I recently got a call from some close friends with the bad news that their credit card number had been compromised, and the thief had gone on all expenses paid, online spending spree. Thankfully, they are vigilant about watching their transactions and caught it early, thus preventing the worst of the damage. However, it occurred to me that perhaps it is time to take a moment and be a geek on this blog...at least for one post. In general, I try not to allow my work to leak into this holy-of-holies space, but as "cyber" security is what I do for a living, it also feels wrong not to share a few tips with my family and friends. So, you have been forewarned. Read on at your own risk. ;o)
Most of us shop online, at least sometimes. Most of us use a credit or debit card to do so, and we hope that our account data is secure. So do the credit card companies--there are regulations in place like PCI and GLBA that require companies and banks to protect your account data. They are audited on a regular basis by the industry or the government to ensure they are compliant. You'd think then, that stories like this would be less common than they are. What's even worse, these are only the ones we hear about--most of the time, cases like this aren't reported until they reach these kind of grand proportions.
There is a lot of money to be gained in hacking these networks, and many of those in organized crime have figured that out. My point is, that if someone really wants to compromise this data, chances are good they'll be able to do so. That's the reality of network security: they're always making a better bad guy. So how do they do it?
To start with, many of today's new computer viruses are specifically targeting banks and their customers. It's not an exact science--the attacker is hoping to lure you into clicking on a fake link that looks like your banking page and entering your online banking credentials. In reality, you are giving your username and password directly to the bad guy. Or (even more sneaky) the program will just sit there, silently, on your computer and record every keystroke you make...then the attacker can sift through it at their leisure and find your logon/password, which isn't typically difficult to identify.
There are much more sophisticated attacks as well. ATM skimming is a popular one, and as you can see in the video on that link, ridiculously quick and easy. Basically, the bad guy installs a scanner on the compromised ATM that reads your number as you enter your card. Your experience does not change, nor does the bank have any indication anything has happened, but the attacker has your number and pin and can now drain your account. And finally, stories like what happened to TJX and Heartland Payment Systems in the link above, where a savvy hacker broke into their network and stole millions of credit card numbers right off the wire.
So how do you protect yourself? The key is to be informed, and be vigilant (at the risk of having a Harry Potter moment: "Constant Vigilance!"). Here are 10 tips that could save your moolah:
1. Your bank should never send you an email or any type of communication asking you to click a link and login, ever. If you get such an email, DO NOT CLICK THE LINK. If it seems legitimate, call your bank first and verify it.
2. Be careful where you use ATMs. Those in public, unprotected spaces (like airports) could easily be compromised--look for an ATM inside a bank lobby or some other relatively secure and watched area.
3. Do not use a debit card when banking online (use a credit card instead). If a thief has your debit card number, they can drain your accounts before you can stop them. With a credit card, you are at least protected from fraud to the degree you can dispute a payment and won't immediately lose all of your liquid assets.
4. Do not allow online companies to save your credit card information. Most companies will give you the option of "Do you want me to remember your number for future use?". Just say no. Believe me, I've seen these people's security systems.
5. Do not access your online banking from a public computer/kiosk. By this I mean internet cafes, computer labs, etc. These computers are ridiculously easy to compromise--make sure you're only entering this type of information on computers you trust that haven't been out there in the wild.
6. Do not let your computer (or any computer) save your online passwords--as in, NONE of your passwords. Come on, admit it, we all reuse passwords. It's not difficult to find them and try them on other sites. If you're worried about forgetting them, either write them down and put them in a safe location (not your wallet), or invest in a password safe application that will encrypt them for you (then you only have to remember 1 password, not 50).
7. When ordering online, try to stick to well-known vendors that use strong security. Anyone can setup a web page and pretend to sell you something. When I find something I want to buy online, I'll usually go check Amazon.com and see if they sell it as well (plus, I like the free shipping you can sometimes score). Just like you wouldn't give your credit card number to some random dude on the street selling lollipops, don't do the online equivalent.
8. Use strong passwords. Don't use your dog's name. Don't use your birthday. PLEASE don't use anything that even remotely resembles your social security number. A strong password is usually a phrase, and at least 8 characters long with letters and numbers. Something like: IL!keGo@tChz would work fine.
9. Install anti-virus and firewall software on your computers and (most importantly) keep it up to date. Anti-virus software is nearly useless if it isn't downloading its updates daily, because there's always something new out there waiting for you. I like AVG. It's free for personal use, effective, and it scans web pages for basic vulnerabilities.
10. Review your banking transactions regularly. The great thing about online banking is that you don't have to wait for that monthly bank statement to keep an eye on things. The sooner you catch a fraudulent charge, the better chance you have of recovering your money.
Phew! Lots to remember. Unfortunately for you who have gotten this far, this blog post isn't quite done yet. The last important question is: what do you do if you find a fraudulent charge and/or are missing money?
1. Call or visit your bank *immediately*. Tell them you suspect fraud and ask them to mark your accounts accordingly (different banks have different processes). If it was related to your credit card, ask them to freeze that card and send you a new one. Find out what their policies and processes are for recovering lost funds, and start whatever paperwork needs to be done (oh yes, there will be a lot of it) immediately.
2. Change your online banking passwords.
3. Update your anti-virus and run a full disk scan (of all files) on your computers.
4. Take a look at the charges. If they were on your credit card only (especially for an online purchase), it's likely the thief only has your credit card number. Believe it or not, that's good news. Hopefully that means that the rest of your accounts haven't been compromised, though you'll want to keep a close watch. However, if you look at the charge and it appears to be an electronic funds transfer directly from one of your checking or savings accounts, you need to be more concerned. This means that the thief likely has your online banking credentials or is able to impersonate you in some other way and has direct access to your liquid assets. If this is the case, you should consider freezing all of your accounts and opening new ones with new account numbers.
Be warned that it may be impossible to determine the "how" of how all of this happened, if for no other reason than the fact so many companies don't report breaches (and aren't required to, in some cases). If you do find yourself in a situation where you feel your actual accounts (not just your credit card number) have been compromised, you need to call your friendly neighborhood geek. If you've only been doing online banking from your home computer, then it is the most likely source of the problem and will need to be scrubbed down, cleaned up, and examined with a fine tooth comb, as it is likely that you're no longer its only master.
I'm hoping that no one will read this post and immediately go out and close all their accounts and hide their money under their mattress (although in the current economy, you may very well be better off doing so). I will tell you that I still shop online every week, and if you take the precautions above, you will not be an easy target...and just like with any type of crime, it's the easy mark that gets hit first.
Also, feel free to call me if you have questions (or comment if you've had experience with identity or account theft and have something to add!). Geek out.
25 School Lunch Ideas Kids Won’t Get Tired Of
2 weeks ago


2 comments:
I love you. But I don't like goat cheese.
And my captcha is "schmanda".
This is great info. I had my credit card number stolen but thank goodness I check my statments weekly and cought it before the person got out of control and was able to get all my money that was taken back. Its a scary world we live in. Love you all.
Post a Comment