« RSA Conference: Assessing online threats | Main | Kids turned cybercriminals »

April 09, 2008

RSA 2008: Only you can prevent cyber-attacks

Stormclouds Ira Winkler looks like a guy with a lot on his mind. And rightly so. After all, he helped orchestrate a hack of a power company, at the request of the company itself, which wanted to test its defenses. It took Winkler, who is president of the Internet Security Advisors Group, and his team just a day to break in. If he'd wanted to, he could potentially have turned out the lights on the power company's customers—or worse, since this company ran a nuclear reactor.

Obviously, the company's defenses did not hold up well. What was most striking was how easy it was for Winkler and his team to break in. One step in accomplishing the task involved tricking employees into clicking on an e-mail that downloaded malicious code onto their work computers.

"There is a major storm brewing that is receiving insufficient attention from the government," Winkler said.

If there's anything immediately apparent from this year's RSA Conference, it's that your own computer security is critical not only to you and your family, but to the safety of no less than the United States itself, its financial institutions, its infrastructure, the government, and its citizens, not to mention the rest of the world. "We can't have physical security without cyber security," said Greg Garcia, assistant secretary for cyber security and communications for the Department of Homeland Security.

Consider research conducted recently by Symantec. With record amounts in campaign donations being raised online, and with 70% of online donors forwarding e-mails to one another, as Symantec found, the election offers an opportunity for phishers or other cybercriminals to steal from campaigns and donors alike, or even affect the election's outcome.

To that end, the easiest way you can avoid supporting an election phisher is to watch out for typos. Symantec's researchers found that a simple misspelling on a campaign site, such as leaving out a period or inadvertently switching two letters in a candidate's name, brought them to a site owned by an entity other than the campaign. Most were advertising sites, but as the election comes closer the likelihood increases that you'll encounter sites with more malicious goals.

Another danger—allowing your computer to become part of a botnet. These networks of individual users' computers are controlled, without the owners' knowledge, by cybercriminals who use them to do everything from sending spam to attacking the government of Estonia. Up-to-date security software and caution when clicking on e-mailed links will help protect you, and the rest of us.

To help you find the best online security software and tips for computer safety and privacy, check out our free cyber-security center online.

—Donna Tapellini

For complete Ratings and recommendations on appliances, cars & trucks, electronic gear, and much more, subscribe today and have access to all of ConsumerReports.org.

Comments

I have been reading all I can about cyber attacks and warfare. The former Chief Strategist of Netscape - Kevin Coleman - has warned that we are at great risk in business, government and industry. Why is it we never listen to the experts before it is too late?

Post a comment

All comments are reviewed by our moderators, and will not appear on this blog unless they have been approved. Comments that do not relate directly to the blog entry's contents, are commercial in nature, contain objectionable or inappropriate material, or otherwise violate our User Agreement or Privacy Policy, will not be approved. Approved posts generally appear within 24 hours of receipt. For general inquiries not related to this blog, please contact Customer Service.

If you have a TypeKey or TypePad account, please Sign In

About this blog

Consumer Reports' electronics reporters, editors, and testers will quickly report on new developments and trends.

Consumer Reports Electronics Blog Archives

-    November 2008
-    October 2008
-    September 2008
-    August 2008
»    View All