Re: [Full-disclosure] [botnets] [funsec] Haxdoor: UK Police Count 8, 500 Victims in Data Theft (So Far) (fwd)



On Mon, 30 Oct 2006, bf wrote:
"So, knowing full-well security is out of our hands, and relies on the
security of our users. Knowing full-well that the same technology can be
used to bypass 2-factor authentication, how do organizations handle their
own security, if they are to have clients?"

Organizations make attempts to protect the resources immediately under
their control and the losses incured by end user compromise are
written off as a loss. Indeed, this sort of loss is so hard to
quantify that the end user and "affected organization" (Bank for
example) have no way of knowing how or why the account or identity of
the end user was ever compromised.

IE:
End user: "Wow my identity was stolen, how did that happen?"

Bank: "No problem, we'll issue you a new card/account/what-have-you.

But you know this already.

It is quantifiable (sp?), if the bank know it was stolen by certain means
already.

Gadi.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • RE: Security and the Under 30 User
    ... ages, sexes, colors, creeds, succumb -- even the holiest of holy network ... I've been into IT security since I was 12. ... I have friends about my age that have had their bank information ... crowd's attitude towards IT security. ...
    (Security-Basics)
  • RE: Security and the Under 30 User
    ... warming people to the need for security. ... ages, sexes, colors, creeds, succumb -- even the holiest of holy network ... I have friends about my age that have had their bank information ... crowd's attitude towards IT security. ...
    (Security-Basics)
  • Online Banking: How Safe is Your Money?
    ... Online banking is suffering through a withdrawal phase. ... who bank online plan to do so less often because of security concerns. ... Web site being spoofed by a fraudulent facsimile that would trick them ...
    (comp.dcom.telecom)
  • Re: Security and the Under 30 User
    ... I've been into IT security since I was 12. ... I have friends about my age that have had their bank information ... being transmitted across the network, they still think that out of the ... crowd's attitude towards IT security. ...
    (Security-Basics)
  • howto protect my private data - env. and setup advice needed
    ... I have some security fears. ... "bank" user have private data in his private folders. ... Installation procedure will install: ...
    (microsoft.public.windowsxp.security_admin)

Loading