<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Get Safe Online (The Blog) &#187; Guest bloggers</title>
	<atom:link href="http://www.getsafeonlineblog.org/category/guest-bloggers/feed" rel="self" type="application/rss+xml" />
	<link>http://www.getsafeonlineblog.org</link>
	<description>News, tips and updates from the GetSafeOnline.org team</description>
	<lastBuildDate>Mon, 26 Jul 2010 12:13:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Meet the rightperson, not a conperson.</title>
		<link>http://www.getsafeonlineblog.org/meet-the-rightman-not-a-conman</link>
		<comments>http://www.getsafeonlineblog.org/meet-the-rightman-not-a-conman#comments</comments>
		<pubDate>Fri, 23 Jul 2010 22:17:52 +0000</pubDate>
		<dc:creator>Tony Neate</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Guest bloggers]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=610</guid>
		<description><![CDATA[Guest blogger: Sharon Lemon OBE. Deputy Director e-Crime, Serious Organised Crime Agency (SOCA) Years ago, when Internet dating started, it did have a reputation as being a bit seedy, but things have moved on and now there are a  number of reputable dating sites which advertise their success in putting couples together, many of whom get married. Needless to say [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Guest blogger: Sharon Lemon OBE. Deputy Director e-Crime, Serious Organised Crime Agency (SOCA)</p>
<p><img src="http://www.getsafeonlineblog.org/wp-content/uploads/2007/06/sharon-lemon.jpg" border="0" alt="Sharon Lemon" width="232" height="240" align="right" />Years ago, when Internet dating started, it did have a reputation as being a bit seedy, but things have moved on and now there are a  number of reputable dating sites which advertise their success in putting couples together, many of whom get married. Needless to say though, there are some people who want to exploit this new form of relationship and romance fraud is a growing problem, and can leave its victims financially and emotionally devastated. Make sure you’re aware of the signs so that you don’t fall for Mr or Mrs Wrong and not Mr or Mrs Right – do not become a victim.</p>
<p>For example, when you sign up to a dating website be careful about giving out your private information, especially to people from a foreign country who contact you out of the blue and claim to care deeply for you after only one or two emails or conversations. Always stay on the website, and don’t take your conversations onto instant messaging or private email. Don’t trust anybody who won’t answer basic questions about where they are and what they do.</p>
<p>So far we have only seen this offence being committed against women. A common tactic is for a fraudster to claim that they are a soldier, maybe American, who is based in Iraq and wants to retire with their children to live with you. Once the relationship is established, you will be asked to speak to their friends in a completely different country, which is when you will be asked for money.</p>
<p>When a romance fraudster (actually probably a group of criminals posing as one person) manages to seduce somebody into an online relationship, often over weeks and months, eventually there will be a problem that only you can help with. Maybe they want to travel to see you, and want you to pay money towards a visa or airline tickets. Or maybe they or a family member falls ill, or even dies, and they need money for medical or funeral bills. There may be many different reasons, but with just one purpose – to get your money.</p>
<p>If you do pay, the fraudster will then give more reasons for you to send money, and you will never see any of the things they promise. If they say they are flying to see you, they won’t turn up but will have a problem at the airport requiring your money to sort out. If they say they have large amounts of cash or gold that only requires some customs charge or other fees before you can get a share, this is just another type of fraud designed to rip you off. You may even be asked to fly abroad, so that you can be exposed to these different types of fraud in person. If you do so there is a real risk of kidnap and extortion, meaning your life could be in danger.</p>
<p>To protect yourself, be wary of contact from these romance fraudsters. Never send money to anybody you don’t know or trust, particularly by a money transfer service instead of to a bank account. If something sounds too good to be true, it probably is. If you become a victim, you could end up losing a lot of money as a result – or worse.</p>
<p>If you think you’ve been a victim of romance fraud, or any other type of fraud, cease all contact straight away, don’t send any more money and get in touch with Action Fraud via their website, <a href="http://www.actionfraud.org.uk/">http://www.actionfraud.org.uk/</a>  or call them on 0300 123 2040.</p>
<p>That’s all pretty serious, but remember – as in real life, most people in the virtual world are good, so enjoy your time in it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/meet-the-rightman-not-a-conman/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ten signs of trust</title>
		<link>http://www.getsafeonlineblog.org/10-signs-of-trust</link>
		<comments>http://www.getsafeonlineblog.org/10-signs-of-trust#comments</comments>
		<pubDate>Mon, 19 Jul 2010 13:48:00 +0000</pubDate>
		<dc:creator>VeriSign</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Trust]]></category>
		<category><![CDATA[VeriSign]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/10-signs-of-trust</guid>
		<description><![CDATA[This is a guest blog post from VeriSign UK, a Get Safe Online sponsor. When you are looking at a website, here are ten signs that can help you decide whether a company is worth doing business with, or not. A well-designed site. If companies don’t take the time to design a website that is [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>This is a guest blog post from </strong><a href="http://www.verisign.co.uk"><strong>VeriSign UK</strong></a><strong>, a Get Safe Online sponsor.</strong></p>
<p><a href="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/iStock_000009164514Small.jpg"><img style="border-bottom: 0px;border-left: 0px;margin-left: 0px;border-top: 0px;margin-right: 0px;border-right: 0px" border="0" alt="iStock_000009164514Small" align="right" src="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/iStock_000009164514Small_thumb.jpg" width="240" height="150" /></a> When you are looking at a website, here are ten signs that can help you decide whether a company is worth doing business with, or not.</p>
<ol>
<li><b>A well-designed site</b>. If companies don’t take the time to design a website that is easy to use, accessible for people with disabilities, simple to navigate and quick to load, then the chances are they won’t take the time to provide good services or proper privacy.</li>
<li><b>Useful information</b>. Look for a company that provides advice, recommendations and help. In particular, look for information about security – it shows they’re thinking about it.</li>
<li><b>A good reputation</b>. A well-known brand can be a reassurance but a small firm with a good reputation can also be trustworthy. Look for customer endorsements and third party reviews online.</li>
<li><b>Real-world contact details</b>. Look for a phone number, email contact and real-world address. If you feel nervous, call them up and see who answers and how helpful they are.</li>
<li><b>SSL Encryption</b>. Every site should use SSL encryption to protect your confidential information when you enter it or when you checkout during a purchase.</li>
<li><b>Extended Validation SSL certificates</b>. This gives you extra reassurance that the site is genuine and that the company behind it really exists.</li>
<li><b>SSL Certificate matches company details</b>. Click on the golden padlock and crosscheck the company details there with the details on the site. Sometimes, you have to look in the site’s terms and conditions to find the company’s trading name and registered address. </li>
<li><b>Trust marks</b>. Trusted third party signs, such as the VeriSign Secured Seal let you check that a site is safe. Click on the symbol to confirm the ownership of the site.      <br /><a href="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/clip_image001.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="clip_image001" src="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/clip_image001_thumb.png" width="131" height="95" /></a></li>
<li><b>Clear policies</b>. Ecommerce sites should offer clear, non-nonsense returns and postage policies. If you don’t understand the deal you’re getting, don’t do it.</li>
<li><b>Support for Get Safe Online</b>. Well, not everybody supports Get Safe Online, but it’s a good sign if they do!</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/10-signs-of-trust/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VeriSign bloggers: inside ecommerce and identity</title>
		<link>http://www.getsafeonlineblog.org/verisign-bloggers</link>
		<comments>http://www.getsafeonlineblog.org/verisign-bloggers#comments</comments>
		<pubDate>Mon, 05 Jul 2010 13:47:00 +0000</pubDate>
		<dc:creator>VeriSign</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>
		<category><![CDATA[Blogs]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/verisign-bloggers</guid>
		<description><![CDATA[This is a guest blog post from VeriSign UK, a Get Safe Online sponsor. VeriSign is delighted to sponsor Get Safe Online and to contribute a few guest posts to the blog here. We have number of bloggers ourselves. Check them out: Notes from the Cyber Trenches. Rick Howard runs our iDefence Operations centre. His [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>This is a guest blog post from </strong><a href="http://www.verisign.co.uk"><strong>VeriSign UK</strong></a><strong>, a Get Safe Online sponsor.</strong></p>
<p>VeriSign is delighted to sponsor Get Safe Online and to contribute a few guest posts to the blog here. We have number of bloggers ourselves. Check them out:</p>
<ul>
<li><a href="http://blogs.verisign.com/idefense/">Notes from the Cyber Trenches</a>. Rick Howard runs our iDefence Operations centre. His blog is an interesting insight into the biggest threats and most serious internet security issues such as a recent post about <a href="http://blogs.verisign.com/idefense/2010/05/shadow-network.html">cyber espionage</a>.</li>
<li><a href="https://blogs.verisign.com/ssl-blog/">Tim Callan’s SSL Blog</a>. Keep up with the latest developments in the world of SSL and ecommerce encryption.</li>
<li><a href="http://blogs.verisign.com/innovation/">Blue Ocean: Innovation at VeriSign</a>. Nico Popp’s blog shows where online verification and encryption is heading, for example, his recent post about ‘cloud identity’.</li>
<li><a href="http://blogs.verisign.com/infrablog/">The VeriSign Infrablog</a>. For IT professionals, this blog is a commentary on infrastructure. </li>
<li><a href="http://blogs.verisign.com/identity/">Online Identity and Trust</a>. This blog deals with consumer identity protection. Written by four people from the VeriSign Identity Protection team, it covers topics such as fraudulent cashpoint access and the security risks of smart meters.</li>
<li><a href="http://blogs.verisign.com/web-user-experience/">Web User Experience Blog</a>. Reshma Kumar is the User Experience Design Manager for VeriSign’s websites. Her April 14<sup>th</sup> post shows how far website design has come since 1997, when VeriSign launched its first site.</li>
<li><a href="http://blogs.verisign.com/ecommerce/">Bob Angus: The Ecommerce Evangelist</a>. Bog’s blog is a great resource for anyone involved in ecommerce.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/verisign-bloggers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Behind the seal</title>
		<link>http://www.getsafeonlineblog.org/behind-the-seal</link>
		<comments>http://www.getsafeonlineblog.org/behind-the-seal#comments</comments>
		<pubDate>Mon, 28 Jun 2010 13:59:00 +0000</pubDate>
		<dc:creator>VeriSign</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/behind-the-seal</guid>
		<description><![CDATA[This is a guest blog post from VeriSign UK, a Get Safe Online sponsor. One of the biggest problems people have is spotting the difference between legitimate websites and fake sites that look real but which are fronts for online criminals. SSL Certificates – the technology that protects your private data when you buy online [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>This is a guest blog post from </strong><a href="http://www.verisign.co.uk"><strong>VeriSign UK</strong></a><strong>, a Get Safe Online sponsor.</strong></p>
<p>One of the biggest problems people have is spotting the difference between legitimate websites and fake sites that look real but which are fronts for online criminals. </p>
<p>SSL Certificates – the technology that protects your private data when you buy online – are helpful and the latest Extended Validation SSL Certificates also provide reassurance about the owners of the site as well as the strength of their encryption.</p>
<p>However, most web pages are not protected by SSL; only the checkout or registration pages where you enter personal information. So we have developed the <a href="http://www.verisign.com/trust-seal/features-benefits/index.html?sl=title">VeriSign Trust™ Seal</a>, which website owners can display on any web page to prove that their site is legitimate.</p>
<p><a href="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/clip_image0011.gif"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="clip_image001" src="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/clip_image001_thumb1.gif" width="135" height="68" /></a></p>
<p>When you see this sign, you know that VeriSign has verified the ownership of the site and checked that the site is free of malware. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/behind-the-seal/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Fake or not? What does safe look like online?</title>
		<link>http://www.getsafeonlineblog.org/fake-or-not-what-does-safe-look-like-online</link>
		<comments>http://www.getsafeonlineblog.org/fake-or-not-what-does-safe-look-like-online#comments</comments>
		<pubDate>Mon, 21 Jun 2010 13:45:51 +0000</pubDate>
		<dc:creator>VeriSign</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=562</guid>
		<description><![CDATA[This is a guest blog post from VeriSign UK, a Get Safe Online sponsor. In the last three months of 2009, criminals hijacked 356 well-known brands to create phishing sites, according to AWPG. These sites are designed to trick people into giving away their personal information, such as credit card numbers. It’s identity fraud on [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>This is a guest blog post from </strong><a href="http://www.verisign.co.uk"><strong>VeriSign UK</strong></a><strong>, a Get Safe Online sponsor.</strong></p>
<p><a href="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/moneybaitsmall.jpg"><img style="margin: 0px; border: 0px;" src="http://www.getsafeonlineblog.org/wp-content/uploads/2010/06/moneybaitsmall_thumb.jpg" border="0" alt="money bait (small)" width="116" height="175" align="right" /></a> In the last three months of 2009, criminals hijacked 356 well-known brands to create phishing sites, according to <a href="http://www.apwg.com/reports/apwg_report_Q4_2009.pdf">AWPG</a>. These sites are designed to trick people into giving away their personal information, such as credit card numbers. It’s identity fraud on a massive scale.</p>
<p>Sometimes, these fake sites are very difficult to detect, even for an expert. But here are a few things to watch out for:</p>
<ul>
<li><strong>Pressure</strong>. Sites and emails that create a false sense of urgency (‘your account has been suspended’, for example) are a common tactic.</li>
<li><strong>Promises</strong>. Alternatively, you get an offer that sounds too good to be true (such as ‘sign up now and get a free MP3 player’).</li>
<li><strong>Pretending</strong>. Check the website address in the browser bar. If it doesn’t look right, be on your guard. For example, weird variations or misspellings of the company name.</li>
<li><strong>Poor spelling</strong>. Criminals who don’t speak English as their first language are prone to make tell-tale spelling errors.</li>
<li><strong>Padlock</strong>. When you are entering personal information, you should check for the golden padlock in the browser address bar. If it’s not there, beware.</li>
</ul>
<p>However, sometimes, criminals can create a perfect copy of a real website and so you need some extra help to detect the fakes. This is where Extended Validation SSL certificates come in.</p>
<p>The SSL bit produces the golden padlock and it means that your data is encrypted before it is sent to the website owner. The Extended Validation bit is new and it shows that the identity of the website owner has been checked and that this is really their site and not a fake. It displays a green background and the name of the site owner in the address bar – this is your sign that you’re safe.</p>
<p>Test your skills in spotting fake sites with VeriSign’s <a href="https://www.phish-no-phish.com/">Phish or No Phish</a> online quiz. Check out Get Safe Online’s tips on <a href="http://www.getsafeonline.org/nqcontent.cfm?a_id=1125">avoiding criminal websites</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/fake-or-not-what-does-safe-look-like-online/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Have you been Rocked.</title>
		<link>http://www.getsafeonlineblog.org/have-you-been-rocked</link>
		<comments>http://www.getsafeonlineblog.org/have-you-been-rocked#comments</comments>
		<pubDate>Fri, 18 Dec 2009 00:23:32 +0000</pubDate>
		<dc:creator>Tony Neate</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=463</guid>
		<description><![CDATA[Another guest blog from  Richard Hollis Did you see the news recently that social networking site RockYou suffered a data breach exposing over 32 million user accounts?   If that wasn’t bad enough, it was also revealed that they were apparently storing all that data (user account information) in plain text in their database. This fact came [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Another guest blog from  Richard Hollis</p>
<p>Did you see the news recently that social networking site RockYou suffered a data breach exposing over 32 million user accounts?   If that wasn’t bad enough, it was also revealed that they were apparently storing all that data (user account information) in plain text in their database. This fact came to light only because when RockYou attempted to downplay and dismiss the severity of the incident, the hacker responsible published a sample of the data to prove it and demonstrate that all the user passwords accessible were stored unencrypted.<br />
 <br />
<img class="alignleft size-full wp-image-466" title="Rockyou" src="http://www.getsafeonlineblog.org/wp-content/uploads/2009/12/Rockyou2.jpg" alt="Rockyou" width="129" height="64" />To make matters worse, the published dataset also contained user password and logon credentials for other social networking sites. </p>
<p> So however you do the maths, there is a possibility that this hack directly affected you if you use a social networking site. The hacker was able to access this information through a SQL injection vulnerability on the RockYou site.  This hacking technique is old, widely known and does not require a great deal of expertise to execute.  The point being that any online business even marginally concerned with security would have closed off this easily exploited security hole before even thinking of launching their site &#8211; but apparently not RockYou.<br />
 <br />
Their attitude towards security is further demonstrated in their published password policies as they only mandate a minimal length of 5 characters for their account passwords.  They have no requirement for mixed case, alpha-numeric characters and in fact enforce password simplicity by not allowing any punctuation at all.  This is where RockYou gets it wrong.  Passwords are the very foundation of online security.  At this time of year we should think of them like underwear- the longer the better.<br />
    <br />
Learn a lesson from this incident &#8211; buyer beware! Next time you sign up to a social networking site or any web service for that matter, read the fine print. What is their security policy?  Do they have one?  If they don’t publish it on the site &#8211; chances are they don’t. Sending you open text passwords in emails are another indication that their approach to security may be short of your expectations.  Read the privacy statement. Do they inform their customers about losses or breaches?  Do you want to use them if they don’t?  The choice is yours.</p>
<p>Richard Hollis – Orthus Ltd</p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/have-you-been-rocked/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Coming to a Theatre near you</title>
		<link>http://www.getsafeonlineblog.org/coming-to-a-theatre-near-you</link>
		<comments>http://www.getsafeonlineblog.org/coming-to-a-theatre-near-you#comments</comments>
		<pubDate>Thu, 17 Dec 2009 08:52:57 +0000</pubDate>
		<dc:creator>Tony Neate</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=453</guid>
		<description><![CDATA[Guest bloger Richard Hollis Last week, the United States Congress, House of Representatives, passed the Data Accountability and Trust Act &#8211; H.R. 2221.  The bill is now on its way to becoming Federal law.  This is long awaited and very good news for consumers.  It’s similar to the breach notification laws enacted by over 30 [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Guest bloger Richard Hollis</p>
<p>Last week, the United States Congress, House of <img class="alignright size-thumbnail wp-image-459" title="CapitolBldg" src="http://www.getsafeonlineblog.org/wp-content/uploads/2009/12/CapitolBldg4-150x150.jpg" alt="CapitolBldg" width="150" height="150" />Representatives, passed the Data Accountability and Trust Act &#8211; H.R. 2221.  The bill is now on its way to becoming Federal law.  This is long awaited and very good news for consumers.  It’s similar to the breach notification laws enacted by over 30 over the 50 states sparked by California mandating public disclosure of breaches back in 2003.  Federal public disclosure laws were previously blocked under the Bush Administration.   In essence it mandates that businesses publically disclose breaches of personal information in their possession.  <br />
     <br />
The new law will formally define personal information as, &#8220;an individual&#8217;s first name or initial and last name, or address, or phone number, in combination with any 1 or more of the following data elements for that individual:</p>
<p>• Social Security number, driver&#8217;s license number or other identification number<br />
• Financial account number, or credit or debit card number and any required security code, access code, or password necessary to permit access to an individual&#8217;s financial account.</p>
<p>It formally establishes the Federal Trade Commission (FTC) as the oversight body and requires organisations holding data to implement a data protection policy and identify an information security officer.   More importantly, the new law will direct that businesses in possession of personal data establish procedures for identifying security vulnerabilities in the networks that process this data and monitor for breaches.  The FTC would also be tasked with posting breaches on their website.</p>
<p>The bill has some more stringent requirements for &#8220;data brokers&#8221;, including audits in the event of a breach.  It also requires two years of quarterly credit reports provided to victims at no charge. Third parties are also required to notify customers in the event of a breach, and the actual owner of the data is then required to notify consumers.  It doesn’t get any better than that.</p>
<p>The law will naturally result in a higher level of protection for personal data held by both public and private sector entities and establish the legal framework for consumer legal actions resulting from breaches.  It will also add some degree of consistency for organizations establishing programs to protect personal data and simplify compliance.<br />
 <br />
Good news for consumers everywhere as US law has a way of affecting legislation worldwide.</p>
<p>by Richard Hollis December 16, 2009 &#8211; Orthus Ltd</p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/coming-to-a-theatre-near-you/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How much is your data worth?</title>
		<link>http://www.getsafeonlineblog.org/how-much-is-your-data-worth</link>
		<comments>http://www.getsafeonlineblog.org/how-much-is-your-data-worth#comments</comments>
		<pubDate>Fri, 11 Jul 2008 07:23:48 +0000</pubDate>
		<dc:creator>John Evelyn</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=231</guid>
		<description><![CDATA[Guest post by Dr. Guy Bunker, Chief Scientist &#38; Distinguished Engineer, Symantec Corporation I don’t mean how much are you worth, it’s more about your information, your ‘data’. Times have changed and while the average cyber-criminal is still after bank account details and credit card numbers, they are also targeting other information as well. In [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Guest post by <a href="www.viewfromthebunker.com ">Dr. Guy Bunker</a>, Chief Scientist &amp; Distinguished Engineer, Symantec Corporation
<p>I don’t mean how much are you worth, it’s more about your information, your ‘data’. Times have changed and while the average cyber-criminal is still after bank account details and credit card numbers, they are also targeting other information as well. In fact anything that you protect with a username and password is of interest to them. Why? The answer is simple, it’s all about money – to them. At Symantec we have a Global Intelligence Network which monitors the internet for spam, viruses and other malware, however it also monitors some of the underground economy / black market traffic in data – your data. This information is published regularly in our Internet Security Threat Report, available from <a href="http://www.symantec.com">www.symantec.com</a>. Here are some of the findings on just how much your data is worth to someone else:
<p><a href="http://www.getsafeonlineblog.org/wp-content/uploads/2008/07/image.png"><img style="0px" height="156" alt="image" src="http://www.getsafeonlineblog.org/wp-content/uploads/2008/07/image-thumb.png" width="392" border="0"></a>
<p>Of course, just like any other ‘business’, you can get volume discounts, so you can get 50 credit card numbers for $40 ($0.80 each) or 500 numbers for $200 ($0.40 each)!
<p>The latest ‘attacks’ are not just through email, but through web browsers and plug-ins and increasingly through social networking sites, so the next time you visit a site and it asks to install a plug-in, just do a quick check to see if the plug-in is legitimate – and that you really want it – there is more at risk than you might have imagined.</p>
<hr />
<p>Dr. Guy Bunker is a Distinguished Engineer at Symantec Corporation. He is responsible for technical strategy for the security and data management group and runs a number of research projects around data loss prevention and intelligent archiving. Guy has worked for Symantec (formerly VERITAS) for more than a decade in a number of different product divisions and roles. </p>
<p>He has been a member of a number of industry bodies driving standards in computer storage and management and is currently an active member of the Enterprise Privacy Group. Guy is a regular presenter at many conferences, including InfoSec, StorageExpo, Transformational Government, Internet Security Forum, RUSI’s Protecting The Critical National Infrastructure, IAAC, Enterprise Architecture and the Symantec user conference, Vision. </p>
<p>Guy has authored a number of books and is currently working on his latest “Data Leaks For Dummies” which is due to be published in early 2009.<br />Guy holds a PhD in Artificial Neural Networks from King’s College London, several patents and is a Chartered Engineer with the IEE.
<p>Guy’s blog on information security and availability can be found at: <a href="http://www.viewfromthebunker.com">www.viewfromthebunker.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/how-much-is-your-data-worth/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eBay guest blogger</title>
		<link>http://www.getsafeonlineblog.org/ebay-guest-blogger</link>
		<comments>http://www.getsafeonlineblog.org/ebay-guest-blogger#comments</comments>
		<pubDate>Wed, 14 Nov 2007 16:18:08 +0000</pubDate>
		<dc:creator>John Evelyn</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=179</guid>
		<description><![CDATA[Meet the Team: Richard Ambrose Richard Ambrose took over from Garreth Griffith as Head of Trust and Safety (T&#38;S) at eBay UK on October 1st. What brought you to Trust and Safety? I’ve been at eBay for four years – I initially joined to manage the Collectibles category and I’ve been in ‘Finding’ for the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><b><a href="http://www.getsafeonlineblog.org/wp-content/uploads/2007/11/richard-ambrose.jpg"><img height="158" alt="Richard Ambrose" src="http://www.getsafeonlineblog.org/wp-content/uploads/2007/11/richard-ambrose-thumb.jpg" width="240" align="right" border="0"></a> Meet the Team: Richard Ambrose</b>
<p>Richard Ambrose took over from Garreth Griffith as Head of Trust and Safety (T&amp;S) at eBay UK on October 1<sup>st</sup>.
<p><b>What brought you to Trust and Safety?</b>
<p>I’ve been at eBay for four years – I initially joined to manage the Collectibles category and I’ve been in ‘Finding’ for the last couple of years. (Finding refers to the way people find items to buy on eBay and it has its own team inside the company.) &nbsp;I’ve always been a very passionate about trust and safety and so I was delighted to get the chance to work with the team.
<p><b>Since you took over, what has been the biggest surprise about T&amp;S?</b>
<p>The global nature of all our challenges was the biggest surprise. Internet crime is a global issue and, unfortunately, there is a small body of professional criminals who attack eBay members in multiple countries. They always try to find the weakest link in our defences so it’s really important that we are consistent wherever we operate. The good news is that if one part of eBay comes up with a brilliant advance to protect members, we can roll it out globally very quickly.
<p><b>How does eBay work with the police?</b>
<p>We have a close relationship with law enforcement. We have an ongoing training course for police on how to investigate eBay reports and how to prosecute illegal activity on eBay. We have trained thousands of police officers to date. We make ourselves available to appear in court and provide witness statements for prosecutions, but we rely on customers to report crimes in the first place. We’ve seen a steady stream of prosecutions. So far this year, in the UK, we have helped secure 210 arrests and guilty verdicts in 69 different court cases. &nbsp;
<p><b>What are your priorities for the next year?</b>
<p>The bedrock is combating professional fraud. We want to make it difficult, risky, time-consuming and expensive for the tiny hardcore of professional criminals to operate on eBay. For example, we can try to stop them getting accounts on eBay in the first place and we can be quicker at identifying fraudulent listings.
<p>&nbsp;We often find that that a majority of professional fraud exploits the misuse of unguaranteed payment mechanisms like Western Union or personal cheques. This is precisely why we have banned these payment types from eBay. Secure digital mechanisms like PayPal have much less risk.
<p>We’re experimenting with mandating the use of PayPal in certain areas where we think will think it will have a dramatic effect. For example, we required people to offer it as a payment option by anyone who wanted to list an Apple iPhone.
<p>We’ve also launched a telephone support line for our most frequent buyers and sellers. We expect to roll this service out to more people during 2008.
<p><b>How widespread is online fraud?</b>
<p>Luckily, the vast majority of eBay users don’t encounter it and have a very positive experience with us. 4m people in the UK visit eBay every day and the vast, VAST majority of their transactions are fun, good value and problem-free.
<p><b>What advice would you give customers?</b>
<p>My number one tip would be to drop the seller a note via the eBay site and ask them a question about the item. It’s pretty much the best way of establishing their bona fides. You can learn a lot from the tone, attitude, the speed and content of a seller’s reply to a question.
<p><b>What do you buy and sell on eBay?</b>
<p>I collect medieval coins. Last month I bought a very rare 11<sup>th</sup> century penny on the site. I was delighted with it. These things are very hard to find and eBay is where I get most of my collection.
<p>Technorati Tags: <a href="http://technorati.com/tag/eBay" rel="tag">eBay</a>, <a href="http://technorati.com/tag/Richard+Ambrose" rel="tag"> Richard Ambrose</a>, <a href="http://technorati.com/tag/Head+of+Trust+and+Safety" rel="tag"> Head of Trust and Safety</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/ebay-guest-blogger/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Where to get help on eBay</title>
		<link>http://www.getsafeonlineblog.org/where-to-get-help-on-ebay</link>
		<comments>http://www.getsafeonlineblog.org/where-to-get-help-on-ebay#comments</comments>
		<pubDate>Wed, 14 Nov 2007 16:16:08 +0000</pubDate>
		<dc:creator>John Evelyn</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=176</guid>
		<description><![CDATA[Here at Get Safe Online, we sometimes get email from people who have had problems buying and selling on eBay. They sponsor Get Safe Online but we are separate organisations. Our resources are limited and we can&#8217;t offer individual advice or help. So we asked eBay for some tips about where to get help on [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Here at Get Safe Online, we sometimes get email from people who have had problems buying and selling on eBay. They sponsor Get Safe Online but we are separate organisations. Our resources are limited and we can&#8217;t offer individual advice or help. So we asked eBay for some tips about where to get help on their site. </p>
<blockquote><p>We’re conscious that there’s more we can do to make it easier for our members to get in contact with us and so we are currently in the process of trialling a phone support facility for some of our more frequent buyers and sellers. If successful, we will roll it out to more customers in future.
<p>However, there are still lots of ways to get in touch with eBay and get help if you have a problem:
<ul>
<li><b>Online help</b>. We have an extensive <a href="http://pages.ebay.co.uk/help/index.html">help library</a>. You’ll find solutions to many common problems
<li><b>Get in touch. </b>You can use our online contact system to <a href="http://pages.ebay.co.uk/safetycentre/contact.html?">report a problem</a>. Here, you can report a seller if your item was not received or not as described, submit an unpaid item dispute, and report any other problems you may have regarding your account
<li><b>Report suspicious emails.</b> If you get any suspicious emails purporting to be from eBay or PayPal you can immediately report them to <a href="mailto:spoof@ebay.co.uk">spoof@ebay.co.uk</a> or <a href="mailto:spoof@paypal.co.uk">spoof@paypal.co.uk</a>. Forward the entire email to us. We will reply promptly letting you know whether or not the email or website is fake or genuine<br />(eBay takes immediate action against spoof or phishing websites – through links with the companies that host them, 80% of fake sites that are reported to us are brought down within 24 hours and 90% are brought down within 48 hours)
<li><b>Report breaches of eBay’s listing policies. </b>At the bottom of every listing, there is a link where you can ‘report this item’ if you believe it may contravene our listing policies. Every single report made in this way is reviewed by our team in Dublin
<li><b>Community boards.</b> The <a href="http://pages.ebay.co.uk/community">Community Boards</a> on eBay are a useful way for members to share information and get advice from other members on a range of topics. Whether you’re looking for real beginner stuff such as how to list an item for sale or something more complex to do with running a business, you can get the answers from other community members on the boards. For those who are new to eBay we’d recommend you visit the ‘new to eBay’ discussion board </li>
</ul>
</blockquote>
<p>Technorati Tags: <a href="http://technorati.com/tag/eBay" rel="tag">eBay</a>, <a href="http://technorati.com/tag/online+help" rel="tag"> online help</a>, <a href="http://technorati.com/tag/community+boards" rel="tag"> community boards</a>, <a href="http://technorati.com/tag/spoof+emails" rel="tag"> spoof emails</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/where-to-get-help-on-ebay/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online crime linked to terror funding</title>
		<link>http://www.getsafeonlineblog.org/online-crime-linked-to-terror-funding</link>
		<comments>http://www.getsafeonlineblog.org/online-crime-linked-to-terror-funding#comments</comments>
		<pubDate>Wed, 19 Sep 2007 09:29:51 +0000</pubDate>
		<dc:creator>John Evelyn</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=163</guid>
		<description><![CDATA[Written by Tony Neate, Managing Director, Get Safe Online Over the last few years, there has been a lot of talk about the link between online crime and terrorism, but I don&#8217;t recall seeing any direct evidence. That&#8217;s changed. A friend sent me this link from the Washington Post. It looks like the link between [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>Written by Tony Neate, Managing Director, Get Safe Online</strong>
<p><img height="240" alt="Criminal" src="http://www.getsafeonlineblog.org/wp-content/uploads/2007/09/istock-000003569842xsmall.jpg" width="160" align="right" border="0"> Over the last few years, there has been a lot of talk about the link between online crime and terrorism, but I don&#8217;t recall seeing any direct evidence. That&#8217;s changed. A friend sent me this link from the <a title="Washington Post article linking terror funding to online crime" href="http://www.washingtonpost.com/wp-dyn/content/article/2007/07/05/AR2007070501153.html ">Washington Post</a>. It looks like the link between online crime and terror funding has been firmly established.
<p>Three men, Tariq Al-Daour, Younes Tsouli and Waseem Mughal, used stolen credit cards numbers to make purchases at hundreds of online stores, armed with shopping lists of items that fellow terrorists might need to complete their activities. Authorities also say the men laundered funds from stolen credit card accounts through more than a dozen online gambling Web sites.
<p>They recently pleaded guilty at Woolwich Crown Court to inciting terrorist murder; they also admitted conspiring to defraud banks, credit card companies and charge card companies.
<p>This has certainly heightened the need for people to protect themselves online.&nbsp;Not only do we need to protect ourselves from online criminals taking our money but we also need to protect ourselves from terrorists using the proceeds of crime to fund their activities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/online-crime-linked-to-terror-funding/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>What&#8217;s the fuss about?</title>
		<link>http://www.getsafeonlineblog.org/whats-the-fuss-about</link>
		<comments>http://www.getsafeonlineblog.org/whats-the-fuss-about#comments</comments>
		<pubDate>Wed, 18 Jul 2007 10:42:32 +0000</pubDate>
		<dc:creator>John Evelyn</dc:creator>
				<category><![CDATA[Guest bloggers]]></category>

		<guid isPermaLink="false">http://www.getsafeonlineblog.org/?p=146</guid>
		<description><![CDATA[Guest blogger: Nick McGrath, Director of Platform Strategy, Microsoft I am often asked what is the biggest challenge people face on Security. My answer is simple:“enablement.” Security is an enabler to help a company to grow. Business owners expect the company’s information to be available for their employees on any device, at any time, anywhere [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://www.getsafeonlineblog.org/wp-content/uploads/2007/07/image2.png"><img alt="image" src="http://www.getsafeonlineblog.org/wp-content/uploads/2007/07/image-thumb1.png" align="right" border="0"></a> </p>
<p><strong>Guest blogger: Nick McGrath, Director of Platform Strategy, Microsoft</strong></p>
<p>I am often asked what is the biggest challenge people face on Security. My answer is simple:“enablement.” </p>
<p>Security is an enabler to help a company to grow. Business owners expect the company’s information to be available for their employees on any device, at any time, anywhere they might need it.
<p>Inside of every successful Business “someone” has to take responsibility for the security of the computers and the information they hold. This is the role of the security professional, a trusted employee or a trust IT supplier working on behalf of the company. They keep the secrets of the company secure, reduce exposures to external threats and allow the right levels of access to the right people. They are the gate keepers that have the keys to the information that’s the life blood of any company.
<p>With this weighty responsibility comes the need to provide access in a controlled manor. Microsoft is one of many industry partners that consumers, small business customers and the security professionals can turn to for help. Many will ask &#8216;why Microsoft?&#8217;&nbsp; Unfortunately, they see us as the cause of these problems not the solution.
<p>The answer comes in three simple words. People, Process and Technology. You can have the world’s most secure technology and it will be useless if the People responsible for it’s implementation do have a Process in place to enable the security within the technology. So where does someone start? How can you understand what the threat looks like within your company?
<p>The quickest and simplest way to secure your business is by getting the right person to implement the right processes using the right technology for your business needs. They in turn need to know the steps that need to be taken on this undertaking. Get Safe Online is run by Government and industry partners like Microsoft, eBay, HSBC and others provides <a href="http://www.getsafeonline.org/nqcontent.cfm?a_id=1046">sound advice for business customers</a>. This is a good place for businesses to start and it&#8217;s one of the ways Microsoft is helping to solve the problems of computer security.
<p>Anyone who uses laptops for business needs to think about encryption and this is another area where Microsoft can help. Here&#8217;s a tip: our <a href="http://www.microsoft.com/technet/security/guidance/clientsecurity/dataencryption/default.mspx?SA_SC=MSsecurity">Data Encryption Toolkit for Mobile PCs</a>. It provides guidance and tools to help you protect your laptops and the information they hold. The tips and tricks outlined in this Toolkit are easy to understand, and the guidance shows you how to use two security technologies already available to you in Microsoft Windows XP or Windows Vista: the Encrypting File System (EFS) and Microsoft BitLocker Drive Encryption (BitLocker).
<p>Every day the security risks we face in the physical world are changing. The television news will often give you an insight to these risks and the steps you should take to protect yourself and your loved ones. The internet is no different to the physical world in that regard. It’s an ever changing environment that forces us to keep vigilant to the latest threats and the steps we should take to protect ourselves.
<p><a href="http://www.getsafeonline.org">Get Safe Online</a> will provide you with the news on these threats in a factual and practical manor. Please continue to tune in and listen to the advice it provides.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.getsafeonlineblog.org/whats-the-fuss-about/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
