Newsvine
  • Welcome
  • Help
  • Report Bug
  • Conversation Tracker
  • Your Column
  • Replies
  • Friends
Type Comments Since You Last CheckedArticle Source Last Checked Stop Tracking All Clear Tracking All
advertisement
Log In | Register
Close the Login Panel
Existing users log in below. New users please register for a free account.

New Users:

Existing Users:

E-Mail:
Password:
Forgot Password?
Please enter the e-mail address or domain name you registered with:
E-Mail/Domain:
Back to Login
Log Out
  • Top News
  • Local News
  • World
  • U.S.
  • Sports
  • Politics
  • Tech
  • Entertainment
  • Science
  • Business
  • Health
  • Odd News
  • More
    • Arts
    • Education
    • Fashion
    • History
    • Home & Garden
    • Religion
    • Travel
    • Environment
Visit M. Spencer's column >>

M. SPENCER

Home Page
Articles Posted: 4  Links Seeded: 194
Member Since: 7/2006  Last Seen: 2/07/2010

What is Newsvine?

Updated continuously by citizens like you, Newsvine is an instant reflection of what the world is talking about at any given moment.

Get a Free Account
Help
Fun Stuff
  • Leaderboard
  • E-Mail Alerts
  • Top of the Vine
  • Newsvine Live
  • Newsvine Archives
  • The Greenhouse
  • Recommended Articles
  • Newsvine Tools
  • Wall of Vineness
Put a Seed Newsvine link on your own site
{"contentId":"2226333","authorDomain":"mspencer"}

Aussie net filtering scheme has serious security risks - The Inquirer

News Type: Event — Seeded on Thu Dec 18, 2008 10:44 AM EST
Read ArticleArticle Source: theinquirer.net
technology, internet, censorship, filter
Seeded by M. Spencer
advertisement

A REVEALING INTERVIEW with computer security techspert, Matthew Strahan, has brought to light disturbing potential problems with Australia's upcoming ISP-level censorship plan, including the facilitating of personal data interception and even bringing down the whole Australian Internet.

In an interview to BanThisURL, Strahan, known as a "white hat hacker" because his job is hacking into company computer systems in order to fix their vulnerabilities, said any filters could be worked around, and might even pose security risks that wouldn't have occurred without them.

The filter proposed by the Aussie government is much like those used by many mean spirited companies that deny their employees the joys of Pr0n and YouTube at work. It will also apparently be a dedicated box rather than simply filtering software.

The main worry expressed by Strahan is that hackers could take over the filter box to carry out Man in the Middle attacks whereby they could intercept private information and emails without anyone being any the wiser.

Another serious concern is denial of service (DOS) attacks, which could allow a talented hacker to bring down the entire ISP by bombarding the filter with hundreds of thousands of HTTP packets in a very short space of time, overwhelming it and stopping it from letting any legitimate requests through.

You wouldn't even need to have a decent sized botnet, according to Strahan, who notes "if you find something that causes a lot of processing in the filter then even an ADSL connection might be able to bring it down."

As if that wasn't bad enough, there are plenty of other problems that could occur with the new filters, including cross site scripting vulnerabilities which could allow hackers to inject HTML or Javascript content into web pages. Also, if everything has to pass through a single box, and that box gets attacked and goes down, you can kiss your connection goodbye.

Another scary consequence could be if a hacker figured out how to add things onto the blacklist. If this happened, he or she could offer to sell their services to rival companies, offering to bung competitors into the blacklist and causing industrial chaos.

It all seems a bit of a shame, really, especially since filters are so easily bypassed using proxies anyway. Especially free VPN software like Hotspot Shield which just tunnels through the censor.

Asked if there were any filters he'd be confident enough deploying in an ISP level filtering system, Strahan replied "I wouldn't be confident enough in any of them," adding "If you standardise what boxes are put in the ISPs, all of them will be vulnerable to the same security vulnerabilities. Which means if somebody makes a single mistake - say the software manufacturer has a buffer overflow - then someone would be able to use that to take over all the filters in Australia."

Blimey!

Of course, that would be the worst case scenario. But that's not to say lots of other problems couldn't also arise. Australia better hope this whole net filtering idea doesn't boomerang on them. ยต

{"contentId":"2226333","authorDomain":"mspencer"}
  • Enjoy this article? Help vote it up the 'Vine.

Published to:

  • M. Spencer's Column, All of Newsvine
  • Groups: none
  • Regions: none
  • Public Discussion (0)
{"canLink":false,"threadId":0,"isPrivate":false}
Leave a Comment:
You're in Easy Mode. If you prefer, you can use XHTML Mode instead.
You're in XHTML Mode. If you prefer, you can use Easy Mode instead.
(XHTML tags allowed - a,b,blockquote,br,code,dd,dl,dt,del,em,h2,h3,h4,i,ins,li,ol,p,pre,q,strong,ul)
Newsvine Privacy Statement
As a new user, you may notice a few temporary content restrictions. Click here for more info.
{"threadId":0,"contentId":"2226333"}
Start TrackingStart Tracking
Stop TrackingStop Tracking
Back To Top | Front Page
FUN STUFF:
  • Leaderboard |
  • E-Mail Alerts |
  • Top of the Vine |
  • Newsvine Live |
  • Newsvine Archives |
  • The Greenhouse |
  • Newsvine Tools
COMPANY STUFF:
  • Code of Honor |
  • Company Info |
  • Contact Us |
  • Jobs |
  • User Agreement |
  • Privacy Policy
LEGAL STUFF:
  • © 2005-2010 Newsvine, Inc. |
  • Newsvine® is a registered trademark of Newsvine, Inc. |
  • Newsvine is a property of msnbc.com