LOS ANGELES - Facebook said Thursday a California court has awarded the social networking Web site $711 million in damages in an anti-spam case against Internet marketer Sanford Wallace.
Facebook sued Wallace for accessing users' accounts without their permission and sending phony posts and messages. The company said on its blog that in addition to the damage award, the San Jose, Calif., court referred Wallace to the U.S. Attorney's office for prosecution for criminal contempt of court — meaning he could face jail time.
Wallace earned the monikers "Spam King" and "Spamford" as head of a company that sent as many as 30 million junk e-mails a day in the 1990s.
In May 2008, the online hangout MySpace won a $230 million judgment over junk messages sent to its members when a federal judge in Los Angeles ruled against Wallace and his partner, Walter Rines, in another case brought under the federal anti-spam law known as CAN-SPAM. In 2006, Wallace was fined $4 million after the Federal Trade Commission accused him of running an operation that infected computers with software that caused flurries of pop-up ads, known as "spyware."
"While we don't expect to receive the vast majority of the award, we hope that this will act as a continued deterrent against these criminals," said Sam O'Rourke, associate general counsel for Facebook, in a blog posting Thursday. "This is another important victory in our fight against spam."
There was no phone number listed for Wallace in Las Vegas, where he is believed to be living, according to the ruling.
The company said the judgment marks the second-largest anti-spam award ever. In November 2008, Facebook won an $873 million judgment against Adam Guerbuez and his business, Atlantis Blue Capital, who bombarded users with sexually explicit spam messages.
http://www.kathy1313.com/
http://perfecttrafficstorm.com/aff/4163
http://www.DesktopLightning.com/fulghamkathleen
http://www.leadsleap.com/?referid=fulghamkathleen
Saturday, October 31, 2009
Friday, October 30, 2009
Is The Government Doing Enough?
October is National Cybersecurity Awareness Month.
Does this mean the U.S. Government is finally getting serious about cybersecurity?? Truthfully, it's our SHARED responsibility of good cyber-hygiene among ALL computer users, not just industry and government.
To give just a hint of the depth of this challenge, the Cybersecurity Act of 2009 is presently making its way through Congress. The bill’s co-sponsor, Senator Olympia Snowe (R-Maine), has stated:
“America’s vulnerability to massive cybercrime, global cyber-espionage and cyber-attacks has emerged as one of the most urgent national security problems facing our country today.”
Folks, the explosion of cybercrime and identity theft has reached a 5-year high, increasing annually at a rate of 22%!! It's escalating rapidly in our difficult economic times. In 2008 alone, 9.9 MILLION Americans were victims of identity theft. In fact, the Wall Street Journal states: "Information breaches to U.S. companies in 2008 reached a per-incident cost of $6.65 MILLION."
Take note of these scary, but very real statistics:
** More than 1 person in 10 knew the person who stole their identity.
** Identity thieves are working dramatically faster to exploit their victims.
** Information stolen and stored for a year or more was up 50%.
** Women are 26% more likely to be victims of identity theft than are men.
** Latinos are 47% more apt to become victims of identity theft.
** Minors are increasingly targets. The thieves know that it can take years before a child's ID
theft is discovered.
** Households with higher incomes -- $75,000 or more -- are now at a higher risk.
So…what do these identity theft stats have to do with cybersecurity? Everything. The common denominator here is easy access to individual and business computers in which hackers [read: cyber criminals] are able to penetrate and hijack computers, jeopardizing proprietary and corrupting computers.
The need to turn the Tsunami tide is CRITICALLY urgent, as both our personal AND our national security hinges on ALL computers (home AND businesses) being secured against the ravages and major headaches of cybercrime....all producing hassles, headaches, and serious problems for the end user, along with being an unsuspecting participant in the raging, stealth war of cybercrime and identity fraud. Yes, folks, we’re in an escalating cyber war….it’s already begun!
I am including in this post a link (below) to a blog article from TechRepublic.com called “Cybersecurity: Is the U.S. Government doing enough?”. This explains exactly WHY cybersecurity is EVERYONE'S responsibility. Especially in these challenging days, what is available as "security" software (like Norton, McAfee, TrendMicro, Kaspersky, Panda, etc.) is merely "entry level" and just isn't capable of meeting -- much less staying on top of -- the increasing challenges of sophisticated cybercriminals and other hackers. (If the off-the-shelf, entry-level software did the job, why would the problems be escalating??)
That's exactly why, in my business as a PC Security and Care and Identity Protection Specialist, access to unlimited service and corporate-grade security is provided to computer owners, enabling them to keep cyber criminals from hijacking personal and business PC’s and stealing proprietary data and committing crimes like identity theft and credit fraud. Truthfully, we’re a hacker’s worst nightmare!
Both individuals and small businesses can now finally keep their PC’s and identities secure and truly free from hassles, headaches, and worry….allowing them to literally and finally gain true peace of mind!
Cybersecurity…it’s our shared responsibility!
http://blogs.techrepublic.com.com/security/?p=2532&tag=nl.e036#comments
http://www.kfidentity.com/
http://perfecttrafficstorm.com/aff/4163
http://www.DesktopLightning.com/fulghamkathleen
http://www.leadsleap.com/?referid=fulghamkathleen
Does this mean the U.S. Government is finally getting serious about cybersecurity?? Truthfully, it's our SHARED responsibility of good cyber-hygiene among ALL computer users, not just industry and government.
To give just a hint of the depth of this challenge, the Cybersecurity Act of 2009 is presently making its way through Congress. The bill’s co-sponsor, Senator Olympia Snowe (R-Maine), has stated:
“America’s vulnerability to massive cybercrime, global cyber-espionage and cyber-attacks has emerged as one of the most urgent national security problems facing our country today.”
Folks, the explosion of cybercrime and identity theft has reached a 5-year high, increasing annually at a rate of 22%!! It's escalating rapidly in our difficult economic times. In 2008 alone, 9.9 MILLION Americans were victims of identity theft. In fact, the Wall Street Journal states: "Information breaches to U.S. companies in 2008 reached a per-incident cost of $6.65 MILLION."
Take note of these scary, but very real statistics:
** More than 1 person in 10 knew the person who stole their identity.
** Identity thieves are working dramatically faster to exploit their victims.
** Information stolen and stored for a year or more was up 50%.
** Women are 26% more likely to be victims of identity theft than are men.
** Latinos are 47% more apt to become victims of identity theft.
** Minors are increasingly targets. The thieves know that it can take years before a child's ID
theft is discovered.
** Households with higher incomes -- $75,000 or more -- are now at a higher risk.
So…what do these identity theft stats have to do with cybersecurity? Everything. The common denominator here is easy access to individual and business computers in which hackers [read: cyber criminals] are able to penetrate and hijack computers, jeopardizing proprietary and corrupting computers.
The need to turn the Tsunami tide is CRITICALLY urgent, as both our personal AND our national security hinges on ALL computers (home AND businesses) being secured against the ravages and major headaches of cybercrime....all producing hassles, headaches, and serious problems for the end user, along with being an unsuspecting participant in the raging, stealth war of cybercrime and identity fraud. Yes, folks, we’re in an escalating cyber war….it’s already begun!
I am including in this post a link (below) to a blog article from TechRepublic.com called “Cybersecurity: Is the U.S. Government doing enough?”. This explains exactly WHY cybersecurity is EVERYONE'S responsibility. Especially in these challenging days, what is available as "security" software (like Norton, McAfee, TrendMicro, Kaspersky, Panda, etc.) is merely "entry level" and just isn't capable of meeting -- much less staying on top of -- the increasing challenges of sophisticated cybercriminals and other hackers. (If the off-the-shelf, entry-level software did the job, why would the problems be escalating??)
That's exactly why, in my business as a PC Security and Care and Identity Protection Specialist, access to unlimited service and corporate-grade security is provided to computer owners, enabling them to keep cyber criminals from hijacking personal and business PC’s and stealing proprietary data and committing crimes like identity theft and credit fraud. Truthfully, we’re a hacker’s worst nightmare!
Both individuals and small businesses can now finally keep their PC’s and identities secure and truly free from hassles, headaches, and worry….allowing them to literally and finally gain true peace of mind!
Cybersecurity…it’s our shared responsibility!
http://blogs.techrepublic.com.com/security/?p=2532&tag=nl.e036#comments
http://www.kfidentity.com/
http://perfecttrafficstorm.com/aff/4163
http://www.DesktopLightning.com/fulghamkathleen
http://www.leadsleap.com/?referid=fulghamkathleen
Labels:
access,
business,
hasseles,
identity theft,
individual,
statistics
Saturday, September 26, 2009
September Identity Newsletter
Latest News On The #1 Crime In America & Tips On How Thttp://www.kathy1313.como Keep Your ID Your Own!
Welcome to the September 2009 Identity Theft Newsletter!
Id Theft is the number one fastest growing crime in America yet most people people believe it will never happen to them.
It is my sincere hope that by helping to get the word out through these newsletters that some may be saved from the personal nightmare of having there identity stolen.
Identity Theft Victim Meets Her Identity Thief
Back in January, Michelle McCambridge found herself staring into the face of the woman who stole her identity.
Only a week earlier, she learned that someone had taken out credit cards in her name and racked up thousands in charges. A federal agent had shown her a surveillance photo. But the image didn't ring a bell.
Now the woman in thick-rimmed glasses was standing there at McCambridge's women's-casual counter at J.C. Penney at Southcenter, asking to open a credit account.
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=iW4R32.w0fLSFOGmfviSFw
Identity theft growing, getting harder to stop
MIAMI - With a few keystrokes, computer security expert Esteban Farao can find all the wireless networks in use in a half-block radius from a Starbucks.One of them, it appears, is intended for guests at the Marriott. Others are private networks for individual businesses.Farao, of Coral Gables-based Enterprise Risk Management, said the security of any of those networks could be compromised - a la Albert Gonzalez."It's a matter of time," Farao said, even for networks that are encrypted and password protected.http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=XpTSy3onzmeuBWLKXHkWCw
TJX hacker pleads guilty in major ID theft case
The hacker involved in a massive data breach at TJX Companies has pleaded guilty to identity theft and fraud for the theft of more than 40 million credit and debit card numbers from TJX and other retailers.Albert Gonzalez, 28, of Miami, pleaded guilty in Massachusetts to 19 charges related to the hacking of computer systems at TJX and retailers including Barnes & Noble. He also pleaded guilty to a charge brought in the Eastern District of New York for hacking into the systems of the Dave & Buster's restaurant chain.
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=u.93zNj9Lht8tHd6w8.f2w
Keep an eye out for the Computer Security Newsletter October first...
PC Security & Identity Theft
Protection 661-256-6642
Kathleen’s Personal Identity Theft Blog.
http://www.kfidentity.com/
Kathleen’s Complete Internet Protection Web Site. Includes tons of computer and identity theft protection information:
http://www.kathy1313.com
Add Me To Your Address Book
To help ensure that you receive all email messages consistently in your inbox with images displayed, please add this address to your address book or contacts list:
synergymrktng@aweber.com
Identity Theft Facts:
The FBI receives close to 300,000 complaints of suspicious activity per month and only investigates around 6,000.
73% of Identity Theft victims suffered due to the misappropriation of their credit card info.
Identity Theives Targeting Small Businesses
Businesses lose an estimated 57 billion dollars a year to identity theft.
Small businesses are even more vulnerable for two reasons:
1.) They rely on local law enforcement to investigate but most local law enforcement agencies are not prepared to handle business identity theft.
2.) As larger companies have taken on more sophisticated computer network protections, cyber criminals have adapted and gone after smaller businesses who do not have high-level security.
In other words, to identity thieves, small businesses are the low hanging fruit just ripe for the picking!
Business Owners, are you complying with the Red Flags Rule?
The Red Flags Rule requires many businesses and organizations to implement a written Identity Theft Prevention Program designed to detect the warning signs - or "red flags" - of identity theft in their day-to-day operations.
The deadline is November 1, 2009.
Are you covered by the Red Flags Rule?
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=2mL35GnR3khOp5HyCqUyAQ
Online Red Flag Training
Red Flag Rules training, is designed to familiarize public sector employees with terms, definitions, and requirements related to FTC Government Red Flag Rules.
It teaches the participants to detect, address, and respond appropriately to Red Flags.
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=QEvEzHG8.wpqj_ttk8UydQ
http://www.leadsleap.com/?referid=fulghamkathleen
http://www.DesktopLightning.com/fulghamkathleen
http://perfecttrafficstorm.com/aff/4163
Welcome to the September 2009 Identity Theft Newsletter!
Id Theft is the number one fastest growing crime in America yet most people people believe it will never happen to them.
It is my sincere hope that by helping to get the word out through these newsletters that some may be saved from the personal nightmare of having there identity stolen.
Identity Theft Victim Meets Her Identity Thief
Back in January, Michelle McCambridge found herself staring into the face of the woman who stole her identity.
Only a week earlier, she learned that someone had taken out credit cards in her name and racked up thousands in charges. A federal agent had shown her a surveillance photo. But the image didn't ring a bell.
Now the woman in thick-rimmed glasses was standing there at McCambridge's women's-casual counter at J.C. Penney at Southcenter, asking to open a credit account.
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=iW4R32.w0fLSFOGmfviSFw
Identity theft growing, getting harder to stop
MIAMI - With a few keystrokes, computer security expert Esteban Farao can find all the wireless networks in use in a half-block radius from a Starbucks.One of them, it appears, is intended for guests at the Marriott. Others are private networks for individual businesses.Farao, of Coral Gables-based Enterprise Risk Management, said the security of any of those networks could be compromised - a la Albert Gonzalez."It's a matter of time," Farao said, even for networks that are encrypted and password protected.http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=XpTSy3onzmeuBWLKXHkWCw
TJX hacker pleads guilty in major ID theft case
The hacker involved in a massive data breach at TJX Companies has pleaded guilty to identity theft and fraud for the theft of more than 40 million credit and debit card numbers from TJX and other retailers.Albert Gonzalez, 28, of Miami, pleaded guilty in Massachusetts to 19 charges related to the hacking of computer systems at TJX and retailers including Barnes & Noble. He also pleaded guilty to a charge brought in the Eastern District of New York for hacking into the systems of the Dave & Buster's restaurant chain.
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=u.93zNj9Lht8tHd6w8.f2w
Keep an eye out for the Computer Security Newsletter October first...
PC Security & Identity Theft
Protection 661-256-6642
Kathleen’s Personal Identity Theft Blog.
http://www.kfidentity.com/
Kathleen’s Complete Internet Protection Web Site. Includes tons of computer and identity theft protection information:
http://www.kathy1313.com
Add Me To Your Address Book
To help ensure that you receive all email messages consistently in your inbox with images displayed, please add this address to your address book or contacts list:
synergymrktng@aweber.com
Identity Theft Facts:
The FBI receives close to 300,000 complaints of suspicious activity per month and only investigates around 6,000.
73% of Identity Theft victims suffered due to the misappropriation of their credit card info.
Identity Theives Targeting Small Businesses
Businesses lose an estimated 57 billion dollars a year to identity theft.
Small businesses are even more vulnerable for two reasons:
1.) They rely on local law enforcement to investigate but most local law enforcement agencies are not prepared to handle business identity theft.
2.) As larger companies have taken on more sophisticated computer network protections, cyber criminals have adapted and gone after smaller businesses who do not have high-level security.
In other words, to identity thieves, small businesses are the low hanging fruit just ripe for the picking!
Business Owners, are you complying with the Red Flags Rule?
The Red Flags Rule requires many businesses and organizations to implement a written Identity Theft Prevention Program designed to detect the warning signs - or "red flags" - of identity theft in their day-to-day operations.
The deadline is November 1, 2009.
Are you covered by the Red Flags Rule?
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=2mL35GnR3khOp5HyCqUyAQ
Online Red Flag Training
Red Flag Rules training, is designed to familiarize public sector employees with terms, definitions, and requirements related to FTC Government Red Flag Rules.
It teaches the participants to detect, address, and respond appropriately to Red Flags.
http://clicks.aweber.com/y/ct/?l=EQNY_&m=1dvgwuLjKmGWfD&b=QEvEzHG8.wpqj_ttk8UydQ
http://www.leadsleap.com/?referid=fulghamkathleen
http://www.DesktopLightning.com/fulghamkathleen
http://perfecttrafficstorm.com/aff/4163
Labels:
fastest growing,
identity theft,
victims,
wireless networks
Thursday, September 24, 2009
Sophisticated Botnet Causing a Surge in Click Fraud

Thursday, September 17, 2009 4:10 PM PDT
A new botnet has caused a sharp spike in click fraud because it is skirting the most sophisticated filters of search engines, Web publishers and ad networks, according to Click Forensics.
The company, which provides services to monitor ad campaigns for click fraud and reports on click fraud incidence every quarter, said on Thursday that the botnet's architects have figured out a way to mask it particularly well as legitimate search ad traffic.
Click Forensics is calling this the "Bahama botnet" because initially it was redirecting traffic through 200,000 parked domains in the Bahamas, although it now is using sites in Amsterdam, the U.K. and Silicon Valley.
Click fraud affects marketers who spend money on pay-per-click (PPC) advertising on search engines and Web pages. It happens when a person or a machine clicks on a PPC ad with malicious intent or by mistake.
For example, a competitor may click on a rival's PPC ads in order to drive up their ad spending. Also, a rogue Web publisher may click on PPC ads on its site to trigger more commissions, which is probably what's behind the Bahama botnet.
Click fraud also includes nonmalicious activity that nonetheless yields a click of little or no value to the advertiser, such as when someone clicks on an ad by mistake or two consecutive times.
Click Forensics has been warning recently that click fraud scammers are increasingly resorting to botnets, which are networks of computers that have been secretly compromised for a variety of malicious tasks.
The Bahama botnet is masking the source of its clicks to convince click-fraud filters they are coming from high-quality, legitimate sources, such as U.S. libraries and schools. The botnet is also altering the "interval and breadth" of the attacks from the compromised PCs, according to Click Forensics.
In a piece of extremely bad news for advertisers running PPC campaigns, Click Forensics has seen worst-case scenarios in which as much as 30 percent of a monthly ad budget is swallowed by Bahama botnet click-fraud traffic.
Ordinary users' PCs are made part of the Bahama botnet with malware. Click Forensics found links to the malware in search results for queries about the non-existent Facebook Fan Check virus.
Last week, security company Sophos and Facebook both warned that malicious hackers were setting up malware-infested Web sites that falsely claimed to remove a non-existent virus from a new Facebook application called Fan Check.
False rumors spread that Fan Check infected PCs with malware, so scammers tried to capitalize on the concern that many Facebook members had about the application.
As Facebook members used popular search engines to find antivirus information about Fan Check, they got results that pointed to sites that offered false virus removal kits and instead infected their computers with malware.
Click Forensics also said the botnet malware is "extremely similar" to the "scareware" program found in malicious ads that The New York Times was tricked into serving up on its Web site last weekend. Before the Times eliminated them, the ads displayed pop-up messages falsely telling users their PCs were infected so they would buy a fake anti-virus program.
Click Forensics is in contact with major search engines, ad network providers, advertisers, publishers and security companies regarding the Bahama botnet and ways to address it.
Neither Google nor Yahoo, which operate the two largest search engines and PPC ad networks, immediately responded to a request for comment.
http://www.kathy1313.com/
http://perfecttrafficstorm.com/aff/4163
http://www.DesktopLightning.com/fulghamkathleen
http://www.leadsleap.com/?referid=fulghamkathleen
A new botnet has caused a sharp spike in click fraud because it is skirting the most sophisticated filters of search engines, Web publishers and ad networks, according to Click Forensics.
The company, which provides services to monitor ad campaigns for click fraud and reports on click fraud incidence every quarter, said on Thursday that the botnet's architects have figured out a way to mask it particularly well as legitimate search ad traffic.
Click Forensics is calling this the "Bahama botnet" because initially it was redirecting traffic through 200,000 parked domains in the Bahamas, although it now is using sites in Amsterdam, the U.K. and Silicon Valley.
Click fraud affects marketers who spend money on pay-per-click (PPC) advertising on search engines and Web pages. It happens when a person or a machine clicks on a PPC ad with malicious intent or by mistake.
For example, a competitor may click on a rival's PPC ads in order to drive up their ad spending. Also, a rogue Web publisher may click on PPC ads on its site to trigger more commissions, which is probably what's behind the Bahama botnet.
Click fraud also includes nonmalicious activity that nonetheless yields a click of little or no value to the advertiser, such as when someone clicks on an ad by mistake or two consecutive times.
Click Forensics has been warning recently that click fraud scammers are increasingly resorting to botnets, which are networks of computers that have been secretly compromised for a variety of malicious tasks.
The Bahama botnet is masking the source of its clicks to convince click-fraud filters they are coming from high-quality, legitimate sources, such as U.S. libraries and schools. The botnet is also altering the "interval and breadth" of the attacks from the compromised PCs, according to Click Forensics.
In a piece of extremely bad news for advertisers running PPC campaigns, Click Forensics has seen worst-case scenarios in which as much as 30 percent of a monthly ad budget is swallowed by Bahama botnet click-fraud traffic.
Ordinary users' PCs are made part of the Bahama botnet with malware. Click Forensics found links to the malware in search results for queries about the non-existent Facebook Fan Check virus.
Last week, security company Sophos and Facebook both warned that malicious hackers were setting up malware-infested Web sites that falsely claimed to remove a non-existent virus from a new Facebook application called Fan Check.
False rumors spread that Fan Check infected PCs with malware, so scammers tried to capitalize on the concern that many Facebook members had about the application.
As Facebook members used popular search engines to find antivirus information about Fan Check, they got results that pointed to sites that offered false virus removal kits and instead infected their computers with malware.
Click Forensics also said the botnet malware is "extremely similar" to the "scareware" program found in malicious ads that The New York Times was tricked into serving up on its Web site last weekend. Before the Times eliminated them, the ads displayed pop-up messages falsely telling users their PCs were infected so they would buy a fake anti-virus program.
Click Forensics is in contact with major search engines, ad network providers, advertisers, publishers and security companies regarding the Bahama botnet and ways to address it.
Neither Google nor Yahoo, which operate the two largest search engines and PPC ad networks, immediately responded to a request for comment.
http://www.kathy1313.com/
http://perfecttrafficstorm.com/aff/4163
http://www.DesktopLightning.com/fulghamkathleen
http://www.leadsleap.com/?referid=fulghamkathleen
Sunday, September 20, 2009
Officials: Special Plastic Sleeves May Stop Identity Theft

To protect against skimming and eavesdropping attacks, federal and state officials recommend that Americans keep their e-passports tightly shut and store their RFID-tagged passport cards and enhanced driver's licenses in "radio-opaque" sleeves.
That's because experiments have shown that the e-passport begins transmitting some data when opened even a half inch, and chipped passport cards and EDLs can be read from varying distances depending on reader techonology.
The cover of the e-passport booklet contains a metallic sheathing that can diminish the distances radio waves travel, presumably hindering unwanted interceptions.
Alloy envelopes that come with the PASS cards and driver's licenses do the same, the government says.
The State Department asserts that hackers won't find any practical use for data skimmed from RFID chips embedded in the cards, but "if you don't want the cards read, put them in an attenuation sleeve," says John Brennan, a senior policy adviser at the Office of Consular Affairs.
Gigi Zenk, a spokeswoman for the Washington state Department of Licensing, says the envelope her state offers with the enhanced driver's license "ensures that nothing can scan it at all."
But that wasn't what researchers from the University of Washington and RSA Laboratories, a data security company in Bedford, Mass., found last year while testing the data security of the cards.
The PASS card "is readable under certain circumstances in a crumpled sleeve," though not in a well maintained sleeve, the researchers wrote in a report.
Another test on the enhanced driver's license demonstrated that even when the sleeve was in pristine condition, a clandestine reader could skim data from the license at a distance of a half yard.
Will Americans consistently keep their enhanced driver's licenses in the protective sleeves and maintain those sleeves in perfect shape — even as driver's licenses are pulled out for countless tasks, from registering in hotels to buying alcohol?
The report's answer: "It is uncertain ... "
And when the sleeves come off, "you're essentially saying to the world, 'Come and read what's in my wallet,'" says Marc Rotenberg, executive director of the Electronic Privacy Information Center in Washington, D.C.
By obliging Americans to use these sleeves, he says, the government has, in effect, shifted the burden of privacy protection to the citizen.
Meanwhile, researchers have raised other red flags.
— In 2006, a mobile security company, Flexilis, conducted an experiment in which the transponder of a partially opened e-passport triggered an explosive planted in a trashcan when a dummy carrying the chipped passport approached the bin. A video of the experiment was shown that year at a security conference.
Flexilis has suggested that the government adopt a dual cover shield and specifically designed RFID tag that would make the e-passport remotely unreadable until it is fully opened.
No changes have been made to the U.S. e-passport in response, according to the State Department.
— Some RFID critics wonder: Could government officials read the microchips in an enhanced driver's license or passport card by scanning people via satellite or through a cell phone tower network?
The short answer is no — because the chips in PASS cards and EDLs are "passive," or batteryless, meaning they rely on the energy of readers to power up. Passive tags are designed to beam information out 30 feet.
However, research is moving forward to make batteries tinier and more powerful, says Ari Juels, director of RSA Laboratories.
A "semi-passive" tag that could transmit into the atmosphere when triggered by a reader "may be feasible at some point," he says.
Separately, a system called STAR, that adapts deep-space communications technologies to read passive tags from distances greater than 600 feet, was announced last year by a Los Angeles startup called Mojix, Inc.
It uses "smart antennas" and "digital beam forming" to process signals in four dimensions — time, space, frequency and polarization.
Mojix, founded by a former NASA scientist, promotes the technology for supply chain management and asset tracking.
http://www.wysong.net/
That's because experiments have shown that the e-passport begins transmitting some data when opened even a half inch, and chipped passport cards and EDLs can be read from varying distances depending on reader techonology.
The cover of the e-passport booklet contains a metallic sheathing that can diminish the distances radio waves travel, presumably hindering unwanted interceptions.
Alloy envelopes that come with the PASS cards and driver's licenses do the same, the government says.
The State Department asserts that hackers won't find any practical use for data skimmed from RFID chips embedded in the cards, but "if you don't want the cards read, put them in an attenuation sleeve," says John Brennan, a senior policy adviser at the Office of Consular Affairs.
Gigi Zenk, a spokeswoman for the Washington state Department of Licensing, says the envelope her state offers with the enhanced driver's license "ensures that nothing can scan it at all."
But that wasn't what researchers from the University of Washington and RSA Laboratories, a data security company in Bedford, Mass., found last year while testing the data security of the cards.
The PASS card "is readable under certain circumstances in a crumpled sleeve," though not in a well maintained sleeve, the researchers wrote in a report.
Another test on the enhanced driver's license demonstrated that even when the sleeve was in pristine condition, a clandestine reader could skim data from the license at a distance of a half yard.
Will Americans consistently keep their enhanced driver's licenses in the protective sleeves and maintain those sleeves in perfect shape — even as driver's licenses are pulled out for countless tasks, from registering in hotels to buying alcohol?
The report's answer: "It is uncertain ... "
And when the sleeves come off, "you're essentially saying to the world, 'Come and read what's in my wallet,'" says Marc Rotenberg, executive director of the Electronic Privacy Information Center in Washington, D.C.
By obliging Americans to use these sleeves, he says, the government has, in effect, shifted the burden of privacy protection to the citizen.
Meanwhile, researchers have raised other red flags.
— In 2006, a mobile security company, Flexilis, conducted an experiment in which the transponder of a partially opened e-passport triggered an explosive planted in a trashcan when a dummy carrying the chipped passport approached the bin. A video of the experiment was shown that year at a security conference.
Flexilis has suggested that the government adopt a dual cover shield and specifically designed RFID tag that would make the e-passport remotely unreadable until it is fully opened.
No changes have been made to the U.S. e-passport in response, according to the State Department.
— Some RFID critics wonder: Could government officials read the microchips in an enhanced driver's license or passport card by scanning people via satellite or through a cell phone tower network?
The short answer is no — because the chips in PASS cards and EDLs are "passive," or batteryless, meaning they rely on the energy of readers to power up. Passive tags are designed to beam information out 30 feet.
However, research is moving forward to make batteries tinier and more powerful, says Ari Juels, director of RSA Laboratories.
A "semi-passive" tag that could transmit into the atmosphere when triggered by a reader "may be feasible at some point," he says.
Separately, a system called STAR, that adapts deep-space communications technologies to read passive tags from distances greater than 600 feet, was announced last year by a Los Angeles startup called Mojix, Inc.
It uses "smart antennas" and "digital beam forming" to process signals in four dimensions — time, space, frequency and polarization.
Mojix, founded by a former NASA scientist, promotes the technology for supply chain management and asset tracking.
http://www.wysong.net/
Labels:
chips,
cover shield,
microchips,
passports,
sleeves
Tuesday, July 7, 2009
Social Security #'s really are not safe

As we have known for quite sometime that our social security numbers are not safe. They can be found through several different sources. Well now it is know that the numbers can be guessed at and the numbers can be accurate.
Researchers have found that it is possible to guess many -- if not all -- of the nine digits in an individual's Social Security number using publicly available information, a finding they say compromises the security of one of the most widely used consumer identifiers in the United States.
Many numbers could be guessed at by simply knowing a person's birth data, the researchers from Carnegie Mellon University said.
The results come as concern grows over identity theft and lawmakers in Washington push legislation that would bar businesses from requiring people to supply their Social Security number when purchasing a good or service.
"Our work shows that Social Security numbers are compromised as authentication devices, because if they are predictable from public data, then they cannot be considered sensitive," said Alessandro Acquisti, assistant professor of information technology and public policy at Carnegie Mellon University, and a co-author of the study.
"For reasons unrelated to this report, the agency has been developing a system to randomly assign SSNs," which should make it more difficult to discover numbers in the future, Mark Lassiter, a spokesman for the Social Security Administration, said by e-mail.
Concern over the privacy of those numbers has grown in the wake of hundreds of data breaches reported by businesses, governments and educational institutions, breaches that have exposed millions of consumer records -- including SSNs.
In recent years, a number of states have passed legislation to redact or remove the numbers from public documents, such as divorce and property records, and bankruptcy filings. In addition, legislation introduced this year by Rep. Rodney Frelinghuysen (R-N.J.) and Sen. Dianne Feinstein (D-Calif.) would prohibit the display, sale, or purchase of Social Security numbers without consent, and would bar businesses from requiring people to provide their number.
The Social Security number's first three digits -- called the "area number" -- is issued according to the Zip code of the mailing address provided in the application form. The fourth and fifth digits -- known as the "group number" -- transition slowly, and often remain constant over several years for a given region. The last four digits are assigned sequentially.
As a result, SSNs assigned in the same state to applicants born on consecutive days are likely to contain the same first four or five digits, particularly in states with smaller populations and rates of birth.
As it happens, the researchers said, if you're trying to discover a living person's SSN, the best place to start is with a list of dead people -- particularly deceased people who were born around the time and place of your subject. The so-called "Death Master File," is a publicly available file which lists SSNs, names, dates of birth and death, and the states of all individuals who have applied for a number and whose deaths have been reported to the Social Security Administration.
CMU researchers Acquisti and Ph.D student Ralph Gross theorized that they could use the Death Master File along with publicly available birth information to predict narrow ranges of values wherein individual SSNs were likely to fall. The two tested their hunch using the Death Master File of people who died between 1972 and 2003, and found that on the first try they could correctly guess the first five digits of the SSN for 44 percent of deceased people who were born after 1988, and for 7 percent of those born between 1973 and 1988.
Acquisti and Gross found that it was far easier to predict SSNs for people born after 1988, when the Social Security Administration began an effort to ensure that U.S. newborns obtained their SSNs shortly after birth.
They were able to identify all nine digits for 8.5 percent of people born after 1988 in fewer than 1,000 attempts. For people born recently in smaller states, researchers sometimes needed just 10 or fewer attempts to predict all nine digits.
Records of an individual's state and date of birth can be obtained from a variety of sources, including voter registration lists and commercial databases. What's more, many people now self-publish this information as part of their personal profiles on blogs and social networking sites. Indeed, the researchers tested their method using birthdays and hometowns that CMU students published on social networking sites, with similar results.
CMU researchers Acquisti and Ph.D student Ralph Gross theorized that they could use the Death Master File along with publicly available birth information to predict narrow ranges of values wherein individual SSNs were likely to fall. The two tested their hunch using the Death Master File of people who died between 1972 and 2003, and found that on the first try they could correctly guess the first five digits of the SSN for 44 percent of deceased people who were born after 1988, and for 7 percent of those born between 1973 and 1988.
Acquisti and Gross found that it was far easier to predict SSNs for people born after 1988, when the Social Security Administration began an effort to ensure that U.S. newborns obtained their SSNs shortly after birth.
They were able to identify all nine digits for 8.5 percent of people born after 1988 in fewer than 1,000 attempts. For people born recently in smaller states, researchers sometimes needed just 10 or fewer attempts to predict all nine digits.
Records of an individual's state and date of birth can be obtained from a variety of sources, including voter registration lists and commercial databases. What's more, many people now self-publish this information as part of their personal profiles on blogs and social networking sites. Indeed, the researchers tested their method using birthdays and hometowns that CMU students published on social networking sites, with similar results.
"Sure, the study says that if you were born in a big state on a busy day you're probably still safe," from having identity thieves guess your entire SSN, Anderson said. "Still, I think many people would find it unacceptable that a system continues in use which in effect exposes tens of millions of Americans to fraud and other kinds of harm."
Linda Foley, founder of the Identity Theft Resource Center, a San Diego based nonprofit, cited another potential problem. She said many businesses have errantly rely upon or have moved to redact all but the last four digits of a person's SSN, the very digits that are most unique to an individual.
"Because of the way the SSN has been designed, asking for the last four numbers of the SSN puts people at risk because those are the only numbers that are unique to you and cannot be guessed easily by someone who might want to use your identity," Foley said.
The National Science Foundation, the U.S. Army Research Office, Carnegie Melon Cylab, and the Berkman Faculty Development Fund provided support for the research. The study, which will be presented July 29 at the BlackHat 2009 security conference in Las Vegas, is available at this link.
Join the LinkShare Referral Program for free!
Another great blog.
http://mypcsafefreefromspyware.blogspot.com/
Researchers have found that it is possible to guess many -- if not all -- of the nine digits in an individual's Social Security number using publicly available information, a finding they say compromises the security of one of the most widely used consumer identifiers in the United States.
Many numbers could be guessed at by simply knowing a person's birth data, the researchers from Carnegie Mellon University said.
The results come as concern grows over identity theft and lawmakers in Washington push legislation that would bar businesses from requiring people to supply their Social Security number when purchasing a good or service.
"Our work shows that Social Security numbers are compromised as authentication devices, because if they are predictable from public data, then they cannot be considered sensitive," said Alessandro Acquisti, assistant professor of information technology and public policy at Carnegie Mellon University, and a co-author of the study.
"For reasons unrelated to this report, the agency has been developing a system to randomly assign SSNs," which should make it more difficult to discover numbers in the future, Mark Lassiter, a spokesman for the Social Security Administration, said by e-mail.
Concern over the privacy of those numbers has grown in the wake of hundreds of data breaches reported by businesses, governments and educational institutions, breaches that have exposed millions of consumer records -- including SSNs.
In recent years, a number of states have passed legislation to redact or remove the numbers from public documents, such as divorce and property records, and bankruptcy filings. In addition, legislation introduced this year by Rep. Rodney Frelinghuysen (R-N.J.) and Sen. Dianne Feinstein (D-Calif.) would prohibit the display, sale, or purchase of Social Security numbers without consent, and would bar businesses from requiring people to provide their number.
The Social Security number's first three digits -- called the "area number" -- is issued according to the Zip code of the mailing address provided in the application form. The fourth and fifth digits -- known as the "group number" -- transition slowly, and often remain constant over several years for a given region. The last four digits are assigned sequentially.
As a result, SSNs assigned in the same state to applicants born on consecutive days are likely to contain the same first four or five digits, particularly in states with smaller populations and rates of birth.
As it happens, the researchers said, if you're trying to discover a living person's SSN, the best place to start is with a list of dead people -- particularly deceased people who were born around the time and place of your subject. The so-called "Death Master File," is a publicly available file which lists SSNs, names, dates of birth and death, and the states of all individuals who have applied for a number and whose deaths have been reported to the Social Security Administration.
CMU researchers Acquisti and Ph.D student Ralph Gross theorized that they could use the Death Master File along with publicly available birth information to predict narrow ranges of values wherein individual SSNs were likely to fall. The two tested their hunch using the Death Master File of people who died between 1972 and 2003, and found that on the first try they could correctly guess the first five digits of the SSN for 44 percent of deceased people who were born after 1988, and for 7 percent of those born between 1973 and 1988.
Acquisti and Gross found that it was far easier to predict SSNs for people born after 1988, when the Social Security Administration began an effort to ensure that U.S. newborns obtained their SSNs shortly after birth.
They were able to identify all nine digits for 8.5 percent of people born after 1988 in fewer than 1,000 attempts. For people born recently in smaller states, researchers sometimes needed just 10 or fewer attempts to predict all nine digits.
Records of an individual's state and date of birth can be obtained from a variety of sources, including voter registration lists and commercial databases. What's more, many people now self-publish this information as part of their personal profiles on blogs and social networking sites. Indeed, the researchers tested their method using birthdays and hometowns that CMU students published on social networking sites, with similar results.
CMU researchers Acquisti and Ph.D student Ralph Gross theorized that they could use the Death Master File along with publicly available birth information to predict narrow ranges of values wherein individual SSNs were likely to fall. The two tested their hunch using the Death Master File of people who died between 1972 and 2003, and found that on the first try they could correctly guess the first five digits of the SSN for 44 percent of deceased people who were born after 1988, and for 7 percent of those born between 1973 and 1988.
Acquisti and Gross found that it was far easier to predict SSNs for people born after 1988, when the Social Security Administration began an effort to ensure that U.S. newborns obtained their SSNs shortly after birth.
They were able to identify all nine digits for 8.5 percent of people born after 1988 in fewer than 1,000 attempts. For people born recently in smaller states, researchers sometimes needed just 10 or fewer attempts to predict all nine digits.
Records of an individual's state and date of birth can be obtained from a variety of sources, including voter registration lists and commercial databases. What's more, many people now self-publish this information as part of their personal profiles on blogs and social networking sites. Indeed, the researchers tested their method using birthdays and hometowns that CMU students published on social networking sites, with similar results.
"Sure, the study says that if you were born in a big state on a busy day you're probably still safe," from having identity thieves guess your entire SSN, Anderson said. "Still, I think many people would find it unacceptable that a system continues in use which in effect exposes tens of millions of Americans to fraud and other kinds of harm."
Linda Foley, founder of the Identity Theft Resource Center, a San Diego based nonprofit, cited another potential problem. She said many businesses have errantly rely upon or have moved to redact all but the last four digits of a person's SSN, the very digits that are most unique to an individual.
"Because of the way the SSN has been designed, asking for the last four numbers of the SSN puts people at risk because those are the only numbers that are unique to you and cannot be guessed easily by someone who might want to use your identity," Foley said.
The National Science Foundation, the U.S. Army Research Office, Carnegie Melon Cylab, and the Berkman Faculty Development Fund provided support for the research. The study, which will be presented July 29 at the BlackHat 2009 security conference in Las Vegas, is available at this link.
Join the LinkShare Referral Program for free!
Another great blog.
http://mypcsafefreefromspyware.blogspot.com/
Labels:
compromised,
guess,
numbers,
random,
social security
Wednesday, June 17, 2009
Easy Target For Credit Card Hackers

Every time you swipe your credit card and wait for the transaction to be approved, sensitive data including your name and account number are ferried from store to bank through computer networks, each step a potential opening for hackers.
And while you may take steps to protect yourself against identity theft, an Associated Press investigation has found the banks and other companies that handle your information are not being nearly as cautious as they could.
It means every time you pay with plastic, companies are gambling with your personal data. If hackers intercept your numbers, you'll spend weeks straightening your mangled credit, though you can't be held liable for unauthorized charges. Even if your transaction isn't hacked, you still lose:
Merchants pass to all their customers the costs they incur from fraud.More than 70 retailers and payment processors have disclosed breaches since 2006, involving tens of millions of credit and debit card numbers, according to the Privacy Rights Clearinghouse. Meanwhile, many others likely have been breached and didn't detect it.
Even the companies that had the payment industry's top rating for computer security, a seal of approval known as PCI compliance, have fallen victim to huge heists.Companies that are not compliant with the PCI standards — including one in 10 of the medium-sized and large retailers in the United States — face fines but are left free to process credit and debit card payments.
Most retailers don't have to endure security audits, but can evaluate themselves.Credit card companies are not in a hurry to tighten the rules. They view fraud as cost of doing business and strickter rules would not be good for their business.Hackers can and have plundered companies that process payments and have PCI standards.
In 2006 retailers and payment processors have spent more than $2 billion on security upgrades to comply with PCI. The payment industry touts the fact that 93 percent of big retailers in the U.S. are compliant with the PCI rules.Computer security experts say the the PCI guidelines are superficial and not monitored the way they should be. That leaves the consumer at risk.We need stricker rules. The public needs the assurrance that the credit card companies are going to take the steps that are necessary to protect their clients. It is their responsiblity to protect the people that do business with their credit cards.
http://www.wysong.net/
http://www.kathy1313.com
Labels:
credit card,
hackers,
heists,
merchants,
PCI compliance.,
personal data
Subscribe to:
Posts (Atom)