Friday, September 30, 2011

CCTV’s ring down petty thefts in Mumbai

The use of CCTV camera’s in developed countries largely acted as forensic tool to trace criminals. Many of whom now wear masks to remain anonymous. In India however, the CCTV camera has proved its importance as a tool to bring down the rising menace of petty theft that takes places on crowded roads and streets.
Indian women normally always wear a gold necklace as a symbol of marriage or as a custom. Gold prices have hit the roof, making gold items a hot pick. Bike borne thieves snatch these chains and purses, from pedestrian women or from those seated in autoricksaws (canopied semiopen three wheelers).
While the state police forces try to fund acity surveillance networks, CCTV's installed by shop owners in crowded markets have proved a quick deterrent as they enable cops to identify the thieves and/or their motorcycle number making it difficult for helmet borne thieves to escape. There has been a steep drop in crime in these areas.

Thursday, September 29, 2011

Believe it or Not! A Fake Police Academy

In the city of Mumbai there were several reports of crooks impersonating policemen committing petty crime. An elderly couple from my neighborhood were recently stopped on the way to a night party and conned of their jewelry by fake cops. Few would have suspected that these impersonations were actually an organized crime ring complete with its own fake academy to train cops. When the ring was busted and the racket exposed, I was amazed at the quality of management and practices used to commit these crimes.
For starters, each recruit was carefully selected based on their credentials which were height, build, basic education to pick up legal terms, command over the local language and confidence to pull off the role. Each fake cop was trained and equipped with police uniforms, id cards and hand cuffs. Trainees were shown how cops spoke, dressed, walked and where they ate. Before entry into the gang, trained recruits were sent on test runs to con women of their jewelry or extort money from hoteliers. Only if successful they were drafted into the gang. Those who did not make it were employed for hard crimes such as robberies, extortion and kidnapping.
Similar methods are used by criminals who indulge in cybercrime such as email scams.

Tuesday, July 26, 2011

Board Members need to review Information Security on par with Financials!

The News of the World Phone Hacking Scandal made a big splash on world headlines. The scandal where reporters allegedly paid hackers to hack into the voicemails of prominent people, celebrities and even a young murder victim to create front page news for the tabloid enraged UK. The drama continued with Rupert Murdoch and his son James being placed in front of a congressional committee, embarrassing links to the UK Prime minister, police force and the voluntary closure of the Tabloid. The effects ran deep, eroding the brand value of the largest media empire, the credibility of a powerful entrepreneur, brought up uncomfortable questions on the integrity of the newsgroup’s acquisitions and impacted stock value.
In the congressional review, Rupert Murdoch said he was unaware of what was going on. I believe him, but does that absolve him of accountability. In the eyes of the parliament and people it did not.
This incident is not isolated. There are others where companies have not ensured the security of private data and suffered serious data breaches. In each of these cases the answer from the board was “I did not know”.
All these examples had the boards offering a public apology for what happened. This in itself underlines how significant the reputational impact of such a breach is on today’s Internet Savvy consumers.
The most significant learning is that security and safety are board room issues. The Board has to review the security dashboard of an organization in the same way it reviews its financial numbers. No longer will Boards have the luxury of treating information security as a hygiene factors and feign ignorance.
The writing is on the wall.

Related Reads:

How CEO’s can pass the Security Test? A letter to CEO’s

Thursday, June 23, 2011

Can Enterprises Crowdsource Security Testing of their Websites?

The rate at which external websites are being hacked demonstrates the lack of an effective defensive mechanism in enterprises. Cyber laws were created to safeguard against script kiddies from hacking into websites and defacing them. These laws scared away much of the early warning system that could have been in place. Hacking for fun is vastly different from hacking for profit.
Would enterprises pay fees to individuals who hacked and privately disclosed flaws be an effective option to find web flaws? Or would it lead to anarchy and mayhem.
Such programs have been in use by product vendors, but not by enterprises.
The advantages:
1.       High Quality Testing
2.       Frequent Testing
3.       Will keep security and IT team on their toes
4.       Reduce the motivation to hack for profit
5.       Value for money as payment will be outcome based.
The disadvantages:
1.       Affect site performance
2.       Reduce the effectiveness of the cyberlaws
3.       Encourage script kiddies
4.       May not be practical to implement
On the whole, I believe a crowd sourcing approach will be a net positive. It will motivate the good guys more that laws deter the bad guys.
I must add a disclaimer to this blog. These are a thoughts and not a recommendation. The key lies in the practicality and legality of the method used for implementation.