October 23, 2009

Don't trust a public PC with your digital identity

Checking your e-mail at an airport or hotel kiosk exposes you to identity theft

Contrary to popular belief, stealing someone's digital identity is a snap. It almost seems as though the more we use digital identities, the easier they are to swipe. The reason can be attributed to general carelessness or perhaps outright ignorance, but whatever the case, letting your digital identity fall into the wrong hands can expose you and your organization to a world of headaches.

Case in point: I routinely use Pretty Good Privacy (PGP) and SMIME to secure e-mails and file transfers. Yet frequently, even somewhat knowledgeable IT security people get confused about which keys to use when. In order to for someone to send me encrypted content, I need to send that person my public key. Similarly, I need the recipient's public key so that I can send him or her encrypted content. We should never share private keys. That's why they are called private. Pretty simple -- or so you would think. More often than not, if the person isn't overly familiar with PGP/SMIME, even if they've been using it, they send me their private key.

[ Is your organization moving to Windows 7? Then be prepared: Check out InfoWorld's essential guide. | Tune in to the InfoWorld Security Central channel for the latest IT security news and reviews. ]

Being the good citizen that I am, I delete their private key and ask again for their public key, explaining that with their private key, I could be them, for all digital purposes. About half the newly educated group then sends back my public key back or, if they're using PGP, their private key ring, which contains all their private keys. You might think that I'm making this stuff up, but it's pretty much been this way with PKI and PGP exchanges since they were invented. PGP's own Phil Zimmerman has often written on this subject.

Real and virtual converge
The danger of having your digital identity stolen is dire. Increasingly, our digital identities are us. I now pay 95 percent of my bills online. My digital self has platinum status with several major hotels and airlines. I get monthly refills on some of my supplements and my family's medication from online stores. Even my dog gets her medicine in the mail. I've had my personal e-mail address for over a decade.

Moreover, Xbox and everything that virtual world entails knows me by my Microsoft Live ID. Netflix only knows me through my Xbox profile. Talk to anyone who has accidentally misaligned their Live ID and Xbox profile. It's a frustrating experience to have your digital self not synced with your real self.

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »
josephadeo 26-Oct-09 9:22am
A good write-up on a tricky topic. Tricky, indeed, because too often we're attracted to the convenience of the internet but aren't willing to take the proper measures to protect ourselves (ie, checking email on the hotel computer--something one should NEVER do, but then it begs the question of whether or not hotels should tempt us with their unprotected machines. I know when I'm away on business it's tough to resist the urge to wire in). But as with the public/private key example you give, it seems like education again is the answer, though making it sticky enough to be effective is tough. I work at VeriSign, and feel the need to mention two-factor authentication here, particularly since it's immune to some of the issues you mention above (even a handful of keylogging attacks, since it's a passive hack). It's likely, for example, that if Google or Hotmail offered 2FA for their respective clouds, it would cut down on credential harvesting. But I have to agree that staying off of public and shared computers is an essential protection strategy.

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.