Showing posts with label online fraud. Show all posts
Showing posts with label online fraud. Show all posts

Friday, March 6, 2009

Do you trust me?

For most of us, the System Administrators, a.k.a Sysadmins, are life-savers. They reset our passwords when we forget them, recover our files when we delete them and sometimes give us a hard time about it. For corporate management, however, this kind of power can be frightening. An administrator would usually have access to every bit of information in the company, including every employees employment and HR data, personal email, and usually customer data as well. This kind of power, if abused, can cause irreparable damage to a company, but despite that, most companies interview and screen their sysadmin just like any other employee. If, for some reason, this employee becomes bitter or estranged, there's no telling what could happen, and there have been documented cases where entire companies have been complete destroyed intentionally by their admins.


Can this happen to your company too? Possibly. CEOs and CIOs have been looking for ways to counteract this sort of threat for a while now. There is a logical problem here - if you don't trust your admin, and appoint someone to watch over him, then how do you trust that someone to not break bad? After all, even CEOs have been known to go astray and stick their hands into inappropriate pockets. Who shaves the barber?


There is no simple answer here, but generally, the answer has two parts. The logical solution is separation of powers. You appoint at least 2 or 3 administrators, and try to make sure they don't become too friendly with each other so there's less chance of collusion. One way to go about this is appointing people who are a world apart - big age difference, for example. Then, add to that job or responsibility rotation. For example, one can be appointed to manage the finance department servers, while the other owns the engineering servers, and then rotate those roles every 3-6 months. This way, if one used abuses these resources, it will most likely be revealed upon the next rotation. Another good practice is the force the administrators to go on vacation on a regular basis (and YES, it's totally worth to give them an extra few annual vacation days just for that). When the admin goes on vacation, someone else has to take over, and that would usually expose any foul play.


The 2nd part is technological - Use some system to track and log activity. This serves two purposes - people tend to mess around a lot less when they know they are being watched, and that will affect not only administrators, but also regular users. Secondly, if someone does go to the dark side, at least there will be a way to check what's been going on, and have evidence in case a law suit or criminal charges need to be filed. One such software solution is Intellinx, and another is InFlight. These solutions can record user activity directly from the network, including keystrokes and screen output from every station in the company.

Is any of that foolproof? Of course not. A smart crook can always find some way to scam his way around, and the only answer to this is to carefully build a security policy that tries to address each and every possible threat - external or internal. Another important lesson to be learned here is that the system administrator is a very sensitive position, and should be screened appropriately. The screening process should include not only technical evaluation, but also personality and psychological testing, and it wouldn't hurt to have this monitored on a regular basis too, especially if a big change has happened in the company. If you had your sysadmin fire half his technicians because the company is tight on money, you can bet he's preparing for the possibility of him being next on the chopping board, and his preparation might include stashing sensitive data or implanting backdoors into servers. Also, keep in mind that even a small-time technician that you are hiring today to haul some printers around might end up being the sysadmin in 10 years. That means that those guys should also be chosen carefully, and reviewed once again upon getting promoted. And speaking of Admins, a fun thing to read is the old classic BOFM, which tells some tails of a particularly nasty sysadmin.

Monday, January 19, 2009

Never take candy from strangers

Yesterday, my darling wife told me that she got a weird SMS about 9.99$ and she's not sure what it is. Turned out it was from some IQ-Test she took online on FaceBook. When she completed the test, she was asked for her phone, to which her score was sent, along with the message that she just subscribed to a 9.99$ a month service. Clearly, this is a scam, but my sweetheart never thought that something from such a reputable source like FaceBook could be harmful.

"This is exactly how the 1st nasty Viruses/worms started to spread", I told her. A worm would harvest his victims address book, and send itself to all of his recipients. The guy's poor friends and family members would think that this, coming from a friend or family member, must be legit, but of course, it wasn't. Later on, some worms got even cleverer, and spoofed the source address to be someone else from the list, so that the victims could not know who of their close-ones is really the source of the infection.

Luckily, some people have learned to beware of wolves in sheep's clothing, and others are protected by more secure software that wouldn't let them open attachments, but the success of that "service" and others like it shows that apparently, many people still fall for that old trick. Well, if you, or your close ones think that since FaceBook is a legitimate site, then everything on it is too, think again. Pretty much anybody can upload data to FaceBook or write an app for it, and although the site has a lot of security features, it's far from secure. This specific application gives you an IQ test comprised of 10 questions (I won't waste your time with explaining why such a test is closer to guessing your IQ that actually measuring it) and asks for your phone number. To that phone, it sends a confirmation code that you need to punch in to the website, which then sends you an SMS with your so-called IQ. By entering the code, you are actually agreeing to be subscribed to a service that charges 10$ a month. Although this is written both on the website and on the SMS message, some people might miss that, or misunderstand it. Many wouldn't notice another 10$ charge on their cell service bill, and some people are making millions on those people's back.

This type of story shows why information security is more about security than information. Although this is propagated by computers, it could just as easily be done via just the phone, through an interactive TV channel, and many others. Even if you don't like computers, or maybe ESPECIALLY if you don't like computers, this poses a real risk. Not only can you be billed, you can never know for sure where your info will end up in. Maybe tomorrow you'll be flooded with 20 SMSs a day, advertizing the current Viagra or Rolex, or maybe be part of an identity theft operation. The most important lesson here is this: FaceBook is NOT your friend, and neither are MySpace or any other web service. Always assume the worst about an information source, even if you've used it for years and it was great otherwise. The bad guys, or "evil doers" as W likes to call them, are all around, and they will keep on finding new ways to separate us and our money. Just make sure it's not you, and I might also suggest educating your friends and loved ones too.

Tuesday, December 2, 2008

Stoneage 101

When you mention "Information Security" in front of people, most of them will shrug. "I ain't no computer guy", some might say. Truly, only very few people are "Computer Guys", but there's information anywhere, not just in computer, and so information security is no more "computers" than mice or speakers.

About a year ago, I was standing in line to buy a ticket to some concert. Apparently, the theatre was offering some sweet deal, by which you could pay for part of the ticket using reward-points accumulated with your credit card. As I was moving down the line, I noticed that the cashier was writing down on a piece of paper the credit card number of each buyer who elected to take advantage of this pitch. I raised my phone and took a snap of the cashier, and later, at home, with some image processing, I could easily decipher every number and name on the sheet.

The point of this little story is that had I been a less honest person, this little exercise in negligence could have easily led to a massive shopping spree, and this is a classic electronic fraud which has nothing to do with computers. It's easy to see who's at fault here, but blame aside, the lesson here is that information security flaws could be lurking everywhere. You could be completely computer-illiterate, but still throw out your credit card statements in the trash, thereby exposing yourself to fraud. In fact, one could say that computer-illiterate people are even more at risk than those who use computers all the time. At least when you have one, you would probably be aware of at least some of the dangers involved with open communication lines.

What you can do? 1st of all, open your eyes. Look around you. Do you have yellow notes sticking on your screen with private information that could be used to hurt you? Do you keep a bunch of sensitive documents in that unlocked top drawer in your cabinet? Is your trashcan full of documents that would go out to the public trash tomorrow, and may reveal a lot about you? If some of those are YES, here's your chance to get better. Next, open your spouse, kids, parents, family and friends ears too. Tell them this tale and help them think more critically about their data. Your parents told you when you were little that when you come in or out of the house, you should lock the door, right? That's a basic security measure that seems to go without saying, but it's up to you as a parent (now or in the future) to educate the next generation how to apply security to stuff other than doors and windows.