Criminals Of The Internet

I am fascinated by the ‘dark side’ of the Internet.  Maybe that’s because I was here (wherever here actually is), back when it all began… or close to it.

How long ago was that?  My first surfing of the Internet was done with a browser (Lynx) that only saw text – no images, much less multimedia content.  I remember sending a  technical comment to Yahoo!.  The person responding (get an actual person to respond today) said he’s pass it along to “Jerry.”  He was talking about  Jerry Yang, Yahoo’s co-founder.

The Internet was trustworthy.  In fact, many of the Internet’s biggest weaknesses are caused by the innocence of software coders who didn’t feel it was necessary to verify much of anything because it was a relatively small group of American geeks – mostly affiliated with colleges, universities or the military.

When I send email from home on my geofffox.com account, it comes from servers run by Comcast.  The same mail, sent from work, comes from a server I use at 1and1.com (not the station’s mail server).  I hardly ever use the server assigned to geofffox.com (long story about its dependability).

No one checks to make sure I really am entitled to use geofffox.com.  I could use anything as my return address with little fear of getting caught or suffering consequences!

It’s that ability to do what you wish with little scrutiny that has allowed parts of the Internet to become a cesspool.

I am often call upon to fix friend’s computers that have slowed down, as if a computer was a mechanical device that doesn’t run quite as well with age.  Of course the real reason for the slowdown is that they’ve been bogged down by hidden garbage on our trustworthy Internet

I read a long article, Invasion of the Computer Snatchers , in today’s Washington Post that shows how far all this scamming is going.  It’s scary.

Compromised computers are turned into ‘bots.’  It’s the PC equivalent of “Invasion of the Body Snatchers.”

As is so often the case with crime, a few criminals can affect hundreds or thousands of unsuspecting computer owners.  And, since the thieves and scammers are giving away your time or money or convenience, they really don’t care how insidious their actions are.

What I don’t understand is why there isn’t a more concentrated effort to crack down on this crime?  OK – maybe mere individuals don’t have much pull, but Citibank, Bank of America, PayPal and others must.

And, since at some point these transactions must lead to the movement of money – why can’t it be tracked down and stopped?  I just don’t get it.

The Internet has such an incredible promise, which will never come to fruition if the net is allowed to remain the cyber equivalent of Times Square, circa 1975.

ChoicePoint Gets Company

You can’t make this stuff up. No sooner did ChoicePoint blaze the trail in purloined data than Bank of America felt the need to join the club!

Bank of America Corp. has lost computer data tapes containing personal information on 1.2 million federal employees, including some members of the U.S. Senate.

The lost data includes Social Security numbers and account information that could make customers of a federal government charge card program vulnerable to identity theft.

Bank of America says they’re taking responsibility. That means they’re admitting what they did. Taking responsibility is a far cry from that and, so far, I see no sign that’s happening.

Dubious Achievements in Credit Cards

Today, in the mail, we received some new credit cards from Bank of America. These are attached to our USAir mileage account – and we only use this account as a backup.

Along with the normal ‘full sized’ cards came a “mini card”. At 1.5 by 2.5″, it’s just a fraction of what you’ve seen for years. On one end a hole is punched in the card. The idea, clip it to your keychain and carry it wherever you go.

So far, so good… though there is a problem. I never give my wallet to strangers, but I give my car keys to strangers all the time. Now, these strangers will have my credit card number.

Actually, for a while they’ll have the physical card, magnetic stripe and all!

In an age where identity theft is rampant, isn’t this a little foolhardy? Even if Bank of America indemnifies me for every penny fraudulently spent, there is the secondary cost of identity theft – time and effort spent to reclaim your life.

I’m thinking, unless I hear compelling evidence to the contrary, this isn’t going on my keychain.

Another “Phishing” Expedition

The term is “phishing.” A phony email is sent, purporting to be from a company you do business with, asking for private information. I wrote, only a few days ago, about a bogus note from Bank of America. Tonight, it’s Citibank!

Dear Citibank Account Holder,

On January 10th 2004 Citibank had to block some accounts in our system connected with money laundering, credit card fraud, terrorism and check fraud activity. The information in regards to those accounts has been passed to our correspondent banks, local, federal and international authorities.

Due to our extensive database operations some accounts may have been changed. We are asking our customers to check their checking and savings accounts if they are active or if their current balance is correct.

Citibank notifies all it’s customers in cases of high fraud or criminal activity and asks you to check your account’s balances. If you suspect or have found any fraud activity on your account please let us know by logging in at the link below.

I’m not a Citibank customer, so I knew immediately this was bogus. Even if I had missed it, Popfile called it spam. Good job!

The last time I put one of these up, McAffee Virus Scanner stopped some people from getting to my site, so I’ve eliminated the link in this one – it’s phony anyway!

Today’s phishing expedition originated with email sent from an account on wideopenwest.com, a high speed Internet service provider (like cable modem or DSL) here in the U.S. The link on the email opens a form that looks exactly like a Citibank form (in fact, it’s probably taken from their site), but it sends the posted data, including credit card and pin, to a site in Korea!

We’re rapidly approaching email meltdown! How long can commerce survive in this untrustworthy environment?

—-

01/11/04 10:38 PM – I have just reported this incident to Citibank via their weblink. I’ll let you know if they respond.