Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
An incident at the AusCERT conference where Facebook photos were taken from a user profile without authorisation and published may be a test case for Commonwealth and state computer crime laws, according to Queensland Police.
In a presentation at the BSidesAu conference held in tandem with AusCERT, an IT security expert siphoned personal photographs from a private Facebook account of the wife of another IT security professional.
Police responded to a complaint of an “alleged hacking incident that saw private material obtain” and arrested Fairfax journalist Ben Grubb at the AusCERT conference.
Police also seized the journalist’s iPad.
Responding to questions by SC Magazine today, Detective Superintendent Brian Hay said that the incident could be considered a test case for computer crimes laws.
“We are investigating issues of that nature,” Hay said. “Some aspects of it can most certainly be a test case. It is fair to say that jurisdictions are coming to grips with cyber based investigations.”
The exploit presentation was designed to demonstrate a well-known vulnerability in Facebook in which URL addresses linking to photographs in a profile set to private were obtained in a brute force style attack.
While the attack did not crack usernames or passwords, it may have contravened Commonwealth and State computer crime laws which outlaw unauthorised access to electronic files, police said.
The Commonwealth Criminal Code Act states that “access to data held in a computer… by a person is unauthorised if the person is not entitled to cause that access, modification or impairment.”
Other laws also prevent use of a telecommunications carriage service to harass or menace.
The accessed photos may be considered a proceed of crime.
Speaking of the avenues of investigation, Hay said “other actions have been put in place”.
“We may have people out there that think it is their right to do this. The reality is the online environment is an extension of the community.”
Copyright © SC Magazine, Australia
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.