Phishing and the wider issue of identity theft

Phishing worries me. In fact, identity theft in general is one of my major concerns (and is the reason I refuse to do any more business with Halifax Bank of Scotland, one of the UK’s largest banks, who will not respond to letters or e-mails requesting that they remove my online access even though I have closed all of my accounts with them).

According to IT Week:

“The anti-phishing working group (APWG), which comprises security vendors, ISPs and financial institutions, has been serving as a clearing-house for information on attacks and trends for more than a year [and has] reported a 24% increase in phishing each month from August to December [2004]”.

Now a group of leading IT companies, including Microsoft and eBay (two companies which have themselves been affected by high-profile phishing attacks), along with electronic payment specialist Visa and security solution provider WholeSecurity have joined forces to create an early warning network for new attacks called the Phish Report Network.

Another Internet security and payment specialist, Verisign, has warned, in its fifth Internet security intelligence briefing, that phishing attacks are the biggest threat to online business, with just over 40% of phishing sites hosted in the US but further sites identified in a total of 37 countries. According to IT Week, Verisign added that effective action against phishing would require international co-operation between Internet service providers (ISPs) and law enforcement agencies.

The problem of identity theft is broader than phishing. Since my mother’s credit card details were used fraudulently a couple of years back (identified, to their credit, by the same bank that I criticised at the head of this post), all of my family have been very careful about how we dispose of sensitive information, but that doesn’t stop me from having my card copied in a restaurant (in the UK, cards are rarely swiped using a mobile card payment terminal, as they would be in many countries – instead, they are taken away and returned with a slip for a signature a few minutes later, although this is changing with the introduction of chip and PIN technology). In his recent article, hook, line and stinkers, which appeared in IT Week, David Neal notes that:

“Identity theft, enabled by a lackadaisical approach to filing and a loose relationship with paper-shredding machines, is big business these days. In fact incidents of stolen identities have rocketed from shoulder-shrugging insignificance in 1999 to a 10 on the ‘Holy Moly’ scale this year”.

UK consumer watchdog Which? recently reported that a quarter of UK adults have either had their identity stolen or knew someone who has been a victim of ID fraud.

One of the most common cases of identity theft is credit card fraud, which cost UK banks £160 million last year and someone has to pay for this (you guessed it – ultimately it is us, the consumers), and the UK is ranked second for the number of fraudulent transactions (whist online trade grew by 88% in Q4 2004, compared with the same quarter in 2003).

The Association for Payment Clearing Services (APACS) has launched Card Watch, a website providing advice to consumers, retailers, police and media about card fraud. Meanwhile, credit card issuer, Capital One has started offering fraud protection services (somewhat embarrassingly, and unfortunately for him, the star of Capital One TV adverts, impersonator Alistair McGowan, had his own rubbish searched by a tabloid journalist who obtained a significant number of items which could be used to steal his identity).

Whilst secure and accountable systems are a must, some gullible users will always fall foul of the type of fraud which most of us delete from our inbox without reading. The IT industry is taking action, with anti-phishing capabilities promised for a new Netscape browser and Microsoft promising anti-phishing tools in Internet Explorer 7. Meanwhile, legislation is also being considered, with the US Senate debating its proposed Anti-Phishing Act and the UK is considering its own legislation, with early draft regulations as possibility as early as the end of this year.

The financial services companies which I transact online with (First Direct and Egg) will not correspond with me by e-mail about anything which requires personal information (i.e. only marketing information) – instead they have a private messaging system embedded within their secure websites. It’s a pain in the backside as I like to keep copies of my correspondence within my e-mail client long after my relationship with a company (and hopefully its secure website – take note HBoS) ends. Now other companies such as eBay are following the same path, but as Ken Young pointed out recently in IT Week:

“The power of email, after all, is that it arrives in your lap. How many of us would trundle down to the Post Office on the off-chance [that there may be some mail waiting there for us]? And therein lies the big problem with private e-mail services – it is a far more restricted form of the real thing. It’s safer, but much less useful.”

Young also notes that such systems represent a challenge to fraudsters who are likely to send out e-mails to entice users to fake inbox sites (with the intention of harvesting personal information), or to use keystroke logging software to gain access to users inboxes.

Whatever happens, its clear that this issue will not disappear overnight. What is needed is consumer education, legal protection and increased use of multi-factor identification – for example extending chip and PIN to the home PC.

Links
Gone phishing (IT Week)
Card Watch
Phish Report Network

Microsoft Application Compatibility Toolkit v4.0 is finally released

Over the last few months I’ve been critical of the time its taken for Microsoft to ship an SP2-aware update to their application compatibility toolkit. Last week, one of the consultants from Microsoft UK e-mailed me to let me know that the Microsoft application compatibility toolkit v4.0 is now available for Windows XP (including SP2) and Windows Server 2003.

The application compatibility toolkit contains tools and documentation to evaluate and mitigate application compatibility issues including the latest versions of the Microsoft Application Analyzer that simplifies application inventory and compatibility reporting, the Internet Explorer Compatibility Evaluator that assists testers in locating compatibility issues with Internet Explorer on Windows XP SP2, and the Compatibility Administrator that provides access to the necessary compatibility fixes to support legacy applications in Windows.

New messaging and collaboration tools from Microsoft

I’m yet to be convinced of the business benefits of instant messaging (IM). My current employer doesn’t prohibit IM – in fact it is encouraged – I use Microsoft’s MSN Messenger service, as do many of my colleagues. I suspect the reason we that we haven’t implemented a corporate IM solution is cost.

According to IT Week, research conducted by Telewest business has found that due to security concerns only a third of UK companies allow staff access to IM. Many other companies are still deciding what their corporate messaging policy should be, but with the rising incidence of spam over IM (spim), ignorance of IM is no longer an option.

For those large enterprises that do allow IM, using the free services from Microsoft, Yahoo!, AOL and others are simply not an option (in fact they are a liability) and if IM is to become a business tool, a corporate IM infrastructure needs to be provided. For many years, Microsoft has produced a variety of chat-like products under the Exchange Server banner, but they were removed from Exchange Server 2003 and replaced with a new product – Microsoft Office Live Communications Server (LCS) 2005, which provides corporates with IM and presence capabilities.

Earlier this month, Microsoft revealed their vision for collaboration with a new product on the horizon – Microsoft Office Communicator 2005 (previously codenamed Istanbul) – supporting all of the current IM capabilities plus PC-to-phone integration and “rich presence awareness” (the ability to route calls by the most appropriate medium – fixed-line, mobile or IP voice, IM, e-mail, video or web conferencing). Microsoft will back up Office Communicator with a service pack for LCS due later this month and including enhancements such as IM spam (spim) controls, auditing (to address regulatory concerns), compatibility with Microsoft Operations Manager (MOM), HTTPS access (removing the need for VPN connections) and public IM connectivity (the ability to communicate with MSN Messenger, Yahoo! Messenger and AOL Instant Messenger clients). Alongside all of this, is Microsoft Office Live Meeting 2005, an upgrade to Microsoft’s web conferencing service, offering call controls for audio conference service providers and the ability to conduct live meeting sessions within Microsoft Office (in the UK this made available as a hosted service from BT, with per-minute, named user or per-seat tariffs – there is a Flash-based demonstration on the BT website).

Taken together with related initiatives, such as Exchange 12, which is expected to manage PBX-based phone messages, and the constantly increasing collaboration functionality within the Microsoft Office System, Microsoft’s efforts are wide-ranging and long-term.

First SUS, then WUS, now WSUS (or is it MUS?)

The SUS/WUS name debate continues…

Today I received notification from Microsoft that the Windows Server Update Services (WSUS) release candidate (RC) is now available. Microsoft’s e-mail to participants of the WSUS open evaluation program (OEP) reads:

“We are pleased to announce that the Windows Server Update Services (WSUS) Release Candidate (RC) released today, Tuesday March 22! The Release Candidate of Windows Server Update Services (WSUS), formerly Windows Update Services (WUS), includes new features such as:

  • Replica mode for WSUS server hierarchies, making them easier to manage.
  • SSL connections between WSUS servers and clients, providing an even more secure end-to-end environment.
  • Automatic Update policy to allow non-administrators to receive update notifications, offering greater flexibility in organizations where logged on users are commonly not administrators.”

Thomas Lee notes that “the name is still a curiosity and WSUS appears to fall a bit short of earlier promises in that no SQL or Exchange updates seem to be supported, it’s an important step on the road on the path to a better patch experience for users”.

Further details of the WSUS RC can be found on the Microsoft Update Services (MUS?) website.

The return of WordPerfect?

Back in my student days I used MS-DOS 5.0 and WordPerfect 5.1. It worked really well. Then I moved to Windows 3.1 and Word for Windows 2.0 (Windows versions of WordPerfect just never made the grade). Obviously I was not alone because over the intervening 12 or so years WordPerfect’s fortunes have not been good until recently when the product’s current owners, Corel, persuaded OEMs to ship WordPerfect products as low-cost alternative to Microsoft Works and Office on new PCs.

Now the US Department of Justice (DoJ) is reported to have adopted WordPerfect Office 12 for its 50,000 users. The WinInfo Update reports that Corel has 20 million user worldwide, marketing WordPerfect for “its unique functionality, broad capabilities, and low price”.

According to Corel, “WordPerfect Office 12 is a full-featured office productivity suite that includes word processing, spreadsheet, presentation, and address book applications”. Because it is compatible with popular file formats, including Microsoft Office and Adobe PDF, WordPerfect Office 12 users can interoperate with users of other applications and, unlike open-source office productivity alternatives such as OpenOffice.org, Corel provides support for WordPerfect.

But the killer (from a licensing perspective) is that Corel gives WordPerfect corporate licensees home and laptop privileges so they can install the same copy of the product at home and on a laptop in addition to a desktop computer.

Microsoft Office is still a highly profitable product for Microsoft and looks unlikely to be usurped from its top spot but with new releases of Windows running late giving Linux the opportunity to build its market share, Firefox rising in popularity (IE’s share now reported to be down to 87%), and new threats in the office productivity space, Microsoft needs to work hard to remain competitive and protect its margins. Competition is back, which is no bad thing, but there could be interesting times ahead.

Linux creator switches to the Mac… nearly

This one made me laugh when I read it in the Windows IT Pro magazine network WinInfo Daily Update:

“The Macintosh community was agog this week at news that Linux creator Linus Torvalds has ‘switched’ to the Mac, but the truth, as is so often the case, is so much less exciting than the rumours. Torvalds is indeed using a Power Mac G5 tower, but some unnamed corporation gave it to him as a gift. And he’s running Linux on the box, not Mac OS X. ‘It obviously runs only Linux, so I don’t think you can call it a Mac any more,’ Linus noted. ‘And … I got the machine for free.’ So much for Apple’s highest-profile switcher.”

New security guidance for consumers and business

Thomas Lee recently blogged about UK government’s security awareness website which is intended to “provide both home users and small businesses with proven, plain English advice to help protect computers, mobile phones and other devices from malicious attack”.

The government hopes the service will help boost confidence in e-commerce, and at the same time protect national security but the trouble is, that I have only heard about it on Thomas’ blog, and in a recent article by David Neal, home users will bodge DIY security, which appeared in IT Week. As Neal points out, there has been no high profile coverage and consumers are not likely to be aware of the new initiative. He goes on to say that even “plain English… will go over the heads of most users” and that “giving someone advice on tinkering with their firewall, updating their virus definitions, rebooting in safe mode and checking their proxy settings is as dangerous as arming everyone in the country with a shotgun, just because there has been a spate of burglaries”- an interesting view, and no doubt intended to be provocative, but nevertheless an opportunity for many small IT businesses consulting to the SOHO and low-end SME marketplace.

Meanwhile, for larger businesses, the Information Security Forum (ISF) has issued updated guidelines in the form of the standard of good practice for information security v4.1 incorporating updated sections in areas that have been the subject of additional research and investigation including:

  • Information risk management in corporate governance.
  • Virus protection in practice.
  • Securing instant messaging.
  • Managing privacy.
  • Information risk analysis methodologies.
  • Patch management.
  • Managing the information risks from outsourcing.
  • Web server security.
  • Disappearance of the network boundary.
  • Feedback from the results for the ISF’s information security status survey.

The many uses for RFID

There’s been a lot of talk about radio frequency identification (RFID) in the IT press recently. For a technology that has been around in various forms since the second world war, its taken a long time to come to market (OK, that’s not strictly true it’s employed within the ID cards that many of us use to access our office buildings, and for Londoners with the strangely named Oyster Card, which is the largest smartcard payment system in the UK, excluding credit and debit cards) but now that RFID transmitters are tiny enough to embed in just about anything, some large organisations are starting to wake up to the potential uses of this technology.

Some of the uses I’ve seen for using RFID in the press over the last couple of weeks include:

RFID is a technology which has the potential to enable enterprises to know every move of every product and service. To privacy campaigners that sounds scary (yeah right, so you have a mobile phone? If so, then your location can already be tracked by the authorities) and the European Union is conducting a public consultation looking at concerns over data protection and how the technology is being used. To me, it sounds scary for another reason – the sheer volume of data that needs to be managed!

The success of RFID deployments is likely to be linked to a network’s ability to handle the data intelligently and securely, according to an IDC report (not surprisingly commissioned by Cisco), predicting that RFID will have a significant impact on enterprise networks not just because of the number of tags involved, but because of the amount of data each tag could hold and the number of times it is scanned during transit or processing.

I recently read an excellent article in Enterprise Server Magazine (now renamed Server Management), contributed by Mark Palmer and entitled “Making Meanings”. I could not find it online, but the nice people at ObjectStore were happy to send me a copy, which I can’t publish here (for copyright reasons), but which I’m sure they would send to anyone else who is interested. In the article, Palmer sets out seven principles for the effective management of RFID data:

  1. Digest RFID event data close to the source of the RFID activity (i.e. convert from many raw events to a collection of meaningful events) to ensure greater reliability and protect the IT infrastructure.
  2. Whether or not a complex event processing (CEP) tool is used or one is built specially, the principle is the same – to turn simple events into meaningful ones in order to derive knowledge on which actions may be taken.
  3. Data concentrators can be used to achieve reliable speed, by buffering event stream flows, combining RFID middleware, event processing and in-memory data cache.
  4. RFID event data can be processed in context by caching reference data.
  5. Federate data distribution so the RFID system can scale and yet still provide information in near real time.
  6. Age RFID data to keep the working set manageable, enrich raw data with context and reduce the load on downstream systems.
  7. Automate exception handling to improved overall business efficiency.

Another area which needs to be addressed for RFID to take off is that of standards – many of the existing standards are US-based and some experts would like to see the RFID electronic product code (EPC) standards body work with the International Organization for Standardization (ISO), so that EPC can focus on product codes and ISO on frequency.

In the meantime, the Computer Technology Industry Association (CompTIA) which runs the A+ and Network+ certifications is said to be developing a certification scheme for RFID skills.

Microsoft plans to launch its RFID services platform in 2006.