Monday, December 6, 2010

Identity Theft Problem Goes Global

Some people think I go overboard in trying to protect my Social Security number. Several weeks ago I blogged about an audit in the Social Security department which uncovered issues in the process of procuring and installing software. Now West Point Professor Lt. Col. Gregory Ponti, a former Army intelligence officer, released a scathing report about the appalling careless in the military with regards to personal information.

Apparently, since the 1960s, military personnel use their Social Security numbers in everyday settings. Checking out sports equipment? Your Social Security number, please. Yes, sir. Flu shot? We need your Social Security number. Yes, sir. The New York Times reported that "thousands of soldiers in Iraq even stencil the last four digits onto their laundry bags." Although the Department of Defense claimed two years ago that it would limit the use of Social Security numbers, it hasn't happened. Only last week did the Defense Department put an end to using Social Security numbers on military ID cards, and that isn't scheduled for another five months. Moreover, Col. Conti noted, "The farther you get away from the flagpole at headquarters, these policies get overturned by operational realities."

I have never served in the military or navy, but it doesn't take much imagination to think of scenarios in which soldiers the idea of identity theft is the last thing on their mind. But soldiers don't have to be in combat to be at a heightened risk for identity theft. Last June, a Staten Island D.A. indicted a gang who stole the identities of 20 soldiers in Fort Hood, Texas.The theft was traced to a former Army member who moved to New York. The gang made more than 2,500 attempts to use the soldiers' identities.
20 soldiers, 2,515 attempts total = 125 attempts per identity theft victim
It gets worse. It's not just the possible carelessness of a soldier or the bureaucracy of the military. Children as young as 10 years old whose parents are in the military carry ID cards that have Social Security numbers. As every parent knows, young children aren't always careful.

The Defense Department is trying a new campaign to make its personnel aware of the problem but, in my opinion, it's moving at snail's pace. The biggest threat is to those who are stationed overseas. They have no control over what's going on here if someone has their Social Security numbers. If the Defense Department asked me, I would immediately issue new identity cards without Social Security numbers and have the old ones shredded and have the bags of shredded paper hauled away with a military police escort.

Call me paranoid about identify theft, but I don't want to have the burden of proof on me that I didn't authorize credit card charges. I'm proud of my credit rating and want to keep it perfect.

http://www.nytimes.com/2010/12/07/technology/07identity.html
http://smallwarsjournal.com/blog/2010/12/the-militarys-cultural-disrega/

Thursday, November 4, 2010

Audit!

It wasn't anything like an IRS audit. It was far worse. According to an evaluation late last month by none other than the Office of the Inspector Attorney General of the Social Security Administration, two Trojan horses and five keyloggers penetrated all the way onto agency workstations. That's right. Everyone's Social Security number is at risk and everyone is more vulnerable than ever to being a victim of identity theft.

These penetrations came via unauthorized installation of non-standard software, according to the report. Non-standard software doesn't mean it's bad. It just means than it was either not developed by in-house programmers or that it wasn't bought through the agency's regular acquisition process. Still, the story gets worse. Two of the workstation workers knew that the software they were installing were potentially unsafe. The other five installed it unintentionally. The SSA uses Microsoft tools to inventory executable files on Windows machines used by both employees and contractors. This tool scans well over 100,000 devices every week to detect unauthorized software. The policy at the SSA permits non-standard software to be installed as long as agency security officers approve it. Some users simply believed that all they had to do was submit their request to the CIO. OK, they were wrong, but it appears that the CIO simply rubber stamped the request instead of issuing reminders about the standard operating procedures of the department.

This makes me wonder what other protocols exist at the SSA. Who writes the policies? Why aren't they being implemented correctly Do the contract workers have Errors & Omissions Insurance? Are they using other firewalls? How often is testing done to detect vulnerabilities? Are they going to make the CIO accountable for this potential disaster?

Everyone who reads this blog knows that I am a fanatic about my personal security. I'm horrified that seniors' Social Security numbers are on their Medicare cards. Many company websites require job applicants to type in their Social security numbers. I mentioned this to someone in my network who works in HR. She said smart applicant type in 000-00-0000. I give my EIN when I'm hired as a consultant. Unless a job offer is on the table, no prospective employer even knows my real birthday. It's just not something that I'm going to make easily available. Suppose my resume or on-line application is printed out and tossed into a waste paper basket instead of shredded? I also block my credit report so that in case my personal information gets out, along with my address and checking account number (for direct deposit), no one can apply for credit in my name. It's easy to block and unblock and the fee is far less than what it would cost me to deal with my identity being stolen.

As for my birthday, just send me presents all year long. One of these days you'll get it right!

http:www.ssa.gov/oig/ADOBEPDF/A-14-10-21082.pdf

Wednesday, October 27, 2010

Uh, Oh. And It's Election Time.

Republican, Democrat, Independents, Tea Party supporters, coffee drinkers and anyone in IT security all agree on one thing: cyberscurity is critical. That said, Andrew McLaughlin, White House Deputy CTO said that the multi-jurisdictional, multi-stakeholder certificate-based web browsing model poses a problem that the government can't fix.

"Government can't fix it and government shouldn't fix it," he told the New America Foundation. "So this is not an area where public policy is going to be able to waltz in with a thunder set of regulations, or some kind of rule set perpetrated down through the system by an authority -- it's just not going to happen."

Uh, oh. Normally phrases that tell businesses that they don't have to worry about regulations bring out loud cheers. Not so in this case, even though he added the magic words most business leaders love to hear. "You don't want government to try to be your front line. We have a history of screwing things up."

Cybercrimes are growing and every business that has been a victim wants the government to be its front line, side line and back line. Hackers will not stop trying to break to bank accounts. They don't do it for fun. They do it for one reason only: quick money and lots of it. If the government takes a back seat, it's definitely going to screw up. There is only one justification for government: and that is to protect it citizens -- all of them. Businesses of all sizes are vulnerable. Many large corporations, including big banks, have had their data hacked into and possibly (read: probably) compromised. Ditto for a consortium of hospitals in New York City. Cybertheft has surpassed half a billion dollars, double from the year before. Ari Schwartz, senior Internet policy advisor at the National Institute of Standards and Technology notes that the Internet is comprised of "voluntarily interconnected networks" and one organization's lax practices cane make the entire network vulnerable, even if all the other parties are up to snuff on security. Nevertheless, Mr. McLaughlin is throwing his arms up because it's difficult to detect the weak link among the players, jurisdictions, standards, hardware and physical interconnections that allow browsing. Hey, wasn't President Obama vocal about going almost completely digital, including medical records? It's ironic that when he ran for office, his opponent, John McCain was living in static black and white, totally computer literate. (At least he's now tweeting.)
Anyway, the last I checked, robbery is robbery, no matter how it's committed. You wouldn't want your local government to announce that the police department isn't going to protect you from robber because it's not the government's job. Tell us again why the government shouldn't be the front line, Mr. McLaughlin? Maybe you should have a web chat with Mr. Schwartz.

Monday, October 18, 2010

Identity Theft Protection Week

October 17-21 is Identity Theft Protection Week. This is a problem that costs individuals and companies millions of dollars each year. Moreover, for an individual, it's hell. Many people whose homes or cars have been robbed describe it as having felt raped. Identity theft is similar, even if the victim did not come home to drawers that were left open after being rummaged through. Identity theft is like having your personal mail and diaries read. The perpetrator need only know four basic things -- your name, address, date of birth and Social Security number -- but those four things are more than you want him or her to know. That perp can drain your savings and damage your credit score.

No reputable business wants to let that happen, but it does occur because the powers might be so determined to keep costs down that mid-level decision-makers choose not to upgrade their security. In the medical community, it's worse. Hospitals are usually non-profit entities, but they run on thin margins even if they are, for all practical purposes, making money. Most private practices don't make huge profits because they have at least one receptionist, one nurse, one medical secretary and one billing clerk. There is no consensus on Electronic Medical Records -- say, the Microsoft Office equivalent that's the standard in the industry. Even though the system for EMR is about $10-12K, many doctors are reluctant to put the money into it, especially if they are going to have to change in a few years.

Note to anyone who does get electronic records: When asking for medical information by e-mail, make sure it is encrypted. Standard e-mail is not protected by PHI (Personal Health Information) compliance standards. Chances are, those e-mails won't contain items that the identity theft perp wants, but there is no reason why anyone other than immediate family or health providers should have information about your personal health.

Thursday, October 7, 2010

Mergers and VDR

It's not uncommon for people to lose their jobs when a merger between two companies occur. From a business standpoint, it makes sense to consolidate some jobs. But management should think hard and long before making decisions to cut staff in some areas, particularly when it comes to Virtual Data Rooms. Here are some of the issues that I see:

1) Different companies probably have different levels of security. Staff members of both IT departments should compare every level of security. For example, it's a well-known fact that banks own shares in each other, as do insurance companies. Let's say that a regional bank merges into another regional bank. The bank with the more advanced IT security may or may not be the one that swallowed the other one. If its IT security is vulnerable, there could be a major problem because often computer systems are changed.

2) Software requires licenses. In an effort to save additional costs, the dominant company may not want to spend money upgrading security or buying additional licenses for software.

3) No one really knows what's going to happen once Obamacare takes effect. The president has talked about having all medical records go digital, but the truth is that hospital computer systems are often incompatible with each other. In addition, many doctors are reluctant to go digital because of the cost and the fact that there is no standard, like Microsoft Office for administrative office work.


Most lawyers use MS, but there are some that still use WordPerfect. If two lawyers can't send each other documents that are readable by their systems, imagine what it would it be like if two financial or insurance firms merged and their security was incompatible. It's an invitation to a security disaster.

Right now I'm doing some research on ShareVault, a leader in Virtual Data Room products. Supposedly, the company has the experience of handling billions of dollars in transactions. If anyone has experience in it, please contact me and let me know your thoughts.

Sunday, October 3, 2010

Stop, Thief!

I just came across this frightening and interesting statistic: online fraud more than doubled to $559.7 million in 2009, up from $255 million stolen in 2008.

This should come as no surprise. Online purchases are a way of life. Just try buying some ordinary things, such as tires or wedding gifts at stores. Hardly anyone keeps inventory at each store, so you have to pay for things in advance and, preferably online. Moreover, as apps have become more popular, guess what? If they're not free, you need to pay for them by credit card.

In theory, it is very easy to detect fraud and to prevent future fraud with a sound strategy. But that costs money and most companies are not willing to part with it if it doesn't bring in immediate revenues. If you are a small business owner, you may not have much budget to combat fraud through the use of intrusion detection systems, but here are things you can do:

  • Look for unusual account activity.
  • Call customers to notify them if you suspect there is a problem. Give them the option of verifying their account activity before they receive nasty surprises on their statement. It will save you a lot of angry calls later.
  • Arrange to have all revenues go in a deposit only account. You would be surprised that company employees innocently give away wiring instructions which have bank routing numbers and your company's account number to anyone who calls. It is easy for a thief to take money out once he or she has your company's account number.

You need to take this evolving security threat seriously or everything you worked hard to achieve will vanish.

Tuesday, September 28, 2010

Virus Alert - For Real

We all get e-mails from well-meaning family members and friends. A huge virus is going around. Don't open this or your hard drive will be destroyed.

But something really is going around. Three different people I know were affected by a virus that cracked their free e-mail account and then sent out e-mails with their address books with a link to a website. Social media sites, such as twitter.com, have also been affected by this virus. The link contains a virus that reads both Outlook and proprietary address books (such as that of AOL) and send out e-mails.

How do you prevent it? Use a complex password and change it often. When you create or change your password, use upper case and lower case letters as well as numbers and punctuation, such as underscores or dots). Another good idea is to create an e-mail address on a free e-mail service and use this e-mail for all your junk e-mails. Finally, keep your spam filter on high. Somehow, e-mails from disreputable people and companies will get through, but it's one of the best measures you can take.

Speaking of hacking, some high profile hospitals in New York City admitted that patient data was compromised. Somehow it got on an open server. Hospital officials claim that no information was used inappropriately, but that remains to be seen. The real danger is not that someone is going to sell information about a celebrity's health problems to the National Enquirer, but that patients are at risk of identity theft. All a perpetrator needs is a name, address, social security number and date of birth. For a while it was available on an open server at large hospitals in one of the biggest cities in the nation. This is why they need to hire experienced security analysts and keep up to date on security software.

Imagine if there were a virus that sucked out a hospital's patient database. If that hospital were in a large city where people go to for the top specialized care, identity theft would be made easier and more widespread than ever. If you can, give only the last two or four digits of your Social Security number when asked for it by a doctor's office or medical institution. Don't make it easier for local amateurs to steal your identity. You don't know how safe your doctor's computer system really is.