FT.com / World - Companies call for centralised e-crime unit
Companies call for centralised e-crime unit
By Maija Palmer, Technology Correspondent
Published: December 17 2007 01:46 | Last updated: December 17 2007 01:46
Businesses are becoming increasingly frustrated at having no centralised organisation to which they can report instances of computer crime, and are calling on the government to form a central police e-crime unit.
David Roberts, chief executive of the Corporate IT Forum, which represents computer users in about half of the FTSE 100 companies, said his members were left with the feeling that the government did not take cybercrime seriously.
“There is no source to go to to report e-crime, other than the local police station – and they have very little understanding of it. It is a significant problem,” Mr Roberts said.
He said businesses previously had a close relationship with the National High Tech Crime Unit. However, since this was merged with the Serious Organised Crime Agency in April 2006, there has been less frequent contact. Soca does not directly take reports of cybercrime, and follows up only larger cases.
“Whereas I fully supported the need for an agency to concentrate on serious and organised crime, the loss of the NHTCU seems to have reduced the focus on ‘everyday’ computer crime that is relevant to UK business and the general public,” said Paul Simmonds, global information security director of ICI.
The recent loss of the personal details and bank accounts of 25m people by HM Revenue and Customs has brought new urgency to tackling the problem of cybercrime.
A number of high-profile security experts have signed an online petition (at http://petitions.pm.gov.uk/ecrime) on the Number 10 Downing Street website, which urges the government to create a central e-crime unit. The petition is backed by Infosecurity Europe, organisers of Europe’s biggest annual IT security conference.
The Association of Chief Police Officers has submitted a proposal to the Home Office for a national e-crime unit, but the Home Office says it needs more clarification on detail and costs.
A report by the science and technology committee of the House of Lords into internet security this summer also recommended the formation of such an organisation, but it was quickly dismissed by the government. There is particular concern that there are too few resources for following up smaller computer crimes, such as fraud on the Ebay auction site, or small amounts of money stolen from online bank accounts.
Under new guidelines, individuals must report cases of identity fraud to the banks rather than police, and it is up to the banks to decide which cases to take to the police. Local police forces will record crimes such as Ebay fraud, but one force, which declined to be named, admitted it did not have the resources to pursue many of these.
“There is no one to chase the small stuff, and that is why we need a central co-ordinating unit. Soca is just interested in the big stuff, but it’s the little stuff that really hurts the citizen,” said Lord Erroll, who sits on the Lords committee and is one of the signatories to the petition. “Losing £500 can be quite critical for the average person.”
A survey last year by Get Safe Online, a government-backed initiative to alert consumers to computer crime, suggested 21 per cent of people thought e-crime was the type of crime they were most likely to encounter.
However, specific statistics on the number of computer crimes are not even being collected by the government.
Copyright The Financial Times Limited 2007
Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts
Monday, December 17, 2007
Wednesday, December 05, 2007
FT.com / Technology - Security Matters: Identity theft is all too easy
FT.com / Technology - Security Matters: Identity theft is all too easy
Security Matters: Identity theft is all too easy
By Ken Munro
Published: December 5 2007 04:40 | Last updated: December 5 2007 04:40
Talking to Peter Whitehead, the Digital Business editor recently, I started ranting about social networking as a means of identity theft. He challenged me to prove my point, confident that his real identity would prove hard to crack.
For the purposes of the challenge, I was armed only with his name and occupation, a laptop and a broadband internet connection. Within three hours I had discovered his full name, date of birth, address, home telephone number, route taken to work, the schools and universities he attended, his career history and his long-harboured passion for rock music, golf and tennis.
Perhaps more worryingly I was also able to find out his daughters’ names, ages, dates of birth, the schools they attend, names and pictures of their friends, along with personal information on his wife and other family members.
I began by searching Peter’s own articles. A quick search of FT.com identified an extensive list, including some he had authored in a travel writing capacity. Reading these quickly established he has two daughters, their names, ages and a family interest in winter sports.
He also helpfully described his route into work – from the fact that he commutes into London via train to the same station every day right down to some of the buildings he passes on the way into the office.
It is, of course, true that only a small number of people are likely to have such information published in the media. But millions do so through social networking sites and blogs. Hence my next stop – Facebook, MySpace, etc.
To my disappointment, the target was not accessible on any of the currently popular social networking sites. But a search of Friends Reunited was more successful. There I learned he is married, the town and county where he lives, the schools and university he attended, along with dates he attended them (and therefore his likely year of birth) and publications he worked on prior to joining the FT.
Armed with this information, a few searches on 192.com yielded his full address, home telephone number and the full data from his daughters’ birth certificates including their dates and places of birth.
But it was only the results of a five-mile charity run that allowed me to make the link between Peter and his wife. Also a journalist, she writes under her maiden name but gives away no personal details in her writing.
A travel article on skiing by Peter yielded the fact that one of his daughters uses a shortened version of her full name. I was then able to go back to the social networking sites. A well-populated profile existed on one site which provided the school she attends, her friends’ names and photos and identified a couple of likely cousins.
Her mother and sister, however, proved much more elusive, neither apparently having succumbed to the lure of virtual socialising.
It is scary stuff for three hours’ surfing but what could you do with this information? I used only the tools any other person with a passing interest in genealogy or a curious streak would be aware of and would have access to and spent only the time I could assign in between running a business.
An attacker with malicious intent towards our target would have both time and a wide range of internet sites on the fringes of legality at their disposal which would, for example, very quickly and easily yield a date of birth and banking history. Or they could simply have hung around his house and raided his bins for non-shredded correspondence (even the day his bins are emptied is available on his local council’s website).
I did not find out bank account details, but I could have paid for and downloaded Peter’s credit report from a credit reference agency (this is unlawful, so I did not pursue this avenue, but a fraudster would have no such qualms). I could then open a bank account, take out a loan or mortgage using a correspondence address to cover my tracks and keep extending the credit for years. Or this information could be used to set up bogus social networking sites to incite others to disclose information.
These same methods can also be used to target businesses. By researching a senior executive using the techniques outlined above, an attack could crack system passwords more easily, gaining access to invaluable corporate data.
Passwords continue to be typically comprised of hobbies, loved ones’ names and dates of birth. Targeting a person in a specific role with a specific level of seniority is a fantastically efficient way of ensuring a good return on investment for an attacker.
It is not just individuals who are at risk. Organisations face industrial espionage or confidential information leaks and those responsible – from employees to suppliers to customers – may not even realise they are doing it. Management is often unaware of the risk. The main concern is over-use of the internet and the impact of social networking on productivity, rather than the security risk it poses.
Sensitive corporate information concerning security arrangements or impending merger or acquisition activity is frequently disclosed on blogs or social networking sites. If someone is targeting a specific organisation – for example for potential information to guide stock market decisions – they can decode references to long hours, management changes, upcoming restructures.
Similarly, any organisation involved in industrial action or complex employee or commercial litigation cases is at risk. Indeed, we consider this such a threat that we advise businesses on how to carry out a social networking audit in order to determine just how much information has already leaked.
Just as there are multiple motives for wanting to access information, there are infinite ways of extracting it if someone wants it badly enough. Much of what’s valuable is out there already, free.
Ken Munro is chief executive of SecureTest
Copyright The Financial Times Limited 2007
Security Matters: Identity theft is all too easy
By Ken Munro
Published: December 5 2007 04:40 | Last updated: December 5 2007 04:40
Talking to Peter Whitehead, the Digital Business editor recently, I started ranting about social networking as a means of identity theft. He challenged me to prove my point, confident that his real identity would prove hard to crack.
For the purposes of the challenge, I was armed only with his name and occupation, a laptop and a broadband internet connection. Within three hours I had discovered his full name, date of birth, address, home telephone number, route taken to work, the schools and universities he attended, his career history and his long-harboured passion for rock music, golf and tennis.
Perhaps more worryingly I was also able to find out his daughters’ names, ages, dates of birth, the schools they attend, names and pictures of their friends, along with personal information on his wife and other family members.
I began by searching Peter’s own articles. A quick search of FT.com identified an extensive list, including some he had authored in a travel writing capacity. Reading these quickly established he has two daughters, their names, ages and a family interest in winter sports.
He also helpfully described his route into work – from the fact that he commutes into London via train to the same station every day right down to some of the buildings he passes on the way into the office.
It is, of course, true that only a small number of people are likely to have such information published in the media. But millions do so through social networking sites and blogs. Hence my next stop – Facebook, MySpace, etc.
To my disappointment, the target was not accessible on any of the currently popular social networking sites. But a search of Friends Reunited was more successful. There I learned he is married, the town and county where he lives, the schools and university he attended, along with dates he attended them (and therefore his likely year of birth) and publications he worked on prior to joining the FT.
Armed with this information, a few searches on 192.com yielded his full address, home telephone number and the full data from his daughters’ birth certificates including their dates and places of birth.
But it was only the results of a five-mile charity run that allowed me to make the link between Peter and his wife. Also a journalist, she writes under her maiden name but gives away no personal details in her writing.
A travel article on skiing by Peter yielded the fact that one of his daughters uses a shortened version of her full name. I was then able to go back to the social networking sites. A well-populated profile existed on one site which provided the school she attends, her friends’ names and photos and identified a couple of likely cousins.
Her mother and sister, however, proved much more elusive, neither apparently having succumbed to the lure of virtual socialising.
It is scary stuff for three hours’ surfing but what could you do with this information? I used only the tools any other person with a passing interest in genealogy or a curious streak would be aware of and would have access to and spent only the time I could assign in between running a business.
An attacker with malicious intent towards our target would have both time and a wide range of internet sites on the fringes of legality at their disposal which would, for example, very quickly and easily yield a date of birth and banking history. Or they could simply have hung around his house and raided his bins for non-shredded correspondence (even the day his bins are emptied is available on his local council’s website).
I did not find out bank account details, but I could have paid for and downloaded Peter’s credit report from a credit reference agency (this is unlawful, so I did not pursue this avenue, but a fraudster would have no such qualms). I could then open a bank account, take out a loan or mortgage using a correspondence address to cover my tracks and keep extending the credit for years. Or this information could be used to set up bogus social networking sites to incite others to disclose information.
These same methods can also be used to target businesses. By researching a senior executive using the techniques outlined above, an attack could crack system passwords more easily, gaining access to invaluable corporate data.
Passwords continue to be typically comprised of hobbies, loved ones’ names and dates of birth. Targeting a person in a specific role with a specific level of seniority is a fantastically efficient way of ensuring a good return on investment for an attacker.
It is not just individuals who are at risk. Organisations face industrial espionage or confidential information leaks and those responsible – from employees to suppliers to customers – may not even realise they are doing it. Management is often unaware of the risk. The main concern is over-use of the internet and the impact of social networking on productivity, rather than the security risk it poses.
Sensitive corporate information concerning security arrangements or impending merger or acquisition activity is frequently disclosed on blogs or social networking sites. If someone is targeting a specific organisation – for example for potential information to guide stock market decisions – they can decode references to long hours, management changes, upcoming restructures.
Similarly, any organisation involved in industrial action or complex employee or commercial litigation cases is at risk. Indeed, we consider this such a threat that we advise businesses on how to carry out a social networking audit in order to determine just how much information has already leaked.
Just as there are multiple motives for wanting to access information, there are infinite ways of extracting it if someone wants it badly enough. Much of what’s valuable is out there already, free.
Ken Munro is chief executive of SecureTest
Copyright The Financial Times Limited 2007
Subscribe to:
Posts (Atom)