Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Friday, 29 January 2010

Security researchers blast credit card verification system


Some credit card companies use a system called 3-D Secure (3DS) that adds an extra step to transactions that are carried out on the Internet. Visa and MasterCard tout their security, but researchers are questioning their efficacy.

When making a purchase, online shoppers are confronted with a validation check that requires them to supply a password—in addition to the standard security code that is on the card itself—in order to prove that they are the real owner of a credit card. Systems built on 3DS are better known by their brand names, which include Verified by Visa and MasterCard SecureCode.

Security researchers say that these validation systems—which are used by over 200 million cardholders—suffer from serious security deficiencies. Although the failings of 3DS and its lack of conformance with best practices are well-documented, it has still been widely adopted by online retailers because it allows them to deflect the liability for fraud back to the credit card companies.

Some of the credit card companies take advantage of 3DS by wrapping their implementations of the validation system in draconian terms of service that force users to agree to accept full liability for credit card fraud. To make matters worse, some retailers don't allow consumers to opt out. The 3DS Activation During Shopping (ADS) functionality often ropes in users and gets them to sign up without fully realizing that they are doing.

In a paper presented at the Financial Cryptography conference, researchers Ross Anderson and Steven Murdoch reveal the dark underbelly of 3DS and show how the service is detrimental to consumers.

"From the engineering point of view, [3DS] does just about everything wrong, and it's becoming a fat target for phishing," wrote Anderson in an entry at the University of Cambridge security research blog. "This is yet another case where security economics trumps security engineering, but in a predatory way that leaves cardholders less secure."

The standard method of integrating 3DS verification in a website involves using HTML iframes. This is highly problematic, because it means that users won't be able to rely on the security features of their browser—such as certificate highlighting in the browser URL bar—to easily distinguish between phishing sites legitimate 3DS verification. The inability to visually ascertain whether the certificate is valid exposes users to the possible risk of man-in-the-middle attacks.

Another problems with 3DS that is highlighted in the report is that it fails to specify a consistent mechanism for verification. Individual implementors are free to determine the means for verification on their own, and often make really poor choices. For example, the report says that one bank requires cardholders to enter their ATM PIN during the verification process. This is a pretty shoddy security practice that encourages consumers to engage in risky practices that will expose them to significant risk from phishing scams.
Fixing the problems

The widespread and growing adoption of 3DS is difficult to combat because it offers built-in incentives for merchants and banks by making it easy for them to shift liability to the consumer. The researchers say that the time has come for better technology and regulatory intervention.

Financial institutions have aggressively embraced the concept of electronic passwords in some countries—such as the UK—because passwords aren't covered by the laws that protect consumers from the consequences of transactions that are carried out with forged signatures. The security researchers say that the banks should only get to shift the liability to the consumer when transactions are validated by a trustworthy payment device—a piece of hardware, similar to a CAP calculator, that connects to the user's computer and implements a two-factor authentication model.
Further reading

* Paper (PDF) (cl.cam.ac.uk)
* PCWorld (news.yahoo.com)

By Ryan Paul
http://arstechnica.com

Thursday, 24 December 2009

Kid uses facebook to blackmail classmates into sex.


From a purely depraved perspective, Anthony R. Stancl's plot was simple and effective. He went on Facebook posing as a girl named "Kayla," then chatted up his male classmates at Eisenhower High School in New Berlin, Wisconsin. The fictitious "Kayla" had a way with the boys, convincing 31 to send Stancl pictures of themselves naked...

​But that's when "Kayla" would turn on her Facebook lovers. Once they sent the photos, she would threaten to send them to the rest of the school unless they had sex with fellow student Anthony R. Stancl.

It didn't work on all 31, but police believe at least seven boys fell for the ruse. They would meet for sex with Stancl in the high school bathroom, the school parking lot, the men's room at the public library, and various parks around town. The victims ranged in age from 13-19.

The scam might have continued if Stancl hadn't overplayed his cards. One 15-year-old boy repeatedly had sex with Stancl to avoid having his naked photos sent around the school. Stancl would then photograph the encounters to add to his leverage.

Then Stancl tried to push the envelope, asking for naked pictures of the boy's brother. The kid didn't want his brother involved, so he told his parents, who in turn called the cops. When detectives grabbed Stancl's computer, they found it loaded with evidence, containing more than 300 nude photos of classmates at Eisenhower High School.

Stancl originally faced 12 felonies that could have landed him nearly 300 years in prison. But yesterday, he pleaded no contest to lesser charges of sexual assault and repeated sexual assault of a minor. The 19-year-old still faces up to 50 years in the slam.

Detectives say the victims were more than happy with the plea, since it kept them from having to out themselves in court.

"I've never had a case where the victims and their families were more apprehensive about testifying," Waukesha County district attorney Brad Schimel told the Associated Press. "From the victims' perspective, they're relieved we're doing this."

By Pete Kotz

Wednesday, 4 November 2009

Phishing

Monday, 26 October 2009

Nigeria actually arrests, shuts down online scammers


Nigerian officials have launched a new initiative called "Project Eagle Claw" that will target Internet scams coming out of the country. The Economic and Financial Crimes Commission has already made a number of arrests and shut down 800 websites, with many more to come.

It turns out Nigeria is taking measures to fight Internet scams—law enforcement there has shut down close to a thousand websites and made 18 arrests as part of a new initiative to save the nation's reputation and crack down on Internet scammers. The program, called "Project Eagle Claw," has only just begun, but Nigerian officials expect it to be fully operational in 2010.

Nigeria's Economic and Financial Crimes Commission (EFCC) described the initiative as "a renewed bid to clap down" (*clap clap*?) on Internet fraudsters. So far, the agency claims to have shut down 800 scam sites in addition to making the arrests, with many more apparently to come.

EFCC Chairman Farida Waziri said Wednesday during a US address to the National Conference of Black Mayors that Nigeria was working with Microsoft to fully deploy Project Eagle Claw, and that it will soon be able to take down up to 5,000 fraudulent e-mails per month. She also expects the system to send up to 230,000 advisory e-mails to victims every month.

Waziri explained that the EFCC's previous strategy for fighting cybercrime involved "cyber raids" and petitions—slow and ineffective in today's fast-moving Internet world—and that Eagle Claw would be much more proactive. "We expect that Eagle Claw as conceived will be 100 percent operational within six months and at full capacity, it will take Nigeria out of the top 10 list of countries with the highest incidence of fraudulent e-mails," Waziri said.

Indeed, if you live outside of Africa, Nigeria is practically synonymous with various scams, some of which predate the Internet. Thanks to the explosion of online connectivity in the last several decades, however, so-called "Nigerian scams" have taken on a new life of their own—fraudsters have managed to grift millions of dollars out of unsuspecting victims in recent years, with even major banks coming dangerously close to wiring their own cash halfway around the world.

This has caused an entire culture of scam baiters to spring up in order to troll scammers and distract them from the real victims (something that we here at Ars briefly dabbled in ourselves), showing that scams out of Nigeria are indeed more than a minor law enforcement annoyance. At this point, it's just nice to see Nigerian officials trying a more realistic strategy towards curbing cybercrime than merely blaming the victim, even if it may take years worth of enforcement before we see any tangible results.

By Jacqui Cheng

Wednesday, 22 April 2009

Report: Payment card data was top target in 2008

More records were breached in 2008 than in the previous four years combined as a result of a few large breaches involving payment cards, according to a report released on Wednesday.

Last year, 295 million records were compromised and there were 90 confirmed breaches, the Verizon Business 2009 Data Breach Investigations Report (PDF) found.

The top five breaches accounted for 93 percent of total records compromised and as a percentage of caseload, 80 percent were payment card breaches while payment card data represented 98 percent of all records compromised last year.

PIN data was increasingly targeted in 2008 in attacks in which magnetic-stripe data and PIN data was used for identity fraud. For example, criminals used the data to make ATM withdrawals from victim's accounts.

PIN data stolen in a breach at payment processor RBS WorldPay was used to clone cards and withdraw millions of dollars from victim bank accounts last year. Meanwhile, payment processor Heartland had a huge data breach of its own last year that it reported in January and there have been reports of another breach at an unidentified institution.

More than three-fourths of organizations suffering payment card breaches were found to be not compliant with PCI data security standards or had never been audited. The typical organization had met less than a third of the requirements in the standards, the report found.

This chart shows threat categories by percent of breaches (black) and records (red).

(Credit: Verizon)

Of the total breaches, 75 percent came from external sources, 39 percent involved multiple parties, 32 percent involved business partners and in 20 percent of the cases insiders were implicated. Three-fourths of the breaches were undiscovered and uncontained for weeks or months.

As far as types of breaches, 64 percent resulted from malicious hacking, 38 percent used malware, 22 percent involved privileged misuse, and 9 percent used physical attacks such as equipment theft or tampering.

In about four of 10 hacking-related breaches, an attacker gained unauthorized access to the victim via one of the many types of remote access and management software, typically provisioned to third-parties for remote administration.

During 2008, malware was involved in more than one-third of the cases investigated and contributed to nine out of 10 of all records breached.

"Malware is now an essential component to nearly all large-scale data breach scenarios," the report said. "Hacking gets the criminal in the door, but malware gets him the data."

Tuesday, 7 April 2009

Survey: Credit card fraud a top concern in U.S.

This should come as no surprise to anyone, but people in the U.S. are worried that as the economy worsens, the chances for identity fraud, particularly with regard to credit card data theft, will increase.

Nearly 75 percent of Americans believe that the global financial crisis increases their risk of identity and related fraud, according to the Unisys Security Index due to be released on Monday.

More than two-thirds surveyed said they are extremely or very concerned about other people obtaining and using their credit and debit card data, with 90 percent at least somewhat concerned.

Credit and debit card fraud is the top security concern for people, with 68 percent saying they are extremely or very concerned. And 66 percent said they are seriously concerned about unauthorized access to or misuse of personal information.

More than 40 percent of respondents said they are extremely or very concerned about security related to viruses and unsolicited e-mail.

Overall, people are more worried about their financial security and less worried about national security than in previous surveys, according to the survey.

The survey of more than 1,000 respondents in the U.S. was conducted from February 20-22.