Aardvark Daily aardvark (ard'-vark) a controversial animal with a long probing nose used for sniffing out the facts and stimulating thought and discussion.

NZ's leading source of Net-Industry news and commentary since 1995
PAYBACK TIME! | Headlines | XML feed | Contact | New Sites | Archives | Forums | About
Note: This column represents the opinions of the writer and as such, is not purported as fact
Security by Obscurity Fails Again 11 March 2004 Edition
Previous Edition | Archives

Please support the sponsor
Sponsor's Message
Last night I watched Fair Go and found myself muttering "I knew that would happen," when it was revealed that a number of people had found unexpected charges on their credit card statements.

In fact, I had posted this very warning in a message to usenet almost exactly a year ago -- perhaps I ought to have included a warning in this column for the benefit of readers.

While many people refuse to purchase online using their credit cards, for fear that their valuable card details may fall into the hands of nefarious types, a good number of them have been oblivious to the risks associated with not treating each and every receipt as if it were a copy of that card.


The Aardvark PC-Based Digital
Entertainment Centre Project

Yes, at last, this feature has been updated again! (31 Mar 2003)

The networks that issue these receipts are owned by two main consortiums of banks and the crazy thing is that they have long-known about this vulnerability, yet did nothing.

Instead of either fixing the problem or advising customers that the risk existed, they just kept quiet and hoped nobody else would notice (security by obscurity fails again).

Readers Say

Got something to say about today's column, or want to see what others think?  Visit The Forums

And it's time for a brickbat for Fair Go...

On last night's programme, they said it seemed odd that the banks would allow this situation to continue when it was they who had so much to lose (since fraudulent transactions are usually credited back to the card-holder).

BZZZT -- wrong answer Fair Go.

The banks lose NOTHING!

It's the poor unsuspecting merchant who accepted the stolen card details who ends up out of pocket -- the banks don't lose a penny.

I guess this explains why the banks felt it unnecessary to inform their customers of the risks or to fix the problem where it existed -- they weren't carrying any risk.

Doesn't this sound awfully familiar to the recent phishing scams that hit Westpac NZ customers?

As I pointed out at the time -- Westpac knew full well that these scams existed, having had customers in Australia duped by several waves of such emails and fake websites long before the first attack on NZ customers. But did they issue a pre-emptive warning? Hell no they didn't.

So why do the banks continue to treat their customers like mushrooms when it comes to matters of security?

How many other risks and vulnerabilities exist within the banking system and which the banks consider it more prudent to simply ignore and keep quiet about rather than actually fix?

Given the *massive* levels of profit that the major trading banks generate, surely it's not too much to ask that they consider the customers' best interests once in a while?

Surely it's time that they gave any employee or consultant that advocated "security by obscurity" a quick trip to the dole queue.

New Forums!
Yes folks, good news. The grotty ezboard forums have been replaced with a new phpBBS-based system that won't assault you with a myriad of pop-ups and other flotsam.

A big thanks to Managed Internet Solutions for offering to provide this service.

You can access the new forums over at aardvarkforums.co.nz

Yes, You Can Gift Money
I've published this website for the past nine years as a service to the local internet and IT industry and during all that time it has been 100% free to access. It is my intention to ensure that it remains completely free and free of charge and contains only the most sparse levels of advertising. Aardvark is not a business, it is a free resource.

If you feel that this is a good thing and/or you hold a "geniune affection" for yours truly -- then you are welcome to gift me some money using the buttons provided. In gifting this money you accept that no goods, service or other consideration is offered, provided, accepted or anticipated in return. Just click on the button to gift whatever you can afford. NOTE: PayPal bills in US dollars so don't accidentally gift more than what you were intending :-)

Contacting Aardvark
The Best of Aardvark Daily I'm always happy to hear from readers, whether they're delivering brickbats, bouquets or news tip-offs. If you'd like to contact me directly, please this form. If you're happy for me to republish your comments then please be sure and select For Publication.

Other media organisations seeking more information or republication rights are also invited to contact me.


Add Aardvark To Your Own Website!
Got a moment? Want a little extra fresh content for your own website or page?

Just add a couple of lines of JavaScript to your pages and you can get a free summary of Aardvark's daily commentary -- automatically updated each and every week-day.

Aardvark also makes a summary of this daily column available via XML using the RSS format. More details can be found here.

Contact me if you decide to use either of these feeds and have any problems.

Linking Policy
Want to link to this site? Check out Aardvark's Linking Policy.

Did you tell someone else about Aardvark today? If not then do it now!


Latest
Security Alerts
New vulnerabilities in Microsoft software
(ZDNet - 10/04/2004)

Microsoft warns of widespread Windows flaw (CNet - 12/02/2004)

RealPlayer flaws open PCs up to hijackers (ZDNet - 5/02/2004)

Macromedia Patches ColdFusion Holes (iNetNews - 1/02/2004)

Latest
Virus Alerts
Worm disguises self as Microsoft patch (CNet - 8/03/2004)

New MyDoom Virus Packs a Wallop (Wired - 25/02/2004)

New Bagle email worm on a roll (IDG - 19/2/2004)

'Robin Hood' virus on the loose (vnunet - 13/02/2004)

Bookmark This Page Now!

 

OTHER GREAT TECH SITES
GeekZone (NZL)
SlashDot (USA)

 

MORE NEWS
NZL Sites
IDG.Net.nz
NZ Netguide
NZ Herald Tech
PC World NZ
Scoop
NZOOM Technology WordWorx

AUS Sites
ZDNet
The Age
Australian IT
AUS Netguide
NineMSN Tech
IT News

USA Sites
Wired.com
CNet
CNNfn Tech
TechWeb
Yahoo Tech
ZDNet Tech
USA Today Tech
7am.com SciTech

UK Sites
The Register
BBC SciTech

 

My Jet Engines
Check Out Me And My Jet Engines

Today's Top News Stories


Open in New Window = open in new window
New Zealand

Open in New Window US start-up specialists keen to help
They want to help you crack the US market because they have an urge to make a difference — in New Zealand...
IDG

Open in New Window BBC buys MET's graphix
The BBC is set to show the world's weather through a Kiwi graphics program after buying Weatherscape XT, a television weather graphics package developed by MetService of New Zealand...
NBR

Other

Open in New Window New vulnerabilities in Microsoft software
Microsoft has revealed three new vulnerabilities in its software, including the first to affect MSN Messenger 6.0, and it is urging customers to patch their systems now...
ZDNet

Open in New Window Security product to strike back at hackers
A Texas company is set to launch a product that can hit back at attackers with its own arsenal of tricks. Security experts, however, say it will only make things worse...
CNet

Open in New Window French group seeks royalties on iPod
A French association representing recorded music rights holders threatened Wednesday to take Apple Computer Inc. to court in a dispute over lost music royalties...
USA Today

Open in New Window Robot Racers Catch a Break
Robot vehicles were having a tough time completing the qualifying course for the Grand Challenge, so Darpa has rewritten the rules to let almost anyone compete...
Wired

Open in New Window E-Mail Providers Slam Spammers
Four of the biggest e-mail providers in the United States are wielding the Can Spam law to sue some of the most prolific junk e-mailers. They say enough is enough...
Wired

Australia

Open in New Window Spies get greater email powers
SPY agencies would have greater powers to intercept people's emails under government changes that have been dubbed over-the-top and intrusive...
Australian IT

Open in New Window Electronic Frontiers board member attacks trade deal
An Electronics Frontiers Australia (EFA) board member has critically assessed the proposed Free-Trade Agreement (FTA) between the United States and Australia released on 1 March, concluding that the document presents "absolutely no benefit to Australia in the IP sections"...
ZDNet

Open in New Window More phishing scams surface
An email scam targeting Westpac has arrived this morning but what's interesting is that it has been closely followed by another email advertising "a perspective (sic) and well-paid job in the Australia."...
The Age

Other

Open in New Window Plugging into the power of sewage
A microbial fuel cell that generates electricity from human waste could mean sewage treatment will pay for itself...
New Scientist

Open in New Window Unused space on hard drives recovered?
READER WILEY SILER has sent us a method which he said was discovered by Scott Komblue and documented by himself which they claim can recover unused areas of the hard drive in the form of hidden partitions...
The Inquirer

Open in New Window Bypassing China's net firewall
Numerous efforts are under way to help Chinese web surfers get around China's censorship of the internet...
BBC

Open in New Window Pay-as-you-go tempts surfers
A service offering low rates for small amounts of broadband is proving popular with consumers...
BBC


Looking For More News or Information?

Google
Search WWW Search Aardvark

Privacy Policy | Copyright © 2003, Bruce Simpson, republication rights available on request

jet engine page