Monday, December 28, 2009

Bank Tech News: Online Banking Protection Still Weak

Bank Technology News  |  December, 2009  | John Adams



BTN: There are still holes in online banking protection, according to Javelin Strategy & Research, which says lots of banks are still using long passwords and very rudimentary information for authentication purposes.



(Editor's Note:  Long passwords don't work.  Either does the 20 questions approach.  It doesn't matter if online banking customers were required to type the entire book, "War and Peace by Tolstoy" into a box on a bank website and then answered 20  questions about quantum physics...everything can easily be keystroke logged by hackers...



it's the typing that provides the online banking credentials to the fraudsters...not the length of the password nor the number of questions asked. 



Another words, fraudsters could cut and paste your password and username as easily as I cut and pasted this article from BTN) Online Banking customers MUST use a hardware device which encrypts their log-in details outside the browser space so the bad guys get gobbly-gook if they intercept.  The good news is the same is true for online shopping with credit/debit/prepaid cards and bank's can derive recurring transactional income for each purchase made with a HomeATM device.  Furthermore, "card not present" fraud is eliminated with our device and CNP fraud is the fastest growing threat facing online shoppers.



At the end of the day, banks ensure a secure online banking session and make money each time their customers use our device.  Throw in revenue derived for real-time bill pay, instant money transfers (any bankcard to/from any bankcard) and the ROI would be a couple transactions.  Add to that the competitive advantage gained by offering a secure solution in the face of weak authentication and it can make for a pretty formidable marketing/branding strategy...one that induces customer loyalty AND makes money.   Last time I read an article on Bank Technology News about online banking, their editor said "it's dead."



Online Banking is Dead - Bank Technology News Editor-In-Chief



"Among the protective measures that should be in the dustbin are authentication data such as birthdays, email addresses and zip codes, since it's information that's very easy for fraudsters to predict or obtain. Yet it's still used by about 20 percent of online banking sites. The percentages are low, but given the use of zip codes and email addresses as authentication pieces were outed as a bad idea years ago, any remaining use of these metrics is a surprise. Also, a quarter of banks still require passwords longer than six digits, considered a no-no in an age of usability. And only about 25 percent of banks reduce data exposure by truncating social security numbers during enrollment.  



Javelin additionally found that 90 percent of banks user generic error messages when a log in attempt fails, and 10 percent still display information that can be used in a “brute force” attack. James Van Dyke, president of Javelin, said it was surprising that so many banks overlook this potential vulnerability. He says a cross-site scripting flaw on a customer-facing Web site could allow crooks to access the internal network or insert counterfeit content along with legitimate content on a site and redirect customers to a fraudulent third party site.



Javelin reviewed the websites of 24 financial institutions, including Banco Popular, Bank of America, Bank of the West (BancWest), Branch Banking and Trust Company, Capital One, Citibank, Fifth Third Bank, Golden One Credit Union, HSBC Bank, ING Bank, JPMorgan Chase, M&I, M&T, NFCU, PNC, RBS Citizens, Regions, Sovereign, SunTrust, Synovus, TD Bank, US Bank, Wells Fargo, and Zions. The firm did not identify specific institutions, presenting its results in aggregate."









Reblog this post [with Zemanta]

NCR Hires It's First CMO





NCR Tabs Bravman As Its First Chief Marketing Officer



NCR Corp.’s hiring yesterday of Richard Bravman as its first chief marketing officer offers more evidence that the company is transitioning from its traditional role as an ATM manufacturer to a technology company involved in a wide-ranging line of businesses.

Bravman, whom NCR also named vice president of corporate development, says he will assist the Duluth, Ga.-based company in forming partnerships with other companies and with purchasing smaller businesses that present opportunities in untapped markets.

“NCR is involved in retail, health care, travel and entertainment,” Bravman tells PaymentsSource.com. “We must challenge ourselves to develop a coherent voice within the company and form strategic alliances to grow the business.”

Continue Reading at Payments Source

The Other Underbanked - Small Biz





US Banker  |  January 2010  | Marian Raab

When Sue Rexford opens a small-business banking account for her new venture - Bodhi Tree Therapeutic Massage - she will be looking for a financial institution that can provide two things: convenience and low fees. "Those are the key factors," says Rexford, a licensed massage therapist who opened Bodhi Tree in South Orange, N.J., in September.



As a small-business owner, Rexford's concerns are pretty typical. Industry experts and analysts say that branch proximity and attractive account rates and fees are among the top concerns cited by small-business owners looking to open new bank accounts.



But Rexford is atypical for a self-employed entrepreneur in planning to open a business banking account at all.

Among the nearly 26 million small firms in the United States, about two-thirds don't have business-bank accounts, according to a Javelin Strategy & Research report released last year.



The bulk of these firms tend to be "overlooked and underserved" by most banks, according to the report examining the underbanked business segment.



Small companies usually "hide in the consumer banking platforms," according to Javelin, a Pleasanton, Calif.-based consulting firm. That means they pay lower account maintenance fees now, but likely won't get specialized services they'll need as they grow, including payroll/invoice management, remote deposit capture, corporate cards and specialized commercial lending.

"Banks need to refine their strategies so that they are recognizing this market and helping small businesses," says Mary Monahan, a managing partner and research director of Javelin.



Continue Reading at US Banker

Credit Union Reality Check 2010

You're Invited...



Credit Union Reality Check 2010

It's Time For Credit Unions to Get Real -

Join Us for

"Credit Union Reality Check 2010"!







The credit union movement is changing fast. Credit unions continue to consolidate. Credit unions' regulatory burden is growing. Congress is focused on new consumer protections for financial services. Clearly, there is no shortage of difficult issues facing credit unions, but opportunity also knocks.

Harrah's - Atlantic City - March 22-24



Credit union leaders that want to be ready for the future need a reality check and they need it now. Please join us for "Credit Union Reality Check 2010" at Harrah's in Atlantic City March 22-24 to see where our movement is headed.



The conference will be packed with hot button topics including:

  • The future of credit union liquidity/investments/payments

  • Retail Savvy: Are you innovating your product line? Banks are, why aren't you?

  • Governance in Focus: How CU boards operate has never been more important.

  • Viability of our CU system: CUs have a unique opportunity, but are we ensuring we will be the model for the future?

  • And more...

Speakers include Paul Gentile, president/CEO of the New Jersey Credit Union League; Bob Hoel, fellow at the Filene Research Institute; Stuart Levine, chairman and CEO at Stuart Levine & Associates; Tom Parliment, president of Parliment Consulting Services; Stan Hollen, CEO of CO-OP Financial Services; Brett Christensen, owner of CU Lending Advice, LLC; Herb Yolles, Region II's associate regional director, operations (ARDO) for NCUA; and more!



The conference will feature all general sessions where attendees will have the opportunity to participate in the discussion. The interactivity doesn't stop there. All attendees will have an electronic polling remote to provide instant feedback on key questions.



Don't miss this unique opportunity to help your credit union to get real about the future. For more information and to register CLICK HERE.




Event Sponsors:

New Jersey Credit Union League

Credit Union Times

CUMAnet





Alpha Omega - Serving Business for 30 Years

Federal Home Loan Bank of New York

The Credit Union Advisory Group at UBS

CO-OP Financial Services



New Jersey Credit Union League | 299 Ward Street | Hightstown, NJ | 08520 | 800-792-8861 | Website



Reblog this post [with Zemanta]

Unisys Predicts 2010 Yields a Biometrics Boom While Organizations Go on the Offensive to Protect Data

http://www.unisys.com
Advances in surveillance systems and continued Trojan attacks also on the horizon



BLUE BELL, Pa.--(BUSINESS WIRE)--Slashed budgets and reduced staffing numbers delayed many security initiatives in 2009, but the vulnerabilities didn’t retreat and will only intensify in 2010, Unisys security experts predict.



“Given the potential harm that can result from new and more dangerous forms of attacks, both physical and virtual, organizations can no longer afford to wait until they are attacked to defend themselves”

Looking ahead to 2010, Unisys predicts that government and commercial organizations will take a more proactive approach to security, implementing new measures to verify identity and protect confidential information. Financial institutions and defense agencies will lead the charge, with ports and other organizations quickly following.



“Given the potential harm that can result from new and more dangerous forms of attacks, both physical and virtual, organizations can no longer afford to wait until they are attacked to defend themselves,” said Sid Pearl, global director, Risk Intelligence Solutions Management, Unisys. “They will begin to more closely monitor behaviors and identities in an effort to predict and prevent attacks before they happen.”



Unisys believes the following seven security trends will emerge in 2010 as business and government agencies look to protect data and strengthen identification methods:



1. The consumerization challenge – Consumerization of IT will continue to blur the perimeters of the enterprise network. As a result, Unisys experts predict organizations’ focus will shift to data protection as opposed to traditional network security or infrastructure security. As more employees and consumers use smartphones and PDAs to conduct business transactions online, organizations will look for new ways to protect data beyond simple PINs and passwords. As consumer devices are increasingly targeted by malware and spyware, users will demand that security platforms and anti-fraud applications need to be strengthened and continually updated to ensure the protection of mobile online transactions.



2. A good offense – Trojan attacks will continue to plague financial institutions and government agencies. Therefore, these organizations will need to take an offensive stance to better guard their data against increasingly sophisticated and harmful threats. Unisys experts predict that banks and government agencies will adopt a more comprehensive, integrated view of their IT environments and will seek to better understand the human element behind illegal activities to help them pinpoint in advance when and where and how attacks are likely to happen.



3. Proactive ports – Port security officials will take a more predictive, proactive approach to preventing threats at key ports of entry. Rather than focusing on mere compliance with security standards, Unisys security experts predict that ports will actively begin assessing risks, simulating response efforts and creating more robust disaster recovery plans in the coming year. In addition, Unisys predicts an increase in U.S. land-based port cargo activity as Asian shipping lanes divert shipments from the congested sea ports of Los Angeles and Long Beach, Calif., to Canadian and Mexican ports. Pressure will increase to rapidly scan cargo shipments as they cross land borders into the U.S.



4. Cloudy forecast – Organizations will also begin to reverse the tendency of “protecting everything” and instead prioritize security controls based on whether the data in question presents low, moderate or high levels of risk. Consequently, more organizations will begin moving less sensitive public data into cloud computing environments to attain cost savings in 2010, and will then migrate more sensitive data to the cloud as new security models are developed to address multi-tier data protection.



5. Biometrics on the border – The coming year will see a tipping point in use of biometric identification tools such as iris, facial or fingerprint scans, to verify identity at the border and customs areas in airports. Unisys experts point out that many governments have invested in an electronic passport infrastructure, but not yet used it. Unisys expects increased rollout of electronic passports which contain a chip to store biometric data that can be matched to its owner to verify that the person carrying the passport is the owner of the passport. Unisys predicts that the rollout electronic passports will be led by countries in the Asia-Pacific region and Europe. The Unisys Security Index recently found a majority of people globally would accept biometric authentication to verify their identities.



6. Taking IT to the streets – Mobile biometric devices will allow governments to take more biometric-based critical services directly to their citizens, rather than requiring their citizens to come to the technology. Police forces in the U.S. and U.K. have already started using mobile fingerprint scanners to facilitate faster processing. In Australia, police officers can use the device to access the national fingerprint database from the field to scan the criminal database for a match. Such devices will also aid in the identification of individuals in a disaster situation.



7. Smart surveillance – Surveillance systems will be become more sophisticated and intelligent. Unisys experts say that real time event detection technology will soon be able to identify a security breach as it occurs and initiate an action instead of simply recording footage to be reviewed after the incident. Improved digital camera technology coupled with intelligent software enables surveillance footage to be combined with other available information, such as facial recognition data, to create alerts so that immediate appropriate action can be taken. Surveillance software will also soon be able to recognize recurring patterns, or individuals to detect when an unusual event is occurring in real-time.



About Unisys



Unisys is a worldwide information technology company. We provide a portfolio of IT services, software, and technology that solves critical problems for clients. We specialize in helping clients secure their operations, increase the efficiency and utilization of their data centers, enhance support to their end users and constituents, and modernize their enterprise applications. To provide these services and solutions, we bring together offerings and capabilities in outsourcing services, systems integration and consulting services, infrastructure services, maintenance services, and high-end server technology. With more than 26,000 employees, Unisys serves commercial organizations and government agencies throughout the world. For more information, visit www.unisys.com.

MasterCard Says eCommerce Holiday Shopping up 15.5%



PURCHASE, NY -- 12/28/09 -PIN Payments News Blog- MasterCard Advisors' SpendingPulse, a macro-economic report tracking national retail and service sales, today provided summary results for the holiday shopping season. The data showed year-over-year growth in the period between Black Friday through December 24 in all sectors measured. In addition, six out of ten sectors showed positive growth in the period from November 1 through December 24. Tempering these results, however, is the fact that there was an extra day this year over last year's holiday season. Adjusting for this could decrease the season's year over-year-growth statistics by anywhere from 2% to 4%.



"Overall this year, we have seen increasing stability in spending, as opposed to the free-fall of 2008," noted Michael McNamara, Vice President, Research and Analysis for SpendingPulse. "This is especially significant considering that prices have been holding up this season, without the broad emergency discounting that consumers benefited from during the 2008 holiday season."



McNamara pointed to several anomalies in the season this year. "The extra shopping day may have given some lift to overall year-over-year comparisons. Also, early discounting in 2008 drew holiday spending into early November, while this year shopping didn't really take off until Black Friday. That shift in sales patterns is one of the factors that made November of this year look weak, and December look stronger. That's why it's important to look at numbers for November and December combined. Finally, several major winter storms disrupted traffic to brick and mortar locations that seemed to benefit online shopping growth rates."



SpendingPulse analyzed the Electronics, Specialty (Apparel), eCommerce and Luxury sectors. Here are the end of season highlights:



  • eCommerce



eCommerce was the big winner this year, with seasonal sales up 15.5% during the period November 1 - December 24. Since Black Friday, eCommerce sales were up 18%. This sector has shown year-over-year improvement every week since the beginning of the season, with double-digit growth in all but one of those weeks.







HomeATM Manufacturers the "only" POS Terminal" designed exclusively for eCommerce use to be certified by MasterCard, Visa, American Express, Discover and JCB.  (PCI 2.x PED) 

Click here
to request more info






  • Apparel

    Specialty Apparel made something of a recovery, finishing down only 0.4% for the season to date beginning on November 1st. Since Black Friday through December 24, the category is actually in positive territory, showing a 2.3% year-over-year gain. However, the extra shopping day helped the sales growth rates.

  • Women's Apparel sales were down 0.3% for the season to date beginning on November 1st. Taking a Black Friday to December 24 view, this category also finished the season in slightly positive territory, up 1.5%, but again benefiting from the additional shopping day.

  • Men's Apparel continued to show strength in the two weeks prior to December 24, bringing the November 1 - December 24 season's year-over-year growth up 3.9%. Footwear sales have likewise improved, ending with an increase of 5% over the November-December period of last year.




  • Electronics

    After a strong November, electronics sales began to slow down in the first two weeks of December. A spike in the week prior to December 24 helped the category finish the season up 5.9% for the November-December period and up 6% in the Black Friday to December 24 period.




  • Jewelry and Luxury

    After a volatile two months, Jewelry ended the season up 5.6%, with both high and low ends of the category showing marked strength. Again the extra shopping day helped the year-over-year growth rate. Although the Luxury retail ex-jewelry category showed some weekly improvement throughout December, it finished the season more with a slight increase of 0.8% over the 2008 holiday season. Luxury is another category that would have been lower without the additional shopping day this year.



SpendingPulse(TM)



Data Source: A macro-economic indicator, SpendingPulse reports on national retail and service sales and is based on aggregate sales activity in the MasterCard payments network, coupled with survey-based estimates for certain other payment forms, such as cash and check. MasterCard SpendingPulse does not represent MasterCard financial performance. SpendingPulse is provided by MasterCard Advisors, the professional services arm of MasterCard Worldwide.



About MasterCard Advisors



MasterCard Advisors provides payments consulting, information, analytics, and customized services to financial institutions and their merchant partners worldwide. Addressing complex challenges in strategy, marketing, risk, and operations, MasterCard Advisors helps clients maximize the value of their payments businesses. As the professional services arm of MasterCard Worldwide, MasterCard Advisors is uniquely qualified to provide clients with insights and solutions that drive tangible impact and financial gain. For more information, go to www.mastercardadvisors.com.



About MasterCard Worldwide



MasterCard Worldwide advances global commerce by providing a critical economic link among financial institutions, businesses, cardholders and merchants worldwide. As a franchisor, processor and advisor, MasterCard develops and markets payment solutions, processes approximately 21 billion transactions each year, and provides industry-leading analysis and consulting services to financial-institution customers and merchants. Powered by the MasterCard Worldwide Network and through its family of brands, including MasterCard®, Maestro® and Cirrus®, MasterCard serves consumers and businesses in more than 210 countries and territories. For more information go to www.mastercard.com.



For further information contact:



Meir Kahtan

+1-212-575-8188

Meir Kahtan Public Relations, LLC

Email Contact



Jennifer Stalzer

+1-914-249-5325

MasterCard Worldwide

Email Contact






Reblog this post [with Zemanta]

Alibaba.com Completes Acquisition of HiChina Web Solutions

http://www.alibaba.com

HONG KONG--(BUSINESS WIRE)--Alibaba.com (HKSE:1688.HK) (HK.1688) has completed a share purchase agreement of China Civilink (Cayman), which operates in China as HiChina Web Solutions, a leading eCommerce company that provides domain name registration. This was the first of a two phase deal with Alibaba.com acquiring 85 percent of HiChina now, and the option to acquire another 14.67 percent equity interest from HiChina’s founders pending HiChina reaching certain performance targets.



The total consideration of RMB539.98 million (US$79.06 million) in cash for both phases, brings four key assets to Alibaba.com: a new, large customer base; new, value-added applications; advanced and automated “do it yourself” Web site technology; and additional leadership strength in HiChina’s strong management and operating team.



“As promised at our IPO, our investment focus is on opportunities to grow our customer base and acquire additional technology and new applications to achieve our mission to make it easy for customers to do business everywhere,” said David Wei, CEO, Alibaba.com. “HiChina is a strategic fit with that vision, and we are happy to close a great year of investment by completing this deal, bringing us that much closer to realizing the synergy of Alibaba.com and HiChina.”



For more information on this announcement, see Alibaba.com’s filing with the Hong Kong Stock Exchange at http://img.alibaba.com/ir/download/200909/EngReleaseHiChina.pdf.



Note: All US dollar conversions are based on an exchange rate of USD1.00=RMB6.83



About Alibaba.com Limited



Alibaba.com (HKSE:1688) (HK.1688) is the global leader in business-to-business (B2B) e-commerce and the flagship company of Alibaba Group. Founded in 1999, Alibaba.com makes it easy for millions of buyers and suppliers around the world to do business online through three marketplaces: a global trade marketplace (www.alibaba.com) for importers and exporters, a Chinese marketplace (www.alibaba.com.cn) for domestic trade in China, and, through an associated company, a Japanese marketplace (www.alibaba.co.jp) facilitating trade to and from Japan. Together, its marketplaces form a community of more than 45 million registered users from more than 240 countries and regions. Alibaba.com also offers business management software solutions targeting small businesses across China under the “Alisoft” brand and incubates e-commerce talent for SMEs in China through Ali-Institute. Founded in Hangzhou, China, Alibaba.com has offices in more than 50 cities across Greater China, Japan, Korea, Europe and the United States.



About HiChina



HiChina, founded in 1996, is the leading Internet application service provider in China. HiChina is devoted to providing comprehensive Internet application services to businesses, which covers domain services, hosting services, email systems, Web site creation, as well as consultation services for E-commerce to assist businesses in applying E-commerce to their business. Having established a strong position in the Internet infrastructure industry in China, HiChina currently serves more than 200,000 paying enterprise members.

Aloha Radiant...Kiss My Grits!



In an excellent article written by Jason Brown for the Acadiana Bureau and published in 2The Advocate, he talks about Radiant Systems' Aloha POS system, the breach that occurred at several Louisiana restaurants using the system and the ramifications for some of the restaurant owners.  One of the victims, Mel's Diner wound up having to pay $50k+ for the whole ordeal.     Suffice it to say, when Mel's Diner received a letter from Visa, informing them they needed to conduct a Visa approved audit, "Kiss My Grits" wasn't an option...

"Keith Bond, owner of Mel’s Diner in Lafayette and Broussard, purchased Radiant’s POS Software in October 2007 for the company’s Broussard location, Mel’s Diner Part II.  The easy-to-use, touch-based system costs about $20,000 and was intended to replace the business’ reliance on handwritten guest checks.



The system had been in place for only a few months when Bond received a letter from VISA informing him that his system had been compromised. The letter stated that Bond needed to hire a forensic auditor to examine the extent of the breach.



If he refused, Bond could have been subjected to tens of thousands of dollars in fines and a possible revocation of his ability to use credit cards at the store.



He consented and paid about $19,000 for a VISA-approved audit, which allegedly confirmed the compromise.



The audit also found that the system had an insufficient firewall for added security, no anti-virus software on the point of sale terminals and that the seller, Computer World, had allegedly sold him an older unit packaged as new.



Bond said he was forced to hire technicians to secure and continuously monitor his system. As an added precaution, Bond said he reverted back to using a dial-up modem, which has built-in security. The system was never installed in his Johnston Street location in Lafayette.



After the audit, Bond received additional fines from VISA and notification that he was liable for up to $30,000 in charge-backs for the charges made on the stolen credit cards. In some cases, Bond said portions of his daily credit card transactions, or settlements, were withheld to pay back the fees.



Bond estimated the ordeal cost him about $50,000. Fortunately, he said he had enough in reserves to handle most of the costs.



“If you had hundreds of cards stolen, it could force you out of business,” Bond said.



Nationwide problem



Charles Y. Hoff, general counsel for the Georgia Restaurant Association and one of the attorneys assisting in the Lafayette lawsuit, said he has received a multitude of calls from restaurant owners all over the country regarding similar claims.  “It is not isolated and it is something that is a real concern on a national level,” Hoff said...

 Continue Reading at The Advocate

Discover® Small Business WatchSM: Small Business Economic Confidence Steady in December



Fewer See Economic Conditions in the Country Getting Worse





RIVERWOODS, Ill.- Economic confidence among America’s small business owners was steady in December as fewer of them think the U.S. economy is getting worse compared to November, and more see conditions for their own businesses getting better in the next six months, according to the Discover® Small Business WatchSM. The Watch index improved slightly in December to 77.0 from 76.5 in November.

“They’re still looking for more encouraging signs in the overall economy, but on a positive note, the number of them who see conditions for their own businesses getting better in the next six months increased for the first time since August.”

“Small business owners are entering 2010 on a cautious note,” said Ryan Scully, director of Discover's business credit card. “They’re still looking for more encouraging signs in the overall economy, but on a positive note, the number of them who see conditions for their own businesses getting better in the next six months increased for the first time since August.”



December Indicators:


  • The number of small business owners who think the economy is getting worse was down to 49 percent from 53 percent in November; while 24 percent of small business owners see the economy staying the same, up from 16 percent in November; 25 percent see the economy getting better, down from 28 percent in November; and 2 percent are not sure.

  • 22 percent see conditions for their own businesses getting better in the next six months, an improvement from 19 percent in November; but still in contrast to the 52 percent who see conditions getting worse, 24 percent who see things staying the same, and 3 percent who aren’t sure.

  • 35 percent rate the current economy as fair, up from 30 percent in November; while 61 percent rate it as poor, and 4 percent rate it as good or excellent.

  • 18 percent of owners say they will increase spending on business development activities such as advertising, inventories and capital expenditures in the next six months, 26 percent will make no changes, 51 percent plan to decrease spending, and 5 percent are not sure.

  • 51 percent of owners have experienced cash flow issues in the past 90 days, down 1 percentage point from last month; 45 percent of owners have not experienced cash flow issues, and 4 percent aren’t sure.

Financial Planning Poll: 62% of Small Business Owners Have a Retirement Plan

When asked about planning for the future, 62 percent of small business owners say they have a financial plan for their retirement, while 33 percent do not, and 5 percent are not sure.

Sixty-three percent say it is “somewhat or very likely” that they will have enough saved to last through their retirement, 25 percent say it is “not very likely,” 7 percent say it is “not at all likely,” and 4 percent are not sure.

Nearly three in four small business owners, 74 percent, say the recession has reduced their retirement savings, 19 percent say the recession had no impact, and 6 percent saw their retirement savings increase.

Of those owners who say their retirement savings have gone down:

  • 12 percent saw a decrease of up to 10 percent

  • 24 percent saw a decrease of 10 to 20 percent

  • 17 percent saw a decrease of 20 to 30 percent

  • 24 percent saw a decrease of 30 to 50 percent

  • 19 percent saw a decrease of more than 50 percent

  • 5 percent were not sure

Most Small Business Owners Make Their Own Investment Decisions

Fifty-six percent of small business owners say that they make their own investment decisions, 35 percent use a financial planner or other investment professional, and 9 percent are not sure. When asked if they have financial planning assistance through a spouse’s employer, 84 percent of owners say they do not, 13 percent say they do, and 4 percent are not sure.

Fifty-two percent of owners have an IRA account, and 29 percent of them have a Keogh, Solo 401(k) or a Simplified Employee Pension plan.



Few Planning Early Retirement


Small business owners seem to be in no hurry to stop working; and depending on how you phrase the question, roughly a third of them don’t ever plan to step down.

When asked at what age they plan to retire, only 13 percent said before age 60, 28 percent said between ages 60 and 65, 18 percent said between ages 65 and 70, and 9 percent will retire past 70. Not surprising – based on previous surveys – is that 30 percent said they do not plan to retire.

When asked what they eventually planned to do with their businesses, 23 percent will close them, 19 percent will transfer ownership to a family member, 13 percent want to sell, 6 percent will hire someone else to run it, and 3 percent aren’t sure. And similar to the age question, 36 percent responded that they do not plan to retire, down from 42 percent in August 2006.



The views and opinions expressed by small business owners and consumers who participate in the Small Business Watch survey are their own and do not necessarily reflect those of
Discover Financial Services or its affiliates.



About the Small Business Watch


The Discover Small Business Watch is a monthly index measuring the relative economic confidence of U.S. small business owners who have less than five employees, a segment that consists of 22 million businesses producing more than a trillion dollars in annual receipts. The Watch is based on a national random survey of 750 small business owners. It is commissioned by Discover Business card, which strives to offer the best business credit card for American small businesses, and is conducted by Rasmussen Reports, LLC (www.rasmussenreports.com), an independent survey research firm. The numeric index is calculated by assigning values to responses to a set of six consistent questions. The base value of the Watch was established at 100.0 based on surveys conducted in August 2006. In addition to generating the index, the Small Business Watch surveys small business owners every month on key issues, and polls 3,000 consumers four times per year to gauge purchasing behavior and attitudes towards small businesses. For past results and survey data, visit www.discovercard.com/business/watch. For information on Discover Business card, visit www.discovercard.com/business.



About Discover


Discover Financial Services (NYSE: DFS) is a leading credit card issuer and electronic payment services company with one of the most recognized brands in U.S. financial services. Since its inception in 1986, the company has become one of the largest card issuers in the United States. The company operates the Discover card, America's cash rewards pioneer, and offers student and personal loans, as well as savings products such as certificates of deposit and money market accounts. Its payments businesses consist of Discover Network, with millions of merchant and cash access locations; PULSE, one of the nation's leading ATM/debit networks; and Diners Club International, a global payments network with acceptance in 185 countries and territories. For more information, visit www.discoverfinancial.com.

Blackhawk Launches Virtual Gift Cards



Payments Source reports today that the BlackHawk Network is taking a page from CashStar's book and introducing virtual gift cards.  Here's a snippet:

Reacting to customer feedback on its Web site, GiftCardMall.com, Blackhawk Network Tuesday announced it is selling prepaid electronic gift cards from Bass Pro Shops, Sears Holding Corp. and J.C. Penney Co. Inc.



“When we relaunched the site last year we got a lot of feedback, and one of the suggestions was the flexibility to e-mail [gift cards],” Teri Llach, Blackhawk group vice president of, tells PaymentsSource.com. Consumers who visit the Web site can load between $5 to $200 into an electronic card account and also include a personalized message. The cards are free.



Recipients receive an e-mail and can print out the card information to use for in-store purchases.  They also can type in the card information to make purchases at the stores online, a service Llach claims differentiates Blackhawk’s card from CashStar Inc.’s. 



Earlier this year, CashStar was the first company to introduce print-at-home gift cards. At the time, observers said CashStar had the potential to change the market. Since then, the Portland, Maine-based company has added The Home Depot Inc. and Papa John’s Pizza to its list of merchant clients.

Continue Reading at Payments Source







VeriFone Prevails Again in Heartland Dispute

http://www.verifone.com
Federal Court Upholds VeriFone's Efforts to Offer Direct Support to Heartland Merchants as Judge Denies Heartland’s Preliminary Injunction Request



VeriFone Holdings, Inc. (NYSE: PAY) today announced that a federal court has completely rejected an effort to prevent VeriFone from offering direct support to merchant customers of Heartland Payment Systems (NYSE: HPY).



Finding that Heartland's contentions “contradict its own claims in this case,” U.S. District Judge Mary L. Cooper in the United States District Court for the District of New Jersey denied, in its entirety, Heartland’s request for a preliminary injunction that sought to prevent VeriFone from communicating its offer to provide direct and free support to Heartland merchants and further rejected Heartland's assertion that VeriFone made any untrue statements.



VeriFone announced November 3 that it would provide that support to prevent any disruption to merchants after determining that pending litigation over Heartland’s alleged infringement of a VeriFone patent is likely to impact Heartland’s ability to maintain service levels with its customers. VeriFone informed Heartland that its support relationships with Heartland would terminate effective end of day December 31, 2009. VeriFone further announced on November 5 that Heartland expects its merchants to contact VeriFone for support.



In an opinion dated December 23, Judge Cooper noted that Heartland had made contradictory claims over its ability to service its clients who are using VeriFone systems. The judge said Heartland’s own assertion in its previous court filings “suggests an ongoing dependence and foreseeable adverse consequences upon withdrawal of such support.”



“We’re pleased that Judge Cooper saw fit not to block our efforts to offer continual support to Heartland’s merchants for VeriFone systems and to find our statements correct,” said Douglas G. Bergeron, the Company's Chief Executive Officer. “Despite Heartland's considerable efforts we believe the right thing to do is to ensure that those merchants do not experience any disruption or degradation in the support they receive for their VeriFone system. We are actively encouraging Heartland merchants to register for direct support with VeriFone. Alternatively, we encourage merchants to sign processing agreements with one of the many organizations currently supported by VeriFone.”



Heartland is dependent on VeriFone for updates and support to the VeriFone operating system, runtime libraries, and in most cases the payment application. After December 31, the only way for Heartland merchants to ensure ongoing support and efficient operation is to register with VeriFone by that date at https://freesupport.verifone.com.



About VeriFone Holdings, Inc. (www.verifone.com)



VeriFone Holdings, Inc. (“VeriFone”) (NYSE: PAY) is the global leader in secure electronic payment solutions. VeriFone provides expertise, solutions and services that add value to the point of sale with merchant-operated, consumer-facing and self-service payment systems for the financial, retail, hospitality, petroleum, government and healthcare vertical markets. VeriFone solutions are designed to meet the needs of merchants, processors and acquirers in developed and emerging economies worldwide.







Reblog this post [with Zemanta]

Moneta and Equifax Agree to Provide Online Instant Credit Option

http://www.monetacorp.com

Moneta to leverage Equifax’s credit decisioning system to enable instant credit approval for online purchases



ATLANTA--(BUSINESS WIRE)--Moneta, a fast-growing online payment alternative to credit cards, announced an agreement with Equifax Inc. (NYSE:EFX), a global leader in information solutions, to utilize the Equifax credit decisioning system for a new instant credit feature for Moneta’s online payment wallet. Merchants accepting Moneta payments may now offer a range of bank-sponsored funding options to their customers including checking, savings, money market and now instant transactional credit lines underwritten by the sponsoring bank.
“Merchants are looking for customer-friendly, real-time transactional credit offerings for online purchases and consumers want simple, easy-to-use credit options,” said Dann Adams, president of Equifax’s Consumer Information Solutions. “We are pleased to team with Moneta to provide innovative solutions for comprehensive risk management and credit decisions in a real-time, online purchase setting.”

Moneta currently offers an easy-to-use online payment method that allows customers to fund online purchases directly from a bank account, without disclosing their personal financial information to the merchant. The instant credit feature, scheduled for release in early 2010, will extend the funding options of Moneta payments to include the extension of transactional credit for online purchases, in real-time. Moneta is primarily marketed and distributed through leading U.S. banks as an extension of their demand deposit account (DDA) service portfolio.



“In choosing an industry leader to drive our credit decisioning engine we selected Equifax, as a widely trusted partner of leading banks and financial institutions throughout the U.S.,” said Guido Sacchi, CEO of Moneta Corporation. “Moneta’s merchant and bank partners have a growing demand for transactional, instant credit offerings to drive sales, and the partnership between Moneta and Equifax provides them with an innovative, differentiated solution. Merchants and their customers will greatly benefit from the addition of instant transactional credit to Moneta’s funding options.”



About Moneta Corporation



Moneta Corporation is a leading payments company offering secure, convenient methods for consumers to pay online merchants directly from their checking, savings or money market accounts. Moneta partners with online merchants and banks to accept and process payments, while providing additional branding opportunities and revenue streams. Moneta’s rapidly growing partner network enables online retailers and travel providers to attract valuable customers with a preference for paying directly from their well-established bank accounts. Moneta is a privately-held company headquartered in Atlanta, Ga. For more information, visit www.monetacorp.com.



About Equifax (www.equifax.com)



Equifax empowers businesses and consumers with information they can trust. A global leader in information solutions, we leverage one of the largest sources of consumer and commercial data, along with advanced analytics and proprietary technology, to create customized insights that enrich both the performance of businesses and the lives of consumers.



With a strong heritage of innovation and leadership, Equifax continuously delivers innovative solutions with the highest integrity and reliability. Businesses – large and small – rely on us for consumer and business credit intelligence, portfolio management, fraud detection, decisioning technology, marketing tools, and much more. We empower individual consumers to manage their personal credit information, protect their identity, and maximize their financial well-being.



Headquartered in Atlanta, Georgia, Equifax Inc. operates in the U.S. and 14 other countries throughout North America, Latin America and Europe. Equifax is a member of Standard & Poor’s (S&P) 500® Index. Our common stock is traded on the New York Stock Exchange under the symbol EFX.

Goodbye PCI - Hello Encryption and Data Loss Prevention Products

December 27, 2009

Summary

More good news for Symantec Vontu, Fidelis, EMC  RSA, Voltage, Verdasys, Trend Micro LeakProof, Websense, McAfee Reconnex and PGP.  The arguably ineffective Breach Avoidance Rules championed by the Payment Card Industry (PCI DSS) are on their way out; and new solutions that rely on Encryption and Data Loss Prevention Products are emerging. Expensive lawsuits could be directed against the founders of PCI: American Express, Discover Financial, JCB, MasterCard and Visa International.

Analysis

Many of the speakers at the December 2009 Payment Card Industry Data Security Standard (PCI DSS) Compliance Conference in Sydney, were downbeat.
  • Speaker Stephen Wilson, said PCI DSS was a “patch” designed by payment card companies in the hope that they could avoid forcing merchants and financial institutions to use more complex, expensive and time-consuming procedures like encryption and two-factor authentication as a standard part of every transaction.

  • Speaker David Kaplan, Director of Security Consulting Practice, Earthwave said the claim by members of the PCI Security Standards Council that no organization that is PCI DSS compliant has been breached was wrong. So far in 2009, there have been over 350 breaches and over 100 million identities and card holder data stolen from companies who were PCI DSS certified.

Visa Inc. To Announce Fiscal First Quarter 2010 Financial Results on February 3, 2010





Visa Inc. will report its fiscal first quarter 2010 financial results on Wednesday, February 3, 2010. The results will be included in a press release, with accompanying financial information, that will be released after market close and posted on the Visa Investor Relations website.



Visa's executive management team will then host a live audio webcast beginning at 5:00 p.m. Eastern Time (2:00 p.m. Pacific Time) to discuss the financial results and business highlights.



All interested parties are invited to listen to the live webcast at http://investor.visa.com/. A replay of the webcast will be available on Visa's Investor Relations website for 30 days.

Concurrent with this press release, Visa will impose its customary "quiet period", during which time company executives will not be interacting with the investment community. This quiet period will extend until fiscal first quarter earnings are released on February 3, 2010.

About Visa: Visa operates the world's largest retail electronic payments network providing processing services and payment product platforms. This includes consumer credit, debit, prepaid and commercial payments, which are offered under the Visa, Visa Electron, Interlink and PLUS brands. Visa enjoys unsurpassed acceptance around the world and Visa/PLUS is one of the world's largest global ATM networks, offering cash access in local currency in more than 170 countries. For more information, visit www.corporate.visa.com

Reblog this post [with Zemanta]

Sunday, December 27, 2009

BofA Settles Security Breach...Liable for up to $850 Million



DOW JONES NEWSWIRES

A U.S. District Court judge in Kentucky on Wednesday gave preliminary approval to a settlement between Countrywide Financial Corp. and millions of customers whose financial data was exposed in a security breach, the Associated Press reports Thursday. The settlement calls for Countrywide, now owned by Bank of America Corp. (BAC), to give as many as 17 million victims of the breach free credit monitoring--includng anyone who obtained a mortgage and anyone who used Countrywide to service a mortgage before July 1, 2008. A consumer would be allowed up to $50,000 in reimbursements from Countrywide for each instance of identity theft. A "fairness hearing" in the case is scheduled for July in Louisville, Ky. 



A Bank of America spokeswoman said the settlement is "in the bank's best interest" to avoid additional legal expenses.





17,000,000 x $50,000 = $850 Million Dollars
 








First Data Buys ICICI



By Shrija Agrawal (VCCircle.com)





First Data Corporation, currently owned by PE giant KKR, has bought an 81% stake in ICICI Merchant Services.    ICICI Bank has concluded the sale of its network of electronic point of sales (PoS) terminals that accept credit and debit card payments to First Data Corporation (FDC), reports The Economic Times.



FDC is currently owned by private equity giant KKR. The bank has hived off its network of over 1.5 lakh electronic swipe machines to a separate company — ICICI Merchant Services.



The report adds that First Data has bought an 81% stake in the company which has been valued at a little over $90 million.   ICICI Bank expects that the specialised company will bring down transactions costs and also grow the payment network more efficiently. This is the first time that an Indian bank has hived off its PoS terminal network.  Other large banks might also follow the move of ICICI Bank. The bank was also reportedly looking to spin off its ATM assets earlier, but decided to hive off only PoS.



Some other banks like SBI have outsourced ATMs from Tata Communications and TCS, while Bank of India, United Bank and Dena Bank have outsourcing deals with Fidelity National Information Service.  Yes Bank tied up with the American payment processing company First Data Corporation (FDC) for an ATM deal, where the bank will pay transaction-based charges.




Continued...

Reblog this post [with Zemanta]

Saturday, December 26, 2009

Internet Security News: December 26th





This Free IT-Security news feed was compiled and is provided by E-Secure-IT; the most comprehensive and complete Business Risk Management Intelligence Service and IT-Security Risk and Threat Early Warning Service available in the market today.  They offer a 30 day complimentary subscription. 





Visit them at www.e-secure-it.com or email more-info@e-secure-it.com for more information on their available services.




































































































































































































































































Kaspersky Predicts Online Threats for 2010





(from spamfighter at 26-12-2009)





According to the security experts from Kaspersky Labs, in the next year (2010) the form of cyber assaults against users will change from assaults launched through applications and websites to those launched via file-sharing or P2P networks. The firm observed that attackers were popularly using the services due to their important role in distributing a large number of malicious infections, including for a very famous malware code for OS X.... read more»


















F-Secure Predicts E-Threats for 2010





(from spamfighter at 26-12-2009)





Internet security firm F-Secure, during the third week of December 2009, released a list of probable e-threats for 2010. The list reveals that the market share of Windows 7 will increase in 2010. Conversely, the overall market share of Windows XP will fall below 50%. Consequently, security will be enhanced and easy assaults in wealthy nations will get reduced. However, malicious assaults will shift to countries still using XP, especially developing countries.... read more»


















SQL Injections Looming on Private and Public Websites





(from spamfighter at 26-12-2009)





According to the X-Force security team of IBM, recent months have seen online assaults against databases, using the technique of SQL injection. An SQL injection attack involves the insertion of malware into an application to make the program issue illegitimate SQL commands so that the attacker can gain control over it for carrying out his sinister operations.... read more»


















Hackers' attacks rise in volume, sophistication





(from SFGate at 26-12-2009)





Security experts describe the typical hacker of 2009 as more sophisticated, prolific and craftier than ever. If anything, criminals will be remembered by the sheer number of attacks they unleashed upon the Web. While the year didn't see many technological leaps in the techniques hackers employ, they continued to expand their reach to every corner of the Internet by leveraging social media, infiltrating trusted Web sites, and crafting more convincing and tailored scams.... read more»


















Pre-Christmas DoS attack hits UltraDNS





(from thetechherald at 26-12-2009)





Limited to Northern California, earlier this evening, late last night for some of you, UltraDNS was hit with a Denial-of-Service attack that lasted for about an hour, which was felt by thousands of last minute shoppers online. The reach of the one hour outage is unknown as to its scale, but Amazon, as well as sites using Amazon’s EC2 and S3 services, experienced slowdowns or outright outages. While there was no real statement, Jeff Barr, the Lead Web Services Evangelist at Amazon.com, noted d... read more»


















Top 10 most read news articles of 2009





(from v3.co.uk at 26-12-2009)





The biggest news story of 2009 with V3.co.uk readers concerned the Conficker worm, which managed to infect a whopping nine million Windows PCs in just seven days in January. This was despite the fact that Microsoft had patched the vulnerability four months previously. It's a perfect example of why we should all keep our systems up to date with the latest fixes. The second most popular story was about Google pouring cold water on a theory that lines on the ocean floor revealed by its mapping t... read more»


















NIST Ready to Take On New Cybersecurity Tasks Cybersecurity





(from govinfosecurity at 26-12-2009)





Among the biggest fans of the National Institute of Standards and Technology are members of Congress familiar with safeguarding government IT systems who are sponsoring legislation to give NIST even more responsibilities in developing cybersecurity metrics. One measure increases NIST's role in developing international cybersecurity technical standards. It also charges NIST with creating IT security awareness and education campaigns for the public, improving inoperability of identity managemen... read more»


















Inmate gets 18 months for thin client prison hack





(from The Register at 26-12-2009)





A former prison inmate has been ordered to serve 18 months for hacking the facility's computer network, stealing personal details of more than 1,100 of its employees and making them available to other inmates. Francis G. Janosko, 44, received the sentence earlier this week in federal court in Boston after pleading guilty to the hacking offenses in September.... read more»


















More on Troj/JSRedir-AK - Large numbers of sites affected





(from Sophos at 26-12-2009)





Since first releasing detection (2 days ago) for Troj/JSRedir-AK SophosLabs have seen thousands of websites affected by it. Since blogging yesterday we have seen a few minor variants and have had to update the our detection. One of the updates has been to detect the malicious script when appended to HTML files within script tags as well as being appended to JavaScript files.... read more»


















Top 10 scams, ripoffs





(from sanmarcosrecord at 25-12-2009)





• Weight Loss Pill Free Trial Offers • Mystery Shopping • Lottery Scam • Friend/Family in Distress • Rescue/Debt Assistance • Phishing E-Mails/Spam • Job Hunter Scams • Memorabilia • Robocalls • Google Work from Home Scams... read more»


















Watch your cyber steps this festive season





(from Indiatimes at 25-12-2009)





This festive season can bring some unpleasant gifts for online shoppers. From fake Santa links, to Christmas themes on social networking sites that install botnets, to shopping websites that steal credit card details, hackers are on the prowl. There are already reports that computers in India also have been compromised.... read more»


















Top 10 highs and lows of 2009





(from v3 at 25-12-2009)





HIGHS 1. Windows 7 2. Apple defying the market 3. Android 4. Spam host shutdowns 5. Software-as-a-service LOWS 1. Job cuts 2. Digital Economy Bill 3. Budget cuts 4. Network neutrality 5. Botnets menace the web... read more»


















Top 10 Nessus Plugins For 2009





(from tenablesecurity at 25-12-2009)





1. Enhanced Web Application Testing Plugins. 2. Microsoft Windows SMB Shares Access. 3. Backported Security Patches (HTTP) 4. Conficker Detection (uncredentialed check) 5. Dell Remote Access Controller Default Password (calvin) for 'root' Account 6. Malware Infected Host 7. USB Drives Enumeration 8. PCI Test Requirements 9. Windows Remote Registry Enable/Disable 10. DD-WRT HTTP Daemon Metacharacter Injection Remote Code Execution.... read more»


















In and Out bound Protection of Data in Motion





(from gssamericainfo at 25-12-2009)





Reliable data security from leading products and expertise – clients rely on the GSS America advantages, proven in many real-world client implementations, to protect against attack. Business continuity preserved – users are safe and the network remains available. Incoming threats are blocked, including viruses, trojans, spyware, DOS attacks, and exploits of browser vulnerabilities.... read more»


















Social and SEO attacks, DDoS key vectors in 2010





(from securityvibes at 25-12-2009)





Next year will see rising IT budgets, massive politically-motivated DDoS attacks and continued social media hijacking, according to security experts. While the UK remains in recession according to the latest Office for National Statistics data, the US is expecting a financial lift for IT next year, claim analysts.... read more»


















Hacker Breaks Kindle's Proprietary E-Book Protection





(from enterprise-security-today at 25-12-2009)





Internet retailer Amazon.com had all the luck in getting its family of proprietary Kindle e-book readers into the hands of consumers while its rivals were faced with delays, but its luck may have turned. The Kindle's copyright protection has been hacked. An Israeli hacker who goes by the name Labba says he has been able to break the Kindle's digital-rights management protection, allowing its electronic books to be viewed on non-Kindle devices.... read more»


















Global Spam King Fined in Australia





(from enterprise-security-today at 24-12-2009)





A New Zealander was fined by an Australian court Tuesday after a guilty plea over his part in a syndicate capable of sending 10 billion spam e-mails a day. Lance Atkinson, was fined 210,000 Australian dollars (189,000 US dollars) for breaching the Spam Act 2003 in a case brought by the Australian Communications and Media Authority.... read more»


















6 security trends to watch in 2010





(from Government Computer News at 24-12-2009)





Security became a watchword for the nation during the first decade of the new millennium. The events of Sept. 11, 2001, exposed, in a single day, our many vulnerabilities and focused the nation like never before on securing the homeland from threats on many fronts. The quest for security continues as we enter 2010 facing persistent as well as emerging threats and risks, which include increasingly sophisticated and difficult-to-detect cyber attacks and new vulnerabilities and challenges relat... read more»


















I had a data breach, Now What?





(from Spaces.Live at 24-12-2009)





Hopefully you won’t have to answer this question, but more than likely you will. The headlines are full of stolen documents or hacked databases, but most of the data breaches never see the light of day. Why not? Because no one wants to talk about their failures and vulnerabilities. If I tell you that your confidential information is now making its way around the Internet, you will lose confidence in me.... read more»


















OSCON 2010 - O'Reilly Conferences, July 19-23, 2010 at the Oregon Convention Center in Portland, Oregon





(from Oreilly at 24-12-2009)





OSCON brings together over 2,500 experts, visionaries, and hackers in the trenches to explore all that open source has to offer. OSCON is the premier gathering place to gain exposure to and evaluate the new projects, tools, services, platforms, languages, software, and standards sweeping through the open source community. Whether you want to make it faster, more effective, or more efficient, open source helps you make it happen for the long term.... read more»


















Credit card provider suffers breach, personal data lost





(from Net-Security at 24-12-2009)





MBNA, the UK’s largest credit card provider, has confirmed that a laptop containing the personal details of its customers has been stolen from one of its third party contractors – NCO Europe Ltd – earlier this month. The information is said to include personal details, however, no PIN numbers were reported to be contained in the stolen data.... read more»


















2010 Threat Predictions: Staying Ahead of the Threat Curve





(from lumension at 24-12-2009)





For those who are determined to stay with the status quo regardless of the documented historical results, let’s take a look at what lies ahead for you in 2010: 1. Web 2.0 tools will become a hacker’s best friend. 2. Traditional IT security approaches are not enough. 3. The scope of data sold on the black market will widen. 4. Believe it not, people will continue to “not get” patch management.... read more»


















Web staggers under pre-Christmas DDoS attack





(from CNet at 24-12-2009)





Updated 6:10 p.m. PST: A customer support representative for Neustar, the company that provides the UltraDNS service to several e-commerce sites, confirmed that its network was hit by a DDOS attack targeting their California network in Palo Alto and San Jose. As of 6:15 p.m. PST, things seemed back to normal. The Internet Health Report also showed an improvement on the Qwest-Savvis line noted earlier, and Amazon's Web Services dashboard confirmed that while there were problems resolving DNS ... read more»


















Warning Out About Scammers Posing as Census Workers





(from newson6 at 24-12-2009)





U.S. Census workers will begin gathering information about you within the next few weeks. Someone from the bureau is likely to show up on your doorstep and speak with you face to face.But now scammers are posing as government workers to try to get access to your bank and credit card accounts. This has become such a problem that the Better Business Bureau put out an alert warning people not to give any information bank or credit card account to anyone claiming to be Census workers.... read more»


















Major security myths of 2009





(from TechRepublic at 24-12-2009)





To help prepare readers for the future, I’ll share my thoughts on ten major security myths I have encountered in 2009. Each of these is chosen for its prevalence, its perniciousness, or its publicity this year. They may even have been chosen for other reasons that begin with P. 1. Myth: Doing something right means you’re doing nothing wrong. 2. Myth: Anonymity and verification are mutually exclusive. 3. Myth: The GPL is needed to encourage project success. 4. Myth: Ubuntu Linux is the most... read more»


















Malware makers colocate servers, grab IPv4 address blocks





(from Arstechnica at 24-12-2009)





Malware distributors, apparently tired of facing the constant threats of disconnection, are taking advantage of lax background checks in the system for distributing IP address blocks and buying them directly. Address blocks, which cover a contiguous range of IP addresses, are typically reserved for legitimate institutions and businesses that can demonstrate a need for that sort of allocation. But, at the top level, there are only five regional registries, most of which cover large and cultur... read more»


















FBI Estimates Consumer Losses of over $150 Million to Rogue Anti-Virus





(from TechWhack at 24-12-2009)





In its press release last week, the Internet Crime Complaint Center, a partnership between the FBI and the National White Collar Crime Center (NW3C) reported that “the FBI is aware of an estimated loss to victims in excess of $150 million” from “Rogue” Anti-Virus. As part of his Internet Security Insider video blog series, Comodo CEO Melih Abdulhayoglu offers his unique, insider viewpoint on this type of threat and what to do about it.... read more»


















Lawyers scared of computers - Fear of own incompetence kills trees





(from The Register at 24-12-2009)





A Crown Court judge has blasted a lawyer's excuse for printing huge bundles of documents rather than delivering them on disc. The telling tale arrives via The Mirror's crime correspondent Jon Clements, who reports that at Wood Green Crown Court on Monday, Judge Francis Sheridan inquired as to why a pile of documents for a jury couldn't be delivered digitally. The paper version was said to be several inches thick.The CPS counsel told him: "We can't put that amount of personal data on a disc in... read more»


















Crown Prosecution Service too scared to use computers now





(from Mirror at 24-12-2009)





Insight into how pathetically risk averse and weedy some of our institutions have become yesterday at Wood Green Crown Court. Prosecutors were discussing with Judge Francis Sheridan the arrangements for a trial involving a huge amount of information, facts and figures which the jury would have to refer to during evidence. His Honour was staggered to learn the Crown Prosecution Service planned to print off all the pages and give them in a traditional "bundle" which would have been several inch... read more»


















Publisher asks Google, AT&T to unmask network intruder





(from The Register at 24-12-2009)





A federal judge has cleared the way for the publisher of GQ magazine to subpoena Google and AT&T in an attempt to learn the identity of a computer intruder who stole unpublished editorial content and posted it online. Sometime in September, an unknown thief accessed the computer network of Conde Nast and made off with more than 1,100 files containing pictures and editorial content for the December issue of GQ, Vogue and Lucky magazines, according to papers filed in US District Court in Manhat... read more»


















2010 data security trends: External attacks from the inside





(from Net-Security at 24-12-2009)





Generally, companies have viewed attacks as either coming from outside the network perimeter or from internal users abusing privileges. However, the line between internal and external is blurring as a result of several new attack vectors: Organized crime targeting specific companies by inserting “sleepers” to infiltrate the organization as employees or contractors, solely for the purpose of gaining access to sensitive data ... read more»


















Greatest security threats to education





(from Net-Security at 24-12-2009)





With education-related cyber-security threats expected to rise in 2010, WatchGuard is predicting the top threats facing schools, colleges and universities. Top threats include: Social Networks The number one threat to school and university networks is social networks, such as Facebook and MySpace. Unfortunately, social networks act as an ideal platform to launch a myriad of attacks against students and departments, including spam, viruses, malware, phishing and more. Adding to this, socia... read more»


















The 5 essential patches of 2009





(from NetworkWorld at 24-12-2009)





Fact: Everyone who patches is safer. Fact: Not everyone patches. The gap between the two facts is too deep for even security experts to explain, although they try, with theories running from the conspiratorial -- pirates hate to patch, they say, because they're afraid vendors, Microsoft mostly, will spy them out -- to the prosaic ... that people are, by nature, just lazy.... read more»


















Smartphone Attacks, Rogue Antivirus, Cloud Breaches Top 2010 Security Concerns





(from CIO at 24-12-2009)





The rise of the Conficker worm and Heartland Payment Systems' enormous data breach were two defining security events in 2009. What's in store for 2010? "It's going to get worse," says Patrik Runald, senior manager of security and research at Websense, who argues there has not yet been a year when things got better in terms of security and the wider Internet. Criminals have been mastering botnets, phishing scams and fake antivirus software sales, and 2010 will bring new waves of attacks that e... read more»


















Pharma link spammers invade Live Space





(from The Register at 24-12-2009)





Cybercrime affiliates of unlicensed pharmaceutical websites have begun moving on from attacks purely designed to poison Google search engine results, and are now targetting Microsoft's web properties. Search engine poisoners are actively making use of Microsoft’s Windows Live Spaces blog hosting environment, net security firm eSoft reports. Miscreants are creating accounts which they use only to push links to the pharma-fraud sites. As a result the search engine ranking of these spamvertised ... read more»


















Briton faces fraud charges over international debit card scam





(from Timesonline at 24-12-2009)





A British man has appeared in an Australian court to face charges over a multi-million dollar scam which police allege is the country’s largest debit card-skimming operation. British national Elangovan Ganeshamoorthy was extradited across the country from Sydney to Perth, in Western Australia, where the 36-year-old appeared in court on Wednesday. He faces charges of conspiracy to defraud following an international police investigation.... read more»


















Verizon Enlists Top E-threats for 2009





(from spamfighter at 24-12-2009)





Verizon Business in its latest security report highlights 15 most prevalent malicious attacks for 2009. These were spyware, SQL injection and remote control program attacks that targeted a large number of businesses. The report states that spyware and keyloggers were responsible for 19% the total data hacks during 2009. On the other hand, SQL injection and remote control program attacks accounted for 18% of the total incidences. Other attacks, though with very low impacts, were brute-force ha... read more»


















Know What Data is Being Collected, and Why





(from Cisco at 24-12-2009)





Privacy and information leakage has become one of my favorite topics on the Security blog. It seems that an enormous amount of information is being willingly plastered all over the Internet, from which significant value can be extracted (especially when combined with other public, or more likely private, datasets). The results are mind-boggling, and the implications are not fully comprehensible.... read more»


















Basic Laptop Security Prevents Identity Theft





(from information-security-resources at 24-12-2009)





In 2003, an estimated 1.5 million laptops were stolen worldwide. Today, that number has climbed to 2.6 million. That’s a 70% increase in just a few years. That’s one stolen laptop every 12 seconds. Laptop computers have been the source of some of the biggest data breaches of all time. 800,000 doctors were recently put at risk for identity theft when a laptop containing their personal data went missing from the Chicago-based Blue Cross and Blue Shield Association.... read more»


















Inmate Gets 18 Months for Hacking Prison Computer





(from CIO at 24-12-2009)





A former Massachusetts prison inmate has been given an 18-month prison sentence for hacking prison computers while he was incarcerated. Francis "Frank" Janosko, 44, was sentenced Tuesday in Federal court in Boston for abusing a computer provided by the Plymouth County Correctional Facility. The computer had been set up to help inmates with their legal research. In 2006, Janosko managed to circumvent computer controls and use the machine to send e-mail and cull data on more than 1,100 Plymo... read more»


















Top 10 Countries Sending Spam (Dec 14-Dec 20)





(from icsalabs at 23-12-2009)





As spam originating in other countries in the top 10 fell last week, spam from India, China, Colombia, and Argentina increased. Most notable were the large jump in spam originating in India and the drop in spam originating from Vietnam compared to the week before.... read more»


















Northern Ireland DFP rapped over data loss





(from ZDNet at 23-12-2009)





Northern Ireland's Department of Finance and Personnel has been penalised by the Information Commissioner's Office for a major loss of people's personal data. The department has been made to sign a formal undertaking to improve data security after it had 12 laptops stolen, two of which contained personal data on approximately 37,000 people. This included payroll, employment and health data, although not all records contained these categories.... read more»


















Keep children safe on social-networking sites





(from computeractive at 23-12-2009)





If chatter about social-networking sites and instant messaging (IM) bewilders you or leaves you cold, don’t worry. Opinion tends to be pretty equally divided as to their worth. At best, many detractors dismiss sites such as Facebook or Twitter or tools such as Aim and Windows Live Messenger as a waste of time. At worst they are perceived as a grievous threat to society and to our and our children’s safety. Social-networking sites are websites that enable people to publish and share informatio... read more»


















China outlines new web site regulations





(from v3 at 23-12-2009)





The Chinese Ministry of Industry and Information Technology (MIIT) has issued new internet regulations which could mean that many overseas web sites will be unavailable to Chinese readers. MIIT now demands that all domain management companies and internet service providers (ISPs) tighten controls over domain registration as part of the government's anti-pornography campaign.... read more»


















Beware of Christmas presents with non-volatile memory





(from h-online at 23-12-2009)





While everyone likes Christmas presents, recipients are well advised to supplement their joy with a small measure of distrust if they receive USB flash drives, MP3 players or digital photo frames. This applies to home as well as business users. These devices may contain malware – whether this was intended by the sender or not. Although applications on USB flash drives can normally only be started by the user, connecting any external flash memory device to a Windows PC can potentially lead to ... read more»


















Decline in Web, increase in P2P attacks predicted for 2010





(from Arstechnica at 23-12-2009)





Cybercriminals have already begun shifting their focus from websites to file-sharing networks when it comes to dispensing malware, and will continue with this trend throughout 2010. Security researchers at Kaspersky Labs predict that malicious applications, such as fake antivirus programs, will be on the decline next year as attacks over P2P go up, while more criminals look to target victims via mobile platforms. In its 2010 Cyberthreat Forecast, Kaspersky Lab said that it expects an increase... read more»


















Companies never safe from cybercrime: Symantec boss





(from Sydney Morning Herald at 23-12-2009)





IT managers who believe they are protected against cybercrime should think again, according to the boss of the world's largest security company. Enrique Salem, president and CEO of Symantec, owner of Norton and Message Labs, said in an interview the business of cybercrime had become so professional, no implemented solution was protected from future advances in criminal attacks. “We have countries attacking countries, criminals attacking individuals," he said.... read more»


















The Top 10 tech trends of 2009





(from CNN at 23-12-2009)





Engineers didn't make huge improvements to technology in 2009. The year's big tech names -- Twitter, Facebook, Google, Apple, Amazon -- all existed before January. Instead, this is the year technology changed us. At year's end, we're connected to each other and to the Internet like never before. In 2009, we carried tiny computers in our pockets, through which we fed the Internet constant real-time info about where we were and what we were doing.... read more»


















Mobile networks line up to bash net snooping plan





(from The Register at 23-12-2009)





Every UK mobile network has serious objections to plans to intercept and store details of every communication via the internet, Home Office documents reveal. Submissions to a government consultation from 3, O2, Orange, T-Mobile and Vodafone highlight the strength of industry concern over the Interception Modernisation Programme (IMP), which aims to capture lists of online contacts and log all website visits and VoIP calls.... read more»


















China moves closer to a smut-free internet





(from The Register at 23-12-2009)





China, which last week effectively ended its citizens' right to register a .cn web address, will now only allow access to websites which have been fully registered with the authorities. Individuals will now need a business licence to register a web address. The Ministry of Industry and Information released more details of measures it says are designed to remove pxxxographic content from China's version of the internet. The reality is that changes are likely to remove a lot more than just smut... read more»


















Marcus Ranum: The Biggest Security Threats Getting the Least Attention





(from Bankinfosecurity at 23-12-2009)





Marcus Ranum has a unique take on the biggest information security threats to organizations and individuals. A renowned expert in secure systems and design, Ranum, currently the CSO of Tenable Network Security, offers a new look at topics such as the risks of cloud computing and what he calls the myth of cyber warfare.... read more»


















BlackBerry Service Hit by Second Outage in a Week





(from PC World at 23-12-2009)





An outage hit BlackBerry smartphone service in the Americas on Tuesday night, operator Research In Motion confirmed via its support service. The outage is the second to affect users in less than a week. "Some BlackBerry customers in the Americas are currently experiencing delays in message delivery," said a recorded message on the BlackBerry support phone line. "Our technical teams are actively working to resolve this issue for those impacted. We apologize for any inconvenience."... read more»


















Intel Breach Reveals Passport Information





(from praetorianprefect at 23-12-2009)





Unu, has demonstrated an attack on an Intel web property. This site handles online registrations for channel partner events and that has been demonstrated to have a SQL injection vulnerability that outputs a database table appearing to contain personally identifiable information (PII). It is unclear whether Intel has been notified ahead of the blog post, but the affected web site https://channeleventsponsors.intel.com has been taken down.This web site has been the subject of a previous attack... read more»


















Cyber criminals become their own ISPs





(from Help Net Security at 23-12-2009)





Hounded by law enforcement agencies and security experts, cyber criminals have been witnessing the ISPs and hosting providers of their botnets being shut down at a greater pace then ever. But, where there's a will, there's a way, and the answer to this problem seemed obvious - they would set up their own data centers, be their own ISPs. While this is difficult to achieve in the U.S. region.... read more»


















As attacks increase, U.S. struggles to recruit computer security experts





(from Washington Post at 23-12-2009)





The federal government is struggling to fill a growing demand for skilled computer-security workers, from technicians to policymakers, at a time when network attacks are rising in frequency and sophistication. Demand is so intense that it has sparked a bidding war among agencies and contractors for a small pool of special talent: skilled technicians with security clearances. Their scarcity is driving up salaries, depriving agencies of skills, and in some cases affecting project quality, indus... read more»


















Hackers break Amazon's Kindle DRM





(from The Register at 23-12-2009)





An Israeli hacker says he has broken copyright protections built in to Amazon's Kindle for PC, a feat that allows ebooks stored on the application to work with other devices. The hack began as an open challenge in this (translated) forum for participants to come up with a way to make ebooks published in Amazon's proprietary format display on competing readers. Eight days later, a user going by the handle Labba had a working program that did just that.... read more»


















Ten 2010 IT Security Predictions, Part 2: Schmidt and ICSA Labs





(from CSOonline at 23-12-2009)





As 2009 draws to a close and a new decade dawns, CSOonline has reached out to some of the industry's best known security pros in search of insight on what the next 12 months and beyond have in store for our IT and cyber infrastructure. We started last week with Mark Weatherford, chief information security officer for the State of California, and Dan Kaminsky, network security specialist, director of pen testing at IOActive and discoverer of last year's massive DNS flaw.... read more»


















ENISA Quarterly Review, 4th Quarter 2009 - Resilience, Incident Reporting and Exercises - Awareness Raising and Security Status





(from Enisa at 22-12-2009)





This edition includes articles following an open call for contributions. Here is a quick sample of the articles you will find in this issue organised in thematic areas: * A Letter from the Executive Director * A Word from the Editor * Resilience - Measuring Resilience - the Next Challenge - ENISA's Good Practice Guide on National Incident Reporting Schemes - Good Practice Guide on National Exercises - The ENISA Virtual Working Group on Providers' Measures for Resilience * Awa... read more»


















The Effectiveness of Antivirus on New Malware Samples





(from Cisco at 22-12-2009)





During the course of security research we often acquire new malware samples. We typically first try to determine what we have acquired and if it is a new or otherwise unknown malware sample or if it is a mutation of something that we have already seen. There are several ways in which a sample can be tested, but the simplest way is to compare the MD5 checksum of the malware sample against other known checksums—several services exist where you can look up the hash of a sample, such as Malware Hash... read more»


















PennDOT computer heist remains unsolved





(from Citizensvoice at 22-12-2009)





Three years after a mysterious heist of computer equipment from a state driver's license center, police are still unsure why the crooks targeted the state Department of Transportation building. The motive behind the sophisticated November 2006 burglary at the Wilkes-Barre Driver's License Center baffled police. They wondered whether the motive was to access personal information for identity theft, or maybe use the equipment to produce fake identification cards.... read more»


















FISMA compliance for federal cloud computing on the horizon in 2010





(from TechTarget at 22-12-2009)





At the end of 2009, cloud computing isn't a bright, shiny toy on the horizon for the enterprise or government. IT professionals, by and large, know what cloud computing is, though they are still skeptical. They just aren't sure if they want to adopt the public cloud, especially for sensitive data or mission-critical applications. Amazon.com Inc. has completed a Statement on Auditing Standards (SAS) No. 70 Type II compliance audit of its Amazon Web Services cloud computing service, but enterpr... read more»


















Community colleges' library server hacked





(from fayobserver at 22-12-2009)





Nearly 51,000 people in North Carolina are finding out that about four months ago someone hacked into a library server containing their personal information. Megen Hoenk, a spokeswoman for the state Community College System, said the hacker did not access Social Security numbers or driver's license numbers, which were stored on the server.... read more»


















Calling on Leakers to Help Document Local Misdeeds





(from nytimes at 22-12-2009)





The organization has applied for a $532,000 two-year grant from the Knight Foundation to expand the use of its secure, anonymous submission system by local newspapers. The foundation’s News Challenge will give as much as $5 million this year to projects that use digital technology to transform community news.... read more»


















Best and worst of 2009: Internet finds





(from washingtonpost at 22-12-2009)





1. Neda Proof that memes can be meaningful, the video and Twitter tributes to a young Iranian woman's death galvanized a movement -- online and in real life. JK Wedding Entrance Dance 33 million YouTube viewers might disagree, but something as stunty as a choreographed wedding march should have been either a whole lot better or a whole lot worse.... read more»


















Security: Cybercrime Vulnerabilities and Targets in 2010





(from channelinsider at 22-12-2009)





Cloud computing and virtualization may promise big business benefits, but a new future threat report from security vendor Trend Micro says these very technologies may increase cybercrime by criminals looking to exploit them. And that’s just the beginning. Channel Insider takes a deeper look at the report’s biggest threat predictions for enterprises and end users.... read more»


















International School Safety Convention to be held in Denver, April 22-23, 2010





(from School Safety Partners at 22-12-2009)





Organized and moderated by international school safety leader Michael Dorn, in association with the Denver-based groups, School Safety Partners and the Foundation for the Prevention of School Violence. Designed for decision-makers and influencers: * Lawmakers * Foundation Executives * Federal Agency Executives * State Education Leaders * Superintendents * Private Sector Executives * Grant Project Managers * School Safety Center Executives * Inter... read more»


















Five Myths About Cybersecurity





(from executivebiz at 22-12-2009)





The Internet is the global communications and information infrastructure that provides the medium for communication and computation that facilitates the provisioning of numerous applications and infrastructure services, including e-mail, on-line banking, data storage, and quantum computing power. It brings with it promises of economic development and prosperity, scientific discovery, increased political participation, and ever changing social networks through which we are connected in ways once... read more»


















Kaspersky issues 2010 cyberthreat predictions





(from iTWire at 22-12-2009)





According to security vendor Kaspersky Lab, 2010 will see several changes in the nature of malware and how it spreads, including new attacks on mobile platforms. Kaspersky has released its "2010 Cyberthreat Forecast," making six predictions about the nature of the security landscape next year. First, Kaspersky predicts "a rise in attacks originating from file sharing networks" accompanied by a shift away from attacks via websites and applications.... read more»


















Top 8 Security Threats of 2010





(from Bankinfosecurity at 22-12-2009)





Over the past several years, law enforcement investigations into cyber crime have uncovered global networks of organized crime groups, including overseas criminal organizations (many based in Eastern Europe) that hire and direct hackers. Rob Lee, senior forensics investigator at Mandiant, a risk assessment firm, says the battle between "us and them" increasingly pits the financial services industry against organized crime organizations. "The days of the Maginot line of information security ar... read more»


















Top 10 Identity Theft Predictions For 2010





(from information-security-resources at 22-12-2009)





More Scams: The recession will lead to more scams. Whenever our nation has faced a difficult time, thieves have found a way to use the problem to their advantage. In my adult life, I’ve never seen more variations of old scams and the degree of sophistication in newer scams. 2. Job Scams: Criminals will take advantage of increasing unemployment rates by tricking desperate people searching for job listings. These fake job listings and work-at-home scams will eventually end with the job seeker p... read more»


















White House Picks New Cyber Coordinator





(from The New York Times at 22-12-2009)





The White House has tapped a corporate cyber security expert and former Bush administration official to lead the effort to shore up the country's computer networks and better coordinate with companies that operate 80 percent of those critical systems. Howard A. Schmidt, a former eBay and Microsoft executive, will become the government's cyber security coordinator, weathering a rocky selection process that dragged on for months, as others turned the job down.... read more»


















O2’s network crashes again





(from IT Pro at 22-12-2009)





O2 has again left its customers with data problems across its network and has yet to indicate when things will be up and running. The mobile provider confirmed via Twitter yesterday that some of its customers were having data problems and said the services would be back up that night. Today, the company tweeted just after midday saying the problem was still affecting customers, but this time offered no deadline for a fully functional service.... read more»


















auDA: No govt request to kill Conroy site





(from ZDNet at 22-12-2009)





Australian Domain Name Administrator (auDA) decided to place newly registered domain www.stephenconroy.com.au on the pending deletion list using its own procedures, not because of a request from the Communications Minister, the administrator said today. "We were not contacted by anyone in the government," auDA CEO Chris Disspain told ZDNet.com.au. "This was picked up by our normal checks and balances." The site was being used to lambast Stephen Conroy's internet service provider level filteri... read more»


















Microsoft's 'whitelist' helps hackers, says Trend Micro





(from ComputerWorld at 22-12-2009)





By recommending that users exclude some file extensions and folders from antivirus scans, Microsoft may put users at risk, a security company said today. In a document published on its support site, Microsoft suggests that users do not scan some files and folders for malware as a way to improve performance in Windows 2000, XP, Vista, Windows 7, Server 2003, Server 2008 and Server 2008 R2. "These files are not at risk of infection. If you scan these files, serious performance problems may occu... read more»


















Brittany Murphy death exploited by hackers





(from Webuser at 22-12-2009)





Cybercriminals are already exploiting the news of actress Brittany Murphy's death in 'scareware' scams, experts have reported. Cybercriminals pushing 'scareware' or fake anti-virus software are exploiting the news of Brittany Murphy's death. Murphy is thought to have suffered a cardiac arrest at around 0800 Pacific Time (1600GMT) on Sunday, with the first reports appearing on celebrity news site TMZ.com. Just hours later, researchers at Finnish security firm F-Secure reported that cyber... read more»


















Santa's Naughty-Nice Database Hacked





(from PCmag at 22-12-2009)





A spokes-elf for Santa Claus has acknowledged that the database posted recently at WikiLeaks was indeed the comprehensive 2009 list of which kids have been naughty and which were nice, according to this report. Speculation of the source for the leak runs from East-European hackers to a renegade reindeer. North Pole sources said that future access to the database would be restricted based on a "need to know." For more Information click the following URL: http://wikileaks.org/wiki/Main_Page... read more»


















UK retail Wi-Fi security still patchy





(from The Register at 22-12-2009)





Wi-Fi security in UK retail environments is improving, but shops remain vulnerable to the sorts of attacks carried out as part of the infamous TJX credit card heist. The cybercrooks, who lifted more than 21 million credit card records, leapfrogged onto the retailer's credit card database after first breaking into the wireless network of a regional store, a subsequent investigation ahead of upcoming US trials revealed. The incident ought to have acted as a wake-up call to retailers worldwide, ... read more»


















Secret neo-Nazi documents published - 11 membership lists about to go online





(from The Register at 22-12-2009)





Wikileaks is in the process of making a cache of documents and files from eleven different neo-Nazi organisations readable, and readily available, online. The membership records and private messages are currently being formatted to make them easy for non-techies to read and will be released on the Wikileaks site shortly. The raw data is already available but needs formatting so: "your grandmother can read them and google can find them... Journalists won't write about it otherwise." The site i... read more»


















Scareware scammers exploit Brittany Murphy's death





(from The Register at 22-12-2009)





Actress Brittany Murphy's sudden death, just like Michael Jackson's untimely demise before her, has quickly been exploited by scareware scammers. A spike in searches on Murphy's death has been taken as a theme for Black Hat SEO attacks, designed to push sites that have been hacked to redirect surfers to scareware portals into prominence in search engine results.Windows users who click on links to poisoned search results get exposed to a fake anti-virus scan, designed to frighten users into bu... read more»


















The 12 scams of Christmas





(from viruslist at 22-12-2009)





My colleague Tanya has just posted over on our Russian site about losses caused by Internet fraudsters in England and Wales. If you want to practice your Russian, hop over there, and take a look! Even though we're a Russian company, we know that most people in the UK (including me!) prefer to get their news in English. So here's a few facts and figures: In a recent statement, the Office of Fair Trading estimated that losses caused by Internet fraud amounted to £14 billion per year. That's ... read more»


















Cybercrime methods continue to evolve to lure business and users alike





(from SecurityPark at 22-12-2009)





In 2010, further adoption of cloud, social media and virtualisation technologies will continue to blur the network parameter, while new cybercriminal methods such as ransomware and crime as a service will lure in unsuspecting users and threaten the enterprise at large. Security postures must move from a container-centric approach that is tied to a physical locale to a data and information-centric security design. To do this, organisations – large and small – should consider a layered, central... read more»


















Drop in .CN Spam after NIC Changes Registration Policy





(from Softpedia at 22-12-2009)





Security researchers point out that spam containing links to abusive .cn domains is on the decline. This trend seems to be related to new domain registration requirements recently introduced by China's Internet Network Information Center (CNNIC). On December 11, CNNIC announced that a stricter registration procedure would be introduced for .cn domains. The new regulation states that "Domain name applicants need to submit the formal paper based application material when making the online appli... read more»


















Rogue AV Scams Result in US$150M in Losses





(from TrendMicro at 22-12-2009)





Tricking users into downloading rogue AV is an age-old cybercriminal tactic that still works. Hence the continuous rise in the number of rogue AV pushed to unwitting scam victims up to this day. In fact, the FBI just recently warned the public about the threat that rogue AV software poses, saying this has resulted in more than US$150 million in losses to victims. The earliest rogue AV ploys relied on scareware tactics that resorted to warning users of supposed infections. The shift toward a m... read more»


















Microsoft Virus Scanning Recommendations Bring Risks





(from TrendMicro at 22-12-2009)





We have recently received queries from customers about the official exclusion list recommendations from Microsoft. It seems that they have published a Knowledge Base entry that lists down recommendations to improve performance in Windows when running antivirus scanners. This list recommends customers to exclude certain extensions and folders from antivirus scanning. Now, although it actually makes sense to stop checking Windows Update and some Group Policy-related files if you really want to ... read more»


















Ten 2010 IT Security Predictions, Part 2





(from Network World at 22-12-2009)





As 2009 draws to a close and a new decade dawns, CSOonline has reached out to some of the industry's best known security pros in search of insight on what the next 12 months and beyond have in store for our IT and cyber infrastructure. Today we continue with predictions from Howard Schmidt, former eBay CISO and vice chairman of the President's Critical Infrastructure Protection Board, and ICSA Labs, a vendor-neutral testing and certification lab for hundreds of security companies.... read more»


















Cybercriminals Go to the Cloud?





(from TrendMicro at 22-12-2009)





In an article by Dancho Danchev, he illustrated Trend Micro’s prediction that cloud hosting services such as Amazon EC2M can be easily used for fail-over command and control (C&C) botnet services. Just recently, Trend Micro had an issue with some IP ranges from the Amazon EC2 data centers. Based on the procedures of our email reputation database, active spamming IP addresses are automatically blocked.... read more»


















Hacker Taps Into College Library Server





(from esecurityplanet at 21-12-2009)





Officials for a community college system in North Carolina this week acknowledged that someone managed to hack his or her way into a server housing the Social Security and driver's license numbers of more than 51,000 library patrons. The data breach affected students and local residents who used computers in the libraries at 25 separate campuses throughout the Tar Heel State in the past year. A spokeswoman for the community college system said officials are in the process of notifying all ... read more»


















Episode 30 of the Who and Why Show - Episode 30: Routing Security





(from YouTube at 21-12-2009)





In the 30th episode of Team Cymru's 'The Who and Why Show', we're joined once again by John Kristoff to talk about Router and Routing Security. We'll cover some common mistakes folks make, quick wins plus some longer term fixes you might want to implement to secure your networks. More Information : www.youtube.com/teamcymru... read more»


















Cyber Challenge tests nation's top hackers





(from CNN at 21-12-2009)





With the coolness of a card shark at the final table of the World Series of Poker, Matt Bergin pulls the hood of his brown sweatshirt over his head and concentrates on the task at hand. The task: hacking into as many target computers as he can and then defending those computers from attacks by other skilled hackers. Other skilled hackers like Michael Coppola, 17, a high school senior who, at this very moment, is hunched over a keyboard in his Connecticut home.... read more»


















Register for Security Log Secrets - Los Angeles, January 25-27, 2010





(from Randy F. Smith at 21-12-2009)





My Security Log Secrets training seminar in Los Angeles is approaching fast. Here's a chance to save if you register before the end of the year. Use coupon code 2009 and my eStore will take off $200. Here's the full detail about the upcoming training event: Many of you have expressed interest in my Security Log Secrets in-person training if I ever scheduled a seminar at a public venue and date. Choosing the right date and venue makes all the difference in getting enough attendees in orde... read more»


















The 2010 Government Information Technology Executive Council (GITEC) Summit





(from gitecsummit at 21-12-2009)





The GITEC Summit (formerly Information Processing Interagency Conference) is the premier forum for government leaders, industry and academia to share ideas, challenges and successes surrounding the implementation, management and use of Information Technology. The theme of the conference is IT Innovations Solving Complex Business Challenges. Key focus areas for the conference include: What are the biggest challenges for the largest upcoming projects What New Technologies can be helpful What... read more»


















The 5th International Conference for Internet Technology and Secured Transactions (ICITST-2010)





(from icitst at 21-12-2009)





The 5th International Conference for Internet Technology and Secured Transactions (ICITST-2010) is Technical Co-sponsored by IEEE UK/RI Communications Chapter. The ICITST is an international refereed conference dedicated to the advancement of the theory and practical implementation of secured Internet transactions and to fostering discussions on information technology evolution. The ICITST aims to provide a highly professional and comparative academic research forum that promotes collaborative e... read more»


















31st IEEE Symposium on Security & Privacy





(from oakland31 at 21-12-2009)





The 2010 symposium marks the 31st annual meeting of this flagship conference. Since 1980, the IEEE Symposium on Security and Privacy has been the premier forum for presenting developments in computer security and electronic privacy, and for bringing together researchers and practitioners in the field. The symposium will be held May 16-19 at the Claremont Resort in Oakland, California.... read more»


















InfoSec World Conference & Expo 2010





(from Misti at 21-12-2009)





The event features over 70 sessions, dozens of case studies, 9 tracks (including a hands-on hacking techniques track), 12 in-depth workshops, 3 co-located summits and an exhibit hall showcasing the industry’s leading vendors. With the primary objective of providing top-notch education to all levels of information security and IT auditing professionals, InfoSec World delivers practical sessions that give you the tools to strengthen your security without restricting your business!... read more»


















Boston SecureWorld Expo 2010





(from secureworldexpo at 21-12-2009)





SecureWorld Expo provides security education and training with nearly 60 sessions including: Cloud Computing, End Point Security, Data Privacy, Risk Management, PCI Compliance, Cybercrime and much more. Exhibit floor featuring nearly 50 exhibitors with the latest products and services available to effectively secure your enterprise. Earn 12-16 CPE credits toward your CISSP certifications. SecureWorld regional conferences deliver the most affordable, highest quality security education, trai... read more»


















Irish spam tides rise





(from Tech Central at 21-12-2009)





A rise in spam e-mails in Irish has been observed by Symantec, the world's largest security software company, in its recent State of Spam report. These e-mails are designed to get users to open them and then click on malicious links, which can leave a laptop, PC or mobile device open to viruses. The Irish spam messages can sometimes be identified by their suspicious phrasing and spelling by fluent speakers, a result of cybercriminals using free online translators which often produce spelling ... read more»


















Cybercrooks Target File-Sharing Networks





(from PCWorld at 21-12-2009)





This year is on its way out and seemingly cybercriminals are also planning their year ahead. Secure content management solutions developer Kaspersky Lab has outlined the threats it expects to see in 2010 as a result of cybercriminal activity. Kaspersky Lab was expecting a rise in the number of global epidemics in 2009 but this year was marked by sophisticated malicious programs with rootkit functionality. Corporates and individuals struggled with the Kido worm (Conficker), Web attacks and bot... read more»


















Malware Opens Door to Possible Information Exposure





(from gantdaily at 21-12-2009)





A computer in the Dickinson School of Law that contained 261 Social Security numbers from an archived class list was found to be infected with malware that enabled it to communicate with an unauthorized computer outside the network. "Malware" is short for malicious software and refers to any software designed to cause damage to a single computer, server, or computer network, whether it's a virus, spyware, worm or other destructive program. ... read more»


















Lack of laptop security leads to ID theft





(from Ciol at 21-12-2009)





In 2003, an estimated 1.5 million laptops were stolen worldwide. Today, that number has climbed to 2.6 million. That's a 70 per cent increase in just a few years. That's one stolen laptop every 12 seconds Laptop computers have been the source of some of the biggest data breaches of all time. 800,000 doctors were recently put at risk for identity theft when a laptop containing their personal data went missing from the Chicago-based Blue Cross and Blue Shield Association... read more»


















'Pxxx' Among Top Search Terms for Kids





(from Mashable at 21-12-2009)





In a somewhat worrying piece of news, security firm Symantec has released the top search terms by kids in 2009. Topping the lists: “YouTube”, “Google”, “Facebook”, “sex” and “porn”. While that result set might not be surprising in the teen search rankings, it’s interesting to note that “porn” ranks 4th in the “7 and under” category, receiving more searches than “Club Penguin” and “Webkinz“. Meanwhile, “sex” is fourth for teens and tweens alike.... read more»


















Lavasoft Lists Online Threats for 2010





(from spamfighter at 21-12-2009)





Lavasoft, a Sweden-based computer security purveyor, has recently come up with its list of top ten predictions and security trends for 2010. The list, released in the second week of December 2009, predicts that the top position will be occupied by malware assaults on Windows 7. With launch of the Microsoft's latest operating system (OS), the company aims to substitute Windows XP as the most preferred OS. With more and people installing Windows 7 on their systems, malware developers will also ... read more»


















Russia, U.S. teaming up to prevent cybercrime





(from Times call at 21-12-2009)





The United States has begun to engage Russia in discussions about threats to national security from Internet-based computer attacks. The two nations look at this issue differently, but in the end, this issue needs discussion and resolution on an international scale. Our nation’s economic system is dependent - and more so by the day - upon computer networks that operate over the Internet. Banking, credit card processing, retail and wholesale order placement, sales transactions of all kinds, me... read more»


















2010 cyberthreat forecast: Attack vectors





(from Net-Security at 21-12-2009)





2009 was dominated by sophisticated malicious programs with rootkit functionality, Conficker, web attacks and botnets, SMS fraud and attacks on social networks. With the start of 2010 quickly approaching, researchers and analysts from Kaspersky Lab have come up with a list of six predictions for what will be the New Year’s greatest threats and newest attack vectors. A rise in attacks originating from file sharing networks. In the coming year we will see a shift in the types of attacks on user... read more»


















Film review site hacked





(from Certifiedbug at 21-12-2009)





The Register reports that hackers exploited a vulnerable PHP script on the movie review site, ‘Ain’t It Cool’, which redirected visitors over a 90-minute period on Thursday morning to a server containing a malicious Adobe Reader file. The booby-trapped PDF, according an analysis by researchers at Praetorian Prefect, exploited two vulnerabilities in Adobe Reader that the company has already fixed. When the file is opened by unpatched versions of Reader, it launches malicious shell code that hi... read more»


















Rackspace Outage Has Limited Impact





(from Yahoo News at 21-12-2009)





Rackspace experienced an outage yesterday--a recurring issue this year for the hosted data center provider--which took down a number of high profile sites including the popular blog site TechCrunch. No network is impervious to outages, but a company like Rackspace needs to provide consistent and reliable service.... read more»


















Plan to meter traffic called 'bad for Internet'





(from chinapost at 21-12-2009)





China wants to meter all Internet traffic that passes through its borders, it has emerged. The move, which would allow countries that currently receive no payment for use of their lines to generate income, would require international agreement. It is being discussed by the United Nations (U.N.) body in charge of Internet standards, reported BBC News.But a European Union cyber security expert has warned that the plan could threaten the stability of the entire Internet, said the report.... read more»


















1st European Workshop on Internet Early Warning and Network Intelligence





(from Europa at 21-12-2009)





Today a larger scope has to be taken into account when assessing the security of networks. However, large scale, collaborative detection efforts have been difficult. Internet Early Warning Systems (EWS) started addressing this a couple of years ago. They enable piecing together information from different parts of the Internet in order to get the big picture - while ideally leaving contributors in control of their data. EWS still require a lot of research efforts and improvements in order to keep... read more»


















Key DHB computers back on line after virus





(from 3news at 21-12-2009)





Computers in key clinical areas of Waikato District Health Board (DHB) are today up and running after being hit by a virus this week. About 3000 computers across the DHB's network were infected with the Conficker virus, forcing a complete shutdown after the worm was spotted about 2am on Thursday.... read more»


















Phishing attempts on the rise and growing





(from newsabahtimes at 21-12-2009)





The number of phishing attempts is on the rise and accelerating, according to an advisory released by the Cyber999 Help Centre of CyberSecurity Malaysia. The Cyber999 Help Centre has been receiving numerous reports from local internet users regarding phishing websites hosted overseas. These look exactly like that of some of the well-known local bank’s, e-banking websites.... read more»


















Cybercrooks Target File-Sharing Networks





(from PCWorld at 21-12-2009)





This year is on its way out and seemingly cybercriminals are also planning their year ahead. Secure content management solutions developer Kaspersky Lab has outlined the threats it expects to see in 2010 as a result of cybercriminal activity. Kaspersky Lab was expecting a rise in the number of global epidemics in 2009 but this year was marked by sophisticated malicious programs with rootkit functionality. Corporates and individuals struggled with the Kido worm (Conficker), Web attacks and bot... read more»


















Online buyers need protection: security expert





(from CBC News at 21-12-2009)





Canadians hoping to avoid malls and buy their holiday gifts online should be aware that not all websites are using the latest security encryption, the head of an Ottawa technology firm says. Mike Borza, chief technology officer at Elliptic Technologies, a company that specializes in security design for devices such as cellphones and laptops, said the government should enact new laws to protect consumers. Borza said consumers should make sure their web browser shows a lock icon when they're... read more»


















Internet cafes on police radar





(from Times of India at 21-12-2009)





The district police is planning to carry out an intensive checking of internet parlours as part of ensuring foolproof security arrangements ahead of the month-long Magh Mela. SP city Awadhesh Kumar Vijeta informed that though checking of internet cafes is a routine affair and action is initiated against erring owners for not following rules laid down by the police, the vigil is beefed up during festive or special occasions when the threat perception is higher.... read more»


















Softpedia's Guide to Free Security – Part I





(from Softpedia at 20-12-2009)





The Internet is certainly one of the greatest inventions in the history of mankind. It helped open the road to unprecedented levels of innovation and communication between people. But, life on the Internet is by no means perfect. Numerous gangs of cyber-criminals lurk in the Internet's underground and plot their attacks against unsuspecting people. Because of this, Internet users have a very real and pressing need to protect their assets, be them online (accounts of all sorts) or offline (the... read more»


















Iranian hackers take Twitter down





(from TGDaily at 20-12-2009)





Twitter was attacked by a group of Iranian hackers last night. A group, calling itself the Iranian Cyber Army, compromised DNS records and redirected visitors to a page showing the Iranian flag. The attack lasted over an hour, according to Twitter boss Biz Stone. "Twitter's DNS records were temporarily compromised tonight but have now been fixed. As some noticed, Twitter.com was redirected for a while but API and platform applications were working. We will update with more information and ... read more»


















'Free trial' or Internet scam?





(from CNNMoney at 20-12-2009)





Free trials are not always free. And in some cases, they are very expensive. The FTC, Visa and the Better Business Bureau are warning today about deceptive advertising. You may have seen those "free trial ads" on the Internet for things like acai berry, teeth whiteners or colon cleansers. According to VISA, almost 30% of online consumers have been victimized by this deceptive marketing. One company that sells acai berry supplements received more complaints this year than BBB receives about th... read more»


















Recycled .mp3 Spam for Cheap Pills





(from Symantec at 20-12-2009)





Spammers are recycling their old spamming methods after more than two years. Symantec reported an .mp3 version of pump-and-dump stock spam back in October 2007. In this recent spam attack, a small .mp3 file promoting a meds domain is attached in the email messages. These email messages contain no subject line or message body. The .mp3 file is a five-second message recorded in a female voice and promotes a particular meds domain. The file is approximately 11 KB in size and recorded at a 16 kbp... read more»


















Cloud Based Vulnerability Management





(from information security resources at 20-12-2009)





Vulnerability and Compliance Management as Software as a Service (SaaS) are springing up like mushrooms. The SaaS model enabled companies which focused on vulnerability management to extend their reach, and offer the services to more and more potential clients. Most companies in this market name their SaaS service the “on-demand solutions for security risk and compliance management”.... read more»


















Former owner of Chandler's Citrus Cafe arrested in Texas





(from Azcentral at 20-12-2009)





A self-proclaimed foodie and former owner of the posh Citrus Café in Chandler will likely be eating jail chow instead of escargot and chardonnay while he awaits trial on multiple theft and fraud charges. Andrew Paparella Jr., 36, was extradited to Chandler from Texas Thursday, said police spokesman David Ramer. He was indicted by a Maricopa County Grand Jury in October on 20 criminal charges including identity theft, credit card theft and fraudulent schemes and is accused of going on spending... read more»


















Spoof Conroy website protests at internet filter plan





(from Sydney Morning Herald at 20-12-2009)





He wants to censor the internet but what will Communications Minister Stephen Conroy do about a spoof website that uses his own name to protest against the Government's internet filtering policy? A net prankster has taken advantage of Conroy's failure to reserve his own domain name by registering stephenconroy.com.au and turning it into an anti-censorship protest site.... read more»


















Threat Bulletin: 'Tis the season to be spamming





(from goodgearguide at 20-12-2009)





With Christmas just around the corner, the Symantec Security Response Team has observed that spammers are hard at work generating Christmas-related spam, including gift shopping offers, greeting cards and courier services in an attempt to lure computer users to open these emails. Many of them have Christmas themed key words in the header to lure users to open emails.... read more»


















Japan servers tied to huge cyberattack





(from Japan Times at 20-12-2009)





The National Police Agency said Thursday it suspects eight computer servers in Japan were involved in a wave of attacks in July on government and commercial Web sites in South Korea and the U.S. and a North Korean connection is suspected. Police found a program on the servers for issuing instructions to terminals outside of Japan to send large amounts of data.... read more»


















Ex-Valley restaurateur convicted in identity fraud scheme





(from Azcentral at 20-12-2009)





A former Valley restaurateur recently was convicted in an identity fraud scheme. Judge James V. Selna of the Central District of California Court found Reha Soylular guilty and sentenced him on Nov. 30 for using unauthorized access to obtain money, a felony offense, according to court records. According to court documents, between 2002 and 2004 Soylular gained more than $1,000 by using other individuals' personal information, including names and Social Security information, to establish merch... read more»


















Upper Darby man arrested, faces identity theft charges





(from delcotimes at 20-12-2009)





An alleged swindler involved in a sophisticated identity-theft ring involving personal information copied from hospital records is facing multiple identity theft and theft charges, police said. The defendant allegedly purchased almost $40,000 worth of merchandise with credit cards in other people’s names.... read more»


















Autopsy reports altered in data breach at WDH: Frisbie says it will notify families of deceased





(from Fosters at 20-12-2009)





Frisbie Memorial Hospital says it will notify the families of two patients whose autopsy reports were altered when a Wentworth-Douglass Hospital employee made unauthorized changes to patients records' at WDH's pathology lab. The breach took place between May 2006 and June 2007 at the hands of a WDH employee who more than 1,800 times accessed patients' pathology lab records after she was transferred from the lab. An audit completed in May showed changes were made to patients records, and Dr. C... read more»

















TSA Cannot Order Sites to Take Down Sensitive Manual





(from FAS at 20-12-2009)





After a Transportation Security Administration (TSA) manual containing “sensitive security information” was inadvertently disclosed on a government website, it was reposted on several non-governmental websites where it remains freely available. Asked what TSA intends to do about that, Acting TSA Administrator Gale D. Rossides told Congress that her agency does not have the legal authority to compel members of the public to remove sensitive TSA documents from their websites, though she wished th... read more»

Disqus for ePayment News