HOME WHAT'S HEADFRY? CONTACT
Security week in review
FUD
Hot topics
Tip of the week
Home users
Security in the movies
Email a friend Print this page
Week of November 8, 2004

Two factor authentication takes hold

New Zealand banks ASB and Bank Direct are using software called Netcode (from US security vendor RSA) to improve the security of on line bank transfers over $2500.

Customers wishing to transfer more than $2500 into a third party account receive an eight-digit text message to their cellphone, which they have to enter online within three minutes to complete the transaction.

The idea is to put a roadblock in the way of criminals (who have obtained users' passwords and log-in information through various phishing scams, etc) who want to steal from on line accounts. Now they need the eight digit code as well to pull off the scam.

As nothing in life is free, customers will pay 25 cents each time a code is sent to their cellphones. If they don't have, or don't want to spend the 25 cents for the service, they can always use telephone banking, or, perish the thought - actually go into the branch and interact with a live human. read more

Note - 2 factor authentication means using something more secure than a dodgy old password to identify yourself on line or to a network. The trend now is towards using tokens (gizmos that look like key chains, often with memory and the ability to encrypt and store data) or biometrics (iris scanners, fingerprints etc) to augment passwords, and raise the bar for attackers.

Banks are so worried about phishing (see Hot Topics and Tips section) that some are reputedly scaling back Internet banking operations. This seems like a pretty wimpy response, and it is more likely that most will simply ramp up existing security with this type of offering - and,of course, make customers pay for it. They are banks after all.

AOl have recently announced such a service (by subscription). read more.

In a salvo to competitors, they also will offer free McAfee anti virus software to existing customers. read more

Ballmer does law - just not very well

Microsoft CEO Steve Ballmer probably should not give up his day job and turn lawyer any day soon. Chairman Bill Gates, by comparison, has always shown a finely honed appreciation for the finer points of the law (and how to use them to pulverize the competition). Probably got it from his Dad.

Ballmer, in a continued attempt to stop the inroads being made by open source software, has recently claimed that Windows is cheaper over time than Linux, more secure, and in a new twist - that it offers better IP indemnification to customers.

Needless to say, the Net has been buzzing with this story, as the fine print in MS contracts and EULA's (end user licence agreements) flies in the face of this gutsy statement.

The fact is - MS and all the other IT vendors will fight tooth and nail from having to indemnify customers against damage caused by viruses, worms and loss of business resulting from downtime - even if the proximate cause of such damage is their buggy software. see my Globe article that discusses the issues

MS have shown signs in recent days that they may extend very limited indemnification to a broader range of customers - other than huge customers (who can expect in any event to demand and receive more).

But don't be naive and expect a seismic change. And read the fine print. It's almost all bad.

Further reading

For an excellent book (and eye opener) on the use of the Law, lobbying efforts, and the manipulation of the regulatory environment to work over the competition, read 'Make the Rules' by Wharton Professor G. Richard Shell (we don't know him; never met him; it's just a good book).

Make your lawyers read it.

 

 

So what's headfry?

Headfry is a common, much used and loved expression in Ireland, the UK and Australia. read more...

 
 

Week of Oct 11, 04

 
   

Phishers seriously up the ante

Security company MessageLabs has found a small number of very nasty new phishing emails - they eliminate the need for fraudsters to con users into clicking on a link to a fake web site, where they are asked to enter on line banking details.

These most evil emails contain scripts that rewrite the host files of targeted machines. According to a report in UK based tech journal The Register, "this means that the next time a user attempts to access their online banking account, they will be automatically redirected to a fraudulent website instead, enabling their log-in details to be stolen"

read the story

It seems that the story we recently covered (see our archives) about a phishing scam at several Brazilian banks, may have utilized this new and very nasty ploy, to great effect.

Bottom line- Don't open any suspicious email - think before you click

For more on the latest phishing scams, see out Tips section and Hot Topics

Microsoft source code on the block

Further to our recent story about source code theft, it seems stolen Microsoft code is finally on the block - or at least the word is generally out that it is up for grabs. That is if you don't end up in jail first.

According to a story in Computerworld, a Connecticut man was arrested November 9 2004 on charges that he sold source code for Microsoft Corp.'s Windows NT 4.0 and Windows 2000 programs.

The Manhattan U.S. attorney's office said William P. Genovese Jr., 27, was charged with unlawfully distributing a trade secret, and could face up to 10 years in Club Fed and a $250,000 fine if convicted.

It seems that MS and the feds used a sting to flush him out- posing as an interested buyer. Money changed hands on line, before the inevitable knock on the door and the handcuffs were broken out.

Needless to say, it is a good day for MS when such a person hails from that radical hacker enclave that is Connecticut, rather than the farthest corners of Eastern Europe or other jurisdictions where laws to deal with this type of crime are deficient, and/or extradition unlikely. Plus, this type of sting operation by US law enforcement is not favoured by the courts in several jurisidictions.

In this instance, MS got lucky. Chances are, this person, if guilty, is a mere lacky- the top guns are heavily insulated from him and getting to them will be a far more difficult proposition.

No champagne in Redmond just yet.