Posts

Showing posts from March, 2009

Protect Your Identity & Don’t Implicitly Trust

Image
I was looking at new cars over the weekend, I saw a car I liked and naturally wanted to take it out for a test drive. On making this request, the car sales guy immediately asked to see my driver’s license or credit card.  A little puzzled by the “or credit card”, I asked whether he needed either one to prove I was lawful to drive, or for identification purposes.  The sales guy said told me it was their policy, and need it to prove my identity and to keep hold of for “security” while I took the car out. Identity theft is the fastest growing crime in the UK, and there are certain elements which we cannot control in protecting ourselves, such as when companies lose or have stolen our personal information. But there are many elements we still can control, such as protecting the personal information we have in our possession. A UK driver’s license is one of the strongest forms of proving our identity in the UK, and therefore has value to identity thieves, who can easily clone fa...

UK Payment Card Fraud Continues to Soar

Image
APACS, a UK trade association for payments and payment service providers, released their annual statistics on UK payment (credit) card fraud losses. As expected the APACS statistics shows UK payment card fraud is continuing to rise, breaking the £600 Million a year mark for the first time. 2008 fraud figures announced by APACS In these times of billion pound bank bailouts, these figures might seem small fry, but we should remember these fraud costs are indirectly paid for by all of us payment card holders, and are recouped by card providers through higher interest rates and various charges. The card issuers and banks do cover consumers against payment card fraud losses and usually reimburse all fraudulent card transactoins, but just as insurance fraud losses are factored into our insurance premiums, payment card fraud losses are passed on to consumers, so in the grand scheme of things we all foot the bill for payment card fraud in UK. So we really ought to care more about these risin...

BBC Click’s Pointless & Unethical Botnet usage

After watching the latest BBC Click technology projavascript:void(0)gramme (see http://news.bbc.co.uk/1/hi/programmes/click_online/7938201.stm  and watch on BBC iPlayer ( UK Only) click here ), it is clear BBC Click not only controlled a botnet of 1,696 PCs to send Spam Emails, but actually paid criminals for the privilege! The angle for the BBC Click programme was to illustrate and highlight the internet botnet problem. Which to be fair is a good awareness objective and interesting, however botnets have been widely known about for many years now, certainly within security circles anyway. "After months of investigation and a few thousand dollars, we had managed to buy a botnet from hackers in Russia and the Ukraine ." - BBC Click I'm ALL for raising awareness of cybercriminal activities, but I think BBC Click programme crossed the ethical line on this one, in they actually used a botnet (namely thousands of PCs infected with centrally controlled malware) w...

Spotify: An Application Security Vulnerability

Yesterday Spotify, a Swedish based online music/social networking type business, announced their music application had been successfully breached by a “Group". The Group/attackers managed to exploit what Spotify describe as a "bug" in their software, which is PR spin, yes maybe it's a bug or just bad application design causing the issue, still most security professionals would describe it as a security vulnerability within the application. This vulnerability was fixed on 19th December 2008. I don’t know how or even whether Spotify had been testing their application for security vulnerabilities, but in my view it’s fairly likely a decent third party application penetration test or code review would have uncovered the vulnerability long before it was taken advantage of by the mystery Group. I think it’s dangerous to assume only the “Mystery Group” had taken advantage of the vulnerability, as eluded to on the Spotify breach statement. Just who this Group is ...