Thursday, February 12, 2009
Blog Review: The rise of identity theft
So what exactly is identity theft? It is a crime used to refer to fraud that involves someone pretending to be someone else in order to steal money or get other benefits. It is a relatively new term, since its not inherently possible to steal an identity, only to use it. The person whose identity is used can suffer various consequences when he or she is held responsible of the perpetrator's actions.
How do they take your identity? It is very easy because all they need is your social security number, your birth date, and other identifying information such as your address and phone number and whatever else they can find about you. These information can be easily found from your place of work, school or your doctor.
It is very dangerous if those information falls on the hand of others because it can be used to facilitate crimes including illegal immigration, terrorism and espionage. Identity theft may also be a means of blackmail. There are also cases of identity cloning to attack payment systems, including online credit card processing and medical insurance.
Therefore, in many countries, specific laws make it a crime to use another person identity for personal gain.
Wednesday, February 11, 2009
The threat of online security
As Internet users display more of their personal information on social networking websites, computer hackers are employing increasingly sophisticated methods to pry that information loose. In many cases, they're devising small attacks that can fly under the radar of traditional security software, while exploiting the trust users place in popular business and consumer websites.
For consumers, its not just their profiles on social network that can be mined for personal information. Sophisticated smartphones that run full-fledged operating systems and e-mail applications, and hence store more reliable data, could present tempting targets.
Security researchers have found numerous ways to break into prominent mobile phone platforms from Symbian and Microsoft and quickly demonstrated ways to break into Apple's new iPhone.
In the corporate world, criminals are hunting for more of the valuable info stored on companies server. Cyberthieves are also attacking corporate databases in search of undiscloses financial data or proprietary design and engineering information that can be sold in return for a large sum of money.
Phishing
Phishing is a method thieves used to get personal information from user in order to steal user identity and then user money or benefits-like bank account numbers, credit card numbers, passwords, passport numbers, etc. into forms on Web sites that are designed to resemble the bank, credit card, or other company who they are claiming to be. Phishing can be carried out in person or over the phone, and are delivered online through spam e-mail or pop-up windows. The e-mail messages, pop-up windows, and the Web sites they link to appear official enough that they deceive many people into believing that they are legitimate.
Example of a phishing e-mail message, (bank)
.png)
Misspelled Web addresses: When a Web site uses an Internet address (also called a "domain name" or "URL") that is similar to the Internet address of a popular Web site or is a common misspelling of popular Web site that could signify a phishing scam.
.png)
Methods avoid Phishing Attacks
1.Make sure your computer is updated and scanned regularly
(as scheduled or manually) with a corporate grade computer security suite.
2.Do not trust any e-mail that urgently requests personal information of any kind.
3. Phishing attacks often ask for personal financial information. Never fill out personal
information of any kind including passwords, usernames, social security numbers, credit card
numbers, and the like through a form on the Internet. A request of this kind should be a big
warning. Legitimate organizations generally do not ask you to verify username, password
except for an initial set up once in a while.
4.Always report suspicious activity to the business or organization being spoofed.
5.Update your anti-virus software frequently. Common anti-virus software includes McAfee and Norton.
6.Change your password every 60 days.
7. If you have any doubts about the authenticity of an email, do not respond; call the sender or
type in the web address.
8.Type addresses directly into your browser or use your personal bookmarks or favorites. If you need to update your account information or change your password for a site, visit the site by
choosing the bookmarked link from your Favorites list or by typing the URL directly into your
browser.
9. Don’t enter personal or financial information into pop-up windows. One phishing technique
launches a fake pop-up window when you click a link in a phishing e-mail message. Even if the
pop-up window looks official or claims to be secure, avoid entering sensitive information,
because there is no way to confirm that it is secure.
How to safeguard our personal and financial data?
1. Choose user name and password wisely.
You have to choose the user name and password that you are easily to remember but don't want it to be something that a clever thief could figure out just by learning your birth date or IC number.
2.Review your transactions, accounts, or statements and keep the history.
You have to review the transactions or your accounts once you had been notified to the website immediately of any unauthorized activity. Besides, you have to keep the history of any transactions made such as the confirmation e-mail, bills, as long as direct mail.
3.Ever reveal your personal information or password or your Social Security number to anyone.
Always remember to log out properly before you leaving the Financial Data Center and must to store your credit card in a safety place and don't simply give anyone know the number of even your signature.
4.Protect your computer's security.
To safeguard your personal information and financial data as safe as possible, you might use as many as possible the ways that can help you to secure your computer's security. Install an antivirus software, anti-spyware, firewall, or even set a password to protect your data when starting the computer. Always to bear in mind, falling to protect your computer is just as similar as unlocked your door after leaving your home.
5.Protect your personal information or password by using technologies.
To level up your security state of your personal and financial data, you are advising to use technologies to safeguard your data and password. For example, designate and implement a safeguards program that includes regular compliance monitoring and evaluation. Besides that you also can use a variety of public key infrastructure (PKI) that which is represent a conner stone for secure e-payments. For example, you can use encryption which is a process of converting readable data into unreadable characters to prevent unauthorized access to secure your data.