Tuesday, November 4, 2014

Got ID Fraud? - Stop, Drop and Roll

   OK, maybe not stop, drop and roll (I'll always remember that fire safety phrase from my childhood), but take action!

   Cyber Security Awareness Month is now over, and I haven't finished covering the ID Fraud topic I started at the beginning of Oct.  I did get distracted on some other issues.  Besides, we can't confine our celebrating to only one month!

   I covered the basics of ID Fraud in these posts.  But if you have been a victim, and particularly if you recently discovered you are victim, you need to take action... and time matters.

   Here are the four key things you need to do, right now, if you have recently been the victim of ID Fraud in the US:
  1. Contact one of the three major Credit Bureaus (we'll leave a discussion of the "4th credit bureau" for another time).
  2. Close the suspect accounts.
  3. File a police report.
  4. File a report with the FTC by phone and in writing.
   I'll provide more detail and add a few more steps below.

   One additional thing you must do throughout this process is to keep a record of everything you do.  This includes: noting date/time of phone calls; copies of letters; printout any web forms, and; keep a chronological log of your overall progress.

   The FTC website has the specifics here.

Contact one of the Credit Bureaus and put a fraud alert on your account.
   This is the first thing to do.  You can put what is called an initial fraud alert on your credit record.  This initial alert will last 90 days.  It should not cost anything to place this alert.  The bureau you call should contact the other two credit bureaus, but it doesn't hurt to verify this with them.
   The fraud alert basically requires extra effort to authenticate any requests for new credit.  This typically means that the credit issuer needs to contact you before issuing credit.  This should make it tougher for a fraudster to open credit in your name.  That's good!  The downside is that it also might make it more difficult for you to open new credit.
   After the initial 90 day period, you can renew the alert each 90 days.  This may cost a nominal fee depending upon what state you live in (US).
   (we'll talk about other measures like credit monitoring services in a future post)

Close the affected accounts.
   Contact the credit issuer and close any accounts you know were affected.  If your purse or wallet was stolen, then close all the accounts for the cards you were carrying.
   If you're not sure if a particular account was affected, you're probably best off closing it as well.

File a police report.
   Contact your local police and file a report.  Except in rare cases where there was additional theft (for example, if your identifying documents and credit cards were stolen as part of a home break-in), the police will not actually take any action.  You're not contacting the police so they will investigate the problem.  You are establishing documentation and proof of the event.  In the future, you may need to prove that you took action and when you took action.  The police report accomplishes this.  Get a copy of that report.

File a complaint with the FTC (US Federal Trade Commission).
   Again, this is part of establishing your documentation trail.  The FTC has a great website for information that I'll link below.  The specific instructions for filing the FTC complaint is here.  Note that they suggest filing with the FTC before filing the police report.  That is not critical, and you need to do both.  You can complete the FTC form online so that might be easier and it's available 24x7.

   Those are the first steps to take.  But there are more.  Here are a few more steps to take:

Who else to notify?
   You may want to notify your other banks and creditors both to find out if there has been any unusual activity (banks and card issuers are usually pretty good at finding anomalous activity before you do) and so they can flag your accounts.  Consider notifying anyone who bills you monthly for services including utilities and insurance providers.

   If you think your US social security number has been compromised, you should contact the Social Security Administration.

   You can notify your state driver and vehicle services department in case someone tries to get a driver's license in your name.

Online defense.
   If this problem started online, perhaps through an information breach, you should change your passwords and consider using multi-factor authentication as I've covered in the past.

   There are more complete details on these steps on the FTC website here.

   Even under the best of circumstances, the process of reporting, documenting and repairing ID Fraud is a major pain.  In our next installment I'll talk about things you can do to help prevent you from becoming a victim, or in those circumstances where this is out of your control, how to increase the odds of early detection and minimize the impact.

   Have you had experience with any of the steps I list above?  Do you have any advice on additional steps to take?

Tuesday, October 21, 2014

Dropbox Wasn't Hacked... This Time!

   I'm sure that many of you have read the news about an apparent attack, and subsequent account breach at Dropbox this past week.  There have been conflicting reports flying around, but Dropbox's own blog points out what appears to be the truth... Dropbox wasn't hacked.


   The story is that apparently the attackers got user IDs and passwords from attacks on other applications.  They then tried these same credentials on a number of internet sites, including Dropbox.  You can read the Dropbox blog post here.

  This is a typical attack scenario, as I've discussed before.  Among the value of stealing a password file from a site or organization is that people unfortunately reuse their IDs and passwords on other sites.  This is because it's difficult to remember all those passwords!  I won't go into that issue because I've covered it plenty of times in the past.

   In this case, like many others, the attackers simply try the IDs and passwords on other sites.  It's almost guaranteed that they will get some logins that work.  That is apparently what happened here.

   So... Dropbox wasn't hacked... this time!  Of course, there have been a number of successful breaches of Dropbox in the past!

   More on that in a moment, but I want to make a quick editorial comment on the use of the term "hacked".

Tuesday, October 7, 2014

Celebrate Cyber-Style!

   It's time again to celebrate that wonderful US event... Happy Cyber Security Awareness month!  This event started in 2003 as a way to build awareness for online security and privacy and to encourage individuals, business and government.

   Over the past couple of posts I've focused on Identity Fraud (here and here).  We'll pause on that topic until next time.

   Today I give you...  The Top 10 Ways to Celebrate Cyber Security Month 2014!
  1. Change your password
  2. Yes, I know... I said in the past that just changing your password is not the effective measure.  That's true but with the frequency with which online sites get compromised, it's not a bad idea.  Even better - use really long passwords.  Remember, when it comes to passwords... size matters!

  3. Use a password vault
  4. A password vault is a program that encrypts and holds all your passwords.  I explain these in detail, and list some good products, in this post.

  5. Look before you click
  6. With most links to can "mouse over" the link.  That means you just move your mouse so it's on the link, but don't click yet!  Your browser will display the address to which the link will lead.  This displays at the bottom of the browser.  The actual link in the display should make sense and be the location you're expecting.  If not then... don't click!

Tuesday, September 23, 2014

"Who Am I?" (or, Who Was I?)

   I like the story of Les Mis.  I definitely like the musical.  I was not wild about the movies.  The book is definitely a good, and very long, read (or listen!).

   At it's core, Les Mis is a story about Identity Fraud!  It's the story of a man, seemingly wrongly convicted, who operates under a false identity in order to be able to live his life.  It's a common literary theme, used in stories like Martin Guirre, The Count of Monte Cristo and Matchstick Men.  In "olden times", Identity Fraud penalties were very serious. Today... not as much.  Last time we started a discussion of Identity Fraud - we'll continue our discussion of this topic.


   Breaches of online merchant websites and databases get a lot of media attention.  But there are many ways ID fraud is committed including:
  • Shoulder Surfing - this means someone looking over your shoulder, for example when you enter your PIN at an ATM
  • Dumpster Diving - it's amazing what people throw away
  • Mailbox theft - checks, financial statements and other sensitive documents get stolen from mailboxes
  • Stolen purse, wallet, laptop, tablet, phone - these all contain plenty of personal information
  • Social Engineering - be careful about what information you give out about yourself
  • Phishing - email or phone - con artists will call or email pretending to be your bank, law enforcement or other authority and ask you for information.
  • Social media - do you really know who your "friends" are?... there are all kinds of requests and information gathering schemes
  • Copy-cat websites - it's pretty easy for scam artists to create a fake site that looks just like your bank's website, perhaps with a misspelled URL like nationa1bank.com (that's a one instead of an L), and then collect the info you enter.
  • By known or unknown thieves! - some ID thieves know their victims.

   So many choices!

Tuesday, September 9, 2014

(SuperValu) Wrote Me A Letter

   I'm hearing the Joe Cocker version of Box Tops song! (though I always picture John Belushi doing this!)

   I don't want my summer to end, but October is coming soon and, in the US, October is National Cyber Security Month.  This will be the first post of a series on Identity Theft that will carry us into October.

   First of all, the term Identity Theft is a misnomer.  According to Findlaw:
 Theft is often defined as the unauthorized taking of property from another with the intent to permanently deprive them of it. Within this definition lie two key elements:
1) a taking of someone else's property; and
2) the requisite intent to deprive the victim of the property permanently.
The taking element in a theft typically requires seizing possession of property that belongs to another, and may also involve removing or attempting to remove the property. However, it is the element of intent where most of the complex legal challenges typically arise in theft-related cases.
   But, with Identity Theft, your identity is not actually stolen, because you still have use of it.  A more accurate term is Identity Fraud.  Someone is using your identity, without permission, to execute fraudulent transactions or commit other crimes.  And, in many cases it's just aspects of identifying or financial information that is being used fraudulently, like your credit card.

Tuesday, August 26, 2014

When USBs Attack!

   Sometimes it seems that the more things change, the more they stay the same.  In information security, we've known for a long time that if someone can get physical access to your system, there's a chance they can get into your system.  Once an attacker has possession of your computer, laptop, tablet or smartphone, they can take their time and try multiple attacks.  We can take some preventative measures like encryption, but it needs to be implemented well.

   Of course, it's best to keep your portable devices in your possession!  But they do get lost or stolen.

   Unfortunately, there's more than one way for an attacker to physically get to your system.  If you've ever been to a conference, or a state fair, or just about any kind of gathering with give-aways, you've probably seen free USB sticks (also called thumb drives).  These supposedly have programs, games or advertising files.  And they usually do.  But they can also contain viruses or other malware.  To make matters worse, USB systems have an auto-run feature to make (legitimately) running these files "easier".

Tuesday, August 5, 2014

When Androids Attack!

   All computers, devices and software have flaws.  In fact, there are so many it's hard to keep up.  In the past (not so long ago), we only had to worry about computers... and they were mostly big desktops.  Then came laptops, and with them the additional problems introduced when connecting to unknown and open networks.  And lately, we seem to spend plenty of time talking about flaws in smartphones and tablets.

   The latest in a long string of smartphone issues is the so-called "Fake ID" flaw affecting Android devices.  This attack exploits a vulnerability in the way an Android device checks the authenticity of an app.

   The issue is kind of similar to controls around US credit cards.  When you sign a credit card receipt or at a terminal, the clerk or cashier might check that signature against the one on the card.  Even if the signatures match (and when does that happen???  I can barely duplicate my own signature! :-), that doesn't mean that you are the owner of the card nor does it let anyone know if the card is fake or stolen.

   In a somewhat analogous way, apps are "signed".  The flaw allows Android phones to accept unverified apps.  This provides a potential opportunity to download fake or malicious apps.

   This issue should be patched on your phone by now.  But this is not the first time this kind of problem has emerged. And it won't be the last time!  This can be a serious issue.