Posts

Showing posts with the label cyber crime

Out with the Old and in with the New

I was asked today by a board member to respond to a question from a prospective investor who wanted to know how Live Ensure (our service) differed from two other – lets call them ….the more traditional solutions.  For the sake of this blog we will call them the Old and the New solutions.   Let me describe the Old Co solutions to you briefly.  They both embody technologies which are over a decade old ( think RSA ) such as tokens and servers ( both physical and virtual).  Their solutions rely on the user entering a PIN into a browser and thereby satisfying the ‘something you know ‘ part of strong authentication.   Here it is slightly edited. The biggest weakness of both Old Co solutions are the vulnerability to MITM and MITB attacks. Both require the user to enter a PIN ( something you know ) ie a second factor over and above the user name and password ( the single factor or weak authentication ). The user enters this PIN back into the browser which is...

Why most security fails and LiveEnsure® does not ?

Image
Mary Meeker informs us that there are now 1.1bn  Smartphones  (17% of all mobile phones) and these are driving Internet growth with a total of 2.4bn people now connected to the Internet. Mary Meeker Internet trends The universe for hackers just grows and grows.    One of the most lethal of these attacks is Zeus (ZITMO) – which is aimed squarely at Smartphones. The Zeus attack is an example of several attacks now being launched that are based wholly on anticipated behavior, especially as it relates to social media, single-sign-on and BYOD. A sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer. The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts, Darrell Burkey, director of IPS products at Check Point Software Te...

SITES DONT GIVE A DAMN ABOUT YOUR SECURITY

The sheer volume of reportage on hacking is overwhelming.   The sites being hit are the ones that you and I use every day.   Some provide useful information, some, valuable services and others perhaps just news or trivia.   We use them multiple times a day – sometimes without even being fully aware that we are,  like DropBox.   We use these sites  to store personal and business information, to connect us with potential clients, employers and employees, to help us choose insurance providers, to send us our groceries and some, to just play on.   Dropbox allows us to seamlessly log in by re-referencing a cookie they have planted on our computer to ‘verify’ our identity.   LinkedIn also uses the same technique when we log in.    A user name and password.  How secure is that ?    Well,  not very,  given that both of these sites have been hacked and your and my perso...

WHY SECURITY MATTERS? (or LET’S START A ‘PASSWORD SPRING’ ! )

You would be forgiven for thinking that perhaps most people have become somewhat nonchalant about online security and that the prevalence of hacks has made most of us somewhat immune to the dangers.    Indeed I would say that some sites have become almost cavalier about their attitude to their member’s security.  The recent hacking of LinkedIn certainly did not elicit the kind of response I would have expected, indeed hoped for,  as a member.   I get the impression that it was something of an irritant that they hope won't come again – and are certainly not bothering with beefing up security.  Far too much hassle.   So is their reaction reflective of their members lack of interest – I think not,  as one of their members has tried to sue them for failing to provide adequate security.  ( http://articles.latimes.com/2012/jun/21/business/la-fi-tn-linkedin-5-million-hack-20120621 )   LinkedIn have said that they will salt their passwords...

SIX MONTHS ON AND EPSILON STILL DONT SECURE THEIR USERS

In April this year,  Epsilon Data Management LLC  (one of the world's largest providers of marketing-email services) , a division of Alliance Data Systems Corp issued a statement, " On March 30th, an incident was detected where a subset of Epsilon clients' customer data were exposed by an unauthorized entry into Epsilon's email system. The information that was obtained was limited to email addresses and/or customer names only ." ( http://www.fastcompany.com/1744738/the-epsilon-breach-should-you-be-angry-worried-or-bored ) When it's all said and done, the Epsilon hack may be the largest name and email address breach in the history of the Internet.  Epsilon handles more than 40 billion emails annually and more than 2,200 global brands. If you are thinking you are safe because you opted-out of marketing emails, think again ( http://blogs.computerworld.com/18079/epsilon_breach_hack_of_the_century ) Epsilon required their customer...

SECURITY SANS FRONTIERS

In many countries around the World, access to the Internet is seen as a basic right, and so it should be.    Those countries which have done so to date include :  Estonia, France,  Spain,  Greece  and Finland,  which was actually the first to do so in June 2010.  ( http://www.publicserviceeurope.com/article/642/internet-access-should-be-a-human-right)  I In fact the United Nations recently declared Internet access as a human right. ( http://www.itproportal.com/2011/06/04/un-declares-internet-access-as-a-human-right/ ) Obviously the next challenge is to build the infrastructure and provide the means of access.    But that is the subject of a separate discussion. So the “World”  has woken up to the importance of closing the digital divide and has also realized the importance of the Internet, and access to it,  to the functioning of society.   Amongst the many momentous events of the last twelve months ...

ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !

I know,   I know – I hear the howls of protest even before finishing this first sentence.   “What about all the innocent lives exposed by the irresponsible publication of peoples names in positions of authority or in sensitive roles. ?”    But where does the fault lie ?  With those doing the breaking and entering?   Or those not providing adequate protection??  It is liked leaving your house locked without an alarm system, going on holiday, and coming back and finding it broken into.   Don’t be surprised.  You have no one to blame but yourself.  “ But these are criminals ! “  – I hear the sounds of self righteous chest thumping.    Maybe, but what they have done – I hope – is scare the s**t out of anyone who has anything (data) that is accessible via the Web  - and into ensuring that their ‘security’ ( if any ) - is rapidly upgraded.    This ranges from personal users who ...

REPUTATION MORE VALUABLE THAN CASH (ASK SONY)

The recent attack (it seems by Anonymous) on SONY which compromised the personal details of almost 100m of their gaming customers has caused massive damage to the SONY brand.   According to Interbrand in 2009 SONY’s brand value was $12bn.   You can safely assume that it will have taken a hit in the order of billions of dollars.  ( This excludes any legal action and the resultant loss.)  The same could be said of Epsilon and RSA who like SONY did not have a major financial breach but their good names have been severely compromised.   The loss to brand value as well as enterprise value could be massive due to the loss of future business.    (There is a report circulating citing research done on RSA’s customers of whom more than half stated that they would not be renewing their contracts. )    If not obvious before,  then now,  executives charged with the stewardship of large valuable corporations must r...

THE SECURITY WEEK THAT WAS !

This week started with a bang with the UK Govt announcing that Cyber War was imminent ( http://www.bbc.co.uk/news/uk-11562969 )  – the ‘Enemy’ now has the capability to :   close down our power grids / transport networks / industry / ( read - critical infrastructure)   – with one flick of a mouse!   ‘They’ could insert Trojans into our infrastructure which could travel through our networks and attack the mainframes running our railways ( for example)  – bringing them to a grinding halt ……with the resulting disorder that ensues.    Just like the onset of winter – actually…… about now – when the falling Autumn leaves start to accumulate ' strategically'  on the railway lines – and when coupled with some strategically placed raindrops - can bring trains to a grinding halt.    Causing commuter chaos. ( We have seen those headlines before !)  So if its not the Unions ( and believe me they are just warming up ...