Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Monday, July 31, 2023

Needless exposures

 It is a matter of grave concern that people are increasingly exposing their personal data , more dangerously the individual photos in public forums. Of late, there are many posts in social networks stating "today is my or my daughter's birthday" and post their latest photos. Just out of curiosity and with academic interest,  I pried further into the profile of the author of the post. Though the person is not in my friend list I was still able to have a good look at important features of their whole profile including their location, their previous photos, siblings, family  and I could say to a fair extent I had enough data to re-build the person's profile to my liking. With some more hunting with the latest sophisticated tools, I am very sure the complete profile of the person who is unknown to the intruder could be built. 

In another post, I saw a senior person posting his photograph at an international airport stating that he will be away from the heat and dust of India for the next six months. I am concerned that how much of efforts will be required to trace the person's house in his native place, which was visible in the social network, and what a field day the miscreants would have should they chose to pay a visit to the locked house !

Recently, I was fortunate to attend a lecture by a leading cyber law advocate who precisely but  elaborately dealt on how photos in unprotected social platforms could be misused and with what  consequences. He detailed that such photos in public forums are picked up methodically every few minutes and then analyzed for their utility (?) values, with the single photo of young women fetching the maximum for obvious reasons and how they could be used to milk further from the hapless victims. 

I sincerely wish such people who keep on sharing their profiles and programmes 'to all' learn more about the 'Dark net' and their activities !! People who frequent social network and boast that they could never live without it should better remember that whatever is posted in such public places are like matters dropped in the ocean and even if it is deleted within minutes, they are already into the hands of those whom you would not like to encounter. Present day technologies offer so much of tools that it is almost possible to recover and bring back anything except lost souls !

Already people in other countries are reported to be avoiding sharing pictures of the children with so many cases of paedophiles in the news. 

So dear friends, please refrain from sharing any travel updates or making such begging for blessings and also avoid posting the pictures of children. Cyber world is far more dangerous than the world we are used to and assume to be .

Shared in the public interest of being forewarned than repenting in leisure !!

Friday, October 18, 2019

Safeguarding personal data

The ease with which our personal data is being sought, the thoughtlessness in handing over the critical data relating to one and the reckless way in which such details are shared in public domain is scary, to say the least.

Recently, I attended a spiritually oriented event of a very popular and revered person who gives discourses on Ramayana, Bhagavatham, Narayaneeyam and other such spiritual activities attracting many devotees. At the event, it was announced that an exclusive group is being formed so that interested people are communicated about further events and to join the group a link was sent. The link led to a web page that asked for many personal data related to the potential member of the group. The page also warned that on submission, the name and photo associated with that particular account will be uploaded! Let me clarify at the outset, I have absolutely no issues in personal data being shared with this particular Group/ Event Management team as they are reliable, reputed and I have no reason to believe that they could leave the data unprotected leading to misuse.

But, the thought occurred as to what would happen, if the data so given is shared unintentionally but as part of further processing to some other third party organization, for maintenance? Or what is the guarantee of that third party keeping such data secure? What if there is a leak somewhere in this process, wherein data could be compromised and if so who is responsible for the same ?

So, while the persons seeking data may not be leaking or misusing it but are they aware of the risks and sensitivity of handling the same? More importantly in a group which is unlikely to be filled with only literates, what is their responsibility in seeking such data? In a belief blinded by other attractions and with some justifiable confidence on this group, many people are likely to share the data. But then, should the data seekers not perform their role and responsibilities in apprising the givers about the risks involved and / or confirming about their safety and security by an assurance of non-sharing with others without their consent ?

Normally with some technical know how, I believe, a reasonable profile outline could be created with one's expanded name, date of birth, contact number, email-id and photo. With the prevailing and proliferating instances of cyber crimes particularly over online banking transactions and with innovative cyber crimes like Sim Swap springing up everyday, while the basic security concern lie with the owner of the data, given the illiteracy and lack of awareness, should the data seekers not apprise the givers about the risks involved, so that the innocence and ignorance of the users are not exploited by some unscrupulous elements?

In another group, filled with bankers who could justifiably boast of atleast three decades of banking service, it is still a task to make them understand the risks in sending a mail to all thousand members and use of BCC in emails ! This is a classic case of the data collector unwittingly leaking personal data, which could have damning consequences !  Well then, can an ignorance be cited as an excuse ?

At the entrance of a popular saree shop in Chennai's busy Pondy bazaar, an young man with a neat neck tie was asking for the mobile number of all visitors under the guise of a free prize scheme!!

When the data collected at such different points are collated by any with crooked intention, will it be a huge task to build their profile? The above instances exhibit how personal data is collected with or without any dubious intention and this is what exactly common man should be aware of  before sharing his data.

I feel, fighting cyber crime must be multi-pronged - while the owners need to keep their personal data safe, the data seekers need to ensure privacy of data collected and also make sure that  before collecting the data, the provider is well informed about the risks involved in sharing. Organizations like Banks and other institutions should not only take up measures to ensure that data collected and also created out of the data provided and out of the business transactions are kept secure, but also subject themselves to security audits by recognized bodies or approved and qualified third party auditors, to gain customer confidence. Right now , these are being held more as a formal exercise towards compliance but the need of the hour is more towards customer protection than formal compliance to satisfy legal requirements

My point is data seekers should be more responsible in asking for data, as such acts could be misused by mischief mongers. For the well intentioned seekers- apprise the givers about the risks involved and the measures taken by them to protect their interest and also better not to ask for such data, unless they have the ways and means to protect them!   More importantly, individuals should be weary of sharing any data , unless absolutely essential or feel secured after a basic personal due diligence.  

Friday, November 7, 2014

Fraud out of Greed !

Today's THE HINDU has reported an incident as 'Vishing' wherein a woman has been defrauded by promising to send an expensive gift, as her phone number was selected in a lucky draw.  After she  sent   Rs 2000/- as courier charges, the 'gift'  received contained  not an iPhone but just few hundred rupees worth of cheap cosmetic items. The cyber crime police investigating this has said  ' there are many such complaints 
 received with similar modus operandi'  !

This is an age old trick and despite the communication and media channels available, its a pity that people are still falling for it.

Though it certainly falls under the category of a fraud, can we do anything to refrain from becoming a 'Victim'? The answer is certainly a big 'Yes'.

Has one not heard about the Nigerian and other scams promising jobs and luring the potential victims to send only the postal charges?

Realistically, can you think of any organisation awarding you with a very expensive gift, for nothing? 

If the org was going to give such an expensive gift, won't they also bear the accompanying courier charges? 

There are many such instances of Emails, short messages and phone calls luring people to part with their personal details such as address, phone numbers and IDs, only to make money out of them rather than parting with any gift. 

In my opinion, such frauds are happening only with the involuntary connivance of the victim! Yes, though the victim has not directly contributed, his/her greed has made the victim also an accomplice.

Let us remember that all those blinking advertisements in the websites you visit, 'click here for a pot of gold' like messages are all meant to lure the gullible.

Understand that not only the innocents are targeted but also the tech-savvy, who in a momentary lapse of mind and act of foolery or more out of persistent annoyance of emails or advertisement, could press that fatal link. 

I am reminded of a huge hoarding outside an erstwhile finance company in Royapettah (Chennai) which proclaimed " Nothing in this world is for free;  the worm at the end of the rod is, after all, a bait and not food for the fish" !!

That the said company also went bust with depositors' money is of course a different story !!

Wednesday, October 15, 2014

Resist the Unknown

In those days, most of the parents used to advise their kids 'not to venture into unknown areas' when they go on a school / college excursions. This singular advice appears to stand true despite the passing of decades.

Gone are the days, when people had to experiment and innovate always, even despite the criticism that curiosity may kill the cat.  These days in the current scenario, the cyber jungle though fraught with myriads of lurking dangers, often lures one to experiment and venture in to the newer areas in the cyberspace.

When one opens the personal email, at times there are many more emails in the spam folder than the Inbox! It could be a claimed ‘official looking’ email from the highest bank of the country announcing your selection for receiving some unclaimed balances in a non-operative bank account! There could be an email from an African country announcing that you have won a million dollar lottery! There could be one just with the single word 'Congratulation' as the subject. There may be others which could warn you that a virus has been detected in your laptop and to click to rectify the same, 'absolutely free of cost'! These are absolute bombs waiting to electronically explode, invade and make away with your data, on a momentary madness of a click on an innocuous looking link.

When one chooses to run away from the email threats into the waiting arms of his friends through social networking sites, there are multitudes of blinking invites awaiting attention on both sides of your operative areas offering more information on the cheapest flight to a destination you were looking for last week. There will be any number of groups , which will be suggested to befriend, courtesy the analytical potential of your own social networking site, which has voluntarily undertaken to (mis)use your data to make an analysis and offer you suggestions. There will be dozens of alternates to a mobile phone you have 'like'ed and at a comparatively cheaper cost than the one, you propose to buy.

Looking to get some peace by closing the laptop, there are any number of phone calls offering you unsolicited advice on a potential purchase for the approaching festival season and requesting you to share your credit/debit card details for further processing of higher loans and incentives.

The unsolicited intrusions into one’s personal life is on the increase and days are not far off when your personal doctor could advise you to stay away from your electronic gadgets for a day of your weekend to regain acceptable levels of your pressure and vitals.

In all the above, there are baits thrown, for the unsuspected, ignorant, greedy and morons. As Mark Twain says “There is a charm about the forbidden that makes it unspeakably desirable.” 

If one could not sight the twirling worm at the end of the rod, it is not far off before he himself hangs there as a bait at the end of the pole. Nothing in this world comes free. The worm at the end of the rod is not for your appetite but to lure you off information.

One is forced to have a day of upavas and to practice the focus of the legendary character Arjuna sighting only the target, so that one is not distracted, one is not tempted and one does not fall a prey, only to rue shortly thereafter.

Please be informed and educate your near and dear ones - not to click on unconfirmed or unknown links and not share information on callers claiming to be from your bank and air your requirements in the Net.   

For, there lies a jungle with deadlier snakes and man-eaters, waiting to pounce on your purse and personal information, devour everything and strip you naked, before you log out and close your system.

Remember “The problem with temptation is that you may not get another chance"

NOTE: Above is my contribution as Editorial, for the eZine of Cyber Society of  India , an abridged version of which has been published in the ezine released today through the website www.cysi.in

Tuesday, June 11, 2013

Sweeping, Seeping and Snooping

Of late, I find many voluntary and service minded organizations indulging in cleaning the surroundings , clearing the lakes of weeds etc., This is a laudable effort in that it shows the involvement and commitment of the individuals towards a better environment that promises a better tomorrow. On the flip side, I also feel whether this could be a solution for the problems littered around us. If some organizations and good hearted people clean the place for a day or two, what lasting benefits is it going to bring? Will this not lull the civic authorities also? I feel that instead of OR in addition to this, such organizations could join hands and pressurize the civic authorities to do do their jobs. It will be better for such organizations to play a supervisory role,  monitor and track their progress instead of taking the brooms themselves. This is with due respect to these organizations and individuals whose efforts I applaud and in no way this is meant to disrespect or degrade their efforts. This is only a thought viewed with a different hat.

It is pathetic to hear about the technical and civil glitches that is surrounding the  newly built  airport terminals at Chennai. It began with the faulty design of the ramp, then a section of the roof or its false ceiling caved in and the latest is the seepage of the  roof. What is surprising is that if the roof seeps for the rain which lashed Chennai for hardly an hour, how will it stand the real fury of the North east monsoon? What happened to the quality standards and controls that are more talked about than implemented? What about the ownership of such misses that could turn costly? It is pathetic because, we talk so much but in reality none of these is observed or implemented.

On to the snooping of the US governmental agencies of one's data through the Gmail, Skype etc., - Shocking to say the least. Particularly from a country which regards high the privacy and rights of individuals, this is the least expected. At the same time, I admire the US President in admitting openly about its attempted peep at others' data, which also show the intentions of the Govt that appears to be genuine.

But, from a layman's perspective I have always wondered as to how on giving your password all the mail, cloud data  etc., are retrieved. This means someone has access to all your data and he goes on to retrieve your personal data even if your security details are lost by you after checking with some personal and private questions. For a query as to why this org which is storing the data of millions of people across the world are not (mis)using them, my conceivable answer is he does not have time to look into all the mails. If this appears naive, remember, my earlier claim of 'layman' here. But, in the unfortunate event of some sensitive data getting into the wrong hands , then you are done and dusted.

But then, it could also be argued that no one pressurized you to store all these data in a public domain protected by private people. It was on your own volition, you chose to believe them as it is without any service charges and so one has to pay for the same. It will be prudent to park only  banal data in such sensitive areas and not your private data such as passwords, bank account details, credit/debit card details, online transaction passwords etc., Prudence is more required and it is the innocent and the gullible and at times even a careless scholar could become a victim here. So, use your discretion.

If you want unhindered services, accesible from across the world with few clicks but with no cost, then one needs to be cautious. You cannot have the cake and eat it too - right ??