Stop cybercrime, protect privacy, save world. Chris Monteiro Cybercrime, dark web and internet security researcher Systems administrator Pirate / Digital.

Slides:



Advertisements
Similar presentations
Weighing the Risks and Benefits of Online Financial Transactions
Advertisements

Achieving online trust through Mutual Authentication.
World of Credit By: Kunal Jolly. What is Credit? Credit mean that you have an opportunity to use someone elses money to meet your own requirements.
Payments and Loyalty Program Issues for the Game Industry Veronica McGregor November 2008.
Zenith Visa Web Acquiring A quick over view. Web Acquiring Allows merchants to receive payments for goods and services through the Internet Allows customers.
The Third International Forum on Financial Consumer Protection & Education “Fostering Greater Consumer Protection & Education” Preventing Identity Theft.
1.7.2.G1 © Family Economics & Financial Education – Revised May 2005 – Financial Institutions Unit – Electronic Banking Funded by a grant from Take Charge.
1. 2 Someone steals your personal information to commit fraud. A “buy now, pay never” shopping experience. What is Identity Theft?
David Abarca, Instructor Del Mar College Computer Corner Online Shopping.
8 Mistakes That Expose You to Online Fraud to Online Fraud.
An electronic machine that bank customers and credit union members can use to withdraw cash and make other financial transactions.
Elias M. Awad Third Edition ELECTRONIC COMMERCE From Vision to Fulfillment ELC 200 Day 24.
Credit Card And Prepaid Process Edward M. Kwang President.
Virtual Point of Sale (VPOS)
Electronic Payment By: El Panda. What is an electronic payment? Electronic money (also known as e-currency, e-money, electronic cash, electronic currency,
FINANCIAL SOCCER Module 3 Credit, debit and prepaid cards Collect a quiz and worksheet from your teacher.
Ecommerce Applications 2009/10 Session 31 E-Commerce Applications E-payment.
Scams Stevie's Scam School videos
Financial Transactions on Internet Financial transactions require the cooperation of more than two parties. Transaction must be very low cost so that small.
Online Shopping Take Charge of Your Finances
© Family Economics & Financial Education –October 2007 – Consumer Protection Unit – Online Shopping Funded by a grant from Take Charge America, Inc. to.
17-2 Financial Services and Electronic Banking. Types of financial services Savings services Financial institutions accept money for safekeeping. A broad.
COMPUTER CRIME AND TYPES OF CRIME Prepared by: NURUL FATIHAH BT ANAS.
EPS (Electronic payment system) is an online business process used for fund transfer using electronic means, i.e  Personal computers  services  Mobile.
Electronic Payment Systems University of Palestine University of Palestine Eng. Wisam Zaqoot Eng. Wisam Zaqoot March 2010 March 2010 ITSS 4201 Internet.
External Threats to Healthcare Data Joshua Spencer, CPHIMS, C | EH.
Banking: Checking Account What is a Checking Account? An account where money is deposited and kept for day-to-day expenses Also called demand deposit.
Banking:
Electronic Payment Systems
What is E-commerce Safety Precautions Password Strengths
STAY SAFE ONLINE. STAY SAFE ONLINE! PLEASE MAKE SURE YOU LOGIN AT THE CORRECT BANK URL / ADDRESS 1.NEVER LOGIN VIA LINKS 2.NEVER REVEAL YOUR PIN.
Cyber crime on the rise. Recent cyber attacks How it happens? Distributed denial of service Whaling Rootkits Keyloggers Trojan horses Botnets Worms Viruses.
Lloydes TSB Case Study Lloyds: LloydsTsb is the banking arm of Lloyds International One of the only banks left with rural branches found in villages They.
© Oklahoma State Department of Education. All rights reserved.1 Credit Cards: More Than Plastic Standard 8. 1 Credit Cards and Online Shopping.
Identity Theft By: Chelsea Thompson. What is identity theft? The crime of obtaining the personal or financial information of another person for the purpose.
Ecommerce Applications 2007/8 Session 61 E-commerce Applications Process views.
Electronic Commerce Semester 1 Term 1 Lecture 18.
Internet Security for Small & Medium Business Week 6
PAPER AC 1 : E-BUSINESS AND CYBER LAWS. MEANING OF E-BUSINESS  E-business, is the application of information and communication technologies (ICT) which.
Traditional and Electronic Payment Methods Chapter 3.
E-Commerce Taruna Diyapradana PBM. What is E-Commerce? E-Commerce is the trading in products and/or services conducted via computer networks.
Business Administration term project 2 (25%) financial Management Systems Debit card and credit card payments By Ashleigh Gray.
PRIVACY IN COMPUTING BY: Engin and Will. WHY IS PRIVACY IMPORTANT? They can use your computer to attack others (money, revenge) They can use your computer.
Copyright ©2005 CNET Networks, Inc. All rights reserved. Practice safety Learn how to protect yourself against common attacks.
Five Types of Payment Systems Cash Checking Transfer Credit Card Stored Value Accumulating Balance.
OBJECTIVES  To understand the concept of Electronic Payment System and its security services.  To bring out solution in the form of applications to.
Alert against Online Shopping Frauds. Online Shopping A form of electronic commerce whereby consumers directly buy goods or services from a seller over.
 Identity theft: When someone steals another identity, usually to obtain credit or other benefits in that person’s name  Phishing: Attempting to acquire.
Langara College PCI Awareness Training
Electronic Commerce Chapter 11 – Computers: Understanding Technology, 3 rd edition 1November 17, 2008.
Networking E-commerce. E-commerce ► A general term used to describe the buying and selling of products or services over the Internet. ► This covers a.
E-commerce Security By John Doran. What is e-commerce?  the buying and selling of products or services over the internet [3].  Most e-commerce transactions.
Protecting Your Assets By Preventing Identity Theft 1.
Electronic Money Lincoln Stein Whitehead Institute/MIT Center for Genome Research.
1 Law, Ethical Impacts, and Internet Security. 2 Legal Issues vs. Ethical Issues Ethics — the branch of philosophy that deals with what is considered.
Protecting Yourself from Fraud including Identity Theft Advanced Level.
1.7.2.G1 © Family Economics & Financial Education – Revised May 2005 – Financial Institutions Unit – Electronic Banking Funded by a grant from Take Charge.
Zeus Virus By: Chris Foley. Overview  What is Zeus  What Zeus Did  The FBI investigation  The virus for phones  Removal and detection  Conclusion.
E-C OMMERCE : T HE E -C ONSUMER AND THE ATTACKS AGAINST THE PERSONAL DATA Nomikou Eirini Attorney at Law, Piraeus Bar Association Master Degree in Web.
CNP Fraud. Occurs when a fraudster falsifies an application to acquire a credit card using an individual’s personal information. (Eg: postal intercept)
Banking in the United States. U.S. Banking System Overview  The Federal Reserve System is the central banking system of the United States.  Regulates.
Paypal PayPal is an e-commerce business allowing payments and money transfers to be made through the Internet. With a PayPal account, you can send and.
Protecting Your Assets By Preventing Identity Theft
Nick Mothershaw - Experian
Credit Cards: More Than Plastic
Shopping experience! Is it safe to pay online? Ian Ramsey
Credit Cards and Online Shopping
ELECTRONIC PAYMENT SYSTEM.
Founded in 2002, Credit Abuse Resistance Education (CARE) educates high school and college students on the responsible use of credit and other fundamentals.
Presentation transcript:

Stop cybercrime, protect privacy, save world

Chris Monteiro Cybercrime, dark web and internet security researcher Systems administrator Pirate / Digital rights activist Futurist

Blog: pirate.london Wikipedia:

Disclaimer!

Today we will cover: ●Clueless politicians ●Unfaithful Wombles ●Drugs ●History of Carding ●Actual solutions to financial fraud

Things we will not be solving today

When will computers be secure?

What do you do following your data being stolen? ●Change passwords ●Cancel credit cards ●Argue with bank ●Move house ●Reissue birth certificate ●Burn off fingerprints ●Facial surgery ●Burn credit agencies to the ground ●Join hippy commune / post WW3 dystopia

AM UK Map here (redacted)

SW18

Problems stopping financially motivated cybercrime ●Larger fines for breaches? Longer development, slows technical innovation ●Better security experts? Expensive, lack of talent ●Bug bounties? A possible step in the right direction, mostly for larger players only ●Unofficial bug bounties - hack the site win a prize

Government responses

History of Carding

Structure

Forums and Markets Online Merchant Desktop malware POS system ATM skimmers In person or receipt skimming, social engineering Hackers Resellers Checker services Offline fraudsters Hacking ecosystem

Cash-out

Buy game currency with stolen cards, minimal verifications Trade or ‘lose’ money to another account or accomplice Accomplice sells game currency directly or via 3rd party brokers Digital currency laundering

Purchase expensive consumer goods via websites will below- average payment verification with stolen details Ships to drop houses List goods on eBay Sell on eBay for ‘clean’ profits Ship to end customers Ship to 3rd party mules Use shady reshipping service Reshipping laundering

Print cards with stolen magstripe data (not chip & pin) Have ‘cashers’ buy luxury goods in-store Sell goods on ebay In-store cashing

Physically steal goods Purchase goods with stolen details Return to store without receipt and get gift card credit or store points Sell gift cards online or offline Gift and loyalty card fraud

Pizza & accounts

Card validation Address data required by the banks for payment verification ●IP address ●Country ●Browser ●Cookies ●Recent purchase history ●Unexpected quantity ●Unexpected currency ●Name match ●Address match “Sorry your payment has been declined” Fraudsters know how to circumvent all of these checks

Merchant Payment processor phish mitm hacksubvert But we use a payment processor so we’re secure!

Solution!

Virtual visa & one time payment options

Merchant Bank Unexpected charges Eventual refunds Eventual loss of merchant account

Merchant Bank Unexpected charges/payment declined Swift refunds #shame company on social media Small claims damages Inform consumer watchdogs Clean up infected local computer Swift action on merchant account Swift action on site breaches

Which site is worth attacking now?

Benefits Increased trust in small businesses for payments Better merchant accountability for banks Better breach and security accountability for merchants Better user accountability for infections / phishing Cybercriminals have almost nothing worth stealing :(

Use in other sectors: Delivery/Postal companies could offer limited use shipping addresses providers could offer integrated limited use addresses Telcos could offer limited use phone numbers

Moving forward Regulatory or deregulatory incentives via legislative changes

Future commerce Never give out ‘non-accountable’ information like credit card details or addresses Never give out personal information

End!