Sunday, August 2, 2009

This is the "Type" of Security That Will Empty Your Bank Account


Excerpts from the Economic Times

By the time you will read this, the new Reserve Bank of India(RBI) norms that enforce (in my opinion, a dangerous) third-factoridentification for all online credit/debit card transactions will bealready applicable. As a cardholder, you will no longer be able to makeonline purchases or payments if you haven’t registered yourself for anadditional security layer with your partner bank. 
TillFriday, all one needed to do to make an unauthorized transaction fromyour card was to steal three security details that included cardnumber, card expiry date and 3-digit or 4-digit card verification value(CVV) number...

...but ifyou think the new security system acts like a guarantee providing forcover against online frauds, then you are treading on wrong turf. 


Editor's Note: Because they are still  instructing you to "type!" your personal information into boxes in a browser.  How dangerous is that?  Well, besides keylogging, just click on the box on the left to enlarge and see what has happened to the state of the malware threat from Janaury to July.  Besides, it's clear from the paragraph below that the purpose of this "added layer of non-security" is to provide a false sense of one and to PIN the fraud liability on the consumer!
This is what bankers have to say on the subject:


1.   If the wrong password is entered as part of this extra authentication, the bank informs e-commerce merchant and if the merchant still goes ahead with the transaction, it becomes merchant’s liability

2.  
On the other hand, if the password is correct even if customer disputes the transaction, it is still a customer’s liability.”

(Hmmm...interesting.  It appears that from now on, fraud is now eitherthe merchants liability or the consumers.  Didn't see a scenario whereit was the banks, did you?
)  Stumped? To help you with all such concerns and questions, here’s a ready reckoner on what does the new security layer implies for you as a cardholder. Editor's Note: It's no accident they wrote: "Implies"... (vs. Provides)

“From the cardholders’ perspective, (Editor's Translation: "perception")another layer of protection gives a lot more comfort in terms ofsecurity for the online transactions using credit/debit cards . (reality: another layer of this type of non- protection simply provides another way for hackers to intercept financial data, whether it be via malware (see malware growth chart above right) keylogging, phishing, XSS, etc.

Though it will also mean you may have to go through another step to complete your transaction online (the extra step is only there to determine whether banks hold the merchant or consumer is liable for the fraud) but doing that (from the banks perspective) is always better thanhaving to deal with fraud and face the risk of losing your hard earnedmoney,” says Basant Shroff, associate director, financial services — advisory services, Ernst & Young.


Editor's Note:

This is what I have to say on the subject

This is such Bullcrap!
  Adding another false layer of "bullcrap protection" will "only" provide a bullcrap "false sense of security" 

Adding another bullcrap step which they say will get rid of thebullcrap fraud actually provides hackers with "ANOTHEROPPORTUNITY" to steal your money. 

C'mon people!  Read between thelines on this one.  It's 100% BS..  Let me sift through the stinkhere. 
Consumershave fears about security, so they are cajoled, no scratch that,"fooled" into thinking online shopping is more secure because banksadded another layer of "Emperor's Clothing." 

So, in reality, the only thing they have providedhere is yet another step for hackers to steal passwords under the "false pretense"  of "enhanced security." 

Question:  If it's truly safer, then why have they covered their butt by stating that if the password is correct, (it doesn'tmatter if you dispute the transaction)...you are liable!   If it was truly secure, then they would assume liabiility! 

Talk about stanky!...openthe windows, turn on the fan, spray some air freshener, scratch that, call in the fumigator!  This is Smoke and Mirrors,  plain and simple.

As per RBI figures, Indian banks lost out on almost Rs 37 crore in 12,959 credit card fraud cases reported last year.

(Editor'snote:  Hence the introduction of a "third new layer" ofauthentication designed to shift bank  liability to merchants andconsumers in a most "shifty" way. 

According to the article, "Some banks,in fact, have gone a step ahead creating the security wall."  (Editor's Note:  Wait til you read this one.  Are you strapped to yourchair?  Because I almost fell out of mine when I read the folowing. 

For instance, while generating 6-digit PIN as an additional security layer at ICICI Bank, you are also asked to type a message, known as personal assurance message. (PAM).

(Editor's Note: Add an S to be beginning of that word and you'll find out how the bad guys will phish your PAM silly) This PAM is known only to you.
  (Editor's Note: Are they joking?  For how long?  Here's for how long.  Until you "type" it into a box somewhere....!)

When you type your credit card number on the merchant’s website, "IT" will take you (what/who will take me?) to the bank’s website to complete the transaction, where you need to "type" in the PIN, explains a ICICI Bank spokesperson.  

Editor's Note:  Thisis beyond bullcrap, it borders on insane.  What's so hard to understand that it's the stupid typing of their passwords, usernames, card numbers, this new "PAM" garbage, etc. that is the root of the problem.  So the NEW system now asks you to type, even more of your information into boxes and double/quadruple your chances of getting hit by fraud.

Another question:  What is this "
IT" that takes me to the bank's website?  It "IT" the web browser?  Is "IT" an API that simply takes you to another website?  There is NO WAY anyone could know whether or not they are being redirected to a legitimate versus a cloned bank website.

This is their idea of the future of ecommerce?  To increase risk by creating more steps which require more typing?

Why is that so hard for supposedly "learned" people to understand that the problem IS the typing?  See "It's the Typing Stupid"

Suppose that after you "type" your credit card number on the merchantswebsite, you are "redirected" to a "cloned bank website?"  Hackers cando this in one of many ways.  And how would you know?  The clonedwebsite looks authentic.   The "https" says it's authentic.  (for those who think that still means anything) Maybe it will display their EV SSL certificate!    Ooops, nevermind.  Those were exposed last week. 

Anyway, once you get to either the bank website, you follow the bank instructions and "type" in your PIN.   Even if you ARE on the "legitimate" website, hackers can steal whatever you type.   If you are on a cloned bank website guess what happens after you "type" your PIN?  Did you say your bankaccount gets emptied.  Correct you are.

Now what?  You have to try and get your money back right?  Well, here's the bad news...according to this article, and Iquote:
"if the password is correct and even if customer disputes the transaction, it is still a customer’s liability.”
  Oh...nowI get it.  They just shifted the responsibility of the loss from the bank onto theconsumer. So, I guess this post is directed at consumers:   "If you expect a secure eCommerce transaction, you won't "type" anythinginto the browser.  It's really not that hard to understand.  Is it?   If it is, take a look at some of the related article below.

How Can HomeATM's Technology Help? 

HomeATM is proud to offer consumers the immediate availability of our PCI 2.x Certified SafeTPIN, a personal credit/debit cardreader that keeps your credit card information and identity completelysafe when you’re banking or shopping online. Simply plug the SafeTPIN into yourcomputer’s USB port, (no software or driverss needed) visit your favorite online banking site and swipe your card and enter your PIN exactly like you would at an ATM.  There is no safer way to log in to your online banking account.  When it comes to shopping, just visit your favorite shopping site, swipe your credit card and the SafeTPIN scrambles and 3DES encrypts the user’s track2 data  before itreaches the user’s computer or Internet providing instant protection from malicious software attacks. 

HomeATM provides complete End to End Encryption (Zones 1-4) for Track2 data. (to the Card Brands) PIN Debit transactions via HomeATM provide 100% "Zone 1 through Zone 5" (including Card Brands) End to End Encryption.

Regarding our PIN Debit transactions...there is not an ePayment method that is safer.  Period.  The ONLY PCI 2.x PIN Entry Device designed for eCommerce in either hemisphere.  With HomeATM's solution, the consumer will NEVER TYPE.  HomeATM has a pending patent on assigning PIN's to credit cards via our PIN MY Card application.    







Reblog this post [with Zemanta]

Saturday, August 1, 2009

Apple Releases Fix to SMS Mess

As we learned this week at Black Hat, a memory corruption issue exists
in the decoding of SMS messages and receiving a maliciously crafted SMS
message may lead to an unexpected service interruption or arbitrary
code execution.



Apple released iPhone OS update 3.0.1 which addresses the issue through improved error handling.













iphone-sms -

CL Verify UK Launches Fraud/Banking Solution

             

CL Verify UK™ launches Fraud and Banking Solution

- Solution provides exclusive access to the most predictive information
available for evaluating UK consumer credit risk -

TAMPA, FL (July 31, 2009)— CL Verify UK™, (www.clverifyltd.co.uk), a leading real time credit reporting agency, today announced the launch of its exclusive Fraud and Banking Solution™, providing lenders, credit issuers and collection firms with exclusive access to highly predictive information available for evaluating UK consumer credit risk. The Solution combines more than 20 years of UK and IRE bank account performance information with the Company's industry leading analytic experience to deliver over 30 identity, bank account and financial performance attributes along with two highly predictive scores.

"The UK consumer demand for short term liquidity is sizable and growing rapidly. Yet the substantial risk of credit losses has resulted in the majority of applications being unapproved because of insufficient risk management information available up to now," said Kim Anderson, Managing Director. "Our Fraud and Banking Solution™ directly meets this challenge by delivering exclusive access to unique, highly predictive information and advanced analytic resources designed to mitigate risk and develop profitable, sustainable loan portfolios for our clients."

Built using unique and proprietary data sources, coupled with the power of the PreView Technology™ platform and the experience of the leading US real-time credit bureau, this innovative decision tool allows users to effectively decision UK consumer credit applications in real-time. By minimising fraud risk and reducing payment defaults and charge-offs, Fraud and Banking Solution™ users can successfully deploy lending strategies which optimise Total Portfolio Profitability™.

For more information, visit www.clverifyltd.co.uk or email sales@clverifyltd.co.uk.

About CL Verify UK™ Ltd.
CL Verify UK™ is a fully licensed credit reporting agency as authorized by the UK Office of Fair Trading and provides an integrated suite of decision support solutions for evaluating UK consumer credit risk. The Company's proprietary consumer data, advanced analytics and PreView Technology™ platform provide clients with the most predictive resources for identifying, managing and optimizing the entire credit life cycle of a customer. For more information, visit www.clverifyltd.co.uk or email sales@clverifyltd.co.uk.

Friday, July 31, 2009

MasterCard/Visa See Debit Grow but"Credit Declined"

MasterCard Inc. saw U.S. debit card purchase volume rise 3.4% from year-earlier levels to $82 billion in the second quarter, and debit purchase transactions rose 11.3% to 2.11 billion. But U.S. credit purchase volumes fell 15.5% to $120 billion on 1.5 billion transactions, off 5.8%. Total worldwide transactions processed grew 7.9% to 5.63 billion...

Visa Inc. processed 10.3 billion transactions in its third fiscal 2009 quarter ended June 30, up 8.4% from 9.47 billion a year earlier. But most of the operating data Visa released Wednesday with its latest earnings report were for the quarter ended March 31, and they showed a 9.7% decline in U.S. credit payments volume and 3.9% decline in credit transactions from the year-earlier quarter. U.S. debit volumes, however, rose 4.7% and transactions increased 10.3%.







Reblog this post [with Zemanta]

Merchant Risk Council Adds New Board Members


FOR IMMEDIATE RELEASE


MERCHANT RISK COUNCIL ADDS NEW BOARD MEMBERS
Leaders from Accertify, GlobalCollect, Linden Lab and Microsoft Join MRC Board

(Seattle, WA—July 31, 2009) The Merchant Risk Council (MRC), a merchant-led trade association focused on electronic commerce risk and payments globally, today announced the results of their 2009-2010 board elections.

New MRC Board Director:
Mike Duffy – President and CEO, Chase Paymentech

Re-Elected MRC Board Directors:
Tom Sullivan – Sr. Director, Global Payments & Risk, Expedia, Inc.
Gerry Sweeney – Global Head, e-Commerce & Authentication, Visa, Inc.

New MRC Board Advisors:

Gary Doernhoefer – Co-Founder and General Counsel, Accertify, Inc.
Floris de Kort – Chief Commercial Officer, GlobalCollect
James Pierson – Trust and Safety Program Manager, Linden Lab
Ronda Sifford – CSAT Risk Management Group Manager, Microsoft

Re-Elected MRC Board Advisors:
Al Boddorf – Director, Global Financial Services, Dell, Inc.
Jerett Sauer – Director Loss Prevention, Gap Inc. Direct
Tom Keithley – Vice President of Credit Policy, PayPal
Mike Petitti – Chief Marketing Officer, Trustwave

Tom Sullivan has been re-elected as MRC Board Chair. Pete Pouridis, Vice President, Loss Prevention, Neiman Marcus Group Services has been re-elected as Board Secretary. Joining the MRC officers is new Board Treasurer, Karl Hebert, Director, Global e-Commerce Product Management, Wal-Mart.

“We are very proud to announce our new board,” said Tom Donlea, MRC Executive Director. “The electronic payment professionals who serve on our board represent the brightest minds in our industry. This group will prove invaluable in driving towards and achieving the vision, mission and strategic goals of the MRC.”

Outgoing MRC Board members include: Tim Laudenbach, Credit Risk Manager, BestBuy.com; David Gee, Director of Finance & Administration, Blizzard Entertainment; Ori Eisen, Founder, Chairman and Chief Innovation Officer, 41st Parameter; and Jon Karl, Vice President of Business Development & Founder, iovation.

“Tim, David, Ori and Jon have been instrumental figures in the evolution of the Merchant Risk Council,” said Tom Sullivan, MRC Board Chair. “Their commitment, energy and expertise have been vital in educating our membership on the advancements and progression of electronic payment fraud prevention.”

Full 2009-2010 Merchant Risk Council Board Roster

MRC Directors:
  • Chair, Tom Sullivan – Sr. Director, Global Payments & Risk, Expedia, Inc.
  • Secretary, Pete Pouridis – Vice President, Loss Prevention, Neiman Marcus Group Services
  • William Lambson – Director, Global Commerce Payments and Risk, Adobe Systems, Inc.
  • Dave Moriarty – Director of Data Mining, Apple
  • Mike Duffy – CEO, Chase Paymentech
  • Perry Dembner – Vice President, Marketing, CyberSource Corporation
  • Brad Craig – Director of Risk Management, Discover Network
  • Gerry Sweeney – Global Head, e-Commerce & Authentication, Visa, Inc.
  • Dave Sessions – Vice President, Strategy and Business Development, Wal-Mart Global e-Commerce
MRC Advisors:
  • Gary Doernhoefer – Co-Founder and General Counsel, Accertify, Inc.
  • Al Boddorf – Director, Global Financial Services, Dell, Inc.
  • Jerett Sauer – Director Loss Prevention, Gap Inc. Direct
  • Floris de Kort – Vice President of Business Development, GlobalCollect
  • James Pierson – Trust and Safety Program Manager, Linden Lab
  • Ronda Sifford – CSAT Risk Management Group Manager, Microsoft
  • Tom Keithley – Vice President of Credit Policy, PayPal
  • Mike Petitti – Chief Marketing Officer, Trustwave
MRC Board Consultants:

The MRC Board will next convene at the Merchant Risk Council’s Semi-Annual Platinum Meeting in San Jose, CA, September 30-October 1, 2009.

About the Merchant Risk Council
The Merchant Risk Council (MRC) is a merchant-led trade association focused on electronic commerce risk and payments globally.  The MRC leads industry networking, education and advocacy programs to make electronic commerce more efficient, safe and profitable.
Today, with the power of its member-base, the MRC is the leading trade association for managing payments, preventing online fraud and promoting secure e-Commerce.  The MRC is dedicated to working with e-Commerce and multi-channel merchants, payment processors, credit card issuers, credit card companies, alternative payment providers, risk management experts, and law enforcement to make the Internet a safer and more profitable place to do business.
The MRC is headquartered in Seattle, Washington.
Jordan Rubin
Communications and Membership Manager
206.364.2789 office | 206.367.1115 fax




Reblog this post [with Zemanta]

In Two Weeks Your iPhone Will Be Hacked



Does the picture on the left look familiar?  Cause I've used it a dozen times in a dozen posts.  In fact,  most recently, about two posts ago.  The article below is justifies it's use once again.  And this is only the tip of the iceberg.  Smartphones use browsers.  Browsers are not safe.  Financial transactions need to be done outside the browser space.  It's the typing.  Researchers at Black Hat exposed a major vulnerability in the iPhone which would allow a hacker to send an SMS message and completely take over not only your iPhone but everybody in your contacts lists phones as well.   

iPhone vulnerable to hacker attacks, experts say


Flaws can be exploited to take complete control over an iPhone (and other smart phones)

LAS VEGAS - Security experts have uncovered flaws in Apple Inc.'s iPhone that they said hackers can exploit to take control of the popular device, using the tactic for identity theft and other crimes.

IPhone users needed to be warned that their devices are not secure and Apple should try to repair the vulnerability as soon as possible, they said at the Black Hat conference in Las Vegas, one of the world's top forums for exchanging information on computer security threats.

"It's scary. I don't want people taking over my iPhone," Charlie Miller, a security analyst with consulting firm Independent Security Evaluators, said in an interview.

Miller and Collin Mulliner, a Ph.D. student at the Technical University of Berlin, also discovered a method for hacking the iPhone that lets hackers easily knock a victim's iPhone off a carrier's network.

It prevents users from making calls, accessing the Internet and exchanging text messages, they added.

The two showed how they can disconnect an iPhone from the cellular network by sending it a single, maliciously crafted text message — a message the victim never sees. The messages exploit bugs in the way iPhones handle certain messages and are used to crash parts of the software.

1. The major issue is a security flaw involving SMS. Specifically, thehack can control an iPhone remotely, including your iPhone’s camera, Safari, and more. It can even send messages to friends in your address book, which is where this hack becomes scariest.
2. The hack works by sending you code in an SMS message (or a seriesof messages) that crashes your iPhone. After that, your iPhone istheirs to use.
3. The offending text would come in the form of a single square character. If you get the square character, turn off your phone IMMEDIATELY.
4. You only have to receive the message to get hacked; you don’t even have to do anything with the text message.
5. The flaw was discovered by noted security expert Charlie Miller, who has hacked everything from MacBook Airs to Second Life, and partner Collin Mullinger.
6. The attack was presented publicly at the Black Hat conference.The duo decided to do this after Apple gave them no response back inJuly, when they provided Apple with information on the security flaw.The goal is to bring attention to the flaw (which they are clearlygetting).
7. According to Reuters, now that the vulnerability is exposed, hackers could build software that mounts this SMS attack within the next two weeks.
8. Apparently Google Android, Windows Mobile phones, and Palm Presare vulnerable to similar hacks. The team demonstrated the attack on anAndroid phone and a Windows Mobile phone.- Mashable.com



They even said it's possible to remotely control an iPhone by sending 500 messages to a single victim's phone. Those messages contain the necessary commands for the attack and would get executed automatically by exploiting a weakness in the way the iPhone's memory responds to that volume of traffic.

Miller said messaging attacks are so attractive, and are going to become more common, because the underlying technology is a core phone feature that can't be turned off.

"It's such a powerful attack vector," Miller said. "All I need to know is your phone number. As long as their phone's on, I can send this and their phone's going to do something with this. ... It's always on, it's always there, the user doesn't have to do anything — it's the perfect attack vector."



They said the information they presented at Black Hat will give criminals enough information to develop software to break into iPhones within about two weeks. 

Continue Reading



Reblog this post [with Zemanta]

Jamaica Fraud Tops $3 Billion Dollars

Jamaica Gleaner News - Fraud hits historic high at $3b - Business - Friday | July 31, 2009
Fraud hits historic high at $3b
Published: Friday | July 31, 2009
Avia Collinder, Business Reporter

Detective Carl Berry of the Organized Crime Unit of the Jamaica Constabulary Force shows merchants and employees a fake credit card that was seized by the police, at a National Commercial Bank 'Merchant Fraud Seminar' in Kingston. To curtail its losses from credit card scams, NCB has partnered with the police on a series of seminars.

Corporate earnings lost to fraud hit $665 million for the first half of this year, prompting the police fraud squad to warn company managers and individuals to be more vigilant in the supervision of employees and pre-paying for goods and services.

But that outcome annu-alised is a more than a two-fold improvement, coming off a spectacular year for crooks in 2008 when monies lost to fraudulent activity passed the J$3 billion mark for the first time in Jamaica's history.

Continue Reading Mawn


Reblog this post [with Zemanta]

Think This is Safe? Think Differently!


Experts predict more mobile Trojan slip-ups on the way
As news that the Symbian Foundation has admitted it needs better safeguards to prevent malicious apps finding their way onto mobiles,

Fortify Software predicts this problem is going to get worse for mobile phone manufacturers and their operating system developers.

"The problem with mobile phones is that their processing capacity is increasing at a near-exponential rate, with some of the latest smartphones the technological equivalent of the PCs seen in the early part of this decade," said Richard Kirk, director of the application vulnerability specialist.


"And whilst the power of the average smartphone has soared on the last few years, the behind-the-scenes technology and security assurance practices required to prevent any security loopholes in the operating system and/or applications is not as up to speed as it is on the desktop/laptop platforms," he added.

Because of this, hackers and malware developers are now turning their attentions to the microcomputer many of us have in our pockets - the smartphone.

Editor's Note:  And the rush to bring a mobile payment platform that is "convenient" and "easy to use" will be a gold mine to hackers. 
A goldmine I say!












Reblog this post [with Zemanta]

4 Arrested in $422,000 ATM Scam

DSCF0593Gang charged in $422,000 ATM scam

Authorities in New York have arrested four people accused of stealing $422,000 by exploiting a regulation requiring banks to reimburse the accounts of customers who claim their ATM cards have been used without their permission.

The four defendants - Lam Dang, Eric Manganelli, John Tluczek and Marzena Tluczek - are charged with making false claims totalling more than $700,000, to more than 20 banks, including HSBC, Wachovia and Chase.

In each case, the defendants opened accounts and padded them with large deposits over the course of several months before draining them again, with withdrawals of $500 to $1000 per day, say prosecutors.

Once the accounts were empty, the scammers would contact the bank and say their ATM cards had been stolen or lost and that the withdrawals were unauthorized. After the banks reimbursed the "stolen" money, the defendants would close the accounts, according to the indictment.

The four are accused of exploiting regulation E of the federal Electronic Fund Transfer Act, which requires banks to reimburse victims within 10 days of reporting the fraud. 

Continue Reading at Finextra



Reblog this post [with Zemanta]

More on Clampi...It's the Big One!


"The best strategy to defend against Clampi is to use separate machines for Web surfingand funds transfer" 

"We weren't all thatworried about Storm, and we weren't all that worried about Conficker, This one you need to worry about." 


- Joe Stewart, one of the world's foremost authorities on botnets and targeted attacks.


Finextra: Bank data-stealing Trojan infects hundreds of thousands of PCs - researcher
Bank data-stealing Trojan infects hundreds of thousands of PCs - researcher

A "tremendous" amount of financial data has been stolen by a Trojan that has infected hundreds of thousands of corporate and personal PCs, according to information security specialist SecureWorks.


Clampi, also known as Ligats, Ilomo or Rscan, has spread across Microsoft networks in a "worm-like fashion" and is "one of the largest and most professional thieving operations on the Internet" says Joe Stewart, director of malware research at SecureWorks' counter threat unit.
Once it has infected a PC, the Trojan monitors Web sessions to see if one of 4500 targeted sites are visited. If a victim uses one of these sites - which include those of banks, credit card companies, stock brokerages and insurance firms - it captures sensitive information such as usernames, passwords and PINs.


Continue Reading at Finextra



Reblog this post [with Zemanta]

Thursday, July 30, 2009

Security Researchers: Online Transactions Aren't Safe


If you think you are seeing a pattern over the last two days, about how insecure the internet is, especially when it comes to financial transactions, then you'll also notice that the Paradigm Shift I've been talking about is starting to take shape. 

It's becoming increasingly clear. 

  • Internet Security Broken
  • No Website is Safe
  • Online Transactions aren't safe
  • Use the Internet for browsing, use another device for payments.  
Read more about those bulletpoints in the related articles section below.  In the meantime, there's only one "another device" in the world designed for online transactions to be is PCI 2.x certified.  I think it's the one HomeATM built.  Yup, it is!    Does that mean we can fix web security.  We can when it comes to transactions.  Here's yet another article proving our methodology:

Security researchers: Online transactions aren’t as safe as we thought

Internet security is busted, said researchers at the Black Hat conference in Las Vegas today.


If this sounds familiar it’s because just a year ago, Dan Kaminsky (pictured left) found a flaw in the Internet’s address book, the Domain Name System, where hackers could fool DNS servers into redirecting traffic to bogus sites. The tech industry pulled together quickly to patch the hole and minimize the vulnerability.

The same thing happened here, as Kaminsky rounded up a coalition of companies to deal with a weakness in X.509, a cryptographic system used to create digital certificates. The digital certificates are the way that a web site can verify the identity of a unique users who is visiting the site and wants to do a transaction. It’s a lot like using a passport photo to identify someone standing in front of you. Everyone from Amazon.com to Microsoft uses it in so-called digital handshakes that precede e-commerce transactions.

When Kaminsky walked into the standing-room only auditorium where he talked about the flaws in X.509, he got a lot of applause. You would never know that a day earlier his own personal web site, Doxpara.com, got hacked.

But Kaminsky held the crowd spellbound as he elaborated in great technical detail. Then he got started describing what he called the “crisis of authentication.” He showed that by altering a line in a digital certificate, hackers could fool users into believing that a site is legitimate when it really isn’t.

Businesses have invested hundreds of millions of dollars in the public key infrastructure system that was developed in the 1990s. Now Kaminsky, as well as grad student Len Sassaman (second from right) says we need to reboot the system. Tim Callen, (pictured far right), a vice president at Internet infrastructure authority VeriSign, pretty much agreed.

Continue Reading

RELATED

Separate Machines Needed for Web Surfing and Transactions
Arenowned researcher has stated our case: "The best strategy to defendagainst Clampi is to use separate machines for Web surfing and fundstransfer" - Joe Stewart, one of the world's foremost...
Jul-30 - 2009 | More ->

No Websites, Legitimate or Not Can Be Trusted
Websense: This Past Month in Web ThreatsSTATE OF THE THREAT ABSTRACT:Theconjunction of technologies and the monetizing of hacking have resultedin a web environment where no websites,...
Jul-30 - 2009 | More ->


 

Reblog this post [with Zemanta]

Down on Main Street

Pain on Main Street: A First-Ever Drop in Card-Based Same-Store Sales

(July 30, 2009) As the recession continues to batter merchants of all sizes, small and medium-size retailers are getting hit especially hard, and as a result so are the acquirers that process their card transactions. Indeed, in a development apparently never seen before, same-store sales on Visa and MasterCard for these Main Street merchants were down fully 4.9% in the January through May period, according to research released this week by First Annapolis Consulting. By contrast, same-store sales for these same merchants had climbed modestly, by 1.5%, last year.

To get a picture of the current state of merchant acquiring, First Annapolis surveyed 17 acquirers—nine bank acquirers and eight non-bank processors--that account for more than half of all U.S. card-based payments. Besides the overall decline it discovered, the firm said 17 acquirers reported same-store sales plummeting by more than 10%. Overall, bank acquirers reported a steeper drop in sale-store sales than did the non-banks.

“To put this into perspective, card-based payments have never registered same-store growth declines overall, even in past recessions,” the Linthicum, Md.-based consulting and research firm said in a statement announcing its results...

Continue Reading at Digital Transactions

Reblog this post [with Zemanta]

Malware Numbers Intensify: 92k into 30 Million

PandaLabs announced a multi-year study that examines the proliferation of rogueware into the overall cybercriminal economy.

Click the graphic on the left and prepare to be shocked and amazed.  In 2006 there were less than 740,000 malware samples.  By the end of 2008 there were 15 million.  By the end of June 2009, there were 30 million.  I'm thinking Swiping vs. Typing here.

The report reviews the various forms of rogueware that have beencreated, and displays how this new class of malware has become aninstrumental player in the overall cybercriminal economy.


The study also provides in depth analysis on the increasinglysophisticated social engineering techniques used by cybercriminals todistribute rogueware via Facebook, MySpace, Twitter and Google.

PandaLabs predicts that it will record more than637,000 new rogueware samples by the end of Q3 2009, a tenfold increasein less than a year.

Approximately 35 million computers are newlyinfected with rogueware each month...

Cybercriminals Earn $34 million dollars per month on rogueware
Background: The History of Malware Growth

Malware has rapidly increased in volume and sophistication over in the past several years. The graph below illustrates the malware landscape from 2003 to 2006 over which the total number of malware samples doubled every year:

Barely five years ago, just 92,000 total malware strains existed; by the end of 2008, there were approximately 15 million. At the conclusion of this study in July 2009, PandaLabs detected more than 30 million malware samples in existence.

The reason behind this vast increase in malware is clear: money. In 2003, banking Trojans quietly emerged on the scene. These malicious codes, designed to steal online banking credentials, now rank among the most common forms of malware. Every day, we see new variants that have evolved technologically in order to evade the security measures banks have implemented.
Click either Graphic to Enlarge and Read




Reblog this post [with Zemanta]

Separate Machines Needed for Web Surfing and Transactions

A renowned researcher has stated our case:

"The best strategy to defend against Clampi
is to use separate machines for Web surfingand funds transfer"


- Joe Stewart, one of the world's foremost authorities on botnets and targeted attacks.


"Using Windows, it's too dangerous todo transactions on the same machine you do for Web surfing," he says."You can't have any crossover between them."

Editor's Note:  Looks to me likethe message we've been trying to get out for 15 months is finallygetting out.  When one of the world's foremost authorities on web security says the only way to protect against Clampi is to use too separate machines,  we agree 100% .  After all, it was HomeATM who has stated unequivocally since day one, that people should use "separate machines" for Web surfing and financial transactions. That's why we created ours.  The fact that it is PCI 2.x and TG-3certified only strengthens the case for using it.    You surf the webon one machine (the PC) and conduct financial transactions on another. (our SafeTPIN device)

DarkReading

LAS VEGAS -- BLACK HAT USA 2009 -- A security researcher has discovered a Trojan that is designed to extract account data from as many as 4,600 of the world's most popular and wealthy businesses.

In "one of the largest and most professional thieving operations on the Internet," a Trojan called Clampi (also known as Ligats, llomo, or Rscan) has spread across Microsoft networks in a worm-like fashion, and may already have infected hundreds of thousands of corporate and home PC users, according to SecureWorks researcher Joe Stewart, one of the world's foremost authorities on botnets and targeted attacks.

"We weren't all that worried about Storm, and we weren't all that worried about Conficker," Stewart says. "This one you need to worry about."



The Trojan uses PsExec -- a popular, lightweight Telnet replacement tool that lets one system execute processes on other systems -- and a sophisticated process of encryption and packing to hide its origins and targets. So far, Stewart says, the Trojan appears to be targeting 4,600 Websites, of which he has identified approximately 1,400 in 70 countries.

Those 1,400 sites include some of the most popular and financially lucrative companies in the world. "This thing is like the Dun & Bradstreet of the underground hacking world," Stewart says. "It's attacking the sites with the most users and the most money." Among the industries being targeted are banks, credit card companies, stock brokerages, insurance, retail, advertising networks, and utilities.


Clampi is operated by a "serious and sophisticated organized crime group from Eastern Europe" and already has been implicated in numerous high-dollar thefts from banking institutions, Stewart says. "This attack is not being sold underground," he says. "You can't buy a Clampi kit like you can for other Trojans."

Clampi generally can avoid detection by antivirus software, and it even has the ability to discover which AV software a PC is using and take steps to avoid it, Stewart says. Enterprises currently can block Clampi with an intrusion prevention system, but Stewart says he doesn't expect that defense to last very long before the Trojan adapts.

The best strategy to defend against Clampi -- and other attacks that use a similar approach -- is to use separate machines for Web surfing and funds transfer, Stewart says. "Using Windows, it's too dangerous to do transactions on the same machine you do for Web surfing," he says. "You can't have any crossover between them." 


Read the Entire Article at Dark Reading

Disqus for ePayment News