Home > United Nations Online Network in Public Administration and Finance (UNPAN)
1. Global
2. Africa
3. Arab States
Arab States
4. Asia & Pacific
Asia & Pacific
5. Europe
6. Latin America & Caribbean
Latin America & Caribbean
7. North America
North America
UNPAN Global
Public Administration News  
Oversharing Information Can Lead to Disaster Online
Source: idg.no
Source Date: Thursday, October 24, 2013
Focus: ICT for MDGs
Created: Oct 28, 2013

Criminals use a variety of tools and tactics when selecting victims and conducting attacks. But information is the key to any malicious campaign, and the more personal it is, the more value it holds. When one goes about their daily life online, how much information is too much, and what should be protected?

The topic of privacy is often interwoven with security, especially when it comes to awareness programs and operational security (OpSec). Online, it's hard not to share information, because inevitably you'll leave pieces of data about yourself behind as you surf the Web. Some of the information left behind you can control. Some of it you cannot, but OpSec in the context of privacy deals with the types of information you can control directly.

Recently, in a post on ITworld, privacy expert Dan Tynan discussed how Box.com allowed a complete stranger to delete his files. However, while the story discusses the risks of trusting sensitive information to the Cloud, Tynan raised his own risk profile by sharing information that may seem harmless and useless at first glance, but acts like a target to criminals on the hunt.

Last month, the CSO editorial staff was targeted by a phishing campaign. We covered the details of the incident here and here, but the interesting thing behind it was how focused it was, and how the use of a spoofed domain allowed it to bypass the company's spam filter.

Earlier this month, the same thing happened again. An email claiming to be from the Xerox WorkCentre offered a .ZIP file to each of the CSO editors, which was promptly ignored. The scam was simple; it claimed to be a scan from the Xerox machine, and offered us our newly scanned document in the form of an attachment. One of the key reasons the message was ignored was the attachment itself, but the fact that it was addressed to CXO Media addresses that didn't exist only added to its fishy nature. As was the case in September, this email also leveraged aexp.com to bypass our spam filters, taking advantage of the fact that American Express is a commonly whitelisted domain.

(By Steve Ragan)

News Home

 Tag This
 Tell A Friend
del.icio.us digg this Slashdot
0 ratings
Views: 609

Comments: 0 Bookmarked: 0 Tagged: 0

0 Comments | Login to add comment

Site map | FAQs | Terms and Privacy | Contact Us
Copyright 2008-2010 by UNPAN - United Nations Public Administration Network