Archive for March, 2010

Unencrypted USB Memory Stick Containing Confidential Information Found on the Street

Monday, March 29th, 2010

A USB flash drive memory stick that contained United Kingdom social services’ confidential information about children in care has been found on a pavement in Stoke-on-Trent. Dozens of sensitive City Council documents were discovered on the memory stick, including records of foster carers, family court proceedings, parenting assessments, child custody arrangements and the psychological history of youngsters. This is a clear breach of UK data protection regulations.

UK Government To Create “Secure Facebook” for Voters to Access Government Services …. What About The Phishers?

Monday, March 22nd, 2010

The United Kingdom Prime Minister announced today that the UK Government plans to issue every voter a unique identifier and web page, where they can access government services such as applying for schools, GP appointment booking, claim benefits, get a new passport, pay council taxes and register vehicles.

It sounds like a very progressive move toward e-government, and in general I am very much in favor of this type of initiative, for it can save billions of dollars in paperwork and lost productivity.

However, has the UK government really thought about the security issues that would surround such an initiative? Let’s face it, the Internet continues to get more dangerous every day. There are no standards for strong authentication, malware is rampant, phishing and spear-phishing continues to grow, websites are easily spoofed, DNS is not secure, and the cyber criminal underground continues to grow in size and sophistication.

If the real Facebook, who has over 100 million users, cannot secure itself, how are we to expect the UK Government to create a “secure Facebook” for government services? Even the world’s biggest banks are facing serious security threats from financial malware that infects the computers of users of corporate banking services. Surely the criminal underground will rapidly turn their attention to a UK Government services system. It seems like a “target rich environment” for scammers and identity thieves to prosper.

Zeus Botnets Come Back Online After Takedowns

Thursday, March 11th, 2010

ISP Troyak was hosting up to 248 command and control servers that were controlling computers infected with the Zeus banking trojan. Security researchers got the ISP’s Internet connection disabled, taking the C&Cs offline. However, 30% of these C&C servers have come back online, due to Troyak being recconnected to the Internet by upstream provider RTCOMM-AS of Moscow.