The minute you settle for less than you deserve, you get even less than you settled for.
Maureen Dowd
IT and Related Security News Update from Centre for Research and Prevention of Computer Crimes, India (www.crpcc.in) Courtesy - Sysman Computers Private Limited, Mumbai
The minute you settle for less than you deserve, you get even less than you settled for.
Maureen Dowd
PAT
Short for port address translation, a type of network address translation. During PAT, each computer on LAN is translated to the same IP address, but with a different port number assignment.
PAT is also referred to as overloading, port-level multiplexed NAT or single address NAT.
Leo King
June 02, 2008
Computerworld UK
Smart phones are seen as a more of a security risk than laptops and mobile storage devices, according to new research.
Some 94% of senior IT staff fear PDAs present a security risk, just above the 88% who highlighted mobile storage devices as a worry.
Nearly eight in 10 said laptops were an issue. Only four in 10 had encrypted data on their laptops, and the remainder said the information was "not worth" protecting.
The results come from a survey of 300 senior IT staff conducted by endpoint data protection supplier Credant Technologies.
A key danger with PDAs was that over half of IT executives surveyed were "not bothering" to enter a password when they used their phone.
Nine in 10 of the smart phones were being given access to company networks without extra security, even though the phones were individually owned by users. There were no access restrictions being applied to 81% of the phones.
Credant Technologies said smart phones had become "easy pickings" for any opportunists trying to steal them and access information.
Peter Mitteregger, European VP at the company, said: "Companies need to regain control of these devices and the data that they are carrying, or risk finding their investment in securing the enterprise misplaced and woefully inadequate."
Technology Problems & Difficult Clients & Suppliers are Top Anxieties
YouGov/Trend Micro survey suggests small businesses need to be more aware of growing electronic crime threat
2nd June, 2008
http://www.searchbyheadlines.com/posted_news/103560.html
Marlow, UK -- A new You Gov survey into British UK small business attitudes to operational business anxieties reveals that technology not working (42% of all respondents) is the number one work issue that causes anxiety, alongside with difficult clients and suppliers (42%) which cause the same level of concern. Heavy workloads (30%), tight deadlines (26%) and long hours (19%) were the next highest ranking issues causing concern.
The survey commissioned by Trend Micro, a global leader in internet content security, also asked small businesses about their anxiety regarding business-related crime. Fear of theft and office break-ins ranked low as issues causing most anxiety (9%) of all respondents ranked this as a top three concern. But there were some regional variations with more than one in ten London respondents (13%) saying business crime was one of their top three concerns. This compared with 3% of Scottish respondents. Anxiety over loss of confidential data was more of a general concern with one in ten of all businesses worried about this; respondents in London and Midlands/Wales registered a slightly higher level of concern (12%).
When asked about electronic crime, the majority of all respondents (83%) said they had not been a victim of electronic crime in the last 12 months. Once again there were some interesting regional anomalies with 18% of Scottish respondents saying they had suffered at least one incident in the last year.
This low rate of reported incidents among small businesses comes as the recorded volume of electronic crime attacks grows and is increasingly targeted at small businesses that do not necessary have the resources or systems to protect themselves. A further worry is that these attacks are hidden and many small businesses may not know when an electronic crime is being committed.
For example, in May 2008 over half a million websites were infected with malicious code. Most of these were small business websites typically made up of old and unsecured coding and running on older or unpatched web server and operating systems. These sites are easy targets for cyber criminals looking to hijack commercial websites for financial gain and identity fraud. Most of the UK businesses affected were sole-traders relying on their web presence for revenue generation.
Paul Burke, SMB Product Marketing Manager - EMEA at Trend Micro says: "Information technology problems top the list of everyday anxieties for small businesses. The survey also suggests that we need to do much more to better inform and help the small business community about the new generation of security threats that are attacking their IT infrastructure silently and with potentially devastating effects to their reputation and finances. Our Worry-Free initiative is geared specifically to provide these businesses with both support and guidance on how to better protect themselves without adding to their IT anxieties and having to become an IT security expert."
While putting into place comprehensive security software is key, Trend Micro suggests a number of tips on how small businesses can protect their assets, their customer information and, most importantly, their reputation:
ü Ensure that all employees use effective passwords, and when possible, stronger authentication technology. Encourage passwords that are comprised of different upper and lower case letter characters and change them frequently
ü Discourage employee downloads from non-trusted sources such as peer-to-peer and video
ü Protect your network; by ensuring that PCs and laptops are protected by firewalls, anti-virus software and web threat protection both within the office network as well as when mobile working
ü Keep all operating systems and software up-to-date, as without updates, your systems will not be well protected against new cyber threats
ü Create and manage back-ups. It is best to store secured copies and use encryption to protect sensitive records about employees, suppliers and customers
ü Maximise encryption. You should protect customer data by encrypting it with passwords or encryption keys
ü Don't leave sensitive data saved on a handheld or mobile device, in case it is stolen or lost
ü Keep in mind that your company will grow, and shop for security solutions that will grow with your business's pace
By Staff Writers
SC Magazine
2 June 2008
http://www.securecomputing.net.au/news/beware-credit-card-fraud-rates-increasing.aspx
Credit and charge card fraud rates increased in 2007, as more dollars were lost to fraudulent overseas online merchants, according to the Australian Payments Clearing Association (APCA).
According to APCA's newly released payments fraud data, payment card fraud that is debit, credit and charge cards, increased from 23.9 cents in every $1,000 in 2006 to 27.9 cents in 2007.
Credit and charge card fraud (signature permitted and card-not-present) fraud increased from 36.9 cents to 44.5 cents in every $1,000 while debit card fraud dropped from 7.7 cents to 7.1 cents in every $1,000.
The report found the largest component of Australia’s credit and charge card fraud relates to card-not present (CNP) fraud and cross-border fraud activity which includes fraud conducted over the Internet, phone, mail and fax.
APCA’s Chief Executive Officer, Chris Hamilton said Australia’s payment card fraud rate has increased over the last 12 months but remains low by global standards.
“The UK’s payment card fraud rate is the equivalent of $1.18 in every $1,000 as against slightly under 28 cents in Australia,” Hamilton said.
"[However] what the statistics are telling us is that even as today’s technology makes it possible to buy anything from anywhere, it is also making it possible for fraudsters to operate globally," he said.
Hamilton warned: "It’s no surprise that Australian consumers and retailers need to take particular care when not dealing face-to-face.”
Commenting on the data, the Australian Bankers’ Association (ABA) said cheque fraud has declined to very low levels, debit card fraud is also at low levels but credit and charge card fraud is showing an increase.
Around 70 percent of the increase in credit card and charge card fraud has been driven by Australian card holders making purchases overseas via the Internet and telephone, claimed the ABA.
According to David Bell, chief executive at the ABA, customers are increasingly shopping online from overseas retailers and unfortunately some of these outlets may not have strong customer protections in place.
“Fraud prevention remains more than ever a priority for the industry," said APCA’s Hamilton.
Vendor nixes protection with step-by-step reset guide
By John Leyden
2 Jun 2008
http://www.channelregister.co.uk/2008/06/02/hp_laptop_bios_security/
HP has come under fire for nullifying BIOS password protection steps on laptops by publishing reset data on its website. UK-based security consultancy SecureTest compared the approach to hiding a front door key under a welcome mat.
Security breaches resulting from stolen laptops have hit the headlines repeatedly over recent months. Full disc encryption is the best approach to making sure data remains secure even if an item of hardware is lost or stolen. But other techniques, such as BIOS password security, still have a role in discouraging casual thieves from bothering to read the data on stolen or 'lost' laptops.
Early BIOS passwords were a product of a more innocent age, but even so password resets typically required technically involved procedures. Initially hardware hacks, such as the opening up the case and applying a parallel loopback connector, were possible. Laptop manufacturers later sharpened up their practices so that better reset processes were applied across the industry.
Laptop BIOS resets typically involve a call to a vendor and going through a challenge-response process before reset codes are handed out. So SecureTest was surprised to discover that HP publishes the reset process for the series of laptop most commonly used in the office on their UK website.
By comparison reseting the BIOS password on a Toshiba laptop involves a visit to a Toshiba dealer, the only parties authorised to obtain reset codes.
"HP might choose to defend itself by saying that its 'bundled security tools' provide a much greater degree of protection than the BIOS, but in reality security is about in-depth defence. Each layer of the security onion needs to be as impenetrable as possible," Ken Munro, a director of SecureTest, explained.
"So it frankly baffles us as to why the likes of HP would publish the reset process if the BIOS password isn’t intended to be used. It’s like hiding your key under the mat and leaving a note to that effect for passing burglars to see," he added.
We put these concerns to HP on Friday. We're yet to hear anything substantive back but will update this story if we do.
Although full disc encryption is the best approach for laptop security other techniques still have their place, according to Munro.
"Full disc encryption is the right thing for laptop security, but vendors often forget to mention the ATA-3 (or ‘drivelock’) standard that effectively ‘locks’ the hard drive to the BIOS.
"Unless this password has been entered, the laptop is rendered unbootable and the hard disc unreadable, even if it is removed and mounted in another machine. ATA-3 appears vulnerable only to a very prolonged brute force crack, rather like regular encryption," he said.
Thanks for your Visit