Feeds

Chinese boffins provoke Oz speed camera kerfuffle

Case binned after image algorithm cracked

Next gen security for virtualised datacentres

Chinese scientists are the unlikely heroes of a New South Wales speeding case which saw a Sydney magistrate dismiss the charge against an alleged speed merchant because the Roads and Traffic Authority (RTA) could not prove that its vital photographic evidence was "secure", news.com.au reports.

At the centre of the brouhaha lies the MD5 algorithm, used to "store the time, date, place, numberplate and speed of cars caught on camera", as smh.com.au explains.

MD5 is intended to safeguard against tampering with this information by turning it into a 128-bit sequence of digits. However, the chaps from the China's Shandong University proved it was possible to alter the data and retain the same code, ie, the RTA could theoretically change, for example, the car's speed without any evidence of tampering.

The whole thing came to a head when lawyer Denis Miralis used this possible abuse against the RTA in the case of a man allegedly caught speeding in a school zone last November. In June, Magistrate Lawrence Lawson gave the RTA eight weeks to produce an expert willing to testify that the photos had not been doctored. When the RTA failed, Lawson threw out the case and awarded the defendant AU$3,300 costs.

Miralis immediately demanded an enquiry into all NSW's 110 speed cameras, declaring: "The integrity of all speed camera offences has been thrown into serious doubt and it appears that the RTA is unable to prove any contested speed camera matter because of a lack of admissible evidence."

Unsurprisingly, the NSW Law Society admitted the judgment might "open the doors for other drivers caught by speed cameras to mount the same defence".

As for MD5, encryption expert Nick Ellsmore said: "Since the [Chinese] research came out, we've been recommending that clients move away from MD5 and we've certainly recommended that people don't use it for new applications." ®

Next gen security for virtualised datacentres

More from The Register

next story
MEN WANTED to satisfy town full of yearning BRAZILIAN HOTNESS
'Prettier, better organised, more harmonious than if men were in charge'
Cops baffled by riddle of CHICKEN who crossed ROAD
'Officers were unable to determine Chicken's intent'
Yes, but what are your plans if a DRAGON attacks?
Local UK gov outs most ridiculous FoI requests...
Drunkards warned: If you can't walk in a straight line, don't shop online, you fool!
Put it away boys. Cover them up ladies. Your credit cards, we mean
Why your mum was WRONG about whiffy tattooed people
They're a future source of RENEWABLE ENERGY
Murder accused DIDN'T ask Siri 'how to hide my roommate'
US court hears of cached browser image - not actual request
Chomp that sausage: Brits just LOVE scoffing a Full Monty
Sales of traditional brekkie foods soar as hungry folk get their mitts greasy
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.