Overblog Tous les blogs Top blogs Technologie & Science Tous les blogs Technologie & Science
Editer l'article Suivre ce blog Administration + Créer mon blog
MENU

Ce blogue complete mon site professionnel de recherche en robotique et couvre tous les sujets liés a l'innovation.

Publicité

Safety first and privacy also

Everyday, we hear more issues related to safety and it seems that some people would be prepared to sacrifice of lot of their human rights in exchange of more safety. These issues are more likely to become important as the popullation ages and new technologies are launched.

I am not against safety but I am for the one that counts and the one that is efficient. We should not let our fears blur our judgements. However, I do understand that it is not easy to say if you have been the victim of aggression. Remember that we live in a risky world. Everyone has ten times more chance to be crippled or killed in a car accident than any other threat.

The question that should come to mind is the one about the effectiveness of applied measures. It is well known that very simple solutions are sometimes the bests. 

Hence, in this post, I would like to talk about banking and transaction security and I aim here the Internet but also all network based activities where there is the need account and password handling. Reports show huge amount of frauds which cost a fortune to banks and building societies.

How can we use account names and passwords safely ?

What measures can make it more difficult to crack ?

The first way is to use encryption in our transactions. If we would use encryption levels higher that 512 bits, nobody could steal your information since this would need to long to decrypt the message with even a large network of computers. There is no secret that encryption is limited to 128 bits, thanks to our Information Agencies (espionnage and counter-espionnage); they have convinced our governments to limit encryption rights so that any conversation or information sent over the phones, the internet, the faxes, etc. can be decrypted with their computers. If spies can sneek into our messages and bank accounts quite easily, so can any high-tech mercenaries which are given sufficient means. Hence, any good IT man can build a computer network with the decryption programmes able to understand your messages. If MI5 (UK) or DST (France) IT specialist can do it, so can any IT pro sitting anywhere in the world. I can easily beleive that criminal organizations can hire the best computer specialists (since they are so many available) and keep them very loyal with the right arguments that you cannot refuse. For national security reasons, we are not allowed to protect ourselves to adequate level. Beware that it is considered a criminal offense to use more encryption than allowed. So do not try it since you might end up in a foreign prison (where human right do not apply) for protecting yourself.

Well, nowadays, most internet services provide encryption to insure a certain level of safety. You can recognize that by the "https:" written ou the path. Of course, they do not offer more than 128 bit encryption. This means that when you transfer your passwords through the Internet, they can be seen especially when you enter them fully to do a transaction since it is easy for any IT pro to check these accesses or to check all your moves by watching your IP address which is you computer identity (like soneone sitting in front of your house watching your moves), if you use fixed IP.

To alleviate this problem, there is one very good solution in three steps:

1) Find an Internet connection which dynamically allocate IP numbers. This way, your IP number will change each time you open a new session and your computer will become a lot more difficult to track down. 

2) All Internet secured activities should be handled the Polish Bank way. They do not ask for the complete password but they always ask for one or two digit out of the password. These digit position always change with each request.

3) Do a password change every month and do not use your spouse name or car make or country name where you are born.

So, each time you enter your password digit, you should make sure that your IP number is different, i-e, your connection is restarted; this way, the rogues will have a very hard time to rebuild your passwords. I do not say it is impossible, I just say it is the best way to slow down the process.

Then, for our safety, I do ask that all Internet providers insure dynamic IP allocation. We shlould have the full right to complete privacy for our business activities and our intellectual property. The BMW-VW crisis over the take-over of Rolls-Royce and Bentley has shown us that even the best companies within one country can be spying on each other in order to get privileged information. It is quite clear that for us living in Europe, the spies can easily operate from America since no law courts protect us between continents.

Well, I do honest research and I do not like to know that any government agent or company PI anywhere in the world can be spying on my intellectual property or on my clients' sensible commercial and technical information. If the counter-espionnage agencies need to spy on us, first they should be obliged to respect the law and obtain a warrant from a court judge.

At the international level, the problem is that any espionnage can easily fall out of national security since the Echelon programme has been known to pass very sensible commercial information to the domestic companies. How can you fight those abuse which do happen more often then all terrorist threaths ? It was even alleged that some European companies, hire  people  on the account of spied information that is obtained from a private investigator located in North America. Everything we do is detected and recorded, since everybody has now access to large memory means.

Using better protection for private reasons is considered a crime, but the law can change and we should require the right  to use heavier encryption.

Finally, the virus makers have been using their genius minds to especially target Windows, one final way to help improve our computer safety is to switch to other operating systems such as LINUX or Machintosh OS-X. Not only are they of better quality, they offer better security measures.

By the way, if any mathematician would come to prove the equivalence between NP-hard and Polynomial problems in terms of complexity, then encryption would become useless and no Internet or banking activity would be safe anymore. This would make a nice plot for the next Ludlum novel, isn't it ?

Publicité
Retour à l'accueil
Partager cet article
Repost0
Pour être informé des derniers articles, inscrivez vous :
Commenter cet article