<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fraud]]></title>
    <link>http://securityratty.com/tag/fraud</link>
    <description></description>
    <pubDate>Tue, 19 Aug 2008 12:12:41 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Supporting CEP with Solace Content Routers]]></title>
      <link>http://securityratty.com/article/8d902f5832f1d3b5efbfc1f409e130b5</link>
      <guid>http://securityratty.com/article/8d902f5832f1d3b5efbfc1f409e130b5</guid>
      <description><![CDATA[Interested in content routing and event preprocessingsupporting futureCEP applications? Check out Solace Systems . You can click on the image below for a better picture of the Solace architecture for...]]></description>
      <content:encoded><![CDATA[<p>Interested in content routing and event preprocessing supporting future CEP applications?  Check out <a href="http://wwww.solacesystems.com" target="_blank">Solace Systems</a>.  You can click on the image below for a better picture of the Solace architecture for event processing.</p>
<p style="text-align: center;"><a href="http://www.solacesystems.com/images/solutions/cep_architecture.gif" target="_blank"><img class="aligncenter" src="http://www.solacesystems.com/images/solutions/cep_architecture.gif" alt="" width="450" height="283" /></a></p>
<p>Solace provides <a href="http://www.solacesystems.com/solutions/fs_event_processing.asp" target="_blank">sophisticated middleware functionality</a> in hardware to monitor, filter, route, transform and secure very large volumes of events in real time and with minimal processing overhead.  Solace uses leading-edge FPGA, ASIC and network processor technology to increase throughput and lower latency of event processing. Applications such as fraud detection, algorithmic trading, compliance, insider trade monitoring, risk management and more can be tackled more effectively by separating the simple monitoring, filtering and normalization of raw events from the complex processing of select events. This event pre-processing takes the burden off CEP engines allowing individual engines to be much more effective. </p>
]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 07:42:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solace">solace</category>
      <category domain="http://securityratty.com/tag/solace systems">solace systems</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/raw events">raw events</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/solace architecture">solace architecture</category>
      <category domain="http://securityratty.com/tag/network processor technology">network processor technology</category>
      <category domain="http://securityratty.com/tag/select events">select events</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <source url="http://www.thecepblog.com/2008/09/06/supporting-cep-with-solace-3230-and-solace-3260-content-routers/">Supporting CEP with Solace Content Routers</source>
    </item>
    <item>
      <title><![CDATA[Software to Facilitate Retail Tax Fraud]]></title>
      <link>http://securityratty.com/article/c541c0e2a682f8958bb71c87da49a528</link>
      <guid>http://securityratty.com/article/c541c0e2a682f8958bb71c87da49a528</guid>
      <description><![CDATA[Interesting : Thanks to a software program called a zapper, even technologically illiterate restaurant and store owners can siphon cash from computer cash registers and cheat tax officials

Zappers...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2008/08/30/technology/30zapper.html">Interesting</a>:</p>

<blockquote>Thanks to a software program called a zapper, even technologically illiterate restaurant and store owners can siphon cash from computer cash registers and cheat tax officials.

<p>[...]</p>

<p>Zappers alter the electronic sales records in a cash register. To satisfy tax collectors, the tally of food orders, for example, must match the register's final cash total. To hide the removal of cash from the till, a crooked business owner has to erase the record of food orders equal to the amount of cash taken; otherwise, the imbalance is obvious to any auditor.</p>

<p>[...]</p>

<p>The more sophisticated zappers are easy to use, according to several experts. A dialogue box, which shows the day's tally, pops up on the register's screen. </p>

<p>In a second dialogue box, the thief chooses to take a dollar amount or percentage of the till. The program then calculates which orders to erase to get close to the amount of cash the person wants to remove. Then it suggests how much cash to take, and it erases the entries from the books and a corresponding amount in orders, so the register balances.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=b0MQKL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=b0MQKL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=mqs4qL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=mqs4qL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 08:24:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cash">cash</category>
      <category domain="http://securityratty.com/tag/cash register">cash register</category>
      <category domain="http://securityratty.com/tag/siphon cash">siphon cash</category>
      <category domain="http://securityratty.com/tag/computer cash registers">computer cash registers</category>
      <category domain="http://securityratty.com/tag/final cash total">final cash total</category>
      <category domain="http://securityratty.com/tag/register">register</category>
      <category domain="http://securityratty.com/tag/dollar amount">dollar amount</category>
      <category domain="http://securityratty.com/tag/amount">amount</category>
      <category domain="http://securityratty.com/tag/dialogue box">dialogue box</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/software_to_fac.html">Software to Facilitate Retail Tax Fraud</source>
    </item>
    <item>
      <title><![CDATA[Amazon's Mechanical Turk Used for Fraudulent Activities]]></title>
      <link>http://securityratty.com/article/807af75303280a00669feb46e63087df</link>
      <guid>http://securityratty.com/article/807af75303280a00669feb46e63087df</guid>
      <description><![CDATA[Although these HITs may stop short of being &quot;fraud&quot; in the legal sense of the word, they are certainly dishonest and unsavory. In addition to these spam bookmarking requests, we're also seeing HITs...]]></description>
      <content:encoded><![CDATA[Although these HITs may stop short of being "fraud" in the legal sense of the word, they are certainly dishonest and unsavory. In addition to these spam bookmarking requests, we're also seeing HITs for Diggs, Stumbles, Slashdots, etc. of spammers' web pages and web sites.]]></content:encoded>
      <pubDate>Sat, 30 Aug 2008 11:50:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/hits">hits</category>
      <category domain="http://securityratty.com/tag/stop short">stop short</category>
      <category domain="http://securityratty.com/tag/legal sense">legal sense</category>
      <category domain="http://securityratty.com/tag/web pages">web pages</category>
      <category domain="http://securityratty.com/tag/stumbles">stumbles</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/requests">requests</category>
      <category domain="http://securityratty.com/tag/unsavory">unsavory</category>
      <source url="http://digg.com/security/Amazon_s_Mechanical_Turk_Used_for_Fraudulent_Activities">Amazon's Mechanical Turk Used for Fraudulent Activities</source>
    </item>
    <item>
      <title><![CDATA[CEP is Not BPM, BAM, BRE, BRMS or SOA]]></title>
      <link>http://securityratty.com/article/19813f3c14d4970ef6ec62577362732d</link>
      <guid>http://securityratty.com/article/19813f3c14d4970ef6ec62577362732d</guid>
      <description><![CDATA[A post in Technology content of current CEP products? reminds me of why I rarely, if ever, agree with anything that comes out of Aleris marketing team. To fair to Jeff, it is not only Aleri but...]]></description>
      <content:encoded><![CDATA[<p>A post in  <a href="http://www.thecepblog.com/wp-admin/viewtopic.php?f=13&amp;t=123&amp;start=0&amp;st=0&amp;sk=t&amp;sd=d">Technology content of current CEP products?</a> reminds me of why I rarely, if ever, agree with anything that comes out of Aleri&#8217;s marketing team.   To fair to Jeff, it is not only Aleri but others, who continually misdefine business process management (BPM) as CEP.</p>
<p>Jeff uses the example, &#8220;Smart Order Routing&#8221; as an example of taking an event and routing the resulting market order match based on some simple rules.    Routing a order kicked off by a simple order match against a deep liquidity pool (or other market factor) does not define complex event processing nor detecting a complex event - the core idea behind CEP.   Order routing based on simple rules is BPM, plain and simple.</p>
<p>Let&#8217;s take another example, fraud.  In this example, there is some complex neural network monitoring for credit card fraud and a potential fraud is detected - this is CEP, detecting a complex event based on some sophisticated analytics.   </p>
<p>After a possible fraud has been detected, a process looks into a database and the routes the incident to someone in the company who is a (1) specialist in credit card fraud, (2) working at the same time of the discovered threat, and (3) immediately available to act on this type of task.   Routing the incident is not CEP, it is BPM.</p>
<p>Jeff makes the argument that it is OK to call an event-driven BPM task CEP because &#8220;it fits the EPTS definition&#8221; in the CEP glossary.   He also avoids the discussion of detection accuracy, and instead insists that latency is a &#8221;very important&#8221; factor in a CEP application.</p>
<p>If you read the various post by vendors in the blog-o-sphere, it is obvious that they are continually defining CEP as BAM, BPM, BRE, BRMS, SOA and just about every other related processing activity that is complimentary to the <a href="http://www.thecepblog.com/2008/08/26/magic-quadrant-for-it-event-correlation-and-analysis-2007/" target="_self">event correlation and analysis </a>required to detect an opportunity or threat to your business.</p>
<p>I&#8217;m not picking on Aleri.  TIBCO has been doing the same thing recently in their <a href="http://tibcoblogs.com/cep" target="_blank">CEP blog</a>, continually attempting to redefine CEP as BRMS.    Detecting business opportunities and threats with high confidence requires sophisticated analytics, and their tools have not yet evolved to &#8220;real CEP&#8221; capabilities.  Instead, vendors are attempting to redefine BPM, BRMS, BRE, and even SOA to some degree, as CEP. </p>
<p>CEP is Not BPM, BAM, BRE, BRMS or SOA.</p>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:37:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/cep blog">cep blog</category>
      <category domain="http://securityratty.com/tag/current cep products">current cep products</category>
      <category domain="http://securityratty.com/tag/cep glossary">cep glossary</category>
      <category domain="http://securityratty.com/tag/bpm">bpm</category>
      <category domain="http://securityratty.com/tag/real cep capabilities">real cep capabilities</category>
      <category domain="http://securityratty.com/tag/cep application">cep application</category>
      <category domain="http://securityratty.com/tag/potential fraud">potential fraud</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.thecepblog.com/2008/08/27/cep-is-not-bpm-bam-bpm-brms-or-soa/">CEP is Not BPM, BAM, BRE, BRMS or SOA</source>
    </item>
    <item>
      <title><![CDATA[Managing a trust-damaging event]]></title>
      <link>http://securityratty.com/article/54e2b4934b24a43c01accb9d1fcca54f</link>
      <guid>http://securityratty.com/article/54e2b4934b24a43c01accb9d1fcca54f</guid>
      <description><![CDATA[How a credit card company or a card issuer manages a trust-damaging event, such as fraud, can have a major impact on long-term customer...]]></description>
      <content:encoded><![CDATA[How a credit card company or a card issuer manages a trust-damaging event, such as fraud, can have a major impact on long-term customer relationships.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=85785?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=85785?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card issuer manages">card issuer manages</category>
      <category domain="http://securityratty.com/tag/long-term customer relationships">long-term customer relationships</category>
      <category domain="http://securityratty.com/tag/credit card company">credit card company</category>
      <category domain="http://securityratty.com/tag/major impact">major impact</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.networkworld.com/news/2008/082708-managing-a-trust-damaging.html?fsrc=rss-security">Managing a trust-damaging event</source>
    </item>
    <item>
      <title><![CDATA[Should Banks Believe Their Customers Who Claim Online Fraud?]]></title>
      <link>http://securityratty.com/article/065fedd6ff7dcb0d99d432293ba7a6a6</link>
      <guid>http://securityratty.com/article/065fedd6ff7dcb0d99d432293ba7a6a6</guid>
      <description><![CDATA[Should banks believe their customers when they claim someone hacked their accounts and committed online fraud? Apparently in one recent case, WaMu first reversed the charges when one customer claimed...]]></description>
      <content:encoded><![CDATA[<p>Should banks believe their customers when they claim someone hacked their accounts and committed online fraud? Apparently in one recent case, WaMu first reversed the charges when one customer claimed a hacker charged up debt in her itunes account &#8212; but later, the bank took back the credit, saying the customer was just plain lying. What great customer service.</p>
<p>The Consumerist has the story:</p>
<blockquote><p>WaMu&#8217;s crack fraud department is at it again, according to reader Kristin. Someone broke into her iTunes account and bought a couple hundred dollars worth of iTunes gift cards with her debit card information. She disputed the charge and WaMu told her not to worry — they&#8217;d take care of it. Two months later, while on a trip to Chicago, WaMu reversed the credits, causing Kristin to become severely overdrawn. No amount of protesting will convince WaMu that she wasn&#8217;t lying about the iTunes break-in. Why? Because she never responded to some mail they sent to her old address.</p></blockquote>
<p>Yuck. Read the customer&#8217;s full account, and more information about the credit card fraud laws, in <a rel="nofollow" target="_blank" href="http://feeds.gawker.com/~r/consumerist/full/~3/374505870/wamu-youre-lying-about-someone-breaking-into-your-itunes-account">the full article</a>.</p>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 16:54:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wamu">wamu</category>
      <category domain="http://securityratty.com/tag/itunes account">itunes account</category>
      <category domain="http://securityratty.com/tag/convince wamu">convince wamu</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/customer service">customer service</category>
      <category domain="http://securityratty.com/tag/debit card information">debit card information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/374897918/">Should Banks Believe Their Customers Who Claim Online Fraud?</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Four]]></title>
      <link>http://securityratty.com/article/89e92ac703db317a9f2d0ad0ae004a56</link>
      <guid>http://securityratty.com/article/89e92ac703db317a9f2d0ad0ae004a56</guid>
      <description><![CDATA[Thanks to the affiliate based business model that's driving the increase of fake security software and rogue codecs serving domains, the very same templates, but with different domain names, continue...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLKFy9dsYiI/AAAAAAAACHE/DiRDPArpb4A/s1600-h/fake_security_software_august.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLKFy9dsYiI/AAAAAAAACHE/jlXrnI7ApPo/s200-R/fake_security_software_august.JPG" /></a>Thanks to the affiliate based business model that's driving the increase of fake security software and rogue codecs serving domains, the very same templates, but with different domain names, continue appearing in blackhat SEO, spam, and malicious doorways redirection campaigns.<br />
<br />
Moreover, with the "time-to-market" of a fake security software decreasing due to the efficiency approach introduced in the form of tips for abuse-free hosting services provided by the "known suspects", and the freely available templates, we're slowly starting to see the upcoming peak of this approach. <br />
<br />
In a true proactive spirit, the domains parked at 216.195.56.88 are all upcoming fake security software, to be introduced anytime soon.<br />
<br />
<b>fast-pc-scanner-online .com</b> - (92.62.101.41; 91.203.92.48; 91.203.92.106; 58.65.238.171)<br />
<b>top-pc-scanner .com<br />
buy-secure-protection .com<br />
security-scan-pc .com<br />
pc-scanner-online .com<br />
viruses-scanonline .com<br />
virus-scanonline .com<br />
antivirus-scanonline .com<br />
topvirusscan .com<br />
virusbestscan .com<br />
best-security-protection .com<br />
infectionscanner .com<br />
virusbestscanner .com<br />
full-protection-now .com</b><br />
<br />
<b>Pwrantivirus .com</b> - 91.208.0.246<br />
<b>vav-x-scanner .com<br />
vav-scanner .com<br />
scanner.vavscan .com<br />
malware-scan .com<br />
Scanner-Pwrantivirus .com<br />
Xpertantivirus .com<br />
Scanner-xpertantivirus .com</b><br />
<br />
<b>spyware-quickscan-2008 .com</b> - (216.195.56.88)<br />
<b>virus-quickscan-2008 .com<br />
spyware-quickscan-2009 .com<br />
virus-quickscan-2009 .com<br />
winmalwarecontrol .com<br />
antispyware-quick-scan .com<br />
virus-quick-scan .com<br />
antivirus-quick-scan .com<br />
winprivacytool .com</b><br />
<br />
<b>topantispyware2008 .com</b> - (216.195.56.86)<br />
<b>cleanermaster .com</b> - (216.195.56.85)<br />
<b>antivirus777 .com</b> - (67.228.120.3)<br />
<b>pcsecuritynotice .com </b>- (67.228.120.3)<br />
<br />
Whereas the average Internet users are falling victims into this type of fraud, what I'm more concerned about is the large traffic the malicious domains receive in general due to all the different traffic acquisition tactics the people behind them apply. This anticipated traffic can then be greatly used as valuable metrics for the many other malicious ways in which it can be monetized.<br />
<br />
Ironically, the participant in the affiliate program whose original objective was to drive traffic to the fake security software's site, may in fact start receiving so much traffic due to the combination of traffic acquisition tactics, that <a href="http://ddanchev.blogspot.com/2008/02/serving-malware-through-advertising.html">introducing client-side exploits courtesy of a third-party affiliate network</a>, may in fact prove more profitable then the revenue sharing partnership with the rogue security software's vendor at the first place.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The Malicious ISPs You Rarely See in Any Report</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T4pWXK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T4pWXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fUdxLK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fUdxLK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wfXZZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wfXZZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DNdBTk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DNdBTk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=A69ooK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=A69ooK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kvp7rK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kvp7rK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PdsGMk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PdsGMk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/374177616" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 01:58:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/drive traffic">drive traffic</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/traffic acquisition tactics">traffic acquisition tactics</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/malicious isps">malicious isps</category>
      <category domain="http://securityratty.com/tag/due">due</category>
      <category domain="http://securityratty.com/tag/traffic due">traffic due</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/374177616/diverse-portfolio-of-fake-security_25.html">A Diverse Portfolio of Fake Security Software - Part Four</source>
    </item>
    <item>
      <title><![CDATA[Technology Tales from Thailand: KBank Fraud Management]]></title>
      <link>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</link>
      <guid>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</guid>
      <description><![CDATA[In The Magical ATM Card and SMS Message in Thailand we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and...]]></description>
      <content:encoded><![CDATA[<p>In <a title="The Magical ATM Card and SMS Message in Thailand" rel="bookmark" href="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/"><span style="color: #105cb6;">The Magical ATM Card and SMS Message in Thailand</span></a> we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and in <a title="Keyloggers: Why Banks Need Two-Factor Authentication" rel="bookmark" href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/"><span style="color: #105cb6;">Keyloggers: Why Banks Need Two-Factor Authentication</span></a> I described how <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">KBank</a> uses SMS-based one-time-passwords (OTP) to authenticate transactions.   </p>
<p>In addition to the above services, KBank offers a service that permits users to receive an SMS message that details any change in account balance and/or point-of-sale (POS) transaction with your debit card.   I really like this service and the feeling of security knowing when, where and by how much my balance changes or my debit card is used in a transaction.    The KBank POS SMS notification is so fast that when I present my card to a merchant I normally receive an SMS message detailing the transaction before the merchant returns for my signature.  (There is an unfortunate lag in the balance change notification that can run minutes to hours behind real-time, but the POS VISA debit card notification is real-time).</p>
<p>As the story goes,  I should have been using my KBank card and account a few weeks ago and not my US-based VISA debit dard.  Why?</p>
<p>My US-based VISA debit card was cloned sometime on or before August 8th.   I am really careful with this card, so I was surprised the magnetic strip was cloned at a POS merchant.   The fraudster made 7 fraudulent transactions beginning on August 8th for a total of around $2500 USD, mostly on August 11th, before I discovered the fraudulent transactions viewing my account on-line.</p>
<p>This would not have happened with KBank SMS-based transaction notification services.</p>
<p>The first transaction with my cloned VISA debit card was less than $50 USD (I assume the fraudster was &#8220;testing the water&#8221;).   If I was using my KBank card, I would have received an immediate SMS message detailing a POS transaction in Bangkok when I was physically far away from Bangkok in Chiang Mai.   I could have immediately called the bank (or logged in) and blocked the debit card, limiting potential losses to the bank or the merchant to one fraudulent transaction, not seven.</p>
<p>In addition, KBank offers what they call a Web-Shopping VISA card, where you can go into your on-line account (verified by SMS OTP as mentioned) and request a VISA debit card number (with expiration date, CCV etc).   You set the limit from 0 to 500,000 THB (Thai Baht) per day; and you can login to your account and change this anytime (authenticating your transaction with another SMS-based OTP). You can also block or cancel this number anytime and apply for another one.</p>
<p>I am amazed that in Thailand I receive much better anti-fraud prevention and detection services than with banks in the US.   I know of no bank or brokerage in the US that offers the same quality of service and security as KBank in Thailand.  </p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:16:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visa debit card">visa debit card</category>
      <category domain="http://securityratty.com/tag/debit card">debit card</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/visa card">visa card</category>
      <category domain="http://securityratty.com/tag/kbank">kbank</category>
      <category domain="http://securityratty.com/tag/kbank card">kbank card</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/transaction notification services">transaction notification services</category>
      <category domain="http://securityratty.com/tag/fraudulent transaction">fraudulent transaction</category>
      <source url="http://www.thecepblog.com/2008/08/20/technology-tales-from-thailand/">Technology Tales from Thailand: KBank Fraud Management</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hacking Injunction Lifted]]></title>
      <link>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</link>
      <guid>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</guid>
      <description><![CDATA[Earlier today, the US District Court dealt a victory to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at...]]></description>
      <content:encoded><![CDATA[<p>Earlier today, the US District Court <a href="http://www.eff.org/press/archives/2008/08/19">dealt a victory</a> to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at <a href="http://defcon.org/">DEFCON 16</a>.  In summary:</p>
<blockquote><p>The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) by enabling others to defraud the MBTA of transit fares. A different federal judge, meeting in a special Saturday session, ordered the trio not to disclose for ten days any information that could be used by others to get free subway rides.</p>
<p>&#8220;The judge today correctly found that it was unlikely that the CFAA would apply to security researchers giving an academic talk,&#8221; said EFF Staff Attorney Marcia Hofmann. &#8220;A presentation at a security conference is not some sort of computer intrusion. It&#8217;s protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing researchers does not improve security &#8212; the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not.&#8221;</p></blockquote>
<p>This sets a good precedent for future cases, and perhaps next time a similar situation arises, a judge will not be so quick to issue a gag order.  It&#8217;s not a happy ending yet though, as the <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/mbta-v-anderson-complaint.pdf">original lawsuit</a> is still in effect.</p>
<p>As Chris Wysopal <a href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">pointed out last week</a>, the MBTA&#8217;s ire is misdirected.  Rather than suing the vendor who sold them the defective system, they sued and attempted to silence the students who discovered the weakness.  This is 2008, not 1988 &#8212; did they honestly think a gag order would prevent the information from reaching the general public?   The DEFCON presentation was already available on the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">Intertubes</a> prior to the injunction being issued, and the MBTA attorneys included a copy of the confidential whitepaper with their filing, thereby making it public.  </p>
<p>I guess you wouldn&#8217;t expect that a transit authority would have paid any attention to the<a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html">Ciscogate fiasco</a> from a few years ago. <a href="http://cryptome.org/lynn-cisco-jpg.htm">That presentation</a> never got out either, did it?  All that taxpayer money the MBTA spent on ridiculous lawsuits and restraining orders could have been put toward fixing the security flaws.  What a concept.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 01:49:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mbta">mbta</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/students publicly">students publicly</category>
      <category domain="http://securityratty.com/tag/defcon presentation">defcon presentation</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/mbta hackers">mbta hackers</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/judge">judge</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/">MBTA Hacking Injunction Lifted</source>
    </item>
    <item>
      <title><![CDATA[Consumer Reports Responds]]></title>
      <link>http://securityratty.com/article/6c99136056552315f93619486db85f54</link>
      <guid>http://securityratty.com/article/6c99136056552315f93619486db85f54</guid>
      <description><![CDATA[Consumer Reports has sent a response to my recent column Security Software Reviews Done Wrong , which criticized their recent story on computer security and review of security products. This statement...]]></description>
      <content:encoded><![CDATA[Consumer Reports has sent a response to my recent column <A href="http://www.eweek.com/c/a/Security/The-Wrong-Way-To-Review-Security-Software/">Security Software Reviews Done Wrong</A>, which criticized their recent story on computer security and review of security products.

This statement is from Jeff Fox, Technology Editor, Consumer Reports:
<blockquote><i>At Consumer Reports, we have always believed that scientific testing is the best way to evaluate products. We also use a statistically-valid survey methodology to measure consumer experiences. In preparing our September security reports, we employed both methods as we have for many decades. Some additional notes on this column:

<ul>
	<li>The story was not, as you state, "filled with data sourced to eMarketer." That service provided just two pieces of data, namely the current number of Internet- and broadband-using U.S. Households</li>
	<li>Using a separate credit card for online transactions avoids having to cancel your main card should fraud occur.</li>
	<li>We test software against modified versions of actual malware because such threats are what security software will often be called upon to recognize on the job.</li>
</ul>

Finally, a note about your claim that Consumer Reports was invited to respond. Your e-mail to us requesting a comment was time-stamped on the same Saturday evening as your column is labeled as having posted. That left fewer than six hours to respond, on a weekend. It would have been helpful to have had more time.</i></blockquote>

It's true, as I said in the column, that I didn't give them much time to respond. I hope I can make up for that some by putting this response out now and including it in the column itself.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/jvhoWp-SQns" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 12:12:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/consumer reports">consumer reports</category>
      <category domain="http://securityratty.com/tag/column">column</category>
      <category domain="http://securityratty.com/tag/measure consumer experiences">measure consumer experiences</category>
      <category domain="http://securityratty.com/tag/products">products</category>
      <category domain="http://securityratty.com/tag/online transactions avoids">online transactions avoids</category>
      <category domain="http://securityratty.com/tag/recent story">recent story</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/september security reports">september security reports</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/jvhoWp-SQns/consumer_reports_responds.html">Consumer Reports Responds</source>
    </item>
  </channel>
</rss>
