Safe door

Spate of blunders raises e-security fears

Are major firms doing enough to guard customers’ information?

Written by Phil Muncaster

A number of data security problems made headlines last week, raising the question of whether major companies are doing enough to protect online customers.

Faith in the safety of online banking suffered a blow as new research found keylogging devices could easily crack the login technology used by HSBC and another major high street bank.

Cardiff University researchers discovered the flaw, which could allow hackers to break into accounts within nine attempts. Unlike some other banks, HSBC asks for a numeric-only passcode and does not always change the order of digits it requests, making it easier for hackers to obtain the code.

"They have an anti-keylogging system that doesn't work – they might as well not have it," said Cambridge University net security expert Richard Clayton. " The only reason it's a theoretical [flaw] is that they're fortunate no bad guys have got at it yet."

HSBC said in a statement that attacks of this kind are unlikely as they require "a particular and time-consuming focus on one individual", although it invited feedback from experts on its online banking service.

Meanwhile, the results of a British Computer Society survey released last week showed around a third of consumers had concerns about the security of online banking. But CA security consultant Steven Cox argued that consumers should take responsibility for securing their PCs so no keyloggers could be installed in the first place.

In other news of high-profile security problems last week, just a day after two men were charged with stealing a laptop containing sensitive data from a US Department of Veteran Affairs employee, the department announced that another computer had gone missing, this time from a subcontractor's offices.

The desktop computer reportedly contained information on up to 38,000 veterans, including names, social security numbers, dates of birth and insurance details.

Meanwhile, AOL apologised after it mistakenly released data from its search logs on over 600,000 customers' search habits. The information was intended to be used on the firm's recently launched AOL Research site, and although the usernames were changed to random identification numbers, privacy activists complained that individuals could still be identified by the information in their search requests.

In another incident last week, one IT Week reader called in to say that while using the Betfair online gambling site he discovered that he was able to see confidential user details of other members of the site, including their names and how much they bet. Despite alerting the firm, it took several hours for the problem to be rectified.

To help firms strengthen protection, analyst firm Gartner last week released a list of best practices. It said companies should deploy content monitoring and filtering tools to prevent sensitive data leaving the network, whether accidentally or maliciously, and they should encrypt backup tapes and laptops in case they are lost or stolen.

Gartner also advised firms to ensure all workstations are kept up to date with anti-spyware and that information downloaded to portable storage media should be controlled and encrypted.

"What is most appropriate for specific organisations depends on their risks – if they have a lot of mobile workers then encryption and lockable USBs is more important," said Gartner analyst Ant Allan. "It's difficult to understand firms' decisions sometimes. [Encryption] seems like the obvious thing to do; the level of awareness to prevent security breaches is less than we'd hope but not as bad as we feared."

Marc Shinbrood, chief executive of web application security vendor Breach Security, said the biggest risk to firms from security breaches is not that they will break the law or lose intellectual property, but that they will suffer bad publicity which may damage brands and undermine customers’ trust.

“Compliance with the law is a necessary evil but it isn’t the driving force for good security,” Shinbrood said. “If you talk to [IT security chiefs] their job is to keep the company off the front page of the Wall Street Journal, or from appearing in front of a government regulatory committee, or having their customers doubting whether they should do business with them.”

Tags:

reader comments

related articles

Chiefs in the dark about breaches

A third of managers clueless about whether or not their network security has been breached 24 Apr 2006

 

Users must be protected from themselves

Gartner has issued new advice to help firms guard data 11 Aug 2006

Ernst & Young loses 250,000 credit card numbers on laptop

Bad publicity shows why firms must have security and policies to protect data and devices 07 Jun 2006

Government issues guidance to protect outsourced data

Downloadable advice is available to help firms comply with the law 25 Apr 2006

Online staff pose risks

DTI survey finds staff at fault for many enterprise security breaches 27 Mar 2006

Indian data breach hits HSBC

Insider fraud at HSBC’s Indian site underscores the need for security that extends to offshore locations 28 Jun 2006

related whitepapers

today's top stories

Best practice: Five steps to achieving your e-commerce goals

Brian Walker of Forrester Research gives his top tips for ensuring e-commerce success 06 Jul 2009

Google meets the NHS? Politicians show their IT naivety again

The Tories like technology. They increasingly seem to think IT is going to help them win the General Election due next year.... 06 Jul 2009

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Reaching the email zero count

I have noticed something quite bizarre today. Both my inboxes (work and personal) are empty – somehow I have managed to work... 06 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation