Thursday, June 13, 2013
Must-Watch Film On Cyber Crime Awareness
Monday, November 5, 2012
No Minimum Age Limit for Identity Theft
Young children have become increasingly at risk for identity theft. In fact, ID theft among victims age five and younger has doubled - just since 2011. According to the 2012 Child Identity Theft report from AllClear ID, children are 35 times more likely to be victims of identity theft than adults.
The impact of identity theft on a child's life can be devastating, affecting the ability to get a loan, scholarship, apartment, credit card or job. For specific ways to protect your child's identity, read the Federal Trade Commission (FTC) fact sheet, "Safeguard Your Child's Future."
It contains instructions for checking your child's credit report, placing an initial fraud alert, requesting a credit freeze, and filing a report with the FTC.
Saturday, September 1, 2012
Don't post risqué photos online
Many of you reading that warning may be thinking "No kidding." But, you'd be surprised how many seemingly self-aware, intelligent, should-know-better adults continue to participate in this risky behavior.
Even if you believe you are posting photos in a private or password-protected location, keep this in mind: If it's on the Internet, it's vulnerable. Hackers have been at this for years and know exactly how to get into "protected sites" to gain access to your information. Plus, the people to whom you've given access to your spicy photos can also copy and post them elsewhere for the world to see and to your embarrassment.
This is particularly evident with the emergence of a recent hacker trend called "fusking." Fuskers hack their way into secure sites with the sole intention of finding nude and other compromising images. And doing unthinkable and unsavory things with them.
Keep in mind the young people in your life may lack the common sense or the perspective necessary to understand just how vulnerable images like these can be, nor what kind of an impact their publication could have on their lives. Frequent reminders and modeling appropriate online behavior are the best ways to prevent your children and others from a potentially life-changing bad move online.
Monday, May 21, 2012
How to protect your Facebook account from hackers?
- Hacking Accounts
When criminals hack a Facebook account, they typically use one of several available “brute force” tools, Grayson Milbourne, Webroot’s Manager of Threat Research for North America, told 24/7 Wall St. in an interview. These tools cycle through a common password dictionary, and try commonly used names and dates, opposite hundreds of thousands of different email IDs.
Once hacked, an account can be commandeered and used as a platform to deliver spam, or — more commonly — sold. Clandestine hacker forums are crawling with ads offering Facebook account IDs and passwords in exchange for money. In the cyber world, information is a valuable thing. - Commandeering Accounts
A more direct form of identity theft, commandeering occurs when the criminal logs on to an existing user account using an illegally obtained ID and password. Once they are online, they have the victim’s entire friend list at their disposal and a trusted cyber-identity.
The impostor can use this identity for a variety of confidence schemes, including the popular, London scam in which the fraudster claims to be stranded overseas and in need of money to make it home. The London scam has a far-higher success rate on Facebook — and specifically on commandeered accounts — because there is a baseline of trust between the users and those on their friends list. - Profile Cloning
Profile cloning is the act of using unprotected images and information to create a Facebook account with the same name and details of an existing user. The cloner will then send friend requests to all of the victim’s contacts. These contacts will likely accept the cloner as a friend since the request appears to be from someone they’re familiar with. Once accepted, the crook has access to the target’s personal information, which they can use to clone other profiles or to commit fraud.
As Grayson Milbourne puts it, “Exploiting a person’s account and posturing as that person is just another clever mechanism to use to extract information.” Perhaps what’s scariest about this kind of crime is its simplicity. Hacking acumen is unnecessary to clone a profile; the criminal simply needs a registered account. - Cross-Platform Profile Cloning
Cross-platform profile cloning is when the cyber criminal obtains information and images from Facebook and uses them to create false profiles on another social-networking site, or vice versa. The principle is similar to profile cloning, but this kind of fraud can give Facebook users a false sense of security because their profile is often cloned to a social platform that they might not use. The result is that this kind of fraud may also take longer to notice and remedy. - Phishing
Phishing on Facebook involves a hacker posing as a respected individual or organization and asking for personal data, usually via a wall post or direct message. Once clicked, the link infects the users’ computers with malware or directs them to a website that offers a compelling reason to divulge sensitive information. A classic example would be a site that congratulates the victims for having won $1,000 and prompts them to fill out a form that asks for a credit card and Social Security number.
Such information can be used to perpetrate monetary and identity fraud. Grayson Milbourne of Webroot, also explained that spearphishing is becoming increasingly common, a practice that uses the same basic idea but targets users through their individual interests. - Fake Facebook
A common form of phishing is the fake Facebook scam. The scammers direct users via some sort of clickable enticement, to a spurious Facebook log-in page designed to look like the real thing. When the victims enter their usernames and passwords, they are collected in a database, which the scammer often will sell.
Once scammers have purchased a user’s information, they can take advantage of their assumed identity through apps like Facebook Marketplace and buy and sell a laundry list of goods and services. Posing as a reputable user lets the scammer capitalize on the trust that person has earned by selling fake goods and services or promoting brands they have been paid to advertise. - Affinity Fraud
In cases of affinity fraud, con artists assume the identity of individuals in order to earn the trust of those close to them. The criminal then exploits this trust by stealing money or information. Facebook facilitates this type of fraud because people on the site often end up having a number of “friends” they actually do not know personally and yet implicitly trust by dint of their Facebook connection.
Criminals can infiltrate a person’s group of friends and then offer someone deals or investments that are part of a scheme. People can also assume an identity by infiltrating a person’s account and asking friends for money or sensitive information like a Social Security or credit card number. - Mining Unprotected Info
Few sites provide an easier source of basic personal information than Facebook. While it is possible to keep all personal information on Facebook private, users frequently reveal their emails, phone numbers, addresses, birth dates and other pieces of private data. As security experts and hackers know, this kind of information is often used as passwords or as answers to secret security questions.
While the majority of unprotected information is mined for targeted advertising, it can be a means to more pernicious ends such as profile cloning and, ultimately, identity theft. - Spam
Not all spam — the mass sending of advertisements to users’ personal accounts — is against the law. However, the existence of Facebook and other social sites has allowed for a new kind of spam called clickjacking. The process of clickjacking, which is illegal, involves the hacking of a personal account using an advertisement for a viral video or article.
Once the user clicks on this, the program sends an advertisement to the person’s friends through their account without their knowledge. This has become such an issue for the social media giant that earlier this year that the company has teamed up with the U.S. Attorney General to try to combat the issue.
Wednesday, February 29, 2012
How to minimize the risk and impact of Identity Fraud?
Javelin Strategy & Research recommends that consumers follow a three-step approach to minimize their risk and impact of identity fraud.
Prevention
- Keep personal data private - At home, at work and on your mobile devices, secure your personal and financial records in a locked storage device or behind a password. Of those consumers who knew how the crimes were committed, nine percent of all identity fraud crimes were committed by someone previously known to the victim in 2011.
Avoid mailing checks to pay bills or to deposit funds in your banking account. Use online bill payment on a secure Internet access (not a public Wi-Fi hotspot) instead and direct deposit payroll checks. - Be social, be responsible - While social networks are popular, be careful about publicly exposing personal information that is typically used for authentication (full birthdate, high school name). This applies to all social networks.
- Use mobile devices responsibly - Mobile devices are a treasure trove of information for fraudsters. The "always on" functionality of mobile devices provides fraudsters with new avenues for securing information. Be sure of the applications you download, the data you share over public Wi-Fi and where you leave your devices.
- Ask questions - Before providing any information on mobile phones, social media sites and transactions sites, question who is asking for the information? Why do they need it? How is the information being used? If volunteering information, ask yourself if you have more to gain or more to lose by sharing personal and unnecessary details.
- Take control - In 2011, 43 percent of fraud was first detected by the victims. By monitoring accounts online at bank and credit card websites, and setting up alerts that can be sent via e-mail and to a mobile device, consumers can more quickly detect if they are a victim of identity fraud and stop it early.
- Learn about methods to protect your identity - There is a wide array of services available to consumers who want extra protection and peace of mind. These include credit monitoring, fraud alerts, credit freezes and database scanning.
Some services can be obtained for a fee and others at no cost. These services can detect potentially fraudulent information from credit reports, public records, and online activity that are difficult to track on your own.
- Report problems immediately - Work with your bank, credit union or protection services provider to take advantage of resolution services, loss protections and methods to secure your accounts.
A fast response can enhance the likelihood that losses are reduced, and law enforcement can pursue fraudsters so they experience consequences for their actions. - Take any data breach notification seriously - If you receive a data breach notification, take it very seriously as you are at much higher risk according to the 2012 Identity Fraud Report: Social Media and Mobile Forming the New Fraud Frontier.
If you receive an offer from your financial institution or retailer for a free monitoring service after a breach, you should take advantage of the offer or closely monitor your accounts directly.
Monday, January 23, 2012
Insider Scams and Fraud a Growing Trend
A 17-year-old was slapped with a 60-day jail sentence after he was busted for skimming credit and debit details while working the drive-thru window at a McDonald's restaurant in Olympia, Wash. This insider scam highlights a card fraud trend the industry needs to watch.
This case highlights just how easy it is for insiders to perpetrate card fraud, especially in a retail environment. Even if we protect the ATMs and POS devices, insider fraud like this will take place due to the ease with which criminals can get their hands on the appropriate devices. This is an industry that clearly needs an elegant and innovative solution (not EMV) that can at least make it an order of magnitude harder for skimmers to succeed.
Transactions Monitored
In the McDonald's incident, the teen's card-fraud scheme was foiled before exceeding $13,000 in losses after transaction monitoring traced the fraud. Detectives connected the dots and linked fraud to the Olympia McDonald's when contacted by the Washington State Employees Credit Union about fraudulent transactions hitting member accounts.
The credit union found one commonality: All of the compromised cards had been used at the same McDonald's. McDonald's management later confirmed the juvenile suspect had worked the drive-thru every time one of the compromised cards had been used.
The teenager used the stolen card numbers, which he collected with a handheld skimming device, to buy gift cards at retail stores such as Walmart and Toys R Us, according to a news report. With the fraudulently purchased gift cards, he allegedly bought about $13,000 worth of merchandise that he later sold on Craigslist and eBay for profit.
The purchases the teenager made included iPads, computers, video game systems and digital cameras, according to the Thurston County Prosecuting Attorney's Office.
The teen has been in custody since Nov. 16, after his parents refused to post bail. On Monday, he pleaded guilty to two juvenile counts of forgery and two juvenile counts of identity theft. As part of his sentence, the court has asked that he pay restitution to the victims whose cards were compromised.
The investigation is ongoing because other suspects may be involved.
Sunday, December 4, 2011
How can a person remove personal information from the Internet?
First, the bad news. As soon as any kind of information, including personal information, is online, anyone can copy and store or post it elsewhere. What's worse, there are tools that are constantly searching the Internet for specific types of data.
4 steps you can take if something gets online that you don't want:
- Delete what you can yourself as soon as possible.
- Contact the website(s) where it is located and ask them to remove it.
- Enlist the help of a lawyer or online data removal service (e.g. Reputation Defender, Reputation Changer) to remove what you can't, or what the website won't.
- Remain diligent and check often (for instance, by setting a Google Alert) to ensure you catch any reposting of the information.
Tuesday, November 29, 2011
BEWARE: Facebook Scam threatening to delete your account!
Experts said the recent assault designed to steal users' Facebook details is among the most sophisticated yet because it mimics the security procedures that sites use to defend against internet trolls and other bad behaviour online.
Thursday, November 17, 2011
How Thieves Steal Your Credit Card Data?
These days, thieves only need a minute, sometimes a second, to pilfer your credit card data.
This year criminals hacked, phished or skimmed their way into the systems of Sony, marketing firm Epsilon, Citibank and even security expert RSA, among others. In some cases, they only obtained names and emails. In the worst cases, they got credit card numbers.
Identity theft and cyber fraud cost Australia a whopping $8.5 billion every year. One in five Australians will be hit and it's getting worse every day.
The most common schemes are simpler than you think. Let's take a look at the most common ways thieves pilfer your credit card information.
Suspect 1: The Waitress At Your Local Cafe
When it's time to pay the waitress whisks away your credit card and swipes it through the restaurant's register. Then, she pulls out a small device, about the size of an ice cube, from her apron and swipes it through that.
While you're scraping the last of the chocolate cake from your plate, your credit card information has been stored in the device, known as a skimmer. The waitress returns your card and performs the same magic trick on dozens of credit cards in a week.
Known Whereabouts:
The data-stealing waitress has been known to moonlight as a bartender, sales assistant or at any place where she can take your credit card out of sight.
Suspect 2: The Toy Store Trio
Mode Of Operation:
Sally, Simon and Greg walk into a toy store. Sally and Simon roam the aisles, while Greg waits in line to check out. When Greg is at the register, Simon comes running up to the shop assistant, screaming that his wife has fainted.
As Sally and Simon distract the shop assistant, Greg switches the credit card reader at the register with a modified one of his own.
For the next week, the shop assistant unwittingly collects credit card data on the modified reader until the trio returns, takes back the modified reader and restores the original terminal.
Known Whereabouts:
The trio will hit other retailers and restaurants, but sometimes the threesome will instead be a duo or a solo criminal.
Suspect 3: The Petrol Prowler
The Petrol Prowler parks her car in front of a petrol station off the highway. It's late. There's no one around except a sleepy shop assistant at the register inside. The Petrol Prowler attaches a skimmer over the credit card reader at the pump. It's a special skimmer: It emits a Bluetooth signal to a laptop close by.
The Petrol Prowler pays, heads off to the motel next door and sets up her laptop to receive the data from the compromised pump over the next several days.
Known Whereabouts:
The Petrol Prowler installs skimmers over ATMs, parking meters, vending machines and any other places with unmanned credit card readers.
Suspect 4: Harry the Hacker and Phishing Phil
Harry the Hacker installs malware - a type of software that damages or infiltrates a computer or network - onto a legitimate website with low security. The malware instantly downloads onto your computer when you visit the site and allows Harry to access your information. In another scenario, Harry puts malware on public computers and gathers the information you share with that computer.
Phishing Phil uses malware to go after your laptop. He sends emails with attachments that promise dancing kittens or some other bait. When the user opens the attachment, malware instantly downloads onto the computer and leaves confidential information vulnerable.
What Happens To Your Information?
Mode Of Operation:
So what happens to these pieces of data when they're in no-good hands? They get sold.
The waitress, trio or Petrol Prowler may be able to sell each swipe for $20 to $40 a pop. Harry the Hacker and Phishing Phil could get $5 to $10 a card and often sell the information online at the eBay of credit card activity.
Identity Theft: How To Avoid It
- Set up mobile alerts for your phone if your financial institution provides the feature. That way, you can be aware of unusual activity as quickly as possible.
- Regularly monitor your accounts online, so you can identify fraudulent transactions faster.
- Avoid public computers. Don't log onto your email if your bank corresponds with you there. One idea is to set up an email account just for your finances and then only check it from safe locations.
- Avoid doing business with unfamiliar online vendors. Stick to established merchants and websites.
- If your information has been compromised, notify your financial institutions immediately and also inform the police what has happened.
Thursday, September 1, 2011
LinkedIn may use your details for advertisement
Did you know that LinkedIn now has a default setting that allows them to use your picture and name in advertising?
Here's how to manually turn it off:
- Click on your name on your LinkedIn homepage. (Upper right corner)
- In the drop-down menu, click "Settings."
- On Settings page, click "Account"
- In the column next to Account, click "Manage Social Advertising." (Lower left)
- Unselect the box next to "LinkedIn may use my name, photo in social advertising."
Tuesday, January 18, 2011
Open WiFi and Firesheep
What’s new about Firesheep isn’t the exploit – HTTP session hijacking has been well known for years – it’s that Firesheep is a simple Firefox plug-in that is available to anyone and requires no technical expertise to utilize. In other words it allows anyone with Firefox and Firesheep to be a hacker. No experience required.
What’s the problem with unsecured WiFi?
If you connect to the internet at unsecured WiFi hotspots, like say your favorite coffee shop or book store, then you have always been at risk of the vulnerability exploited by Firesheep. So what exactly is this vulnerability?
This exploit is commonly referred to as HTTP session hijacking or side-jacking and, it’s been known and used by bad guys for a very long time. Up until now it required some modicum of expertise on the part of the hacker to accomplish a side-jacking attack. The attacker had to use a packet sniffer to capture all those packets flying around, decode the packets to find session cookies in the clear and then create spoofed session cookie responses to join your session. For experienced hackers this wasn’t terribly challenging since they usually had software that would automate the process.
Firesheep was developed for the express purpose of exposing the HTTP session hijacking problem to everybody on the internet, ostensibly to force sites like Facebook to quit making it so easy. This Firefox plugin is named for the notorious Blackhat Wall of Sheep where clueless, unsuspecting users’ unprotected private information is intercepted and displayed very publicly. If you are foolish enough to attend the Blackhat conference in Las Vegas without seriously locking down your communications you will end up on the Wall of Sheep where you will be mocked and worse by other participants.
Firesheep automates side-jacking attacks in a very simple way by building it all right in to your Firefox browser. Facebook advised checking their new Account Security Page, which gives you a history of sign-ins by IP address thereby letting you know if there are two IPs currently signed-in from the same access point.
Anti-Firesheep tools like Fireshepherd were released. Written by Gunnar Atli Sigurdsson, an electrical engineering student at the University of Iceland, Fireshepherd periodically jams the local wireless network with a string of junk characters intended to crash Firesheep when the snooping program reads them.
How can websites keep you secure over unsecured WiFi?
The vulnerability that is exploited by side-jacking has been well understood for years, so too has the solution / mitigation. Consequently your bank has been using this more secure mechanism for most of those years.
On Internet banking websites, an HTTP over SSL (HTTPS) connection is established before you send your credentials to the your bank’s web site. But note that after your credentials are validated, the secure HTTPS connection is maintained for the entire session. In other words once you establish that secure encrypted channel with your bank, everything for the entire session is protected. I know what you’re thinking now:
Why doesn’t Facebook, Twitter and Flickr do their sessions like this? Clearly they have the SSL capability because they use it for the logging in part of the session. It turns out that Eric Butler, the developer of Firesheep, was motivated by exactly these questions. Quoting from the announcement on his blog:
This is a widely known problem that has been talked about to death, yet very popular websites continue to fail at protecting their users. The only effective fix for this problem is full end-to-end encryption, known on the web as HTTPS or SSL.
There are several reasons that websites don’t use strictly HTTPS sessions. First, they want their sites to be accessible to the largest possible audience, including users of older mobile devices that may not support HTTPS connections. Second, there is a lot more overhead involved on both ends when everything is encrypted. Those are the main reasons, but I don’t mean to imply that they good reasons. The first reason may have been valid five years ago, but smart phones and other portable devices have come a long way in that time. The second reason may have been valid before broadband internet connections were ubiquitous, but certainly no one in a WiFi hotspot is connecting via a modem at 28K. Besides, it would be easy to keep the legacy mode connection for those few users who actually have old smart phones or dial-up connections. As always, the real reason is financial.
They would have to develop and roll out changes to not only the web servers but to all of those slick little apps that everybody is using. Remember the problems that Microsoft encountered when making Hotmail use fulltime HTTPS that were mentioned earlier.
What can you do to be secure over unsecured WiFi?
So while popular websites like Facebook are trying figure out how they can fix this problem with the smallest amount of effort, what can you and I do if we want to mess around on Facebook while enjoying a latte at our favorite coffee shop? There are several approaches you can take but the goal is to create a secure connection between your web browser and the insecure website. The best way to do this is to connect to a secure Virtual Private Network (VPN) and once that secure connection is established, surf wherever you like since the last hop on the journey to and from your web browser will be secure. This is great if you have access to a VPN like most road warriors use to connect to the office. Problem with that is that most businesses take a dim view of using VPN bandwidth and company resources to play around on Facebook.
You could install a VPN at home, but that is not an exercise for the fainthearted. There are some subscription based VPN services such as Hide My Ass (HMA http://hidemyass.com/ vpn/) that will provide a VPN to anyone for a fee. It’s not terribly expensive (1 month for around $12 US or a year for around $80 US) and is certainly easier than setting up your own VPN and way cheaper than getting fired for misusing the company VPN.
Finally there are browser add-ons that attempt to force HTTPS connections to sites that don’t offer them, like say Facebook, Twitter or Flickr. Unfortunately there are many websites where these just won’t work. Furthermore most of these add-ons are implemented as intrusive toolbars and egregious ad-ware.
Wednesday, January 12, 2011
Beware - Facebook phishing scam
The email, which resembles genuine friend requests, includes the message `Hi, the following person invited you to be their friend on Facebook’ and an invitation to join the social networking site.
Symantec security channel product manager, Robert Pregnell, said the email can be identified as a fake because it has no confirm button and there is no prompt for an email address to sign up to the site.
“At this time we can’t say that this particular email is of a particularly aggressive or high-profile attack,” he said.
According to Pregnell, the emails can be stopped by checking the privacy policy and user account settings on the social networking site. He also advised users to have separate passwords for different accounts and regularly update their internet security.
“Have a different password for each online account and stay updated,” he said. “Make sure your antivirus, internet security, operating system and web browser software is up-to-date.”
“Multi-layered internet security programs offer additional protection with strong, non-obtrusive firewalls, watching for personal details going out of your computer, and for suspicious behaviour, even by legitimate programs on your computer.”
McAfee Asia Pacific chief technology officer, Michael Sentonas, said the Facebook phishing scam is designed to trick the recipient into going through the login process in order to accept the new friend request.
“For the unsuspecting people that do click on this and submit their login information, they may appear to login as they would normally, however, their credentials are almost always sent to the scammer as well,” he said.
He said research conducted by McAfee has shown that as much as 85 per cent of emails in some months are spam, including these types of phishing scams.
Saturday, October 30, 2010
Identity Theft: Trends, Patterns and Typologies Report
According to a new ID theft report from the Financial Crimes Enforcement Network, most cases of ID theft are linked to a victim's family members or coworkers.
John Summers, a project officer at FinCEN and a lead in FinCEN's report, "Identity Theft: Trends, Patterns and Typologies Reported in Suspicious Activity Reports", says ID theft perpetrated by family, friends and business partners ranked No.1 among SARs filed by U.S. depository institutions in 2009. "In 27.5 percent of the filings, this was the highest," he says. "It basically means someone close to them was getting access to their files and using their information."
In the FinCEN study, of the 372 depository institutions reviewed - a mix of banks and credit unions of varying assets sizes - the majority of ID theft incidents, not surprisingly, were reported by the largest financial institutions.
Identity theft was the sixth most frequently reported characterization of suspicious activity, trailing money laundering, check fraud, mortgage-loan fraud, credit-card fraud, and counterfeit-check fraud. In the study, FinCEN defines identity theft as involving the theft and misuse of unique identifying information, such as financial account numbers, depository accounts, investments, loans, credit cards, online payment accounts, officially issued federal or state identification documents, and biometric information.
Impersonation of an actual person without consent also fell into the ID theft definition, whether that impersonation occurred in-person or through an electronic form or other medium.
The most important takeaway from the study, Summers says: The narrative section on the SAR, which provides the most critical information. "It is very key to the analysis," he says. "Since we added the identity theft box in 2003, we've used the narrative to tell law enforcement what happened; and the more information the banks can provide in the narrative, the more the regulators and law enforcement can do."
Please refer here to download the report.
Sunday, June 27, 2010
Apple customers have no privacy under new policy
Unexpected new privacy rules give Apple and its associated “partners and licensees” the legal right to track, monitor, and store the whereabouts of its customers in real time. Users who do not agree to these draconian measures are prohibited from downloading from the iTunes store.
Apple says that its customers' consent to tracking improves service, although it leaves questions about privacy, security, and safety unanswered.
In spite of a pledge to keep data anonymous, Apple customers have no reason to believe they have any privacy or anonymity. Studies at the University of Texas have demonstrated that customers can be identified by their behavior even when their names are not explicitly stated. Even worse, Apple customers are not told why they are being tracked or who is tracking them.
Refer here for more details.
Friday, April 9, 2010
Staying Anonymous in a Time of Surveillance
From Googling to e-mailing to social networking, every day millions of Internet users unknowingly leave behind digital breadcrumbs while surfing the web, sometimes at the risk of compromising their anonymity. But while there’s technology available to stay anonymous in a time of surveillance, experts say policies and legislation won’t protect us from privacy invasion or being attacked in cyberspace.
As a medium, the Internet has allowed its users an unprecedented level of anonymity. Usernames and avatars hide names and true identities in online forums and communities, and anyone can choose how much to disclose to others in cyberspace. However, while most understand how posting personal information could have severe consequences, very few realize their online activity can be monitored and cross-referenced to reveal clues about their identity.
It’s important to think about every time that you interact with a third party online, they have information about you. You may buy your books online–lots of people buy things online. It’s not just social-networking sites where we volunteer this information; we volunteer it in a lot of ways.
Take the simple task of doing a web search, for example. In 2006, The New York Times reported how leaked records from AOL revealed how users’ search-engine queries could be linked to their identities. By collecting and analyzing a user’s web searches, AOL’s researchers peeled away the many layers of cyber anonymity, unveiling the identity of user No. 4417749: Thelma Arnold, a 62-year-old widow who lived in Lilburn, Ga.
During a three-month period, Arnold typed into AOL’s search engine sentences such as “60 single men,” “landscapers in Lilburn, Ga” and “tea for good health,” clues that led AOL researchers to her. Commenting on AOL’s practice of storing users’ information, Arnold said to The Times, “We all have a right to privacy … Nobody should have found this all out.”
Search engines are just one of many places that–unknowingly to most–track users’ activity. Traveling through cyberspace, you provide information to others almost every click of the way, including to the ISP that knows your IP address, the browser that tracks which sites you’ve visited, and the cookies that store login or registration identification and user preferences.
How you read and gather information can be very sensitive. People often go on an intellectual journey where they really discover and explore fringes of political thought or other thoughts. It’s not hard to imagine a young person reading up about homosexuality, for example, if they have questions of their sexual orientation. That’s something that’s far from illegal but something they don’t want the world to know.
However, while anonymity allows people to express themselves freely without the fear of retaliation or persecution, there is always a darker side to it: It breeds criminal behavior.
From phishing and spam to botnets and DDoS attacks, global crime rings have been able to form in an environment that fosters concealment. While anonymity in cyberspace is “generally a good thing,” one imminent problem is how criminals are using it in combination with the borderless nature of the Internet to develop international crime rings.
Cyber crime is an international problem and the lack of true authentication leads many to fall victim to scams–419 advance fee frauds, for example. Criminals can freely and openly do business via web forums because they are able to cloak themselves.
As the majority of today’s cyber threats are profit based, criminals don’t want to be caught or have their businesses hampered, either by law enforcement or by competitors, so almost all cyber threats work to be untraceable. Compromised computers act as proxies and/or illicit bulletproof hosting is used to mask true sources. Unless serious investigations are made, at best, most cyber threats can only be traced to a proxy.
The future may bring a realignment of the Internet and its network of networks–untrustworthy networks that provide cloaking for criminals may be disconnected. Businesses that are attacked from anonymous sources may well decide to pull out of those countries that allow for such attacks to [be] carried out. Google is now a prominent example of this.
Tuesday, February 16, 2010
Criminals are harvesting and selling Facebook users' information
Facebook users have become easy prey for criminals as more and more people share personal information on the social networking site, says a computer anti-virus company.
Criminals are harvesting and selling Facebook users' information, stealing identities, sending spam and planting viruses, according to AVG (AU/NZ).
People put themselves at risk every day by carelessly clicking on invitations sent by 'friends' to join groups or write on their wall. They put all their personal information including date of birth and photos on their page. They even respond to fake Facebook requests for security details.
To help people stay safe on Facebook, AVG gave 10 tips:
1. Think about who you add: accepting a friend request provides your new mate with access to posts, photographs, messages and background information about yourself. Perhaps go through your list of friends and think about who you really want accessing your stuff.
2. Check privacy settings: Facebook recently got a face-lift, changing default privacy settings. It's worth going through them again - you may be sharing more than intended.
3. Why are you on Facebook? Is it just to share photos? Keep in touch with people? Share links and updates of your activities? Ask yourself what you want to achieve with your profile. It could be better to cut down on information-sharing.
4. Be smart about your password: try not to use the same passwords for all your accounts. Think about the type of security questions you set and where you are sending your updates.
5. Be aware of where you sign in from: When signing in from a different computer, check that it doesn't store your e-mail address and password. It's easy to accidentally choose it to "remember you".
6. Be careful what you say: once status updates and comments are posted, anyone can see, copy, and post it elsewhere. Do you really want people to know you'll be home alone tonight or away on vacation next week?
7. Watch out for phishing attacks: there have been numerous attempts to get users' login and passwords by tricking them with fake Facebook e-mails. Never select any e-mail links asking you to reset your password. Always go directly to Facebook.
8. Take immediate action: If friends start receiving spam from you or status updates appear that you didn't make, your account may be compromised. Immediately change your password. If you can't log into your account, go to the Help link at the bottom of any Facebook page and click on "security" to notify Facebook.
9. Protect your mobile device: Many mobile phones have direct access to social networking sites, including Facebook. Be mindful about who has access to your cellphone and make sure you log off the sites.
10. Monitor suspicious activity: Watch out for suspicious activity on your wall, news feeds and Facebook inbox. Never click on a suspicious link. Look closely, if the link does not look authentic, don't click.
Wednesday, August 19, 2009
Hackers Stole IDs for Attacks
Russian hackers stole U.S. identities and software tools for use in a cyberattack against Georgian government Web sites during the war between Russia and Georgia in 2008, according to a new report by the U.S. Cyber Consequences Unit. The report says that Russian hackers converted Microsoft software into a cyberweapon and collaborated on popular U.S.-based social-networking sites, including Facebook and Twitter, to coordinate attacks against Georgian sites. Although the cyberattacks were closely examined following the war, the connections to the United States had remained hidden until this year.
Personal and credit card information stolen from U.S. citizens was used to register Web sites that launched the botnet attacks, and once the attacks started, Facebook and Twitter were used to exchange attack code and encourage others to join the attack. Experts say the study shows how cyberwarfare has outpaced military and international agreements, which do not account for the possibility of using U.S. resources and civilian technology as weapons.
Identity theft, social networking, and modifying commercial software are all common attack strategies, but combining these strategies raises the attack to a new level, says former U.S. Department of Homeland Security cybersecurity chief Amit Yoran. White House officials are now studying how laws of war and international obligations need to be adjusted to account for cyberattacks. The U.S. Cyber Consequences Unit says the Georgian attacks were perpetrated by Russian criminal groups, and had no clear link to the Russian government, but the time of attacks, which started only hours after the military invasion started, suggests the Russian government may have at least indirectly coordinated with the cyberattackers.
Refer here to read more details about this research.
Thursday, December 4, 2008
Finally New laws to target ID fraud nationwide in Australia
Draft laws aimed at combatting the fraud, which has been exacerbated by social websites such as Facebook, have been introduced to parliament.
Presently, it is only an offence to steal someone's identity in Queensland and South Australia.
Identity theft across the country will be punishable by up to five years jail.
The crime includes a range of offences including using another person's credit card details to stealing their personal information to open bank accounts and take out loans.
Thursday, July 3, 2008
PINS can leak while in transit....
ATM breach reveals PIN problems
Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.
The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs - the numeric passwords that theoretically are among the most closely guarded elements of banking transactions - by attacking the back-end computers responsible for approving the cash withdrawals.
The case against three people in U.S. District Court for the Southern District of New York highlights a significant problem.
Please refer here to read full details.
Thursday, June 26, 2008
ID Theft ruins credit history
A guy went to buy a car, but his credit application was turned down. He was shocked when he called the credit reference agency and was told that he had too many credit cards and other loans outstanding to qualify for any more credit. His credit file had fraudulent loans and store cards, as well as three credit cards taken out in his name. It all added up to over seven thousand pounds/dollars. His local police did give him a crime number, but he has been left trying to sort out the mess.
He found it hard to know exactly what to do. It is now over eighteen months later. A guy still has not been able to get all those fraudulently created entries off his credit record.
All in all he had to contact different companies, write over a 100 letters and make as many phone calls. It is not just the time and money that is difficult for victims, it is the stress. A guy have to deal with debt collectors, been turned down for mortgage and he still cannot get credit to buy that car.
Unfortunately, this guy’s story is common. Victims often find it difficult and time consuming to get their good credit re-instated. They have to deal with many different companies.
What should we do in order to protect our self?
First of all we should use little bit of our common sense. At least, once in every 3 months get a copy of your credit history so you can monitor any unusual credit inquiries. Keep track of your credit applications so that you can match it with the report you get. Last but not least, make sure you give your personal information to right people or organization. Your identity means alot to yourself - it just doesn't ruin your credit history but it also affects your personal life.