Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 2 February 2010

Fact, Fiction and the Internet

Posted on 11:42 by Unknown

By David Harley BA CISSP FBCS CITP, Director of Malware Intelligence, ESET

In their simplest form, many social networking sites are not much more than online diaries. Whether you’re thinking of Bridget Jones or Adrian Mole, Alan Clark or Samuel Pepys, most of us realize that a diary is just someone’s personal view, and not a reliable source of indisputable information. Most of us except for financial institutions, that is, or so it appears.

In a recent blog post, security expert Roger Thompson related how an authentication check by his credit card company resulted in their asking him a question to verify his identity, using information publicly available. (As opposed to, or in addition to, the use of the sort of information we share with such institutions as “secret questions”, for instance.) The required answer in this case concerned the age of Roger’s daughter-in-law, to whom they referred to by her maiden name. The only public resource that Roger could think of that would connect the two of them is Facebook, though other commentators have pointed out that genealogy sites are used in identity checks too.

For a while now, some security researchers have advised people to be economical with the truth when using chatrooms, forums and social networking sites. Why would you give your true date of birth to a site that doesn’t need to know it, and can’t be trusted to keep it private? Is it a good idea to let all your facebook friends know you’re on holiday next week when you may not have met them all personally and can’t be sure how much of your information is available to their friends? If you must use your dog’s name as a password (you really shouldn’t be using names for passwords), talking about Fido on Facebook gives a determined attacker a good start along the password guessing route. How much easier is it to harvest information about a target when their place of birth or current home town is public knowledge?

In the security industry, we talk a lot about the dangers of social networking and sharing information that may be valuable to burglars and scammers, or even spies (if you happen to be married to the head of MI some-number-or-other). But it isn’t just about what you do, or information that you give away. Other people can give away information that impacts on you, like that photo of you next to Niagara Falls that your mate posts to his Facebook page, giving clear notice that you aren’t at home right now.

This latest revelation about how information posted to websites is being used (or misused) suggests a potential scenario where false information might actually be seen as more valid than true information, simply because it’s “publicly available” and your bank assumes that you – or someone within your social network – will never lie to a social networking site.

There is probably more misinformation than information in the online world, whether it’s deliberate deception, propaganda, fraud, well-meaning lack of comprehension, or just data that are no longer current. So any instance of an organization relying on the accuracy of data from a wider (more public) range of resources raises concerns about inaccuracy and perhaps even the deliberate poisoning of data. How can individuals keep track of and validate everything that is "known" about them when presumed-valid information is pulled from who knows where? More so, if the organization pulls that information long after it has supposedly already validated you as a customer.

While a bad guy who has access to all the information that a bank has may not need to change it in order to profit from it, there are several scenarios where he might want to. This might include hampering remediation; influencing the presentation of data he can write to even when he can't read it (a more common situation than one might think); and compromising public data as part of a social engineering attack. Not to mention where the objective is to actually block legitimate access to information as well as or instead of impersonation.

Regulation of data is nowhere near keeping up with the Internet age, and some of our legalist assumptions were outdated in the 19th century. The possibility of an organisation using one customer to validate (or invalidate) another poses more awkward ethical and practical issues than most of us have thought of. It might benefit us all to think for a moment about the long-term impact that our next Facebook update or tweet may have on ourselves or our friends, before we put fingers to keyboard or keypad...

ESET is exhibiting at Infosecurity Europe 2010, the No. 1 industry event in Europe held on 27th – 29th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk

Courtesy of Infosecurity PR

<>

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin unveils new functionality & updated PCI DSS 2.0 compliance reporting
    TUFIN TECHNOLOGIES UNVEILS enhanced firewall operations management functionality and UPDATEd pci dss 2.0 compliance reporting New Perm...
  • Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event
    Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this co...
  • Safer Internet Day - The role of Security within Social Networks
    Amichai Shulman – CTO and co-founder of Imperva Last week researchers unveiled a “ dating database ” consisting of 250,000 users. This was...
  • ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking
    ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking 20-23 March 2011, Manchester, UK Rolling Meadows, IL,...
  • Experts warn about risks of multi-tasking on new iPhone 4.0 OS
    Fortify Software warns companies to beware multi-tasking aspects of new iPhone 4.0 operating system Following a rash of news reports about...
  • Experts says trashed hard drive fiasco at Pfizer could have been avoided with Encryption
    Credant says trashed hard drive at Pfizer would not have happened if data had been encrypted Credant Technologies says that a security gaffe...
  • IT services provider, FORT, brings AVG to Irish market
    by Michael Smith (Veshengro) ISP customers to benefit from complete Internet security solution London, UK – AVG, the world’s most downloaded...
  • Lieberman Software and Q1 Labs Partner to stop insider threats
    Joins Q1 Labs Security Intelligence Partner Program London – February 1, 2011 Organisations seeking to eliminate the potential for anony...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ▼  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ▼  February (27)
      • ISAF raising awareness of the main threats to onli...
      • Goldman Sachs indictment highlights need for secur...
      • Malware in Current Cybercrime and the Grey zone
      • Novatel MiFi makes its debut in Thailand
      • Launchpad Europe Launches "API" to Encourage Sprea...
      • Common Assurance Metric – Beyond the Cloud
      • Securing the Smart Grid: The Road Ahead
      • Cloud computing creates a new legal ballgame
      • How Important is the Role of Testing?
      • Who can you trust?
      • Four stolen laptops highlights need for multiple l...
      • Imperva’s SecureSphere 7.5 Bolsters Protection aga...
      • Value of stolen credentials determined by Internet...
      • Novatel Wireless Announces First Successful 4G LTE...
      • Lancashire Constabulary Chooses 3ami MAS for Prote...
      • Two Thirds of Internet Users Expose their Online B...
      • 360°IT Welcomes Renowned CIO to Management Team
      • Major European retail bank adopts DeviceLock to pr...
      • UK Security Breach Investigations Report 2010 Publ...
      • Data Privacy Day report highlights need for encryp...
      • Rise in data breaches drives growth for Imperva
      • It Can Happen So Easily
      • British Tories aim for 100 Mbps broadband by 2017
      • Top 10 Reasons the Firewall Guy's Hair is on Fire
      • BridgeHead Software gives thumbs up to Sun/Oracle ...
      • Fact, Fiction and the Internet
      • HMRC tax return phishing twice as likely to defrau...
    • ►  January (27)
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile