Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, March 16, 2015

POLITICS - eMail Security MuckReads

Purely Republican partisan politics.

"Hillary Clinton’s Top Five Clashes Over Secrecy" by Jeff Gerth, ProPublica 3/13/2015

The latest flap over her private emails as secretary of state is far from the first time she’s been accused of lacking transparency.

Back in April of 2007, when she was campaigning for the Democratic Presidential nomination for the first time, then-Senator Hillary Clinton lashed out at the secrecy of the George W. Bush administration.

She told a New Hampshire audience that if elected she would implement a "plan to enhance accountability and transparency" and "to replace secrecy and mystery with openness."  One part of her plan:  "It's time our government went fully online as well."

She lost her White House bid.  But 20 months later, before Barack Obama took that job and she became secretary of state, she set up a private computer server registered to her home in Chappaqua, N.Y., to handle all her official, as well as private, emails for the next four years.  Her decision — a secret until earlier this month — impeded efforts by the press and others to review State Department actions.

Today it is Hillary Clinton's record of transparency that has come under fire.  At a press conference Tuesday, she acknowledged that in retrospect "it would've been better for me to use two separate phones and two email accounts."  She has asked the State Department to release her official emails, a process that could take months.

Few public figures have been as scrutinized as Hillary Clinton.  Sometimes her disclosures go beyond what is required, but she's also racked up a reputation for secrecy that at times has returned to haunt her.

Here are five examples covering the last two decades.  Some are drawn from a 2007 book I did, with Don Van Natta Jr., entitled "Her Way:  The Hopes and Ambitions of Hillary Rodham Clinton."  (Little Brown & Co.)  Clinton's office didn't respond to a request for comment.

1) 1992:  The Commodity Trades

During Bill Clinton's first run for the White House, his campaign declined to release all of the couple's tax returns.  Later it emerged that the campaign had weighed requests from the press and decided not to do so, because a few of the returns showed Hillary Clinton's spectacular success in commodities trading, in which she made almost $100,000 from an initial investment of $1,000 in a matter of months for a return of almost 10,000 percent.  Hillary Clinton threatened a campaign lawyer who had access to the material with retribution if she released the data:  "You'll never work in Democratic politics again," the lawyer, Loretta Lynch, says Clinton told her.  It wasn't until 1994, as the New York Times prepared to publish an article detailing the trades, that the Clintons made public the returns.

2) 1993:  The Health Care Task Force

As First Lady, Clinton led a Presidential task force to overhaul the U.S. health care system.  The group, which produced a 1,342-page bill that failed to win approval, came under intense criticism from lawmakers and interest groups for meeting behind closed doors.  Several court challenges were brought in an attempt to open the process. Ultimately the courts provided a partial legal victory to the administration.  Clinton later wrote she didn't mind the criticism since she was "trying to do something important for people" but acknowledged the failure was partially the result of her "own missteps" in "trying to do too much, too fast."

3) 1994:  Records from the Rose Law Firm

U.S. investigators in 1994 subpoenaed the First Lady's billing records from her years at the Rose Firm in Little Rock, Arkansas, documents that had been also sought by reporters.  A focus of their interest was her legal work for a failing savings and loan, but records of those billings weren't found.  Much later, Clinton's long-time assistant, Carolyn Huber, said she found in the White House residence an additional box of records that contained the billing memos.  They were turned over to the independent counsel in 1996.  Clinton testified she had no knowledge of how the records wound up where they did.

4) 2006:  The Energy Task Force

Late in her first term as U.S. senator from New York, Clinton set up an energy task force to help her work through the issue, deliver a major speech on the subject and prepare for a possible Presidential run, participants in the task force told us for the book.  They produced a 40-page report in April 2006.  The whole project, including the existence of the group, its members and its work product was a secret, designed, participants said, to encourage frank discussions of the issue.  The leader of the task force headed an investment firm with major holdings in the energy sector.  Senators routinely get input from outsiders and no law requires their disclosure, but a secret task force is unusual.

5) 2015:  The Family Foundation

The Clinton family foundation, now called the Bill, Hillary and Chelsea Clinton Foundation, made disclosures that exceed the legal requirements.  Charities are not required to list donors, but as part of Clinton's selection as Secretary of State the foundation agreed to disclose the identity of contributors and restrict solicitations from foreign governments.  Still, the information on the foundation's website is less than full.  Donors are identified but not the exact amount of each donation or the date of those contributions.  Instead donations fall under ranges and are listed cumulatively.  The foundation did not announce that it started raising money from foreign governments after Hillary Clinton left office.  But last month the Wall Street Journal pieced together some new foreign donations after the foundation's web site was updated.  That article was the first in a spate of news accounts raising questions about foreign money coming into the Clinton network as she prepares a run for President.  The foundation has said donors are carefully vetted and their money goes to important charitable projects.


"Email Escapades MuckReads Edition:  Hillary is Just the Latest Politician to Avoid Official Email" by Leticia Miranda, ProPublica 3/13/2015

Former Secretary of State Hillary Clinton has been on the defensive ever since the New York Times first reported that she used a private email account for government business.  In light of the imbroglio, we decided to look at the email escapades of other politicos for this week's MuckReads:

Colin Powell relied on personal emails while secretary of state, Politico, March 2015

Since news of Clinton's use of private email for White House business broke, an aide to Colin Powell says he "might have occasionally used personal email addresses" to correspond with staff and officials during his tenure as Secretary of State.

Bush Advisers' Approach on E-Mail Draws Fire, The New York Times, April 2007

The Bush Administration admits that as many as 22 political advisers to the president, including Karl Rove, used their Republican National Committee email accounts for White House related business.  At the time, the RNC automatically purged emails after 30 days.  Later, a White House spokesperson reported that as many as 5 million emails could have been lost from the White House's official server.

Jeb Bush Owned Personal Email Server He Used as Governor, NBC News, March 2015

A Mar. 4, 2015 report from NBC News finds that between 1999 until early 2007 Jeb Bush used his own private email server for official business as Florida Governor.

Two ex-Walker aides charged with illegal campaigning, The Milwaukee Journal-Sentinel, January 2012

Two former aides to Gov. Scott Walker, while he was Executive of Milwaukee County, used a private Internet network to conduct campaign work.  They are later charged with illegally campaigning on government time.

Trove of Palin E-Mails Draws Press to Alaska, The New York Times, June 2011

In 2011, Sarah Palin releases more than 24,000 pages of emails sent from a private account while she was Alaska governor, responding to public records requests made in 2008.  The emails reveal less-than scandalous details of her life including her early attempts to meet John McCain, a draft ghostwritten letter-to-the-editor in response to criticism against her and plans to see a controversial Christian pastor in Juno, Alaska.

U.S. Ambassador to Kenya J. Scott Gration resigns over 'differences' with Washington, The Washington Post, June 2012

Scott Gration, US Ambassador to Kenya, resigns in Jun. 2012 just before the publication of an Office of Inspector General report that found he had "repeatedly violated diplomatic security protocols at the embassy" by using a private email account for official business, according to the Washington Post.

Christie administration may have violated public records law, The Record, January 2014

The Record releases a cache of emails sent from personal accounts between top Chris Christie aides that reveals their plan to create a traffic jam over the George Washington Bridge possibly as retribution against the mayor of Fort Lee who refused to endorse Christie in the 2013 New Jersey gubernatorial election.

After Pledge of Sunlight, Gov. Cuomo Officials Keep Their Email in the Shadows, ProPublica, May 2014

ProPublica finds that top advisers to New York Gov. Andrew Cuomo conduct government business through personal email accounts including Howard Glaser.  ProPublica recently obtained emails from Glaser in which he touted his " significant, critical, and current input" on a deal that weakened rules to prevent misdeeds in the mortgage market.

Monday, April 28, 2014

AMERICA - Are We Living in George Orwell's '1984' Society

NOTE:  Chula Vista, CA, San Diego County, is the city just north of where I live (South San Diego).

George Orwell, novel "Nineteen Eighty-Four"

IMHO:  You do NOT have expectation of privacy in public areas, which includes streets and highways, nor should you.

"With power of facial recognition and high-tech surveillance, where to draw the line between safety and spying?" (Part-1) PBS NewsHour 4/25/2014

Excerpt

JUDY WOODRUFF (NewsHour):  During the past year, we have learned a lot about the U.S. government’s surveillance program.

But those efforts are not limited to the National Security Agency.  Local law enforcement agencies are also gathering and mining unprecedented amounts of data.  Privacy advocates worry police can use this information to track anyone at any time without a warrant.

The Center for Investigative Reporting, in partnership with KQED San Francisco, has been looking into these new tools for fighting crime.

The center’s Amanda Pike has this report.

AMANDA PIKE, Center for Investigative Reporting:  Officer Rob Halverson of the Chula Vista Police Department is testing the technology that could change how police fight crime.

He’s on a call to verify the identity of a woman just arrested for possession of narcotics.  He doesn’t need to ask her name or check her I.D.  He just takes her picture.

OFFICER ROB HALVERSON, Chula Vista Police Department:  Just look here, please.

AMANDA PIKE:  His tablet uses facial recognition software to find the suspect’s mug shot and criminal history.

OFFICER ROB HALVERSON:  You can lie about your name.  You can lie about your date of birth.  You can lie about your address, but tattoos, birthmarks, scars don’t lie.

AMANDA PIKE:  Police have access to more data than ever before, raising questions about how that information is used and stored.  The tablet is part of a pilot program in San Diego County.

OFFICER ROB HALVERSON:  It’s been very helpful.  And some people just have to have the threat of, OK, you don’t want to tell us who you are?  We are just going to take a photo and we’re going to be able to compare.  And then when people kind of realize the technology we now have, they’re more likely to tell us their real name in that.

AMANDA PIKE:  More and more, police are using biometrics, biological markers from face scans and palm prints, in addition to fingerprints, to identify suspects.



"New surveillance techniques raise privacy concerns" (Part-2) PBS NewsHour 4/26/2014

Excerpt

SUMMARY:  A report from the Center for Investigative Reporting and KQED delves into a wide-scale surveillance system being developed for police forces.  How can the trade off between safety and privacy be negotiated as technology gets more and more sophisticated?

Tuesday, March 11, 2014

MALAYSIA - Security Failure on Malaysia Airlines Flight 370

"Security failures of missing Malaysian flight spark concern" PBS NewsHour 3/9/2014

Excerpt

HARI SREENIVASAN (NewsHour):  For more about whether the crash of that Malaysian jetliner was an act of terrorism, we are joined now from Washington by Rafi Ron.  He is an aviation security expert and former director of security at Tel Aviv Ben Gurion International Airport.

So, Mr. Ron, of what we do know we have a few things confirmed:  We had good weather.  We had experienced pilots.  We had solid safety records for both the airline and the aircraft.  We had no distress signal.  And then we have the incidence of these stolen passports.  Does it all point toward a security failure and terrorism.

RAFI RON:  There’s no question that there is a security failure by the fact that two people were allowed to board the flight with identities that do not belong to them.  But whether this security failure is connected in any way to the destruction of the aircraft – or the disappearance of the aircraft – it is still yet to be determined.  At this time there is no direct evidence to tie up the two events.



"How does a modern jetliner vanish without a trace?" PBS NewsHour 3/10/2014

Excerpt

SUMMARY:  There are still many more questions than answers in the mysterious disappearance of Malaysia Airlines Flight 370.  Judy Woodruff asks former NTSB investigator Alan Diehl and former NTSB board member John Goglia to speculate on different known factors and possible theories.

Wednesday, January 22, 2014

AFGHANISTAN - Political Uncertainty Affecting Security?

"How does political uncertainty affect Afghanistan's security?" PBS Newshour 1/20/2014

Excerpt

GWEN IFILL (Newshour):  The Taliban carried out a brazen attack today against a military base in Southern Afghanistan. Using a truck bomb, gunmen stormed the complex and killed an American soldier.  That followed an assault Friday that targeted a restaurant frequented by Westerners in Kabul; 21 civilians were killed, 13 of them non-Afghans, in the single deadliest attack against foreign citizens since the war started.

Claiming responsibility, the Taliban said the attack was in retaliation for an airstrike last week against insurgents in the eastern Parwan province.  There is little agreement on the genesis of that attack.  There were a number of civilian causalities, but there are conflicting reports on how many were killed.

For more on the instability in Afghanistan, we turn to Washington Post reporter Pamela Constable.  She recently returned from the country.  And Omar Samad, a former Afghan Foreign Ministry spokesman who also served as the country's ambassador to France and to Canada.

Wednesday, January 15, 2014

CYBERCRIME - Can Shoppers Protect Their Personal Information?

My answer, you cannot completely secure your information when using ANY form of online commerce, which includes the card scanners at stores.  "If you build a 10ft firewall, hackers will build a 12ft ladder."

All you can do is closely monitor ALL your statements (bank and credit) and use at least on well known credit protection service.  One example is LifeLock.  These services are worth every penny.

The government does need to make it easier, AND faster, for consumers to clear their credit and identity from Identity-Theft.

"How can shoppers keep their information secure amid retail hacks?" PBS Newshour 1/14/2014

Excerpt

GWEN IFILL (Newshour):  New revelations have come to light in the past several days about the massive hacking attack of consumers' information affecting customers of some major retail stores.  They're raising more concerns over how many people may be at risk and what individuals need to know to protect themselves.

The holiday shopping season is over, but the data breach that hit retail giant Target is still growing.  The company now acknowledges that information on up to 110 million accounts was compromised.  Initial estimates were 40 million.

Today, two U.S. senators demanded answers from Target's CEO.  Commerce Committee Chairman John Rockefeller and fellow Democrat Claire McCaskill said in a letter:  "We expect that your security experts have had time to fully examine the cause and impact of the breach and will be able to provide the committee with detailed information."

The breach has scared some shoppers away from pulling out their credit cards.

WOMAN:  I would rather just use -- try and use cash here until they straighten everything out.  So, it seems a little scary.

GWEN IFILL:  While others say they're just going about their business.

MAN:  Yes, I use a credit card, but it wouldn't deter me, because, really, Target is like all the big businesses, you know?  Cyber-theft is cyber-theft.

Monday, November 04, 2013

AIRPORT SECURITY - How Secure, Can We Do Better?

"How secure can we make our airports?" PBS Newshour 11/2/2013

Excerpt

HARI SREENIVASAN (Newshour):  And now back to that attack at LAX yesterday.  For more about its possible repercussions, we’re joined from Washington by Rafi Ron, he’s a security expert and the former director of security at Ben Gurion International Airport in Tel Aviv.

So Mr. Ron, I think the first thing most people are asking this morning is, “What did we miss?  How could we have stopped this?”

RAFI RON:  Well, I think that, uh, for the last 12 years, uh, we have focused tremendously on the security of the aircraft, or the flight.  And we paid relatively little attention to the security of the airport facility.  Um, we, uh, obviously, uh, seem to have forgotten about some of the experience that the European airports have suffered way back at the peak of attacks against aviation in Europe – way back in the 70s and 80s – where most of the major airports in Europe, including Paris, Munich, Zurich, and others were attacked on the ground, leaving many casualties behind.

HARI SREENIVASAN:  But one of the things people are considering is arming the TSA.  Good idea?  Bad idea?

RAFI RON:  No, I think it’s a bad idea actually because we need to keep in mind – we’re looking at about over 50,000 screeners that were not selected on the basis of their ability to carry a weapon.

Friday, September 06, 2013

HUMOR - Dilbert on Internet Security

Dilbert
9/6/2013

TECHNOLOGY - Easy Hack Smart Devices?

One of the wost ideas is a phone-app that allows you to unlock your door at home.  Ya, great idea, give the opportunity for a hacker access the app and unlock your door, or if you loose your phone.  Boy, high-tech robbers are going to love this one.  Then the car manufacturers who offer phone-app to control and unlock your car, while you can loose your keys or phone, you cannot hack the electronic key.

"Smart Devices That Make Life Easier May Also Be Easy To Hack, Says FTC" PBS Newshour 9/5/2013

Excerpt

JEFFREY BROWN (Newshour):  New technology presents new concerns over privacy in unexpected places.

An ever-expanding array of appliances and household devices has made our lives easier and sometimes safer.  Now connected to the Web, they're becoming known as the Internet of things, baby monitors with cameras, home thermostats, even refrigerators.  These so-called smart devices are programmable and easy to access remotely, both by their owners and, as it turns out, by hackers.

Yesterday, the Federal Trade Commission cited one seller of Web-enabled video cams for its inadequate security protections.  It found that a breach in the company's software allowed hackers to post links to the live video feeds of its customers' security cameras.

Hari Sreenivasan takes the story from there.

HARI SREENIVASAN (Newshour):  Kashmir Hill is a senior editor and writes the technology and privacy column "Not-So Private Parts" at Forbes.com.
----
HARI SREENIVASAN:  Now, you said in one of your articles that there's even a search engine to help people find this.

KASHMIR HILL, Forbes.com:  There is a search engine.

It's called Shodan.  It's like Google.  But where Google crawls for websites, this actually crawls the Internet looking for connected devices.  And it's found all kinds of things.  It's found cars that are connected to the Internet, the cameras that we have heard about, building control systems for Google's headquarters in Australia and power plants and water filtration companies.

There are so many products now that are connected to the Internet, because it's so useful to be able to check on them or control things from afar.  But a lot of times, these products are being designed without good security, so that somebody can, one, see that they're there, and in some cases even go in and control those devices or access their streams.

Monday, February 25, 2013

CYBERCRIME - Social Networking Hacking

"Twitter Hackings Put Focus on Security for Brands" by TANZINA VEGA and NICOLE PERLROTH, New York Times 2/24/2013

Excerpt

While most Americans were winding up their holiday weekends last Monday, the phones at the Vancouver headquarters of HootSuite, a social media management company, began to ring.

Burger King’s Twitter account had just been hacked.  The company’s logo had been replaced by a McDonald’s logo, and rogue announcements began to appear.  One was that Burger King had been sold to a competitor; other posts were unprintable.

“Every time this happens, our sales phone lines light up,” said Ryan Holmes, the chief executive of HootSuite, which provides management and security tools for Twitter accounts, including the ability to prevent someone from gaining access to an account.  “For big brands, this is a huge liability,” he said, referring to the potential for being hacked.

What happened to Burger King — and, a day later, to Jeep — is every brand manager’s nightmare.  While many social media platforms began as a way for ordinary users to share vacation photos and status updates, they have now evolved into major advertising vehicles for brands, which can set up accounts free but have to pay for more sophisticated advertising products.

Burger King and Jeep, owned by Chrysler, are not alone.  Other prominent accounts have fallen victim to hacking, including those for NBC News, USA Today, Donald J. Trump, the Westboro Baptist Church and even the “hacktivist” group Anonymous.

Those episodes raised questions about the security of social media passwords and the ease of gaining access to brand-name accounts.  Logging on to Twitter is the same process for a company as for a consumer, requiring just a user name and one password.

Twitter, like Facebook, has steadily introduced a number of paid advertising options, raising the stakes for advertisers.  Brands that pay to advertise on Twitter are assigned a sales representative to help them manage their accounts, but they are not given any more layers of security than those for a typical user.

Ian Schafer, the founder and chief executive of Deep Focus, a digital advertising company that also fielded a few phone calls from clients concerned about the Burger King attack, argued that Twitter bore some responsibility.

“I think Twitter needs to step up its game in providing better security,” Mr. Schafer said.  In a memo to his staff about such attacks, he called on social networks like Facebook, Twitter, Pinterest “and anyone else serious about having brands on their platform” to “invest time in better understanding how brands operate day to day.”

“It’s also time for these platforms to use their influence to shape security standards on the Web,” he wrote.

The risk for Twitter is in offending potential business partners as the company tries to build its advertising dollars, which make up the bulk of its revenue.  In 2012, the company grew more than 100 percent, earning $288.3 million in global advertising revenue, according to eMarketer.

On Wednesday, it introduced a product that would allow advertisers to create and manage ads through third parties like HootSuite, Adobe and Salesforce.com.  Advertising is estimated to account for more than 90 percent of the company’s revenue.

“This is not something we take lightly,” said Jim Prosser, a Twitter spokesman, in an interview last month.  (The company declined to comment on the Burger King hacking, saying it did not discuss specific accounts.)  Mr. Prosser said Twitter had manual and automatic controls in place to identify malicious content and fake accounts, but acknowledged that the practice was more art than science.

Mr. Prosser said Twitter had taken an active role in combating the biggest sources of malicious content.

Last year, the company sued those responsible for five of the most-used spamming tools on the site.  “With this suit, we’re going straight to the source,” it said in a statement.  “We hope the suit acts as a deterrent to other spammers, demonstrating the strength of our commitment to keep them off Twitter.”

But security experts say, and the recent hacks of Burger King, Jeep and other brands have demonstrated, that Twitter could do more.

“Twitter and other social media accounts are like catnip for script kiddies, hacktivists and serious cybercriminals alike,” said Mark Risher, chief executive at Impermium, a Silicon Valley start-up that aims to clean up social networks.  “Because of their deliberately easy access and liberal content policies, accounts on these networks prove irresistibly tempting.”

Monday, October 15, 2012

SECURITY - The Issue of Private Security Firms for U.S. Diplomatic Sites

"After Benghazi Attack, Private Security Hovers as an Issue" by JAMES RISEN, New York Times 10/12/2012

Excerpt

Lost amid the election-year wrangling over the militants’ attack on the United States Mission in Benghazi, Libya, is a complex back story involving growing regional resentment against heavily armed American private security contractors, increased demands on State Department resources and mounting frustration among diplomats over ever-tighter protections that they say make it more difficult to do their jobs.

The Benghazi attacks, in which the United States ambassador and three other Americans were killed, come at the end of a 10-year period in which the State Department — sending its employees into a lengthening list of war zones and volatile regions — has regularly ratcheted up security for its diplomats. The aggressive measures used by private contractors eventually led to shootings in Afghanistan and Iraq that provoked protests, including an episode involving guards from an American security company, Blackwater, that left at least 17 Iraqis dead in Baghdad’s Nisour Square.

The ghosts of that shooting clearly hung over Benghazi. Earlier this year, the new Libyan government had expressly barred Blackwater-style armed contractors from flooding into the country. “The Libyans were not keen to have boots on the ground,” one senior State Department official said.

That forced the State Department to rely largely on its own diplomatic security arm, which officials have said lacks the resources to provide adequate protection in war zones.

On Capitol Hill this week, Democrats and Republicans sparred at a House Oversight and Government Reform Committee hearing over what happened in Benghazi, whether security at the mission was adequate, and what — if anything — could have been done to prevent the tragedy.

But amid calls for more protection for diplomats overseas, some current and former State Department officials cautioned about the risks of going too far. “The answer cannot be to operate from a bunker,” Eric A. Nordstrom, who until earlier this year served as the chief security officer at the United States Embassy in Tripoli, Libya, told the committee.

Barbara K. Bodine, who served as ambassador to Yemen when the destroyer Cole was bombed in 2000, said: “What we need is a policy of risk management, but what we have now is a policy of risk avoidance. Nobody wants to take responsibility in case something happens, so nobody is willing to have a debate over what is reasonable security and what is excessive.”

For the State Department, the security situation in Libya came down in part to the question of whether it was a war zone or just another African outpost.

Even though the country was still volatile in the wake of the bloody rebellion that ousted Col. Muammar el-Qaddafi, the State Department did not include Libya on a list of dangerous postings that are high priority for extra security resources.

Only the American Embassies in Iraq, Afghanistan and Pakistan are exempted from awarding security contracts to the lowest bidder. Dangerous posts are allowed to consider “best value” contracting instead, according to a State Department inspector general’s report in February.

Ah, yes. 'Have Gun, Will Travel' for cheap = good security... NOT!

Tuesday, June 26, 2012

MEXICO - Mexican Election Issue, War on Cartels

"Mexicans Focus on Security as Top Election Issue" PBS Newshour 6/25/2012

Excerpt

SUMMARY: In a time of relatively stable economic growth, the top concern for Mexican voters is the national war on cartels and widespread drug violence. Margaret Warner previews the upcoming Mexican election and the various party factions competing for control, including the campaign frontrunner who out-"dazzles" the other candidates.

JUDY WOODRUFF (Newshour): Finally tonight, we begin a weeklong series of reports from Mexico by Margaret Warner.

Her first focus is on its upcoming presidential election.


Friday, March 02, 2012

NASA - And The Cyberwar

"Report: Hackers Seized Control Of NASA Computers" by Dan Merica (CNN), WCVB Boston 3/2/2012

NASA Says It Was Subject To 47 Hacking Incidents In Fiscal Year 2011

Hackers with IP addresses originating from China took control of computers in NASA's Jet Propulsion Laboratory last November, according to a report from the space agency's inspector general.

The attack led to intruders gaining access to 150 NASA employee credentials. Additionally, the report stated that the ongoing investigation into the incident found that the hackers gained the ability to "modify, copy or delete sensitive files" and "upload hacking tools to steal user credentials and compromise other NASA systems.

"In other words," writes Inspector General Paul K. Martin, "the attackers had full functional control over these networks."

Though highlighted, this attack was far from the only violation of NASA networks and computers.

In fiscal year 2011, NASA reported it was subject to 47 hacking incidents -- 13 of which successfully compromised the agencies computers. In total, 5,408 computer security incidents "that resulted in the installation of malicious software on or unauthorized access to its systems" were reported by NASA in 2010 and 2011.

"These incidents spanned a wide continuum from individuals testing their skill to break into NASA systems, to well-organized criminal enterprises hacking for profit, to intrusions that may have been sponsored by foreign intelligence services seeking to further their countries' objectives," writes Martin.

NASA has conducted 16 investigations over the last 5 years, investigations that led to the arrests of foreign nationals from China, Great Britain, Italy, Nigeria, Portugal, Romania, Turkey and Estonia.

These intrusions, the report continues, "have affected thousands of NASA computers, caused significant disruption to mission operations, and resulted in the theft of export-controlled and otherwise sensitive data, with an estimated cost to NASA of more than $7 million."

Loss and theft has also been an issue for NASA. Forty-eight agency mobile computing devices were reported lost or stolen between April 2009 and April 2011. This led to the possibility that sensitive algorithms and data landed in unauthorized hands.

"For example, the March 2011 theft of an unencrypted NASA notebook computer resulted in the loss of the algorithms used to command and control the International Space Station," Martin writes.

Martin testified in front of Congress on Wednesday and the report served as a precursor to his testimony. While in front of a House committee, Martin spoke about the slow pace of encryption for the agencies' mobile devices and the lack of technological security monitoring at NASA.


"Stolen NASA laptop contained space station control codes" by Matt Liebowitz (SecurityNewsDaily), Mother Nature Network 3/1/2012

A laptop stolen from NASA last year was unencrypted and contained command and control codes for the International Space Station (ISS) on it, the agency's inspector general told a United States House subcommittee on Feb. 29.

In his testimony before a Science, Space and Technology House subcommittee, NASA Inspector General Paul K. Martin said the notebook computer stolen in March 2011 "resulted in the loss of the algorithms" used to control the ISS. This particular laptop, Martin said, was one of 48 NASA notebooks or mobile devices stolen between April 2009 and April 2011.

Some of these thefts resulted in the leak of sensitive data "including export-controlled, Personally Identifiable Information, and third-party intellectual property," as well as Social Security numbers and data on NASA's Constellation and Orion programs, Martin said.

he actual number of stolen and compromised devices could be much higher because NASA relies on employees to self-report incidents.

In an email, NASA public affairs officer Trent Perrotto told SecurityNewsDaily that "at no point in time have operations of the International Space Station been in jeopardy due to a data breach."

"NASA has made significant progress to better protect the agency's IT systems and is in the process of implementing the recommendations made by the NASA Inspector General in this area," Perrotto added.

In 2011, NASA, which Martin rightly called a "target-rich environment for cyberattacks," was the target of 47 advanced persistent threats (APTs), 13 of which successfully compromised NASA computers.

These attacks are part of the 5,408 cybersecurity incidents in 2010 and 2011 that resulted in unauthorized intrusions or malware being planted on its systems and cost the space agency an estimated $7 million.

"These incidents spanned a wide continuum from individuals testing their skill to break into NASA systems, to well-organized criminal enterprises hacking for profit, to intrusions that may have been sponsored by foreign intelligence services seeking to further their countries' objectives," Martin said.

An example of one of these "skill-testing" hacks is the attack perpetrated by "TinKode," a 20-year-old Romanian hacker (real name Razvan Manole Cernainu), who tapped into a computer server at NASA's Goddard Space Flight Center in April 2011.

Martin continued, "Some of these intrusions have affected thousands of NASA computers, caused significant disruptions to mission operations, and resulted in the theft of export-controlled and otherwise sensitive data."

Martin's testimony highlights the difficulties NASA information technology officials face in securing the agency's laptops and mobile devices. As of Feb. 1, 2012, only 1 percent of NASA portable devices and laptops have been encrypted.

"Until NASA fully implements an agency-wide data encryption solution, sensitive data on its mobile computing and portable data storage devices will remain at high risk for loss or theft," he said.

Martin said software vulnerabilities in NASA computers are often left unpatched, a problem stemming from an IT chain of command in which the chief information officer "has limited ability" to fully implement mandated IT security programs across the agency.

Thursday, April 28, 2011

SECURITY - Cybercrime With World-Wide Impact

This is about more than PlayStation users. The information gleaned by this crime is a threat to any personal information on your personal computers (directly for PlayStation users, indirectly for others) or by way of any online business you deal with.


"Sony PlayStation System Hacking Incident Highlights Web-Security Gaps" PBS Newshour Transcript 4/27/2011 (includes video)

Excerpt

RAY SUAREZ (Newshour): The latest episode involved millions of people around the world who use Sony's PlayStation video game system and who may have had their credit card information stolen in a hacking incident.

The intrusion caused the company to shut down PlayStation's Internet network a week ago. It provides access to online gaming, music, movies, sports and TV shows. Seventy-seven million user accounts were disconnected worldwide. But it wasn't until yesterday that Sony disclosed a hacker obtained information, including players' names, addresses, birth dates, email addresses, passwords and log-in names.

And on the company's blog, Sony spokesman Patrick Seybold said, "While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility."

Near Sony headquarters in Tokyo, some said the breach may stop them from using PlayStation.

KAZUNORI SANO, resident of Tokyo (through translator): I will be afraid of playing with the game machine after hearing of this. I don't want my credit card information to be leaked out somewhere else in the world.

RAY SUAREZ: And in Australia, police urged PlayStation users to be vigilant.

DETECTIVE SUPERINTENDENT COL DYSON, New South Wales State Police Force: It would appear that the risk in relation to credit cards may be low. But if people have concerns, they should be talking to their banks and watching for unauthorized usage of the cards.

RAY SUAREZ: Some industry experts say the scale of the breach could cost the company billions of dollars.

THOMAS PUHA, "Pelaaja": This is going to have a very negative impact on a business that they have built up, because I think a lot of -- obviously, a lot of consumers will really be very wary of putting their credit card information back online or even buying anything.

RAY SUAREZ: Sony said it expects the PlayStation Network to be restored in a week. In the meantime, an outside security firm has been hired to investigate what Sony deems the malicious intrusion.

For a closer look at all this, we turn to Kevin Poulsen, senior editor at Wired.com. A former hacker himself, he's also author of a new book, "Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground."

And, Kevin, for those people who aren't gamers, why would you have to load personal information into a game console in the first place?

KEVIN POULSEN, Wired.com: Well, a lot of gaming takes place now online. You have multiplayer games where you could play with or against opponents live in real time.

And, of course, a game console isn't just a game console anymore. You want to be able to download movies and other content. And all -- you pay for all of that, which means you have to give up this information.

RAY SUAREZ: Sony says it has no direct evidence that credit card numbers were taken, but it says -- quote -- "We cannot rule out the possibility."

When you have had a breach, when someone has been rifling around in your files electronically, can you tell what they have seen and what they haven't?

KEVIN POULSEN: There are usually -- there's usually some kind of trail left, yes. But if the hacker is good and took steps to cover his or her tracks, then it could -- it could take a while to extract that.

I imagine that's why Sony took so long to announce this. They were probably hoping to find better news. They were probably hoping to find evidence that the -- that information wasn't accessed. Now that they have brought in an outside company, I expect they will know a lot more than they do now, eventually. Of course, they -- they may know more than they're telling us now.

RAY SUAREZ: The PlayStation system has been down for over week, disappointing a lot of people who are frequent users.

Does that long-term shutdown tell you something about the seriousness of the breach, that they're not patching it, but rebuilding the whole network?

KEVIN POULSEN: Absolutely.

It's a really radical measure to take. And it's surely going to cost them a lot of money and a lot of fan loyalty. There are people that aren't even going care about the breach itself who are just going to be extremely angry that they were denied access to the PlayStation Network for so long. So, it's bad news all around.

If this had just been a casual intruder, a recreational intruder, some kid working from his bedroom, I doubt they would have taken this measure. So, they probably have some indication that this was a serious, focused attack.

RAY SUAREZ: Well, as we reported earlier, they got user names, passwords, various other kinds of personal information. What's the risk to account holders at this point?

KEVIN POULSEN: You know, the biggest risk is probably with the personal information, especially the passwords, because a lot of people use the same passwords everywhere.

So, that, coupled with your email address and your real name and your date of birth, the hackers will, if this was done for profit, then, all of that could wind up being sold on the black market, probably for a nice sum of money.

And then, whoever buys it, other computer intruders could use the information to try and hack into other accounts held by these PlayStation Network users. It could be anything from Facebook to online banking. You could use it to stage scams targeting the users in other ways.

So, it could be -- it could wind up that this becomes the first stage in a lingering problem that haunts users for a long time, if, in fact, that that was the nature of the breach.

Stress this quote, "You know, the biggest risk is probably with the personal information, especially the passwords, because a lot of people use the same passwords everywhere."

HINT, do not use the same password for all your online accounts.

Thursday, February 24, 2011

CYBERWARS - It's Not Just Your PC Anymore

"Security to Ward Off Crime on Phones" by RIVA RICHMOND, New York Times 2/23/2011

Excerpt

More consumers are buying smartphones. So more criminals are taking aim at those devices.

Criminals still prefer PCs for stealing personal data, bank and credit card account numbers as well as for running frauds. However, most PC attacks focus on Microsoft’s decade-old Windows XP operating system, which is slowly being replaced by the more secure Windows 7. Over the next few years, hackers will have to find new targets.

With smartphones outselling PCs for the first time — 421 million of the hand-held computers are expected to be sold worldwide this year, according to market analysts at IDC — the long-predicted crime wave on hand-held devices appears to have arrived. According to the mobile-security firm Lookout, malware and spyware appeared on 9 out of 100 phones it scanned in May, more than twice the 4-in-100 rate in December 2009.

In fact, the most practical rule for protecting yourself is to start thinking of the smartphone as a PC.

Most malicious incidents on mobile devices involve bogus phone or text-message charges or rogue mobile applications, of which there are now more than 500 varieties, according to F-Secure, a Finnish security firm. All these ruses require users to take some kind of action, like clicking to accept or install a program, so caution while using mobile devices can prevent most problems. (However, experts warn that automated attacks are possible and could emerge in the future.)

Most attacks happen in Eastern Europe and China. An overwhelming number — 88 percent, according to F-Secure — have singled out devices running Nokia’s Symbian operating system. Symbian is the world’s most commonly used smartphone platform, but Nokia said this month that it would be replacing it over the next few years with Microsoft’s Windows Phone operating system.

Early attacks, like the Cabir and Commwarrior worms in 2004 and 2005, caused little damage. But since 2009, attacks have grown more menacing. In September, hackers trying to steal money from accounts at a Spanish bank installed malicious applications on Symbian devices when they synced to home PCs infected with a version of the ZeuS malware. The application enabled criminals to reply to security codes sent by the bank to validate cash transfers.

Such assaults could be a preview of what is to come for devices popular in the United States. Criminals have attacked phones running on Google’s Android, Research In Motion’s BlackBerry, Apple’s iPhone and Microsoft’s Windows Mobile operating system software, suggesting that more is ahead.

Tuesday, January 25, 2011

WORLD - New START Treaty; Signed, Sealed, and Delivered

"Russia OKs Landmark Nuclear Arms Pact with U.S." AP, CBS News 1/25/2011

Russia's lower house of parliament on Tuesday ratified a landmark nuclear arms pact with the United States that was earlier been approved by the U.S. Senate.

The State Duma voted 350-96 with one abstention to pass a ratification bill of the New START treaty. The treaty will now go to the upper house for final approval.

The New START would limit each country to 1,550 strategic warheads, down from the current ceiling of 2,200 and also re-establish a system for monitoring that ended with the expiration of a previous arms control pact.

The treaty's passage has never been in doubt in the Kremlin-controlled parliament, but Russian lawmakers wanted to counter a U.S. Senate resolution that accompanied its December's ratification with a similar motion.

Just like the U.S. Senate resolution that raised some Republican concerns about the pact without directly affecting it, the Russian ratification bill wouldn't interfere with the deal.

While the Senate resolution said the treaty shouldn't restrict U.S. plans to develop a missile defense system, the Duma ratification bill stated that the treaty can only be fulfilled if emerging missile defenses don't erode the Russian nuclear deterrent.

The Russian draft bill also mimicked the Senate resolution that mentioned increased funding for the U.S. nuclear arsenal by emphasizing the need to modernize Russia's nuclear forces.

Neither the Senate, nor the Duma resolution would affect the text of the treaty, which is a centerpiece of President Barack Obama's efforts to "reset" ties with Russia.

Wednesday, November 17, 2010

SECURITY - Our Security vs Privacy

"TSA Chief: Disagreement Over Security, Privacy Balance Understandable" Report PBS Newshour, 11/16/2010

Excerpts

MARGARET WARNER (Newshour): The issue was brought to the fore with last month's discovery of timed bombs headed for the U.S. On October 29, British authorities intercepted a shipment from Yemen on a UPS cargo plane bound for Chicago. They found a printer with a toner cartridge that had been rigged with a detonator and a powdered explosive.

A similar device was found aboard a Qatar Airways cargo plane in Dubai that also came from Yemen. At the same time, a furor has erupted over airport security screening for passengers. Two new security measures are at issue, first, the use of full-body scanners, which reveal images of the naked body. They're now in 60 U.S. airports, with more to come.

Some people have balked at submitting to the scan, for reasons ranging from invasion of privacy to fears of radiation. Homeland Security Secretary Janet Napolitano insists the scanners are safe and the images are viewed in private, without identifying the passengers.

Those who refuse the scans are subject to new intensive full-body pat-downs. And those, too, have raised hackles.
----
MARGARET WARNER: Did you here at TSA underestimate the estimate of blowback, of anger from passengers over these more intrusive screening procedures?

JOHN PISTOLE, administrator, Transportation Security Administration: We are a risk-based, intelligence-driven organization. And knowing that, any time we make changes in the protocols that we use to screen passengers, in dealing with the latest intelligence, that we have to do a good job of informing the public as to what we're doing, without providing a road map to the terrorists.

So, that's the tension that we deal with. How much do we inform ahead of time, here's what we're going to be doing, as a counterbalance to the security that we need to ensure that everybody who gets on every flight has been properly screened?

I think there -- reasonable people can disagree as to the balance between the privacy that some people have raised as issues. And I'm sympathetic to those concerns. But the job is really security in terms of, how can we provide the best security?

MARGARET WARNER: Now, Secretary Napolitano said yesterday, well, if people don't want to fly, they have other means of travel.

But that isn't really practical, is it, for a businessperson?

JOHN PISTOLE: You know, if you have two flights, and you have the option of going on the two, and you know, the one, people have been thoroughly screened, and, the other plane, people have opted out and not had a thorough screening, and so you don't have that confidence, I think virtually everybody is going to go with the flight that has thorough screening.

MARGARET WARNER: A lot of passengers are wondering whether these procedures are proportionate to the threat. And I'm just wondering, would, for instance, these more extensive pat-downs and the full-body scans, would they have caught the Christmas Day bomber with the explosives in his underwear?

JOHN PISTOLE: So, I know the threats are real. And I believe that the techniques and the technology we're using today are the best possible that we have. And it gives us the best opportunity for detecting a Christmas Day-type bomber.
----
MARGARET WARNER: What about the level of radiation? The pilots and flight attendants are objecting, saying it's going to expose them to a higher level than is safe. Have you done any kind of testing? Do you know how much radiation an individual is exposed to and how that measures up to what is allowable, what's safe?

JOHN PISTOLE: There have been a number of studies done, Margaret, that deal with this, whether by the National Institute of Standards and Technology, NIST, or the FDA, or Johns Hopkins, which have independently assessed this, because, obviously, that's something we're concerned about. What is that exposure?

They have all come back to say that they're -- the exposure is very, very minimal. It's equivalent to -- I have heard several analogies -- a couple minutes of flight, like, at 30,000 feet, the same amount of exposure you would get there. So, it's well, well within all the safety standards that have been set.

This is the world we live in today, thanks to fanatics around the world (including USA).

This issue no longer applies to me, since I don't travel long distances any more. During my Navy carrier I flew many times (including landing on Aircraft Carriers), so flying is not the problem. My problem IS having to restrict what I can carry with me on an airplane.

Monday, October 18, 2010

SECURITY - Our National Security With Blinders

The following emphasizes the problem with our National Security Agencies and methods. It's a very human one, a matter of judgement of individual people in these agencies.

We really need to re-educate ALL the people in our National Security community that our nation's security come BEFORE political considerations, AND this includes inter-agency problems. It should NOT have mattered that Mr. Headley was an informant for the D.E.A.

"U.S. Had Warnings on Plotter of Mumbai Attack" by JANE PERLEZ, ERIC SCHMITT and GINGER THOMPSON, New York Times 10/16/2010

Excerpt

Less than a year before terrorists killed at least 163 people in Mumbai, India, a young Moroccan woman went to American authorities in Pakistan to warn them that she believed her husband, David C. Headley, was plotting an attack.

It was not the first time American law enforcement authorities were warned about Mr. Headley, a longtime informer in Pakistan for the United States Drug Enforcement Administration whose roots in Pakistan and the United States allowed him to move easily in both worlds.

Two years earlier, in 2005, an American woman who was also married to the 50-year-old Mr. Headley told federal investigators in New York that she believed he was a member of the militant group Lashkar-e-Taiba created and sponsored by Pakistan’s powerful intelligence agency.

Despite those warnings by two of his three wives, Mr. Headley roamed far and wide on Lashkar’s behalf between 2002 and 2009, receiving training in small-caliber weapons and countersurveillance, scouting targets for attacks, and building a network of connections that extended from Chicago to Pakistan’s lawless northwestern frontier.

Then in 2008, it was his handiwork as chief reconnaissance scout that set the stage for Lashkar’s strike against Mumbai, an assault intended to provoke a conflict between nuclear-armed adversaries, Pakistan and India.

An examination of Mr. Headley’s movements in the years before the bombing, based on interviews in Washington, Pakistan, India and Morocco, shows that he had overlapping, even baffling, contacts among seemingly disparate groups — Pakistani intelligence, terrorists, and American drug investigators.

Those ties are rekindling concerns that the Mumbai bombings represent another communications breakdown in the fight against terrorism, and are raising the question of whether United States officials were reluctant to dig deeper into Mr. Headley’s movements because he had been an informant for the D.E.A.

More significantly, they may indicate American wariness to pursue evidence that some officials in Pakistan, its major ally in the war against Al Qaeda, were involved in planning an attack that killed six Americans.

Monday, June 26, 2006

POLITICS - FTC Is Fighting Identity Theft... Well Maybe

"Government Hit by Rash of Data Breaches" by HOPE YEN, Associated Press Writer

The government agency charged with fighting identity theft said Thursday it had lost two government laptops containing sensitive personal data, the latest in a series of breaches encompassing millions of people.

The Federal Trade Commission said it would provide free credit monitoring for 110 people targeted for investigation whose names, addresses, Social Security numbers - and in some instances, financial account numbers - were taken from an FTC attorney's locked car.


Duh! When are agencies going to realize that our personal data should not be taken out of agency's offices? The data should not be on any portable computer (laptops, notebooks, etc.). How many times do they, and private companies, have to be hit over the head with a 2-by-4 before they get it?!

Private personal data belongs only on highly secure servers that can be accessed only from equally secure desktop workstations at the office, period. This data should never be allowed to be copied to the workstation nor portable computer.

Inconvenience is not a reason to put your personal data at risk!

Monday, May 08, 2006

INTERNET - Government + Corporate Assault the Open NET

There is a behind-the-scenes assault on what we know as the Internet (NET) today.

"The Great American Firewall: Why the Net is poised to become a global weapon of mass deception" by Elliot D. Chhen, PH.D., SmirkingChimp

Hindsight is often touted as better than foresight, yet such a truism should not blind us to an imminent threat before it happens. Like someone who takes up with an abusive mate and rationalizes the threat to life and limb until the battering leaves undeniable, indelible scars, there are good reasons right now to expect the worst when it comes to the survival of the free Internet. Now unfolding is a legal-political-corporate plot for turning a vibrant, democratic Internet into a global web of corporate and government deceit. The tell-tale signs exist but as in domestic abuse, the perpetrators (federal government and a small group of interconnected, powerful telecom and mainstream media monopolies) have done their utmost to keep it hidden behind closed doors.

Under the veil of a virtual mainstream media blackout, on June 27, 2005, the United States Supreme Court granted giant cable companies like Comcast and Verizon the legal right to dominate and control the Internet. It ruled that broadband Internet was an information service like cable TV rather than an interactive telecommunication service like the telephone (National Cable & Telecommunications Association vs. Brand X Internet Services). This gave these behemoths the green light to exclude Independent Service Providers (ISPs) from using their pipes, thereby laying the foundation for a corporate dominated and controlled Internet. Succinctly, in controlling the conduit of communication across the Internet, these companies now had acquired the legal right to control the content (Web of Deceit: How Internet Freedom Got the Federal Ax, And Why Corporate News Censored the Story). Moreover, in writing this decision, the Court also left the door open for telephone companies like ATT to control telephone modem connectivity to the Internet. As a result, just three weeks after the decision was handed down, the Federal Communications Commission (FCC) seized the opportunity to grant this right, effectively ushering in the beginning of the end of free-access Internet.

The Supreme Court ultimately rested its decision on its own Chevron ruling which held that courts should defer to government agencies, such as the FCC on matters of statutory interpretation so long as the statute in question was ambiguous and the agency’s interpretation was reasonable. Despite the fact that there was unambiguous, prior precedent for considering the Internet to be a telecommunication service rather than an information service (AT&T Corporation vs. Portland); and despite the fact that treating an interactive service such as the Internet like a one-way, cable TV station defied rationality, it still deferred to the FCC, which sought to interpret the Internet as an information service.

Brand X has now set the legal stage for a further maneuver in the dismal saga of the declining free Internet. Now in Congress, under extreme pressure by telecom lobbies, is a pending house bill introduced by Congressman Joe Barton (R-TX) entitled the “Communications Opportunity Promotion and Enhancement Act of 2006.” This Act includes a “Title II- Enforcement of Broadband Policy Statement” that states the FCC “shall have exclusive authority to adjudicate any complaint alleging a violation of the broadband policy statement or the principles incorporated therein.” With the passage of this provision the FCC would no longer have to rely on Chevron to attain deference. Instead, it would be given a blank check to enforce its own mandates. This would mean that courts would have scant authority to challenge and overturn its decisions.

Unfortunately, the FCC harbors a political bias that makes granting it this authority dangerous. Under the direction of former FCC Chair Michael Powell, and now under its current chair, Kevin Martin, the FCC has moved toward increased deregulation of telecom and media companies, and there is now little reason to expect that this trend will reverse. The consequence is the thickening of the plot to increase corporate control of the Internet.


This is why there have been proposals by phone companies who want to charge by the minute for NET access. When it comes to cable used to connect the WWW (WEB-Server to WEB-Server), the legal definintion "information service" is giving corporate interests unchecked control and raises the specter of corporate and government censorship that the legal definition of "telecommunication service" does not have.

The Internet is the last bastion of totally free (like in freedom) and open access to information that is not in controll by governments or corporations. To not provide the same legal protections as telephone vioice commnuications has, is a threat to free speach and the exchange of information that good citizens need to monitor what their government is doing. There is not one government, including the USA, that has not tried to keep the bad news from the people (at worst) or manipulate information to present only its views (suppressing any other views).

Monday, January 23, 2006

POLITICS - Personal Information Security

There was an interesting piece on PBS's The News Hour the other day, GOOGLE'S PRIVACY FIGHT

In included a discussion about personal information security in today's environment, specifically the internet.

There are to categories of basic non-technical personal security issues.



  1. The federal government needs to pass a law that makes absolutely clear that the individual person is the OWNER of his/her information, and NOT the private agency collecting it. The owner then controls what is included in that information and how it gets distributed. There are laws that address portions of this topic but such laws are not comprehensive nor clear. Example, companies have long treated your personal information they collect as their's, so they could sell it to interested parties, this is why we now have a law (full of loopholes) addressing this issue. The law does not specifically state who the OWNER of the information is.


  2. Internet personal information security is another matter. Note that I do not use my real name in on-line forms, also my real name is NOT part of my email address. These are examples of basic personal information security. You should never put your real name "in the clear" on the internet whenever it is not required (online credit card info is one valid exception). Companies violate this basic security issue when they use an employee's real name in the company email address scheme. These basic personal security issues were taught when the Internet first came into existence, but it is NOT being emphasized today, and it should.


A few additional internet personal information reminders:



  • Credit card companies never ask for any part of your card number in emails. Latest example, the bogus "Security Alert Your Credit Card Possibly Illegally Accessed" that asks to verify your credit card's security digits by replying with the digits. This one even reminded you if you had any questions to call Customer Service. Luckily the person who reported this did call and that's when they found out it was a fraud but noted that this meant the the sender already had the basic credit card number. The card had to be cancelled and a new one issued.


  • Emails that include links to access your accounts (rather than saying to access your accounts via. the normal method you use) even if they look correct. Awhile back, PayPal customers were sent a fraudulent link that ended up giving the requested account info to Identity Thieves. Even the online form looked legit.


  • You should think twice, no, three times about entering personal information at a WEB site that is not a secure site. Secure sites have a "https://" prefix.

We do need to bring privacy law up-to-date in general, and we need to address these two topics specifically.