Cybercrime: Protecting digital identity on Spain’s National Radio, on “Els Matins” on RADIO 4, with Selva Orejón

30/06/2016
|

Digital identity protection, cybercrime, privacy, the lack of it, and cybersecurity, led by @selvaorejon, our director, who was interviewed yesterday by Mr Ramón Castelló Punsoda.

The topic began with growing concern about (in)security on social media as the holidays approach.

Children and teenagers are off school and have more free time, parents keep working, and BAM! Those unsupervised gaps begin—gaps that must be monitored and, of course, prepared for in advance.

The interview essentially revolved around the topics we will outline below, and it was mainly aimed at clarifying concepts, setting the scene, and providing examples to support what was explained; 30 minutes is not enough, but as we say where we come from (BAM by BAM, step by step):

CYBERCRIMES may use the internet as a means, or may occur almost/only within that environment, and we will now explain how Selva Orejón classifies them.

I divide them into 2 types of attacks

1. Random attacks: attacks where criminals go “net fishing” to see who is most vulnerable and, at the same time, which attack would yield the greatest return—although that assessment comes later.

Generally, advice is given on how to prevent these massive and seemingly random attacks (although, as David Pérez would correct me, Selva, nothing is random—we agree—it is only aimed at those with greater vulnerabilities, but not because it is motivated by a personal or professional issue, as targeted attacks are):

PHISHING (to obtain credentials): explain an iCloud example, from offline to ONLINE.

SCAMS: identity theft—access to credit cards. How? It depends: it can go from offline to ONLINE or be directly ONLINE. Bank websites (we fall for them less and less), having filled out a survey, phishing, access to your device and credential theft by placing apparently invisible malicious links.

ILLEGAL ACCESS TO COMMUNICATIONS (Wi‑Fi, viewing your partner’s device and communications—”explain important differences when it is a desktop device in a shared place…”)

DISCOVERY AND DISCLOSURE OF SECRETS: generally goes hand in hand with the previous offence; whoever accesses the information may want it to use it against the victim, or to publish it if there is nothing left to negotiate.

Let us pause for a moment… it often happens that evidence of infidelity, child abuse, etc. is presented, but it has been obtained unlawfully. The moment how that electronic evidence was obtained is revealed, it would be ruled inadmissible—and they could even be investigated for committing an offence.

2. Targeted or personalised attacks / PRIVACY

– 2.1) HARASSMENT / ABUSE: insults, threats against someone’s identity online

CYBERBULLYING (against minors): the use of telematic means (primarily the internet, mobile phones and online video games) to carry out psychological harassment among peers. This does not cover harassment or abuse of a strictly sexual nature, nor cases where adults are involved.

– 2.2) EXTORTION: forcing a person, through violence or intimidation, to perform or refrain from performing a legal act or transaction for profit, with the intention of causing financial harm to the victim.

SEXTORTION: a form of sexual exploitation in which a person is blackmailed with an image or video of themselves nude or performing sexual acts, generally previously shared via sexting.

– with or without contacting a group of contacts (think of the 4 stages of extortion)

– 2.3) SEXTING: distribution of sexual images—often of minors—obtained illegally or not, online

– They may be asking for something in return that is not only financial, but is of great value.

– More information, money, simply destroying your reputation (here they only threaten you and tell you to stop doing X activity, or due to a “psychological issue”).

– 2.4) GROOMING: behaviours and actions deliberately undertaken by an adult with the aim of befriending a minor, creating an emotional bond, in order to lower the child’s inhibitions and sexually abuse them.

– 2.5) STALKING: stalking (this opens the topic of privacy): a new offence of harassment, stalking or intimidation (stalking) through phone calls continually, following, or any other method that can seriously undermine the victim’s freedom and sense of safety, even if no violence occurs (Art. 172 ter of the Criminal Code).

The minimum age of sexual consent is raised from 13 to 16.

Attention: the unauthorised disclosure of intimate recordings or images obtained with the victim’s consent is classified as a new offence when they are later shared without the victim’s knowledge and seriously affect their privacy (sexting).

– A case of someone who tells me that a person calls and intimidates her, saying they have information about her, that she should stay calm, that the conversation will be long… They call from an unhidden number; we eventually track that number and it belongs to a person, we look for mutual contacts, and they appear.

– Invasion of privacy: sometimes it is worth noting that some people circumvent privacy very easily.

– 2.6) INCITEMENT TO HATRED (more common now due to how easily it spreads via networks): it follows the ruling of Constitutional Court Judgment 235/2007 of 7 November, which requires an interpretation of the offence of denial of genocide that limits its application to cases where such conduct constitutes incitement to hatred or hostility against minorities.

These offences may give rise to criminal liability for legal entities.

PREVENTION AND ADVICE

Think of security and privacy in 3 blocks; this way we can always do a quick review of where we stand on security and privacy.

1. DEVICES

1. ALWAYS keep software up to date

2. Update from secure websites

3. Antivirus/antimalware

4. Keep the webcam covered (HAND OUT A WEBCAM COVER)

2. NETWORK

1. Access secure networks (define “secure”:

2. You know who the owner is,

3. How it is configured,

4. How access is provided,

5. Username and password are not known or published (example: cafés, hotels…)

6. One-time username and password (public spaces, Starbucks)

7. At home/work

1. MAC filter (device identifier)

2. Remove MACs that are no longer in use

3. Monitor which devices are connecting

8. When they do not meet the rules: VPN (private browsing network, encrypted traffic)

3. USER BEHAVIOUR

1. This is truly the hardest part to control; they say we are the weakest link, AND I CAN CONFIRM IT.

2. TRAINING and knowledge are what save us from certain dangers.

3. Be aware of where you are, with whom, when, why…

4. Be responsible in browsing, connecting, and sharing data.

5. ATTENTION: PRIVACY—be clear that there are social, professional, family, personal, private and intimate areas of our lives, and lately we have mixed them up and we do not know whether the network profile we are using is for professional matters, and we make a mishmash of public and private; we also talk about our family (children, whom we love very much…, parents, uncles, grandparents, cousins…).

6. Awareness of EXTIMACY leaks

7. We have continuous information haemorrhaging, which comes in 2 types of communications.

8. PASSWORDS on networks: the issue is no longer passwords; it is about two-factor verification—implemented across almost all services.

ACTIVE AND PASSIVE COMMUNICATION

1) ACTIVE COMMUNICATION

1. We are aware that we are transmitting that information.

What is Digital Identity?

2) . PASSIVE COMMUNICATION

1. We are not aware of it and we are not tracking that leakage (photos say more than we think).

11. PROTECTING OUR DIGITAL IDENTITY:

1. Set up alerts for our most sensitive data

2. Full name

3. National ID number (DNI)

4. Phone numbers

5. Emails

6. Home and work addresses

7. TIP, if applicable

8. Carry out systematic monitoring of our information and request the removal of content that is not in our interest.

4. Special: SUMMER TIPS

1. Exercise extra caution in general—when we are very relaxed, and when we are very stressed!!!

2. Do not let your guard down: when we are relaxed our alertness drops, and BAM—that is when we fall most; curiosity gets the better of us… ALWAYS PREPARED, NEVER AFRAID (in honour of the Guardia Civil).

3. Mass attacks on WordPress sites—there have been some in recent weeks.

4. Be careful with active and passive communication, especially in relation to minors.

1. Contact networks and geolocation

2. Social media and images

3. Twitter and creepy (geolocation)

4. Mobile iCloud/Google account and theft

5. THEFT (impersonation pages copy the HTML and you fall for it)

1. iCloud cases in Barcelona

6. Purchases on “bargain” websites

7. Fraudulent charges

8. Do not enter credentials on iCloud/Gmail copy sites; sometimes they spoof SMS or email (they simulate a sender address different from the real one).

9. Do not publish personal information on social media.

5. DO NOT THINK THAT SHARING INFORMATION IS NOT WORTH IT—IF YOU DO, THEN GIVE ME YOUR COMPUTER AND EMAIL CREDENTIALS.

5. REPORTING / CITIZEN COLLABORATION

And if, even so, someone is or has been the victim of a breach, they must activate the onBRANDING post-breach protocol.

In summary:

  1. PREVENT
  2. ALERT/REPORT
  3. ASSIST/RESOLVE

Digital Identity

Methods for analyzing and
assessing online
reputation damage