Has Facebook killed the undercover cop?

Tomorrow's recruits have already been compromised
  • Stilgherrian (CSO Online (Australia))
  • — 25 August, 2011 13:58

Face-recognition technology and the near-universal adoption of social networking tools by teenagers could have already made future covert police and intelligence operations difficult, if not impossible, according former Australian Federal Police commissioner Mick Keelty.

"You don't just immerse somebody into an organised crime group. It takes sometimes five, six, seven years to be able to get them into the right place where you need them to be feeding back the intelligence you need," Keelty told the Security 2011 Conference in Sydney yesterday.

Yet that undercover operative's cover could be blown by simply taking photograph and comparing it with images already posted online. Current face-recognition software can even match images taken decades apart.

Keelty is currently researching the policy implications of social networking for covert operations by  police and security agencies in his roles with Charles Sturt University and the Australian National University.

As part of his research, a survey was conducted on all of the recruits for the AFP and NSW Police, and for "some other agencies, national security agencies, as well as some other state agencies" from late 2010 through to February 2011.

"Interestingly, everybody aged 26 years or younger had uploaded their photo onto the internet," Keelty said. 85 percent were using at least one of the major social networking sites. Some 47 percent were using them daily, and another 24 percent weekly.

Of those surveyed, 85 percent had had their photos uploaded by another person, and 42 percent said it would be possible to identify their relationships with other people.

Apart from the massive trove of photographs on social networking sites like Facebook, which receives 100 million new images every day, governments and other organisations can create their own long-term image archives.

"We had anecdotal evidence given to us that outlaw motorcycle gangs were actually going to police graduation parade and taking photos, because some of you in the room would be aware that outlaw motorcycle gangs actually won a lot of tenders for contacts for major entertainment establishments around the capital cities of Australia during the last decade," Keelty said.

"How can you turn up at the Australian embassy in Jakarta and say that you're the trade commissioner for education when you've got a photograph of your graduation from [Royal Military College] Duntroon in 2006 and an unexplained absence from the world in the interim years?"

The same combination of technologies could also make things difficult for witness protection programs, and open up formerly-unidentifiable public servants to the threat of extortion and other crimes.

"Facebook, we have to say, has been difficult in trying to get them to come on board about the privacy issues associated with their network.

But there is a positive side.

"There's a gold mine of intelligence that comes out of all of this," Keelty said, pointing to the use of social networking tools by police in the Queensland floods and for identifying suspects in the UK riots.

View the Security 2011 Slideshow 

Surveillance equipment, robot guards and even a Black Hawk helicopter was seen at the Security 2011 Exhibition in Sydney this week. Neerav Bhatt went along with his camera.

Contact Stilgherrian at stil@stilgherrian.com, or follow him on Twitter at @stilgherrian.

Tags: AFP, Facebook, face recognition, Mick Keelty, networking tools, nsw police, Security 2011 Conference, social media, social networking

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CSO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
CSO Corporate Partners
  • FirEye
  • Clear Swift
  • Trend Micro
  • Sophos
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Cloud Security and Compliance Solutions

Manage and visualize the security and compliance of VMware, physical, and hybrid-cloud infrastructure from the RSA Archer eGRC Platform.

Security Awareness Tip
Clearswift tips: Guidelines for introducing and policing an effective IT Policy

1. Make it clear that the policy is not about playing ‘Big Brother’ but to ensure the security of employees, company information and data and to safeguard the company’s reputation.
2. Invest time to get buy-in from managers and their teams.
3. Convey the message of flexibility – with regard to social media, it is not about blocking staff usage but working in everyone’s interests to ensure that threats are contained.
4. Introduce a regular company-wide training programme that everyone attends at regular intervals throughout the year, not merely as part of an induction programme.
5. Within the training programme make sure that there are specific examples to demonstrate each rule or regulation, and that there is a clear explanation of the dangers of casual or careless talk on social networking sites. Again use examples, employees need to understand the consequences of raising a throwaway comment that has negative connotations for the business, as much as they need to be aware of dangers of making a more direct but ill-considered attack on a competitor, regulator or even a fellow colleague. They need to be clearly advised on any impact on the company and/or legal action or inquires that may be raised as a result.
6. Alert employees to any changes in policy through regular clear communication.
7. Reinforce the operational policy guidelines regularly, cover everything from blogging to Facebook, LinkedIn and Twitter.
8. Ensure that the rules are fair and that they apply throughout the business.
9. Enforce the rules – if there is a deliberate or malicious contravening, disciplinary action needs to be taken. A policy isn’t worth having if it is seen to be lax and unenforced.
10. Review the policy regularly to ensure you keep up to date with new systems and technology.

Phil Vasic is Regional Director, APAC, at Clearswift, the software security company www.clearswift.com
Security ABC Guides

7 Ways to Protect Your Business Printers

Can a hacker burn down your business by remotely setting one of your printers on fire? Researchers at Columbia University have recently proposed such a scenario, although HP quickly denied that it's possible. However, even if your printers can't be used as remote firestarters, there are many risks involved in networking a printer.