Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Thursday, December 24, 2015

Tips for Safe usage of Internet



Internet has already become an essential part of our lives.We access our banking records, credit card statements,  and other highly sensitive personal information through Internet. 


With all the benefits the Internet offers us, there are also many devastating threats in using Internet. 



The tips given below  offer you basic information on how you can be safe on Internet and enjoy Safe surfing through it. 
  1. Don't login on third party applications which require your email login details.
  2. Don't access your account through any email link as it can be risky. If the email turns out to be fraudulent then cyber criminal will have access to your account information.
  3. Don't have single password or PINs for accessing all your online accounts, this can again lead to identity theft.
  4. Don't use unsafe site that does not come with term ‘https‘. The “S” stands for secure and you should always make note of it before accessing any site.
  5. Don't click on pop-ups that says “Your Pc is Insecure”, such links can have malware automatically downloaded to your PC.
  6. Don't download free stuffs such as screen saver and those stupid smiley faces. Such things are very dangerous to your PC and you will soon notice it has turned slow then earlier. Sites like download.com are safe to use.
  7. Be careful with  phishing mails, they may create a sense of urgency as “Your Account is in Risk” or an “Unauthorized transaction has taken place” so send your account details. Remember any bank will not ask your account detail via mail.
  8. Make sure you always have updated antivirus software in place.
  9. Always check with your bank if they have any additional security for your online transactions, such as IPIN’s or Zero liability card.
  10. Always have your CC details save in real world. Do not share it with anybody via sending mails or over even on telephone.
  11. Never forget to delete the system’s cache, passwords or history, it could easily lead to identity theft and stolen bank and email information.
  12. You have won a lottery and or an IPod are the common terms used by spammers to trap you, avoid falling to such traps.
  13. Always blacklist the spammers you come across in mails without just deleting the spam mails.
  14. Don’t ever click on the Close window without logging of your account especially if you are at cybercafé for accessing Internet then you are more at risk.
  15. Always have a back up for your emails just as how you keep a hard copy of your important docs and other things.
  16. Avoid believing in those brainless “Microsoft Is Sharing Its Fortune” kind of mail, they are just spammers requiring your details to trouble you more.
  17. Always have a habit of not clicking on phishing email, the goal of phisher is to fool you for entering your details into something that actually appears to be safe and secure, but in reality is just a fake site set up by the scammer.
  18. Avoid giving your full name, home address, phone number, Social Security number, passwords, names of family members, credit card numbers online. Best is to remain anonymous and enjoy surfing
  19. Never forget to scan the attachment you receive in your mail box. Virus attacks are mostly through such attachments.
  20. Social networking sites like Face book, Orkut etc are something we cannot avoid these days, yet it is always secure to follow known person on Twitter or to add on Facebook. Don’t forget to do security check if you tend to add unknown person.
Read more ...

Thursday, October 15, 2015

Know about Card Skimming and how to protect your card

Of late there are many reports about frauds related to  Credit/Debit/ATM cards. In many instances it is reported that the card details were obtained by the  fraudsters  using a technique called "Skimming". 


In this article, the modus operandi of skimming and the precautionary steps to be taken by the card holders are given for the benefit of card users.


What is Card Skimming?

Skimming is the unauthorised copying of information stored on the magnetic strip of a credit/debit/atm card.  It is typically an "inside job" by a dishonest employee of a legitimate merchant. The dishonest employee usually procures a victim's  card number using basic methods such as photocopying receipts or more advanced methods such as using a small electronic device (skimmer) to swipe and store hundreds of victims’ credit card numbers

The employee  sells the information through a contact or on the Internet, at which point counterfeit cards with your details on it are made. The criminals go on a shopping spree with a copy of the credit or debit card, and cardholders are unaware of the fraud until a statement arrives with purchases they did not make. 

Watch this video(from Youtube) on Credit card Skimming operations:






Skimming of ATM cards:


Instances of skimming have been reported where the perpetrator has put a device over the card slot of an ATM (automated teller machine), which reads the magnetic strip as the user unknowingly passes their card through it. 


These devices are often used in conjunction with a miniature camera (inconspicuously attached to the ATM) to read the user's PIN at the same time. This method is being used very frequently in many parts of the world, including South America, e.g. in Argentina and Europe, e.g. in the Netherlands 


Another technique used is a keypad overlay that matches up with the buttons of the legitimate keypad below it and presses them when operated, but records or transmits the keylog of the PIN entered by wireless. 


The device or group of devices illicitly installed on an ATM are also colloquially known as a "skimmer". Recently-made ATMs now often run a picture of what the slot and keypad are supposed to look like as a background, so that consumers can identify foreign devices attached. (Source:http://en.wikipedia.org/wiki/Credit_card_fraud).


Preventive steps to avoid fraud by skimming:

  • If you are in a restaurant or in a shop and the assistant wants to swipe your card out of your sight, or in a second machine, you should ask for your card back straight away and either pay with a cheque or cash, or not make the purchase.
  • Keep your credit card and ATM cards safe. Do not share your personal identity number (PIN) with anyone. Do not keep any written copy of your PIN with the card.
  • Check your bank account and credit card statements when you get them. If you see a transaction you cannot explain, report it to your  bank.
  • Choose passwords that would be difficult for anyone else to guess and keep your password secret.
  • If you are using an ATM, take the time to check that there is nothing suspicious about the machine like an unusual gadget or camera .If the ATM looks suspicious, do not use it and alert the bank which owns the ATM.

       FINALLY  HOPE THAT ALL WILL AGREE THAT PREVENTION IS BETTER THAN CURE!           






Read more ...

Tuesday, October 6, 2015

IMPORTANCE OF STRONG PASSWORDS






This article on Password is re-posted with some revisions. 

Wikipedia's definition of a password as below:

"A password is a secret word or string of characters that is used for authentication, to prove identity or gain access to a resource (example: an access code is a type of password). The password must be kept secret from those not allowed access."

Passwords ensure the security and confidentiality of data that is stored on various workstations and servers

Passwords are one of the important things for any system. It will help you to maintain your identity so that others will not be able to view your account. You need to have a good password otherwise your password is likely to be hacked by others. Once they are successful in hacking your password they easily view your account. 


Generally, a password is made of many characters or digits and will not use any special character or a white space in between. In some systems passwords are case sensitive. Here you need to be extremely careful and remember to type the correct password accordingly. This is because some of the system will have some restriction and if you are mistyping the password repeatedly it is likely that your account will be denied access and you need to then go through the procedure that is in place in the system.

If you are going to choose a password which is not good then it means that your security of your account is not very good and there is always a fear that your account is going to be hacked and they will be able to access all the information that you have in your account. 


This is why it is stressed that the password that you choose should be good and a strong one. You need to realize the importance of having a strong password. 


Remember the password that you choose is only going to protect all the information that you have in your account. Keep this in your mind when you are selecting the password.


DOS AND DONTS FOR PASSWORD


DOs
  • Use a password with mixed-case alphabets and special characters.
  • Change the password after initial log on without fail
  • change your password regularly
  • Use Passwords difficult to guess.use a password with 8 or more characters. More is better.
  • Store passwords in sealed envelopes and handover to the officer-in-charge wherever required.
  • Maintain secrecy of password
  • Your passwords should be as unique as you are.
  •  create different passwords for different accounts and applications.
DON’Ts
  • For Password do not use related words like your user-ID, your first or last name, Spouse’s/ family member’s names, date of birth , vehicle numbers, telephone numbers, the brand of your vehicle, the name of the street you live on, 123123, etc.
  • Do not allow tracking of password while typing the password on keyboard.
  • Do not write Passwords on the desk/keyboard etc to remember /preserve
  • Do not lend Passwords/reveal passwords to others
  • Do not reset passwords without the user’s acknowledgement in the register maintained.
  • Do not pronounce the letters loudly while keying in the password
  • DON'T choose your username as your password.
  • DON’T Provide your password—or any of your sensitive or confidential information—over e-mail or instant message. 

Now watch this interesting video on "How to choose a Strong Password":





                DON'T FORGET TO FOLLOW THE FOLLOWING SIMPLE RULES



    Read more ...

    Sunday, October 4, 2015

    Tips for Safe Use of Automatic Teller Machines(ATMs)

    About Automatic Teller Machines(ATMs)


    An Automated Teller Machine (ATM), also known as a Cash Point (which is a trademark of Lloyds TSB), Cash Machine or sometimes a Hole in the Wall in British English, is a computerised telecommunications device that provides the clients of a financial institution with access to financial transactions in a public space without the need for a cashier, human clerk or bank teller. ATMs are known by various other names including ATM Machineautomatic banking machine, and various regional variants derived from trademarks on ATM systems held by particular banks.

    Invented by IBM, the first ATM was introduced in December 1972 at Lloyds Bank in the UK. However, there is a plaque on Barclays Bank in Enfield Town, north London stating that the first ATM (in the world) was installed there on the 27th June 1967. 
    On most modern ATMs, the customer is identified by inserting a plastic ATM card with a magnetic stripe or a plastic smart card with a chip, that contains a unique card number and some security information such as an expiration date or CVVC (CVV). 
    Authentication is provided by the customer entering a personal identification number (PIN).
    Using an ATM, customers can access their bank accounts in order to make cash withdrawals, credit card cash advances, and check their account balances as well as purchase prepaid cellphone credit. If the currency being withdrawn from the ATM is different from that which the bank account is denominated in (e.g.: Withdrawing Japanese Yen from a bank account containing US Dollars), the money will be converted at a wholesale exchange rate. Thus, ATMs often provide the best possible exchange rate for foreign travelers and are heavily used for this purpose as well.
    Source:http://en.wikipedia.org/wiki/Automated_teller_machine)


    Whereas there are many advantages in the usage of  Automatic Teller Machines, the users should take enough precautions in the safe keeping  of the ATM cards provided to them and also to take precautions while doing transactions in  ATMs.


    Tips for Safe Use of  Automatic Teller Machines(ATMs)

    KEEP ATM CARD SAFE AND SECURE
    i) Your card is very important and must be kept safely.
    ii) Do not not keep your ATM card near any magnet or magnetic gadget like television set, magnetic compass, purse or wallet having magnetic locking arrangements as magnetic field may erase all data stored in the magnetic strip of your ATM card.
    iii) Store your ATM card in a secure place where you will immediately know if it is missing.
    iv) Store the ATM card carefully so that the magnetic stripe does not get damaged.
    v) Never leave your Card unattended at places like your car, in a hotel room, workplace or at the bar and restaurant you visit
    vi)DO NOT bend the card.
    vii)DO NOT place two cards with magnetic stripes together.
    viii)Cancel unused cards and shred blocked cards.
    ix)Immediately report any stolen or lost ATM card to the proper authorities


                                              Security of ATM  PIN
    • Your ATM PIN must be kept very secret since ATM card  can be misused by a person if he/she steals both the ATM card and the ATM PIN together.
    • Change your PIN frequently; do not write it a piece of paper  or on the face/back of the ATM card but memorise it.
    • Select a PIN that must be difficult to guess; avoid household numbers such as house number, car number, birthday etc.
    • Never disclose your PIN to anyone including members of your family or relatives; if it gets divulged for some reason, change it immediately.
    • Do not  keep pin and card together under any circumstances.
    Precautions to be taken while doing transaction with the card

    • Avoid using ATMs in remote / unprotected areas and avoid ATMs adjacent to obvious hiding places.
    • If you want us to alert you whenever a transaction takes place on your account / Credit Card, you can register for the Bank's SMS Service by registering your Mobile number.



    • Shield the screen and keyboard so anyone waiting to use the ATM cannot see you enter your PIN or transaction amount.
    • Be careful when people you do not know offer to help you at an ATM.
    • If you notice anything suspicious at the ATM you want to use e.g. tampering with the card slot / numbers pad or any suspicious activity around the ATM area, do not use the ATM and report your concern to the Bank immediately.
    • Do not force your card into the card slot or if you feel that the ATM machine is not working properly for any reason, press the “Cancel” key, take your card and report it to the Bank. 
    • If your card gets lost, captured or stuck in the ATM, report it to the Bank to block your card immediately.
    • Make sure you get the card back after every transaction & only use it at ATMs /Point of Sale (POS) machines in reputed public locations / locations known to you.




    • When using a drive in ATM, keep doors locked and passenger side and rear windows up.
    • While using your card at a POS, ensure  that the merchant swipes the card in your presence.
    • Check your account balances and statements regularly to ensure your accounts have not been accessed by anyone else and to identify any unusual transaction(s). 

    Read more ...

    Wednesday, September 2, 2015

    Beware of Phishing while doing online transactions



    There has been increasing incidences of phishing recently which targets the customers of leading banks throughout the world .

    The modus operandi of the attacks, how they are perpetrated to get the personal credentials from unsuspecting customers and also how to avoid becoming victims to such attacks are given below .

    Phishing Fraud

    What is Phishing?

    Phishing pronounced "fishing" is an act undertaken by fraudsters to gain your private and sensitive information through emails that appear to be sent by your Bank. Such fake emails encourage you to click on a link in the email which leads you to a fake website with a similar look and feel as that of the Bank's authentic website. It is designed so, to capture your personal confidential account information such as Customer ID, IPIN, Credit/Debit Card number, Card expiry date, CVV number, etc.

    Customers’ email addresses are obtained/purchased by the fraudster through non-trusted sites where the customer would have revealed his email ID by means of casual browsing or shared it on chat rooms, blogs or mailing lists, etc.

    How do the fraudsters operate?
    1. Fraudsters send spoofed emails, appearing to be sent by the customer's Bank, to large number of recipients with an urgent tone that calls for quick action to verify, update or reveal your confidential account information by clicking onto a link in the email .
    2. Once the recipient clicks on the link in the email, he is diverted to a fake website with a similar look and feel of the Bank's original website.
    3. The customer is presented a web form to divulge his confidential account information i.e. customer ID, IPIN, Credit / Debit Card numbers, Card expiry date and CVV number, etc.
    4. Once the unaware customer reveals his confidential account information on the fake website he may be directed to the authentic website of the Bank to suppress any suspicion arising in the customer's mind. This is how the customer’s identity is compromised .
    5. This customer confidential account information or identity credentials are then used by the fraudster to gain access to the customer's account to commit fraudulent transactions

    How do you identify a fake / phishing email?
    1. The fraudster may use the customer's Bank's email address, domain name, logo, etc to give an authentic look to the fake email
    2. Do not rely on the name and source in the "From " field of the email address as it may be easily manipulated by the fraudster to a valid email account of Customer's Bank.
    3. Such fake emails will always address you by a generic salutation or address you by "Dear Customer" or "Dear Net Banking Customer" or "Dear xxx Bank Customer". "
    4. Very often, such fake emails are poorly drafted and may have spelling or grammatical mistakes.
    5. Such fake emails will always encourage you to click on to a link to verify or update your confidential account information.
    6. The links embedded in such fake emails may sometimes look authentic but when you move the cursor/pointer over the link, there may be an underlying link/url to a fake website.

    Security Guidelines for safe online banking


      1. Keep your passwords confidential
      2. Avoid using simple passwords and use strong passwords
      3. Change the passwords periodically and whenever you feel that your password has been compromised or made known to anybody accidentally
      4. Destroy the password/pin mailer after changing the password/pin
      5. Use the virtual keyboard displayed on the login screen to enter passwords
      6. Avoid accessing online banking websites from cybercafés/shared networks
      7. Upgrade the Operating System (OS) of the computer system promptly as newer/upgraded versions would help make your system more secure.
      8. Use newer/upgraded versions of browsers as they are regularly updated to block and alert you from accessing the phishing sites
      9. Install Antivirus software on your computer systems and update them continuously as this will reduce the risk of virus attacks
      10. Installation of personal firewall would provide added level of security
      11. Any potential risk caused through pop up windows may be eliminated by removing spy ware or ad ware installed on your system by using spyware/adware removing tools.
      12. Avoid downloading from unknown/unfamiliar sources. They may contain Trojans/malicious programs or worms/viruses that may compromise your system security.
      13. Disconnect your internet connection when not in use. This would avoid unnecessary access to the information on your systems and help protect yourself even if you have a personal firewall installed in your system.
      14. Logout completely after using the online application, i.e., by clicking the logout button and closing the browser windows.





    Read more ...

    Tuesday, September 1, 2015

    SECURITY TIPS FOR USING YOUR CREDIT/DEBITCARD



    With the increase in the usage of Credit cards and Debit cards, the number of frauds committed are also on the increase.


    Your card could be lost or stolen and fraudulently used; it could be copied; the details could be stolen and used via the internet, over the phone or by fax and mail order; or you could be a victim of identity fraud, where the criminal will use your personal details to apply for a credit/debit card, or to take over your credit/debit card account.

    Here are some tips to protect your cards from the fraudulent persons:

    1. RECEIPT OF THE CARD:


    • When you receive a new card/Pin Mailer, check that the envelope containing the card /Pin Mailer does not show any signs of being opened or tampered with.

    • If the card is received in a sealed condition, sign on the signature panel on the reverse immediately. If it is not in sealed condition, inform the issuing bank.

    • Write down the number of your card, CVV Number /PIN Number and phone number of Customer care printed on the reverse of the card in a Diary or a document which can be accessed by you only. This will enable you to inform the issuing bank immediately in the event of theft or loss of your card.

    • Since the CVV number printed at the back of the credit card is to be furnished for transactions through Internet, it is advisable to mask the CVV number to avoid misuse of the card in case of loss of the card.

    • Keep all the documents of your cards that are in use in a safe place.

    • If your card has expired, cut it into four pieces with a pair of regular scissors, making sure that you cut through the middle of the magnetic strip and the card numbers. Then dispose of the pieces. If you want to close the account you have to surrender the card.

    • Destroy all the charge receipts of your cards and any stationery that you may not use. Tear them to pieces before throwing them into the dustbin.


    2) USING THE CARD IN SHOPS /ESTABLISHMENTS:


    • Take with you only the card that you are going to use.

    • After making any transaction, always make sure to get back the card.

    • Do not use your card in shops/establishments where you do not feel secure for some reason because of the place itself, the sales persons or just the of the day.


    3) USING THE CARD IN ATMS:

    While operating the ATM

    • Insert the card in the Access Lock Slot (or swipe through the slot as the case may be) to gain entry into the ATM cabin.

    Before gaining entry into the ATM cabin ensure that no one is inside the cabin

    • Always enter the ATM cabin alone and operate; do not allow any other person to enter with /without your notice.

    • Avoid seeking help from others; ATM operations are very simple and menu driven; you can do it yourself

    • Insert the card in the Card Reader Slot of the ATM with the arrow marked in the card pointing towards the Card Reader Slot.

    • Collect the card on its ejection as delay in collecting it may result in capturing of the card by the ATM.

    • Follow the menu based instructions appearing on the screen for further operations

    • Enter the PIN obtained from the Bank after ensuring that no one around can watch the PIN being keyed in.

    • Use ‘Change the PIN’ option as the first operation to maintain secrecy

    • Change the pin periodically through the ‘pin change’ option

    • In the case of getting a printout from the ATM, destroy the same completely if not required for further reference and put in the dustbin; others may build information about your account if not properly destroyed


    Cash withdrawal:

    • In case of cash withdrawal

    o collect the entire cash in the tray and count for its correctness

    o collect the transaction slip and card from the respective slots

    • Use ‘fast cash’ option to reduce your waiting time at the ATM.

    Deposit of cash/Cheques:



    In case of deposit of cash/cheques

    • Use separate envelope for each deposit and seal the same

    • Enclose filled in pay-in-slip with each deposit

    • Deposit cash in the ATM, if the account is maintained in the same ATM branch.

    • Deposit only crossed cheques

    • Deposit local clearing cheques for collection in the ATM only if the account is maintained in the same ATM branch.

    • Collect the receipt issued by the machine for future verification.


    Don’ts
    • Do not forget your PIN
    • Do not write your PIN anywhere including the face of the card
    • Do not disclose your PIN or give the card to anybody
    • Do not keep pin and card together under any circumstances
    • Do not fold notes or pay in slip/cheques while depositing
    • Do not use pin or stapler while depositing cash/cheque
    • Do not place more than 30 notes in an envelope
    • Do not deposit coins
    • Do not enter into the cabin if the ATM is being used
    4) USING THE CARD THROUGH INTERNET:


    • If you want to buy /or pay for any service like Telephone bill/booking railway/air tickets etc., first of all make sure that the selected site has a Secured Sockets Layer (SSL) connection.

    • Usually, when you log into this kind of shopping website, you receive a notification of the SSL Certificate. If you do not receive it, the symbol of a small lock will appear at the bottom right corner of the screen. When you click lock, the certificate information will appear.


    5) USING YOUR CARD OVER THE PHONE:


    • Never give you card number over phone to unknown persons or telemarketers.

    • If you need to make a purchase over the phone, make sure that the company from whom you want to make your purchase is widely known.

    • Under no circumstances give your card number, CVV No or PIN for over-the-telephone transactions.

    • Do not provide any personal information by phone or fax, such as your home or working address, account numbers,credit/debit card numbers, account balances or income related information, until you make sure that the company requesting the information is empowered to do so and that the call is really coming from the company. If the request is for entering the information via the internet, make sure the Web site complies with the required security standards.


    6) SAFE KEEPING OF THE CARD:

    The black magnetic stripe on the back of the CARD contains important information about the account / card and needs special handling.

    • Keep the card away from heat and direct sun light.

    • DO NOT keep the card in vehicles parked in sunlight.

    • DO NOT bend the card.

    • DO NOT place two cards with magnetic stripes together.

    • DO NOT keep the card in an area where there is a continuous magnetic field.

    • DO NOT leave it on top of TV set or near any electronic appliance.

    • Avoid scratching the magnetic stripes.

      
    Read more ...