http://www.boston.com/business/articles/2008/04/23/stung_by_hackers_grocer_encrypts_customer_data/
As any Hannaford exec will tell you, the last place you want to secure is the first place hackers will target. As the cliché goes - a chain is only as strong...
In this case, although details are quite nebulous, it appears that malware running on internal servers intercepted credit card data as the cards were swiped (plaintext data is sent from the POS terminals to the processing servers before the data is encrypted, so anyone snooping right in the middle could easily get access to the entire card data), and then simply shipped the info off to the hackers.
Really simple operation, but how did the malware get inside the internal servers? There are a few ways:
a. Someone used it to surf the 'Net, and probably downloaded it by mistake
b. Someone planted it on purpose (inside job)
c. Hackers got in from outside and planted the program
The company will not really say what happened, so the possibility that it was an inside job is quite high.
Steps the company has taken to avoid such illegal interception include encrypting the data right at the POS, having IBM monitor the network for suspicious activities and so on. This, thus, is another case of bolting the barn...although it is a sure deterrent to hackers planning the same method of stealing information in future.
The problem is hackers will probably find a way around it; they always do. The PCI-DSS standards (see one of my previous blogs) only regulate the encryption of data when it reaches the servers and not before or during, so that is definitely a weakness.
Further, as the article in the link notes (and is so true anyway), retailers depend badly on the software vendors to update their software/patch issues and vulnerabilities, and overall make sure their product is not a gateway for hackers to drill into the enterprise and steal information.
One critical step would to monitor INTERNAL traffic (in terms of always monitoring who accesses sensitive servers, implement a strict ACL, and checking ALL packets that leave the servers - especially those that break known patterns/signatures).
Doing extensive background checks on staff that must have access to these machines should be made mandatory, and any unauthorized attempts to peek at the database or perform any kind of illegal operation should result in immediate termination, no exceptions. Quite obviously (as before in my earlier blogs) I am not advocating tyranny at the workplace, just prudence/caution/curiosity- and lots of it.
Hacking is done by humans - not machines or software, although they're indispensable in meeting their nefarious goals. The instigator is still a living, breathing human; so any security plan that mindlessly targets malware, viruses, worms, trojans etc without taking into account the human element (especially employees and also the psychological aspects of hacking/hackers) is doomed to fail.
For most large corporations that deal in data (finance, medicine, retail etc) there is nothing more horrific than a panicky call in the middle of the night from the sys admin. Don't let it happen to you - tighten your network; encrypt; monitor; adjust; implement; monitor.
Be safe!
Showing posts with label data encryption. Show all posts
Showing posts with label data encryption. Show all posts
Wednesday, April 23, 2008
Wednesday, March 5, 2008
Amazingly Tamper-Friendly Machines
http://www.news.com/Windows-based-cash-machines-easily-hacked/2100-7349_3-6233030.html
By now you probably realize no data is safe from hackers, no matter where it may be stored.
However, hacking into ATMs, which in simpler times consisted of simply attaching one end of a strong rope to the machine and the other end to a truck and then hauling the whole thing off, has now become a fine art.
ATMs (esp in the UK) are supposedly highly vulnerable - essentially because they are nothing but wintel machines, networked with other wintel machines, and specifically built to perform one function - manage the transfer of money (and charge you sky-high fees while at it).
As the article discusses quite clearly, it's not so difficult getting into one of these black boxes and electronically heave away any $$ - leaving probably no traces of any kind.
Solutions? The article says (and I quote):
" It says the most effective way to protect against these new threats is to use a multifunction device with routing, firewall, intrusion detection system/intrusion prevention system and VPN (virtual private network) capabilities, positioned in front of, and protecting, the ATM network."
What got me? The fact that only the PIN was encrypted - everything else was plain text, EVERYTHING else. Talk about an open invitation to network fiends.
Best solution - don't use one of these things; just pay cash or use credit cards if you must.
By now you probably realize no data is safe from hackers, no matter where it may be stored.
However, hacking into ATMs, which in simpler times consisted of simply attaching one end of a strong rope to the machine and the other end to a truck and then hauling the whole thing off, has now become a fine art.
ATMs (esp in the UK) are supposedly highly vulnerable - essentially because they are nothing but wintel machines, networked with other wintel machines, and specifically built to perform one function - manage the transfer of money (and charge you sky-high fees while at it).
As the article discusses quite clearly, it's not so difficult getting into one of these black boxes and electronically heave away any $$ - leaving probably no traces of any kind.
Solutions? The article says (and I quote):
" It says the most effective way to protect against these new threats is to use a multifunction device with routing, firewall, intrusion detection system/intrusion prevention system and VPN (virtual private network) capabilities, positioned in front of, and protecting, the ATM network."
What got me? The fact that only the PIN was encrypted - everything else was plain text, EVERYTHING else. Talk about an open invitation to network fiends.
Best solution - don't use one of these things; just pay cash or use credit cards if you must.
Labels:
ATM,
data breach,
data encryption,
data theft,
plaintext
Monday, February 11, 2008
Data Breach at Georgetown University
In what constitutes an inexcusable breach of trust and security, GU reported to its students and faculty that nearly 38,000 people have had their personal data exposed.
http://explore.georgetown.edu/news/?ID=31245
Apparently a sensitive hard disk was stolen - with the disk containing UNENCRYPTED information (SS numbers, names etc) of many thousands of students and faculty. I cannot imagine how such a prestigious institution could let such a thing happen.
Does security begin and stop with/at the ethernet cable?!!
Physical security is as important as network/digital security. For anyone to minimize the value or importance of one over the other is beyond ludicrous. GU is offering to pay for one year's worth of credit monitoring, but what about after that? The govt should mandate a MINIMUM of 5 years' worth of credit monitoring for each such incident, plus total insurance covering at least 5 times the total of the existing credit limit of all of the current credit cards owned by the affected people.
Further to that, the govt, which seems to have absolutely no take on such issues, needs to get off its lazy behind and do something meaningful, like legislating strong penalties for careless and negligent organizations.
I've repeated such thoughts ad nauseam and probably will continue to do so until such events become a thing of the past. At the rate things are going vis-a-vis data theft, it's going to be a VERY long time before we can stop worrying about such horrible incidents of violation of our trust and safety.
Be safe!
http://explore.georgetown.edu/news/?ID=31245
Apparently a sensitive hard disk was stolen - with the disk containing UNENCRYPTED information (SS numbers, names etc) of many thousands of students and faculty. I cannot imagine how such a prestigious institution could let such a thing happen.
Does security begin and stop with/at the ethernet cable?!!
Physical security is as important as network/digital security. For anyone to minimize the value or importance of one over the other is beyond ludicrous. GU is offering to pay for one year's worth of credit monitoring, but what about after that? The govt should mandate a MINIMUM of 5 years' worth of credit monitoring for each such incident, plus total insurance covering at least 5 times the total of the existing credit limit of all of the current credit cards owned by the affected people.
Further to that, the govt, which seems to have absolutely no take on such issues, needs to get off its lazy behind and do something meaningful, like legislating strong penalties for careless and negligent organizations.
I've repeated such thoughts ad nauseam and probably will continue to do so until such events become a thing of the past. At the rate things are going vis-a-vis data theft, it's going to be a VERY long time before we can stop worrying about such horrible incidents of violation of our trust and safety.
Be safe!
Labels:
data breach,
data encryption,
data safety,
data theft,
Georgetown,
GU,
id theft
Saturday, November 24, 2007
Why Deja Vu May Not be a Good Thing
...in the case of Britain's worst security breach ever -- the loss of 2 CDs containing details of nearly every child in the UK and the bank details of every family.
Somehow it seems astoundingly asinine that a junior-level official would be first permitted charge of this information and then scapegoated when something went wrong. Well, not much of a new thing there, but the really sad part is that a report had warned the govt of improper protocols and the implications of not following proper rules just a few months ago.
You can read about the shamefulness of it here: http://www.telegraph.co.uk/news/main.jhtml?xml=/news/2007/11/25/ncustoms425.xml
Why am I not surprised that most of the core recommendations are completely based on common sense, and that they are not that difficult to follow? I myself have repeated myself a few times on this blog concerning the same security steps to be taken to protect sensitive information.
How does one combat such breaches? How does one prevent occurrences of such mishaps? Unless those that are involved learn a very harsh lesson it's going to be difficult to expect much by the way of data protection. The other thing is for the masses to wake up to what is essentially the pillaging of the bits and bytes that constitute their lives, and do something about it. Quickly. Very quickly.
You can refer to my previous posts for my thoughts on this disturbingly frequent issue.
Be safe!
Somehow it seems astoundingly asinine that a junior-level official would be first permitted charge of this information and then scapegoated when something went wrong. Well, not much of a new thing there, but the really sad part is that a report had warned the govt of improper protocols and the implications of not following proper rules just a few months ago.
You can read about the shamefulness of it here: http://www.telegraph.co.uk/news/main.jhtml?xml=/news/2007/11/25/ncustoms425.xml
Why am I not surprised that most of the core recommendations are completely based on common sense, and that they are not that difficult to follow? I myself have repeated myself a few times on this blog concerning the same security steps to be taken to protect sensitive information.
How does one combat such breaches? How does one prevent occurrences of such mishaps? Unless those that are involved learn a very harsh lesson it's going to be difficult to expect much by the way of data protection. The other thing is for the masses to wake up to what is essentially the pillaging of the bits and bytes that constitute their lives, and do something about it. Quickly. Very quickly.
You can refer to my previous posts for my thoughts on this disturbingly frequent issue.
Be safe!
Labels:
data encryption,
data protection,
data safety,
data theft,
UK data breach,
Walport
Subscribe to:
Posts (Atom)