June 05, 2008

More laws, collaboration required for online safety

At Authentication and Online Trust Summit, security experts discuss ways businesses, law enforcement, and policy makers must work together to solve cybercrime

Washington state's attorney general is only half joking when he suggests that perhaps sites like Facebook and MySpace should require members to use a credit card to sign up for access as a way to prove their identity.

"We need good age and identity verification technology so that it's much harder for an individual to get online and pretend to be 15 when really it's a 45-year-old man," said Attorney General Rob McKenna at the Authentication and Online Trust Summit in Seattle on Thursday. "There is a way to accomplish this quickly. It's wildly unpopular," he said, before suggesting that social-networking sites require users to have credit cards.

In addition to online identity verification techniques, McKenna and other security experts discussed ways that businesses, law enforcement, and policy makers must work together to solve cybercrime.

"We need to figure out what we can do not just with law enforcement but with each other," said Hemanshu Nigam, chief security officer at Fox Interactive Media and MySpace. "If there are bad guys in MySpace or eBay or Facebook, are they the same people?"

He pointed to MySpace's lawsuit against Scott Richter, a notorious spammer who was also sued by Microsoft, settling with the software giant for $7 million. The industry might have better success shutting down such people if they work together to pursue single actions, he said.

In addition, the entire legitimate online community should be on the same page in terms of strict safety and security policies, said Mozelle Thompson, a former commissioner on the U.S. Federal Trade Commission and currently a consultant. Sites like MySpace and Facebook represent implementations of the best security policies, he said. "There are a lot of sites out there doing nothing," he said. "You're only as good as where the bottom is."

Some of the speakers pushed for new laws that might help companies shut down some cybercrime. MySpace would like to have laws that ensure education for law-enforcement agents, who need training, as well as consumers. States should require schools to teach online safety every year to students, Nigam said.

That kind of education could very easily prevent some of the most common online fraud, he said, including one technique described by Chris Siouris, a cyberinvestigator at the U.S. Postal Inspector. His office pursues schemes where people unwittingly sign up for a job advertised online that they think simply involves receiving items in the mail, repackaging them, and sending them to a new address. However, they usually don't know that the items are purchased with stolen credit cards.

When Siouris and his colleagues discover someone has begun engaging in this type of job, they serve the person with a cease-and-desist letter and require them to sign an agreement not to do such work in the future or they'll be arrested. Rarely if ever has anyone engaged in the activity again, usually because they didn't realize that they were doing anything illegal, he said.

In addition to laws that would ensure education so that people realize that such jobs are illegal, every state should have antispyware laws, said McKenna. He also said that there should be federal data-loss notification requirements and legislation regarding spyware.

Washington state is seen as a leader in the country in its efforts to pursue cybercrime. In 2005, McKenna was instrumental in expanding the state's high-tech unit, which investigates cybercrime. His department now trains other states on how to bring spyware and other online crime cases to court.

Online privacy should also be addressed from a broader perspective, McKenna said. There is far more identity theft in the United States than in Europe or other regions that have stronger privacy protections, such as requirements for opt-in, rather than opt-out, data collection, he said. "I think as a society we need to discuss more fully the affects on our privacy and the impacts on issues like ID theft from the extensive commercialization of private information that we've seen in this country," he said.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2010 Infoworld, Inc.