Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

BT: Sloppy identity verification 'must make firms liable'

  • Email a Friend
  • Print Page
BT: Sloppy identity verification 'must make firms liable'
By Joy Persaud
Aug 8, 2008 11:06 AM
Tags: BT | Fraud | Identity | verify | Legal | data | TJX |
Organisations that hold personal data should be made liable for fraudulent transactions, say British Telecommunications (BT) security experts.

The company commented following the case in which 11 people were charged with what is thought to be the biggest case of credit card identity theft in the United States – with an estimated 41 million credit and debit card details stolen.

The alleged culprits used a technique known as ‘wardriving' – they drove around the suburbs of Miami and San Diego with laptops, scanning for security holes in wireless internet networks of banks and shops.

Authorities said they used sniffer programs to obtain card numbers, personal information and passwords, which were either allegedly used by the accused to furnish blank cards and withdraw cash, or sold on the black market.

Bruce Schneier, BT's chief security technology officer, said it is easier for criminals to get hold of data that could be used for fraud, as the amount of personal information collected, sold and collated increases.

Our current culture where identity is verified “simply and sloppily” makes it easier for criminals to commit identity fraud crimes, he added.

“We need to make the entity that is in the best position to mitigate the risk to be responsible for that risk," he said. "And that means making the financial institutions and companies who hold the data liable for fraudulent transactions – this will result in a lot more prosecutions and a much safer environment. These prosecutions in the U.S. are just the tip of the iceberg and more needs to be done.”

Ray Stanton, BT's global head of business continuity, security and governance practice, said: “The charging of the individuals involved with the retail ID theft is great news for business. However, it is also bad news. Why? Because,
this basic problem should not have happened.

It is irrelevant whether the charged individuals gained access via the wireless network or any other method. It was a failure of the organisations involved to implement basic controls and then maintain and monitor them.”

The thefts are said to have begun in 2003, but remained undiscovered until February 2007, when retailer TJX reported that the data on 45.7 million debit and credit cards from the United States, U.K. and Canada had been breached.

The retailers affected are TJX, BJ's Wholesale Club, Barnes and Noble, Sports Authority, Boston Market, Office Max, Dave and Busters, DSW shoe stores and Forever 21.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Legal Whitepapers