Sunday, September 20, 2009
E-Trade Skimming Scam
Man Gets 15 Months for E-Trade Skimming Scam
Internet Scammers Leap on Patrick Swayze's Death
The most obvious reason hackers would do this is because after the actor's death, it would only seem logical that people would get on their computers to try and find out what happened. Even as soon as people figure out this report is a fake, the pop up has already been activated. The most rational response to a pop up is to exit out, which in the process could accidentally trigger the download. In order to avoid being infected by this malware, one should avoid using rouge news outlets for information and stick to trusted news outlets. If one does become infected, they should immediately perform a legitimate virus scan on their system.
Greene, Tim. "Internet Scammers Leap on Patrick Swayze's Death." PC World. 16 Sept. 2009. Web. 20 Sept. 2009.
Friday, September 18, 2009
A Victim of Information Insecurity
Take this example from me:
We've been talking about information security since the class started. One of the topics that we've talked about and discussed is letting people know if their information has been compromised. I recently got a letter from the Notre Dame Federal Credit Union telling me that in fact my information HAS been compromised. That information might have included my debit card number. Now, before learning about this, I would have been like "Hmm that's weird. I don't really know how seriously I need to look into this. They give me the option of canceling my current card until they send me a new one. Should I do that?" Now, my thought process has been much different. "I wonder what happened that caused them to compromise my information. Did someone misplace a laptop? Did a computer get infected with a virus? I wonder how many different people had their information compromised. How many people are they automatically sending out new cards to? It says that they were notified that my information may have been compromised... does that mean that it was compromised by some other company? Maybe somebody I purchased from? It must have been somewhat serious for theme to already be sending me a new card." Along with giving me the number to call in case I decide to cancel it, they also inform me about VISA's Zero Liability policy, which is nice to know. Overall, I'm just glad they let me know. I'm appreciative of their responsibility.
The Koobfaces of Facebook
Have you ever gotten a weird message from your Facebook friend asking you to view their cool new video? Then once you click on it you are directed to one of those File>run screens? If you proceeded with those directions, there is a good chance that you were exposed to the Koobface worm. This is a virus that has the ability to access Facebook log-in credentials in order to assume the identity of a Facebook user. It then sends a message to all of the users’ friends asking them to click a link leading to their new video which in actuality a link to download malicious software to your computer.
Facebook CEO reported in March of 2009 that only a small number of users have been affected by this virus but it is not the first of its kind to infiltrate the site. Therefore Facebook has taken new security precautions in the last year to better screen invalid users and applications. They also implemented a way for users to verify Facebook approved applications by looking for the Facebook validation badge [seen below.] Facebook says that many of the applications are not intentionally vicious but were improperly setup by the application creator.
This leads me to the central problem which is Facebook’s blanket acceptance of Facebook applications with not enough attention given to the intentions or abilities of the creator to form a secure product. Facebook concedes that they “err on the side of permissiveness” in order to promote growth of the site but this is at the risk of the users and their personal information. Many viruses target such social-networking sites due to this same fact of popularity that Facebook strives for. For this reason, Facebook must establish a list of priorities in that the safety and security of their users comes before marketing and site expansion.
Facebook should be more critical when deciding which application is able to be circulated on the site and should also test these applications before exposing them to the users. In turn, users [such as ourselves] should be more mindful of the possible threat that applications may carry and always check for the new Facebook validation badge before allowing an application access to your profile and its contents. These measures may not eliminate the possibility of exposure to malicious material, but it may reduce Facebook’s attractiveness and popularity in the world of viruses; and send worms like “Koobface” somewhere else.
Sources:
Sunday, September 13, 2009
Geographic Privacy
This would make a great case study topic for someone who is still looking...
Friday, September 11, 2009
The IRS wants my computer too?!
This is not a spear phishing attack meant to target any particular business or group of people. The IRS had also been used in a phishing scam in February involving stimulus package payments. The IRS, however, doesn't even know your email address and will never contact you with official business over email according to Sam Masiello, vice president of information security at MX Logic. Reipients are advised by the IRS to forward the emails to phishing@irs.gov.
You can see a sample of the email and fraudulent link here: http://www.mxlogic.com/itsecurityblog/1/2009/09/5E.New-Malware-Campaign-Spoofs-the-IRS.cfm
This is just another example of what people are going to attempt to do in order to scam people. They are willing to impersonate something such as the IRS. The email even appears from no-reply@irs.gov which gives the email another item to try and prove its legitimacy.
People need to always continue to be wary of email that comes from distant sources. People even need to be always on the alert even with people they know. People who end up getting the trojan need to get that taken car of as soon as possible. Having a trojan on your computer just leads to more and more problems (I know from past personal experience). So, be diligent, and when it comes to email, it almost seems like you actually shouldn't ever trust the government, just like so many people say.
Sources:
Kaplan, Dan. "Cutwail botnet authors behind wave of malicious IRS spam." SC Magazine. Sept. 09, 2009. Web accessed: Sept. 11, 2009. http://www.scmagazineus.com/Cutwail-botnet-authors-behind-wave-of-malicious-IRS-spam/article/148474/
Thursday, September 10, 2009
Guessing Social Security Numbers
Recently, a team of computer scientists from Carnegie Mellon University discovered that using select public information they can actually guess a person's social security number. They concluded that there are “distinct patterns in how the numbers are assigned” that correlate to an individual’s date of birth and state that they were born in. The computer scientists used information from the “Death Master File” from 1989 to 2003 to conduct an experiment to see how accurately they could predict the nine digit numbers. They were able to successfully predict the social security numbers of 8.5 percent of the 1000 records that were used in the experiment. The frightening factor in this experiment is that this process is legal. The information that the Carnegie Mellon computer scientists used was public information to which almost anyone could gain legitimate access. Personal profile sites like facebook.com make this information even more accessible as most individuals have their date of birth and home state on their profiles.
Privacy expert Alessandro Acquisti said that this is a matter of policy, not of personal protection. He stated that information like names and birth dates are already on the web. Because it is becoming nearly impossible to absolutely protect social security numbers, policy makers are reconsidering the use of social security numbers as personal identifiers. The Washington Post quoted Alessandro Acquisti as saying, "Our work shows that Social Security numbers are compromised as authentication devices, because if they are predictable from public data, then they cannot be considered sensitive." The issue has recently been pushed into the spotlight as Washington lawmakers are attempting to prevent businesses from asking new employees for their social security numbers because the routine use of social security numbers is contributing to the problem.
Sources:
Krebs, Brian. "Researchers: Social Security Numbers Can Be Guessed." The Washington Post. 6 July 2009. Web. 10 Sept. 2009. http://www.washingtonpost.com
Leggett, Haddley. "Social Security Numbers Deduced from Public Data." Wired. 6 July 2009. Web. 10 Sept. 2009. http://www.wired.com