Showing posts with label information industry. Show all posts
Showing posts with label information industry. Show all posts

Tuesday, August 21, 2007

The sad state of affairs in the information (identity) theft crisis

It shouldn't surprise anyone that data breaches are becoming more prevalent than ever, or that identity theft is up fifty percent since 2003.

Robert L. Scheier (courtesy of InfoWorld) wrote an article about this that is getting a lot of play in the press:

Today's electronic world is a risky place for your personal data -- and it's not getting any safer. More than 158 million data records of U.S. residents have been exposed as a result of security breaches since January 2005, according to The Privacy Rights Clearing House, a nonprofit consumer rights organization.

As fast as banks, merchants and consumers add new layers of security to their storage systems and network, say security analysts, new technologies -- or simply careless users -- create new security holes that aggressive and sophisticated identity thieves eagerly exploit. The result, says Avivah Litan, a vice president and distinguished analyst at Gartner Inc., is that "things will get worse before they get better."

Whether information is being stolen by phishing, pharming, hacking, insider theft, or common dumpster diving - the problem seems to be growing by leaps and bounds.

An interesting aspect, which I've covered in previous posts is that criminals seem to be using technology as a marketing tool - just like their counterparts in more legitimate businesses:

Criminals are also getting smarter. Larry Ponemon, chairman and founder of Ponemon Institute, which conducts research on privacy and security issues, calls it "inverted customer relationship management," in which criminals target the wealthiest individuals for their attacks.

Some are even buying marketing lists to piece together profiles of "who's got the Platinum [American Express card] and who's got the account with Merrill Lynch and who doesn't," says Litan.
I found this particularly interesting because a reasonable person would have to question, who is selling them these lists?

In the most recent high profile data breach to hit the news at Certegy, a dishonest insider sold the information to a broker. Interestingly enough, as far as I know, this information broker has yet to be identified. The next question might be - who did the information broker sell the information to?

Recently, another data broker (InfoUSA) was pegged for selling marketing lists to sweepstakes scammers.

Perhaps PogoWasRight, who states "We have met the enemy and he is us" hits the reason for the problem right on the nose.

A lot of people are making billions, if not trillions of dollars making it easy to use information. So much information has been plastered in so many places, we seem to have lost track of it all.

This gives the criminals behind this phenomenon a lot of places to steal, or even buy everything they need to commit identity theft.

Another sad statistic is that these criminals seem to rarely get caught. Pretty sure the last statistic I saw was less than 1 percent. This makes it a pretty lucrative criminal enterprise to be involved in.

Despite this, we still don't have a law that addresses data breaches?

With the elections coming up, perhaps we should be asking our elected leaders, why this is the case?

The only way to turn this trend around is to make everyone involved in it, more accountable.

Interesting article by Robert L. Scheier, here.

The article mentions statistics gathered by the Privacy Rights Clearinghouse, which I quote frequently. Other places that gather information on this are PogoWasRight and Attrition.org.

And all of them will be the first to tell you - these are only the breaches we know about. The mysterious criminals stealing the information would rather not disclose, who they are stealing IT from. Of course, the people getting the information stolen from them would probably rather not make it public, either.

Saturday, May 27, 2006

Hacking the Paparazzi

I've never been much of a fan of "paparazzi" types. Their whole goal in life is to invade "people's personal domains" for no other reason than to satisfy the public's need for gossip.

Now, it appears, they are using technology to spy on each other and the FBI is taking action.

As reported in the LA Times:


"Federal agents want to know whether one of the owners of Sunset Photo and News attempted to learn what stories the staff at US Weekly, a Hollywood gossip magazine, was working on, said the sources, who spoke on the condition of anonymity."

Please note that the FBI isn't commenting.

Link to LA Times story, here.

Another story, from Hollywood.com was a little more specific and claims that Charlie Sheen was the target of the alleged "hacking" exploit. The "person of interest" at the Sunset Photo and News (Jill Ishkanian) is allegedly good friends with Heidi Fleiss, who has claimed that the "hacking allegations" are untrue.

Not sure how credible this is, but Heidi allegedly knows Charlie quite well.

All kidding aside, hacking and a legal "Spy Industry" threaten a lot of people's privacy and now that the "Stars" are being targeted -- perhaps we can get George Clooney, Sean Penn, Barbara Streisand, and maybe Charlie's father (Martin) to speak out on this issue.

The Federal Trade Commission is taking notice and recently went after a bunch of Private Investigators, who had people's personal telephone records for sale.

Now, I'm not sure, but I might guess that some of these people are "outraged" about the telephone companies giving information to the NSA. As I've said before, the NSA is only using the best information out there - which has been gathered for years - from the private sector.

The Information Industry is big business and has been buying and selling our personal information for years.

Personally, I'd rather have my telephone records with the NSA than sold to, "whomever."

As technology continues to grow and laws fail to keep pace with it, we are all at risk. Recently, "hacking kits" were being sold on the Internet via dubious sources and if you need advice on how to do it, there are plenty of Internet groups that thrive on this subject.

Not only are there shady "Internet" sources, but you can also buy a lot of "neat" technological devices to invade people's privacy and no one will ever ask you what it's intended use is.

Industrial and personal espionage is a real problem and needs to be addressed by going after the root causes, which seem to be perfectly legal. Until we do this, our personal privacy will be out there for whoever wants to buy it.