Saturday, March 18, 2006

Rootkit + keylogging is not to be ignored

I have mentioned several times that the threat of rootkit and keylogging would be something for this year.

Again, from the report, "Hacking Made Easy" of the Washingtonpost.com indicates how serious this problem would be.

That is the reason for me to ask users of USC Password Security Storage System Light Version 2.0 use a specific webpage to avoid keyboard input. The version 2.5 is now in the final test stage and will be released within a week. The major change is to have the function embedded with the program so that users can manage the input easily and without the keylogger risk.

It may be difficult for us to detect if there is any rootkit type spyware. As pointed out in the report, it is an international organization and not individual that threatened the safety of our passwords.

Saturday, March 11, 2006

Can personal information be protected?

After visiting my dentist last week, I suddenly realized that personal information would be difficult to protect. The reason is simple; my dentist has my name, birthday, telephone number, address and Identity Card number. That means if someone can access my dentist's computer, the personal information of all his patients would be at risk.

I believe that it is a common practice for medical records etc. to have full information of patients. It is easy to know why such data is for our own good.

If someone uses my name, address, birthday, telephone number and Indentity Card number to apply for credit card, bank loan etc., will banks accept that? Of course, we may say the banks must check the person and have some procedure to confirm. In Hong Kong, even if I apply in person, the bank will not give me my credit card or anything. Instead, a confirmation by telephone and advice will be sent to my address for me to pick up the credit card etc. again in person and with Identity card.

Yes, it seems quite troublesome and some may demand the bank to simplify such procedure. Well, without such procedure, we are at risk. Remember that we cannot avoid to give personal information to our doctors, dentists etc. I accept such type of procedure.

The only thing that we must not give out is our passwords.