Computers Security Quick Search Engine :
NB:
*For Meaning Use : Meaning of 'WORD' .
*For Download Use : Download ' Product'
*For More Posts About A Subjet Use : Posts About 'WORD/SENTENSE')
Thursday, April 23, 2009
Hackers Test Limits of Credit Card Security Standards
All merchants that handle credit and debit card data are required to show that they have met the payment card industry data security standards (PCI DSS), a set of technical and operational requirements designed to safeguard cardholder information from theft or unauthorized access.
Yet, some of the most notable data breach incidents last year targeted companies that had recently been certified as compliant with those standards, raising the question of whether the standards go far enough, or if entities that experienced a breach are falling out of compliance with the practices that led to their certification.
In a recent hearing on PCI standards at a House Homeland Security Committee panel, experts from the retail sector charged that the entire PCI scheme is only a tool to shift risk off the banks and credit card companies' balance sheets.
"The premise behind PCI -- that millions of retail establishments will systematically keep pace with the ever-evolving sophistication of today's professional hacker -- is just not realistic," said David Hogan, senior vice president and chief information officer for the National Retail Federation.
YOU CAN USE QUICK SEARCH ENGINE IN THE TOP FOR MORE DOWNLOADS OR DETAILS.
Glut of Stolen Banking Data Trims Profits for Thieves
For a glimpse of just how many financial records were lost to hackers last year, consider the stats released this week by Verizon Business. The company said it responded to at least 90 confirmed data breaches last year involving roughly 285 million consumer records, a number that exceeded the combined total number of breached records from cases the company investigated from 2004 to 2007. Breaches at banks and financial institutions were responsible for 93 percent of all such records compromised last year, Verizon found.
As a result, the stolen identities and credit and debit cards for sale in the underground markets is outpacing demand for the product, said Bryan Sartin, director of investigative response at Verizon Business.
Verizon found that profit margins associated with selling stolen credit card data have dropped from $10 to $16 per record in mid-2007 to less than $0.50 per record today.
According to a study released last week by Symantec Corp., the price for each card can be sold for as low as 6 cents when they are purchased in bulk.
"[Cyber thieves] now have their hands on a tremendous amount of data, and there's certainly no scarcity of it out there right now," said Alfred Huger, vice president of development at Symantec. "Given all that we've seen in the past year, we're not sure why we haven't seen even more of a drop in pricing, but it could be that the people doing the selling have sewn up the market and no longer have to worry about being undercut by other sellers."
Steve Santorelli, director of investigations at the private security research firm Team Cymru, said his group's monitoring of cyber criminal forums appear to support Huger's hunch: Many forums are simply restricting the registration of new "verified" members. Getting verified involves successfully conducting a number of transactions with other members to demonstrate that the new entrant is not merely a "ripper," someone who will abscond with the money or goods before a transaction is completed.
"The rate of new additions allowed into the miscreant verified lists is very low," Santorelli said.
What's more, Santorelli said, thieves in possession of huge troves of stolen credit and debit card data appear to be hoarding the credentials, releasing them onto the market in smaller chunks in an effort to control the overall supply of card data available at any one time.
"This results in lower average prices for buyers and some sellers stockpiling products to restrict supply in a bid to keep prices inflated," he said.
YOU CAN USE QUICK SEARCH ENGINE IN THE TOP FOR MORE DOWNLOADS OR DETAILS.
Microsoft Fixes 23 Software Security Flaws
One patch fixes six flaws in Internet Explorer 6 & 7 (the flaws are not present in IE8), including the carpetbombing issue. Microsoft addressed that vulnerability with this IE update, as well as with a stand-alone fix for Windows XP and newer Windows versions. Microsoft has rated this update critical, meaning attackers could exploit these IE flaws merely by convincing a user to visit a hacked or booby-trapped Web site.
Redmond also issued updates to fix at least two zero-day threats, vulnerabilities that hackers have been exploiting in targeted attacks to break into Windows systems. These updates include a fix for an Microsoft Excel vulnerability, and an update for a hole in most supported versions of Wordpad/Microsoft Office that hackers have been exploiting since December.
One patch addresses a particularly insidious vulnerability that Microsoft assigns a lesser "important" rating, but one which security experts say could become a huge threat for Web hosting facilities that fail to apply this update.
The issue has to do with a vulnerability in Windows that is susceptible to a technique known as token kidnapping (PDF research paper). In a way-oversimplified explanation, one way to prevent programs from being able to make key changes to the underlying operating system is to run the program in a mode that simply does not have all-powerful, system-level rights to modify important settings on the host system.
Least-privilege approaches are most useful for applications that face known-hostile environments on a pretty much constant basis, such as Web browsers and Web servers. This vulnerability, however, could allow an attacker to bypass that protection, and gain full control over an affected system.
Eric Schultze, chief technology officer for Shavlik Technologies, said this flaw is especially dangerous for systems running IIS Web servers and SQL database servers. In the context of a shared Web hosting environment, where multiple customers will host their Web sites on the same Web servers, a malicious customer or hacked customer account could be used to upload a file to the server that gives the attacker total control over all of the sites on that server.
Schultze called this fix the most ambitious patch Microsoft has ever produced, noting that Microsoft originally said this was too complex of an issue to fix.
"Microsoft expended a great deal of effort in correcting this issue - even pulling developers off of Windows 7 to assist with this patch," Schultze said. Microsoft has even more detail on this process here.
Security researchers already have released instructions describing how to attack roughly half of all of the vulnerabilities Microsoft addressed in this patch release. If you run a Windows machine, try not to let too much time elapse before you apply these security updates. Most of the updates will not take effect until the patched system has been restarted.
As always, please sound off in the comments below if any of these updates appear to introduce problems for your system. Likewise, I will keep an eye out for any reports of issues with this large bundle of updates. A listing of each vulnerability addressed by today's updates can be found on Micosoft website.
YOU CAN USE QUICK SEARCH ENGINE IN THE TOP FOR MORE DOWNLOADS OR DETAILS.
The climate in the middle of a crisis
The financial crisis is starting to hurt. Some people are saying that our ambitions for the climate agreement in Copenhagen should be scaled down. But this is an entirely wrong.
Climate and energy policy are not part of the problem, but rather part of the solution. In 2050 there will be nine billion of us. The winners of the future will be the countries which improve energy efficiency and expand renewable energy production.
Climate and energy issues are no luxury we can ignore until the economy recovers. These are not the first sandbags to be dropped when the economic balloon starts losing height. The truth is that clean energy technology and efficient energy use are cornerstones in managing the challenges of the future. Not just for the sake of the climate, but also for growth, jobs and security of supply.
The financial crisis has exacerbated fears that production will move to countries with less exacting requirements on greenhouse gas emissions, with a consequential loss of European jobs. However, there are many ways to lose jobs, and one thing is certain: Europe will lose jobs unless we become better at developing and using energy-efficient solutions and green technologies.
Even if we ignore all the other problems arising from global warming, demand for energy-efficient technologies will grow significantly in the future. According to the UN, by 2050 the globe will have to sustain nine billion people, compared with today’s 6.7 billion. In 2050 eight billion people will live in countries we currently refer to as developing countries, and all these people will naturally be looking for the energy-consuming luxuries we enjoy today in our part of the world. They will also demand food, heating, air-conditioning, transport and other comforts for their children; just as we demand them for ours.
In its latest annual report, the International Energy Agency estimates that as much as 62 per cent of the increase in energy consumption up to 2030 will come from developing countries. In India, despite explosive growth rates, there are still some 500 million people without electricity. In the Chinese capital of Beijing, 1,000 new cars roll out from the factories and onto the roads every day. There is little doubt that both energy needs and oil prices will remain at a very high level in the future, despite the current drops due to the financial crisis.
But there is nothing wrong in spending money carefully. In the Washington Post recently, former US Secretary of State Henry Kissinger and Ronald Reagan’s chief economic advisor, Harvard Professor Martin Feldstein, estimated that this year alone will see transfers to the 13 OPEC countries of USD 1,000 billion in payments for oil. According to Kissinger and Feldstein, oil price increases since 2001 have given rise to the largest redistribution of wealth in world history – and to countries which do not all lead the democratic league tables.
So, financial crisis or not, in the long term energy efficiency is no political luxury. On the contrary, it is a precondition for growth, to be addressed by every country, every economy and every company. The winners will be those who are the first to become energy efficient and develop energy-smart products.
It is very telling that the three large US car manufacturers, General Motors, Chrysler and Ford, are all suffering because of the high oil prices, while fuel-economical Asian brands continue to win market share in the US. In part of the US financial aid package, more than USD 4.5 billion has been earmarked for the hard-pressed American motor industry because the industry has been too slow to adapt. Perhaps the forthcoming American Government will seek to avoid having to dig into its purse once again because of a lack of diligence.
A little conservative common sense can argue that in times of economic crisis it is advisable to limit energy consumption. This doesn’t mean that the whole family must make do with one cold shower a week; rather it means using the common resources we have with a little care. Phenomenal amounts of energy are still being consumed uselessly.
Denmark has benefited from common-sense energy policy. Since 1981 we have seen economic growth totaling 75 percent, while energy consumption has remained almost stable. Denmark has invested in energy-efficient solutions and in renewable energy. At the same time, through the tax system we have made it more attractive to focus on alternative and more efficient solutions. The incentives structure has proved successful and in fact it has not harmed Danish competitiveness. On the contrary, Denmark is experiencing historically low unemployment of just 1.6 percent; the Danish investment climate is one of the best in the world; and energy-correct and environmentally friendly technology is one of the fastest growing export sectors in Denmark.
Of course we must add to this the consequences of climate change in a world where last year saw global CO2 emissions grow by more than three percent. Projections from climate researchers can no longer keep up, and neither can nature. We are seeing temperature rises, more frequent and more violent weather incidents, damage to buildings and infrastructure, flooding and drought. All consequence of our behavior which will hit hardest in developing countries and provide a feeding ground for local conflicts, increased numbers of refugees, and ultimately greater pressure on European borders. Climate policy is also security policy.
A long-term solution to the current financial crisis must incorporate climate challenges. It is encouraging that, despite heated debate, heads of state and government at the EU summit this week could agree on maintaining objectives already set. The climate challenge is part of the solution, not part of the problem. Now it is up to the EU to deliver and to reach an agreement on reductions burden sharing before the end of this year. Without this, it will only be more difficult to achieve an ambitious international agreement in Copenhagen in December 2009. The world has never needed this agreement more than it does now.
Source: Ministry of Climate and Energy (USA)
YOU CAN USE QUICK SEARCH ENGINE IN THE TOP FOR MORE DOWNLOADS OR DETAILS.