Banks have been picking up on this (pdf) trend lately, that is, having a “personalized” picture to greet you when you login to your online checking account. As pointed out by Laura, it is a cheap and fake version of two factor authentication. The idea is that after you enter your account number (or something similar) you are presented with a customized picture that “proves” you are logging into the correct site. The problem is that users only notice the image once or twice and then are quickly desensitized to the fact that it is even there. It also teaches people to trust what they see on the screen. “If it looks like my banking site, it must be my[…]

I first noticed this phenomena when ING started it a few months ago. It was a minor annoyance then because only one of my banks was doing it, but now, others have started following suit, and it’s getting very annoying. I’m talking about the new login procedures that some banks are using – enter your account/user name/number, then you’re shown a butt ugly picture that you chose, and then you can type your password/passphrase in. I’m just glad they haven’t changed the way Quicken accesses my accounts (yet). I’m put through extra inconvenience for something that ultimately isn’t any securer than my standard username/password. This is supposedly to mimic two-factor authentication, but since I’m still only typing in my username[…]

One more: Facing a possible layoff from his job as an IT systems administrator, a 50-year-old New Jersey man was charged yesterday with planting malicious “logic bomb” code into the company systems where he worked that could have damaged more than 70 servers. The government alleges that Lin then modified the inserted logic bomb code in November 2003, but that it was still scheduled to deploy on his birthday on April 23, 2004. Due to an error in the code, however, it didn’t deploy as scheduled. In September 2004, Lin allegedly corrected the code error and changed the deployment date to April 23, 2005. Just because attacks involve computers doesn’t mean the attackers are any smarter. Lucky for us…

This person , after leaving the company he worked for planted a “logic bomb” on his old company’s network. A logic bomb is essentially leaving a piece of code to mess things up at a specified time. Duronio quit his job as a systems administrator in February 2002 after repeatedly expressing dissatisfaction about his salary and bonuses, the statement said. He then planted malicious computer code known as a “logic bomb” into about 1,000 of UBS PaineWebber’s approximately 1,500 networked computers in branch offices. On March 4, 2002, the “bomb” detonated and began deleting files. Now this not-so-bright person was trying to profit off of the potential drop in stocks his old company would suffer after the files were deleted.[…]

Just another hack attack, via SecurityFocus A fan of the music group Linkin Park appears to have hacked into the lead singer’s mobile phone web account, stealing the phone bill, call records and digital photos taken using the phone. Yeah, so what’s the big deal? Why am I suggesting it might be time to panic? The explosive attack on the privacy of the band member reportedly came from Devon Townsend, an obsessed fan inside Sandia National Laboratories Sandia Labs is part of the Nuclear Regulatory division of the Department of Energy… These are the folks that are dealing with the safety and security of our nuclear weapons. If there’s someone working there that can get this obsessed with Linkin Park,[…]

Trying looking online to find some good security news, come on…I dare you. That’s what I did today – as it is a somewhat slow news day. You know the old saying, “lead by example,” well that’s hard to do for the public if there aren’t many good examples. Oh well, I suppose, Man Doesn’t Have Identity Stolen because he Patched Windows doesn’t make for interesting reading…