
Got the Love Bug? Scared of spyware? Read all about what's keeping techies awake at night...
Published: 14 November 2006 12:30 GMT
You
You are the weakest link in the security chain - for the simple reason that it's easier to trick a human than a machine. A system is only as secure as its users are security savvy - and when it comes to computers something as rudimentary as a poor choice of password can create a flimsy door into a corporate network that even the most amateur of hackers can kick down.
Security from A to Z
Click on the links below to find out more...
A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day
But it's not just hackers breaking and entering - online fraudsters rely on duping end users to perpetrate their scams. Phishing is a technique that relies exclusively on tricking humans. Phishers send emails spoofed to appear as if they come from reputable outlets - such as banks or ecommerce companies - and the unwary reader is then hoodwinked into handing over confidential info such as bank account details and passwords. This allows the fraudster to skip past security systems without the hassle of having to crack them. (For more on phishing, read our Cheat Sheet.)
Another online con relying on the credulity of human nature is the so-called Nigerian 419 scam. Typically these scams originate as spam email that tells a long and convoluted story about a vast amount of money stuck in some far off African state, a share of which could find its way into your bank account if only you follow their instructions... (which usually involve requests for personal details and some kind of 'transaction fee').
Once someone takes the bait and replies to the original email the scam develops as the scammers attempt to cream off as much cash as they can by requesting advance fees. One 419er was so effective it took down a bank in Brazil. Armed with your bank account details and a photocopy of your passport and driving licence it also doesn't require a huge leap to commit identity theft.
To find out what happened when silicon.com replied to a 419 scam email click here.
Other common security slips made by users include opening infected email attachments and clicking on malicious links in spam email. This PR stunt, carried out by IT skills specialist The Training Camp at the start of this year, effectively illustrated the problem of staff not having a 'safety first' attitude when using the corporate network.
Human gullibility is not the only problem however - the end user is even more of a security risk if they are acting with malicious intent. A silicon.com analysis earlier this year warned businesses to consider threats 'from within' - such as employees with a grudge or those seeking to defraud the business.
The term for the criminal intent to 'hack the human' part of the security chain is social engineering. The techniques used vary widely but the premise is to apparently offer something desirable to a large number of users (such as pictures of naked celebrities) in order to trick them into clicking.
Job Title: Security Consultant Ethical Hacking / Penetration Testing Location: London (City) Salary: Competitive Job Type: Permenant NET2S is an ...
The Senior Medical Writer will: * Produce high quality scientific copy for a wide variety of medical communication products, including manuscripts, ...
A highly successful Investment Bank is seeking a strong Oracle Application Architect to come on board and work on numerous greenfield projects ...
CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.
Staffing Service Coordinates Sales Activities, Utilizes Business Intelligence With...
Teachers Association Turns to Centralized Data Repository to Improve Member Service
Financial-Software Leader Credits Productivity Boost, Reduced IT Costs to 2007 Software
United States Coast Guard Explores Potential to Enhance Training With Digital Note-Taking...
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... XP lives, the femtocell 'truth', BlackBerry bashing… Reader Comments of the Week
Martin Brampton The Brampton Factor: Open source 'brotherhood' closed to co-operation Where's the real sharing?