Getcher extra cute Giant Microbe plush doll! You know you
want one...

Google
Showing posts with label computer crime. Show all posts
Showing posts with label computer crime. Show all posts

Tuesday, May 15, 2007

Computer Code Finds 744 Sex Predators On MySpace, Paves Way for Arrest.

Wired's Kevin Poulsen went undercover online & found some some alarming information about who's lurking on MySpace. Armed with a sheaf of information on convicted sex offenders, and his knowledge of the cimputer language Perl, the reporter confirmed a total of 744 sex criminals with MySpace profiles, after an examination of about a third of the data. Almost 500 of them are registered for sex crimes against children, 6 listed as repeat offenders and at least 243 of the child sex offenders have convictions in 2000 or later.

Poulsen built an automated program, using Perl, to sift through all of MySpace's profiles looking for 385,932 convicted and released sex offenders from 46 states. He says he mined the list from the US Department of Justice's National Sex Offender Registry website which he says is "gateway to the state-run Megan's Law websites". He used first and last names and limited results to a five-mile radius around each offender's ZIP code. Here is the guy that Poulsen's code caught, which enabled him (the sex offender, not Pouslen :) to be busted for trying to solicit sex online with a 14 year-old gay boy.

WiredSafety.org is working with MySpace to fight this kind of thing, according to Poulsen's article.

Wired News published the code Poulsen used last year under an open-source license. It's not a plug and play application however. And it's not perfect. And it's not an excuse, he points out, 'to go vigilante', it only finds matches by name - the person could easily be someone else with the same name who not the offender. Poulsen went through the entire possible list of potential offenders which the program dug up, using his own eyes to verify if the people were the same as the offenders - age, mug shots, etc. He did find false positives. Lots of them. The program cannot find anyone who is using an assumed name, nor anyone who has legally changed their name. Here's Wired's follow-up article about the code. The article has a link to download the gzipped tar file with the program. If you have to ask what a tar file is, you will not be able to use the program. To use it you need to have at least some familiarity with Perl, says Poulsen, who also notes that the program's code could use some cleaning up.

Wednesday, April 25, 2007

Stopping (Optical and I.D.) Data Theft

Fiber optic cables are used for networking computers together. But hi-tech cabling may not be as secure to hackers and crackers as businesses think, according to "The Register", a top online technology daily. According to the article, hackers armed with small clip-on monitoring devices manufactured by Canada's EXFO, could patch into networks and their computers and read data. They say only 0.1dB of the optical rating of light needs to be captured in order to snatch data from an optical link.

A hacking device was discovered on a Verizon cable in 2003, according Swiss encryption machine company Infoguard. The perpetrators were not caught. According to the company such data taps can be avoided by encrypting the data going through the fiber optic cables. Other ways to protect the data are given by one of the people who commented on the article on The Register's website.

Here is an encryption technique reported last year by two US researchers. (Found via SANS Institute's excellent newsletter).

Below is a small sampling of the useful stuff SANS has. You don't need to be a computer and information security specialist to make use of this:

"5 Ways to Stop Identity Theft".
Published April 20, 2007 on the SANS Insitute's tip of the day!
Five Ways to Protect against Identity Theft

1. The next time you order checks, have only your initials (instead of first name) and last name put on them. If someone takes your checkbook, they will not know if you sign your checks with just your initials or your first name. Your bank will know.
2. Do not sign the back of your credit cards. Instead put "PHOTO ID REQUIRED".
3. When you are writing checks to pay on your credit card accounts, DO NOT put the complete account number on the "For" line. Instead, just put the last four numbers.
4. Don't list any telephone number. You can always write it on the check at the time of the transaction. If you have a PO Box, use that instead of your home address or your work address.
5. Place the contents of your wallet on a photocopy machine. Do both sides of each license, credit card, etc. You will know what you had in your wallet and all of the account numbers and phone numbers to call and cancel. Store in a secure place and refresh it when you change cards." So, that's from SANS Institute.

Wondering what, if anything else you can do to protect your identity, in this day of ID theft? Check this out: LifeLock.. (Thanks to the Security Curmudgeon over at Attrition for posting info on these guys to their dataloss list.