InfoSecurity Europe 2005
InfoSecurity Europe 2005

Online crime spirals out of control

New threats demand new practices, warns security expert

Written by Iain Thomson at InfoSec in London

The increasing number of criminals using the internet means that companies will have to completely rethink security practices, according to security guru Bruce Schneier.

Hacking activity has shifted over the past two or three years from being an amateur activity to one where organised crime has taken over. The two groups are very different and security officers will have to change tactics to deal with new threats.

"It used to be the hacker attacking and looking for glory, but now it's criminals looking for money," Schneier told vnunet.com.

"Forcing the criminal attacker to make a meaningless change of tactics by changing network settings doesn't work. In the language of fraud your tactic is merely a tactic, whereas hackers would look on it as a whole new challenge."

Schneier explained that the criminal classes are not hackers, but are using hacking techniques because they provide an automated way to commit fraud on a large scale. Factor in poor legislation in some countries, and online crime is booming.

He pointed to denial of service attacks as an example. These are now being used against e-commerce sites such as online gaming, gambling and pornography to extort money.

Schneier also punctured some security myths. He advised people not to bother shredding bills and mail, maintaining that thieves are not interested in stealing credit card numbers by the ones or twos when they can steal them online in the hundreds of thousands.

Politically motivated hacking is not on the rise, according to Schneier. It has remained a low-level threat and tends to increase only around specific events like the downing of a US spy plane in China two years ago.

He concluded that the change in tactics by criminals would lead to more and more online fraud and that they would always be one step ahead of the police.

"Criminals by their very nature are distributed whereas the police are an institution," said Schneier. "As such the police will always be slower to respond. Indeed most police [investigation] occurs only after a crime has happened."

Tags:

Further reading

Hackers move into information kidnap

Pay up or you'll never see your data again   More...

IT security perimeters 'limiting growth'

Companies losing out by hiding behind firewalls   More...

Web services promise new security headaches

Perimeter security no longer enough   More...

ISPs urged to bear security burden

Providers 'missing a sales opportunity', claim experts   More...

Related articles

Data breaches 'easily' avoided

Verizon report points to sloppy security   More...

Security experts slam Soca job cuts

Greatly increased threat to UK business   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Organised crime holding off on mobile viruses

Mostly the work of amateurs, say experts   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement