Thursday, January 03, 2008

Lou Dobbs' audience responds to Hillary's allegation that he is full of hot air!

My wife, who is a die hard Lou Dobbs fan brought to my attention that Hillary Clinton had recently called him "full of hot air."

In the response to this statement, Lou and crew ran this poll on their show yesterday.

The question they asked was:

Do you believe presidential candidates who support open borders, illegal alien amnesty, and outsourcing of middle class American jobs to cheap overseas labor markets are full of "hot air"?
I decided to check the results this morning and 95 percent of the people responding felt that the presidential candidates supporting open borders, illegal alien amnesty and outsourcing were "full of hot air."

Strangely enough -- if I remember one of the debates correctly -- it seems difficult to get Hillary to commit herself on some of the above listed issues.

Would that make some believe that her responses to these issues are full of hot air?

With the primarys starting today in Iowa, it will be interesting to see what the voice of the American people will be!

You can see the results of Lou's poll on his site, here.

You can also see the article that reported Hillary calling Lou full of "hot air" at Iowa State University (courtesy of NewsDay.com), here.

If you would like to revisit Hillary's stunning reversal on the driver's licenses for illegal aliens issue (within 2 minutes) in the State she represents, the Captain's Quarters blog has commentary, here.

Tuesday, January 01, 2008

IT Policy Compliance Group looks back at what was important in 2007

The IT Policy Compliance Group issued a great year end analysis of the important events that took place in the world of IT security in 2007.

Lamont Wood wrote this interesting analysis and leads into it by saying:

Looking back, those who specialize in the history of corporate and cultural debacles may one day hail 2007 as the year when the dusty topic of document retention became a matter of corporate life and death. Thanks to the pervasiveness of networked computers, corporate data proved again and again that it could not only leak into the wild, but, once there, take on a life of its own-and do enormous harm to its parent.

The essay covers some interesting subjects like Data Breaches, PCI DSS Folies, CyberWars and the The Dark Side.

It also includes a summary of the regulations that businesses had to learn to deal with in 2007.

I'm going to refrain from commenting further to direct people to these interesting observations, here.

I did another post on a report from the ITPCG entitled, IT Policy Compliance Group issues study on data breaches and information theft.

This report revealed that focusing on fewer risk focused control points, and then inspecting them more frequently made an organization less likely to suffer data breaches/information theft.

If you haven't read the report yet, it is a worthwhile read, also.

In case you are unfamiliar with the IT Policy Compliance Group, here is their mission (in their own words):

The ITpolicycompliance.com web site is dedicated to promoting the development of research and information that will help IT security professionals meet the policy and regulatory compliance goals of their organizations. Specifically, this site focuses on assisting organizations to improve compliance results by providing reports based on primary research as well as other related information and resources.

Here is who supports this site:

CSI (Computer Security Institute), The IIA (The Institute of Internal Auditors), ISACA (Information Systems Audit and Control Association), the IT Governance Institute, Protiviti, and acknowledge Symantec for providing the financial support to make this site possible.

FTC issues report on Malicious Spam and Phishing

The Federal Trade Commission just released it's report on the current state of malicious spam and phishing in today's electronic world.

Interestingly enough, it points out that spammers are criminals.

While this isn't a new revelation, the report seems to want to drive that point home. Maybe this is part of the education process referred to at the bottom of this post?

Here is what the press release had to say:

During the workshop, panelists confirmed that spam has increasingly become a significant global vector for the dissemination of malware and the propagation of financial crimes. Panelists opined that, in most instances, the acts of malicious spammers are inherently criminal, and criminal law enforcement agencies are best suited to shut down their criminal operations.
The report discusses the problem of botnets at length and refers to a 2006 report stating that an estimated 12 million bot infected computers are being used to send spam. The report also states that most of these computers are physically located outside the United States.

Going deeper into the problem the report discusses a phenomenon called fast flux:

With fast flux, infected bot computers serve as proxies or hosts for malicious websites. The IP addresses for these sites are rotated regularly to evade discovery. For example, a phisher can deploy numerous and different IP addresses for a single phishing campaign, foiling the efforts of ISPs and law enforcement seeking to stop these campaigns by dismantling a single web site. Despite these challenges, the record reflects that at least one ISP does take proactive measures to detect and disconnect “fast flux” web sites from a portion of its network.
The report also acknowledges that DIY (do it yourself) crimeware kits are making it easy for just about anyone to mount a phishing campaign. One kit described sells for as little as $17.

Also cited are some statements from jailed bot-herders that botnets are being rented by the hour for $300-$700 an hour.

The report also give some statistical information on what this is costing all of us:

A survey by Consumer Reports reveals that viruses, phishing, and spyware resulted in over $7 billion in costs to U.S. consumers in 2007. The survey revealed further that computer infections prompted 850,000 U.S. households to replace their computers. The costs to businesses also are high. One panelist reported that 80 percent of 639 businesses it studied experienced cybercrime-related losses, totaling $130 million.
Also included in the report is information on Operation Bot Roast conducted by the FBI and Department of Justice.

Besides going after the criminal element, the report states that e-mail authentication is crucial in detecting spam at the ISP level so that it can be filtered out by existing spam filters.

Of greatest importance (call me a socialist) is that the report calls that a broader effort needs to be made to educate the public on the dangers of spam:

Consumer and business education can have a significant impact in the fight against spam and phishing. Because spam is an ever-evolving problem, stakeholders should revitalize efforts to educate consumers about how to protect their computers from online threats and improve methods for disseminating educational materials to consumers and businesses. In addition, the Summit identified consumer-interfacing tools such as spam reporting buttons as valuable tools for ISPs and reputation service providers. Accordingly, staff will encourage industry to continue to develop and fine-tune such tools.

In keeping with this theory, the FTC has three sites listed on the right side of the press release to educate the public about spam, FTC Spam site, OnGuard Online: Spam Scams and OnGuard Online: Phishing.

The full report can be viewed, here.

Discovering a record amount of information theft only solves half the problem

Has anyone besides me noticed that when data breaches are reported, we see an official statement that the information hasn't been used by identity thieves?

After thinking on that one for awhile, it makes sense that criminals would stop using the information from a data breach after it has been reported.

So far as information used before the breach is discovered, it's pretty hard to prove where the information came from in an identity theft case. With so much compromised information out there, it's nearly impossible to figure out where the point-of-compromise is in any individual case.

When a data breach occurs, a lot of accounts are closed down and everyone who has been compromised runs out and checks their credit reports. Most of the time, free identity theft monitoring is made available to those who have been breached, also.

My guess is that once the stolen information is made public, it's probably dangerous to use. At the very least, it probably doesn't hold the same profit value that it had when no one knew it had been stolen.

For the past week, the news has been awash with the year end statistics on data breaches. By all the recent news accounts, 2007 was a record year.

While reporting data breaches is painful and costly, reporting them probably makes the information a lot harder to exploit for criminal purposes.

Although 2007 was a record number for reported data breaches, very few of criminals stealing the information got caught. Organizations losing the information are starting to be held accountable, but it would be nice to see more of criminals stealing the information brought to justice.

Another thing to consider is that data breaches aren't putting organizations out of business. True, they are costly, but in the end the cost is normally passed on to everyone using their services.

In the end, we are all paying for the cost of fixing data breaches.

And while a record number of data breaches were reported, there would have to be some that no one (except the criminals) know about.

My guess is that there is a lot information theft that is never detected. I would also surmise that this is considered the most valuable information being sold and used by criminals.

Compromised information is normally most effective when the person who it belongs to doesn't know it's being used.

Until we impact both sides of the equation -- the people losing information and punishing the people stealing it -- we are probably going to see news reports reflecting record statistics on the amount of data breaches occurring.

To do this, we need to focus more resources on catching the people stealing the information and enact laws that make it hurt when they get caught.

The last statistic I saw was that less than 1 percent of them get caught, and if they do, they normally get a slap on the wrist. A lot of the reasons for this are insufficient resources to investigate fraud and a lot of cases that are never reported by both organizations and individuals.

AP article (courtesy of the Washington Post) on 2007 data breach trends, here.

Update: Dissent from the Chronicles of Dissent and PogoWasRight left a good comment on this post pointing out that a lot of people did get caught this year. He is right and I did posts on a number of them.

The people out there catching the crooks stealing the data would be able to do a lot more if they were given more resources!

The Chronicles of Dissent has an excellent article on this subject that I highly recommend to anyone interested in the phenomenon of data breaches, here.