BTemplates.com

Powered by Blogger.

Pageviews past week

Quantum mechanics

Auto News

artificial intelligence

About Me

Recommend us on Google!

Information Technology

Popular Posts

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, June 23, 2011

What to Do If Your Online Account's Been Hacked



Dylan Valade owns a Web design and software business. As part of his business, he deals with Web and network security issues every day.

One day, Valade received a confirmation email from a brokerage account letting him know that a trade had been made. That would have been fine, except for one thing.

"In this case, a stock had been sold that I did not sell," Valade said.

Recognizing that the account had been compromised, Valade changed all of his passwords immediately.

"My brokerage account was closed and a new one was opened," he added. "The equities were transferred to the new account, with a new login and password."

Valade's experience happened on a brokerage site, but any online account can be a target.

"The most valuable targets are financial services like PayPal, online bank accounts and investment accounts," explained Morgan Slain of Los Gatos, Calif.-based SplashData. "Facebook, LinkedIn, and other social networking sites are increasingly common targets. Online email accounts, including Gmail and Yahoo! Mail, are often hacked too."

The most sophisticated hackers actually don't target individual accounts, but instead go after repositories of account data on servers owned by large organizations, which is why companies such as Sony and Epsilon, a major email forwarder, are targeted.



What the hackers are looking to steal depends on the type of account they are hacking into. When banks or financial services such as PayPal are targeted, the objective is to steal money.

"But often the hacker has a larger objective than attacking one individual," said Lance James, director of intelligence at New York's Vigilant. "In most cases, they're gaining access to email or social network accounts specifically to enable further distribution of their activity, or to steal information that will give them access to other places — potentially more valuable places. For example, a hacker might conduct a series of intrusions with the aim of getting into an employer's payroll system."

If one of your online accounts has been hacked, it compromises the overall integrity of your computer, James added. This comes with two primary manners of impact.

"First, if there [was] personal or confidential information on that system, the owner must assume it has been hijacked by criminals," he explained. "This could have long-lasting effects including identity theft, credit fraud, bank account theft and misplaced trust between friends and associates.

"Second — in some ways more detrimental in terms of reach — that compromised computer can be used to launch attacks against others, expanding the sphere of impact geometrically," James said. "It is therefore the responsibility of organizations and every individual to take precautions wherever they can."

The surest sign that your account has been compromised is unusual activity.

"For a financial account like PayPal, the most obvious sign that your account has been compromised are suspicious transactions," said Kevin McNamee, security architect at Kindsight of Mountain View, Calif. "You should regularly check your account to look for any unauthorized transactions and report them immediately.

"For social networking services like Facebook," McNamee added, "you may notice unusual activity on your wall, but the most likely indication that something is wrong is when your friends ask why you’ve been sending them unusual links and email messages."

Some things to look for, according to Chris Boyd, senior threat researcher at GFI Software of Cary, N.C., include:

— Friends are asking you about random requests for money or messages that you've apparently sent them, claiming that you're stranded somewhere – for example, messages saying you got mugged in London. Scammers use this tactic for financial fraud. This is an especially popular tactic where compromised Facebook accounts are concerned, due to exploiting the trust of friends and family.

— Strange messages are posted from your Twitter account promoting websites and offers that you're unaware of.

— You find you're selling items on eBay that you didn't list.

If you find that one of your accounts has been compromised, the first step is to ensure that no additional damage can be done, McNamee suggested.

If you still have access to the account, change the password immediately. And then change the passwords to other online accounts, especially for any accounts that share an email address and/or a password with the compromised account.

Also, said McNamee, contact the organization that operates the service and let them know that your account has been compromised.

"Their website will provide information on how to report a problem and regain control over your account," he said.

If the account that was compromised held any financial data or credit/debit card information, James said it's best to contact the financial institutions and cancel the cards.

Even the most vigilant computer user is at risk for an attack. But Asaf Greiner, vice president of products at Sunnyvale, Calif.'s Commtouch, provided the following tips that will keep your accounts less vulnerable to a hacker:

— Use different passwords for different accounts, so if you lose one, you don't lose them all.

— Use strong passwords (e.g. ones that are hard to guess), especially with more valuable resources, such as bank accounts. When possible, use multiple-factor authentication, as with a code-number-generating token. If you find passwords hard to remember, use a password vault application to remember them for you.

— Install all recommended software patches and updates – and anti-virus software – on machines you manage.

— Don't log into valuable accounts from public machines or from unencrypted Wi-Fi networks.


Saturday, June 18, 2011

Crypto-currency Security under Scrutiny



Reports that $500,000 worth of Bitcoin currency was stolen from one user's computer this week has highlighted the poor security of the digital cash and the systems available for managing it. For the currency to gain large-scale popularity, it may need to create or work with financial institutions—making Bitcoin less distinct from the conventional currencies some users hope to supplant.
An alleged robbery suggests Bitcoin—an anonymous,
decentralized currency may need bank-like institutions after all.

To use Bitcoin, a person downloads the official software client, which connects over the Internet to a global network of other copies of the program. Together, these implement the mathematical scheme that ensures that bitcoins can be transferred, created, and verified without any need for a central authority such as a bank (read How Bitcoin works).

That official client stores the security needed to use a stash of bitcoins with minimal security, in an unprotected file known as wallet.dat. In a forum post this week, a bitcoin user whose screen name was "allinvain" claimed that a remote attacker gained access to his or her wallet file and stole over 25,000 bitcoins. The value of a single bitcoin at the time of writing (just over $19) makes the alleged heist worth nearly $500,000, although in practice converting such a large number of bitcoins at once would be tricky. It is impossible for the alleged victim to know who stole the money because the cryptographic architecture of Bitcoin is designed to preserve the anonymity of people transferring the currency. Today the security company Symantec reported it had caught a piece of malicious software that infects computers over the Internet and attempts to steal wallet files.

The vulnerability highlighted by the controversy is very real, says Jeff Garzik, one of the lead developers of the official Bitcoin client and one of a few individuals who are the closest thing the currency has to official spokespeople. Today, anyone able to access the machines of Bitcoin users, either directly or remotely—via malicious software—can grab their wallet files, he acknowledges.



An upgraded version of the client, which will encrypt a person's wallet and ask for a password each time it is accessed, will be released in "just a week or two," says Garzik.

Yet users will still essentially be maintaining their own bank vaults on their computers. "[Wallet encryption] does nothing against many modern malware techniques, such as keystroke logging," says Garzik. He advises Bitcoin users to keep encrypted backups of their wallet files away from the Internet, for example on a USB stick, since the file is needed only when sending money to others.

This may be an option for technically minded early adopters. But if the currency is to be used more widely, a new generation of simple and secure tools for using bitcoins is needed, says Amir Taaki, who leads a U.K.-based consultancy of software developers working on a range of technologies for use with Bitcoin, which operates the exchange site Britcoin.

"Bitcoin is in the very early stages as a piece of software, and if you're a regular home user, then it's not for you at the moment," says Taaki. "It started as a plaything, and now we're at the stage that for Bitcoin to grow, it needs the software used to get money in and out to be more solid and secure."

Earning wider trust will likely require the Bitcoin ecosystem to become more like that of a conventional currency. Taaki and Garzik both say that in the future, there will be established, trustworthy exchanges to look after users' bitcoins, and online services to manage and disburse their cash.

That might go against the libertarian aspirations of some Bitcoin users, who are attracted by its decentralized nature and lack of any controlling authority. Yet the currency will still offer those features, says Patrick Strateman, a developer working on building more robust, secure software for bitcoin exchange sites. "The big difference here is that people will have a real option," says Strateman. "Everyone has the options offered by the old system, plus they have new options as well." Even if many users turn to bank-like organizations to keep their bitcoins safe, it will still be possible to use the less controlled (if riskier) methods that prevail today, he says.

Bitcoin exchanges would benefit from becoming friendlier to investigations of fraudulent transactions, says Taaki, though their doing so would make them even more like conventional banks. Claims by two U.S. senators last week that bitcoins' "untraceable" nature facilitated the purchase of illicit drugs were unfounded, says Taaki: the Bitcoin protocol is built around a public record of every transaction made with the currency. That log, called the "block chain," is maintained and stored by all Bitcoin clients and can be used to trace the movement of any and all bitcoins. But it records only the cryptic public keys that swapped funds, not the identities of the people using them. For example, an online version of the block chain can be used to see how the address "1KPTdMb6p7H3YCwsyFqrEmKGmsHqe1Q3jg" received 25,000 bitcoins this week, the transaction that allinvain complained about.

But Taaki says his Britcoin exchange will help authorities interpret the block chain in cases like money-laundering investigations, and could even correlate it with records of the identities of users of the exchange. The operator of the Mt Gox exchange, the largest bitcoin exchange in the world, has made a similar pledge, says Taaki. "We don't want Bitcoin to be outlawed by well-meaning but ignorant regulators."