Posts

Showing posts from 2009

Facebook Privacy Settings Change Swindle

Image
I logged onto Facebook today and to my utter horror I was automatically forced to page to accept changes to my privacy settings. These privacy settings had defaulted to new settings to replace my existing "secure" settings, which are configured to protect my personal information from strangers. Now I wasn't caught out by this cheap stunt, but I fear many people who had previously made the effort to configure their Facebook acccounts to only share their private information with friends they know, may of been tricked. I only blogged about how to configure Facebook securely a couple of weeks ago, http://blog.itsecurityexpert.co.uk/2009/11/child-facebook-safety.html   My blog posting was aimed at protecting children using Facebook, and I fear this forced privacy settings change will have caught out many children, as I find children tend to have a just click and not read properly approach when using the Internet.  Facebook...

Child Facebook Safety

Image
Recently I was invited to participate on Radio Five Live debate on children’s usage of social networking sites, and specifically child bullying within Facebook. Various parents were calling the radio programme and were saying their children had suffered from issues like cyber bullying and the receipt of obscene messages from perverts. Several individuals thought the answer was to prevent their children using social networking websites and even suggesting banning children from using the Internet altogether. The main point I made was banning children from using social networking sites like Facebook, Bebo and MySpace will just not work, for one banning illegal activities like under aged smoking and drinking doesn’t work, sooner or later children will find a way to access social networking websites anyway, which isn’t illegal by the way. Furthermore preventing a child from using the home PC is a reckless approach in the information age and pretty pointless exercise, as children can ac...

Gary McKinnon Extradition

Image
Gary McKinnon is in the news again after the Home Secretary, Alan Johnson refused to block the intended extradition to the United States. I was invited to comment on Radio Five Live on Friday morning, to raise points on the security and technical specifics of the case. It is clear Gary has plenty of public support in the UK, from people who believe he shouldn’t be extradited to the United States, mainly on human rights grounds. Gary’s lawyers stated he is happy to pled guilty to the crimes in a UK court, therefore he appears to be guilty of these crimes, but his lawyer feel justice just won’t be served if he was sent to a US court. I have actually meet Gary a couple of years back, however my comments on Radio Five Live were made from totally impartial and an Information Security expert’s point of view. Here is a summary of what I said. The main point to understand is, what was the motivation of Gary McKinnon’s “hacking” attack? It clearly wasn’t for fraud, as he wasn’t ...

How Secure is your UK Online Banking?

Image
The UK maybe still in the midst of a recession, but these times are proving anything but a recession for cybercriminals, as UK Online Banking fraud is sky rocketing at the moment. The ‘Financial Fraud Action’ showing a 55% increase for the first half of 2009, while the ‘UK Payments Administration’ figures reports a 44% year on year rise. Through my own research and underground monitoring of UK cybercriminal activity, I am seeing increasing numbers of stolen UK online bank account access details being put up for sale, and increasing numbers of keylogger malware being deployed, which are specifically targeting the theft of UK online bank access credentials covertly. Despite these increases in criminal activity and years of warnings, UK banks still aren’t doing enough to protect their customers from the dangers of the internet. Many UK banks are still yet to provide their customers with a security best practice Two-Factor authentication access to their online banking, so are making it...

TalkTalk’s WiFi Hacking No No!

Last week Internet Service Provider (ISP) TalkTalk pulled a hacking publicity stunt, which they aimed to demonstrate why they should be absolved of all responsibility for the portion of their customers who illegally file shared pirated material. TalkTalk visited a street in North London, and hacked into poorly secured residential wireless networks. Accessing insecurely configured residential WiFi is old news and is illegal, TalkTalk’s point in doing this was to show that anyone could be using residential wireless access points for file sharing illegal material, again nothing new in that either.   http://blog.itsecurityexpert.co.uk/2008/11/reason-to-secure-your-home-wifi.html However the double standards here, is the prime reason why the majority of home wireless networks in the UK aren’t secured to a sufficient degree in the first place, is because ISPs have been providing their customers with wireless access points (routers) in an insecure fashion for years. As far back a...

How the Payment Card Industry could stop Card Fraud

Image
If the payment card industry, the card schemes such as Visa and MasterCard, and merchants really desired to dramatically reduce payment card fraud, it can be simply done. Today, by far the biggest problem with payment card security (credit and debit cards), is the little black magnetic stripe on the back. This magnetic stripe holds the full card details unprotected. This information is referred to as “track 2 data” within the payment card industry. The problem is this magnetic stripe track 2 data can be easily read with a "cheap to buy" magnetic stripe reader (see picture above), allowing fraudsters to “skim” card details quickly in a variety of ways, for instance placing covert magnetic stripe readers on ATMs (see picture below). Track 2 data is also held in plain text on some payment devices and payment processing applications which store this information. Once track 2 data falls into the hands of card fraudsters, they simply create clone cards by replicating the ma...

Secure Encrypted Data Backup on a Budget Tutorial

Image
FOREWORD: It's a bit tricky doing proper document formating and decent screenshots within this blog format, so I have also created separate PDF document for this post/tutorial, which can be downloaded/viewed here - http://itsecurityexpert.co.uk/downloads/ITSE_Secure_Encrypted_Data_Backup_on_a_Budget.pdf One of the most neglected areas of home computing and indeed with many small businesses, is data backup, and properly securing data backup. What personal value do you place on the data files stored on your PC right now? How would your business cope if all the business data held on that single PC was lost? Backing up puts all your data, including sensitive files, in one easier to access single place, how do you ensure it is protected from prying eyes. These days most people have built up quite sizeable collections of digital camera pictures and videos spanning many years on their PCs, which they regard as irreplaceable. And then there is those word processing documents and s...

Who you gonna Trust to repair your PC or Laptop?

A Sky News investigation uncovered the shady dealings of some computer repair shops in London. An undercover reporter presented a laptop for repair at several computer repair shops, with the only problem being an easy to detect loose memory chip. However Sky had rigged their laptop to monitor how it was dealt with utilising keylogger software and they even had the laptop camera video the dodgy goings on. One cheeky rogue trader charged the reporter £130, saying the laptop required a new motherboard, even though the original motherboard was absolutely fine, however more sinister and worrying was the invasion of customer privacy. Computer shop repair engineers were recorded rifling through marked private documents held on the laptop (folder was titled "private"), one scoundrel was captured actually stealing documents, removing them onto a USB memory stick, which included a text file labelled as holding passwords for Facebook, Hotmail, eBay and an online bank account. After l...

A History of Battling Payment Fraud

Image
On Wednesday I popped into The Manchester Museum , and as I strolled into the “Money" collection of exhibits, I was greeted by a bunch of friendly guys sat behind a desk. The desk had various old coins laid out and a sign stating “Please DO Touch”. After a couple of minutes of weighing up and flipping various 2,000+ year ancient Alexander the Great and Roman coins, naturally me being me I started chatting about the fraud aspects, when one of the guys produced a Chinese bank note from the 14th century, which was safely housed in a protective plastic cover. This particular note happens to be one of the oldest surviving banks notes in existence. Now the Chinese invented and started using paper money around 960 following a metal shortage, without copper, silver and gold they couldn’t meet the demand to make coins, although there is evidence of cruder forms of paper money being made by Chinese centuries earlier, but these weren't widely adopted. The construction of the Great Wall o...

118800 Mobile Phone Directory Search Privacy Concerns

Image
"118800” is a new commercial Mobile Phone Directory Search venture, which charges absolutely anyone at all, £1 to obtain the mobile phone number of a UK citizen, searching by name and location. 118800 have amassed a database around 15 Million UK names, locations and mobile numbers for their directory, which was set to launch earlier in the week. I read a quote from an 118800 representative who stated the contact names and mobile phone numbers in their directory were harvested from the public domain, but what they really meant by public domain, was means they probably purchased the information from market research companies, online businesses and information brokers. EDIT 12/06/09: Since I originally posted, a representative from 118800 has been in contact and provided further clarity on the 118800 directory search method. It seems my brief description of service was only partial, so may be misleading. I was unable to fully test the service at the time of posting, as the...

Secret Service tells UK Government not to Publicly Disclose Data Breaches

Image
Are you wondering why there haven’t been any UK Government Department Information breaches making the news headlines in recent months? Has our government departments resolved their poor Information Security Management and poor security cultures? Has other topics such as swine flu and dodgey MP expenses claims kept government data breach headlines out of the press?  I would love to think UK Government Departments have cleaned up their Information Security Act, as I know serious efforts are being made, however we can't really be sure government have stemmed their poor information management tide, as I heard another reason which goes to explain why the once steady drip of media coverage of government departments data breaches has come to a halt. I don’t want to name any names, but I heard a member of government committee working on the Digital Britain report say, government departments had been advised by a UK security service department to stop publicis...

Insecure placing of Chip & Pin (PED) places Customers at Risk

Image
Don't tell the misses, but I walked into a popular fast food restaurant in Central London today, I noticed the restaurant had fixed to the payment counter their Chip & Pin payment devices, these devices are known as Pin Entry Devices (PEDs) within the Payments Card Industry. The problem was they had fixed these devices behind the main raised counter, and the devices had no “pin protectors” on them, so forcing their customers to reach over a raised counter to the cashier's side, to type in the their 4 digit pin numbers. I observed several transactions taking place, each customer did not shield their pin entry with their free hand, probably because it would be too cumbersome to reach over the raised counter with both hands. The net result was most people in the queue and behind the counter could observe the 4 digit pin number as it was typed in. This type of setup is a real goldmine for any potential pickpocket or mugger, as obtaining a payment card together with the pin nu...

A Clear CRB Check means They haven’t been Caught Yet!

Vanessa George, who worked at a Portsmouth nursery, stands accused of appalling sexual offences against young children. Already media reporters are queuing up in criticising the “enhanced Criminal Records Bureau (CRB)“ check, which this apparently despicable person passed, saying the check must of either failed or the CRB checking system itself is at fault. The CRB checking system has not failed nor is the CRB system at fault, as any seasoned security professional worth his salt will know, clear staff background checks does not guarantee an individual is not a dodgy person and is not capable of doing bad things. The truth is no background security check or test can ever provide a guarantee, whether it’s checking airport workers aren’t terrorists, checking child minders are suitable to be alone with children, or a data entry clerks aren’t data thieves. Most organisations with staff dealing with financial information, government data or child care are required to carry out a CRB checks...

EU Elections & Hypocritical Privacy Protection Practices

Image
I reluctantly posted my European electoral postal vote today, reluctantly because I considered not voting at all mainly due to a lack of an anonymous voting system, reluctantly because the European Union Parliament is not very democratic, in that unelected and non-accountable members of committees make the laws, not the people to whom I am being asked to vote to represent me as an European Union (EU) Member of Parliament. Voting choice wise, there is no other option provided other than a postal vote, for whatever reason it is just not possible to vote at a traditional polling station, not in my area anyway. The postal voting system involves enclosing a traditional ballet form within a pre-paid envelope, on which your full name is pre-printed with a unique ID number, your date of birth and your signature. Once sealed, the envelope must be placed into the public postal system as a “normal” letter, with its contents easily identifiable as a voting ballot (see picture). Should the en...

Secure Hard Disk Wiping & Disposal

Image
A study by researchers from the University of Glamorgan and BT, resulted in several alarming privacy headlines in the media today - http://news.bbc.co.uk/1/hi/wales/8036324.stm The study involved the purchasing of old computer equipment from trade fairs and online auctions from the UK, US, Germany, France and Australia, and the recovery of data from these purchased items. The researchers were able recover a raft of personal and sensitive data from hard disks, including detailed medical records from a Scottish NHS Trust, military secrets, business financial transactions and an variety of personal information, which included bank details, and the sorts of things identity thieves crave. The study concluded around 40% to 50% of the second hand hard disk drives they randomly purchased held sensitive data which could be recovered by pretty much anyone with half a brain. I have to say, I am not surprised by this study’s outcome, which highlights the problem of hard disk disposal by both ...

Should companies block Twitter?

Image
Recently I have heard several security professionals say Twitter is a source for corporate information leakage, and therefore must be blocked by businesses using web filtering. Should companies block Twitter? In my view the question is wrong, as I don’t think blocking access to Twitter on corporate networks will do much to prevent business information leakage. The question should be, how do businesses better educate their employees in the usage of social networks such as Twitter, educating instead of blocking will surely do a better job of mitigating the risks of information leakage and company reputation damage. The latter being the most likely outcome of unchecked employee social network website usage. Twitter allows a person to make a 140 character statement to the entire world, so in terms of information leakage it’s not about controlling data files leaving an organisation, the most someone can do is to send an Internet link along with some text, all be it the text element c...