Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Friday, May 19, 2017

HSBC's "Secure" Voice Recognition System Sucks


The BBC have managed to shoot holes in HSBC's claims that their voice recognition system is secure.

BBC Click reporter Dan Simmons set up an HSBC account and signed up to the bank's voice ID authentication service.

HSBC says the system is secure because each person's voice is "unique".

However, HSBC let Dan Simmons' non-identical twin, Joe, access the account via the telephone after he mimicked his brother's voice.

The bank said it would "review" ways to make the ID system more sensitive following the BBC investigation.

HSBC introduced the voice-based security in 2016, saying it measured 100 different characteristics of the human voice to verify a user's identity.

Customers simply give their account details and date of birth and then say: "My voice is my password".

Although the breach did not allow Joe Simmons to withdraw money, he was able to access balances and recent transactions, and was offered the chance to transfer money between accounts.

To add insult to inury, HSBC allowed him seven attempts to mimic his brother's voiceprint and get it wrong, before he got in at the eighth time of trying!

Tuesday, December 18, 2007

Norwich Union Fined

The Financial services Authority (FSA) fined Norwich Union (NU) £1.26M for failing to protect its customers against fraud. The fine is the largest ever issued by the FSA in relation to security lapses and fraud.

The Charges

Norwich Union Life failed to take reasonable care to both assess where its financial crime risks lay and establish adequate procedures and controls to manage those risks and respond to the frauds in an appropriate and timely manner once they had become apparent.

How many policyholders were affected

- Over 632 policies were targeted by the fraudsters.

- There were 74 fraudulent surrenders amounting to approximately £3.3M in total.

Fraudsters obtained publicly available information on people who were directors of a business from Companies House, including their full names, addresses and date of birth. They phoned NU's call centres and used the data to answer security questions, alter addresses and bank account details, and surrender the policies.

Will the FSA also be fining HMRC for losing data belonging to 25 million people, and putting their personal security at risk for the next 20 years?

Wednesday, November 21, 2007

HMRC's Staggering Incompetence

The HMRC and Treasury finds itself further in the mire today, as more details emerge about the colossal failures of security in respect of the loss of child benefit data.

Yesterday I wrote that 15 million people were affected, in fact the figure is a mind numbing 25 million.

The discs seemingly were only password protected, they should in fact have been encrypted. This means that the data will be very easy to access, and it is reasonable to assume that the underworld is now looking for these discs.

Security experts have lambasted HMRC for its incompetence.

Tom de Jongh, product manager at SafeBoot, said:

"Basic policies were ignored. It appears that the fundamental policies upon which the National Audit Office and HMRC operate are flawed and it is no wonder that this breach has occurred.

The Chancellor freely admits that NAO and HMRC broke clear procedures, but that will not reassure the millions of families that are praying their financial details don’t get into the wrong hands
."

Brian Spector, general manager for content protection group at Workshare, said:

"It is staggering that an organisation responsible for the data of over 25 million child benefit claimants is still copying data onto CDs and not ensuring its full protection through encryption techniques.

It has never been acceptable for businesses or government departments to lose data, but in today’s information society, the flagrant disregard for the protection and security of this type of data is not acceptable.

The money invested in IT by the UK government must now be prioritised on security to ensure that the data of those the government serve – the public - is secure and protected
."

Jamie Cowper, director of European marketing at PGP Corporation, said:

"These discs should never have been transported in the first place – information of this type should only be transmitted using the strongest security protocols available such as encrypted batch transfer – but more to the point, these details should not have been stored in this medium.

Discs are easy to lose, but difficult to protect. This type of information should only be stored on formats where the data can be encrypted transparently, so that it remains protected wherever it resides, and whether at rest or in motion
."

An ex member of the HMRC spoke anonymously to the BBC:

"I wasn't surprised in the least when I heard the news. The problems with Child Benefit are only the tip of the iceberg.

Morale is non-existent. Mistakes happen continuously. Rooms full of unopened post are not uncommon.

Arbitrary individual hourly targets meant that people cut corners. It doesn't matter if you make mistakes because you won't be held accountable.

There is no trust between management and staff.

You are like a number. It is utterly demoralising.

I've spoken to some of my former colleagues about the Child Benefit blunder, and they are utterly apathetic. It's just one thing on top of another.

People hate it, but after 20 years or whatever they feel they can't get a job in the private sector.

Something like this was going to happen sooner or later
."

The above is not only a damning indictment of HMRC but also an indictment that applies equally well to all other bodies in the public sector, and exposes the consequences of ten years of Brown's rule at the Treasury.

The damage he will do to the country as Prime Minister, were he to remain in office for that long, is mind boggling.

Tuesday, November 20, 2007

HMRC Lose Data

Congratulations to HMRC who have succeeded in losing data relating to the child benefit records of 15 million people.

That's quite an achievement, even by HMRC standards of incompetence.

Chancellor Alistair Darling, who is having less than a pleasant week (what with the Northern Rock debacle etc), is making a statement to MPs.

The confidential details were contained on a computer disc, and is understood to have been lost in transit.

HMRC's chairman, Paul Gray, has resigned.

Seemingly the Treasury and government have known of this for the past ten days. One might ask why it is only now that they have chosen to share this knowledge with the rest of us.

The answer is simple, the news leaked.

Revenue and Customs claims that it does not think that the records (names, addresses, date of birth and bank accounts) have fallen into the wrong hands.

This statement is of course complete nonsense, given that they don't know where the records are. Quite why they assume that the public are so naive and gullible as to believe their reassurances is beyond me, and adds insult to injury.

The Metropolitan Police have confirmed they are "making inquiries" into the discs.

This is the same government that would have you believe that data stored on their beloved id cards would be safe in their hands!

Thursday, June 21, 2007

Credit Card Fraud Decriminalised

Quite a row is breaking out over the revelation that the Home Office has lessened the criminality of credit card fraud.

Victims of credit card fraud can no longer report it directly to the police.

New rules came into force in April, under these rules it is now the responsibility of banks to decide which offences to pass on for investigation.

Given that the banks will want to maintain their reputation for good security, and effective fraud controls, it is unlikely that they will be incentivised to report every single id theft.

Cynics also suggest that the new rules are a method of reducing the crime figures.

In 2006 approximately £430M was lost as a result of credit and debit card fraud in the UK last year.

A Home Office spokesman confirmed that discretion had been handed to the banks, to ensure the police could concentrate on cases "more likely to result in a positive outcome.

The Government is determined to tackle the problem of card fraud, whether the account holder is an individual or multi-million pound organisation and we are working closely with finance and retail sectors along with the police to tackle this crime
."

Nonsense, the banks have no incentive whatsoever to report the failings of their security checks.

This is a green light to criminals, telling them that they can commit credit card fraud with impunity!

Wednesday, June 13, 2007

HBOS Loses Customer Data

HBOS's reputation for professionalism has taken another knock, as it emerged that it has lost a disc holding confidential data on 62,000 HBOS banking group mortgage customers.

As if this were not embarrassing enough, it transpires that the disc was not encrypted.

One wonders quite what their internal audit and IT departments are being paid for, if they do not have procedures in place to ensure that confidential data held on discs is encrypted as a matter or course.

Regrettably, for HBOS, this was not the first time that it has lost customer data. There was also a loss of data in March, we are assured that the second loss was "unrelated" because the data had gone missing in a different way.

So that's alright then!

This month's data breach included names, addresses, dates of birth and mortgage account numbers on a CD-ROM sent by HBOS subsidiary Bank of Scotland to a credit reference agency. It was reported missing when the agency did not receive the expected monthly dispatch of information.

The lost data would enable any self respecting fraudster to have a "jolly time" doing what he does best, namely perpetrate identity theft.

An HBOS spokesperson said:

"The disc would usually be encrypted.

Unfortunately, due to human error on this occasion the usual policy was not followed. We apologise to our customers for this
."

As if this were not bad enough HBOS, for some unknown reason, chose to send the data via the Royal Mail's ordinary service rather than a secure service. This invites theft, as the Royal Mail is notoriously prone to theft and losses.

HBOS said:

"That was a mistake on our part."

Quite!

In March, Halifax building society, another HBOS subsidiary, lost a printout containing data on 13,000 mortgages from an employee's car.

HBOS general manager for group communications, Shane O'Riordain, at the time said:

"Lessons have been learned. We are reviewing our procedures as a matter of urgency."

This was the same month in which HBOS, along with 11 banks, was ordered by the information commissioner to sign a formal undertaking to comply with Data Protection Act principles, after dumping customers' personal data in rubbish bins outside their premises.

HBOs now claim the following:

"Lessons have been learned and we have revised our procedures accordingly," he said. "The other incidents ... are all unrelated. One was the theft of a briefcase from an employee (which has been recovered) and the undertaking referred specifically to the disposal of confidential waste."

Given that banks are forever lambasting their customers over their handling of passwords and personal data, this series of events is pretty pathetic.

Sauce for the goose is evidently not sauce for the gander.

Saturday, June 09, 2007

PINsentry

In the war against on line fraud and id theft, Barclays have announced the launch of PINsentry.

Barclays customers who use their online bank account, to set up payments to new third party accounts, will begin using PINsentry devices in the latter part of this year.

The devices will be used together with the customer's normal debit card and PIN, to authenticate their identity at log in and for making certain payments. This will replace the need for passcodes and memorable words.

Over half a million customers will be automatically sent free PINsentry card readers and instructions by the end of the year, with this number increasing further as more customers are added to the service.

Customers who simply wish to use online banking to view their accounts and pay bills to established payees, will be able to continue to use online banking as normal without the need for PINsentry.

It is a good idea, and unfortunately a necessary one. Quite how long it will take for the fraudsters to find a way around the new controls is not clear.

Tuesday, April 10, 2007

Hacking Threat To 5 Million PC's

Research, carried out by the government, indicates that around 5 million UK home computers are open to criminal attack.

"Internet Safety: The State of the Nation" has been published on the government's website www.getsafeonline.org.

The research shows that UK PC owners are making fundamental errors, that expose them to hacking and identity theft.

Tony Neate, managing director of Get Safe Online said:

"Protecting your home PC is a basic part of being safe and secure from the threat of criminal activity on the internet.

The fact that there are millions of households where the virtual backdoor is left wide open for criminals is a real concern – these people risk not only losing their own personal and financial information, but also put others at risk if criminals are able to access an innocent user's PC or internet connection. None of us would ever leave home without locking our doors and windows; by taking a few simple steps we can all ensure that our computers' doors and windows are automatically 'locked' every time they are switched on
."

The research found that:

  • 36% of the UK's 13.9 million home internet-connected PC users – 5 million machines – do not have any form of firewall stopping hackers from gaining access to their computers and using personal information.


  • 46% do not have anti-spyware software.


  • 35% of home PC users said they do not download updates from Microsoft or Apple to ensure that their machines have the latest security updates.


  • Over 10% of the 9 million broadband users in the UK do not have a firewall on their home PCs.


  • 21% households that use wireless broadband for their PCs say that they do not have password protection on their connections. This means that criminals could "take over" their internet connection and use it to send thousands of spam emails, posing as the legitimate user.


  • 25% of home PC users do not have anti-spam programmes which would protect them from "phishing" attacks and other email frauds.


  • Almost 1 million home PC users do not have anti-virus software on their machines.


Nick McGrath, Microsoft and Get Safe Online spokesperson, said:

"Governments and businesses are working tirelessly to counter online security threats but the reality is we're dealing with criminals who use ever more sophisticated methods to attack computers.

Regardless of security measures that have been pre-installed, entirely new and complex threats will continue to emerge.

Prevention is the best defence! For many people today, a PC is increasingly becoming a vital investment for the home and as long as some basic measures are taken from the moment of boot-up and throughout its life-time, it can remain that way
."

You have been warned!

Friday, March 16, 2007

Banks' Behaviour Unacceptable

The Information Commissioner has publicly accused banks, that have left customer details in the street, of an 'unacceptable' breach of the Data Protection Act.

It seems that the ever popular banks, who provide their customers with such "value for money", have been leaving customer account details in waste bins, skips and bin bags outside 11 branches across the country.

Needless to say this exposes the hapless customer to identity theft and fraud.

Deputy Information Commissioner David Smith said:

"It is unacceptable for banks and other organisations to carelessly discard their customers.

It is vital that banks and other organisations take security seriously. If they do not, they not only risk further action from the Information Commissioner but also risk losing the trust of their customers.

Individuals must feel confident that banks and other organisations are safeguarding their personal information
."

The 11 financial institutions that have been named and shamed are:

-Halifax-Bank of Scotland
-Barclays
-Alliance & Leicester
-Royal Bank of Scotland
-NatWest
-Nationwide Building Society
-Co-operative Bank
-HFC Bank
-Clydesdale Bank
-Scarborough Building Society
-United National Bank

Also on the list were the Post Office and the Immigration Advisory Service.

The information publicly discarded by the banks included; names, addresses and bank account numbers.

Nigel Evans MP, chairman of the All Party Parliamentary Group on Identity Fraud, demanded heavy fines for the organisations involved.

Quote:

"It is absolutely unforgivable that these financial institutions have acted so irresponsibly.

They seem to have ignored warnings about the need to keep customer details secure. Quite frankly, I am amazed that this is still going on. It is well known that criminals actively target bins in search of this sort of detail. This behaviour shows a cavalier disregard towards the protection of customers
."

The Information Commissioner's Office has asked the banks and other organisations to sign a formal undertaking to abide by the Data Protection Act in future. If they fail to do so, they would face action leading to prosecution and fines.

The British Bankers' Association said:

"Banks take their responsibilities for protecting customers' personal information very seriously and each bank has secure arrangements for disposing of confidential customer information.

The banks concerned have fully investigated the circumstances and taken appropriate steps to ensure that any weak links in their security practices have been addressed
."

The statement by the Bankers' Association is of course contradictory, what is the point of having secure arrangements if they are not followed?

Pretty pathetic really, it hardly leads one to conclude that the high fees that banks charge for their "services" are justified.