- Wednesday 19 June 2013
- My Account
- Logout
- Register
- Login
- News
-
Voices
-
Find by writer
- Yasmin Alibhai-Brown
- Rebecca Armstrong
- Memphis Barker
- Terence Blacker
- Chris Blackhurst
- David Blanchflower
- Archie Bland
- Ian Burrell
- Andrew Buncombe
- Ben Chu
- Patrick Cockburn
- Laura Davis
- Mary Dejevsky
- Grace Dent
- Robert Fisk
- Andrew Grice
- Stefano Hatfield
- Philip Hensher
- Ian Herbert
- Howard Jacobson
- Ellen E Jones
- Alice Jones
- Owen Jones
- Simon Kelner
- Dominic Lawson
- Donald Macintyre
- Lisa Markwell
- Comment
- Campaigns
- Debate
- Editorials
- Letters
- IV Drip
- Archive
- Our Voices
- Commentators
- Columnists
- Democracy 2015
- IV Drip Archive
-
Find by writer
- Sport
- Tech
- Life
- Property
- Arts & Ents
- Travel
- Money
- IndyBest
- Blogs
- Student
- Offers
Wednesday 19 August 2009
Rhodri Marsden: How can we stop these criminals in cyberspace?
It's disconcertingly easy for someone to pretend to be you and use your money
I've had many pieces of well-meaning advice given to me by my father over the years – most of them ways to avoid repeating my embarrassing DIY errors – but one memorable maxim of his was "never let your credit card out of your sight".
Before the advent of PIN terminals, following this rule would require him to pursue slightly perturbed waiters around restaurants until they gave him a slip of paper to sign; I don't think he knew exactly what underhand deeds he was looking out for, but having never been defrauded while using the technique, he stuck doggedly to it. He never worried about what happened to the credit card information after the transaction – where his number might be stored and who might have access to it – figuring that that was all probably taken care of by companies employing sophisticated security measures. Most of the time, that's probably true. But not always.
On Monday, a 28-year-old Floridan by the name of Alberto Gonzalez, along with two unnamed Russian co-conspirators, were charged in the US for stealing some 130 million credit and debit card numbers by hacking into the databases of a number of American companies that process card transactions. Gonzalez, already in federal custody for his part in the previous record-breaking theft of 40 million card numbers, is alleged to have used sophisticated software to infiltrate the systems and scoop out the data. If found guilty, all three face 35 years in prison.
Those unfortunate enough to own one of the 130 million compromised cards will probably be spluttering in indignation as to why these companies hang on to such details anyway. The answer is that they're legally obliged to, for a length of time, in case of queried transactions. But why aren't they forced to do it in a way that doesn't put our own security at risk?
There is a worldwide standard (the PCI-DSS) that any companies dealing with cardholder information are obliged to sign up to, but many security experts have pointed out that it's possible to tick all the PCI's boxes and still be insecure. The offence allegedly committed by Gonzalez is as vivid an illustration of that as one can imagine.
For once, this lapse in online security has nothing to do with us, the general public. We're guilty of all manner of stupidity when it comes to our personal financial security – writing down PIN numbers on Post-it notes, using the word "password" as our password – but in this case there's nothing we could have done, save for withdrawing entirely from the 21st century and using cash instead.
So what should these companies be doing to protect us? Graham Cluley, from internet security firm Sophos, has expressed his disbelief that our card details aren't encrypted when they're stored, so that hackers just find random gobbledygook. "If they were properly encrypted," he says, "it would take until the sun burns out for anyone to decode it."
But it's not just the companies storing our details that need to shape up. The 130 million stolen credit card numbers would be of no use to anyone if they couldn't be used to buy stuff. Any masterminds wouldn't have been the ones picking a card number and using it to buy soft furnishings on eBay; they'd sell the numbers on to other criminals in blocks of a few thousand. But eventually, someone would pretend to be you and use your money, because it's still disconcertingly easy to do.
Online shopping is a click-happy cinch, but with that convenience comes risk; if you can tap out your 16-digit number, expiry date and a supposed "secret" three-digit number on the back of your card to book a flight to the South of France, so can anyone else. We may balk at the idea of carrying around an additional device (of the kind Barclays customers now have to use for online banking) to enter our PIN every time we make a credit card purchase online, but when these kind of measures are inevitably introduced, we'll have to grin and bear it. It's for our own good, after all.
As for the likes of Alberto Gonzalez, they're talented individuals capable of writing sophisticated software that can detect weaknesses in even the strongest computer defences. Indeed, such characters frequently find themselves with job offers in the industry following their release from prison. But after a 35-year stretch, technology is likely to have marched on a bit too far for anyone to catch up. Marched on so far, one would hope, that our money would finally be safe from marauding cybercriminals. Fingers crossed.
-
Russell Brand lets loose on MSNBC hosts in promo interview for Messiah Complex tour
-
We never knew Nigella Lawson - and we still don’t
Ellen E Jones -
The Daily Cartoon
-
Should we intervene? Our response to the Charles Saatchi and Nigella Lawson assault is shocking too
Stig Abell -
This isn’t ending world hunger. It’s just a sham
Ian Birrell
-
Russell Brand lets loose on MSNBC hosts in promo interview for Messiah Complex tour
-
The Girl Guides have nothing to do with religion and they never have done
-
Our love for the NHS blinds us to its failures. Morecambe Bay is yet another wake up call
-
Fifty signs of getting older? They missed a few
-
Letters: Islam and assaults on women
-
The problem with the Taliban peace talks is not women, it’s their absence
How will you make today delicious?
Tell us how you plan to make today delicious and you could win a £50 M&S gift card.
Win a Nook® Simple Touch eReader
Find out how Nook® is supporting the Evening Standard's Get Reading campaign - and your chance to win one.
Free reading festival for families
Follow The Standard's campaign to get London's children reading - and experience this unique event at Trafalgar Square on 13 July.
Enter the latest Independent competitions
Win anything from gadgets to five-star holidays on our competitions and offers page.
Business videos from commercial thought leaders
Watch the best in the business world give their insights into the world of business.
Related Articles
Get the best in opinion from Independent Voices, straight to your inbox every Thursday lunchtime.
Subscribe
Amol Rajan
A weekly update from the Editor
iJobs General
FX Options Front Office Java / C# Developer
£500 - £600 per day: Orgtel: FX Options Front Office Java / C# Developer - Ba...
Project Manager - Front Office - Regulatory IT
£600 - £700 per day: Orgtel: Project Manager - Front Office - Regulatory IT C...
Lighting Design Engineer
£33000 - £35000 Per Annum: The Green Recruitment Company: The Green Recruitmen...
Are you an Primary NQT looking for your first role in Essex?
£21000 - £22000 per annum: Randstad Education Chelmsford: NQTs required now fo...
Day In a Page
Babies behind bars
Sonic youth: The high-pitched sound alarm
The art of living in small spaces
Can technology lure us back to the high street?


