Tuesday, January 31, 2012

Exam cheat caught using a spy pen

I found, and quite unusually so, that spy pens were heavily advertised on leading dailies and sold onboard flights in India. Spy pens can be used to make copies of documents, but with mobile phones around there is no need for an additional gadget. Today’s news “Gadget guru fails to crack it” demonstrated an innovative use of spy phones for cheating in examinations. The student in question inserted the cap of the spy phone with the camera in his shirt pocket. Each time he bent over the question paper the camera clicked an image and sent it via Bluetooth to a concealed mobile phone in his trouser, which then got relayed to a friend outside who quickly replied back with the answers via a hearing aid. Unfortunately for the student, due to an alert invigilator and a cctv monitoring system, he was caught when his apparatus failed to work and he was trying to fix it.

There are several such spy cameras available in the market inserted into innocuous objects like alarm clocks. These are cheap and used for monitoring people at work, conducting sting operations, in business discussions or filming victims in a state of undress. There are however, very few reported instances of this form of surveillance either because the victim chose to keep silent or was unaware of the incident. Unfortunately because these equipment are disguised it is difficult to detect, but it pays for women to keep their eye open when they visit changing rooms in stores and in common toilets. Airport worker fired for filming women on the toilet

Saturday, January 28, 2012

15 Categories that constitute Cybercrime

It is acknowledged that there is no comprehensive definition for Cybercrime. Definitions vary, as cybercrime is a new and rapidly evolving theme. Cybercrimes are crimes that a) are targeted against a computer system such as the theft of data or service interruption or b) crimes perpetuated through the use of a computer such as asset misappropriation and cyber harassment or c) where the computer is used as an accessory such as a file sharing site.

To me cybercrime has many dimensions from economical, social, ideological, military to political. Crimes may or may not have an economic impact and may be targeted against an individual, property or government.Cybercrime can be categorized in the following 15 categories:

Piracy and Copyright Infringement
Piracy in online goods such as music, films, ebooks, games and software is a 200m$ business. Piracy occurs when individuals share these products using file sharing sites. Sites which host pirated goods may also be liable.

Pornography, Pedophilia and prohibited sexual content
Pornographic content may be legal or illegal depending on country, but the act of child pornography or pornography which depicts violence in illegal everywhere. Some laws prevent creation, viewing and storage of content (i.e. the creator and user are both equally liable) or a subset.

Corporate Espionage
Corporate espionage is the act of insiders or external hackers infiltrating an organization to steal IPR or confidential business data.

Cyber Warfare
Cyber warfare involves the act of creating cyber weapons for offense and defense by military organizations. Cyber weapons may be designed to cripple the Internet or selectively cause destruction to parts of the critical national infrastructure like power, water, and nuclear plants. When some of these weapons are used without a declaration of war, this act in my opinion constitutes cybercrime. As part of cyber warfare there is a component of military espionage which involves the theft of military plans, documents, from defense organizations and their suppliers.

Terrorism
Cyber warfare carried out by ideological group’s intent on creating damage or disruption to nations or organizations opposed to their cause or belief. Individuals or groups disseminating information with a view to cause national panic or threaten key figures also falls into this category.

Hacktivism
Hacktivism is the act of undertaking denial of service attacks or hacking in protest against governments or organizations seemingly acting against the ideological beliefs of the Hacktivist.

Online Scams, Counterfeits, Drug Trafficking
The Internet abounds with online scams which deal in the sale of counterfeit or spurious goods, drugs, advance fee frauds (lottery scams), of frauds designed to dupe victims into voluntary donations or subscriptions. Most of these frauds perpetuate through email or social networks.

Social Crime
Social crime is the act of causing emotional distress through a deliberate act of harassment, bullying, slandering, black mail, hate, stalking, defamation, impersonation online. Common avenues for propagating such crime involve social media, smses, emails, tweets and blogs. Content is usually offensive or derogatory and targeted against a specific individual.

Identity Theft and Impersonation
Stealing a person’s credentials with the objective of either defrauding the individual for monetary gain or to use the person’s identity to commit or perpetuate fraud.

Spying
All forms of spying which are not sanctioned by law which violates an individual’s privacy. This includes software’s that spy on cellphones, reading emails and so forth. Such acts may be undertaken by individuals, detectives and agencies.

Insider Theft
Using computers or computer systems to commit economic fraud by employees. Computer systems may be used to manipulate internal records such as expenses and payments for individual gains. They may also be used for the willful destruction of records or theft of information for financial gains.

Hacking for profit by external parties
The act of infiltrating or disrupting the services a company offers for monetary gain by individuals or organized crime with intent to blackmail, cyber extortion, cause economic fraud or cause reputational damage. Such acts may be caused on behest of competitors.

Development of Malware, Botnets, and Sending Spam
Malware development or the setting up botnets with the intention of using them for illegal activities. Spam or sending bulk unsolicited mail is unlawful in certain countries.

Sabotage
Launching denials of service attacks or hacking websites with a view to disrupt their functioning for fun, protest or profit.

Obscene or offensive content
Websites designed to be offensive, hurtful, slanderous, derogatory, inflammatory, and seditious with respect to sections of society. This is sensitive area which typical ends up in a court for arbitration.

Friday, January 27, 2012

Personal Data Websites Collects Online

Google recently released its new Privacy Policy which explains what information it collects and its use in simple terms. It is important for each cybercitizen to fully understand the extent of  personal information that can be collected either because they voluntarily subscribed to a service or from the use of a particular service. This information could be aggregated to provide a 360 degree view of a cybercitizens online activity.

I have summarised relevant parts of Google’s privacy policy which provide a generic view of information either in part or whole, which may be available to websites that we interact with online. This information can be used by the webfirm, its partners, by law enforcement and by courts.

Information can be collected in two ways. Firstly, when we sign up for an online account, we normally provide personal information such as our name, email address, telephone number, photo or credit card number, and secondly when we visit a website and interact with ads and content.
During our online interactions with website, various types of personal information as outlined below can be collected:
    • Device information such as your hardware model, operating system version, unique device identifiers and mobile network information, including phone number.
    • Log information when services are used or content viewed information may be automatically collected and stored. This may include:  
      • details of how you used our service, such as your search queries.
      • telephony log information, such as your phone number, calling-party number, forwarding numbers, time and date of calls, duration of calls, SMS routing information and types of calls.
      • Internet protocol address
      • device event information, such as crashes, system activity, hardware settings, browser type, browser language, the date and time of your request and referral URL.
      • cookies that may uniquely identify your browser or your Account.
    • Location information Services which  may collect and process information about your actual location, such as GPS signals sent by a mobile device
    • Local storage  where personal information may be stored locally on user devices
    • Cookies and anonymous identifiers are used  to collect and store information when services are used or for services that websites offer partners such as advertising

Thursday, January 26, 2012

Google Scores A+ with new Privacy Policy

Google has set an example by being transparent in how it manages the privacy of personal information it collects from the use of its services. There is hue and cry over some aspects of its disclosures such as the need for an opt out option and the use of personal information for targeted advertisement, but we need to appreciate that GOOGLE with 70% market share did not have to write a simple policy which all its users could read and understand, but it did. It set an example which other firms do not. Let us commend and not condemn Google for this historic act.

Google says it intent is to use information shared with it to make its services even better – to show you more relevant search results and ads, to help you connect with people or to make sharing with others quicker and easier. They do not sell this information to third parties. Let us be fair, free services need to be paid for in some manner. Advertising is a great way to keep services free.
We should also appreciate steps taken in the right direction, so that other can follow suit without governments turning to regulation or censorship.