Identify Theft

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

7 comments

Comments 1 - 7 of 7 previous next Post a comment

  • + dherar08 Dherar 10 months ago
    great presentation,can U please kindly email me with that presentation..... thanx.
    bin_d3aij@hotmail.com
  • + guest74e2fe guest74e2fe 2 years ago
    Very good material, Jorge. Very informative and usefull information. congratulations.

    Anchises (Brazil)
  • + slide911 slide911 2 years ago
    base on your slideshow, and i have conclusion....'nice main idea'.so,can U please kindly email me with that presentation.......thx......akhyar.teach@gmail.com
  • + grahairs Graham Bennett 2 years ago
    Very informative Jorges! Thank you for sharing this with us, Graham
  • + guest95b3ff guest95b3ff 2 years ago
    Great.. thanks u for posting such a great presentation to aware the public about security. G.Binu
  • + mvc000 mvc000 2 years ago
    Excellent awareness show .... congragulations on this professional piece of work Jorge
  • + guestfb27d1 guestfb27d1 2 years ago
    Bravo Jorge;



    Very well done, and up to date...



    Theo

Post a comment
Embed Video
Edit your comment Cancel

14 Favorites & 2 Groups

Identify Theft - Presentation Transcript

  1. Identity Theft Jorge Sebastião Founder and CEO
  2. May 2006 – Veterans Administration laptop with personal information on 26.5M veterans is stolen. “Total losses could top $500M.” – VA Secretary Nicholson Jan 2007- Hackers stole data from at least 45.7 million credit and debit cards at retailer T.J.Maxx – total costs could exceed $1.0B May 2006 – CIO, CSO fired Ohio University 137,000 student accounts compromised
  3. More Stats
    • 2007 Breaches ID Theft Resource Center as of: Oct 2007
    • Total Breaches: 305
    • Records Exposed: 76,734,967
  4. News
  5. More sophisticated Attacks
  6. What happens when Hackers grow UP? Criminals
  7. ATM Attack-1
  8. ATM Attack-2?
  9. Skimmer • Capacity > 2500 credit cards • 40 hours Operations • Panic button can deleted information to avoid prosecution. • Cost = $500
  10. Credit Cards for Sale
  11. Identity Theft brokers
  12. What Is Identity Theft?
    • Acquisition of key pieces of someone’s identifying information to impersonate them.
    • Includes:
      • Name
      • Address
      • Date of Birth
      • Social Security Number
      • Driver Licenses
      • Student Memberships
      • Mother’s Maiden Name
      • Credit Card Number
      • ATM PIN’s
      • Bank Account Numbers
  13. ID Theft– The old way
    • Stolen wallets + purses
    • Pickpocket
    • Stolen mail (snail mail)
    • “ Dumpster Diving” and “Trash Rips”
    • Telephone scams
  14. ID Theft– New Way Phishing / Pharming Hijack/Skimming
  15. Online Applications Role **2007 top 5-WOASP attacks
    • Online skimming
    • Mal-ware
    • Key loggers
    • Social Engineering
    • Wireless phishing
    • Botnets
    • Spyware
    Victim's browser sends a pre-authenticated request to a vulnerable web application, which then executes hostile actions in the browser. Cross Site Request Forgery (CSRF) 5 Attackers can manipulate information exposed as a URL or form parameter without authorization. Insecure Direct Object Reference 4 Include hostile code and data in file accepted by web application, resulting in devastating attacks, such as total server compromise. Malicious File Execution 3 Injection occurs when user-supplied data is sent to an interpreter as part of a command or query. Injection Flaws 2 XSS flaws occur whenever an application takes user supplied data & sends it to a web browser without first validating that content. Cross Site Scripting (XSS) 1
  16. Social Engineering
  17. Social Engineering
    • … 70 percent of those asked said they would reveal their computer passwords for a …
    Schrage, Michael. 2005. Retrieved from http://www.technologyreview.com/articles/05/03/issue/review_password.asp?p=1 Bar of chocolate
  18. People is the biggest problem?
  19. WHAT CAN YOU DO?
    • DETER - Deter identity thieves by safeguarding your information
    • DETECT – Detect suspicious activity by routinely monitoring your financial accounts and billing statements
    • DEFEND - Defend against identity theft as soon as you suspect a problem
  20. DETER = Protect
    • Shred all documents. Cross shred is preferred.
    • Do not carry extra credit cards.
    • Don’t give personal information over the telephone, or internet.
    • Remove mail promptly from mailbox.
    • Deposit outgoing mail at Post Office.
    • Don’t leave receipts at the point of sale.
    • Memorize pins, social security numbers, and passwords.
    • Sign all new credit cards.
    • Match receipts to monthly billing statements.
    • Notify Financial Institutions in advance of address changes.
    • Keep your information secure
  21. DETECT
    • Be alert
      • Mail or bills that don’t arrive
      • Denials of credit for no reason
    • Inspect your credit report
      • Law entitles you to one free report a year from each nationwide
      • credit reporting agencies if you ask for it
      • Online: www.AnnualCreditReport.com by phone: …
      • or by mail: …
    • Inspect your financial statements
      • Look for charges you didn’t make
  22. DEFEND = Respond
    • Place a “Fraud Alert” on your credit reports by calling any one of the
    • three nationwide credit reporting companies:
      • Equifax
      • Experian
      • TransUnion
      • Review reports carefully, looking for fraudulent activity
    • Close accounts that have been tampered with or opened fraudulently
    • File a police report
    • Contact the Federal Trade Commission
  23. Online Resources
  24. Old ID Systems ID CARD CPR CARD Driving License
  25. Replaced by Modern ID Systems
    • Driving License
    • CPR CARD
    • ID CARD
    Storage CHIP All external information is duplicated In the Chip in addition to other data of the combined cards.
    • ELECTRONIC SECURITY
    • encryption
    Biometrics
  26. Biometrics also victim
  27. Banks Credit Card Technological Safeguards Truncation of Account Numbers CISP Verified By Visa Issuers’ Clearinghouse Advanced Authorization CVV Address Verification CVV2 Technology Innovations
  28. Free Services to customers
  29. End User Awareness
  30. Questions? [email_address]

+ Jorge SebastiaoJorge Sebastiao, 2 years ago

custom

5701 views, 14 favs, 8 embeds more stats

Identity Theft Presentation at Infosec Cyprus 2007. more

More info about this document

© All Rights Reserved

Go to text version

  • Total Views 5701
    • 5548 on SlideShare
    • 153 from embeds
  • Comments 7
  • Favorites 14
  • Downloads 0
Most viewed embeds
  • 113 views on http://www.esgulf.com
  • 16 views on http://4sec.blogspot.com
  • 9 views on http://nipissinguais2008.pbwiki.com
  • 7 views on http://anchisesbr.blogspot.com
  • 5 views on http://cyberinsp.blogspot.com

more

All embeds
  • 113 views on http://www.esgulf.com
  • 16 views on http://4sec.blogspot.com
  • 9 views on http://nipissinguais2008.pbwiki.com
  • 7 views on http://anchisesbr.blogspot.com
  • 5 views on http://cyberinsp.blogspot.com
  • 1 views on http://blogtaller.nirewiki.com
  • 1 views on http://209.85.171.104
  • 1 views on http://translate.googleusercontent.com

less

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel
File a copyright complaint
Having problems? Go to our helpdesk?

Categories