Posts

Andy Gray & Richard Keys Sky Sports Data Breach

Image
First of all let me just stress I certainly do not approve of any of the sexist remarks made by Andy Gray and Richard Keys on Sky Sports last weekend (21st Jan 11). I have been watching live football nearly all my life and I have seen some really bad football officials in my time. I really don’t care about a football official’s gender, as long as they are the best officials for the job. Believe it or not, Premier League officials are ruthlessly vetted and monitored to ensure they are the best of the best. Indeed it is said women are better at multi-tasking than men, that may be considered a sexist remark in itself, but if this were true, then ladies are going to make better ‘lines-people’ than men, anyone who’s tried being a linesman will know it is about monitoring several things at the same time, I can tell you it’s not an easy job. Anyway what business has the dismissal of Andy Gray and the resignation of Richard Keys from Sky Sports got to do with a ‘Security’ Blog. Well actually ...

Lush Credit Card Data Breach

Image
Before I go into my thoughts on the recent Lush website credit card data breach, I have some important advice to all Lush online customers. If you have bought anything from the www.lush.co.uk website between October 2010 and January 2011, and even if you think your credit or debit card hasn’t been fraudulently used, you must consider your credit or debit card to be compromised, so cancel your card and have it replaced. Also note this breach does not affect anyone who used credit or debit cards over the counter at Lush shops, as it’s an entirely different payment system. When Lush announced their website, www.lush.co.uk had been successfully hacked last week (21 Jan 11), leading to thousands of their customer’s credit card details being stolen, I was genuinely surprised. I wasn’t surprised that yet another UK online business had completely shirked their responsibilities, in not properly protecting their customer’s information by neglecting one of the most basic of web application sec...

Is Club Penguin Safe for my Child?

Image
Disney’s Club Penguin is an online multiplayer game with social networking elements. Played by 6 to 14 year olds, Club Penguin is accessed and played through any web browser. Each player logs into the game with their own account, and plays in the Club Penguin ‘game world’ as their own specific Penguin character. Players use their Penguin avatar to play a series of games within the Club Penguin world, which in turn earns them in-game money which they can use to buy accessories for their Penguin character. While playing players can see other players’s Penguins in the game world and can interact with them. Club Penguin: Online Multiplayer Beware of the in game Chat Capability The player interaction, specially the ability to chat with other players is the prime area to be concerned about as a parent, as typically a child’s usage of Club Penguin goes unmonitored. I find most parents aren’t always by the side of their child when they play the game, and I even had one parent ...

iPhone Security Guide

Image
Last week a reporter asked for my opinion on iPhone Security, I said I thought it was a good idea. But seriously, Apple are actually taking steps to better secure the iPhone, this is driven by Apple's desire to impact the business smart phone market more, and better compete with the likes of Blackberry, who are the dominate force when it comes to business smart phone usage. Blackberry has been widely adopted by larger enterprises not only because their devices are easy to centrally manage, but because it comes with a whole raft of essential business security features, such as device level encryption and remote wipe functionality. When you think about it, you realise your iPhone is absolutely crammed with your personal information, think about the details within your Contacts list, Email accounts, Facebook account and even your personal photographs and videos all stored on the device, so if you care about your privacy ...

The Human Factor: Turning your Prime Weakness into your Prime Defence

Image
The slides from my talk on information security awareness at RSA Conference Europe 2010 The Human Factor: Turning your Prime Weakness into your Prime Defence  

Love it or Hate it, PCI DSS helps cut UK Card Fraud

Image
UK card fraud is significantly decreasing, according to the “UK Cards Association” statistics UK card fraud is down 20% to £187m for the first half of 2010. http://www.theukcardsassociation.org.uk/media_centre/press_releases_new/-/page/1037/ There are several reasons why card fraud in the UK has been dropping in my opinion: 1. Chip & Pin Chip & Pin, known as EMV in the payments industry, has been highly successful in cutting "cardholder present" fraud, namely face to face debit and credit card transactions, since its adoption in the UK in 2005. Chip and Pin has forced card fraudsters to commit fraud against stolen UK cards in different ways, typically by using online payments or by creating counterfeit UK credit cards to use in countries where Chip and Pin hasn’t been mandated. However since 2005 more and more countries have observed the huge success of Chip and Pin in the UK, and have been adopting the same payment approach, this in turn is also helping to red...

An Evening with Samy, creator of the Samy MySpace Worm

Image
Last night I was out talking security, drinking beer and eating curry with Samy Kamkar, following his presentation at an OWASP Chapter event in Leeds. Samy was responsible for writing and delivering the infamous Samy MySpace Worm in October 2005, which was one of the fastest growing malware infections to date. Samy Kamkar Samy delivered an excellent and fresh presentation at the OWASP Leeds Chapter meeting, highlighting several areas of new research and frankly new concern for us all. But I’ll save that for another blog posting once I’ve investigated it further, however you can read a little about one issue he discussed, which was highlighted in a recent BBC News report “ The Web attack knows where you live ” http://www.bbc.co.uk/news/technology-10850875 What I found particularly interesting about his presentation aside from the vulnerabilities and clever exploits, was you got to see how his mind ticks, his thought processes in finding and ex...