Posts

Showing posts from May, 2007

How Secure is your Bank's Call Centre?

I have long suspected Call Centres are one of the main places where Credit Card and Bank details are stolen. Today BBC Scotland will air a TV programme where they have uncovered this as a fact. The BBC sent in an undercover reporter into a Scottish Call Centre, operating on behalf of several financial sector organisations. The report showed how lacs the security training and security controls were, with the reporter easily able to write down and remove personal banking details at will. The programme also focuses on how organised gangs have infiltrated the Cal l Centre, and traces back a guy who had his account used for money laundering, by a gang operating out of the Call Centre. UK Call Centres are renowned for having a high staff turnover and low paid staff, so it’s a no brainer that this is a recipe for a higher tendency and greater risk for internal fraud. However my personal worry is with those "offshore" Call Centres in countries outside the European Union. I mean...

Google – "Don’t be Evil" - My Arse!

I continue to worry about Google and where they are going, for company that has an informal motto of “Don't be evil”, they potentially are doing some evil things. Don’t get me wrong, I think Google is by far the best search engine there is, I have been using it as my default search engine since the late 90s, just after they went live. One of the reasons I preferred them over the dominate “Yahoo” search engine in the early days, was because Google was just a simple search engine, the search engine page didn ’t have loads of crappy media bits and adverts around it, a huge plus in those low bandwidth modem days. These days Google are offering many extra services, and to be fair most are free to the user, but don’t worry they make plenty of money from advertisements. Some of these extra services are going to give Microsoft some decent competition for once, which is a big plus in my book. So what are my concerns? Well first of all, just in case you didn ’t know, Google record every s...

Wi-Fi Health Risks

Wi - Fi was in the news in relation to possible health risks associated with exposure, apparently they wi - fi devices and hotspots give off radiation beyond that given off by mobile phones, although you don't exactly put your wireless network cards to your head like with your phone. It's one of those grey areas where the technology hasn't been around long enough to make a health assessment based on prolonged use, as it might be years before health effects are known, I mean you don't exactly get lung cancer from cigarettes overnight do you. It's pretty much too late to stop the relentless roll out of wi - fi in the UK now, since there are wireless networks and wi - fi hotspots just about everywhere these days. I must admin for many years when I have been configuring wi - fi access points, and I always get a headache, but then again I get a headache whenever I go near a power pylons too, perhaps I'm just sensitive like that or it's just psychological...

New Podcast Released

I have just released IT Security Expert Podcast Episode 2, which focuses on Mobile Phone and Bluetooth Security. You can subscribe/download via iTunes or from the main site, www.itsecurityexpert.co.uk

BlueTooth Security

We all have mobile phones with a BlueTooth wireless capability these days, but what are the risks and the hacking techniques being used against? Basic Phone Security Always protect your mobile phone with a pin-lock password, think about the information you have stored on your phone, not just the phone contacts, but records of your calls, text messages and even voice mail, if it's not needed, delete them. If you ever sell your phone, give it to charity or trade it in, make sure you delete all the information on the phone, there is always a "master reset" option someone within the menus. It's amazing how many second hand phones you can you buy off eBay will the information still intact, pretty scary stuff if it's your private information. Make sure you do not use 0000 or 1234 as your Bluetooth pin code, it's the first pin codes any hacker will try, and they will get in no matter what phone firmware you are using. BlueTooth Hacking The big security weakness with ...

Wireless Networking

So I'm sat at home, I boot my laptop, and my wireless network card instantly detects 3 of my neighbour’s wireless networks. None of them I would consider as being secure. Being a member of ISC2 and I have strict ethical code of practice to adhere to, so I would never dream of hacking any networks or PCs without the written permission of the owners. However without using any specialist software I can tell these networks are not secure. One of the networks even has zero security, meaning anyone with a Wi-Fi network card could attach to and use it, and getting free broadband access and possible access to files on any PCs in that household,very bad indeed. The other two wireless networks my laptop picks up do have some security, but not enough. The fact I can see their SSID names is not a good sign, the broadcast of a SSID name is great starting point for any would be amateur hacker out there. Even worst, one of these networks is using the default wireless router name, which probab...

Home Network Security Scrutinised

I found the following article on the BBC news website, which happens to be exactly what I had been talking about in my presentations this week. None of the findings is surprising to me, but I find many people I talk with are in the dark about digital security. Anyway, I thought I'd write this post about it and start my own blog. Home computer users who leave default passwords on network hardware unchanged could be at risk from attack say security experts. Researchers created an attack that surreptitiously redirects a user to nefarious sites once they have visited a booby-trapped webpage. The attack works by re-writing the address book in network hardware to point victims to the scam sites. About 50% of users leave default passwords unchanged, suggests research. The theoretical attack was explored in a paper written by researchers from the University of Indiana and security firm Symantec. In the paper, the authors detail how to compromise the routers many people use to sh...