Friday, September 18, 2009

The Koobfaces of Facebook

Have you ever gotten a weird message from your Facebook friend asking you to view their cool new video? Then once you click on it you are directed to one of those File>run screens? If you proceeded with those directions, there is a good chance that you were exposed to the Koobface worm. This is a virus that has the ability to access Facebook log-in credentials in order to assume the identity of a Facebook user. It then sends a message to all of the users’ friends asking them to click a link leading to their new video which in actuality a link to download malicious software to your computer.

Facebook CEO reported in March of 2009 that only a small number of users have been affected by this virus but it is not the first of its kind to infiltrate the site. Therefore Facebook has taken new security precautions in the last year to better screen invalid users and applications. They also implemented a way for users to verify Facebook approved applications by looking for the Facebook validation badge [seen below.] Facebook says that many of the applications are not intentionally vicious but were improperly setup by the application creator.

This leads me to the central problem which is Facebook’s blanket acceptance of Facebook applications with not enough attention given to the intentions or abilities of the creator to form a secure product. Facebook concedes that they “err on the side of permissiveness” in order to promote growth of the site but this is at the risk of the users and their personal information. Many viruses target such social-networking sites due to this same fact of popularity that Facebook strives for. For this reason, Facebook must establish a list of priorities in that the safety and security of their users comes before marketing and site expansion.

Facebook should be more critical when deciding which application is able to be circulated on the site and should also test these applications before exposing them to the users. In turn, users [such as ourselves] should be more mindful of the possible threat that applications may carry and always check for the new Facebook validation badge before allowing an application access to your profile and its contents. These measures may not eliminate the possibility of exposure to malicious material, but it may reduce Facebook’s attractiveness and popularity in the world of viruses; and send worms like “Koobface” somewhere else.

Your browser may not support display of this image.

Sources:

Sunday, September 13, 2009

Geographic Privacy

Philippe Golle and Kurt Partridge from Xerox PARC wrote an interesting article recently called "On the Anonymity of Home/Work Location Pairs".

This would make a great case study topic for someone who is still looking...

Friday, September 11, 2009

The IRS wants my computer too?!

After seeing in class today just how convincing phishing scams can be, it was interesting to find another one that sets its sight even higher than a court subpoena. This one uses the IRS as its fraudulent cover. The spam email that is going around says that the U.S. Internal Revenue Service wants to contact the recipient over their own fraud. About 90,000 emails are being sent each hour trying to spread Cutwail, which is described as "the world's highest-volume spam-sending botnet". The recipients are being blamed for under reporting their income. In the body of the email there's a link encouraging people to click on it to view their tax statement. When they click on the link, users are directed to a mock website containing links that download a trojan.

This is not a spear phishing attack meant to target any particular business or group of people. The IRS had also been used in a phishing scam in February involving stimulus package payments. The IRS, however, doesn't even know your email address and will never contact you with official business over email according to Sam Masiello, vice president of information security at MX Logic. Reipients are advised by the IRS to forward the emails to phishing@irs.gov.

You can see a sample of the email and fraudulent link here: http://www.mxlogic.com/itsecurityblog/1/2009/09/5E.New-Malware-Campaign-Spoofs-the-IRS.cfm

This is just another example of what people are going to attempt to do in order to scam people. They are willing to impersonate something such as the IRS. The email even appears from no-reply@irs.gov which gives the email another item to try and prove its legitimacy.

People need to always continue to be wary of email that comes from distant sources. People even need to be always on the alert even with people they know. People who end up getting the trojan need to get that taken car of as soon as possible. Having a trojan on your computer just leads to more and more problems (I know from past personal experience). So, be diligent, and when it comes to email, it almost seems like you actually shouldn't ever trust the government, just like so many people say.

Sources:
Kaplan, Dan. "Cutwail botnet authors behind wave of malicious IRS spam." SC Magazine. Sept. 09, 2009. Web accessed: Sept. 11, 2009. http://www.scmagazineus.com/Cutwail-botnet-authors-behind-wave-of-malicious-IRS-spam/article/148474/



Thursday, September 10, 2009

Guessing Social Security Numbers

Your social security number is the key to your identity. Its confidentiality is of the utmost importance, and individuals take intensive measures to protect the confidentiality of their social security numbers, especially as recent information security failures have compromised numerous identities in online scams. But what if no one even needed to hack into your bank information or send you a phishing email to steal your social security number?

Recently, a team of computer scientists from Carnegie Mellon University discovered that using select public information they can actually guess a person's social security number. They concluded that there are “distinct patterns in how the numbers are assigned” that correlate to an individual’s date of birth and state that they were born in. The computer scientists used information from the “Death Master File” from 1989 to 2003 to conduct an experiment to see how accurately they could predict the nine digit numbers. They were able to successfully predict the social security numbers of 8.5 percent of the 1000 records that were used in the experiment. The frightening factor in this experiment is that this process is legal. The information that the Carnegie Mellon computer scientists used was public information to which almost anyone could gain legitimate access. Personal profile sites like facebook.com make this information even more accessible as most individuals have their date of birth and home state on their profiles.

Privacy expert Alessandro Acquisti said that this is a matter of policy, not of personal protection. He stated that information like names and birth dates are already on the web. Because it is becoming nearly impossible to absolutely protect social security numbers, policy makers are reconsidering the use of social security numbers as personal identifiers. The Washington Post quoted Alessandro Acquisti as saying, "Our work shows that Social Security numbers are compromised as authentication devices, because if they are predictable from public data, then they cannot be considered sensitive." The issue has recently been pushed into the spotlight as Washington lawmakers are attempting to prevent businesses from asking new employees for their social security numbers because the routine use of social security numbers is contributing to the problem.

Sources:
Krebs, Brian. "Researchers: Social Security Numbers Can Be Guessed." The Washington Post. 6 July 2009. Web. 10 Sept. 2009. http://www.washingtonpost.com
Leggett, Haddley. "Social Security Numbers Deduced from Public Data." Wired. 6 July 2009. Web. 10 Sept. 2009. http://www.wired.com

Wednesday, September 9, 2009

Wal-Mart Card Phishing Scheme

A recent article detailed how a phishing scam was being used in order to set up Wal-Mart credit cards. Tien Truong Nguyen and his accomplices worked out of Romania to set up fake phishing websites to steal peoples' information. After getting the information, they would set up instant credit accounts at kiosks in different Wal-Marts in northern California. The offenders could typically print out credit coupons valued between $1000 and $2000 to then use in the stores.

The scariest part about this story is that, when asked why he chose to perform identity theft, Nguyen's response was "because it was so easy." In fact, he had tried to "quit" identity theft before, but had found it to be the easiest way for him to fund his methamphetamine addiction. When arrested, Nguyen had possession of tens of thousands of peoples' credit card numbers, bank account numbers, and other sensitive information. He primarily gained this information by either sending e-mails or pop-up windows from the popular site paypal.com asking people for their information. However, he had branched off into also creating fake websites for smaller institutions such as Fairwinds Credit Union,Heritage Bank and the Honolulu City and County Employee's Credit Union.

The main takeaway from this article was how easy it is for someone to willingly give away their sensitive information. Just because a site looks legitimate, which all of Nguyen's reportedly did, does not mean that it is safe. For this reason we all need to remember to be on the lookout for ways we may compromise our own information security.

Source:
McMillan, Robert. "Man Pleads Guilty in Wal-Mart Card Phishing Scheme" September 9, 2009.

Monday, September 7, 2009

Rise in ATM Crime in Europe

Two recent articles from pcworld.com and guardian.co.uk detail the rise of ATM fraud and theft in Europe. The articles report that €485m (£423m) was stolen in 2008, a 149 percent increase from ATM crime in 2007. Those perpetrating these crimes and fraud utilize various techniques to obtain valuable financial information. The customary method used by offenders is known as "skimming": the attaching of false equipment to existing ATMs which records a card's magnetic strip. Following this, offenders use various covert means to capture a person's PIN number. Other techniques involve the use of Bluetooth technology and nearby laptops, entirely fake machines, malware and other malicious software, physical attacks, and so on.

There are a number of reasons for the susceptibility of ATMs. One of the primary causes is that ATMs do not implement specific, unique software. Most use "publicly available operating systems and off-the-shelf hardware." (pcworld.com) As a result, criminals can easily construct their false machines and card swipers, and can work to find methods for infecting machines with malicious software. Another reason is cash machines around the world do not have the same safety measures; this is a likely reason crime across the many countries of Europe is prevalent. ATM users may be used to the security of specific machines and be unaware of the risks of strange machines. The fact that tampering occurs is also evidence that ATMs are not monitored carefully enough. Obviously the purpose of an automated machine is that it does not require non-machine supervision, but the use of security cameras and other monitoring techniques could prove a successful deterrent to these crimes.

Awareness is key in addressing these situations; customers must be aware that these crimes occur and take precaution against the most basic attacks at the very least. This involves taking care when entering one's PIN, only using machines in areas where it is fitting for machines to exist, checking what one is swiping one's card through, regular changing of PIN numbers, and so on. I think it would also believe it would be beneficial for European banking companies to create standards in regard to their ATMs. This could include machine appearance, safety/security measures, machine-monitoring techniques, etc. Overall, awareness is essential for both the company and the customer.


Sources:
Kirk, Jeremy. "European Banks Warned: Brace for Rise in Cash Machine Fraud" September 7, 2009. http://www.pcworld.com/businesscenter/article/171542/european_banks_warned_brace_for_rise_in_cash_machine_fraud.html

Collinson, Patrick. "Huge rise in cash-machine crime, watchdog warns" September 7, 2009. http://www.guardian.co.uk/uk/2009/sep/07/cash-machine-crime-increase-fraud


Password Hackers are Slippery to Collar

Here's an interesting article in this morning's Washington Post:

Password Hackers are Slippery to Collar.

It relates to the conversation we had in class on Thursday regarding password security. As you'll read in the story, there are firms out there that as their "business" will hack into web-based e-mail accounts and provide the customer with the password.

Obviously, this is illegal, but it is also very difficult to track. We'll discuss the reasons why in more detail when we cover incident handling toward the end of the semester, but most of these companies are located in other countries where authorities do not have good working relationships with the United States.

Despite being profiled in the newspaper, this website is still in business today. They boast:

"We Hack Passwords for $100 USD
We Crack all major web based emails
This include Hotmail, Yahoo! AOL and Gmail
We Provide Proofs Before payment."

Interesting. What are your thoughts?