PDA

View Full Version : ALL EYES ARE ON YOU.


hobbes
07-07-2002, 18:02
Tollbooths, ATMs, doctors' offices, online chat: You leave critical personal data behind wherever you go. Let's follow one American as he scatters his digital DNA.
by Mary Behr ( POPULAR SCIENCE )
First, Meet Mark, a graphic designer in Chicago. Like most of us, Mark knows his boss can read his e-mail, insurers can access his medical data. but he's blind to the bigger truth: personal data is collected, and sometimes shared, at a fantastic rate.
7:20 am: ATM Mark withdraws $100 at his bank's ATM machine.
Who's watching: An ATM is a data terminal that's connected to a central computer, or hub, at a bank networking company such as NYCE Network or MAC. The ATM sends Mark's request to the hub; it, in turn, contacts Mark's bank. Once the bank's computers approve the transaction, the hub gives the ATM machine the go-ahead to spit out the bills. Though the three computer networks involved may be hundreds or more miles apart, the transaction takes just 2.5 seconds.
The NYCE Network alone logs 68.4 million transactions per month; each is stored on tape for seven years, as required by law. ATMs have become a vital, if secretive, way for authorities to track people who are either on the run or just raising suspicions. In May of this year, for example, an 18-year-old Miami girl was kidnapped and murdered on a Saturday night. By working with her bank to track transactions on her ATM card, the police were able to follow her abductors as they traveled from one location to another. The men were arrested Monday morning, soon after making yet another ATM withdrawal.
Financial information isn't the only data an ATM stores. It also holds photos of every customer?s we were vividly reminded by the haunting pictures of September 11 hijackers Mohamed Atta and Abdulaziz Alomari, taken at two Portland, Maine, ATMs the night before the attacks.
7:49 am: Surveillance Mark enters his office building and takes the elevator to 5.
Who's watching: Virtually every large U.S. company employs video surveillance?ounting cameras on buildings (to monitor people's movements from as far away as one city block), on elevator ceilings, and in some cases even focusing them on workers' offices. There are at least 2,400 outdoor surveillance cameras in Manhattan alone, many of them installed by corporations, according to the New York Civil Liberties Union. Municipal governments have also embraced the technology: More than a dozen cities, including Memphis, Tennessee, and Hollywood, California, have placed video cameras on street corners, hoping to catch criminal activities such as drug deals or robberies.
Most companies say they keep videotapes for 30 days, and the Washington, D.C., police department?hich hopes to expand its surveillance capabilities from 12 cameras to 1,000?as tried to placate privacy advocates by saying it might destroy footage after 72 hours. But no laws limit how the cameras must be used or the tapes archived. Researchers at the University of Hull in England have found that when a human operator is controlling surveillance cameras?hether at a police station or behind a security desk?hey are often used improperly: to spy on women, monitor political protesters, or for racial profiling. And the tapes can get into the wrong hands. A British video called "Caught in the Act," available on the Internet, consists of a compilation of sex acts and illegal activities captured by surveillance cameras; the "filmmaker" created it from tapes he'd purchased from private companies and police departments.
Some surveillance technology goes well beyond mere videotape. Several airports across the country, including Logan Airport in Boston and Oakland International Airport in California, are testing software that scans people's faces as they pass through checkpoints and compares those digital photos to a database of mug shots that includes suspected criminals and people on watch lists supplied by the CIA, FBI, and other agencies. Visionics' FaceIt system can scan as many as 15 faces a second. For now, though, the technology is far from foolproof: Sunglasses, smiles, and hats can confuse it.
10:31 am: E-mail Mark writes a friend: "No raise. My boss is a liar."
Who's watching: When Mark sends an e-mail, it's routed through an exchange server on the company's network that places a copy in Mark's Sent folder. If Mark tries to purge this message by pressing "Delete," he creates yet another copy, which pops up in his Delete folder. A third copy of the e-mail will be stored in the daily backup of Mark's mail folders that's automatically made by his employer's network at the end of each day and archived on tape. These tapes, which at many companies are never erased, can be examined by supervisors at any time, subpoenaed as evidence in lawsuits, or viewed by law enforcement authorities with a warrant. In addition, some corporations have e-mail filtering systems that set off an alarm when an employee sends a message that is clearly non-company-related. Many of these programs also monitor employee Web usage, providing supervisors with real-time logs of Internet activity for each individual at the company. These detailed readouts include which Web sites employees visit, how long they stay there, which chat groups they access, and what they say during those chat sessions.
Because Mark's e-mails travel across the Web, copies of them may also reside in the computers of the various service providers that carry Internet traffic. These files, and all of Mark's other Internet activity, are accessible to the government. Last October, in reaction to the September 11 terrorist attacks, Congress passed the USA Patriot Act, which requires Internet service providers (ISPs) to release individuals' Web browsing records to law enforcement officials armed with merely a subpoena, not a harder-to-obtain warrant. Such a blanket order can snare a variety of information: terms entered into search engines, pages surfed, session times and durations, and the source of e-commerce payments, including credit card or bank account numbers. The targeted person does not have to be notified of the investigation, and the government does not have to report any findings back to the court that issued the subpoena.
Private companies also have access to sensitive ISP information. Raytheon Corp. recently sued 21 employees who had criticized the company anonymously on a Yahoo message board, for breach of contract and disclosure of proprietary information. Raytheon's lawyers didn't know the workers' names when they filed the suit, but a court-approved subpoena to Yahoo yielded them. Once the employees' identities were revealed, the suit was dropped, but several exposed workers resigned.
9:14 am: Instant messaging Mark IMs his girlfriend: "Don't worry about last night. I'll get tested. Love you."
Who's watching: Though often thought to be untraceable, instant messages can be monitored using software like FaceTime Communications' IM Auditor 2.0, which maps an employee's screen name to his corporate network ID and then stores every instant message that is sent. The software can be programmed to automatically notify supervisors when, for example, an employee sends an instant message to someone who works for a competitor. The program can also put out an alert to management whenever an instant message contains suspicious?r non-business-related?ords or phrases, including endearments, profanity, or proprietary information.
11:23 am: Hard drive Mark deletes a file containing freelance work he did for a competitor.
Who's watching: Mark thinks he erased the file, but what he actually deleted was the computer's pointer to it. The file is still on the hard drive, though it has disappeared from his directory and now has no identifier. After a few weeks (sooner if the computer is used intensively), new data will be stored over the old file and it will truly disappear. Several programs?uidance Software's EnCase and Panara Soft's PC Smart Cleaner among them?an restore deleted data before it's overwritten (afterward, nothing can bring it back). These utilities produce a snapshot of the hard drive at an earlier period, including a directory of now-pointerless files, listed by the last name they had before they were deleted. The ability to recover so-called orphaned files has been at the heart of the Enron case. Almost as soon as it was learned that auditor Arthur Andersen had deleted potentially incriminating computer data in the months leading up to the energy company's bankruptcy last year, high-tech forensic experts were called in by prosecutors to scour Andersen's network. In many cases, the computer sleuths were able to successfully unearth the missing files, according to lawyers involved in the case. To stymie recovery of deleted data, government agencies that handle top-secret information, such as the CIA, FBI, and the National Security Agency, use proprietary programs that constantly overwrite free space on hard drives.
12:36 pm: Cellphone Mark calls a friend from the street at his lunch break. "Dude, she wants me to get an AIDS test," he confides.
Who's watching: A cellphone operates like a radio transmitter and receiver: The phone sends signals to the cell tower and the tower sends signals back. Analog phones like Mark's older model broadcast calls via FM waves, which are easily intercepted by police scanners, baby monitors, and cordless phones. Digital phones are harder to monitor, because calls are encrypted. But newly mandated emergency locator services known as E911 (see page 56) may make it impossible for anyone to hide their whereabouts, whether from law enforcement authorities or marketers.
12:42 pm: Medical data Mark gets tested.
Who's watching: In a few days, Mark will learn from his doctor that he is HIV-free. But had the result been positive, it would have set in motion a cascade of data sharing. A network of databases would have given thousands of people access to Mark's HIV-positive diagnosis before he knew it himself.
Because HIV must be reported?ike syphilis, Lyme disease, rabies, and tuberculosis?he lab would have sent a positive result to the Illinois Board of Health. All test results, meanwhile, are distributed to the patient's insurer, the clearinghouse that sends doctors' bills to his health plan, the company that handles the lab's insurance claims, the patient's employer?nd the Medical Information Bureau. MIB, a consortium of 600 health insurers, was created to give underwriters access to medical data, but employers may check its records before making hiring decisions. In addition, some insurance plans call for pharmacies to inform companies about the drugs workers are taking.
No federal laws protect the privacy of medical records. Moreover, a black market has developed: Tennis star Arthur Ashe's AIDS diagnosis became public when a health care worker disclosed it for a price. And a few years ago, a Colorado medical student was found selling patient records to lawyers looking for malpractice cases.
5:47 pm: Discount card Almost home, Mark stops to buy deodorant and toilet paper; the card saves him 36 cents.
Who's watching: Supermarkets can link a customer's discount card to his name, address, e-mail address, phone number, social security number, and state ID (likely a driver's license) in a database that also includes a list of the products he's purchased. Grocery chains claim this data is used only to ensure that the most popular products are always on the shelves and to target discounts effectively; they say they do not sell, rent, or lease customer information. A former Food Lion employee, however, has said that during two separate periods between 1994 and 1999, he was instructed by his superiors to send the detailed purchasing preferences of customers, along with their names and addresses, to database marketing companies and major product manufacturers. Food Lion, which is based in Salisbury, North Carolina, has denied the allegation.
Meanwhile, Larry Ponemon, the CEO of Privacy Council, says that since September 11 he's been hired by at least one major supermarket chain to oversee the handing over to law enforcement agencies of the buying records of customers with specific ethnic backgrounds. The authorities requested the data, Ponemon says, because they were trying to compile a profile of "terrorist eating habits."
6:15 pm: Identity scanning Mark shows his driver's license to enter his favorite bar.
Who's watching: Before letting Mark in, the bouncer runs the license through a scanner that captures its magnetic strip data?hich, depending on the state, could include age, date of birth, address, social security number, fingerprint, and photo. Some scanners can hold as many as 64,000 records, providing a database of potentially embarrassing information?epending on the type of establishment?uch as who has been in the bar, how frequently, and when. Mark has a beer with friends.
7:03 pm: Tollbooths Mark drives through a toll plaza.
Who's watching: Mark's car has an I-Pass tag above the rearview mirror that lets him prepay tolls. The tag? transponder that's activated by a signal from an antenna at the tollgate?ends the I-Pass ID number and the price of the toll to the system's central database. If there's enough money in the driver's account to cover the toll, an OK is transmitted back and the car is allowed to proceed. At the same time, a record of the time the vehicle arrived and left the tollbooth is logged into the I-Pass database.
Because the system uses the standard 802.11 wireless transmission protocol, it's dangerously easy to hack, potentially allowing snoops to keep track of the movements of specific cars. What's more, law enforcement authorities regularly subpoena records from I-Pass and similar systems to monitor individuals suspected of illicit activity.
Toll lanes may also be routinely monitored by video surveillance to nab scofflaws. In general, three cameras monitor each booth: One is aimed at the vehicle, the coin machine, and the fare display; the second camera is focused on the car's rear license plate and the stoplight at the front of the booth; and the third camera watches for vandalism and other incidents by recording from above.
7:11 pm: GPS On his way to reassure his girlfriend at a new bistro, Mark gets lost.
Who's watching: Many new cars employ GPS-based navigation systems, which use a network of 24 satellites to help drivers find their way. The newest equipment also enables individuals to trace their own cars from a distance. For instance, parents can monitor the speed of teenage drivers; if they exceed a limit, the GPS system in the car will notify the parent, who can?ia the Internet, cellphone, or a pager?onk the horn to tell the teenager to slow down. This technology also opens the way for government agencies to monitor the movement of people suspected of illegal activity. Car rental companies have already adopted these systems aggressively. Two years ago, James Turner of New Haven, Connecticut, discovered that Acme Rent-A-Car had taken $450 from his bank account as a penalty for speeding?ased on information the company obtained by watching Turner's driving habits remotely. The company utilized a software program, AirIQ, that makes it possible to continuously monitor the location, speed, and direction of a fleet on digitized maps. Turner sued and won, because the state's Department of Consumer Protection ruled that Acme had not adequately notified him of the purpose of the GPS/AirIQ system. Still, more such cases seem inevitable.
Mark falls into bed feeling secure and anonymous. Just one thing's on his mind: how did that blood test turn out?

hobbes
07-08-2002, 18:19
From www.msnbc.com/news/768843.asp?pne=msn (http://www.msnbc.com/news/768843.asp?pne=msn)
‘Zilterio’ wreaks havoc with banks, Web sites
By Bob Sullivan MSNBC
June 20 — “Mr. Zilterio” is hardly shy about the havoc he wreaks at his computer. “Blackmailing is just a hobby for us, not a business. We like to be famous,” he says in an e-mail interview with MSNBC.com.
For over a year, Zilterio has been hacking into online companies and financial institutions, stealing data, then demanding extortion payments. Nine firms have paid him $150,000 “quiet money,” he claims. While the money may in fact be a fantasy — there’s no proof anyone has paid — the crimes are quite real, and he’s being sought by the FBI for extortion.
THE E-MAILS ALWAYS look the same, as if cut-and-pasted by someone on an assembly line: “I hate to inform you that your account has been hacked.” Tens of thousands of Internet users have received a note beginning like that from Zilterio, whose real identity is a mystery. It’s followed by personal details, such as name, address, e-mail address, and credit card numbers — and finally, the name of the Web site where the data was taken. “This site has a very weak security protection system and the database with credit cards and other personal information is not protected at all,”
Zilterio’s e-mails continue, in a transparent attempt to shift the blame for his crime. It’s their fault, because the company rejected his offer of “help,” the e-mails say. “Top management ... doesn’t care about their customers — you. They care only about their money.” Of course, Zilterio cares about the money too. In four high-profile extortion attempts which have been made public since October, he’s demanded close to $100,000.
None of the victims paid. Zilterio sent an unnerving e-mail to many of the 350,000 customers at Webcertificate.com last fall. Just a month ago, people who shopped at electronics retailer TheNerds.net got their share of Zilterio spam. He’s still threatening to release data taken from LinkLine, a small Internet service provider. And in April, Zilterio sent e-mails to reporters announcing he had stolen data from Fahnestock & Co. a stock brokerage.
All four firms have indicated they are working with federal authorities, including the U.S. Secret Service and the FBI, to help track down Zilterio. The FBI declined to discuss its ongoing investigations while the Secret Service said it had no current investigation of Zilterio.
But there are more than the four rather public extortion attempts. Mark Burnett, a private investigator hired by one of Zilterio’s victims, told MSNBC.com that several other extortion attempts have been kept quiet, and at least one victim has chosen to negotiate with the criminal. Another source familiar with the hunt for Zilterio said investigators believe he might be responsible for hundreds of computer break-ins. Zilterio said he has stolen data from over 15 companies, claiming nine have paid him off — eight U.S. companies, and one in Europe, to the tune of $150,000. “Usually they pay $15-20,000. We ask for 30-40, but they pay only 50 percent of our request,” he said.
THOUSANDS OF BANK STATEMENTS TAKEN
Zilterio also claimed his latest victim was a small mid-America bank named Home National Bank. In part to establish his identity, Zilterio told MSNBC.com he had accessed critical data at Homenational.com, the online arm of Home National Bank, a bank with 11 branches in Kansas, Oklahoma and Arizona. In an e-mail to MSNBC.com, Zilterio sent some of the data he had allegedly taken from the bank to prove he had accessed their systems. In the e-mail were thousands of customer bank statements, similar to the monthly statements mailed to homes and businesses. They included Social Security numbers, checking and savings account numbers, balance information — even lists of ATM withdrawals and cleared checks.
MSNBC.com provided the data to Home National to seek verification, but Home National’s director of operations, Joe Spiser, said the bank had “no comment” on the alleged incident. The data revealed very personal details — the amount of one customer’s Social Security check was visible, and another customer, sporting a balance of $99,000, ordered new checks for $41.50. Zilterio claimed to have 500 megabytes worth of these bank statements. He said he had tried to contact Home National, but had yet to hear back from the company.
ZILTERIO’S MISSION
Zilterio was relatively generous with his replies after initially contacting MSNBC.com, admittedly looking for publicity. “I do want fame only for one reason,” he wrote. “To show our future clients, that we don’t play a game, but all we offer is for real.” Zilterio, he claimed, is actually a group of eight hackers — three in Moscow, and five elsewhere in Russia. “Mr. Zilterio,” the correspondent and appointed spokesperson, wrote in good, even colloquial English, suggesting he’s either well educated, or lying. As usual, the alleged computer criminal offered twisted logic to defend his actions. Essentially: Web sites don’t care about security, and if we break in, it’s their fault.
On a Web site devoted to the group’s effort, there’s an extortionist’s manifesto, of sorts: “The situation with online security is very and very dangerous now. Almost 75 percent of all big e-commerce sites can be breaken in less than 2 hours. Customers should not trust these sites, but they do. These online shops and banks don’t pay enough to their software developers and technical directors maybe. We don’t know why, but this is what we have now. Our mission is to help companies to protect their customers’ data. There are many skilled hackers in our team. We can break almost any modern computer system, including online banks and big online shops. When we get access to such systems we notify their owners about it. Some companies are ready to cooperate and they get our help. We send them instructions about how to improve their systems and later we track the process of this improvement. These companies care about their customers. But some Internet sites don’t want to cooperate. In this case we notify all their customers about existing security loopholes. We do it to protect people against further lost of personal information. This is our mission.” The Web site was removed soon after it was viewed by MSNBC.com
AUCTION, CREDIT CARD FRAUD
The group’s name, Zilterio, has no special meaning, he said. “Zilterio — just a name. FBI asked me the same. Maybe you work for them?” he answered. And extortion is just their hobby, he said. The group spends most of its time engaging in other computer crimes, like “auctions fraud, credit card fraud, direct bank hacking,” though he admits it’s recently become harder to run fake electronics funds transfers through the U.S. system. That means most of their money comes from credit card fraud. He also claimed the group gained income the old-fashioned way, promising protection to any firm which paid them off. “We never reveal information about companies who cooperate with us,” he wrote, and again couldn’t provide any evidence that anyone had cooperated with them. “We help them to protect their systems against future possible attacks. And we monitors their systems in the future.”
NOT AFRAID OF FBI The group has done just about everything — except, until now, granting an interview — to call attention to itself. With each extortion attempt come dozens of clues: e-mail addresses, IP addresses, computer logs. Is the group afraid of getting caught? After all, last year, Russians Alexei Ivanov and Vasily Gorshkov were arrested in Seattle for extorting Internet companies after they were lured to the U.S. by FBI agents.
Not at all, Zilterio said, taking a potshot at the FBI. “Several FBI agents tried to catch me and my partners. They are not professionals, as we see for now. They even can’t do a detailed tracing of bank transactions,” he said. There may be truth to that claim, said Burnett, a private investigator who was hired to hunt for Zilterio after the group stole information from a firm that provides data to “financial companies.” He declined to name the victim. “He had the information for each customer of each of those companies,” Burnett said. “In all, he was asking for probably $200k-$300k in extortion money. None of these companies paid him and all worked with the FBI.” But the FBI didn’t work with Burnett. “What was interesting through all this was the lack of effort on the FBI’s part. They did very little investigation themselves,” Burnett said. “Most of the investigation work was done by myself. I tracked him down to a prepaid dialup ISP account in Ukraine. I had very strong evidence backing this all up, but I never heard anything more from the FBI about it,” he said. “It’s quite amazing that with all the e-mail accounts, break-ins, domain registrations, web hosting, etc. there must be a ton of evidence to track this guy down. .... I’d say the FBI is seriously dropping the ball on this case.”
Zilterio may be smart, but he — or they — is not perfect. Burnett said bank investigators have tracked and stopped any number of electronics transfers Zilterio attempted, including attacks on well-known banking Web sites. During the Webcertificate.com incident, Zilterio mistook temporary Webcertificate.com numbers for credit card numbers. Repeated attempts to embarrass the company with e-mails to customers actually backfired, since the Webcertificate numbers were easily voided. A $45,000 payment demand was ignored because the stolen data was almost worthless, according to the company. At other times, Zilterio’s actions have seemed a bit random, as if chaos was more the goal than financial gain.
EGGHEAD.COM BREAK-IN On the group’s now-vanished Web site, Zilterio hinted he was behind the Egghead.com credit card hack in December 2000, perhaps the most famous e-commerce credit card heist. Initially, the firm suggested 3.7 million card numbers were taken, but later, indicated a far fewer number had actually been downloaded. Still, the incident was costly for card-issuing bank, as many customers demanded replacement credit cards.
Zilterio even seemed a bit naive during negotiations with Fahnestock. According to an e-mail exchange he provided to MSNBC.com, he believed the company when it suggested his extortion terms were “reasonable” and it would pay for protection, “but then decided to refuse,” he said, seemingly unaware that the firm might have been merely stringing him along in cooperating with an FBI investigation, as other firms have done.
PASSPORT AS INSURANCE The exchange shows how unsophisticated the operation can be. As security that the data wouldn’t be released after payment, Zilterio offered Fahnestock “an ensurance document from me. It will contain my name, copy of my passport and you will send money to my personal account. If I try to do something with this info in the future, you will forward this document to FBI and I will have problems, as you understand. But if you will forward this document to cops before you pay me — my friends will send this info to public. Even if cops will catch me.”
The exchange happened in December, but Zilterio didn’t follow through on a threat until April 1, when several reporters received e-mails claiming Fahnestock data had been compromised. Then last month, when Zilterio sent e-mails to customers of TheNerds.net, he had yet to make any demands on the company. TheNerds.net site operator Jeremy Schneiderman was left confused, merely assuming an extortion note may come eventually. But as of June 19, no demand had been made on TheNerds.net. A spokesperson for Fahnestock said the firm hadn’t heard anything more from the criminal since the April 1 e-mail. “My guess is he’s sending out a couple of e-mails saying ‘Here’s what I can do to you,’” Schneiderman said when the hack was first announced.
MORE extortion ATTEMPTS COMING? And that is likely the reason he contacted MSNBC.com recently. Zilterio claimed to have information about a “very big and very famous U.S. payment system,” but declined to prove any details. If Zilterio has progressed from stealing meaningless Webcertificate numbers last August to thousands of bank statement records this spring, it’s conceivable he has committed more sophisticated crimes. But merely embarrassing the companies hasn’t worked in many cases — hence, perhaps, a new strategy for turning computer wits into dirty money. Zilterio just hasn’t revealed what that is yet.