Read The Times Australia

Daily Bulletin

Spyware merchants: the risks of outsourcing government hacking

  • Written by: Monique Mann, Lecturer, School of Justice, Researcher at the Crime and Justice Research Centre and Intellectual Property and Innovation Law Research Group, Faculty of Law, Queensland University of Technology

An Australian Tax Office (ATO) staffer recently leaked on LinkedIn a step-by-step guide to hacking a smartphone.

The documents, which have since been removed, indicate that the ATO has access to Universal Forensic Extraction software made by the Israeli company Cellebrite. This technology is part of a commercial industry that profits from bypassing the security features of devices to gain access to private data.

The ATO later stated that while it does use these methods to aid criminal investigations, it “does not monitor taxpayers’ mobile phones or remotely access their mobile devices”.

Nevertheless, the distribution of commercial spyware to government agencies appears to be common practice in Australia.

This is generally considered to be lawful surveillance. But without proper oversight, there are serious risks to the proliferation of these tools, here and around the world.

The dangers of the spyware market

The spyware market is estimated to be worth millions of dollars globally. And as Canadian privacy research group Citizen Lab has noted, spyware vendors have been willing to sell their wares to autocratic governments.

There are numerous examples of spyware being used by states with dubious human-rights records. These include the surveillance of journalists, political opponents and human rights advocates, including more recently by the Mexican government and in the United Arab Emirates. In Bahrain, the tools have reportedly been used to silence political dissent.

image A rally in support of Apple’s refusal to help the FBI access the cell phone of a gunman involved in the killings of 14 people in San Bernardino, in Santa Monica, California, United States. REUTERS/Lucy Nicholson

Commercial spyware often steps in when mainstream technology companies resist cooperating with law enforcement because of security concerns.

In 2016, for example, Apple refused to assist the FBI in circumventing the security features of an iPhone. Apple claimed that being forced to redesign their products could undermine the security and privacy of all iPhone users.

The FBI eventually dropped its case against Apple, and it was later reported the FBI paid almost US$1.3 million to a spyware company, reportedly Cellebrite, for technology to hack the device instead. This has never been officially confirmed.

For its part, Cellebrite claims on its website to provide technologies allowing “investigators to quickly extract, decode, analyse and share evidence from mobile devices”.

Its services are “widely used by federal government customers”, it adds.

Spyware merchants and the Australian Government

The Australian government has shown considerable appetite for spyware.

Tender records show Cellebrite currently holds Australian government contracts worth hundreds of thousands of dollars. But the specific details of these contracts remain unclear.

Fairfax Media has reported that the ATO, Australian Securities and Investment Commission, Department of Employment , Australian Federal Police (AFP) and Department of Defence all have contracts with Cellebrite.

The Department of Human Services has had a contract with Cellebrite, and Centrelink apparently uses spyware to hack the phones of suspected welfare frauds.

In 2015 WikiLeaks released emails from Hacking Team, an Italian spyware company. These documents revealed negotiations with the Australian Security and Intelligence Organisation (ASIO), the AFP and other law enforcement agencies.

Laws and licensing

In Australia, the legality of spyware use varies according to government agency.

Digital forensics tools are used with a warrant by the ATO to conduct federal criminal investigations. A warrant is typically required before Australian police agencies can use spyware.

ASIO, on the other hand, has its own powers, and those under the Telecommunications (Interception and Access) Act 1979, that enable spyware use when authorised by the attorney-general.

ASIO also has expanded powers to hack phones and computer networks. These powers raise concerns about the adequacy of independent oversight.

image Centrelink is using the services of spyware company, Cellebrite. AAP Image/Dan Peled

International control of these tools is also being considered.

The Wassenaar Arrangement, of which Australia is participant, is an international export control regime that aims to limit the movement of goods and technologies that can be used for both military and civilian purposes.

But there are questions about whether this agreement can be enforced. Security experts also question whether it could criminalise some forms of cybersecurity research and limit the exchange of important encryption technology.

Australia has export control laws that apply to intrusion software, but the process lacks transparency about the domestic export of spyware technologies to overseas governments. Currently, there are few import controls.

There are also moves to regulate spyware through licensing schemes. For example, Singapore is considering a license for ethical hackers. This could potentially improve transparency and control of the sale of intrusion software.

It’s also concerning that “off-the-shelf” spyware is readily accessible to the public.

‘War on math’ and government hacking

The use of spyware in Australia should be viewed alongside the recent announcement of Prime Minister Malcolm Turnbull’s so-called war on maths.

The prime minister has announced laws will be introduced obliging technology companies to intercept encrypted communications to fight terrorism and other crimes.

This is part of a general appetite to undermine security features that are designed to provide the public at large with privacy and safety when using smartphones and other devices.

Despite the prime minister’s statements to the contrary, these policies can’t help but force technology companies to build backdoors into, or otherwise weaken or undermine, encrypted messaging services and the security of the hardware itself.

While the government tries to bypass encryption, spyware technologies already rely on the inherent weaknesses of our digital ecosystem. This is a secretive, lucrative and unregulated industry with serious potential for abuse.

There needs to be more transparency, oversight and strong steps toward developing a robust framework of accountability for both the government and private spyware companies.

Authors: Monique Mann, Lecturer, School of Justice, Researcher at the Crime and Justice Research Centre and Intellectual Property and Innovation Law Research Group, Faculty of Law, Queensland University of Technology

Read more http://theconversation.com/spyware-merchants-the-risks-of-outsourcing-government-hacking-80891

Business News

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

Options Available When a Company Faces Financial Distress

Financial distress can develop gradually or arrive suddenly, and when it does, the decisions made in the early stages often determine what options remain available later. Directors who act promptly ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...