Saturday, July 14, 2007

総務省、携帯電話の本人確認義務違反でソフトバンクモバイルを指導

総務省、携帯電話の本人確認義務違反でソフトバンクモバイルを指導

永井美智子(編集部)

2007/06/12 17:55


 総務省は6月12日、携帯電話の新規契約時に契約者の本人確認を怠ったとして、携帯電話販売代理店のケアアンドコミュニケーションに是正命令を出した。また、監督義務を負うソフトバンクモバイルに再発防止を指導した。

 携帯電話が犯罪等に使われないようにするため、総務省では携帯電話不正利用防止法という法律で契約者の本人確認を義務付けている。しかしケアアンドコミュニケーションは2007年2月、法律が求める方法で本人確認をせずに、24件の契約を結んだ。これを重く見た総務省は、ケアアンドコミュニケーションに対して是正を命じた。

 また、契約した通信事業者がソフトバンクモバイルであったことから、同社に対して再発防止策を確実に実行すること、代理店に対する監督を再度徹底するよう指導した。なお、今回の問題はソフトバンクモバイルからの申告を受けて発覚した。

携帯電話、目で本人確認・沖電気が認証ソフト

携帯電話、目で本人確認・沖電気が認証ソフト

 沖電気工業は携帯電話の所有者を目の色や瞳の形で簡単に認証できるソフトを開発した。2年以内に200万台の端末への搭載を目指す。NTTデータは携帯のネット接続サービスを利用する際の本人認証に、高度な暗号が使えるサービスを2011年にも始める。携帯を使った電子マネー利用も拡大し、紛失・不正利用による被害や個人情報漏洩(ろうえい)のリスクが高まる中、セキュリティー関連市場を開拓する。

 沖電気が製品化したソフトは「アイリス」(商品名)。通常の携帯電話に搭載したカメラで写した虹彩によって所有者を認証する。(10:08)

Friday, June 1, 2007

Trend Micro gains allies in Cisco and Tech Data

Trend Micro gains allies in Cisco and Tech Data

Security vendor piggybacks on networking giant's channel programs to boost margins for partners
5/24/2007 10:39:00 AM
by Paolo Del Nibletto

Trend Micro maybe the third most recognized security vendor behind Symantec and McAfee, but it is trying to become the top margin provider in the already over-crowded market.

One of the ways it's doing so by leveraging a new alliance with Cisco Systems and its channel partners.

According to Pat Kewin, director Canada for Trend Micro Inc. margin levels go on top of what Cisco Systems is offering in its VIP, OIP and SIP programs.

“If a Cisco VAR sells Trend Micro along with the Cisco solution with an attach strategy, they'll have an extremely rich security sale,” he said.

For example, the Cisco VAR would net 14 or 15 per cent off of any advanced technology sale. By adding Trend Micro with that solution they would be reward with an additional five to 24 per cent. In the end, the deal could net a reseller close to 40 per cent of margin.

Without Cisco, traditional Trend Micro partners would get between five and 19 per cent in margin.

Trend Micro, based in Cupertino, Calif., has only six Cisco partners in Canada in its SecureOne partner program at the moment, but Kewin sees this as a growth opportunity to sign more Cisco partners.

In 2005, Trend Micro's Canadian office gained 49 per cent revenue growth. Last year, because of much higher revenue, the division reported a 22 per cent uplift, which is still above the industry average, said Kewin.

“Customers are making the move to Trend Micro. I believe a share shift has happened and the Cisco channel alliance provided some lift to grow the numbers. Customers who are with Cisco are now engaged by Trend Micro,” Kewin said.

The Cisco partnership was in a way future-proofing Trend Micro and its technology in the market. Kewin said customers know Cisco infrastructure and its Adaptive Security Architecture (ASA), which is a blade with Trend Micro technology for firewall and spyware.

The Cisco alliance became part of Trend Micro's channel expansion in Canada. The subsidiary has only two distribution partners here: Broadliner Tech Data Canada and Interwork, which is a security specialist. Back in 2005, Trend Micro Canada had only 200 channel partners. Today it has 400.

“The channel expansion focused on Cisco VARs because not many of them have a security practice, but they do look to stop threats and attacks at the networking layer,” Kewin said.

Trend Micro also made another significant deal with Tech Data. Through the distributor, reseller can get access to Trend Micro usage-based licensing program. This program will be rollout in Canada shortly, Kewin said. It will also enable resellers to go out and offering a managed service in a usage-based model.

“Smaller VARs can buy licenses and get more annual revenues, while customers can cut out capital costs,” he said.

Comment: cdnedit@itbusiness.ca

Saturday, May 5, 2007

Wi-fi users warned to beware of evil twins

From Times Online
January 20, 2005
Wi-fi users warned to beware of evil twins
By Holden Frith, Times Online

Wireless internet users were warned today that they could be at risk from “evil twins”, bogus internet connections set up by fraudsters to mimic the real thing.

People connecting to the internet using wireless technology, known as wi-fi, may think that they have logged in to a bona fide internet provider and then unknowingly submit personal details such as bank passwords and credit card numbers to criminals.

Firewalls and other internet security devices offer little protection as the user has, in effect, voluntarily logged on to the fraudster's network.

“Users need to be wary of not using their wi-fi enabled laptops or other portable devices in order to conduct financial transactions or anything that is of a sensitive personal nature,” said Professor Brian Collins from Cranfield University, a former chief scientist at GCHQ, the Government's electronic eavesdropping station.

Instead of using cables, wi-fi devices link to the internet by sending radio waves to a nearby “hotspot” which relays data to the internet service provider. This makes them more vulnerable to attack, as anyone with suitable equipment can locate a hotspot and take its place, substituting their own “evil twin”.

Dr Phil Nobles, a wireless internet and cybercrime expert at Cranfield University, near Swindon, said that the evil twin hotspots present a hidden danger for web users.

“In essence, users think they've logged on to a wireless hotspot connection when in fact they've been tricked to connect to the attacker's unauthorised base station,” he said. “The latter jams the connection to a legitimate base station by sending a stronger signal within close proximity to the wireless client.

“Cybercriminals don't have to be that clever to carry out such an attack. Because wireless networks are based on radio signals they can be easily detected by unauthorised users tuning into the same frequency.”

Unwitting web users are invited to log into the attacker's server with bogus login prompts that may masquerade as a bank or email login page, tempting them to give away sensitive information such as user names and passwords.

Users may be unaware that they have been duped until well after the incident has occurred, allowing fraudsters time to make use of the stolen details.

Dr Nobles spelled out the warning today at a wireless crime event held at the Dana Centre, the Science Museum's forum for discussing controversial science, in London.

Lisa Jamieson, head of programmes at the Dana Centre, said, “Half of all business wireless networks in this country have inadequate security controls in place, making their information vulnerable to attack.”

Hackers target wi-fi hotspots in new phishing attack


From Times Online
May 4, 2007
Hackers target wi-fi hotspots in new phishing attack
Starbucks has been targeted by hackers using 'evil twin' wi-fi networks

Jonathan Richards

Computer users have been warned of the dangers of using wi-fi hotspots after it emerged that cyber-criminals are targeting the networks in café chains including Starbucks.

Times Online has uncovered evidence that criminals are using a technique known as an 'evil twin attack', where victims think that they are logging on to the genuine network in a café but are in fact being diverted to a 'rogue' connection.

Once logged on to the twin network, the victim's every keystroke is captured by the fraudster, who controls the connection from a nearby laptop and uses it to extract information for the purpose of committing identity fraud.

In a chatroom used to discuss the technique, also known as a 'man in the middle' attack, Times Online saw information changing hands about how security at wi-fi hotspots – of which there are now more than 10,000 in the UK – can be bypassed.


During one exchange in a forum entitled 'T-Mobile or Starbucks hotspot', a user named aarona567 asks: "will a man in the middle type attack prove effective? Any input/suggestions greatly appreciated?"

"It's easy," a poster called 'itseme' replies, before giving details about how the fake network should be set up. "Works very well," he continues. "The only problem is,that its very slow ~3-4 Kb/s...."

Another participant, called 'baalpeteor', says: "I am now able to tunnel my way around public hotspot logins...It works GREAT. The dns method now seems to work pass starbucks login."

From the language used, the criminals appear to be US-based, though at one point one says: "i doubt that the architecture of the tmobile hotspot networks in europe varies from the technologies deployed here in the US."

T-Mobile, which runs a network of 2,000 hotspots, including those in Starbucks cafés, said it was aware of the technique, but was yet to have any incident reported in the UK. It advised customers to update their virus protection software and "ensure they were connected to a valid, certified website."

Security experts said, however, that safeguards such as digital certificates could not always guarantee protection, and that users would continue to be fooled by imitation sites, which were increasingly sophisticated.

"This is the most pressing current security threat that remains to be addressed," Paul Cronin, technical director at Pentura, which test wireless security, said. "People are spending all this money on firewalls and yet their machines with wireless cards immediately go searching for the nearest network."

"It's shocking how easy it is to set up a 'soft access point' and get devices to connect to it," he added

A police source said that evil twin attacks were 'not uncommon', but that they mostly went undiscovered. The problem was being "talked about", according to a spokeswoman for the Metropolitan Police, but she said there had been no reports of any crimes yet.

In a speech about wireless security last week, Phil Cracknell, a technology officer at Deloitte's, said: "This type of attack where the operator sits around and harvests details while you are connected to the hotspot is destined to become the new type of phishing.

"All you need to clone the Starbucks hotspot is a laptop, and the software can be configured within two hours," Mr Cracknell told an audience at InfoSec, in London.

Paul Vlissidis, technical director at NCC, another security firm, said: "It's a more costly scam to run, but we'll certainly see it happen as the number of wireless networks continues to grow."

There are now more than 10,000 hotspots across the UK, and blanket wi-fi coverage is now offered in large portions of Manchester, Edinburgh and, as of last week, the City of London.