future" at the TEDGlobal 2012 conference, "Today most 3-D printers can print more than 50% of the parts required to make another 3-D printer -- a percentage that is increasing rapidly. Once 3-D devices cannot only produce weapons but also replicate themselves, the security and economic ramifications will escalate."

What are the risks to the global financial markets when mobile manufacturing can replicate the physical and the biological -- for illegal profit?

Robert Herjavec is best known as one of the millionaire investors on television's Shark Tank. He is the well-groomed, smiling Canadian – and usually the calmest -- shark on the panel. The program's introduction mentions The Herjavec Group, but offers few details on its function. Turns out Herjavec's firm is a 150 person operation in Toronto claiming to be the country's largest IT security provider. The company consults clients in 50 countries on cyber crime and terrorism, prevention and solutions. So when it comes to next-tech threats, Herjavec naturally has an opinion or two. His first thought when it comes to 3-D printers: he wants one.

Also see: The Underbanked and the Unbanked

"Firstly, I would like approval to order one of these for 'research purposes,'" Herjavec says. "Secondly, if I was to use it for no good; making copies of badges, such a police officer, detective, fireman, and the like, come to mind. Making copies of keys or thumbprints would be simple. Combining these two techniques with social engineering skills, would likely grant me access to banks and other financial institutions that historically would not have been accessible."

But Herjavec sees more of a threat from the technology than just breaking and entering and simple robbery.

"At a more global markets level, the fact that it becomes easy to copy any physical object, share its blueprints online, and then recreate it at home at manufacturing cost, with no shipping charges, would very quickly knock out the widget market right up to the automotive industry," he says. "But why stop there? As industrial sized 3-D printers become available, and blueprints for everything become accessible online, the public will gain access to aerospace technologies, missile designs, robotics, drones, spy gear and more. The era of 'Spy versus Spy' will be born and accessible to the 13-year-old living in his mother's basement."

Now that is scary.

"Many of our SCADA (supervisory control and data acquisition) systems that control everything from power, water, traffic, heating, cooling, and various other building or city controls utilize proprietary connectors and technologies that are relatively simple but inaccessible to hackers because of interfacing limitations," Herjavec continues. "3-D printers can instantly solve that problem by creating adaptors that would allow hackers to access previously unreachable systems. By creating these new attack vectors, many businesses and infrastructure systems will face a new era of threats they may not be prepared for."

Also see: Believe No Falsehood: Old Dog, New Blog

Herjavec notes that up until recently, only large corporations had the resources and technology to genetically modify organisms. 3-D printers can eventually put this power in the hands of the public -- meaning anyone could create and release a deadly biological attack.

"If you targeted a particular ethnic group, global financial markets could easily be swayed as manufacturing shuts down in one area and moves to another," he says. Transformative tech, like 3-D printing -- also known as "additive manufacturing" --perennially gets into as many hands of the bad guys as the guys in white hats.

Always have, always will.

"There have been technological advances that have shaken the world in a relatively short amount of time, changing it forever -- these included the discovery of electricity, the telephone, the computer, the Internet and now the 3-D printer will join these coveted ranks," Herjavec says. "What can we do to reduce the threat? Adapt. As the bad guys figure out how to use this technology for evil, the good guys will figure out a way to stop them."

--Written by Hal M. Bundrick for MainStreet

EXCLUSIVE OFFER: See inside Jim Cramer’s multi-million dollar charitable trust portfolio to see the stocks he thinks could be potentially HUGE winners. Click here to see his holdings for FREE.


View the original article here

Sunday, February 3, 2013

PowerPoint about the Mayan "end of the world" secretly boobytrapped with malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Will the world end in 2012Earlier this week my colleagues Peter Szabo and Richard Wang respectively discovered and wrote about malware disguised as a Microsoft Excel spreadsheet used to generate Sudoku puzzles to help pass the time.

This morning I was contacted by another SophosLabs researcher, Scott Sitar, about a booby-trapped PowerPoint presentation titled "Will the world end in 2012?"

Like the Excel spreadsheet, this file contained Visual Basic macro code that drops an executable file called VBA[X].exe, where [X] is a random capital letter. In fact, the macro was functionally identical to that found in the Sudoku puzzle.

Also like the Sudoku generator, this sample required the user to enable macros, but didn't include the helpful tip on how to do it or really any good reason you might need a macro to learn about the end times.

What are these macros up to? They are designed to construct a valid Windows PE file (Portable Executable) from arrays of single bytes.

While this isn't particularly new, it would throw off the average user from understanding what these macros are designed to do even if they bothered to take a look.

Screenshot of malicious VB macros

Owl image retrieved by malwareThe EXE file that is extracted is what we call a dropper. It extracts another Windows PE file which downloads a picture of an owl, then contacts a command and control server.

It is designed to download another payload it will rename as Wmupdate.exe, but during our testing no instructions were sent from the command-and-control server to retrieve this payload.

Scott mentioned his suspicions that these were being automatically generated and not necessarily handcrafted by their creators. I think he's right.

I took a look around and discovered the original, uninfected files that these dangerous macros had been added to.

The presentation about the world ending was created by a preacher in the United States who appears to have nothing to do with this booby-trapped version. Don't go looking for this presentation though!

His legitimate WordPress blog has been compromised and is currently performing search engine manipulation duties for Viagra pushers, "off-shore" casinos, forex fraud and payday loans.

SEO keywords on compromised blog

If you do want to see what this presentation has to say, I was able to find it online in a safe to view format.

While macro viruses certainly aren't a new phenomenon, they aren't something many people think about.

Be careful with documents you acquire from random sources and never enable macros in documents you download or receive as email attachments.

You never know what might be lurking in there, but I suspect it won't be the end of the world.

A special thanks to Scott Sitar in SophosLabs Vancouver for spotting this and doing all of the analysis necessary to share this story.

Sophos Anti-Virus on all platforms blocks this malware as follows:

WM97/ExeDrop-G: The malicious Office macro
Troj/DwnLdr-KLB: The Windows malware dropped by the above

Follow @chetwisniewski


View the original article here

Wednesday, November 7, 2012

World of Warcraft players massacred in hack attack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

If you're one of the millions of avid players of the online MMORPG World of Warcraft, then you may have been surprised to find the populations of entire cities killed off this weekend.

Skeletons in World of Warcraft

According to the game's developers, Blizzard, hackers managed to exploit a vulnerability in the game, resulting in the deaths of many player and non-player characters.

In a forum posting, the company said it was taking the attack "very seriously":

Earlier today, certain realms were affected by an in-game exploit, resulting in the deaths of player characters and non-player characters in some of the major cities. This exploit has already been hotfixed, so it should not be repeatable. It's safe to continue playing and adventuring in major cities and elsewhere in Azeroth.

As with any exploit, we are taking this disruptive action very seriously and conducting a thorough investigation. If you have information relating to this incident, please email hacks@blizzard.com. We apologize for the inconvenience some of you experienced as a result of this and appreciate your understanding.

The hackers' attack saw every character in cities such as Stormwind, Orgrimmar, Tarren Mill and Ragnaros killed off, leaving piles of skeletons cluttering the streets and buildings. According to the Blizzard, the vulnerability exploited by the hackers has now been patched.

Blizzard is likely to ban the culprits if they manage to identify them, and could possibly take legal action if they can prove that financial losses occurred as a result of the hack.

Follow @gcluley

View the original article here

Thursday, September 6, 2012

Google staffs up 'Red Team' to protect the world from its privacy lapses

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Privacy. Image from ShutterstockAfter agreeing earlier in the month to cough up a record $22.5 million in a settlement with the Federal Trade Commission for sneaking tracking cookies past Safari browsers' no-tracking controls, Google is creating a privacy "Red Team" to police its products' own privacy bugs and dangers.

The settlement is over Google's override of the cookie controls in Apple's Safari browser.

As the FTC explained, Google snuck around those controls by creating an invisible HTML form and then using JavaScript to pretend a user had submitted it.

Google thereby bypassed the browser's blocking of third-party cookies - i.e., those set by sites other than the ones a user originally visits.

The form was invisible and lacked either content or a Submit button, meaning the user could never have actually submitted it.

But Safari, duped into thinking the user had submitted a form, then allowed Google to place a DoubleClick cookie on the user's computer.

The FTC cried foul, charging Google with misrepresenting its use of tracking cookies and of breaking its privacy promises.

Now, Google's hiring a ninja - pardon me, make that a "back-end ninja" - to slap itself into privacy shape.

Specifically, a recently posted job listing advertises for a Data Privacy Engineer to join its team of privacy "back-end ninjas".

Google job advert

The task of the Google back-end ninja:

As a Data Privacy Engineer at Google you will help ensure that our products are designed to the highest standards and are operated in a manner that protects the privacy of our users. Specifically, you will work as member of our Privacy Red Team to independently identify, research, and help resolve potential privacy risks across all of our products, services, and business processes in place today.

Red teams are nothing new: the term refers to an independent group that serves to challenge an organization to keep it on its toes.

Penetration-testing is on Google's wish list, so the search empire is obviously planning to kick its own privacy tires.

The responsibilities are to:

Analyze software and services from a privacy perspective, ensuring they are in line with Google's stated privacy policies, practices, and the expectations of our users.

That sounds, actually, like whoever assumes the role will function as something of an ombudsman, watching out for the constituent interests of the user base.

Google to date hasn't done much to earn users' trust that even a large-ish fine will stop it from pulling egregious privacy shenanigans.

When Sophos's Paul Ducklin polled users, over 90% said that no, financial penalties are certainly not enough to make the online behemoths play ball on privacy.

Well, hiring a privacy red team certainly sounds like Google's on the road to improving a situation that led to its slipping ghost forms, cookies and ads past the blocks on users' browsers.

This time, let's hope Google's privacy promises aren't as empty as that Safari-bamboozling, empty HTML form.

Follow @LisaVaas

Privacy image from Shutterstock.

Tags: browsers, Data Privacy Engineer, DoubleClick, Federal Trade Commission, fine, ftc, Google, job listing, Red Team, Safari, settlement


View the original article here

Friday, January 6, 2012

Samoa moves to the other side of the world - and misses a day!

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Regular readers of Naked Security will know that I have some strong feelings about timestamps in logfiles.

In particular, the ambiguities created by logfiles based on local time - which is subject to local timezone regulations and changes - can work against your security interests.

Here's one reason why:

"..Don't let year-ends, timezones, daylight saving changes or varying local conventions confuse your logs. If you suffer a breach, you will almost certainly want to put together an irrefutable historical sequence of events, based on your system logs, possibly from many systems and many locations.."

Local time can confuse even local residents, let alone outsiders trying to make sense of unqualified timestamps in logfiles some time after the event.

For example, in New South Wales, Australia, there are three official timezones: one for the far west of the state, 1000km inland; one for the bulk of the mainland; and a third for Lord Howe Island, 700km to the east of Sydney. And there are two different increments for daylight savings: one hour for most of us; but just half an hour for Lord Howe.

Furthermore, the Government of New South Wales has made three legislative tweaks to local time in the past six years: a switch from GMT to UTC in 2005; a temporary change to daylight savings for the Commonwealth Games in 2006; and a long-term change to prolong daylight savings in 2007.

Confused?

Don't be, because all of this is as nothing compared to what is going to happen in Samoa and the nearby New Zealand dependency of Tokelau tomorrow.

Or, to put it another way, the day after tomorrow.

As I write this, it's 1pm on Friday 30 December 2011 in Sydney. It's 2pm in Samoa, and 3pm in New Zealand.

That sounds pretty convenient, considering that the majority of Samoan expatriates live in New Zealand and Australia, and that the three countries have strong business and sporting ties.

Except that it's only Thursday 29 December in Samoa. Back in 1892, Samoa did quite a bit of trade with Hawaii and California, so it made sense to decide to be twelve hours behind Greenwich, rather than 12 hours ahead. (Hawaii is UTC-10; California is UTC-8 or UTC-7.)

But in the 21st century, being the most westerly country in the world has become a huge business pain to Samoans when it comes to dealing with Australia and New Zealand, since our weekends don't line up.

By Friday, Samoans trying to wrap up the week's business can no longer get hold of their counterparts across the South Pacific - we're all at the beach, at the shopping mall, or in the pub. And to contact us early on Monday to catch up, the Samoans have to work on their Sunday.

So the Samoan legislature has taken a surprisingly simple, but astonishingly bold, step. At midnight tonight, the country will make a timezone adjustment, switching from UTC-12 to UTC+12. Figuratively, at least, Samoa will jump from one side of the world to the other.

Clocks won't change at all. Just the calendar will.

Simply put, there will be no Friday 30 December 2011 in Samoa.

How funky is that?

(Samoa is surprisingly good at low-fuss but potentially high-impact bureaucratic change. In 1997, the country changed its name from Western Samoa; in 2009, it switched from driving on the right to driving on the left, as does most of the South Pacific; and in 2011, it will calmly skip an entire day.)

Let this remind you once again why standardised and unambiguous timestamps are vital in logfiles, and take a moment to revisit RFC3339: Date and Time on the Internet: Timestamps.

As I wrote back at the start of 2010:

"..Without reliable logs, you are unlikely to understand [a security] breach, which makes it harder to prevent it happening again. Without reliable logs, you are unlikely to be able to prove your case against the perpetrator, if you are even able to get anyone in your sights. And without reliable and consistent logs, you might not even spot breaches in the first place.."

To everyone in Samoa and Tokelau - Happy New Year! This time, we can celebrate together. And remember this: tomorrow, footy season will be two days closer, not one.

Follow @duckblog
-


View the original article here

Wednesday, July 6, 2011

Milly Dowler phone 'hacked by News of the World private investigators' - Daily Mail

Dowler family's lawyer says former News of the World editor's position is a 'question for her conscience'Questions over whether it could have hampered police investigation into her disappearance in 2002Labour demands full police probe into allegations

By Chris Greenwood

Last updated at 12:01 PM on 5th July 2011

News International boss Rebekah Brooks's position looked increasingly untenable today as both David Cameron and Ed Miliband condemned the hacking of Milly Dowler's phone.

The Prime Minister described the allegations as a 'truly dreadful act', while Labour leader Ed Miliband urged Brooks to 'consider her position' and "examine her conscience'.

Their words were backed by the Dowler family's lawyer Mark Lewis, who said of Brooks's position: 'It is a matter for her own personal conscience to decide.

Close: Prime Minister David Cameron today condemned the hacking of Milly Dowler's phone by News of the World investigators while his friend Rebekah Brooks, right, was editor Close: Prime Minister David Cameron today condemned the hacking of Milly Dowler's phone by News of the World investigators while his friend Rebekah Brooks, right, was editor

David Cameron, speaking from Kabul, has said the hacking, if true, is 'a truly dreadful act' David Cameron, speaking from Kabul this morning, said the hacking, if true, is 'a truly dreadful act'

'We have to wait and see whether she decides to do the honourable thing.'

The condemnation from Mr Cameron is a major blow to Ms Brooks, who considers him a personal friend.

Both have homes in his Oxfordshire constituency and Mr Cameron visited her as a guest during the Christmas period last year.

Their friendship is one of a number the Prime Minister holds with senior media industry figures, who live nearby including Elizabeth Murdoch and Jeremy Clarkson.

It has been claimed that her parents Bob and Sally Dowler also had their phones hacked by a private detective in the weeks after the 13-year-old disappeared in 2002.

Speaking at a press conference in Kabul, Mr Cameron said: 'These are really appalling allegations about the telephone of Milly Dowler.

'If they are true this is a truly dreadful act and a truly dreadful situation.'

Mr Cameron said police investigation the allegations should do so without 'fear or favour'.

He added: 'They should pursue this in the most vigorous way that they can to get to the truth of what happened.'

Today the Dowler family's lawyer Mark Lewis said: 'This is cruel. It is evil that people thought this was the right thing to do.'

The alleged hacking took place when Rebekah Brooks, who now runs the British arm of News International, was editor of the News of the World.

She will not resign over the matter, sources at the organisation said.

Labour leader Mr Miliband said: 'I am shocked by the news of the hacking of Milly Dowler's phone. It beggars belief that anyone would undertake such a cruel and immoral act.

'The police inquiry must get to the bottom of who was responsible for this and who was complicit in it.'

He also criticised the News of the World for the 'culture' that allowed it to happen. He said: 'Of course she (Brooks) should consider her position but this goes well beyond one individual.

'This is about the culture and practices, which were obviously going on at that newspaper, the News of the World, over a sustained period of time.

'Despicable': Investigators for the News of the World are accused of hacking Milly Dowler's voicemail 'Cruel': Investigators for the News of the World are accused of hacking Milly Dowler's voicemail. Ed Miliband has attacked the newspaper for its alleged actions 'Cruel': Investigators for the News of the World are accused of hacking Milly Dowler's voicemail. Ed Miliband has attacked the newspaper for its actions

Operation Weeting is mainly focused on the News of the World's activity during 2005 and 2006, by which time Rebekah Brooks had left the paper fro the Sun.

But the Dowler episode, in March 2002, happened while she was editor.

When she took over the paper in 2000, Brooks brought back Greg Miskiw from New York, shortly after he had been sent there as U.S. correspondent.

She made him her assistant editor in charge of news. It was Miskiw who then hired private investigator Glenn Mulcaire, who proceeded to steal confidential data and hack voicemails.

While Brooks was in the editor's chair, the News of the World also regularly hired Steve Whittamore, who ran a network of specialists who stole information from British Telecom, mobile phone companies and the DVLA.

Records published by the Information Commissioner's Office show that 23 journalists from the News of the World hired Whittamore a total of 228 times (including for the purchase of addresses and ex-directory numbers relating to Milly Dowler's disappearance).

Journalists who worked at the News of the World say that their use of private investigators was routine, open and officially sanctioned.

The former showbusiness reporter, Sean Hoare, who worked there under Brooks, last year told the New York Times that he was actively encouraged to hack into voicemail by her deputy, Andy Coulson.

One of Brooks's assistant editors, Paul McMullan, told the Guardian last year that he personally had commissioned several hundred acts that could be regarded as unlawful - which senior editors were of.

'It wasn't about a rogue reporter, it wasn't just one individual, this was a systematic series of things that happened.

'What I want from executives at News International is for them to start taking responsibility for this.'

He added: "They (the public) will be horrified that the grieving parents of an abducted child were made to go through further torture that somehow she was alive because her voicemails were being retrieved or deleted.

'People will ask "where have we got to?" that that was thought to be an acceptable way for parts of the British press to behave.

'My wife said to me this morning "this is sick, what was going on" and I think that is going to be the reaction of people up and down this country.'

Asked if the Prime Minister backed the Labour leader's call, a Downing Street spokesman said: 'We should await the outcome of the police investigation into phone hacking.'

Mr Miliband's words were echoed by shadow Home Secretary Yvette Cooper.

She said: 'Everyone across the country will be deeply disturbed and horrified at this shocking news. The idea that private investigators working for a newspaper would hack into the phone of a missing 13-year-old girl is truly despicable.

'It is deeply distressing that the Dowler family, who have already been through so much, should now have to go through yet another media ordeal.

'I am now seeking immediate assurances that these actions did not affect the police inquiry into Milly Dowler's disappearance.'

Bob and Sally Dowler's solicitor, Mark Lewis, said the 'heinous' actions could have jeopardised the police inquiry as messages were deliberately deleted from Milly's phone to create space for new ones.

This meant her parents clung to 'false hope' that she was still alive because police wrongly thought she was erasing voicemails when, in fact, she was already dead.

At the time she vanished in March 2002, they had been sending desperate text messages and voicemails to her. They now fear those pleas were listened to by the hackers.

Police believe that if Milly's abductor had been accessing the phone at the time of the hunt for her, those deleting the messages may have destroyed potential evidence.

It is alleged the hackers deleted the messages because Milly’s phone - an old model - had a limited memory, meaning no more voicemails could be left.

Ex Sun editor Rebekah Wade may also have had her phone tapped by News Of The World investigators Ex News Of The World editor Coulson resigned earlier this year Controversy:  Rebekah Brooks (left) was editor of the News of the World at the time of the allegations while her predecessor Andy Coulson (right) resigned earlier this year as David Cameron's Director of Communications as a result of the phone hacking scandal

Grief-stricken: Bob and Sally Dowler with daughter Gemma, centre, speaking outside court after Bellfield's conviction Grief-stricken: Bob and Sally Dowler with daughter Gemma, centre, speaking outside court after Bellfield's conviction

Mr Lewis said her parents had already been through 'so much grief and trauma' before these 'further distressing revelations'.

Last month they revealed how traumatised they had been by the trial that led to the conviction of Levi Bellfield, 43, for Milly's murder.

Mr and Mrs Dowler said they were in effect put on trial as their personal lives were torn apart in the witness box.

'It is distress heaped upon tragedy to learn the News of the World had no humanity at such a terrible time,' said Mr Lewis.

'The fact that they were prepared to act in such a heinous way that could have jeopardised the police investigation and give them false hope is despicable.'

The Dowler family were only told about the hacking in April - more than nine years after their daughter went missing.

Her remains were found 25 miles away from her home in Walton-on-Thames, Surrey, in September 2002.

Abuse: Bellfield is seen here with his former girlfriend Johanna Collings at Yateley Heath - where Milly's body was found Abuse: Bellfield is seen here with his former girlfriend Johanna Collings at Yateley Heath - where Milly's body was found years later

Grief: Flowers are laid for schoolgirl Milly Dowler outside Heathside School, Weybridge, in September 2002 after her body was found Grief: Flowers are laid for schoolgirl Milly Dowler outside Heathside School, Weybridge, in September 2002 after her body was found

Grieving: Parents of Milly Dowler, Robert and Sally, make an appeal during the time of her disappearance in 2002 Grieving: Parents of Milly Dowler, Bob and Sally, make an appeal during the time of her disappearance in 2002

A source close to the inquiry said officers were 'shell shocked' when they learnt about the hacking. 'This is devastating news for the family,' he said.

'When the trial finished they wanted to reclaim the memory of Milly for themselves. But this has thrown it open again.'

Police sources said they did not know what journalists hoped to achieve by the alleged hacking of Milly's phone. But it is possible they were after fresh leads in the search for her.

It also emerged yesterday that Colin Stagg, the man cleared of murdering Rachel Nickell, may have been hacked as early as 2000.

The latest revelations are likely to mark a turning point in Operation Weeting, Scotland Yard's investigation into hacking at the News of the World, in which five people have been arrested.

Detectives found evidence of the Dowler hacking amid paperwork seized from the home of private investigator Glenn Mulcaire, who was jailed in January 2007, along with former News of the World royal editor Clive Goodman, for intercepting voicemail messages.

Scotland Yard was first alerted to phone hacking in 2005 when royal aides reported their suspicions to police.

After the conviction of Goodman and Mulcaire, concerns were raised that the initial inquiry was too limited.

In January Scotland Yard announced a new inquiry after detectives were handed 'significant new information' by News International.

News International has reportedly set aside a multi-million pound fund to settle compensation claims with victims. They include actress Sienna Miller, who was recently paid ?100,000, and sports pundit Andy Gray, who received ?20,000.

A spokesman for News International said: 'We have been co-operating fully with Operation Weeting since our voluntary disclosure in January restarted the investigation into illegal voicemail interception.

'This particular case is clearly a development of great concern and we will be conducting our own inquiries as a result. We will obviously co-operate fully with any police request on this should we be asked.'

Levi Bellfield Levi Bellfield Killer: Levi Bellfield, pictured in 2011 (left) and 2004 (right) was convicted of murdering Milly Dowler


View the original article here