Posts

SIX MONTHS ON AND EPSILON STILL DONT SECURE THEIR USERS

In April this year,  Epsilon Data Management LLC  (one of the world's largest providers of marketing-email services) , a division of Alliance Data Systems Corp issued a statement, " On March 30th, an incident was detected where a subset of Epsilon clients' customer data were exposed by an unauthorized entry into Epsilon's email system. The information that was obtained was limited to email addresses and/or customer names only ." ( http://www.fastcompany.com/1744738/the-epsilon-breach-should-you-be-angry-worried-or-bored ) When it's all said and done, the Epsilon hack may be the largest name and email address breach in the history of the Internet.  Epsilon handles more than 40 billion emails annually and more than 2,200 global brands. If you are thinking you are safe because you opted-out of marketing emails, think again ( http://blogs.computerworld.com/18079/epsilon_breach_hack_of_the_century ) Epsilon required their customer...

HSBC EMBRACES OLD TECHNOLOGY IN ITS BATTLE AGAINST HACKERS

 If you live in the UK and are somehow involved in the business world and exposed to media you could not help but have noticed the extensive advertising campaign that HSBC has been running on its new (sic) ‘security device’ for online banking - Secure Key.    ( I was tempted to refer to them as  ‘ large UK bank’  - but it is so obvious who it is – no point in pretending. ) A lot of money has been thrown at this campaign – I would guess millions.  ( http://www.youtube.com/watch?v=Jx0Z5CiQMIw )   Full page spreads in large circulation newspapers cost big bucks not to mention prime time TV slots.   So here you have the worlds largest retail bank splashing millions on advertising and even more on a ‘cool’ little device that looks like a mini-calculator  - but basically a technology that has been around for about a decade.   This will be rolled out to 4m retail customers worldwide at a reported cost of up to £50 per pop!...

SECURITY SANS FRONTIERS

In many countries around the World, access to the Internet is seen as a basic right, and so it should be.    Those countries which have done so to date include :  Estonia, France,  Spain,  Greece  and Finland,  which was actually the first to do so in June 2010.  ( http://www.publicserviceeurope.com/article/642/internet-access-should-be-a-human-right)  I In fact the United Nations recently declared Internet access as a human right. ( http://www.itproportal.com/2011/06/04/un-declares-internet-access-as-a-human-right/ ) Obviously the next challenge is to build the infrastructure and provide the means of access.    But that is the subject of a separate discussion. So the “World”  has woken up to the importance of closing the digital divide and has also realized the importance of the Internet, and access to it,  to the functioning of society.   Amongst the many momentous events of the last twelve months ...

ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !

I know,   I know – I hear the howls of protest even before finishing this first sentence.   “What about all the innocent lives exposed by the irresponsible publication of peoples names in positions of authority or in sensitive roles. ?”    But where does the fault lie ?  With those doing the breaking and entering?   Or those not providing adequate protection??  It is liked leaving your house locked without an alarm system, going on holiday, and coming back and finding it broken into.   Don’t be surprised.  You have no one to blame but yourself.  “ But these are criminals ! “  – I hear the sounds of self righteous chest thumping.    Maybe, but what they have done – I hope – is scare the s**t out of anyone who has anything (data) that is accessible via the Web  - and into ensuring that their ‘security’ ( if any ) - is rapidly upgraded.    This ranges from personal users who ...

DOES YOUR WEBSITE HAVE A LOG IN ?

Well - you’re probably thinking - this is going to make a fun read !!   Does my website have a log in ??  Well damn right it does ( you’re saying to yourself) – we can’t just let any old passer by onto our site!! I mean look at all these big cheeses being hacked like RSA , SONY and even the CIA !! But if users have to log in - that means they need to register and they need to remember yet another user name and possibly -  but not necessarily - another password.    Well - that means that customers desert in droves !  Or does it? Are customers put off when they have to log in ?  Well I guess a lot has to do with whether the service you offer is valuable enough.   Lets see – Twitter, Facebook and Gmail just to name a few at random – you would expect to see some kind of ‘identification ‘ process going on.  And indeed you do.  And now to make it all that much easier – SSO (Single Sign On) ,  OpenID and now BrowserID co...

HACKING - A 50 DAY LOVE ( LULZ) FEST ( or safe sex for the masses)

Image
So Lulz have ( supposedly ) fallen out of love with us after only 50 days !!   WOW -  that was a short and sharp,  whirlwind romance.    One hell'uve steamy affair.    One day SONY,  the next day the IMF,  the next CIA – no one - was safe from her charms. This little slut(z) came into our lives for a bit of fun and has left us breathless and embarrassed with no-where to hide .  Why ?  Because she wanted to show that with a little bit of seduction –by showing a little cleavage /  a bit of leg – she was able to conquer all before her.   Like Helen of Troy – no one could resist her charms. She made us realize that we don’t actually know what protection is all about.   The protection we are  supposed to use  – was either damaged / wrongly spec’d or else we just could not get it 'on' quick enough.   Sure -  she may have laid some of our secrets bare – and many were left red-faced with no-where to...

MOBILE MONEY - A SOLUTION READY TODAY

Google have just announced with some fanfare that they have created a mobile money eco-system.   Android users can now use their devices fitted with NFC chips to make payments at selected Points of Sale in the US.   This will only be launched on a limited scale some time in the Summer.  It is not actually ready yet. ( http://googleblog.blogspot.com/2011/05/coming-soon-make-your-phone-your-wallet.html ) There is no doubt that those of us in the ‘advanced’ West will value the utility of being able to swipe our phones (which have become extensions of our very beings) when we buy coffee  - the Starbucks app has been out for a while – ( http://www.starbucks.com/coffeehouse/mobile-apps ) or when we make our day to day purchases.   It will be  ‘cool’ just as it is cool today to flash an NFC enabled credit card at an NFC enabled POS when making small value purchases. However I would argue that the utility,  of the full functionality of mobile money transa...