28 November 2022

Australia's bad policy and privacy tech contributes to data hacks!

The colonial government of Australia is truly backwards when it comes to implementing technology and policies that protect its citizens as opposed to policies and technology used to spy on them.

Medibank, Optus, Woolworths data hacks show how a 'decade of anti-security policy' is putting Australia at risk, experts say


Millions of Australians have had a bad run with their personal data lately.

Whether it's telecommunications companies like Optus, private health insurers like Medibank, massive online retailers like MyDeal, or smaller online wine sellers like Vinomofo — hackers are getting hold of our data regularly.

With all this going on, you might be left wondering what exactly the hackers are doing with your data and how it could affect you.

Is Australia particularly exposed to data breaches? And is there anything that can be done about it?

We spoke to a few experts to break it down.

Going Phishing

For the people who hacked your data, it's all about money.

And in most cases, they are probably going to sell your data to others who'll use it in various ways like identity theft or extortion, and — or — try to extort the company they stole it from.

There's a lot of talk about those sales of people's data happening on the so-called dark web — sites the average person can't access, without using anonymising software like Tor.

But internet security expert Troy Hunt, who runs the website haveibeenpwned.com said the data was often sold on the "clear web": websites accessible to anyone.

He said data like what was taken in the Optus breach, would often first be used in mass automated phishing attempts.

Since the hackers have your email, they know you are an Optus customer, and they have some other personal information — maybe it's your name and address — they can quickly create thousands or millions of relatively convincing emails that look like they are coming from Optus, said Mr Hunt.

Security researcher Troy Hunt says the data will often be sold on internet sites accessible by anyone. (Supplied: Troy Hunt)

An email might address you by name, note that you are an Optus customer, and have other information obtained through the breach that attempts to demonstrate the legitimacy of the email.

It could then ask you to enter your credit card number or ask you for further information.

"Imagine targeting 10 million people, you're going to get maybe one in a thousand," he said.

"But that's like 10,000 people that have fallen for the scam."

Highly targeted scams

The data can also be used in more targeted ways, according to Professor Vanessa Teague, a cryptographer from the Australian National University.

"In the Optus breach, what it seems to have primarily involved is identity documentation," she said.

"And the thing that a person with malice might use it for, is exactly what you might use it for — and exactly the (reason) Optus had it for — which is identifying as that person in an online setting," she said.

The information held by Optus was gathered to initially set up mobile phone accounts. Telecommunications providers conduct full identity checks, usually requiring 100 points of ID, before they'll grant you a phone contract.

In Australia, getting a "burner phone" — a phone not attached to your real name — is difficult, and criminals could use your 100 points of ID to get a phone attached to your name to use as a burner phone.

Professor Teague said the same information you might provide to your mobile provider is often used to get lines of credit, which could allow someone to spend a lot of money in your name too.

In the case of the Medibank breach, details are still emerging about what exactly was stolen. It's possible identity information was breached in that too.

Also concerning is the suggestion that medical records were stolen, which could be used to extort money from the victims.

"On the one hand, [medical data] isn't as useful for fraud," Professor Teague said.

"On the other hand, it potentially gives you much more power over some people, because it might reveal very intimate details about the person." 

Bad policy 'contributes directly to the current situation'

With all the breaches happening in Australia, you might be wondering whether the country is particularly vulnerable?

Professor Teague was scathing of Australia's approach to security, which she said left the door open to attacks and hacks.

"We've had a decade of anti-security policy," she said.

"We've had laws that required the acquisition of data that didn't need to be acquired, laws that demand the retention of data that didn't need to be retained."

 Vanessa Teague says it is surprising we haven't seen more serious data breaches in Australia.(ABC News: Kyle Harley)

In addition, she said other laws were in place that undermine some encryption and authentication that would provide security for that information.

Professor Teague said amendments to the Telecommunications Act that required the retention of metadata should be scrapped, along with the Assistance and Access Act and the Identify and Disrupt Bill, which she said undermined security, encryption and authentication.
 
She said the previous government saw encryption as a tool used by criminals, and as a result, made it harder for legitimate organisations to use encryption to keep personal data safe.

"It's surprising that we haven't had more serious data breaches more often," said Professor Teague.

"I think this bad policy contributes directly to the current situation and it has to be reversed."

Australia not using good privacy technology

Mr Hunt said Australians were more vulnerable than they needed to be.

He said when someone went to a pub to prove they were over 18, they would generally show their drivers licence.

But when they did that, they were also handing over a photo, licence number and home address, exposing all that to potential theft or misuse.

Mr Hunt said digital drivers licences could show only the information that is required at the time. Like the fact you are over 18.

And he said it was "crazy" that we still use things as simple as licence numbers as identification.

"That sort of thing is absolutely crazy, particularly in an era where we've got cryptographic devices in our pockets." 

Professor Teague agreed, and said Belgium and Estonia now use cryptographic identifying tools, which are easy to use and much harder to steal.

Is there anything you can do to improve your security?

The short answer from Mr Hunt and Professor Teague is simple: not much.

After a breach like Optus, measures can be taken to minimise the impact, said Mr Hunt, like replacing your licence and passport.

The Australian Cyber Security Centre and Home Affairs Minister Clare O'Neil have emphasised checking and improving the security of all your important accounts: turning on two-factor authentication where possible, making sure your passwords are secure and unique, and guard against phishing attempts.

Experts also recommend checking how much of your information is already available online — like contact details on LinkedIn, or dates of birth on Facebook — which criminals could use in addition to anything they've retrieved through a hack, to steal your identity. 

But there's not much you can do to change your health records, if it emerges those were stolen in the Medibank breach, said Professor Teague.

Once you've handed over data, it's rarely up to you what happens to it after that.

"So really, the only thing you can do is refuse to hand it over, except in situations where it's absolutely unavoidable, which unfortunately are increasingly common," she said. 

Source:abc.net.au

27 November 2022

This is how to create a secure password that will take a hacker up to 300 years to crack


If you're worried about security, you might come up with a password like ZXxA64RTEGHYRTZZX22!!! that might not be so easy for hackers to crack. But most people still prefer to come up with something simple. Recently password manager company NordPass (via SamMobile,Naver) revealed that "samsung" (lowercase 's' and all) was one of the most used passwords in at least 30 countries.

Would you believe that the most popular password in the world is..."password"


Using as a password the name of the company that manufactured the phone in your hand might not be a great idea. But over the last few years, the "samsung" password has grown in popularity. In 2019 it was the 198th most popular password, rising to 189th most popular the next year. In 2021, "samsung" was number 78 on the list of most popular passwords. Imagine if you owned the Nothing Phone (1). If you used the brand for your passwords, you could claim that you use nothing for your passwords (Hey, they can't all be gems!).


Now here's the interesting part. The most used password in the world is..."password." Nearly 5 million people believe that this will keep out attackers. Would you use "password" as the (ahem) password for your banking app? Other widely used passwords include "123456," "123456789," and the always popular "guest." Anyone using passwords like those should not be allowed to complain about the lack of security on their phones or tablets.


The "samsung" password is one of several brand names used for account protection. Others include Adidas, Nike, and Tiffany. Different countries have different favorites based on cultural differences and other factors. In soccer-mad England, the fourth most popular password is Liverpool (globally, there could be another reason to use that as a password, right fellow Beatlemaniacs?) with Arsenal sixth and Chelsea at number 11. In Italy, Ciao (which means 'Hello') is number four.

How to create a password that can take up to 300 years to crack


Short or simple passwords are easier to crack. A CNBC report once discovered that a password made up of 4 to 11 characters could be discovered immediately. A password using 12 characters took two seconds to crack while one with 13 characters lasted for all of 19 seconds. Even combining uppercase, lowercase and numbers isn't safe. Such a password made up of 4 to 6 characters can be discovered immediately. One with 7 characters will take seven seconds to decipher while using that combination for an eight-digit password will take seven minutes to crack.

The safest passwords use a combination of uppercase letters, lowercase letters, numbers, and symbols. A seven-to-10-character password in this vein takes up to five months to discover. If you use 11 characters, it will require as many as 34 years of work to decipher. And a 12-character password containing all of the aforementioned "ingredients" will take a hacker as long as 300 years to discover.

But to prove how important the length of a password is to your digital security, even if you create a password made up of uppercase letters, lowercase letters, numbers, and symbols, if it is only four to six characters in length, hackers can still figure it out immediately! NordPass says that most of the most popular passwords can be discovered in about one second which is why you should try to come up with a password made up of 12 characters that include uppercase letters, lowercase letters, numbers, and symbols.

Of the top ten passwords according to NordPass, the only two that take more than one second to crack are "guest," and "col123456." These two can be discovered in 10 and 11 seconds, respectively.

Also, NordPass suggests never using the same password on different apps. And you should change the password that you use on each app every now and then. While you might be thinking to yourself that there is no way you can remember so many complex passwords for all of the apps you use, well that is why there are Password Manager apps in the App Store and the Google Play Store.

24 November 2022

Victorian Election, Victoria the secretive Police State


Victorians are living under a Chinese influenced 'dictatoship' led by Daniel Michael Andrews, where the state's police force acts under his dictation.

Andrews is criminally rorting the public purse with his rigged 'money for mates' tenders which also includes family members.

The 'best' part about this Andrews is allegedly a public servant, where his actions are accountable to the 'public' yet no one is able to see this accounting.

What's more concerning is that the courts support the secrecy.

Surely this is not in the 'interest of the public', no?

Conspiracy theory: Criminals in office cause more harm to society than criminals within society.

ATO 'Director-ID' fines unlawful?


Australia has been a colony since the (hostile) take-over by the colonialists, the UK’s monarchy together with its government from 1788.

Why ‘hostile’? 

Because there is no treaty with the original inhabitants of the land, even until today.

How honourable, but what else can one expect from English pirates.

The colony has been turned into a police state, a totalitarian state, a corporatocracy, a duopoly dictatorship, a fascist state that would even make Mussolini proud.

In the “good ol’ days”, when the pirates in the colony’s government misbehaved the motherland stepped in and put them in line with a law called the Colonial Laws Validity Act of 1865.

Today? Crickets!

Unlawfully enacted law has been put into circulation, by dishonourable people in government for decades, and for the better part the courts have been ‘supporting’ this, deceiving the people.

Australia is a ‘free range’ prison isle, obviously meaning that you are (at the moment) ‘free’ to roam around within the borders.

As time goes on though, law is being put into circulation that further enslaves the inhabitants of the land akin to that of a real life prison.

For example, now directors of corporations must register their ‘mug shots’ or more accurately biometric data, with the authorities, like one does when entering a real prison.

Why?

Allegedly to stop criminal activity?

Rubbish/Bullocks/Crap!

It’s nothing to do with that.

It's ALL about expanding the Nanny State agenda, where 'you' (the general population, more specifically the 'conspiracy theorists' i.e. those who do not support an offical govenrment sponsored agenda) are the enemy.

So, the question now remains is: what lawfully enacted instrument has been put in place that a person must obey?

The answer is: NONE!

No lawfully enacted law (i.e. Act) has been put in place.

Now, whether the ‘brethren’ of those parliament, that being the judiciary will rule on this in a legal challenge is yet to be determined, but don’t hold your breath.

Australia’s courts are ‘kangaroo courts’ where there is no separation of powers between the three tiers of government, that being the Parliament, Judiciary and the Executive, where they also act under dictation.

So much for a ‘fair hearing’, there is none, and there never ever was one.

See Director ID hard copy form:

See also

ACTS INTERPRETATION ACT 1901 - SECT 25C

Compliance with forms

                   Where an Act prescribes a form, then strict compliance with the form is not required and substantial compliance is sufficient.

Document soruce and Act reference:

https://constitutionwatch.com.au/director-id-hardcopy-form/

23 November 2022

Australia's corrupt police - Corruption crusader KHALESIRAD goes after top cop

“There are many reasons why QPS Deputy Commissioner Steve Gollschewski should not accept the role of  Queensland "Special Coordinator for Police Reform".

Instead of punishing the sexual misconduct being reported as a public interest disclosure, Gollschewski punished the whistleblower who reported the sexual misconduct. 

This appointment was not on its merits. It's 100% political!”

Source:supplied


22 November 2022

France bans Office 365 and Google Workspace in schools

Country has concerns over competition and regulation


The French Ministry of National Education has urged educational institutions in the country to stop using free versions of Google Workspace and Microsoft Office 365 for schools and students.

The Ministry said such offers are not compatible with the EU's General Data Protection Regulation (GDPR), the Schrems II judgment of the European Court of Justice, and the Dinum circular on the 'cloud at the centre'.

The Ministry issued the statement in response to a query from MP Philippe Latombe, who wanted to know whether Microsoft's free offer in schools amounted to unfair competition.

The Ministry agreed with Latombe's assertion and said it has directed schools to discontinue using Google Workspace and Microsoft Office 365.

It said that the Dinum (La direction interministérielle du numérique, the French ministry for digital transformation) circular makes it 'quite clear' that the use of Office 365 is not permitted in French administrative offices.

According to the 2021 circular government data should not be kept on Microsoft 365 cloud services, to safeguard it against a potential security breach or even abuse by US intelligence agencies.

Ministries may continue to use Microsoft software with appropriate applications (Word, Excel, etc.), but only as an on-premise version.

France has been focusing on cloud service security for a long time. The nation is attempting to defend itself against the US CLOUD Act of 2018, which mandates that businesses must reveal required data from their servers when ordered. The legislation applies both to US businesses and the clients they serve abroad.

The Ministry of National Education also referred to an earlier letter by the French data protection authority, CNIL (Commission Nationale de l'Informatique et des Libertes), which directed institutions in the country to ensure that their data is hosted on servers within the EU, rather than in the United States.

CNIL suggested using services offered by firms that are exclusively governed by European legislation and do not transfer customer data to countries outside the EU.

The Ministry of National Education also considered the Schrems II ruling from the EU Court of Justice, which declared the transatlantic framework for sending personal data from European users to the United States invalid.

Both Germany and France prohibit the use of free versions of Microsoft Office 365 in education.

Similar to France, Germany has concluded that the app gathers data from the user's machines and transfers it to American datacentres, in violation of the GDPR guidelines.

Source:computing.co.uk

21 November 2022

No 'State of Emergency' for Victoria, government lies

The people in goverment lie to you every single day.

Politicians, public servants, premiers, 'chief' health officers lie via press conferences live broadcasts or in print media articles.

MANY people are not aware that Australians live in a fascist state that would make Mussolini proud.


The colony's governments are not transparent, there is no seperation of powers, the police act under dication and the people are (ultimately) silenced.


With regards to the government's lies on the Victorian 'State of Emergency':

In respect of subordinate instruments, The Presumption of Validity does not apply in the case of such instruments; therefore a prosecution must prove the legality of the Stay at Home Directions beyond reasonable doubt (which requires it to prove, inter alia, the legality of the Declaration of Emergency); and Must disclose the evidence upon which the prosecution relies upon as the alleged proof of the legality of the said instruments as part of its duty of disclosure in criminal proceedings.

See court docucment:

Document source: https://constitutionwatch.com.au/there-was-no-victorian-emergency/

17 November 2022

Victoria Police Corporate Plan 2022-2023


Victoria Police, a 'corporation' or 'business' with a 'trading name' of "VICTORIA POLICE" is telling you it's prospectus for the financial year of 2022-2023.

MANY people consider this label of the police being a business/corporation/trading entity (POLICE DEPARTMENT (VIC)) a 'conspiracy theory', where even if you confront an 'employee' at a road side stop, you may be laughed at or considered mentally unstable or even labelled as a terrorist or more precisely a sovereign citizen (technically an oxymoron).

BUT, in reality the evidence is in the government's own documentation:


This is 'unlawful' as these 'entities' must be departments of the state, as per the Commonwealth Constitution, but that is another topic outside of the scope of this post.

Did you ever get an 'Infringement Notice' with their ABN (63 446 481 493), as required at law?

See the corporate plan:



Victoria Police want you to forget their (illegal, unlawful and criminal) actions


BUT they will not forget their unalwfully issued 'C-19' fines.

16 November 2022

Australia, the White Elephant project colony


The Australian Taxpayers’ Alliance was privileged to attend the recent launch in Brisbane of this very enlightening book. Brought to you by Connor Court Publishing and edited by David Gration, Bruce Kingston and Scott Prasser, White Elephant Parade catalogues some of the biggest, most unworkable white elephants across recent government policy.

Given our obvious enthusiasm for rooting out and exposing White Elephants wherever various governments try to hide them, we eagerly secured a copy - signed by all three editors - to give away to one lucky follower.

Simply fill out your details below, tell us about your favourite White Elephant and we’ll send it out to the best entry.
If you miss out, you can always grab a copy from the Connor Court website.

See: https://www.taxpayers.org.au/white-elephant-stampede

Hear: https://soundcloud.com/user-132698377/abc-612-brisbane-white-elephants-20221109