AusCERT Facebook photo hack may be a test case

 

Possible breach of Commonwealth and State computer crime laws, says Queensland Police.

A demonstration at the AusCERT conference in which Facebook photos were taken from a user profile without authorisation and published may be a test case for Commonwealth and state computer crime laws, according to Queensland Police.

In a presentation at the BSidesAu conference held in tandem with AusCERT, an IT security expert siphoned personal photographs from a private Facebook account of the wife of another IT security professional.

Remember to sign up to our Security bulletin for the definitive summary and analysis of Infosec threats.

Police responded to a complaint of an “alleged hacking incident that saw private material obtain” and arrested Fairfax journalist Ben Grubb at the AusCERT conference. 

Police also seized the journalist’s iPad.

Responding to questions by SC Magazine today, Detective Superintendent Brian Hay said that the incident could be considered a test case for computer crimes laws.

“We are investigating issues of that nature,” Hay said. “Some aspects of it can most certainly be a test case. It is fair to say that jurisdictions are coming to grips with cyber based investigations.”

The exploit presentation was designed to demonstrate a well-known vulnerability in Facebook in which URL addresses linking to photographs in a profile set to private were obtained in a brute force style attack.

While the attack did not crack usernames or passwords, it may have contravened Commonwealth and State computer crime laws which outlaw unauthorised access to electronic files, police said.

The Commonwealth Criminal Code Act states that “access to data held in a computer… by a person is unauthorised if the person is not entitled to cause that access, modification or impairment.”

Other laws also prevent use of a telecommunications carriage service to harass or menace.

The accessed photos may be considered a proceed of crime.

Speaking of the avenues of investigation, Hay said “other actions have been put in place”.

 “We may have people out there that think it is their right to do this. The reality is the online environment is an extension of the community.”

Copyright © SC Magazine, Australia


AusCERT Facebook photo hack may be a test case
"However the presenter maliciously chose to target an industry colleagues wife page! "allegedly" Publishing that knowing that this wasn't a dummy demonstration account may well be illegal."
By BaysNet
 
 
 
Comments: 5
Ace
May 18, 2011 5:04 PM
Apparently iPad 2's are very hard to come by, and it appears the police are willing to use any means to acquire one.
meski
May 18, 2011 5:51 PM
Unauthorised? I read it as him having the permission of the wife of other professional, else he would have picked a random account. Who asked for charges to be laid?
BrettWinterford
May 19, 2011 12:10 AM
@meski - I don't think he had the wife's permission. He wouldn't have needed to spend a week guessing URLs for that!
BaysNet
May 19, 2011 11:37 AM
The demonstration was a quite reasonable IT Security demonstration of the vulnerability and insecurity in the hosting of data on the internet, cloud or more specificly Facebook.
BaysNet
May 19, 2011 11:39 AM
However the presenter maliciously chose to target an industry colleagues wife page! "allegedly"

Publishing that knowing that this wasn't a dummy demonstration account may well be illegal.
Comments have been disabled for this article.
 
 
 
Top Stories
Australian miners send drones to work
In-depth: Unmanned aerial vehicles in the resources sector.
 
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 510

Vote