Showing posts with label credit card. Show all posts
Showing posts with label credit card. Show all posts

Wednesday, January 21, 2009

The New Year begins with a bang ! Break My Heart....

What a start to the New Year ! And they told me 2008 was a bad one.

January '09 and we brought in memories of a tragic 26/11 here in Mumbai. And we did not celebrate the passing of the old year so was this due to the baggage we carried from the last year or a foreboding of the times to come.

Seems to be the latter... when we take stock on this 21st day of the year 2009 AD. (And when I think about the 344 odd days ahead a shiver runs through me)

First Satyam lives down it's name. Raju confessed that he was lying for the past 7 years and more. So a billion dollar behemoth shows it had no pants (maybe no underwear too) and all the good men running along with it also may be in the buff. That was a $ 1.2 b shocker and for those of you who do not know this, the word Satyam means "truth" in Hindi / Sanskrit.

Now Heartland breaks my heart by announcing the mother-of-all breaches. They say they have been compromised. Heatrland processes about 100 millin transactions every month and we can well imagine how bad this is going to be. TJX now may seem like small change because Heartland has beaten them to the tape.
It seems that they have a backdoor running on their systems for quite some time and that they have foind 'multiple' instances of malicious software on the network. Now they will work to make things better by bringing in "a next-generation program designed to flag network anomalies in real time".
Cute.

Confickr a.k.a. Downadup is a big bad worm spread to over 3.5 million PCs worldwide and has the potential to create "one badass botnet" according to F-Secure. So users be warned about using your convenient USB sticks. Read more about this online before using your USB drives any more, or any autorun device.

So this is it, in three weeks we have three major events one in the east, one in the west and one worldwide. That's a nice number once a week.

And I am not yet talking about the seesawing markets or the billions that are still being handed out to the big banks and corporations to help them stay alive or afloat.

There it goes... the mantra for success : Incorporate and employ thousands, since the numbers are so big some fools will pay you for nothing (the numbers will impress and so will window dressing like sub-prime). In a few years go tell the Government (whisper to them) that you are going under and they will give you a billion or a trillion, then they will lower interest rates and generously fill your begging bowl.

We shall soon see a new elective - the art of becoming a C-level beggar.

Sunday, December 2, 2007

Bhelpuri - the ultimate privacy mish mash

Inspired by

http://timesofindia .indiatimes. com/articleshow/ msid-2586516, prtpage-1. cms


Isn't it apt that identity and card information was available in a bhelpuri, and that too at the hands of a techie with the source being the world's largest chip maker and the world\s largest car rental company.

The bhelpuri is the ultimate Indian smorgasbord - a mish mash of a snack which can be spiced up on a scale of 0 to infinity and can symbolize all the regulations and controls thrown into a wrapper and mixed into obliviion so no one knows what came from where - just pass the audit, make sure there is evidence controls.

Oh, I am digressing, this can be a plot for a new Bollywood blockbuster "Secure Bhel" and the catch line will be CIA on the street.... Compromised and Internationally Available.

Is this another lapse which is being swept under the carpet ? Now we wonder, as security professionals, that if a company on the bleeding edge of technology can send private data in this manner what is the state of it's internal systems. Not that they will reveal this.

Well that is the international giant, the bleeding edge technology company and they do not have a clue about security of private information, because they are busy securing technology IP. So how about the leading car rental company which handles tons of personal data from credit cards to driver licences, addresses, birthdates, travel plans etc - so how does current and valid personal data land up in a snack ! Is this how they treat personal data of clients - boy I would love to audit them and take them to the cleaners.

This rambling was prompted by this article......

Credit card info found on bhelpuri wrapper
1 Dec 2007, 0238 hrs IST,Kavita Kukday,TNN

MUMBAI: On Tuesday evening, Aneesh, a media professional in his thirties, bought a packet of bhelpuri from the roadside vendor in MIDC, Andheri. While munching on the snack, he happened to glance at the paper cone in which the vendor had mixed the bhel. His curiosity was piqued. It was a computer printout of an invoice for a car rental. Once he had eaten up his bhel, he studied it carefully: it had the name of a credit card holder, the 16-digit credit card number, the three-digit batch number (from the back of the card) and the expiry date. In short, all the ammo needed for online transactions.

It was an American Express card. The request had gone on email from tech firm Intel to Avis, an international car rental firm with offices in India. It was sent in March last year for an Intel guest who was staying at the Grand Hyatt and needed to hire a car for a day. Despite the invoice being more than a year old, the expiry date (Feb 2008) showed that the card was still valid. To heighten the risk, it was a company credit card, which automatically scales up the chances of misuse --- not only is the credit limit higher even the authenticity of the spends are tougher to track.

So how did such sensitive information find its way to the bhelwalla? While the paper trail is hard to trace to source, an important stop must certainly have been the raddiwalla.

An Intel spokesperson said, "It is an unfortunate incident and Intel is deeply concerned. We hold our employee confidentiality in the highest respect. We are currently investigating the matter."

Those in the credit card business warn that this is not an isolated case. Security norms for digital transactions are still very lax in India, and the use of shredders for documents is almost non-existent.

The bhel-puri credit card story, however, had a safe ending. The person eating bhel didn't head for the nearest cyber cafe. He carefully ironed out the paper cone and passed it on to a writer friend, who called TOI.

http://timesofindia .indiatimes. com/articleshow/ msid-2586516, prtpage-1. cms