Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Thursday, 4 March 2010

Wi-Fi 'Finders' Helping Thieves Locate and Steal Laptops

We don't recommend leaving your laptop in the car for any reason, but, if you must, make sure you turn off the Wi-Fi signal first. According to Network World, thieves are using devices meant to locate Wi-Fi networks to detect laptops and steal them. Apparently, just closing the screen won't prevent your laptop from being detected, either. Wi- Fi disconnection must be done manually, as it can take as long as a half-hour for a laptop to go into sleep mode.

The Wi-Fi "finders" that crooks use are often cheap and easily accessible. For less than $20, a start-up thief can purchase a ballpoint pen with a built-in Wi-Fi detector. Of course, the cheaper models aren't as accurate when locating the signals. (Using one in a full parking lot would be akin to searching for a needle in a haystack.) But for $50, you could purchase this Wi-Fi finder (pictured), which makes finding a laptop stuffed in the trunk of a car easy as pie.

What's our advice? Keep those laptops close at hand and make sure you only turn on the Wi-Fi signal when you'll be using it. [From: Network World]

Tuesday, 2 March 2010

FTC: Identity Theft Is No. 1 Consumer Complaint


Are you really you? It’s hard to say.

That’s because identity theft was the top consumer complaint for 2009, the Federal Trade Commission reported Wednesday.

It was also the top complaint from the year before, although 5 percent fewer consumers reported it in 2009, the commission said.

Overall, of the 1.3 million complaints the agency received last year, 21 percent were for identity theft. Debt collection agencies ranked second, with 9 percent of complaints, according to the Consumer Sentinel Network Data Book released Wednesday.

Credit card fraud was the top complaint when it comes to identity theft, followed by fraud related to government benefits, utilities, phones and loans.

The FTC did not verify the complaints lodged with it. It said 72 percent of those reporting identity theft also notified a police department.

The complete 101-page report (.pdf) is available here.

By David Kravets

Thursday, 28 January 2010

Pentagon Searches for ‘Digital DNA’ to Identify Hackers


One of the trickiest problems in cyber security is trying to figure who’s really behind an attack. Darpa, the Pentagon agency that created the Internet, is trying to fix that, with a new effort to develop the “cyber equivalent of fingerprints or DNA” that can identify even the best-cloaked hackers.

The recent malware hit on Google and other U.S. tech firms showed once again just how hard it is to pin a network strike on a particular person or group. Engineers are pretty sure the attack came from China, and it sure was sophisticated enough to come from a state military like China’s. But it’s hard to say conclusively that the People’s Liberation Army launched the strike.

It’s the kind of problem Darpa will try to solve with its “Cyber Genome” project. The idea “is to produce revolutionary cyber defense and investigatory technologies for the collection, identification, characterization, and presentation of properties and relationships from collected digital artifacts of software, data, and/or users,” the agency announced late Monday.

These “digital artifacts” will be collected from “traditional computers, personal digital assistants, and/or distributed information systems such as ‘cloud computers’,” as well as “from wired or wireless networks, or collected storage media. The format may include electronic documents or software (to include malicious software - malware).”

Ultimately, Darpa wants to develop the “digital equivalent of genotype, as well as observed and inferred phenotype in order to determine the identity, lineage, and provenance of digital artifacts and users.”

“In other words,” The Register’s Lew Page notes, “any code you write, perhaps even any document you create, might one day be traceable back to you - just as your DNA could be if found at a crime scene, and just as it used to be possible to identify radio operators even on encrypted channels by the distinctive ‘fist’ with which they operated their Morse keys. Or something like that, anyway.”

The Cyber Genome project kicks off this week with a conference in Virginia.

[Photo: NASA]

By Noah Shachtman

Friday, 8 January 2010

1 in 6 Massachusetts Residents Estimated Affected By Data Breaches from 2008 Through 2009


The Boston Globe had a sobering story over the weekend where it estimated that 1 in 6 Massachusetts residents were affected by some type of data breach over the past two years.

According to the Globe, its review of state recorded data breaches showed that at least 1 million state residents had their data compromised through credit card theft, unauthorized medical information disclosures, or other types of confidential data breaches. The Globe story also provides a list of some of the more prominent data breaches reported to the state from June to November 2009 - there were 13 of them affecting over 88,000 residents.

In 2007, Massachusetts passed a law requiring institutions such as banks, stores, universities, etc., must inform consumers and state regulators about security breaches that might result in identity theft. Since then, some 807 data breaches have been reported to state officials by the end of November 2009 the Globe says.

The Globe said that 60% of the disclosed data breaches were caused by criminal acts, while 40% were due to negligence.

However, the Massachusetts disclosure law has some loopholes that were exposed by the Hannaford episode in 2008 which may result in an under reporting of unauthorized data disclosures.

In addition, according to this paper by Sasha Romanosky et al. at the Heinz School of Public Policy and Management at Carnegie Mellon University, disclosure laws such as the one in Massachusetts don't do much in the way of reducing identify theft.

Given the number of data breaches, it is almost a certainty that someone in Massachusetts has had their personal data disclosed more than once. If anyone has had this happen to them, I would be very interested in hearing about it.

The Globe also writes that, "On March 1, new state regulations will require organizations to take stronger measures to ensure data security. Institutions that hold such personal data will have to write an official security program and train employees to follow it. In addition, organizations will have to encrypt all personal data stored on laptops, flash drives, or other portable devices, or that is transmitted over the public Internet or wireless networks."

It will be interesting to see how long after the 1st of March it will be before a data breach is disclosed to state officials that violates these new rules. I would be surprised if it takes more than 3 months

POSTED BY: Robert Charette

Saturday, 19 September 2009

Learn how to protect yourself from identity theft


Did you know that there are numerous steps you can take to protect yourself against identity theft besides just checking your credit report? Here, we talk with an expert and offer tips on what regular people can do to ensure their identities stick with them instead of other shady characters.

Identity theft is big business, and it keeps getting bigger as more and more information about us floats around in an ever data-obsessed society. From every swipe of your credit card to every time you go to the doctor, doors are opened for thieves to snatch information and use it to their advantage. And, as the name implies, it's not just about fraudulent charges showing up on your bank account, either. At worst, you could find that someone has been using your social security number for years to work various jobs or, as in one Chicago student's recent experience, you could even get thrown in jail because a thief using your identity has a warrant out for his arrest. "Oops" doesn't even begin to describe it.

Most Americans know the basic principle of checking their credit reports once a year. Every US citizen can now get a free report from the three major credit bureaus every year to ensure everything is right on their accounts. However, that's the extent of most of our knowledge, and only addresses one facet of identity theft (financial institutions). It turns out there are a number of other preventative measures that can be taken, especially if you're the paranoid type.
Protect against spyware and malware. Seriously.

Electronic theft may not be the most common, but it's the fastest growing, as noted by TrustedID CEO Scott Mitic. (The most common form of ID theft is still via people in your life who have physical access to your stuff—family, friends, your cleaning lady, your waiter, etc.) Still, theft via computer is one of the fastest growing areas and protecting against it is extremely simple. "Go online and find one of the many different companies that provide anti-spyware protection, which everyone should have," Mitic told Ars.

Indeed, many companies even offer free software to do so, such as McAfee's free SiteAdvisor plugin that aims to prevent users from being phished or forced to download malicious software. And, as always, practice safe file and link opening practices from your e-mail: only open files that you are expecting from people you trust, and if you're ever suspicious of a link from somewhere like PayPal or your bank, it's always safest to go to your browser and type in the URL yourself to log in instead of clicking from an e-mail.
Fraud alerts are your friend

People are often advised to place fraud alerts on their files with the credit bureaus after someone has stolen their information, but how often are you told to do it before? As it turns out, paranoid types do it all the time, and it's not such a bad idea either. There are two steps to this: putting a fraud alert on your credit reports, and putting a freeze on your credit. "These two mechanisms work in similar ways—someone cannot simply get your name and address and apply for credit in your name, because lenders must check with consumer first when these freezes are in place," Mitic said. "These are highly effective ways of reducing most of the most dangerous forms of identity theft."

Of course, if you're the type who regularly applies for those department store credit lines to get a discount on your purchase, or you're about to apply for a time-sensitive loan (such as a mortgage on a house), this may be something you'll want to hold off on. However, if you don't usually open up many new credit accounts or if you have had a close call with ID theft, it may be a good idea.
Check for your kids

Children's identities are currently going for a premium, it turns out. And, because most people don't think to check up on their kids' credit reports, the use of their IDs can go on for years (or sometimes even decades) before it ever comes to light. "Consumers and parents should be checking their children's info by going to the three credit bureaus once per year and inquiring as to whether or not there is a credit report," Mitic said. In this case, no news is good news, but if your kid is only 5 and has a report, there could be a problem.

Another way to check on your kid's identity is to request a yearly summary of his or her earnings from the Social Security Administration. Obviously, if your child is too young to work, there shouldn't be any earnings. But, as Mitic pointed out, undocumented workers might get a job with a stolen social security number and, if it's a child's, might be able to use it for many years. If that happens, though, the earnings will be reported on the yearly summary, so it's a good way to make sure things are clean for your child (and you, as well).
Think about your medical identity, too

"What many people don't realize is that their medical insurance is valuable to those who don't have insurance," Mitic said. Your name, address, and insurance information can easily be used by fraudsters to get medical treatments in your name. This is the most serious if someone has used your insurance already for treatment in a life or death situation. "If you end up in the hospital with a split appendix and doctors look at your medical charts, they might think it's not an appendix problem because you've already had yours removed."

Okay, so that's an extreme case, but it could still happen. "Half a million to a million people per year are paying for medical procedures that are not theirs," Mitic warned. (Ouch.) A good idea in this case would be to contact your insurance company once per year to ask for an annual disclosure of benefits processed in your name. This document will show every claim processed for you and you can examine it to make sure every item is legit.
Oh social networking, you minx

We already know that social networking sites can pose a threat to people's machines and networks thanks to the proliferation of malware, but it's also a good medium to steal people's identities and scam "friends." According to Mitic, there have been repeated incidents of people getting messages from friends describing extreme circumstances like a car accident and asking for money.

"Employ a reasonable level of suspicion when someone who is not standing immediately in front of you is asking you for anything," he said. "That's especially true in this era of social networking. The message that seems to be coming from your friend may not be coming from your friend."

Similarly, ensure that your own accounts don't get hacked or stolen by employing best practices when determining your passwords, and of course, don't share your password information (or your secret questions!) with anyone.
Conclusion

The rabbit hole is pretty deep when it comes to little things you could do to protect yourself from identity theft, but these basic steps will help mitigate the large majority of situations. If there's one thing that could be improved upon, it's the fact that each individual entity must be dealt with if you end up finding something fishy—if you find something on your credit report, you must deal directly with the credit agencies and financial institutions. If you find something on your insurance, you must deal with your insurance company and hospitals involved. If it's a case of social security fraud, you have to deal with the Social Security Administration to sort it out. Aside from this inconvenience, though, it's not hard to keep regular checks going on various parts of your life to make sure someone else isn't pretending to be you.