Will this reduce the amount of spam? I do not think so: 419 scams are almost neglegible in my spambox. However, if they actually shut down the scammers, it might help Nigeria's internet reputation, which might help Nigeria's economic development.
Sunday, 25 October 2009
Nigeria Closes down Spammers
The Nigerian Anti-Fraud commission EFCC states on its website that they started an operation against spam that has already resulted in the termination of 800 web sites. Nigeria is the home of the 419 scam emails where people are promised a substantial amount of money from questionable origin if the make some advance payments.
Sunday, 18 October 2009
Kaspersky wants to end Internet Anonymity
In an interview with zdnet Asia Eugene Kaspersky suggests to put an end to internet anonymity. He says "I'd like to change the design of the Internet by introducing regulation--Internet passports, Internet police and international agreement". Well, first this won't happen because it would be way to expensive. Even if an established system like OpenID would be used as the source of the identity management required here all ISPs and website operators would have to adopt their software. Second, it should not happen because anonymity is sometimes a part of freedom.
However the present system of website logins is a mess and should be fixed by using a voluntary identity management system.
Cnet reports that Comcast have a similar initiative where they disconnect users with infected PCs. This is also problematic, but it sounds a little better becasue it's good internet citizenship not to act as a springboard for internet criminals.
Realistically spaking, the responsibility for PC security remains with the vendors, not with the users as long as the systems are too complicated to be fully managed by the end users.
Labels:
privacy,
single sign on,
society,
web security
Sunday, 11 October 2009
Secure Online Banking
The Swiss company Crealogix has announced the CLX.Sentinel, a USB device which promises secure online banking. As I was with them team that developed it, it's no surprise that I like it.
But here is why: It uses a smart card to verify the user identity and set up a SSL connection to the bank. Thus, man-in-the middle attacks are prevented. As an additional security benefit it uses an internal list of legitimate banking sites so that phishers can't use the null prefix issue. The CLX.Sentinel won't connect to anything that's not on its list, so the browser infections are next to impossible.
The software is installed on the flash memory inside the token, so it can't be patched and it contains countermeasures against debugging and code injection at runtime.
I believe that this amount of countermeasures is needed nowadays.
Labels:
browser,
e-commerce,
smart cards,
web security
Tuesday, 6 October 2009
The URLZone Trojan
RSA Fraud Action Research Lab publish an article about a online-banking trojan called URLZone. This trojan has an interesting new feature:
It can determine if whether requests for new "mules" come from a botnet member or a security company. If the request comes from a security company or researcher, the server will respond with account data of innocent people, thus protecting their mules from prosecution.
The accounts are people who received a legitimate transfer from a URLZone victim before.
'Mules' are the people who receive payments from infected PCs and forward them to the gangster's accounts. That's money-laundering, and not only criminal, but also quite dangerous. The fake mule responses will put innocent people under suspicion of money laundering.
Sunday, 27 September 2009
Google suggest Online Payment with Single Sign On
Google has suggested a micropayment System to the Newspaper Association of America. How is this asecurity issue? They suggest to combine it with a Single Sign On System also operated by Google.
I welcome paid-for Internet content because I believe that advertising As the only Business model for online content endangers the journalistic quality of the articles. The dependency on the advertisers leads to articles written for the advertisers, not for the readers. Also, I hope that flash and popups will become less intrusive if publishers get an additional revenue stream.
The bad news is that Google would know even more about their users, in particular if they operate the micropayment system.
I really would prefer having a small micropayment token connected to my computer that performs Single Sign On and micropayment operations under my control.
I welcome paid-for Internet content because I believe that advertising As the only Business model for online content endangers the journalistic quality of the articles. The dependency on the advertisers leads to articles written for the advertisers, not for the readers. Also, I hope that flash and popups will become less intrusive if publishers get an additional revenue stream.
The bad news is that Google would know even more about their users, in particular if they operate the micropayment system.
I really would prefer having a small micropayment token connected to my computer that performs Single Sign On and micropayment operations under my control.
Labels:
e-cash,
e-commerce,
privacy,
single sign on,
society
Sunday, 13 September 2009
Linux Botnet
The Register reports a new linux server botnet originally reported here. It is not yet clear how the servers are infectected. The purpuse of these servers is to serve malware from an additional webserver installed on listening on port 8080. It seems to me that people look at their web forum security again very closely: Not only can be used to exploit a server, but also if it is possible to post links at public discussion sites it is also possible to post links to such malware.
Labels:
e-crime,
malware,
server security,
web security
Sunday, 6 September 2009
Quantum Computer Chip
One popular use for the quantum computer is the factorization of big numbers. If one could factor a big number as quickly as it can be multiplied from its prime components the RSA algorithm would be broken. Theory says that this should be possible, but no practical implementation has been seen so far. The most important obstacle is the quantum noise that leads to random changes in quantum states.
Researchers at the university of Bristol have found a way to cram a complete quantum computer on one silicon chip. However, the largest number they can factor right now is 15. Also, the peripheral devices still fill up a complete desktop.
In order to factor larger numbers the quantum computer needs more degrees of freedom, which are called 'qbits'. Miniaturizing the computer might help with increasing the number of qbits.
Subscribe to:
Posts (Atom)