Monday, June 9, 2008

Here Phishy Phishy: Another Phishing Example

I've changed the original site name in this email - it is typically in capital letters, and is the domain of the user the email was sent to.

Giveaways this time? The capitalized domain, the request for password, date of birth, and country, the thank you, signature, and the warning code, as well as the headers showing a non-local email origin.

The good news is that most users won't fall for a phishing email like this - but I still see users fall for some of the more sophisticated bank and Paypal scams.

Dear YOURSITE.COM Email Account Owner,

This message is from YOURSITE.COM messaging center to all YOURSITE.COM email account
owners. We are currently upgrading our data base and e-mail account
center. We are deleting all unused YOURSITE.COM email account to create more
space for new accounts.

To prevent your account from closing, you will have to update it below so
that we will know that it's a present used account.

CONFIRM YOUR EMAIL IDENTITY BELOW

Email Username : .......... .....
EMAIL Password : ................
Date of Birth : .................
Country or Territory : ..........

Warning!!! Account owner that refuses to update his or her account within
Seven days of receiving this warning will lose his or her account
permanently.

Thank you for using YOURSITE.COM!

Warning Code:XXXXXXXXX

Thanks,
YOURSITE.COM Team
YOURSITE.COM BETA

PGP announces Mac full disk encryption

Macworld writes that PGP has announced their MacOS full disk encryption product with a July release date for PGP Whole Disk Encryption 9.9. Not quite here yet, but close!

Friday, June 6, 2008

Why My Printer Received a DMCA Takedown Notice

Michael Piatek, Tadayoshi Kohno, and Arvind Krishnamurthy of the University of Washington have released a very interesting research paper titled "Challenges and Directions for Monitoring P2P File Sharing Networks". They studied P2P clouds and monitoring methods, and succeeded in getting takedown notices sent to spoofed IPs and IPs of hosts that were not actually sharing files (but which did send in queries). The paper is well worth a read for staffers who have to deal with DMCA takedown notices, and will likely be of interest to those who are dealing with legal cases dealing with P2P based copyright infringement.

The New York Times' BITS section covered the article today as well.

Thursday, June 5, 2008

Cell Phones and Privacy: Is Location Data A Risk?

Nature.com's recent coverage of the work done by a team from Northeastern University raises some interesting questions.

By monitoring the signals from 100,000 mobile-phone users sending and receiving calls and text messages, a team from Northeastern University in Boston, Massachusetts, has worked out some apparently universal laws of human motion.
This becomes a bit more scary in context - readers may remember the AOL search data scandal from 2006. As cell data is made available for research, probably without the knowledge of individuals, and without the opportunity to opt out, the same techniques that the New York Times used to hunt down searchers might be used to track down individual cell users. Would cell users turn their cells off if they knew they would be tracked and used for research when they go places they might not want others to know about?

What would you think if you were one of those whose data was used?
Barabási and his colleagues teamed up with a mobile-phone company (unidentified to protect customers' privacy), who provided them with anonymized data on which transmitter towers had handled the calls and texts for 100,000 individuals over the course of 6 months.
Does this protect the users? Or does it protect the company?

Update: CNN's article does a good job of discussing the researcher's take on privacy issues, as well as the ethical and privacy concerns third parties have raised.

Wednesday, June 4, 2008

Security Certifications Hold Value While IT Certifications Drop

EWeek's Deb Perelman notes in a recent article that compensation for those with IT certifications has fallen for the 7th straight quarter, but that security certifications are holding their value:

Foote found some exceptions to the decline of certifications as well, but only in the security arena, due to its heavily technical nature.

"Security is a deeply technical domain and certification is an important qualification in areas where technical skills dominate," he explained.


Will security certifications see a similar drop? It seems that as security becomes more of a commodity in the IT space that we will see a similar devaluing for the certificates and an increased focus on the skillsets and experience. Certificates will continue to be useful in technically focused positions, or those that need some basic form of filter for candidates. They will also continue to help mark out those candidates who are interested in continuing education.

Tuesday, June 3, 2008

Did you check "Yes" to "Terrorist"?

The BBC covered the US visa waiver program, which includes a form that asks about prior involvement with terror activities:

A Homeland Security spokesman said the new registrations would require the same information as the I-94 card, which is currently filled out by visitors to the US and turned in to customs on arrival in the country.

That information includes passport number, country of residence, and any involvement in terror activities.


This seems like a control that might cause more mistakes than benefits, or which could lead to interesting information based exploits. Of course, many forms ask for criminal record, so perhaps being involved in terror activities will also become a common checkbox on government forms. After all, screeners are identifying shirts with guns on them and jewelry in the form of guns as prohibited items.

Does a mistake on this form enter you as a terrorist in a database? How would you remove such a mistake, or prove that it wasn't you? Worse, can others submit a form in your name with "yes" checked?

Saturday, May 31, 2008

Anatomy of a Paypal Scam Email

I'm often asked what a typical Paypal email scam looks like. Today's email included a pretty standard sample. What should let a layman know that this is a scam?


  • The account that received the email isn't one with a PayPal account.
  • PayPal typically won't send emails with a subject like "Account limited"
  • The email is addressed to "PayPal Inc. account holder" rather than to a specific name. PayPal knows who their account holders are.
  • The URL included is not on Paypal's site (it is, however, not the real URL).
  • The email changes topic from screening that requires more information to unauthorized access.
  • The email requests that users "upgrade" their account with more information.
  • Department is misspelled in the closing greeting, and referring to the group as the "PayPal Inc. Account Departement." is suspicious.


For the more technically adept users, I recommend reading headers. Those show interesting things like:


  • A from address of "PayPal." which is "service@paypall.com" - yes, two l's.
  • A source IP that doesn't resolve to PayPal: "from 64-60-103-180.static-ip.telepacific.net (HELO User) (64.60.103.180) by ns1.4thframe.com with SMTP; 30 May 2008 14:14:13 +0200"


At this point, many anti-spam systems will have flagged the message and will have tossed it - that's lucky for us, although people do still fall for the messages.

Without further ado, the message itself:

Dear PayPal Inc. account holder,

PayPal is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience.

*Why is my account access limited?*

Your account access has been limited for the following reason(s):

We have reason to believe that your account was accessed by a third party. Because protecting the security of your account is our primary concern, we have limited access to sensitive PayPal account features. We understand that this may be an inconvenience but please understand that this temporary limitation is for your protection.

(Your case ID for this reason is PP-0XD2-0XBC-0XDA-0X37.)

*How can I restore my account access?*

*Please visit the Resolution Center and complete the "Steps
to Remove Limitations."

Completing all of the checklist items will automatically restore your account
access.

Be aware that until we can verify your identity we will have no other liability for your account or any transactions that may have occurred as a result of your failure to upgrade your account as instructed above.

Sincerely,
PayPal Inc. Account Departement.