Friday, April 9, 2010

Staying Anonymous in a Time of Surveillance

Read digital books? Then your e-book provider probably knows which titles you’ve read

From Googling to e-mailing to social networking, every day millions of Internet users unknowingly leave behind digital breadcrumbs while surfing the web, sometimes at the risk of compromising their anonymity. But while there’s technology available to stay anonymous in a time of surveillance, experts say policies and legislation won’t protect us from privacy invasion or being attacked in cyberspace.

As a medium, the Internet has allowed its users an unprecedented level of anonymity. Usernames and avatars hide names and true identities in online forums and communities, and anyone can choose how much to disclose to others in cyberspace. However, while most understand how posting personal information could have severe consequences, very few realize their online activity can be monitored and cross-referenced to reveal clues about their identity.

It’s important to think about every time that you interact with a third party online, they have information about you. You may buy your books online–lots of people buy things online. It’s not just social-networking sites where we volunteer this information; we volunteer it in a lot of ways.


Take the simple task of doing a web search, for example. In 2006, The New York Times reported how
leaked records from AOL revealed how users’ search-engine queries could be linked to their identities. By collecting and analyzing a user’s web searches, AOL’s researchers peeled away the many layers of cyber anonymity, unveiling the identity of user No. 4417749: Thelma Arnold, a 62-year-old widow who lived in Lilburn, Ga.

During a three-month period, Arnold typed into AOL’s search engine sentences such as “60 single men,” “landscapers in Lilburn, Ga” and “tea for good health,” clues that led AOL researchers to her. Commenting on AOL’s practice of storing users’ information, Arnold said to The Times, “We all have a right to privacy … Nobody should have found this all out.”

Search engines are just one of many places that–unknowingly to most–track users’ activity. Traveling through cyberspace, you provide information to others almost every click of the way, including to the ISP that knows your IP address, the browser that tracks which sites you’ve visited, and the cookies that store login or registration identification and user preferences.

How you read and gather information can be very sensitive. People often go on an intellectual journey where they really discover and explore fringes of political thought or other thoughts. It’s not hard to imagine a young person reading up about homosexuality, for example, if they have questions of their sexual orientation. That’s something that’s far from illegal but something they don’t want the world to know.

However, while anonymity allows people to express themselves freely without the fear of retaliation or persecution, there is always a darker side to it: It breeds criminal behavior.

From phishing and spam to botnets and DDoS attacks, global crime rings have been able to form in an environment that fosters concealment. While anonymity in cyberspace is “generally a good thing,” one imminent problem is how criminals are using it in combination with the borderless nature of the Internet to develop international crime rings.

Cyber crime is an international problem and the lack of true authentication leads many to fall victim to scams–419 advance fee frauds, for example. Criminals can freely and openly do business via web forums because they are able to cloak themselves.

As the majority of today’s cyber threats are profit based, criminals don’t want to be caught or have their businesses hampered, either by law enforcement or by competitors, so almost all cyber threats work to be untraceable. Compromised computers act as proxies and/or illicit bulletproof hosting is used to mask true sources. Unless serious investigations are made, at best, most cyber threats can only be traced to a proxy.

The future may bring a realignment of the Internet and its network of networks–untrustworthy networks that provide cloaking for criminals may be disconnected. Businesses that are attacked from anonymous sources may well decide to pull out of those countries that allow for such attacks to [be] carried out. Google is now a prominent example of this.

Wednesday, April 7, 2010

6 Steps to Reduce Online Fraud

What Must Be Done to Protect Business Accounts

What can - and should - a banking institution do to help protect its business customers?

Current Fraud Trends

There are three variations of fraud that is commonly seen as particularly prevalent now:

First Party - where criminals open accounts and use them as pass-through accounts to move money. Additionally, there also may be legitimate business owners who are kiting -- they create additional float so they have additional line of credit. They're not meaning to defraud the bank, but creating float type of credit.

Internal - where employees sell information about a business' accounts to outside organizations. Another scenario is where the small business employee who is accessing the business accounts moves out money and then leaves town. One twist to detecting internal fraud is the possibility that employees who perform the transactions will muddy the trail by saying their account credentials were taken in a phishing email. They can almost use that as an excuse, and it can't be proven unless the business has internet web logs, So it is hard to prove if the employee was colluding with outsiders, or their account actually was phished.

Third party - where most of the warnings are coming in via phishing, social engineering or spear-phishing. There are even infected webpages that can compromise a user's PC. Criminals attack the business, compromise the online credentials and move money out of the accounts.

Areas to Improve Security

Many institutions impose transaction limits as a way to stop fraud. This is a "stop gap measure" and these additional steps should be followed:

Account Level Check - Look at the types of transactions that are happening -- what is typical behavior, logins, when they happen. Then if they start logging in at night or over weekend, that's a red flag to hold transactions until you can talk to the business owner, stopping fraud from taking place. The key is to use analytics to scope "out of the ordinary" transactions. Look across all of the customer's behavior to spot what is unusual for that account holder.

Create Unique Account User IDs - Make sure users all have different log-in identification. Do not let them use the same user name and password. There should be a unique user names for each person in order for the institution to be able to create unique profiles of use for each of the users. This is similar to the PCI requirements; for anyone who accesses data, they each need a separate log-in.

Dual Control - Have two unique users approve transactions. If you can implement that, it goes a long way in reducing the chances of criminals stealing from the SMB account with a single user logon, and it also stops the threat of internal fraud as well.

Multi-Factor Authentication - Even though this solution is susceptible to man-in-the-middle and man- in-the-browser attacks, it is still an effective layer of protection. A lot of times business owners will ask 'I have so many users on the account' how many tokens will I need?' You need a unique token for every user."

SMS Messaging - This out-of-band message to users and account owners is important. It can be bypassed if a criminal can get into and change numbers or email contacts. But an institution can get around that by contacting the old number or email when a change is requested to verify that it was the account holder -- not a criminal -- making that request. This is something that banks already do with address changes. You need to realize that criminals will go in and change email and phone number contact information, so it is a heads-up that something is taking place.

IP-Email Address Controls - Only allowing certain email address/IP locations to go to the bank's online website to do transactions is another good control to put in place. It can be overcome, but it is another good layer of control. What's the risk that someone has just changed their phone and email contact information and is coming in from another email IP location to make these transactions? If they're coming in from another IP address, by looking at the risk, the institution can stop and look at it and question the transaction.

Tuesday, April 6, 2010

Social networking is driving hacker attack strategies

Study says that changes in online user's behaviour – driven largely by the rise of social networking – is pushing hackers to develop ever more sophisticated attack strategies

The report, from Blue Coat Systems, which tapped the data pool generated by its WebPulse security service, says that hackers are developing broader attack strategies, including complex blended threats, faster malware lifecycles and search engine manipulation.

According to to Blue Coat, malware is starting to be adapted by hackers in relatively rapid lifecycles – the average lifespan of a typical piece of malware dropped from seven hours in 2007 to just two in 2009, notes the report.

As a result of this faster malware lifecycle, the study says that defences that require patches and downloads are simply unable to keep pace.

Increased reliance on social networking for communication, says Blue Coat, means there is less reliance on web-based email, which dropped in popularity from fifth place in 2008 to ninth place in 2009.

And, the report adds, exploiting user trust drives most common threats. The two most common web-based threats in 2009 – the fake antivirus software and the fake video codec – both exploited user trust on the internet, search engines and social networks.

According to Blue Coat, these were not the 'drive-by' attacks of recent years, nor did they require a vulnerability to exploit other than human behaviour.

Download the report to read the detailed study and findings.

Sunday, April 4, 2010

iPhone Poses Biggest Smartphone Security Risk

57 of respondents in nCircle survey believe the iPhone carries the greatest security risk

iPhones present the greatest smartphone security risk to the enterprise, according to a recent survey from nCircle, a network security and compliance auditing firm.

The online survey of 257 security professionals was conducted between February 4 and March 12, 2010. In addition to smartphones, the survey covered a range of security topics including healthcare, cloud computing and social media.

Key findings include:

* 57% believe that the iPhone carries the greatest security risk * 39% ranked Google Android as presenting the highest risk * 28% named Blackberry the riskiest * 13% ranked Nokia as having the highest risk * 58% of respondents have a corporate smartphone security policy in place * 65% of enterprises with a smartphone security policy enforce it.

The Director of Security Operations for nCircle, Andrew Storm, mentioned:

"The general consensus is that Apple continues to do only the absolute minimum to address enterprise security and supportability requirements, We haven't seen any new enterprise iPhone security features from Apple since the summer of 2009 when they introduced their new hardware level encryption, which was almost immediately subverted. This is not the kind of behavior security professionals want to see in vendors."

"The good news from this survey is that a greater number of companies are starting to understand the security ramifications of mobile devices. It is encouraging that a majority of companies have a smartphone security policy and enforce it."

Thursday, April 1, 2010

What is 'Reasonable Security?

What is considered "reasonable security?"

When it comes to protecting your organization and your customers from a data breach, what is considered "reasonable security?"

This question is at the center of several ongoing lawsuits, and how the courts answer it may be one of the biggest stories of 2010.

Shedding light on this hot topic is David Navetta, founding partner of the Information Law Group and co-chair of the American Bar Association's Information Security Committee. In an exclusive interview, Navetta discusses:

Current regulatory trends, including the HITECH Act;
Legal issues surrounding "reasonable security;"
How to use existing standards to establish "reasonable security."

It's worth reading interview, please refer here to read further details.

Sunday, March 28, 2010

Chinese student describes how to attack a small U.S. power grid sub-network

Cascade-based attack vulnerability on the US power grid

A paper by Chinese researchers envisioning a cyberattack on the U.S. power grid has ignited concerns in the United States. The researchers outlined an assault on a small U.S. power grid sub-network that triggers a cascading failure of the entire electrical infrastructure.

The paper's co-author, Chinese graduate engineering student Wang Jianwei, says the research is purely theoretical, and that its intent is to find ways to augment power grids' stability by investigating potential vulnerabilities. Although some analysts see the paper as a sign that China has an interest in interfering with the U.S. power grid, University of Pennsylvania physicist Reka Albert disagrees. "Neither the authors of this article, nor any other prior article, has had information on the identity of the power grid components represented as nodes of the network," Albert says.

"Thus no practical scenarios of an attack on the real power grid can be derived from such work." Wang says he chose the United States as a potential target because it publishes data on power grids, and it was the only country he could find with accessible, useful information.

Refer here to read more details about this news and click here to access the research paper.

Friday, March 26, 2010

Fully patched iPhone Hacked

Using all new ARM exploit - Entire SMS database hijacked

A pair of European researchers used the spotlight of the CanSecWest Pwn2Own hacking contest here to break into a fully patched iPhone and hijack the entire SMS database, including text messages that had already been deleted.

Using an exploit against a previously unknown vulnerability, the duo — Vincenzo Iozzo and Ralf Philipp Weinmann — lured the target iPhone to a rigged Web site and exfiltrated the SMS database in about 20 seconds. The exploit crashed the iPhone’s browser session but Weinmann said that, with some additional effort, he could have a successful attack with the browser running.

“Basically, every page that the user visits on our [rigged] site will grab the SMS database and upload it to a server we control,” Weinmann explained. Iozzo, who had flight problems, was not on hand to enjoy the glory of being the first to hijack an iPhone at the Pwn2Own challenge.

Please refer here to read more details.

Saturday, March 20, 2010

Don't download attachments even from trusted source unless you are really sure

Faux Facebook emails use password reset ploy

A widespread phishing campaign is making the rounds that claims to be from Facebook but is meant to infect victims' PCs.

The fraudulent emails arrive with a note stating that the recipient's Facebook password was changed and they can find the new one in an attached ZIP file.

The malicious attachment actually contains an assortment of malware, depending on the message, including trojans and rogue anti-virus programs. The scam is global in its reach and, as of Wednesday afternoon, the malware contained in the phishing run ranked as the sixth most prevalent global virus that McAfee was tracking. It is possible that machines compromised with the Cutwail or Rustock botnets are delivering the spam messages.

Facebook Security, in a status update on its profile page, told users that the social networking site never would send a new password as part of an attachment.

"There's another spoofed email going around that claims to be from Facebook and asks you to open an attachment to receive a new password," read the update. "This email is fake. Delete if from your inbox, and warn your friends."

Monday, March 15, 2010

ATM Skimming: 8 Tips to Fight Fraud

Banking Institutions Must Take Preventive Measures

ATM fraud is on the rise and shows no sign of abating. There is a list of incident response tips for financial institutions that want to fight back against ATM skimming attacks.

Mike Urban, Senior Director of Fraud Solutions at FICO (Fair Isaac Corporation, the provider of credit scoring), says all types of ATMs - and even pay-at-the-pump gasoline stations - are under attack by tech-savvy fraudsters.

"As I have seen, [fraudsters] pretty much go after anyone; it's not one manufacturer or one model."

Several skimmers have been found at gas stations around the country in the last month, and these are where the criminals are placing readers to capture the PIN and the card number before the PIN is encrypted. "I predict we're going to see more of those," he says. "They are targeting the weakness of the mag stripe, and that will be something we have to live with until a better solution is developed."

The Skimming Trends

The current trend began slowly, says Urban. Several years ago, the targets were primarily off-premise ATMs. Criminals could buy ATMs, place skimming devices in them and collect card and pin information. But when changes such as the encrypting PIN pad and other advancements in technology changed how PINs were protected, criminals began focusing on financial institutions' ATMs.

Recent arrests show the criminals perpetrating these crimes are from Eastern Europe. A lot of the techniques and a lot of the technology they are placing on the ATMs are coming from Eastern Europe. Those criminals have been targeting financial institution ATMs for years, primarily because those are the kinds that are deployed -- there aren't as many stand-alone ATMs in Europe.

Incident Response Tips

Action items for banking institutions include:

Have a Plan -- for what you do if you find a skimming device on one of your ATMs.

Document the Plan -- listing everything that should happen, people to be contacted, actions to be taken.

Educate Your Branch Employees -- If a device is found, all employees should know what and what not to do. Educate branch employees and third-party vendors, as well as ATM servicers. Make sure they are monitoring the outside of the ATMs for residue or devices that actually are on the ATM.

Inspect All Locations - frequently, checking the facia and surroundings around the ATMs, making sure nothing has been added or moved.

Set ATM Standards - including visual standards for all ATMs in all branches. Keep it standard. Take a photograph of each ATM, inside and outside. Show employees what it should look like, so ATMs can be quickly examined to see what may be out of place. "It sounds like a bit of overkill, but a picture is worth a 1000 words," says Urban.

Don't Touch Skimmer If Found -- Contact law enforcement if a device is found on the ATM. Tell employees to not touch it or pick it up or pull it off the ATM. Secure the area with bank robbery tape until law enforcement arrives.

Be Vigilant At All Times -- Increase your checks on ATMs, especially if you've heard of ATM skimming in your area. If there are reports of ATM skimming, increase the number of checks. Even if there are no reports, have employees check ATMs in off-hours and over weekends, which are prime times for skimmers to be put on ATMs.

Contact Other Institutions -- Share information with local and regional institutions about what's happening at your branches and make sure they share information with your institution.

If you know of any more tips, please let me know.

Saturday, March 13, 2010

Attack Unmasks User Behind the Browser

Researchers develop proof-of-concept that exploits social networking patterns to 'deanonymize' online users

Vienna University of Technology researchers have developed the "deanonymization" attack as a way to reveal the identity of Internet users based on their interactions in social networks. The attack uses social networking groups as well as traditional browser history-stealing tactics to single out specific users.

The researchers focused on Germany's Xing business social network and Facebook and matched stolen browsing histories with social network group members to identify users. "It is the combination of history stealing and group information that is novel," says Vienna University post-doctoral researcher Gilbert Wondracek. Criminals could use the deanonymization method for targeted attacks, which only requires that the victim visit a malicious Web site that contains the attack code.

There is no fix for the attack, but users can turn off their browsing history or use a private-browsing mode to minimize the risk.

Refer here for more details.

Wednesday, March 10, 2010

US identified cybersecurity as a top priority

US plan to make hacking harder revealed

The Obama administration has declassified part of its plan to improve the security of cyberspace in an attempt to cultivate greater collaboration between government and civilian groups. More cooperation between the private sector and the U.S. National Security Agency is the centerpiece of the Comprehensive National Cybersecurity Initiative (CNCI).

The declassified abstract of the plan reveals that the U.S. Department of Homeland Security will operate a new security system, called Einstein 3, that analyzes email and other data traffic into and out of federal networks. CNCI also urges merged oversight of federal spending on research and development in cybersecurity, with a particular focus on "leap-ahead" technology.

Although the initiative acknowledges that traditional security approaches "have not achieved the level of security needed," it says the federal government is now outlining "grand challenges" for the research community to help solve the most difficult problems.

Refer here to read more details.

Monday, March 8, 2010

GPS vulnerable to hacker attacks

Technology that depends on satellite-navigation signals is increasingly threatened by attack

Experts warn that technology reliant on satellite navigation signals is increasingly vulnerable to attack from widely available equipment. At a U.K. conference at the National Physical Laboratory, professor David Last said the global positioning system's (GPS's) biggest vulnerability is the extreme weakness of the signals that reach receivers, which allows jamming by Earth-based equipment to be executed.

Such jamming has been conducted by military systems for years to disrupt adversaries' navigation systems, but small jamming devices are increasingly available online. Moreover, receivers can be fooled into accepting erroneous data by bogus GPS signals, Last warned. Seagoing vessels are especially susceptible to GPS hacking, given that their systems increasingly use satellite navigation directly as well as feed GPS signals into other equipment.

Refer here to read the news.

Saturday, March 6, 2010

Single sign-on system for Internet session?

The safe way to use one Internet password

Queensland University of Technology (QUT) Ph.D. researcher Suriadi is investigating using an anonymous credential system, an Internet authentication system from the 1980s, to enable Web users to securely log in only once per Internet session. Suriadi says future single sign-on systems could give users access to multiple accounts--including email, bank, and shopping--but would need to provide extreme privacy to avoid hackers.

He says the anonymous credential system could enhance the security and privacy of a single sign-on system. "The system works by revealing as little information about who you are as necessary for logging into an account, therefore allowing you to remain anonymous," Suriadi says. A single sign-on system backed by the anonymous credential system requires the cooperation of business and organizations to enable it, Suriadi notes.

"However, if one of the parties is compromised, for example by a virus, a 'denial of service' attack or insecure set-up, it puts all the user's linked accounts at risk."

Refer here to read more details.

Wednesday, March 3, 2010

Customer Vs. Bank: Who is Liable for Fraud Losses?

Customer raises Key Questions About Responsibility and Security

The lawsuit, filed by EMI in a Michigan circuit court, alleges that Dallas-based Comerica opened its customers to phishing attacks by sending emails asking customers to click on a link to update the bank's security software. In January 2009, an EMI employee opened and clicked on links within a phishing email that purported to be from Comerica. The email duped the employee into believing the bank needed to update its banking software. Subsequently, more than $550,000 was stolen from the company's bank accounts and sent overseas.

EMI says even though the bank had two-factor authentication using digital certificates for its online banking portal, the phishing scam was able to circumvent these measures. The bank says its online security methods were reasonable "because they were in general used by other similarly situated customers of other banks."

Anytime a company incurs a data breach that compromises personal information, the organization risks having its customers walk away for good. That's why it's so important that, before an incident occurs, a company take proactive steps to implement a reasonable security program.

Is a Bank Liable For Phishing?

Should a bank be held liable for a customer's employee falling for a phishing email that supposedly represents the bank?

Most employees have been warned about phishing attempts, but even the most robust training does not protect against occasional human error. Does this training need to occur more frequently, or is it a matter of customizing the training to the evolving and specific types of phishing attempts? If a company is going to be responsible under the law for employees' vulnerability to phishing attempts, that's a pretty good incentive to increase training.

Can a bank be held liable? Some security experts say emphatically 'No.' "The bank clearly could have made better decisions on how to update security information.

What is 'Reasonable Security'?

In this case, was the bank's two-factor security token technology an unreasonable safeguard based on the information available at the time it was implemented by the company?

The key issue here is that What measures were in place to detect unauthorized, unusual activity involving this customer account, and did the bank act quickly enough in response to such detection? "All companies could benefit from evaluating and assessing how they compare the issues raised in this case against their own information security programs.

Banks should view it as a wake-up call and work on mitigating phishing attacks.

Refer here to read more details.

Monday, March 1, 2010

Security Threat Against ‘Smart Phone’ Users

Personal computer security threat can now attack smart mobile phones

Rutgers University (RU) computer scientists have demonstrated how rootkits could surreptitiously instruct a smartphone to eavesdrop on a meeting, track its owner's location, or rapidly drain the battery. Smartphones "run the same class of operating systems as desktop and laptop computers, so they are just as vulnerable to attack by malicious software, or malware," says RU professor Vinod Ganapathy.

Rootkit attacks on smartphones could be especially effective because smartphone users tend to carry their phones with them all the time, which creates opportunities for attackers to eavesdrop, extract personal information, or pinpoint the users location using the phone's global positioning system.




Refer here to read more details about the research.