Posts

Secret Government Security Standards Heard of CoCo & IL3?

Image
In the UK much of our digital sensitive and personal information entrusted to UK government departments and their commercial partners, are supposedly protected by sets of unpublished information security standards. These non-public accessible standards, such as the Government Code of Connection (CoCo) and the required security controls around the various “Impact Levels” classifications (IL2, IL3 etc.), have only been made available to a select few bodies, some of which decide on whether organisations comply with these standards or not, all out of the public eye. Why the Secrecy? Why aren’t these important security standards concerning the protection of UK sensitive citizen information made public? What exactly are the specific requirements to which UK government departments and their commercial partners are seemingly vetted against? Are these requirements up-to-date and strong to ensure to ensure the breach risk to our information is adequately low? Why can’t the public find out ...

Facebook Privacy Settings Change Swindle

Image
I logged onto Facebook today and to my utter horror I was automatically forced to page to accept changes to my privacy settings. These privacy settings had defaulted to new settings to replace my existing "secure" settings, which are configured to protect my personal information from strangers. Now I wasn't caught out by this cheap stunt, but I fear many people who had previously made the effort to configure their Facebook acccounts to only share their private information with friends they know, may of been tricked. I only blogged about how to configure Facebook securely a couple of weeks ago, http://blog.itsecurityexpert.co.uk/2009/11/child-facebook-safety.html   My blog posting was aimed at protecting children using Facebook, and I fear this forced privacy settings change will have caught out many children, as I find children tend to have a just click and not read properly approach when using the Internet.  Facebook...

Child Facebook Safety

Image
Recently I was invited to participate on Radio Five Live debate on children’s usage of social networking sites, and specifically child bullying within Facebook. Various parents were calling the radio programme and were saying their children had suffered from issues like cyber bullying and the receipt of obscene messages from perverts. Several individuals thought the answer was to prevent their children using social networking websites and even suggesting banning children from using the Internet altogether. The main point I made was banning children from using social networking sites like Facebook, Bebo and MySpace will just not work, for one banning illegal activities like under aged smoking and drinking doesn’t work, sooner or later children will find a way to access social networking websites anyway, which isn’t illegal by the way. Furthermore preventing a child from using the home PC is a reckless approach in the information age and pretty pointless exercise, as children can ac...

Gary McKinnon Extradition

Image
Gary McKinnon is in the news again after the Home Secretary, Alan Johnson refused to block the intended extradition to the United States. I was invited to comment on Radio Five Live on Friday morning, to raise points on the security and technical specifics of the case. It is clear Gary has plenty of public support in the UK, from people who believe he shouldn’t be extradited to the United States, mainly on human rights grounds. Gary’s lawyers stated he is happy to pled guilty to the crimes in a UK court, therefore he appears to be guilty of these crimes, but his lawyer feel justice just won’t be served if he was sent to a US court. I have actually meet Gary a couple of years back, however my comments on Radio Five Live were made from totally impartial and an Information Security expert’s point of view. Here is a summary of what I said. The main point to understand is, what was the motivation of Gary McKinnon’s “hacking” attack? It clearly wasn’t for fraud, as he wasn’t ...

How Secure is your UK Online Banking?

Image
The UK maybe still in the midst of a recession, but these times are proving anything but a recession for cybercriminals, as UK Online Banking fraud is sky rocketing at the moment. The ‘Financial Fraud Action’ showing a 55% increase for the first half of 2009, while the ‘UK Payments Administration’ figures reports a 44% year on year rise. Through my own research and underground monitoring of UK cybercriminal activity, I am seeing increasing numbers of stolen UK online bank account access details being put up for sale, and increasing numbers of keylogger malware being deployed, which are specifically targeting the theft of UK online bank access credentials covertly. Despite these increases in criminal activity and years of warnings, UK banks still aren’t doing enough to protect their customers from the dangers of the internet. Many UK banks are still yet to provide their customers with a security best practice Two-Factor authentication access to their online banking, so are making it...

TalkTalk’s WiFi Hacking No No!

Last week Internet Service Provider (ISP) TalkTalk pulled a hacking publicity stunt, which they aimed to demonstrate why they should be absolved of all responsibility for the portion of their customers who illegally file shared pirated material. TalkTalk visited a street in North London, and hacked into poorly secured residential wireless networks. Accessing insecurely configured residential WiFi is old news and is illegal, TalkTalk’s point in doing this was to show that anyone could be using residential wireless access points for file sharing illegal material, again nothing new in that either.   http://blog.itsecurityexpert.co.uk/2008/11/reason-to-secure-your-home-wifi.html However the double standards here, is the prime reason why the majority of home wireless networks in the UK aren’t secured to a sufficient degree in the first place, is because ISPs have been providing their customers with wireless access points (routers) in an insecure fashion for years. As far back a...

How the Payment Card Industry could stop Card Fraud

Image
If the payment card industry, the card schemes such as Visa and MasterCard, and merchants really desired to dramatically reduce payment card fraud, it can be simply done. Today, by far the biggest problem with payment card security (credit and debit cards), is the little black magnetic stripe on the back. This magnetic stripe holds the full card details unprotected. This information is referred to as “track 2 data” within the payment card industry. The problem is this magnetic stripe track 2 data can be easily read with a "cheap to buy" magnetic stripe reader (see picture above), allowing fraudsters to “skim” card details quickly in a variety of ways, for instance placing covert magnetic stripe readers on ATMs (see picture below). Track 2 data is also held in plain text on some payment devices and payment processing applications which store this information. Once track 2 data falls into the hands of card fraudsters, they simply create clone cards by replicating the ma...