Posts

Showing posts from 2012

UK InfoSec Review for November 2012

Vital  Microsoft (4 critical)  and  Adobe (7 critical flash)  Security patches released this month. Adobe have joined Microsoft in with releasing patches on Microsoft’s Patch Tuesdays, such is the regularity of new vulnerabilities that are found in their applications. Fraudulent Westminster Council parking charge emails sent At least 800 fraudulent emails have been sent telling people they owe Westminster Council money for parking. Westminster's contractor, PayByPhone, said it had been the victim of a phishing scam.  The council said it had received complaints from 800 people saying they had received fraudulent emails. However, it could not provide an estimate for the number of emails that had been sent out.  Spam Emails are becoming more sophisticated and believable to end consumers, with attacks become more targeted against organisations, and personalised using stolen information. It is worth noting consumers and media can place blame a...

UK Data Protection Review for November 2012

ICO serves Prudential with a £50,000 fine after a mix-up over the administration of two customers’ accounts led to tens of thousands of pounds, meant for an individual’s retirement fund, ending up in the wrong account.   This is the first monetary penalty served by the ICO that doesn’t relate to a significant data loss, but is against not ensuring the customer information held was accurate and kept up-to-date  The original error was caused when the records of both customers, who share the same first name, surname and date of birth, were mistakenly merged in March 2007. The accounts remained confused for more than three years, and the problem was only resolved in September 2010. This was despite the company being alerted to the mistake on several occasions, including a letter from one of the customers in late April 2010 which clearly indicated his address had not changed for over 15 years. The company failed t...

Text Spammings, Finally an ICO Fine of Merit

Image
Today t he Information Commissioner's Office (ICO) announced a record fine of £440,000  against the owners of Tetrus Telecoms. The ICO stated the Manchester based Tetrus Telecoms, were responsible for sending millions of unsolicited text messages using unregistered SIM cards, and personal data gained illegally.  Tetrus Telecoms were said to be sending 840,000 spam text messages a day promoting PPI claims and accident compensation claims, in the hope of earning a referral fee should any of the recipients respond. These referral fees netted the text spammers £8,000 a day. This is a lot of easy money, but it does mean 99.9% of those receiving the texts didn't reply, and so didn't want the text message in the first place. Who hasn't had a PPI Text Message this year? Finally the ICO dishes out a fine which is close to their maximum amount of £500K. Often criticised as a toothless tiger, the ICO fi...

The Death of PCI: Two-Factor Online Payments

Image
Back in September 2007, I attended the inaugural Payment Cards Industry Security Standards Council (PCI SSC) Community Meeting in Toronto.  These were the days before PCI was big business, there must of been only a couple of hundred people at the event in a typical down town Hotel in Toronto.  PCI was still finding its feet, the PCI SSC Board members spent most of the event being grilled by delegates brimming with questions about the PCI standard, and it is fair to say some delegates weren't happy chappies at all.  I took the opportunity of asking SSC Board members several questions myself, looking back today some of my questions could be seen as rather naive, given who is behind setting up the PCI SSC and why.  I asked why PCI SSC doesn't just regulate the card issuers, challenge them with a standard to secure the cards and cardholder data to a higher degree, instead of passing the buck onto to everyone else in the industry. I ...

4 Ways Your Child is Vulnerable to Identity Theft

Scary American made awareness video on Child identity theft by Good Money .  It's titled "5 Ways", but it's actually 4 ways for UK parents, we can ignore number 2 on Social Security numbers. My recommendation is to educate and monitor your children/teenagers online activity, and teach them to secure their personal information digital footprint online. 5 Ways Your Child is Vulnerable to Identity Theft Online from Good Money by CreditScore.net on Vimeo . According to the United States Bureau of Justice Statistics, in 2010, 7% or “8.6 million households had at least one member age 12 or older who experienced one or more types of identity theft victimization.” But identity theft is not just reserved for tweens and adults. In this age of information, children are increasingly vulnerable to the same kinds of attacks that cripple credit scores and bust bank accounts. Check out this video to learn about five ways you could be exposing your child’s sensitive...

UK InfoSec Review for October 2012

UK Police net suspected phishing gang http://www.scmagazineuk.com/police-net-suspected-phishing-gang/article/266148/ UK police have arrested three men suspected of being involved in thousands of phishing attacks on banking customers. One Nigerian and two Romanian men were arrested at a central London hotel on conspiracy to defraud and money laundering charges.   The three men were allegedly involved in an operation that placed over 2,000 phishing pages on the internet XSS remains the most frequently attacked website flaw according to FireHost http://www.securityweek.com/cross-site-attacks-rise-top-q3-says-firehost The third quarter of 2012 showed another increase in attacks against cross-site scripting (XSS) flaws on websites. Analysis of 15 million cyber attacks by FireHost users found XSS, directory traversals, SQL injections, and cross-site request forgery (CSRF) attacks to be the most serious and frequent and are part of FireHost's 'Superfecta' group....

UK Data Protection Review for October 2012

ICO fines Stoke-on-Trent City Council £120,000 after sensitive information about a child protection legal case was emailed to the wrong person   11 emails containing sensitive information relating to the care of children were sent to the wrong address by Council employees The fact the Email and attachments were not encryption protected was the root cause of the seriousness of the incident, leading to the high fine. An encrypted file cannot be opened by unintended recipient, therefore it is best practise to use file encryption on any document contain sensitive personal information sent outside a company infrastructure via email. ICO fines Greater Manchester Police £150,000 following the theft of a memory stick holding sensitive personal data from an police officer’s home The ICO action was prompted by the theft of a memory stick containing sensitive personal data from a police officer’s home. The memory stick was not encrypted and contained details of mo...

Social Media Witch Hunting

Image
Last Friday evening (19th October 2012), I was at home watching a football match between Leeds United and Sheffield Wednesday. You could feel the bitter rivalry between the teams through the tv, both on the pitch and with the crowd atmosphere, which in all honestly added to the entertainment as a neutral watching it, as football played with passion rarely fails not to entertain. Sheffield Wednesday had taken the lead just before the end of the first half, but with 12 minutes from the end of the game, Leeds equalised. Then several Leeds supporters spilled onto the pitch behind the Wednesday goal, then one Leeds fan ran around the goal and up to the Wednesday goalkeeper Chris Kirkland, the fan raised his hands and shoved the keeper in the face, knocking the keeper to the ground for several minutes. Outrage: Chris Kirkland Assaulted Live on TV This sort of incident is extremely rare in the English game, unlike other European countries, fans are "trusted" not to encourage ...

PCI SSC Community Meeting Dublin 2012 Review

Image
I attended the Payment Card Industry Security Standards Council (PCI SSC) Community Meeting in Dublin this week, in all honestly there isn't a lot happening with PCI SSC Standards at the moment, namely, PCI DSS, PA-DSS and PTS, and I will explain why. Firstly the PCI SSC and PCI DSS has been around for many years now, I was at the inaugural SSC community meeting in Toronto in 2007. Since then the PCI standard has only undergone a few fairly minor changes, don't be fooled with PCI SSC's version control process i.e. PCI DSS V1.21 to V2.0. We can certainly expect PCI DSS Version V3.0 next year. The actual changes since the original release of PCI DSS are minor, so in essence we have a mature and highly static data security best practice standard. Secondly, over the last 6 years PCI SSC has provided reams of guidance, FAQs and have improved how they communicate with those within the payment card industry trying to comply. Again this has matured,  there just aren't any...

RSA Conference Europe 2012 Review

Image
A conference is only as good as its speakers, specifically the speaker's subject matter expertise, presentation subject and presenting ability, in this the RSA Conference Europe succeeds where many others conferences fail miserably. The best InfoSec speakers do not regurgitate topics with arrogance, repeating empty messages to sell products and services. No, the best speakers converse with their fellow information security professionals at the same level, informing and exploring the latest and future issues that will matter to business. Speakers are not bound and gagged by their company sales and marketing reps, are free to share and open up new ideas, new thinking, new solutions, and so challenge thinking and generating discussion by security professionals and businesses influencers beyond the conference, which ultimately leads to improvements for society. Why? Because ultimately when businesses get information security wrong, it is everyone that ends up footing the impact, whethe...

UK InfoSec Review for September 2012

Glasgow City Council has lost 750 devices over the last five years according to an IT audit The Council incurred significant national and local media criticism following discovery of 56 unencrypted laptops and 487 desktop PCs, also thought to be unencrypted, are unaccounted for. These were also lost from an office in the City Chambers which contained about 17,000 bank details. A reported theft in May, which the Information Commissioner is aware of, led to the audit of all the council's IT hardware and revealed that almost 750 devices that are unaccounted for. Microsoft release emergency Security Patch for remote code execution flaw within Internet Explorer Microsoft released an emergency patch for the zero-day flaw in Internet Explorer on 21 st September 2012. IPad led BYOD leaves gaping holes in enterprise security Sophos warn many firms are leaving themselves open to attack based on the findings of Sophos' Warbike research. Quest Software iss...

UK Data Protection Review for September 2012

ICO fines Scottish Borders Council £250,000 after employee records found in supermarket car park over-filled recycle bin More than 600 files were deposited at the recycle bins, containing confidential information and, in a significant number of cases, salary and bank account details. The files were spotted by a member of the public who called police, prompting the recovery of 676 files. A further 172 files deposited on the same day but at a different paper recycling bank are thought to have been destroyed in the recycling process. Even though a third party caused the breach, the Council found responsible. Scottish Borders Council employed an outside company to digitise the records, but failed to seek appropriate guarantees on how the personal data would be kept secure. The Data Protection Act requires that, if you decide to use another organisation to process personal data for you, you remain legally r...

Look out for the Spies in the Skies

Image
Using an Unmanned Aerial Vehicles (UAV) to covertly survey a target sounds like something out of a Tom Clancy novel or a hi-tech military operation in the middle east, but in reality decent quality UAVs costing less than £300 are available to anyone. Military UAV The AR drone Parro t is one such model made for the "home market". This quadricopter UAV can be easily controlled from your Smartphone, and is highly stable in flight outdoors. This stability clearly is a key factor in the design to meet the craft's main purpose, recording video via an on board HD camera, which not only records clear footage but can even send a live stream it to your phone. This UAV could be yours for less than £300! UAVs such as these will be a cool toy to many people, but there will be others that will purchase these spies in the skies for more sinister purposes, and not just for spying on the neighbours. These UAVs aren't as easy to spot as you might, newer models are...