<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3129434197637637826</id><updated>2011-07-28T23:45:32.061+01:00</updated><category term='information security USB spy encryption SOCA'/><category term='07755 postage scam'/><category term='OWASP Top ten 10 TCF FSA Security Requirements'/><category term='forbidden planet credit card scam hack PCI DSS'/><category term='pen testers secure email'/><category term='RBS misselling protection insurance'/><category term='GSX government uk births keylogging keylogger'/><category term='keyloggers linux infowar hack security'/><category term='phish secure email solutions'/><category term='social engineering blagging 192 google'/><category term='FSA IFA independent financial advisers DPA ICO data security'/><category term='protective marking'/><category term='life pensions security email pgp'/><category term='information loss'/><category term='paypal phish address security'/><title type='text'>There's Never Safety In Numbers</title><subtitle type='html'>It's commonly thought that the Internet provides us and criminals anonymity due to the sheer size of it all.  This blog presents a number of forensic and security articles to show that it's not necessarily true.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>17</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-8432808101297735133</id><published>2010-10-21T12:46:00.002+01:00</published><updated>2010-10-21T13:46:51.822+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social engineering blagging 192 google'/><title type='text'>Real Time Social Engineering</title><content type='html'>In "information gathering" circles the terminology "Open Source" refers to information that can be gathered overtly and in the public domain (rather than today's definition of code licensing).  I have been wondering just how easy it is to perform social engineering tasks using open source information in the sort of time that one could operate in conversation. &lt;br /&gt;&lt;br /&gt;Whilst social engineering is pretty unethical and it's not the business RapSec is in; I was attending a seminar about social engineering and attempted to see how much open source information I could attain about the speaker in less than 15 minutes whilst standing at a back of a crowded room.&lt;br /&gt;&lt;br /&gt;Here is my methodology:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Listen&lt;/span&gt;.    Clues are available from the subjects demeanour (middle class? got kids? clothing style, name, job, title, engagement ring, wedding ring, phone type etc)&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Plan&lt;/span&gt;.       If this is being performed in a short time then there are only certain facets of information that will be relevant - there is no point doing a normal graph of attack because there isn't the time and drawing out a plan will incite suspicion.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Gather&lt;/span&gt;.   One must never believe everything you read on the internet.  When I do this, I assign probabilities to each bit of data and then only follow high probability routes or indeed try to double check information from another source.  I multiply probabilities when working with data depending on other data.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;Gathering is quite hard on a mobile phone/small device.  So I have been wondering if it is worth creating an 'app' to field specially crafted requests to various sites to aggregate the response quickly and for the user to assign probabilities to each leg of the outcomme in order to quickly prioritise the investigation.  This has to be very fast.  The target data would then be given an overall percentage probability that the user could act on, or dismiss.  For most people, probably only useful at parties - but whilst performing a social engineering attack it would be very useful to be able to do this quickly from a standard mobile handset using open source information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;example&lt;/span&gt;&lt;br /&gt;For the case mentioned above, I was just testing to see how much data I could find from my phone and in the end got close to the financial KYC minimum in 15 mins. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;checked the name of the speaker.  speaker was female and many females use maiden names in a professional context.  I missed the first part of the talk so had to google "speaker first name" and company name to double check surname.  came up with one hit.  probability 100% (there was a photo and a movie)&lt;/li&gt;&lt;li&gt;the speaker was introduced to being a lot of things (in a humorous "maybe I have been suckered" way) but one crucial word "director" was mentioned.  If one is a director of a UK Ltd company then there will be an AP01 or a CH01 form at companies house.  Have WebCheck bookmarked into phone with spare credit and do a lookup.  This 9 times out of 10 provides home address and also age. In my case I got a 100% probability but typically this is not so certain if you have had no direct contact with the target.  For me this got a crucial middle name.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;double check the address: directors often don't update their address (this target had).  I tend to use 192.com which is quite good for getting previous addresses and date or birth.   Obviously previous address (especially shared flats) is very useful as legs of the investigation but in a real time situation they have to be forgotten about.  I got a hit on the targets name and middle name with a recent address.  Same as the one in companies house.  100% probability.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;I was at the back of the room and so I saw a rather large engagement ring.  There was another name at the main address so googled that to find a rather nice story about engagement on a university alumni website and so with reasonable precision I could say they were married - and here is where I made a wee mistake - I presumed that the target was operating under a maiden name (as many professionals do) and in fact, there wasn't a wedding ring hiding there, just engaged.&lt;/li&gt;&lt;li&gt;time ran out, but I would have gone back to 192. and looked for the wedding registration to treble check for better probability of outcome.&lt;/li&gt;&lt;li&gt;Made for an amusing question at the end of the seminar, job done.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;so summing up: I got name including middle name, date of birth, employment company including a little extra information about the company, current address, previous address (20% probability), partners name on a mobile phone, in 15 minutes.&lt;br /&gt;&lt;br /&gt;Websites that are useful for UK searches:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.linkedin.com"&gt;LinkedIn&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.facebook.com/advancedsearch"&gt;facebook advanced search&lt;/a&gt; and the facebook search sites&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.friendsreunited.com"&gt;friends reunited&lt;/a&gt; (not so good as it used to be)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.192.com"&gt;192&lt;/a&gt; - voters roll, telephone directory, companies house data&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.companieshouse.gov.uk/"&gt;companies house webcheck&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Skype Diretory&lt;/li&gt;&lt;li&gt;Google - but be smart.  Common names bring up to many false positives.  So include favourite sports, industry, company names and so on.  use Google crafted urls (see &lt;a href="http://theresneversafetyinnumbers.blogspot.com/2009/11/googling-for-protectively-marked-pdfs.html"&gt;previous &lt;/a&gt;blog article)&lt;/li&gt;&lt;li&gt;Google maps and streetview can provide contextual information but aren't that useful.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Proper social engineers use a far wider scope than this and will follow up and interact with high probability leads through the investigation using pretty much unregulated techniques and methods.  Be aware that the new data Protection rules prevent "Blagging" but the act does not include using the above websites.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-8432808101297735133?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/8432808101297735133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/10/real-time-social-engineering.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/8432808101297735133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/8432808101297735133'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/10/real-time-social-engineering.html' title='Real Time Social Engineering'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-6378841494096535819</id><published>2010-09-30T08:38:00.005+01:00</published><updated>2010-09-30T08:58:26.309+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pen testers secure email'/><title type='text'>Pen testers, secure email and sexy vulnerabilities</title><content type='html'>Email has been likened to writing a postcard to a friend, in pencil and sending through the post.   It can be read and altered at any point along the way.  The postal metaphor encouraged by email clients such as Outlook, Notes, Thunderbird etc is that of a closed envelope so that users are trained into thinking that sending an email is secure.&lt;br /&gt;&lt;br /&gt;The recent IT cockup at ACS:law, a law firm specialising in intellectual property theft has now made public what senders and recipients clearly assumed would be private for ever.   ACS:Law's website was left mis-configured allowing anyone visiting their home page to right-click download an entire tar.gz archive file of their emails.  individuals have taken the database of emails and made websites (e.g. http://ueof.co.uk/acslaw/ [now offline]) allowing various groups to mine the data. &lt;br /&gt;&lt;br /&gt;A sample of the data included&lt;br /&gt;&lt;ul&gt;&lt;li&gt;national insurance numbers&lt;/li&gt;&lt;li&gt;bank account details&lt;/li&gt;&lt;li&gt;data that would be classified as personal information&lt;/li&gt;&lt;li&gt;and a lot of internal emails that may well prove inflammatory for various regulators and opposition groups to this firm.&lt;/li&gt;&lt;/ul&gt;Not only is the data now public - but it is public forever.  The data has been spread far and wide over geo-political domains and like garden weeds, it will be difficult to eradicate and will keep coming back.&lt;br /&gt;&lt;br /&gt;Clearly, for security researchers, communicating the level of risk inherent in system configurations should be part of the work that they do but all too often I see penetration testers chasing the sexy exploits rather than inform the business of actual risk.  It takes skill for a security consultant to communicate the risk in terms that the business will understand without scaremongering. &lt;br /&gt;&lt;br /&gt;One client of mine has just implemented a "Secure Email" system using Cisco Ironport.  The Cisco product is market leading and has been implemented in a robust way.  However, the pen tester (not us!!) brought in to look at the system focussed primarily on the Cisco product, and to their credit found some sexy-yet-minor Information and data leakage vulnerabilities HOWEVER, they totally failed to advise their client about the wider picture and thus missed client-built bespoke addons that were full of holes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-6378841494096535819?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/6378841494096535819/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/09/pen-testers-secure-email-and-sexy.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/6378841494096535819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/6378841494096535819'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/09/pen-testers-secure-email-and-sexy.html' title='Pen testers, secure email and sexy vulnerabilities'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-2183770538090101662</id><published>2010-07-23T11:20:00.002+01:00</published><updated>2010-07-23T11:27:50.985+01:00</updated><title type='text'>BMI sends out diamond club emails to wrong members</title><content type='html'>A simple mistake:  &lt;a href="http://www.flybmi.com"&gt;BMI&lt;/a&gt; (British midland Airways) sent all of its Diamond Club members an email this morning - but, they sent the wrong data in the emails so that:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;emails are addressed to the right individual who owns the email address&lt;/li&gt;&lt;li&gt;have the wrong diamond club information, including membership number&lt;/li&gt;&lt;li&gt;but have direct HTTP GET links to update promotional choices for the incorrect diamond club account&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: courier new;"&gt;So, I rang them up and the telephone operator even told me the name of the account holder whose information i received.  So, I'm sorry Mr Mason - when I clicked on &lt;span style="font-family: courier new;"&gt;http://bmi-email.co.uk/re?l=5uh9yaI1nklj0xI1I5sdpup&amp;amp;req=dcnumber%3D00000710196&lt;/span&gt; - I opted for your account to receive status miles instead of destination miles...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-2183770538090101662?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/2183770538090101662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/07/bmi-sends-out-diamond-club-emails-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/2183770538090101662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/2183770538090101662'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/07/bmi-sends-out-diamond-club-emails-to.html' title='BMI sends out diamond club emails to wrong members'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-7556943105070534553</id><published>2010-04-13T08:56:00.002+01:00</published><updated>2010-04-13T09:18:38.299+01:00</updated><title type='text'>Separating a fool from their money</title><content type='html'>It's never been easier.  The UK Gov (including the &lt;a href="http://www.hmrc.gov.uk"&gt;HMRC)&lt;/a&gt; have made it's online systems and telephone services so complex to get advice that many individuals are turning to the web for advice and support.  What astounds me however is the information that people are adding as comments to blogs. &lt;br /&gt;&lt;br /&gt;On&lt;a href="http://dailydigit.com/business-finance/www-hmrc-gov-uk-income-tax-rates-and-allowances-2010-2011"&gt; this blog&lt;/a&gt;, the following information was given out by one individual:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;name&lt;/li&gt;&lt;li&gt;address&lt;/li&gt;&lt;li&gt;age&lt;/li&gt;&lt;li&gt;national insurance number&lt;/li&gt;&lt;li&gt;some tax code history&lt;/li&gt;&lt;/ul&gt;Another, offered their change of address - as a comment?  There are at least 5 national insurance numbers &amp;amp; names.  Did they really think that the dailydigit blog was the HMRC?  Has none of the advice given out about web surfing and verifying the site identity got through to people - and more importantly, why are blogs like this moderating comments like this to appear?&lt;br /&gt;&lt;br /&gt;It's also &lt;a href="http://www.justanswer.com/questions/31xsm-i-require-my-utr-my-n-i-number-is-zr758571a-my-full"&gt;here&lt;/a&gt;; where a retired police officer volunteers even more information after being asked (well enough for an identity fraud)&lt;br /&gt;&lt;br /&gt;For more information - google popular queries - "my NI number is", "my tax ref no is", "my passport number is"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-7556943105070534553?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/7556943105070534553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/04/separating-fool-from-their-money.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/7556943105070534553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/7556943105070534553'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/04/separating-fool-from-their-money.html' title='Separating a fool from their money'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-1474020259715945858</id><published>2010-03-08T10:41:00.002Z</published><updated>2010-03-08T11:21:34.223Z</updated><title type='text'>Argos Sending Private Data in Receipt Emails</title><content type='html'>TheRegister &lt;a href="http://forums.theregister.co.uk/forum/1/2010/03/05/argos_email_security_snafu/"&gt;has a great story&lt;/a&gt; about Argos using receipt emails that have HTML embedded in them that contains parameters including full unencrypted card number, CVV code, expiry date, name as printed on the card and address.  Clearly a massive breach.&lt;br /&gt;&lt;br /&gt;However, it gets more interesting when you look at one of these emails, Chris Geek Guy &lt;a href="http://chris.gg/2010/03/in-detail-argos-credit-card-security-breach/"&gt;has copied one to his blog&lt;/a&gt;.  Whilst it is clear that Argos have copied lots of personal data to the HTML email, I think there are bigger problems.  The data is embedded in a GET html link.  To me, this shouts out XSS and CSRF risk and also, if you look at the link, this data would always be sent across the internet in the clear - usually being cached as it travels through the internet -  if the user did in fact click on the link in the email.&lt;br /&gt;&lt;br /&gt;Potential targets for exploitation (and I haven't tried) would be: includeName, the com.ibm.commerce.context.experiment.ExperimentContext which looks like it is directly referencing an object (!!!) outside the context of the system.  It would also be worth exploring what this link actually does and whether manipulating the receipt and performing a replay attack changes anything on the Argos server.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-1474020259715945858?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/1474020259715945858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/03/argos-sending-private-data-in-receipt.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/1474020259715945858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/1474020259715945858'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2010/03/argos-sending-private-data-in-receipt.html' title='Argos Sending Private Data in Receipt Emails'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-4161402311407371792</id><published>2009-11-24T08:50:00.006Z</published><updated>2009-11-24T09:31:35.342Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='protective marking'/><category scheme='http://www.blogger.com/atom/ns#' term='information loss'/><title type='text'>Googling for Protectively Marked PDF's</title><content type='html'>The number of protectively marked PDF's on the web is staggering, try these:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Confidential:&lt;/span&gt; &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+confidential+%28htm+OR+html+OR+mhtml%29&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi="&gt;http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+confidential+%28htm+OR+html+OR+mhtml%29&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi=&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Restricted:&lt;/span&gt; &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+restricted+%28htm+OR+html+OR+mhtml%29&amp;amp;btnG=Search&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi="&gt;http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+restricted+%28htm+OR+html+OR+mhtml%29&amp;amp;btnG=Search&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi=&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;NATO restricted:&lt;/span&gt;  &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+%22nato+restricted%22+%28htm+OR+html+OR+mhtml%29&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi="&gt;http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+%22nato+restricted%22+%28htm+OR+html+OR+mhtml%29&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi=&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;NATO Confidential:&lt;/span&gt; &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+%22nato+confidential%22+%28htm+OR+html+OR+mhtml%29&amp;amp;btnG=Search&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi="&gt;http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf+file+%22nato+confidential%22+%28htm+OR+html+OR+mhtml%29&amp;amp;btnG=Search&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi=&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;Try other protective markings from other countries to see more.  Clearly searching for "Top Secret" will incur a lot of separating chaff from wheat.  The biggest surprise is the number of government protectively marked papers that are searchable - these are typically papers that are being passed between departments and the paper is being mis handled down the line of recipients.&lt;br /&gt;&lt;br /&gt;I've seen a lot of misuse of confidentially marked papers in commercial organisations - I see them regularly sitting on a printer in open plan offices.  Largely because staff working for big financial companies do not have information security drilled into them.  They have to sit computer based training tests regularly - but there is little comeback for employees who regularly flout the rules.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-4161402311407371792?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/4161402311407371792/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/11/googling-for-protectively-marked-pdfs.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/4161402311407371792'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/4161402311407371792'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/11/googling-for-protectively-marked-pdfs.html' title='Googling for Protectively Marked PDF&apos;s'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-922851218797457285</id><published>2009-09-08T10:58:00.007+01:00</published><updated>2009-09-08T11:29:37.188+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FSA IFA independent financial advisers DPA ICO data security'/><title type='text'>Independent Financial Advisers oblivious to data protection</title><content type='html'>Who has the most information about you, as an individual?&lt;br /&gt;&lt;ul&gt;&lt;li&gt;your doctor?&lt;/li&gt;&lt;li&gt;your lawyer?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;your bank manager?&lt;/li&gt;&lt;li&gt;the HMRC?&lt;/li&gt;&lt;li&gt;your local council?&lt;/li&gt;&lt;/ul&gt;No - it is likely to be an &lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Independent Financial Adviser&lt;/span&gt;.  If you consider what is "personal data" (see the &lt;a href="http://www.ico.gov.uk/upload/documents/determining_what_is_personal_data/whatispersonaldata2.htm"&gt;ICO Web pages&lt;/a&gt;) then the IFA pretty much ticks off more data categories than any other professional relationship in your life except for UK Gov vetting.  Classification of personal data is not listed, but is classified by asking 8 questions:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Can a living individual be identified from the data?  &lt;/span&gt; &lt;span style="font-weight: bold;"&gt;Yes, all forms carry name, address, date of birth and often National insurance Number.  IFA's will also ask for proof of identity such as bank cards, passport, drivers licence.&lt;/span&gt;  For regulatory reasons, all of this information is stored by the IFA.&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Does the data 'relate to' the identifiable living individual, whether in personal or family life, business or profession?&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;Again, yes it does.  Joint Life cover and family health schemes will typically hold data about family members and the business that the policyholder works in.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Is the data 'obviously about' a particular individual?&lt;/span&gt;  &lt;span style="font-weight: bold;"&gt;Yes, it has to be!&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Is the data 'linked to' an individual so that it provides particular information about that individual?&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;Yes, quotes, policy numbers, national insurance numbers, passports, bank account details all help link and identity an individual.&lt;/span&gt;  These are all needed for commencing many policys.  Often bank details are used for some types of investments.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Is the data used, or is it to be used, to inform or influence actions or decisions affecting an identifiable individual?  &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Yes, policies with Life Cover options will have varying costs depending on the health, location o&lt;/span&gt;f their home address.  Income will play a part in pensions and other investments such as bond products.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Does the data have any biographical significance in relation to the individual?&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;yes, in particular medical history reports for health cover will cover the individual in detail.  &lt;/span&gt;Income history, previous addresses and knowledge of past and current financial products build a picture of the individual.  Even, for some individuals, country of residence (for tax purposes) adds more colour to the picture.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Does the data focus or concentrate on the individual as its central theme?&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;Yes, pretty much all products concentrate on the individual - particularly once anti-money laundering legislation came in.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Does the data impact or have the potential to impact on an individual, whether in a personal, family, business or professional capacity?&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;Yes, for example a rejection for life cover on medical grounds could have an impact.  As would knowledge of an individuals financial situation&lt;/span&gt;.  Especially for targeted identity theft etc.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;So given that IFA's have ticked all the boxes for data categories deemed 'personal' by the ICO, then surely the must have stringent measures in place for data security?&lt;br /&gt;&lt;br /&gt;Well no, actually they don't. &lt;br /&gt;&lt;br /&gt;Larger firms and the product providers (Aviva, L&amp;amp;G, Prudential, Standard Life etc etc) will have strict enforcement of data security - but the majority of IFA's are independent and will operate as a small business with no formal IT strategy and no formal training on data security. Many IFA's will buy laptops from retail stores like PC World and Dell retail online and configure them themselves.  They are also using Blackberry's and Apple iPhones with no knowledge of how data is secured or not.  Potentially - all of your data is being stored on unencrypted, unsecured devices. &lt;br /&gt;&lt;br /&gt;The FSA regulates IFA's but it is my view that many IFA's play lip service to the "regulated by" statement on their business cards.  It is only a matter if time before the FSA gets some teeth and in combination with the ICO (which will soon be allowed to prosecute) will close down IFAs that have non-existent security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-922851218797457285?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/922851218797457285/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/09/independent-financial-advisers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/922851218797457285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/922851218797457285'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/09/independent-financial-advisers.html' title='Independent Financial Advisers oblivious to data protection'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-6072610784031812838</id><published>2009-08-18T14:10:00.003+01:00</published><updated>2009-08-18T14:21:03.213+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='GSX government uk births keylogging keylogger'/><title type='text'>A Moment of Realisation during Registration</title><content type='html'>I was registering the birth of our new baby boy last week and, as you do, noticed a huge problem with the way registration of births are carried out in Scotland.  The Scottish system for registration of births, deaths and marriages is different from England and Wales, with registrations being made at the General Register of Scotland and not Somerset House.&lt;br /&gt;&lt;br /&gt;Whilst registering my wee boy; I was left alone in an interview room with an unlocked PC.  I didn't have my phone on my but I would have taken some photos.  The PC was linked and logged into the GROSfer application which, in Scotland, is on the GSX Government Secure Extranet system.  The UK Government uses various classifications of network for various types of traffic according to its own data classification.  I presume birth data must be protectively marked as restricted and so GROSfer is on the GSX. &lt;br /&gt;&lt;br /&gt;I had approximately 3 to 4 minutes of "own time" in the office with the unlocked PC, plenty of time to attack a keylogger to the USB keyboard, whilst the registrar took the payment for the birth certificate.  I also had access to GSX which could pose threats.  All pretty disturbing - a simple flick of Cntrl-Alt-Del and a little bit of desk &amp;amp; cable management would reduce the threat.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-6072610784031812838?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/6072610784031812838/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/08/moment-of-realisation-during.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/6072610784031812838'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/6072610784031812838'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/08/moment-of-realisation-during.html' title='A Moment of Realisation during Registration'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-925395727978640300</id><published>2009-07-25T23:11:00.010+01:00</published><updated>2009-07-25T23:56:05.329+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='07755 postage scam'/><title type='text'>Mysterious 07755 International Calling</title><content type='html'>Today I received an interesting postal spam - it's not one I've seen before and am still a little puzzled to figure out what the angle is with this one - if indeed there is one, here are the case notes:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;A postal letter is sent to me recorded delivery - I have to sign for it.&lt;/li&gt;&lt;li&gt;The cost of the letter is £1.14&lt;/li&gt;&lt;li&gt;The postage label has been printed out by the &lt;a href="http://www.royalmail.com/onlinepostage"&gt;online royal mail service&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;My address, is curiously an address I use for a single paypal account.&lt;/li&gt;&lt;li&gt;Inside the envelope is a flyer for cheap international calls using the 07755 service - you see these all over the place - there are all sorts of similar websites such as cherry call, planet numbers and this one: 999calls.com&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mFLq7mDVJqE/SmuLgiH-2uI/AAAAAAAAACw/wxw2fbfINqw/s1600-h/spampostalletter1.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 108px;" src="http://2.bp.blogspot.com/_mFLq7mDVJqE/SmuLgiH-2uI/AAAAAAAAACw/wxw2fbfINqw/s200/spampostalletter1.jpg" alt="" id="BLOGGER_PHOTO_ID_5362533172347067106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;So where is the scam?&lt;br /&gt;&lt;br /&gt;I have just chuckled into a whisky because I love this one.  I have not totally confirmed it, but I am postulating that it is an old fashioned postage scam.  I took the royal mail signed for receipt code and typed it into the &lt;a href="http://www.royalmail.com/"&gt;track and trace facility&lt;/a&gt; and basically, this has come up with a duplicate signee (i.e. not me)  Interestingly, the signature is for someone in Enfield, next to a local post office and the 999calls.com whois address is in E1 London (so, much closer than Scotland.)  The interesting part for me is the value that UK citizens place on a postal letter that has been hand delivered and has to be signed for.  We automatically filter messages sent to us using cheap mechanisms - we don't believe emails in our email inboxes anymore - we are beginning to see spam texts.  The general priciple has always been that a cheap delivery mechanism usually incites fraud and spam.  This one is different - it tries to look expensive.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;I am still working on it, but I think the &lt;a href="http://www.royalmail.com/onlinepostage"&gt;royal mail postage online service&lt;/a&gt; has also been hacked to produce forged address labels!&lt;/li&gt;&lt;li&gt;The peel off "recorded" Signed For labels have been reproduced - but not with unique numbers.&lt;/li&gt;&lt;li&gt;Also, one of my paypal addresses has been used for this so no doubt that has been stolen from somewhere.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;I had to actu&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mFLq7mDVJqE/SmuLnxtu8bI/AAAAAAAAAC4/MRjXAgLTp_g/s1600-h/postagescam1.jpeg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 176px;" src="http://3.bp.blogspot.com/_mFLq7mDVJqE/SmuLnxtu8bI/AAAAAAAAAC4/MRjXAgLTp_g/s200/postagescam1.jpeg" alt="" id="BLOGGER_PHOTO_ID_5362533296791024050" border="0" /&gt;&lt;/a&gt;ally sign for this bit of spam from a smiling postman - imagine a phishing scam using this trusted delivery methodology?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-925395727978640300?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/925395727978640300/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/07/mysterious-07755-international-calling.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/925395727978640300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/925395727978640300'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/07/mysterious-07755-international-calling.html' title='Mysterious 07755 International Calling'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mFLq7mDVJqE/SmuLgiH-2uI/AAAAAAAAACw/wxw2fbfINqw/s72-c/spampostalletter1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-2807084124260107734</id><published>2009-06-15T13:36:00.007+01:00</published><updated>2009-06-15T16:08:39.638+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RBS misselling protection insurance'/><title type='text'>Royal Bank of Scotland inviting consumers to buying protection insurance</title><content type='html'>When customers confirm the receipt of a credit card at RBS; they are being invited to buy protection insurance under slightly dubious pretences.  I listened into a call where a call centre operator called Daniel said:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;"We notice that you do not have protection cover on your credit card&lt;/span&gt;&lt;/span&gt;. &lt;span style="font-style: italic;"&gt;Did you know that anyone who has your name and date of birth can apply for loans and credit in your name and you will be liable for the full amount?"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Daniel at no point mentioned that he was selling a type of insurance policy until being prompted to by the caller.  After some discussion the policy is subject to all sorts of small print that most consumers would not understand.  He also did some rather silly scaremongering by suggesting that fraudsters could get passports etc in the name of the caller at the click of a button on a website and generally inferring that the responsibility for poor lending practices is the fault of the consumer rather than the lender.   At that point I stopped him.&lt;br /&gt;&lt;/blockquote&gt;In the UK, the financial services distance selling rules specifically state that a name and address is required for consumer credit and the &lt;a href="http://www.oft.gov.uk/advice_and_resources/resource_base/legal/cca/"&gt;act&lt;/a&gt; has controls in place so that there is time to reverse a credit agreement.  The Consumer Credit Act also has controls in place to ensure that the onus is on the lender to establish the identity of the creditor  - &lt;span style="font-weight: bold;"&gt;crucially, it is not the consumer&lt;/span&gt;.  The 3 large credit reference agencies in the UK are in business to help their clients do this.&lt;br /&gt;&lt;br /&gt;This sales call was bordering on mis-selling of an insurance policy.  If you are going to take out such a plan, read the small print carefully and understand your rights.&lt;br /&gt;&lt;br /&gt;If you are the victim of identity theft then, get in touch with the credit reference agencies; here is &lt;a href="http://www.parliament.the-stationery-office.co.uk/pa/cm200708/cmselect/cmhaff/58/58we41.htm"&gt;a snippet from the house of commons written evidence&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;If Experian has established that an individual is a true victim of fraud and their identity has been fully authenticated, they are provided with the following:&lt;br /&gt;&lt;ul&gt;—    A dedicated case worker (with a freephone number), who will give general and ongoing advice on identity fraud as well as dealing with the specific problems being experienced by that individual and helping to liaise with lenders on their behalf.&lt;/ul&gt;&lt;ul&gt;—    A free copy of their credit report along with copies of Experian's consumer advice leaflets—&lt;i&gt;Your Credit Report Explained and Identity Fraud Explained&lt;/i&gt;.&lt;/ul&gt;&lt;ul&gt;—    A discrete password which is added to their credit report which ensures lenders are alerted to the fact that an individual has been an ID fraud victim and should therefore request the password prior to proceeding with an application for credit.&lt;/ul&gt;&lt;ul&gt;—    Information about and referral to CIFAS (the UK's fraud prevention service) for Protective Registration.&lt;/ul&gt;&lt;ul&gt;—    Free 12 month membership Experian's credit report monitoring service, CreditExpert.&lt;/ul&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-2807084124260107734?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/2807084124260107734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/06/royal-bank-of-scotland-scaring.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/2807084124260107734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/2807084124260107734'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/06/royal-bank-of-scotland-scaring.html' title='Royal Bank of Scotland inviting consumers to buying protection insurance'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-5946153880839706612</id><published>2009-06-12T15:47:00.007+01:00</published><updated>2009-06-12T16:30:45.764+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP Top ten 10 TCF FSA Security Requirements'/><title type='text'>Developing Security Requirements</title><content type='html'>I've just managed to get a set of "security requirements" agreed by my large financial client. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;So why write requirements at all?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In a complex organisation where there are many system delivery departments with complex commercial arrangements including outsourcers and contracting organisations - writing a definitive set of standards for designing &amp;amp; developing applications can be&lt;br /&gt;&lt;ul&gt;&lt;li&gt;too prescriptive,&lt;br /&gt;&lt;/li&gt;&lt;li&gt;expensive - because telling 3rd party delivery organisations to "do it my way" is always expensive&lt;/li&gt;&lt;li&gt;inflexible for the business.&lt;/li&gt;&lt;/ul&gt;Since mandating the implementation would be a risky endeavour - I've created requirements at a higher level that each of the organisational departments can take and use it to derive their own:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;training and awareness processes&lt;/li&gt;&lt;li&gt;coding standards and quality gateways&lt;/li&gt;&lt;li&gt;testing approaches and automatic review&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Clearly, some of the departments will be more efficient by co-operating but some of the 3rd party suppliers will simply wind these requirements into their own delivery mechanisms.  My clients audit staff then have a clear set of requirements to measure delivery projects and also measure the 3rd party suppliers themselves.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Rating and Prioritisation&lt;/span&gt;&lt;br /&gt;My plan involved taking the &lt;a href="http://www.owasp.org/index.php/Top_10_2007"&gt;OWASP Top Ten list&lt;/a&gt;, the &lt;a href="http://www.pcisecuritystandards.org"&gt;PCI DSS&lt;/a&gt; standards and the &lt;a href="http://www.fsa.gov.uk/Pages/Doing/Regulated/tcf/index.shtml"&gt;FSA Treating Customer Fairly&lt;/a&gt; legislature and turning them into requirements; with each sub requirement rated with a MoSCoW rating.  The MoSCoW rating system is standard for requirements in that it not only prioritises requirements but also allows the author to set custom measurement:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Must Have: &lt;/span&gt;means that it the system does not meet this security requirement then the project has to stop as soon as it is known - the project cannot move forward.&lt;/li&gt;&lt;li&gt; &lt;span style="font-weight: bold;"&gt;Should Have: &lt;/span&gt;means that the system has to design in to meet this requirement.  If it cannot meet the requirement then the project can only go ahead if there is business, tech &amp;amp; risk agreement that the project can carry on.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Could Have: &lt;/span&gt;means that the project have got to consider the requirement in the plans, but may drop it if it is too expensive.  They have to give a reason and any risk exposure explained - but this is not scruitinised in the same way as a should have.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Want, or Would Have&lt;/span&gt;:  Aspirational security requirements that the business recognise as important but understand they will cost more, or might not be possible with todays technology etc.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;I find it surprising that many security professionals that I deal with do not recognise RISK.  They automatically will say YES, WE MUST HAVE all the security features without realising that the selection of the security features is a risk balance.&lt;br /&gt;&lt;blockquote&gt;e.g. one organisation I worked for mandated fibre to every desktop because the risk or ethernet radiation leakage would be too damaging for their business.  Clearly desktops in a financial insurance company do not require this - although, if the price was right then the business would have this extra security.  So for one organisation it was a MUST, the other a WOULD HAVE.&lt;br /&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-weight: bold;"&gt;What about the requirements that have been missed?&lt;/span&gt;&lt;br /&gt;Sure, there will be some that have been missed.  However, in my experience, the online applictaions that will generate huge breaches tend to show signs very early on that anti-patterns existed.  Over-worked teams, poorly educated, poor communication etc etc,  &lt;br /&gt;&lt;br /&gt;By focussing the requirements on the OWASP etc, it gives auditors concrete foundations to measure the security quality of projects in a commercial context.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Example Requirement&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;ID:&lt;/span&gt; Z1.1  (in the AntiXSS chapter)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Name&lt;/span&gt;: Strong output encoding&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Description&lt;/span&gt;: Ensure that all user-supplied data is appropriately entity encoded before rendering, taking the approach to encode all characters other than a very limited subset.  This is the approach of the various Anti-XSS libraries.  Also, set the character encodings for each page output, which will reduce exposure to some attack vectors.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Type&lt;/span&gt;: Security requirement&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Source&lt;/span&gt;: OWASP Top 10, 2007&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MoSCoW&lt;/span&gt;: MUST&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Measure of Success&lt;/span&gt;: All input and output data must be encoded appropriately with the output encoding specified, e.g. UTF-1, ISO 8859-1&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-5946153880839706612?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/5946153880839706612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/06/developing-security-requirements.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/5946153880839706612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/5946153880839706612'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/06/developing-security-requirements.html' title='Developing Security Requirements'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-976588193109489000</id><published>2009-05-14T22:14:00.009+01:00</published><updated>2009-05-14T22:48:56.037+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='keyloggers linux infowar hack security'/><title type='text'>In The Field: Keylogging</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;I've never actually had to use keyloggers out in the field o&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;n assignment - I don't normally take on the all-out 'break in' jobs because they are fraught with mishap and, if I'm going to be a bit snooty, they are usually more 'private investigator' than proper security researcher.   I do however give presentations to organisations about the dangers of these wee devices and how easily they can be smuggled in and out of data centres and the workplace.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mFLq7mDVJqE/SgyKxNvyVdI/AAAAAAAAACQ/p7xZi9-HrVo/s1600-h/keyloggers.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 202px;" src="http://1.bp.blogspot.com/_mFLq7mDVJqE/SgyKxNvyVdI/AAAAAAAAACQ/p7xZi9-HrVo/s320/keyloggers.jpg" alt="" id="BLOGGER_PHOTO_ID_5335792236635510226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;Keyloggers are&lt;span style="font-family:arial;"&gt; a real threat because they have come of age:&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul  style="font-family:arial;"&gt;&lt;li  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;They're cheap, a pair can be had for less than GBP40.&lt;/span&gt;&lt;/li&gt;&lt;li  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;They are&lt;/span&gt;&lt;span style="font-size:85%;"&gt; small and inconspicuous.&lt;/span&gt;&lt;/li&gt;&lt;li  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;They are easy to use and easy to get data from.&lt;/span&gt;&lt;/li&gt;&lt;li  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;Standard anti-virus software will not pick them up.&lt;/span&gt;&lt;/li&gt;&lt;li  style="font-family:arial;"&gt;&lt;span style="font-size:85%;"&gt;They typically have 2Mb to 4Mb of text memory (which could be several years worth)&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:arial;font-size:85%;"  &gt;The standard M&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: arial;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mFLq7mDVJqE/SgyMYrk0jTI/AAAAAAAAACY/EgaiAkbW1pc/s1600-h/keyloggeronpc.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 150px; height: 200px;" src="http://1.bp.blogspot.com/_mFLq7mDVJqE/SgyMYrk0jTI/AAAAAAAAACY/EgaiAkbW1pc/s200/keyloggeronpc.JPG" alt="" id="BLOGGER_PHOTO_ID_5335794014169107762" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=";font-family:arial;font-size:85%;"  &gt;O is to plug the relevant keylogger into the PS/2 or USB port and then the keyboard into the keylogger.  it act&lt;/span&gt;&lt;span style=";font-family:arial;font-size:85%;"  &gt;s as a man in the middle and records the input from the leyboard and also looks out for a keyword entered from the k&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="font-family:arial;"&gt;eybo&lt;/span&gt;ard that will activate the text based user interface.  They typically come with a predetermined work such as '&lt;span style="font-family:courier new;"&gt;keylog&lt;/span&gt;'.  When the keylogger sees that word being typed in, it sends characters to the PC and that is how the inetrface works.  So long as you are in a text editor then the text will roll onto the screen.  No software is required.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mFLq7mDVJqE/SgyMyw-HniI/AAAAAAAAACg/qVpy8cdN6gA/s1600-h/keysafe.jpeg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 190px;" src="http://1.bp.blogspot.com/_mFLq7mDVJqE/SgyMyw-HniI/AAAAAAAAACg/qVpy8cdN6gA/s200/keysafe.jpeg" alt="" id="BLOGGER_PHOTO_ID_5335794462293990946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;In fact, here is a sample from kate, the KDE text editor.  This ou&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;t&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;put is from a 2Mb PS/2 type keylogger used in Fedora Linux.  Typing keylog into kate has automatically typed in the interface menu.  The attacker can change the keyword and some of the behaviour of the data recovery.  In this sample you can see a URL that has been&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt; typed into a &lt;span style="font-family:arial;"&gt;browser.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;  Obviously as part of the job recon, the duration of time the logger has to be carefully assessed so that drops can be organised with minimum disruption (people crawling under desks create suspicion), but also, most users will log on once a day to systems and so day start is a critical time.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;For corporates protecting against this - I have only ever used one solution.  Glue.  One client I advised filled the USB slots with araldite and glued the PS/2 connectors in place.  This may sound insane, but software based solutions won't work when the PC is switched off and also USB drop detections and so on will create huge amounts of noise.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Laptops are less risky - however, ZIF solutions that sit between the keyboard ZIF scket and the keyboard connector are not impossible and will one day be mainstream.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-976588193109489000?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/976588193109489000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/05/in-field-keylogging.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/976588193109489000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/976588193109489000'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/05/in-field-keylogging.html' title='In The Field: Keylogging'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mFLq7mDVJqE/SgyKxNvyVdI/AAAAAAAAACQ/p7xZi9-HrVo/s72-c/keyloggers.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-8419293355388475222</id><published>2009-05-08T21:47:00.005+01:00</published><updated>2009-05-08T22:50:12.237+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phish secure email solutions'/><title type='text'>Secure Email solutions and Phishing Email</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:arial;"&gt;One of the &lt;/span&gt;&lt;/span&gt;main problems with the secure email products (Cisco Ironport, Tumbleweed, Trend Micro) is that there is still no internet wide standard for securing email.  So if a large corporation wishes to send data to its consumers then it has either got to:&lt;div style="text-align: center;"&gt;&lt;div style="text-align: left;"&gt;&lt;ul&gt;&lt;li&gt;Distribute identities to its customer base out of band, e.g. on the last statement or by letter.&lt;/li&gt;&lt;li&gt;Invite customers to sign up (low return rates).&lt;/li&gt;&lt;li&gt;Implement a shared key secure email system (fraught with danger and a big deployment cost)&lt;/li&gt;&lt;li&gt;Implement a public key system like PGP/MIME (customers don't understand it + who should own the key directory?)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Implement a secure pick up solution by emailing out a link&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mFLq7mDVJqE/SgSaiEyoq1I/AAAAAAAAAB4/4QzGcD8PYuk/s1600-h/s3.jpeg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 103px;" src="http://3.bp.blogspot.com/_mFLq7mDVJqE/SgSaiEyoq1I/AAAAAAAAAB4/4QzGcD8PYuk/s200/s3.jpeg" alt="" id="BLOGGER_PHOTO_ID_5333557768905861970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The problem is that many of the solutions implement the latter because of the technical and cost limitations of the other strategies.  Another key problem with all of these strategies is that the &lt;a href="http://www.getsafeonline.org/"&gt;Government&lt;/a&gt; and the &lt;a href="http://www.banksafeonline.org.uk/"&gt;Banking Industry&lt;/a&gt; are aquite rightly advising the public not to click on links that offer to retrieve messages etc - this flies in the face of the secure email product strategy and shows a clear weakness.  A 'secure email' with a constructed link to pick up the email looks too similar to a phishing scam to be useful.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mFLq7mDVJqE/SgSo2bwOUlI/AAAAAAAAACI/vx5CUBPHLqs/s1600-h/pgpkmail.jpeg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 90px;" src="http://2.bp.blogspot.com/_mFLq7mDVJqE/SgSo2bwOUlI/AAAAAAAAACI/vx5CUBPHLqs/s200/pgpkmail.jpeg" alt="" id="BLOGGER_PHOTO_ID_5333573511829934674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;At present, only PGP/MIME is an email encryption strategy that I support because it maintains the postal metaphor in that "I send you an email" and that you can open it in your email client.  All the other schemes break the metaphor by requiring the recipient to go and find a webserver to get the message with credentials 'owned' by a third party leaving the recipient with an enormous number of schemes and credentials to remember.  However, until PGP public keys become ubiquitous and key management made to be usable by an ordinary user then secure email will continue to be a mish-mash of unique solutions across corporations and product providers.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-8419293355388475222?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/8419293355388475222/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/05/secure-email-solutions-and-phishing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/8419293355388475222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/8419293355388475222'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/05/secure-email-solutions-and-phishing.html' title='Secure Email solutions and Phishing Email'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mFLq7mDVJqE/SgSaiEyoq1I/AAAAAAAAAB4/4QzGcD8PYuk/s72-c/s3.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-9188258399800412464</id><published>2009-04-28T13:04:00.011+01:00</published><updated>2009-04-28T13:53:55.577+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='information security USB spy encryption SOCA'/><title type='text'>You only lose it once</title><content type='html'>Whenever there is mention of "an agent" and "spying" in a story; the popular press seems to collectively turn into a pre-pubescent teenager when reporting the facts with images of sports cars and shady manoeuvres in hot climates.&lt;br /&gt;&lt;br /&gt;Recent allegations of a female agent in Columbia losing her handbag containing a USB key full of potentially secret information has cropped up on all the press wires.  Newswire stories are appearing simply mixed up and redrafted (&lt;a href="http://www.securitypark.co.uk/security_article263006.html"&gt;here&lt;/a&gt;, &lt;a href="http://www.globalsecuritymag.com/Credant-says-MI6-drug-information,20090428,8815"&gt;here&lt;/a&gt; and &lt;a href="http://www.net-security.org/secworld.php?id=7399"&gt;here&lt;/a&gt;) are floating the opinion that somehow a handbag was left on a bus from the airport and the data was lost in 2006.  Other press sources such as &lt;a href="http://www.timesonline.co.uk/tol/news/politics/article6169077.ece"&gt;The Times&lt;/a&gt; throw a little more light on the matter quoting the shadow home secretary in a small chance to make a political quip.  A little inter-service squabbling can be found as some news sources quote MI6, others are quoting it as a SOCA problem.&lt;br /&gt;&lt;br /&gt;What astounds me is that the IT Security press are jumping on the "She should have had an Encrypted USB stick" and some are even mentioning products.  No, they are missing the point.  If the story facts as we have them are true (and that's something I seriously doubt) then the problem is not about secure storage but about security controls on the information in the first place.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;That information should have been &lt;a href="http://en.wikipedia.org/wiki/Classified_information_in_the_United_Kingdom"&gt;protectively marked&lt;/a&gt; (it sounds like SECRET from the press reports) .  There are &lt;a href="http://en.wikipedia.org/wiki/Classified_information_in_the_United_Kingdom"&gt;plenty of rules about couriering protectively marked documentation&lt;/a&gt; - these should have been enforced.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The quantity of information should not have been made available to an individual agent - who, after all, according to the press stories isn't a sworn in employee of HMG and could have sold it.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;For what operational reason would an individual be travelling with this amount of data? Why not send it by secure comms?  It's cheaper and the data receipt would have been repudiable.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;If I were to choose between conspiracy and cockup - the latter always wins.  Especially with a poorly setup new organisation lacking adequate controls and poor discipline.  Also, I thought it would be common knowledge that a handbag owned by a single travelling female at &lt;a href="http://en.wikipedia.org/wiki/El_Dorado_Airport"&gt;El Dorado airport&lt;/a&gt; (one of the busiest in S America) is going to be a target...&lt;br /&gt;&lt;br /&gt;I hope no one died because of the information loss.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-9188258399800412464?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/9188258399800412464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/you-only-lose-it-once.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/9188258399800412464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/9188258399800412464'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/you-only-lose-it-once.html' title='You only lose it once'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-4746005761937553992</id><published>2009-04-27T08:49:00.007+01:00</published><updated>2009-04-27T10:33:37.714+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forbidden planet credit card scam hack PCI DSS'/><title type='text'>Forbidden Planet - not disclosing Credit Card Fraud</title><content type='html'>In a similar subject to my previous blog post about the data loss at Impulse Group; Forbidden Planet (UK) managed to have their customers credit card details breached.  In what seems to be norm nowadays, Forbidden Planet (UK) have not sent messages to their customers to report the problem, instead, a rather strange message was left on the 'closed' Dr Who forums by the site owner - but the statement is &lt;a href="http://www.blogomatic3000.com/?p=790"&gt;available &lt;/a&gt;&lt;a href="http://www.blogomatic3000.com/?p=790"&gt;at Blogomatic 3000&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The data is being used by fraudsters - one customer I spoke to said that £10 transactions had gone through his Maestro card.  Fraudsters use "taster" £10 transactions because they are small and confirm the card is still active before selling the details on.&lt;br /&gt;&lt;br /&gt;The big question that I'm seeking an answer to:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Why wasn't the system PCI DSS compliant?  because if it was then the card numbers would have not been available to those that stole the data. The 3rd PCI DSS data security requirement specifically says that cardholder data has to be 'protected' - were not just talking database passwords; it has to be encrypted wherever the PAN + data is used, including log files.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Why was credit card data older than 2 months still be stored?  The 3rd PCI DSS also says that cardholder data must not be stored for longer than necessary.&lt;/li&gt;&lt;/ul&gt;more information on PCI DSS can be found here:  &lt;a href="http://www.pcisecuritystandards.org/"&gt;http://www.pcisecuritystandards.org&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-4746005761937553992?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/4746005761937553992/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/forbidden-planet-not-disclosuring.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/4746005761937553992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/4746005761937553992'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/forbidden-planet-not-disclosuring.html' title='Forbidden Planet - not disclosing Credit Card Fraud'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-9132551089204224804</id><published>2009-04-24T19:07:00.003+01:00</published><updated>2009-04-24T19:15:43.107+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='life pensions security email pgp'/><title type='text'>Securing Business to Business Email in the Pensions Industry</title><content type='html'>The UK life assurance and pensions industry sends huge amounts of confidential documents 'B2B' between product providers, intermediaries and advisers.  The majority of the big providers have bought into &lt;a href="http://www.assureweb.co.uk/"&gt;portal-style platforms&lt;/a&gt; where advisers can conduct business across many different players (such as Norwich Union, Legal &amp;amp; General, Zurich etc) - however, more than 60% of the business is conducted over the phone between adviser and product provider with the provider emailing, posting or faxing the resultant client documents back to the adviser.  Documents usually are client agreements, quotes or illustrations on how financial products such as pensions pay back depending on a clients circumstances.&lt;br /&gt;&lt;br /&gt;The life and pensions industry in the UK typically revolves around Financial Advisers who are independent or tied to an organisation.  The majority of IFA's are one or 2 man bands with little IT knowledge and little gumption to learn how to use IT assets properly.  The FSA has included data loss as an "reportable breach" and certainly, all staff who work at financial organisations have to pass regular training to detect what has to be encrypted.&lt;br /&gt;&lt;br /&gt;The problem the industry has is that IFA's who work with many financial product providers have to remember lots of credential-sets and remember how to use multiple mechanisms for receiving quotes and illustrations for pensions, investments and annuities from each of the main product providers.  The majority of secure email solutions are considered difficult to use and are not popular with recipients of secure email who have to browse to, register, and retrieve email through a web front end.&lt;br /&gt;&lt;br /&gt;To make matters worse - some of the core intermediaries are trying to dictate their secure email solutions are the only mechanism that they will do business.  One particular Wealth division of a big player has suggested "Password Encrypted Winzip" (crikey!) whilst others are moving to PGP/MIME solutions through products like Tumbleweed, Trend Micro and Cisco Ironport.&lt;br /&gt;&lt;br /&gt;We need a worldwide solution for securing email communication that the big organisations will buy into.  The solutions that involve plugins and proprietary solutions will just never work in the long term.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-9132551089204224804?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/9132551089204224804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/securing-business-to-business-email-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/9132551089204224804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/9132551089204224804'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/securing-business-to-business-email-in.html' title='Securing Business to Business Email in the Pensions Industry'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3129434197637637826.post-5632786757882101624</id><published>2009-04-24T18:54:00.007+01:00</published><updated>2009-04-24T19:15:59.968+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='paypal phish address security'/><title type='text'>Sophistication in PayPal Phishing Scams - name and address</title><content type='html'>The content of phishing emails tends to skew to the generic so imagine my surprise when a paypal scam email started as "&lt;tt&gt;Dear CALLUM WILSON&lt;/tt&gt;" and included my full address and postcode.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;Dear CALLUM WILSON ,&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;PayPal Resolution Center: Your account is limited.&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;Why is my account access limited?&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;As part of our security measures, we regularly screen activity in the PayPal system. During a recent screening, we noticed an issue&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;regarding your account:&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;...&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;- A clear copy of a recent bank statement or utility bill on which your name and address (NNN XXXXXX STREET,STIRLING,STIRLING,FK8 XXX) are clearly visible and less than 3 months old.&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;...&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;The email suggests that victims send compromising information such as copies of both sides of debit cards, passport, utility bills etc to &lt;tt&gt;secure@paypalcompany.com&lt;/tt&gt; - this, hosted on a compromised host [89.255.10.39] at a Dutch ISP.  The host redirects port 80 HTTP traffic to the real Paypal.com site but has SMTP, POP3 and IMAP daemons running suggesting tools to take in and process victims emails sent to the domain.  The server also has a copy of MySQL running, allbeit locked down for out of domain access.  The site is running Plesk [http://en.wikipedia.org/wiki/Plesk], a cpanel like ISP hosting platform on port 8443.  Firefox is now showing the site as a forgery - but &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mFLq7mDVJqE/SfH-_A-80-I/AAAAAAAAAAk/csl07nV1vEM/s1600-h/paypalcompany1.jpeg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 156px;" src="http://4.bp.blogspot.com/_mFLq7mDVJqE/SfH-_A-80-I/AAAAAAAAAAk/csl07nV1vEM/s200/paypalcompany1.jpeg" alt="" id="BLOGGER_PHOTO_ID_5328320192705254370" border="0" /&gt;&lt;/a&gt;how many internet users have anti-phising browsers?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;So what is the root of this scam?&lt;/b&gt;&lt;br /&gt;I always use unique usernames for any access to online shops - the interesting thing about my email was that whilst it had the correct name and address for my PayPal account, the email address was not correct.  The data had come from http://www.brother-store.co.uk - a UK based retailer of print stationery for the fabulous Linux compatible Brother QL-550 that runs in our office printing labels.&lt;br /&gt;&lt;br /&gt;The Impulse Group Ltd (Cambridge, UK) [http://www.impulse-group.ltd.uk] run a set of affiliate sites that retail various printer supplies share a common platform for sales enquiries and orders:  &lt;a href="http://www.enquiry-system.co.uk/"&gt;http://www.enquiry-system.co.uk&lt;/a&gt; and &lt;a href="http://www.secure-internet-payment.co.uk/"&gt;http://www.secure-internet-payment.co.uk&lt;/a&gt; (irony not included).&lt;br /&gt;&lt;br /&gt;Some 24 hours after the breach, some of the sites are still not functioning.  I rang Impulse Group Ltd this morning and they confirmed there had been a breach and that &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mFLq7mDVJqE/SfH-_WrayHI/AAAAAAAAAAs/L-II9T4-dV4/s1600-h/paypalcompany3.jpeg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 136px;" src="http://3.bp.blogspot.com/_mFLq7mDVJqE/SfH-_WrayHI/AAAAAAAAAAs/L-II9T4-dV4/s200/paypalcompany3.jpeg" alt="" id="BLOGGER_PHOTO_ID_5328320198528911474" border="0" /&gt;&lt;/a&gt;they would inform their customers through the website: &lt;a href="http://news.impulse-group.ltd.uk/"&gt; see the Impulse news site&lt;/a&gt; for more information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3129434197637637826-5632786757882101624?l=theresneversafetyinnumbers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://theresneversafetyinnumbers.blogspot.com/feeds/5632786757882101624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/sophistication-in-paypal-phishinh-scams.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/5632786757882101624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3129434197637637826/posts/default/5632786757882101624'/><link rel='alternate' type='text/html' href='http://theresneversafetyinnumbers.blogspot.com/2009/04/sophistication-in-paypal-phishinh-scams.html' title='Sophistication in PayPal Phishing Scams - name and address'/><author><name>Callum Wilson</name><uri>http://www.blogger.com/profile/09950179686755414486</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_mFLq7mDVJqE/SfV7S_D0KKI/AAAAAAAAAA4/OzHbTwdatKg/S220/10195.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_mFLq7mDVJqE/SfH-_A-80-I/AAAAAAAAAAk/csl07nV1vEM/s72-c/paypalcompany1.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
