Σάββατο 12 Δεκεμβρίου 2015

Merry Riskmas


People of all ages look forward to Christmas holidays. Children think of the gifts they will receive from Santa, and those of us who are older savor the thought of spending the holidays in joyous company with friends and family. Christmas is considered by most, including myself, as the most wonderful time of year.

Cyber criminals feel the same way about the holidays. They exploit online shoppers’ longing for a good sale by slamming them with phishing scams laden with "special offers" and try to turn our beautiful Christmas to Riskmas.

We have talked about this subject in the past but constant repetition carries conviction.

The holiday season is retailers’ busiest time of year, with an estimated 20% of the year’s shopping taking place between November and December in the UK and over half of online retailers expecting to achieve 20% growth. During this time, retailers arguably face a more difficult problem with IT than other industries for many reasons. The holiday retail "freeze" is underway, which means that any security upgrades or technology additions for retailers are put on hold until after the busy holiday shopping season. For the next few weeks, only critical security patches will get installed. The concept of a holiday IT freeze is outdated in today’s world, and while many retailers implement such a "freeze", there should be exceptions when it comes to areas that support the business. Security should certainly be one of those exceptions.

The main challenge and priority is service availability to the customers, whether it is for online or in-store purchases. At executive level, service availability translates to transactions, which in turn relates to revenue growth. However, executives often neglect the wider collateral damage that can be caused by a data breach, not only in terms of brand damage but also in the resultant fall of consumer confidence and any remediation activities required (legal and operational) to mitigate those losses.

In December 2009, a hacker, then operating under the alias of “igigi,” succeeded in stealing the account credentials for all 32.6 million users after successfully penetrated RockYou, a company which develops games and advertisements for social media sites. All of the information had been stored in clear text, meaning that neither account holders’ usernames nor passwords had been encrypted. Company’s databases were infiltrated as a result of an SQL injection vulnerability, one of the most common security vulnerabilities with respect to web applications today.

Following the breach, the security firm Imperva analyzed the stolen information, portions of which were published online by the hacker. The study revealed that 40% of account holders had used a password consisting only of lowercase letters, 30% had chosen a password less than six characters in length, and nearly 1 in 100 had set their password to "123456".

Nevertheless, companies are not the sole targets of holiday breaches. The amount of unwanted traffic increases significantly before Christmas, and people need to be wary of viruses and other malware. Christmas, like other holidays, is a time of opportunity for junk mailers and information phishers. An ill-advised click can ruin your holiday, when an electronic Christmas card from a friend or business partner installs malware on your computer. People are in holiday spirits and behave more casually in the online environment. For example Christmas greetings sent by email can be disguised so that they look like they have been sent by someone you know. When the unsuspecting recipient opens a picture or link contained in the message, a virus is released.

Back in 2010, just two days before Christmas, attackers sent out an email that spoofed “seasons greetings” from The White House to a number of government employees and contractors. The text of the email was published on Brian Krebs’ website. It read:
“As you and your families gather to celebrate the holidays, we wanted to take a moment to send you our greetings. Be sure that we’re profoundly grateful for your dedication to duty and wish you inspiration and success in fulfillment of our core mission.”
The card then prompted users to click on a link, which downloaded a variant of ZeuS malware.

A control server allegedly based in Belarus manually sent out the email to a small number of recipients, which made the attack undetectable by security traps and sensors. Ultimately, more than 2GB of government documents were stolen in the attack. However, no classified documents were compromised.

On December 2013, Symantec reported a spike in the number of NTP amplification attacks. NTP stands for Network Time Protocol. It was originally developed by a professor at the University of Delaware as a means syncing the clocks of multiple computers.

According to Symantec’s blog post on the topic, NTP attacks are similar to DNS amplification attacks in that they use a small packet to request the delivery of a large amount of data to a specific IP address. In this case, the attackers used the monlist command, a query found in older versions of NTP that sends requesters a list of the last 600 hosts who connected to the server, as part of a series of DDoS attacks against certain targets, including a number of gaming sites in late December. The evolution of NTP amplification attacks in part reflects the Internet’s development thus far.

To sum up, here are some additional tips you can use to avoid becoming a victim of cyber fraud: 
  • Enable 2-factor authentication in all your accounts. You can find a list of services that support this here.
  • Do not respond to unsolicited (spam) e-mail.
  • Do not click on links contained within an unsolicited e-mail. Ask yourself: "Why am I being asked to click here?" If you’re not sure, don’t click!
  • Be cautious of e-mail claiming to contain pictures in attached files; the files may contain viruses. Only open attachments from known senders. Scan the attachments for viruses if possible. Ask yourself: "Does this look authentic?"
  • Avoid filling out forms contained in e-mail messages that ask for personal information.
  • Always compare the link in the e-mail to the link you are actually directed to and determine if they match and will lead you to a legitimate site.
  • Log on directly to the official website for the business identified in the e-mail instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.
  • Contact the actual business that supposedly sent the e-mail to verify that the e-mail is genuine.
  • If you are requested to act quickly or there is an emergency that requires your attention, it may be a scam. Fraudsters create a sense of urgency to get you to act quickly.
  • Remember if it looks too good to be true, it probably is not.
For organisations: 
  • Ensure your staff are educated ahead of the Christmas period. Phishing presents as much danger to businesses as it does individuals.
  • Get a penetration test now before the Christmas period to test the security of your networks and systems.
Have A Very Merry Christmas and Stay Safe Online!

Τετάρτη 1 Ιουλίου 2015

Cyber Safety Tips for Summer Vacation


Haven't taken your summer vacation yet? You should make sure that you enjoy your vacation to the fullest by avoiding the stress of dealing with identity theft.

Last Day in the Office
When you will be away from work for an extended period, make sure your computer, external drives and other copies of sensitive information are behind a locked door, in a locked cabinet, or under close supervision from others. Before traveling with your computer, make sure you have a current backup of your files.

Be Cautious of Public WiFi Networks
When you connect to email, social networking sites or online stores via public WiFi, make sure you are using a secure connection (https://), so that traffic is encrypted and no one else can access the information. Always check with the hotel first to properly connect to their network and correct SSiD (bad guys might try to setup sneaky networks like “Hotel_Free_Wireless”). Perhaps you should consider turning off features on your computer or mobile devices that allow you to automatically connect to WiFi.

Save the (Public) Social Media Vacation Posts Until You Get Back Home
It may be tempting to post details of where and when you'll be traveling, but don't. By revealing such specifics, you are providing information that could be used by criminals to target your home while you're gone. Before you post your travel plans or vacation photos on Facebook or Twitter, stop and think: ‘who will be able to see this?’. Another common scam involves compromising email accounts to contact your friends or family with requests for help, claiming that you were robbed while on vacation and need money. Sending private posts and photos during your vacation to family and friends is ok, but if you post them publicly, you increase the risk of someone using that information for malicious activities. Also, make sure your children understand what, and when, they should post regarding your vacation plans.

Mobile Devices
If you are traveling with a laptop computer or USB drives, don't get separated from your computer bag. When getting out of a taxi, bus or train; be sure you have all of your items with you. Back up any important data before traveling, also make sure to have your smartphones and tablets locked with a security code/PIN to protect if stolen. Most devices allow you to activate the GPS tracking option to locate the device if stolen. If your device goes missing, report it immediately to the police and your service carrier. If the thief might have access to your banking, email and other accounts, change your passwords immediately.

Monitor Account Activity
Prior to your trip, write down important contact numbers such as credit card, banking and your cell phone customer service so you can quickly report any lost or stolen items. When you return from your trip, use a secure network to check your online bank account for any unauthorized purchases while you were gone.

Have a great and safe summer!

Τετάρτη 25 Μαρτίου 2015

Setup an Information Security Awareness Program


Protecting corporate data should be part of any organization-wide information security awareness program. The security awareness program should be delivered in a way that fits the overall culture of the organization and has the most impact to personnel. Security awareness should be conducted as an on-going program to ensure that training and knowledge is not just delivered as an annual activity, rather it is used to maintain a high level of security awareness on a daily basis. Ensuring staff is aware of the importance of data security is important to the success of a security awareness program and will assist in meeting various standards’ requirements.

The first step in the development of a formal security awareness program is assembling a security awareness team. This team is responsible for the development, delivery, and maintenance of the security awareness program. The size and membership of the security awareness team will depend on the specific needs of each organization and its culture.

Security awareness may be delivered in many ways, including formal training, computer-based training, e-mails, memos, notices, bulletins, posters, etc. It is important to target cyber security awareness notifications to the appropriate audience to ensure the information is read and understood. By disseminating security awareness training via multiple communication channels, the organization ensures that employees are exposed to the same information multiple times in different ways. By targeting the material and communication channel to relevant personnel, the security awareness team can improve adoption of the security awareness program. One key to an effective security awareness program is in targeting the delivery of relevant material to the appropriate audience in a timely and efficient manner.

Role-based security awareness provides organizations a reference for training personnel at the appropriate levels based on their job functions. Establishing a minimum awareness level for all personnel (management and employees) can be the base of the security awareness program. The first task when scoping a role-based security awareness program is to group individuals according to their job functions within the organization. Having a team in place will help ensure the success of the security awareness program through assignment of responsibility for the program. A solid awareness program will help all personnel to recognize threats, see security as beneficial enough to make it a habit at work and at home, and feel comfortable reporting potential security issues.

Management leadership and support for the security awareness program is crucial to its successful adoption by staff. Managers are encouraged to:

  • Encourage personnel to actively participate and uphold the security awareness principles.
  • Model the appropriate security awareness approach to reinforce the learning obtained from the program.
  • Include security awareness metrics into management and staff performance reviews.

As stated above, it is recommended that training content be determined based on the role and the organization’s culture. The security awareness team may wish to coordinate with the appropriate business units to classify each role in order to determine the level of security awareness training required for those specific job duties. This is vital in development of content, to avoid “over-trainning” or “under-trainning” an employee. In addition to general security awareness training, it is recommended personnel be exposed to general concepts of data security, to promote proper data handling throughout the organization, according to their role in the organization.

Training materials should be available for all areas of the organization, such as the corporate intranet. Choosing which materials to use in a security awareness training program is highly dependent on the organization. Each organization should consider its culture when selecting the materials to use for the security awareness training. The following are examples of reference materials that may help in the development of a Security Awareness Program:

  • National Institute of Standards and Technology (NIST) Special Publication 800-50, Building an Information Technology Security Awareness and Training Program, www.nist.gov
  • International Standards Organization (ISO) 27002:2013, Information technology -- Security techniques -- Code of practice for information security controls, www.iso.org
  • International Standards Organization (ISO) 27001:2013, Information technology — Security techniques — Information security management systems, www.iso.org
  • COBIT 5 Appendix F.2, Detailed Guidance: Services, Infrastructure and Applications Enabler, Security Awareness, www.isaca.org/cobit
Additionally, due to the increased focus on cyber security awareness, many government agencies and industry bodies provide training materials to the public at no cost.

To ensure all personnel are engaged stakeholders in the security awareness program, the roles and responsibilities of all staff to protect corporate data should be outlined during all security awareness training, in accordance with organizational policy.
Because data is at risk both in electronic form and in non-electronic (paper) form, it is recommended that the different ways to safeguard information for different media be covered at a basic level for all personnel. For instance, considerations for protecting data in electronic format may include secure storage, transmission and disposal. Considerations for paper-based formats may also include secure storage and disposal as well as a “clear desk” policy. Without an understanding of how different media types need to be protected, personnel may inadvertently handle data in an insecure manner.
Another important consideration for inclusion in general security training is awareness of social engineering attacks. One way an attacker may use social engineering is to acquire a user’s credentials and work their way through the organization from a low-security area to a high security area. Tailoring this awareness to reflect the types of attacks that the organization may encounter provides the most effective results. Users should be aware of the common methods by which fraudsters, hackers or other malicious individuals might try to obtain credentials, payment card data, and other sensitive data, to minimize the risk of personnel unintentionally disseminating sensitive information to outsiders. Training in organizational policies and procedures that specify proper data handling, including sharing and transmission of sensitive data, is also recommended.
Feedback on training content and comprehension are key to ensuring personnel understand the content and the organization’s security policies.
In addition to content for all personnel, management training should include more detailed information regarding the consequences of a breach to management stakeholders. Management should understand not only the monetary penalties of failing to safeguard assets, but also the lasting harm to the organization due to reputational (brand) damage.
As previously discussed, management will need to understand security requirements enough to discuss and reinforce them, and encourage personnel to follow the requirements. It is recommended that management security awareness training include specific content relevant to the area of responsibility, particularly areas with access to sensitive data.
Management that is security-aware better understands the risk factors to the organization’s information. This knowledge helps them make well-informed decisions related to business operations. Managers who are security-aware can also assist with development of data security policies, secure procedures, and security awareness training.

Metrics can be an effective tool to measure the success of a security awareness program, and can also provide valuable information to keep the security awareness program up-to-date and effective. The particular metrics used to measure the success of a security awareness program will vary for each organization based on considerations such as size, industry, and type of training.

Δευτέρα 26 Ιανουαρίου 2015

Privacy on the Web


1. Use Common Sense
This is pretty self-explanatory: don't go to places on the web that you would be embarrassed to have your wife, husband, children, or employer see. This is a very low-tech way to protect your Web privacy, and yet, out of all the methods on this list, might be the one that is most effective.

2.  Guard Your Private Information 
Before sharing anything online - on a blog, website, message board, or social networking site - be sure it's not something you would mind sharing in real life, off the web. Do not share information that could identify you in public, especially if you are a minor. Keep identifying details, like user names, passwords, first and last names, addresses, and phone numbers, to yourself. Your email address should be kept as private as possible, because an email address can be used to track other identifying information. There is a useful service called Paranoid Paul to track major sites for updates in their privacy policy.

3.  Log Out Of Search Engines 
Most search engines these days require you to create an account and log in to access the full array of their services, including search results. In order to best protect your privacy, it's always a good idea to log out of your account after executing your Web searches. In addition, many browsers and search engines have an auto-complete feature that suggests endings for whatever word you might be typing in. This is a very convenient feature, however, if you're looking for privacy it's something you'll want to get rid of.

4.  Watch Your Downloads 
Be extremely cautious when downloading anything (software, books, music, videos, etc.) from the web. This is a good idea for privacy advocates, but it is also a great way to keep your computer from freezing up and malfunctioning. Be very cautious when choosing what to download from the Web; some programs include adware that will report your surfing habits back to a third-party company that will then use that information to send you ads and unwanted emails, otherwise known as spam.

5.  Avoid Unnecessary Forms 
A good Web safety rule of thumb is to avoid filling out forms that require personal information in order to keep anything from being entered into public, searchable record, aka Web results. You can use BugMeNot to avoid filling out unnecessary forms that ask for too much personal information.

6.  Clean Your Search History 
Most web browsers keep track of every single web site you type into the address bar. This web history should be periodically cleared out not only for privacy's sake, but also to keep your computer system running at top speed. In Internet Explorer, you can delete your search history by clicking on Tools, then Internet Options. In Firefox, all you need to do is go to Tools, then Options, then Privacy. You can also clear your Google searches very easily. A simple search will return numerous step-by-step tutorials.

7.  Use Caution When Using Social Media 
Social networking sites such as Facebook are extremely popular, and for good reason: they make it possible for people to connect with each other all over the world. It's important to make sure that your privacy settings are set appropriately and that what you share on social networking sites would not reveal anything of a personal or financial nature. For more on how to keep yourself safe on Facebook, try reading a post from AVG on the subject.

8.  Watch Out For Scams 
If it seems too good to be true, than it probably is - and this especially applies on the web. Emails promising free computers, links from friends that seem legit but lead to virus-laden websites, and all sorts of other web scams can make your online life quite unpleasant, not to mention add all sorts of nasty viruses to your computer system. Think carefully before following links, opening files, or watching videos sent to you by friends or organizations. Watch for signs that these might not be for real: these include misspellings, lack of secure encryption (no https in the URL), and improper grammar.

9.  Protect Your System 
Keeping your computer safe from harmful content on the web is simple with a few precautions, such as a firewall, appropriate updates to your existing software programs (this ensures that all security protocols are kept up to date), and antivirus programs. 

10.  Monitor Your Online Reputation 
Have you ever googled yourself? You might be surprised to see what is out there on the web. You can control much of what is out there on the web with the precautions laid out in this article, as well as keeping track of what is found about you in at least three different search engines on a regular basis (you can accomplish this process on auto-pilot using news alerts or RSS). 

Δευτέρα 29 Δεκεμβρίου 2014

The Seven Deadly Sins in an Information Security Context

Hieronymus Bosch-The Seven Deadly Sins,
created cr. 1500-1525,
www.museodelprado.es

The seven deadly sins (a.k.a cardinal sins) is a classification of vices as part of Christian ethics, used to educate and instruct believers since early christian times. In the film Seven (1995), two detectives, a rookie and a veteran, hunt a serial killer who uses the seven deadly sins as his modus operandi. In this post, I will try to map the original seven deadly sins in the context of Information Security.

Lust
Defined as an intense desire. Is the power that mostly drives the actions of the attackers. Desire for money, fame and power are the most common urges of the bad guys. Clearly a threat in Information Security context. Lust can be a powerful driver for illicit activities on the web and also a sin that cannot be easily suppressed. The lust to know was the impulse that lead the first hackers/crackers in the ‘80s and ‘90s to break into computer networks in order to satisfy this need.

Gluttony
Every day we are recipients of vast amounts of data. In our turn we contribute data for others to consume. Information addiction is a condition whereby the diagnosed is addicted to the hit of pleasure and stimulation from information. It has been referred to as "pseudo-attention deficit disorder" because it tends to cause somewhat ADD-like symptoms. This addiction usually begins with continuously using an Information streaming service, like Television, YouTube, Facebook, Twitter, etc, which gets the brain unaccustomed to idleness, always watching/reading/listening something. Then it spreads onto other Information retrieval activities.
This flooding of information leads to information overload, which refers to the difficulty a person can have understanding an issue and making decisions, that can be caused by the presence of too much information. In recent years, the term information overload, has evolved into phrases such as "information glut" and "data smog" (Shenk, 1997). What was once a term grounded in cognitive psychology has evolved into a rich metaphor used outside the world of academia. In many ways, the advent of information technology has increased the focus on information overload: information technology may be a primary reason for information overload due to its ability to produce more information more quickly and to disseminate this information to a wider audience than ever before (Evaristo, Adams, & Curley, 1995; Hiltz & Turoff, 1985).

Greed
Click here for some free stuff!. Did you click? You did it because greed is applied to a very excessive or rapacious desire and pursuit of material possessions. Faster download, free trips, opening an attachment from an unknown sender are all signs of greed. It is exactly that kind of behavior that cyber criminals want from you. You are classified as an easy victim for cyber scams, or as an information junkie (see gluttony above). Obviously a threat. Differs from lust, in a way that it is a passive sin that exists in the target side.

Sloth
Major target vulnerability. Derives from the fact that information security is something boring. Have you ever postponed to change your password and use the old one "just for this transaction"? When was the last time you pressed the "Remind me later" button when an update was available? Most infosec professionals, though fully aware of the risks, they do not follow a process because it takes too much time. All these are types of Information Security sloth. I would really love to learn a metric: Percent-of-accounts-changing-password after a successful data breach has gone public.

Wrath
Another threat, of the worst kind, the internal ones. Internal attacks are far more difficult to predict and prevent. These threats come from all parts of the company and no organization is immune to this. Wrath may be described as inordinate and uncontrolled feelings of hatred and anger. In its purest form, presents with self-destructiveness, violence, and hate. But there are more subtle facets of wrath and revenge. Think again before you fire your DBA because his last statement might be: DROP * COMMIT.

Envy
Now that was a tough one. Comes from Latin invidia and is defined as an emotion which "occurs when a person lacks another's superior quality, achievement, or possession and either desires it or wishes that the other lacked it". I could not match envidia into InfoSec context so I searched the net about it. And I found some interesting statements of C-level executives envying other companies about their security infrastructure, but when their own CISO comes and asks for some budget they whistle indifferently. I would classify it in the vulnerabilities, since it is part of the organization’s culture.

Pride
Often referenced as the deadliest of all sins. In information security pride is shown in various ways. "I have a very strong password...", "Our system is the most secure one...", "A hacker will never attack me...". Vain statements like these pose a grave danger for any individual or organization. Risk assessment professionals are commonly mocked for their risk scenarios, as they are considered “impossible to happen”. Pride rides side-by-side with vanity. The term vanity originates from the Latin word "vanitas" meaning emptiness, untruthfulness, futility, foolishness and empty pride. In this context empty pride means a fake pride, in the sense of vainglory, unjustified by one's own achievements and actions, but sought by pretense and appeals to superficial characteristics. Vanity comes into play during control performance evaluation. Eric Ries talks about vanity metrics a lot as part of "The Lean Startup":

Actionable metrics can lead to informed business decisions and subsequent action. These are in contrast to “vanity metrics” – measurements that give “the rosiest picture possible” but do not accurately reflect the key drivers of a business. Vanity metrics for one company may be actionable metrics for another. For example, a company specializing in creating web-based dashboards for financial markets might view the number of web page views per person as a vanity metric as their revenue is not based on number of page views. However, an online magazine with advertising would view web page views as a key metric as page views as directly correlated to revenue.
This is what we must have in mind when designing and evaluating controls to mitigate risk.

Conclusion: We are all sinners in a way. Amend for your sins before it is too late, a self atonement process can help us become more secure and more aware of the dangers that lurk in cyberspace.

Δευτέρα 24 Νοεμβρίου 2014

The Ghost of Christmas Yet to Come

Attention holiday shoppers, beware of cyber criminals who are out to steal money and personal information. Scammers use many techniques to defraud consumers, from phishing e-mails offering too good to be true deals on brand-name merchandise to offering quick cash to victims who will re-ship packages to additional destinations. Previously reported scams are still being executed today.

Consider these stats

  • During Christmas period of 2013, online spending was about £13 billion (over US$20 billion) according to Sage Pay.
  • In the UK 2013, 61% of people did at least half of all their Christmas shopping online. This is only set to increase.
  • On 2014, 95% of online shoppers will use companies’ click-and-collect services.
  • eBay expected 2,7 million Christmas-related searches in August. (yes August!!!)
  • Some e-commerce businesses achieve 80% of their total annual revenue during the Christmas period.
While monitoring credit reports on an annual basis and reviewing account statements each month is always a good idea, all of us should keep a particularly watchful eye on our personal credit information at this time of year. Scrutinizing credit card bills for any fraudulent activity can help to minimize any losses. Unrecognizable charges listed on a credit card statement are often the first time consumers realize their personally identifiable information has been stolen.

Bank transactions and correspondence from financial institutions should also be closely reviewed. Bank accounts can often serve as a target for criminals to initiate account takeovers or commit identity theft by creating new accounts in the victims’ name. Consumers should never click on a link embedded in an e-mail from their bank, but rather open a new webpage and manually enter the URL (web address), because phishing scams often start with phony e-mails that feature the bank’s name and logo.

When shopping online, make sure to use reputable sites. Often consumers are shown specials on the web, or even in e-mail offers, that look too good to be true. These sites are used to capture personally identifiable information, including credit card numbers, addresses and phone numbers to make fraudulent transactions. It’s best to shop on sites with which you are familiar and that have an established reputation as trusted online retailers.

If you look for an item or company name through a search engine site, scrutinize the results listed before going to a website. Do not automatically click on the first result, even if it looks identical or similar to the desired result. Many fraudsters go to extreme lengths to have their own website appear ahead of a legitimate company on popular search engines. Their website may be a mirrored version of a popular website, but with a slightly different URL.

Purchases made on these sites could result in one or more of the following consequences: never receiving the item, having your credit card details stolen, or downloading malware to your computer. Before clicking on a result in a search engine, inspect the URL of the destination website. Look for any misspellings or extra characters such as a period or comma as these are indicative of fraud. When taken to the payment page of a website, again verify the URL and ensure it is secure by starting with "https", not just "http".

Here are some additional tips you can use to avoid becoming a victim of cyber fraud:
  • Do not respond to unsolicited (spam) e-mail.
  • Do not click on links contained within an unsolicited e-mail. Ask yourself: "Why am I being asked to click here?" If you’re not sure, don’t click!
  • Be cautious of e-mail claiming to contain pictures in attached files; the files may contain viruses. Only open attachments from known senders. Scan the attachments for viruses if possible. Ask yourself: "Does this look authentic?"
  • Avoid filling out forms contained in e-mail messages that ask for personal information.
  • Always compare the link in the e-mail to the link you are actually directed to and determine if they match and will lead you to a legitimate site.
  • Log on directly to the official website for the business identified in the e-mail instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.
  • Contact the actual business that supposedly sent the e-mail to verify that the e-mail is genuine.
  • If you are requested to act quickly or there is an emergency that requires your attention, it may be a scam. Fraudsters create a sense of urgency to get you to act quickly.
  • Remember if it looks too good to be true, it probably is not.

For organisations:
  • Ensure your staff are educated ahead of the Christmas period. Phishing presents as much danger to businesses as it does individuals.
  • Get a penetration test now before the Christmas period to test the security of your networks and systems.

Κυριακή 16 Νοεμβρίου 2014

Smartphones, Tablets and Fraud

Consumers rely on their mobile devices on an ever-growing basis to keep them connected. Smartphones and tablets provide them with access to each other through email, messaging, and social media while also putting financial services and shopping in the palm of their hands. And each and every one of these activities holds value for criminals in search of account credentials and PII to sell or misuse. Unfortunately, for all of the potential that mobile devices represent, the apathy of every mobile stakeholder is undermining the security of mobile devices and the accounts of their users. Protecting Android, iOS, and Windows mobile device users from fraud will require a concerted effort by all stakeholders to eliminate vulnerabilities, encourage security-minded behaviors, and to leverage all the security benefits that mobile devices have to offer.
The study, conducted by Javelin Strategy & Research and sponsored by online authentication solutions firm Nok Nok Labs, polled more than 5.600 U.S. adults in 2013 to determine their mobile habits on Android, iOS and Windows devices.

Key Findings

Android, iOS, and Windows mobile users are undermining their security by reusing passwords more often than the average consumer. These mobile users are about 25% more likely than all consumers to use the same password to access more than one online account. This motivates criminals to target them and their devices to secure credentials with the expectation that they will facilitate access to a variety of the victim’s valuable accounts and services.
Heavy reliance on one-time passwords is placing Android users’ financial accounts at risk. 41% of Android users take advantage of one‐time passwords (OTPs) with their financial accounts. The prevalence of mobile malware for Android capable of intercepting OTPs sent by text (i.e., Short Message Service or SMS) is contributing to the rate of fraud these users experience. Mobile users prefer fingerprint authentication, which bodes well for Apple and Samsung. Fingerprint scanning is preferred by Android, iOS, and Windows mobile users among the prevailing biometric modalities. Recent moves by Apple and Samsung to expand fingerprint-based authentication is likely to be well received and will subsequently bolster the preference for this modality. One in five or fewer Android, iOS, or Windows mobile device users are truly protecting their data from a physical intrusion. While using a password, or better yet a fingerprint, to protect the lock screen can effectively deter some attempts to physically access a mobile device, more safeguards are needed to dissuade professional criminals. Unfortunately the use rates of remote wipe software and disk
Mobile users desperately want to protect their devices from vulnerabilities in outdated OSs, but updates are not always convenient or available. Updating the OS can be hampered by limited availability from carriers and manufacturers in the case of Android or because of how an update has the potential to undermine performance after installation in the case of iOS.
Android and iOS users face a significantly higher rate of fraud than the average consumer, but the reasons differ. Users in both camps display similarly poor password and security habits, which are contributing to their risk of being victimized. More specifically, it is mobile malware that is spurring the fraud experienced by Android users, while the attractiveness of iOS users’ income has placed them in the crosshairs of fraudsters.
Passwords are the typical first line of defense for online accounts, and in some cases they are the only means by which an account is secured from unauthorized access. Given the= breadth of available apps and services that mobile users have at their fingertips that require a password, it is unsurprising that convenience has taken a back seat to security. Mobile users have fallen into the “password trap,” reusing the same passwords for multiple sites and services. As a result, they are exposing their online accounts to a greater risk of compromise and eventual misuse.
Ultimately, the multitude of threats facing mobile devices and the habits of their users are conspiring to create an environment where fraud can flourish. Not every device owner experiences fraud at similar rates, though:
  • Among Windows mobile device users, 4.8% experienced identity fraud in 2013, which is 10% below the rate at which all consumers were victimized (5.4%).13 This can partially be attributed to the smaller share of the mobile device market they represent, which makes them less attractive targets, but could also be the result of other factors such as the use of non-SMS-based two-factor authentication common to Microsoft services, such as Outlook.
  • Android users face the most serious threat from malware and are placing their financial accounts at risk when relying on SMS-based OTPs for authentication, both of which contribute to a rate of identity fraud that is 31% higher than what all consumers experienced last year (7.1% vs. 5.4%, respectively).
  • Despite owning devices far less prone to malware infection than Android, 7.3% of iOS users experience identity fraud that is 36% higher than average (5.4%). This is because of their substantial market share, which makes them higher profile targets, the use of Apple services, which rely heavily on a single set of credentials, and users that have higher-than-average incomes, which make them more attractive to fraudsters.
For more details read the full Javelin report titled SMARTPHONES, TABLETS, AND FRAUD: When Apathy Meets Security