Sunday, May 25, 2008

The Women of Bletchley Park

Last Friday, I visited Bletchley Park, home of the WWII code-cracking team, now a somewhat tattered, yet still inspiring remnant of the glory days of Churchill's England.


On this visit, I was fortunate to encounter several excellent guides, including Tony Sale, former MI5 engineer, and the man behind the reconstruction of Colossus - the computer built to break Lorenz, the code used by Hitler and his generals.

Between witnessing a live demonstration of the world's first computer (which, unbelievably, still uses some of the original valves from the WWII period), touring the huts where Turing and his peers worked, and viewing a simply incredibly array of artifacts, including several Enigma machines and replicas of the famous Turing Bombes, I enjoyed a terrific few hours.

However, during the course of the visit, I came across one fact that had somehow eluded me while reading several of the books that have Bletchley Park at their core: the pivotal role of women at Bletchley Park during the war.

According to the displayed HR logs, photos graphs, and anecdotal stories, more than 75% of personnel at Bletchley were female, including virtually all of the radio station operators, Bombe operators, motorcycle dispatch riders, analysts, and many of the code-breakers.

In the hut made famous by Alan Turing - Hut 8 - an excellent video is on display featuring Mavis Batey (nee Lever), one of Dilly Knox's "girls". Ms. Batey, who is now in her eighties, came up with one of the critical breakthroughs of the war -an inspired analysis that resulted in victory over elite Italian naval forces during the Battle of Matapan.

In the room next to it are several stories involving female leaders of resistance groups that Hollywood producers need to immediately check out. I had not heard of several of these women but was awed by their toughness - and sacrifice.

The one down point of the day occurred as my guide showed me the remains of the hut that housed the world's first computer - hut F. The only thing remaining is a concrete slab - the hut itself was knocked down by a housing developer in the early '80s. The rebuilt Colossus II is now housed in a hut a hundred yards from where the original stood.

It is estimated by some experts that the code-breaking carried out at Bletchley shortened the war by two years, and sparing Berlin from an atom bomb. Whether or not that is true, what is clear upon visiting Bletchley Park is that this group of scientists, like those at Los Alamos, moved forward computing at an unprecedented pace, in the years from 1938 to 1945.

Thursday, May 15, 2008

Protecting The (Brand New) User

Over the past few weeks, I've had the opportunity to meet with literally dozens of leading banks and financial service providers, as part of the Authentium SafeCentral rollout.

Authentium SafeCentral, for those unfamiliar with the service, provides consumers with a simple, highly-effective way of securing online banking and transaction sessions, by combining a locked-down virtual desktop with a secure browser and dedicated secure DNS network.

For the most part, banks are doing a good job of deploying and employing additional security layers and user authentication methods.

I witnessed a number of very practical and well-designed technologies, including several practical and well-designed out-of-band text-based transaction confirmation systems, and some terrific automated fraud and AML (anti-money laundering) controls.

However, one glaring gap in security that almost everyone agreed needs improvement is the issue of how to protect the personal data supplied by a "brand new user." Nobody I've spoken to has yet gotten this right.

Visit the web page of virtually any bank (except those than only allow branch-based processing of new accounts) and you'll see what I'm talking about. Most banks host multiple online application forms for credit cards, home equity loans, insurance, and numerous other products.

All require massive amounts of personal data to be entered at the time of application.

Which leads to a problem. At the time of the application, the only security is "implied" security - which is to say, the user assumes that the bank is somehow protecting them while they go through the process.

In actuality, both parties are "flapping in the wind" when it comes to this data transfer. Banks don't yet know their (new) customer, and cannot verify if the data is legit or stolen, and cannot protect the user using anything more sophisticated than an SSL session.

In the event of a breach, users, unfamiliar with the site, don't know they are being redirected to a phishing site, a spoofed sign-up page, or a page designed to serve up malware.

During this critical application process, the user is, for possibly the only time in the banking relationship, laying out every single personal detail, include the details most critical to their identity - for the world (and any installed keylogger or screen-scraper) to see.

Here's an example of how this can affect behavior - and the pace of account sign-ups.

While having a very pleasant lunch recently with the CTO of a billion dollar financial services firm, we got to discussing Mint.com (a service that we're both fans of, in concept), and discovered that neither of us had gone "all the way" through the sign-up process. We'd stopped short of plugging in our accounts.

Why? Security. The part in the sign-up process where you need to share all your passwords to all your bank accounts "in the clear" - without any prior relationship being in place with the company, and any knowledge of security processes - was just too scary for either of us.

Which is a shame, because the service Mint offers looks tantalizingly good.

Obviously, our service - SafeCentral - offers a possible solution here. And it wouldn't be an expensive solution. Offering it as part of a new account sign-up wouldn't cost Mint (or anyone else in the business of signing up new users online) anything - there's a 30 day free trial version.

And it would help those users (like me) that are deeply uncomfortable sharing personal data online - and help plug a hole that I am certain, based on my recent conversations, that online criminals are bent on further exploiting.

Whatever solutions are eventually utilized, these gaps for me loom larger ever time I visit a financial services site. I feel for the (brand new) user, who has no way of knowing whether or not their personal data is going to be protected, or stolen, as a result of applying for a new service.

Lori Drew Indicted in MySpace Hoax

Several months ago in this blog, I predicted that US Federal authorities would find a way to prosecute Lori Drew, the alleged perpetrator of the Dardenne Prairie MySpace cyberbullying effort that resulted in the death of Megan Meier, her teenage neighbor.

My prediction was based on the fact that Drew's alleged messages undoubtedly traveled through the MySpace Los Angeles data center - a detail that I thought would enable Feds to take an interest in the case.

The good news out of Los Angeles today is that the Feds there have come to the same conclusion, and indicted Drew. I doubt this action would have been taken without some serious reflection on behalf of prosecutors, and careful examination of the evidence.

Regardless of whether or not Drew goes free at the end of this (I'm sure First Amendment free speech rights will form at least part of the argument for the Defense), Megan's mother Tina and the rest of the Meier family - and other families affected by cyber-bullying - can at least be comforted that some level of justice may be in sight.

Undoubtedly the case, when it comes to trial, will get massive media attention - and spur some attempts at legislation. Watch this (My) Space!

Note: On the subject of parental controls, I've been recently playing with a new version of Authentium's SafeCentral that enables parents to lock their kid's surfing choices to a manifest.

This service, which will hopefully launch this year, adds some new options to parents seeking to protect kids from some of the more extreme users (see above) of the more anonymous social networks, like MySpace.

Friday, April 25, 2008

Phishing Scams - What's Old is New Again

The amazing thing about crime is that criminals continue to perpetuate the same old scams, with remarkably good results, time and again.


I just finished reading "The Rescue Artist" this morning - the story of the recovery of Munch's "The Scream", post its theft from an Oslo museum in 1994. It's a good read. But what stands out is the number of times criminals have perpetrated exactly the same crime against exactly the same asset, with outstanding results.

An example: The most valuable paintings shown in Russborough House, a private gallery outside of Dublin, have been stolen four times in twenty years - from exactly the same hooks on the wall. No doubt the police and insurers have advised the owners several times as to the weaknesses in their systems. Yet the crimes keep being committed.

Like other security companies, Authentium has a number of antiphishing partners and approaches, including interception and user education. The challenge seems to be that as far as user education is concerned, the lure of gain will ensure the crimes keep on being committed, over and over again.

Case in point: Today, I received an email from The Camelot Group PLC, Operators of "The Uk National Lottery" (note lower case "k"), informing me that I have won over $1.2m.

Reading through the phishing email, I had the feeling that I was viewing an extremely amateurish "first time" output of a phishing kit. The obvious grammatical issues and bad use of cut and paste stood out like beacons.

But even though it reeked of a scam, I knew that someone somewhere was busy sending in their personal details to the hackers. Half a million pounds is a lot of money. Which is why this stuff keeps working, and will continue to keep working for years to come.

Note: We have a new beta phishing interception approach scheduled for release on May 22nd that will provide users with a much better feedback mechanism than currently exists. Stay tuned.

Saturday, April 12, 2008

UAC Is Not Terrible

David Cross, a product guy at Microsoft, today came out and admitted what all of us Vista users already know - UAC was designed to be annoying.

But let me buck the trend here for a second. I don't think UAC is anywhere near the devil people are making it out to be.

Sure, there are things about Vista that I don't like (does the redesigned folder hierachy drive anyone else nuts?), but I'm actually a fan of the UAC, and as a power user - someone who uses more than five apps for more than five hours a day - I get to see a lot of it.

Here's why I'm a fan: as a warning system, it works. When UAC is in focus, you can't miss it. It forces you to make decisions. It talks to you using language that I think is well-chosen for users at any level:

Don't run this program unless you know where it's from, or you've used it before.

In my experience, user interfaces rarely include instructions that are this well thought-out, in terms of conveying precisely what the user needs to consider in their action.

I'd love to know who came up with this line. I wish all UI's could contain instructions this clear. Unfortunately, few do. Most are written by people with far too much knowledge in how their systems work. Most UIs interface badly.

Many moons ago, long before co-founding Authentium, I got a grounding in user interface design working with the extremely smart folks at KRDL in Singapore, then MIT's sister lab in Asia. A lot of folks were extremely generous with their knowledge there, and over the course of being around them, I got a lot of advice and also got handed a lot of papers from over thirty years of research into UIs.

Much of the research in the area of user interface design over the past thirty years is well summed up in the book "The Media Equation". This book is a masterpiece of simplification when it comes to user interaction with machines, and they boiled the results down simply:

* Users prefer bigger displays over smaller displays
* Users prefer active video over inactive video
* Users like interacting with video using graphic displays
* Users prefer menu hierarchies that visually reflect the importance of each level
* Users rely on audio for narrative, video for context (users hate discontinuous audio)

On the subject of trusted user interfaces, UAC does almost everything right. It presents itself as a global, or overarching warning system (the most effective kind of warning - as with the severe weather alerts we get in Palm Beach, you are forced to pay attention), it presents a clear and logical explanation of what the user should consider in taking their next action, it presents a limited number of options, it disables screen-capture or outside manipulation of the control, and the frequency of display is entirely up to developers.

I know I'm going to get emails from friends and colleagues on this, but given the amount of increasingly bad malware out there, I personally thing UAC was a smart inclusion for the world's most widely-distributed operating system.

Now, about those folder icons... ;-)

Note: One of my favorite stories about the relative important of video and audio in user interface design for narrative media involves Thai Kick Boxing. Once, in Vietnam for WorldSpace, I met a man who told me about makeshift village cinemas that were being run up-country in Laos - primarily so people could keep up with the latest kick-boxing champions.

He described a shack with a dirt floor and the snowy screen of a black and white television in one corner - a television that was running off a bank of car batteries. He said, often times the video reception was so poor, you could barely make out the participants at all - but he said, so long as the audio was clear, people would not demand their money back.

Saturday, February 23, 2008

Simple Decryption Using Dust Remover

The New York Times reported this week that Princeton University researchers, armed with nothing more than Homeland Security funding and some cans of household dust remover, have come up with a method for cracking even the strongest encryption keys.


According to the Times' John Markoff:

The move, which cannot be carried out remotely, exploits a little-known vulnerability of the dynamic random access, or DRAM, chip. Those chips temporarily hold data, including the keys to modern data-scrambling algorithms. When the computer’s electrical power is shut off, the data, including the keys, is supposed to disappear.

In a technical paper that was published Thursday on the Web site of Princeton’s Center for Information Technology Policy, the group demonstrated that standard memory chips actually retain their data for seconds or even minutes after power is cut off.

When the chips were chilled using an inexpensive can of air, the data was frozen in place, permitting the researchers to easily read the keys — long strings of ones and zeros — out of the chip’s memory.

In other words, simply by freezing the memory chips on which the keys have been stored, you can cause the data to stay around long enough to decrypt even the longest, most secure keys.

That is not good news for anyone in the defense, media, or communications business.

The usual IT security forums have been abuzz on the topic - and because this hack affects Windows and Linux/Apple OS's equally, the posts have been unusually bipartisan, which makes a nice change.

"Nick", a poster at The Register, articulated the type of hack that is most likely in a corporate or core research environment - a drive-by download based on physical access to a machine that leaves almost no trace:

"The more worrying attack is the 'room temperature' one, where by you could power cycle the machine and dump the memory to the USB drive (as they did), and then leave the scene quickly. The user would just come back and mutter "stupid Windows" at the machine that crashed whilst they were at the coffee machine."

It will be interesting to watch the rebuttals come in over the coming days and weeks - especially those from dedicated security chip manufacturers. Unlike security software development firms like Authentium, hardware security companies typically maintain massive plants and large investments in materials and inventory.

It's anyone's guess as to how these companies will react to this news, and what their researchers will demand in terms of new materials - after all, they are going to need to quickly extend their existing tamper-proofing techniques to include protection against freezing. That won't be cheap , and will probably require new inventories - if in fact it even proves possible.

The first solutions to market will no doubt be neither cheap, fast, or good. But long-term, as long as there are valuable secrets in the world or commercial systems that are dependent on robust keys, there will be *lots* of venture money available for smart folks who think they have the solution to this problem.

Thursday, January 31, 2008

P2P Loans and Kiva.org

If you use LinkedIn, you're probably familiar with Kiva.org. Kiva has done an outstanding job using the Group functionality in LinkedIn to grow awareness of the work they are doing in the area of providing syndicated loans to third-world entrepreneurs.


Kiva's microfinance model seems to be working - at least for me. This morning, my first loan - to a female grocer in rural Mexico - was repaid on time, and in full.

Rather than withdraw the money, I have now joined a syndicate that will provide $1025 (all Kiva loans are around this size) to Baqi, a wood salesman living in District 10 in Kabul, Afghanistan. Baqi's use of funds is to purchase stock, so he can expend the business. Kiva provides a useful hub for enabling financing of this kind of basis funding requirements, and their syndication technique enables the risk to be spread across a multitude of lenders.

Incidentally, there are a ton of emerging fist-world "Kiva.orgs", such as Prosper.com, that are well-known and well-trafficked. If you're a subscriber to Jim Breune's excellent Online Banking Report, you're probably aware that he is predicting that 2008 will be the year that peer-to-peer loans move from the back of the wave to the front.

Check out the above graph (based on Celent data) that was published here in USA Today. It certainly seems to back up what Jim has been saying in OBR.

Prosper.com reminds me of PayPal circa 2002 - some teething problems, some fraud issues that occasionally get in the news, but I personally find the service fascinating, and I think it provides a useful secondary source of funds for people that have had their identities or credit access compromised.

By the way, if you're interested in Kiva, head over to Kiva.org and sign up. For the low (starter) price of $25, you'll help create wealth, and learn a lot about the emerging P2P marketplace.

No Gender Bias in Identity Fraud

Candy Colp in our sales group sent me an interesting article yesterday regarding a study conducted by antivirus firm AVG into gender bias and online security. The crux of the article, which appeared here was:

"Most men believe that they know more about online security than women, but new research suggests that both sexes are equally vulnerable to malware and other threats."

The study, which involved 1400 presumably equally distributed by gender subjects in the UK, did indeed conclude that men and women and equally likely to fall afoul of malware.

But reading between the lines, the survey also indicated that men were more likely to assume that the security in place on their PC was adequate, versus women, who (more wisely) more often assumed it might not be.

This would possibly explain the tendency of some identity protection firms (see my most recent post below) to target women as customers using television and press.

Two points that I found interesting in the survey was the fact that 1 out of every three people surveyed in the UK had been victimized by identity theft.

AVG's spokeperson was quoted as saying most people felt there was nothing they could do about the situation.

Proactive Vs. Reactive Identity Theft Protection

As many of you know, Authentium is currently rolling out SafeCentral, a solution we consider the best identity theft protection solution on the market.


SafeCentral is the result of almost five years of core R&D (what used to be called VirtualATM is now the SafeCentral client), three years of service back-end development (our ESP platform), and a ton of feedback from users and distributors.

The purpose of this posting is to point out a critical difference between our service and other approaches to "identity theft protection."

The critical distinction between SafeCentral and other solutions offered up as "Identity Theft Protection" is that our solution is designed to *protect* identities - as in stop them from being stolen in the first place.

Other solutions are designed mainly to help consumer *reclaim* their assets - after their identity has been stolen.

These other solutions, well-branded and well-intentioned, don't provide proactive protection - they simply provide a financial guarantee that there will be money available for you if you need to hire lawyers to get your identity back.

As anyone who has ever had their identity stolen knows, there is a massive difference between these two approaches.

Using SafeCentral is like going into war already "armored-up" - using the other solutions is like going into battle, being wounded, and getting hauled off to hospital - and then finding out, as you fight for your life, that your health insurance is paid up.

I have only had my identity compromised once - when money was claimed by an impostor at the other end of a Singapore-USA international money transfer. Getting the money recovered was painful. It took a lot of international phone calls and three days of haggling.

I have been told that my experience was on the "lighter side" of identity fraud cases. According to the most recent statistics, identity theft victims typically spend a year and a half and around $2500 dollars getting things rectified.

This is the core reason why installing a proactive solution is important - as anyone knows, most of the time, you get your money back when defrauded online. What people don't know is how much of a hassle it is to get square., using a "reactive" solution.

When it comes to identity theft protection, Authentium SafeCentral = proactive, the rest = reactive. You decide.

Note: If you're interesting in joining the beta program and trying out the SafeCentral service for free, you can sign up here.

Tuesday, January 22, 2008

Credit Monitoring - A Vector for Hackers?

It's happened. Driving home tonight, listening to FOX WJNO, I heard a country music-based jingle for a credit monitoring service.

"They say a man should always dress for the job he wants
So why am I dressed up like a pirate in this restaurant?
It's all because some hacker stole my identity
Now I'm in here every evening serving chowder and iced tea

Should have gone to Free Credit Report dot com
Could've seen this coming at me like an atom bomb
They monitor your credit and send you e-mail alerts
So that you don't end up selling fish to tourists in t-shirts"

Catchy - and certainly an indication that identity theft protection is headed for the mainstream. But WJNO listeners should beware - you could end up selling fish to tourists anyway.

The problem with consumer credit monitoring services like FreeCreditReport and other online identity protection services is this: the sign-up processes of these services are so easily spied upon that they expose consumers to the very problem they claim to solve - identity theft.

Yes, you read that right - while there is growing awareness of identity theft as a problem, consumers are not yet broadly aware that critical vulnerabilities exist during the account creation processes that have not yet been addressed by any of the major credit monitoring companies - or, for that matter, any of the online banks.

Think about it. During the service application or credit card application process, the maximum possible amount of personal data is exposed to hackers running key-loggers or screen-capture software on your system. Yet at this time, no meaningful legal relationship yet exists between you and the company requesting the data.

Not following my argument? Think about the amount of data you shared the last time you applied for a financial service, such as a credit card or loan, online. Think about the data you shared last year, while submitting your taxes. Did someone tell you up front that they would take responsibility for any data lost by you during the sign-up process?

I didn't think so.

And, chances are, you shared a lot of data during that session - your social security number, your spouse's social security number, your employer, your bank account details, your address - everything on the identity thief's checklist.

There's no doubt that the Citibank ads of last year, and the new FreeCreditReport.com radio commercials are good for consumer awareness. However, these companies need to do more to protect data during the sign-up process - and during the browsing session as well.

Consumers need to speak out as well. Consumers should insist on using services and technologies like the one that we've developed - Authentium SafeCentral, which uses our patent-pending VERO secure session technology.

This kind of technology enables true end-to-end protection for data against key-loggers and screen-capture-based spyware, even if you're just starting out your relationship with a financial service provider.

There is no reason why your provider shouldn't enable this service - we give it to them for free. Alternatively, starting Feb 26th, you can go over to www.authentium.com and sign up for the service yourself.

All of us at Authentium use SafeCentral every day. We wouldn't dream of signing up for a new personal financial management service, credit monitoring service, or bank account, without firing up SafeCentral first.

You should think about making this a habit too.

NASDAQ at 0930

The news overnight from Asian markets, particularly India, and this morning from Europe, meant a lot of people got out of bed early this morning in the US to do what they couldn't do yesterday because of the holiday.

The result was predictable - this from NASDAQ.com:


One of the stories that will come out of today is the story of how much financial information accounts for in terms of total Internet traffic.

The NASDAQ server wasn't the only one groaning the the weight of information requests from the anxious public investor pool this morning - repeated requests to Google servers ended up with half-built pages and missing information.

Saturday, December 15, 2007

"Entrapment" Meets "Ocean's Seven"

Before I start this post, let me make one thing clear: I hate terrorists. I think terrorists and criminals that actively plan to reduce the quality of our lives and destroy things precious to other people are the lousiest creatures on the planet.

Now that this is understood, let's discuss the Miami Seven, aka "Ocean's Seven".

That group of supposed would-be terrorists was handed a combination of acquittals and mistrials yesterday by a jury of their peers when defense lawyers were able to suggest that, absent the presence of government agents, there exists a reasonable doubt that there never would have been a crime worthy of prosecution.

Maybe it's the fact that this is taking place just an hour away, but this case has concerned me from the start. This is Ocean's Seven played by seven hapless saps, with a government stooge standing in for Andy Garcia.

As Albert Levin summed up for the defense:

"The entire situation was concocted by the government. The warehouse was paid for by the FBI, and the defendants moved their operations there at the suggestion of an undercover informant who was also paid by the FBI. The [Al-Qaeda] swearing-in ceremony was led by the informant — who at another point also suggested a plan to bomb FBI offices in Miami. The case was written, produced and directed by the FBI."

Now I'm a big fan of the FBI and I'm extremely thankful that these guys exist. But when I take this case and extrapolate this case into the world that I work in - Internet crime - what emerges is a really lousy picture.

Imagine or a moment the government decides that Internet crime needs to be "managed" the same way - by embedding agents and encouraging criminal activity.

In this scenario, the government agent rents an office, recruits computer programmers, moves them into cubicles, gives them PCs, connects them to a network, trains them, guides them, and then encourages them to develop a bunch of malware and unleash a sophisticated criminal action against consumers.

At which point they become criminals.

Assuming the FBI guy is the smartest guy in the room (and a natural leader, whom people feel compelled to follow), should the hired programmers be considered "criminals" or "feckless* pawns"?

As much as I hate terrorists, I hate "fake crime" so much more. Albert Levin made the right summation for the defense. Jeffrey Agron, foreman, and the rest of the jury in Miami, made the right call, regardless of the potential any of these individuals may have had for evil.

Inducing criminals to conduct a crime is the wrong way to reduce terror and the absolutely worst way to run a police force.

The FBI can serve us better by reporting on crime and prosecuting criminals, rather than encouraging the progress of would-be criminals.

Contrary to prosecutor Jacqueline Arango's statement, in which she said "The government need not wait until buildings come down or people get shot to prove people are terrorists" - I'm sorry, but you really do need to wait.

Because a lot of the time, when people say they plan to do something, they don't. Not without a strong leader. The FBI should leave the big talkers underfunded and discouraged - that's the best way to fight crime.

*My thanks to Doug Brunt and Megan Kelly for their introduction to the word "feckless" earlier this evening. "Feckless" (i.e. feeble and/or ineffective) describes this group of would-be criminals precisely.

Sunday, December 9, 2007

How To Turn Off Facebook Beacon

Facebook CEO Mark Zuckerberg reacted to angry users this week by issuing a public apology and adding a privacy control web page for Facebook users.


Checking "Don't allow any websites to send stories to my profile" turns off Facebook Beacon and your purchasing choices (i.e. "John Sharp just rented Pride and Prejudice at Blockbuster") will no longer be published to your friends' News Feeds.

This is a welcome step, but it didn't need to be this way. All Facebook needed to do was take a step to the other side of the table and "think user".

It isn't that hard. Take this user posting from "Adam" in the comments section of the recent NY Times article on Beacon.

In less than a hundred words, he provides an articulate and sensible accounting of all the necessary UI components Beacon would require to be acceptable. Here's a sample of some good "think user" thinking:

Had Facebook included a global opt-out option at the beginning, the outcry would have likely been muted. Coupled with an opt-in-by-item with a STRAIGHTFORWARD yes/no, Facebook users would have been happy, privacy advocates would have been happy, and so on.

I mean, something like this:
“Would you like to let your Facebook friends know that you just bought [x] from [y]?
_ YES, SHARE. List this in my friends’ newsfeeds.
_ NO, DON’T SHARE. Keep this private.

NOTE: You can click on PRIVACY in Facebook to set a default for this feature.”

Adam, maybe they should give you Chris Kelly's job.

Facebook isn't out of the woods yet. There is still the question of what happens to user data provided by the user.

In Zuckerberg's recent blog/apology, there was no mention of any changes to their method of dealing with user data, and no clarification as to whether or not the personal data provided by the user is deleted immediately, rather than "stored, then deleted".

In a recent statement released by Facebook to Stefan Berteau, senior spyware research engineer with (Authentium partner) CA, Facebook says user data is always sent to Facebook ("in order for Facebook to operate technologically"), but that data will be deleted from its servers, once they receive the news that the user has opted out.

"When a Facebook user takes a Beacon-enabled action on a participating site, information is sent to Facebook in order for Facebook to operate Beacon technologically. If a Facebook user clicks "No, thanks" on the partner site notification, Facebook does not use the data and deletes it from its servers. Separately, before Facebook can determine whether the user is logged in, some data may be transferred from the participating site to Facebook. In those cases, Facebook does not associate the information with any individual user account, and deletes the data as well."

I look forward to seeing Berteau's follow-up Wireshark capture logs and analysis. It would be nice to find out that Facebook has kept its word on the changes.

Note: Facebook users, here's that link again.

Saturday, December 8, 2007

Man Loses $20,000, eBay Says "Not Our Problem"

Shaqir Duraj appears to have become the latest person to lose money to an eBay fraud.

CBC News reports that Duraj, a Calgary bakery owner, lost $20,000 last Thursday, after purchasing a car at a site that he thought was eBay Motors. The sale later turned out to be a hoax.

This sounds like a replay of that incident - in which a US-based eBay customer lost over eight thousand dollars when she purchased a fictional Jeep Cherokee via a fake "eBay Motors" site that was downloaded onto her computer by the BayRob Trojan.

eBay has obviously decided what its strategy is going to be re customers who get taken by elaborate electronic scams that use the eBay brand - blame it on the Internet.

In fact, after hearing about the $20,000 theft, Erin Sufrin, Public Relations Manager at eBay's Canadian subsidiary, told Canada's CBC News, "That's an internet problem, not an eBay problem."

She went on to offer the following advice:

"Spoofing and phishing is something that we're all a victim of and that we try very hard to combat — trying again to get that education out. Never click on — if you think it's a fake eBay, or a fake PayPal or a fake anything site, report it."

Ms. Sufrin added, "eBay is working with the RCMP to get help for customers scammed out of large amounts of money."

According to the CBC News web site, this contradicted a Royal Canadian Mounted Police fraud investigator who told CBC News no one from eBay had returned his calls.

Am I the only one who thinks eBay customers deserve better?

Note: eBay *only* covers frauds up to $20,000 that take place on the eBay Motors site. Frauds that take place outside of the eBay environment (regardless of whether or not your thought you were inside the "real" eBay environment at the time) are *not* covered by the terms and conditions listed on the eBay Motors site, specifically:

"The eBay Motors Vehicle Purchase Protection (VPP) program provides protection of up to $20,000 against certain losses associated with some types of fraud. You are automatically enrolled in the program at no charge when you complete the purchase of an eligible vehicle on the eBay Motors site (motors.ebay.com)."

Update 1: On Thursday, PR Manager Erin Sufrin added some new details, saying that the scam involved a BMW and a hijacked high-rated seller account (not a downloaded BayRob version of eBay Motors). She added that a "warning" was sent to Duraj.

Further Q's for Ms. Sufrin: Was the warning sent by eBay-branded email? If so, should Duraj (the buyer) have assumed the email to be a hoax email? Or should he have assumed it to be real? Also, isn't it reasonable to assume that payment instructions from a seller with a 98% (high) reputation should be trusted?

"Cyber Attackers" are Looking for PII, Not Nukes

The headlines keep coming about the news that several high-profile military labs - including some of the world's leading nuclear research labs - have been compromised by phishing scams. Unfortunately, many of these headlines are missing the point.


Example: In one story published today, PC World claims that Chinese Hackers "launched" a coordinated "major attack" on two US Military Laboratories.

This is almost certainly *not* what happened. According to most of the published data, this was a phishing attack, plain and simple.

Case in point: The "FTC" phishing scam, cited by ORNL reps. As I blogged yesterday, this scam has been around for months, and is extremely widespread. In fact, Authentium's malware lab analysts first reported this scam in March.

The scam typically targets the capture of PII (Personally Identifiable Information) - such as the data that appears to have been stolen from the Oak Ridge Labs visitor database.

Need more evidence for the theory these are phishing scams, rather than coordinated, military-style attacks?

According to a link on the PC World web page hosting this article, those very same "Chinese hackers" are also hard at work "attacking" major oil companies and manufacturers of jet engines (check out the above link in the posted image under "Related Content", entitled "Chinese Hackers Accused of Attacking Shell, Rolls-Royce") .

Does anyone really think there is a coordinated attack going on right now against the US Military, Rolls-Royce, Shell Oil - and consumers?

Folks, the real story is, in some ways, far more scary than the one being reported by PC World.

It would appear, unfortunately, that we now have evidence that really smart people fall for phishing scams too - and sometimes those smart people happen to have a large database on their network filled with the personal information of other really smart people.

And sometimes, databases filled with nuclear secrets.

Update: To Steve B's point, these DBs *are* air-gapped, but physical separation is only successful if policies are adhered to - see comments below.

Let me repeat what I said yesterday: the technology exists to stop these kind of attacks. And some of that technology can be used in really simple ways.

Firewalls and email servers, when configured correctly and used in conjunction with robust filtering technologies and/or services located either in the DMZ or inside a secure MSSP data center, can provide a useful first-level defense.

Note: One additional approach used by some IT administrators at ISPs and businesses is the wholesale blocking of IP addresses, or super-blocks, based on the country or region originating the email.

You need to be careful when taking this approach - for example, Australia and China share the same registry (APNIC). But as an additional defense mechanism, it probably should be on this list for consideration.

Which of course leads to the obvious (political) question: Do folks that work at sensitive places like Los Alamos or the Oak Ridge National Laboratory *really* need to be able to receive email from China?

Friday, December 7, 2007

Phishing Attacks Fool 1% of Nuclear Scientists

The Secretary of the Department of Homeland Security, Michael Chertoff, announced today that IT systems at the Oak Ridge National Laboratory have been compromised by phishing.


Secretary Chertoff confirmed the attacks Friday and added:

"Thieves made approximately 1,100 attempts to steal data with a very sophisticated strategy that involved sending staff a total of seven 'phishing' e-mails, all of which at first glance appeared legitimate."

A DHS spokesperson further confirmed:

"...
the hackers potentially succeeded in gaining access to one of the laboratory's non-classified databases that contained personal information of visitors to the laboratory between 1990 and 2004.... the personal information at risk includes names, dates of birth and Social Security numbers of the visitors..."

According to ABC News, one of the fake phishing e-mails appeared to be an announcement for a scientific conference; the other claimed it was a notice of a complaint on behalf of the Federal Trade Commission.

The internal investigation of ORNL, which is ongoing, has so far found that approximately 11 employees out of 1100 targeted "took the bait" and opened the e-mail attachments, "which enabled the hackers to infiltrate the system and remove data."

In other words, phishers scored a hit rate of 1% against employees at one of the world's leading nuclear research facilities.

Let's discuss. First of all, if the target is a consumer, any form of well-crafted phishing attack, such as the recent FTC letter scam, can be called "sophisticated." Consumers are typically not well protected and do not have large IT budgets and enterprise-class filtering systems at their disposal.

However, if you're a four-thousand person enterprise like ORNL, this attack is inexcusable.

Secure Computing, Postini (Google), Microsoft, WebSense, MessageLabs - there are literally hundreds of ISVs and service providers out there, many of whom partner with Authentium, that are highly capable of providing extremely robust, and affordable, email filtering services that can and will prevent these emails getting to in-boxes inside sensitive government facilities.

And then there are emerging technologies such as Raytheon SureView that enable recording, rapid response, and treatment of behavior contrary to an enterprise's security policy, such as clicking on attachments in emails.

Authentium to ORNL: these phishing attacks were "consumer-grade" attacks. Technology exists to stop them. There is no excuse for allowing these attacks to occur within the walls of one of the world's leading scientific facilities.

Note: If you have visited ORNL within the last five years, you should probably give them a call and find out if your data was housed in the database that was compromised. You can do this by contacting ORNL Visitor Services at 865.574.7199.

Wednesday, December 5, 2007

EV Certs Don't Stop Phishing

Earlier this year, Netcraft published a survey that showed more than there were more than 600,000 "secure sites" capable of hosting an SSL session on the web.


To quote Netcraft, "The first survey, in November 1996, found just 3,283 sites; since then, the number of SSL sites has had an average compound growth of 65% per annum."

As an indicator of commercial activity, I think this is a useful survey. If you accept the premise that mergers and acquisitions lead to less new certificates being issued, then the growth in e-commerce may actually be in excess of 65% annually.

Which brings me to the biggest potential failure on the SSL roadmap to date: EV Certs.

The recent launch of EV (Extended Validation) merchant certificates by Microsoft, Verisign and others has not exactly set the world on fire. By May this year - the last time data on EVs was published by Netcraft - the total number of EV certs being utilized by Internet merchants was just 700, or 0.1% of the total.

There's a good reason for this: EV certificates don't work.

They don't stop phishing, they don't communicate well to users, they do away with the SSL padlock, and the whole thing is so easily spoofed, it may as well not be there.

You don't have to take my word for it - there is a scientific study available conducted by Standford University and Microsoft Research that backs this up.

The findings of the analysis were unequivocal: users paid zero attention to the green background applied to the address bar by the EV cert:

"We presented a controlled between-subjects evaluation of the extended validation user interface in Internet Explorer 7. Unfortunately, participants who received no training in browser security features did not notice the extended validation indicator and did not outperform the control group."

The results improved slightly after a reading of the IE Help File, but then the group uncovered a second problem - the EV-powered address bar can be spoofed very easily, essentially rendering any investment in education, or pushing people to read the manual, completely valueless:

"Like its predecessor, the lock icon, extended validation is vulnerable to picture-in-picture user interface spoofing attacks. We found these attacks to be as effective as homograph attacks, the best known phishing attack."

They are absolutely right on this count. As our Chief Scientist, Helmuth Freericks, has previously warned, creating a spoofed version of this attack is rather trivial.

So how can consumers get their hands on real security? Obviously, there is a real need for innovation. At Authentium, we have spent three years designing a secure Internet browsing environment that does away with the need for UI gimmicks. In other words, we've followed the advice of Stanford and Microsoft researchers:

"Designing a user interface that resists both homograph and picture-in-picture attacks should be a high priority for designers of future browsers."

That's what our guys have done. To take a look, click here, or take a look at Corey's video about VERO and VirtualATM in the right-hand column.

Tuesday, December 4, 2007

IC3 Internet Crime Complaint Form Rates An A+

Earlier in the year I published a post about the Federal Trade Commission's Identity Theft Complaint Form.


At the time, I believed the FTC asked for way too much information, and risked becoming a serious secondary contributor to identity theft.

Unfortunately, nothing much has changed - as you can see from the above image, the FTC form still exposes way too much user information to any key-loggers and screen-scrapers running on your PC.

This is why I was very glad to find that the FBI have taken a different, and in my view far more sensible approach to logging reports regarding Internet crime.

There are two things I particularly like about the FBI site. The first is that it places emphasis on engaging with local law enforcement offices about the crime, including establishing a process for isolating who you need to talk to, and how you should contact them.

The second thing I like about this form is that it doesn't collect too much personal information to be a threat in and of itself. Only the reporter's name and address is captured. The rest of the data collection schema is clearly focused on collecting information designed to help resolve the crime, rather than information that could potentially further compromise the victim.

Authentium says: the FBI and their Internet Crime group deserve an "A+" for this service, and the design of the IC3 form. If you find yourself the victim of an Internet crime, and don't know what your next steps should be, this is potentially a very good first step.

Sunday, December 2, 2007

Coming Soon to Second Life: FBI Field Office

Second Life, the popular "virtual world" created and operated by Linden Labs, is certainly proving to be on the cutting edge of real/virtual legal issues.


First, back in May, German police launched an investigation into alleged inworld child pornography (this investigation ultimately seems to have subsided in the wake of the recently-announced deal between Linden Labs and Washington DC-based age-verification company, Aristotle).

Then ten days ago, virtual thieves stole at least US$11,500 in *real money* from avatar-customers of virtual banks located inside Second Life.

According to Nobody Fugazi, an avatar/commentator who runs a Second Life fan site called your2ndplace.com, the hacked Second Life banks included L&L Bank and Trust, SL Investor's Bank, Giovinazzo Choice Investments, Whitfield Holdings/Royal Invest and SL Business Bank.

L&L Bank and Trust has admitted they lost $11,000. Nobody Fugazi was quoted on Massively.com as saying he believed SL Investor's Bank did not suffer any losses.

When the news broke, users, who spend about US$1.5mm in real money every day in Second Life, were understandably upset (one blogged that "the sky ripped apart" when he found out the theft had happened). Second Life citizen "Gr1zz" left this response, not untypical, at Massively.com:

"I have alwase felt virtural property IS PERSIONAL PROPERTY! Wether you work long and hard for in game credits, or purchase them with real dollars, its damaging when you loose it. "

Spelling mistakes aside, this comment raises some interesting questions about Second Life, the nature of its assets, how its citizens feel about those assets, the duty Second Life has to protect their value, and the whole idea that an entire economy and banking environment based on the US$ should be allowed to exist, regulation-free.

$11,000, the "real" amount publicly acknowledged as lost by L&L Bank and Trust, would probably not normally be a large-enough amount for the FBI to get involved, but if they don't get involved, what is going to happen when things get serious?

Authentium says: the FBI should consider treating these virtual heists as real crimes, so we're ready and prepared when the first large-scale virtual heist happens inworld, which may be for a considerable amount more Linden dollars than the heists two weeks ago.

Note: Anyone wishing to peer inside the mind of a Second Life bank should venture here for an informative read, courtesy of the SL Investor's Bank blog.

Note: The chart above is courtesy of the Reuters inworld Second Life news office. To see the live updating Linden dollars vs. USD conversion and daily spending widgets, click here.

Saturday, December 1, 2007

FaceBook's CPO Should Step Down

Facebook announced this morning that they are in the process of modifying Beacon, their advertising service, so your shopping decisions will no longer be broadcast to your friends on Facebook, and your privacy re-respected.


This is a step in the right direction - and a big win for MoveOn.org and Internet activism. But Facebook's Chief Privacy Officer, Chris Kelly, should never have allowed Beacon to become a "consumer purchase broadcasting system" in the first place.

Try this simple test. Imagine you're at your local supermarket. You've finished shopping and you're placing stuff on the conveyor belt at the checkout counter, when suddenly the checkout clerk grabs a microphone and starts reading out the labels on your choices, item by item, broadcasting this information to every other person in the store.

Here's what your neighbors get to hear: Your food choices - including the items you just purchased for your special needs diabetic child. Your personal hygiene buying decisions. Your choice of magazines. Your alcohol and tobacco purchases. The flowers just just bought - hey, where is your wife? Are they really for her?

For a company that produces some pretty cool software, Beacon is about as uncool as it gets. Though there exist some obvious legal limits as to what can be broadcast - pharmaceutical or birth control purchases, medical treatments, insurance - there are still plenty of purchasing decisions that many of us would prefer remain private.

Example - the Facebook-Fandango link. I doubt that many people really want *all* of their friends knowing *all* of their content choices...

Everyone understands that Facebook needs to make money in order to keep operating. No reasonable person would deny that advertising is the right business model. But Beacon was really a step too far.

Everyone knows - and most people accept - that when you search on one of the major search engines, your actions will be tracked and recorded and added to a profile. Most people also understand that this purchasing data, like the data generated every time you shop at the supermarket, is an increasingly necessary part of business.

Without it, businesses cannot run as efficiently, or meet the needs of their customers as effectively, which ultimately means less productivity and higher pricing. That said, there is no precedent I can think of for the broadcasting of consumer purchasing choices to other consumers, either in the real world, or on the Internet.

This is the second high-profile, privacy-related incident faced by Facebook in less than a year. Authentium says: Facebook's CPO, Chris Kelly, needs to stop thinking about the bottom line and focus 100% on keeping personal information private - or he should step down and allow someone else to come in with a stronger consumer privacy focus.

In the event that you think I'm being a little harsh, Mr. Kelly had a chance to jump on the side of the consumer two days ago at the Commonwealth Club, but he presented himself as a Facebook executive first, and a consumer privacy advocate second.

Image from moveon.org.

Friday, November 30, 2007

HijackThis is Goodware

I occasionally get worried calls from friends saying they have seen our brand turn up on the Internet listed in a long list of programs under the heading "Hijack This".

This certainly does happen. A quick search on Google for "Authentium" will come up with several examples of logs created by folks who have downloaded and used the software, and discovered our software among other programs in their Startup menu.

Authentium says: stop worrying. "HijackThis" is a "goodware" utility program with an unnecessarily-scary name that is owned and maintained by Trend Micro. It enables consumers to quickly create log files containing details on all programs listed in their StartupList, and root out spyware and other potential nasties.

It's really something that only sophisticated users should use. As Trend Micro itself says, "HijackThis does not determine what is good or bad. Do not make any changes to your computer settings unless you are an expert computer user."

That said, it's a useful tool. Here's a short description from download.com:

If persistent spyware is bogging down your computer, you might need HijackThis. The tiny program examines vulnerable or suspect parts of your system, such as browser helper objects and certain types of Registry keys.

Pressing the Scan button generates a log of dozens of items, most of which are just customizations. Don't check off an item and hit the
Fix checked button unless you're sure it's malware.

Clicking
Info on selected item tells you why the entry was flagged as suspicious, but not whether it's actually malware. To find that out, search the Web for that item's name or go straight to a forum, such as SpywareInfo or Computer Cops. Saving the log creates a text document you can post to these forums.

The latest version adds powerful tools to the Config window. The process manager and hosts file editor help you excise virulent infections. The unique ADS Spy tool scans for alternate data streams, which some browser hijackers use to hide from spyware removers.

The program still installs into whatever directory in which you unzip the file, which can make it hard to locate. HijackThis is a serious tool for any user who needs to root out a serious infestation, but wield it with caution.

NZ Cops Praise "Bright and Gifted" Hacker

New Zealand police announced today they have, with the help of Dutch investigators and the FBI, apprehended an 18 year old resident of Hamilton, NZ.

The 18 year old is accused of creating - and selling to criminal gangs - an encrypted piece of malware that enabled professional criminals around to world to evade certain antispyware apps and cause more than $20 million in economic losses.

Martin Kleintjes, the head of the New Zealand Police Computer Crime Unit, knew exactly how to deal with this kind of criminal, and very quickly put him in his place:

"He is very bright and very skilled in what he’s doing. He hires his services out to others. [He is} one of the world leaders in terms of developing this sort of software - it’s absolutely first-class."

At the conclusion of this damning statement, sure to drive fear into the hearts of aspiring NZ hackers everywhere, Mr Kleintkes metaphorically patted the youth on the head, and sent him home to await a call back.

Test Question. You've just nabbed a bank robber that you're pretty sure has stolen $20m from a bank in downtown Auckland. Do you let him go home?

Despite the size of the crimes perpetrated, and the fact that the youth appears to have actively sought out criminal partnerships, the youth, known as "AKILL" online, is not facing an immediate stint in jail.

He has indeed been sent home by Mr. Kleintjes, pending further investigation. In addition, his identity has been protected, just in case some of the crimes he allegedly conducted happened prior to him turning 18.

Note: his crime was enabling identity fraud. Anyway see a contradiction here?

Authentium to New Zealand Police Computer Crime Unit: murderers can oftentimes appear intelligent and charming. That doesn't mean they should be mollycoddled. Cybercrime of this magnitude needs to be taken seriously and the perpetrators treated no differently than any other form of grand larceny, including bank robbery.

Consumers are sick to death of this kind of crime, and praise just leads to replication of effort. We need to start throwing the book at these guys.

Further note re this hack: Most sophisticated forms of antispyware or antimalware technology can detect encrypted malware of this type. Users should update to the latest available definition files regularly.

Tuesday, November 27, 2007

40% of Consumers Lose Trust in "Phished" Brands

YouGov and CloudMark have published a survey that brand managers might find worthwhile reading - not that they are likely to learn anything new. To the surprise of no one, brands, once phished, are no longer trusted by 40% of consumers.

From VUNet: "Banks' reputations were the hardest hit when it comes to phishing. Over 40 per cent of respondents said that a phishing email about their bank would put them off. A similar percentage felt the same about their ISP, 36 per cent about an online shopping site and 33 per cent about a social networking site."

That wasn't the most surprising statistic to me - according to the survey, only 26% saw it as a user-level problem, while fully 40% of those surveyed felt their ISP should be primarily responsible for stopping phishing attacks. From The Register:

One in four (26 per cent) of 1,960 adults surveyed reckon the main responsibility for protecting against phishing attacks lies with themselves, with a similar percentage (23 per cent) responding that their ISP ought to bear the brunt of filtering spam emails. A further (17 per cent) think the sender's ISP and email service provider holds the greatest responsibility in combating scam emails.

Also troubling is the news that VOIP-based caller ID spoofing (aka "vishing") appears to be well on its way into the mainstream of attacks in the UK as well. Here's Neil Cook, Cloudmarks's UK technology chief, quoted in the same article:

"If the recipient makes the call, it gets routed to a cheap VoIP answering system, which may have been set-up on a compromised host. The system captures the user ID and pincode to sell on to the highest bidder, who then has full access to your account. All the while the call seems very genuine. The reassurance of speaking to an individual rather than working online will lead to many instances of consumers falling foul to such threats."

If you've never set up a call center, this probably sounds like science fiction, but unfortunately, this kind of "vishing" is extremely easy to set up, very cheap, incredibly portable, and because it sounds so real and involves live call-center-like humans, rather convincing.

Full article here.

Saturday, November 24, 2007

"Koffi Anan" Email Scam

This morning I was forwarded an email from none other than "Koffi Anan", the former Secretary General of the United Nations.


Sadly, since leaving the UN, "Mr. Anan" has apparently forgotten how to correctly spell his own name. I guess it must have been the stress of the job.

That said, "Koffi" was considerate in wishing to apologize for all the email scams that have taken place under the masthead of the UN. He suggested that I contact a certain Mr. Jim Ovia at Zenith Bank Nigeria Plc, who has been instructed to forward me $150,000, no questions asked.

Folks, this ranks as probably the dumbest scam email I've ever seen. It is so outrageous that I'm left wondering if The Onion isn't somehow behind it.

If not, I take back everything I have said recently about criminals getting more sophisticated and intelligent, as a whole. Clearly, some criminals are evolving at a considerably slower pace than others.

Everyone, Authentium says: beware of any email that promises you money, or contains advice from a celebrity, or suggests you immediately contact a bank or lawyer you've never heard of because money is waiting.

Every single one of these emails is a scam, and if you respond, you're going to get duped.

Friday, November 23, 2007

BayRob Downloads Fake eBay to Desktops

The BayRob Trojan currently tormenting eBay Motors demonstrates some of the increasingly sophisticated tactics that online criminals are using to defraud eBay's customers.

Like most malware these days, BayRob appears to be primarily distributed in the form of a phishing email carrying eBay Motors branding. The Trojan is attached in the form of an image, which presents itself to the user as the image of a vehicle.

When the user clicks on the image, BayRob installs a web server, does a location search on the user's IP address, then launches the user's web browser and starts serving up fake pages designed to appear as if they are coming from eBay or CarFax or similar services.

According to Symantec, quoted by the Register, the web server is in constant communication with a "fleet of control servers" designed to mimic the auction site and constantly update the pages.

Consider for a moment what is happening here, from the end user's perspective. The end user's aim is to get a great car for a great price, from a trusted brand (eBay). The criminal's aim is to take money from the consumer without providing goods.

The criminal accomplishes this by using the trusted brand in combination with a reverse IP address lookup to place the cars in the fake ads just a little bit too far away from the user's home address. In this carefully-calibrated scam, the criminal has everything they need to control the user's action - control of price, control of the desktop, control of the transaction mechanism.

The sad part of this (or happy part, depending on how you look at it) is that there are solutions out there that can mitigate this eBay scam and remove the problem entirely.

Our technology, Authentium VERO, completely prevents these scams from occurring, by ensuring eBay pages are identified as coming from actual eBay web servers (not faked local web servers), and disallowing all other (fake) pages access to the user's web browsing environment.

For an example of how bad this might get, check out this story about how one potential buyer of a Jeep Cherokee lost $8,600 - and was unable to be compensated for her loss, because, according to eBay customer service, "the fraud happened outside of eBay."

Note: Symantec reports that one victim was recently almost scammed out of $10,000 but managed to track the money to its final destination - a Western Union outlet in Greece - and halt the payment.