Sunday, September 20, 2009

E-Trade Skimming Scam

Another interesting article for someone looking for a case study. First come, first served...

Man Gets 15 Months for E-Trade Skimming Scam

Internet Scammers Leap on Patrick Swayze's Death

After hearing the news of famous actor Patrick Swayze's death, many turned to the Internet to find details pertaining to the circumstances surrounding this tragic event. While most turned to reputable media websites, such as television news channels and print newspapers, some simply went to search engines and typed in several keywords. A few unknowingly stumbled upon a fake news report which contains a pop up stating that the individual's computer needs to have an anti-virus scan performed immediately. Unfortunately, the creators of this site are not benevolent programmers concerned with the well being of the computes of the site's visitors. The program is malware and can have a detrimental effect on the computer's performance. The biggest catch to this program is that one need not even click on the pop up to download the malware. It has been programmed in such a way that only moving the cursor over the box initiates the download.

The most obvious reason hackers would do this is because after the actor's death, it would only seem logical that people would get on their computers to try and find out what happened. Even as soon as people figure out this report is a fake, the pop up has already been activated. The most rational response to a pop up is to exit out, which in the process could accidentally trigger the download. In order to avoid being infected by this malware, one should avoid using rouge news outlets for information and stick to trusted news outlets. If one does become infected, they should immediately perform a legitimate virus scan on their system.

Greene, Tim. "Internet Scammers Leap on Patrick Swayze's Death." PC World. 16 Sept. 2009. Web. 20 Sept. 2009.

Friday, September 18, 2009

A Victim of Information Insecurity

It's interesting how sometimes things in life make a lot more sense once you learn about them. And, when they make more sense, you think about them differently.

Take this example from me:
We've been talking about information security since the class started. One of the topics that we've talked about and discussed is letting people know if their information has been compromised. I recently got a letter from the Notre Dame Federal Credit Union telling me that in fact my information HAS been compromised. That information might have included my debit card number. Now, before learning about this, I would have been like "Hmm that's weird. I don't really know how seriously I need to look into this. They give me the option of canceling my current card until they send me a new one. Should I do that?" Now, my thought process has been much different. "I wonder what happened that caused them to compromise my information. Did someone misplace a laptop? Did a computer get infected with a virus? I wonder how many different people had their information compromised. How many people are they automatically sending out new cards to? It says that they were notified that my information may have been compromised... does that mean that it was compromised by some other company? Maybe somebody I purchased from? It must have been somewhat serious for theme to already be sending me a new card." Along with giving me the number to call in case I decide to cancel it, they also inform me about VISA's Zero Liability policy, which is nice to know. Overall, I'm just glad they let me know. I'm appreciative of their responsibility.

The Koobfaces of Facebook

Have you ever gotten a weird message from your Facebook friend asking you to view their cool new video? Then once you click on it you are directed to one of those File>run screens? If you proceeded with those directions, there is a good chance that you were exposed to the Koobface worm. This is a virus that has the ability to access Facebook log-in credentials in order to assume the identity of a Facebook user. It then sends a message to all of the users’ friends asking them to click a link leading to their new video which in actuality a link to download malicious software to your computer.

Facebook CEO reported in March of 2009 that only a small number of users have been affected by this virus but it is not the first of its kind to infiltrate the site. Therefore Facebook has taken new security precautions in the last year to better screen invalid users and applications. They also implemented a way for users to verify Facebook approved applications by looking for the Facebook validation badge [seen below.] Facebook says that many of the applications are not intentionally vicious but were improperly setup by the application creator.

This leads me to the central problem which is Facebook’s blanket acceptance of Facebook applications with not enough attention given to the intentions or abilities of the creator to form a secure product. Facebook concedes that they “err on the side of permissiveness” in order to promote growth of the site but this is at the risk of the users and their personal information. Many viruses target such social-networking sites due to this same fact of popularity that Facebook strives for. For this reason, Facebook must establish a list of priorities in that the safety and security of their users comes before marketing and site expansion.

Facebook should be more critical when deciding which application is able to be circulated on the site and should also test these applications before exposing them to the users. In turn, users [such as ourselves] should be more mindful of the possible threat that applications may carry and always check for the new Facebook validation badge before allowing an application access to your profile and its contents. These measures may not eliminate the possibility of exposure to malicious material, but it may reduce Facebook’s attractiveness and popularity in the world of viruses; and send worms like “Koobface” somewhere else.

Your browser may not support display of this image.

Sources:

Sunday, September 13, 2009

Geographic Privacy

Philippe Golle and Kurt Partridge from Xerox PARC wrote an interesting article recently called "On the Anonymity of Home/Work Location Pairs".

This would make a great case study topic for someone who is still looking...

Friday, September 11, 2009

The IRS wants my computer too?!

After seeing in class today just how convincing phishing scams can be, it was interesting to find another one that sets its sight even higher than a court subpoena. This one uses the IRS as its fraudulent cover. The spam email that is going around says that the U.S. Internal Revenue Service wants to contact the recipient over their own fraud. About 90,000 emails are being sent each hour trying to spread Cutwail, which is described as "the world's highest-volume spam-sending botnet". The recipients are being blamed for under reporting their income. In the body of the email there's a link encouraging people to click on it to view their tax statement. When they click on the link, users are directed to a mock website containing links that download a trojan.

This is not a spear phishing attack meant to target any particular business or group of people. The IRS had also been used in a phishing scam in February involving stimulus package payments. The IRS, however, doesn't even know your email address and will never contact you with official business over email according to Sam Masiello, vice president of information security at MX Logic. Reipients are advised by the IRS to forward the emails to phishing@irs.gov.

You can see a sample of the email and fraudulent link here: http://www.mxlogic.com/itsecurityblog/1/2009/09/5E.New-Malware-Campaign-Spoofs-the-IRS.cfm

This is just another example of what people are going to attempt to do in order to scam people. They are willing to impersonate something such as the IRS. The email even appears from no-reply@irs.gov which gives the email another item to try and prove its legitimacy.

People need to always continue to be wary of email that comes from distant sources. People even need to be always on the alert even with people they know. People who end up getting the trojan need to get that taken car of as soon as possible. Having a trojan on your computer just leads to more and more problems (I know from past personal experience). So, be diligent, and when it comes to email, it almost seems like you actually shouldn't ever trust the government, just like so many people say.

Sources:
Kaplan, Dan. "Cutwail botnet authors behind wave of malicious IRS spam." SC Magazine. Sept. 09, 2009. Web accessed: Sept. 11, 2009. http://www.scmagazineus.com/Cutwail-botnet-authors-behind-wave-of-malicious-IRS-spam/article/148474/



Thursday, September 10, 2009

Guessing Social Security Numbers

Your social security number is the key to your identity. Its confidentiality is of the utmost importance, and individuals take intensive measures to protect the confidentiality of their social security numbers, especially as recent information security failures have compromised numerous identities in online scams. But what if no one even needed to hack into your bank information or send you a phishing email to steal your social security number?

Recently, a team of computer scientists from Carnegie Mellon University discovered that using select public information they can actually guess a person's social security number. They concluded that there are “distinct patterns in how the numbers are assigned” that correlate to an individual’s date of birth and state that they were born in. The computer scientists used information from the “Death Master File” from 1989 to 2003 to conduct an experiment to see how accurately they could predict the nine digit numbers. They were able to successfully predict the social security numbers of 8.5 percent of the 1000 records that were used in the experiment. The frightening factor in this experiment is that this process is legal. The information that the Carnegie Mellon computer scientists used was public information to which almost anyone could gain legitimate access. Personal profile sites like facebook.com make this information even more accessible as most individuals have their date of birth and home state on their profiles.

Privacy expert Alessandro Acquisti said that this is a matter of policy, not of personal protection. He stated that information like names and birth dates are already on the web. Because it is becoming nearly impossible to absolutely protect social security numbers, policy makers are reconsidering the use of social security numbers as personal identifiers. The Washington Post quoted Alessandro Acquisti as saying, "Our work shows that Social Security numbers are compromised as authentication devices, because if they are predictable from public data, then they cannot be considered sensitive." The issue has recently been pushed into the spotlight as Washington lawmakers are attempting to prevent businesses from asking new employees for their social security numbers because the routine use of social security numbers is contributing to the problem.

Sources:
Krebs, Brian. "Researchers: Social Security Numbers Can Be Guessed." The Washington Post. 6 July 2009. Web. 10 Sept. 2009. http://www.washingtonpost.com
Leggett, Haddley. "Social Security Numbers Deduced from Public Data." Wired. 6 July 2009. Web. 10 Sept. 2009. http://www.wired.com