Posts

Anonymous network will be popular

There is a sad but true story that corporate-PR "corrected" wikipedia pages in order to downplay the mistakes done by company and government organizations. Some of the "corrections" may be a true account of history but there are deliberate censorship. Most people think the network address (IP address) are useless and could not reveal the location or identity of individuals. However, most IP address is similar to telephone number and could be traced to specific organizations. This traceability enabled Wikiscanner (mentioned in the article) to find the editor of wiki. There are some anonymous networks like Tor for people to conceal their identity. I believe the PR will continue their censorship on wikipedia with these anonymous networks. It is sad that when truth is the battlefield between individual and large organisations.

"science may be the main determinant of how a case is resolved"

The gap between law and science is ever widening. In the past, the court is a place for justice but now justice is bury among scientific experiments and mathematical calculations. Judges trained to filter fake science from USA Today

Stealing credit card numbers via home Wifi network

The Hong Kong district court heard a computer crime case on 18th June 2007. An African visitor had rented a flat and stole credit card numbers from his neighbor using wireless sniffing, then he used the credit card information to do online shopping. The charge was brought under HK Crime Ordinance Chapter 200 s116 . More detailed information will be available when the judgment is posted online. The 23-year old defendant was caught since he had used his home address for online shopping and the police were able to trace the delivery records. His ignorance of fraud detection systems and traceability of online shopping transactions seems to suggest that he is not a professional criminal. There are lots of ways to use stolen credit card numbers, buying cash coupons and delivering to an unoccupied house's mail box are common. According to statistics , credit card fraudis increasing and costs 3 billion USD in 2006, up from 2.7 billion in 2005. Different measures (like adding chips or usi...

DDOS attacks are getting more frequent

On 7 June, there was a reported case of a successful botnet Distributed Denial of Services DDOS attack. This type of attack was difficult to prevent since current technology could only divert the traffic after the attack has been launched. Due to the fact that the sources of attack are highly distributed, we could never monitor nor stop the DDOS attack. Once the attack is launched, the affected system will be unable to response to normal users. DDOS attacks are real and there were even reported cases on DDOS against a national body Estonia . The scary thing about DDOS is the growing number of botnet . With the higher penetration of broadband internet, more computers will be connecting to the Internet 24x7. If the management of these computers is not done securely, they will be a breading ground for botnets and viruses. One area to pay special notice to is the growing trend of networked devices. Vetting machines, CD juke boxes and other everyday electronic devices are likely to be conne...

Catch up with the Web

I saw an article on Yahoo news about "25 Web Sites to Watch " and the web advanced so rapidly that one could never be able to catch up. I grouped some of the web sites according to their features. One thing I noticed is that the web is getting specialised and each website is good doing one particular domain. This fragmented development is the result of a distributed web but in history every development will eventually reverse its course. " speculated that the Internet will become, in essence, a vast operating system" Popfly Yahoo Pipes Goowy Data/Opinion Site BuzzDash Swivel Multimedia Web creation tools SplashCast Squidoo Yodio

WAP Volumn in China

China Internet Network Information Centre released a survey result on the current usage of WAP in China. As of March 2007, there were 39M WAP (Wireless Acccess Protocol) users, about 28% of fixed Internet population in China. Not too surprising, Guangdong Province has the large WAP population. The report summary could be find here .

Transfer files on P2P is an offence in Hong Kong

The legal battle on BitTorrent cases reached an end on 18 May 2007 and the full judgement released on Hong Kong Legal Information Institute On 12 Jan 2005, officers from HKSAR Custom Department raided thedefendant's (Mr. Chan) home after tracking his address from an online forum. Mr. Chan he had uploaded 3 .torrent files on 10 Jan 2005 and 11 Jan 2005 to the forum and these enabled BT users to download copies ofmovies. In first instance, Mr. Chan was charged by virtue of section118(1)(f) of the Copyright Ordinance, Cap 528 and of obtaining access to a computer with dishonest intent, contrary to section 161(1) (c) ofthe Crimes Ordinance, Cap 200. But in the final judgement in the Court of Final Appeal, the 5 judges unanimously dismissed Mr Chan appeal andhe was convicted of 118(1)(f) of the Copyright Ordinance only. This was a high profiled case and the HKSAR government launched propaganda on their determination on combating the copyright battle. Since charges was brought to the cou...

Control points missed in Symantec

This morning I heard astounding news about Symantec. It released a faulty virus definition that deleted (or quarantined) two essential files on Windows XP (Simplified Chinese Version). The result was that around 3 millions computers were unable to start and must restore the deleted files from the original Microsoft installation CD. SANS and Sina confirmed this news. They claimed that only people who downloaded the updates from the Symantec China webpage between 01:00 a.m. and 02:30 p.m. on May 18th AND have MS06-070 installed on their computer were affected. This incident has many implications. The one that worries me the most is that people will try to download these files on the web in order to repair their computers. The integrity of these files is in question (if they do not come from an authenticated source). A malicious hacker may plant a virus or backdoor in these system files and offer them in discussion groups. As an auditor, I always think of process control. There are ac...

The root of China SMS-based Payment

Image
McKinsey recently released an article on the prospect of a SMS-basedpayment system in China rural area. The arguments were that China has a low level of non-cash payments when compared to other countries and the Chinese government is keen to develop non-cash payments in order to simulaterural spending. There are both economical and political reasons to have an efficient rural payment system. I agree with the article's contention that ATM and POS are not the right products for Chinese farmers. The main reason is cost. While the annual income of the averagefarmer in China is below USD 2000, it is relatively costly to acquire and maintain an ATM or POS, which usually costs more than USD 20000. Apart from cost, there is also a trend in other countries of declining rates of ATM adoption. According to the BIS statistics , the number of automated banking machines per million inhabitants decreased by 1123 in the year 2000to 1069 in 2005. However, the picture portrayed by McKinsey seems to ...

CFCA -- the China next payment infrastruture

There was a news about 16 China Banks released a press release about a coordination framewrok between banks against online fraud (網上銀行反欺詐聯動機制) The banks will share their fraud information with China Financial Certification Authority CFCA, which was found by the banks in year 2000. CFCA is a certificate authority (i.e. a PKI service provider) and from ChinaTechNew.com 25 banks uses their certificates in 2005. If this alliance is successful and continues its development, I think CFCA has the potential to be the center of China payment network. A secure PKI is important, especially for using client-side authentications. When the banks establish a cross-banks PKI process and agreements, the payment network may function a bit like VISA in plastic card business. For China, the development and innovations are unlimited.

Internet Law -- A US testmonial

When we talk about Cyberspace, we usually think of US. Partly due to there technology innovations and partly due to their obsession about Internet. Then it is not surprise to know US has many legislations on regulating the Internet and citizens' cyber-activities. Below is an snapshot of the status of Internet regulations in US and quite interesting. http://www.imanet.org/technotes/stnewsb.asp

When there is no choice .. ...

I joined a discussion forum oragnised by Legislator CK SIn on 26 Apr at HKPC where a group of industry leaders are invited to express their view on Hong Kong Government consultation paper on new copyright legislations. The speakers concentrated on two major themes: 1 Criminalisation of infringing downloading 2 Requiring ISP to keep IP-to-Physical Address records One important discussion item was that almost everyone acknowledged the fact that a viable business model is needed for substantial development of online contents. But when there is no widely adopted business model, legislations are considered necessary. PISA is monitoring these developments and will submit our views to the government.

IEEE 1667

The IEEE is working on a standard for USB and other flash authentications. The new protocol is a standardization on how a USB disk could authenticate against a computer. That is how you could limit which portable disk to be able to store your data. It is a long-waited protocol and is vital for protection against data-theft. Authentication in Transient Storage Device Attachments The standard will be published in June 2007

RFID ticket in China

Image
I saw some puzzling situations when I traveled to GuangZhou (southern China) this weekend. GuangShen Railway installed a RFID ticketing system and all tickets are embedded with a electronic circuit (photo 1). RFID application on train ticket is quite advance. In last winter,I traveled to UK and Sweden but did not see any RFID application in transportation system (even airlines). What puzzling me is the ticket-checking in Photo 2. You could see there are two railway staff standing behind a gate to check passengers ticket. The narrow opening is to prevent people from passing the gate. Except the tickets embedded with a electronic circuit, very little has changed. The railway staff still need to validate passenger's ticket one by one. When a few hundred passengers passing through the small gate, one can image the chaos it created! China being late in infrastructure investment projects are applying advance technologies but this example shows that the benefit of technology may not be r...

PCI Industry standard audit checklist

Image
IT Compliance Institute just released PCI Industry standard audit checklist . It also include a self-assessment questionniare.

Poorly regulated DNS services

For most of the telecom service (from dial-up, broadband, network TV), the services are regulated by country government. Consumers depend on the government to ensure proper operation of telecom services since these services affect a large scope of the society and the services are very technical. However, domain-name registrars are poorly regulated according Business-Week. Not that government-regulation must be good; it could be self-regulated (like the industry-associations). The current state of DNS is worrying. This phenomena is not unique in US. In HK, Hong Kong Internet Registration Corporation Limited is also a commercial organisation but the government sent one senior official to sit on its broad.

User education is missing !

The reports on China as a centre of Cybercrime and SPAM is appearing. In this Western media article, cybercrime problem is associated with use counterfeit software ! I think more importantly is that the user educations is weak. The OGCIO has radio drama to teach HK people to protect against phising and other online risk. But do we have similar radio broadcast or media attentions in China! Is there a government division work on user educations!! http://www.businessweek.com/globalbiz/content/feb2007/gb20070221_774722.htm?link_position=link2

Anti-Online Game Addiction System implemeted in China (country-wide)

I am not in the online game industry and not sure about the statistics about online game addiction. But China government is serious about stopping online game to become a social problem. According the Chinese article below, a country-wide anti online game addiction system will go live in Jan 2007. The system will monitor user activity in RPG games. When a user spend more than 3 hours per day playing games, their gaming-scores will reduced to 50%. All online game company will need to modify their system to enable the monitoring. China is not leak of innovation when it comes to online monitoring and controls. http://www.ce.cn/cysc/tech/yw/200701/18/t20070118_10130593.shtml

Internet Blackout Seminar @ PISA

2 weeks after the earthquake strike Taiwan, Hong Kong is still suffering slow internet surfing, although 70% of website is not accessible. To understand the impact of this event to our society, PISA organized a seminar and invite industry experts. Panel Discussion: Internet Blackout - Lesson Learned from Large Scale Network Disruption Date 20-Jan-2007 (Sat) Time 2:00pm - 5:00pm

Undersea cable damage bring an issue of operantion risk in Basel

The earthquake stoke southern Taiwan on 26 Dec caused a major disruption of network communication in Hong Kong . It is believed that several cable connecting Taiwan, Japan and US were damaged and the restoration will take days. As banks and stocker brokers rely heavily on electronic settlement and straight though system, their operation are affected. Especially cross country trading, i.e. accepting oversea order to be executed in Hong Kong Exchange and at the same time, placing order to the US market. One of my broker in HK informed me that they will not be able to accept buy order until the network is restored (sell order is possible since they will execute instruction with telephone). The real issue is with STP system, there is a timeout value for each data transmissions and the timeout value is usually set to a reasonable time under normal network connections. The system may retry after timeout but the number of retry will only create more traffic on an already congested network. Th...