linux operating commands and unix operating commands

Shredded Checks


 
Thread Tools Search this Thread
# 1  
Old 09-01-2008
Shredded Checks

Recently, I saw a report on CNN about a Texas salsa company that was caught shipping their orders using shredded checks as packing material. And they didn't use a cross-cut shredder either, so it was a nest of thin paper strips. This was revealed by an honest customer who decided to push back to say "should they really be doing this?" (I'm paraphrasing.) And to prove this point, the customer pieced together enough material to glean a few people's bank routing and account number, names, addresses and signatures. So the questions is: was this a new discovery? Or are there a few "customers" out there that have been quietly making orders over the years to get a box of valuable, exploitable information (and maybe some picante) delivered right to their door?

But stupid mistakes like this happen all the time. Hundreds of unencrypted laptops and PDAs are lost yearly, many (unfathomably) containing sensitive information about all of us even though encryption solutions have been available for years. And once our information leaks out it can travel around the world instantly.

The real problem is that this ill-gotten information can be used far too easily.

For example, there is a gas station (which I no longer frequent) that has pumps that only have "something you have" factor authentication: if you have a credit card (anybody's credit card), you can buy gas. The self-checkout lanes at a home improvement chain (which I also avoid) will let you charge away as long as you have a credit card--any signature will do. And that's the problem. For far too many companies, the key to an illegal purchase, or logging onto someone's financial account, requires just a single form of authentication: something you have (a stolen credit card) or something you know (a person's account information.)

Yes, activity on these stolen accounts will eventually be disallowed once theft is discovered, but there are those few hours until discovery that the thief has free reign to rack up some substantial charges. And then there is the aftermath for the victim to sort through, which sometimes can take years.

The answer is strong authentication at the point of purchase.

There is a great read at Red Tape Chronicles that details how bits and pieces of information being sold by the virtual truckload all over the world, which criminals can go through to piece together someone's profile. They eventually get enough information to get the victim's password to a financial site--a costly inference attack.

Perhaps we should accept the fact that privacy is as much a myth as 100% security, and insist that the stores and financial institutions we patronize implement stronger forms of authentication, such as 2-factor authentication. Fellow blogger Tim Bass has also written about this need. There are some banks and other financial sites that have begin to pay attention. But for now they are the exception. Let's hope this proactive stance continues to spread, and at an exponential rate, because there's a lot of catching up to do.


Image
Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Want to automate some DNS checks

I'd like to automate some common DNS checks that I do regularly. I do tech support, part of my job being to walk customers through setting up various DNS records, including SPF and DKIM. Most of these customers are small to medium sized businesses. The first part of the call is always me doing some... (6 Replies)
Discussion started by: pica
6 Replies

2. Shell Programming and Scripting

TCSH user input checks

I would like to check user input for arguments 1 and 2 for my Solaris TCSH script for the following: 1. That both user input arguments are numbers. 2. That they are both at least 5 digits. Thanks for the help. (1 Reply)
Discussion started by: thibodc
1 Replies

3. Shell Programming and Scripting

Script to do the following checks

Hi , I need a script for processing below scenario. I have to check daily by doing ftp IP to check it is logging or not. So i want this activity to be automated such that if login succesful i will get "FTP LOGIN SUCCESS" in a log file and if fails i want the error message in the same log... (1 Reply)
Discussion started by: sv0081493
1 Replies

4. Shell Programming and Scripting

Script to performs checks

Hi , I need a script which performs below activity I have one file named "testfile" in 9 different directories with same name. I want to perform below action with each testfile of each directory. if ; then mv listfiles listfiles_`date +%b%y` else echo No Such files fi ... (4 Replies)
Discussion started by: sv0081493
4 Replies

5. Shell Programming and Scripting

Daily Checks

Hey Guys, I'm seeking some assistance in getting this script to run as a cron job for the user oracle.. the script is basically to perform 2 ADRCI checks... see the script below... i'm getting the following error: /export/home/oracle/Daily_Checks/ADRCI_Daily_Checks.sh: syntax error at line 16:... (7 Replies)
Discussion started by: Racegod
7 Replies

6. UNIX for Dummies Questions & Answers

Daily File Checks

Hello all, I'm sorry if this is answered elsewhere, I've used the search function and can't find the specifics of what I'm after. I am brand new to playing with linux, and ideally I want to get better to help the company that I now work for. What I want to do: Create a script that I... (4 Replies)
Discussion started by: Aussiemick
4 Replies

7. Shell Programming and Scripting

Parameter checks -

Another stupid question. Why does this work on our Solaris box but not on our much newer red hat box... if then echo "running in test" else echo "running in live" I assume I am missing something between the . Any help is of course greatly appreciated. (2 Replies)
Discussion started by: mcclunyboy
2 Replies

8. AIX

Pre-checks

AIX Guys!!! What pre-checks would you do on a 5.3 server before TL/SP/APAR installation? Bala (2 Replies)
Discussion started by: balaji_prk
2 Replies

9. UNIX for Advanced & Expert Users

Doing Checks on a file

I have a process that I am trying to provide a solution for and have hit a brick wall and would like some pointers in the right direction. Basically on a daily basis a report is automatically generated in a CSV format (FIRST.CSV) which includes codes and amounts in the following format: ... (6 Replies)
Discussion started by: SAMZ
6 Replies

10. UNIX for Dummies Questions & Answers

health checks

Hello Anyone please help me with a health check script on HP-UX. (1 Reply)
Discussion started by: mahlathini
1 Replies
Login or Register to Ask a Question