Saturday, March 29, 2008

Lifelock is getting sued, again!

Lifelock -- the identity theft service founded on an identity theft tale that was later deemed not to be very credible -- is now facing another law suit. This one, which is of the class action variety, alleges that their advertising is misleading and they don't necessarily protect a person from all the different varieties of identity theft.

From the press release on the Hagens Berman LLC site:

Today an Arizona consumer filed a proposed class-action lawsuit against LifeLock, a heavily promoted company that claims to protect consumers against identity theft. The lawsuit alleges that the three-year-old company defrauds customers by offering services it cannot legally perform, and by touting a $1 million guarantee that the suit alleges is wildly misleading.
The suit also alleges that Lifelock doesn't protect a person from all the forms of identity theft citing a case where -- Lifelock's flamboyant CEO (Todd Davis) who plasters his social security number everywhere as a marketing tool -- had his own identity stolen.

The press release didn't mention that the case was dropped after Davis employed a PI, along with a film crew to obtain a confession from the identity thief. Reportedly, the reason the case was dropped is because of a legal term called, "coercion."

One point of contention in the law suit is that the $1 million guarantee Lifelock promises is deceptive and laden with fine print:

Its advertisements prominently feature a supposed $1 million guarantee. In one commercial, Todd Davis, a founder and CEO of LifeLock, announces to a crowd of individuals, "If anything happens for any reason while you're a client of LifeLock, we will cover all losses and all expenses up to one million dollars." On its Web site, LifeLock makes similar statements, claiming that it will "do whatever it takes" to restore a member's good name.

According to the complaint, the fine print says otherwise: LifeLock will not pay any losses directly to the consumer and does not cover consequential or incidental damages to identity theft. The guarantee is limited to fixing failures or defects in the LifeLock services and paying other professionals to attempt to restore losses.

In this first paragraph of this post, I mentioned that Lifelock is getting sued again. Recently, one of the big three credit bureaus (Experian) filed a law suit for the costs of placing and replacing alerts on people's credit files.

In this post, I covered that the fact the credit bureaus are also in the identity theft protection business and that other companies (Debix, TrustedID) offer essentially the same service that Lifelock does.

This brings about speculation that both of these actions against Lifelock have the potential to set legal precedents and might bring about additional actions in the future. There has also been speculation that there is a "turf war" going on between Lifelock and the big three credit bureaus.

There is no guarantee what will become of all of this. The sad fact is that identity theft is a growing problem. Because of this, there are a lot of people getting involved in the identity theft protection business. The last time I checked, the industry was showing double-digit growth. This alone is quite remarkable considering the current state of the economy.

Given the fact that this is an "unregulated" industry involved in assisting victims of crime, everyone involved in it needs to take a hard look at the product they are offering to ensure it passes the "smell" test.

If they fail to do so, they will probably subject themselves to bad press, litigation and potentially government intervention (regulation).

They need to remember that identity theft victims are people, who fell victim to a crime that happened because their information was stored in too many places and WAS NOT protected properly. Of course, saying that, the people buying and selling information make a lot of money from doing it, also.

The sad truth is everyone is making money from this except the identity theft victim.

The post, I did on the first Lifelock law suit contains links to free resources to protect yourself and recover from identity theft. It also highlights a few of the organizations that are actively trying to do something about the overall problem identity theft has become without making a profit off it.

That post can be seen, here.

How did hackers plant malware at Hannaford Bros. and steal 4.2 million payment card numbers?

Hannford Brothers, the latest retailer to be compromised in a large scale data breach is reporting that hackers using malware breached their systems.

The next million dollar question (literally) is how was the malware (sometimes referred to as crimeware) dropped on their system? A lot of people are looking at this carefully because the company had been certified as meeting PCI (Payment Card Industry) data protection standards.

Ross Kerber at the Boston Globe, who gets the hat tip for breaking this latest development in the story wrote:

Data security specialists say the new details show how hackers have grown more adept at penetrating weak links in the systems that connect merchants and banks. In previous breaches, such as the record-setting intrusion at TJX Cos. of Framingham, where as many as 100 million card numbers were compromised, hackers took advantage of merchants who stored customer names and card data - sometimes in violation of payment industry standards - at central locations in their computer networks.

In contrast, Hannaford says it did not store customer information. The hackers who struck Hannaford mined a stream of data that the merchant and banks were not responsible for protecting under industry rules, industry specialists said.
Because hackers, criminals and misfits rarely give up their latest hacks, we'll have to be content with speculation from the experts.

Jaikumar Vijayan at ComputerWorld was able to get some expert speculation from "Mike Paquette, chief strategy officer at Top Layer Networks, a vendor of intrusion-prevention systems in Westboro, Mass." Bill Brenner at SearchSecurity.com wrote about increasing speculation that a dishonest insider planted the malware on Hannaford's network.

The insider theory intrigues me because it seems that most security breaches can be traced to a social cause. A dishonest human --who has been given access to a system -- can defeat a lot (most) computer security.

Going further into all the speculation has come about from the Hannaford announcement, I decided to see what the blogosphere had to say.

Securosis.com gives a lot of interesting perspective in their post, Picking Apart The Hannaford Breach- What Might Have Happened .

The post points out some interesting thoughts, such as that credit card numbers are useless without names (Hannaford claims no names, or social security numbers were stolen) and that the breach was most likely discovered at financial instiutions when customers complained about fraudulent transactions on their cards.

rmogull summed up his "admitted" speculation with:
In conclusion, it looks like some sort of a network breach (which could be anything from phishing/malware to compromise from a retail location to a full network hack). A sniffer was possibly installed, since it seems they don’t keep credit card information (again, assuming statements are true). The fraud was detected by the banks or credit card companies, then it took a little under two weeks to contain. Not great, and indicative of either a little sophistication on the attacker’s part, or a lack of sophistication on Hannaford’s part.
There are also some interesting comments with more speculation at the bottom of the post. From what I can gather a lot IT types read this blog.

In the end, as long as there is lack of transparency in data breaches, the best anyone can do is speculate. The reasons for a lack of transparency in data breaches are a mile long, encompassing everything from protecting ongoing investigative efforts to avoiding the financial pitfalls of all the litigation that arises after a data breach.

Of course, in more simple terms, it might also mean that no one is really sure?

Given that, I wonder if anyone can be really sure that their personal information is safe? Your guess is probably as good as mine!

Previous posts on this blog about the Hannaford Data Breach:

Security vendor removes Hannaford as a client on their site after data breach is revealed!

Hannaford Brothers data breach might reveal current security standards are outdated

Saturday, March 22, 2008

Barack, Hillary John - Does anyone know where our (your) privacy has gone?

About a week ago, I wrote a post about Britney having her privacy "jacked" by a bunch of "naughty" hospital employees. This occurred at one of the most respected medical and institutions of higher learning in the world, the University of California, Los Angeles.

Ironically, it's now been revealed that another highly respected institution, the State Department had some "naughty" employees "jack" the privacy of the three major presidential candidates, Barack, Hillary and John.

While a lot of us take Britney's exploits with a grain of salt, it's another example where too many people are being given access to too much sensitive information. Even if we take most of Britney's adventures in a not very serious light -- she is a human being and therefore worthy of a little respect and privacy in her personal affairs.

This should be especially true when someone is seeking medical attention of a sensitive nature.

The official spin in both instances is that these events were caused by naughty employees, who were snooping where they shouldn't have been. While it appears there was no sinister intent in all of this, it points to the fact that none of us can count on a little respect or privacy, anymore.

Maybe we have too many databases containing highly personal information that the wrong people have been given access to? You can spend millions on security, but no amount of it will prevent something from being compromised if the wrong person has been given access to it.

Of course, the there is a financial motive to not wanting to fix the problem anytime in the near future. It's no secret that selling personal information is a multi-billion dollar business. Implementing technology is a multi-billion dollar venture, also. It shouldn't surprise us that there is a lobby (with a lot of money), who wants to keep things the way they are.

Because of this, it shouldn't surprise us that we see criminals exploiting the loopholes in protecting information, either. After all, they're making a lot of money off it, also.

If naughty employees with a penchant for snooping could obtain the personal information of three political candidates, it isn't a far stretch that someone with more sinister intentions could have accomplished the same thing. I wonder, who failed to notice that we are now granting "contract employees" access to information of this nature?

After all, this isn't the first time a contract employee, government or otherwise, has compromised sensitive information.

I guess private businesses aren't the only entities outsourcing jobs (and a lot of people's personal information) in the process. We seem to live in a world, where in order to save a little on the bottom line, we seem to ignore basic principles (like need to know) when protecting information.

Perhaps, if we stopped storing sensitive information in too many places with little regard to who can look at it, we would stop being "shocked" when it's compromised?

All a reasonably intelligent person would have to do is look at the number of reported compromises involving sensitive information that occur and then wonder how many more there are that no one knows about? I threw that in because most people, who do something wrong normally don't disclose what they did to third parties.

After a compromise occurs, we all seem content that security enhancements will prevent the next one. Sadly, most of the enhancements introduced so far haven't put a dent in the problem and the saga goes on. In fact, it normally doesn't take very long before we hear about the latest security enhancement being defeated.

Maybe the problem needs to be taken to a more simple level? Perhaps if we weren't storing information in places -- where too many people have access to it -- we would see less of it being compromised?

We live in a world, where technology has made things easier and more productive. The problem is that "easy and productive" is taking a toll on what should be a basic human right, privacy.

The bottom line is that it has become too easy to compromise information and technology makes both good and bad people, more productive.

Saying all that, the three candidates are on record, when it comes to privacy. In July of 2006, Hillary Clinton spoke to a lot of same issues in a speech, where she said:

Privacy is at the crossroads of all these issues, and modern life makes many things easier… and many things easier to know. And yet, privacy is somehow caught in the crosshairs of these changes.

Our economy is increasingly data driven. We have dramatically ramped up surveillance in our efforts to fight terrorists who hide among innocent civilians.

But every day the news contains a story of how the records of millions of consumers, veterans, patients have been compromised.

At all levels, the privacy protections for ordinary citizens are broken, inadequate and out of date.

Likewise, Barack Obama has the following statement about this issue on his site:

Dramatic increases in computing power, decreases in storage costs and huge flows of information that characterize the digital age bring enormous benefits, but also create risk of abuse. We need sensible safeguards that protect privacy in this dynamic new world. As president, Barack Obama will strengthen privacy protections for the digital age and will harness the power of technology to hold government and business accountable for violations of personal privacy.
John McCain (as part of a bipartisan committee) has expressed frustration on the privacy issue, also. Here is what he was quoted as saying in a CNet story after a FTC report was released on the state of the state on privacy:

A bipartisan group of senators led by Sen. John McCain, R-Ariz., said it is determined to pass new laws restricting the ability of Web sites to collect and use information from a visitor without that person's consent.

For the last several years, Web sites have operated under a form of self-regulation, and industry groups have touted the ever-increasing number of sites posting privacy policies. However, members of the Senate Commerce Committee today decried those steps as inadequate and cited polls showing that the vast majority of consumers opposed industry self-regulation.
There is no doubt that by this point in the game, most of our politicians have made a statement on the privacy issue. Despite these statements, most of the legislation presented in Washington hasn't been passed yet?

In fact if memory serves me correctly, the last time we tried to pass some federal legislation, the end result was that it would have watered down more proactive laws already passed into law at the State level.

I know everyone is busy with the campaign underway so I'm going to include a reference to an article (with an interactive map) showing what State laws on this issue have already been enacted. Included on the map is a interactive flag over the District of Columbia showing which federal laws have not.

Well put together article by csoonline.com, here.

In case anyone reading this can't keep up with the record number of data breaches, Attrition.org had a chronology, here.

PogoWasRight is another place that helps me keep up with the record number of compromises, also.

Friday, March 21, 2008

OCCRP reports on Eastern European/Eurasian organized crime


(Photo courtesy of the OCCRP site)

Eastern European/Eurasian organized groups seem to have their hands in a wide variety of organized criminal activity. They are often mentioned when referring to anything from auction fraud to payment (credit/debit) card skimming and computer crimes.

eBay claims there are entire towns in Romania making a living via auction fraud on it's well known site.

A new site called the Organized Crime and Corruption Reporting Project has been launched by a group of journalists to cover this activity, which seems to have to have a global reach.

In their own words, here is their vision:

The Organized Crime and Corruption Reporting Project (OCCRP) is a joint program of the Center for Investigative Reporting in Sarajevo, Romanian Center for Investigative Journalism, Bulgarian Investigative Journalism Center, Media Focus, the Caucasus Media Investigation Center, Novaya Gazeta and a network of investigative journalists in Montenegro, Albania, Moldova, Ukraine, Macedonia and Georgia.

Our goal is to help the people of the region better understand how organized crime and corruption affect their lives. OCCRP seeks to provide in-depth investigative stories as well as the latest news pertaining to organized crime and corruption activities in the Eastern Europe and Eurasia. In addition to the stories, OCCRP is building an online resource center of documents related to organized crime including court records, laws, reports, studies, company records, etc that will be an invaluable resource center for the journalists and public alike.
The site has been given financial support by the Foundation Open Society Institute (FOSI) and the United Nations Democracy Fund.

Although many of the journalists aren't well known in Western Europe and North America, they have been recognized as putting out some award winning work:

Recently, the program’s first project on energy traders was awarded the Global Network of Investigative Journalists “Global Shining Light Award” for quality investigative journalism under adverse conditions. The project was done in cooperation with SCOOP.

Journalists who have participated in projects published on this website have included Stanimir Vaglenov, Alison Knezevich, Boris Mrkela, Sorin Ozon, Eldina Pleho, Beth Kampschror, Stefan Candea, Roman Shleynov, Mirsad Brkić, Michael Mehen, Mubarek Asani, Paul Cristian Radu, Milorad Ivanović, Vitalie Calugareanu, Vlad Lavrov, Michael Mehen and Altin Raxhimi. The Editors are Rosemary Armao, Paul Radu and Drew Sullivan.
The site covers a wide variety of organized criminal activity (besides what I mentioned above) coming out the the area. Some of these activities include narcoterrorism, illegal arms sales, shell companies and even tobacco smuggling.

Interestingly enough, by reading through the site, I discovered that organized crime even has it's hands in the energy business in the region.

This subject, or the underlying causes of it aren't covered in depth when we read about this phenomenon in the West. Normally, we hear rumors pointing to mysterious Eastern European gangs associated with a sophisticated scam that has surfaced in our own back yard.

In scam circles, some of these people are referred to as "Vlads," which refer to Vlad Tepes, who as the inspiration for the Dracula story. Recently, a person who goes by the name of "Vladuz" has given eBay and the authorities considerable grief when hacking into their system.

Given that this activity reaches far beyond Eastern Europe and Eurasia, this has always amazed me. If you live in any major city in North America or Western Europe, Eastern European/Eurasian organized crime groups are probably operating not very far from where you live.

As the site matures, my guess is that it will provide evidence to ties between these groups and terrorist organizations, also. In fact, if you read what is on the site, some of the evidence I mention is already being written about.

The OCCRP is an excellent and well-written resource for the lay person and professional writer to learn more about a problem, which has become International in nature. Furthermore, since it is written by journalists from the Region, it is a great research tool for anyone interested in the subject.

OCCRP site, here.