Posts

Showing posts from 2011

Why PCI DSS is good for Information Security

Image
There is a growing consensus within the Information Security Community that the Payment Security Industry Data Security Standard (PCI DSS), is actually proving to be detriment to the general information security across the business. One point regularly made is the Payment Card Industry standard is responsible for diverting precious funding and resource away from the overall business information security strategy, where the breach risks can be much greater for the overall business.  That well maybe the case in larger enterprises which rightly regard best practice information security as a business priority, but consider the medium to small businesses, this is the land where information security ignorance is bliss. Within such SMEs  PCI can be a real InfoSec wake up call, as in merely attempting to comply with the many PCI DSS requirements, it can provide benefits across the business, where before the business were previously completely unaware of the risks...

Securely Wiping your Personal Data from the iPhone

Image
It seems like every year Apple release a better 'must have' version of the amazing iPhone, sparking a rush to upgrade by the masses. Ensuring all your precious personal information is securely removed from your old iPhone is an essential step to take before trading in or selling your old iPhone on eBay. Like any smartphone, the iPhone hoards all types of sensitive information about you, not just your embarrassing ABBA playlist and dodgy drunken pictures from the weekend, but all your Emails including access to future mails, username and passwords for websites and social media, and even sensitive financial information such as bank account and credit card details are often stored. So unless you are putting your iPhone through an industrial crusher, you really need to ensure you erase all the data from it before passing it on, this post explains how. This data erasing advice and method also applies to the iPad and iPod Touch If your old iPhone is a 3GS or an above model, then se...

Internet Troll Stomping

Image
I was featured in The Sun newspaper today in relation to Internet Trolls.  Trolling or a Troll is net slang for an individual who intentionally posts inflammatory, insulting or threatening remarks online. Pretty much anywhere where people can feedback comments on the Internet, such as on Forums, Facebook pages, Twitter, YouTube, Newspaper comments, is often subject to abusive comments. People can say the most extreme things when they think they are protected with the shroud of anonymity, words they’d never dream of saying to anyone face to face. However there are increasingly individuals that post abusive comments which go well beyond the boundaries of decency and taste, these are the individuals which are really regarded as the trolls under the definition. Recently a troll was convicted for abusing tribute websites of deceased girls, bringing the whole trolling issue into the public arena - http://www.bbc.co.uk/news/uk-england-14907590 You're not as anonymous as you might thi...

Evolution of UK Home Banking Security - In progress?

I was featured in an article by MSN Money titled "Online Banking Security gets more Complex" http://money.uk.msn.com/news/crime/articles.aspx?cp-documentid=159017310 Nothing ground breaking, but it would appear UK banking consumers are starting to feel the pain of increased online banking security trade-offs, due to UK banks trying to save money by cutting previously acceptable losses from online account fraud. "One person, one bank: three devices But despite the evidence that new measures are more than just inconvenient, many banks are pressing ahead. Lloyds, Barclays, Cooperative Bank, RBS and Nationwide Building Society all require customers to use a card reader when amendments are made to standing orders, direct debits or when setting up payments. "This is called two-factor authentication," said independent bank security expert Dave Whitelegg. How two-factor authentication works The idea is that no fraudster can access your account, however muc...

How to comply with the EU Cookie Law in the UK

Image
There is still much confusion and to be completely frank, some plain old nonsense being sprouted about the so called EU Cookie Law. So I thought it is high time to explain what it is all about, and specifically what UK businesses should be doing about complying with it. I am not a lawyer or an EU Law expert, therefore you should regard this blog entry as guidance and personal opinion. Having said that, it has not escaped my attention, there are some in the legal profession that are jumping on the EU Cookie Directive bandwagon in order to make a quick buck, and even providing very questionable technical advice to UK businesses. If you are already in the know with this issue, you may just want to skip to the bottom paragraph, where I provide my advice – “ How to comply with EU Cookie Law and avoid Fines.” What is the EU Cookie Directive and its requirements? All member countries (states) of the European Union are obligated to adopt EU Directives. One such EU Directive, known a...

Security Breach Epidemic: Are we becoming Complacent about Security?

Image
At the moment hardly a day goes by without a security breach making the news, even as I write this I am hearing the CIA website has been taken down by a ‘Distributed Denial of Service’ (DDoS) attack by LulzSec. These are unprecedented times, as we are seeing large corporations, government enforcement agencies, banks and even reputable IT security companies being successfully attacked, which goes to validate phrases I regularly use, such as ‘there is no such thing as 100% security’ and nothing can ever be considered as being ‘secure’. My face always etches up with contempt when reading words like “this is a secure website”.  So what is going on, why are these breaches occurring now? Are these cyber attacks becoming cleverer and more sophisticated? Are such attacks going to continue? I’ll endeavour to explore and answer these questions in this post. Cyber attacks appear to have reached an epidemical scale, why?  Firstly we must take into account the public breach disclosure l...

PlayStation Hack: PSN Gamers Security Help

Image
On 20 th April 2011, without announcement Sony took down their online gaming network, the PlayStation Network (PSN), which is used by millions of gamers worldwide. I immediately suspected it was hacked, and my fears were confirmed by Sony, who stated between April 17 and 19, they suffered an “illegal and unauthorised intrusion”.   Sony also explained user account personal profile information ‘may’ have been compromised, which presents a major breach of personal information,  a real gold mine of black market personal information for use by identity thieves and card fraudsters. PSN Profile Information at Risk Full Name Full home address Email Address Date of Birth PlayStation ID PlayStation Password PlayStation Security Questions  & Answers (password reset) Purchase History Billing address Credit Card Details When a company uses the word “may” in reference to a data breach, it is always wise assume the information has been stolen and i...

RSA SecurID - What's the Risk?

Image
This week there has been plenty of concern following RSA’s announcement about their two-factor authentication solution, SecurID, which was subjected to a sophisticated cyber attack.  A lot of people are asking for my views on the risk in continuing to use RSA SecurID following this attack, so I am going to attempt to explain this risk in simple terms, but it won’t be easy. Facts What are the facts? Well we simply don’t know exactly what has been stolen from RSA at present, as RSA aren’t providing details beyond “the attack resulted in certain information being extracted from RSA's systems. Some of that information is specifically related to RSA's SecurID two-factor authentication products”. However in Information Security we always hope for the best but prepare for the worst, the worst case scenario is all of the RSA SecurID private keys (seeds) records along with corresponding serial numbers were stolen. http://www.rsa.com/node.aspx?id=3872 Stolen Seeds? Every RSA Secu...

Play.com Breach – Don’t Trust your Third Parties

Image
Over the last couple of days many Play.com customers have received an Email, informing them their personal information has been breached, including me. This Email states “We are emailing all our customers to let you know that a company that handles part of our marketing communications has had a security breach. Unfortunately this has meant that some customer names and email addresses may have been compromised.” So personal details were stolen thanks to a security breach at Play.com’s third party service provider, namely a US based marketing company called SilverPop.  Play.com sent the warning Email in response to an increase in malicious Emails being targeted at Play.com customers, this was first noticed on 20th March 2011.  It is worth noting SilverPop, actually a US based Email marketing company, was breached in December last year; this was the point which the Play.com customer information was actually stolen, although Play.com nor SilverPop failed to realised the data was ...

EU Cookie Wars: The Nanny State Vs Common Sense

Image
From May this year (2011), the EU are set to introduce a new law to safeguard our privacy, but this law could mean the majority of websites you visit must 'explicitly request' your permission to use a cookie, this could mean a lot of needless pop-up boxes. EU Directive 2002/22/EC (See 66 ) st03674.en09.pdf  What is a Cookie? Most websites use a “cookie”, which is essentially a file holding a small amount of text within it, this file is locally stored on your PC. This simple text file (cookie) is actually really important for websites to operate efficiently, amongst things the cookie is used to identify you as an individual on the website. For instance the cookie is used to keep you logged into the website and to provide access to specific information meant only for you. By their nature cookies tend to provide the ability to track what you have done on any given website, which again is important for the website to work effectively, however this tracking can also be used ...

The Spy Next Door: Stealing your life for £44

Image
How easy can it be to steal your life?  For less than 44 quid is it possible to steal your bank account username, password and bank account security questions? For less than 44 quid is it possible to harvest your credit card details, including your credit card security code and Verified by Visa or MasterCard SecureCode password? Is it possible to read your private Emails and access your Email account?  Is it possible to monitor all your private web surfing habits and instant messenger conversations, and obtain your username and passwords for all your websites? Well for £43.83 all this is possible by using the Spy Cobra USB drive .  Once plugged into your Windows PC, it installs a hidden monitoring application in less than 20 seconds, after which the drive can be removed. From that point on every single key stroke is recorded, it records all websites visited and even takes screenshots of what is displayed on the screen, and stores these screenshots at regular intervals. T...

Andy Gray & Richard Keys Sky Sports Data Breach

Image
First of all let me just stress I certainly do not approve of any of the sexist remarks made by Andy Gray and Richard Keys on Sky Sports last weekend (21st Jan 11). I have been watching live football nearly all my life and I have seen some really bad football officials in my time. I really don’t care about a football official’s gender, as long as they are the best officials for the job. Believe it or not, Premier League officials are ruthlessly vetted and monitored to ensure they are the best of the best. Indeed it is said women are better at multi-tasking than men, that may be considered a sexist remark in itself, but if this were true, then ladies are going to make better ‘lines-people’ than men, anyone who’s tried being a linesman will know it is about monitoring several things at the same time, I can tell you it’s not an easy job. Anyway what business has the dismissal of Andy Gray and the resignation of Richard Keys from Sky Sports got to do with a ‘Security’ Blog. Well actually ...