InfoSecurity Europe 2005
InfoSecurity Europe 2005
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Online crime spirals out of control

New threats demand new practices, warns security expert

Iain Thomson at InfoSec in London, vnunet.com 26 Apr 2005
ADVERTISEMENT

The increasing number of criminals using the internet means that companies will have to completely rethink security practices, according to security guru Bruce Schneier.

Hacking activity has shifted over the past two or three years from being an amateur activity to one where organised crime has taken over. The two groups are very different and security officers will have to change tactics to deal with new threats.

"It used to be the hacker attacking and looking for glory, but now it's criminals looking for money," Schneier told vnunet.com.

"Forcing the criminal attacker to make a meaningless change of tactics by changing network settings doesn't work. In the language of fraud your tactic is merely a tactic, whereas hackers would look on it as a whole new challenge."

Schneier explained that the criminal classes are not hackers, but are using hacking techniques because they provide an automated way to commit fraud on a large scale. Factor in poor legislation in some countries, and online crime is booming.

He pointed to denial of service attacks as an example. These are now being used against e-commerce sites such as online gaming, gambling and pornography to extort money.

Schneier also punctured some security myths. He advised people not to bother shredding bills and mail, maintaining that thieves are not interested in stealing credit card numbers by the ones or twos when they can steal them online in the hundreds of thousands.

Politically motivated hacking is not on the rise, according to Schneier. It has remained a low-level threat and tends to increase only around specific events like the downing of a US spy plane in China two years ago.

He concluded that the change in tactics by criminals would lead to more and more online fraud and that they would always be one step ahead of the police.

"Criminals by their very nature are distributed whereas the police are an institution," said Schneier. "As such the police will always be slower to respond. Indeed most police [investigation] occurs only after a crime has happened."

See also:

Security experts warn of sinister new hacking scamPay up or you'll never see your data again  25 May 2005
InfoSecurity Europe 2005Companies losing out by hiding behind firewalls  27 Apr 2005
InfoSecurity Europe 2005Perimeter security no longer enough  26 Apr 2005
InfoSecurity Europe 2005UK's Security Co-ordination Centre 'cannot fulfil its remit'  26 Apr 2005
InfoSecurity Europe 2005Providers 'missing a sales opportunity', claim experts  26 Apr 2005
InfoSecurity Europe 2005Biggest threat from current or former employees, warns Met Police  26 Apr 2005
InfoSecurity Europe 2005The IT security trade show rolls into London  25 Apr 2005

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | Utilyx
Senior Business Analyst - London Highly professional individual capable of working at senior / board level with blue chip clients - shaping and driving the analysis and design of their energy management solutions Proven capability ... more >
London, United Kingdom | National Policing Improvement Agency
The NPIA, National Policing Improvement Agency, works for the police service and directly supports forces to deliver improvements today, and into the future. We're a single national support agency led by the police, for the ... more >
Bicester, Oxfordshire, United Kingdom | EDS
Position # 398435 Test Manager - EDS - Bicester Must be eligable for security clearance Short Description: EDS's Defence Logistics (DL) testing group tests a range of logistics information systems for the MOD. The Test ... more >
Reading, Berkshire, United Kingdom | EDS
Job Description: A skilled System Integrator to integrate application hosting environments to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating technical Infrastructures and system management facilities within ... more >
More job opportunities