Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Feb 22, 2010

Online Banking made tamper proof?


In recent development banking powerhouse UBS has developed a device made from IBM that is thought to have the ability to secure online banking transactions without the interference of hackers. The device is called Zone Trusted Information Channel (ZTIC) and it is a smart card reader that attaches to a computer through a USB cable.

How this device works is that it when your doing a online transaction instead of going through the web browser it bypasses it and makes a direct secure Socket Layer Connection(SLC) with the bank. And with this access the ZTIC is able to show the banking customer what is really happening even if there was malicious and dangerous software infected on the computer.

When you are connected to the PC via USB, the customer enters the ZTIC card and enters their own PIN code onto the UBS website. When the account information of the beneficiary is entered for payment, the ZTIC will display the target account on the device screen. If the transaction has been hacked and the account numbers don't match the customer can the abort payment This is a good process because hackers steal information by interfering with transactions in real time and modifying the data. With ZTIC it eliminates the middle man attacks and hacks and gives you a direct connection to the source.


UBS primarily bought this device mainly for corporate customers trying to set up new payment beneficiaries in their online banking system. This technology has been around but IBM is the first company to get a major banking corporation to deploy it.

Feb 17, 2010

US Cyber Attack Test

This week the United States performed a test cyber attack against our nations infrastructure in order to become more familiar with vulnerabilities of the current system. While I had assumed that this is something that is done often in order to ensure stability in the systems, it was clear after reading the article that this is not something that is done on a routine basis.

The Article which appeared on CNN.com, clearly illustrates holes in a system that could leave certain services unavailable for hours to weeks depending on the impact to the system. As stated by National Intelligence Director Dennis Blair "successful cyberattack against a major financial service provider could severely impact the national economy, while cyberattacks against physical infrastructure computer systems, such as those that control power grids or oil refineries, have the potential to disrupt services for hours to weeks."

What is so surprising (well not really) about all of this is that in todays day and age when nearly all information or infrastructure is nearly completely relient on a computer system and has been for the last decade, we are only now beginning to run through realistic as opposed to apocalyptic type tests against these systems. Once again it is clear that the Government, while always trying to become more in the loop, has proven that most of the time it is rarely looking at the big picture of protecting this nation. That is too bad, because in my opinion, some of our largest threats are more than likely going to use some sort of attack to these systems long before they will invade our shores.

Dec 13, 2009

Most Hacked Software

Forbes magazine recently posted an article about the year's most hacked software. Believe it or not it was not Microsoft, but Adobe. According to iDefense, 45 bugs were found in Adobe reader software this year opposed to only 14 last year. Most of the more common Microsoft programs dropped in number of bugs found. Experts believe that one of the things that make Adobe a good candidate for hackers is because of the large number of users who have Adobe reader. They also explain that the complex code causes the potential of having a high risk of flaws.



Adobe is aware of these problems with their software being targeting so they have recently decided to require a quarterly patching cycle, an idea taken from Microsoft. Adobe has decided to take a more proactive approach to finding and fixing bugs.

Some of the other companies that made the most hacked software list were Internet Explorer, Firefox, Adobe Flash, Apple Quicktime, Microsoft Office, and Windows. Cybersecurity research frim Qualys was one of the companies that Forbes used to do find out the most vulnerable software and their chief technology officer, Wolfgang Kandek, states that "wormable" quality to Windows bugs means they remain his top priority.

Some people believe that if they are only using trusted software that they will not be vulnerable to many of the bug you read about in the news, but really it is the most common software that we use that causes the hackers to be able to get into our system.

Dec 12, 2009

Antivirus Scamming

I'm sure we have all came across a pop up window that claims that it is scanning your computer for viruses and then claims you have one. I have never trusted these pop up scanners because I never know where there come from and since I have an up to date antivirus running on my computer I always figure its some sort of scan to get people to spend money. Well recently the FBI's Internet Crime Complaint Center issued a warning stating that a majority of these are in fact scams. They state that "At best, the software is subpar. At worst, it could result in viruses, Trojans and/or keyloggers being installed on the user's computer". It is estimated that by the FBI that victims of these scams have lost more than $150 million.

The FBI recommends that you do not click on these pop ups and should in fact close your browser immediately and possibly your computer. You should also run your antivirus to make sure there is nothing on your computer.

Security FAQ's website lists ways to help you identify fake antivirus programs:
  • Fake anti-virus software will often find more suspicious activity on your computer than those programs that are made by legitimate companies.
  • The number of pop-ups you see will increase drastically, even when you are not connected to the internet.
  • After installing the fake anti-virus program you may notice that your computer slows down drastically due to the amount of junk that has been installed onto your system.
  • You may also find that your default homepage has been changed and now points to the scammer’s ‘official-looking’ site.
  • Words on websites are now underlined and now hyperlink to undesirable locations, such as adult sites.

Of course the best possible way to prevent these scams is to never use any of these sort of antivirus programs and use only the one you have installed on your computer.