Showing posts with label Security Breach. Show all posts
Showing posts with label Security Breach. Show all posts

Thursday, September 19, 2019

Data Security and Facebook

An online report published by CNET on September 4, 2019 identified that at least 419 million records  of phone numbers tied with Facebook accounts appeared in databases online. The report was based on the revelation by TechCrunch

The exposure identified 133 million users from US alone and another 18 million and 50 million records from UK and Vietnam respectively.  The flaw as highlighted is Lack of Password protection on the server by Facebook. Records were identified with Demographic details also.

Now the big question, does this impact my privacy and security of my data online (read facebook data too)? Answer to this is pretty simple - if your demographic data and phone number is available example - sex, country and phone number (along with Facebook's Unique User ID) it is pretty much a compromise of your personal information leaving you vulnerable to certain cyber attacks. The data can also be misused to forge your identity with the modern mechanics of hacking.

This certainly is a big mess here by the team at Facebook to have left a critical server without password, the first baseline defense mechanism to check against unauthorized access. Though the very next day or so Facebook reverted with a statement that the data has been scrapped and is no more exposed to the open web. But from the time that server would have been put in place to the time the data was reported to be exposed and the steps by Facebook to scrap the data, do you think that the data would not have been compromised?  In all probabilities it would have been.

Though this is not the first time that such exposure or compromise has been reported. We keep on hearing such cases almost every other day.  The corporates accumulate our data for their business benefits and then miss out on the aspects of security to be deployed.  As per Facebook, this server probably served the purpose of searching a person on Facebook using the Phone Number of that person. My question here is why should the Phone Number search for Facebook user be activated in the first place? That itself is a breach of privacy and compromise of data that has been provided to a service provider as a security feature for secondary authentication.  

Facebook may state that they have this feature of find by phone to be controlled by the user and if user doesn't want to have this feature on, they can restrict it. Based on this aspect, I had a few discussions with a few facebook users and majority of them (close to 65%) didn't have an idea that they can control this feature of Search by Phone.  

So, the question still looms - "Should Corporates be allowed to Introduce Features that may pose Security and Privacy threats to the users?"

Friday, July 5, 2013

Use of Technology for Payment Transactions

The days when we used to make payments with hard cash are long gone.  With the advent of new age technology, Bank cards (Debit/Credit) and the Internet Banking, we all do go for convenience payment sitting in the comfort of our home and / or office.  The payments made in this way are something that can be tracked without dealing with the trouble of paper receipts.  

That's said, it is critically important to review the options before making payments with the use of technology as along with the convenience of making payment, technological advancements have provided the newer ways for attacks and scams.  Initially there were Phishing Attacks where the attacker would host a Dummy Site for the target bank and get the required information and enjoy the proceedings.  As the users started getting smarter and the Banks started implementing tighter security norms and getting the fake sites down, there came the Vishing Attack or where the attacker posing as the genuine Phone Banker or Customer Service Associate tries to extract relevant information including Sensitive Personal Information and PIN/CVV/CVC of the Card being discussed about. In many instances the Customers Do fall pray to such calls and they end up loosing their hard earned money.  Typical Case to be read here - Paying bill online costs man Rs 50,000

Now the main points to be noted while making online payments or while getting on for online transactions  are - 
  1. For making online payments, ensure that you register the organization, to whom you want to make payment, at your Bank's Internet Banking site
  2. If you find it cumbersome to register the Biller at your Bank's site, please ensure that you make the payment from the Official Site of the Biller and also by creating your own Account on that site
  3. Ensure that you DO NOT use any third party website for any online Bill Pay, as they may claim  to facilitate the transaction, but this is NOT always safe
Another aspect that needs to be taken care of is the payment through IVR System of the Biller or the Bank.  It is pretty important to note the following points - 
  1. Never reveal Sensitive Information like CVC/CVV/PIN during an Automated Call or while talking to the Phone Banker or Customer Service Representative
  2. It is critical to note that you never get a Call from either the Bank or the Biller stating to share your sensitive information to enable the payment through Phone Banking or IVR.  A Payment through IVR or Phone can only be initiated when you would call the Bank or the Biller to make such Payments
  3. Please ensure that if anyone claiming to be from the Bank or from the Biller seeks to gain your PIN/CVV/CVC and other information that is generally not sought by Banks / Biller, disengage yourself from the call and raise a written complain with your Bank / Biller through netbanking/biller website. This will trigger a automated response to your mail box.  Do not reply to that address and just wait for an official mail from your bank (delivered in netbanking inbox) and or Biller (delivered at your Registered email address).  
  4. You have a choice to refer the case to the Consumer Forum / RBI / Appellate Tribunal depending on your choice and party involved. When you refer the case to concerned authority you wold need to provide details around the transaction that is being referred, the person's name (if you remember), time you made the call, duration of the call and summary of the call proceedings.  Remember that IVR calls are always recorded and in such a case your claims can be verified at the Bank / Biller's side.
So, to be safe is in your hands and to ensure that you don't fall pray to such cases is totally in your hands.  You need to be really careful for not disclosing the sensitive information to anyone or on any weblink that you may get claiming to be of a bank.

Please ensure to verify the Website address as it would always have some altered information if it would be from the imposter. And the most important thing - if you suspect that your information has been compromised - raise a Red Flag Complain immediately with the Bank.  Bank's Do provide you with all the required help to protect against any fraudulent activity in your account.  In case you know that someone gained your personal information and has misused it, please lodge a written complain with the bank before you head to the Law Enforcing Agency.  A Copy of the Complain raised with Bank always helps you in your case and the Banks then have to ensure that they do cooperate in your case to get you the rightful justice.

However, in the current technological era, the old saying "Better to be Safe than Sorry" as well as "Precaution is Cure" still stand true.  So take due precautions to not let someone defraud you...its your information and you have the right to refusal for imparting the same...

Saturday, March 7, 2009

Information Security Breach - Minimize Points of Entry to the Network

Information Security Breach can be referred to as the compromise with Confidentiality of Data / Information with an Unauthorized and Unwarranted access. However a breach might not always result in Data Theft, but as the Information Guardian, the Information Security Team of an organization must vigilantly secure access to the Information Assets hosting/processing critical information including Personally Identifiable Information (PII) of customers, vendors, employees and other associated entities, Card Holder Data (ChD, that includes, PAN, Expiry Data, Name as on Card and other such information as identified under PCI-DSS v 1.2).

The Information Security Team and the IT operations team must be aware of the Security Scams and the methods that may be used to attempt and effect the Breach.  General methods deployed for the purpose are - 
  • Theft of Physical Equipment/s
  • Social Engineering
  • Phishing
  • Hacking
  • DoS, DDoS, Ping of Death, Syn Flood Attack
  • Defacement of Website
  • URL / IP redirects (also referred as Pharming, normally is man-in-middle attack)
  • Malware implants (trojans, worms, viruses to capture keyboard inputs, sniff network activity etc)
To reduce the chance and to reduce the impact of any breach, it is always a good practice to identify the entry points to the corporate network and reduce them to the minimum.  With minimized entry points the steps that must be taken to reduce the impact of any attempt or breach therein are - 
  • Firewall / IDS / IPS and System logs must be reviewed on a regular basis to identify any sign of security Breach or attempt therein
  • Consider deployment of an effective event-correlation mechanism to help you in root cause analysis and establishing the entry point and the probable target system.
  • Ensure that the Mobile Equipments are configured with Data Security and Protection measures like File / Hard Disk encryption
  • Employee awareness must be maintained with regards to the procedures for reporting suspicious activities, system issues, mails etc
  • Engage Interaction with external parties (Law Enforcement, Security Consultants, Industry Associations etc) to be informed about the porabable or possible Security Breach
The steps discussed above are just the preliminary steps and organizations need to do more than just guarding the gates / entry points. 

I would discuss the road ahead in next post.

Regards
Mayank Trivedi
E-mail - mayank.a.trivedi@gmail.com
Being Proactive Saves Time and Money