Tuesday, January 22, 2008
Iron Mountain Not So Invincible After All...
Hardly a month goes by without mention of at least one MAJOR breach (and who knows how many of these go unreported), so the important thing here is for the general public not to get jaded and let these things slide. The right thing to do for the various consumer groups is to get together and form a united front in pushing the govt to pass STRONG and EFFECTIVE consumer protection laws.
Yes, GE Money will offer a year's worth of ID monitoring for those that had their SS lost, but who's to say what'll happen after 1 year? SS numbers are permanent unless you have a VERY good reason to request a new one (Witness Protection Program, shelter from an abusive spouse etc), so how does one escape this?
The cleanest way to protect your id is not to apply for credit cards (just have a max of 2 for convenience and an emergency backup) and pay CASH everywhere. No wonder they say cash is king! Every year check out your credit report for free from each of the reporting agencies and spread it around so that you do it every 4 months (e.g. first from Equifax, second from TransUnion, and third from Experian). That way you have the entire year covered and can check for incosistencies and errors - and any fraudulent activities as well.
You'd think companies that store information for others would have a process in place to avoid just these kinds of incidents. That they'd have a tracking mechanism to identify the 'chain of trust' or the breadcrumb trail of what went where and why. I'm quite surprised that a tape (not a tiny floppy, you know) could just VANISH with nobody having any idea of where it may have gone.
To their credit, they do handle millions of items, so things may get 'lost' every now and then, but that again raises the question - that's precisely why customers invest in such methods for backing up and storing their critical data - that why should a company spend so much money on a backup solution that could go wrong? I guess one of the criteria in selecting a backup vendor would be to look at their processes (and audit them via third-party if the contract allows - or just make it a requirement) to see how it compares with other companies, and maybe their record as well.
Be safe!
Wednesday, January 2, 2008
Friday, December 7, 2007
Why I Won't Join Facebook
How did they figure this out? Well, simple - network monitoring via WireShark (I saw it on the blog of the original CA researcher that found this activity).
The idea behind Beacon was to send out info on your online habits to your friends on the site. However, soon people started complaining that the surprise element behind their surprise gifts were ruined because the intended recipient got to know of the purchase. Well, that's fine, and you can turn it off, but not even when you're logged off?? Whoa - that's serious breach of trust in my opinion.
As a reference, see this:
http://www.cio-today.com/story.xhtml?story_id=010000ZKE6WS
So, they track non-users as well - except that they will discard the data if it did not include an FB cookie saying it's an FB user - and then even if you were an FB user and even if you'd opted out of the 44 websites that work with FB, your info will STILL be sent except they won't process it (because you'd opted out). I don't think this is a good idea. Doesn't matter if you throw away the information or not: if I'm not an FB user you have NO RIGHT to my data. And who's to say the data is being REALLY thrown out? Who audits that?
You should know that you have to opt out ONE BY ONE - not all of the sites simultaneously. Couldn't be more painful than that. And considering how popular the site is, what if hundreds of companies choose to join the program. You'd have to constantly change your preferences to avoid opting in. It should be the reverse - unless you chose to opt in, nothing about you should be known to anyone.
This is why they are in very serious need of a customer privacy advocate, someone who can dispassionately identify such issues and guide the misguided person that chose to implement it so that people don't start abandoning the site or decide against joining it.
I'm quite sure that many people have decided not to join FB after this fiasco. I know I won't.
Be safe!
Wednesday, November 28, 2007
Don't Go Looking for Trouble...
I thought it was a minimal but visually arresting article - enough information to make sure you don't stumble into the dark areas of the web - or at least know what to look for.
By seeding all sorts of sites (blogs/trackbacks/comments) with their infernal site links they try to fool search engines into listing their URL at the top, or at least at the middle of the search results. Unwary users will no doubt not bother to CHECK the URL before clicking it, and what happens next should not be surprising: a whole lot of popups for installing malware/rootkits/password stealers, and of course, the maddening ads.
Here's my suggestion:
When you search for anything, first make sure you check the URL to see if it's a nonsensical mix of meaningless words. If yes then stay away.
You could also try searching your favorite sites first (such as GPSPassion/Poi-Factory for GPS stuff; ExpertsExchange for technical questions; dpreview for camera questions etc). You get the idea.
Be safe!
Saturday, November 24, 2007
Why Deja Vu May Not be a Good Thing
Somehow it seems astoundingly asinine that a junior-level official would be first permitted charge of this information and then scapegoated when something went wrong. Well, not much of a new thing there, but the really sad part is that a report had warned the govt of improper protocols and the implications of not following proper rules just a few months ago.
You can read about the shamefulness of it here: http://www.telegraph.co.uk/news/main.jhtml?xml=/news/2007/11/25/ncustoms425.xml
Why am I not surprised that most of the core recommendations are completely based on common sense, and that they are not that difficult to follow? I myself have repeated myself a few times on this blog concerning the same security steps to be taken to protect sensitive information.
How does one combat such breaches? How does one prevent occurrences of such mishaps? Unless those that are involved learn a very harsh lesson it's going to be difficult to expect much by the way of data protection. The other thing is for the masses to wake up to what is essentially the pillaging of the bits and bytes that constitute their lives, and do something about it. Quickly. Very quickly.
You can refer to my previous posts for my thoughts on this disturbingly frequent issue.
Be safe!
Saturday, November 17, 2007
Two Articles to Read on Data Breach
and then
http://ap.google.com/article/ALeqM5gqGfy6HNMsTyAGUesRe43dQCGsDgD8SV20PO2
And you'll get an idea of how much money is at stake for institutions and companies that deal in (and store) personal data, especially sensitive data.
Be safe!
Monday, November 12, 2007
TOR!
In a somewhat scary 4-page article ( http://www.theage.com.au/news/security/the-hack-of-the-year/2007/11/12/1194766589522.html) the author describes how easy, VERY EASY, it is to monitor sensitive, so-called anonymous electronic conversations that were previously thought to be on secure ground - traveling over the "TOR" network.
The use of TOR(http://www.torproject.org), an open source project, helps mask the origins of a user that wants to surf or send/receive data anonymously. However, the most obvious vulnerability of this software, that the endpoint (exit node) of the traffic can be monitored and plaintext, unencrypted data can be easily captured - was/is not very well understood by users.
The only solution is to use SSL (HTTPS) or end-end authentication and encryption (use GPG etc).
Who uses TOR? Lots of people: (apparently) the intelligence community, human rights activists in nations with a less-than-impressive human rights credentials, embassy employees, those that hold sensitive jobs, and, of course, people that want to see (ahem!) objectionable content while hiding behind mangled ones and zeroes.
Further, more than half the people that use it have is misconfigured, which can lead to some undesirable results. In any case, the point is that any software is only as good as its end-user understanding of it.
It's not the fault of the software that users/promoters allegedly overestimated its value (esp in terms of anonymity) - as the article says.I looked at TOR out of curiosity back in 2004/5, and found it incredibly slow, so I lost interest. But I do remember thinking this could be a pretty interesting tool for those that want the claws of the Web away from their private data.
Be safe!