Showing posts with label Phish. Show all posts
Showing posts with label Phish. Show all posts

June 24, 2008

New Biometric Bank Protection

A voice biometric system for authorizing banking transactions was launched yesterday, and even Rory Bremner's impressions are not clever enough to fool it.

Voice Transact, which is the brainchild of Nick Ogden, the founder of the WorldPay remote payment system, uses a vocal signature that is matched against a pattern stored on file when the account it opened. It is designed to help reduce fraud, particularly phishing-related online scams.

"We are creating a global network for banks to use that is changing the way people confirm their transactions," Mr Ogden said. "Voice biometric signatures can enable consumers to have complete control over signing for financial transactions anywhere in the world."

The company is in talks with a major pan-European bank and expects to launch a service in the UK towards the end of the summer. It is also in discussion with MasterCard, and in six weeks' time, consumers at a participating Dubai bank will be able to take money out of a cash machine without their bank card. By selecting the "cardless transaction" option, and inputting the mobile phone number, the customer will be immediately rung back and asked to repeat a random string of numbers. Once the voice pattern has been matched, the cash machine will dispense money in the normal way.

The company invested $10m (£5m) in the technology, which works by creating a profile when a customer registers their account. Transactions are authorized by repetition of a random string of numbers that do not relate to the financial information but merely function as a way of getting the person to talk.

While a customer who has actually lost their voice could have problems, a normal cold should present no problems, and a three-hour test session was conducted with Rory Bremner last year to ensure that the system cannot be cracked. "We guarantee the integrity of the system so we will stand behind any transaction that is processed through the network," Mr Ogden said. If an authorization is rejected, the customer will immediately be contacted by a call centre as an alternative verification.

My thoughts? This system will not make a flipping difference in regards to limiting the amount of phishing. Nearly all phishing scams are geared towards the least technological savvy people, so harvesting authorization will be no problem. All that would be required is to get a person to "Verify Their Account" on a phishing server, including having a person say numbers 1-9. This would include verifying the account with their Voice authorization , which would be ftp'd to the Phishers records. The recording could be then played using any high grade audio output, thus bypassing the authorization. Yet another biometric meant to keep honest people honest.

June 7, 2008

British Beauty Queen Hijacked!

Am I being a little sensationalistic? I may be, however no one ever said that Beauty Queens were the brightest of the bunch. Cases like this are why I suggest that people be required to have a driver's license for the Internet.

Miss Scarborough has become the latest victim of online phishing fraudsters, with the the beauty contest winner having had £10,000 stolen from her bank account.

Jade Saunders, a 20-year-old student, was crowned Miss Scarborough in April this year, and is also a semi-finalist for Miss England 2008.

Saunders reportedly clicked on a link in an e-mail purporting to be from her bank, which took her to a genuine-looking, but fake, website. By entering her security log-in details on the fake site, Saunders provided the cybercriminals with all they needed to set up a standing order on her account for £10,000.

Alright, Here are a few checkpoints upon receiving an email from a seemingly legitimate source

[] IS IT FROM A LEGITIMATE SOURCE? LEGIT COMPANIES DO NOT USE FREE EMAIL ACCOUNTS
(Free Emails such as Yahoo, Hotmail, Gmail)
[] IS THE EMAIL GRAMMATICALLY INCORRECT
(Legit Companies typically don't spell words improperly)
[] IS THE EMAIL UNFORMATTED? (i.e No breaks, Paragraphs, Letterhead, Etc.)
(Companies will usually use some sort of professional formatting)
[] IS EMAIL STATING THAT YOU MUST ENTER PERSONAL INFORMATION?
(Companies do not ask for Passwords, SS #'s, or Bank Info)
[] DOES THE EMAIL STATE THAT CHARGES ARE BEING MADE TO YOUR ACCOUNT?
(If so, contact the companies customer support phone number immediately)
[] IS THERE A LINK? If you have checkmarks above, DO NOT CLICK!
(If so, hover your mouse over the link and a box will come up and say where it goes. If it Is not the company's website- Do Not Click!)

IF the email makes you feel uneasy at all, in general, don't click anything at all.
When you enter information on a phisher's website, he has all the information to take out a line of credit, transfer funds, or do any number of other unscrupulous things. Companies will not ask you to enter information in order to verify anything, and if you do recieve such an email- be sure to immediately contact the company in question on the phone support line.

BE SAFE ONLINE! IF NOT, YOU MAY SUFFER BIG LOSS IN THE REAL WORLD.