The growing threat of spyware

July 27, 2005

The Federal Deposit Insurance Corporation -- the New Deal-era government agency designed to restore confidence in the Great Depression-shattered banking system of the United States -- is now providing guidance to banks to protect themselves and their customers from spyware, the latest threat to the integrity of the banks, experts told UPI's The Web.

Millions of Americans, banking at institutions such as Wachovia and Bank of America, have had their private financial information stolen by hackers through spy software, downloaded unknowingly from the Internet.

"The information collected through spyware can be used to compromise a bank's systems or conduct identity theft," said Michael J.Zamorski, director of the FDIC's division of supervision and consumer protection in Washington. "So it is critical that banks stay vigilant about the risks involved with this malicious software, and take appropriate action so that they and their customers do not fall victim to it."

The FDIC recommends that banks consider threats from spyware as part of their risk-assessment process. They should bolster Internet security and enhance employee training to understand the machinations of hackers. Experts had a mixed reaction to the FDIC's plans. Terry Brown, chief executive officer of Caymas Systems in Petaluma, Calif., a network-security firm, said the government's recommendations do not go far enough and will not "significantly alter" the risks that consumers face.That is because a May 2005 study by the software lab at Carnegie Mellon University in Pittsburgh -- financed by the science and technology directorate of the Department of Homeland Security -- found that the greatest risk to banks comes from insiders, and 49 percent of all network security breaches can be linked to employees, former employees, contractors and temporary workers. Still, the risk from spyware itself is significant, because 90 percent of spyware traversing the Internet is written for criminal purposes, according to Kaspersky Lab, an international anti-virus developer with an office in Woburn, Mass. "An entire industry exploded in 2004 as virus writers and hackers became increasingly involved with criminals to create malicious code," said Steve Orenberg, Kaspersky Lab's president.

The FDIC's guidance to banks may just be the first step by the government to protect consumers against hackers from Russia and China. Orenberg said some forms of e-mail advertising -- the lure that hackers use to plant spyware in PCs -- may be banned in the United States. Similar legislation may be introduced in Europe and other industrialized countries, he added.Another step may be mandating multi-layered authentication -- passwords -- for online banking accounts. "We believe the guidance regarding the bank's own infrastructure makes sense, since the bank can enforce it, but the guidance regarding consumers is naïve," said Naftali Bennett, chief executive officer of Cyota Inc.in New York City, an anti-fraud software developer for banks. "Banks cannot expect or enforce customers to keep spyware out of their computers, but banks can take steps to minimize or eliminate the damage that spyware causes."

Banking from public terminals, such as at colleges, libraries and Internet coffee shops, are a major problem, as most of those computers may be already infested with spyware, said Robert Siciliano, an ID-theft expert in Boston. Bennett suggested that banks begin to track and monitor all of the online transactions of their customers, from login to logout, to discern suspicious patterns. "Only by analyzing all transactions, invisibly and in real-time, and invoking stronger authentication at the first sign of potential fraud, will banks be able to reduce the damage of spyware and Trojans," Bennett said.

Another potential solution is "smart cards," which can be created to contain a number of one-time-use passwords. Once employed, they are not usable again.Unless banks implement such solutions, they might have to give up e-mail marketing altogether and, like eBay, reduce or eliminate the use of e-mail ads, experts said.

Copyright 2005 by United Press International. All rights reserved.


Rank not rated yet
Tags

Related Stories
Relevant PhysicsForums posts

More news stories

Anonymous knocks CIA website offline (Update)

The website of the Central Intelligence Agency was inaccessible on Friday after the hacker group Anonymous claimed to have knocked it offline.

Technology / Internet

created 11 hours ago | popularity 5 / 5 (10) | comments 16

New error-correcting codes guarantee the fastest possible rate of data transmission

Error-correcting codes are one of the triumphs of the digital age. They’re a way of encoding information so that it can be transmitted across a communication channel — such as an optical fiber o ...

Technology / Computer Sciences

created 19 hours ago | popularity 4.9 / 5 (8) | comments 6 | with audio podcast

Google users warned of threat to smartphone wallets

Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit shopping sprees.

Technology / Internet

created 9 hours ago | popularity 5 / 5 (2) | comments 0

New power source discovered

(PhysOrg.com) -- Researchers at the Massachusetts Institute of Technology (MIT) and RMIT University have made a breakthrough in energy storage and power generation.

Technology / Energy & Green Tech

created 18 hours ago | popularity 4.7 / 5 (31) | comments 8 | with audio podcast

Small modular reactor design could be a 'SUPERSTAR'

(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...

Technology / Energy & Green Tech

created 19 hours ago | popularity 4.4 / 5 (13) | comments 25 | with audio podcast


Humans may have helped the decline of African rainforests 3000 years ago

(PhysOrg.com) -- Large areas of rainforests in Central Africa mysteriously disappeared over three thousand years ago, to be replaced by savannas. The prevailing theory has been that the cause was a change ...

The power of estrogen -- male snakes attract other males

A new study has shown that boosting the estrogen levels of male garter snakes causes them to secrete the same pheromones that females use to attract suitors, and turned the males into just about the sexiest ...

Advanced power-grid model finds low-cost, low-carbon future in West

(PhysOrg.com) -- The least expensive way for the Western U.S. to reduce greenhouse gas emissions enough to help prevent the worst consequences of global warming is to replace coal with renewable and other ...

Could Venus be shifting gear?

(PhysOrg.com) -- ESA’s Venus Express spacecraft has discovered that our cloud-covered neighbour spins a little slower than previously measured. Peering through the dense atmosphere in the infrared, the ...

Complex wiring of the nervous system may rely on a just a handful of genes and proteins

Researchers at the Salk Institute have discovered a startling feature of early brain development that helps to explain how complex neuron wiring patterns are programmed using just a handful of critical genes. ...

Japan scientist makes 'Avatar' robot

A Japanese-developed robot that mimics the movements of its human controller is bringing the Hollywood blockbuster "Avatar" one step closer to reality.