My Pages

Showing posts with label data. Show all posts
Showing posts with label data. Show all posts

Tuesday, 5 April 2011

Social Engineering: That Epsilon email data breach

Another data breach and scare

News that Epsilon [1], an email marketing service provider had suffered a security breach that involved the loss of data has been received with some angst and the analysis of security of data on corporate systems.

This firm handles the email marketing for quite a number of big names in the US like Target, Chase, Marriott & Tivo referring to the names that came up in the opinion pieces that form my source for this blog.

It is interesting to note that the first article dealt with the matter of Outsourcing email [2]; this is just a matter of responsibility, the data is vulnerable no matter whose system it is on but where the data is hosted in-house, after the fire-fighting and damage control there might be a person or department to take the blame with the possible rolling of heads in mock absolution for faults.

This is a big deal

The second article dwells on the value of an email address [3] but only in reference to the service provider from reputation, through information management to the possible loss of custom – the figures are high but they hardly address the more important point which is how it affects the customer.

Another news story suggests Epsilon sends out [4] over 40 billion emails annually from over 2,500 clients which include 7 of the Fortune 10 companies. This is big business at first and quite a large customer base too.

You’ve got mea culpa mail

In one instance the writer had received an apologetic email from Epsilon and seemingly exculpatory emails from three other organization which whom he had registered for some service that used his email as part of the transactional and interaction process.

Interestingly, even one comment suggested the receipt of emails from organisation they thought they had already cancelled subscriptions to, in effect, cancelling a subscription only stops emails from going out, it does not expunge the host database of the email information.

Where it gets worrisome is that what was exposed to unauthorised access was email addresses and/or customer names.

Proof you exist

There are a number of inalienable facts that derive from this piece of information, the fact that it was on Epsilon systems means there is a likelihood that the addresses are active and where a customer name is attached, it serves enough as a uniqueness identifier just for a spammer to use or purvey and even conduct more extensive searches that can match that information to home addresses and other personal information that could be found online.

This is the equivalent of looking through a telephone directory which probably contains current and valid information to use a service or contact a person.

Over a year ago, my phone number strayed into the hands of scammers in Ghana, one of whom called me at an unholy hour, the moment I answered the call, I had validated the working order of that number and for 5 consecutive days I received calls from different people in Ghana and it was my ignoring the subsequent calls that fed back into that network that it was useless calling me.

Another analogy is the having an email address with a customer name is the equivalent of knocking on a door and knowing there is an occupant of that premises that offers the opportunity for the criminal to watch out for when they might burgle the premises.

Getting familiar

Beyond that, having a customer name allows for the spammer to send friendlier and more familiar type communication that can break down the usual resistance to spam email.

Where the customer has different email addresses with particular ones being used for trusted Internet activity, receiving spam emails on those addresses can be rather irksome.

By the time the customer has been irredeemably spammed even important emails would have ended up in the bin whilst ameliorating acts of changing email addresses can be fraught with unnecessary administrative problems of reviewing all subscriptions, informing all contacts and many other troublesome issues.

The cost to the customer is high and I have in certain instances had to discontinue the use of a service provider just because they were doing nothing to stem the flow of spam.

Remediation is fraught

However, as it stands, there is really no compensation for the inconvenience of the expected deluge of spam from a new set of spam addresses and who because they now have customer names could suggest they have established a relationship with the victims of these criminal activities.

I am saddened that of most the computer press I have read about this data breach have not really addressed this angle of the matter, it is the multitude of customers that give the companies the business they have, they seem to have been forgotten in their face-saving and damage-limitation quests.

Taking care

Customers should beware of phishing email, check that URLs in emails are really from where they purport to come from, never send any personal details to anyone seeking such information via email, at least not before verifying that with the company via a telephone call.

You should never have to share your security number, home address, credit card numbers or personal identity numbers with anyone either by email or on the phone, if in doubt, ignore the email especially if it reads like a threat and if on a phone call, excuse yourself from the call, recompose yourself and call at another time – the taker of your call should never fill you with additional angst and anxiety.

Sources

[1] Epsilon is a subsidiary of Alliance Data - Wikipedia, the free encyclopedia

[2] Outsourcing email: Do the benefits outweigh the risks? | ZDNet

[3] Epsilon data breach: What's the value of an email address? | ZDNet

[4] Massive Breach at Epsilon Compromises Customer Lists of Major Brands | SecurityWeek.Com

Monday, 17 January 2011

Nigeria: INEC - One finger is enough 10 fingers is insanity

Edited and updated.

One little finger, thank you

I think it is time to get beyond unnecessary analysis to the practicalities of the matter of what improvement in data-quality is offered by having 10 fingerprints or one thumbprint as part of the biometric identification for the Nigerian voter registration exercise.

One is at a loss for the why 10 fingerprints are necessary, it appears a demonstration of the digital data capture process had excited the decision-makers that they went for the full capability of the system rather than weighing in very crucial factors of speed, efficiency, throughput, validity and uniqueness.

Evidence is usual not 10 fingers

Over a hundred years of usage, fingerprint evidence has helped criminology well and though DNA analysis seems to have become a finer tool for forensic criminology, it has not completely obviated the need fingerprint capture at the crime scene.

Generally, the 10 fingers are only captured for police documents or in this age of paranoia regarding terrorism at certain points of entry around the globe.

I hate to think that this voter registration exercise has been sold to the election commission as a dual-purpose function to be shared with the security agencies in Nigeria and probably the Interpol; which for all intents and purposes can be very helpful to crime solving, but it should not have featured at all in the primary exercise of voter registration.

The issue of civil liberties probably has not gained enough traction as to the sensitivity of this kind of data, who would eventually have access to it, how it would be secured, if citizens have right of access to modify or delete their information and much more.

Which finger did it bite?

In the scheme of things when one reads of reports of registrants failing to obtain the fingerprint differentiator as part of their voter registration exercise because the 10th finger does not scan frustration is compounded.

So far, we have read that the ex-president of Nigeria and the current Senate president have been unable to obtain their voter registration cards, it is not clear if this is because none of their fingers could be scanned or some could not be scanned.

That is beside the point, the registration exercise has so many points of failure and has been made unduly complicated that it offers the opportunity to truncate or circumvent the process.

Bad data awaiting good challenge

My fear is that vexatious litigious politicians who are too regularly up to mischief might put a spanner in the works by requiring all voter registrations without the cumbersome and unnecessary 10-fingerprint excess of data be voided either at the voter registration review or after voting is exercised if they feel they can gain some political advantage.

It is incumbent on INEC to revisit this issue immediately and recalibrate the system whilst issuing new instructions only to do a single thumb capture. It is not like Nigerians are prone to losing their fingers that by April, they might need another finger to authenticate themselves at the time of voting.

Reality strikes

The other matter that has not been addressed is how this data would be retrieved at the time of voting, would the registrant have to check each finger against the database or would one finger suffice?

The absurdity of this whole thing only becomes so evident by looking at how the data would supposedly be put to use, how much processing is needed to check one finger out of 10 for a matching finger or all fingers in a particular order.

We do not need complex solutions for simple actions, the voters register does not have to match the security requirement for atomic-grade weapons activation or access to the Fort Knox vaults – in my humble opinion, this 10 finger salute to authentication is an overkill and that does not begin to describe that waste of time, resources and productivity that defines what could easily be a more efficient way of doing easy tasks.

Let us be smart about this – ONE THUMB is enough 10 fingers is madness raised to the power of insanity.

Sources

Fingerprint - Wikipedia, the free encyclopedia

Monday, 6 December 2010

Thought Picnic: WikiLeaks is the new porn

The landscape has changed

This is my first blog on the WikiLeaks and I doubt it would be the last. I am of the opinion that the backlash against the organ and the public face of the organ hardly begins to address the main issues that WikiLeaks present us.

For a while now, governments institutions, politicians and the elite who used to have exclusive access to information and data for use in our name for their own purposes and motives have begun to realise that they have been made powerless if the knowledge that separates them from us the people becomes common place.

WikiLeaks has changed the information landscape and much as some can moralise to the point of suggesting extra-legal measures to punish as it were illegal activities we in the process fail to uphold the great principles that millions had already sacrificed their lives for in the Twentieth Century.

Porn can be compelling viewing

The anger is felt and the international framework of the black hand of diplomacy is placing heretofore conglomerates of capitalist democracies under pressure to dissemble about the marketplace that allowed for them to take WikiLeaks’ business.

WikiLeaks has become the new hard-core porn; whilst you as adults would for all sorts of reasons have the right to entertain yourselves with such material, it cannot be done on office time, you should not be found viewing such as US Federal employees have now been told not to do because the material is classified even though it is all now in the public domain but more egregious of us is a directive that threatened students who showed even the tacit support for WikiLeaks with the inability to find employment.

What you decide to do with hard-core porn on your own time in the confines of your privacy should be your business and yours only. If the pants of guilt consume you such that you seek absolution from your pleasure which to some is a vice and to the fundamentalist is a sin depends on how impressionable you might feel about the things you decide to consume and the kind of moral agent you are.

Our dependency complex

Human-beings seem to exercise the greatest dependency in reaching maturity and whilst some grow into maturity others transfer the dependency complex from parental and patriarchal figures to other kinds of leaders be they political, religious, social, economic or some other sphere of influence.

The seeming benefactors instil enough fear, threat and terror to curtail adventurism on the part of the many who can be dictated to, to toe the line and follow orders with the premise of patriotism and justice, their indignation whipped up into the frenzy of the mob as they are relieved of their rights of observation and expression for the greater good of not requiring their governments hold themselves accountable.

The function of WikiLeaks

The security breaches that have fed WikiLeaks are in no way the fault of WikiLeaks, the function of WikiLeaks if we have failed to notice is to leak information that has come into their possession, the matter of how that information is processed before dissemination is hardly the responsibility of WikiLeaks.

Like with hard-core porn some might want to watch the plot and the making out that develops into the full-blown action, others might just want to jump to the activity but it is unlikely that the viewer would have acquired the material for the purpose of assessing the dramatic content of the film – however, people would be titillated in different ways having viewed the material.

Where the porn analogy might fall through is where within that material something illegal seems to have occurred like the abuse of minors or something worse – in that case, caveat emptor, the viewer is advised.

Information all round

As for the detail contained in the leaks, I seem to know where every nuclear plant in Iran is courtesy of leaks provided by defectors (traitors of Iran but friends of the West) and now I know where every strategic US asset is, call your guards out, if your diplomats cannot maintain discretion preventing embarrassment the cost mounts in ensuring the guards are motivated enough not to allow the unfortunate to happen on their watch.

If anyone thinks hounding Julian Assange or closing WikiLeaks will end the expansive domain of the whistle-blower they have not learnt the most basic lesson of this WikiLeaks saga; as long as there is a message, there will always be a messenger and world is a very listening and attentive audience.

Just because porn works across borders, cultures, traditions, morals or feigned ethics, we all have our needs, even the ones we deny ourselves.

Monday, 7 January 2008

Jeremy Clarkson teaches Data Protection

Clarkson learns data protection

If there was anything that would make people learn the fact that the protection of personal data is so important, we have Jeremy Clarkson to thank for that.

Now, Mr. Jeremy Clarkson is someone you would very much love to hate as an opinionated right-wing commentator who for all his faults does present a very entertaining car programme called Top Gear.

In many ways, as our society has growth soppy and more intolerant of political incorrectness, the man has tempered his opinions with a bit of restraint. The attempts to gentrify the man with more cerebral engineering programmes did not however endear him to me anymore than I can accept his professional judgement about cars.

Mr. Clarkson pooh-poohed the whole uneasiness about the loss of data concerning 25 million people in the UK by publishing his details in his column on the Sun newspaper.

These details included his full bank account information and his address, enough for someone who must have wanted to prove a point to set up a Direct Debit of GBP 500.00 to the Diabetes UK charity.

Every little data helps

Obviously, it also shows how such details can be used maliciously by others to extract a lot more than a gesture to charity from unsuspecting people who are careless with their data.

I, for instance would never dispose of anything containing my details without shredding the lot and like I observed a few weeks ago, I need a better shredder when I saw a lady trying to put together strips from a shredder waste-basket.

This matter of details could be as minor as envelopes that have just my postcode and house-number or the till receipt after paying with my bank card at the supermarket. Every little data helps the thief assume your identity on the one hand and sometimes conduct harmful transactions in your name.

Mr. Clarkson happens to be someone who checks his bank statements or else a few more transactions would have been made before he found out about the shenanigans done in his name.

Privacy from excessive data accumulation

This brings me to the Advance-Fee Fraud emails that people receive asking for their bank details in confidence so as to pay in supposedly ill-gotten gains from which the bank account holder can benefit up to 25% of the deposit.

Well, in most cases, these accounts get fleeced and emptied because the information the culprits have is good enough for either debits or credits to the account.

As penance, I would expect Mr. Clarkson to honour this Direct Debit to the Diabetes UK charity for at least a year whilst the bank works at completely changing his account details from what was published.

It also shows why our liberties have to be protected by preventing the government from acquiring more data than they require to transact any business. The fact that the Data Protection Act would not allow for the banks to pursue the “criminal” who showed up this problem of loose data management is a great enlightenment for all.

Sunday, 1 October 2006

Air data going nowhere

Information overload

Sometimes I wonder where all that accumulation of information goes apart from feeding the voyeuristic and controlling tendencies of the state and its apparatus in the pretence of fighting the war on terror.

Months ago when the highest European Court declared the data exchange, or rather the whole scale one-way data transfer of confidential data of European citizens who deign to travel to America illegal, that was triumph to be celebrated by all liberty seeking persons who do not want to sacrifice their freedom for temporary safety.

It so happens that the court asked that a better arrangement with legal grounding be negotiated between Europe and American authorities.

A bloody inconvenience

That negotiation seems to have broken down, and so it should, there is no valid reason for sending all that confidential information to America within 15 minutes of take-off only to find that more than halfway into the flight, the airplane has to be turned back because the computers throw up some innocuous and suspicious information which ends being a red herring.

Having never been to America, it does not really bother me, but, I have a newfound interest to visit and tour kindled by the arrival of this month’s National Geographic which had a foldout with a large map of the United States of America.

Extradition on a whim

The next thing to be resolved is that rotten extradition treaty that lets countries throw their citizens to American “justice” and sometimes gallows without court-tested evidence and with nothing of reciprocal equivalence from America.

The whole concept should be declared, unfair, unjust and illegal, the treaties should be annulled and made of non effect.

The poorest standard

The question is why America’s paranoia should become the poor standard of protecting our freedoms, that we end up serving America’s security ends at the expense of protecting and enforcing the rights of our own citizens.

It should not be so; the reciprocation of bad treaties is not the solution, rather the principles of justice, fairness, liberty, freedom and democracy that respects our privacy and protects our confidentiality grounded in good laws and enforce by good government globally is the way to go.

I do not want to know anything about American private lives; neither do I want Americans brought over to Europe on a whim without adequate legal and due process to determining proper cause.