Saturday, August 26, 2006

Secret Service is Studying the Problem from Within

The USSS (Secret Service) is studying how dishonest "insiders" can pose a large problem to organizations.

Here's what they say about it in their press release:


The report released today focuses on the people who have had access to and have perpetrated harm using information systems in the banking and finance sector, which includes credit unions and financial institutions. The findings underscore the importance of organizations’ technology, policies and procedures in securing their networks against insider threats, as most of the cases showcased in the report were perpetrated by insiders with minimal technical skills. Various proactive practices are among the suggestions offered by the report.

“With the potential for cyber crime and network intrusion expanding rapidly around the globe, the importance of cooperation with our partners in the private sector is greater than ever,” said Secret Service Director W. Ralph Basham. “The Insider Threat Study is a solid example of the role the Secret Service and its partners can play in understanding threats and helping to prevent serious crimes such as network intrusions, identity theft and financial fraud.”
Link to press release, here.

Link to full study, here.

I have no doubt that individuals and even people planted as "insiders" pose a serious threat to the safety/security of any organization. Information is worth a lot of money and getting an asset on the inside makes stealing it, pretty easy.

There is a report by the Privacy Rights Clearinghouse, I quote often, which shows that the reason for a lot of data breaches is never discovered, here.

I wonder if any of them were inside jobs?

Sponsors

ING Direct
Office Max
Yellow Pages

Friday, August 25, 2006

Phishermen Reel in Porn Users

Users of "adult services" on the Internet are the latest target of Phishermen. Being phished normally guarantees that you will become a victim of identity theft. Here's a warning from Sophos:

Experts at SophosLabs™ have warned internet users that criminals are not just targeting online bankers in their phishing campaigns as an attack is launched against users of an adult webcam site.

Spam experts based in Sydney, one of the global network of virus, spyware and spam analysis centers operated by Sophos, have identified an active phishing campaign focused on users of iFriends, which claims to be the world's largest online videochat community with more than two million registered users. Many of the video chatrooms hosted by iFriends are of an adult nature.

Link, here.

Many adult sites harbor all kinds of adware, spyware and malware. Websense did a survey, about this, here.

My guess would be that it's smart to stay away from these sites, unless your system is "bulletproof."

Not all porn is legal. I did a earlier post on how financial information might be used for another purpose:

Child Pornographers to be Tracked Financially

Wednesday, August 23, 2006

Debix Study Finds Fault with the Fraud Alert System

Debix (one of the many companies entering the identity theft business) did a study indicating that the fraud alert system mandated by the Fair Credit and Reporting Act doesn't work as well as it was intended to.

Here is what the New York Times had to say about this:

The Debix study included privacy and consumer rights advocates, as well as data security executives from Citigroup, Charles Schwab, Expedia, Discover Financial and other companies.

Participants were registered for fraud alerts at one credit reporting agency — most at TransUnion, Ms. Fergerson said.

Of the 54 volunteers, 32 received confirmation letters within a week or so — the sign that things worked as they should. But in 22 cases, something went awry.

In 18 cases, the fraud alert was set at only two agencies. In four cases, it took hold at only one.

Full story, here.

Note that the credit bureaus are disputing this - stating that this conclusion is "absurd" and the sampling was too small to be effective.

Maybe the Federal Trade Commission (who is charged with enforcing this) should do their own "study?"

After all - the important factor in this equation are the millions of people - who are, or might become "victims of identity theft."

To learn more about "fraud alerts," courtesy of the FTC, link here.