Saturday, October 28, 2006

A Hidden Cost of Identity Theft - "Credit Card Gotchas"

Just got my copy of the Consumers Union newsletter and they did an interesting article about "credit card gotchas."

Here is what they had to say:

The bank can change the interest rate and other terms at any time, for no reason, and you get stuck with a higher interest rate on purchases you already made. You mail the bill before it's due, but get hit with a late fee anyway. You sign up for a 7% interest rate, but it goes to 27% if you bounce a check, go over the limit, or miss payments.

Congressional elections are coming up. Let’s tell our members of Congress -and their challengers- that we want better treatment. Demand sensible reforms for credit cards!

These credit card "gotchas" aren't just happening to you. A recent Government Accountability Office report shows that one fifth of credit card holders pay an interest rate of 20% or more. Even if you have a lower rate, it can go up at any time, for no reason. The report also found in just a year, more than one third of consumers were charged a late fee averaging $34! And, credit card companies are still raising interest rates based on whether the consumer missed a payment to a different creditor. Every year, bills to reform credit card practices are introduced but not passed. To learn more, click here.


Link to Consumer Union article, here.

This made me wonder how many times a victim of identity theft is hit with higher interest rates because they were compromised and negative data was erroneously (wrongfully) put on their credit report?

The answer is probably pretty scary and how much "extra revenue" could financial institutions be making as a result of this?

Then consider how much personal and financial information has been breached at financial institutions - where "everything was kept as quiet as possible" and we were told the victims were compensated.

As I've said before -- no business is in the business of losing money -- and the costs associated with fraud (in reality) are passed on to everyone.

Perhaps if more "sensible laws" on this matter were passed - financial institutions would have to protect people's personal and financial information a little better to maintain their profitability?

The latest tally of people breached (courtesy of the Privacy Rights Clearinghouse) is 95,000,000 - and some might argue - when we see those being breached "being very tight-lipped," the true figure might be higher.

Here is a post, I did on how fraud costs are misplaced:

Are We Addressing Cyber Crime from the Wrong End

Are the Phishermen Planning a Christmas Offensive?

Vnuet is reporting that security experts have noted a massive botnet (1,000,000 compromised PCs) being formed and the suspicion is that it will be used for a holiday season (Christmas) attack on Internet consumers.

"No one knows yet exactly what nefarious activity the army of captive PCs will be used for. But the chances are it will be a massive onslaught of phishing aimed at defrauding web consumers in the run up to Christmas."

Story, here.

Historically, criminals take advantage of the Christmas season due to the sheer volume of transactions - which makes it easier for them to disguise their activity.

According to Wikipedia, a botnet is "a jargon term for a collection of software robots, or bots, which run autonomously. This can also refer to the network of computers using distributed computing software."

In less technical terms, Internet criminals take over people's systems and then use them to launch spam and scams without the owner's knowledge.

According to the report - no one is certain who is behind the botnet being assembled - or exactly what the intention is. Less than effective protection (security) is normally the reason a computer can be compromised.

If the intention is phishing - the Anti-Phishing Working Group has a great page on their site on how the average person can avoid these scams, here.

Thursday, October 26, 2006

Online Brokerage Scams are a Sign of a Bigger Problem

A couple of weeks ago, I did a post on "Cyber Crooks Targeting Online Brokerages." Now more information is being released on this latest financial crimes target.

Courtesy of Linda Epstein at Blogging Stocks:

"E*Trade reported on a conference call last week that it spent $18 million in the third quarter to compensate customers affected by trading fraud, according to a report from Bloomberg. TD Ameritrade also admitted to losses, but gave no numbers. We may get more details when it reports its numbers, expected later today. Charles Schwab told Bloomberg that it didn't see "anything unusual enough to warrant a financial disclosure." Well, if I were a Schwab customer and my account were infiltrated, I certainly would consider it important enough for disclosure. I hope Schwab is being more candid with its customers. Fidelity did not comment on Bloomberg's story."

Blogging Stocks article, here.

InformationWeek did another article with good information about this, here.

According to the articles, accounts are being used in "pump and dump" schemes after personal computers are compromised with crimeware.

Wikipedia describes a "pump and dump" scheme as "a term used to describe a form of financial fraud that typically involves artificially inflating the price of a stock or other security through promotion, in order to sell at the inflated price (creating artificial demand)."

The InformationWeek article, also mentions that money is being stolen directly from accounts.

It seems that some of the brokers are disclosing their problems and some aren't. Thus far, victims are being compensated, however (in reality) fraud costs are normally passed on to the consumer.

Corporations aren't in business to lose money.

The InformationWeek article mentions law enforcement's frustration that a lot of these incidents aren't reported, or are being "underreported."

They also mention that only a "handful" of States have laws on the books to address "phishing" and that our legislators can't agree on a Federal law.

Until we enact the necessary legislation and give law enforcement "full cooperation," the criminals behind this will be "laughing all the way to the bank."

Wednesday, October 25, 2006

Are RFID Credit Cards Safe?

The RFID ConsortiUm for Security and Privacy (CUSP) has issued a study about vulnerabilities in first-generation RFID-enabled credit cards.

In their blog, Ari Juels writes:

Consumers in the United States today carry some twenty million or so credit cards and debit cards equipped with RFID (Radio-Frequency IDentification) chips. RFID chips communicate transaction data over short distances via radio. They eliminate the need to swipe cards or hand them to merchants. Consumers can instead make payments simply by waving their cards—or even just their wallets—near point-of-sale terminals.

While appealing to both consumers and merchants, the convenience of RFID credit cards has a flip side. What a legitimate merchant terminal can read, a malicious scanning device can also read without a consumer’s consent or knowledge. RFID credit cards therefore call for particularly careful security design.

Blog post, here.

In a "nutshell," the study warns that current RFID credit cards are vulnerable to having the identities of the cardholder scanned from afar and the information could also be used in credit/debit card skimming.

They also state that this can be accomplished without great technical difficulty and that "slightly stronger data protections and cryptography would largely prevent the problems they discovered."

The study admits that "card skimming" is already a big problem, therefore these cards are unlikely to change anything that isn't already going on.

My question is when will we start developing technology that will protect the consumer instead of developing technology that will "probably" add to the problem?

There is an interesting demonstration posted by RFID-CUSP on YouTube about this, here.

Here is a previous post, I did on RFID:

RFID, A Necessary Evil; or an Invasion of Privacy?