Showing posts with label Philadelphia. Show all posts
Showing posts with label Philadelphia. Show all posts

Friday, January 22, 2010

How Blippy Will Give Crooks and Phishers Info to Attack You

Cyveillance, a most-excellent cyber intelligence blog, has an informative write-up on Blippy, a newly-launched service that allows users to post their financial transactions to the web in a Twitter-esque manner.

Yeah. And putting your credit card purchases online for the world to see, while a terrible idea, isn't the worst part of this. Not by a long shot.

Example:




Not sure why the world needs to know that Jason bought a SanDisk card at Amazon, but I'm old and just want the kids to get off of my lawn.

Cyveillance points out the wealth of good data available to evildoers:

We find:

    * a user’s name
    * the name of a business with whom they had a financial transaction
    * how much they spent
    * for certain retailers, what they bought

And then they speculate on the following scenario:

From a cyber criminal’s point of view, Blippy currently offers great information to construct a highly targeted spear phishing attack. After examining the types of purchases Blippy shows for Best Buy, consider the spear phishing attack one could construct for a hypothetical Blippy user named Johann Gonzales:

Dear Johann Gonzales,

Thank you for your recent purchase of $52.99 at Best Buy. To receive credit for your purchase in our Best Buy Reward Zone program and receive valuable discounts on future purchases, click here…

Putting together such an email would require software to “scrape” information from Blippy that it would then use to send to an array of likely email addresses for Johann Gonzales, like jgonzales@gmail.com, jgonzales@hotmail.com, johanngonzales@gmail.com, johanngonzales@hotmail.com, and so on. Given that software needed to carry out such an attack is freely available online, it must be assumed that cyber criminals are preparing such an attack on Blippy users. Even if they are not yet preparing, for the sake of Blippy’s users, Blippy must plan ahead as if they are.

What could possibly go wrong?

Dear Blippy - I think I'll keep my purchases to myself, as much as that's possible given our global data-sharing practices, but thanks for asking.

Now get off my lawn.




Monday, September 14, 2009

Philly Free Library System Is Kaput

Cory Doctorow over at BoingBoing has the sad news - the Philadelphia Free Library System is out of money, and it's being shut down. All of it.

This includes "all branch and regional library programs, programs for children and teens, after school programs, computer classes, and programs for adults" and "all children programs, programs to support small businesses and job seekers, computer classes and after school programs" and "all library visits to schools, day care centers, senior centers and other community centers" and "all community meetings" and "all GED, ABE and ESL program."

That's just lousy. I can't think of many entities that give broader access to information resources at a lower cost than libraries, especially for segments of our population that often have scant resources available in the first place.

Doctorow sums it up nicely:

Picture an entire city, a modern, wealthy place, in the richest country in the world, in which the vital services provided by libraries are withdrawn due to political brinksmanship and an unwillingness to spare one banker's bonus worth of tax-dollars to sustain an entire region's connection with human culture and knowledge and community.

Think of it and ask yourself what the hell has happened to us.