Pages

Showing posts with label Identity. Show all posts
Showing posts with label Identity. Show all posts

Apple to toughen identity verification for iCloud security

Apple will toughen security measures for iCloud password recovery, the company has confirmed, after shortcomings in telephone support were cited as key to a high-profile hack of one journalist’s digital life. The Cupertino firm had already frozen over-the-phone password resets earlier today, but has since told the LA Times that when the service is restored it will be following a new and more stringent security policy.

“We’ve temporarily suspended the ability to reset AppleID passwords over the phone,” Apple spokesperson Natalie Kerris said in a statement. “When we resume over-the-phone password resets, customers will be required to provide even stronger identity verification to reset their password.”

Concerns about Apple’s policies arose when journalist Mat Honan saw his digital life deleted in front of his eyes, after hackers used nuggets of personal data culled from different cloud services to convince iCloud customer care to grant them access. A temporary iCloud password was handed out after the hackers provided the final four digits of Honan’s credit card, a detail which Amazon customer services had freely given them access to.

Exactly what Apple’s policies will be when the service is restored is unclear, though Amazon has already apparently changed its system so as to reduce the likelihood of a repeat attack. Nonetheless, good data and account practices are still advised; there are suggestions as to how to stay safe amid the cloud here.

Read more >>

Avoid Identity Rip-Off At The Pump

$('#byline').hoverIntent( function(event) { $('#bylineExpanded').slideDown('fast'); }, function() { $('#bylineExpanded').hide(); } );
Get the in your inbox!

You can’t be too careful these days, it seems. While identify theft is commonly considered to be the realm of thieves obtaining sensitive information by hacking computers or sifting through personal trash, the fact is that you can have your identity, and your finances, hijacked by crooks at the gas pump as well.

According to the Federal Trade Commission (FTC), as many as nine million Americans have their identity stolen every year. While thieves bent on securing your identity use a variety of tactics, one that can affect you at the pump involves skimming.

Bank Info Security recently reported that pay-at-the-pump skimming has reached “epidemic” proportions, especially in Texas, Florida, California and other states. The National Association of Convenience Stores (NACS) says that while skimming accounts for relatively few compromises of card purchases at the fuel pump, the issue of master keys that allow access to pump enclosures is an “industry problem.”

Skimming usually involves the thief attaching a piece that looks like an extension to the card insertion slot at the gas pump. Other skimmers include a magnetic device, called a card cleaner, which collects your sensitive data. While card cleaners have been around for a while, the latest iteration is now smaller, more sensitive and harder to detect than before.

The NACS advises retailers to use the WeCare tamper-evident label that can help them identify potential security breaches if skimming devices are inserted in fuel dispensers. The security labels are to be used on fuel dispensers near the credit/debit area. If the label is lifted by thieves to insert a skimmer, a “void” message appears on the label and provides a visual alert to gas station employees so that additional action can be taken.

As a consumer, here are some of the things you can do to avoid having your identity and your finances purloined at the pump.

Look for the WeCare security label. The WeCare security label can help assure you that your data is secure, as well as to discourage crooks who may be targeting the gas station pumps.

Pay for gas inside. Sure, it’s a little less convenient and you may not be inclined to take the few extra steps before and after filling up the family car with fuel. But you’re much less likely to be ripped off by thieves if you pay inside the station instead of swiping your credit or ATM card at the pump. If you’re in an unfamiliar area, it’s much wiser to use this payment process than to trust that the pump is secure and free of skimmers thieves have placed there.

Use a pump closest to the cashier. Another suggestion is to park at the pump closest to the cashier, where you and your vehicle are in full view of the attendant. These high-visibility pumps are perhaps a little less likely to have been infiltrated by crooks attempting to steal your identity.

Watch out for anything suspicious. If possible, go to the same gas station you always use, or frequently use. Become familiar with how the pumps operate as well as what the card slots look like, and be on the lookout for anything out of the ordinary. Some identity theft protection experts recommend running your little finger over the card insertion area. That way, you may be able to detect if a card cleaner is there. It’s typically the size of a matchbox. If you think anything is off, let the gas station attendant know immediately.

Pay with cash. Thieves can’t skim your identity if you pay with cash. Obviously, this isn’t always practical, especially if you need to fill up a big SUV, since you may not carry that much cash with you. Again, if you’re in an unfamiliar area, you might want to either pay inside with your credit or debit card, as previously recommended, or just buy enough gas with cash until you get to a more familiar gas station in your neighborhood.

Read more >>

Who Owns Your Identity on the Social Web?

When I go to a bar, the bouncer usually stops me and asks for an ID. I show him my state-issued driver’s license and walk on by. This may be unusual, as I’m 36 (thanks, mom, for the good genes), but we’re all pretty accustomed to presenting our official identification when needed. We need IDs to vote in an election, and when we get pulled over for speeding. If identification is so commonplace in the physical world, why is it still such a hazy area on the Internet?

In the old days of web publishing, almost every site required its users to register in order to access certain functionalities, like commenting. However, each login was only useful to its corresponding website. Users had to remember a myriad of usernames and passwords just to read up on the morning news.

With the rise of social networks and search platforms, a few large B2C companies evolved into large-scale consumer identity providers (a.k.a. IdPs) — Facebook, Twitter and Google, among others. These companies began to fill the identity-management gap by giving users a few different IDs that worked across media websites. For instance, you can register using your Facebook or Twitter ID, and a few others (like Google) will be activated soon.

As many of you know, when you register on a media site with your Facebook or Twitter identity, you’re usually asked to give access to your profile data (like name and email address), and allow that site to publish to your feeds (like your News Feed on Facebook, or your Timeline on Twitter). Presumably, media sites, not unlike us, do this with the best of intentions. But they’re only going to publish content to your feed that you’ve expressed interest in, and then follow up with you via email, right? Maybe.

For instance, we just launched our Awards 2011 microsite. By registering with us using your Facebook or Twitter account, you can nominate your favorite company, person, site, game, app or gadget for any of the 28 categories. Once you nominate, we’ll publish a notification to both your Twitter and Facebook accounts. When your notification appears on your feed, presumably your friends will see it, and stop over to nominate their own favorites. (This is, in fact, what’s happening now, and the main reason why Awards is such a fun project for us.)

So, what’s the harm in this? None really, as long as this newfound power is wielded properly. In short, the media company posts to your feed when it’s supposed to. If you get annoyed, simply revoke access. You can take my word that we will use this access appropriately. But that’s just it: You have to take my word. Easier said than done.

There’s a great burden placed on identity providers to police the media companies that connect with their users. There’s also a great burden on media companies to fulfill and not violate the trust of their end-users, and to behave appropriately.

In the end, if we violate your trust, you’ll just revoke our access and probably not return. But, is that the best means of policing media companies, or more generally, is that the best way of policing access to your shared identity?

How can we prevent media companies from abusing this level of access to your identity?

Or, how can identity providers give users greater control without making the whole process too complicated?

Identity management, and more pointedly, identity ownership, is a topic of great concern. Many heated viewpoints exist; the only agreement so far is that the “driver’s license” of the Internet faces a long road of obstacles.
Read more >>
Next Post