ORLANDO—The ease with which even the most-secure computer systems can be breached was put on full display here—to say nothing of laptops, email accounts and mobile phones.
Were all that not enough concern for credit unions with an enterprise’s worth of data at risk, the risk is compounded by a demonstration of how easy it is to breach security via an accidental inside job.
Security guru Jim Stickley, CEO of San Diego-based Stickley on Security and co-founder of Trace Security, has been what’s known as a white hat hacker for years, breaking into the computers at biotech labs, the military and, yes, banks and credit unions to expose where vulnerabilities lie.
“Any company that has secured data has probably hired me to try to steal their data,” Stickley told NACUSO’s annual meeting here.
Speaking to the issue of “The Risk of Having Members: The Unfortunate Side Effect of Credit Union Success,” Stickley reiterated throughout his remarks how critical education is to the security of data. The biggest problem: the door to data breaches is often opened willingly and voluntarily by members and employees.
“Understanding the risks members are is important,” said Stickley.
When Stickley asked if anyone is his audience did not currently carry a mobile device, not a single hand was raised.
“Mobile technology,” he said, “is the new PC.”
Where the security risk lies is in the millions of apps available for download, and, related, the fact consumers installing those apps are all too happy to grant the app creator all kinds of access to their device and their data.
“Android and Apple now have more than one-million apps available for download,” said Stickley. “On GooglePlay there is no (security check); you can put up a malicious app. In many cases permissions are necessary to allow the application to perform properly. While mobile devices will warn you about the permissions required, do people really pay attention?” The answer, he said, is an obvious “no.”'
As Easy As Clicking 'Agree'
To test his own theory that the average person doesn’t read the permission questions Stickley created a very simple app and put it out on GooglePlay. The app was a Gmail counter that would tell the user how many unread Gmail messages the person had. The test was to see just how many people would not only download it but also “agree to everything,” every request for permissions to access personal information, network communication, storage, phone calls, system tools, messages, and everything else.”
Three months later and 1,300 people had installed the app, generating 1,950 e-mail addresses (reflecting people who had more than one email address).
“What did I learn? If I wanted to create a malicious app that would need people to allow all permissions, that will not be an issue,” said Stickley. “People have no idea what these permission questions are talking about, so they just hit ‘next.’”
Stickley then took it one step further. With permission from 20 friends and family members, he modified his app to steal online account log-in credentials.
“In this case it would retrieve email addresses and send them to me. Just an email address alone is so valuable,” said Stickley. “When I am doing any kind of hacking into an organization one of the main things I want to do is get their email addresses. It’s like gold to me. I can learn all about a person if I can get access to their email.
“I then went to all the major online vendors, Amazon, eBay, etc.,” he continued. “I click and say I forgot my password (while using the other person’s email). And I got that message where they send me a temporary link. It says ‘Check your email for a temporary link to reset the password.’ I changed the code that’s sitting on their phones and designed it to look for anything that came from any of these organizations, and forward on to me. And that included that temporary link. I changed the password. Once I have control I can do whatever I want. But one issue: a lot of times a second message is sent to the account saying a change took place. So I changed code so that message came just to me and deleted out of theirs.”
As a result of his test of just 20 people, he was able to change the password on more than 100 online applications, able to gain access to banking accounts, and able to do much more.
What many hackers or even nation-backed organizations will do, said Stickley, is find an app that is good and has a number of users, buy it, and place malicious code into it and send it out as an update.
Simple, And Risky
Often the riskiest apps are those that are the simplest, he said, such as an app that shows someone the strength of their wireless network, said Stickley, who gave a demonstration of how easy it was for him to take over a webcam on someone’s computer.
Shockingly, there are still organizations that will send you your real password,” added Stickley. “Who would be dumb enough to do that? Greyhound would be dumb enough to do this.” He showed the audience a screen shot of Greyhound sending him an actual password.
“If I have a plain text password, there is a very, very good chance that this person has used that password everywhere else. It’s shocking how many times people use the same password over and over again,” he said.
What can someone do to protect themselves?
First, said Stickley, pay attention to permissions. Even if an app has been downloaded thousands of times, he cautioned it’s not guarantee of security.
“When in doubt, don’t install the application,” said Stickley. “Also, a ‘Password no longer working’ message is a red flag.”
Mobile devices have become ubiquitous and, not surprisingly, also become the gateway into computer networks—including corporate networks.
“If you have a mobile device on the wireless network at your house or company, (malware) looks around at other computers on the network, and then looks for a place to attack. Once code is placed on that computer, the mobile device is no longer needed,” said Stickley. “You can have complete compromise of any unpatched systems on network. The code is not hard to write. If I was targeting an organization, if you allow mobile devices on your network, you could be compromising your entire network. IT security staff will often place desktops behind proxy servers designed to protect against viruses and other attacks. Internal desktops and servers are often missing critical patches. Mobile devices give hackers the ability to bypass firewalls.”
When it comes to stealing a credit union’s member database, malware essentially becomes the teller. Once breached, it pushes all the member data out to a server, and then deletes the file at the credit union.
Turning $100 Into $320 Million
How profitable can all this be?
Stickley offered this example: “If I could hack 2% of 16,000 FIs, that’s 320. If there is an average of 10,000 members/customers at these financial institutions, and if I stole $100 from each member, that’s $320 million.”
So what does all this mean to credit unions? According to Stickley:
- Manual hacking is an outdated practice.
- Organization attacks will become fully automated.
- What used to take days or months will now take just minutes.
- BYOD policies can mean bypass of the firewall and placement of hackers directly on internal network.
“Education of members and employees is really important,” said Stickley. “Make sure your employees aren’t installing apps they shouldn’t be. I am a big fan of limited Internet access. If employees don’t need it, don’t give it to them. If they need access to three or four sites, give them just three or four sites. At your credit union, patch all computers on local network, even computers that generally do not connect to the Internet. Remember that you can spend hundreds of thousands of dollars on security products and it just takes one human mistake to bypass it all.”
