Posts

RSA SecurID - What's the Risk?

Image
This week there has been plenty of concern following RSA’s announcement about their two-factor authentication solution, SecurID, which was subjected to a sophisticated cyber attack.  A lot of people are asking for my views on the risk in continuing to use RSA SecurID following this attack, so I am going to attempt to explain this risk in simple terms, but it won’t be easy. Facts What are the facts? Well we simply don’t know exactly what has been stolen from RSA at present, as RSA aren’t providing details beyond “the attack resulted in certain information being extracted from RSA's systems. Some of that information is specifically related to RSA's SecurID two-factor authentication products”. However in Information Security we always hope for the best but prepare for the worst, the worst case scenario is all of the RSA SecurID private keys (seeds) records along with corresponding serial numbers were stolen. http://www.rsa.com/node.aspx?id=3872 Stolen Seeds? Every RSA Secu...

Play.com Breach – Don’t Trust your Third Parties

Image
Over the last couple of days many Play.com customers have received an Email, informing them their personal information has been breached, including me. This Email states “We are emailing all our customers to let you know that a company that handles part of our marketing communications has had a security breach. Unfortunately this has meant that some customer names and email addresses may have been compromised.” So personal details were stolen thanks to a security breach at Play.com’s third party service provider, namely a US based marketing company called SilverPop.  Play.com sent the warning Email in response to an increase in malicious Emails being targeted at Play.com customers, this was first noticed on 20th March 2011.  It is worth noting SilverPop, actually a US based Email marketing company, was breached in December last year; this was the point which the Play.com customer information was actually stolen, although Play.com nor SilverPop failed to realised the data was ...

EU Cookie Wars: The Nanny State Vs Common Sense

Image
From May this year (2011), the EU are set to introduce a new law to safeguard our privacy, but this law could mean the majority of websites you visit must 'explicitly request' your permission to use a cookie, this could mean a lot of needless pop-up boxes. EU Directive 2002/22/EC (See 66 ) st03674.en09.pdf  What is a Cookie? Most websites use a “cookie”, which is essentially a file holding a small amount of text within it, this file is locally stored on your PC. This simple text file (cookie) is actually really important for websites to operate efficiently, amongst things the cookie is used to identify you as an individual on the website. For instance the cookie is used to keep you logged into the website and to provide access to specific information meant only for you. By their nature cookies tend to provide the ability to track what you have done on any given website, which again is important for the website to work effectively, however this tracking can also be used ...

The Spy Next Door: Stealing your life for £44

Image
How easy can it be to steal your life?  For less than 44 quid is it possible to steal your bank account username, password and bank account security questions? For less than 44 quid is it possible to harvest your credit card details, including your credit card security code and Verified by Visa or MasterCard SecureCode password? Is it possible to read your private Emails and access your Email account?  Is it possible to monitor all your private web surfing habits and instant messenger conversations, and obtain your username and passwords for all your websites? Well for £43.83 all this is possible by using the Spy Cobra USB drive .  Once plugged into your Windows PC, it installs a hidden monitoring application in less than 20 seconds, after which the drive can be removed. From that point on every single key stroke is recorded, it records all websites visited and even takes screenshots of what is displayed on the screen, and stores these screenshots at regular intervals. T...

Andy Gray & Richard Keys Sky Sports Data Breach

Image
First of all let me just stress I certainly do not approve of any of the sexist remarks made by Andy Gray and Richard Keys on Sky Sports last weekend (21st Jan 11). I have been watching live football nearly all my life and I have seen some really bad football officials in my time. I really don’t care about a football official’s gender, as long as they are the best officials for the job. Believe it or not, Premier League officials are ruthlessly vetted and monitored to ensure they are the best of the best. Indeed it is said women are better at multi-tasking than men, that may be considered a sexist remark in itself, but if this were true, then ladies are going to make better ‘lines-people’ than men, anyone who’s tried being a linesman will know it is about monitoring several things at the same time, I can tell you it’s not an easy job. Anyway what business has the dismissal of Andy Gray and the resignation of Richard Keys from Sky Sports got to do with a ‘Security’ Blog. Well actually ...

Lush Credit Card Data Breach

Image
Before I go into my thoughts on the recent Lush website credit card data breach, I have some important advice to all Lush online customers. If you have bought anything from the www.lush.co.uk website between October 2010 and January 2011, and even if you think your credit or debit card hasn’t been fraudulently used, you must consider your credit or debit card to be compromised, so cancel your card and have it replaced. Also note this breach does not affect anyone who used credit or debit cards over the counter at Lush shops, as it’s an entirely different payment system. When Lush announced their website, www.lush.co.uk had been successfully hacked last week (21 Jan 11), leading to thousands of their customer’s credit card details being stolen, I was genuinely surprised. I wasn’t surprised that yet another UK online business had completely shirked their responsibilities, in not properly protecting their customer’s information by neglecting one of the most basic of web application sec...

Is Club Penguin Safe for my Child?

Image
Disney’s Club Penguin is an online multiplayer game with social networking elements. Played by 6 to 14 year olds, Club Penguin is accessed and played through any web browser. Each player logs into the game with their own account, and plays in the Club Penguin ‘game world’ as their own specific Penguin character. Players use their Penguin avatar to play a series of games within the Club Penguin world, which in turn earns them in-game money which they can use to buy accessories for their Penguin character. While playing players can see other players’s Penguins in the game world and can interact with them. Club Penguin: Online Multiplayer Beware of the in game Chat Capability The player interaction, specially the ability to chat with other players is the prime area to be concerned about as a parent, as typically a child’s usage of Club Penguin goes unmonitored. I find most parents aren’t always by the side of their child when they play the game, and I even had one parent ...