Posts

Cost of Identity Theft

There is a blog about Effects of ID theft. It is quite a good reference but the whole process of cleaning up ID theft only after you know your identity was comprised.

Building cultural walls in Cyberspace

An article from Bloomberg News discussed how Google adjusted their web services with national cultures. In Thailand, they banned YouTue to show videos which offended King Bhumibol Adulyadej. In China, Google stopped offering Gmail to Chinese Citizen to avoid government demands for messages. To be able to stop user from using a specific web services, Google must rely on the programming codes. Now these codes with geo-sensitive information are used to build walls within Cyberspace, either due to political reason or to respect the natioanl cultures. The multinational enterprise is now taking the duty to fund the building of these walls using their codes. Cultural walls is not an entirely bad concept since a neigbhood enjoy more harmony when there are walls between them. Contrast this to Lawrence Lessig's "Code wants to be free" concept, we could see that multinational enterprises were using codes to control information flow. The force to from multinational enterprises is ...

ISP guideline on Cybercrime investigation released

I wrote about US Senate's approval of Council of Europe Cybercrime Convention . Recently, the Cybercrime Committee of Council of Europe released a guideline on how ISP and law enforcement agencies should cooperate in cybercrime investigations. Guidelines for law enforcement - service provider cooperation (adopted on 2 April 2008) From this document, it could be see that there is a large gap between law enforcement and ISP on obtaining evidences. Both sides need to formalise their procedures (either request or giving evidences). If there is no force from the government or other external factor, I could see no reason for them to incur additional resource in this process.

Coming PISA events

I have been busy with my LLM study at The Hong Kong University in the past year. All goes well, I will graduate this year. The course I took covers Telecommunication, Cybercrime and IP. Will share about all these topic in the coming posts. First, PISA will has several events in pipeline. Today, we just finished an Oracle Security Seminar On 31 May, there will be Data Protection Public Forum . Speakers from ISACA, ISOC and Privacy Commissioner will share their view on recent incidence on data breaches . Then on 5 June, PISA invited Aloysius Cheang (Head of Security Services for Cable&Wireless Asia-Pacific) to share his experience on malware detections and preventions.

homophily part II - Social Capital

Below are some extracts from NY Times Blog http://freakonomics.blogs.nytimes.com/2008/02/15/is-myspace-good-for-society-a-freakonomics-quorum/ "social capital", a concept that describes the benefits individuals receive from their relationships with others. Bridging social capital reflects the benefits we receive from our "weak ties" — people we don't know very well but who provide us with useful information and ideas. As our social networks are becoming increasingly more geographically fragmented, social network sites are a useful way for us to keep in touch and seek social contact with our friends. When many students begin university, they find themselves with a group of ready-made acquaintances. Given people’s preferences for people who are like them, it could be that friendship networks become increasingly homogeneous. Is this a bad thing? It might be if, by choosing potential friends via their Facebook profiles, it means that folk cut themselves off from ser...

Anonymous network will be popular

There is a sad but true story that corporate-PR "corrected" wikipedia pages in order to downplay the mistakes done by company and government organizations. Some of the "corrections" may be a true account of history but there are deliberate censorship. Most people think the network address (IP address) are useless and could not reveal the location or identity of individuals. However, most IP address is similar to telephone number and could be traced to specific organizations. This traceability enabled Wikiscanner (mentioned in the article) to find the editor of wiki. There are some anonymous networks like Tor for people to conceal their identity. I believe the PR will continue their censorship on wikipedia with these anonymous networks. It is sad that when truth is the battlefield between individual and large organisations.

"science may be the main determinant of how a case is resolved"

The gap between law and science is ever widening. In the past, the court is a place for justice but now justice is bury among scientific experiments and mathematical calculations. Judges trained to filter fake science from USA Today

Stealing credit card numbers via home Wifi network

The Hong Kong district court heard a computer crime case on 18th June 2007. An African visitor had rented a flat and stole credit card numbers from his neighbor using wireless sniffing, then he used the credit card information to do online shopping. The charge was brought under HK Crime Ordinance Chapter 200 s116 . More detailed information will be available when the judgment is posted online. The 23-year old defendant was caught since he had used his home address for online shopping and the police were able to trace the delivery records. His ignorance of fraud detection systems and traceability of online shopping transactions seems to suggest that he is not a professional criminal. There are lots of ways to use stolen credit card numbers, buying cash coupons and delivering to an unoccupied house's mail box are common. According to statistics , credit card fraudis increasing and costs 3 billion USD in 2006, up from 2.7 billion in 2005. Different measures (like adding chips or usi...

DDOS attacks are getting more frequent

On 7 June, there was a reported case of a successful botnet Distributed Denial of Services DDOS attack. This type of attack was difficult to prevent since current technology could only divert the traffic after the attack has been launched. Due to the fact that the sources of attack are highly distributed, we could never monitor nor stop the DDOS attack. Once the attack is launched, the affected system will be unable to response to normal users. DDOS attacks are real and there were even reported cases on DDOS against a national body Estonia . The scary thing about DDOS is the growing number of botnet . With the higher penetration of broadband internet, more computers will be connecting to the Internet 24x7. If the management of these computers is not done securely, they will be a breading ground for botnets and viruses. One area to pay special notice to is the growing trend of networked devices. Vetting machines, CD juke boxes and other everyday electronic devices are likely to be conne...

Catch up with the Web

I saw an article on Yahoo news about "25 Web Sites to Watch " and the web advanced so rapidly that one could never be able to catch up. I grouped some of the web sites according to their features. One thing I noticed is that the web is getting specialised and each website is good doing one particular domain. This fragmented development is the result of a distributed web but in history every development will eventually reverse its course. " speculated that the Internet will become, in essence, a vast operating system" Popfly Yahoo Pipes Goowy Data/Opinion Site BuzzDash Swivel Multimedia Web creation tools SplashCast Squidoo Yodio

WAP Volumn in China

China Internet Network Information Centre released a survey result on the current usage of WAP in China. As of March 2007, there were 39M WAP (Wireless Acccess Protocol) users, about 28% of fixed Internet population in China. Not too surprising, Guangdong Province has the large WAP population. The report summary could be find here .

Transfer files on P2P is an offence in Hong Kong

The legal battle on BitTorrent cases reached an end on 18 May 2007 and the full judgement released on Hong Kong Legal Information Institute On 12 Jan 2005, officers from HKSAR Custom Department raided thedefendant's (Mr. Chan) home after tracking his address from an online forum. Mr. Chan he had uploaded 3 .torrent files on 10 Jan 2005 and 11 Jan 2005 to the forum and these enabled BT users to download copies ofmovies. In first instance, Mr. Chan was charged by virtue of section118(1)(f) of the Copyright Ordinance, Cap 528 and of obtaining access to a computer with dishonest intent, contrary to section 161(1) (c) ofthe Crimes Ordinance, Cap 200. But in the final judgement in the Court of Final Appeal, the 5 judges unanimously dismissed Mr Chan appeal andhe was convicted of 118(1)(f) of the Copyright Ordinance only. This was a high profiled case and the HKSAR government launched propaganda on their determination on combating the copyright battle. Since charges was brought to the cou...

Control points missed in Symantec

This morning I heard astounding news about Symantec. It released a faulty virus definition that deleted (or quarantined) two essential files on Windows XP (Simplified Chinese Version). The result was that around 3 millions computers were unable to start and must restore the deleted files from the original Microsoft installation CD. SANS and Sina confirmed this news. They claimed that only people who downloaded the updates from the Symantec China webpage between 01:00 a.m. and 02:30 p.m. on May 18th AND have MS06-070 installed on their computer were affected. This incident has many implications. The one that worries me the most is that people will try to download these files on the web in order to repair their computers. The integrity of these files is in question (if they do not come from an authenticated source). A malicious hacker may plant a virus or backdoor in these system files and offer them in discussion groups. As an auditor, I always think of process control. There are ac...

The root of China SMS-based Payment

Image
McKinsey recently released an article on the prospect of a SMS-basedpayment system in China rural area. The arguments were that China has a low level of non-cash payments when compared to other countries and the Chinese government is keen to develop non-cash payments in order to simulaterural spending. There are both economical and political reasons to have an efficient rural payment system. I agree with the article's contention that ATM and POS are not the right products for Chinese farmers. The main reason is cost. While the annual income of the averagefarmer in China is below USD 2000, it is relatively costly to acquire and maintain an ATM or POS, which usually costs more than USD 20000. Apart from cost, there is also a trend in other countries of declining rates of ATM adoption. According to the BIS statistics , the number of automated banking machines per million inhabitants decreased by 1123 in the year 2000to 1069 in 2005. However, the picture portrayed by McKinsey seems to ...

CFCA -- the China next payment infrastruture

There was a news about 16 China Banks released a press release about a coordination framewrok between banks against online fraud (網上銀行反欺詐聯動機制) The banks will share their fraud information with China Financial Certification Authority CFCA, which was found by the banks in year 2000. CFCA is a certificate authority (i.e. a PKI service provider) and from ChinaTechNew.com 25 banks uses their certificates in 2005. If this alliance is successful and continues its development, I think CFCA has the potential to be the center of China payment network. A secure PKI is important, especially for using client-side authentications. When the banks establish a cross-banks PKI process and agreements, the payment network may function a bit like VISA in plastic card business. For China, the development and innovations are unlimited.

Internet Law -- A US testmonial

When we talk about Cyberspace, we usually think of US. Partly due to there technology innovations and partly due to their obsession about Internet. Then it is not surprise to know US has many legislations on regulating the Internet and citizens' cyber-activities. Below is an snapshot of the status of Internet regulations in US and quite interesting. http://www.imanet.org/technotes/stnewsb.asp

When there is no choice .. ...

I joined a discussion forum oragnised by Legislator CK SIn on 26 Apr at HKPC where a group of industry leaders are invited to express their view on Hong Kong Government consultation paper on new copyright legislations. The speakers concentrated on two major themes: 1 Criminalisation of infringing downloading 2 Requiring ISP to keep IP-to-Physical Address records One important discussion item was that almost everyone acknowledged the fact that a viable business model is needed for substantial development of online contents. But when there is no widely adopted business model, legislations are considered necessary. PISA is monitoring these developments and will submit our views to the government.

IEEE 1667

The IEEE is working on a standard for USB and other flash authentications. The new protocol is a standardization on how a USB disk could authenticate against a computer. That is how you could limit which portable disk to be able to store your data. It is a long-waited protocol and is vital for protection against data-theft. Authentication in Transient Storage Device Attachments The standard will be published in June 2007

RFID ticket in China

Image
I saw some puzzling situations when I traveled to GuangZhou (southern China) this weekend. GuangShen Railway installed a RFID ticketing system and all tickets are embedded with a electronic circuit (photo 1). RFID application on train ticket is quite advance. In last winter,I traveled to UK and Sweden but did not see any RFID application in transportation system (even airlines). What puzzling me is the ticket-checking in Photo 2. You could see there are two railway staff standing behind a gate to check passengers ticket. The narrow opening is to prevent people from passing the gate. Except the tickets embedded with a electronic circuit, very little has changed. The railway staff still need to validate passenger's ticket one by one. When a few hundred passengers passing through the small gate, one can image the chaos it created! China being late in infrastructure investment projects are applying advance technologies but this example shows that the benefit of technology may not be r...

PCI Industry standard audit checklist

Image
IT Compliance Institute just released PCI Industry standard audit checklist . It also include a self-assessment questionniare.